<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>ADLab</title>
    <link>https://wechat2rss.xlab.app/feed/16f16b9f4eb45442a824a52e3ddb040941a49f68.xml</link>
    <description>启明星辰积极防御实验室（ADLab）成立于1999年，致力于攻防技术人员培养、网络安全、信息安全深层攻防技术研究，开拓安全领域前瞻性技术研究，发现计算机及网络系统中存在的各种安全缺陷，帮助用户获得全面、持久的安全。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (ADLab)</managingEditor>
    <pubDate>Fri, 13 Dec 2024 19:18:04 +0800</pubDate>
    <lastBuildDate>Fri, 13 Dec 2024 19:18:04 +0800</lastBuildDate>
    <image>
      <url>http://wx.qlogo.cn/mmhead/Q3auHgzwzM4x3IXzAobkYKcrToe9pK80TM0qk8p8nf1VFxcYiawQADA/0</url>
      <title>ADLab</title>
      <link>https://wechat2rss.xlab.app/feed/16f16b9f4eb45442a824a52e3ddb040941a49f68.xml</link>
    </image>
    <item>
      <title>Unix通用打印系统cups-browsed远程代码执行漏洞分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619760&amp;idx=1&amp;sn=941fa5fb1aeba9276998379a942c2a88&amp;chksm=83062020b471a936682483c6d85729d8982115b1c593f912008de19196d755214a58855c0e6d&amp;scene=58&amp;subscene=0#rd</link>
      <description>安全研究员Simone Margaritelli披露了Unix通用打印系统CUPS存在一系列安全漏洞，利用多个漏洞组合可在受影响的系统上执行远程命令。启明星辰ADLab研究人员对该漏洞的原理进行深入分析，同时提出修复建议和缓解措施。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-12-13 19:18</span> <span style="display: inline-block;">北京</span>
</p>

<p>安全研究员Simone Margaritelli披露了Unix通用打印系统CUPS存在一系列安全漏洞，利用多个漏洞组合可在受影响的系统上执行远程命令。启明星辰ADLab研究人员对该漏洞的原理进行深入分析，同时提出修复建议和缓解措施。</p>


<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=7eb6abc3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTaSKkZcqvCYdngxqj978QIibR74VbxeN4aTR5YCza3FM59KgynB0W2Vw%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br/></p><p><strong>一、漏洞描述</strong></p><p><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">2024年9月，安全研究员Simone Margaritelli披露了Unix通用打印系统CUPS(Common UNIX Printing System)存在一系列安全漏洞，利用多个漏洞组合可在受影响的系统上执行远程命令。启明星辰ADLab研究人员对该漏洞的原理进行深入分析，同时提出修复建议和缓解措施。</span></p><table cellspacing="0" cellpadding="0" width="699"><thead><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="120" style="border-top: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-bottom: none;padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:
   widow-orphan;"><span style="font-size: 14px;color: rgb(136, 136, 136);"><strong><span lang="EN-US" style="font-size: 14px;font-family: 宋体;">CVE </span></strong><strong><span style="font-size: 14px;font-family: 宋体;">编号</span></strong><strong><o:p></o:p></strong></span></p></td><td width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: none;border-right: 1pt solid rgb(223, 226, 229);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:
   widow-orphan;"><span style="font-size: 14px;color: rgb(136, 136, 136);"><strong><span style="font-size: 14px;font-family: 宋体;">严重程度</span></strong><strong><o:p></o:p></strong></span></p></td><td width="162" style="border-top: 1pt solid rgb(223, 226, 229);border-left: none;border-bottom: none;border-right: 1pt solid rgb(223, 226, 229);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:
   widow-orphan;"><span style="font-size: 14px;color: rgb(136, 136, 136);"><strong><span style="color: rgb(136, 136, 136);font-size: 14px;font-family: 宋体;">受影响的服务</span></strong><strong><o:p></o:p></strong></span></p></td></tr></thead><tbody><tr style="mso-yfti-irow:1;"><td width="120" style="border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">CVE-2024-47176</span></p></td><td width="66" style="border-top: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: none;padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">8.3</span></p></td><td width="162" style="border-top: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: none;padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">cups-browsed &lt;= 2.0.1</span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="120" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-top: none;background: rgb(248, 248, 248);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">CVE-2024-47076</span></p></td><td width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">8.6</span></p></td><td width="162" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">libcupsfilters &lt;= 2.1b1</span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="120" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-top: none;padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">CVE-2024-47175</span></p></td><td width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">8.6</span></p></td><td width="162" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">libppd &lt;= 2.1b1</span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td width="120" style="border-right: 1pt solid rgb(223, 226, 229);border-bottom: 1pt solid rgb(223, 226, 229);border-left: 1pt solid rgb(223, 226, 229);border-top: none;background: rgb(248, 248, 248);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">CVE-2024-47177</span></p></td><td width="66" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">9.0</span></p></td><td width="162" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(223, 226, 229);border-right: 1pt solid rgb(223, 226, 229);background: rgb(248, 248, 248);padding: 2.25pt 4.9pt;"><p style="text-align:center;mso-pagination:widow-orphan;"><span style="font-family: 宋体;font-size: 14px;color: rgb(136, 136, 136);">cups-filters &lt;= 2.0.1</span></p></td></tr></tbody></table><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"></span></p><p><br/></p><p><br/></p><p><strong data-brushtype="text">二、相关介绍</strong></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"><br/></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">CUPS是一个开源的打印系统，用于Linux和其他类UNIX操作系统。CUPS 提供 Web界面和Berkeley</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">命令行界面</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">等多种方式来管理打印机和打印任务。例如访问<a href="http://localhost:631可管理打印机。" target="_blank">http://localhost:631可管理打印机。</a></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136095" data-ratio="0.3945945945945946" data-s="300,640" style="" data-type="png" data-w="555" src="https://wechat2rss.xlab.app/img-proxy/?k=5553facc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTl1ria2w4qNf2iaVEDbDZm8sT0xJoHJjb9H8khy2sFYz0lFQgPNekwdPQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">CUPS主要使用Internet Printing Protocol(IPP)来实现本地和网络打印机的打印功能。IPP是一个在</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">互联网</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">上打印的标准</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">网络协议</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">，它容许用户可以通过互联网作远距离打印及管理打印工作等。IPP采用的超文本传输协议HTTP的POST方法在客户端和打印服务器之间进行会话。</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136096" data-ratio="0.32194244604316546" data-s="300,640" style="" data-type="png" data-w="556" src="https://wechat2rss.xlab.app/img-proxy/?k=c7569522&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTc6kqj2ftwBltFC4Sbv6n6To8CPUA3h3bOhS3hzJHFtmPLaROxkrahA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">cups-browsed是一个开源的打印服务组件，它是Common UNIX Printing System(CUPS)的一部分。cups-browsed负责在本地网络上自动发现和添加打印机，使用mDNS（多播DNS）或DNS-SD（DNS服务发现）协议来侦测网络上的打印设备。它使得用户能够无需手动配置即可使用网络打印机。</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><br/></p><p><br/></p><p><strong data-brushtype="text">三、原理分析</strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><br/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">该漏洞源于cups-browsed服务，该服务绑定在UDP INADDR_ANY:631端口上，接受任何ip发送过来数据。同时该服务适配大多数UNIX系统，且大多数设备默认开启该服务。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">该服务的功能是发现互联网上的打印机，然后将打印机添加到系统服务上，相关功能的实现代码在cups-browsed.c文件中。代码中创建一个名为BrowseSocket的套接字，然后绑定在631端口。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136097" data-ratio="0.5809352517985612" data-s="300,640" style="" data-type="png" data-w="556" src="https://wechat2rss.xlab.app/img-proxy/?k=6e980b3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTYLMxzYNFsS1B4MSwRgRh8m644icPb0Lsc8LTOwyIKSfOqicP3lSiawkPQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">当检查到系统支持BrowseRemoteProtocols时，创建一个 UNIX 套接字通道，并设置监视该通道上的输入事件。一旦有数据可读，将调用process_browse_data函数来处理这些数据。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136098" data-ratio="0.18705035971223022" data-s="300,640" style="" data-type="png" data-w="556" src="https://wechat2rss.xlab.app/img-proxy/?k=2a489a8e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTMJ5C2ANeictkXWnbzqqXC0YSdkohJqgiafBiaXiagYdTS6dEa6tGOD8u7A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">BrowseRemoteProtocols参数可通过/etc/cups/cups-browsed.conf文件进行配置，此处一般默认开启。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136099" data-ratio="0.3345323741007194" data-s="300,640" style="" data-type="png" data-w="556" src="https://wechat2rss.xlab.app/img-proxy/?k=09db31d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTzhffG149NLGsyic7qgneWBBbpsnt9QaoolOIWbtyQl4KNVhlmOelo6w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">process_browse_data是关键的数据处理函数，该函数调用recvfrom从BrowseSocket套接字读取数据包packet。数据包格式遵从HEX_NUMBER HEX_NUMBER TEXT_DATA，使用该格式的数据的原因时是程序在处理packet时使用了下面的函数对数据进行处理。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">sscanf (packet, &#34;%x%x%1023s&#34;,&amp;type, &amp;state, uri)</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">接收到数据包后会调用allowed函数对ip进行合理性检查，该检查规则可通过/etc/cups/cups-browsed.conf文件进行配置。</span><o:p></o:p></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136100" data-ratio="0.5783783783783784" data-s="300,640" style="" data-type="png" data-w="555" src="https://wechat2rss.xlab.app/img-proxy/?k=f4befe41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTCUZ0EOew3I6b8c37m61K0icp1K4Yh9u848vofRe3Pf0sqE7OHf9JJzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;text-align: justify;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">allowed检查通过后会将数据包传入found_cups_printer函数进行进一步处理。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;text-align: justify;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">found_cups_printer函数中调用httpSeparateURI函数解析传入的uri参数并将其拆分为协议、用户名、主机名、端口、资源路径等部分。然后根据解析得到的各部分信息，对uri是否等于”/printers/”和”/calsses/”字符串进行检查。检查通过后调用examine_discovered_printer_record函数来处理发现的打印机记录。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136101" data-ratio="1.0864864864864865" data-s="300,640" style="" data-type="png" data-w="555" src="https://wechat2rss.xlab.app/img-proxy/?k=54fea005&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTicS5oSP8DM95mvzOicvldb8GJiavRPofLyticMQkDAoicUW2y468mEhkEuQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">处理完数据后调用cfGetPrinterAttributes函数进行回连，其中先使用httpConnect函数先建立http连接，然后调用ippNewRequest建立IPP连接，最后向IPP Server发送获取打印机属性的请求。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136102" data-ratio="0.6798561151079137" data-s="300,640" style="" data-type="png" data-w="556" src="https://wechat2rss.xlab.app/img-proxy/?k=9c49e966&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTVcZLjLAkJVqxwwXQFdVSY7vz8kQ5Tso9bkIjkrpnaEM4xw5ZZ1LMPQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;text-align: justify;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">发送完请求后cups-browsed程序会调用ppdCreatePPDFromIPP2函数创建PPD文件然后将接收的打印机属性依次保存到文件里面。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136103" data-ratio="0.11351351351351352" data-s="300,640" style="" data-type="png" data-w="555" src="https://wechat2rss.xlab.app/img-proxy/?k=6eaacb68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtT2YMJRr7NlSX0ajJhdakMskH8teWsIRZY7e6zlD4vKiblhHjKA33UGuA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">至此，已经可以成功设置PPD的属性，接下来就是想办法执行写入的数据。这需要使用CUPS的一个过滤器指令cupsFilter2，该指令用于处理打印作业中的筛选和转换操作。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">例如下面的指令要求cups将符合打印机属性的postscript格式的数据传递给program过滤器进行处理，优先级为0。</span><o:p></o:p></p><p><strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">*cupsFilter2:&#34;application/pdf application/vnd.cups-postscript 0 program</span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"></span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;text-align: justify;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">CUPS规定只能使用/usr/lib/cups/filter路径下面的可执行文件，最终以</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">foomatic-rip过滤器</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">作为利用的目标。该过滤器接受PPD文件中的FoomaticRIPCommandLine指令，通过它可以执行任意命令。</span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"><br/></span></p><p><br/></p><p><strong data-brushtype="text">四、漏洞修复</strong></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"><br/></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">截至目前，Ubuntu，Debian，Fedora等多个系统中涉及漏洞的多个版本已基本修复。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136104" data-ratio="0.5323741007194245" data-s="300,640" style="" data-type="png" data-w="556" src="https://wechat2rss.xlab.app/img-proxy/?k=f36f82b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTzbEeabPvgmCOygNZOGkKhCxR0mRSVJ0LovhZJlFbB4ZyE6pCgcEx2g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">在Ubuntu最新版的修复方案中完全删除对旧版 CUPS 协议和 LDAP 的支持。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136105" data-ratio="0.31351351351351353" data-s="300,640" style="" data-type="png" data-w="555" src="https://wechat2rss.xlab.app/img-proxy/?k=ca184964&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTFvSLwhMQBSAeNIUD2ZYtTDiaJn7E4Eo6mFkfPvXInQAw0SEAaWvDAOo1S5RDCJh4KzUI3mrPvtlA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"><br/></span></p><p><br/></p><p><strong data-brushtype="text">五、缓解措施</strong></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">漏洞修复版本已经上传，Ubuntu系统中运行下面两条命令即可进行升级。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">sudo apt update</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">sudo apt upgrade</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">如果上面的升级不成功，使用下面两种办法缓解该漏洞：</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">（1）直接禁用cups-browsed服务</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">sudo systemctl stop cups-browsed</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">sudo systemctl </span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">disable cups-browsed</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;visibility: visible;">（2）如果该功能需要使用，建议将/etc/cups/cups-browsed.conf中BrowseRemoteProtocols指令值从默认的“dnssd cups”更改为“none”。</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><br/></p><p><br/></p><p><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 15px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;">参考链接：</span></strong></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[1]<a href="https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/" target="_blank">https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/</a></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[2]<a href="https://gist.github.com/stong/c8847ef27910ae344a7b5408d9840ee1" target="_blank">https://gist.github.com/stong/c8847ef27910ae344a7b5408d9840ee1</a></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[3]<a href="https://censys.com/common-unix-printing-service-vulnerabilities/" target="_blank">https://censys.com/common-unix-printing-service-vulnerabilities/</a></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[4]<a href="https://blog.ostorlab.co/cups-vulnerabilities.html" target="_blank">https://blog.ostorlab.co/cups-vulnerabilities.html</a></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[5]<a href="https://github.com/OpenPrinting/cups-browsed/security/advisories/GHSA-rj88-6mr5-rcw8" target="_blank">https://github.com/OpenPrinting/cups-browsed/security/advisories/GHSA-rj88-6mr5-rcw8</a></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[6]<a href="https://ubuntu.com/security/notices/USN-7043-4" target="_blank">https://ubuntu.com/security/notices/USN-7043-4</a></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[7]<a href="https://ubuntu.com/security/notices/USN-7042-3" target="_blank">https://ubuntu.com/security/notices/USN-7042-3</a></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[8]<a href="https://launchpad.net/ubuntu/+source/cups-browsed/2.0.1-0ubuntu2.1" target="_blank">https://launchpad.net/ubuntu/+source/cups-browsed/2.0.1-0ubuntu2.1</a></span><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[9]<a href="https://www.upwind.io/feed/analyzing-the-latest-cups-rce-vulnerability-threats-and-mitigations" target="_blank">https://www.upwind.io/feed/analyzing-the-latest-cups-rce-vulnerability-threats-and-mitigations</a></span></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;color: rgb(0, 0, 0);font-size: 15px;">启明星辰积极防御实验室（ADLab）</span></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap-style: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br/></p><p><br/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">“黑雀攻击”概</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/CVE累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、数据安全研究、5G安全研究、人工智能安全研究、移动安全研究、物联网安全研究、车联网安全研究、工控安全研究、信创安全研究、云安全研究、无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等<span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1.5px;">。</span></span></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap-style: initial;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap-style: initial;background-color: rgb(255, 255, 255);"><br/></p><p style="margin-bottom: 0px;-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap-style: initial;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-align: start;text-indent: 24px;"><img class="rich_pages wxw-img" data-imgfileid="502136107" data-ratio="1.1205673758865249" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.969px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a7f561d3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAwNTI1NDI3MQ%3D%3D%26mid%3D2649619760%26idx%3D1%26sn%3D941fa5fb1aeba9276998379a942c2a88%26chksm%3D83062020b471a936682483c6d85729d8982115b1c593f912008de19196d755214a58855c0e6d%26scene%3D58%26subscene%3D0%23rd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 13 Dec 2024 19:18:00 +0800</pubDate>
    </item>
    <item>
      <title>Android恶意软件混淆与对抗技术专题</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619740&amp;idx=1&amp;sn=c2db7658cccb38ac22236f6cd4b17e7a&amp;chksm=8306200cb471a91a7e1750b3803c9179fa15d7a2915b68786133c51080a0360f0633d437e9b3&amp;scene=58&amp;subscene=0#rd</link>
      <description>本文将对我们分析Android恶意软件过程中所遇到的常见混淆技术进行总结和分析，从恶意软件混淆与对抗的视角来阐述另一面的安全攻防技术，以帮助安全工程师和用户们更加深入理解这一领域的技术情况，同时也有助于分析人员更高效地分析恶意代码。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-11-25 17:19</span> <span style="display: inline-block;">北京</span>
</p>

<p>本文将对我们分析Android恶意软件过程中所遇到的常见混淆技术进行总结和分析，从恶意软件混淆与对抗的视角来阐述另一面的安全攻防技术，以帮助安全工程师和用户们更加深入理解这一领域的技术情况，同时也有助于分析人员更高效地分析恶意代码。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=6ad026a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nTzwg0o7nrGOLJCgoEn5UJbEovqkL2pLAnrPKq9dOhpGsJiaTcaC2poNwOj5MD7uqdusaQqTO2j4xQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br/></p><p><br/></p><p><span style="color: rgb(120, 172, 254);"><strong>第一章</strong></span></p><p><br/></p><p><strong><span style="font-size: 16px;color: rgb(120, 172, 254);">概 述</span></strong></p><p><br/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">近年来，Android恶意软件数量不断攀升，其采用的攻击和对抗技术也变得越来越复杂。为了对抗安全分析，绕过安全检测，窃取敏感数据或破坏系统安全，恶意软件利用各种对抗技术来伪装和隐藏其恶意行为和代码逻辑。这些对抗技术中，针对资源、文件、字节码指令及机器码指令的混淆技术被广泛地引入到恶意软件中，成为高级黑客与逆向工程师对抗的重要战场。</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">混淆技术的核心目标是增加分析复杂性来对抗逆向工程，同时也能提高免杀能力，主要对抗目标包含逆向工程师、静态分析工具、动态调试工具以及自动化检测系统。混淆技术通过设置分析陷阱、改变文件结构、增加指令复杂度、虚拟化指令、隐藏代码和资源等各种繁杂的技术来掩盖其行为特征和攻击意图，同时给分析人员尽可能大的制造分析障碍，延后其恶意行为暴露的时间。同时，恶意软件通过组合运用各种各样的混淆与分析对抗技术，对现有安全检测工具和防护机制形成了严峻挑战。这需要不断跟进各种技术的发展，对新的手段进行深入研究，制定有效且快速的应对方法，强化分析工具和检测工具，同时也有助于快速应对高级且复杂的恶意软件攻击。</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">本文将对我们分析Android恶意软件过程中所遇到的常见混淆技术进行总结和分析，从恶意软件混淆与对抗的视角来阐述另一面的安全攻防技术，以帮助安全工程师和用户们更加深入理解这一领域的技术情况，同时也有助于分析人员更高效地分析恶意代码。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(120, 172, 254);"><strong>第二章</strong></span></p><p><br/></p><p><strong><span style="font-size: 16px;color: rgb(120, 172, 254);">Android恶意软件混淆技术的演进</span></strong></p><p><br/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">随着移动安全领域对抗的不断升级，Android 恶意软件的混淆技术也经历了显著的发展，从简单的标识符混淆逐步演进到复杂的虚拟化保护（VMP）技术，呈现出由浅入深、逐步升级的趋势。为更清晰地理解这一变化，我们将混淆技术的发展大致划分为早期、中期和当前阶段，并从不同层面进行详细解析。</span><o:p></o:p></p><h2 style="text-indent: 0em;margin-bottom: 16px;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);color: rgb(120, 172, 254);">2.1 早期阶段：基础伪装与简单加密 </span></strong><o:p></o:p></h2><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">在早期，恶意软件的混淆技术主要以掩盖代码和资源内容为目标，手段较为简单直接，其混淆技术主要集中于Java层，利用Android应用以Java语言开发的特性，通过简单的混淆手段规避安全分析和检测。在这一时期，恶意软件开始探索文件格式相关的混淆策略。例如，通过修改ZIP格式的APK伪加密，以及2012年黑帽大会上首次提出的利用DEX头隐藏代码的技术，这一策略随后被Syrup恶意软件所采用。同时，木马Obad利用商业混淆工具DexGuard（ProGuard的增强版）实现了Manifest字段的复杂混淆以及基于clinit方法的动态代码解密，被誉为“史上最强Android木马”。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">这一阶段，短信拦截类和锁机勒索类恶意软件广泛采用多种混淆手段，包括代码混淆、字符串加密、代码分割、垃圾代码注入，以及商业加固工具的使用。这些技术尽管相对基础，但在当时的安全环境中，已经显著提高了恶意软件的隐蔽性和抗检测能力。下图展示了一款短信拦截木马的混淆效果。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136038" data-ratio="0.4527777777777778" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ddb79a9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5fNAHsNDctGZXPbdqPFPLc30r3WGGuEuTyILpSicfXAYicN8tC8zicgsKQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><o:p></o:p></p><p style="text-indent: 0em;text-align: center;margin-bottom: 16px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图1 一个短信拦截木马的混淆示例</span><o:p></o:p></p><h2 style="text-indent: 0em;margin-bottom: 16px;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);color: rgb(120, 172, 254);">2.2 中期阶段：逻辑复杂化与动态对抗 </span></strong><o:p></o:p></h2><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">随着安全检测技术的不断提升，恶意软件逐步引入更加复杂的混淆手段，以提高隐蔽性并有效规避分析。为规避静态分析，它们利用动态加载和反射机制，通过反射动态调用隐藏的关键代码。同时，恶意软件采用多重加密与解压策略，对关键代码进行多层次加密，并在运行时通过复杂的解密过程逐步释放真实的恶意逻辑。例如：在我们发布的分析报告《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649612933&amp;idx=1&amp;sn=481bc0a8b24a26bd9ef89c908cc6799b&amp;chksm=83063f95b471b6839633e344628c4e8b642673270d9c050f78e986113c913239c7481bc3b59a&amp;scene=21#wechat_redirect" textvalue="新型Android银行木马“MoqHao”利用社交网络隐藏C&amp;C服务器" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">新型Android银行木马“MoqHao”利用社交网络隐藏C&amp;C服务器</a>》中，恶意软件将真正的恶意dex文件加密后，以Base64编码的形式保存在原始APK的assets目录下。在这种情况下，原始APK仅作为一个外壳存在，其在运行时会动态解密并加载真正的恶意dex文件，以实现其攻击目的，其过程如下图所示：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136039" data-ratio="0.5914438502673797" data-s="300,640" style="" data-type="png" data-w="935" src="https://wechat2rss.xlab.app/img-proxy/?k=9c965038&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5tGjgg9WFe4aQvv074C6SILE66kyxpAB8WIpnBansIIPkjAssdMrnSw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图2 Java层混淆dex文件的示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">为了扰乱分析路径，恶意软件引入控制流混淆技术。通过插入无关的分支、循环和跳转语句，恶意软件使代码执行路径更加复杂，阻碍分析人员还原其逻辑。而在结合商业加固解决方案后，通过内存加载、指令抽取和指令转换等技术，进一步提升了对抗分析的能力，使得分析人员难以准确还原其实际的执行逻辑。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">随着反混淆技术的进步和现代化反编译工具的普及，恶意软件逐渐将混淆策略向Native层转移，以进一步提升逆向分析的难度。其常用技术包括对会话数据加密以防止敏感信息泄露、加密关键函数体以隐藏恶意行为、插入花指令干扰反汇编工具分析、利用LLVM框架实施复杂的代码混淆，以及通过反调试技术检测和阻止调试器介入。这些策略相辅相成，不仅显著增加了逆向工程的复杂性，也进一步提高了安全研究人员分析的技术门槛。例如：在我们发布的《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649612437&amp;idx=1&amp;sn=b6ac85b49e79f1a6a059b2f55cc0822a&amp;chksm=83063d85b471b493d01a9219241cb79da9652b824caa61695871503311ce0ed0cdd1d56c13fa&amp;scene=21#wechat_redirect" textvalue="一款通过SO进行自保护的银行APP劫持木马深度分析报告" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">一款通过SO进行自保护的银行APP劫持木马深度分析报告</a>》中，详细分析了该木马的运行行为。具体而言，libload.so模块负责解密并加载实际的恶意代码。该模块利用Java反射机制调用javax.crypto包中的加解密函数，对存储在assets目录下的mycode.so文件进行AES解密。解密后的文件通过自定义的DexClassLoader加载并执行，执行完毕后，解密的文件会被删除。这些精心设计的混淆手段有效隐藏了恶意行为，显著增加了安全分析的复杂性，使得恶意软件的检测和分析变得更加困难。加载Native解密库的部分代码如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136040" data-ratio="0.2828162291169451" data-s="300,640" style="" data-type="png" data-w="838" src="https://wechat2rss.xlab.app/img-proxy/?k=22831f16&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5UKAxiaF0iapKicPJROu2bv6zWUpMucibZibr2zbTZTM3qSLAxHauibw6pqsA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图3 Natvie层混淆示例</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">此外，针对文件格式的混淆策略也变得更加多样和复杂。它们巧妙利用 Android系统对某些文件格式字段宽松校验的特性，同时借助反编译工具对文件格式的严格解析逻辑，设计了多种干扰和隐藏机制。通过对这些文件格式的灵活利用，恶意软件得以实现更高程度的隐蔽性，进一步提高了逆向分析和检测的难度，同时也为混淆技术的持续发展奠定了基础。</span><o:p></o:p></p><h2 style="text-indent: 0em;margin-bottom: 16px;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);color: rgb(120, 172, 254);">2.3 当前阶段：复杂混淆与多层对抗 </span></strong><o:p></o:p></h2><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">在当前阶段，恶意软件的混淆技术已经高度复杂化，广泛结合动态和静态对抗手段，以增强隐蔽性并对抗多种检测方法。通过将Java层代码混淆、动态加载与Native层加壳技术融合使用，恶意软件将核心逻辑分布于不同层次中，大幅提高了检测和分析的复杂性。以下是目前常见的混淆策略：</span><o:p></o:p></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">Java层与Native层相结合：恶意软件通过将Java层的代码混淆、动态加载、VMP等技术与Native层的代码混淆手段相结合，将恶意逻辑分散在不同层次中。这种跨层混淆策略显著增加了检测和分析的复杂度，要求分析人员同时掌握多种技术，才能全面理解其运行机制。</span><o:p></o:p></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">使用其他开发语言：恶意软件常利用Lua、GoLang、Flutter、易语言等非传统的 C/C++ 语言进行开发，从而显著增加逆向分析的难度。这些语言独特的特性进一步提高了分析的复杂性，同时削弱了传统逆向分析工具的效率和效果。</span></p></li><li><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">运行环境检测及反调试：恶意软件通过检查设备的系统属性、文件系统结构、系统权限状态等，判断目标设备是否为模拟器或已获取Root权限，并在检测到这些特征时阻止恶意逻辑的运行。同时，它们调用系统API检查调试状态，监测调试工具特有的行为，甚至主动引发异常以捕获调试工具的反应，有效阻止动态分析工具的干扰。</span></p></li><li><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">商业加固保护技术：一些恶意软件使用商业加固保护技术，进一步加强了代码的抗逆向能力，使得传统的安全工具和分析方法难以奏效。</span></p></li><li><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">代码虚拟化技术：通过将代码翻译为自定义的虚拟指令集，并在运行时通过嵌入的虚拟机解释执行，这种技术极大地提高了逆向分析的难度。</span></p></li></ul><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">例如，某恶意软件通过使用Native代码实现对Frida和IDA的检测，其代码如下：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136041" data-ratio="0.4145758661887694" data-s="300,640" style="" data-type="png" data-w="837" src="https://wechat2rss.xlab.app/img-proxy/?k=9b34798a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL56727eCTok17QZoJ07INCPaEaUHTniaI47S73H8IlgaqVEkDwNufhMQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图4 Natvie层检测调试器的代码示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">Android恶意软件的混淆技术已经从简单的代码混淆逐渐发展到如今复杂的跨层结合形式，其隐蔽性持续增强，技术手段也愈发多样化。这种发展趋势对传统安全检测工具而言是严峻的挑战，同时也促使研究人员必须不断创新应对策略，以此来应对恶意软件日益复杂的混淆手段。在此背景下，深入了解并解析常见的混淆技术，是提升恶意软件分析和检测能力的关键。接下来，我们将通过实际工作中常遇到的恶意软件混淆技术进行详细分析，探讨这些技术的应用方式及相应的防范对策。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(120, 172, 254);"><strong>第三章</strong></span></p><p><br/></p><p><strong><span style="font-size: 16px;color: rgb(120, 172, 254);">常见混淆手段与技术解析</span></strong></p><p style="letter-spacing: 0.578px;text-indent: 2em;margin-bottom: 8px;"><br/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">在分析Android恶意软件时，安全研究人员通常需要从静态分析和动态分析两方面入手。静态分析往往是最先进行的步骤，而混淆技术通过修改代码的结构和表达方式（如字符串加密、代码拆分、动态加载等），使恶意软件的分析难度显著增加。本文将以安全研究人员分析APK文件的过程为切入点，逐步介绍各种反混淆策略，帮助研究人员有效应对不同层次的混淆技术挑战。</span><o:p></o:p></p><h2 style="text-indent: 0em;margin-bottom: 16px;"><span style="color: rgb(120, 172, 254);"><strong><span style="color: rgb(120, 172, 254);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">3.1 APK反编译工具的对抗</span></strong></span><o:p></o:p></h2><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">在分析Android应用时，首先需要使用APK反编译工具（如Apktool、Jadx）提取APK文件中的源代码和资源。然而，恶意软件往往会通过多种混淆手段对APK进行保护，以干扰反编译过程。例如，恶意软件可能利用Android在解析APK文件时未严格校验ZIP格式的某些字段，从而通过篡改APK文件的ZIP格式字段来绕过基于ZIP格式解析的反编译工具。这种手段尤其常见于一些基于Android的银行木马（如BianLian、Cerberus和TeaBot）中，目的是阻止安全研究人员和自动化分析平台有效提取APK文件内容，进而对抗静态分析和反病毒检测。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">为了更好地理解恶意软件的混淆策略，尤其是如何通过篡改ZIP格式字段来干扰反编译过程，有必要了解一些ZIP文件结构的基本信息。虽然ZIP格式的详细结构超出了本文的讨论范围，但我们可以简单介绍一些常见的、恶意软件经常篡改的字段。我们以 Python 的zipfile.py 模块中的 ZipInfo 类为例，展示了 ZIP文件元数据中的多个关键字段。具体字段及其含义如图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136042" data-ratio="0.7457795431976166" data-s="300,640" style="" data-type="png" data-w="1007" src="https://wechat2rss.xlab.app/img-proxy/?k=b92e7c83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5sO2Wumonm1xhusLicmlWJrFfQ73DFIZReguxZQANiapTRtBhnfRQqibhg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图5 Zipinfo类的结构信息</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">其中，compress_type、extract_version、reserved和flag_bits都是恶意软件常常篡改的字段。这些修改可以导致反编译工具在解析文件时出现错误或无法正确读取文件内容，从而有效地阻碍静态分析过程。通过篡改这些字段，恶意软件不仅能够规避常见的反编译工具，还能增加被检测的难度，提高其在静态分析中的隐蔽性。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">在了解了恶意软件如何通过篡改ZIP格式字段来对抗静态分析后，接下来我们需要关注Android应用中另一个常见的反编译手段——AndroidManifest.xml文件（以下简称“清单文件”）。清单文件是反编译过程中必须解析的关键部分，它包含了应用的核心配置，如组件、权限等信息。因此，提取、读取和分析清单文件是静态分析APK样本时的首要步骤。为了规避反编译工具的识别，恶意软件通常通过精心篡改清单文件来干扰其正常解析。由于清单文件在静态分析中的重要性和复杂性，它成为了恶意软件常用的反编译对抗手段之一。如果读者对清单文件的具体结构不太了解，可以自行访问以下链接（<a href="https://bbs.kanxue.com/thread-194206.html）查阅相关信息。" target="_blank">https://bbs.kanxue.com/thread-194206.html）查阅相关信息。</a></span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">接下来，我们将介绍几种常见的清单文件混淆手段，探讨恶意软件是如何通过这些手段对抗反编译工具并隐藏其恶意行为的：</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（1）修改XML文件的魔术：恶意软件通过篡改清单文件中的魔术字段，使得静态分析工具在解析时出现错误。这些修改通常不会影响应用的正常运行，但会导致分析工具无法正确解析清单文件的结构，甚至可能引发反编译工具的异常错误，从而阻止反编译过程，无法提取源代码。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136043" data-ratio="0.4185185185185185" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b132d0b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5cRwicTicmqofqSt0pfhbFiaWib6XozJIUC1RbbwBFsug5SIVianzx0xKW3g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图6 左图为正常的魔术，右图为混淆的魔术示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（2）篡改关键字段：恶意软件可能会篡改清单文件中的关键字段，例如通过修改StringPool中字符串的个数。虽然Android系统在运行时并不依赖这个字段来计算字符串的个数，而是通过动态计算来处理字符串，但一些反编译工具却会依赖这个字段来解析XML文件中的内容。通过篡改这个字段，恶意软件可以干扰反编译工具的正常解析，导致工具读取到错误的字符串个数，从而无法正确解析清单文件的结构，进而影响静态分析的准确性和完整性。这种手段有效增加了静态分析工具的分析难度，提升了恶意软件的隐蔽性。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136044" data-ratio="0.875" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=188bcd49&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5HCzIkBF2hDCUHf60xKzO4BzJkBRbBIJn2ibLYa2MNJ8BqFGoddXptWA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图7 篡改StringPoolSize的混淆示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">在上图中，我们可以看到，stringCount的值为2907，而StringOffsets开始于偏移位置36，大小为 11628。StringOffsets是一个包含每个字符串在字符串池中的相对偏移量的数组，其大小为 stringCount * 4，即 11628。反编译工具按照混淆后的stringCount值计算StringOffsets大小，并进行解析，因此解析结果出错。这种不一致性是导致反编译工具解析失败的原因。然而，Android系统在处理清单文件时并未直接依赖stringCount字段的值。通过查看 Android 源码可以发现，Android系统在运行时根据实际数据动态计算 stringPoolSize，而非直接使用文件中提供的数值。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136045" data-ratio="0.48518518518518516" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5cfaecbe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5b8hbm3zF4NR5EPYZRjIxHrQQfd8FeTlckZLgdIzTe6c1yiaOaWmbuVg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图 8  Android系统源码中计算mStringPoolSize的代码示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（3）插入脏数据：有些恶意软件会故意在清单中插入一些脏数据。这种数据不会被实际使用，但会破坏清单文件的格式，使得解析工具难以识别其中的有效信息。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136046" data-ratio="0.44722222222222224" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c3cbe443&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5jabOKuiaofTsrq3ypVz13h3y0e1ln4ib0BZ5GJTkWe9elibH3KJ562qUw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图9 </span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">左图显示`startEle0`内容，右图展示`startEle0`和`startEle1`的偏移量及大小</span></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">上图展示了一个混淆后的清单文件。在左图中，第一个startElement的大小字段为196，但header中的size字段为224，意味着startElement后附加了28字节的未知数据。右图中，第二个startElement的起始位置为0x15A4，正好位于插入的这28字节垃圾数据之后（右图中绿色部分所示）。这些多余的28字节会导致反编译工具在后续解析时出错。Android系统能够正常解析，是因为系统计算每个startElement的位置时，仅依赖上一个startElement的起始位置和大小字段，从而自动跳过垃圾数据。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（4）插入超长字符串或特殊字符：为了干扰静态分析工具的正常解析，恶意软件可能会在特定字段中插入超长字符串、特殊符号、emoji表情或不可见字符。这些字符虽然不会影响应用的正常功能，但它们显著增加了分析工具的处理难度。如果反编译工具的容错能力较差，这些修改可能导致工具崩溃或无法正确解析清单文件，从而使静态分析变得更加困难。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136047" data-ratio="0.475" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3030d1df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5bAvLl2etsibhJPazQmUu3B1xCgHvdDqart6O4Zs3N6NXuzj6vtKYO2Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图10 通过不可见字符实现超长应用名称（label）的示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">上图中，清单文件中的label字段从string.xml中的app_name字段读取，而app_name字段则包含了不可见字符（如\u0000）和超长字符串。通过这种方式，恶意软件可以有效干扰反编译工具的解析过程。如果自动化分析平台的容错机制不足，如数据库字段对app_name或version字段长度有限制，这些篡改可能导致异常，进而使恶意软件在自动化分析平台上“隐身”，难以被检测到。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">在正常的清单文件中，Start Namespace Chunk通常存储命名空间信息，其中Prefix是一个4字节的索引，指向字符串池中相应的字符串，用于标识命名空间前缀；Uri也是一个索引，指向字符串池中表示命名空间URI的字符串。例如，在一个未经过混淆的清单文件中，我们可以看到Prefix的值对应的字符串为android，即它引用了标准的Android命名空间。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136048" data-ratio="0.1062618595825427" data-s="300,640" style="" data-type="png" data-w="1054" src="https://wechat2rss.xlab.app/img-proxy/?k=8d8cb637&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL58CQN0wDNLM4Pdt5bs21iaUzXX33snS52szIojJUc1jjmnNUsWpdUJpQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图11 正常的prefix前缀示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">然而，通过对恶意软件中发Prefix字段进行恶意篡改，攻击者可以导致反编译工具在解析时发生错误。这种混淆方式利用了反编译工具对Prefix的依赖，使得其在解析时发生异常，干扰分析人员对恶意软件的判断。下图是一个经过混淆的清单文件。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136049" data-ratio="0.5314814814814814" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=136656ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5wrenyhBm2KIVZJgb7mCZh5U6JwiaGjFoxyibqNQeIszvJqqwBsMKCNiaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图12 混淆后的prefix示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">从图中可以看到，命名空间的Prefix显示为非标准字符串。Prefix的索引值指向字符串池中的位置67，而Uri显示正常。查看字符串池中索引67的内容，我们发现该字符串是一段长度为20470的乱码字符。如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136050" data-ratio="0.8768518518518519" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=06800fdc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5yO17YO7tKhwK9NxL7oENZ4kCUUovLDxcpzOZFM6utEcH5ykQ2u36SA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图13 索引值67处的prefix字符串的值示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">这种超长字符串会导致Apktool在反编译时崩溃。在Apktool的错误日志中，显示了“Array Size”异常信息。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136051" data-ratio="0.9455511288180611" data-s="300,640" style="" data-type="png" data-w="753" src="https://wechat2rss.xlab.app/img-proxy/?k=90b56964&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5tJ60YqNuBBcnPt5ic2AB5cWBEIt7yHMnOC9nwhzia5aJX1rdGeoYLLhQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图14 Apktool反编译时出现的异常错误示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">经过对崩溃问题的绕过处理后，生成的AndroidManifest.xml文件达到了16.7MB，且包含大量乱码，难以阅读。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136052" data-ratio="0.9009259259259259" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=24e61bda&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5J96EwsGqiaKvA2fhS1AuKEp4oNdWnUr46fISrh15oGtAp917YKue24w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图15 包含大量垃圾字符的AndroidManifest.xml文件示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">一个有效的处理方法是将Prefix的索引值指向字符串池中较短的字符串，以便生成的清单文件内容正常显示，便于后续分析和阅读。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">此外，一些恶意软件会在清单中插入符号或表情符号，若反编译工具在解析时未正确处理这些特殊字符，也可能导致反编译工具崩溃。插入表情符号进行混淆的清单如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136053" data-ratio="0.7027777777777777" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1dc1f71a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL54koT28eW9EyzGpMoibldQeZfac7iaEl4UJDX5X1IXGBqIBM2ca2qprbw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图16 通过表情符号进行混淆的示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">除了通过篡改ZIP格式字段和混淆清单文件来对抗反编译工具外，恶意软件还常常采用一种强有力的策略——混淆resources.arsc文件。resources.arsc文件是Android应用中存储资源映射关系的核心文件，它维护了资源ID与实际资源文件之间的映射。恶意软件通过篡改这个文件，能够有效干扰反编译工具对资源的正确解析，甚至可能导致反编译工具崩溃或异常退出。例如，BOOMSLANG（树蚺）移动欺诈家族就利用这一策略对抗Apktool的反编译过程，下图是其反编译失败时Apktool提示的错误信息。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136054" data-ratio="0.9500805152979066" data-s="300,640" style="" data-type="png" data-w="621" src="https://wechat2rss.xlab.app/img-proxy/?k=20e344bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5u3r3mb1ecOHBjcJ6oU1fZDGh2ndkhDeB1mIy97Q4FPMibnJu05S2Trw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 16px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图17 混淆后的BOOMSLANG样本导致Apktool反编译失败</span><o:p></o:p></p><h2 style="text-indent: 0em;margin-bottom: 16px;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);color: rgb(120, 172, 254);">3.2 代码混淆与反混淆技术</span></strong><o:p></o:p></h2><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">一旦研究人员突破了APK包的初步混淆，接下来便会进入到代码层面的分析。在这一层面，恶意软件通常采用各种混淆技术，大幅地增加了静态和动态分析的难度。</span><o:p></o:p></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">3.2.1 标识符混淆</span></strong><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">标识符重命名是代码混淆中最常见且最有效的技术之一，旨在通过将有意义的包名、类名、方法名和变量名替换为无意义的、随机生成的名称，从而干扰逆向工程师的分析过程。此外，标识符混淆还能有效避开一些自动化分析平台，这些平台通常依赖于标识符来制定检测规则。通过混淆标识符，恶意软件能够规避基于标识符的检测，减少被识别的风险。常见的标识符混淆策略包括使用随机字符组合（如数字、字母或特殊符号）、采用非英语语言的标识符（如中文、日语、韩语、俄文等）、使用超长字符标识符，或通过替换形状相似但含义不同的字符（如字母“O”与数字“0”、字母“I”与小写字母“l”等）来干扰分析。这些混淆策略使恶意软件能够有效隐藏其功能并增加逆向分析的难度，从而延缓被检测和识别的时间。为了应对这种混淆，安全研究人员可以使用带有反混淆功能的反编译工具，如Gda、Jeb、Jadx等，这些工具有助于快速恢复被混淆的代码并帮助识别恶意行为。标识符混淆示例如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136055" data-ratio="0.45740740740740743" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b58cbafd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5zcHjlQ6hC8SNiahms7yicyMWqphC0HXIBbVDdUdxm7JkxuHgibhXeL6dQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图18 标识符混淆示例</span><o:p></o:p></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">3.2.2 字符串加密</span></strong><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">恶意软件通常采用编码或加密手段对代码中的敏感字符串进行处理，以防止恶意关键字（如恶意URL、命令或其他敏感数据）在反编译过程中被直接暴露。这些技术有效地阻止了分析人员从反编译结果中提取关键信息，尤其在对抗自动化分析平台的静态分析时，具有较强的防护效果。常见的字符串混淆方法包括字符拆分和编码混淆。字符拆分将敏感字符串分割成多个部分，程序在运行时再拼接成完整的字符串；而编码混淆则通过对字符串进行加密或使用编码技术（如Base64编码、简单加密算法等），在程序运行时再进行解码。这些手段不仅增加了静态分析的难度，也使得分析工具无法直接识别出恶意行为。这种技术使得静态分析工具无法直接看到关键数据。安全研究人员可以使用动态分析工具，如Frida，来捕捉运行时的解密过程，揭示恶意软件在运行时所做的操作。字符串加密示例如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136056" data-ratio="0.4546899841017488" data-s="300,640" style="" data-type="png" data-w="629" src="https://wechat2rss.xlab.app/img-proxy/?k=be2a7181&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5bwadslRJEmqD10vKFDJsiaeOw5T5ZTicHeNCSsKetkRRFEFYKOpH486Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图19 字符串加密混淆示例</span><o:p></o:p></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">3.2.3 控制流混淆</span></strong><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">控制流混淆技术通过插入无意义的控制结构（如多余的条件分支、循环或冗余代码），故意改变程序的执行路径，代码块重新排序等手段使得分析工具在尝试解析程序时，陷入过于复杂的代码结构中，导致无法准确地还原程序的真实逻辑。由于控制流混淆引入了大量不必要的执行路径，静态分析工具可能无法有效提取出程序的实际行为。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">为了应对这种混淆，安全研究人员通常需要通过模拟执行以及动态分析技术来辅助手动追踪程序的执行流，逐步还原程序的真实逻辑。下图展示了一个简单的控制流混淆示例，展示了在混淆前后的控制流结构差异。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136057" data-ratio="0.6083333333333333" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=75c73274&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL57TF5xzvmYaxkyRlWG2u5iasgxLjh5C7eO5roJvSMpKK8WySB2DE0haw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图20 控制流混淆前后的差异对比</span><o:p></o:p></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">3.2.4 反射机制与动态加载</span></strong><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">动态加载机制是恶意软件常用的反静态分析技术，主要包括本地动态加载和远程动态加载两种方式。本地动态加载通过加载本地存储的动态库或dex文件，动态调用方法或类，使得恶意行为在静态分析阶段无法被发现。远程动态加载则通过在运行时从远程服务器下载动态库或dex文件来加载并执行恶意代码，这种方式进一步规避了静态分析工具的检测，因为恶意代码并未出现在apk文件中。恶意软件往往通过反射技术结合动态加载，利用运行时的反射调用机制隐藏恶意行为，使得初期静态分析无法识别这些恶意活动。为了应对这一挑战，安全研究人员通常依赖动态分析手段，如通过Frida注入脚本、使用调试工具动态跟踪或通过日志分析捕捉反射调用的过程，从而揭示恶意代码的真实行为。这些动态分析方法能够绕过静态分析的限制，识别通过反射和动态加载隐藏的恶意行为。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">接下来，我们来看一个利用本地动态加载的恶意代码示例。下图展示了该恶意代码的目录结构。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136058" data-ratio="0.5759493670886076" data-s="300,640" style="" data-type="png" data-w="474" src="https://wechat2rss.xlab.app/img-proxy/?k=12bbf2e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5dxr9HJRCnMgHQmUjcd1ian30meYQgESxxGpcosBf18shws1oZ0gLzwg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图21 目录树信息</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">虽然从表面上看，该目录仅包含几个方法，但深入分析后发现，恶意代码通过attachBaseContext方法调用了一个名为b的方法，进一步实现了从assets目录加载加密的代码文件。该文件经过异或解密后，通过动态调用的方式被加载并执行，代码如下图所示：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136059" data-ratio="0.7166666666666667" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3a6e0175&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5wf1LncI0iaqd48ibeicSBygjJs78qMwxtH5BRF7NY8gqnU00mhKhQWfxw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图22 动态加载后通过反射调用代码示例</span></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">3.2.5 Native混淆</span></strong><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">Native混淆技术是通过多种手段加大对恶意软件逆向分析的难度，常见的技术包括以下几种：</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（1）JNI接口混淆：恶意软件通过JNI（Java Native Interface）将关键逻辑转移到.so文件中，并通过混淆的JNI接口调用本地代码。通过将原本清晰的本地方法名替换为无意义的符号或随机字符，恶意代码的功能和结构变得更加难以理解和追踪。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136060" data-ratio="0.4634888438133874" data-s="300,640" style="" data-type="png" data-w="986" src="https://wechat2rss.xlab.app/img-proxy/?k=252761f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5Xqm3dXzHibPbbX1KokXwrDzmP8nYYLgYEK3cd5rY5MjGITj9ibtXdjZg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图23 JNI接口混淆示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（2）Session加密：将关键方法存储在自定义的.section中，并对这些自定义的.section内容进行加密。由于.so文件在加载时会优先执行.init_array段，因此将解密逻辑嵌入到.init_array中。在运行时，通过解密方法获取内存中各个.section的起始地址和大小，对加密的.section进行解密还原，从而恢复关键方法的正常执行。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136061" data-ratio="0.7703703703703704" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=07805478&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL54cnbylFPw7sMvGRgYUfEO8YaHSzVKRnsiaveqSVttYib84O0kqBDzH3g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图24 Session加密的示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（3）函数加密：解析.so文件，通过方法名定位目标方法后，对其进行加密。在加载.so文件时，通过指定方法的地址调用解密逻辑，将加密的方法动态解密还原，以实现对关键逻辑的保护。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136062" data-ratio="0.7231481481481481" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=89e07bb8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5XL7w3bD6ZoMic4ektyKp5ciaJf6H51ibOWKCKAL4rvgYyY184heANxnyw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图25 JNI加解函数经解密还原的部分代码示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（4）字符串加密与动态解密：恶意软件通过加密关键字符串（如URL、命令、密钥等），并在运行时通过动态解密恢复其原始内容。加密的字符串通常存储在静态数据区域，而解密则通过特定算法或在内存中动态完成，从而使得静态分析工具无法直接提取恶意信息。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136063" data-ratio="0.21071428571428572" data-s="300,640" style="" data-type="png" data-w="840" src="https://wechat2rss.xlab.app/img-proxy/?k=a6f575b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL53iaCgnSeibZjAiaJ9Af9J1BXAOua8tiaXszpjZjaaiaZtPOHtqHiceJkPETQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图26 Native解密字符串示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（5）花指令与垃圾代码插入：通过在代码中插入伪指令或无效代码，恶意软件能够混淆程序的实际行为。这些花指令没有实际功能，但增加了逆向工程的复杂性。垃圾代码不仅增加了程序的体积，还使得追踪和理解恶意代码变得更加困难。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136064" data-ratio="0.7568345323741007" data-s="300,640" style="" data-type="png" data-w="695" src="https://wechat2rss.xlab.app/img-proxy/?k=3c5dd2e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5IIEp99avWUkCfGKPkzeO3exDomaiaiaVIsevNms41wibZicdeQMrrbptHA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图27 一个简单的垃圾指令示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（6）代码加壳与自修改代码：在Native层，恶意软件经常使用加壳技术来隐藏核心恶意代码。加壳后，恶意代码以加密或压缩形式存储，只有在运行时才会解密或解压。自修改代码技术则允许恶意软件在运行时动态生成、修改和执行代码，进一步阻止静态分析工具识别完整的恶意行为。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136065" data-ratio="0.7137637028014616" data-s="300,640" style="" data-type="png" data-w="821" src="https://wechat2rss.xlab.app/img-proxy/?k=4e9f461d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL58425MCSXnPaa0Iny5ZeJOLWHOn9zMXMFH8SX6wAQWMiaPXRRAXUmDLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图28 通过Hook修改代码的示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（7）反调试与模拟器检测：为了抵抗动态分析，恶意软件往往会在Native层嵌入反调试机制，例如通过检测调试器的存在（如gdb或Frida）来中断分析过程。此外，恶意软件也会进行模拟器检测，通过检查设备是否运行在模拟器或沙盒环境中来避免被动态分析工具捕捉。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136066" data-ratio="0.7683315621679064" data-s="300,640" style="" data-type="png" data-w="941" src="https://wechat2rss.xlab.app/img-proxy/?k=11238e14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5TvMSygzfOUfIXnbcVX3QficChXjnhGpWy6qFveRBNS1dnzMBINdcUibg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图29 检测模拟器示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（8）控制流混淆：控制流混淆通过改变程序的执行路径，使得分析人员难以理解程序的实际流程。常见的方法包括插入无效的控制流（如跳转、分支语句）、无用的循环和函数调用，扰乱分析工具追踪指令的顺序。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136067" data-ratio="2.3783783783783785" data-s="300,640" style="" data-type="png" data-w="481" src="https://wechat2rss.xlab.app/img-proxy/?k=ce936e6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5K3B8khQXosPRCUOllu97IoicozGC5tMBCmicRbDsIt1dqcu0lwnmBdicw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图30 一段控制流混淆代码示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（9）LLVM混淆：LLVM是一种强大的编译器框架，恶意软件通过使用LLVM技术来对Native代码进行复杂的混淆处理。LLVM混淆能通过优化编译过程，生成难以阅读和理解的二进制文件，同时对文件大小影响较小。这种技术有效增加了逆向工程的复杂度。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136068" data-ratio="0.6481481481481481" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d567a9a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5qqWFaGF9sMsTWsZf60iaRKwU5lVBq1Tju2V4rzhXkGTLic26wBnzOvCQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图31 LLVM混淆前后对比示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">这些Native混淆技术通常被组合使用，构建多层次的保护机制，从而使传统的静态分析和动态分析方法面临巨大的挑战。借助这些技术，恶意软件能够有效隐藏其真实行为，规避安全研究人员的检测以及防护系统的拦截。此外，商业加固保护进一步提升了防护的全面性。恶意软件常利用商业加固产品对自身进行保护，甚至黑灰产软件也频繁采用此类技术进行防护，如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136069" data-ratio="0.2175925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9870cab1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL54wh9Fm2I7Ve2fl6h5eN73JCwqGrChNBHJCdibQicnxg1PdQXFeCatgqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图32 使用商用加固的诈骗应用</span><o:p></o:p></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">3.2.6 代码虚拟化</span></strong><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">代码虚拟化是目前最先进的混淆手段之一，它通过将原始代码转换为自定义的虚拟机指令，极大地提高了代码复杂度和分析难度。与传统的控制流混淆不同，虚拟化技术将关键代码的执行逻辑封装在虚拟机中，使得核心功能和控制流几乎无法通过常规反编译手段还原。以下从DEX虚拟化和SO虚拟化两个维度进行分析：</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">DEX虚拟化技术主要针对Android应用中的Dalvik字节码。这种技术通过将DEX中的字节码转换成自定义的虚拟机指令，然后由Native层虚拟机解释执行，从而保护关键代码和核心逻辑。这种转换使得传统的反编译工具难以还原代码的原始逻辑，因为它们无法识别转换后的指令集。例如，某电商平台通过漏洞提权实施恶意行为，并为隐藏其核心代码逻辑，采用了一套基于JVM构建的虚拟机保护（VMP）技术对代码进行加固。下图展示了其保护后的二进制内容，可以明显看出，代码已被虚拟化为高度抽象的虚拟机指令，使得传统的反编译和静态分析方法几乎无效。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136070" data-ratio="0.3333333333333333" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=390c4296&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL519SHGqzIboBic9piahJmDVEOJvjK3xVGzm98h6HSY7PibrMhqL5V40ulg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图33 解析经vmp保护的dex文件示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">SO虚拟化技术则关注于保护应用中的Native代码，即SO文件。这种技术可以通过隐藏符号表、资源加密等方式来保护SO文件中的功能不被轻易分析和篡改。例如，Virbox Protector提供了对SO文件的保护选项，包括隐藏符号表和对特定SO文件的加密保护。通过这种方式，即使攻击者能够访问到SO文件，也无法轻易理解文件中的函数和逻辑，从而保护了应用的安全。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136071" data-ratio="0.39171974522292996" data-s="300,640" style="" data-type="png" data-w="942" src="https://wechat2rss.xlab.app/img-proxy/?k=85f77354&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5spkxcJO01RCl8voaYyhY8zfMBicnbq3MbPUW7qa6h9MyMFWKF1bjsRg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 16px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图34 某商业加固产品对DEX和SO的虚拟化保护介绍</span><o:p></o:p></p><h2 style="text-indent: 0em;margin-bottom: 16px;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);color: rgb(120, 172, 254);">3.3 其他混淆手段</span></strong><o:p></o:p></h2><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">一些恶意软件通过巧妙利用Windows和Android文件系统的差异性，有效对抗静态分析和逆向工程。在Windows系统中，文件名不区分大小写，但会保留其原始格式，而Android文件系统则区分大小写。这种差异使得某些在Windows系统上可能引发冲突或错误的文件名，能够在Android设备上正常使用。此外，Windows系统对文件名中的特殊字符（如 &gt; &lt; : &#34; / \ | * ?）有严格限制，而Android系统允许这些字符的存在。恶意软件常通过在文件名中嵌入这些特殊字符，干扰基于Windows的分析工具，导致文件无法读取或处理，从而增加逆向分析的难度。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">不仅如此，恶意软件还可能利用Android文件系统允许同名文件和文件夹共存的特性，进一步增加分析的复杂性。例如，在Android中，一个名为AndroidManifest.xml的文件和一个名为AndroidManifest.xml的文件夹可以同时存在，但在Windows系统中则会因命名冲突而无法实现。这种差异可能导致基于Windows的分析工具处理这些结构时出错或跳过解析这些关键文件或文件夹，进而为恶意软件提供伪装。例如，BOOMSLANG恶意软件的一个在野样本采用了特殊字符混淆和同名文件与文件夹共存的对抗技术，其APK文件在使用ZIP工具打开时如图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136072" data-ratio="1.0079286422200198" data-s="300,640" style="" data-type="png" data-w="1009" src="https://wechat2rss.xlab.app/img-proxy/?k=b7b0c276&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5nAYoia1pFnVxAtKGNIuqJo7UicicQLFPmbDIKCCibHROUZHvGsIVaWL2GQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图35 同名文件和文件夹混淆示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">从图中可以看出，恶意软件会同时创建 “\AndroidManifest.xml”和“AndroidManifest.xml”目录，以及 “\classes.dex” 和“classes.dex”目录。这种操作会在Windows系统上导致文件夹相互覆盖，造成文件内容丢失，从而影响反编译的完整性。此外，恶意软件还会使用非法文件名，导致这些文件在使用apktool反编译时被忽略，如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136073" data-ratio="1.1961367013372957" data-s="300,640" style="" data-type="png" data-w="673" src="https://wechat2rss.xlab.app/img-proxy/?k=46ef2017&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5bX7VBgUwTneOuqhU0oOv0afgRlOYJfDRIf3mxXKpDHAiaxk9UIUkJPg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图36 apktool忽略非法文件名的示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">一些恶意软件还会在文件中嵌入同名但大小写不同的文件，通过利用Windows文件名不区分大小写的特性干扰分析工具，造成解析错误或异常。以下图片展示了一例包含同名但大小写不同文件的恶意APK示例。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136074" data-ratio="0.7030784508440914" data-s="300,640" style="" data-type="png" data-w="1007" src="https://wechat2rss.xlab.app/img-proxy/?k=e38067e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5ln6dR10CDK662207BdvQOTU57GzibXb5VwanicKia5172Z9VW0v5pROWA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图37 Windows文件系统不区分文件名大小写的示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">在Android恶意软件中，资源混淆是一种常见的对抗技术，广泛应用于assets和res等文件夹中的资源文件。常见的资源混淆手段包括：对assets目录中的资源文件进行加密处理，创建深层嵌套的目录结构或使用畸形目录名称，插入大量无用文件或伪装资源文件，将关键资源与无效资源混杂在一起，从而增加分析难度；对res目录中的资源文件进行混淆，例如篡改资源映射关系、删除资源文件名或更改文件扩展名等。这些手段旨在干扰分析工具的解析过程，使得分析人员难以快速定位和识别关键数据，进一步提高逆向工程的难度。下图是一个插入垃圾资源的示例：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136075" data-ratio="0.9048562933597621" data-s="300,640" style="" data-type="png" data-w="1009" src="https://wechat2rss.xlab.app/img-proxy/?k=bf859ec8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5Nm3iaLmtYXShkUy2noBQKmyFgGXD7PZzsYs8qwZTiaIDzPjaOnMO1nfw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图38 插入垃圾资源示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">一些恶意软件通过将原始DEX文件分割成多个小的DEX文件或插入垃圾代码，增加静态和自动化分析的难度。分割DEX文件使分析工具需要逐个处理，增加了分析时间和复杂度，且这些文件通常通过动态加载技术在运行时才会合并，难以在静态分析中识别。此外，插入的垃圾代码不执行实际操作，但通过虚假的逻辑和复杂的控制流干扰分析，掩盖恶意功能。此类策略使得恶意软件的行为更加隐蔽，迫使分析人员采用更复杂的动态分析和手动逆向工程方法。一个apk中包含大量dex的例子如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136076" data-ratio="1.0074074074074073" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7e7c7493&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5WBjEbqcnNpPgH3VQH79s4cR2LMnE0pcdibqzrjR7nL3icu7zicVWkp6Ag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图39 分割多个dex示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">除了上面提到的混淆技术，还有一些其他常见但未详细介绍的技术，这些技术能进一步增强恶意软件的逆向分析难度。以下是一张混淆工具的示例图片，其中展示了多种混淆功能，如：增加包体积、内建独立签名证书、DEX代码混淆、资源混淆、APK防篡改等多个功能。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136077" data-ratio="0.6611111111111111" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=27858d04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5QWZ4Q9TPbibBUmDPJobkstNVOdKzPGI8pm7MfCqUzSBxZyu5dR1xHNw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图40 一种混淆工具示例</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(120, 172, 254);"><strong>第四章</strong></span></p><p><br/></p><p><strong><span style="font-size: 16px;color: rgb(120, 172, 254);">实际案例解析</span></strong></p><p><br/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">为了更好地理解混淆技术的实际应用，以下是几个常见的Android恶意软件的混淆技术案例。</span><o:p></o:p></p><h2 style="text-indent: 0em;margin-bottom: 16px;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);color: rgb(120, 172, 254);">4.1 Joker恶意软件混淆方法</span></strong><o:p></o:p></h2><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">Joker（中文名称“小丑”，也被称为Bread）是一个在Google
Play商店中极为活跃的恶意软件家族。自2016年12月首次被检测到以来，Joker家族的活动一直在持续，并且其恶意软件的变种数量也在不断增加。本月最新披露的Google Play商店中Joker样本信息如下：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136078" data-ratio="0.5712962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8d131b43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5vnWusdkko5LZDUKaucicOgRGDF5dUuzkLlKXARAlBuc6eGiaYria53Q5Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图41 GooglePlay上的Joker木马信息</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">Joker家族的恶意软件能够反复进入Google官方应用市场，其关键原因在于其采用了多种高级代码混淆技术，从而绕过了Google Play Store的安全检测和审查机制。这些混淆技术包括但不限于：</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（1）字符串加密：通过加密关键字符串，如API请求和配置信息，避免静态分析工具的直接识别。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（2）动态加载：将恶意代码分离到单独的Payload文件中，仅在运行时加载，以躲避静态代码扫描。 </span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（3）反射调用：利用反射机制动态调用方法，隐藏关键功能调用路径。 </span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（4）动态下发配置：通过网络请求动态获取配置或恶意指令，降低被静态检测的风险。 </span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（5）利用第三方服务：使用Github页面和存储库存储恶意配置或代码，进一步混淆来源和流量。 </span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">这些技术的组合使Joker恶意软件能够成功规避静态分析检测，其真实行为往往隐藏在复杂的动态流程中。为了揭示其行为，分析人员通常需要依赖动态调试和运行时解密技术。针对这些混淆手段，安全研究人员可以借助动态分析工具（如Frida和Xposed）追踪解密过程，提取关键数据并识别恶意 API 调用，从而全面还原其恶意行为。</span><o:p></o:p></p><h2 style="text-indent: 0em;margin-bottom: 16px;"><span style="color: rgb(120, 172, 254);"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">4.2 BadPack的混淆手段</span></strong></span><o:p></o:p></h2><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">BadPack是恶意软件通过篡改ZIP文件结构头，使Apktool和Jadx等分析工具无法正常解析。其通过使用非标准的压缩算法来干扰反编译工具的正常运行。经010 Editor分析该APK文件格式，发现其压缩方法值为0xF753，如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136079" data-ratio="0.41586280814576637" data-s="300,640" style="" data-type="png" data-w="933" src="https://wechat2rss.xlab.app/img-proxy/?k=762df9a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5h1jTFy7lnT4ZSHRSMNVoJM5SxdMZbWialm2ZhwHhaeH46WRzlb59iccg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图42 篡改apk文件压缩算法标识示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">这一数值并不属于任何已知的标准压缩方法，因此导致反编译工具无法识别和处理该文件。根据标准ZIP格式规范，压缩方法的取值通常如图所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136080" data-ratio="0.8386763185108583" data-s="300,640" style="" data-type="png" data-w="967" src="https://wechat2rss.xlab.app/img-proxy/?k=0c78e566&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5rA4SLUj9Zblt8MNxjFwsulbuqyqV2GbzY05PjM4Xw9K9OBav3L4spw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图43 ZIP支持的各压缩方法的标识值示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">根据Android系统源代码，当系统遇到非COMP_DEFLATE（即 0x08）压缩方法时，会默认将输入文件按 “未压缩” （COMP_STORED，即 0x00）方式处理。具体而言，系统会直接读取文件的未压缩数据长度，并以此进行解析。因此，恶意软件利用了Android系统对ZIP格式的容错机制，通过使用非法的压缩算法进行混淆，从而达到规避反编译工具的目的。这种混淆技术简单却有效。在分析Android恶意软件时，若遇到类似情况，可将压缩方法修改为0以便正确解压和分析。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">APK伪加密通过修改ZIP文件的头部，将加密标志设置为true，但并未实际对文件内容进行加密。这种技术利用了Android系统在处 ZIP文件时不会验证头部的加密标志，而普通的解压软件则会检测该标志。例如，当使用RAR工具解压该APK文件时，会提示用户输入密码，如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136081" data-ratio="1.0051334702258727" data-s="300,640" style="" data-type="png" data-w="974" src="https://wechat2rss.xlab.app/img-proxy/?k=ab393c6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5b2OuaVxxjDkqkVWXg1JPMCibrZwYLxBHTyZ7LgDIHPsSic9grXuksI5Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图44 伪加密的混淆示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">由于Jeb和Jadx都使用标准的ZIP库，因此无法正常解压并反编译该文件。它们的反编译错误信息如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136082" data-ratio="0.37962962962962965" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6d648bc2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5rGAdTzHmpibwjZZBO435Hicz8wUAZ7UDx6GYicVvE0yCuMvGo6ViapRN0A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图45 无法使用Jadx和Jeb打开的混淆APK示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">通过采用BadPack技术，恶意软件将自身伪装为异常格式的文件，利用反编译工具对文件解析的严格性触发异常，从而显著增加静态分析的难度。这种策略有效干扰了安全研究人员的分析流程，提升了恶意软件的隐蔽性。 </span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">针对这一技术，可以通过以下方法进行应对： </span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（1）使用修订后的ZIP库：通过修改ZIP解压库的解析逻辑，忽略非标准字段或异常格式，确保文件内容能够正确解压。 </span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（2）编写修复脚本：分析BadPack文件的异常字段，针对特定格式设计脚本，自动修正文件结构，使其恢复为标准格式以便后续分析。 </span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">这些应对措施能够有效绕过BadPack技术的混淆手段，为静态分析提供可靠的数据支持。</span><o:p></o:p></p><h2 style="text-indent: 0em;margin-bottom: 16px;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);color: rgb(120, 172, 254);">4.3 SpyNote恶意软件混淆策略</span></strong><o:p></o:p></h2><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">SpyNote是一种间谍软件，常通过短信和钓鱼网站等方式进行传播。攻击者通常发送包含恶意链接的SMS消息或创建伪装成合法网站的钓鱼页面，诱导目标用户点击链接并下载伪装成合法应用程序的恶意软件。自2016年在恶意软件论坛首次曝光以来，SpyNote一直作为一种持续威胁的恶意工具在全球范围内活跃。公开数据显示，今年1月和2月期间，SpyNote的新增样本数量已超过3400个，表明其威胁活动仍在快速扩散。最新披露的威胁情报显示，SpyNote伪装成安全应用程序实施攻击，其主要目标是加密货币账户，窃取私钥和余额信息，尤其针对比特币、以太坊和Tether等热门数字资产。相关攻击事件如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136083" data-ratio="0.8804347826086957" data-s="300,640" style="" data-type="png" data-w="736" src="https://wechat2rss.xlab.app/img-proxy/?k=b52bb070&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5ic0yZiaML9gicZ23mTudPNaVEic8dqlpYkw2TuPX8MzFicarkOTnibnyicbJQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图46 SpyNote仿冒安全软件实施攻击</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">SpyNote 除了通过多种渠道进行传播，还采用了一系列高级混淆与隐藏策略，以规避检测和分析。以下是其主要混淆技术的简要概述：</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（1）篡改 APK 文件的 ZIP 格式，从而导致反编译APKTool在解析时失败，如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136084" data-ratio="0.9442675159235668" data-s="300,640" style="" data-type="png" data-w="628" src="https://wechat2rss.xlab.app/img-proxy/?k=5dd1fb9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL56icYhpGicGoPeib8uFQPb2KEXeHtnLcbjoMk3iaeUfjdA6XJBlLDg3Ea6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图47 修改zip格式导致Apktool反编译失败的示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（2）篡改清单文件魔术、插入垃圾字符串。修改的魔术示例如下图：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136085" data-ratio="0.4405099150141643" data-s="300,640" style="" data-type="png" data-w="706" src="https://wechat2rss.xlab.app/img-proxy/?k=627b0ef2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5GUnCjGOwHYIf2jicHKIay4EnnNMcWTXyyIZOiayGAkrW8icX9lDft4xwg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图48 修改魔术混淆示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（3）利用相近字符实现代码混淆，如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136086" data-ratio="0.5407407407407407" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=29b67531&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5UZVYyOOJicv70G8nythKNibUOYPxNDrOfwKZsC4SCsvtVB4RX8WFMKfg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图49 相近字符代码混淆示例</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">（4）对resources.arsc文件混淆，使jadx反编译工具在分析时出错，如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136087" data-ratio="0.5298759864712514" data-s="300,640" style="" data-type="png" data-w="887" src="https://wechat2rss.xlab.app/img-proxy/?k=a7981b31&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSNQEWIhkheyGJTtTFWIcL5B5BHpicWfwQnhFapcZ5aEgeFyA3ZicM6XfficZ1ic5j76ECCvLxSCsAggQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">图50 Jadx无法解析resources.arsc文件</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(120, 172, 254);"><strong>第五章</strong></span></p><p><br/></p><p><strong><span style="font-size: 16px;color: rgb(120, 172, 254);">结论与未来展望</span></strong></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"></span><br/></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">Android恶意软件的混淆技术不断进化，从简单的代码重命名到复杂的动态加载与反调试技术，恶意软件通过这些手段极大地提升了恶意代码的隐蔽性和分析难度。随着混淆技术的不断发展，安全研究人员也需要不断更新自己的分析手段，从静态分析扩展到动态分析、行为分析等多维度的分析方法。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">未来，随着机器学习、人工智能等技术的引入，混淆技术和逆向分析技术将继续呈现出更加复杂和高效的态势。在这种情况下，开发更强大的自动化检测和分析工具将是破解恶意软件防护的关键。同时，开发者和安全专家也应加强对混淆技术的研究，制定出更具针对性的应对策略，以确保Android平台的安全性。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">通过持续的研究和技术创新，我们有望能够更好地对抗恶意软件的混淆技术，保护用户的隐私与安全。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;"></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/<span style="-webkit-tap-highlight-color: transparent;outline: 0px;">CVE</span>累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="-webkit-tap-highlight-color: transparent;outline: 0px;">数据安全研究、<span style="-webkit-tap-highlight-color: transparent;outline: 0px;">5G安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">人工智能安全研究、</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">移动安全研究、物联网安全研究、车联网安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">工控安全研究、信创安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">云安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1.5px;">。</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1.5px;"></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><img class="rich_pages wxw-img" data-imgfileid="502136088" data-ratio="1.1205673758865249" data-s="300,640" width="281.979px" data-type="jpeg" data-w="282" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.969px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ad24474a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAwNTI1NDI3MQ%3D%3D%26mid%3D2649619740%26idx%3D1%26sn%3Dc2db7658cccb38ac22236f6cd4b17e7a%26chksm%3D8306200cb471a91a7e1750b3803c9179fa15d7a2915b68786133c51080a0360f0633d437e9b3%26scene%3D58%26subscene%3D0%23rd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 25 Nov 2024 17:19:00 +0800</pubDate>
    </item>
    <item>
      <title>Apache Solr漏洞CVE-2024-45216分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619683&amp;idx=1&amp;sn=60a15fd441cd9eab219b60845a04dbe7&amp;chksm=830621f3b471a8e5e11cc53b92b9756704bbee8115dbe4190e0b328174348e1c15e74a33205e&amp;scene=58&amp;subscene=0#rd</link>
      <description>Apache Solr官方发布了一个安全漏洞公告（CVE-2024-45216），使用PKIAuthenticationPlugin的Solr服务会受到身份验证绕过的影响。该漏洞的利用已被公开到互联网。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-11-01 17:34</span> <span style="display: inline-block;">北京</span>
</p>

<p>Apache Solr官方发布了一个安全漏洞公告（CVE-2024-45216），使用PKIAuthenticationPlugin的Solr服务会受到身份验证绕过的影响。该漏洞的利用已被公开到互联网。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=759f8826&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nQ74EtNogT0N9dPXh0dy6sg4QHQDibNLIMNxpNLDr0szaTbyiaibv8kPjXBbozH5EJaVoaic5nHVRxcJA%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><span style="font-size: 16px;"> 一、漏洞描述</span></p><p style="color: rgb(96, 152, 249);font-size: 15px;line-height: 15px;font-family: 思源黑体;letter-spacing: 1px;font-weight: bold;"><br/></p><p><br/></p><p><br/></p><p style="text-indent: 2em;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">2024年10月，Apache Solr官方发布了一个安全漏洞公告（CVE-2024-45216），使用PKIAuthenticationPlugin的Solr服务会受到身份验证绕过的影响（在Solr Cloud模式下，该身份验证插件默认启用）。在任何Solr API URL路径末尾加入特定的字符串将会绕过身份验证，并且同时可以正确访问该API端点功能。该漏洞的利用已被公开到互联网。</span></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><span style="font-size: 16px;"> 二、影响与修复</span></p><p style="color: rgb(96, 152, 249);font-size: 15px;line-height: 15px;font-family: 思源黑体;letter-spacing: 1px;font-weight: bold;"><span style="font-size: 16px;"></span></p><p><br/></p><p><br/></p><h2 style="text-indent: 0em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h2><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">受影响的Apache Solr版本：</span><o:p></o:p></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">5.3.0 &lt;= version &lt; 8.11.4</span><o:p></o:p></p></li><li><p style="margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">9.0.0 &lt;= vesion &lt; 9.7.0</span><o:p></o:p></p></li></ul><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">Apache Solr在8.11.4以及9.7.0版本已经对该漏洞进行了修复。</span><o:p></o:p></p><h2 style="text-indent: 0em;margin-bottom: 0px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></h2><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p> 三、漏洞复现</p><p style="color: rgb(96, 152, 249);font-size: 15px;line-height: 15px;font-family: 思源黑体;letter-spacing: 1px;font-weight: bold;"><br/></p><p><br/></p><p style="margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">本文在Solr 8.11.3的Cloud模式下复现。在未登录的情况下访问/solr/admin/info/system，如下图所示：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136019" data-ratio="0.44907407407407407" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1f79db74&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ74EtNogT0N9dPXh0dy6sgM1NJFVW7XibgQiaS3btbBt3UyibrZekxaic2qGkRADn2nQnib7v9yD0lypA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"></span></p><h2 style="margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></h2><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p> 四、漏洞分析</p><p style="color: rgb(96, 152, 249);font-size: 15px;line-height: 15px;font-family: 思源黑体;letter-spacing: 1px;font-weight: bold;"><br/></p><p><br/></p><p style="margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">核心代码在solr-core-8.11.3.jar!/org/apache/solr/servlet/SolrDispatchFilter.class:401 。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136021" data-ratio="0.6018518518518519" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5ca23110&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ74EtNogT0N9dPXh0dy6sg2yanKyLic0DjiagjwGFwaso8Wgv38WHPyxyAxaagHvGDJFEjdpjVVQXQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">这里有两个点，第1个箭头是做身份验证的，第2个箭头是做功能调度的，问题就出在这两个过程中。</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">先分析身份验证流程：</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">在solr-core-8.11.3.jar!/org/apache/solr/servlet/SolrDispatchFilter.class:501 。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136022" data-ratio="0.7425925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e90b7e6b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ74EtNogT0N9dPXh0dy6sgic7g6d1RdtX3OCpZHghY23KGpsx2QvrGBPZQAeibjWKBhV2iagVKoERpw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">当请求头中存在SolrAuth或者SolrAuthV2，并且PKIAuthenticationPlugin启用的话，就调用该插件进行身份验证。</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">继续跟进该插件的身份验证流程：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136023" data-ratio="0.22870370370370371" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=56ae5cea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ74EtNogT0N9dPXh0dy6sg2ibPZ8MbASRxu6bh35jwB84TfiaDdwSNJo5UAd8yO11icDz4GhntWvTUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">当URL以/admin/info/key结尾的话，就直接略过身份校验，说明该接口是个白名单。</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">显然，此处就产生了一个漏洞，任何以/admin/info/key结尾的URL请求都会绕过该身份校验。</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">但其他以/admin/info/key结尾的URL能绕过身份校验，并不意味着能正确路由到正常的功能。</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">因此就到了开头第二个箭头处。也就是Action result = call.call();</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136024" data-ratio="0.6175925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=76cad2f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ74EtNogT0N9dPXh0dy6sgreQFFgDibIPyP4mSEVOB3rk1B2cGklxS9ViaWeHRLb29uGMymHz85y8w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">此处调用init方法。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136025" data-ratio="0.5148148148148148" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2ea10be3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ74EtNogT0N9dPXh0dy6sgKRLWLYP548ica1wTE6yrCibYgNYoQhibOrtKnPj5ZUDTZT1JE2icaibOZLw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">这里判断我们的path中是否有冒号(ascii 58)，如果有的话，就截取到冒号处当做真正的请求路由。</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);">所以结合上文的身份绕过，此处就很容易得到权限绕过payload。</span><o:p></o:p></p><h2 style="margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></h2><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space: pre-wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 15px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 2px;">参考链接：</span></strong></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[1] Apache Solr官方漏洞通告</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;"><a href="https://solr.apache.org/security.html#cve-2024-45216-apache-solr-authentication-bypass-possible-using-a-fake-url-path-ending" target="_blank">https://solr.apache.org/security.html#cve-2024-45216-apache-solr-authentication-bypass-possible-using-a-fake-url-path-ending</a></span><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: left;line-height: 1.5em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[2] GitHub Commit <a href="https://github.com/apache/solr/commit/7ef2c0ef36601d8ce8c83192738376ed7c2429ac" target="_blank">https://github.com/apache/solr/commit/7ef2c0ef36601d8ce8c83192738376ed7c2429ac</a></span></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;color: rgb(0, 0, 0);font-size: 15px;">启明星辰积极防御实验室（ADLab）</span></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap-style: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br/></p><p><br/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">“黑雀攻击”概</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/CVE累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、数据安全研究、5G安全研究、人工智能安全研究、移动安全研究、物联网安全研究、车联网安全研究、工控安全研究、信创安全研究、云安全研究、无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等<span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1.5px;">。</span></span></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap-style: initial;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap-style: initial;background-color: rgb(255, 255, 255);"><br/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap-style: initial;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-align: start;text-indent: 24px;"><img class="rich_pages wxw-img" data-imgfileid="502136026" data-ratio="1.1205673758865249" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.969px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></span></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e1814244&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAwNTI1NDI3MQ%3D%3D%26mid%3D2649619683%26idx%3D1%26sn%3D60a15fd441cd9eab219b60845a04dbe7%26chksm%3D830621f3b471a8e5e11cc53b92b9756704bbee8115dbe4190e0b328174348e1c15e74a33205e%26scene%3D58%26subscene%3D0%23rd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 01 Nov 2024 17:34:00 +0000</pubDate>
    </item>
    <item>
      <title>“荣耀”时刻~ 启明星辰获2024年度杰出团队奖</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619660&amp;idx=1&amp;sn=ce9fa9124779c286d1957ed85a9fdbb3&amp;chksm=830621dcb471a8ca8f9eb9b31ce95886a78bfca51e9dc781e5fbe31b42a18972f67cb793cb1c&amp;scene=58&amp;subscene=0#rd</link>
      <description>启明星辰将持续与荣耀携手并进，共同筑牢安全防线，为用户打造坚不可摧的网络安全屏障，为信息安全行业的高质量发展注入新的强劲动力。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-10-31 22:17</span> <span style="display: inline-block;">北京</span>
</p>

<p>启明星辰将持续与荣耀携手并进，共同筑牢安全防线，为用户打造坚不可摧的网络安全屏障，为信息安全行业的高质量发展注入新的强劲动力。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=ced834f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nSiaFBVENwh7T6eaqfAHOQNlZw1qKNoAQ5QVFiapOtvmib0liaeOAKyUwFiaYVRM5rxm4lzbibsahObfxfw%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;visibility: visible;"></span><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-indent: 0em;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;visibility: visible;"/></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">近日，第三届荣耀开发者大会暨MagicOS9.0发布会在北京盛大举行。在荣耀隐私安全分论坛上，荣耀公司正式公布了2024年度荣耀安全奖励计划优秀合作伙伴获奖名单，启明星辰积极防御实验室（ADLab）凭借在荣耀终端安全研究领域的突出贡献，获评“</span><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);"><strong>荣耀安全隐私 荣耀安全奖励计划‘杰出团队奖’</strong></span><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">”。</span></p><p><br/></p><p><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="549" data-cropsely1="0" data-cropsely2="403" data-imgfileid="502136006" data-ratio="0.7342592592592593" data-s="300,640" data-type="jpeg" data-w="1080" style="vertical-align: middle;width: 549px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=619b04b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FBwR7Xg3aXhYtvxjwIhXyMVK1sUeWSpcgJbK9pqENxiciaxrHibiaxEKqZNMFte4RG2sMLaMXuLicFDLIGEgHPd7fNDg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg%26wxfrom%3D13"/></p><p><br/></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">随着移动互联网的飞速发展，智能手机已深融入到企业业务的方方面面,给企业带来便利的同时，也使企业面临严重的数据泄露和网络攻击风险挑战。</span></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br/></span></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">ADLab作为中国安全行业最早成立的攻防技术研究实验室之一，基于自身二十余年攻防实战经验和在漏洞挖掘等方面的安全能力，深入开展移动终端系统和终端应用安全，聚焦国内外主流top厂商系统架构、系统组件、蓝牙和无线通信安全，向华为、小米等厂商提交数十个漏洞。同时在隐私安全方向，启明星辰ADLab实验室研究员连续两年向荣耀安全应急响应中心提交了多个高价值漏洞。</span></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br/></span></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">截至目前，ADLab已通过 CNVD/CNNVD/NVDB/CVE累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、数据安全研究、5G安全研究、人工智能安全研究、移动安全研究、物联网安全研究、车联网安全研究、工控安全研究、信创安全研究、云安全研究、无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等。</span></p><p><br/></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br/></span></p><p><img class="rich_pages wxw-img" data-imgfileid="502136005" data-ratio="0.03125" data-s="300,640" style="vertical-align: middle;width: 640px !important;visibility: visible !important;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=229680a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FBwR7Xg3aXhYtvxjwIhXyMVK1sUeWSpcgJMLiaiaOUcvyfH8LAia3FydqNTbatKjvNf0s4icFDb8oFCicjf8GkmQpPOQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p><br/></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">未来，启明星辰将持续与荣耀携手并进，共同筑牢安全防线，为用户打造坚不可摧的网络安全屏障，为信息安全行业的高质量发展注入新的强劲动力。</span></p><p><br/></p><p><br/></p><p><br/></p><p style="text-align: center;"><span style="font-size: 14px;">•</span></p><p style="text-align: center;"><span style="font-size: 14px;">END<br/></span></p><p style="text-align: center;"><span style="font-size: 14px;">•</span></p><p style="text-align: center;"><br/></p><p><br/></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;"></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;"><br/></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;"><br/></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;"><br/></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;"><br/></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><br/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/<span style="-webkit-tap-highlight-color: transparent;outline: 0px;">CVE</span>累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="-webkit-tap-highlight-color: transparent;outline: 0px;">数据安全研究、<span style="-webkit-tap-highlight-color: transparent;outline: 0px;">5G安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">人工智能安全研究、</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">移动安全研究、物联网安全研究、车联网安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">工控安全研究、信创安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">云安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1.5px;">。</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1.5px;"></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"></span></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135948" data-ratio="1.1205673758865249" data-s="300,640" width="281.979px" data-type="jpeg" data-w="282" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.97px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/><span style="color: var(--weui-FG-1);font-size: var(--articleFontsize);letter-spacing: 0.034em;text-indent: 24px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;"></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d7f60470&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAwNTI1NDI3MQ%3D%3D%26mid%3D2649619660%26idx%3D1%26sn%3Dce9fa9124779c286d1957ed85a9fdbb3%26chksm%3D830621dcb471a8ca8f9eb9b31ce95886a78bfca51e9dc781e5fbe31b42a18972f67cb793cb1c%26scene%3D58%26subscene%3D0%23rd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 31 Oct 2024 22:17:00 +0000</pubDate>
    </item>
    <item>
      <title>启明星辰ADLab：MSC文件的在野利用情况与黑客攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619652&amp;idx=1&amp;sn=a06360fe1b9f47f340788b4327279a2b&amp;chksm=830621d4b471a8c25d1b37e710fb8f052799858f44736b861a693ace441e4b3dd29f041b66dd&amp;scene=58&amp;subscene=0#rd</link>
      <description>启明星辰ADLab针对近期捕获到的MSC样本进行了深入的分析，本文将主要介绍目前MSC文件在野利用技术的相关原理，披露近期利用MSC文件的多起攻击活动，并重点针对其中的两个案例进行深入分析。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-09-14 18:10</span> <span style="display: inline-block;">北京</span>
</p>

<p>启明星辰ADLab针对近期捕获到的MSC样本进行了深入的分析，本文将主要介绍目前MSC文件在野利用技术的相关原理，披露近期利用MSC文件的多起攻击活动，并重点针对其中的两个案例进行深入分析。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=31d9dc2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiacT8lPtZIgcVIFrDzxsKTwib4M76ibf6ic9KvQvnvXDUpdYHlibJrCbVJPw%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;visibility: visible;"></span></p><p><br/></p><p style="font-size:16px;letter-spacing:2px;color:#494949;"><span style="color: rgb(120, 172, 254);font-size: 17px;"><strong>一、背 景</strong></span></p><p><br/></p><p><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">2024年6月22日，一个利用MSC格式的新型攻击技术的恶意样本出现在VT平台上，此时利用这种技术的恶意样本在VT上均显示为零检测率。这种技术被Elastic研究团队命名为“GrimResource”，其通过恶意构建的MSC文件在Microsoft管理控制台中执行任意代码。启明星辰ADLab在此后的两个月时间中，持续关注使用这种利用手法的攻击，通过监测的结果分析发现：自该技术公开后，同类攻击迅速增加，到目前为止能够监测到的有效攻击及其攻击样本有100多起。并且有越来越多的APT组织、黑产团伙和红队利用该技术在全球范围内进行网络攻击，包括Kimusuky、银狐、海莲花等。目前已发现的目标有中国、韩国、越南、蒙古等国家的政府机构和企业，涉及政府、科技、教育、石油等敏感行业。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">这些攻击普遍通过MSC文件作为恶意payload，通过各种方式发送给目标并诱使目标打开该文件。由于MSC格式的攻击文件是一种相对罕见的文件类型（多数被攻击者可能熟悉.exe、.doc等常见的可执行文件扩展名，但并不了解.msc文件，因此可能在实际攻击中产生奇效），并且目前防护系统也鲜有对此类文件的针对性检测，所以黑客利用该技术实现攻击的成功率高，被检测和发现的几率低，就目前我们观察到攻击诱饵，有包含如：“《**论坛》外审专家邀请函与文章评审单”、：“匿名审稿专家回执 (校外) ”、“适用于南海的两种法律制度研究 (稿件)”、“美国战略收缩对中东地缘政治的影响”、“****网络大会”等极具引诱性的攻击，一旦点击其中的MSC文件，其系统便会被植入窃密木马，导致重要敏感数据被窃取。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">通过我们对攻击的追溯发现早在2024年4月，Kimusuky APT组织就开始利用MSC文件来对其目标实施了大量的攻击，但其利用手法与GrimResource技术有所不同。由于MSC样本的公开利用和技术演变尚处于发展初期，因此有关攻击样本和手法的变化值得引起持续关注。此外，Outflank于8月13日发文称GrimResource技术源于其武器库，其在攻防演练中被防守方上传到公共沙箱。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">MSC(Microsoft Snap-In Control)文件，是微软管理控制台(MMC)用来添加/删除的嵌入式管理单元文件, 由于此类文件能够执行命令和脚本，因此攻击者能够借助MSC文件在目标系统上执行各类恶意任务。自微软默认限制来自互联网的Office宏文档后，LNK、MSI、ISO等其他类型的恶意利用数量就开始大幅增加，此次新出现的GrimResource技术也理所当然成为了黑客们的新宠，相关MSC样本数量自4月以来呈高速增长态势。因此，启明星辰ADLab针对近期捕获到的MSC样本进行了深入的分析，本文将主要介绍目前MSC文件在野利用技术的相关原理，披露近期利用MSC文件的多起攻击活动，并重点针对其中的两个案例进行深入分析。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p style="font-size: 16px;letter-spacing: 2px;color: rgb(73, 73, 73);"><span style="color: rgb(120, 172, 254);font-size: 17px;"><strong>二、近期在野攻击活动分析</strong></span></p><p><br/></p><p><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">通过对目前收集到的100余个MSC样本的分析，我们发现最早的利用样本出现在2024年4月5日，所有样本中，出现在4-5月的攻击样本主要属于Kimusuky组织。6月后，随着GrimResource技术的公开，MSC格式的样本数量以月为单位呈明显的递增关系，表明黑客们正积极利用和测试相关攻击技术并转化为实际攻击。以下是近几个月捕获到的MSC格式的攻击样本数量图。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135958" data-ratio="0.5324074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7cb39841&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaBg5qfcGAyibNIEM5lYmPiaibPHVcjMnl38ZZYLCBpE4eKZxQaF0vwcLgA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图1 </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">MSC攻击样本数量统计图（单位:月）</span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">在这批攻击样本中，其中一些是基于开源项目编译的样本（如下图中图标为“眼睛”的样本即为开源项目MSC_Dropper生成），这类样本可能是部分攻击者正在积极地进行技术准备和免杀测试。同时，一些真实的攻击活动也越来越频繁地出现，在实际攻击中样本通常会把图标伪装成WORD、PDF、MP4等各类常见的文件格式用以迷惑受害目标，下图是部分样本及图标示例。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135959" data-ratio="0.5995893223819302" data-s="300,640" style="" data-type="png" data-w="974" src="https://wechat2rss.xlab.app/img-proxy/?k=9f609342&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiadj1iaMdG8DphPibOhs5baHxyZBgicf1UOpJg9vSJic5sTkvI9ZZbia2RDtQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图2 捕获MSC样本示例</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">从中我们发现了数起针对全球多个国家和地区的攻击活动，目标主要包括中国、韩国、越南、蒙古等，攻击的目标行业则涉及政府、科技、教育、石油等敏感行业。其中，针对中国的APT攻击活动在近期开始明显增多。在7月初期，有关攻击主要以“易翻译助手”、”抖音千粉企业号”、“教育行业数据”等为诱饵的黑产组织攻击为主。而在8月之后，开始陆续出现了多起以政治议题、专家邀请、会议日程、投诉建议、举报材料等针对政府组织或科研部门的针对性攻击，需要引起高度警惕，部分诱饵文档如下所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136000" data-ratio="0.4864376130198915" data-s="300,640" style="" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=a158830b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaH4iaOBnSE29VQJfgSugeWQrcxhQJeeLOyBnWj7icV5ib6cRfzWRYn3QIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图3 主题为“专家邀请函”类的诱饵文档</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135961" data-ratio="0.5185185185185185" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5599e26f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaoTkibUM6uWLkv8FkW5U0xa5YYFXUf7Py5xicMqib8FdK16iabvfxUlibQ1w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图4 主题为“政策制度研究”类的诱饵文档</span><o:p></o:p></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136001" data-ratio="0.6238698010849909" data-s="300,640" style="" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=57c1bbb0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiat9bTlGM2o5ZoLUNeOte7n3ricnLP8Y4GV5AHlRJGMQgG4ZtZtD4LsHA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图5 主题为“****网络大会”的诱饵文档</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135965" data-ratio="0.45" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;text-wrap: wrap;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7d66d199&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiabGwtE7IsW9HOvicCiaz3MDAbm2w0Q2We7sotKV7VRLfGiaHGoiaTt27sNQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图6 针对水利署的诱饵文档</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">除了针对中国以外，韩国、越南、蒙古等多国也接连遭遇到利用MSC文件的攻击活动，其中尤以韩国遭受的攻击最多，这可能与kimsuky组织的攻击目标倾向有关，部分攻击活动诱饵如下所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135966" data-ratio="0.7518518518518519" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=99035b20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaNWahibfV8GwN3vGqfq7wzkI06ZtYQwKZFTz6Y2E4L9mlRBibkbQcFB3w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图7 针对韩国的诱饵文档</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135967" data-ratio="0.4564814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ac5d38eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaQMJkALThOwSIdIdy97Io0c4QRibk7fW6fkdUUyMSh8RbF1kgP60DaOQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图8 针对越南石油公司的诱饵文档</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">在针对这批样本进行深入分析后，我们发现了攻击者使用的多个基础设施，包括多阶段下载服务器和C2服务器等，其中大部分都采用了云服务来干扰溯源追踪，其中一些服务器归属于美国、日本、瑞典、法国、新加坡等国家。部分样本及C2服务器如下所示。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">表1 恶意服务器地址</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-indent: 28px;white-space-collapse: preserve;"></span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:14.2pt;"><td width="198" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(37, 64, 143);padding: 0cm 5.4pt;" height="14"><p style="text-align:center;margin:0cm;margin-bottom:.0001pt;mso-add-space:auto;line-height:normal;"><span style="color: rgb(255, 255, 255);font-size: 12px;"><strong>HASH</strong><strong><o:p></o:p></strong></span></p></td><td width="144.33333333333334" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(37, 64, 143);padding: 0cm 5.4pt;" height="14"><p style="text-align:center;margin:0cm;margin-bottom:.0001pt;mso-add-space:auto;line-height:normal;"><span style="color: rgb(255, 255, 255);font-size: 12px;"><strong>服务器地址</strong><strong><o:p></o:p></strong></span></p></td><td width="88.33333333333333" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(37, 64, 143);padding: 0cm 5.4pt;" height="14"><p style="text-align:center;margin:0cm;margin-bottom:.0001pt;mso-add-space:auto;line-height:normal;"><span style="color: rgb(255, 255, 255);font-size: 12px;"><strong>服务器归属</strong><strong><o:p></o:p></strong></span></p></td></tr><tr style="mso-yfti-irow:1;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin:0cm;margin-bottom:.0001pt;mso-add-space:
  auto;line-height:normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">7445a07afe6d8f21f93308d73cdd7939<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin:0cm;margin-bottom:.0001pt;mso-add-space:
  auto;line-height:normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">sz-everstar[.]com（83.183.214.19、77.221.152.139）<o:p></o:p></span></p></td><td width="77.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin:0cm;margin-bottom:.0001pt;mso-add-space:
  auto;line-height:normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">瑞典、法国<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:2;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin:0cm;margin-bottom:.0001pt;mso-add-space:auto;line-height:normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">597fd2daf8db08e4be40caff97223e26<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">sz-everstar[.]com<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">瑞典、法国<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:3;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">80b5bddf4c7e027832fa20b6490ca026<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">sz-everstar[.]com<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">瑞典、法国<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:4;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">2eef23a26f8f501d02b134bfef698ff2<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">sz-everstar[.]com<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">瑞典、法国<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:5;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">1c5fdc9e8c7106b88ce0aeda1dca55bb<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">sz-everstar[.]com<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">瑞典、法国<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:6;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">380a1a10a6ae1042b7601dd23c2d9026<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">delospartnership[.]info/js/MFWBlackFilter.js（38.180.147.44）<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">日本<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:7;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">8078bf622c5389baa00614c104e0a71d<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">laicai168[.]com（154.91.82.161）<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">塞舌尔<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:8;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">2d624c978e3c5f36aa44b1761f0b27b4<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">850.co[.]il（213.8.166.6）<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">以色列<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:9;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">dcff629818a142ad408eed934677c046<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">goclamdep.net/dxkqdn<br/>
  conflictaslesson[.]com<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:10;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">d707b44aecc91c956df6fba7885d8ba1<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">lokjopppkuimlpo[.]shop/vxedw<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:11;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">5eae3d3b9aeeb0a4186ad3b68ff2da59<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">profilepimpz[.]com/dudubkol  <o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:12;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">5cff45a0307b8d7564a19ccc0c23702e<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">kxmmcdmnb[.]online<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:13;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">b7891b8d75a0a185de4de71c2522cef5<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">goclamdep[.]net<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:14;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">8ccc4ccb2d53f699bca2cfc801b300b5<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">152.42.226[.]161 <br/>https://proradead.s3.sa-east-1[.]amazonaws.com/new.txt<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:15;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">56e2281d11fb81d010d8ca4c6714fecb<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;word-break: break-all;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">api.s2cloud-amazon[.]comfootracker-statics.s3.sa-east-1.amazonaws[.]com<br/>p-game.s3.sa-east-1.amazonaws[.]com<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:16;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">29481c9c38ed246261eadbe27528ff97<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">proradead.s3.sa-east-1.amazonaws[.]com<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:17;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">e51f2ea5a877e3638457e01bf46a20e1<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">footracker-statics.s3.sa-east-1.amazonaws[.]com<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:18;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">249c2d77aa53c36b619bdfbf02a817e5<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;word-break: break-all;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">status.s3cloud-azure[.]com
  wordpresss-data.s3.me-south-1.amazonaws[.]com </span></p><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">360photo.oss-cn-hongkong.aliyuncs[.]com<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:19;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">bf7a1b294efe4f37da8ead2e04968360<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">conflictaslesson[.]com</span></p><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">goclamdep[.]net<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:20;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">29f46e90e30ab47bc786c979cccf67dc<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">154.91.83[.]194<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:21;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">5fec1fcbf0f18242ce916d3804609247<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">154.91.65[.]103<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">云服务<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:22;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">2f0bf617e1326afe7f426d0dfbd690fd<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">103.94.78[.]35<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">香港<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:23;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">6906ccb4442efcc72ec33cd460144521<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">118.107.42[.]233<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">新加坡<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:24;height:14.2pt;"><td width="198" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">41c656c497d7ec24de57a9927c13e81c<o:p></o:p></span></p></td><td width="154.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">108.177.121[.]94<o:p></o:p></span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">美国<span lang="EN-US" style="font-size: 12px;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:25;mso-yfti-lastrow:yes;height:14.2pt;"><td width="483" colspan="3" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="text-align:center;margin-bottom:0cm;margin-bottom:.0001pt;line-height:normal;mso-pagination:widow-orphan;"><span style="color: rgb(136, 136, 136);font-size: 12px;">……<span lang="EN-US" style="font-size: 12px;color: rgb(136, 136, 136);font-family: Arial, &#34;sans-serif&#34;;"><o:p></o:p></span></span></p></td></tr></tbody></table><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;background-color: rgb(255, 255, 255);">同时，我们也捕获到了部分样本的投递URL地址如下表所示。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;background-color: rgb(255, 255, 255);">表2 样本投递URL</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-indent: 28px;white-space-collapse: preserve;"></span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="202.33333333333334" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(37, 64, 143);padding: 0cm 5.4pt;"><p style="text-align:center;margin:0cm;margin-bottom:.0001pt;mso-add-space:auto;line-height:normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);"><strong>HASH</strong><strong><o:p></o:p></strong></span></p></td><td width="248.33333333333334" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(37, 64, 143);padding: 0cm 5.4pt;"><p style="text-align:center;margin:0cm;margin-bottom:.0001pt;mso-add-space:auto;line-height:normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);"><strong>下载URL</strong><strong><o:p></o:p></strong></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="202.33333333333334" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">01c958f316f3fd4676c347893eb23ae4<o:p></o:p></span></p></td><td width="246.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">https://goclamdep[.]net/avefsjdv<o:p></o:p></span></p><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">https://goclamdep[.]net/wltckyw<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="202.33333333333334" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p style="margin:0cm;margin-bottom:.0001pt;mso-add-space:auto;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">41c656c497d7ec24de57a9927c13e81c<o:p></o:p></span></p></td><td width="248.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">https://cdn.discordapp[.]com/attachments/1123151698899255366/1282214424664604744/Twitch_x_Loot_Lab_Event_-_2025.msc?ex=66de8abd&amp;is=66dd393d&amp;hm=918239cc6a1f0564786bb2319fa10e123071d9d6147d8a86ab3f27afe4528d72&amp;<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="202.33333333333334" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p style="margin:0cm;margin-bottom:.0001pt;mso-add-space:auto;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">b40a947a6ad4c5dc03496d1eb61f7edd<o:p></o:p></span></p></td><td width="248.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">https://goclamdep[.]net/roqq<o:p></o:p></span></p><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">https://goclamdep[.]net/btndbgxl<o:p></o:p></span></p><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">https://goclamdep[.]net/ccaot<o:p></o:p></span></p><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">https://goclamdep[.]net/kqnagt<o:p></o:p></span></p><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">https://goclamdep[.]net/xdbhlr<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="202.33333333333334" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">b40a947a6ad4c5dc03496d1eb61f7edd<o:p></o:p></span></p><span style="font-size: 12px;color: rgb(136, 136, 136);">
  </span><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);"><o:p> </o:p></span></p></td><td width="248.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">https://my.microsoftpersonalcontent[.]com/personal/4bcedc9a91fa75d6/_layouts/15/download.aspx?UniqueId=b2a7653d-3b87-4368-a5ce-07e95dfcf641&amp;Translate=false&amp;tempauth=v1e.eyJzaXRlaWQiOiIxZGM3MWYyNi00MTgwLTQxOGUtOGJjNC1mZGY0MzY3Y2M3NDciLCJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvbXkubWljcm9zb2Z0cGVyc29uYWxjb250ZW50LmNvbUA5MTg4MDQwZC02YzY3LTRjNWItYjExMi0zNmEzMDRiNjZkYWQiLCJleHAiOiIxNzI0OTQyNTcwIn0.yFUomtWGIxJtII5BBORkNUEdhd2tALBrXXsCcJzowT5H6WL3tUDuU90pBpbtrfY9hADteNtW8K71TA7FS4y_GBViCuGr83zd8lV-wYrTZjd9tAKet4TwcDUVv7H5AcI2n-npBiko9FqX-sjpIaCX5UZtKCIGen4F9YQkRyfjqo4pS-ukYPgwCVPSwkUXvWMhCNRDd8yoiomnBWRjzG4YjO79H7AZQ0LiH5ce4omBgbVYlLA6TpHrZCmoEC_R9GKiBDGvJ44jQGXb46cFQ7xNqrSvudqWGyLwr1fvx2z5TkDyaPs6WRziZCN5jKTMcBegZKq87IhdxqTdL3Bvl5_-PKbPIhZOvhxGn2iI7n7ri-BKF7QnYsjCrC1LU8G2VtByuzkzA4L7nrC0A3gCfBfUb3kcLi9cV39eA88dE8GNRTqyfOVQ6mOoYWDy-kY2CZg4Dcb4YxFMBPFHAxMIwhtdKdYTAlmaNcNy3eEGFSgCJT0hGxLGUTAHlXANu6Vy-Z__IhuTVRCofIiABMMekG53Kg.Cc-XhDEv7TmvYPmpgrYZV6iIEF0ZXhS1zuyGP6IwUpw&amp;ApiVersion=2.0<o:p></o:p></span></p><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);"><o:p> </o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;"><td width="483" colspan="2" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;margin-bottom:0cm;margin-bottom:.0001pt;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">……<span lang="EN-US" style="color: rgb(136, 136, 136);font-size: 12px;font-family: Arial, &#34;sans-serif&#34;;"><o:p></o:p></span></span></p></td></tr></tbody></table><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;background-color: rgb(255, 255, 255);"></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p style="font-size: 16px;letter-spacing: 2px;color: rgb(73, 73, 73);"><span style="color: rgb(120, 172, 254);font-size: 17px;"><strong>三、MSC文件利用技术原理分析</strong></span></p><p><br/></p><p><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">MSC(Microsoft Snap-In Control)文件，是微软管理控制台(MMC)用来添加/删除的嵌入式管理单元文件, 管理员通过创建控制台可以管理计算机的各种设置，添加各类功能如用户账户管理、系统服务、设备驱动程序等，然后可以将这些管理单元的自定义配置以XML的形式保存到磁盘上，即MSC格式。Windows中常见的设备管理器、磁盘管理器、组策略管理器等都是MSC格式文件。如下图是自定义MSC文件的管理单元任务板界面，攻击者可以通过编程的方式与MMC进行交互，从而构造自定义的界面和内容。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135968" data-ratio="0.5786578657865786" data-s="300,640" style="" data-type="png" data-w="909" src="https://wechat2rss.xlab.app/img-proxy/?k=7611d90a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaesFWiaLAOTyBNG1xzzNxwlK3Y1ZX7n7pyYc1SvVnLe9MoaVBNgOVKicA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图9 MSC文件管理单元任务板</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">我们在进一步针对这批样本分析后，发现目前MSC格式文件的在野利用方式主要有两种。在受害者默认开启用户账户控制（UAC）的情况下，第一种利用方式需要与受害者交互两次（主要由Kimusuky组织使用）；另一种只需交互一次(GrimResource技术)，相关技术利用流程图如下所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135969" data-ratio="0.7027777777777777" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f9baa006&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiatwlFDTQxopVaibQQ387bvBgmXLzNCfk2avXnHvSByTBicj56dhLjP7bw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图10 MSC文件技术利用流程图</span><o:p></o:p></p><p><strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">利用方式一</span></strong><strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">：</span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">在受害者打开MSC文件后，首先弹出UAC控制选项，如果选择是，则继续弹出攻击者定制的Microsoft管理控制台界面诱导目标，一旦受害者继续点击open打开文档即会中招，执行cmd命令、powershell脚本等后续利用阶段。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135970" data-ratio="0.3293347873500545" data-s="300,640" style="" data-type="png" data-w="917" src="https://wechat2rss.xlab.app/img-proxy/?k=5c21e7d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiarvJq7iasKFk2wMI701Rt2tU2eCYzjEJ8tIMUBycPgl7rbXoop5QfaQw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图11 利用方式一</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">对于此类样本，攻击者通过编辑MSC文件的界面伪造UI外观，从而诱骗受害者点击控制台任务板上的链接，而不会产生怀疑。这种利用方式借助了MMC中的控制台任务板实施攻击，控制台任务板是在MMC1.2中引入的，攻击者可以借助控制台任务板来执行各类任务，例如打开属性页、执行菜单命令、运行命令行和打开网页等，目前主要发现Kimsuky组织在大量使用此类攻击方式，相关利用样本的最早出现时间是在今年4月5日，利用示例如下图所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135971" data-ratio="0.31574074074074077" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5e8fcd9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiavT43cHLRs045aYfQib0pNQ6cQEQHxvrBTnw2VvXz6OzhEq29IibiapZdg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图12 控制台任务板执行任意命令示例</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135972" data-ratio="0.5981481481481481" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=addae912&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaicrXma65W1sTzYVhqIianOoLWl8qk5qgStVvSSRQkDheBx5Rc2YDIyng%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图13 任务板执行任意命令XML</span><o:p></o:p></p><p><strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">利用方式二</span></strong><strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">：</span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">GrimResource技术，该技术利用apds.dll中的XSS漏洞，通过MSC文件的StringTable部分引用易受攻击的APDS资源，从而实现嵌入在MSC文件中的JS代码任意执行，最后执行XML中的脚本代码。相较于利用方式一，其具有最少的安全警告，无疑能够使得攻击的成功率大大提高。同时，对于很多为了方便而默认取消UAC通知的受害者来说更是能达到无交互即可执行的效果。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">技术利用关键点：</span><strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span><o:p></o:p></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">将ActiveX对象加载到“ActiveX控件”管理单元中。</span></p></li><li><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">将HTML文件加载到“链接到Web地址”管理单元中。</span></p></li><li><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">在HTML文件中，使用JavaScript与加载的ActiveX对象进行交互。</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">并通过 MSXML方法，触发XSL转换来执行JScript代码。</span></p></li><li><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">最后从JScript代码中调用系统函数，或者通过 DotNetToJScript 执行.NET代码。</span></p></li></ul><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">首先，在MMC程序中，攻击者可以自定义插入ActiveX控件。通过文件编辑器打开创建的MSC文件时，可以看到创建的ActiveX控件存储在XML的StringTable中。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135973" data-ratio="0.287962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=62cf6e33&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaQbfPT93ZnkRhss8lLIahOG3O4OxnDxJoz1IzuicoMhHwENkjkbToD7Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图14 插入ActiveX控件对象</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">但如果想成功加载对象，就要绕过ActiveX 控件的安全警告。攻击者采用了一种巧妙的方法，通过Microsoft Internet Explorer浏览器组件访问external 对象，从而与MMC控制台的其他元素进行交互，这是微软官方支持的一种方式。如下图中，scopeNamespace和docObject即是通过external.Document获取现有对象，而非创建新的ActiveX对象，进而绕过了直接创建ActiveX控件时的安全限制。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135974" data-ratio="0.5425925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9a92b46c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaZQolV3SvNkRTvcdAJ6N4hXvsF6vENYyPEmicbMnRib1eX9RmroorSsKA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图15 GrimResource技术利用代码</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">同时，攻击者利用了apds.dll的一个XSS漏洞，从而可以执行Console Root中的Jscript，进而再执行XML中的脚本。这其中还涉及到一个技巧，即利用MSXML（Microsoft.XMLDOM /
{2933BF90-7B36-11D2-B20E-00C04F983E60} ）执行XSL文件中嵌入的脚本。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">XSLT是一种用于将XML文档转换为其他文档格式的语言，XSLT样式表（XSL）则定义了如何将一个XML文档转换为其他形式。微软支持MSXML XSLT使用&lt;msxsl:script&gt;元素及其属性implements-prefix实现并扩展函数以提供脚本级支持。因此，攻击者通过MSXML的方式即可执行XSL文件中嵌入的脚本，如调用函数 XML.transformNode(xsl)，即可执行嵌入的脚本及后续的恶意利用模块，解码脚本中的&lt;ms:script&gt;标签如下图所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135975" data-ratio="0.30462962962962964" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=64d5cd7d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaUMNDh4ehmojroZ3x7sX6ylxcB0SgPK0aSt1xf8XCCfkfH4GrCD6yMQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图16 脚本中的&lt;ms:script&gt;</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p style="font-size: 16px;letter-spacing: 2px;color: rgb(73, 73, 73);"><span style="color: rgb(120, 172, 254);font-size: 17px;"><strong>四、案例分析</strong></span></p><p><br/></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;margin-bottom: 16px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">启明星辰ADLab接连捕获到了多起利用MSC文件针对全球目标的攻击活动。其中已发现针对中国、韩国、越南、蒙古等国家的政府机构和企业的攻击，越来越多的APT组织、黑产团伙和红队正在利用相关技术在全球范围内进行网络攻击，包括Kimusuky、银狐、海莲花等。在诸多的攻击案例中，我们选取了在技术层面较有代表性且相对敏感的两类攻击样本作为此次的分析案例，利用GrimResource技术针对中国的攻击活动，以及Kimsuky组织利用MMC控制台任务板针对韩国的最新攻击活动。下面我们将对选取的两个案例进行深入的分析。</span><o:p></o:p></p><h3 style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">4.1 以政治话题为诱饵针对中国的攻击活动</span></strong></span><o:p></o:p></h3><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">此案例利用的是GrimResource技术，当受害者点击运行msc文件时，mmc.exe会执行样本中的js代码，继而执行嵌入在xml中的VBScript代码。其中，引致VBA代码的执行的关键点是transforNode(xsl)方法的调用。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135976" data-ratio="0.24722222222222223" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ab705141&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaZGaSXpItlYpQoebIKsXicXeAnFyNuvknC0w4331ic3EumQIgBib4DicdNA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图17 引致VBA代码执行的关键点</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">transforNode方法常用于将一个XML文档通过XSLT样式表（作为参数）转换为其他文档格式。如果XSLT样式表中含有&lt;ms:script&gt;或&lt;stylesheet&gt;元素时，那么元素中的脚本则会在转换过程中被执行。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135977" data-ratio="0.5040106951871658" data-s="300,640" style="" data-type="png" data-w="748" src="https://wechat2rss.xlab.app/img-proxy/?k=28b989ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaNGCrnHkjhuRobhyormJJe2Yq5nI1U8Ex3MuomM5nkyLDsDn3B2sJsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图18 </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">XSLT样式表内容</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">被执行的VBScript代码通过自定义编码和解码、字符串拼接、特殊字符混合编码等混淆技术，能够有效地隐藏其真实逻辑和恶意行为，同时增加了分析人员进行逆向分析的时间成本。下图展示了在首次解码之后的部分代码块，能够看到代码中依然存在着其他混淆。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135978" data-ratio="0.4759259259259259" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d690d67e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaFn0IUL1ONOH14YazhoEtJEoBXSB2xXkYWiaSbI3e8G27M7ibw5t2F51g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图19 混淆的VBScript代码</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">我们继续对代码进行去混淆以及函数重命名处理后，可以看到脚本先是设置文件路径和目录结构，再从XML结构中提取数据进行base64解码并保存为指定文件（诱饵文档），最后打开该文件。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135979" data-ratio="0.6259541984732825" data-s="300,640" style="" data-type="png" data-w="786" src="https://wechat2rss.xlab.app/img-proxy/?k=e703ab4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiakLIhfUnSrgnXK6pO05ALrPntEWeftgQ8jx76a3tfY9ic6icwwDiaRGnfA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图20 释放诱饵文档</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">在本案例中，用于迷惑受害者的是三个伪装成Word的诱饵MSC文件，具体内容如下图所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136002" data-ratio="0.644927536231884" data-s="300,640" style="" data-type="png" data-w="552" src="https://wechat2rss.xlab.app/img-proxy/?k=20fa9591&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiahMrwib5QDiceHFU2ODQc8Nahx516P8QD2xM7gWeKDHUSd6LuQObkM7Ng%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图21 诱饵文档示例一</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135981" data-ratio="1.0818619582664526" data-s="300,640" style="" data-type="png" data-w="623" src="https://wechat2rss.xlab.app/img-proxy/?k=8162d6c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiad7ye01w7MVb9OD0FDUibk1gQdu6ibQEZiaw0fPBFNqia9Rykcamo7mfffg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图22 诱饵文档示例二</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502136003" data-ratio="0.47833935018050544" data-s="300,640" style="" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=29e15439&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiabea0nsH1rXPfQRFPjPibQg5ODsVO7WiaXszSc7TFh5Z9udWykLrmG09A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图23 诱饵文档示例三</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">接着提取和解码其他base64数据，再将解码后的数据保存为最终的Warp.exe和7z.dll可执行文件。随后将“ t 8.8.8.8”作为参数（自动加载同目录下“7z.dll”的所需条件）启动Warp.exe程序。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135983" data-ratio="1.13" data-s="300,640" style="" data-type="png" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=3539e3d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaCWykXTPWAxZawygo4pXArOjWHjF6lpqKoTrKjjQJs5KWlcI3coWpSw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图24 生成并执行warp.exe程序</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">经查看，“Warp.exe”具有 “Lenovo (Beijing) Co., Ltd.”的合法数字签名，其原文件名为“7zwrap.exe”。具体信息如下图所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135984" data-ratio="0.8989547038327527" data-s="300,640" style="" data-type="png" data-w="574" src="https://wechat2rss.xlab.app/img-proxy/?k=ba4f2fd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiax3PPdCl2jPApLV2Qso7AfdrIBQmtRkIYLM4n1vq31GQZUibx9uRGImg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图25 “Warp.exe”详细信息</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">当恶意“7z.dll”文件被“Wrap.exe”成功加载后，其会在内存中对指定数据进行解密。经内存特征扫描后，判定最终被加载执行的是CobaltStrike，我们提取出的CS配置信息如下图所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135985" data-ratio="0.5953703703703703" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=08e444d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiac0h1ycDdCgric5K8o93tic0EJ3bn2NibScLBLPBv3cfTGiaf7rsUhgxKUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图26 </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">CS配置信息</span><o:p></o:p></p><h3 style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">4.2 以学术演讲为诱饵针对韩国的攻击活动</span></strong></span><o:p></o:p></h3><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">该案例是Kimsuky APT黑客组织在今年所引入的一种新的攻击策略，攻击者通过XML的设置属性将MSC恶意文件的图标设置为Word图标，借以伪装成WORD文档来迷惑受害者。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135986" data-ratio="0.4165554072096128" data-s="300,640" style="" data-type="png" data-w="749" src="https://wechat2rss.xlab.app/img-proxy/?k=9b4a72eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaOKSnByMtYpEWE8f8pQONQv3B2BbI6MFjJ6Eiaoun4ZhMZSicFohWF5oQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图27 伪装的Word图标</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">当受害者点击MSC文件时，用户账户控制（UAC）会弹出请求权限选择，如果选[是]，则会通过执行msc连接程序mmc.exe，展示攻击者定制的名为“강면의뢰서.docx”的Microsoft管理控制台界面。具体如下图所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135987" data-ratio="0.3683409436834094" data-s="300,640" style="" data-type="png" data-w="657" src="https://wechat2rss.xlab.app/img-proxy/?k=509b4678&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaywM3neI74fbrkL9cqPIdSofMMibXuHKcpjFtWiaXMLtubmBXGiaUp8xqQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图28 “강면의뢰서.docx”的Microsoft管理控制台界面</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">代码中包含一段cmd参数命令行，其中使用了三个网页浏览器可识别的HTML特殊符号，其所对应的解析内容如下表所示。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">表3 特殊符号内容解析</span><o:p></o:p></p><table cellspacing="0" cellpadding="0" style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tbody style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tr style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="214.33333333333334" valign="top" style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">特殊符号</span></strong><o:p></o:p></p></td><td width="229.33333333333334" valign="top" style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">解析</span></strong><o:p></o:p></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="234" valign="top" style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">&amp;quot;</span><o:p></o:p></p></td><td width="229.33333333333334" valign="top" style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">“</span><o:p></o:p></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="234" valign="top" style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">&amp;gt;</span><o:p></o:p></p></td><td width="249.33333333333334" valign="top" style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">&gt;</span><o:p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;"> </span></o:p></p></td></tr><tr style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="234" valign="top" style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">&amp;amp;</span><o:p></o:p></p></td><td width="249.33333333333334" valign="top" style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">&amp;</span><o:p></o:p></p></td></tr></tbody></table><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135988" data-ratio="0.1935185185185185" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6cab1dec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbia2IWLCFLAONuCS6xFpEy27tYHdasv5hqq4AM1ghic6BzhStibVWGUX65g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;background-color: rgb(255, 255, 255);">图29 含有特殊符号的cmd参数命令行内容</span><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">通过该符号所对应的解析进行替换后，得到了如下图所示的批处理命令。该串批处理命令则是执行MSC后的管理控制台根任务窗口的命令行参数。该段命令的主要功能是从指定URL下载名为“Grieco Kavanagh Passive Supporters.docx”的用于伪装的诱饵文档，以及后续阶段的“pest.exe”和“pest.exe.manifest”文件。除此之外，其还会创建一个名为“TemporaryClearStatesesf”的计划任务，每58分钟执行一次“%appdata%\pest.exe”文件。内容如下图所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135989" data-ratio="0.4320083682008368" data-s="300,640" style="" data-type="png" data-w="956" src="https://wechat2rss.xlab.app/img-proxy/?k=7c828ae8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiapt33OqVzD9PAmQPINtUOuEMMmBibuZkcPmLtLHSDRYjQyZ4qHpWcB6A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图30 </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">cmd参数命令行内容</span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">查看“pest.exe”程序详细信息，发现该程序的数字签名名称为“Adersoft”，原始文件名为“launcher.exe”。该程序为VBSEdit（由Adersoft公司出品的一款小巧而强悍的VBScript编辑工具）脚本启动器。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135990" data-ratio="0.5580608793686584" data-s="300,640" style="" data-type="png" data-w="887" src="https://wechat2rss.xlab.app/img-proxy/?k=70daa04b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaYGsmR9ibduQCR09Rjlg1eBibnK3ibFrEVXTkdx4SvkpL6yBq9fzZOEU1g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图31 “pest.exe”程序详细信息</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">在“pest.exe”程序启动时，会默认加载“pest.exe.manifest”文件，. manifest文件是Windows应用程序清单文件的一部分，常用于指定应用程序的运行时条件和环境变量等。攻击者利用此程序的运行机制将恶意代码写入至清单文件中，那么当“pest.exe”程序运行时恶意代码便可被自动加载执行。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135991" data-ratio="0.5942028985507246" data-s="300,640" style="" data-type="png" data-w="552" src="https://wechat2rss.xlab.app/img-proxy/?k=49c40f07&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaDbRIic5AciboqCKKic0tBVaApbSicibgwH3y7A1NmshaDL50r2NYy4KmdmA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图32 “pest.exe”程序执行报错</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"> “pest.exe.manifest”文件内容是XML格式，恶意代码包含在“&lt;!--BEGIN_VBSEDIT_DATA”和“END_VBSEDIT_DATA--&gt;”标签之间。该文件的主要功能是由一段经base64编码的VBScript代码来实现。部分代码如下图所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135992" data-ratio="0.8816155988857939" data-s="300,640" style="" data-type="png" data-w="718" src="https://wechat2rss.xlab.app/img-proxy/?k=0af53573&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbia8TaY3JdibRz6ibkaEo8VczRA99aIBnv1Koa19HBAKnSvyA23TJjTKMsA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图33 </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">base64编码的VBScript代码</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">解码后我们可以看到，恶意代码首先会判断&#34;%appdata%\ Microsoft \&#34;目录下是否存在“sim.sid”文件。若存在且小于9字节，则删除该文件并退出脚本；否则，将“sim.sid”移动至”%appdata%\Microsoft\sif.bat&#34;并运行bat文件，执行完成后删除自身文件。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135993" data-ratio="0.5455820476858345" data-s="300,640" style="" data-type="png" data-w="713" src="https://wechat2rss.xlab.app/img-proxy/?k=559af175&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaI9SvlApSCScPDJwqibVqZGCia48K1ImSQ2mraWHhfvGexAicTv3pRO3bw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图34 </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">bat文件操作代码</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">如果“sim.sid”文件不存在，则向指定的Google drive链接发送HTTP请求，并获取响应内容。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135994" data-ratio="0.11123110151187905" data-s="300,640" style="" data-type="png" data-w="926" src="https://wechat2rss.xlab.app/img-proxy/?k=20b70479&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiaVczhxxfdlB8aocG8bicTDkAf3uXBEBFRvDpC66sPN36YUy404ricSVLg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图35 向Google drive共享链接发送请求</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">成功获取后，从接收到的内容中提取base64编码的数据（在&#34;pprbstart--&#34;和&#34;--pprbend&#34;标签之间），最后替换特殊字符并将解码后的数据写入至”%appdata%\Microsoft\sif.bat&#34;。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135995" data-ratio="0.49842271293375395" data-s="300,640" style="" data-type="png" data-w="634" src="https://wechat2rss.xlab.app/img-proxy/?k=674287f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSnFbrYfUBd1ibxCFnzLDGbiasJCnwecZwJyh0Vic7nZaDUyoMWMQs1q5XsUMlKy4CFwSzdj2sqpibUMw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图36 解析响应内容</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">截止分析时该Google drive共享链接已失效，暂时无法获取到后续阶段的攻击样本，分析至此结束。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p style="font-size: 16px;letter-spacing: 2px;color: rgb(73, 73, 73);"><span style="color: rgb(120, 172, 254);font-size: 17px;"><strong>五、总 结</strong></span></p><p><br/></p><p><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">本文针对我们近期捕获到的一系列基于新型MSC文件的攻击活动进行了分析，重点介绍了目前MSC文件在野使用的两种利用技术原理，披露近期利用MSC文件的多起敏感攻击活动，并针对其中的两个案例进行了深入分析。从近几个月MSC文件相关攻击的活跃趋势来看，攻击活动涉及到越来越多的APT组织、黑产组织以及红队等，尤其是近期针对政治、科技、教育、石油等领域的APT攻击开始显著增多，需要引起相关政企和个人用户的重点关注。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">同时，MSC文件的公开利用和技术演变尚处于发展初期，尽管目前只是发现了两种在野利用方式，但MMC本身存在不少安全隐患，未来随着更多攻防研究人员的深入挖掘，可能会出现更多基于MSC或是其它Windows组件的新型恶意利用技术，启明星辰ADLab也将持续追踪相关技术的发展演进，及时披露有关威胁活动。</span><o:p></o:p></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;color: rgb(0, 0, 0);font-size: 15px;">启明星辰积极防御实验室（ADLab）</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: var(--articleFontsize);letter-spacing: 0.544px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">“黑雀攻击”概</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/CVE累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、数据安全研究、5G安全研究、人工智能安全研究、移动安全研究、物联网安全研究、车联网安全研究、工控安全研究、信创安全研究、云安全研究、无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等<span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1.5px;">。</span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-align: start;text-indent: 24px;"><img class="rich_pages wxw-img" data-imgfileid="502135996" data-ratio="1.1205673758865249" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.969px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6b3fff32&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAwNTI1NDI3MQ%3D%3D%26mid%3D2649619652%26idx%3D1%26sn%3Da06360fe1b9f47f340788b4327279a2b%26chksm%3D830621d4b471a8c25d1b37e710fb8f052799858f44736b861a693ace441e4b3dd29f041b66dd%26scene%3D58%26subscene%3D0%23rd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 14 Sep 2024 18:09:48 +0800</pubDate>
    </item>
    <item>
      <title>实力加冕 启明星辰揽获多项荣誉→→</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619600&amp;idx=1&amp;sn=ac74c9ca5500c70afb72fb95dc30e457&amp;chksm=83062180b471a89681ac19c7d9a9269d5fa8ad069cde7fc795cc838d0d41756047e4b786ac81&amp;scene=58&amp;subscene=0#rd</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-09-13 16:48</span> <span style="display: inline-block;">北京</span>
</p>

<p></p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=34716a01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nSDr2VW7MLZ55BBPmz1ueg7szYh98Dtz4ibuurUukhV7XwkoyeXLsEicF8135Z9acJu8aDMcibxnWuQw%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;visibility: visible;"></span><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 16px;padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;visibility: visible;"><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">9月10日，2024年第21届中国网络安全年会暨网络安全协同治理分论坛圆满结束。大会对2023年国家信息安全漏洞共享平台（CNVD）、中国互联网网络安全威胁治理联盟（CCTGA）等工作进行总结与表彰。</span><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: Optima-Regular, PingFangTC-light;">启明星辰凭借自身在漏洞发现、信息报送、威胁情报、协同防御等方面硬核实力，被授予CNVD2023年度“</span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);">技术组支撑单位、原创漏洞发现贡献单位、漏洞信息报送突出贡献单位</span></strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: Optima-Regular, PingFangTC-light;">”及CCTGA2023年度网络安全威胁情报共享工作、协同防御试点工作“</span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);">优秀成员单位</span></strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: Optima-Regular, PingFangTC-light;">”等多项荣誉。</span></p><p><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="463" data-cropsely1="0" data-cropsely2="323" data-imgfileid="502135945" data-ratio="0.6972222222222222" data-s="300,640" style="vertical-align: middle;width: 463px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e732066e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FBwR7Xg3aXhZV6skK67VTpmwweqW5jzT5vYHmQ7MPbibIdbmchFGnIfSrCzTqM1jXWKaFYbagBgHB5vzYV4pD7mA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg%26wxfrom%3D13"/></p><p><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="489" data-cropsely1="0" data-cropsely2="348" data-imgfileid="502135943" data-ratio="0.7148148148148148" data-s="300,640" style="vertical-align: middle;width: 489px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3081d980&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FBwR7Xg3aXhZV6skK67VTpmwweqW5jzT5eb31vViaQIFAn09Bnqj3BHMFlGTnUh7Kh7OXia4WicY8JUHIP3ibvDNubQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg%26wxfrom%3D13"/></p><p><img class="rich_pages wxw-img" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_jpg/BwR7Xg3aXhZV6skK67VTpmwweqW5jzT5DpufMtgpSAFyIcD5wOmq8AEiaVPXkukehRNg0nDHHibQS5Z5bBPeBF4g/640?wx_fmt=jpeg&amp;from=appmsg" data-cropx1="2.1218074656188604" data-cropx2="1069.3909626719055" data-cropy1="0" data-cropy2="740.5108055009823" data-imgfileid="502135942" data-ratio="0.6944704779756327" data-s="300,640" style="vertical-align: middle;width: 503px !important;visibility: visible !important;" data-type="jpeg" data-w="1067" src="https://wechat2rss.xlab.app/img-proxy/?k=5d1c5d28&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FBwR7Xg3aXhZV6skK67VTpmwweqW5jzT5OhePQSHLxtgRnUr4CXc9Y5hJ0rzZKgSz1ibZmYQsNX3YmibIIlHRIFNw%2F640%3Fwx_fmt%3Dother%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p><img class="rich_pages wxw-img" data-croporisrc="https://mmbiz.qlogo.cn/sz_mmbiz_jpg/BwR7Xg3aXhZV6skK67VTpmwweqW5jzT5ia9oTAmmPp855VtqbbJ7ZtfGoAVNIO242icSH7jXPnNIeQsMkuTQwb1Q/0?wx_fmt=jpeg&amp;from=appmsg" data-cropx1="61.657032755298644" data-cropx2="1210.9441233140653" data-cropy1="22.196531791907518" data-cropy2="826.204238921002" data-imgfileid="502135944" data-ratio="0.7" data-s="300,640" style="vertical-align: middle;width: 466px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4ea9ae0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FBwR7Xg3aXhZV6skK67VTpmwweqW5jzT5Qu0wvJ28ticzG5ic4mBuLHFUIodiaib5tHTpsbq6kanksljXib8Iia6RsdJw%2F640%3Fwx_fmt%3Dother%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p style="color: rgb(62, 62, 62);font-size: 14px;text-wrap: wrap;text-align: center;"><br/></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">2023年，启明星辰对CNCERT在APT攻击、新型网络攻击等领域的专项分析工作中做出积极贡献，向CNVD提交的原创漏洞中高中危漏洞占比达86%，全面覆盖系统安全、主流应用和网络设备安全、移动终端安全、物联网安全、工控安全、无线安全、云安全、信创安全、数据安全等领域，并在5G协议标准、网络设备、操作系统和Web应用等方向提交了多个危害程度高、影响范围广的高质量原创漏洞。此外，启明星辰在原创漏洞的研究上持续发力，</span><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);"><strong>原创漏洞总积分持续占据“企业单位原创积分排名”第一</strong></span><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">。</span></p><p><br/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135941" data-ratio="0.4324074074074074" data-s="300,640" style="vertical-align: middle;width: 643.141px !important;visibility: visible !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=76c3aabd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FBwR7Xg3aXhYKVNavnwxuniawiaboRqpWC0N9Jwlv6xnpzLzz6rryVfib3vm53FMibGOObmWibASb4opzRib4Bk26ibG7g%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"></span><br/></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">启明星辰积极防御实验室（ADLab）成立于1999年，是国内最早的攻防技术研究团队之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者，拥有卓越的安全技术研究和安全攻防实力。截至目前，<span style="text-wrap: wrap;">ADLab</span>已通过CNVD/CNNVD/NVDB/CVE累计发布安全漏洞5000余个，持续多年多名成员多次入选微软“MSRC全球Top100最具价值研究者”等国际榜单，团队攻防技术研究实力和专业性在全球范围内获得高度认可。</span></p><p><br/></p><p><br/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135946" data-ratio="0.03125" data-s="300,640" style="vertical-align: middle;width: 640px !important;visibility: visible !important;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=af5a33fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FBwR7Xg3aXhYKVNavnwxuniawiaboRqpWC0RPD47uEwfSb0liaIcxrOJp5aAiarS0X8hHebDNIDaFNKJmfUa6P7vAibA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p><br/></p><p><span style="color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">未来，启明星辰将继续深耕核心技术的研发与创新，不断强化在漏洞发现、信息报送、威胁情报共享等方面的综合能力与实战经验积累，为用户提供更加精准、高效、全面的安全服务与技术支撑，推动国家网络安全事业的高质量发展。</span></p><p><br/></p><p style="font-size: 16px;text-wrap: wrap;"><br/></p><p style="text-align: center;text-wrap: wrap;"><span style="font-size: 14px;">•</span></p><p style="text-align: center;text-wrap: wrap;"><span style="font-size: 14px;">END<br/></span></p><p style="text-align: center;text-wrap: wrap;"><span style="font-size: 14px;">•</span></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;"></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/<span style="-webkit-tap-highlight-color: transparent;outline: 0px;">CVE</span>累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="-webkit-tap-highlight-color: transparent;outline: 0px;">数据安全研究、<span style="-webkit-tap-highlight-color: transparent;outline: 0px;">5G安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">人工智能安全研究、</span></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">移动安全研究、物联网安全研究、车联网安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">工控安全研究、信创安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">云安全研究、</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1.5px;">。</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1.5px;"></span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;"></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135948" data-ratio="1.1205673758865249" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.979px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2cdaad8b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAwNTI1NDI3MQ%3D%3D%26mid%3D2649619600%26idx%3D1%26sn%3Dac74c9ca5500c70afb72fb95dc30e457%26chksm%3D83062180b471a89681ac19c7d9a9269d5fa8ad069cde7fc795cc838d0d41756047e4b786ac81%26scene%3D58%26subscene%3D0%23rd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 13 Sep 2024 16:48:34 +0800</pubDate>
    </item>
    <item>
      <title>启明星辰ADLab：对近期某未知黑客组织攻击活动追踪与分析报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619588&amp;idx=1&amp;sn=179fcb6618f08dc7a5c93bfe4b6c5ae5&amp;chksm=83062194b471a8829debf48fc09a9e93bcb5cf3c7dfad5ff58bd163cb2a3c8874a9c66e44bac&amp;scene=58&amp;subscene=0#rd</link>
      <description>启明星辰ADLab陆续发现一批利用商业木马remcosRAT攻击全球多个大型企业的网络攻击活动，这些攻击活动试图将窃取的敏感数据回传至美国的多台C2服务器上，通过组织溯源发现这批攻击活动并不属于已知的任何黑客组织(包括APT组织).</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-08-30 18:23</span> <span style="display: inline-block;">北京</span>
</p>

<p>启明星辰ADLab陆续发现一批利用商业木马remcosRAT攻击全球多个大型企业的网络攻击活动，这些攻击活动试图将窃取的敏感数据回传至美国的多台C2服务器上，通过组织溯源发现这批攻击活动并不属于已知的任何黑客组织(包括APT组织).</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=72a650de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiau59pJKmq77kYAQuyiaNk6E2p6YBCcPv6yq3GWLedB034BfyVwIdq2Bg%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;visibility: visible;"></span></p><p><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p style="font-size:16px;color:#0080FF;margin-bottom:unset;letter-spacing:0px;"><span style="color: rgb(120, 172, 254);"><em><strong>01</strong></em></span></p><p style="font-size:16px;letter-spacing:2px;color:#0080FF;line-height:1;"><span style="color: rgb(120, 172, 254);"><strong>分析简述</strong></span></p><p><img class="rich_pages wxw-img" data-imgfileid="502135906" data-ratio="0.9772727272727273" style="width:100%;display:block;vertical-align:bottom;" data-w="44" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=19e2db04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjtGuuzaSlftg58JibibSX2PbTIjDsURueNwNryPfGw723DEtv2hNPibNdjKMQgB1MGhth5pjiayic7rLQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">在过去几个月里，启明星辰ADLab陆续发现一批利用商业木马remcosRAT攻击全球多个大型企业的网络攻击活动，这些攻击活动试图将窃取的敏感数据回传至美国的多台C2服务器上，这其中被攻击的企业还包含一家中国央企控股的外运企业，通过组织溯源发现这批攻击活动并不属于已知的任何黑客组织(包括APT组织)，因此，为了进一步掌握该黑客组织的活动情况，我们从4月份开始对该黑客相关的活动进行特别关注和追踪，直到本文完成时仍未有该攻击活动的披露报告。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">通过长时间的攻击样本收集，最后我们获得了跨度5个月时间的190多个攻击样本，这些攻击样本中有140多个都试图回连到位于美国地区的控制命令服务器上。其中服务器主要集中在173.255.204.62、107.173.4.18和107.175.229.143。通过溯源分析确定这批攻击活动从2024年3月份就已经开始了对目标企业进行攻击，在接下来的几个月里攻击活动变得越来越活跃，直到7月份达到活跃高峰后，8月份攻击活动渐渐变少。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">通过基础设施和样本分析发现，这是一个自动化程度非常高的黑客组织，其甚至可能将整个攻击周期都进行了自动化，我们发现攻击组织将黑客邮箱注册、域名注册、漏洞利用代码、loader即时编译、木马生成、攻击投放等过程都进行了自动化。当然除了自动化外，黑客组织也会根据自身掌握目标的程度而选择进行定制化的攻击。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">从攻击目标来看，这批攻击活动除了攻击我国某外运企业外，还包含一些全球性的国际贸易企业以及化学制品、机械制造、金融保险等领域相关企业。我们追踪到的攻击活动主要以鱼叉邮件和早期office漏洞为主，大量样本的文件特征表现为高度自动化生产与自动化投放的特点，同时一些攻击邮件也表现出与目标产品和客户关系细节相关的高度定制化的特性。投放的窃密木马主要为5.1.0 Pro版本的remcosRAT，相较于我们之前分析的remcosRAT版本，新版本允许黑客通过Telegram机器人与木马端交互，如此一来，黑客可以使用手机、平板电脑等移动设备随时随地进行木马控制，攻击场景更加灵活。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">从对抗手法上来看，该未知黑客组织利用了多阶段远程加载技术、混淆技术、AD技术和进程镂空技术来躲避流量监测和杀毒软件的查杀，其中AD（ADD-TYPE）技术是一种较为少见的技术，在混淆的powershell代码中，其常常被用来实现隐蔽的.net程序集的调用，黑客在本攻击活动中用来实现远程恶意代码的隐蔽下载。</span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p style="font-size:16px;color:#0080FF;margin-bottom:unset;letter-spacing:0px;"><span style="color: rgb(120, 172, 254);"><em><strong>02</strong></em></span></p><p style="font-size:16px;letter-spacing:2px;color:#0080FF;line-height:1;"><span style="color: rgb(120, 172, 254);"><strong>攻击活动分析</strong></span></p><p><img data-imgfileid="502135907" data-ratio="0.9772727272727273" style="width:100%;display:block;vertical-align:bottom;" data-w="44" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=19e2db04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjtGuuzaSlftg58JibibSX2PbTIjDsURueNwNryPfGw723DEtv2hNPibNdjKMQgB1MGhth5pjiayic7rLQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><br/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">我们在追踪这批攻击活动的过程中，总共收集了190多份攻击样本，从每个攻击样本的入侵路径上分析，发现黑客主要有两种攻击手段。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">第一种是通过投递恶意的带有漏洞利用代码的office文档（xls和doc文档）来进行，其中的漏洞利用程序会从黑客服务器上下载一个带有JS脚本的hta文件并加载执行，此时JS脚本内一段被混淆的VBS脚本便会被启用，而这段VBS执行后最终会调用一段被混淆的powershell代码。这段powershell脚本采用了AD技术，其为当前程序添加了一个新的 .NET 类型，该类型包含一个从 urlmon.dll 动态链接库中导入的 URLDownloadToFile 函数，powershell利用该函数从黑客服务器上下载一个被二进制混淆过的loader程序并执行，该loader最终会解密并执行窃密木马remcosRAT。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">第二种攻击手法就是直接将混淆过的hta文件（或其链接）和loader程序伪装成为正常文件/链接附在钓鱼邮件中，诱使目标执行诱饵文档。</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">我们先以7月25日的一起鱼叉钓鱼邮件攻击开始来简单分析黑客的攻击过程，在整个攻击周期中，有大量类似的攻击邮件，如图1这样。这个案例里黑客将发件人伪装成了印度高档面料制造商“Raymond”相关工作人员，将一个恶意文件投递到我国某外运公司的工作人员。邮件主题为 “RFQ”（报价请求），邮件附件为“Quotation.xls”（报价.xls），正文翻译成中文是“请查收附件所需项目的报价单，并以报价单确认，请确认收据”。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135939" data-ratio="0.6044905008635578" data-s="300,640" style="" data-type="png" data-w="579" src="https://wechat2rss.xlab.app/img-proxy/?k=6a5084e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaob7XPyrYWpiaqFxwu2GOtRrC8YnZqf9jnVKcBlNmrO6PgibFxgicWLZ5w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图1 针对我国某外运公司的攻击邮件</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">这种以报价为诱饵的攻击邮件主要通过某些模板自动化生成，其适用范围较广，成功率也较高。这种类似的攻击大概流程如图2所示：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135910" data-ratio="0.42592592592592593" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b0cf867e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiapa2ibEwFcpXPCicSSxiahkpEZPMicibOXEjPGUsv3MhMs0OIKYuwBAK3Fmg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图2 黑客攻击流程图</span><o:p></o:p></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">黑客首先将木马存放于自己建立的文件服务器上，在配置好邮件payload后，通过自动化程序（以邮件模板库与情报库中目标信息为依据）生成攻击邮件，并向目标企业投放木马。当受害者不慎打开邮件的附件文档，其中被精心构建的漏洞利用程序便会被触发，获得执行权限的shellcode接下来会通过多级级联下载（为了便于躲避查杀），最后成功投放木马remcosRAT。黑客利用该木马可完全接管和控制目标主机，且可以对目标所在的网络进行下一步的入侵，以寻求更具价值的数据。其他类似攻击如图3所示。</span><o:p></o:p></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135911" data-ratio="0.6046296296296296" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=33c5be06&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaic9ChxkWpk0pa35ZdLxsWicgQ2A60A5Hqu7NC2jCptHBzMeZ40euukkA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图3 关联到的部分网络攻击邮件截图</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">这一系列攻击活动中，黑客的伪装对象还包括我国某海运服务集团、我国某国际物流公司、美国物流公司“Expeditors”、新加坡物流航运公司“Interion Pte Ltd” 等实体。</span><span style="font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"><span lang="EN-US"><o:p></o:p></span></span></p><table cellspacing="0" cellpadding="0"><tbody><tr><td width="85.33333333333333" valign="top" style="border-width: 1pt;border-color: rgb(68, 114, 196);background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;color:white;">时间（<span lang="EN-US">utc</span>）<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="124.33333333333334" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;color:white;">邮件主题<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="134.33333333333331" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;color:white;">发件人<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="139.33333333333331" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;color:white;">收件人<span lang="EN-US"><o:p></o:p></span></span></strong></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024/6/27
  4:45<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Inquiry
  - Pumps &amp; Accessories - (Oasis Pump Indusry LLC)<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Linda
  Parker &lt;anything@taihuashpg.com&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">boema@boematec.com<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024/6/18
  14:29<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">RV:
  Solicitud de presupuesto<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Comunicandonos
  &lt;comunicandonos@smsv.com.ar&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">seguridad.informatica@smsv.com.ar<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024/6/13
  7:49<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Request
  for Quotation<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">sales@mail-con.ink<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">zmakower@se-kure.com<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024/5/30
  15:36<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Request
  for Quotation<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">retail@goldentools.ae<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">abuse@nic.cl<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024/4/18
  5:52<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">RFQ<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Aditi
  Parikh &lt;dilip.singh@naprodgroup.com&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">info@stranskyapetrzik.cz<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024/4/18
  3:31<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">RFQ<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Aditi
  Parikh &lt;dilip.singh@naprodgroup.com&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">baris.ozcelikci@akkim.net<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024/4/9
  0:16<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Request
  for Quotation<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Terri
  Rinetti &lt;guillermoc.panamascrub@gmail.com&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">info@stranskyapetrzik.cz<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024/4/8
  20:58<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">*****SPAM*****
  Request for Quotation<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Terri
  Rinetti &lt;guillermoc.panamascrub@gmail.com&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">ipcmkt@ipc.com.mx<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024/4/8
  15:46<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Request
  for Quotation<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Terri
  Rinetti &lt;guillermoc.panamascrub@gmail.com&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;word-break: break-all;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">k.kocianova@ronas.com<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2023/3/31
  2:33<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">New
  Enquiry<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;word-break: break-all;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Jojo-JHT
  &lt;janice@****.com&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">undisclosed-recipients:<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2023/3/30
  13:14<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">RE:
  Freight<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Brokerage-SIN
  &lt;Brokerage-SIN@expeditors.com&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">info@dawex.cz<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2023/3/30
  8:35<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">RE:
  New Items order<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;word-break: break-all;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Holiday-TJ-RMS-FOOD
  SALES &lt;food-ae@****.com&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">info@dawex.cz<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2023/3/22
  11:54<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">PAYMENT<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Rena
  Ng &lt;rena@interion.com.sg&gt;<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">info@dawex.cz<o:p></o:p></span></p></td></tr><tr><td width="85.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2023/3/21
  18:12<o:p></o:p></span></p></td><td width="124.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">RE:
  NEW PO-23101<o:p></o:p></span></p></td><td width="134.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">admin@oudhalanfar.com<o:p></o:p></span></p></td><td width="139.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">export.sales@aqs.dz<o:p></o:p></span></p></td></tr></tbody></table><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">表1 部分定向攻击邮件相关信息</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">攻击目标还包含韩国“船舶燃油系统、推进系统和操纵系统等系统”代理商“Boema Hi-Tec Ltd”、智利网络信息中心“Network
Information Center Chile（NIC Chile)”、 捷克气动元件、机床、食品加工设备公司“Stransky a Petrzik”以及墨西哥“称重、识别和检测系统”制造商“Grupo
IPC”等企业，部分受害企业相关信息如图4。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135912" data-ratio="0.6212962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2f8ddaf7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaHO7uNuRTOUfQibvxuvCJqESyZHDTdNotwwDNhAE9RqZ48lVKf6FwUSA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">4 </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">部分受害企业相关信息</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;text-align: justify;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">而对于一些特定的目标，黑客会根据这些目标的不同业务内容和企业情况进行邮件定制。如图5所示：黑客声称自己来自一个泵工业企业，向韩国船舶加工、轮船推进相关代理商“Boema
Hi-Tec Ltd”发送了主题为“Inquiry - Pumps &amp; Accessories -
(Oasis Pump Indusry LLC)（查询-泵和配件-绿洲泵业有限责任公司）”的邮件，正文中声称是要从该企业购买水泵和配件产品，附件为“Pumps
Product List &amp; Drawing Dimensions.xls（泵产品清单及图纸尺寸）”是其需要的产品规格和图纸尺寸。类似的主题和内容还有“New Enquiry”（新询盘）、“New Items order”（新项目订单）和“PAYMENT”（付款）等。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135913" data-ratio="0.6574074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fa95aeda&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaJS6icMRH4PI6IYIlOCkwTzhuBlx6JDSibrPnCL8vyvvLvFIz9mml3yyQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">图</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">5 </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;">定制化攻击邮件示例</span><o:p></o:p></p><h2 style="margin-bottom: 8px;text-indent: 0em;"><br/></h2><p style="font-size:16px;color:#0080FF;margin-bottom:unset;letter-spacing:0px;"><span style="color: rgb(120, 172, 254);"><em><strong>03</strong></em></span></p><p style="font-size:16px;letter-spacing:2px;color:#0080FF;line-height:1;"><span style="color: rgb(120, 172, 254);"><strong>基础设施分析</strong></span></p><p><img data-imgfileid="502135914" data-ratio="0.9772727272727273" style="width:100%;display:block;vertical-align:bottom;" data-w="44" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=19e2db04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjtGuuzaSlftg58JibibSX2PbTIjDsURueNwNryPfGw723DEtv2hNPibNdjKMQgB1MGhth5pjiayic7rLQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><h2 style="margin-bottom: 8px;text-indent: 0em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></h2><p style="text-indent: 2em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">在我们持续的追踪和分析后，总共得到了194个攻击样本，这些样本分别出现在黑客攻击的不同阶段，我们把这些样本大致分为四大类，其中第一类是利用office漏洞的xls和word恶意文档；第二类是内嵌有js脚本的hta文件；第三类是存储在黑客文件托管服务器上的remcosRAT木马的loader；第四类是用于直接通过邮件进行木马投递的压缩包文件。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">通过最终分析确认，黑客窃密木马的控制命令服务器为“bossnacarpet.com”和“vegetachcnc.com”，目前这两个域名都解析到位于美国73.255.204.62服务器上，回传端口为2556。除了用于控制目标主机的控制命令服务器外，黑客还有一些用于存储hta和remcosRAT木马loader的托管服务器，大部分的样本托管服务器都位于美国境内。这些托管服务器相关信息如下。</span><span style="font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"><span lang="EN-US"><o:p></o:p></span></span></p><table cellspacing="0" cellpadding="0"><tbody><tr><td width="143" valign="top" style="border-width: 1pt;border-color: rgb(68, 114, 196);background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">托管服务器</span></strong><span style="font-size:
  8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">服务器<span lang="EN-US">ip</span></span><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"><o:p></o:p></span></p></td><td width="130.33333333333331" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">托管的恶意样本数<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="210.33333333333334" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">托管服务器归属国家<span lang="EN-US"><o:p></o:p></span></span></strong></p></td></tr><tr><td width="123.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">107.173.143.46<o:p></o:p></span></p></td><td width="110.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">13<o:p></o:p></span></p></td><td width="190.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">美国<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr><td width="143" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">172.245.135.155<o:p></o:p></span></p></td><td width="130.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">24<o:p></o:p></span></p></td><td width="190.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">美国<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr><td width="143" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">192.3.95.135<o:p></o:p></span></p></td><td width="130.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">16<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">美国<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr><td width="143" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">192.3.118.15<o:p></o:p></span></p></td><td width="130.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">8<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">美国<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr><td width="143" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">192.3.176.131<o:p></o:p></span></p></td><td width="130.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">14<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">美国<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr><td width="143" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">91.92.245.100<o:p></o:p></span></p></td><td width="130.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">8<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">荷兰<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr><td width="143" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">91.92.120.127<o:p></o:p></span></p></td><td width="130.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">20<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">保加利亚<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr><td width="143" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">103.67.162.213<o:p></o:p></span></p></td><td width="130.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">23<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">越南<span lang="EN-US"><o:p></o:p></span></span></p></td></tr></tbody></table><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">表2 恶意服务器IP地址</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">窃密木马控制命令服务器域名“bossnacarpet.com”注册于2023年8月4日，但是一直未有使用直到2024年4月解析到了服务器107.175.229.143。从4月份到8月份更换了2次服务器分别为5月更换为服务器107.173.4.18，7月份更换为服务器173.255.204.62。服务器173.255.204.62一直使用到现在。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">而控制命令服务器域名“vegetachcnc.com”是2024年3月21日新注册的域名，其直到2024年7月才被配置到服务器107.173.4.18和服务器173.255.204.62上。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">此外，从这两个域名的注册信息来看（见图6），黑客极有可能使用了自动化注册工具来实现，如果推测成立，那么我们所发现这批攻击可能只是该黑客组织某一个分支。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135915" data-ratio="0.3965785381026439" data-s="300,640" style="" data-type="png" data-w="643" src="https://wechat2rss.xlab.app/img-proxy/?k=0bb63622&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpialx7KiaKoLtJBRlswOQ9gkibeDNAeicxWd3XfDPlrfNxNq8tDMfr6orwbA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图6 域名注册信息</span><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">当然除了域名注册存在自动化的痕迹外，该黑客组织的攻击样本看起来也具有很强的自动化特性。部分文件信息如表4所示，在我们收集到的样本中存在大量8字节十六进制名称的漏洞利用文档如“A5570000”和“00870000”类似的形式，这些攻击文档无疑是黑客通过自己的攻防平台自动化生成的恶意文件。这类文件的出现时间主要集中在2024年3月份到8月份。</span></p><table cellspacing="0" cellpadding="0"><tbody><tr><td width="77" valign="top" style="border-width: 1pt;border-color: rgb(68, 114, 196);background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">文件名<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="75" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">文件类型<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="126.33333333333333" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">最早发现时间<span lang="EN-US">(UTC)<o:p></o:p></span></span></strong></p></td><td width="185.33333333333337" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span lang="EN-US" style="font-size:8.0pt;font-family:
  &#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">MD5<o:p></o:p></span></strong></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">FF770000<o:p></o:p></span></p></td><td width="55.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-08-01
  12:42:14<o:p></o:p></span></p></td><td width="165.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">0c8ee6c0cbf2182285a1c6c38748f518<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">88070000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-25
  04:24:07<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">b06d8bfa821fa5593ac2ba7ad0edc7d3<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">A2970000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-24
  06:25:55<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">6b2b204dbc5a807bb6fd0eef32448a33<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">5CA70000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-17
  05:54:01<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">8c620da9b73df86d33957e7a8e83ae89<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">57270000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-16
  07:42:23<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">67f1db2184a214f146189e1b66324a32<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">B1770000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-01
  07:41:28<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">6bc960e28b5f15db4c6eb81be32bb905<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">87970000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-27
  02:07:06<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">71b9276dc19e8e95bb6e95408fe0f9ac<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">1B770000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-26
  13:12:17<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">cf896ea8b812a392ee2f1488135ddfa4<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">C8B70000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-25
  04:55:38<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">9577e342a776ee82982f05a75cb26022<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">C1D70000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-25
  01:01:12<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">46f23a7db98759d7d8b2021958ba148f<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">38080000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-21
  00:54:22<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">d217bb5277a59b5ab0c9a21e1536eb17<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">AA470000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-19
  00:57:18<o:p></o:p></span></p></td><td width="165.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">c6a534ce296e6cdf0a2eeca480f396ae<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">4C870000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-18
  08:38:58<o:p></o:p></span></p></td><td width="165.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">e1716595fd0f969b32ce2b7f5e9a920c<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">12A70000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-12
  10:04:14<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">e52c25f3153170e27bf9a836fb1256c6<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">00870000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-22
  08:05:22<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">9ea8cb0e5a0d9e44e50f0f0e67150e27<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">37170000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-17
  13:08:52<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">13b75900703bca0efcb8bac0ecd86e3f<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">7D370000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-17
  12:24:36<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">77bfacbe5363ddb8a9bee3665bf7e1c5<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">A5570000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-16
  06:07:59<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">365a99677725a7f22e20601349cd765b<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">81B80000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-09
  14:05:59<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">4e6a56da7a363affa0470bd18fc24e82<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">28870000<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">xls<o:p></o:p></span></p></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-03-26
  00:32:04<o:p></o:p></span></p></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">0a0e56afc68c9eaf7c524ba2e443f1b5<o:p></o:p></span></p></td></tr><tr><td width="77" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">……<o:p></o:p></span></p></td><td width="75" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><br/></td><td width="146.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><br/></td><td width="185.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><br/></td></tr></tbody></table><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">表3 恶意诱饵文档</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">此外这批样本中的一些doc漏洞利用文件呈现出一种奇怪的文件名形式，类似于文件“iwanttosxwithudeeolybecauseitrulylovesxwithoumygirlireallymissingu__nowiwantsxwithou.doc，这类文件看起来像是利用一些文章或者小说内容作为字典，通过某种算法自动化生成的样本，这类文件主要出现在2024年3月至4月期间。部分文件信息如下表所示。</span><span lang="EN-US" style="font-size:10.5pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"><o:p></o:p></span></p><table cellspacing="0" cellpadding="0"><tbody><tr><td width="142.33333333333331" valign="top" style="border-width: 1pt;border-color: rgb(68, 114, 196);background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">文件名<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="70.33333333333333" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">文件类型<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;" width="91.33333333333333"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">最早发现时间<span lang="EN-US">(UTC)<o:p></o:p></span></span></strong></p></td><td width="159.33333333333334" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span lang="EN-US" style="font-size:8.0pt;font-family:
  &#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">MD5<o:p></o:p></span></strong></p></td></tr><tr><td width="122.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">mewillthinkaboutthegoodthingstogetinbacktheprojecttointernationalideatoseehowitswillbekissing___lovertogetmebackthetruthfeel.doc<o:p></o:p></span></p></td><td width="50.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" width="71.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-22
  08:05:22<o:p></o:p></span></p></td><td width="159.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">524722cd8d4be3abb16529cf7d6f0c33<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">iwanttosxwithudeeolybecauseitrulylovesxwithoumygirlireallymissingu__nowiwantsxwithou.doc<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" width="91.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-16
  06:07:59<o:p></o:p></span></p></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">1626a8bd20e14d78a9eed883017016ec<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">ibelieveitsagreatideatoenjoythelovertokissherlipswithouthavinganythingbecausesheislovemetrulyalot____itspurelovewithoutkissingandall.doc<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" width="91.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-11
  03:23:28<o:p></o:p></span></p></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">83bfd4345304237618b51536358bdb5c<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">heisbestgirlieeverseeninmylifeiwanttokissherbadlytheniwillfuckherbadlysheismywife___ilovehertrulyfromtheheartsheismygirllover.doc<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" width="91.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-09
  14:05:59<o:p></o:p></span></p></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">c4785b8b112ecee3de38b826d9b7ee82<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">weareverybeautifulgirlsxygirlwantokissmeharderthanbeforetogetmeback___sheisverybeeautifulgirlforme.doc<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" width="91.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-09
  13:48:18<o:p></o:p></span></p></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">f8b201556d3c349d0fce9702c424c556<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">wecontactedloverstounderstandhowhotgirlchickessheisbutshesaidiamveryhotgirltokiss____whatabeautifulgirlsheistokissandenjoytheday.doc<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" width="91.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-08
  07:43:58<o:p></o:p></span></p></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">3d9950539df8ffe5a6ad65a287dd1abe<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">greatwaytounderstandhowimporantthingsitisgreatgoodtounderstandlover____ireallywantthenewloversinthelineto.doc<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" width="91.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-03-26
  04:44:03<o:p></o:p></span></p></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">8b48d774bf6e4937f73026c9a35c9e64<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">shewantihavetohughimtigtlyandshewillfeelgoodbeausesheisverybeautifulgirl___undestandhowmuchilovehretwith.doc<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" width="91.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-03-25
  12:28:52<o:p></o:p></span></p></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">0e02c559c765b23be23017f984e1d5df<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">hyperloversknowthathowmuchiamfeelingonthelovewhichumadeformeireallykiissmyloverfrmtheheart____becauseshelovedmetrulyalot.doc<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" width="91.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-03-21
  04:56:50<o:p></o:p></span></p></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">62763ea99a08c8de0139281ea02be501<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">ilovehimtrulyfrommediafxpixelhandtreatedbymediapixelnetworkstilleverythinggodd____sweetkissigivenheronneckandfacetoget.doc<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" width="91.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-03-20
  17:46:23<o:p></o:p></span></p></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">e7b1dab5d64b8e37ab2c8b0a05fd486c<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">kissingagirlissoeasyrecentlyireallyfeelsheismygirlineverwanttohurtherweneverwantotkissher_______ilovehertrulyfromtheheartiloveyou.doc<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">doc<o:p></o:p></span></p></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" width="91.33333333333333"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-03-19
  12:54:54<o:p></o:p></span></p></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">6e0935d0e6c119b346c499f2d8ec171e<o:p></o:p></span></p></td></tr><tr><td width="142.33333333333331" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">……<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><br/></td><td valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" width="91.33333333333333"><br/></td><td width="179.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><br/></td></tr></tbody></table><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">表4 恶意诱饵文档</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">对于前面提到的第二类文件并不多，如表6所示。这是黑客攻击路径中的一类中间文件，一部分攻击将此类文件的链接附着在钓鱼邮件中，诱使目标点击；一部分通过漏洞利用文档从远程下载执行。这些文件实际上是一些包含多层混淆和编码的JavaScript脚本文件，JavaScript脚本文件中再嵌套混淆的VBScript和混淆的PowerShell命令，最后利用PowerShell命令从黑客服务器上下载被二进制混淆过的loader程序并执行。</span><span style="font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"><span lang="EN-US"><o:p></o:p></span></span></p><table cellspacing="0" cellpadding="0"><tbody><tr><td width="118.33333333333333" valign="top" style="border-width: 1pt;border-color: rgb(68, 114, 196);background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">文件名<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="74.33333333333333" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">文件类型<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="95.33333333333333" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">最早发现时间<span lang="EN-US">(UTC)<o:p></o:p></span></span></strong></p></td><td width="195.33333333333334" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span lang="EN-US" style="font-size:8.0pt;font-family:
  &#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">MD5<o:p></o:p></span></strong></p></td></tr><tr><td width="98.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">browserEdge.hta<o:p></o:p></span></p></td><td width="54.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">hta<o:p></o:p></span></p></td><td width="75.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-31
  08:19:15<o:p></o:p></span></p></td><td width="175.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">09a3afb87212a72facb6b2fae875425e<o:p></o:p></span></p></td></tr><tr><td width="118.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: white;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">gdfc.hta<o:p></o:p></span></p></td><td width="72.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: white;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">hta<o:p></o:p></span></p></td><td width="93.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: white;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-24
  11:31:32<o:p></o:p></span></p></td><td width="195.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: white;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">38a6a104600db0a1f4be52e6d456783a<o:p></o:p></span></p></td></tr><tr><td width="118.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">gmo.hta<o:p></o:p></span></p></td><td width="72.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">hta<o:p></o:p></span></p></td><td width="93.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-19
  01:47:30<o:p></o:p></span></p></td><td width="195.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">06538ec5e3bb8ed07933e829cace74ae<o:p></o:p></span></p></td></tr><tr><td width="118.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">IEnetCache.hta<o:p></o:p></span></p></td><td width="72.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">hta<o:p></o:p></span></p></td><td width="93.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-03
  15:42:59<o:p></o:p></span></p></td><td width="195.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">22fcf581f5b10ceda9fa0610e42c8d85<o:p></o:p></span></p></td></tr><tr><td width="118.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">gdfvr.hta<o:p></o:p></span></p></td><td width="72.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">hta<o:p></o:p></span></p></td><td width="93.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-01
  10:06:01<o:p></o:p></span></p></td><td width="195.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">a0cf81c7d9ee5987b418fa6bf46ce1ed<o:p></o:p></span></p></td></tr><tr><td width="118.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">gdfvr.hta<o:p></o:p></span></p></td><td width="72.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">hta<o:p></o:p></span></p></td><td width="93.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-25
  05:03:38<o:p></o:p></span></p></td><td width="195.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">5947bc33bbccaa5c37872e3e612c8719<o:p></o:p></span></p></td></tr><tr><td width="118.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">InetCache.hta<o:p></o:p></span></p></td><td width="72.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">hta<o:p></o:p></span></p></td><td width="93.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-18
  10:24:56<o:p></o:p></span></p></td><td width="195.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">5ff8d84e5a1c5839ffc6cbf174a3cc6a<o:p></o:p></span></p></td></tr></tbody></table><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">表5 恶意hta文件</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">恶意hta文件执行后，会从黑客服务器上下载被二进制混淆过的loader程序并执行，这些loader最终会解密并执行窃密木马remcosRAT。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">而这些loader正是我们上面提到的第三类样本文件,，如表7所示，这些恶意loader文件名大致可以分为两类：一类是伪装成如“csrss.exe”、“ wininit.exe”这类系统进程名称，以隐藏恶意行为为目的；一类是命名成“Quotation.exe”、 “RFQ.exe”这类名称以配合攻击邮件来诱使受害者运行。这些文件的编译时间最早为2024年4月16日（UTC），最新为2024年7月23日（UTC）。</span><span style="font-family:
&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"><span lang="EN-US"><o:p></o:p></span></span></p><table cellspacing="0" cellpadding="0"><tbody><tr><td width="81" valign="top" style="border-width: 1pt;border-color: rgb(68, 114, 196);background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">文件名</span></strong><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"><o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;color:white;">类型<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="94.33333333333333" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">最早发现时间（<span lang="EN-US">UTC</span>）</span></strong><strong><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;color:white;"><o:p></o:p></span></strong></p></td><td width="61.33333333333333" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;color:white;">编译时间（<span lang="EN-US">UTC</span>）<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="177.33333333333334" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span lang="EN-US" style="font-size:8.0pt;font-family:
  &#34;微软雅黑&#34;,&#34;sans-serif&#34;;color:white;">MD5<o:p></o:p></span></strong></p></td></tr><tr><td width="61.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">winiti.exe<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">csrss.exe<o:p></o:p></span></p></td><td width="30.333333333333332" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="74.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-24
  06:20:47<o:p></o:p></span></p></td><td width="61.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-23
  02:19:53<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="157.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">f6bf8ada032d17192526ffebb48aed79<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Quotation.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-24
  10:40:50<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-23
  02:19:53<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="157.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">3dc93db22f80681d7d49143038d8ff8a<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Quotation.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-23
  07:11:14<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-22
  11:39:08<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">df3a32a59e276774a045fd80fa2b53db<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">name.exe<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">csrss.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-17
  17:33:40<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-17
  11:03:44<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">350dbaf45daa47766afc3eaef7b38f86<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">csrss.exe<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">chrome.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-17
  05:47:59<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-17
  05:18:02<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2fa05aa214a3f718d4bac19aa282266e<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">csrss.exe<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">igccu.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-03
  15:45:44<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-02
  19:41:53<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">a2dcc2e9dd81e3a5f6440ed7027a86da<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><br/></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-03
  23:30:37<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-29
  08:17:25<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">a6811199672d0cae053f475a52b1c74c<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">csrss.exe<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">igccu.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-01
  07:33:24<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-27
  17:36:50<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">a273d142217177ab8013d6ebeafbc22f<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">csrss.exe<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">igccu.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-18
  08:35:13<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-14
  14:11:56<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">08475c0ab2386f3353d1c2f254a839c3<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">program.exe<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">csrss.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-12
  03:00:52<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-03
  21:36:23<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">8e89966ab41edae5077f3fec85407273<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Quotation.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-28
  06:14:09<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-27
  22:14:51<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">b408a3e79df21addbf0430a0d9737dd4<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><br/></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-06-04
  14:39:17<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-24
  14:14:53<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">95626a1bca4871e5d3fd14604d688c71<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Quotation.exe<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">file.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-27
  07:03:35<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-24
  14:14:53<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">9fdbdf0d36096938ce99cb83d35729ca<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Qotation.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-21
  09:07:53<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-21
  08:28:59<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">becda418348d1e2326d6e4e96f4d360e<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Quotation.pdf.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-14
  07:26:53<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-14
  06:18:33<o:p></o:p></span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">416a4e202f3164d4c9c37bd162aa66fb<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Shipping
  Document.P.df.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-13
  04:52:46<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-13
  03:40:13<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">43832ccc8ceca159daa9c54f73d0874c<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">RFQ.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-09
  11:36:50<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-09
  09:17:32<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">40f0b9dc3aa0c66a2eacd624e48b9b7e<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">RFQ.PDF.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-23
  14:12:28<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-23
  12:30:02<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">d97247a8713bbfa67764e6dfef1dc154<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">wininit.exe<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">cnn.exe<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-22
  07:59:12<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-22
  07:32:00<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">e5767608d3a2d83625b16c4666f14485<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">wininit.exe<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">cnn.exe</span><strong><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"><o:p></o:p></span></strong></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">exe<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-16
  04:54:54<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-16
  04:09:03<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"> </span></p></td><td width="157.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">ee0f619c36e219d029614aaaa9699200<o:p></o:p></span></p></td></tr><tr><td width="81" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">......<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">......<o:p></o:p></span></p></td><td width="94.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">......<o:p></o:p></span></p></td><td width="81.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">......<o:p></o:p></span></p></td><td width="177.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">......<o:p></o:p></span></p></td></tr></tbody></table><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">表6 恶意loader程序</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">通过该表我们还可以看出，有许多loader程序在编译好后就在很短时间里便投入使用了，和我们观察到的时间非常接近，有的最短间隔甚至不到半小时，这显然是通过自动化的木马即时编译即时投放平台实现的。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">第四类文件目前发现的也并不多，目前还无法明显看出其存在自动化实现的痕迹。黑客将混淆过的hta文件（或其链接）或loader伪装成正常文件并进行打包，然后作为邮件附件添加到鱼叉邮件中，再通过邮件话术诱使攻击目标解压执行。</span><span style="font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;"><span lang="EN-US"><o:p></o:p></span></span></p><table cellspacing="0" cellpadding="0"><tbody><tr><td width="122" valign="top" style="border-width: 1pt;border-color: rgb(68, 114, 196);background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">文件名<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="61.33333333333333" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">文件类型<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="89.33333333333333" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">最早发现时间<span lang="EN-US">(UTC)<o:p></o:p></span></span></strong></p></td><td width="210.33333333333334" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><strong><span lang="EN-US" style="font-size:8.0pt;font-family:
  &#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:宋体;color:white;">MD5<o:p></o:p></span></strong></p></td></tr><tr><td width="102.33333333333333" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Quotation.txz<o:p></o:p></span></p></td><td width="49.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">rar<o:p></o:p></span></p></td><td width="69.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-24
  10:40:29<o:p></o:p></span></p></td><td width="190.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">7cad5fe29e9c6ec840ffa59e1605797c<o:p></o:p></span></p></td></tr><tr><td width="122" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Quotation.txz.rar<o:p></o:p></span></p></td><td width="61.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">rar<o:p></o:p></span></p></td><td width="89.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-07-23
  07:24:36<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">9c48437f190dfb0958e0293000882802<o:p></o:p></span></p></td></tr><tr><td width="122" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Quotation.txz<o:p></o:p></span></p></td><td width="61.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">rar<o:p></o:p></span></p></td><td width="89.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-28
  06:12:48<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">4b4234292c8e0df9b9eb647583a3daa3<o:p></o:p></span></p></td></tr><tr><td width="122" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Quotation.txz<o:p></o:p></span></p></td><td width="61.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">rar<o:p></o:p></span></p></td><td width="89.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-27
  07:02:54<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">d5fb4332295a69e781290eef563a589a<o:p></o:p></span></p></td></tr><tr><td width="122" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Qotation.lzh<o:p></o:p></span></p></td><td width="61.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">rar<o:p></o:p></span></p></td><td width="89.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-21
  09:04:39<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2978a02292bf45b1cdab805d6a56c73f<o:p></o:p></span></p></td></tr><tr><td width="122" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Quotation.pdf.gz<o:p></o:p></span></p></td><td width="61.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">rar<o:p></o:p></span></p></td><td width="89.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-14
  07:26:33<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">5e73e0126999d8d4930015eb854c19e1<o:p></o:p></span></p></td></tr><tr><td width="122" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">Shipping
  Document.Pdf.gz<o:p></o:p></span></p></td><td width="61.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">rar<o:p></o:p></span></p></td><td width="89.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-13
  04:52:16<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">7f22877e37036b3685e1a05567ee501f<o:p></o:p></span></p></td></tr><tr><td width="122" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><br/></td><td width="61.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">rar<o:p></o:p></span></p></td><td width="89.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-05-09
  11:36:15<o:p></o:p></span></p></td><td width="190.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">0e390313084f6d356057ed21a43f2c85<o:p></o:p></span></p></td></tr><tr><td width="122" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">RFQ.PDF.lzh<o:p></o:p></span></p></td><td width="61.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">rar<o:p></o:p></span></p></td><td width="89.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">2024-04-23
  21:13:49<o:p></o:p></span></p></td><td width="210.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:8.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;">bfd11c09d12e016a72838e3368da964a<o:p></o:p></span></p></td></tr></tbody></table><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">表7 作为邮件附件的压缩文件</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">因此，结合上文的分析来看，黑客似乎具有完整的自动化攻击平台，其具有非常强的自动化能力，这些能力包括自动化的邮箱申请、域名注册、诱饵文档生成、木马loader即时编译、木马投放等。</span></p><h2 style="margin-bottom: 8px;text-indent: 0em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></h2><p style="font-size:16px;color:#0080FF;margin-bottom:unset;letter-spacing:0px;"><span style="color: rgb(120, 172, 254);"><em><strong>04</strong></em></span></p><p style="font-size:16px;letter-spacing:2px;color:#0080FF;line-height:1;"><span style="color: rgb(120, 172, 254);"><strong>攻击案例分析</strong></span></p><p><img data-imgfileid="502135916" data-ratio="0.9772727272727273" style="width:100%;display:block;vertical-align:bottom;" data-w="44" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=19e2db04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjtGuuzaSlftg58JibibSX2PbTIjDsURueNwNryPfGw723DEtv2hNPibNdjKMQgB1MGhth5pjiayic7rLQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">我们以该黑客团伙针对我国某外运公司的一次邮件攻击为例进行说明。如图7所示，在此次攻击中，攻击者先在自己的恶意服务器“192.3.118.15”和“107.173.143.46”上分别配置和部署好恶意文件“gdfc.hta”和“csrss.exe”，之后，攻击者向我国某外运公司的工作人员投递带有恶意附件“Quotation.xls”（报价.xls）的邮件，该xls文档是携带有漏洞“CVE-2017-0199”利用代码的恶意漏洞利用文件，漏洞利用代码一旦执行，会加载执行事先部署的恶意文件“http://192.3.118.15/xampp/mnu/gdfc.hta”， 恶意gdfc.hta包含的恶意脚本会请求并执行恶意文件“http://107.173.143.46/T2307W/csrss.exe”。csrss.exe为商业木马remcosRAT的loader， 其执行后，会解密其中的商业远控木马remcosRAT 到受害者的设备执行。通过上述过程，攻击者最终成功向攻击目标投放了remcosRAT远控木马。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135917" data-ratio="0.42592592592592593" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b0cf867e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiapa2ibEwFcpXPCicSSxiahkpEZPMicibOXEjPGUsv3MhMs0OIKYuwBAK3Fmg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p style="text-indent: 0em;text-align: center;margin-bottom: 16px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图7 攻击流程图</span><o:p></o:p></p><h3 style="text-indent: 0em;margin-bottom: 16px;"><strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;color: rgb(120, 172, 254);">4.1 诱饵邮件投递</span></strong><o:p></o:p></h3><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">此次攻击始于一封试图伪装成印度高档面料制造商“Raymond”相关工作人员的报价请求邮件（见图8），此邮件是发送给我国某外运公司的工作人员的。邮件主题是“RFQ（报价请求）”，附件诱饵文档名称为“Quotation.xls（报价.xls）”，正文翻译成中文是 “请查收附件所需项目的报价单，并以报价单确认，请确认收据”。从邮件的主题和正文内容来看，攻击者是想伪装成印度高档面料制造商“Raymond”对我国某外运公司实施邮件攻击。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135918" data-ratio="0.4898148148148148" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1572adad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaLic7jiccLAuLqJ4WD8vt6wSiaIbpXxNicsGmhJfG8FzNb42jU8ox2psgFg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图8 攻击者投放的攻击邮件</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">附件文档“Quotation.xls”（见图9）是一个“CVE-2017-0199”漏洞利用的恶意文档，如果受害者设备上的Office未及时更新，而受害者又由于疏忽打开了该文档，漏洞利用代码便会执行。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135919" data-ratio="0.6129629629629629" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=964409a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiavKUk9ibSibKbYKuFU91ZWNgmFfn0SQtc9UZLibEWBORhuWXOtGwwfkfFg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图9 诱饵xls文档</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">漏洞利用代码会加载和执行攻击者部署的恶意hta文件：“http://192.3.118.15/xampp/mnu/gdfc.hta”， gdfc.hta文件的内容如图10所示，该文件只包含一个混淆处理过的Javascript脚本。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135920" data-ratio="0.5052430886558628" data-s="300,640" style="" data-type="png" data-w="1049" src="https://wechat2rss.xlab.app/img-proxy/?k=59047f0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpia6F2UQbiaGKHCq6oSbQXNyVuZ2zJuLgHicvSNzicsRcWNkVvtwGl3HDvjA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图10 gdfc.hta文件部分内容</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">这段 JavaScript 脚本使用了 unescape() 函数来解码一个经过编码的字符串‘%3C%73%63%72%69%70%74%20%6C%61%6E%67%75%61%67%65%3D%4A%61%76%61%53%63%72%69%70%74%...... 69%74%65%28%64%29%3B%3C%2F%73%63%72%69%70%74%3E’，并通过 document.write()方法将解码后的内容输出到页面上。这段经过编码的字符串解码后见图11，我们来看这段代码都干了些什么：m 变量包含了完整的 HTML 和嵌入的 恶意VBScript 代码（这部分代码使用了 JavaScript）；unescape(m) 函数用于解码 m 中的转义字符，将其还原为原始文本；document.write(d)将解码后的 HTML 和恶意 VBScript 代码写入到文档中，这一步相当于动态加载恶意代码到用户的浏览器环境中。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135921" data-ratio="0.25277777777777777" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4fc154ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaiaJUJ388a4JibtmFVytMEfaiaM88CSYUbUpgwgUtMMFzj1VLGqdbE5wwQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图11 解码后的代码结构</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">恶意VBScript 代码如图12所示，我们看到这段代码混淆了变量名和命令并使用了超长变量名“FZmVzmbnJlDsrDPejjREhoSUpLccYGThfiITYHmlYTerSIATfMkpyNZNbIRRjmhWgbmEymiqenIvsgxmwrNLYaeXZijiaptaxmbXnjqXRcpyedgHXEBNUiJUXUhXLWgRSybTIFmCYTdxsJdzwjCoDvqZLzLfGqVOgsqmVJ”和“BMheopsbVrJXHOKkrGKTzUVwCTPAsCMcYpVBKRxInxQgxxxJNQGzAmHManmtkLfnoAWzQzvWZLNeeRnjqUjxMjVNGzutUDKfYPYGIjBZFBqBFTwUBnhvlFXGUZbhzaOLDDQDpQeYIpmdbxmXWpqbaweBsgWtZWGnHmnaLp”。这样操作既躲避了一些安全软件的检测又增加了分析人员的阅读难度，可以说是“一举两得”。这段代码的目的是执行一个PowerShell命令（绿色部分）。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135922" data-ratio="0.38425925925925924" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ba7c6fa0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiag66Qf1ndlF4TjLhgvSwUhprxu1B6WHoeWH2QQa2fkNPrnl9wKWJtFQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图12 恶意VBScript代码</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"> PowerShell要执行的命令解码后如图13所示，这段代码使用一种“AT”技术来躲避杀毒软件的行为查杀。其利用 Add-Type cmdlet 添加了一个新的 .NET 类型。这个类型包含一个从 urlmon.dll 动态链接库中导入的 URLDownloadToFile 函数；然后调用 URLDownloadToFile函数，从地址http://107.173.143.46/T2307W/csrss.exe 下载文件到本地路径 $ENV:APPDATA\winiti.exe；接着让脚本暂停 3 秒钟，确保文件下载完成；最后</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">执行下载的可执行文件。我们可以看到，这段代码的主要功能是从指定的 URL 下载恶意可执行文件，并在下载完成后运行它。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135923" data-ratio="0.3106682297772567" data-s="300,640" style="" data-type="png" data-w="853" src="https://wechat2rss.xlab.app/img-proxy/?k=69555221&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiawOicWD5xAX1q9aOY77k5QBIPZcSUia0TQ61ZiceuYOibC1hjFq5FF8OtUg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p style="text-indent: 0em;text-align: center;margin-bottom: 16px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图13 PowerShell要执行的命令</span><o:p></o:p></p><h3 style="text-indent: 0em;margin-bottom: 16px;"><strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;color: rgb(120, 172, 254);">4.2 恶意程序分析</span></strong><o:p></o:p></h3><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">通过前面下载并执行的恶意程序为“http://107.173.143.46/T2307W/csrss.exe”， 经过分析，我们发现csrss.exe是一个恶意loader，由于该恶意loader经过了严重的混淆，并且很多函数使用了动态加载技术，因此仅通过静态分析我们很难知道它的关键执行逻辑。结合动态分析，我们发现，该loader在执行后会在内存中解密出商业木马remcosRAT，然后新起一个傀儡进程如“msbuild.exe”，接着使用进程镂空技术将remcosRAT木马注入到新起的傀儡进程空间中执行。进程镂空技术常被恶意软件用于注入恶意代码，以逃避杀毒软件的监测和防御机制，并在目标系统上执行恶意活动。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">loader会在目标计算机上Microsoft.NET Framework的安装目录下选择一个合法的.NET相关程序如“msbuild.exe”、“ regsvcs.exe”、“ jsc.exe”和“installutil.exe”等作为目标来创建傀儡进程。如图14所示，恶意loader首先使用CreateProcessW函数创建C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\msbuild.exe进程，需要注意的是，这个进程的主线程被设置为挂起状态，在后续注入完成恶意代码后，loader会调用ResumeThread函数来恢复目标线程的执行。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135925" data-ratio="0.21574074074074073" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ce3551de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaLkPkYYOMxJLmg3Qk4NoxVDYdlJ0pR1bQjNMasUWbib9qQ9C1xBsXTVA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图14 创建目标进程</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">创建完傀儡进程后，loader通过调用ZwUnmapViewOfSection函数来取消傀儡进程中的内存映射，如图15所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135926" data-ratio="0.24074074074074073" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=382b255f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaY1xChlOQcq8uN7fe9yhURuZG4ZBibhbCeAkpFKnibV6bnXynnVYGmMSQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图15 取消目标进程中的内存映射</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">接着，loader调用VirtualAllocEx函数来为傀儡进程分配内存（如图16），为的是将后续的恶意代码写入到傀儡进程的地址空间。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135927" data-ratio="0.26851851851851855" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=926e895e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiadh2pdOqUxlFvavBzI2tQkLEaZ2zsYvV0UOPX7ab2EsoWQEXgic10YlA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图16 为傀儡进程分配内存</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">分配完内存后，loader再调用NtWriteVirtualMemory函数将remcosRAT的PE头注入到傀儡进程地址空间，如图17所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135928" data-ratio="0.48518518518518516" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fca900a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpia5O3EMTiboIbwATumtQNQ2aewdh5pk2oPmY9qOUMvHIID2gXnpWzJVIw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图17 注入remcosRAT的PE头</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">注入PE头后，如图18所示，loader继续将remcosRAT 的“.text”section注入到傀儡进程空间。接着，loader会以同样的方式依次注入remcosRAT的“.rdata”、“ .data”、“.tls”、“ .gfids”、“ .rsrc”和“.reloc”section。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135929" data-ratio="0.47314814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1d1ed80e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpia5jK1BeicPjRvI8aDcnSreJYtg1mvcu6SD9HwVbtPJIWVssyxpjuBcMA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图18 注入remcosRAT 的“.text”section</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">如图19所示，在整个remcosRAT恶意代码注入完成后，loader则调用ResumeThread函数恢复目标傀儡进程的主线程，这样，remcosRAT木马就在目标傀儡进程中执行了。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135930" data-ratio="0.1685185185185185" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b262ba22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaHiaQAkvlIXp9XsZyJCqZNaporUB22JC3Bg8qsibibGJLoiaLu733rlzf3w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 16px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图19 恢复傀儡线程</span><o:p></o:p></p><h3 style="text-indent: 0em;margin-bottom: 16px;"><span style="color: rgb(120, 172, 254);"><strong><span style="color: rgb(120, 172, 254);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">4.3 remcosRAT木马</span></strong></span><o:p></o:p></h3><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">通过前面的分析，我们知道，恶意loader通过内存解密和进程镂空技术，最终在感染设备上执行了商业远控木马Remcos
RAT，其版本号为“5.1.0 Pro”（如图20所示）。自2016年在暗网上的地下黑客社区开始出售以来，Remcos RAT非常活跃，基本上每个月都会发布两个左右的新版本。该工具由一家名为Breaking Security的公司发行出售，其具有键盘记录、屏幕记录、调用摄像头和麦克风进行录像录音、远程执行Shell命令、远程执行脚本、上传文件以及下载文件，文件管理、进程管理、注册表操作和安装卸载远控等功能，只要Remcos RAT被成功植入到目标设备，其背后的黑客便可完全控制目标设备，对其进行监控、数据窃取甚至是更进一步的破坏活动。我们此前在报告</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649615525&amp;idx=1&amp;sn=972046bb870e2c9b4a59aa17b63e3661&amp;chksm=830631b5b471b8a3748144ca3a0c3d89f878ff6bdb84f4edcd201d650f10ea76bccc21f89ac1&amp;scene=21#wechat_redirect" textvalue="《【深度】ADLab针对新型黑客组织“海毒蛇”深度追踪与分析》" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">《</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">【深度】ADLab针对新型黑客组织“海毒蛇”深度追踪与分析</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">》</span></a><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">和</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619252&amp;idx=1&amp;sn=271b4383d46172c9f85d7c3f321c8c98&amp;chksm=83062624b471af32c0d9071cc7b11463ef25703f36e126f99414d7f8bfebcfc79fdafdeb41ee&amp;scene=21#wechat_redirect" textvalue="《关于近期俄乌网络攻击活动追踪分析报告》" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">《</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">关于近期俄乌网络攻击活动追踪分析报告</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">》</span></a><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">中曾对其进行过详细的技术分析，在此不做过多赘述，下面仅对其配置文件部分进行简要说明。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135931" data-ratio="0.4888888888888889" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=395e9b51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiakJD3MxmmCrV1yXMSQBXG1NiaIPOs2MLRusufydrQswiaaAPjYv00HiaIw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图20 最终执行的商业远控木马remcosRAT</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">如图21所示，Remcos RAT运行后会从自身资源中解密出配置信息，里面包括C&amp;C服务器地址“bossnacarpet.com:2556，vegetachcnc.com:2556”、互斥对象名“chrome-6W1HCC”、键盘记录文件名“logs.dat”、Licence
ID“C90245FEC67A6F41723337BDF4A60126”以及和截图、录音等操作相关的其他信息。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135932" data-ratio="0.7528735632183908" data-s="300,640" style="" data-type="png" data-w="522" src="https://wechat2rss.xlab.app/img-proxy/?k=39b89a11&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaO3pEPVbnR71BibGpUydHFPG7ynvzCyQt7mz7WXQiaxoAgF5iaqC3krmSg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图21 解密出来的配置信息</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">相较于旧版本，Remcos从 v5.0.0版本开始增加了移动端的控制支持，图22是Remcos官网下相关的更新介绍，由介绍可知，Remcos v5.0.0版本允许黑客通过Telegram机器人与木马端交互，因此黑客可以通过智能手机、平板电脑和浏览器完成对目标主机的控制。同时Remcos Telegram机器人支持以实时通知的方式让黑客及时了解目标设备运行情况。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135933" data-ratio="0.4861111111111111" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7fd146a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiar7IDyR1PgFhTzhVjejckfBee7GdiaVAsmE16hYiauoEpw3ErRjQtQKTQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图22 Remcos新功能</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图23是Remcos Telegram机器人支持的控制命令列表，黑客可以通过其完成对目标主机的各项控制，如屏幕记录、调用摄像头录像、远程执行Shell命令、远程执行脚本、下载和文件，浏览器操作等。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135934" data-ratio="1.0462962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1e7e11be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT1APcKR153gkiceiany61rpiaGdH4mBezGTAGxU9cwssy4cUnQF3UIELAJDxIcfzBIVZt2h4sicDvKBw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">图23 Remcos Telegram机器人控制命令</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">虽然Remcos Telegram机器人支持的控制命令目前没有原始的 C2控制端多，但是借助于Telegram的跨平台支持，黑客可以使用手机、平板电脑等移动设备随时随地进行木马控制，极大拓展了黑客的攻击场景。借助于Telegram的实时通知，黑客可以实时接收受感染设备的状态更新和通知，便于其及时采取下一步行动。另外，由于 Telegram 在国外是常见的通信工具，使用它进行控制可以规避一些安全软件和网络监控的检测。这些优势使得 Remcos RAT 在 5.0.0 版本后变得更加强大和灵活，进一步提升了其在恶意活动中的应用价值。黑客购买新版Remcos进行攻击，可以根据他们自己的具体需求选择合适的控制方式。而针对新版Remcos的这些特性，安全人员和厂商需要不断提升检测和响应能力，采用多层次的防御策略，并保持对最新威胁情报的持续关注。</span><o:p></o:p></p><h2 style="margin-bottom: 8px;text-indent: 0em;"><br/></h2><p style="margin-bottom: unset;font-size: 16px;color: rgb(0, 128, 255);letter-spacing: 0px;"><span style="color: rgb(120, 172, 254);"><em><strong>05</strong></em></span></p><p style="font-size: 16px;letter-spacing: 2px;color: rgb(0, 128, 255);line-height: 1;"><span style="color: rgb(120, 172, 254);"><strong>总 结</strong></span></p><p><img class="rich_pages wxw-img" data-imgfileid="502135924" data-ratio="0.9772727272727273" style="width: 15px;display: block;vertical-align: bottom;" data-w="44" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=19e2db04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjtGuuzaSlftg58JibibSX2PbTIjDsURueNwNryPfGw723DEtv2hNPibNdjKMQgB1MGhth5pjiayic7rLQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><br/></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">我们就近几个月观测到的一系列利用托管在多个黑客服务器公开路径上的大量恶意文件进行的网络攻击活动进行了分析，我们对这些攻击活动使用的基础设施、攻击武器、活动历史和攻击手法等信息进行了全面的分析，并且我们对最近出现的一次针对我国某外运公司的攻击进行了详细的逆向分析。从这些攻击活动的攻击目标和攻击手法来看，其背后的攻击者很大概率上是一个以经济利益为目标的犯罪团伙。几个月来，他们一方面对于重点目标定制恶意文件进行定向攻击，一方面大批量自动化生成邮件、漏洞利用文件和loader进行广撒网式的攻击，随后窃取目标公司的商业机密、重要工业技术信息等敏感信息，以实现其经济利益，也不排除该犯罪团伙以这些攻击目标为跳板，进一步向相关企业的上下游公司、合作伙伴、政府高校等机构进行攻击，以获取更多的“攻击成果”。这些攻击不仅会对相关企业的运营和声誉造成严重影响，还可能导致工业配方、客户资料等核心涉密数据泄露，后果不堪设想。</span><o:p></o:p></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">截至目前，该犯罪团伙的攻击活动仍然活跃，仍将有不少公司会成为其新的猎物，我们会持续关注和跟进该黑客团伙的相关攻击活动。</span></p><p><br/></p><p><br/></p><p><br/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.8;color: rgb(0, 0, 0);font-size: 15px;">启明星辰积极防御实验室（ADLab）</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: var(--articleFontsize);letter-spacing: 0.544px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">“黑雀攻击”概</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/CVE累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、数据安全研究、5G安全研究、人工智能安全研究、移动安全研究、物联网安全研究、车联网安全研究、工控安全研究、信创安全研究、云安全研究、无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等<span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 1.5px;">。</span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-align: start;text-indent: 24px;"><img class="rich_pages wxw-img" data-imgfileid="502135935" data-ratio="1.1205673758865249" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.969px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ee3d683d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAwNTI1NDI3MQ%3D%3D%26mid%3D2649619588%26idx%3D1%26sn%3D179fcb6618f08dc7a5c93bfe4b6c5ae5%26chksm%3D83062194b471a8829debf48fc09a9e93bcb5cf3c7dfad5ff58bd163cb2a3c8874a9c66e44bac%26scene%3D58%26subscene%3D0%23rd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 30 Aug 2024 18:20:14 +0800</pubDate>
    </item>
    <item>
      <title>VMware ESXi CVE-2024-37085漏洞验证分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619550&amp;idx=1&amp;sn=a751128726875a90e9107764b6a4f4f3&amp;chksm=8306214eb471a8587a8054c43873cb1e5814242a375db72abc83c7e76aa3595bc3c594e0a52c&amp;scene=58&amp;subscene=0#rd</link>
      <description>近日，微软披露了一个ESXi漏洞（CVE-2024-37085）的在野攻击报告。该漏洞是VMware ESXi的一个认证绕过漏洞，已被多个勒索软件利用。通过该漏洞，攻击者可获取加入AD域的ESXi的完全操作权限，控制该ESXi中包含的虚拟机</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-08-08 17:38</span> <span style="display: inline-block;">北京</span>
</p>

<p>近日，微软披露了一个ESXi漏洞（CVE-2024-37085）的在野攻击报告。该漏洞是VMware ESXi的一个认证绕过漏洞，已被多个勒索软件利用。通过该漏洞，攻击者可获取加入AD域的ESXi的完全操作权限，控制该ESXi中包含的虚拟机</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=0cd7c05f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmQT32n6Jc7u5wv4gtcnCnStykWqRGicXM4Ldhn0wicrKHPqG4icqbcjYYw%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><span style="outline: 0px;text-align: center;color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;visibility: visible;"></span><br style="outline: 0px;visibility: visible;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><br/></p><p style="font-size: 16px;color: rgb(99, 151, 221);line-height: 35px;"><strong data-form="0" data-num="1">01</strong></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>漏洞概述</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135856" data-ratio="1.5757575757575757" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=041a56c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjSlib8KpiaZKibkhzWNSZ2PLmicwQwsQMjBDgBOzpu5PtibGuqWpsTkcOSlcqicsPdvpC3cUFwk6KZZWxw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135857" data-ratio="0.5882352941176471" style="vertical-align:bottom;" data-type="gif" data-w="170" src="https://wechat2rss.xlab.app/img-proxy/?k=99a1dc1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjSlib8KpiaZKibkhzWNSZ2PLmBfKicU8B0EX4bnUZ18Zd1N0fGnptPjI0MbHWXJIXtva3emVk1OpOLxA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">近日，微软披露了一个ESXi漏洞（编号为CVE-2024-37085）的在野攻击报告[1]。该漏洞是VMware ESXi的一个认证绕过漏洞，已被多个勒索软件所利用。通过该漏洞，攻击者可获取加入AD域的ESXi的完全操作权限，控制该ESXi中包含的虚拟机等。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">漏洞的NVD描述为[2]：VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group (&#39;ESXi Admins&#39; by default) after it was deleted from AD。</span><o:p></o:p></p><h2 style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></h2><p style="font-size: 16px;color: rgb(99, 151, 221);line-height: 35px;"><strong data-form="0" data-num="1">02</strong></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>漏洞影响版本</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135859" data-ratio="1.5757575757575757" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=041a56c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjSlib8KpiaZKibkhzWNSZ2PLmicwQwsQMjBDgBOzpu5PtibGuqWpsTkcOSlcqicsPdvpC3cUFwk6KZZWxw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135858" data-ratio="0.5882352941176471" style="vertical-align:bottom;" data-type="gif" data-w="170" src="https://wechat2rss.xlab.app/img-proxy/?k=99a1dc1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjSlib8KpiaZKibkhzWNSZ2PLmBfKicU8B0EX4bnUZ18Zd1N0fGnptPjI0MbHWXJIXtva3emVk1OpOLxA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><h2 style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></h2><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">官方发布的ESXi影响版本：</span><o:p></o:p></p><table cellspacing="0" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tbody style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td valign="center" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;" width="162.33333333333334"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">VMware Product</span></strong><o:p></o:p></p></td><td valign="center" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;" width="147.33333333333331"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">Version</span></strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;"></span><o:p></o:p></p></td><td valign="center" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;" width="173.33333333333334"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">Running On</span></strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;"></span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td valign="center" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;" width="162.33333333333334"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi </span><o:p></o:p></p></td><td valign="center" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;" width="127.33333333333333"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">8.0</span><o:p></o:p></p></td><td valign="center" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;" width="153.33333333333334"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">Any</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td valign="center" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;" width="125.00000000000007"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi </span><o:p></o:p></p></td><td valign="center" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;" width="147.33333333333331"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">7.0</span><o:p></o:p></p></td><td valign="center" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;" width="173.33333333333334"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">Any</span><o:p></o:p></p></td></tr></tbody></table><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;background-color: rgb(255, 255, 255);">经过启明星辰</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;background-color: rgb(255, 255, 255);">ADLab的</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;background-color: rgb(255, 255, 255);">测试和验证，发现低版本的ESXi同样受影响。</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-align: center;text-indent: 28px;white-space-collapse: preserve;background-color: rgb(255, 255, 255);">实测的ESXi影响版本：</span></p><table cellspacing="0" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tbody style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="249.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">VMware Product</span></strong><o:p></o:p></p></td><td width="234.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">漏洞存在性</span></strong><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="229.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 8.0</span><o:p></o:p></p></td><td width="214.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">存在</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="249.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 7.0</span><o:p></o:p></p></td><td width="234.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">存在</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="249.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 6.7</span><o:p></o:p></p></td><td width="234.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">存在</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="249.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 5.5</span><o:p></o:p></p></td><td width="234.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">存在</span><o:p></o:p></p></td></tr></tbody></table><p><br/></p><p style="font-size: 16px;color: rgb(99, 151, 221);line-height: 35px;"><strong data-form="0" data-num="1">03</strong></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>漏洞机制</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135860" data-ratio="1.5757575757575757" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=041a56c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjSlib8KpiaZKibkhzWNSZ2PLmicwQwsQMjBDgBOzpu5PtibGuqWpsTkcOSlcqicsPdvpC3cUFwk6KZZWxw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135861" data-ratio="0.5882352941176471" style="vertical-align:bottom;" data-type="gif" data-w="170" src="https://wechat2rss.xlab.app/img-proxy/?k=99a1dc1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjSlib8KpiaZKibkhzWNSZ2PLmBfKicU8B0EX4bnUZ18Zd1N0fGnptPjI0MbHWXJIXtva3emVk1OpOLxA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">根据官方文档的描述[3]，为了方便管理大量ESXi主机，VMware ESXi支持通过Active Directory (AD)来管理账号权限。其中，对于加入AD域的ESXi主机，默认设置了AD域ESX Admins用户组具有ESXi主机的管理员权限。因此，攻击者如果在AD域中能创建ESX Admins组或更改现有组为ESX Admin，就能具备对加入该域的ESXi主机的完全控制。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">微软研究人员披露了此漏洞的三种利用方式：</span><o:p></o:p></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">创建并添加用户：创建“ESX Admins”组，添加用户，进而获得完全管理权限。</span><o:p></o:p></p></li><li><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">重命名组并添加用户：重命名现有组为“ESX Admins”，添加用户或使用现有成员，进而获得完全管理权限。</span><o:p></o:p></p></li><li><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">权限刷新：在网络管理员把权限转移给AD域的其它组后，ESX Admins组的管理权限不会立即消失，仍可被利用。</span><o:p></o:p></p></li></ul><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">ADLab研究员对三种利用方法进行了复现验证。</span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p style="font-size: 16px;color: rgb(99, 151, 221);line-height: 35px;"><strong data-form="0" data-num="1">04</strong></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>漏洞验证<br/></strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135863" data-ratio="1.5757575757575757" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=041a56c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjSlib8KpiaZKibkhzWNSZ2PLmicwQwsQMjBDgBOzpu5PtibGuqWpsTkcOSlcqicsPdvpC3cUFwk6KZZWxw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135862" data-ratio="0.5882352941176471" style="vertical-align:bottom;" data-type="gif" data-w="170" src="https://wechat2rss.xlab.app/img-proxy/?k=99a1dc1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjSlib8KpiaZKibkhzWNSZ2PLmBfKicU8B0EX4bnUZ18Zd1N0fGnptPjI0MbHWXJIXtva3emVk1OpOLxA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">本节的漏洞验证以ESXi6.7为例，域控在Server2012服务器中，ESXi6.7加入了该域控。</span><o:p></o:p></p><p><strong><span style="outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;color: rgb(0, 82, 255);">4.1 方法一验证</span></strong><o:p></o:p></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">（1）在ESXi 6.7加入域控后，域控默认是没有ESX Admins组的，如下图所示。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135867" data-ratio="0.8574074074074074" data-s="300,640" style="" data-type="png" data-w="540" src="https://wechat2rss.xlab.app/img-proxy/?k=71cca3d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQTEEnvIlBzrZAM5ucuFiaret27ffcTpawbGVONFO30Cqx8PeodfL6dAibuicaIpxPAtrWQyEqXribEGw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-indent: 28px;white-space-collapse: preserve;background-color: rgb(255, 255, 255);"> </span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">（2）使用test账户登录ESXi（该账号目前还不在”ESX Admins”组内）。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135870" data-ratio="0.47058823529411764" data-s="300,640" style="" data-type="png" data-w="493" src="https://wechat2rss.xlab.app/img-proxy/?k=16969e7c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQTEEnvIlBzrZAM5ucuFiareLahuqH4ibIp9TEL2pTQCWYxdFZG6BTMCAJnvaoUiauAZrCuIC5RWywRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-indent: 28px;white-space-collapse: preserve;"> </span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">登录失败，提示操作权限被拒绝：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135869" data-ratio="0.25501432664756446" data-s="300,640" style="" data-type="png" data-w="698" src="https://wechat2rss.xlab.app/img-proxy/?k=ef1a501b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQTEEnvIlBzrZAM5ucuFiaree2Z6aLblVDkapnQDCeH6cJUJYSbo1bSFPMcQZb4IyeFlvyeric6fdqw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">（3）使用net group命令，创建1个名为ESX Admins的用户组。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135871" data-ratio="0.0896551724137931" data-s="300,640" style="" data-type="png" data-w="725" src="https://wechat2rss.xlab.app/img-proxy/?k=135c01ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQTEEnvIlBzrZAM5ucuFiareLzsia3DMyia9MSRF1H0aiboQNXMvkG5I5pZ8CbIEHTaOxelicd4Cp8BUUw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135872" data-ratio="0.178714859437751" data-s="300,640" style="" data-type="png" data-w="498" src="https://wechat2rss.xlab.app/img-proxy/?k=b5c049f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQTEEnvIlBzrZAM5ucuFiarenymn56tibicj5yTY4zO2TPazx4JYko3Ujv36VnSGKqCI3wbRMKYft1IQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">使用net group命令，将test用户加入ESX Admins组：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135873" data-ratio="0.10734463276836158" data-s="300,640" style="" data-type="png" data-w="708" src="https://wechat2rss.xlab.app/img-proxy/?k=8453ac07&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQTEEnvIlBzrZAM5ucuFiareFX8YnY3aj4wM10jrdR8ovasu7mCdNXzibqrTT8bNibMRat2SvUR0o6lg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135879" data-ratio="0.48963317384370014" data-s="300,640" style="" data-type="png" data-w="627" src="https://wechat2rss.xlab.app/img-proxy/?k=b4cb6e46&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQTEEnvIlBzrZAM5ucuFiaresBiaCVoZJeUKuaZNaRVkwWutbtwYm97mbf4hCLT2Xxs4fnib4ibFiaYFkw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">使用test用户登录，能够登录成功且能执行高权限操作：</span><o:p></o:p></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135877" data-ratio="0.3123359580052493" data-s="300,640" style="height: 180px;letter-spacing: 0.578px;text-align: center;text-wrap: wrap;width: 578px;" data-type="png" data-w="762" src="https://wechat2rss.xlab.app/img-proxy/?k=10b59e39&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQTEEnvIlBzrZAM5ucuFiareIDEMFfP6onETnALkRTeXckA33PnU85BufrWLgbEzl3t6aX5XfMHX8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135878" data-ratio="0.5125925925925926" data-s="300,640" style="text-indent: 28px;letter-spacing: 0.578px;" data-type="png" data-w="675" src="https://wechat2rss.xlab.app/img-proxy/?k=8cb72169&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQTEEnvIlBzrZAM5ucuFiarelNicLYt51dDt5VmUw9iaugXKHSibcOgEtTUCTfW2lqNL9Ku3zU4iblHvwA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">经测试，该方法在其它ESXi版本上也能成功，具体测试版本有：</span><o:p></o:p></p><table cellspacing="0" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tbody style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="247" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">VMware Product</span></strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;"></span><o:p></o:p></p></td><td width="236.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">方法可利用</span></strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;"></span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="227.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 8.0</span><o:p></o:p></p></td><td width="216.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="247" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 7.0</span><o:p></o:p></p></td><td width="236.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="247" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 6.7</span><o:p></o:p></p></td><td width="236.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="247" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 5.5</span><o:p></o:p></p></td><td width="236.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr></tbody></table><p><span style="outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;color: rgb(0, 82, 255);"><strong>4.2 方法二验证</strong></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">（1）在ESXi 6.7加入域控后，域控默认是没有ESX Admins组。</span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">（2）首先，创建1个名为g1的组，把test用户加到g1组，使用test登录ESXi。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135880" data-ratio="0.7293497363796133" data-s="300,640" style="" data-type="png" data-w="569" src="https://wechat2rss.xlab.app/img-proxy/?k=46d18732&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmHMGoCjOMnvgKzAloRZr1aYBQPEd5LiaU1nCxGkaXJVPImU4fQCibr5zw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135881" data-ratio="0.4238178633975482" data-s="300,640" style="" data-type="png" data-w="571" src="https://wechat2rss.xlab.app/img-proxy/?k=d59470f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmRMfubA8BbMcR6hkPJHS1WIIeqFjbfb8sFTCpH2qK1gjXtQzYdzvP7Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;orphans: 4;text-indent: 28px;white-space-collapse: preserve;background-color: rgb(255, 255, 255);"> </span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">登录失败，提示操作权限被拒绝。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135882" data-ratio="0.23578363384188628" data-s="300,640" style="" data-type="png" data-w="721" src="https://wechat2rss.xlab.app/img-proxy/?k=516ffdac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmZ5RQeic5sTgL4zSUdibU08q6iawBK086TDN3nKxjCJkzqypY9os7iadMwA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">（3）然后，修改g1的名称为ESX Admins。</span><span style="text-align: center;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135884" data-ratio="0.9391727493917275" data-s="300,640" style="" data-type="png" data-w="411" src="https://wechat2rss.xlab.app/img-proxy/?k=170bf214&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmVwAwEc1OIOWmfR88V3mIVG0IEaasMTTKmCmd4tOgjoD6pgLbVWLelA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">（4）最后，利用test用户登录ESXi。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">登录成功，查看权限为管理员。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135885" data-ratio="0.2815884476534296" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=d5419bef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmMiaWJrQ5C7HDaecZkeiclc2eMNtjJlX01M9iaPpI6c7dJicKGo7mEWhGUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">经测试，该方法在其它ESXi版本上也能成功，具体测试版本有：</span><o:p></o:p></p><table cellspacing="0" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tbody style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="234" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">VMware Product</span></strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;"></span><o:p></o:p></p></td><td width="249.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">方法可利用</span></strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;"></span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="234" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 8.0</span><o:p></o:p></p></td><td width="249.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="214.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 7.0</span><o:p></o:p></p></td><td width="229.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="214.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 6.7</span><o:p></o:p></p></td><td width="249.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="234" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 5.5</span><o:p></o:p></p></td><td width="229.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr></tbody></table><p><span style="outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;color: rgb(0, 82, 255);"><strong>4.3 方法三验证</strong></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">（1）在ESXi 6.7加入域控后，创建ESX Admins组和g1组，test和test2分别加入2个组。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135886" data-ratio="0.15821501014198783" data-s="300,640" style="" data-type="png" data-w="493" src="https://wechat2rss.xlab.app/img-proxy/?k=414ba9d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmdMbVWskWypslBLWa70eBBLePQiaU4LsM9Sh8Sia1gcVPicMiauzd6iaZqIQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135887" data-ratio="0.394" data-s="300,640" style="" data-type="png" data-w="500" src="https://wechat2rss.xlab.app/img-proxy/?k=dbccfd03&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmewbkZic7BAx3B3iaiaBBiap8Io1DvZ1dRXsDd6wehY2NaibfjjibEn2T6xKg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135888" data-ratio="0.40208333333333335" data-s="300,640" style="" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=da75320f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmfzNQEUM18nX50Qzr9daa4bnBYFUibMRQIwuTic5vCicA0aOYCajzBvEfg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">（2）登录ESXi尝试。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">用户test属于ESX Admins组，能够成功登录。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135889" data-ratio="0.22984356197352587" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=c6afc9ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmeBRNGmQsj2nib22yUZhv7C2V5dxvbHQ1vsAm9oXO109NPyz6or9ZmLA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">用户test2属于g1组，登录失败，提示操作权限被拒绝。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135890" data-ratio="0.273164861612515" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=c639da4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmQyXtNIVbaYffibpYejCwRKqaF0c6uV4p0syMhvQr7MibvSpWGicFC189A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">（3）修改ESXi的配置，修改默认的域管理员组为g1。</span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">用户test2登录，能够登录成功。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135891" data-ratio="0.22743682310469315" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=e49cf5f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmHCASjYtnxkVcpliaxbM9xAWw17vliawoG8t6EOVUbEu0GgbyZYWs8XwA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">用户test登录，仍然能登录成功。尽管，此时test用户实际已经不属于ESXi配置的域管理员组。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135892" data-ratio="0.2250300842358604" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=22ca1151&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT4ibTxeHqxe6AE6Qzs9w8DmLC9N3f6YDcoQt6AeoWpHqOgicm9yLID2YAq97QSzou2y9TR4cenJvJQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">经测试，该方法在其它ESXi版本上也能成功，具体测试版本有：</span><o:p></o:p></p><table cellspacing="0" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tbody style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="242" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">VMware Product</span></strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;"></span><o:p></o:p></p></td><td width="241.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">方法可利用</span></strong><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;"></span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="222.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 8.0</span><o:p></o:p></p></td><td width="221.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="222.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 7.0</span><o:p></o:p></p></td><td width="241.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="222.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 6.7</span><o:p></o:p></p></td><td width="241.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr><tr style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><td width="242" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">ESXi 5.5</span><o:p></o:p></p></td><td width="241.33333333333334" valign="top" style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;word-break: break-all;"><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;font-size: 12px;">是</span><o:p></o:p></p></td></tr></tbody></table><h2 style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></h2><p style="font-size: 16px;color: rgb(99, 151, 221);line-height: 35px;"><strong data-form="0" data-num="1">05</strong></p><p style="font-size: 16px;letter-spacing: 2px;color: rgb(254, 254, 254);"><strong>漏洞修复<br/></strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135893" data-ratio="1.5757575757575757" style="width: 15px;display: block;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=041a56c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjSlib8KpiaZKibkhzWNSZ2PLmicwQwsQMjBDgBOzpu5PtibGuqWpsTkcOSlcqicsPdvpC3cUFwk6KZZWxw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135894" data-ratio="0.5882352941176471" data-w="170" data-type="gif" src="https://wechat2rss.xlab.app/img-proxy/?k=99a1dc1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjSlib8KpiaZKibkhzWNSZ2PLmBfKicU8B0EX4bnUZ18Zd1N0fGnptPjI0MbHWXJIXtva3emVk1OpOLxA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><br/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 2em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">博通官方给了相关修复版本的ESXi下载链接和文档，将ESXi升级到最新的修复版本即可，补丁下载地址：</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/security-advisories/0/24505</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;visibility: visible;"><br/></span></p><p><br/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 15px;"><strong style="outline: 0px;"><span style="outline: 0px;letter-spacing: 2px;">参考链接：</span></strong></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[1] https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/</span><br style="outline: 0px;"/></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[2] https://nvd.nist.gov/vuln/detail/CVE-2024-37085</span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[3] https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/security-advisories/0/24505</span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[4] https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html</span></p><p><br/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br/></p><p><br/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;color: rgb(0, 0, 0);font-size: 15px;">启明星辰积极防御实验室（ADLab）</span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span><br/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，</span><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">“黑雀攻击”概</span><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/CVE累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、数据安全研究、5G安全研究、人工智能安全研究、移动安全研究、物联网安全研究、车联网安全研究、工控安全研究、信创安全研究、云安全研究、无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等<span style="outline: 0px;letter-spacing: 1.5px;">。</span></span></p><p><br/></p><p><br/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-align: start;text-indent: 24px;"><img class="rich_pages wxw-img" data-imgfileid="502135898" data-ratio="1.1205673758865249" data-s="300,640" data-type="jpeg" data-w="282" style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;text-wrap: wrap;outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.97px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ad644c8e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAwNTI1NDI3MQ%3D%3D%26mid%3D2649619550%26idx%3D1%26sn%3Da751128726875a90e9107764b6a4f4f3%26chksm%3D8306214eb471a8587a8054c43873cb1e5814242a375db72abc83c7e76aa3595bc3c594e0a52c%26scene%3D58%26subscene%3D0%23rd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 08 Aug 2024 17:38:23 +0800</pubDate>
    </item>
    <item>
      <title>双奖加冕！启明星辰获工信部NVDB两项殊荣</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619502&amp;idx=1&amp;sn=07b5c4e071571ffdb8c83049085ae9db&amp;chksm=8306213eb471a8280934e4bcb3ffd48a54caee31f3d8bd36ed06529c2d69dcd367243fd4d57b&amp;scene=58&amp;subscene=0#rd</link>
      <description>启明星辰获NVDB“2023年度漏洞报送最具贡献单位”、“2023年度漏洞治理合作最具贡献单位”两项荣誉。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-07-09 20:27</span> <span style="display: inline-block;">北京</span>
</p>

<p>启明星辰获NVDB“2023年度漏洞报送最具贡献单位”、“2023年度漏洞治理合作最具贡献单位”两项荣誉。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=87b7a53d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nQtf1wWz9WgQgaZHP9HROicvZG0E98iaibSAwzXwOdWxTQYGIhhE1fK7f9okcITeWCic6icFOgt46X2Zng%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><span style="outline: 0px;text-align: center;color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;visibility: visible;"></span><br style="outline: 0px;visibility: visible;"/></p><p style="margin-bottom: 0px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;"><br style="outline: 0px;visibility: visible;"/></p><p style="margin-bottom: 16px;padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">近日，</span><strong style="outline: 0px;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);">工业和信息化部网络安全威胁和漏洞信息共享平台（NVDB）</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">对2023年度在网络产品安全漏洞管理方面作出杰出贡献的单位进行表彰。启明星辰凭借信息安全领域专业的安全研究、漏洞挖掘、应急支撑等能力，获“</span><strong style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 122, 170);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">2023年度漏洞报送最具贡献单位</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">”、“</span><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);"><strong style="outline: 0px;">2023年度漏洞治理合作最具贡献单位</strong></span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">”两项荣誉。</span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;text-align: center;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="546" data-cropsely1="0" data-cropsely2="363" data-galleryid="" data-imgfileid="502135849" data-ratio="0.7194444444444444" data-s="300,640" data-type="jpeg" data-w="1080" style="outline: 0px;color: rgb(62, 62, 62);font-size: 14px;width: 546px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9a9bede5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FBwR7Xg3aXhasmc9ykicWicEUXFgKejHntEFLkTSNfNMC6GePocG9PibKK9M329u7VmETdvsRN2Z05nOXsJe1Kcu4A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg%26wxfrom%3D13"/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;text-align: center;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="546" data-cropsely1="0" data-cropsely2="393" data-galleryid="" data-imgfileid="502135848" data-ratio="0.7194444444444444" data-s="300,640" data-type="jpeg" data-w="1080" style="outline: 0px;color: rgb(62, 62, 62);font-size: 14px;width: 546px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=a3b792b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FBwR7Xg3aXhasmc9ykicWicEUXFgKejHntEOk4MRUUO367LwKpGoccPhDXdOdQ06pDI2fChfaic0S0KTd8gIPRKNZA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br style="outline: 0px;"/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">NVDB是目前国内权威的官方漏洞平台之一，由工业和信息化部网络安全管理局组织建设，支持开展网络产品安全漏洞技术评估，督促网络产品提供者及时修补和合理发布自身产品安全漏洞，切实提升我国在安全漏洞方面的整体研究水平和及时预防能力。</span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br style="outline: 0px;"/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">作为最早与</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">NVDB合作的技术单位之一，启明星辰一直以来积极投入漏洞发现、重要漏洞信息报送、原创漏洞报送、漏洞处置支撑、漏洞和安全事件预警信息共享及安全研究报告共享等工作，</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">全力</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">配合</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">NVDB</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">相关漏洞预警和应急响应支撑工作，持续为国家开展安全漏洞管理工作和提升网络安全风险应对能力贡献力量。此次</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">获奖</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">，</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">也</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">充分体现了</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">NVDB对启明星辰安全团队漏洞报送工作以及漏洞治理能力的高度肯定。</span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br style="outline: 0px;"/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">启明星辰长期致力于网络安全攻防技术的研究探索，于1999年成立的</span><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);"><strong style="outline: 0px;">积极防御实验室（ADLab）</strong></span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">，是中国安全行业最早的攻防技术研究实验室之一，也是微软MAPP计划核心成员及“黑雀攻击”概念首推者，拥有卓越的安全技术研究和安全攻防实力，在基础安全、数据安全、5G安全、人工智能安全、移动安全、物联网安全、车联网安全、工控安全、信创安全、云安全、无线安全、高级威胁、攻防体系建设等领域均有前瞻性技术研究成果。截至目前，启明星辰ADLab已通过NVDB/CNNVD/ CNVD/CVE累计发布安全漏洞5000余个，漏洞研究和挖掘能力受到国内外信息安全领域的广泛认可。</span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><br style="outline: 0px;"/></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><br style="outline: 0px;"/></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><img class="rich_pages wxw-img" data-imgfileid="502135847" data-ratio="0.03125" data-s="300,640" style="outline: 0px;vertical-align: middle;font-size: 16px;letter-spacing: 0.034em;width: 578px !important;visibility: visible !important;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=a04dc6f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FBwR7Xg3aXhZmjUxuIzxDuGOnIo3wgF9icyRqAcTaPcB2882QLK9osYv0Jxiak81cp7GZWe2na9CvwichD5icSByTnA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><br style="outline: 0px;"/></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">随着全社会数字化进程的不断深入，漏洞日益成为网络安全防护的焦点和攻守对抗的核心所在</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">，</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">漏洞治理为国家安全赋能，是保障数字经济国家战略顺利推进的一把利剑，是网络安全能力提升的关键环节，启明星辰将持续全方位支持</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">NVDB相关工作，携手加强网络安全漏洞和重要安全事件的研究、发现和处置能力，防范和消控网络安全重大风险，共同保障国家网络安全。</span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><br style="outline: 0px;"/></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><br/></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;text-wrap: wrap;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-align: center;"><span style="outline: 0px;font-size: 14px;"></span><span style="outline: 0px;font-size: 14px;">•</span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-align: center;"><span style="outline: 0px;font-size: 14px;">END<br style="outline: 0px;"/></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-align: center;"><span style="outline: 0px;font-size: 14px;">•</span></p><p><span style="outline: 0px;font-size: 14px;"><br/></span></p><p><br/></p><p><br/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="outline: 0px;line-height: 1.8;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="outline: 0px;"></span><span style="outline: 0px;">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/<span style="outline: 0px;">CVE</span>累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="outline: 0px;">数据安全研究、<span style="outline: 0px;">5G安全研究、</span><span style="outline: 0px;">人工智能安全研究、</span></span></span><span style="outline: 0px;">移动安全研究、物联网安全研究、车联网安全研究、</span><span style="outline: 0px;">工控安全研究、信创安全研究、</span><span style="outline: 0px;">云安全研究、</span><span style="outline: 0px;">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="outline: 0px;letter-spacing: 1.5px;">。</span><span style="outline: 0px;letter-spacing: 1.5px;"></span></span><span style="outline: 0px;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135850" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.989px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Tue, 09 Jul 2024 20:27:49 +0800</pubDate>
    </item>
    <item>
      <title>LibreSSL之CVE-2023-35784漏洞分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619493&amp;idx=1&amp;sn=e9d1f2ad207f3e8e64a50c9cc89cd4e3&amp;chksm=83062135b471a8232cf508716d87bc50ee2bf479f2007457d4ee0531dbe8482e9fc549a2de08&amp;scene=58&amp;subscene=0#rd</link>
      <description>LibreSSL是2014年心脏滴血漏洞爆发后，OpenBSD fork OpenSSL 1.0.1g并进行维护的安全SSL库。CVE-2023-35784漏洞出现在LibreSSL 3.6.2等版本中。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-06-28 17:21</span> <span style="display: inline-block;">北京</span>
</p>

<p>LibreSSL是2014年心脏滴血漏洞爆发后，OpenBSD fork OpenSSL 1.0.1g并进行维护的安全SSL库。CVE-2023-35784漏洞出现在LibreSSL 3.6.2等版本中。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5be9450e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nT0FFbLiaH0wu0rCkjVJY6lp7WvPtfciakxEhwS1iaCge25DYjnEKkwtkDE03zlibFMNZ9YcDZDqhiaSibg%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><span style="outline: 0px;text-align: center;color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;visibility: visible;"></span><br style="outline: 0px;visibility: visible;"/></p><p><br/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;margin-bottom: 0px;text-indent: 2em;text-align: justify;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;white-space-collapse: preserve;orphans: 4;">LibreSSL是2014年心脏滴血漏洞爆发后，OpenBSD fork OpenSSL 1.0.1g并进行维护的安全SSL库。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">CVE-2023-35784是LibreSSL 3.6.2等版本中的ssl3_free函数在释放s-&gt;internal-&gt;verified_chain后未能及时赋值为NULL，导致潜在的Double Free或者Use After Free漏洞。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><img class="rich_pages wxw-img" data-imgfileid="502135833" data-ratio="0.9333333333333333" style="display:block;width:100%;vertical-align:bottom;" data-w="60" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=68fea431&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWhmnYXzPXn4Sicd8gWrhI0EkicibnUzw4452rkLR5pxoSa7FjIy8cia30OdtQ3prNjUCj98nOQUUPZAPQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>一、漏洞信息</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135834" data-ratio="0.7551020408163265" style="display:block;width:100%;vertical-align:bottom;" data-w="49" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=078e5a22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn4C0FYH0nFKAymyuxf2NdPClbfuNRZdOP0ictdaia8wiaPwaQey3ZxCxNo9mhnZEicCAGUEaojuKQtzCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><br/></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">漏洞描述</span></strong></p></li></ul><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="sql"><code><span class="code-snippet_outer">A double free or <span class="code-snippet__keyword">use</span> <span class="code-snippet__keyword">after</span> free could occur <span class="code-snippet__keyword">after</span> SSL_clear <span class="code-snippet__keyword">in</span> OpenBSD <span class="code-snippet__number">7.2</span> <span class="code-snippet__keyword">before</span> errata <span class="code-snippet__number">026</span> <span class="code-snippet__keyword">and</span> <span class="code-snippet__number">7.3</span> <span class="code-snippet__keyword">before</span> errata <span class="code-snippet__number">004</span>, <span class="code-snippet__keyword">and</span> <span class="code-snippet__keyword">in</span> LibreSSL <span class="code-snippet__keyword">before</span> <span class="code-snippet__number">3.6</span><span class="code-snippet__number">.3</span> <span class="code-snippet__keyword">and</span> <span class="code-snippet__number">3.7</span>.x <span class="code-snippet__keyword">before</span> <span class="code-snippet__number">3.7</span><span class="code-snippet__number">.3</span>. NOTE: OpenSSL <span class="code-snippet__keyword">is</span> <span class="code-snippet__keyword">not</span> affected.</span></code></pre><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">补丁</span></strong></p></li></ul><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer">Index: lib/libssl/s3_lib.c</span></code><code><span class="code-snippet_outer">===================================================================</span></code><code><span class="code-snippet_outer">RCS file: /cvs/src/lib/libssl/s3_lib.c,v</span></code><code><span class="code-snippet_outer">diff -u -p -r1<span class="code-snippet__number">.238</span> s3_lib.c</span></code><code><span class="code-snippet_outer">--- lib/libssl/s3_lib.c <span class="code-snippet__number">21</span> Aug <span class="code-snippet__number">2022</span> <span class="code-snippet__number">19</span>:<span class="code-snippet__number">39</span>:<span class="code-snippet__number">44</span> <span class="code-snippet__number">-0000</span>  <span class="code-snippet__number">1.238</span></span></code><code><span class="code-snippet_outer">+++ lib/libssl/s3_lib.c <span class="code-snippet__number">15</span> May <span class="code-snippet__number">2023</span> <span class="code-snippet__number">05</span>:<span class="code-snippet__number">05</span>:<span class="code-snippet__number">28</span> <span class="code-snippet__number">-0000</span></span></code><code><span class="code-snippet_outer">@@ <span class="code-snippet__number">-1573</span>,<span class="code-snippet__number">6</span> +<span class="code-snippet__number">1573</span>,<span class="code-snippet__number">7</span> @@ ssl3_free(SSL *s)</span></code><code><span class="code-snippet_outer"> </span></code><code><span class="code-snippet_outer">    sk_X509_NAME_pop_free(s-&gt;s3-&gt;hs.tls12.ca_names, X509_NAME_free);</span></code><code><span class="code-snippet_outer">    sk_X509_pop_free(s-&gt;internal-&gt;verified_chain, X509_free);</span></code><code><span class="code-snippet_outer">+   s-&gt;internal-&gt;verified_chain = <span class="code-snippet__keyword">NULL</span>;</span></code><code><span class="code-snippet_outer"> </span></code><code><span class="code-snippet_outer">    tls1_transcript_free(s);</span></code><code><span class="code-snippet_outer">    tls1_transcript_hash_free(s)</span></code></pre><p><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;visibility: visible;"></span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">上面的漏洞描述和补丁是目前能在网络上找到的所有有意义的公开内容。</span></p><p><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135835" data-ratio="0.9333333333333333" style="display:block;width:100%;vertical-align:bottom;" data-w="60" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=68fea431&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWhmnYXzPXn4Sicd8gWrhI0EkicibnUzw4452rkLR5pxoSa7FjIy8cia30OdtQ3prNjUCj98nOQUUPZAPQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>二、漏洞分析</strong></p><p><img data-imgfileid="502135836" data-ratio="0.7551020408163265" style="display:block;width:100%;vertical-align:bottom;" data-w="49" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=078e5a22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn4C0FYH0nFKAymyuxf2NdPClbfuNRZdOP0ictdaia8wiaPwaQey3ZxCxNo9mhnZEicCAGUEaojuKQtzCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></strong></p><p><br/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">这里分析3.6.3版本打过补丁后的ssl3_free函数（/// ...略... 为省略的部分无关代码，下文相同）：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer"><span class="code-snippet__comment">// 3.6.3 s3_lib.c</span></span></code><code><span class="code-snippet_outer">void</span></code><code><span class="code-snippet_outer">ssl3_free(SSL *s)</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (s == <span class="code-snippet__keyword">NULL</span>)</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    tls1_cleanup_key_block(s);</span></code><code><span class="code-snippet_outer">    ssl3_release_read_buffer(s);</span></code><code><span class="code-snippet_outer">    ssl3_release_write_buffer(s);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    sk_X509_NAME_pop_free(s-&gt;s3-&gt;hs.tls12.ca_names, X509_NAME_free);</span></code><code><span class="code-snippet_outer">    sk_X509_pop_free(s-&gt;internal-&gt;verified_chain, X509_free);   <span class="code-snippet__comment">////// [1]</span></span></code><code><span class="code-snippet_outer">    s-&gt;internal-&gt;verified_chain = <span class="code-snippet__keyword">NULL</span>;                         <span class="code-snippet__comment">////// [2]</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    tls1_transcript_free(s);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    freezero(s-&gt;s3, sizeof(*s-&gt;s3));</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    s-&gt;s3 = <span class="code-snippet__keyword">NULL</span>;</span></code><code><span class="code-snippet_outer">}</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">相比3.6.2版本的ssl3_free函数，该函数多了[2]处赋值为NULL的语句。</span></p><h3 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">2.1 几个结构体</span></strong></span></h3><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">这里涉及到几个主要的结构体（v3.6.2），首先是SSL结构体。</span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">SSL结构体是LibreSSL（包括OpenSSL）进行安全套接字编程时最直接与程序员打交道的结构体，安全编程主要的操作都直接或间接与其有关，因此，其重要性不言而喻。</span></p><h4 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">2.1.1 SSL</span></strong><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></strong></h4><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">typedef</span> <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">ssl_st</span> <span class="code-snippet__title">SSL</span>;</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">ssl_st</span> {</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/* protocol version</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     * (one of SSL2_VERSION, SSL3_VERSION, TLS1_VERSION, DTLS1_VERSION)</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     */</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> version;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">const</span> SSL_METHOD *method;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> server; <span class="code-snippet__comment">/* are we the server side? - mostly used by SSL_clear*/</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">ssl3_state_st</span> *<span class="code-snippet__title">s3</span>;</span> <span class="code-snippet__comment">/* SSLv3 variables */</span>   <span class="code-snippet__comment">////////// [1]</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">dtls1_state_st</span> *<span class="code-snippet__title">d1</span>;</span> <span class="code-snippet__comment">/* DTLSv1 variables */</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    X509_VERIFY_PARAM *param;</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    SSL_CTX * initial_ctx; <span class="code-snippet__comment">/* initial ctx, used to store sessions */</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">define</span> session_ctx initial_ctx</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">ssl_internal_st</span> *<span class="code-snippet__title">internal</span>;</span>    <span class="code-snippet__comment">/////////// [2]</span></span></code><code><span class="code-snippet_outer">};</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">在该结构体中，重点关注末尾的internal成员变量，因为导致漏洞发生的verified_chain位于该结构体变量内；我们同时留意s3成员变量，留意的原因见下文。</span></p><h4 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">2.1.2 ssl_internal_st</span></strong></h4><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">ssl_internal_st结构体的定义如下：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">typedef</span> <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">ssl_internal_st</span> {</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">tls13_ctx</span> *<span class="code-snippet__title">tls13</span>;</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">uint16_t</span> min_tls_version;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">uint16_t</span> max_tls_version;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/*</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     * These may be zero to imply minimum or maximum version supported by</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     * the method.</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     */</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">uint16_t</span> min_proto_version;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">uint16_t</span> max_proto_version;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> empty_record_count;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">size_t</span> num_tickets; <span class="code-snippet__comment">/* Unused, for OpenSSL compatibility */</span></span></code><code><span class="code-snippet_outer">    STACK_OF(X509) *verified_chain;  <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer">} SSL_INTERNAL;</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">漏洞发生的成员变量verified_chain位于ssl_internal_st结构体的末尾，为一STACK_OF(X509)指针。</span></p><h4 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">2.1.3 BTW</span></strong></h4><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">这里顺便提一下SSL（指广义上的SSL，包括后续的TLS）的证书系统，有利于我们理解漏洞发生的机理。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">SSL证书系统</span></strong></p></li></ul><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">（1）逐级签发</span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">一般来说，服务器返回的证书包含了多个机构，由根证书颁发机构逐级向下签发。以百度的证书为例，根证书颁发机构GlobalSign颁发给机构</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">GlobalSign BE，而GlobalSign BE再颁发给百度。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（2）证书包含颁发者、颁发给谁、公钥、校验等信息</span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">服务器返回的证书中，包含了各个机构的多种信息，比如颁发者，颁发给谁，公钥信息，版本、有效期、以及签名等。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（3）链式包含</span></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">逐级签发的证书，确定了在数据序列上由下至上的链式包含结构。</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">操作系统至少包含根证书。</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">证书系统确保了链式可信，从而要求操作系统至少要包含根证书，比如GlobalSign的根证书。</span></p></li></ul><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">（4）自签名</span></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">一级</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">主要供测试用</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">缺陷：中间人攻击</span></p></li></ul><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">这里也提一下自签名证书，通常由OpenSSL程序生成，由自己颁发给自己，也因此，无法通过操作系统的证书信任链，无法对抗中间人攻击，一般仅用于测试。</span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">下图为服务器返回的百度证书链：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135826" data-ratio="0.34346846846846846" data-s="300,640" style="" data-type="png" data-w="888" src="https://wechat2rss.xlab.app/img-proxy/?k=6abdb5ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT0FFbLiaH0wu0rCkjVJY6lpSicjxLRglfGgdxWBV8222fgJHDMI8vdB3VgC9XEI4zWwMaXtfqJtNjg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">STACK_OF(X)宏</span></strong></p></li></ul><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">该漏洞发生于STACK_OF(X509)宏指向的堆，因此，有必要弄清楚verified_chain的堆结构。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__meta">#typedef STACK_OF(type) struct stack_st_##type</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">typedef</span> <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">stack_st</span> {</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> num;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">char</span> **data;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> sorted;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> num_alloc;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> (*comp)(<span class="code-snippet__keyword">const</span> <span class="code-snippet__keyword">void</span> *, <span class="code-snippet__keyword">const</span> <span class="code-snippet__keyword">void</span> *);</span></code><code><span class="code-snippet_outer">} _STACK; <span class="code-snippet__comment">/* Use STACK_OF(...) instead */</span></span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js"><code><span class="code-snippet_outer">STACK_OF(X509) *verified_chain;</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">这里，我们主要关注num成员变量和指向数组的指针data（LibreSSL使用了Linux偏早期的编码风格，使用char **表示）。</span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">客户端获取到服务器端的证书后，verified_chain在堆中的结构如下图：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135827" data-ratio="1.013003901170351" data-s="300,640" style="" data-type="png" data-w="769" src="https://wechat2rss.xlab.app/img-proxy/?k=720c4a87&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT0FFbLiaH0wu0rCkjVJY6lpXaia4yBkUcNmTOkN8ORc637WicWU2q8iaqoSAOra0pMxHicicoLwmYlkplw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">可以看到，num的值为3，表示证书链为三级证书链（仍以百度的证书为例，三级分别为GlobalSign、GlobalSign BE和百度各自的证书），因此data数组指向3个x509_st证书结构体，上图示例中打印出了最底层的根证书的部分成员变量。</span></p><h3 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">2.2 sk_X509_pop_free宏</span></strong></span></h3><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">我们看一下最终释放s-&gt;internal-&gt;verified_chain的sk_X509_pop_free宏。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">define</span> sk_X509_pop_free(st, free_func) SKM_sk_pop_free(X509, (st), (free_func))</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">define</span> SKM_sk_pop_free(type, st, free_func) \</span></span></code><code><span class="code-snippet_outer">    sk_pop_free(CHECKED_STACK_OF(type, st), CHECKED_SK_FREE_FUNC(type, free_func))</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">void</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__title">sk_pop_free</span><span class="code-snippet__params">(_STACK *st, <span class="code-snippet__keyword">void</span> (*func)(<span class="code-snippet__keyword">void</span> *))</span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> i;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (st == <span class="code-snippet__literal">NULL</span>)                 <span class="code-snippet__comment">/////// [*]</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (i = <span class="code-snippet__number">0</span>; i &lt; st-&gt;num; i++)</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">if</span> (st-&gt;data[i] != <span class="code-snippet__literal">NULL</span>)</span></code><code><span class="code-snippet_outer">            func(st-&gt;data[i]);      <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer">    sk_free(st);                    <span class="code-snippet__comment">/////// [2]</span></span></code><code><span class="code-snippet_outer">}</span></code></pre><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">可以看到，该宏最终调用sk_pop_free函数。在该函数内，先判断st是否等于NULL（[*]处），若等于则直接返回，说明已经不再需要释放了；若st不等于NULL，则使用for循环共循环stack_st结构体里的num次，并每次使用函数的第二个参数（为一函数指针）逐个释放数组内的各个成员（[1]处），对于sk_X509_pop_free(s-&gt;internal-&gt;verified_chain, X509_free)而言，func即为X509_free函数；最后释放st。</span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">简而言之，</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">对于漏洞而言，sk_pop_free的第一个参数st(即s-&gt;internal-&gt;verified_chain)上次释放后没有赋值为NULL，第二次sk_pop_free时因为st不</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">等于NULL，从而导致再次被sk_free函数释放。 </span></p><h2 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></strong></h2><p><img data-ratio="0.9333333333333333" style="display:block;width:100%;vertical-align:bottom;" data-w="60" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=68fea431&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWhmnYXzPXn4Sicd8gWrhI0EkicibnUzw4452rkLR5pxoSa7FjIy8cia30OdtQ3prNjUCj98nOQUUPZAPQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>三、漏洞验证</strong></p><p><img class="rich_pages wxw-img" data-ratio="0.7551020408163265" style="display:block;width:100%;vertical-align:bottom;" data-w="49" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=078e5a22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn4C0FYH0nFKAymyuxf2NdPClbfuNRZdOP0ictdaia8wiaPwaQey3ZxCxNo9mhnZEicCAGUEaojuKQtzCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></strong></h2><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">根据漏洞描述和补丁信息，我们知道需要有机会执行sk_X509_pop_free(s-&gt;internal-&gt;verified_chain, X509_free)两次。</span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">这涉及到SSL结构体的重用，我们先看一个最简单的使用SSL结构体的伪代码。</span></p><p><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">3.1 SSL_new和SSL_free的配对使用</span></strong></span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">首先为SSL结构体变量申请出堆空间，然后使用SSL_connect函数完成SSL连接的握手，这时会得到服务器端响应的证书，最后使用SSL_free函数释放堆空间，伪代码如下：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">SSL* ssl = SSL_new(sslCtx);</span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// ...</span></span></code><code><span class="code-snippet_outer">SSL_connect(ssl);</span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// ...</span></span></code><code><span class="code-snippet_outer">SSL_free(ssl);</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><h3 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">3.2 SSL_clear函数</span></strong></span></h3><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">根据漏洞描述，查看OpenSSL官方对SSL_clear函数的解释，看看能获取到哪些信息提示。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135828" data-ratio="0.7242152466367713" data-s="300,640" style="" data-type="png" data-w="892" src="https://wechat2rss.xlab.app/img-proxy/?k=dbd9d952&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT0FFbLiaH0wu0rCkjVJY6lpvic8ZTGYnUCShA7dxGdC8oAicI5ScrYIttaRZhJWeKnDAkhCyduiav50Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">也就是说，SSL_clear提供重置SSL对象的功能，以为下次新连接做准备，这样避免内部资源的申请和初始化，有利于提高资源的利用效率。而且提到了SSL_shutdown函数的使用。下面为SSL_clear函数的代码：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer">int</span></code><code><span class="code-snippet_outer">SSL_clear(SSL *s)</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (s-&gt;method == <span class="code-snippet__keyword">NULL</span>) {</span></code><code><span class="code-snippet_outer">        SSLerror(s, SSL_R_NO_METHOD_SPECIFIED);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> (<span class="code-snippet__number">0</span>);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    s-&gt;internal-&gt;first_packet = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/*</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     * Check to see if we were changed into a different method, if</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     * so, revert back if we are not doing session-id reuse.</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     */</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (!s-&gt;internal-&gt;in_handshake &amp;&amp; (s-&gt;session == <span class="code-snippet__keyword">NULL</span>) &amp;&amp;</span></code><code><span class="code-snippet_outer">        (s-&gt;method != s-&gt;ctx-&gt;method)) { <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer">        s-&gt;method-&gt;ssl_free(s);          <span class="code-snippet__comment">/////// [2]</span></span></code><code><span class="code-snippet_outer">        s-&gt;method = s-&gt;ctx-&gt;method;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">if</span> (!s-&gt;method-&gt;ssl_new(s))      <span class="code-snippet__comment">/////// [3]</span></span></code><code><span class="code-snippet_outer">            <span class="code-snippet__keyword">return</span> (<span class="code-snippet__number">0</span>);</span></code><code><span class="code-snippet_outer">    } <span class="code-snippet__keyword">else</span></span></code><code><span class="code-snippet_outer">        s-&gt;method-&gt;ssl_clear(s);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> (<span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">}</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在重置SSL结构体对象时，如果我们创造条件满足[1]处，能够使程序代码运行到[3]处，从而有机会使得sk_X509_pop_free(s-&gt;internal-&gt;verified_chain, X509_free)执行两次。留意到，在[2]处已经有一次对ssl_free指向的函数的调用，以及[3]处的ssl_new指向的函数的一次调用。</span></p><h3 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">3.3 ssl3_new函数</span></strong></span></h3><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">先看看ssl3_new函数：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">int</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__title">ssl3_new</span><span class="code-snippet__params">(SSL *s)</span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> ((s-&gt;s3 = <span class="code-snippet__built_in">calloc</span>(<span class="code-snippet__number">1</span>, <span class="code-snippet__keyword">sizeof</span>(*s-&gt;s3))) == <span class="code-snippet__literal">NULL</span>)</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> (<span class="code-snippet__number">0</span>);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    s-&gt;method-&gt;ssl_clear(s);    <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> (<span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">}</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">留意[1]处。</span></p><h3 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">3.4 ssl3_clear函数</span></strong></span></h3><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">还有，ssl3_clear函数的源代码：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer">void</span></code><code><span class="code-snippet_outer">ssl3_clear(SSL *s)</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    unsigned char *rp, *wp;</span></code><code><span class="code-snippet_outer">    size_t rlen, wlen;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    tls1_cleanup_key_block(s);</span></code><code><span class="code-snippet_outer">    sk_X509_NAME_pop_free(s-&gt;s3-&gt;hs.tls12.ca_names, X509_NAME_free);</span></code><code><span class="code-snippet_outer">    sk_X509_pop_free(s-&gt;internal-&gt;verified_chain, X509_free);   <span class="code-snippet__comment">///////// [1]</span></span></code><code><span class="code-snippet_outer">    s-&gt;internal-&gt;verified_chain = <span class="code-snippet__keyword">NULL</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    freezero(s-&gt;s3-&gt;hs.sigalgs, s-&gt;s3-&gt;hs.sigalgs_len);</span></code><code><span class="code-snippet_outer">    s-&gt;s3-&gt;hs.sigalgs = <span class="code-snippet__keyword">NULL</span>;</span></code><code><span class="code-snippet_outer">    s-&gt;s3-&gt;hs.sigalgs_len = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    memset(s-&gt;s3, <span class="code-snippet__number">0</span>, sizeof(*s-&gt;s3));</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    s-&gt;s3-&gt;rbuf.buf = rp;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    s-&gt;s3-&gt;hs.state = SSL_ST_BEFORE|((s-&gt;server) ? SSL_ST_ACCEPT : SSL_ST_CONNECT);</span></code><code><span class="code-snippet_outer">}</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">观察[1]处的代码。</span></p><h3 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">3.5 触发过程</span></strong></span></h3><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">如果我们能先后触发ssl3_free和ssl3_new，那么也就能触发该漏洞。</span></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">创建SSL需要的上下文环境；</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">调用SSL_connect函数，使得SSL连接返回证书链;</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">然后使用SSL_shutdown函数关闭该SSL连接;</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">接下来调用TLSv1_method函数，以返回一个新的SSL_METHOD指针（和第一次使用SSL_CTX_new函数创建SSL_CTX变量时传入的参数不同）;</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">调用SSL_set_ssl_method函数，其第二个参数为上一步返回的新SSL_METHOD指针；</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">正常释放相关资源。</span></p></li></ul><ul class="list-paddingleft-1" style="list-style-type: square;"><li><h4 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">使用TLSv1_method函数的原因</span></strong></h4></li></ul><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">我们看一下TLSv1_method函数的相关代码：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__comment">// ssl_methods.c</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">const</span> SSL_METHOD *</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__title">TLSv1_method</span><span class="code-snippet__params">(<span class="code-snippet__keyword">void</span>)</span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> (&amp;TLSv1_method_data);</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// ...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">const</span> SSL_METHOD TLSv1_method_data = {</span></code><code><span class="code-snippet_outer">    .dtls = <span class="code-snippet__number">0</span>,</span></code><code><span class="code-snippet_outer">    .server = <span class="code-snippet__number">1</span>,</span></code><code><span class="code-snippet_outer">    .version = TLS1_VERSION,</span></code><code><span class="code-snippet_outer">    .min_tls_version = TLS1_VERSION,</span></code><code><span class="code-snippet_outer">    .max_tls_version = TLS1_VERSION,</span></code><code><span class="code-snippet_outer">    .ssl_new = tls1_new,</span></code><code><span class="code-snippet_outer">    .ssl_clear = tls1_clear,</span></code><code><span class="code-snippet_outer">    .ssl_free = tls1_free,  <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer">    .ssl_accept = ssl3_accept,</span></code><code><span class="code-snippet_outer">    .ssl_connect = ssl3_connect,</span></code><code><span class="code-snippet_outer">    .ssl_shutdown = ssl3_shutdown,</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer">    .enc_flags = TLSV1_ENC_FLAGS,</span></code><code><span class="code-snippet_outer">};</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">能够看到，此时，ssl_free函数其实指向了tls1_free函数，而tls1_free函数内部调用了ssl3_free。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__comment">// t1_lib.c</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">void</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__title">tls1_free</span><span class="code-snippet__params">(SSL *s)</span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (s == <span class="code-snippet__literal">NULL</span>)</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">free</span>(s-&gt;internal-&gt;tlsext_session_ticket);</span></code><code><span class="code-snippet_outer">    ssl3_free(s);   <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer">}</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">我们再来看一下SSL_set_ssl_method函数：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer">int</span></code><code><span class="code-snippet_outer">SSL_set_ssl_method(SSL *s, <span class="code-snippet__keyword">const</span> SSL_METHOD *method)</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    int (*handshake_func)(SSL *) = <span class="code-snippet__keyword">NULL</span>;</span></code><code><span class="code-snippet_outer">    int ret = <span class="code-snippet__number">1</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (s-&gt;method == method)</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> (ret);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (s-&gt;internal-&gt;handshake_func == s-&gt;method-&gt;ssl_connect)</span></code><code><span class="code-snippet_outer">        handshake_func = method-&gt;ssl_connect;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">else</span> <span class="code-snippet__keyword">if</span> (s-&gt;internal-&gt;handshake_func == s-&gt;method-&gt;ssl_accept)</span></code><code><span class="code-snippet_outer">        handshake_func = method-&gt;ssl_accept;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (s-&gt;method-&gt;version == method-&gt;version) { <span class="code-snippet__comment">//// [1]</span></span></code><code><span class="code-snippet_outer">        s-&gt;method = method;</span></code><code><span class="code-snippet_outer">    } <span class="code-snippet__keyword">else</span> {</span></code><code><span class="code-snippet_outer">        s-&gt;method-&gt;ssl_free(s);                  <span class="code-snippet__comment">//// [2]</span></span></code><code><span class="code-snippet_outer">        s-&gt;method = method;                      <span class="code-snippet__comment">//// [3]</span></span></code><code><span class="code-snippet_outer">        ret = s-&gt;method-&gt;ssl_new(s);             <span class="code-snippet__comment">//// [4]</span></span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    s-&gt;internal-&gt;handshake_func = handshake_func;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> (ret);</span></code><code><span class="code-snippet_outer">}</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">我们使用TLSv1_method函数返回的method-&gt;version故意不等于s-&gt;method-&gt;version，从而导致[2]的执行，而此时的s-&gt;method-&gt;ssl_free的值为tls1_free，且运行到[4]处时，s-&gt;method-&gt;ssl_new的值为tls1_new：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135829" data-ratio="0.591764705882353" data-s="300,640" style="" data-type="png" data-w="850" src="https://wechat2rss.xlab.app/img-proxy/?k=7d53615c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nT0FFbLiaH0wu0rCkjVJY6lpL0pHdYyIXmzicBcibyYicoIeuhTwhQSIPiaibtP3kyicH4JyGa25mz9k1h2Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">根据tls1_free函数的代码，它会调用ssl3_free一次，而ssl3_free内部会执行一次sk_X509_pop_free(s-&gt;internal-&gt;verified_chain, X509_free)，导致s-&gt;internal-&gt;verified_chain被释放。</span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">当程序执行到SSL_set_ssl_method内的[4]处时，会调用tls1_new函数。</span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">我们再来看一下tls1_new的代码：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">int</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__title">tls1_new</span>(<span class="code-snippet__params">SSL *s</span>)</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (!ssl3_new(s))        <span class="code-snippet__comment"><span class="code-snippet__doctag">///</span>// [1]</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> (<span class="code-snippet__number">0</span>);</span></code><code><span class="code-snippet_outer">    s-&gt;method-&gt;ssl_clear(s);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> (<span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">}</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">可以看到，无论如何，[1]处的ssl3_new函数都会执行，而ssl3_new内部会调用s-&gt;method-&gt;ssl_clear，此时的s-&gt;method-&gt;ssl_clear指向tls1_clear函数，tls1_clear函数的实现如下：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer">void</span></code><code><span class="code-snippet_outer">tls1_clear(SSL *s)</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    ssl3_clear(s);      <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer">    s-&gt;version = s-&gt;method-&gt;version;</span></code><code><span class="code-snippet_outer">}</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">注意到tls1_clear内部会调用ssl3_clear，而ssl3_clear内部一定会执行sk_X509_pop_free(s-&gt;internal-&gt;verified_chain, X509_free)语句，从而导致s-&gt;internal-&gt;verified_chain被再次释放。在调试器中的崩溃如下图：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135844" data-ratio="0.8832772166105499" data-s="300,640" style="" data-type="png" data-w="891" src="https://wechat2rss.xlab.app/img-proxy/?k=7b4fa82e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSGD14uPU0T6LPaFKuMicGBXfbdSOsgbt2lV7eappvibmw2349yQ1K1jaw5XMfe3oUgHnXUAkVgltYQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><h2 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></strong></h2><p><img data-imgfileid="502135839" data-ratio="0.9333333333333333" style="display:block;width:100%;vertical-align:bottom;" data-w="60" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=68fea431&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWhmnYXzPXn4Sicd8gWrhI0EkicibnUzw4452rkLR5pxoSa7FjIy8cia30OdtQ3prNjUCj98nOQUUPZAPQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>四、漏洞修复</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135840" data-ratio="0.7551020408163265" style="display:block;width:100%;vertical-align:bottom;" data-w="49" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=078e5a22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn4C0FYH0nFKAymyuxf2NdPClbfuNRZdOP0ictdaia8wiaPwaQey3ZxCxNo9mhnZEicCAGUEaojuKQtzCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></strong></h2><h3 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></strong></h3><h3 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">4.1 对于3.6.3</span></strong></span></h3><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">对于3.6.3版，官方直接在ssl3_free函数里把s-&gt;internal-&gt;verified_chain赋值为NULL：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer"><span class="code-snippet__comment">// ssl3_free(SSL *s)</span></span></code><code><span class="code-snippet_outer">    sk_X509_pop_free(s-&gt;internal-&gt;verified_chain, X509_free); <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer">    s-&gt;internal-&gt;verified_chain = <span class="code-snippet__keyword">NULL</span>;                       <span class="code-snippet__comment">/////// [2]</span></span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><h3 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">4.2 最新版本3.9.2</span></strong></span></h3><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在分析打过补丁后的较新版本时，会发现ssl3_free函数没有了3.6.3版时把verified_chain赋值为NULL的语句，比如最新版3.9.2的：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer">void</span></code><code><span class="code-snippet_outer">ssl3_free(SSL *s)</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (s == <span class="code-snippet__keyword">NULL</span>)</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    tls1_cleanup_key_block(s);</span></code><code><span class="code-snippet_outer">    ssl3_release_read_buffer(s);</span></code><code><span class="code-snippet_outer">    ssl3_release_write_buffer(s);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    sk_X509_pop_free(s-&gt;s3-&gt;hs.peer_certs, X509_free);</span></code><code><span class="code-snippet_outer">    sk_X509_pop_free(s-&gt;s3-&gt;hs.peer_certs_no_leaf, X509_free);</span></code><code><span class="code-snippet_outer">    sk_X509_pop_free(s-&gt;s3-&gt;hs.verified_chain, X509_free); <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer">    tls_key_share_free(s-&gt;s3-&gt;hs.key_share);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    freezero(s-&gt;s3-&gt;peer_quic_transport_params,</span></code><code><span class="code-snippet_outer">        s-&gt;s3-&gt;peer_quic_transport_params_len);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    freezero(s-&gt;s3, sizeof(*s-&gt;s3));     <span class="code-snippet__comment">/////// [2]</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    s-&gt;s3 = <span class="code-snippet__keyword">NULL</span>;</span></code><code><span class="code-snippet_outer">}</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">同时，留意[2]处的freezero函数。</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"> </span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">原因在于结构体定义的变化，从sk_X509_pop_free宏的第一参数可以看出一些端倪：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer">sk_X509_pop_free(s-&gt;s3-&gt;hs.verified_chain, X509_free);</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">该版本几个相关结构体的定义如下：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__comment">// 3.9.2</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">ssl_st</span> {</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/* protocol version</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     * (one of SSL2_VERSION, SSL3_VERSION, TLS1_VERSION, DTLS1_VERSION)</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     */</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> version;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">const</span> SSL_METHOD *method;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> server; <span class="code-snippet__comment">/* are we the server side? - mostly used by SSL_clear*/</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">ssl3_state_st</span> *<span class="code-snippet__title">s3</span>;</span> <span class="code-snippet__comment">/* SSLv3 variables */</span>    <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">dtls1_state_st</span> *<span class="code-snippet__title">d1</span>;</span> <span class="code-snippet__comment">/* DTLSv1 variables */</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer">};</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">typedef</span> <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">ssl3_state_st</span> {</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">long</span> flags;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> server_random[SSL3_RANDOM_SIZE];</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> in_read_app_data;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    SSL_HANDSHAKE hs;                                  <span class="code-snippet__comment">/////// [2]</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer">} SSL3_STATE;</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">以及ssl_handshake_st：</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">typedef</span> <span class="code-snippet__class"><span class="code-snippet__keyword">struct</span> <span class="code-snippet__title">ssl_handshake_st</span> {</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/*</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     * Minimum and maximum versions supported for this handshake. These are</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     * initialised at the start of a handshake based on the method in use</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     * and the current protocol version configuration.</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     */</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">uint16_t</span> our_min_tls_version;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/// ...略...</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/* Certificate chain resulting from X.509 verification. */</span></span></code><code><span class="code-snippet_outer">    STACK_OF(X509) *verified_chain;                    <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    SSL_HANDSHAKE_TLS12 tls12;</span></code><code><span class="code-snippet_outer">    SSL_HANDSHAKE_TLS13 tls13;</span></code><code><span class="code-snippet_outer">} SSL_HANDSHAKE;</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">可以看到在[2]处的hs是一个SSL_HANDSHAKE类型的结构体成员变量。ssl3_free函数里的freezero函数会把s-&gt;s3的堆空间的内容全部设置为零，查看freezero函数及其内部的explicit_bzero的代码即可得知。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="color: rgb(136, 136, 136);font-weight: bold;"><h3 style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 0em;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;color: rgb(136, 136, 136);">freezero函数和explicit_bzero函数</span></strong></h3></li></ul><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__comment">// freezero.c</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">void</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__title">freezero</span><span class="code-snippet__params">(<span class="code-snippet__keyword">void</span> *ptr, <span class="code-snippet__keyword">size_t</span> sz)</span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/* This is legal. */</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (ptr == <span class="code-snippet__literal">NULL</span>)</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    explicit_bzero(ptr, sz);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">free</span>(ptr);</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// explicit_bzero.c</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">void</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__title">explicit_bzero</span><span class="code-snippet__params">(<span class="code-snippet__keyword">void</span> *buf, <span class="code-snippet__keyword">size_t</span> len)</span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">memset</span>(buf, <span class="code-snippet__number">0</span>, len);               <span class="code-snippet__comment">/////// [1]</span></span></code><code><span class="code-snippet_outer">    __explicit_bzero_hook(buf, len);</span></code><code><span class="code-snippet_outer">}</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p style="line-height: inherit;orphans: 4;margin-top: 0.8em;white-space: pre-wrap;width: inherit;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;, &#34;Clear Sans&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, &#34;Segoe UI Emoji&#34;, sans-serif;font-size: 16px;letter-spacing: normal;text-align: justify;background-color: rgb(255, 255, 255);margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">这样，[1]处的memset函数会导致s-&gt;s3-&gt;hs.verified_chain被赋值为NULL，从而在sk_pop_free函数[1]处时即返回，进而避免了漏洞的发生。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 15px;"><strong style="outline: 0px;"><span style="outline: 0px;letter-spacing: 2px;">参考链接：</span></strong></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[1]https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/026_ssl.patch.sig</span><br/></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[2]https://www.cvedetails.com/cve/CVE-2023-35784/</span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;font-size: 12px;color: rgb(136, 136, 136);"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;letter-spacing: 0.544px;"/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;color: rgb(0, 0, 0);font-size: 15px;">启明星辰积极防御实验室（ADLab）</span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，</span><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">“黑雀攻击”概</span><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/CVE累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、数据安全研究、5G安全研究、人工智能安全研究、移动安全研究、物联网安全研究、车联网安全研究、工控安全研究、信创安全研究、云安全研究、无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等<span style="outline: 0px;letter-spacing: 1.5px;">。</span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135832" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.979px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Fri, 28 Jun 2024 17:20:41 +0800</pubDate>
    </item>
    <item>
      <title>启明星辰集团荣获CNNVD两项大奖，彰显技术支撑与漏洞贡献实力</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619472&amp;idx=1&amp;sn=12c61bb289e700cfa056163835c01592&amp;chksm=83062100b471a816935ff426847dcaeeff6f35310a087f47e0ce61fd95f1da0466fe7a4869db&amp;scene=58&amp;subscene=0#rd</link>
      <description>启明星辰集团荣获CNNVD两项大奖，彰显技术支撑与漏洞贡献实力&#xD;&#xA;被CNNVD授予“2023年度优秀技术支撑单位”和“2023年度高质量漏洞优秀贡献单位”两项殊荣。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-06-19 17:08</span> <span style="display: inline-block;">北京</span>
</p>

<p>启明星辰集团荣获CNNVD两项大奖，彰显技术支撑与漏洞贡献实力</p>
<p>被CNNVD授予“2023年度优秀技术支撑单位”和“2023年度高质量漏洞优秀贡献单位”两项殊荣。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=125c0a38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nRHia0hZdsYeUGTAP0ltYFwpLjGgiaq7sYQw48uPXbQ02NIc9Dvfxjrs1XrBL23kxVEJQKoet0Uic1iaA%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><span style="text-align: center;color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;"></span><br/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 0px;"><br/></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;visibility: visible;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;visibility: visible;">6月18日，</span><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);visibility: visible;"><strong style="outline: 0px;visibility: visible;">国家信息安全漏洞库（CNNVD）2023年度工作总结暨优秀表彰大会</strong></span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;visibility: visible;">在中国信息安全测评中心隆重举行。启明星辰集团借卓越的技术实力以及在高质量漏洞报送等方面的突出贡献，在260多家技术支撑单位中脱颖而出，荣获</span><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);visibility: visible;"><strong style="outline: 0px;visibility: visible;">“2023年度优秀技术支撑单位”</strong></span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;visibility: visible;">和</span><strong style="outline: 0px;visibility: visible;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);visibility: visible;">“2023年度高质量漏洞优秀贡献单位”</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;visibility: visible;">两项殊荣。</span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;visibility: visible;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;visibility: visible;"><br style="outline: 0px;visibility: visible;"/></span></p><p style="outline: 0px;visibility: visible;"><img class="rich_pages wxw-img" data-imgfileid="502135812" data-ratio="0.700925925925926" data-s="300,640" style="outline: 0px;visibility: visible !important;width: 677px !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=78f402a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FBwR7Xg3aXhYgibdoLuGGSI7UhOjz8qhKECTK5wzUA7xleklibpkz38EPMztTFjRc2dIFfhuodicFYH4z34elhA02Q%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p style="outline: 0px;"><br style="outline: 0px;"/></p><p style="outline: 0px;"><img class="rich_pages wxw-img" data-imgfileid="502135813" data-ratio="0.7027777777777777" data-s="300,640" style="outline: 0px;visibility: visible !important;width: 677px !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=02626abe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FBwR7Xg3aXhYgibdoLuGGSI7UhOjz8qhKEnGtkjKVqOFwiclt1HjEq65a0eIskicSxCOAicHqU5IoXSRsaojia6bQejA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br style="outline: 0px;"/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">自2013年首批获得国家信息安全漏洞库(CNNVD)技术支撑单位（一级）起，启明星辰集团至今已</span><strong style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 122, 170);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">连续11年</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">获得“年度优秀技术支撑单位”荣誉，并在2023年CNNVD开展的</span><strong style="outline: 0px;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);">网络安全漏洞消控专项工作</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">中，充分发挥了网络安全漏洞分析和预警消控领域的专业技术水平，为专项工作成功开展提供了坚实支撑。</span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br style="outline: 0px;"/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">多年来，启明星辰集团积极履行其作为</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">CNNVD</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">技术支撑单位的职责，包括重要漏洞信息报送、原创漏洞报送、漏洞发现、漏洞处置支撑、漏洞和安全事件预警信息共享及安全研究报告共享等任务。通过远程和现场支撑等方式，<span style="outline: 0px;">集团</span>积极配合</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">CNNVD</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">相关漏洞预警和应急响应支撑工作，为提升国家网络安全漏洞治理体系和信息安全保障发挥了重要作用。</span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br style="outline: 0px;"/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 122, 170);"><strong style="outline: 0px;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">启明星辰积极防御实验室（ADLab）</span></strong></span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">成立于1999年，是国内最早的攻防技术研究团队之一，拥有卓越的安全技术研究和安全攻防实力，在基础安全、数据安全、5G安全、人工智能安全、移动安全、物联网安全、车联网安全、工控安全、信创安全、云安全、无线安全、高级威胁、攻防体系建设等领域均有前瞻性技术研究成果，以攻促防带动重要网络信息系统安全防御能力的提升，推动安全行业的不断发展。</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br style="outline: 0px;"/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br style="outline: 0px;"/></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">在原创漏洞挖掘方面，ADLab的表现尤为突出。截至目前，已通过 CNVD/CNNVD/NVDB/CVE累计发布安全漏洞</span><strong style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 122, 170);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">5000余</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">个，并持续多年荣获优秀技术支撑单位、原创漏洞发现突出贡献单位、漏洞信息报送贡献单位、漏洞处置突出贡献单位等荣誉，持续多年多名成员多次入选微软</span><strong style="outline: 0px;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;color: rgb(0, 122, 170);">“MSRC全球Top100最具价值研究者”</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">等国际榜单，团队攻防技术研究实力和专业性在全球范围内获得高度认可。</span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><br style="outline: 0px;"/></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><img class="rich_pages wxw-img" data-imgfileid="502135811" data-ratio="0.03125" data-s="300,640" style="outline: 0px;vertical-align: middle;font-size: 16px;letter-spacing: 0.034em;width: 578px !important;visibility: visible !important;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=32a30f7c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FBwR7Xg3aXhZmjUxuIzxDuGOnIo3wgF9icyRqAcTaPcB2882QLK9osYv0Jxiak81cp7GZWe2na9CvwichD5icSByTnA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"></span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><br style="outline: 0px;"/></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">此次获奖，不仅是对启明星辰集团长期坚持高质量漏洞报送、积极推动国家级网络安全漏洞综合运筹能力建设的肯定，更是对其技术实力和专业精神的高度认可。未来，启明星辰集团将继续发挥技术支撑单位的作用，深化技术研究，拓展服务边界，不断提升信息安全防护能力，为构建安全可信的信息环境贡献更多力量。</span></p><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-align: center;"><span style="outline: 0px;font-size: 14px;">•</span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-align: center;"><span style="outline: 0px;font-size: 14px;">END<br style="outline: 0px;"/></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-align: center;"><span style="outline: 0px;font-size: 14px;">•</span></p><p><span style="outline: 0px;font-size: 14px;"><br/></span></p><p><br/></p><p><br/></p><p><br/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="outline: 0px;line-height: 1.8;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="outline: 0px;"></span><span style="outline: 0px;">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/<span style="outline: 0px;">CVE</span>累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="outline: 0px;">数据安全研究、<span style="outline: 0px;">5G安全研究、</span><span style="outline: 0px;">人工智能安全研究、</span></span></span><span style="outline: 0px;">移动安全研究、物联网安全研究、车联网安全研究、</span><span style="outline: 0px;">工控安全研究、信创安全研究、</span><span style="outline: 0px;">云安全研究、</span><span style="outline: 0px;">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="outline: 0px;letter-spacing: 1.5px;">。</span><span style="outline: 0px;letter-spacing: 1.5px;"></span></span><span style="outline: 0px;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135814" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.99px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Wed, 19 Jun 2024 17:08:16 +0800</pubDate>
    </item>
    <item>
      <title>PHP CGI参数注入漏洞（CVE-2024-4577） 分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619453&amp;idx=1&amp;sn=63b2fc50c252461f42ca85a82d7ec730&amp;chksm=830626edb471affb43c80e4ba3ee6c17101a4fedc31150f6899cf4f8a9b231fc587b151c8b48&amp;scene=58&amp;subscene=0#rd</link>
      <description>2024年6月6日，PHP官方发布了多个新版本，其中都包含对编号为CVE-2024-4577的安全漏洞的修复更新。该漏洞是PHP CGI的参数注入漏洞，是对CVE-2012-1823漏洞的修复绕过。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-06-08 13:00</span> <span style="display: inline-block;">北京</span>
</p>

<p>2024年6月6日，PHP官方发布了多个新版本，其中都包含对编号为CVE-2024-4577的安全漏洞的修复更新。该漏洞是PHP CGI的参数注入漏洞，是对CVE-2012-1823漏洞的修复绕过。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=39f01970&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nSRhnJ3Cm0QSoWTAV8IVUgiayIsr0NPPukR6tVgbPvfXspelyE5WT0Uk4BcIWMgVPB01e116mnTBZQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p style="outline: 0px;visibility: visible;"><br/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135787" data-ratio="0.6494845360824743" style="width:100%;display:block;vertical-align:bottom;" data-w="97" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=ecfe4b12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn6EGYmpsicFMaBPicpiaQIic4TsQPcSW2xfDibiaVz9Ym05fXJxA4j63jIKdzTN9lbHQGg7qBFdxTa2QQsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p><br/></p><p style="font-size:16px;letter-spacing:2px;color:#7ad0f9;"><span style="color: rgb(0, 82, 255);"><strong>一、漏洞描述</strong></span></p><p><br/></p><p><br/></p><p style="margin-bottom: 8px;text-indent: 2em;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">2024年6月6日，PHP官方发布了多个新版本，其中都包含对编号为CVE-2024-4577的<span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">安全漏洞的</span>修复<span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">更新</span>。该漏洞是PHP CGI的参数注入漏洞，是对CVE-2012-1823漏洞的<span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">修复绕过</span>。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">该漏洞产生的原因是：在PHP CGI模式下，未正确处理Windows系统中的“Best-Fit Mapping”特性，导致简体中文、繁体中文、日文或其他受影响语言环境将某些字符错误的识别成了&#39;-&#39;。攻击者可通过引入恶意参数实现任意代码执行。</span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><img class="rich_pages wxw-img" data-imgfileid="502135788" data-ratio="0.6494845360824743" style="width: 48.9962px;display: block;" data-w="97" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=ecfe4b12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn6EGYmpsicFMaBPicpiaQIic4TsQPcSW2xfDibiaVz9Ym05fXJxA4j63jIKdzTN9lbHQGg7qBFdxTa2QQsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p><br/></p><p style="font-size: 16px;color: rgb(122, 208, 249);"><span style="color: rgb(0, 82, 255);"><strong>二、漏洞复现</strong></span></p><p><br/></p><p><br/></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);">如下图所示：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135803" data-ratio="0.275" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e9da6a02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSRhnJ3Cm0QSoWTAV8IVUgiaMMvCmnic80GxaL6zOCSWCQwAzLzTtVlgTYIgbLwCfpaFf92DVjicaDgw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135790" data-ratio="0.6494845360824743" style="width: 48.9962px;display: block;" data-w="97" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=ecfe4b12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn6EGYmpsicFMaBPicpiaQIic4TsQPcSW2xfDibiaVz9Ym05fXJxA4j63jIKdzTN9lbHQGg7qBFdxTa2QQsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p><br/></p><p style="font-size: 16px;color: rgb(122, 208, 249);"><span style="color: rgb(0, 82, 255);"><strong>三、漏洞分析</strong></span></p><p><br/></p><p><br/></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);">CVE-2012-1823补丁的修复措施是，PHP处理传递进来的字符串时，在跳过前面空白符后，判断第一位是否是&#39;-&#39;；如果是&#39;-&#39;，就不对后面的字符进行参数解析，比如-d,-s,-c等参数。</span><o:p></o:p></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);">PHP官方的commit如下图所示：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135804" data-ratio="0.4981481481481482" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=32926966&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSRhnJ3Cm0QSoWTAV8IVUgiasibEvIicxqk6fpxxZoLzoSnYIUjtUZnspCapgEdRRd3S80ZglA09iaEGQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);"></span></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);">可以看到，当运行系统环境为Windows时，PHP调用WideCharToMultiByte函数来加强对宽字符的判断。如果转换后的字符为&#39;-&#39;，则将skip_getopt置为1，使得后续就不会对传入的字符串进行参数解析。</span><o:p></o:p></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);">那么，什么样的宽字符能够转换后变成&#39;-&#39;，从而绕过之前的修复呢？</span><o:p></o:p></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);">以受影响的简体中文、繁体中文、日文举例，他们对应的Windows 代码页分别是936、950、932。其中都有将0x00ad映射为0x002d的操作，如下图所示：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135792" data-ratio="0.20320855614973263" data-s="300,640" style="" data-type="png" data-w="561" src="https://wechat2rss.xlab.app/img-proxy/?k=049ca8c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSRhnJ3Cm0QSoWTAV8IVUgiaMrG598cn2nCkJI2JDtQbM4Dc7FyDhZibr3yOFzpXWZGq9ZSavgTiapkQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135793" data-ratio="0.26916221033868093" data-s="300,640" style="" data-type="png" data-w="561" src="https://wechat2rss.xlab.app/img-proxy/?k=7910c91a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSRhnJ3Cm0QSoWTAV8IVUgiav7xicQ1ps12SIPEWnoRRcjIUb7M10BNyFg0OI39ob7aKPTe3sYnkd3w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);"></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135794" data-ratio="0.33037300177619894" data-s="300,640" style="" data-type="png" data-w="563" src="https://wechat2rss.xlab.app/img-proxy/?k=29a07a37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSRhnJ3Cm0QSoWTAV8IVUgiaunEK4iaYXwtxYFjQDmG1bdxG3OPMiaVDASPvCBAQeClRFxiaCEbCNZmaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 8px;text-indent: 2em;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">因此通过引入0x00ad即可替代0x002d，实现参数注入来执行任意代码。</span></p><p><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><img class="rich_pages wxw-img" data-imgfileid="502135795" data-ratio="0.6494845360824743" style="width: 48.9962px;display: block;" data-w="97" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=ecfe4b12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn6EGYmpsicFMaBPicpiaQIic4TsQPcSW2xfDibiaVz9Ym05fXJxA4j63jIKdzTN9lbHQGg7qBFdxTa2QQsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p><br/></p><p style="font-size: 16px;color: rgb(122, 208, 249);"><span style="color: rgb(0, 82, 255);"><strong>四、总结</strong></span></p><p><br/></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><br/></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);"><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;Cambria&#34;,&#34;serif&#34;;mso-fareast-font-family:宋体;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">CVE-2024-4577</span></span>漏洞利用简单，危害严重。特别在某些对Apache、PHP进行集成部署和管理的流行软件中，如果未正确配置php cgi，即可造成严重危害。</span></p><p><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span lang="EN-US" style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 15px;"><strong style="outline: 0px;"><span style="outline: 0px;letter-spacing: 2px;">参考链接：</span></strong></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="color: rgb(136, 136, 136);"><strong><span style="outline: 0px;font-size: 12px;">PHP官方commit</span></strong><span style="outline: 0px;font-size: 12px;"></span></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;font-size: 12px;color: rgb(136, 136, 136);">https://github.com/php/php-src/commit/4dd9a36c165974c84c4217aa41849b70a9fc19c9</span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="color: rgb(136, 136, 136);"><strong><span style="outline: 0px;font-size: 12px;">DEVCORE的漏洞通报</span></strong><span style="outline: 0px;font-size: 12px;"></span></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;font-size: 12px;color: rgb(136, 136, 136);">https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability/</span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;letter-spacing: 0.544px;"/></p><p><br/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;color: rgb(0, 0, 0);font-size: 15px;">启明星辰积极防御实验室（ADLab）</span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，</span><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">“黑雀攻击”概</span><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/CVE累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、数据安全研究、5G安全研究、人工智能安全研究、移动安全研究、物联网安全研究、车联网安全研究、工控安全研究、信创安全研究、云安全研究、无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等<span style="outline: 0px;letter-spacing: 1.5px;">。</span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135798" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.989px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Sat, 08 Jun 2024 12:59:47 +0800</pubDate>
    </item>
    <item>
      <title>乌克兰卫星电视系统攻击事件安全分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619432&amp;idx=1&amp;sn=11c2534d729a959da91b5120146bc275&amp;chksm=830626f8b471afee7c52a41b92f10b62ec17880d1d9bf2c685b777e95cd3b97b841b022d94af&amp;scene=58&amp;subscene=0#rd</link>
      <description>黑客对乌克兰的电视频道进行了入侵，使部分乌克兰居民意外观看到了莫斯科红场的胜利日阅兵直播。这次攻击影响StarLightMedia和Inter两家电视台的卫星广播。为此，启明星辰ADLab针对这次数字卫星电视系统的攻击事件进行了技术性分析。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-05-21 18:16</span> <span style="display: inline-block;">北京</span>
</p>

<p>黑客对乌克兰的电视频道进行了入侵，使部分乌克兰居民意外观看到了莫斯科红场的胜利日阅兵直播。这次攻击影响StarLightMedia和Inter两家电视台的卫星广播。为此，启明星辰ADLab针对这次数字卫星电视系统的攻击事件进行了技术性分析。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=945fadd7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nRlj0JO6OP3WOic68KtibvLVEVMVowibzNbhzmK4YlAsnGKmkSXPk55O8AZprvnMTrO1VvuJjNe5rECQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br/></p><p style="outline: 0px;visibility: visible;"><br/></p><p style="text-align:center;font-size:16px;color:#fefefe;margin-bottom:unset;"><strong>1</strong></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>概述</strong></p><p><img data-imgfileid="502135766" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="37" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=d3ac5042&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWhucrX7YicTDxTtwjVtSayEMJoicHsvs3HDduLbgIIRibuicLBf18LEx8QvcLlccCynZ0MwniawCsktemw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><br/></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(0, 0, 0);"><span style="outline: 0px;text-wrap: wrap;line-height: 17.25px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);visibility: visible;">据外媒报道，2024年5月9日，黑客对乌克兰的电视频道进行了入侵，使得部分乌克兰居民意外观看到了莫斯科红场的胜利日阅兵直播。这次攻击影响了StarLightMedia和Inter两家电视台的卫星广播，攻击分别在当日上午10点至10点18分、11点27分至11点29分以及中午12点51分至12点55分三个时间段内发生。为了应对这一情况，相关频道不得不暂时切断卫星信号</span>。</span></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">黑客通过播放莫斯科的胜利日阅兵直播，意在传播特定的政治信息和宣</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;color: rgb(0, 0, 0);">传，这种信息战的战术旨在塑造或扭曲乌克兰民众对俄乌冲突的认知。这种策略可能对乌克兰内部的政治稳定和民意造成影响，增加社会分裂。</span></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">近年来网络空间地缘政治化的趋势日益显著，针对卫星或电视系统的关键基础设施的安全事件越来越多：</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;color: rgb(0, 0, 0);">2022年2月24日俄乌冲突爆发时，覆盖乌克兰地区的美国卫星运营商Viasa</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;color: rgb(0, 0, 0);">t遭遇网络攻击，导致数千乌克兰用户、数万名欧洲其他地区用户断网。</span></p></li><li><p><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;color: rgb(0, 0, 0);">2023年，以色列13频道电视台遭到黑客网络攻击，画面被插播巴勒斯坦国</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;color: rgb(0, 0, 0);">旗。</span></p></li><li><p><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;color: rgb(0, 0, 0);">2023年，莫斯科国家广播电台和电视频道服务器在遭到黑客入侵后，发出了虚假的空袭警报。</span></p></li></ul><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">为此，启明星辰ADLab针对这次数字<span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">卫</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">星</span>电视系统的攻击事件进行了技术性分析。</span></p><p><br/></p><p style="text-align:center;font-size:16px;color:#fefefe;margin-bottom:unset;"><strong>2</strong></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong><strong style="color: rgb(254, 254, 254);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 2px;text-wrap: wrap;background-color: rgb(142, 191, 240);">卫星</strong>电视系统架构</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135767" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="37" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=d3ac5042&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWhucrX7YicTDxTtwjVtSayEMJoicHsvs3HDduLbgIIRibuicLBf18LEx8QvcLlccCynZ0MwniawCsktemw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 16px;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135768" data-ratio="0.5361111111111111" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f58961e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRlj0JO6OP3WOic68KtibvLVEbBz0fEavnPCjWHEkwnWFgtnfgfOn9ZK07pBWr2ATZ9AvnTOerWAiahg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">1 </span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">卫星</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">电视系</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">统示意</span></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">卫星</span>电视系统通信过程，涉及内容的编码、传输和接收。这个过程主要可以分为以下几个步骤：</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（1）内容编辑与编码：拍摄后的原始视频和音频内容需要通过编辑整理成最终的播出格式。之后，这些内容会被转换（编码）成适合于卫星传输的格式。这一步通常包括压缩和编码，这样能够减少数据的大小，确保它可以有效地通过卫星链路传输。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（2）上行信号传输：编码后的信号被传输到上行地面站。这里，信号会被进一步处理，并转换为微波信号，然后通过强大的发射天线发射到空中的卫星。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（3）卫星中继：微波信号到达地球同步轨道上的卫星后，卫星会接收这些信号，并对其进行再放大和处理。然后，卫星会使用不同的频率（下行信号通常使用与上行不同的频率，以防止信号干扰）将信号重新发送回地球。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（4）下行信号接收：地球上的各种接收站（如有线电视网络的地面接收站或个人的卫星接收盘）捕捉来自卫星的信号。这些信号经过低噪声放大器(LNA)放大后，被转换为电视机或其他设备可以识别和处理的格式。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（5）内容分发与播出：接收到的信号被送往电视网络或直接传送到用户的电视接收器。在电视网络中，信号可能会经过进一步的处理和分发，以适应不同地区或用户群的需求。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（6）电视接收：最终，观众通过他们的电视或接收设备观看这些节目。这些设备将卫星信号解码，转换成音频和视频输出，供用户观看和听取。</span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="text-align:center;font-size:16px;color:#fefefe;margin-bottom:unset;"><strong>3</strong></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>数字电视卫星的安全攻击面</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135769" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="37" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=d3ac5042&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWhucrX7YicTDxTtwjVtSayEMJoicHsvs3HDduLbgIIRibuicLBf18LEx8QvcLlccCynZ0MwniawCsktemw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><h3 style="line-height: normal;margin-bottom: 16px;"><br/></h3><h3 style="line-height: 2em;text-indent: 2em;margin-bottom: 16px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">卫星电视系统包括地面发射控制系统、星载转发系统和地面接收系统三大部分。</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">与卫星相关的攻击面主要包括以下四部分</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">。</span></h3><h3 style="line-height: normal;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">3.1 卫星信号干扰</span></strong></span><span lang="EN-US"><o:p></o:p></span></h3><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">信号干扰是常用的卫星攻击技术。攻击者淹没或压制信号、发射机或接收机，干扰合法传输。</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;"></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">干扰已成为卫星服务受损或拒绝服务的主要原因。黑客使用定向天线，输出专门的干扰信号，其功率足以覆盖原始传输的信号。卫星信号干扰的两种形式主要是轨道干扰和地面干扰。</span><span lang="EN-US"><o:p></o:p></span></p><h4 style="margin-bottom: 8px;"><strong><span lang="EN-US">3.1.1 </span><span style="font-family:黑体;mso-ascii-font-family:
Arial;mso-hansi-font-family:Arial;">轨道干扰</span></strong><span style="font-family:黑体;mso-ascii-font-family:
Arial;mso-hansi-font-family:Arial;"></span><span lang="EN-US"><o:p></o:p></span></h4><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在轨道干扰中，攻击者通过恶意上行链路站直接向卫星发送覆盖频率波段的信号。这样卫星会收到混合的干扰信号与合法信号，因而无法正常工作。干扰信号能够覆盖合法传输并阻断其向接收方的传输。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">针对上行链路的洪泛攻击被认为是最具破坏性的攻击，因为它能够大面积地影响所有可能的接收方的通信。</span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;">上</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;">行链路干扰对卫星的物理影响相对较小，因为它可以干扰卫星在大范围内的传输，但只是暂时的，并且不会永久损害目标系统。</span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">针对控制命令的上行链路干扰可以阻止卫星接收来自地面的命令。它还可以针对用户传输的数据，从而干扰接收方的正常数据的接收。</span><span lang="EN-US"><o:p></o:p></span></p><h4 style="margin-bottom: 8px;"><strong><span lang="EN-US">3.1.2 地面干扰</span></strong><span lang="EN-US"><o:p></o:p></span></h4><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">地面干扰不是像轨道干扰那样以卫星本身为目标，而是向当地消费者级卫星天线的方向发射恶意的卫星信号。干扰频率限于特定区域，并且仅能够干扰特定位置的卫星发出的频率。小型便携式地面干扰机易于购买和使用；它们在城市地区的射程通常为3-5公里，而在农村地区，它们的射程可以增加到20公里。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">下行链路干扰是一种可逆攻击，它只影响干扰机视线范围内的用户。针对对地面设备的干扰攻击可能会影响卫星架构的有限部分，从而造成轻微损害。</span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">干扰攻击的一个显著特点是它们可以使用现成的技术进行，并且很难检测到攻击方，特别是间歇性干扰。</span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">2006年，Robert Kehler中将在美国众议院军事委员会战略部队小组委员会作证时强调，美国军方租赁的商业系统已经受到干扰。在“伊拉克自由行动”期间，对16个月期间商业卫星通信链路的分析发现，有50起记录在案的商业卫星通信干扰军事通信的事件；其中五次攻击肯定是由敌对干扰源实施的。</span></p><p style="text-indent: 0em;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;">3.2 卫星流量窃听</span></strong></span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;"></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">与干扰不同，窃听传输允许攻击者访问传输的数据。尽管几乎每一个卫星通信都是加密的，但是我们可以从很多公开的信息渠道获得如何使用现成的产品来拦截卫星传输，无论这些传输是携带卫星广播媒体、卫星电话对话还是互联网流量。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">2012年初，德国安全研究人员证明，使用市场上现成的设备，只要一台个人电脑和一根天线，就可以很容易地拦截和破译卫星电话。卫星电话运营商采用了两种加密标准算法 GMR-1和GMR-2来保护运营商的卫星电话信号的安全。在非洲、中东和北亚的Thuraya卫星电话都采用了这两种加密算法。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">GMR-1是由GSM标准实现的A5/2算法的变体。它很容易受到纯密文攻击。GMR-2标准引入了一种新的加密算法，但是它的加密强度不够，只有64bits。2017年，两名中国安全研究专家发现GMR-2算法存在严重缺陷，采用新型实时反转攻击方法，几乎可以实时破解GMR-2的加密密钥。研究人员称：“在一个3.3GHzCPU的计算机平台上，我们可以在0.02秒内破解出GMR-2密码。我们的研究成果再次证明，在GMR-2密码标准中存在严重的安全缺陷，因此卫星通讯服务提供商应该尽快升级各自所采用的加密系统，以提升通讯的保密性。”</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">增强卫星传输数据的加密会带来一系列的问题。首先是运营成本的增加；另一个需要考虑的因素是对整体性能的影响。安全专家称加密卫星信号会导致性能下降80%。</span></p><h3 style="line-height: normal;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;">3.3 卫星信号重放攻击</span></strong></span></h3><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">卫星信号重放攻击主要是针对地面站的上行链路信号重放，地面发射站的上行链路信号包括卫星控制命令及用户传输数据。卫星的控制命令是卫星控制指针对卫星的控制技术，包括卫星姿态控制、温度控制、动力控制等。攻击者提前录制并重放卫星遥控命令可以伪造合法用户控制卫星，严重的可以调整卫星的空中姿态，注入恶意代码等。</span><br/></p><h3 style="line-height: normal;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;">3.4 高能脉冲攻击</span></strong></span><span lang="EN-US"><o:p></o:p></span></h3><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">反卫星激光武器可以通过地基或天基向目标卫星发射高功率脉冲，高脉冲能量通过卫星接收天线对卫星内部电子器件造成不可逆的伤害，可能导致整个卫星测控模块完全失效，造成卫星的拒绝服务。</span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="text-align:center;font-size:16px;color:#fefefe;margin-bottom:unset;"><strong>4</strong></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>事件分析</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135770" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="37" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=d3ac5042&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWhucrX7YicTDxTtwjVtSayEMJoicHsvs3HDduLbgIIRibuicLBf18LEx8QvcLlccCynZ0MwniawCsktemw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><h2 style="margin-bottom: 16px;"><br/></h2><h3 style="line-height: normal;margin-bottom: 16px;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;color: rgb(0, 82, 255);">4.1 卫星介绍</span></strong><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Georgia&#34;,&#34;serif&#34;;mso-bidi-font-family:
Georgia;color:#333333;background:white;"><o:p></o:p></span></h3><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;margin-bottom: 8px;text-indent: 2em;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">乌克兰电视频道StarLightMedia和Inter TV是乌克兰的两大电视台，其中StarLightMedia采用了以色列Spacecom公司的Amos-3及Amos-7卫星进行数字电视卫星广播。Inter TV采用了以色列Spacecom公司的Amos-3卫星进行数字电视卫星广播。</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="205" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;"><strong>参数</strong></span></p></td><td width="262" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;"><strong>数值</strong></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">位置</span></p></td><td width="242.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;word-break: break-all;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);"><span lang="EN-US" style="color: rgb(0, 0, 0);font-size: 12px;font-family: Verdana, &#34;sans-serif&#34;;background: white;"> 4° W (4° </span><span style="color: rgb(0, 0, 0);font-size: 12px;background: white;">西经</span><span lang="EN-US" style="color: rgb(0, 0, 0);font-size: 12px;font-family: Verdana, &#34;sans-serif&#34;;background: white;">)</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">卫星运营商</span></p></td><td width="262" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;word-break: break-all;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">以色列Spacecom卫星通信公司</span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">开始运营时间</span></p></td><td width="262" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">2008年1月28日</span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">制造商</span></p></td><td width="262" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">以色列航空工业公司</span></p></td></tr><tr style="mso-yfti-irow:5;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">预期寿命</span></p></td><td width="262" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">17年</span></p></td></tr><tr style="mso-yfti-irow:6;mso-yfti-lastrow:yes;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">波段及覆盖地区</span></p></td><td width="262" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">12 Ku波段及2 Ka波段，区域覆盖中东，欧洲，非洲及北美部分地</span></p><p><span style="font-size: 12px;color: rgb(0, 0, 0);">区。</span></p></td></tr></tbody></table><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">表1 Amos-3卫星基本参数表</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135771" data-ratio="0.6151866151866152" data-s="300,640" style="" data-type="png" data-w="777" src="https://wechat2rss.xlab.app/img-proxy/?k=2c5259e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRlj0JO6OP3WOic68KtibvLVENHYjdW1OKiaDTKbLQ9hIKGIWHYiaViajIdRWs331VJjkm75mRsgOB9Qsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="text-align: justify;"></span></p><p style="text-align: center;text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图2 Amos-3卫星Ku波段垂直方向在欧洲覆盖情况</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="205" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0cm 5.4pt;"><p><strong><span style="font-size: 12px;">参数</span></strong></p></td><td width="262" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;padding: 0cm 5.4pt;"><p><strong><span style="font-size: 12px;">数值</span></strong></p></td></tr><tr style="mso-yfti-irow:1;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">位置</span></p></td><td width="242.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;"><span lang="EN-US" style="font-size: 12px;font-family: Verdana, &#34;sans-serif&#34;;color: black;background: white;"> 4° W (4° </span><span style="font-size: 12px;color: black;background: white;">西经</span><span lang="EN-US" style="font-size: 12px;font-family: Verdana, &#34;sans-serif&#34;;color: black;background: white;">)</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">卫星运营商</span></p></td><td width="262" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;word-break: break-all;"><p><span style="font-size: 12px;">以色列Spacecom卫星通信公司</span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">开始运营时间</span></p></td><td width="262" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2014年8月5日</span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">制造商</span></p></td><td width="262" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;"><span style="font-size: 12px;color: windowtext;text-decoration: none;">Maxar Technologies (SSL/MDA)</span></span></p></td></tr><tr style="mso-yfti-irow:5;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">预期寿命</span></p></td><td width="262" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">15年</span></p></td></tr><tr style="mso-yfti-irow:6;mso-yfti-lastrow:yes;"><td width="205" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">波段及覆盖地区</span></p></td><td width="262" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">24个Ku波段转发器和一个Ka波段波束，提供覆盖欧洲、中东和非洲部分地区的多区域体验，从而为中欧和东欧、非洲和中东的现有和新客户提供服务。</span></p></td></tr></tbody></table><p style="padding-right: 16px;padding-left: 16px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 14px;color: rgb(62, 62, 62);line-height: 2;letter-spacing: 2px;visibility: visible;text-align: center;margin-bottom: 8px;"><span style="text-align: center;color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;">表</span><span style="text-align: center;color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;">2 Amos-7</span><span style="text-align: center;color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;">卫星基本参数表</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;"></span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135773" data-ratio="0.9980916030534351" data-s="300,640" style="" data-type="png" data-w="524" src="https://wechat2rss.xlab.app/img-proxy/?k=e0664080&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRlj0JO6OP3WOic68KtibvLVEXvb8rZYqkkaZbMYyIbxFB4kL3N4MLWGerFv6pwVqpraib2Qy1ibwbRhg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;"></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图3 Amos-7卫星Ku波段垂直方向在欧洲覆盖情况</span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Inter TV共有两个频道分别是Inter频道及Inter+频道，StarLightMedia旗下共有STB、Novy Channel、ICTV、M1、M2、QTV五个电视频道，这五个电视频道都采用</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">了Amo</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">s3卫星提供数字电视转播服务， 其中高清频道采用Amos7卫星提供数字电视转播服务</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">。</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="130" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0cm 5.4pt;word-break: break-all;"><p><strong><span style="font-size: 12px;">频道</span></strong></p></td><td width="69" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;padding: 0cm 5.4pt;"><p><strong><span style="font-size: 12px;">卫星</span></strong></p></td><td width="50.33333333333333" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;padding: 0cm 5.4pt;word-break: break-all;"><p><strong><span style="font-size: 12px;">波段</span></strong></p></td><td width="70.33333333333333" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;padding: 0cm 5.4pt;"><p><strong><span style="font-size: 12px;">频率(MHZ)</span></strong></p></td><td width="88.33333333333333" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;padding: 0cm 5.4pt;"><p><strong><span style="font-size: 12px;">调制方式</span></strong></p></td></tr><tr style="mso-yfti-irow:1;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Inter</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos3</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">11389</span></p></td><td width="88.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S</span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Inter+</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos3</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">11389</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S</span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">M1</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos3</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">10722</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S</span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">M2</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos3</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">10926</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S</span></p></td></tr><tr style="mso-yfti-irow:5;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">ICTV</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos3</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">11175</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S</span></p></td></tr><tr style="mso-yfti-irow:6;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">M1 HD</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos3</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">11222</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S2</span></p></td></tr><tr style="mso-yfti-irow:7;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">M2 HD</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos3</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">11222</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S2</span></p></td></tr><tr style="mso-yfti-irow:8;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">STB HD</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos7</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">12297</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S2</span></p></td></tr><tr style="mso-yfti-irow:9;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">ICTV HD</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos7</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">12297</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S2</span></p></td></tr><tr style="mso-yfti-irow:10;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">NOVY CHANNEL HD</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos7</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">12297</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S2</span></p></td></tr><tr style="mso-yfti-irow:11;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">M1 HD</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos7</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">12297</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S2</span></p></td></tr><tr style="mso-yfti-irow:12;mso-yfti-lastrow:yes;"><td width="130" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">M2 HD</span></p></td><td width="69" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Amos7</span></p></td><td width="70" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Ku</span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">12297</span></p></td><td width="108.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">DVB-S2</span></p></td></tr></tbody></table><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: center;margin-bottom: 16px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">表3 被攻击的卫星电视频道基本参数表</span><span lang="EN-US"><o:p></o:p></span></p><h3 style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;line-height: normal;text-align: justify;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">4.2 攻击方式分析</span></strong></span><span lang="EN-US"><o:p></o:p></span></h3><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">乌克兰电视频道StarLightMedia和Inter的卫星广播发生了3次干扰——分别是10:00至10:18、11:27至11:29和12:51至12:55。本次攻击事件中实现了卫星电视节目的恶意插播，除了卫星电视节目外，这些电视台的OTT、IPTV等信道的节目是可以正常接收的</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135774" data-ratio="0.6369268897149938" data-s="300,640" style="" data-type="png" data-w="807" src="https://wechat2rss.xlab.app/img-proxy/?k=36a96318&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRlj0JO6OP3WOic68KtibvLVESyicppAC9J1lkspLYQMQzEc44a3A8syKAXVdXGZ2LTvMkibSgCWLuJPA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-align: justify;"></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图4 卫星电视攻击事件现场效果</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">从卫星电视插播的攻击效果来看，攻击者可能采用的攻击方式有轨道干扰，地面干扰及网络渗透攻击三种方式</span>。</p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="85.33333333333333" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0cm 5.4pt;word-break: break-all;"><p style="text-align:justify;text-justify:inter-ideograph;"><strong><span style="font-size: 12px;">攻击方式</span></strong></p></td><td width="176.33333333333334" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;padding: 0cm 5.4pt;word-break: break-all;"><p><strong><span style="font-size: 12px;">影响面</span></strong></p></td><td width="63.33333333333333" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;padding: 0cm 5.4pt;"><p style="text-align:justify;text-justify:inter-ideograph;"><strong><span style="font-size: 12px;">成像质量</span></strong></p></td><td width="98.33333333333333" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;padding: 0cm 5.4pt;"><p style="text-align:justify;text-justify:inter-ideograph;"><strong><span style="font-size: 12px;">可复用性</span></strong></p></td></tr><tr style="mso-yfti-irow:1;"><td width="105" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">轨道干扰</span></p></td><td width="176.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">影响范围大，可覆盖国土面积，只能影响卫星电视信道。</span></p></td><td width="63.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">一般</span></p></td><td width="78.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">高</span></p></td></tr><tr style="mso-yfti-irow:2;height:17.1pt;"><td width="105" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="17"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">地面干扰</span></p></td><td width="196.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="17"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">影响范围小。</span></p></td><td width="83.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="17"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">一般</span></p></td><td width="98.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="17"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">高</span></p></td></tr><tr style="mso-yfti-irow:3;mso-yfti-lastrow:yes;"><td width="105" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">网络渗透</span></p></td><td width="196.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">影响范围大，可覆盖国土面积。并可以影响到卫星，OTT、IPTV、微波等信道。</span></p></td><td width="83.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">高</span></p></td><td width="98.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">一般</span></p></td></tr></tbody></table><p style="padding-right: 16px;padding-left: 16px;outline: 0px;background-color: rgb(255, 255, 255);line-height: 2;visibility: visible;text-align: center;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;">表4 被攻击的卫星电视频道基本参数表</span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">如果是采用地面干扰，影响的范围有限，只能覆盖有限的乌克兰地区。另外容易暴露攻击者位置。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">如果是网络渗透攻击的方式，这意味着需要攻击者渗透到两个电视台的电视播控系统或传输网络，因为这些电视台的OTT，IPTV等信道的节目是可以正常接收的。当然攻击者也有可能渗透了同时两个电视台的卫星电视信号发射系统，但这样的攻击难度较大，而且从现场电视图像质量来看，成像质量一般，也不符合网络攻击的特点。</span><span lang="EN-US"><o:p></o:p></span></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;margin-bottom: 8px;line-height: 2em;text-indent: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">因为这种攻击手法采用攻击时间较短，但覆盖面及影响面比较大，可以影响到乌克兰大面积的国土面积。采用卫星信号干扰攻击的方式，由于攻击源头由攻击者控制，车载的攻击源可以移动，攻击可以在境外不同位置完成，很难从源头定位并切断攻击来源。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">从攻击的情况来看，考虑到两个电视台都用到了Amos3卫星, 而且频率范围接近，本次攻击发生针对Amos3卫星的可能性比较大</span>。</p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;line-height: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">据报道，2024年4月17日乌克兰1+1 Media旗下的卫星电视频道也遭受了严重的攻击，攻击者干扰 Astra 4A和Hotbird 13E 星上属于乌克兰电视频道的卫星信号。这家媒体巨头透露，包括其该媒体旗下的39个频道无法访问，这对该国媒体基础设施造成了重大打击。官方建议采用其他方式获取电视信号，包括 T2、有线、OTT 和基于互联网的平台，以减轻未来攻击对卫星广播的影响。</span></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;line-height: 2em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">综合上述分析，我们认为攻击者采用轨道干扰的攻击方法进行插播的可能性最大。</span></p><p style="text-align: center;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135775" data-ratio="0.33451957295373663" data-s="300,640" style="" data-type="png" data-w="843" src="https://wechat2rss.xlab.app/img-proxy/?k=548a2a94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRlj0JO6OP3WOic68KtibvLVEKSPkAVYNUnXXCLc7feSqNqyU1Tibv2PuDjW0qsicJppeZHDTDIH7T9Dw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图5 卫星电视信号发射系统插播示意</span></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;line-height: 2em;margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">下面我们来分析一下数字卫星电视插播的原理。</span><o:p></o:p></p><h4 style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;line-height: 2em;margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">4.2.1 卫星电视插播的技术原理</span></strong><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span><o:p></o:p></h4><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;line-height: 2em;margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">卫星转发器的主要部件是大功率放大器。Ku波段的功率输出转发器通常采用行波管放大器或固定功放，当输入功率小于饱和点时，放大器工作在线性区。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;line-height: 2em;margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">如果输入功率超过额定值时，功率放大器就进入饱和区或过饱和区。大功率放大器会出现非线性效应。当功率放大器工作在过饱和区，其输出功率大大降低，而且会出现功率大的信号挤压功率小的信号的情况，并伴随出现大量噪声和误码率。</span><o:p></o:p></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">黑客通过采用与地面站发射站相同上行频率，极化参数等伪造合法地面发射台接入卫星网络，并加大功率压制合法信号，使得卫星的转发器工作在非线性区，出现功率掠夺现象，导致广播电视信号失真，电视出现马赛克黑屏，严重时将播出非法信号。</span><o:p></o:p></p><h3 style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;line-height: 2em;text-indent: 0em;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">4.3 卫星干扰攻击溯源技术</span></strong></span><o:p></o:p></h3><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;line-height: 2em;margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">针对上行信号的干扰攻击，可以通过“双星定位”技术等技术来追溯攻击者的方位。“双星定位”的原理就是利用两颗运行在地球同步轨道的卫星和用户之间的三角关系，来确定用户在地球表面的位置。双星定位系统可以实现对一个有限区域内的导航定位。双星定位主要涉及到地面接收站及两颗在轨卫星及卫星信号攻击者。在攻击者发送干扰信号的时候，卫星地面接收站根据两颗在轨卫星的位置及两颗卫星接收到攻击者发送的同一信号的时间差，可以计算出攻击者到两颗卫星的距离（星户距）。根据卫星地面接收站的地心坐标，推算出攻击者到地心的距离。根据同步轨道卫星1，卫星2，地面接收站的地心坐标，就可以计算出攻击者的当时的三维位置。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135776" data-ratio="0.5226480836236934" data-s="300,640" style="" data-type="png" data-w="574" src="https://wechat2rss.xlab.app/img-proxy/?k=fd91d9e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRlj0JO6OP3WOic68KtibvLVExGzSO6lIddGDxlhyAXd7n90O7OgC3ibRiaYPCExQFibPl1icHiaMRVuTvicQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: center;text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图6 双星定位溯源示意</span></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: center;text-indent: 0em;margin-bottom: 24px;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><h2 style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;margin-left: 0cm;text-indent: 0cm;text-align: justify;margin-bottom: 16px;"></h2><p style="text-align:center;font-size:16px;color:#fefefe;margin-bottom:unset;"><strong>5</strong></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>安全防范建议</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135777" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="37" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=d3ac5042&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWhucrX7YicTDxTtwjVtSayEMJoicHsvs3HDduLbgIIRibuicLBf18LEx8QvcLlccCynZ0MwniawCsktemw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;margin-bottom: 8px;line-height: 2em;"><br/></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">近年来，我国电视广播建设取得了较大的发展。建成了中央和地方二级IPTV播控平台，实现了节目安全、可靠播出的目标。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">网络空间是地缘政治的映射。随着国际形势的变化，卫星或电视系统的关键基础设施面临严重的安全挑战。我们仍需要在以下方面加强工作：</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（1）加强卫星通信的抗干扰能力</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">通信抗干扰技术比较有效的方法是采用扩频通信。根据扩频的方式不同，主要分为直接序列扩频（DS）、跳频（FH）和跳扩结合等方式。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">法国商业卫星机队运营商欧洲通信卫星组织在其推出的Eutelsat8 West B卫星上部署了实验性尖端电视频道干扰缓解功能。欧洲通信卫星组织在卫星接收天线后面安装新一代变频器能够在不影响用户终端接收的下行链路频率的情况下更改上行链路信号的频率，这意味着卫星可以在被恶意上行链路信号干扰时，地面发射台和卫星接收机可以进行同步变频，保证了服务的稳定性。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">此外，在地面卫星信号上行站也可采用功率较大的发射机和高增益发射天线来增加广播电视节目的上行功率，使干扰小于正常信号，进而达到强功率压制效果。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">2023年底, 我国发射的中星6E卫星在自主可控的基础上，采用多种措施提升卫星抗干扰能力，并优化转移轨道程序控制方案，确保卫星安全，保障广播电视节目安全传输。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（2）加强卫星信号传输链路、地面传输链路的安全监测。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">当非法电视信号插播时，由于TS传输信号的编码结构，复用结构等参数都会发生突变，在输出侧解码时会出现短时间的马赛克及黑屏现象。地面接收站通过对码流或音视频质量的实时监控可以发现异常并报警。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（3）运用卫星通信加密技术，保障播出内容安全。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">通过对卫星电视的上行数据及控制信号的加密，可以有效防止插播攻击及敏感信息泄露。由于上行数据是加密的，接收端收到加扰视频数据后需要解扰解码后才能正确显示。如果解密不成功则会拒绝显示电视视频内容。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在这种情况下，攻击者需要获得密钥才能发起插播攻击，否则只能造成黑屏的攻击效果。根据卫星电视单点发射多点接收的特点，合理地运用公钥体系技术可以很好地保障了内容的安全。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（4）加强素材来源、EPG、第三方CP、OTT直播的管控，从输入侧减低风险隐患。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">对于节目制作的素材，我们要做到素材来源都要先进行安全杀毒检测，对于来历不明的素材坚决不使用。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">由于OTT传输由于采用互联网传输，容易受到网络攻击。关闭OTT直播通道，关闭不安全的内容入口，保障电视传播的安全。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">EPG（电子节目指南系统）、CP（第三方内容提供商）这些影响到安全播出的第三方系统往往是我们防御的薄弱环节，容易成为攻击者的目标。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（5）强化网络边界防护,在网络关键节点部署上网行为管理、入侵防御检测、边界防火墙等安全设备，有效拒绝非授权访问，主动防御阻断外部攻击。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">2015年4月8日晚间，法国电视5台（TV5 Monde）法语频道受到黑客攻击。</span><o:p></o:p></p><p style="color: rgb(62, 62, 62);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 2px;text-wrap: wrap;text-align: justify;text-indent: 2em;margin-bottom: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">法国电视5台向媒体介绍说，8日晚10时左右，袭击从电视台的社交网络开始，紧接着，电视台内部信息系统以及全球范围内的发射台同时陷入瘫痪。工作人员在两小时后恢复了对社交网络的控制，但直到9日早上，电视台网站仍无法使用，电视节目也只能在部分地区播放。</span><o:p></o:p></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">近年来针对电视广播系统的攻击大部分都是通过网络攻击渗透完成的。为规避风险，需要我们整体规划电视广播系统的安全建设，从根源上增强网络健壮性和抗风险能力。推进安全防护系统建设，提升网络安全主动防御能力。</span><span style="mso-bidi-language:AR;"><span lang="EN-US"><o:p></o:p></span></span></p><p><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br style="outline: 0px;"/></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 15px;"><strong style="outline: 0px;"><span style="outline: 0px;letter-spacing: 2px;">参考链接：</span></strong></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;font-size: 12px;color: rgb(0, 0, 0);">[1]https://news.china.com/socialgd/10000169/20240510/46499879.html</span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;font-size: 12px;color: rgb(0, 0, 0);">[2]https://www.infosecinstitute.com/resources/scada-ics-security/hacking-satellite-look-up-to-the-sky/</span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;font-size: 12px;color: rgb(0, 0, 0);">[3]http://www.xinhuanet.com/science/2022-08/19/c_1310654162.htm</span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;font-size: 12px;color: rgb(0, 0, 0);">[4]https://m.spacechina.com/n2014789/n2014809/c3972913/content.html</span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p><br/></p><p><br/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;color: rgb(0, 0, 0);font-size: 15px;">启明星辰积极防御实验室（ADLab）</span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，</span><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">“黑雀攻击”概</span><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;color: rgb(0, 0, 0);">念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/CVE累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、数据安全研究、5G安全研究、人工智能安全研究、移动安全研究、物联网安全研究、车联网安全研究、工控安全研究、信创安全研究、云安全研究、无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等<span style="font-size: 14px;color: rgb(0, 0, 0);outline: 0px;letter-spacing: 1.5px;">。</span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135780" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.99px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Tue, 21 May 2024 18:16:44 +0800</pubDate>
    </item>
    <item>
      <title>青春挺膺 强国有我 | 启明星辰积极防御技术研究院荣获2023年度“海淀青年榜样”集体</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619412&amp;idx=1&amp;sn=7ba9ae46a48b3516b70021375ff69f58&amp;chksm=830626c4b471afd21149cfc6f8b66c572df84b70051bfcc1cb22acdd19ad7598b01843017868&amp;scene=58&amp;subscene=0#rd</link>
      <description>牢记使命、踔厉奋发，为网络强国建设贡献青春力量。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-05-04 08:59</span> <span style="display: inline-block;">北京</span>
</p>

<p>牢记使命、踔厉奋发，为网络强国建设贡献青春力量。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=9c7e94ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nRQbSxanic6tJ0iazMTx1lYxRCFo31qribWWoEMho1rR6ia53C6LdDPoVIE2DJpzI98IeqI5sPO4TjiazA%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 0px;"><span style="outline: 0px;line-height: 17.25px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">为深入学习贯彻习近平新时代中国特色社会主义思想，全面贯彻落实党的二十大和二十届二中全会精神，充分发挥青年榜样模范带头作用，引领和激励全区团员青年在新征程上续写海淀高质量发展新篇章，海淀团区委开展</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">2023</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">年度“海淀青年榜样”教育实践活动，并开展了</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">青年榜样个人</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">与</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">集体</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">的评选。</span></p><p style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);"><br style="outline: 0px;"/></span></p><p style="outline: 0px;"><strong style="outline: 0px;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);color: rgb(0, 122, 170);">启明星辰积极防御技术研究院</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">在本次激烈的评选中脱颖而出，荣获2023年度</span><strong style="outline: 0px;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);color: rgb(0, 122, 170);">“海淀青年榜样”集体</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">。这一荣誉不仅是对该集体在网络安全攻防技术领域贡献的肯定，更是对新时代网信青年牢记使命、踔厉奋发，为网络强国建设贡献青春力量的崇高礼赞。</span></p><p style="outline: 0px;"><br style="outline: 0px;"/></p><p><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="549" data-cropsely1="0" data-cropsely2="366" data-imgfileid="502135759" data-ratio="0.7305555555555555" data-s="300,640" data-type="jpeg" data-w="1080" style="outline: 0px;vertical-align: middle;width: 549px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=888e3e48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FBwR7Xg3aXhaQBZWMdWzt4uSFOliaEZVRUibgeWnuSH4DkcRPm0nZ7Qz0T739yOcpgU6Ud32O5M4mPeMfPJYGZ4SA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p style="outline: 0px;"><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">启明星辰积极防御技术研究院，成立于1999年，是微软MAPP计划核心成员，</span><strong style="outline: 0px;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);color: rgb(0, 122, 170);">“黑雀攻击”</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">概念首推者。该集体一直致力于攻防技术人员培养、网络安全、信息安全深层攻防技术研究，开拓安全领域前瞻性技术研究，发现计算机以及网络系统中存在的各种安全缺陷，帮助用户获得全面、持久的安全。</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">截至目前，该集体已通过CVE发布Windows、Linux、Unix等操作系统安全或软件漏洞近</span><strong style="outline: 0px;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);color: rgb(0, 122, 170);">1200</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">个，通过NVDB/CNVD/CNNVD/累计发布安全原创漏洞</span><strong style="outline: 0px;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);color: rgb(0, 122, 170);">4000</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">余个，并连续多年获得相关主管部门表彰。</span></p><p style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"><br style="outline: 0px;"/></span></p><p style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">习近平总书记在党的二十大上寄语广大青年，要坚定不移听党话、跟党走，怀抱梦想又脚踏实地，敢想敢为又善作善成。</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;">启明星辰积极防御技术研究院的青年们正是这样一群有理想、敢担当、能吃苦、肯奋斗的新时代好青年。他们深入学习贯彻习近平新时代中国特色社会主义思想和党的二十大精神，内化于心、外化于行，在学知识中悟思想，在办实事中强担当，为党的网络安全事业勇攀高峰，为实现网络强国贡献火热青春。</span></p><p style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);"><br style="outline: 0px;"/></span></p><p style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">青春挺膺，强国有我。在集团党委的坚强领导下，自2021年起，启明星辰团委在集团内部发起并推动了面向启明星辰青年及集体的</span><strong style="outline: 0px;"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);color: rgb(0, 122, 170);">“创优评优”</span></strong><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">主题实践活动，通过该活动的深入开展，先后涌现出了包括：</span><span style="outline: 0px;color: rgb(0, 0, 0);"><span style="outline: 0px;font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">“2022-2023年度北京市青年文明号”</span></span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">集体、“2022年度海淀青年榜样”集体、 “2023年度海淀青年榜样”集体等在内的多个优秀青年集体以及多名优秀青年，坚定引领启明星辰青年建功新时代、奋进新征程。</span></p><p style="outline: 0px;"><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;text-align: left;"><br style="outline: 0px;"/></span></p><p style="margin-right: auto;margin-left: auto;outline: 0px;width: 5em;"><img class="rich_pages wxw-img __bg_gif" data-imgfileid="502135758" data-ratio="0.2920353982300885" data-w="113" style="outline: 0px;display: block;visibility: visible !important;width: 70px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ae456b0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWg0S67fc5Tc43xia8h8eIvqL8VMwsmibu53yG4DpLsn7tVdyGvkalEVPexzxB8g511VCicfLsMDeHD4A%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwxpic"/></p><p style="outline: 0px;"><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">奋斗是青春最亮丽的底色，行动是青年最有效的磨砺。作为中国移动专责网信安全专业子公司，启明星辰将积极肩负“安全核心技术攻坚者、安全产品服务引领者、安全运营体系支撑者”重要角色，引领广大青年听党召唤，勇当国家网络安全的排头兵和生力军，</span><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;background-color: rgb(253, 253, 254);">在推进强国建设、民族复兴伟业中展现青春作为、彰显青春风采、贡献青春力量，奋力书写为中国式现代化挺膺担当的青春篇章。</span></p><p style="outline: 0px;"><span style="outline: 0px;color: rgb(0, 0, 0);font-family: Optima-Regular, PingFangTC-light;font-size: 15px;"></span></p><p style="outline: 0px;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;font-size: 14px;">•</span></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;font-size: 14px;">END<br style="outline: 0px;"/></span></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;font-size: 14px;">•</span></p><p><span style="outline: 0px;line-height: 17.25px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 17.25px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 17.25px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p><br/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="outline: 0px;line-height: 1.8;"></span></p><p><br/></p><p style="outline: 0px;"><br/></p><p><br/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="outline: 0px;"></span><span style="outline: 0px;">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/<span style="outline: 0px;">CVE</span>累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="outline: 0px;">数据安全研究、<span style="outline: 0px;">5G安全研究、</span><span style="outline: 0px;">人工智能安全研究、</span></span></span><span style="outline: 0px;">移动安全研究、物联网安全研究、车联网安全研究、</span><span style="outline: 0px;">工控安全研究、信创安全研究、</span><span style="outline: 0px;">云安全研究、</span><span style="outline: 0px;">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="outline: 0px;letter-spacing: 1.5px;">。</span><span style="outline: 0px;letter-spacing: 1.5px;"></span></span><span style="outline: 0px;"></span></p><p><br/></p><p style="outline: 0px;"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135760" data-ratio="1.1205673758865249" data-s="300,640" data-type="jpeg" data-w="282" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 281.998px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Sat, 04 May 2024 08:58:16 +0800</pubDate>
    </item>
    <item>
      <title>警惕新型僵尸Goldoon：一款指令集覆盖最广的零检出率僵尸家族</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619396&amp;idx=1&amp;sn=f31cb39ab32a5fd77f3fa976bc1f3ed6&amp;chksm=830626d4b471afc2e62cc4230b032ae10bc316e1698fec09aa7fd2a47a07a74250aea07f8df8&amp;scene=58&amp;subscene=0#rd</link>
      <description>启明星辰ADLab监测到一批VT平台零检出率的新物联网僵尸，我们对僵尸程序的二进制代码和通信协议做了深入同源性分析，判断该系列僵尸为一款从未出现过的新型僵尸家族“Goldoon”。本文将对其攻击活动特点、功能代码以及控制协议等进行深入分析。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-04-29 18:04</span> <span style="display: inline-block;">北京</span>
</p>

<p>启明星辰ADLab监测到一批VT平台零检出率的新物联网僵尸，我们对僵尸程序的二进制代码和通信协议做了深入同源性分析，判断该系列僵尸为一款从未出现过的新型僵尸家族“Goldoon”。本文将对其攻击活动特点、功能代码以及控制协议等进行深入分析。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=fc9cef67&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAia13ZUZ3ibSbUPWmxDSEw1YV9Dp5NQu96MONicoy58RR2BrEuicWia6eYOtQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p style="font-size:20px;color:#c9eaff;line-height:1;"><span style="font-size: 17px;"><em><strong>01</strong></em></span></p><p><br/></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><span style="font-size: 16px;"><strong>概 述</strong></span></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p style="margin-bottom: 8px;text-indent: 2em;"><br/></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">近期，启明星辰ADLab监测到一批VT平台零检出率的新物联网僵尸，我们对僵尸程序的二进制代码和通信协议做了深入同源性分析，并判断该系列僵尸为一款从未出现过的新型僵尸家族。该僵尸的文件命名、代码特征中常常包含” Goldoon“的字符串，因此我们将此僵尸网络家族命名为“Goldoon“。此外该僵尸具有极强的平台兼容性，是目前支持指令集最全的僵尸家族（目前已发现的支持指令集多达18种），除了支持主流的x86、arm、mips、mipsel、powerpc、s</span><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">parc、riscv、sh4、m68k等指令集外，其还支持一些非常罕见的指令集alpha、hppa等。值得注意的是，alpha指令集目前除了我国某国产处理器（主要用于我国超级计算机）在使用外，其他国家几近绝迹，其可能造成的威胁值得我们重视。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">我们最初于2024年4月8日发现Goldoon僵尸，起初，我们对这些零报毒的ELF文件进行了快速分析确认，发现其存在恶意行为，但<span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">对于</span>这些文件安全软件在近两周时间内都未能检测预警，这引起了我们的浓厚兴趣并进一步对其追踪分析，最后我们发现了80多个样本。通过逆向工程这些样本发现，该僵尸通过模块化设计和分阶段作业的方式降低被检测的风险，比如将入侵扫描、远程下发、本地加载及僵尸守候等功能设计成独立模块。此外相比于常规的物联网僵尸，Goldoon僵尸的攻击设备类型可覆盖超过18种处理器架构，并且几乎支持包括windows、unix/linux以及所有POSIX标准的系统，除此之外，其还将“魔爪”伸向了一些相对小众的指令集架构，这对于物联网设备尤其是一些长期未遭遇攻击的小众架构设备来说可能构成严重的威胁。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">目前，大量新出现的被各大厂商重新命名的物联网僵尸网络大部分还是基于开源僵尸框架如Mirai、Gafgyt等进行定制开发，此次我们发现的Goldoon则是完全重新设计和开发的新僵尸程序，目前，攻击者还在持续针对多阶段样本进行功能的更迭和测试。截止本文发布，尚未发现控制者发起大规模攻击活动，不过我们已经监测到其发出的一些零星的指令用于测试攻击，这说明Goldoon当前可能处于快速构建阶段，需要高度警惕其后续的扩张和攻击活动。本文将具体介绍Goldoon僵尸网络并针对其攻击活动特点、功能代码以及控制协议等进行深入分析。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135711" data-ratio="0.4564814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=793694e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiauA4VyibgxGXTLOogHesK3xsteVCmh6jbd0dZsM9caHRdQk2bF3fiagicw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图1: Goldoon Loader在VT的检测情况</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135712" data-ratio="0.4685185185185185" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ea62e606&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiagu1smFm8yZibPNC4CjF4kcich2iajS3TqN4fjsRdRCicuMKLateMLV2u7A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图2: Goldoon dropper在VT的检测情况</span></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><br/></p><p><br/></p><p style="font-size:20px;color:#c9eaff;line-height:1;"><span style="font-size: 17px;"><em><strong>02</strong></em></span></p><p><br/></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><span style="font-size: 16px;"><strong>攻击威胁分析</strong></span></p><p style="margin-bottom: 8px;text-indent: 2em;"><br/></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">通过我们的物联网威胁数据平台及相关情报的交叉印证，目前共发现和关联到Goldoon相关样本80余个。从这批样本的攻击目标来看，Goldoon僵尸网络除了针对传统的PC端设备如Windows、Linux（x86、x64）实施攻击外，还盯上了物联网设备这块肥肉，包括arm、mips、mipsel、powerpc、sparc、riscv、sh4、m68k等常见处理器架构的设备都在其攻击范围之内。Goldoon共计支持18种处理器架构，有意思的是其中还涉及到s390x、alpha、hppa等相对小众的指令集，这些指令集虽然普及率较低，但仍有不少小众设备、旧设备或是基于相关指令集自研升级的国产设备在使用，比如IBM zSystems服务器（s39</span><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">0x）、某国产处理器（alpha）等，该国产处理器目前主要用于我国超级计算机，涉及到国家算力安全。</span><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">因此不能仅仅因为设备小众、潜在攻击少就放松警惕，高枕无忧，同样需要重视其中可能隐藏的安全风险。Goldoon当前支持攻击的指令集架构如下表所示：</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">表1：Goldoon支持的指令集架构</span></p><table cellspacing="0" cellpadding="0" style="margin-bottom: 8px;text-indent: 2em;"><tbody style="margin-bottom: 8px;text-indent: 2em;"><tr style="margin-bottom: 8px;text-indent: 2em;"><td width="96.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;word-break: break-all;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">aarch64</span></p></td><td width="92.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">Arm</span></p></td><td width="102.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">x86-64</span></p></td><td width="134.33333333333334" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">i686</span></p></td></tr><tr style="margin-bottom: 8px;text-indent: 2em;"><td width="96.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">m68k</span></p></td><td width="92.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">mips64</span></p></td><td width="102.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">mips64el</span></p></td><td width="134.33333333333334" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">mipsel</span></p></td></tr><tr style="margin-bottom: 8px;text-indent: 2em;"><td width="96.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">mips</span></p></td><td width="92.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">Powerpc</span></p></td><td width="122.33333333333331" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">powerpc64</span></p></td><td width="134.33333333333334" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">powerpc64le</span></p></td></tr><tr style="margin-bottom: 8px;text-indent: 2em;"><td width="96.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">s390x</span></p></td><td width="92.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">sparc64</span></p></td><td width="114.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">sh4</span></p></td><td width="134.33333333333334" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">riscv64</span></p></td></tr><tr style="margin-bottom: 8px;text-indent: 2em;"><td width="96.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">alpha</span></p></td><td width="92.33333333333333" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 12px;">Hppa</span></p></td><td width="122.33333333333331" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><br/></td><td width="134.33333333333334" valign="top" style="margin-bottom: 8px;text-indent: 2em;"><br/></td></tr></tbody></table><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">由于Goldoon目前还处在构建扩张阶段，我们根据已知的攻击手法和投递样本等特点，梳理它的攻击流程</span><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">如下所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135714" data-ratio="0.9231481481481482" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d1ad4070&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAia20G17eHb2KibF1ibzR3k82vWs5p1j0iaOENrUzGkicuAITG3J0yYRian6kQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图3：Goldoon攻击流程图</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">攻击者针对Linux和Windows平台分别设计了模块分离的方式降低耦合度从而减少被检测风险，包括漏洞扫描、脚本执行、Loader、Dropper等模块。从目前捕获到的样本代码来看，尚未发现漏洞扫描模块，猜想该模块应被设计用于在C2服务器中执行以避免泄露漏洞POC和情报资源。入侵成功后，攻击者进一步利用脚本或Loader程序下载执行最终的僵尸程序(Dropper)。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">为了确认攻击者是否在进行免杀测试，我们统计了这批样本中存在编译时间的PE样本并与上传VT平台的时间进行比较，从下表可以看出样本的编译时间与上传时间间隔通常在数分钟内，非常接近。因此基本可以判断这部分样本是由攻击者自行上传并用于测试免杀效果，以下是部分PE样本的时间信息：</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">表2：PE样本时间信息</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="138" valign="top" style="border-top: 1pt solid rgb(21, 96, 130);border-left: 1pt solid rgb(21, 96, 130);border-bottom: none;border-right: none;background: rgb(21, 96, 130);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;"><strong><span style="color: white;">文件名<o:p></o:p></span></strong></span></p></td><td width="138" valign="top" style="border-right: none;border-bottom: none;border-left: none;border-top: 1pt solid rgb(21, 96, 130);background: rgb(21, 96, 130);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;"><strong><span style="color: white;">编译时间</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="207" valign="top" style="border-top: 1pt solid rgb(21, 96, 130);border-left: none;border-bottom: none;border-right: 1pt solid rgb(21, 96, 130);background: rgb(21, 96, 130);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;"><strong><span style="font-size: 12px;color: white;">上传时间<o:p></o:p></span></strong></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="138" valign="top" style="border-top: 1pt solid rgb(21, 96, 130);border-bottom: 1pt solid rgb(21, 96, 130);border-left: 1pt solid rgb(21, 96, 130);border-right: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);"><strong>GoldooNet.exe</strong><strong><o:p></o:p></strong></span></p></td><td width="138" valign="top" style="border-top: 1pt solid rgb(21, 96, 130);border-left: none;border-bottom: 1pt solid rgb(21, 96, 130);border-right: none;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2024-04-14 14:34:47</span></p></td><td width="187.33333333333334" valign="top" style="border-top: 1pt solid rgb(21, 96, 130);border-right: 1pt solid rgb(21, 96, 130);border-bottom: 1pt solid rgb(21, 96, 130);border-left: none;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2024-04-14 14:40:14</span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="138" valign="top" style="border-top: none;border-right: none;border-bottom: none;border-left: 1pt solid rgb(21, 96, 130);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);"><strong>GoldooNet.exe</strong><strong><o:p></o:p></strong></span></p></td><td width="138" valign="top" style="border-width: initial;border-style: none;border-color: initial;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2024-04-14 14:44:39</span></p></td><td width="207" valign="top" style="border-top: none;border-bottom: none;border-left: none;border-right: 1pt solid rgb(21, 96, 130);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2024-04-14 14:45:32</span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="138" valign="top" style="border-top: 1pt solid rgb(21, 96, 130);border-bottom: 1pt solid rgb(21, 96, 130);border-left: 1pt solid rgb(21, 96, 130);border-right: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);"><strong>Firewall.exe</strong><strong><o:p></o:p></strong></span></p></td><td width="138" valign="top" style="border-top: 1pt solid rgb(21, 96, 130);border-left: none;border-bottom: 1pt solid rgb(21, 96, 130);border-right: none;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2024-04-17 23:48:16</span></p></td><td width="207" valign="top" style="border-top: 1pt solid rgb(21, 96, 130);border-right: 1pt solid rgb(21, 96, 130);border-bottom: 1pt solid rgb(21, 96, 130);border-left: none;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2024-04-17 23:49:43</span></p></td></tr><tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes;"><td width="138" valign="top" style="border-top: none;border-left: 1pt solid rgb(21, 96, 130);border-bottom: 1pt solid rgb(21, 96, 130);border-right: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);"><strong>main.exe</strong><strong><o:p></o:p></strong></span></p></td><td width="138" valign="top" style="border-top: none;border-right: none;border-left: none;border-bottom: 1pt solid rgb(21, 96, 130);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2024-04-20 17:58:44</span></p></td><td width="207" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(21, 96, 130);border-right: 1pt solid rgb(21, 96, 130);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2024-04-20 18:00:16</span></p></td></tr></tbody></table><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">之后，我们针对这批样本进行了多维度的溯源和分析，包括与常见僵尸家族的代码相似度、同源性等比对分析后，确认这是一款新出现的物联网僵尸网络。这批样本最早的活跃时间在4月8日，可以初步判断幕后的控制者应该在4月初完成了僵尸代码的开发布局，目前已经处于功能测试和扩张的前期阶段。我们从中提取到攻击者使用的两个C2服务器：185.106.94.51（奥地利）和94.228.168.60（德国）。在持续监测其活跃动向的过程中，曾监控到2次攻击者发送的指令，其采用udp_legit的攻击方式分别针对位于荷兰和伊朗的IP发起DDoS攻击，判断可能是用于小规模的测试活动。截止目前尚未发现有大规模的攻击活动发生，我们也会持续关注和追踪Goldoon的最新版本变化和攻击动态。</span><o:p></o:p></p><h2 style="margin-bottom: 8px;"><br/></h2><p><br/></p><p><br/></p><p style="font-size:20px;color:#c9eaff;line-height:1;"><span style="font-size: 17px;"><em><strong>03</strong></em></span></p><p><br/></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><strong>攻击样本分析</strong></p><h3 style="margin-bottom: 8px;"><br/></h3><h3 style="margin-bottom: 16px;"><strong><span style="line-height: 115%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(0, 82, 255);">3.1 Linux平台样本</span></strong><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">目前，监测到Goldoon基于Linux平台的样本约50个，其中绝大部分样本做了符号剥离处理。同时，相同架构平台的样本间也大多存在功能相异的情况，不过由于这些功能变化间隔时间较短且多属于独占设备、反调试、持久化等对抗性功能的变化，整体代码框架和通信协议等并未改变，因此不做版本的细分。此外，我们还从中发现了个别保留符号的调试版样本（猜测属于作者误传），同样能够佐证Goldoon处于测试功能及免杀的版本快速更迭阶段。</span><o:p></o:p></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">3.1.1 Shell脚本</span></strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">在相关攻击中已发现了超过5种不同代码格式的脚本文件，代码实现的基本功能类似，均是通过wget、curl、ftp等方式下载执行不同架构的恶意模块Dropper，之后删除自身和下载的模块以清除痕迹。更进一步的，攻击者通过改变一些代码因子，如不同的命令执行参数、函数封装、循环嵌套、结构乱序、换行符、引号包裹等方式来尝试对抗静态特征检测，目前相关脚本在VT上依然是0报毒的状态。部分脚本示例如下图：</span><o:p></o:p></p><p><o:p></o:p></p><p style="text-align: center;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135716" data-ratio="0.6324074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=53727fe4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaibVUqYMtA0XDf5OIgCkB58ArV2w1HU0PsMgN8HgibFhD6BlRUrHyaJHQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图4：Shell脚本</span><o:p></o:p></p><h3 style="margin-bottom: 8px;"><span style="color: rgb(136, 136, 136);"><strong><span style="line-height: 115%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">3.1.2 Loader</span></strong></span><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Loader主要是用于加载后续的恶意模块Dropper，相较Shell脚本加载Dropper的方式，会增加部分对抗检测的机制及功能，这里以Debug版Loader为例介绍。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135717" data-ratio="0.7" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3472b922&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAia3rvIxbvWTuQTRzXs2ianfGmmTic7IoicznexRtXO5ZPLk6NibGNljPSHLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图5：Loader核心代码</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">在Loader和Dropper中，Goldoon的多个样本均包含initkiller函数或是保留该函数未调用，类似的初始化和对抗功能较多，由于这些版本更迭的时间非常接近且不同功能版本的数量很多，因此不做更细的版本区分，一些重要功能例如：独占设备，程序通过禁用CVE-2017-17215漏洞端口(37215)、禁用telnet端口(23)以及禁用SSH端口(22)等方式来尝试独占设备。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135747" data-ratio="0.23425925925925925" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ec1ecaba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaanOtMw1bTibbKrYoZ4SGQO7uRFicS8gBr0k0oJNQxibwhDb9SErFcJia3A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图6：独占设备</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">在Start_dropper函数中，程序会从指定C2下载恶意代码，并在修改文件权限后执行恶意程序。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135719" data-ratio="0.5712962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5a415ab2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiatlpegzkNMYDhxV2HLQTSTUKZJgTQcL0LjoLXqrIVCWbovlWY9HZdWg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图7：下载执行后续恶意代码(Dropper)</span><o:p></o:p></p><h3 style="margin-bottom: 8px;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><strong>3.1.3 Dropper</strong></span><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">首先，后续下载执行的恶意代码(Dropper)会通过SetInjectMethod函数获取程序执行参数来设置BOT_INFECT_METHOD值，此值应指设备被感染的方式（如入侵使用的漏洞或爆破类别），该值之后在上线包中会作为系统信息回传。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135720" data-ratio="0.29907407407407405" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3f7bbc0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiazvBdg0ibYjchtdI4ZOJTpWiaWvCibOibuqVG0A2ZiaWPibibeL54cCMhK480A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图8：获取设备被感染方式</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Start函数中则是程序核心的代码部分，包括初始化配置、上线机制、心跳机制、控制指令解析等。</span><o:p></o:p></p><p><o:p></o:p></p><p style="text-align: center;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135721" data-ratio="0.42407407407407405" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=88eefb51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaYnFn9dLk6htrvpsSoJ8yB2jdSwtkIXaic878ndfl9AqFsDT45w3jWeA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图9：核心代码部分</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">（1）初始化配置</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">包括初始化异常处理、初始化随机种子、初始化DNS解析、初始化攻击管理等，其中还初始化了wolfSSL_Init的加密库，wolfSSL是一个轻量级、可移植、基于C语言面向嵌入式的TLS 库，不过从目前掌握的情况来看，攻击者还没有实际调用该库来加密通信流量，但是后期可能会通过wolfSSL加密以增强流量隐匿性。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135722" data-ratio="0.1962962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e52e0b8c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaLIJjDY6VrviaTJuCdhic1ugBh1pVu3L66Yq8hQeaOwXeODQicbfUQtPIQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图10：初始化配置</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">在初始化配置的基础上，Goldoon的一些版本还在测试增加不同的功能，例如反调试、持久化等对抗功能。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135723" data-ratio="0.2972222222222222" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d69f7015&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaDlKCGyPUBaicicqFrVFxtRVshdIg4SQCPkrVVXqCJewIRHHaQSYa7NOw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图11：反调试代码</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135724" data-ratio="0.44537037037037036" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=efb7f5f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAia7OM8iawptxZfJKLwIjcKFscslGKpoJLcwI37wSmRzkpLxjibWUq1GhTA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图12：持久化代码</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">（2）上线机制</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">在open_connection函数中，程序会获取系统信息，包括用户名、主机名、操作系统信息、受感染方式、CPU核心数、是否支持IPV6、内存、系统版本等，并组包发送至C2。相关代码及上线数据包如下所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135725" data-ratio="0.49166666666666664" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=25a2d6dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaImWta7sNxQQU17JnDCsVNaXBuEQ6oibeicGKc5XInw5xPngShXNTxicgQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图13：上线机制代码</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">通过分析，我们将上线数据包格式进行解析，解析后的具体结构如下表所示。</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">表3：上线数据包格式</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="99" valign="top" style="border-width: 1pt 1pt 2.25pt;border-style: solid;border-color: rgb(79, 129, 189) rgb(79, 129, 189) white;background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);">数据大小<o:p></o:p></span></p></td><td width="90.33333333333333" valign="top" style="border-top: 1pt solid rgb(79, 129, 189);border-left: none;border-bottom: 2.25pt solid white;border-right: 1pt solid rgb(79, 129, 189);background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);">数据说明<o:p></o:p></span></p></td><td width="294.33333333333326" valign="top" style="border-top: 1pt solid rgb(79, 129, 189);border-left: none;border-bottom: 2.25pt solid white;border-right: 1pt solid rgb(79, 129, 189);background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);">数据内容示例<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="99" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">4字节<o:p></o:p></span></p></td><td width="70.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">固定值<o:p></o:p></span></p></td><td width="294.33333333333326" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">00 00 00 00（Packet.type）<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="99" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">4字节<o:p></o:p></span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">固定值<o:p></o:p></span></p></td><td width="274.3333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">00 00 00 01（Packet.args_length）<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="79.33333333333333" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">4字节+Char*<o:p></o:p></span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">字串长度+固定字串<o:p></o:p></span></p></td><td width="294.33333333333326" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">strlen(“SystemInof”) +“SystemInfo”（Arg.key）<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="99" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">4字节<o:p></o:p></span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">固定值<o:p></o:p></span></p></td><td width="294.33333333333326" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">00 00 00 0A（Arg.type）<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;"><td width="99" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">4字节+Char*<o:p></o:p></span></p></td><td width="90.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">字串长度</span><span style="font-size: 12px;color: rgb(136, 136, 136);">+字符串<o:p></o:p></span></p></td><td width="294.33333333333326" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">00 00 00 4F+”username...”（Arg.value，<span style="color: rgb(136, 136, 136);font-size: 12px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">字串为获取的系统信息）</span><o:p></o:p></span></p></td></tr></tbody></table><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">（3）心跳机制</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">程序创建单独的线程用于发送心跳包，每间隔60秒发送”Time”及时间戳，相关代码和上线数据包如下：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135726" data-ratio="0.18443002780352177" data-s="300,640" style="" data-type="png" data-w="1079" src="https://wechat2rss.xlab.app/img-proxy/?k=dc7f66ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiacW4A2CDr0IFZWRsujY9KRv3RMjKic7WGB9lXoWqA6icLxYJLf9ywCU3w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图14：心跳包机制代码</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">心跳包数据解析如下表所示。</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">表4：心跳包数据格式</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="80" valign="top" style="border-width: 1pt 1pt 2.25pt;border-style: solid;border-color: rgb(79, 129, 189) rgb(79, 129, 189) white;background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);">数据大小<o:p></o:p></span></p></td><td width="93.33333333333333" valign="top" style="border-top: 1pt solid rgb(79, 129, 189);border-left: none;border-bottom: 2.25pt solid white;border-right: 1pt solid rgb(79, 129, 189);background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);">数据说明<o:p></o:p></span></p></td><td width="310.33333333333326" valign="top" style="border-top: 1pt solid rgb(79, 129, 189);border-left: none;border-bottom: 2.25pt solid white;border-right: 1pt solid rgb(79, 129, 189);background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);">数据内容示例<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="80" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">4字节</span><span style="font-size: 12px;color: rgb(136, 136, 136);"><o:p></o:p></span></p></td><td width="93.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">固定值<o:p></o:p></span></p></td><td width="310.33333333333326" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">00 00 00 0</span><span style="font-size: 12px;color: rgb(136, 136, 136);">3（Packet.type）<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="60.33333333333333" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">4字节<o:p></o:p></span></p></td><td width="73.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">固定值<o:p></o:p></span></p></td><td width="290.3333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">00 00 00 01（Packet.args_length）<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="80" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">4字节</span><span style="font-size: 12px;color: rgb(136, 136, 136);">+Char*<o:p></o:p></span></p></td><td width="73.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">字串长度+固定字串<o:p></o:p></span></p></td><td width="310.33333333333326" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">strlen(“Time”) +“Time”（Arg.key）<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="80" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">4字节<o:p></o:p></span></p></td><td width="89.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">固定值<o:p></o:p></span></p></td><td width="310.33333333333326" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">00 00 00 <span style="font-size: 12px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">0</span></span><span style="font-size: 12px;color: rgb(136, 136, 136);"><span lang="EN-US" style="color: rgb(136, 136, 136);font-size: 12px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">8 00</span> 00 00 0A（Arg.type）</span><span style="font-size: 12px;color: rgb(136, 136, 136);"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;"><td width="80" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">4字节+Char*<o:p></o:p></span></p></td><td width="89.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">字串长度+字符串<o:p></o:p></span></p></td><td width="310.33333333333326" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);"><span lang="EN-US" style="color: rgb(136, 136, 136);font-size: 12px;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">strlen(timestamp)+timestamp</span>（Arg.value）</span><span style="font-size: 12px;color: rgb(136, 136, 136);"><o:p></o:p></span></p></td></tr></tbody></table><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">抓取的上线包和心跳包流量数据如下图所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135727" data-ratio="0.10830324909747292" data-s="300,640" style="" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=ff730b9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAia6XQ6jm36vR5kh3Pk8KfiaGq5C2oAMPnDWX6VxPyzkaaJ6jfibJoo2tow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图15：上线包和心跳包流量数据</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">（4）控制指令解析</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">这里需要注意的是，在read_packet函数中，程序首先会接收两次（4字节/每次）数据，该数据分别为type和args_length，且在成功接收后进行判断，若值不为-1时再继续接收其他数据。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135728" data-ratio="0.6312056737588653" data-s="300,640" style="" data-type="png" data-w="846" src="https://wechat2rss.xlab.app/img-proxy/?k=802859d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaQP0PPkanpvpT5nJeeUshiaXrR9HScgKWIPm8cYiaicDqsuyPEyJLIqspg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图16：接收数据代码</span><o:p></o:p></p><p style="margin-bottom: 8px;text-align: justify;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">在handle_packet函数中，程序解析控制指令如下：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135729" data-ratio="1.1481481481481481" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c1ccafc2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaQ5NA2VEzFLPg0S0xotiagenVY3E55mLfibfwFoibe8icVSSR3JXyibic2azQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图17：控制指令代码</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">攻击指令数据包所对应的结构体如下所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135730" data-ratio="0.5745140388768899" data-s="300,640" style="" data-type="png" data-w="463" src="https://wechat2rss.xlab.app/img-proxy/?k=3c4f7413&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAia1icRicXw2qXSXulDntibtJib8tRMbyPIAm80PVibbVEswkyGa74hibFXDHvw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图18：控制指令数据包结构体</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">攻击指令由Packet结构体中的type决定，共包含五类：</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">表5：攻击指令</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="113.33333333333333" valign="top" style="border-width: 1pt 1pt 2.25pt;border-style: solid;border-color: rgb(79, 129, 189) rgb(79, 129, 189) white;background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: white;font-size: 12px;">控制码<o:p></o:p></span></p></td><td width="350.33333333333337" valign="top" style="border-top: 1pt solid rgb(79, 129, 189);border-left: none;border-bottom: 2.25pt solid white;border-right: 1pt solid rgb(79, 129, 189);background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: white;font-size: 12px;">控制指令说明<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="113.33333333333333" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">0x01<o:p></o:p></span></p></td><td width="350.3333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">开始攻击<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="113.33333333333333" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">0x0</span><span style="font-size: 12px;color: rgb(136, 136, 136);">2<o:p></o:p></span></p></td><td width="350.3333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">判断自身进程是否正在运行/关闭远程连接<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="113.33333333333333" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">0x04<o:p></o:p></span></p></td><td width="370" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">执行system命令<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="113.33333333333333" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">0x05<o:p></o:p></span></p></td><td width="370" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">停止指定攻击<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;"><td width="113.33333333333333" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">0x06<o:p></o:p></span></p></td><td width="370" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">DNS相关操作<o:p></o:p></span></p></td></tr></tbody></table><p style="margin-bottom: 8px;text-align: justify;text-indent: 2em;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;">攻</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;">击指令的数据包（模拟数据包）如下图所示。</span><br/></p><p><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135731" data-ratio="0.10307017543859649" data-s="300,640" style="" data-type="png" data-w="456" src="https://wechat2rss.xlab.app/img-proxy/?k=612fccc5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiasQYDKPwb97xW6wwqpr7E8RgAhxBXQSlibFDdia5ynKhu9oicL7Tl99pog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图19：攻击指令数据包</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">攻击指令数据解析如下表所示。</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">表6：攻击指令数据解析</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="163" valign="top" style="border-width: 1pt 1pt 2.25pt;border-style: solid;border-color: rgb(79, 129, 189) rgb(79, 129, 189) white;background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);">结构类型<o:p></o:p></span></p></td><td width="83.33333333333331" valign="top" style="border-top: 1pt solid rgb(79, 129, 189);border-left: none;border-bottom: 2.25pt solid white;border-right: 1pt solid rgb(79, 129, 189);background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);">数据大小</span><o:p></o:p></p></td><td width="73.33333333333333" valign="top" style="border-top: 1pt solid rgb(79, 129, 189);border-left: none;border-bottom: 2.25pt solid white;border-right: 1pt solid rgb(79, 129, 189);background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);">数据说明</span><o:p></o:p></p></td><td width="163.33333333333337" valign="top" style="border-top: 1pt solid rgb(79, 129, 189);border-left: none;border-bottom: 2.25pt solid white;border-right: 1pt solid rgb(79, 129, 189);background: rgb(79, 129, 189);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="font-size: 12px;color: rgb(255, 255, 255);">数据内容示例<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="143.33333333333334" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;word-break: break-all;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">type（Packet.type）<o:p></o:p></span></p></td><td width="63.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">4字节</span><span style="color: rgb(136, 136, 136);font-size: 12px;"><o:p></o:p></span></p></td><td width="56.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">攻击指令</span><o:p></o:p></p></td><td width="143.33333333333334" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">00 00 00 01<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="163" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">args_length</span><span style="color: rgb(136, 136, 136);font-size: 12px;">（</span><span style="color: rgb(136, 136, 136);font-size: 12px;"><span lang="EN-US" style="color: rgb(136, 136, 136);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">P</span>ack</span><span style="color: rgb(136, 136, 136);font-size: 12px;">et. args_length）<o:p></o:p></span></p></td><td width="83.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">4字节<o:p></o:p></span></p></td><td width="56.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">args数组大小<o:p></o:p></span></p></td><td width="163.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">00 00 00 01<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="163" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">struct args[]<o:p></o:p></span></p><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">（</span><span style="color: rgb(136, 136, 136);font-size: 12px;"><span lang="EN-US" style="color: rgb(136, 136, 136);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">P</span>acket.</span><span style="color: rgb(136, 136, 136);font-size: 12px;">args[]）<o:p></o:p></span></p></td><td width="83.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">由args_length决定</span><o:p></o:p></p></td><td width="73.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">Arg结构体数组<o:p></o:p></span></p></td><td width="163.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;"><span lang="EN-US" style="font-size: 12px;color: rgb(136, 136, 136);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">00 00 00 03 00 00 00 08 52 65 71 75 65 73 74 00 00 00 04 00 00 00 12</span> <o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="163" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">mx（</span><span style="color: rgb(136, 136, 136);font-size: 12px;"><span lang="EN-US" style="color: rgb(136, 136, 136);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">P</span>acket.mx）</span><span style="color: rgb(136, 136, 136);font-size: 12px;"><o:p></o:p></span></p></td><td width="83.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">8字节<o:p></o:p></span></p></td><td width="73.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">线程互斥体</span><o:p></o:p></p></td><td width="163.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">00 00 00 00 00 00 00 05<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;"><td width="163" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">type（Arg.type）<o:p></o:p></span></p></td><td width="83.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">4字节<o:p></o:p></span></p></td><td width="73.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">反序列化转换类型</span><o:p></o:p></p></td><td width="163.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">00 00 00 03<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:6;"><td width="163" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">key（Arg.key）<o:p></o:p></span></p></td><td width="83.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">字串长度</span><span style="color: rgb(136, 136, 136);font-size: 12px;">+<span style="color: rgb(136, 136, 136);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">C</span>har*</span><o:p></o:p></p></td><td width="73.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">配合控制指令0x02和0x05使用</span><o:p></o:p></p></td><td width="163.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: white;padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;color: rgb(136, 136, 136);font-size: 12px;">00 00 00 08 52 65 71 75 65 73 74</span><span style="color: rgb(136, 136, 136);font-size: 12px;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:7;mso-yfti-lastrow:yes;"><td width="163" valign="top" style="border-right: 1pt solid rgb(79, 129, 189);border-bottom: 1pt solid rgb(79, 129, 189);border-left: 1pt solid rgb(79, 129, 189);border-top: none;background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">value（Arg.value）<o:p></o:p></span></p></td><td width="83.33333333333331" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">字串长度+<span style="color: rgb(136, 136, 136);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">C</span>har*</span><o:p></o:p></p></td><td width="73.33333333333333" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">攻击线程、攻击时长、攻击类型，攻击ID</span><o:p></o:p></p></td><td width="163.33333333333337" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(79, 129, 189);border-right: 1pt solid rgb(79, 129, 189);background: rgb(184, 204, 228);padding: 0cm 5.4pt;"><p style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
  normal;"><span style="color: rgb(136, 136, 136);font-size: 12px;">00 00 00 04 00 00 00 12<o:p></o:p></span></p></td></tr></tbody></table><p style="margin-bottom: 8px;text-align: justify;text-indent: 2em;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;">结</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;">构体数组args[]中value值会根据数组成员依序从下标0至3进行相应的数据提取，具体数据内容如下图所示。</span><br/></p><p><o:p></o:p></p><p><o:p></o:p></p><p style="text-align: center;margin-bottom: 0px;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135733" data-ratio="0.3967168262653899" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;text-wrap: wrap;" data-type="png" data-w="731" src="https://wechat2rss.xlab.app/img-proxy/?k=9375be26&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaW50iaibgJYW58qrhUA9kJO3mvC54x0aIJw9nb9ZMoybD19lM0NxT2ULA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图20：结构体数组内容</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Linux版样本目前共发现28种攻击方式，其中http_exploit、http_xflow、http_pps函数内功能代码为空，攻击者未来可能会继续扩展相关功能。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135734" data-ratio="1.3628230616302186" data-s="300,640" style="" data-type="png" data-w="1006" src="https://wechat2rss.xlab.app/img-proxy/?k=cf02c56e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaaOJTAa3mDrgYh26aLCz6mo4DjurNjvpGHQRTg0H7ibDFZxU0Y0Fk89g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;margin-bottom: 16px;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图21：Linux版样本攻击方式代码</span><o:p></o:p></p><h3 style="margin-bottom: 16px;"><strong><span style="line-height: 115%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(0, 82, 255);">3.2 Windows平台样本</span></strong><o:p></o:p></h3><h4 style="margin-bottom: 8px;"><strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">3.2.1 powershell脚本</span></strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h4><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Windows版的powershell脚本相对较简单，从指定地址下载并执行下一阶段的恶意模块。同时该脚本在VT检测率也极低，结果显示仅1家报毒。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135735" data-ratio="0.6121399176954733" data-s="300,640" style="" data-type="png" data-w="972" src="https://wechat2rss.xlab.app/img-proxy/?k=a2557920&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaL3aw3mwu5thJ6rbx52dcnKgq7x5oeAoS4vflicqg0jEg8AsCVJajnBw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图22：powershell脚本</span><o:p></o:p></p><h4 style="margin-bottom: 8px;"><strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">3.2.2 Loader</span></strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h4><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Windows版与Linux版本的Loader功能相比，仅具有下载并执行下一阶段恶意程序的功能。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135736" data-ratio="1.1452830188679246" data-s="300,640" style="" data-type="png" data-w="530" src="https://wechat2rss.xlab.app/img-proxy/?k=e867c66d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiajouS99xIe0Oyuod76XbozEHYmxYtJuW1rDicogJEauzp4m2ibnnicJeRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图23：Loader部分代码</span><o:p></o:p></p><h4 style="margin-bottom: 8px;"><strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">3.2.3 Dropper</span></strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h4><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">当Dropper完成初始化异常处理、初始化随机种子、初始化DNS解析以及初始化攻击管理等配置后，其会开启单独的线程来遍历当前运行的进程，并从中查找”taskmgr.exe”和”debugg”进程，若存在则关闭该进程，以达到隐藏自身和反调试目的。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135737" data-ratio="0.4488078541374474" data-s="300,640" style="" data-type="png" data-w="713" src="https://wechat2rss.xlab.app/img-proxy/?k=85fb78de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaFeBTU6HCM99OTw8dicQiaYiapxIA4HKrYfQ1nLibraShkic3Fezw8Ze7Asw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图24：反调试代码</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">通过控制台命令查找正在监听3389端口（通常用于远程桌面连接）的进程，若存在则结束该进程，随后再绑定和监听该端口。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135738" data-ratio="0.579092159559835" data-s="300,640" style="" data-type="png" data-w="727" src="https://wechat2rss.xlab.app/img-proxy/?k=d7b9ada5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaJtkq7NanaEOv2ao764ibQearCKj97m4OohL4Y5heKz8iaQ5W3dK7Qn8w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图25：端口监听代码</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">设置当前进程优先级为实时以及当前线程优先级为最高级别。具体代码如下图所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135739" data-ratio="0.3930722891566265" data-s="300,640" style="" data-type="png" data-w="664" src="https://wechat2rss.xlab.app/img-proxy/?k=b247dd01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiaum7HzdH6Fwib1ztvWhoQQlaiaH0Yg0dgm9M479moOU9ZxlKuOB6n9wiaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图26：设置进程和线程优先级</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">将自身文件复制到启动项文件夹路径下和Windows系统文件夹中，并添加到注册表自启动项，以实现其持久性。</span><o:p></o:p></p><p><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135740" data-ratio="0.7189695550351288" data-s="300,640" style="" data-type="png" data-w="854" src="https://wechat2rss.xlab.app/img-proxy/?k=dccdb23e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiab2ZslOicXOUwcMThp86QhYc537BufBA9icEC23YvF19o1WFchgHaGXyA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图27：实现持久化</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">通过分析我们发现，Windows版与Linux版的上线机制、心跳机制以及控制指令解析等通信协议相同，因此我们便不再进行赘述。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">但在攻击模式方面，Windows版Goldoon目前总共仅包括15种攻击模式，且其中有4种攻击模式暂未实现，具体如下图所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135741" data-ratio="1.6941964285714286" data-s="300,640" style="" data-type="png" data-w="448" src="https://wechat2rss.xlab.app/img-proxy/?k=3c9f7dd3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQr3u0KrINJiccID3Nk2PIAiajukfYkoDeGTIFq3UTn8qPtGiceIA8H1WficM9V0ECl3G8QgDZvZu4BFw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图28：Windows版攻击模式代码</span><o:p></o:p></p><h2 style="margin-bottom: 8px;"><br/></h2><p><br/></p><p><br/></p><p style="font-size:20px;color:#c9eaff;line-height:1;"><span style="font-size: 17px;"><em><strong>04</strong></em></span></p><p><br/></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><span style="font-size: 16px;"><strong>总 结</strong></span></p><p style="margin-bottom: 8px;text-indent: 2em;"><br/></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">本文披露了近期新出现的物联网僵尸网络Goldoon，重点针对其攻击活动特点、各独立模块的功能代码以及控制协议等进行了深入分析和介绍，并分别对Linux平台和Windows平台的样本进行了技术分析，包括其中涉及的功能迭代、兼容性、免杀性等特性。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Goldoon在设计之初就已适配了超过18种指令集架构，这在大多数物联网僵尸中是较为少见的，也可能成为未来僵尸网络扩张的一个新方向。通常来说，存在安全隐患的设备往往可能被不同的僵尸网络重复多次入侵，而当前越来越多的僵尸都开始尝试禁用漏洞端口以独占设备，这就造成大量易入侵的
“肉鸡”资源在海量的僵尸攻击下越来越稀缺。与此同时，对于一些小众指令集架构来说，由于大多数僵尸网络并没有做适配支持，那么即使其中存在安全隐患的设备被入侵也很可能未成功植入恶意代码。因此，针对这些“漏网之鱼”定制攻击可能成为未来僵尸网络控制者快速扩大网络规模的一种相对高效的方式，需要格外警惕。未来我们也会持续关注和追踪Goldoon的最新版本迭代变化和攻击动态。</span><o:p></o:p></p><h2 style="margin-bottom: 8px;"><br/></h2><p><br/></p><p><br/></p><p style="font-size:20px;color:#c9eaff;line-height:1;"><span style="font-size: 17px;"><em><strong>05</strong></em></span></p><p><br/></p><p style="font-size:16px;letter-spacing:2px;color:#fefefe;"><span style="font-size: 16px;"><strong>IOC</strong></span></p><h2 style="margin-bottom: 8px;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></h2><p><br/></p><p><strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">C&amp;C :</span></strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></p><p style="margin-bottom: 0px;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">94.228.168.60</span><o:p></o:p></p><p style="margin-bottom: 16px;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">185.106.94.51</span><o:p></o:p></p><p><strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Shell脚本：</span></strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">3f0e0c2f929d2e8ed24efac137fba2100a9afa317b5e74cb9a98b306e36d38bd</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">53acad3c3017049c5b02bbbb39118198d22c494d21fd2a528eccc8ea7feb6c33</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">f25f235823386935504b91e74f34a581c8c66982e51d0d94b9af2fb9e528aac7</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">35ad992121d507477793fc3cd555fbabf38b399a282bd6a29e4361f0b42ebbe8</span><o:p></o:p></p><p style="margin-bottom: 16px;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">6ddd5789e2ed4d071a17f6aaeba61f3a7c4844168a3cb02fb4cebdbaee183b49</span><o:p></o:p></p><p><strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Loader：</span></strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">b48afb4e5fed1a42e2d60709329f2ac1009aae5fb18a6ec23917e64872ed540f</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">8eb9c1eaecd0dcdd242e1bc8c62a1052915b627abe2de8ce147635fb7da3bfcc</span><o:p></o:p></p><p style="margin-bottom: 16px;"><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">48130a7c09a5c92e15b3fc0d2e1eb655e0bd8f759e01ba849f7734e32dbc2652</span><o:p></o:p></p><p><strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Dropper:</span></strong><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">e7cd7305eeb4b26b36648febbed3ed5bfebf0345464f73deefa54d366bbbb6a1</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">cd416d8ef5c1274a5e77dfd4830d495a29f02442fb5ccaa9842824d70a43c640</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">a60b505d0d42c334901fb4972b004a4bcb78de5035ed4f8c3f27b16df35429c3</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">df8d88ff3e138be09c921058265e07df98ad50121dd70d9a292f223b19f456ac</span><o:p></o:p></p><p><span style="line-height: 115%;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">26737091fe62098ec80bf03ae1377bafd85c6796fffd538519689fd663649af7</span><o:p></o:p></p><p><br/></p><p><br/></p><p><br/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="outline: 0px;line-height: 1.8;"></span></p><p style="outline: 0px;"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="outline: 0px;"></span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/<span style="outline: 0px;">CVE</span>累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="outline: 0px;">数据安全研究、<span style="color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">5G安全研究、</span><span style="outline: 0px;">人工智能安全研究、</span></span></span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">移动安全研究、物联网安全研究、车联网安全研究、</span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">工控安全研究、信创安全研究、</span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">云安全研究、</span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 1.5px;">。</span><span style="outline: 0px;letter-spacing: 1.5px;"></span></span><span style="outline: 0px;"></span></p><p style="outline: 0px;"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135743" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 282px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Mon, 29 Apr 2024 18:04:11 +0800</pubDate>
    </item>
    <item>
      <title>aiohttp目录穿越漏洞（CVE-2024-23334）分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619355&amp;idx=1&amp;sn=1ed27f1eba0c7366a9be820049cc063b&amp;chksm=8306268bb471af9dedcda9839735fda2d6189dcd97e08b983e9942973ae6c43df0c647457c03&amp;scene=58&amp;subscene=0#rd</link>
      <description>aiohtp 是构建于 Python l/0 框架 AsyncI0 之上的开源库，用于处理无需基于传统线程网络的大量并发HTTP请求。启明星辰ADLab研究员在漏洞情报跟踪中发现aiohttp存在目录遍历漏洞，并对其进行了深入分析和验证。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-04-01 17:36</span> <span style="display: inline-block;">北京</span>
</p>

<p>aiohtp 是构建于 Python l/0 框架 AsyncI0 之上的开源库，用于处理无需基于传统线程网络的大量并发HTTP请求。启明星辰ADLab研究员在漏洞情报跟踪中发现aiohttp存在目录遍历漏洞，并对其进行了深入分析和验证。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b6d32ec4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONWgREoMh81nUSbDz2bgiaMT7v6f1WcC02wylXSSDiawhGs5IziagHJVjng%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 0px;"><br/></p><p style="font-size:16px;letter-spacing:2px;color:#0080ff;"><em><strong>一、漏洞概述</strong></em></p><p><br/></p><p><br/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135681" data-ratio="1.5277777777777777" style="display:block;width:100%;vertical-align:bottom;" data-w="36" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e51e7399&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjhhvzHakFdRmzfzEcAatogZUGyupZQOht0Fs3icKWJtDYIkBTx67UoSH7XoJ0WGGEJbpqCgxcAeew%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;margin-bottom: 0px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">aiohtp 是构建于 Python l/0 框架 AsyncI0 之上的开源库，用于处理无需基于传统线程网络的大量并发HTTP请求。aiohttp支持HTTP客户端、HTTP服务端、WebSocket客户端、WebSocket服务端、服务端中间件等。aiohttp被广泛使用，在网络中有大量基于该框架开发的在线系统。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">启明星辰ADLab研究员在漏洞情报跟踪中发现了aiohttp目录遍历漏洞（CVE-2024-23334），并对其进行了深入分析和验证。</span><span style="mso-spacerun:&#39;yes&#39;;font-family:Cambria;mso-fareast-font-family:宋体;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:12.0000pt;"><o:p></o:p></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p style="font-size:16px;letter-spacing:2px;color:#0080ff;"><em><strong>二、影响版本</strong></em></p><p><br/></p><p><br/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135684" data-ratio="1.5277777777777777" style="display:block;width:100%;vertical-align:bottom;" data-w="36" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e51e7399&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjhhvzHakFdRmzfzEcAatogZUGyupZQOht0Fs3icKWJtDYIkBTx67UoSH7XoJ0WGGEJbpqCgxcAeew%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><br/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">受影响版本：&lt;3.9.2，请相关用户尽快升级到3.9.2及以上版本。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p style="font-size:16px;letter-spacing:2px;color:#0080ff;"><em><strong>三、漏洞分析</strong></em></p><p><br/></p><p><br/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135685" data-ratio="1.5277777777777777" style="display:block;width:100%;vertical-align:bottom;" data-w="36" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e51e7399&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjhhvzHakFdRmzfzEcAatogZUGyupZQOht0Fs3icKWJtDYIkBTx67UoSH7XoJ0WGGEJbpqCgxcAeew%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;text-indent: 0em;margin-bottom: 0px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">该漏洞的关键信息如下[1]：</span><span style="mso-spacerun:&#39;yes&#39;;font-family:Cambria;mso-fareast-font-family:宋体;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:12.0000pt;"><o:p></o:p></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-indent: 2em;margin-bottom: 8px;"><em style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-family: Cambria;font-size: 12pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;">aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option &#39;follow_symlinks&#39; can be used to determine whether to follow symbolic links outside the static root directory. When &#39;follow_symlinks&#39; is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.</span></em><br/></p><p><em><span style="font-family: Cambria;font-size: 12pt;background: rgb(127, 127, 127);"></span></em><em><span style="font-family: Cambria;font-size: 12pt;background: rgb(127, 127, 127);"><o:p></o:p></span></em></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">根据关键信息，定位到开发文档的说明[2]：</span><br/></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135686" data-ratio="0.45454545454545453" data-s="300,640" style="" data-type="png" data-w="539" src="https://wechat2rss.xlab.app/img-proxy/?k=7378fedf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONHs5lxzTJ0UAKhyYMIicJv4U33ibXO01mnDvJQt4BrsW59PiaiajAXRRkUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">根据文档描述，follow_symlinks是一个设计上用于非生产环境的功能，并且已在文档中明确提示启用该功能是一个安全风险。</span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">编写如下的示例代码，测试follow_symlinks的功能：</span><o:p></o:p></p><p><o:p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135688" data-ratio="0.5702746365105008" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;text-wrap: wrap;" data-type="png" data-w="619" src="https://wechat2rss.xlab.app/img-proxy/?k=34d72a5a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONGxicq4YdE1dhwh13wpq1a4iaHiarrGCLdvXo2OqF9GVjmibaYoe7hutZ1A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">在static目录下创建符号链接d，指向其它目录d:\test（该目录下存在测试文件123.txt）。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135689" data-ratio="0.13956466069142126" data-s="300,640" style="" data-type="png" data-w="781" src="https://wechat2rss.xlab.app/img-proxy/?k=43e142dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycON1u0QiakqAeWwWUk02icKXB9jW9U1dZxoiaTaPOGTiaYoawGAgc6NiblxZrw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">以follow_symlink=fasle的模式启动测试webserver，访问static/d/123.txt的结果如下所示（提示找不到文件）：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135690" data-ratio="0.4106145251396648" data-s="300,640" style="" data-type="png" data-w="716" src="https://wechat2rss.xlab.app/img-proxy/?k=eebc3234&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONGBZgYUQA1T5BYS2Hyu3EiaMX6yt0TcuGjGL8IUnVpnBX5IDlZuKb01g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">以follow_symlink=true的模式启动测试webserver，访问static/d/123.txt的结果如下所示（成功读取文件内容）：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135691" data-ratio="0.37139107611548555" data-s="300,640" style="" data-type="png" data-w="762" src="https://wechat2rss.xlab.app/img-proxy/?k=40e1e3ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycON4OnWumic7PCzyiarX3WRXYhOZWe2icK9PneJiceyWt4f2FjKyVsIWtLL8w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">显然，根据文档的描述，如果follow_symlink=true且存在符号链接，结果就是程序的正常预期功能。那么，该功能是如何被认定成漏洞？</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">漏洞的关键信息[1]中有一句重要描述：漏洞不依赖于符号链接的存在性。但是，在请求路径中使用不存在的符号链接，底层又如何能访问到目标文件。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">经过分析，发现底层处理请求的关键函数如下：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135692" data-ratio="0.9375" data-s="300,640" style="" data-type="png" data-w="656" src="https://wechat2rss.xlab.app/img-proxy/?k=0ffe4456&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONicfGmb6I22CdJgjN7ru5aLyUiag8ib2YBicKdPnQQJicXVdCf854N9fA38w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">首先，获取请求文件名（filename）。以 GET /static/d/123.txt为例，filename就是d/123.txt。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">然后，把filename转换为Path对象，并检测该对象是否存在anchor属性。如果存在，则拒绝访问。在windows平台上，anchor对象就是盘符（比如d:\）。因此，此处存在安全检测，即不允许跨盘符访问。比如GET /static/d:\test\123.txt，会被视作非法请求而拒绝：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135693" data-ratio="0.33903133903133903" data-s="300,640" style="" data-type="png" data-w="702" src="https://wechat2rss.xlab.app/img-proxy/?k=32b9dff4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONNZxFFtSV0p9EEJCrHZlMZM9LHWibyj5MDgSX8XWnCyJibceA1TglUzyA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">再然后，把static目录的Path对象和filename的Path对象做拼接，形成新文件路径filepath。最后，读取filepath的数据，并返回给客户端。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">显然，如果filename包含不存在的符号链接，但能访问到目标文件，那说明对象拼接产生了非预期的结果。由于Path对象是标准的python类，直接单独进行测试。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">（1）设定directory=c:\test , filename =
d:\test\123.txt，拼接代码和结果如下:</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135694" data-ratio="0.3443456162642948" data-s="300,640" style="" data-type="png" data-w="787" src="https://wechat2rss.xlab.app/img-proxy/?k=3b36f06e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONeBttzBJdb9PGrF5eQZGkPWhHqaK23NCT5ZYBu1JtI85ad0lW0y3IiaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">拼接结果指向目标文件d:\test\123.txt，但是fname包含anchor，无法通过前面的filename.anchor检查。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">（2）设定directory=c:\test
, filename = ..\d:\test\123.txt，拼接代码和运行结果如下：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135695" data-ratio="0.3443456162642948" data-s="300,640" style="" data-type="png" data-w="787" src="https://wechat2rss.xlab.app/img-proxy/?k=41a343c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONIB6leYLONKicsRL8EY5fVkENSKeCWVrWX3Ny6Fq5cMcZcwNJArh0R8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">拼接结果读取到目标文件，且fname不包含anchor，能通过filename.anchor检查。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">（3）设定directory=c:\test
, filename = ..\..\d:\test\123.txt，拼接代码和运行结果如下：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135697" data-ratio="0.3443456162642948" data-s="300,640" style="" data-type="png" data-w="787" src="https://wechat2rss.xlab.app/img-proxy/?k=e0c07b62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONh8kbaLj4ic67STNtreOD0EVwUHrrrSibNRcCL18hfNdzAuRS7IVV0YYw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">拼接结果也读取到了目标文件，且fname不包含anchor，能filename.anchor检查。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">因此，只要在filename之前加上..\就能直接引入盘符，违背原始功能设计中需要符号链接存在的限制，从而形成了可以读取磁盘上任意文件的安全漏洞。</span><o:p></o:p></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><br/></h3><p style="font-size:16px;letter-spacing:2px;color:#0080ff;"><em><strong>四、补丁分析</strong></em></p><p><br/></p><p><br/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135698" data-ratio="1.5277777777777777" style="display:block;width:100%;vertical-align:bottom;" data-w="36" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e51e7399&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FLjib4So7yuWjhhvzHakFdRmzfzEcAatogZUGyupZQOht0Fs3icKWJtDYIkBTx67UoSH7XoJ0WGGEJbpqCgxcAeew%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><p><br/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">补丁关键代码如下：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135699" data-ratio="0.960960960960961" data-s="300,640" style="" data-type="png" data-w="666" src="https://wechat2rss.xlab.app/img-proxy/?k=d6aa83f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONu2VD8sUaF1UiaRDsWNe2YGz06WpfrSbYHX92F9iawOibiaLGnWQUj7t3Qw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">补丁的核心机制是：路径拼接成unresolved_path后，首先调用normpath处理unresolved_path来形成normalized_path，然后判定normalized_path是否位于静态目录_directory之下。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">单独测试补丁机制的代码和结果如下：</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135700" data-ratio="1.0152542372881357" data-s="300,640" style="" data-type="png" data-w="590" src="https://wechat2rss.xlab.app/img-proxy/?k=550eff8a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nRufmGJVpaoYTqz9VXMycONOjlKpYUo0CY63OFCng0bZkicsppbQsurQqWg189YxqTDMvGxYXFk2uA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">显然，由于拼接后的路径不是static目录的子目录，所以触发了异常，导致后续代码不再读取拼接后路径下的文件，从而导致了该漏洞不再存在。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">补丁不影响aiohttp的符号连接支持，因为符号链接文件必须存在于static目录之下。使用符号链接文件来处理static资源本身就是一个潜在的安全风险，开发者仍需要引起足够的重视，谨慎使用该功能。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 15px;"><strong style="outline: 0px;"><span style="outline: 0px;letter-spacing: 2px;">参考链接：</span></strong></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;"></span><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;"></span><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;">[1]https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23334<span style="outline: 0px;letter-spacing: 0.544px;"></span></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;">[2]https://docs.aiohttp.org/en/stable/web_reference.html</span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;"></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p><br/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br style="outline: 0px;"/></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="outline: 0px;line-height: 1.8;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="outline: 0px;">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截至目前，ADLab已通过 CNVD/CNNVD/NVDB/<span style="color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">CVE</span>累计发布安全漏洞5000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="outline: 0px;">5G安全研究、数据安全研究、<span style="outline: 0px;">人工智能安全研究、</span></span></span><span style="outline: 0px;">移动与物联网安全研究、</span><span style="outline: 0px;">工控安全研究、信创安全研究、</span><span style="outline: 0px;">云安全研究、</span><span style="outline: 0px;">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="outline: 0px;letter-spacing: 1.5px;">。</span></span><span style="outline: 0px;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135703" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 282px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Mon, 01 Apr 2024 17:35:53 +0800</pubDate>
    </item>
    <item>
      <title>秘鲁军方勒索事件及相关勒索组织深度分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619326&amp;idx=1&amp;sn=e028182ffdc29d2df0cfe12c4cf4e623&amp;chksm=8306266eb471af7826b2f22b29309547ff2b8420e61dbbe5ab671a105cc696aa2fe97295b449&amp;scene=58&amp;subscene=0#rd</link>
      <description>近日，启明星辰ADLab在暗网安全威胁跟踪研究过程中，发现一起成功入侵到秘鲁军方重要系统的勒索攻击事件，这起攻击致使军方超过500G重要涉密信息泄露，同时导致大量关键系统数据被破坏。本文重点分析该勒索组织的历史攻击活动、攻击手法、样本案例。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-03-29 18:51</span> <span style="display: inline-block;">北京</span>
</p>

<p>近日，启明星辰ADLab在暗网安全威胁跟踪研究过程中，发现一起成功入侵到秘鲁军方重要系统的勒索攻击事件，这起攻击致使军方超过500G重要涉密信息泄露，同时导致大量关键系统数据被破坏。本文重点分析该勒索组织的历史攻击活动、攻击手法、样本案例。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=ed9d3921&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdvRhKokXVNnwiatibDBic9bp6W5jzYbuFhuR4Whibn0t7MVibepMbyj14ibFw%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br/></p><p style="font-size:16px;color:#fefefe;line-height:25px;letter-spacing:0;"><strong>1</strong></p><p style="font-size:16px;letter-spacing:2px;color:#77b4f2;"><strong>背景</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135629" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e29f16e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn5O6B3JBlb4TgDrxf0ROk3SU0YBQ0Gc7mWbXoU0KzfSGvXFuATYYsTyaDSG7QKSia3icjFqRYjfpPqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;"><br/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">近几年，在加密货币和暗网的保护下，各种新兴勒索组织层出不穷，其在全球范围内的攻击活动也越来越猖獗。他们通过利用各种各样的黑客攻击手段入侵到各种系统内部，窃取敏感数据，加密并破坏信息系统，以此为威胁勒索巨额财产。以往的勒索攻击大多针对企事业单位，已然造成了不可估量的损失。然而，现如今，有极少数勒索团伙开始将魔爪从企业和政府延伸到了军队。由于军队内部系统的敏感性和特殊性，常常处于物理隔离的状态，安全性相对较高，即便有相关的攻击出现，出于保密需要，受害方也几乎不会公开受攻击情报，因此我们也极难观察到军队相关的勒索攻击事件。</span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">2024年</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">3月2</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">5</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">日</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">，</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">启明星辰</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">ADLab在暗网安全威胁跟</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">踪研究过程中，</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">发现了一起成功入侵到秘鲁军方重要系统的勒索攻击事件，这起攻击致使军方超过</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">5</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">00G</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">重要涉密信息泄露，同时导致大量关键系统数据</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">被破坏。</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">这是自去年</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">5月智利军队勒索攻击事件以来</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">的又一次对国家军队的恶性勒索攻击。</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">这次勒索攻击事件的作案团伙是一个成立仅仅</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">7个月的新兴勒索组织</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">INC Ransom</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">，却在全世界范围内成功地实施了近</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">7</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">0次的勒索攻击</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">。</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">其对网络安全的威胁值得引起我们足够的重视。</span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在对该</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">勒索组织追踪过程中我们还发现，其在</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">2023年9月20</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">日</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">成功入侵了我国深圳某电池公司，致使部分重要系统数据被加密破坏，同时导致该公司</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">17个文件和压缩包，超过87GB数据被公开，其中包括企业内部技术文档、财务文件、交易文件、供应商信息、管理员账户及密码等敏感文件。</span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">根据勒索组织已公开的文件内容进行评估，秘鲁军方</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">勒索事件</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">可能引发重大的失泄密影响并严重损害其国家的安全和利益。</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">通常来说，军队网络作为国家安全的重要组成部分，大多采用物理隔离的方式来提高安全性，从而防止外部网络攻击和数据泄露。</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">而在已知的攻击活动中，也鲜有成功针对军方的</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">APT入侵案例或是勒索攻击案例披露。</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">尤其是针对军方的“威胁曝光式”窃密勒索攻击，由于相关敏感数据价值巨大，即使交纳赎金，勒索团伙也极有可能将数据二次贩卖和扩散传播，引发不可控的泄密风险。</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">因此，我们认为此类攻击具有很高的研究价值和警示意义。</span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">由</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">于目前缺乏完整的分析要素和攻击细节，且秘鲁军方基于保密要求很可能不会再披露更多信息，因此，启明星辰</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">ADLab通过复盘该组织的历史攻击活动、攻击手法、样本案例等进行分析和解析，针对事件中可能暴露的防御侧安全风险进行警示，并提出相应的防御和治理建议。</span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="font-size:16px;color:#fefefe;line-height:25px;letter-spacing:0;"><strong>2</strong></p><p style="font-size:16px;letter-spacing:2px;color:#77b4f2;"><strong>勒索事件分析</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135630" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e29f16e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn5O6B3JBlb4TgDrxf0ROk3SU0YBQ0Gc7mWbXoU0KzfSGvXFuATYYsTyaDSG7QKSia3icjFqRYjfpPqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在此次攻击活动中，INC Ransom勒索组织声称成功入侵了秘鲁军队网络，并窃取了秘鲁军队内部的大量机密文件用于勒索赎金。该勒索组织在其暗网的官网中公开了部分窃取的文件内容，其中包括秘鲁军队官员的个人信息、陆军司令部和陆军经济办公室等内部命令和决议、军队关键资产地图分布等文件，并且声称如果受害者不与他们取得联系，将公布所有窃取到的机密文件，文件大小超过500G。截至目前，秘鲁军方尚未做出任何关于此次攻击的声明。不过，从窃取的文件信息判断，其涉及的机密文件种类多、分布广、数量大，除了核心的办公室、组织部门外通常不会在单一部门出现，因此初步判断勒索组织很可能入侵了掌握大量秘鲁军队资料的核心部门（如秘书处、办公室等）或是同时入侵了其内网中的多台设备并合计窃取了500G资料。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135639" data-ratio="0.5074074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6be1a982&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdTE2JyWL8lvkSpa5oQYdqaFW5lTbkFGDaXxNgXIsFKxCQ5cianaleiazA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图1 针对秘鲁军队的攻击声明</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:11.0000pt;mso-font-kerning:1.0000pt;"><o:p></o:p></span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135646" data-ratio="0.6346396965865992" data-s="300,640" style="" data-type="png" data-w="791" src="https://wechat2rss.xlab.app/img-proxy/?k=583bf53a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdsc3ZoEkCmqsnzWlgIABGjPFjOQZKPr4CQDlLdZMu9Hoh3I19AILwGg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图2 被泄露的军方人员证件</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135647" data-ratio="0.6880984952120383" data-s="300,640" style="" data-type="png" data-w="731" src="https://wechat2rss.xlab.app/img-proxy/?k=9f36c0d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdScVZdRvcWt2rBCRJjbOA6DLz8LibCNBLIgqrYOicPQ8jgpoH4xFfjN2Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图3 被泄露的军官档案资料</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135648" data-ratio="1.1885245901639345" data-s="300,640" style="" data-type="png" data-w="488" src="https://wechat2rss.xlab.app/img-proxy/?k=d36e3c24&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdQKias7szUmA8ls8xs4KRibe09kVscicxkHYwuQibMpImSDVJSWybic5iaibPQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图4 被泄露的军事用地建设规划图</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135641" data-ratio="0.7074074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=efa6b574&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdTMQb2u0MWJoqf8DvI7UotoPKSFluTBJgVuPnC2icW1y8MTWQdDaU6YQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;"></span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图5 秘鲁军队被泄露的内部决议文件</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135642" data-ratio="0.524074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=41a159fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdPYZSf2bFz03Oh12wRRxonPLAxr0aFDJuM5mRnb0WPbic52eVURicwib4Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图6 秘鲁军队被泄露的重要资产分布</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">从近几年的勒索攻击活动来看，其中针对军队外围机构（如国防军工单位、供应商等）并成功勒索攻击的事件相对于其它行业是较为少见的，而直接针对军方的勒索攻击案例更是屈指可数。这主要是由于国防和军队行业的特殊性和敏感性，其通常与外界网络物理隔绝，勒索组织很难入侵到其内部主机或网络之中。不过也正因为长期存在的物理隔离屏障，反而可能带来一些意想不到的安全隐患，比如物理隔离造成的内部人员安全意识薄弱，隔离内网中往往存在大量有安全隐患的老旧版本设备或操作系统，一旦单点遭到入侵可能导致内网整体失陷；比如内部威胁行为难以防范，外部攻击者通过买通内鬼实施攻击的手段极难应对；再比如随着数字化、云服务化的不断发展，可能出现接入各类移动端、物联网等新设备导致网络拓扑改变，间接造成内网暴露；甚至是一些能够突破物理隔离的跨网窃密新型技术，都可能对传统物理隔离安全构成风险和危害。而一旦军队遭到勒索组织的入侵和攻击，其造成的后果也将远远超过勒索组织攻击其他对象所带来的影响，国家的军事计划、军事部署和军事情报等机密文件都将面临泄露的风险，这无疑将一把利剑递到了政治和军事对抗国家的手中，将直接威胁国家安全。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">最近一次公开的针对国家军队的勒索攻击事件是2023年5月智利军队遭到Rhysida组织勒索攻击，在此次攻击事件中，Rhysida 勒索软件团伙入侵了智利军队的内部网络并且从其内部网络中窃取了超过220GB的军方文件，并且在其官网上公布了其中部分资料，包括各种军队人员信息、军事命令、军事情报和军事战略部署等文件。智利陆军在攻击发生后立刻启动了网络隔离并发布声明，证实了攻击的真实性同时声称对军队和国防造成了严重的影响。</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="font-size:16px;color:#fefefe;line-height:25px;letter-spacing:0;"><strong>3</strong></p><p style="font-size:16px;letter-spacing:2px;color:#77b4f2;"><strong>勒索组织分析</strong></p><p><img data-imgfileid="502135636" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e29f16e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn5O6B3JBlb4TgDrxf0ROk3SU0YBQ0Gc7mWbXoU0KzfSGvXFuATYYsTyaDSG7QKSia3icjFqRYjfpPqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p style="margin-bottom: 0px;"><br/></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">INC Ransom组织，是一个2023年8月开始活跃的新兴勒索组织，该组织在全球范围内开展勒索攻击活动，通常会选择拥有大量财务资源和敏感数据的目标，这方便它们能够向受害者索取更高额的赎金，这也使得该组织在短时间内声名狼藉。该组织通常会使用窃取的登录凭证进入到受害者企业内部网络，使用正常软件和工具进行信息收集和数据扫描，然后在受害者主机上安装MegaSync软件进行数据窃取，最后使用WMIC 和 PSEXEC 部署勒索软件进行勒索。INC Ransom组织目前主要面向Windows、Linux和VMware虚拟化平台的主机系统和平台进行攻击，该组织使用的勒索软件采用了部分加密和多线程结合方法进行加密操作，加密速度明显快于其他全文加密的勒索软件，被加密的文件会被重新命名为 .inc 为后缀的文件。与LockBit组织一样，INC Ransom也会在其暗网的官网上实时更新其受害者的信息，该组织目前已经攻击了超过68家企业或机构，受害者涉及医疗、工程建筑、学校、金融和工业制造等多个领域（截至目前为止，仍有12家机构和企业正在被勒索）；此外，暗网主页中还为受害者提供了单独的联系界面和登录界面，方便受害者与该组织进行谈判。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135643" data-ratio="0.5064814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c6281067&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdckRpcGTbSXkhSM252CvL8fLTMDRbuOlwYny0q7edYJk7C5TRvbH7Tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;"></span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图7 INC Ransom组织暗网官网首页</span><o:p></o:p></p><p style="text-align: center;margin-bottom: 8px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135644" data-ratio="0.5995717344753747" data-s="300,640" style="" data-type="png" data-w="934" src="https://wechat2rss.xlab.app/img-proxy/?k=b7d4c0c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdZavuDcdGm1icT4INXsFtao3P8eaE0NWZibjII9dKMibAsljcbvImI7U1w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;"></span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图8 INC Ransom组织暗网官网提供的联系界面</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135645" data-ratio="0.8395303326810176" data-s="300,640" style="" data-type="png" data-w="511" src="https://wechat2rss.xlab.app/img-proxy/?k=fba3bfe5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVd4nsI85EmNCT8OQGPAiclpl2wibFlCwr94h5a5WkxneomdKfrmYet6wRA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;"></span></p><p style="text-indent: 0em;text-align: center;margin-bottom: 16px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图9 INC Ransom组织提供的谈判登录界面</span><o:p></o:p></p><h4 style="text-indent: 0em;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">3.1 历史攻击活动</span></strong></span><o:p></o:p></h4><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">自去年8月以来，INC Ransom组织一直在频繁地开展勒索攻击活动，其暗网的官网更新频率较为频繁，每个月都有不少来自世界各地的受害者信息被新增到其暗网主页。该组织和LockBit勒索组织一样，同样采用了 “威胁公开受害者敏感信息+加密受害者文件” 双重勒索的策略，这也大幅提高了该组织勒索攻击的威胁程度，特别是对某些敏感政府单位和特殊领域的企业，如政府办公室、国家军队、军工企业、能源企业等。在其暗网的主页中，短短七个多月以来，INC Ransom组织已经公布了68家受害企业的信息，其中还包括我国深圳的某电池企业；仅在2023年11月，就有15家企业受到该组织的勒索攻击。这说明该组织一直保持较高的活跃度，各个企业或机构需要保持警惕。值得注意的是，暗网主页公布的这些数据仅代表该组织勒索成功的案例，说明该组织实际的攻击活动其实更加频繁，该组织的攻击频率及攻击的成功率都不容小觑。此外，这些公开的数据仅仅是该组织公开的受害者信息，还有可能存在未被公开的受害者，因为某些受害者在发现遭到勒索后可能会选择私下联系勒索组织进行私下谈判解决问题，而不会在暗网中公开受害者企业信息，LockBit组织就已经证实过这种情况。这意味着INC Ransom组织的实际受害企业数量不止于此，该组织正在使全球勒索威胁进一步严重，需要引起各个政府单位或企业的警惕。</span><o:p></o:p></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">表1 INC Ransom组织历史攻击典型案例</span><o:p></o:p></p><h4 style="margin-bottom: 0px;text-indent: 0em;"></h4><h4 style="margin-bottom: 0px;text-indent: 0em;"></h4><table cellspacing="0" cellpadding="0" width="553"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:14.15pt;"><td width="78" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(37, 64, 143);padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><strong><span style="font-size:9.0pt;mso-bidi-font-size:12.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:微软雅黑;color:white;mso-font-kerning:0pt;">攻击时间<span lang="EN-US"><o:p></o:p></span></span></strong></p></td><td width="177" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(37, 64, 143);padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><strong><span style="font-size:9.0pt;mso-bidi-font-size:12.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:微软雅黑;color:white;mso-font-kerning:0pt;">受害企业或机构</span></strong></p></td><td width="159" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(37, 64, 143);padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><strong><span style="font-size:9.0pt;mso-bidi-font-size:12.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:微软雅黑;color:white;mso-font-kerning:0pt;">造成的影响<span lang="EN-US"><o:p></o:p></span></span></strong></p></td></tr><tr style="mso-yfti-irow:1;height:14.15pt;"><td width="78" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2024/3/16<o:p></o:p></span></p></td><td width="177" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">美国Acculabs 环境检测公司</span><o:p></o:p></p></td><td width="159" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">5个压缩包，超过<strong>80GB</strong>实验室数据被公开<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:14.15pt;"><td width="78" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2023/12/7<o:p></o:p></span></p></td><td width="177" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">英国Precision Technologies 机械制造集团</span><o:p></o:p></p></td><td width="159" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">27个文件和压缩包，超过<strong>430GB</strong>企业内部数据被公开<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:14.15pt;"><td width="78" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2023/11/23<o:p></o:p></span></p></td><td width="177" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">德国B+P Gerüstbau
  GmbH 工程技术公司</span><o:p></o:p></p></td><td width="159" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">13个文件和压缩包，超过<strong>15GB</strong>数据被公开<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:14.15pt;"><td width="78" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2023/11/23<o:p></o:p></span></p></td><td width="177" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">澳大利亚DM Civil 建筑公司</span><o:p></o:p></p></td><td width="159" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">16个压缩包，超过<strong>120 GB</strong>公司数据被公开<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;height:14.15pt;"><td width="78" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2023/11/15<o:p></o:p></span></p></td><td width="177" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">菲律宾Yamaha 摩托汽车公司</span><o:p></o:p></p></td><td width="159" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">10个压缩包和文件，超过<strong>40GB</strong>内部数据被公开<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:6;height:14.15pt;"><td width="78" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2023/11/15<o:p></o:p></span></p></td><td width="177" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">法国Guardian Alarm 信息技术公司</span><o:p></o:p></p></td><td width="159" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">16个压缩包，超过<strong>59GB</strong>数据被公开<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:7;height:14.15pt;"><td width="78" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2023/11/15<o:p></o:p></span></p></td><td width="177" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">意大利SCOLARI Srl 工业集团</span><o:p></o:p></p></td><td width="159" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">9个压缩包，超过<strong>157GB</strong>数据被公开<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:8;height:14.15pt;"><td width="78" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2023/11/6<o:p></o:p></span></p></td><td width="177" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">巴基斯坦EFU Life 保险集团</span><o:p></o:p></p></td><td width="159" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">51个文件和压缩包，超过<strong>59GB</strong>数据被公开<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:9;mso-yfti-lastrow:yes;height:14.15pt;"><td width="78" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">2023/9/20<o:p></o:p></span></p></td><td width="177" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">我国深圳某电池技术公司</span><o:p></o:p></p></td><td width="159" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">17个文件和压缩包，超过<strong>87GB</strong>数据被公开<o:p></o:p></span></p></td></tr></tbody></table><h4 style="text-indent: 0em;margin-top: 16px;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">3.2 攻击目标</span></strong></span><o:p></o:p></h4><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">INC Ransom组织自去年开始活跃以来，持续在全球范围内开展勒索攻击活动，其受害者遍布全球15个国家和地区。我们对所有受害者的地区进行了分析和统计，受害者地区热力图如下图所示，该组织目前针对的攻击目标集中在北美地区、欧洲地区、东南亚地区和大洋洲地区。其中，北美地区的受害者最多，相关受害企业或机构高达47家，占目前所有INC Ransom勒索受害者总数的67%；值得一提的是，我国企业在去年8月也遭受过该组织的勒索攻击。可以看出INC Ransom组织似乎倾向于寻找较为发达地区的企业或机构作为攻击目标，一方面可能向受害者索要更高额的勒索赎金，另一方面也可以扩大该组织的影响力以提高收取赎金的成功率。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135649" data-ratio="0.562037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=15533f13&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdgd0XEmAPJduI8rkH3iciazOsRXxibcsYWiaLgs5kjDWQcNiatv50IHhPA5w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图10
INC Ransom组织受害者地区分布</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">此外，通过对该组织历史活动的大量调查分析，我们对该组织自去年首次攻击到目前为止的所有攻击活动进行了综合统计和分析，并将所有受害者的行业进行了统计。从统计图中可以发现，INC Ransom组织的攻击目标涉及多个行业；其中，学校、公益组织和工程技术行业的受害者最多，占所有受害者总数的比例超过30%；其次是医疗、金融、信息技术、化工、工业制造、能源、科研、航空等行业。可以看出，INC Ransom组织并不以特定行业的企业或机构为目标，而是倾向于那些拥有大量财务资源和敏感数据的企业或机构，以便向受害者勒索高额的赎金。INC Ransom组织在不到8个月的时间内，就攻击了超过23个行业的企业和机构，这说明它们的目标范围非常之大，各行业的企业和机构都有可能成为该勒索团伙的下一个目标，这也加剧了该组织对各企业和机构的网络安全威胁。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135650" data-ratio="0.7301775147928994" data-s="300,640" style="" data-type="png" data-w="845" src="https://wechat2rss.xlab.app/img-proxy/?k=d578d400&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdNyFiciaDBibUdSWsDtkgTdqiaYEoPuTe0MFcXRO67wGOfCYnJcbobun5Ww%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 16px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图11
INC Ransom组织受害者行业分布</span><o:p></o:p></p><h4 style="text-indent: 0em;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">3.3 攻击手法</span></strong></span><o:p></o:p></h4><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">通过对该勒索组织的历史攻击事件的分析，我们发现INC Ransom组织通常采用多种攻击手段组合的方式来对目标进行入侵，其中包括利用鱼叉式网络钓鱼方式进行初步访问权限获取、利用漏洞（比如CVE-2023-3519）以及各种商用软件（如Anydesk）和正常的系统工具（如mstsc）进行内部网络的侦察和横向移动，然后利用系统工具或软件对目标主机中的敏感文件进行获取，并上传勒索软件进行文件加密和勒索。这种组合式攻击手段相对复杂，需要攻击者分阶段完成入侵任务，通常需要较长的攻击周期，但这种使用漏洞和正常软件的入侵方式相对隐蔽并且不易被内部网络防御系统和安全系统检测，往往能够取得较高的攻击成功率。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">结合历史攻击案例，我们总结了INC Ransom组织的主要攻击流程：</span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p style="text-indent: 2em;margin-bottom: 0px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（1）初始访问权限获取：该组织首先使用漏洞攻击、鱼叉式钓鱼邮件或购买IAB(Initial Access Brokers-初始访问代理业务)来获取系统的初始访问权限（如系统或者软件登录凭证）。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 0px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（2）远程桌面软件利用：INC Ransom组织经常使用窃取的身份凭证通过远程桌面软件登录目标系统。在此期间，它们会进行多种信息收集和网络测试活动，其中包括扫描域管理员、网络连接测试和内部主机脆弱性扫描等。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 0px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（3）数据收集和存储：在整个入侵过程中，INC Ransom 组织会使用多种正常的软件或工具进行数据实际和存储，比如使用Zip归档命令进行数据收集、使用Wordpad、Notepad 和 MSPaint 等主机自带的正常工具进行文档和图像等文件搜索。它们还会在目标主机上安装MEGASync进行数据传输。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 0px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（4）横向移动和凭据访问：INC Ransom 组织会尝试在网络中进行横向移动，尝试访问内网中的其他主机或服务器以获取更多的重要数据或控制更多的设备。该组织经常使用Advanced IP Scanner等工具来进行内网扫描，同时使用lsassy等工具从系统中提取登录凭证。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 0px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（5）文件加密和勒索软件部署：前期的横向移动和数据收集通常会持续较长的时间，以获取更多的重要数据或控制更多的设备，从而扩大攻击范围。待横向移动和数据收集工作完成后，INC Ransom 组织才会在目标主机上部署勒索软件以提示受害者。INC Ransom组织经常使用 wmic.exe 和 PSExec（伪装为winupd）的组合方式来跨多个端点启动文件加密程序，这种方式可以自动化并且快速地完成文件加密任务。</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（6）故障排除：在整个攻击过程中，可能出现多种异常情况，INC Ransom组织还针对不同故障制定了不同故障排除方案和问题解决方案。例如，INC
Ransom组织会在部署勒索软件的过程中多次尝试部署相关的解决脚本或命令，从而使得勒索软件正常执行</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">。</span></p><p><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">INC Ransom 组织在某次历史勒索攻击活动中的攻击流程如下图所示：</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135651" data-ratio="1.2736686390532543" data-s="300,640" style="" data-type="png" data-w="676" src="https://wechat2rss.xlab.app/img-proxy/?k=66042795&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdLw9JtDjgoXGPVLngNy9vq1pAllPibT8jRVEgUPov1AROd1icZlScmOtA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图12
INC Ra</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">nsom组织攻击历史流程示例</span></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><br/></p><p style="font-size:16px;color:#fefefe;line-height:25px;letter-spacing:0;"><strong>4</strong></p><p style="font-size:16px;letter-spacing:2px;color:#77b4f2;"><strong>案例分析</strong></p><p><img data-imgfileid="502135652" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e29f16e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn5O6B3JBlb4TgDrxf0ROk3SU0YBQ0Gc7mWbXoU0KzfSGvXFuATYYsTyaDSG7QKSia3icjFqRYjfpPqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;"><br/></span></p><h3 style="text-indent: 2em;margin-bottom: 0px;"><o:p></o:p></h3><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">通过对收集到的INC Ransom家族样本进行分析，我们发现该团伙同时针对Windows平台和Linux平台开展勒索攻击。其中，Linux平台主要针对VMware ESXI虚拟机实施定制化攻击，更多有关针对云虚拟化平台的攻击的原理与技术分析可以参阅我们发布的专题文章《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649618009&amp;idx=1&amp;sn=177518c3527e4343c736914b06501a3d&amp;chksm=83062b49b471a25f8c0fe854b31d51089e46f9c4806d03b71b8fbbaf64c7fa2dea89e0c1c1bd&amp;scene=21#wechat_redirect" textvalue="针对VMware云虚拟化平台的定制化攻击专题分析" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">针对VMware云虚拟化平台的定制化攻击专题分析</a>》，下文将分别对INC Ransom家族的两类样本进行具体分析。</span><o:p></o:p></p><h4 style="text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">4.1 Windows平台勒索攻击样本</span></strong></span><o:p></o:p></h4><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">勒索软件在启动后先获取命令行参数，再由此决定要执行的初始功能。若无参数则尝试加密本地设备中的所有可用卷和文件。相关代码如下图所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135653" data-ratio="0.6564885496183206" data-s="300,640" style="" data-type="png" data-w="524" src="https://wechat2rss.xlab.app/img-proxy/?k=bc8a4a42&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVde6rT1d9y0b4obOu3N8k9M2ibiaehIIw1v08ib5SeHpfAOUU0ZNjKhu2nQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图13 获取命令行参数</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">该勒索软件支持多种命令行参数，通过分析我们整理出其支持的所有参数及相对应的功能。具体如下表所示。</span><o:p></o:p></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">表2 参数与相关功能</span></p><table cellspacing="0" cellpadding="0" width="544"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:14.15pt;"><td width="153" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(37, 64, 143);padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;"><strong><span style="font-family: 微软雅黑, &#34;sans-serif&#34;;color: white;">参数<o:p></o:p></span></strong></span></p></td><td width="254" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(37, 64, 143);padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><strong><span style="font-size:9.0pt;mso-bidi-font-size:12.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:微软雅黑;color:white;mso-font-kerning:0pt;">功能<span lang="EN-US"><o:p></o:p></span></span></strong></p></td></tr><tr style="mso-yfti-irow:1;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--file<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">加密指定文件<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--dir<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">加密指定目录<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--sup<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">停止正在运行的进程<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--ens<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">加密网络共享<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--lhd<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">本地隐藏驱动器（加密隐藏的启动和恢复卷）<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:6;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--debug<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">输出有关加密过程的信息记录<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:7;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--kill<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">杀死指定进程和服务<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:8;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--help<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">显示help信息<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:9;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--safe-mode<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">启动安全模式<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:10;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--hide<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">隐藏控制台窗口<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:11;mso-yfti-lastrow:yes;height:14.15pt;"><td width="153" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--mode<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">文件加密模式<o:p></o:p></span></p></td></tr></tbody></table><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在参数“--file”命令（加密指定文件）功能代码中，为了避免在加密过程中出现不能访问的错误，勒索软件会重新启动管理器，并杀死所有正在运行的进程。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135654" data-ratio="0.6025998142989787" data-s="300,640" style="" data-type="png" data-w="1077" src="https://wechat2rss.xlab.app/img-proxy/?k=b0be2ddd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdxaia8fGOkJGiayBPW07qzVibibDDA3uN5Tsegvn16mGxsfFia7pn6fS0XtA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图14 杀死正在运行的进程</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">当参数为“--dir”命令时，勒索软件首先会排除特定扩展名的文件及目录，随后再对指定目录进行加密处理。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135655" data-ratio="0.792022792022792" data-s="300,640" style="" data-type="png" data-w="702" src="https://wechat2rss.xlab.app/img-proxy/?k=4422aa51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdcsWAib4Td7dmo8n2o954vGMiaUJRiaKmSwKrvpHIicXfEQo1IDLaBdjGibA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图15 排除指定文件和目录</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">当使用“--lhd” 参数执行时，勒索软件会检查主机上是否存在隐藏驱动器，若存在则加载该驱动器，以便对其进行加密处理。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135656" data-ratio="1.0778816199376946" data-s="300,640" style="" data-type="png" data-w="642" src="https://wechat2rss.xlab.app/img-proxy/?k=7776813d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVduELsMDOuVibBia44ibuTz3l4H1CNJSqpTlGQD6StaaEXBI1I6zLDgZx6g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图16 查看隐藏驱动器</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">当参数为“--ens”时，勒索软件还会对网络共享进行加密操作，具体代码如下图所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135657" data-ratio="1.124748490945674" data-s="300,640" style="" data-type="png" data-w="497" src="https://wechat2rss.xlab.app/img-proxy/?k=ed926ca1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdibLwaELc7biczQFUVXpvO1WFJUlZm7tn2kJTY5MH5TfLePhCiaopFtwJg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图17 加密网络共享</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">为了进一步巩固对受害者数据的控制，勒索软件会使用DeviceIoControl函数试图将受害者主机中的卷影副本（VSS）进行删除，并清空回收站。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135658" data-ratio="0.7715355805243446" data-s="300,640" style="" data-type="png" data-w="801" src="https://wechat2rss.xlab.app/img-proxy/?k=cfbe15e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdYkE8jT0ZQBCTtFz2PBZLAqKaXVdEKP37A0BBVLOSTKyPicMbCm7Pt6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图18 删除卷影副本及清空回收站</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在根据参数进行一系列操作之后，勒索软件则使用CryptStringToBinaryA函数将硬编码在内存中的base64数据进行解码，以此获得勒索信内容。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135659" data-ratio="0.5069033530571992" data-s="300,640" style="" data-type="png" data-w="1014" src="https://wechat2rss.xlab.app/img-proxy/?k=2194937b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVd8BTq52eWiahCQlRp0pyq3LUPnbJZHuk8Cia6Mia6ibrQicYS8yMp5glnKvg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图19 解码勒索信内容</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">解码后我们可以看到勒索信包括两种文件格式（如下图），后续勒索软件会将勒索信写入到每个包含加密项目的文件夹中，而勒索信的副本则以.TXT和.HTML格式分别命名为”INC-README.html”和“INC-README.txt” 。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135660" data-ratio="0.7551401869158878" data-s="300,640" style="" data-type="png" data-w="1070" src="https://wechat2rss.xlab.app/img-proxy/?k=b243f845&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdXgtTuATNhcAVM5TIm5BT3tbgvibxBCCX8xnoxDrrGicel7tsJhSWP5Iw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图20 勒索信内容</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">勒索软件还会查看受害者主机系统中是否存在特定驱动程序（Microsoft Print to PDF，或Microsoft XPS
Document Writer）。之后在网络内寻找可使用的打印机，若有则尝试连接打印机并打印勒索信。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135661" data-ratio="0.7842876165113183" data-s="300,640" style="" data-type="png" data-w="751" src="https://wechat2rss.xlab.app/img-proxy/?k=46ad515a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdXOFdIk1NgReqKaO4qYicAKKBMm056yzpYJpJqrvGPHK78XWCc7lY5icQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图21 查找并打印勒索信</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在完成所有加密功能之后，勒索软件会更改受害者主机的背景壁纸，再使用Fixdsys字体在屏幕上显示勒索信内容。具体代码如下图所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135662" data-ratio="0.655448717948718" data-s="300,640" style="" data-type="png" data-w="624" src="https://wechat2rss.xlab.app/img-proxy/?k=6946c4d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdaGC2wKgOC4icQ3nqUKz4TRUCiaSMIuyYehib5PvD8MUoEn4Y4k0D3daaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图22 更改主机背景</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">通过分析我们发现，该勒索软件在加密过程中采用多线程技术来加快其加密速度，为了使多线程能够并行运行，其还采用了IOCP（I/O Completion Port，中文译为I/O完成端口）模型。IOCP是一种高效的异步I/O处理机制，可用于管理和调度线程池中的线程，使用该模型既能减少线程资源，又能够提高线程的利用率。具体代码如下图所示。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-backh="178" data-backw="578" data-galleryid="" data-imgfileid="502135663" data-ratio="0.30757097791798105" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="634" src="https://wechat2rss.xlab.app/img-proxy/?k=fc030db3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdQkFwPGL7fTibIEN3Hx6AlU16BAmHBG9DosxpKWwiakouPTDAFswRYABQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图23 I/O完成端口的使用</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">除此之外，勒索软件还使用仅加密部分文件来提高加密速度，实现规则为：若文件小于1MB，则将整个文件加密；如果文件大于1MB且小于3MB时，则加密1MB内容；如果文件大于3MB，则采用间隔加密（1MB加密，2MB不加密）的方法。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135664" data-ratio="0.5361111111111111" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ad5986e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdVBUgouTm6vBTFZlyEU7JgdrNdLoiaxtNulYy3JAD5cdsXTBf7GicSjXA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图24 加密部分文件</span><o:p></o:p></p><h4 style="text-indent: 0em;margin-bottom: 16px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">4.2 Linux 平台勒索攻击样本</span></strong></span><o:p></o:p></h4><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">INC Ransom定制了针对Linux平台的攻击武器，以实现支持VMware ESXI的定制化攻击。程序执行时，勒索软件会根据程序运行时的参数执行不同的操作，相关参数和代码如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135665" data-ratio="0.4638888888888889" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=413cc161&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdsVicKTodHmCNcA1stLyhfYuHN3x0L3BZsKdDp3v1OUPvKEzKFXkRDVA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图25  解析命令行参数</span><o:p></o:p></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">表3 参数及相关功能</span></p><table cellspacing="0" cellpadding="0" width="525"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:14.15pt;"><td width="139" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;background: rgb(37, 64, 143);padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;"><strong><span style="font-family: 微软雅黑, &#34;sans-serif&#34;;color: white;">参数<o:p></o:p></span></strong></span></p></td><td width="254" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: none;background: rgb(37, 64, 143);padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="mso-bookmark:_Hlk148452972;"><strong><span style="font-size:9.0pt;mso-bidi-font-size:12.0pt;font-family:&#34;微软雅黑&#34;,&#34;sans-serif&#34;;mso-bidi-font-family:
  微软雅黑;color:white;mso-font-kerning:0pt;">功能<span lang="EN-US"><o:p></o:p></span></span></strong></span></p></td></tr><tr style="mso-yfti-irow:1;height:14.15pt;"><td width="139" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--debug<span lang="EN-US" style="font-size: 12px;font-family: Arial, &#34;sans-serif&#34;;"><o:p></o:p></span></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">输出有关加密过程的信息记录<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:14.15pt;"><td width="139" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--file<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">加密指定文件<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:14.15pt;"><td width="139" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--dir<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">加密指定目录<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:14.15pt;"><td width="139" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--daeon<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">守护进程<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;height:14.15pt;"><td width="139" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--esxi<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">停止esxi vm服务<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:6;height:14.15pt;"><td width="139" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--motd<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">勒索信息写入/etc/motd（登录提示）<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:7;mso-yfti-lastrow:yes;height:14.15pt;"><td width="139" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-top: none;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;mso-pagination:widow-orphan;"><span style="font-size: 12px;color: rgb(136, 136, 136);">--skip<o:p></o:p></span></p></td><td width="254" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;" height="14"><p style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:
  justify;text-justify:inter-ideograph;line-height:normal;"><span style="font-size: 12px;color: rgb(136, 136, 136);">排除esxi vm服务（不停止）<o:p></o:p></span></p></td></tr></tbody></table><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">其中的关键参数介绍如下：</span></p><p><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">首先，为了避免在执行加密时出现不能访问的错误，恶意软件通过设置“--esxi”参数和“--skip”参数从而关闭已开启的虚拟机及ESXI服务，其中skip参数用于排除相关的VM虚拟机。相关代码如下图所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135666" data-ratio="0.23981481481481481" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ea385594&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdRyrRq3icZGkgtAicf75JEntibvrtl0yPPErTh85Bcnvxzia7QkfbGO5zgw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图26 停止VM虚拟机(排除指定虚拟机)</span><o:p></o:p></p><p style="margin-bottom: 0px;text-indent: 2em;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在排除指定虚拟机后，针对其它vm虚拟机进行强制关闭。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135667" data-ratio="0.1712962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=418eacf5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdKyia95icc9nBWUWrn8nrOnrZUSDL0sA3DByz6OFUJdbTPnd5jDfHMsuA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图27 停止VM虚拟机代码</span><o:p></o:p></p><p style="margin-bottom: 0px;text-indent: 2em;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">之后，勒索软件通过配置“--dir”参数或“--file”参数实施加密。</span><o:p></o:p></p><p style="margin-bottom: 0px;text-indent: 2em;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">当执行“--dir”参数时，程序默认只加密指定目录下的Vmware虚拟机相关后缀文件，包括vmdk、vmem、vmx、vswp、vmsn，说明其主要目标是加密虚拟机文件。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135668" data-ratio="0.41203703703703703" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d15baf7a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdYRkVUW94k2qluyUiawmgg3icLXDPt0LEgAwFl4QibrpF8scjsZZ0dE45A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图28 加密的虚拟机文件后缀</span><o:p></o:p></p><p style="margin-bottom: 0px;text-indent: 2em;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">当执行“--file”参数时，则不限制文件类型，可针对任意文件进行加密。</span><o:p></o:p></p><p style="margin-bottom: 0px;text-indent: 2em;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">当执行“--motd”参数时，程序会将勒索信写入/etc/motd文件中，/etc/motd文件可以在用户每次系统登录时，通过终端展示消息给<span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">登录</span>用户，如向用户提示欢迎信息（此处被勒索软件更换为勒索信息）。命令行登录界面如下图所示（测试机）：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135669" data-ratio="0.603578154425612" data-s="300,640" style="" data-type="png" data-w="1062" src="https://wechat2rss.xlab.app/img-proxy/?k=04fb2c4b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdKGsIakatREWUh7QImCbk7GctFbwuC5WHpBwibibs6eG96aicicfO1wxlqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图29 命令行<span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">登录</span>勒索信息</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">加密目录时，与windows平台的勒索相似，linux勒索程序也会在该目录内同时创建html格式和txt格式的勒索信如下所示：</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135670" data-ratio="0.5833333333333334" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=329d1a62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTbxhNCHe9JORQk4x4aOnVdmT4x88OyXN0bIy1j7UVJAnSvWohpzDdcBC4QKictAJiak3QnYRicgX9LA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图30 html和txt格式的勒索信</span><o:p></o:p></p><p style="text-indent: 0em;text-align: center;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="font-size:16px;color:#fefefe;line-height:25px;letter-spacing:0;"><strong>5</strong></p><p style="font-size:16px;letter-spacing:2px;color:#77b4f2;"><strong>复盘与思考</strong></p><p><img data-imgfileid="502135671" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e29f16e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn5O6B3JBlb4TgDrxf0ROk3SU0YBQ0Gc7mWbXoU0KzfSGvXFuATYYsTyaDSG7QKSia3icjFqRYjfpPqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">随着勒索团伙逐渐“APT化”、“定向化”，其攻击方式开始逐渐演变为“窃密+加密”的双重勒索策略，甚至还可能增加DDoS攻击等更多攻击<span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">形式</span>作为“多重勒索”的手段，迫使受害方交纳赎金。其中，尤以窃取文件并实施威胁曝光的手段最为致命，对于一些敏感行业，如国防工业、关键基础设施领域的相关部门和企业来说，相关系统涉及重要的机密资料，即使交纳赎金，勒索团伙也可能将数据二次售卖和传播，如若涉及机密数据则可能造成重大的安全隐患。从去年智利军方遭到勒索攻击和此次秘鲁军方遭到攻击的事件来看，尽管军队网络与互联网存在物理隔离，但同样可能因为不当的网络安全防御策略、不严格的文件授权管理方式、甚至是“内部人员”主动参与勒索等情况，造成内网中的敏感文件遭到窃取并导致失泄密事件的发生，需要引起足够的重视。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">物理隔离主要用于在一定程度上抑制涉密网络与公共网络连接所涉及衍生的各类安全问题。包括国防工业和各类国家基础工业领域中的大量工控系统，如电力、水利、石油、交通等诸多方面，其数据价值不可估量。采用物理隔离能够在一定程度上减少网络安全威胁，但采用物理隔离措施进行安全防范的网络同样需要面对诸多风险，如：</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（1）物理隔离造成的安全意识薄弱</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">在物理隔离的内网环境中，其管理人员的安全意识往往会更加薄弱。这也造成大量物理隔离网络中，存在网络设备和操作系统等版本老旧、漏洞更新不及时等大量安全隐患，一旦单点设备遭到攻击入侵，往往整个内网都极易沦陷。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（2）内部威胁行为难以防范</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">安全管理最困难的地方在于内部威胁，内部人员一旦受到利益胁持，包括有意或无意的恶意行为都有可能引发网络安全事件，如通过U盘实施“摆渡攻击”，“震网”攻击、“水腹蛇”攻击等都是美国通过“摆渡攻击”的形式成功渗透进入伊朗核设施隔离网络并造成严重破坏；再比如去年智利军方遭到勒索攻击的事件，也疑似与内部一名陆军下士的参与有关。</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（3）物理隔离往往难以完全隔绝</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">随着当前云服务、数字政务、物联网互联等新型技术的不断发展，大量号称物理隔离的系统，其实也可能存在与外网的联通点。即使网络系统在设计之初符合安全要求，但随着相关系统的长期建设与发展，难免存在私自接入设备或网络拓扑被改变的情况，又或是一些移动可联网终端的加入，当这些设备同时接入办公网和外网时，就可能间接造成内网暴露并存在安全隐患。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（4）跨网窃密新型技术</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">目前，已知物理隔离面临的一些跨网窃密攻击方式，包括如USB攻击、电力线攻击、光信道攻击、声信道攻击等等，都可能对物理隔离安全构成风险和危害。例如以色列研究人员开发的“Bitwhisper”技术，通过利用计算机处理数据时产生的热量变化来传输信息；例如利用设备电磁辐射跨网窃密，通过发送特殊设计的密文，引起目标计算机电磁场变化，攻击者通过接收这些变化来提取信息；再比如利用“PowerHammer”技术通过在物理隔离设备上安装恶意软件，并利用电源线传输数据等。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">目前，尽管秘鲁军队还未披露此次遭到勒索攻击的更多细节，比如其内网是否遭到了全面入侵亦或是有内鬼参与了攻击活动，但这起勒索事件警示我们，要正视传统物理隔离网络也正在面临着越来越多的挑战。物理隔离只能作为基础防护措施，随着攻击手段的日新月异，伴随着更多的新型攻击手段出现，包括越来越复杂的APT攻击、定向勒索攻击、供应链攻击等等，需要结合各类有效的防护措施，尤其是内部人员的安全意识培训和严格管理，做好事前预防、事中控制、事后处置的全面准备，只有构建全系统防御体系和完善的应急响应机制，才能更好的应对各类频发的网络攻击活动。</span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="font-size:16px;color:#fefefe;line-height:25px;letter-spacing:0;"><strong>6</strong></p><p style="font-size:16px;letter-spacing:2px;color:#77b4f2;"><strong>防护建议</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135672" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e29f16e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn5O6B3JBlb4TgDrxf0ROk3SU0YBQ0Gc7mWbXoU0KzfSGvXFuATYYsTyaDSG7QKSia3icjFqRYjfpPqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p><br/></p><p style="margin-bottom: 0px;text-indent: 2em;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（1）针对核心业务系统做好数据备份与灾难恢复方案（3-2-1规则）。</span><o:p></o:p></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">至少准备三种副本；</span></p></li><li><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">两种不同保存形式：</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">进行多存储类型保存，如服务器、移动硬盘、云端、光盘等；</span></p></li><li><p style="text-indent: 0em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">至少一份异地备份（脱机）：</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">防止勒索病毒将联机的备份系统加密。</span></p></li></ul><p><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（2）提高内部人员安全意识，不要点击来源不明的邮件以及附件，尤其对于敏感部门要警惕内部威胁并做好风险预防。</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（3）定期检查操作系统和软件漏洞，及时更新安全补丁。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（4）定期更换<span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">登录</span>口令，避免空口令或弱口令。</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（5）如无必要，尽可能不将产品直接暴露在互联网中，如必须联网应将设备连接至防火墙、IDS、IPS等安全设备以加强防护。</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（6）加强网络边界入侵防范和管理，关闭非必要网络服务和端口，如445、135、139、3389、5900。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">（7）严格针对核心业务系统进行安全隔离。</span><o:p></o:p></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="font-size:16px;color:#fefefe;line-height:25px;letter-spacing:0;"><strong>7</strong></p><p style="font-size:16px;letter-spacing:2px;color:#77b4f2;"><strong>IOC</strong></p><p><img class="rich_pages wxw-img" data-imgfileid="502135673" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="33" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=e29f16e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn5O6B3JBlb4TgDrxf0ROk3SU0YBQ0Gc7mWbXoU0KzfSGvXFuATYYsTyaDSG7QKSia3icjFqRYjfpPqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p style="text-indent: 0em;margin-bottom: 8px;"><strong><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">勒索URLs：</span></strong><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span><o:p></o:p></p><p style="text-indent: 0em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">incblog7vmuq7rktic73r4ha4j757m3ptym37tyvifzp2roedyyzzxid.onion</span><o:p></o:p></p><p style="text-indent: 0em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">incbackrlasjesgpfu5brktfjknbqoahe2hhmqfhasc5fb56mtukn4yd.onion</span><o:p></o:p></p><p style="text-indent: 0em;margin-bottom: 8px;"><strong><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">样本SHA256:</span></strong><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span><o:p></o:p></p><p style="text-indent: 0em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">508a644d552f237615d1504aa1628566fe0e752a5bc0c882fa72b3155c322cef</span><o:p></o:p></p><p style="text-indent: 0em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">36e3c83e50a19ad1048dab7814f3922631990578aab0790401bc67dbcc90a72e</span><o:p></o:p></p><p style="text-indent: 0em;margin-bottom: 8px;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">a0ceb258924ef004fa4efeef4bc0a86012afdb858e855ed14f1bbd31ca2e42f5</span><o:p></o:p></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">fcefe50ed02c8d315272a94f860451bfd3d86fa6ffac215e69dfa26a7a5deced</span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p><br/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="outline: 0px;line-height: 1.8;"></span></p><p><br/></p><p style="outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="outline: 0px;">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截止目前，ADLab已通过CVE累计发布安全漏洞近1200个，通过 CNVD/CNNVD/NVDB累计发布安全漏洞4000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="outline: 0px;">5G安全研究、<span style="outline: 0px;">人工智能安全研究、</span></span></span><span style="outline: 0px;">移动与物联网安全研究、</span><span style="outline: 0px;">工控安全研究、信创安全研究、</span><span style="outline: 0px;">云安全研究、</span><span style="outline: 0px;">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="outline: 0px;letter-spacing: 1.5px;">。</span></span><span style="outline: 0px;"></span></p><p><br/></p><p style="outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135674" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 282px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=d9cfb2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Fri, 29 Mar 2024 18:51:22 +0800</pubDate>
    </item>
    <item>
      <title>启明星辰ADLab：工控设备数据安全研究</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619274&amp;idx=1&amp;sn=e621bc62df882b2d58bc946ae329384d&amp;chksm=8306265ab471af4cd48015e690b288c6bc23656534cee137543659ab31e100bd4f4b25182b83&amp;scene=58&amp;subscene=0#rd</link>
      <description>工业互联网是传统制造业数字化转型的必然选择，工控设备数据安全在工业数据安全中具有关键地位。本文旨在探讨数据安全体系建设中，围绕工控设备数据构建的防御机制和薄弱点。通过具体案例揭示工业数据安全问题的实际影响。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-01-25 18:38</span> <span style="display: inline-block;">北京</span>
</p>

<p>工业互联网是传统制造业数字化转型的必然选择，工控设备数据安全在工业数据安全中具有关键地位。本文旨在探讨数据安全体系建设中，围绕工控设备数据构建的防御机制和薄弱点。通过具体案例揭示工业数据安全问题的实际影响。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=d8f025f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6CrrsribMTM4ibGbVA4wAw2bprgSdovnC8Ae1HGgCwzSJy7nLiblcqVCibRw%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br/></p><h2 style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;text-indent: 2em;visibility: visible;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></h2><p><br/></p><p style="font-size:16px;letter-spacing:2px;color:#1f5cc1;"><strong>一、前 言</strong></p><p><br/></p><p><img class="rich_pages wxw-img" data-imgfileid="502135606" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="44" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=b5477a90&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn4gtOjGqNzIohBYJMwzicFE86qgtMctYnvEuW8mh3tBT15aZDbia6DbPKho1v3iaGmE4kDeUCIIdQdsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">近年来，我国围绕“加快数字化发展，建设数字中国”战略目标，持续出台数字化转型相关政策，驱动传统产业数字化转型，推动数字化赋能千行百业。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">工业互联网是传统制造业数字化转型的必然选择，而工业数据安全又是工业互联网安全的核心所在。随着物联网的不断发展，工控设备之间的连接性日益增强，工业数据安全的挑战日益严峻。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">工控设备数据安全在工业数据安全中具有关键地位。工控设备如可编程逻辑控制器（PLC）、人机界面（HMI）、分布式控制系统（DCS）等，直接接触生产设施，是现代工业自动化生产的关键节点和控制中枢。工控设备数据的泄露、篡改或被未授权方访问有可能导致生产中断、原料报废，甚至设备破坏和人员伤亡，产生巨大安全风险和直接经济损失。相比较其它工业数据的泄露，工控设备数据安全的破坏带来的影响更加直接和剧烈。因此，保护工业环境中的工控设备数据安全尤其重要。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">本文旨在探讨数据安全体系建设中，围绕工控设备数据构建的防御机制和薄弱点。通过具体案例，我们将揭示工业数据安全问题的实际影响。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p><br/></p><p style="font-size:16px;letter-spacing:2px;color:#1f5cc1;"><strong>二、防御机制</strong></p><p><br/></p><p><img data-imgfileid="502135607" data-ratio="1" style="width:100%;display:block;vertical-align:bottom;" data-w="44" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=b5477a90&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn4gtOjGqNzIohBYJMwzicFE86qgtMctYnvEuW8mh3tBT15aZDbia6DbPKho1v3iaGmE4kDeUCIIdQdsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 8px;"><br/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">工控设备数据指的是在工业控制系统中产生、处理和传输的数据。工控设备通过收集、监控、分析数据，从而执行相应的逻辑指令。工控设备数据涵盖多种极为敏感的信息，按照来源和类型分类，主要包括：</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">设备数据：</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">涉及到工控设备的型号、版本、性能、运行时长等数据。</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">运行数据：</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">包括生产线的实时运行状态、设备的运转情况、生产效率等信息。</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">程序数据：</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">包括产线控制逻辑、生产工艺、产线规模、生产过程中的各个参数和指标等数据。</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">传感器数据：</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">工业传感器收集并汇集到工控设备中的产线数据，如温度、湿度、压力、振动等参数。</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">通信数据：</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">工业网络中传输的数据，包括设备之间的通信、远程监控等信息。</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">记录数据：</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">控制器或其它存储设备中存储的过往数据，包括生产记录、故障报告、历史记录。</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">加密数据：</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">用于管理设备和文件读写权限的加密机制相关数据，包括用户设置的密码和通信加密密钥等。</span></p></li></ul><p><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">为了保护上述数据，工业设备供应商通常会设计多种防御机制，以应对工业环境中有可能出现的入侵和威胁，主要包括：</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">工程加密：</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">基于工程项目的加密验证机制，保护项目工程数据不被非法阅览、修改、运行。</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">能够同时作用于上位机端和设备端。</span></p></li></ul><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135608" data-ratio="0.55" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3cabc5e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6C7ftBtWtEf1UQDibsNTkiaXYJZuKFKQB3WOtPG6zrIj7iaI0w97B6IKGuQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><o:p></o:p></p><p><o:p></o:p></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">设备加密：基于工控设备的加密验证机制，能保护工控设备不执行非法用户通过数据传输的功能指令。</span><o:p></o:p></p></li></ul><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135609" data-ratio="0.3953033268101761" data-s="300,640" style="" data-type="png" data-w="1022" src="https://wechat2rss.xlab.app/img-proxy/?k=ac20def1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6CsvWCnbVUm1n41rYWWBxpVwmexKX2icUpKPWiaGFj3MYg9w7m4xb2nG3w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">程序加密：基于程序的加密机制，能保护关键程序数据信息不被非法读取。</span><o:p></o:p></p></li></ul><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135610" data-ratio="0.38796296296296295" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2f16ef00&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6Cr9II2mjGhqqtNVQILcqWwkYN5BVOV7c8gHI3tcB4xYlhPicnvefAQ9w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><span style="font-size:10.5pt;mso-bidi-font-size:
12.0pt;font-family:&#34;Calibri&#34;,&#34;sans-serif&#34;;mso-fareast-font-family:宋体;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-font-kerning:1.0pt;mso-ansi-language:
EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;mso-no-proof:yes;" lang="EN-US"></span></span></p><p><o:p></o:p></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">文件加密：防止非法读写工控设备中存储的文件数据。</span><o:p></o:p></p></li></ul><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135612" data-ratio="0.32037037037037036" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=706f785a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6CzSR6GTia25oiaHsuJdDnmmzZbBJju57qX6M7RuabeoDDK0kJiczvgzibOA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">以太网加密：限制允许访问工控设备的外部设备，验证数据的来源和出入口。主要包括IP、端口、协议筛选，直接连接功能禁用（限定IP），不响应网络搜索，以太网口禁用，启停以太网服务（web服务、ftp服务）等功能。</span><o:p></o:p></p></li><li><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">连接加密：保护允许远程连接的工控设备被外部设备访问时连接权限的安全性。</span><o:p></o:p></p></li></ul><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135613" data-ratio="0.3907407407407407" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2f42a348&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6CN9es5gPiaJbZeKHwnw0iarup9AaGvsPB4RhdQN1sib6LB9WbJWAYump7A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">动作权限加密：保护工控设备被已连接的外部设备下达关键指令时指令权限的安全性。</span><o:p></o:p></p></li></ul><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135614" data-ratio="0.4861111111111111" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d388f3ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6CtRzo9KIicdXnFrs7x5bOK0u1ZIRick8QMrBxJoTzdd3jibvQ6tEHibpia6A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p style="font-size: 16px;letter-spacing: 2px;color: rgb(31, 92, 193);"><strong>三、案例分析</strong></p><p><br/></p><p><img data-imgfileid="502135615" data-ratio="1" style="width: 20px;display: block;vertical-align: bottom;" data-w="44" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=b5477a90&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn4gtOjGqNzIohBYJMwzicFE86qgtMctYnvEuW8mh3tBT15aZDbia6DbPKho1v3iaGmE4kDeUCIIdQdsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="letter-spacing: 0.578px;text-wrap: wrap;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;margin-bottom: 8px;"><br/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">虽然业界已经存在多种多样的验证机制，但考虑工控设备在过去通常在封闭环境内运行，且使用专有的通信协议，不如通用的网络协议那样经过充分的安全性设计和迭代，因此常常存在众多薄弱点；且工控设备要求稳定长期运行，因此其固件更新和迭代受到限制，带洞设备存量较大。一旦工控设备与企业内部网络或者互联网连接，面对全新的安全挑战，就会更容易招致攻击。设备后门、web类、硬编码加密等问题，会导致攻击者无需破解复杂的加密机制，即可获取设备权限，接触敏感数据。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">为了进一步深入理解，下面我们将通过案例展示工控设备数据面临威胁的实际情况。我们将重点放在案例中存在的安全问题上，从而提供对工控设备数据安全管理的参考见解。</span><o:p></o:p></p><p><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">3.1 工程加密存在后门问题：导致设备数据泄露</span></strong></span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">使用工程加密机制的工控设备，密码数据与项目高度关联，加密数据存储在工程项目中，与项目一一绑定，其设置、修改、重置操作均视为对项目的修改。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135616" data-ratio="0.4537037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8c849726&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6CicCG35icII6QBbE2kqRKsH7KE9uClXM6kmYZVSqnx9qiaIfeZWeicIg8Cw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">上图是一种基于项目的加密机制示意图，可见密码信息随项目移动并生效的机制：当项目存储在本地时，该密码用于保护项目数据不被非法阅览；当项目存储在工控设备中时，该密码用于保护工控设备不被非法连接或执行非法功能。外界用户在访问装载有加密工程的工控设备时，需要首先输入密码，以获取连接权限。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">此类设备由于项目与密码联系紧密，供应商通常提供官方售后服务：如果用户忘记密码，可从官方途径获取动态后门密钥，而只需提供上位机软件中自动记录的设备通信数据。后门密钥基于项目数据和通信数据，通过某种密钥算法生成。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">虽然后门密钥的生成需要仰赖官方，但由于后门密钥的校验步骤在上位机端进行，因此上位机软件内也存在密钥生成算法。通过对上位机软件进行研究，可以逆向分析出相关算法。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135617" data-ratio="0.19696969696969696" data-s="300,640" style="" data-type="png" data-w="990" src="https://wechat2rss.xlab.app/img-proxy/?k=9b93387f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6C5wqFwThGSCTDahW6dpFzyYjrYb9xMWztWL0W6cp0rZLmbl0QibiczDOg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135618" data-ratio="0.7583333333333333" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=555e58bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6CtFfHpK3icH0q2EYhYMykIEprJOt44twq9cmuvpibcH7YmahPhziaUp9WA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p><o:p></o:p></p><p><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">一旦找到后门密钥的算法，攻击者就掌握了绕过设备密码验证的备用钥匙。通过编写通信脚本，攻击者可直接通过上位机和设备的校验，获取连接权限，从而窃取设备数据。</span><o:p></o:p></p><p><strong><span style="outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;color: rgb(0, 82, 255);">3.2 文件加密存在未授权备份问题：导致工程数据泄露</span></strong><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">PLC的SD卡插槽是一种较为经典的设计，它为PLC的使用和功能扩展带来了便利。PLC的SD卡通常用于以下几个方面：</span><o:p></o:p></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">程序的存储、备份：用于存储PLC的程序和配置文件。在需要批量更新多个PLC时，使用SD卡进行程序的复制和分发是一种可靠且便捷的方法。同时，SD卡也可以用于备份当前系统的配置和项目程序，以便在出现问题时快速恢复。</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">数据记录：</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">可将运行数据、事件日志或故障记录保存到SD卡中。</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">这对于故障诊断、性能监测和数据分析非常有用。</span></p></li><li><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">固件更新：</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">通过SD卡，可以方便地对PLC进行固件升级。</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">用户只需将更新文件复制到SD卡，然后插入PLC进行更新。</span></p></li></ul><p><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">就SD卡备份功能而言，其初衷为保存PLC中项目文件的副本，以用于程序备份和复制。然而随着工业互联网发展，对数据安全要求的提高，PLC中的安全机制越来越多，这使得缺乏验证权限机制的SD卡备份功能成为许多攻击者关注的薄弱点。物理层面能够接触到PLC的攻击者，可以使用SD卡通过备份方式获取PLC中数据，从而无视既有安全机制。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">当然，不乏已经开始设置SD卡通道权限的厂商，但受限于工控设备硬件更新限制，在现有条件下，此类新式机制常常仅在软件层面起效，未能在硬件层面建立保护。攻击者依旧可以通过绕过上位机软件，使用预先设计的脚本启动SD卡备份流程，再通过读取SD卡获取备份文件。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135619" data-ratio="0.8240601503759398" data-s="300,640" style="" data-type="png" data-w="665" src="https://wechat2rss.xlab.app/img-proxy/?k=90a93566&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6CFTIkAldMtribZZiaJgSXsu7JynI4uWjD9wuM6iazH8ib5iahfoKgH4E2oAA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">攻击者通过对备份文件进行解密，可以获取目标PLC的整个项目文件，其中包括经过加密存储的项目程序原文、机器码、密码、识别码信息等。</span><o:p></o:p></p><p><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">3.3 通信数据存在硬编码问题：导致加密数据泄露</span></strong></span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">工控设备通常使用私有协议与上位机和其它内网设备通信，为了防止通信数据被截获解读从而导致信息泄露，符合安全规范的做法是在通信中使用经过动态特殊加密的密文而非明文，来传输密码和其它重要信息。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">然而，未经过严格安全设计且不及时更新迭代的工控设备中，许多都存在硬编码密钥问题。工控设备的硬编码密钥指在设备的固件或上位机软件中，存在着直接嵌入到源代码或可执行文件中的敏感信息，如密码、密钥、访问凭证等；此类信息通常以硬编码的形式存在于设备的程序代码中，而非动态从设备外部获取。这种存储和加密方式可能对设备的安全性产生潜在威胁。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">攻击者可以通过分析设备的固件或软件，定位加密模块进行反编译，直接从设备处获取加密算法。再使用动态调试，获取加密算法中的关键加密密钥。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135620" data-ratio="0.8722222222222222" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6fe34c1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nQ6f7HXXEGucNRTPC5oyE6CmzgoWDLtUiaiaR9Q5GkudKSAJGJBYcuxs7bSCJyCPDFhlMGduWia2tPrg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">获取加密算法和密钥的攻击者，就能突破加密保护，通过分析通信数据，解读出设备的真实密码。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p><br/></p><p style="font-size: 16px;letter-spacing: 2px;color: rgb(31, 92, 193);"><strong>四、总 结</strong></p><p><br/></p><p><img data-imgfileid="502135621" data-ratio="1" style="width: 20px;display: block;vertical-align: bottom;" data-w="44" data-width="100%" src="https://wechat2rss.xlab.app/img-proxy/?k=b5477a90&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FbL2iaicTYdZn4gtOjGqNzIohBYJMwzicFE86qgtMctYnvEuW8mh3tBT15aZDbia6DbPKho1v3iaGmE4kDeUCIIdQdsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><br/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">本文从工业数据安全出发，详细探讨了工控设备中的关键数据类型，介绍了厂商为了保护这些数据采用的常见安全机制和安全机制固有的薄弱点。最后，本文通过引入威胁案例，展示了在现实环境中，这些安全薄弱点是如何被利用并实施攻击的。</span><o:p></o:p></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">综上所述，我们可以清楚地看到，保障工控设备数据安全是一个多层面的动态过程。在未来，随着技术的进步和威胁环境的变化，工控设备的防御机制和攻击方法的对抗还会继续。这要求研究人员保持关注、不断更新技术和策略，参与到工控设备安全机制的迭代演进中，进而加固工业数据安全的基石。</span><o:p></o:p></p><p><br/></p><p><br/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="outline: 0px;line-height: 1.8;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="outline: 0px;">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截止目前，ADLab已通过CVE累计发布安全漏洞近1200个，通过 CNVD/CNNVD/NVDB累计发布安全漏洞4000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="outline: 0px;">5G安全研究、<span style="outline: 0px;">人工智能安全研究、</span></span></span><span style="outline: 0px;">移动与物联网安全研究、</span><span style="outline: 0px;">工控安全研究、信创安全研究、</span><span style="outline: 0px;">云安全研究、</span><span style="outline: 0px;">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="outline: 0px;letter-spacing: 1.5px;">。</span></span><span style="outline: 0px;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="margin-bottom: 0px;outline: 0px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135622" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 282px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=acf4e31d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Djpeg%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Thu, 25 Jan 2024 18:38:35 +0800</pubDate>
    </item>
    <item>
      <title>关于近期俄乌网络攻击活动追踪分析报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619252&amp;idx=1&amp;sn=271b4383d46172c9f85d7c3f321c8c98&amp;chksm=83062624b471af32c0d9071cc7b11463ef25703f36e126f99414d7f8bfebcfc79fdafdeb41ee&amp;scene=58&amp;subscene=0#rd</link>
      <description>近期，启明星辰ADLab又观察到了一系列针对乌克兰国家卫生服务局、农业政策和粮食部、战略产业部、州议会等实体的网络攻击。攻击主要是投递远控木马remcosRAT和Poverty Stealer以实现对目标的完全控制。本文将详细阐述和分析。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-01-19 17:57</span> <span style="display: inline-block;">北京</span>
</p>

<p>近期，启明星辰ADLab又观察到了一系列针对乌克兰国家卫生服务局、农业政策和粮食部、战略产业部、州议会等实体的网络攻击。攻击主要是投递远控木马remcosRAT和Poverty Stealer以实现对目标的完全控制。本文将详细阐述和分析。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=fb1a9e2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vgQjAF8ZKf6yAchxjbnicRCeK2tCvxT5ArvcWfqMa9cKBuO2o1EO8jcg%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br/></p><p><strong>0</strong><strong data-original-title="" title="">1</strong></p><p><br/></p><p><strong data-brushtype="text">分析背景</strong></p><p><br/></p><p><br/></p><h2 style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);"></span></h2><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">自俄乌战争爆发以来，无论是前期的所谓“军事特别行动”还是中后期的拉锯战和消耗战，网络间谍活动始终都未曾间断过。通过网络攻击获取军事情报成为战争过程最为频繁的一项行动，这种行动任务在远早于战争开始之前就已经开始布局，并始终贯穿整个战争过程，直到现在从未停止。启明星辰ADLab长期以来密切关注战争过程中双方之间所发生的网络攻击战况，也曾进行过多次的追踪、分析和披露，这种网络攻击随着战争变化而变化，从战前为试探军事部署而对边防局和国防部的攻击，到战争爆发时为闪击战而准备的网络瘫痪行动，再到战争僵持期间为获得实时军情而针对国安部和军队目标的网络间谍行动，最后发展到近期的以战略产业、医疗卫生和粮食部为目标的阶段性攻击活动。</span><o:p></o:p></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">从去年上半年开始，我们观察到一些网络攻击常常与战争中的具体事件存在着紧密的关联。比如：5月中旬俄罗斯向乌克兰西部赫梅利尼茨基州发动大规模无人机攻击造成了大量人员受伤后，5月29日左右就出现了伪装成医药公司账单的攻击，攻击的主要目标为该州的国家安全局；同样是5月中旬，乌克兰切尔尼戈夫州遭到俄罗斯导弹打击，5月29日左右就出现了伪装成乌克兰矿石加工和采矿设备修理厂的发票攻击，攻击的主要目标是乌克兰切尔尼戈夫州政府。这些说明，网络攻击某种程度上在和一些战争行动打配合，而这种配合又会反过来给予攻击方更加实时的情报。详细分析见我们披露的</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649616869&amp;idx=1&amp;sn=af14838076b4affcf371e4db4e23aef9&amp;chksm=83062cf5b471a5e3b877c59cf0cb26722ac32eb6c2ef554010e204fa40ee641c2e89f98c3374&amp;scene=21#wechat_redirect" textvalue="《针对乌克兰边防局和国防部攻击活动深度分析》" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">《</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">针对乌克兰边防局和国防部攻击活动深度分析</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">》</span></a><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649617232&amp;idx=1&amp;sn=83d75c1a0d4297c0a5de804e94bb8ebb&amp;chksm=83062e40b471a756b6f8ed2f4b00bd79bd5cf5fb313c50c2fad19bf5fbb70e3c33746d50b728&amp;scene=21#wechat_redirect" textvalue="乌克兰战争背后的网络攻击和情报活动" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">乌克兰战争背后的网络攻击和情报活动</span></a><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">》和《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649618803&amp;idx=1&amp;sn=7f69a671e387af508ca4ed81aa7e560f&amp;chksm=83062463b471ad755d030232f8c36c55def47da7f82b023c8863556abbdeb7311b22c9ed8512&amp;scene=21#wechat_redirect" textvalue="俄乌战争下最新网络情报活动分析" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">俄乌战争下最新网络情报活动分析</span></a><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">》等分析报告。</span></p><h2 style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></h2><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">而在近期，我们又观察到了一系列针对乌克兰国家卫生服务局、农业政策和粮食部、战略产业部、州议会等实体的网络攻击，攻击者企图向这些攻击目标投放remcosRAT木马来窃取情报，这和此前的一系列攻击采用的是同一款木马。此外，我们还观察到一系列传播乌克兰安全局官网仿冒站点的攻击活动，并试图投放窃密木马Poverty Stealer。本次观察到网络攻击的目标涉及战时资源调配和后勤补给等有重要影响的机构，覆盖医疗、粮食、包装运输和财务结算等多个环节。我们由此可以看出，网络战的范围正在逐步扩大，可能已经蔓延到战争过程中的整个决策和调度链条，其中涉及到实时的军事政治情报以及医疗、粮食、武器弹药等情报信息。</span><o:p></o:p></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">同样，新发现的网络攻击依然试图与战争行动打配合，比如2023年11月28日，俄罗斯对乌克兰扎波罗热州发动导弹袭击，这些导弹袭击引发该州议会对被袭事件的议题进行讨论并做出相关决策，随后我们便发现黑客两天后对扎波罗热市议会进行隐秘的网络窃密攻击，同时针对医疗机构的攻击也频繁出现；同样情况发生在乌克兰第聂伯罗彼得罗夫斯克州，2023年12月8日，该州受到多架无人机袭击后卡米安市议会遭受到了网络窃密攻击。这种通过网络攻击打配合战的手法在战争中会持续存在。</span><o:p></o:p></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">本文将详细阐述和分析我们所观察到的这些网络攻击，我们首先以这些攻击事件为线索关联出尽可能多的基础设施、诱饵文件以及投放的恶意可执行程序等信息并做深入的分析。这一系列攻击主要是投递远控木马remcosRAT和Poverty Stealer以实现对目标的完全控制，remcosRAT和Poverty Stealer木马有着非常强的窃密能力和灵活的插件扩展能力。本文将选取一起典型的攻击进行详细而深入的分析。</span></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><strong>0</strong><strong data-original-title="" title="">2</strong></p><p><br/></p><p><strong data-brushtype="text">攻击事件分析</strong></p><p><br/></p><p><br/></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">2.1 诱饵投递</span></strong></span><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">在过去几个多月时间里，不管是乌方的微弱反攻还是俄方的缓慢进攻，俄乌双方均未在战线上取得突破性进展，战事已经陷入拉锯战。我们也在这段时间观察到了一系列为获得战时情报而实施的网络窃密活动。在这些攻击活动中，黑客伪装成乌克兰敖德萨州商事法院（地区）和乌克兰电信公司Kyivstar相关工作人员将精心构造的恶意payload通过邮件投递给乌克兰国家卫生服务局、农业政策和粮食部、战略产业部、韦尔霍维纳区国家管理局、扎波罗热市议会、卡米安市议会和乌克兰塑料包装解决方案供应商“RETAL”以及乌克兰银行“Agroprosperis
Bank”等实体机构。黑客试图通过这些恶意payload将remcosRAT木马植入到目标设备上，以获取乌方的军事情报如：作战计划、物资调配计划等机密信息。我们下面列举几个攻击事件对该黑客组织的攻击行动进行详细说明。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图1是一封2023年11月30日发送的攻击邮件：发件人伪装成了乌克兰敖德萨州商事法院（地区）相关工作人员，收件人是乌克兰国家卫生服务局的工作人员。邮件主题为
“Повістка в суд-вихідний : 2844288114 
від 30.11.2023”，中文意思是“传票日：2023年11月30日起2844288114”，邮件附件为“Господарський
суд Одеської області Повістка до суду.rar（敖德萨州商事法院传票.rar）”，正文大意是 “这封信是由系统自动创建的，您需要在敖德萨地区的经济法院出庭考虑索赔，所有信息都包含在文档中。为了维护附件的机密性，设置了密码：8161，此电子邮件及其附带的任何文件都包含机密信息”。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">附件文档解压后包含名称为&#34; Повістка
до суду.doc （传票.doc）&#34;的恶意文档，如果受害者轻信邮件打开该文档，并启用宏选项，恶意宏代码便会执行</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">。宏代码执行后会从恶意服务器SMB共享地址“\\89.23.98.22\LN\scandoc.exe”下载名称为scandoc.exe
的恶意Loader，并最终向受害者设备投放商业木马remcosRAT，然后利用该木马对攻击目标实施进一步的攻击行动。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135561" data-ratio="0.5351851851851852" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e07467ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1v3WktMvr13rLuQviaoNJgPfl6LQrsW54w5xDJ1WDib2iahaQphLqdYibQNQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图1 针对乌克兰国家卫生服务局的攻击邮件</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图2是一封2023年12月21日发送的攻击邮件：该邮件的攻击目标是乌克兰韦尔霍维纳区国家管理局的工作人员。邮件主题为
“Заборгованість за договором Київстар”，中文意思是“Kyivstar合同下的债务”，邮件附件为“Заборгованість
абонента.zip（认购人的债务.zip）”，正文大意是
“您好，您在合同编号下有逾期债务：通信服务038208716。如果在 2023 年 12 月 29 日之前未偿还债务，Kyivstar 将不得不起诉您以在法庭上追讨债务。有关您帐户的详细信息，请参阅附件。由于
Kyivstar 隐私政策的变化和个人数据的保存，为附件设置了以下访问代码：558732”。从邮件主题和邮件正文的内容，我们可以看出攻击者试图伪装成乌克兰电信公司“Kyivstar”来欺骗攻击目标，但邮件的发送人邮箱却冒用了乌克兰独立法医鉴定研究所“NISE”的邮箱，这应该是来自攻击者的“失误”。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">附件文档解压后包含名称为&#34; Заборгованість абонента.doc （认购人的债务.doc）&#34;的恶意文档，同上面一样，该恶意文档同样试图利用恶意宏代码从恶意服务器SMB共享地址“\\89.23.98.22\LN\GB.exe ”下载恶意文件，并最终向受害者设备投放商业木马remcosRAT。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135562" data-ratio="0.6814814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c54b4bd7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vsGrS4ibLZPNvHySy49oLe4y9ZLr84yXJW1jM5jByicQQt7guBzOXIkfg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图2 针对乌克兰韦尔霍维纳区国家管理局的攻击邮件</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">我们还发现，同样在2023年11月30日和2023年12月21日，该黑客组织除了攻击乌克兰国家卫生服务局和乌克兰韦尔霍维纳区国家管理局，其同时又对乌克兰的多个政府机构和实体公司发起了网络攻击。图3是部分相关攻击使用的网络攻击邮件截图。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135563" data-ratio="0.7" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a919f866&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1v3CA1CCjGyVicpf6HBv3C2nB7nzQkoYEOIl2VVH16HoQlLKNtyyYMo6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><h2 style="margin-bottom: 8px;text-indent: 0em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></h2><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图3  监测到的其他攻击邮件</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">我们将该黑客组织这段时间使用的部分定向攻击邮件的相关信息列到表1。从表1中，我们可以看到，黑客构造了迷惑性的邮件向目标实施网络攻击。该黑客组织分别伪装成乌克兰敖德萨州商事法院（地区）、乌克兰敖德萨地区行政法院和乌克兰电信公司Kyivstar的工作人员向目标实施网络攻击。其使用了
“传票日：2023年11月30日起2844288114”、“[警告：消息已加密] 传票日：2023年11月30日起3667588807125”以及“Kyivstar合同下的债务”这样的内容作为邮件主题来诱使目标相信邮件内容。如果受害者相信邮件内容并执行了邮件附件中的恶意程序，恶意商业木马remcosRAT就被植入到了受害者的计算机上。</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="98" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-bottom: 1pt solid rgb(68, 114, 196);border-left: 1pt solid rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 14px;"><strong><span style="color: white;">时间</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="172" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-left: none;border-bottom: 1pt solid rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 14px;"><strong><span style="color: white;">邮件主题</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="149" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-left: none;border-bottom: 1pt solid rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 14px;"><strong><span style="color: white;">发件人</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="163" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-right: 1pt solid rgb(68, 114, 196);border-bottom: 1pt solid rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 14px;"><strong><span style="font-size: 14px;color: white;">收件人</span></strong><strong><span style="font-size: 14px;color: white;"><o:p></o:p></span></strong></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="77" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023/11/30 10:12</span></p></td><td width="147" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Повістка в суд-вихідний : 2844288114  від 30.11.2023</span></p></td><td width="126" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Господарський суд Одеської області
  &lt;zal16@od.arbitr.gov.ua&gt;</span></p></td><td width="143" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Info
  Mailbox &lt;info@nszu.gov.ua&gt;</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:2;"><td width="78" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023/11/30 14:08</span></p></td><td width="172" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Повістка в суд-вихідний : 89802139144  від 30.11.2023</span></p></td><td width="149" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Господарський суд Одеської області
  &lt;zal12@od.arbitr.gov.ua&gt;</span></p></td><td width="163" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Info
  Mailbox &lt;info@nszu.gov.ua&gt;</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:3;"><td width="98" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023/11/30 13:50</span></p></td><td width="172" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Повістка в суд-вихідний : 0981999364  від 30.11.2023</span></p></td><td width="149" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Господарський суд Одеської області
  &lt;zal02@od.arbitr.gov.ua&gt;</span></p></td><td width="163" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">support &lt;support@minagro.gov.ua&gt;</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:4;"><td width="98" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023/11/30 13:25</span></p></td><td width="172" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Повістка в суд-вихідний : 438685484505  від 30.11.2023</span></p></td><td width="149" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Господарський суд Одеської області
  &lt;inbox@adm.od.court.gov.ua&gt;</span></p></td><td width="163" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Приймальня КП «Наше місто»
  &lt;reception.nashemisto@zp.gov.ua&gt;</span></p></td></tr><tr style="mso-yfti-irow:5;"><td width="98" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023/11/30 9:41</span></p></td><td width="172" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">[WARNING:
  MESSAGE ENCRYPTED] Повісткавсуд-вихідний :
  3667588807125  від 30.11.2023</span><o:p></o:p></p></td><td width="149" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">ГосподарськийсудОдеськоїобласті
  &lt;zal17@od.arbitr.gov.ua&gt;</span><o:p></o:p></p></td><td width="163" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">evgeniya.averiyanova
  &lt;evgeniya.averiyanova@retal.dp.ua&gt;</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:6;"><td width="98" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023/12/21 12:28</span></p></td><td width="172" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Заборгованість за договором Київстар – Передсудове</span></p></td><td width="149" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Чередниченко Шерлок Давидович &lt;osawa@takaroku.biz&gt;</span></p></td><td width="163" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">citizen
  &lt;citizen@mspu.gov.ua&gt;</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:7;"><td width="98" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023/12/21 2:50</span></p></td><td width="172" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Заборгованість за договором Київстар – Передсудове</span></p></td><td width="149" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Гісем Жито Вікторович &lt;hello@mixandclean.com&gt;</span></p></td><td width="163" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">s-email
  &lt;bank@ap-bank.com&gt;</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:8;"><td width="98" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023/12/21 4:19</span></p></td><td width="172" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Заборгованість за договором Київстар</span></p></td><td width="149" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Пантелюк Еміль Валентинович &lt;office@nise.com.ua&gt;</span></p></td><td width="163" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">cufra
  &lt;cufra@verhovuna-rda.gov.ua&gt;</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:9;mso-yfti-lastrow:yes;"><td width="98" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023/12/26 10:40</span></p></td><td width="172" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Запит на отримання публічної інформації</span></p></td><td width="148" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Олег Яковлев &lt;uprava.com@gmail.com&gt;</span></p></td><td width="163" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">miskrada@kam.gov.ua</span></p></td></tr></tbody></table><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">表1部分定向攻击邮件相关信息</span><o:p></o:p></p><p style="margin-bottom: 8px;text-align: justify;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">从攻击邮件的收件人我们可以看出，这些网络攻击是针对乌克兰国家卫生服务局、乌克兰农业政策和粮食部、乌克兰扎波罗热市议会、乌克兰塑料包装解决方案供应商“RETAL”、乌克兰韦尔霍维纳区国家管理局、乌克兰战略产业部、乌克兰卡米安市议会以及乌克兰银行“Agroprosperis
Bank”的工作人员发起的。部分受害部门相关信息见图4至图9。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135564" data-ratio="0.4527777777777778" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9a4cf859&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vYYvTSqFSOy89OCF4J4chLaudx1jicS0bBYibZaHicyDxXdqYwHcMCjdnQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图4 目标为乌克兰国家卫生服务局相关信息</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135565" data-ratio="0.36574074074074076" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5e3e69ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vibMYm7eDx76NpvniaXqMEmdqwa1OleATr2ricKsexiayFPGlD4UCgdn2sw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图5 </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">目标为乌克兰农业政策和粮食部</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">相关信息</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135566" data-ratio="0.33425925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a98aa626&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vWaxFYQBgia1bDqZDxSIkGjq3mTV9NiaRNX5UIqLpdMwyYGPHRXia7fIVQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图6 目标为乌克兰战略产业部相关信息</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135567" data-ratio="0.3490740740740741" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4310d158&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vave0Y2DqCzxeE1hPztbcIrvkauHIiauQmIG0CcficcQ6shZiawddhqMqw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图7 目标为乌克兰卡米安市议会相关信息</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135568" data-ratio="0.36666666666666664" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=62aad824&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1v22YsmiaFx6MbUq6ic6lOR0063MeOwvZS9uIkH9FFTQfWs7qUAFd8cvGQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图8 目标为乌克兰扎波罗热市议会相关信息</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135569" data-ratio="0.35185185185185186" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=50bcda5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1v4vjCTrpHjGgiaicpUcx3TQqMQn8MMibeWINRN0LrRHtEzRm3GvuzV47Rw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图9 目标为乌克兰韦尔霍维纳区国家管理局相关信息</span></p><h3 style="margin-bottom: 8px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">2.2 仿冒网站</span></strong></span><o:p></o:p></h3><p style="margin-bottom: 8px;text-align: justify;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">另外，我们发现该黑客组织除了使用恶意邮件对目标进行网络攻击外，还通过仿冒乌克兰安全局官网传播恶意文档。图10是攻击者仿冒的乌克兰安全局的官网页面，恶意文档的存放地址为https://npddocs.com/ssu.gov.ua/docs/file/util/0/d12934-0202334.doc（目前已失效），该恶意文档包含有恶意宏代码，宏代码执行后会从恶意服务器SMB共享地址“\\89.23.98.22\LN\Konstantin.exe”下载名称为Konstantin.exe的恶意Loader，并最终向受害者设备投放窃密木马Poverty Stealer。Poverty Stealer是一款信息窃取木马，其执行后，可以收集受害者计算机上存储的个人文档、图片、cookie、telegram会话数据等敏感信息，此外，Poverty Stealer还能够截取屏幕截图。收集到这些敏感信息后，其会将窃取的数据传输给攻击者。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135570" data-ratio="0.7842592592592592" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1c3503cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1veJUslyb3Tfb5icxq5u5wUYicMCtQ7wRicKV5b9YoQiaReQpT7Ker9XN4BQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图10 攻击者仿冒的乌克兰安全局的官网页面</span></p><p><br/></p><p><br/></p><p><strong>0</strong><strong data-original-title="" title="">3</strong></p><p><br/></p><p><strong data-brushtype="text">黑客攻击分析</strong></p><p><br/></p><p><br/></p><h2 style="text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">3.1 基础设施</span></strong></span><o:p></o:p></h2><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">我们将监测到的攻击邮件的恶意附件和其投放的恶意文件以及黑客组织利用仿冒站点传播的恶意文件信息整理到表2，从表2中我们可以看到，这些恶意文件类型包含rar、zip、
doc和exe文件。它们在VirusTotal上的首次上传时间最早为2023年11月7日，最新为2023年12月21日。</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="179" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-bottom: 1pt solid rgb(68, 114, 196);border-left: 1pt solid rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 14px;"><strong><span style="color: white;">文件名称</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="64" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-left: none;border-bottom: 1pt solid rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 14px;"><strong><span style="color: white;">文件类型</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="111" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-left: none;border-bottom: 1pt solid rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 14px;"><strong><span style="color: white;">首次上传时间</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="184" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-right: 1pt solid rgb(68, 114, 196);border-bottom: 1pt solid rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 14px;"><strong><span style="font-size: 14px;color: white;">MD5</span></strong><strong><span style="font-size: 14px;color: white;"><o:p></o:p></span></strong></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="152" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Господарський суд Одеської області Повістка до суду.rar</span></p></td><td width="86" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;word-break: break-all;"><p><span style="font-size: 12px;">rar</span></p></td><td width="110" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;word-break: break-all;"><p><span style="font-size: 12px;">2023-11-30 04:22:43 UTC</span></p></td><td width="184" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;word-break: break-all;"><p><span style="font-size: 12px;">cfcf6395c7cf7c879c8a697a6e2cd4fa<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="179" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Повістка до суду.doc<o:p></o:p></span></p><p><span style="font-size: 12px;">вірусяка_повістка_до_суду.doc<o:p></o:p></span></p><p><span style="font-size: 12px;">123.doc</span></p></td><td width="86" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">doc</span></p></td><td width="110" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-30 06:05:46 UTC</span></p></td><td width="204" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">4cd0efe60c932a3ff25a976386cf9bc9<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="179" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">7zipInstall.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">8161.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">scandoc.exe<o:p></o:p></span></p></td><td width="86" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span></p></td><td width="110" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-30 06:15:07 UTC</span></p></td><td width="204" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">3f38596cc3a4d9d6020d3cebff1a8f6c<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="179" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">13018627804.zip</span></p></td><td width="86" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">zip</span><o:p></o:p></p></td><td width="110" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-18 11:42:01 UTC</span></p></td><td width="204" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">c0f73c98bcbf311f2ca4030d325abe1f<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;"><td width="179" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">d12934-0202334.doc</span></p></td><td width="86" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">doc</span></p></td><td width="110" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-07 15:17:09 UTC</span></p></td><td width="204" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">eac138b49c6f90896c9af5cbc8fe38b8<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:6;"><td width="179" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">novapdf.exe</span></p><p><span style="font-size: 12px;">Konstantin.exe</span></p></td><td width="86" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span><o:p></o:p></p></td><td width="110" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-07 16:06:59 UTC</span></p></td><td width="204" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">b8e53ea5efc220fe80f217a0fe9ba89c</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:7;"><td width="179" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Заборгованість абонента.zip</span></p></td><td width="86" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Zip</span></p></td><td width="110" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-12-21 05:56:16 UTC</span></p></td><td width="204" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">4754f0ede14f1bae26b69bd43c7b6705<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:8;"><td width="179" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Заборгованість абонента.doc</span></p></td><td width="86" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">doc</span></p></td><td width="110" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-12-21 06:29:28 UTC</span></p></td><td width="204" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">de2e053acae98adbecc23ab3c0e9cf5d<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:9;"><td width="179" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">GB.exe</span></p></td><td width="86" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span></p></td><td width="110" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-12-21 08:56:59 UTC</span></p></td><td width="204" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">c3e7cfa2e076c3ca421ddc00496c71b5<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:10;mso-yfti-lastrow:yes;"><td width="179" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">wsuscr.exe</span></p></td><td width="86" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span></p></td><td width="110" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-12-21 07:43:02 UTC</span></p></td><td width="204" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">fc99e0883a1fa153693547953a83674e</span></p></td></tr></tbody></table><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">表2 恶意文件列表</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">虽然黑客组织使用了恶意邮件和仿冒站点这两种网络攻击方式，但最后它们企图在攻击目标设备上投放的恶意程序都来自同一服务器地址“89.23.98.22”，我们尝试访问SMB共享地址</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">\\89.23.98.22\LN\</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">，发现该地址已失效，不过从公开沙箱中，我们找到了该地址早前的共享文件信息，如图11所示：该地址上早前存放的可执行程序中，除了“putty.exe”为正常的管理工具外，其余9个可执行程序均为恶意程序。其中的“scandoc.exe”和“Konstantin.exe”被用于此次攻击乌克兰的相关机构和公司实体。从这些恶意程序的修改时间上看，最早修改时间是2023年10月11日，最近的修改时间是2023年11月29日。由此可以推断，这波针对乌克兰相关机构和公司实体的攻击时间最早至少为2023年10月11日。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135571" data-ratio="0.637962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4fdea831&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vql8Qrc1H6yKjPa5BiawibgPw4B7El4b3SlTaYYGoQvVfg2hxW8vbpDWA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="text-indent: 0em;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图11 恶意文件服务器上存放的文件</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">我们再以恶意文件服务器地址“89.23.98.22”为线索进行关联分析，发现了该黑客组织所使用的更多的恶意文件（见表3）。这些恶意文件有的是作为邮件附件发送给攻击目标，用于投放remcosRAT远控木马，有的是附带有恶意宏的doc文档，用于投放Poverty Stealer窃密木马，有的则是携带这些木马的恶意Loader。这些恶意文件在VirusTotal的首次上传时间最早为2023年10月14日，最新为2023年11月30日。结合我们最初监测到的那几次网络攻击，可以看出此次针对乌克兰军事和政府等机构的攻击分别发生在2023年10月前后和2023年12月前后。</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="150" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-bottom: 1pt solid rgb(68, 114, 196);border-left: 1pt solid rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;"><strong><span style="color: white;">文件名称</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="84" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-left: none;border-bottom: 1pt solid rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;"><strong><span style="color: white;">文件类型</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="151" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-left: none;border-bottom: 1pt solid rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;"><strong><span style="color: white;">首次上传时间</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="225" valign="top" style="border-top: 1pt solid rgb(68, 114, 196);border-right: 1pt solid rgb(68, 114, 196);border-bottom: 1pt solid rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;"><strong><span style="font-size: 12px;color: white;">MD5</span></strong><strong><span style="font-size: 12px;color: white;"><o:p></o:p></span></strong></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="130" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;word-break: break-all;"><p><span style="font-size: 12px;">d12934-0202334.doc</span></p></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;word-break: break-all;"><p><span style="font-size: 12px;">doc</span></p></td><td width="130" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-15 06:49:13 UTC</span></p></td><td width="205" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;color: rgb(0, 0, 0);">22ec6c0a1b5690a63c28f20b552ba7c6</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:2;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">chrome_exe</span></p><p><span style="font-size: 12px;">Konst.exe</span></p></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-30 14:24:05 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">cb031980eb0030f7096b5e097e841a87</span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">CV Ali Frost.doc</span></p></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">doc</span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-30 18:03:18 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">87b7b11c7e69e02d195f587695541040</span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">GenericSetup.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">officetrackernmp116.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">crome.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">IEUpdater116.exe</span></p><p><span style="font-size: 12px;">(PrivateLoader)</span></p></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">dxe</span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-30 14:20:04 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;"><br/>
  3afed19a3ec0d96e4db93b7d6a34d154<o:p></o:p></span><span style="font-size: 12px;"><o:p></o:p></span><span style="font-size: 12px;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><br/></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">doc<o:p></o:p></span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-30 08:14:41 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">32e6fd665e35cfcabb9b519db619a66e<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:6;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><br/></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">doc<o:p></o:p></span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-12-01 02:02:28 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">d3c1df6b9dad19c91deb8548743c73fe<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:7;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><br/></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">doc<o:p></o:p></span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-12-02 01:34:24 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">dad8cf0dc54e94df5a0d9c209d924b8f<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:8;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">information.exe</span></p></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-30 14:21:16 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">98a0bf4af1e1e9a69bddee4421e1772d<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:9;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">kent.exe</span></p></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-11-07 16:46:17 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">31ddb76cee6b27419e729bdc4b60428e<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:10;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">vpnsetup.exe</span></p><p><span style="font-size: 12px;">PDF.exe</span></p></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-10-22 09:49:55 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">59788e9764eb60d5f0ff277b646bddcd<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:11;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">putty.exe</span></p></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2020-06-27 09:30:35 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">dcf21ca46349ce36f7866c24f1f60f0f<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:12;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">9060.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">Exiland
  Backup Standard<o:p></o:p></span></p><p><span style="font-size: 12px;">ExilandBackup.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">claim_video_Hotel291023<strong><o:p></o:p></strong></span></p><p><span style="font-size: 12px;">.mp4.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">claim_video_Hotel291023<strong><o:p></o:p></strong></span></p><p><span style="font-size: 12px;">.mp4 - <span style="font-family: Batang;">복사본</span>.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">complaint_hotel_291023<strong><o:p></o:p></strong></span></p><p><span style="font-size: 12px;">.mp4.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">claim_Hotel291023<strong><o:p></o:p></strong></span></p><p><span style="font-size: 12px;">.mp4.exe<o:p></o:p></span></p></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-10-29 08:43:25 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">15a8cc209cc9bd77f5bf901d07d3d0a9<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:13;mso-yfti-lastrow:yes;"><td width="150" valign="top" style="border-right: 1pt solid rgb(142, 170, 219);border-bottom: 1pt solid rgb(142, 170, 219);border-left: 1pt solid rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">chrome.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">Baldr.exe<o:p></o:p></span></p><p><span style="font-size: 12px;">1.exe<o:p></o:p></span></p></td><td width="84" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">exe</span></p></td><td width="151" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">2023-10-23 14:36:06 UTC</span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(142, 170, 219);border-right: 1pt solid rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">e47d4a3c6c18349547847ab18211f323</span></p></td></tr></tbody></table><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">表3 关联到的其他恶意文件</span></p><h2 style="text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(0, 82, 255);"><strong><span style="color: rgb(0, 82, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">3.2 攻击目标</span></strong></span><o:p></o:p></h2><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">从攻击目标上看，该定向攻击是针对乌克兰国家卫生服务局、农业政策和粮食部、战略产业部、韦尔霍维纳区国家管理局、扎波罗热市议会、卡米安市议会和乌克兰塑料包装解决方案供应商“RETAL”以及乌克兰银行“Agroprosperis
Bank”等多个实体发起的（见图12）。攻击者主要通过向这些机构的工作人员发送带有恶意附件的攻击邮件，向攻击目标投放remcosRAT木马。这些攻击目标覆盖乌方在战争中对资源调配和后勤补给等方面有重要影响的机构，涉及医疗、粮食、包装运输和财务结算等多个环节。除此之外，黑客组织还以经常访问乌克兰安全局的人员为攻击目标，攻击者通过仿冒乌克兰安全局官网来投放窃密木马Poverty Stealer。攻击者选择这些机构和人员作为攻击目标，一方面是想掌握乌方的医疗、粮食等战略物资的调配情况和乌方的作战情报信息，另一方面可以将其作为跳板，渗透进乌方的军方和政府机构，以进一步获取更有价值的机密信息。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135572" data-ratio="0.6833333333333333" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b764011d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vXxUNshLvrn6DBaRYtvLJcbyv9lS2cW2BnfSaVVW7SyZSWt9zrAWYuA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 8px;text-indent: 2em;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图12 攻击目标</span><o:p></o:p></p><h3 style="margin-bottom: 8px;text-indent: 0em;text-align: justify;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(0, 82, 255);">3.3 组织归属</span></strong><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">从前文攻击目标上看，该黑客组织目前的攻击活动带有明显的军事意图，该定向攻击是针对目前阶段俄乌冲突乌方战时资源调配强相关的机构发起的。而且，根据我们的基础设施分析，黑客使用的核心恶意文件服务器来自俄罗斯。因此，不管从该组织的攻击目标、还是其使用的恶意服务器等基础设施来看，该黑客组织都很符合俄罗斯黑客组织的习惯。再结合俄乌战争的大背景，尤其是2023年10月、11月和12月份前后，俄乌双方在战场上的新动向，我们认为此次攻击活动是由俄罗斯黑客组织发起的。我们将会持续关注该黑客组织的相关基础设施变化以对其动向进行持续追踪。</span></p><p><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></strong></p><p><strong>0</strong><strong data-original-title="" title="">4</strong></p><p><br/></p><p><strong data-brushtype="text">攻击案例分析</strong></p><p><br/></p><p style="letter-spacing: 0.578px;text-indent: 0em;text-wrap: wrap;margin-bottom: 8px;"><br/></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">我们以该黑客组织的其中一次邮件攻击为例进行说明。如图13所示，在此次攻击中，攻击者先在自己的恶意服务器“89.23.98.22”上配置和部署好恶意文件GB.exe，同时，攻击者将恶意Loader “wsuscr.exe”部署在了合法的托管服务提供商“Bitbucket”上，准备工作做好后，攻击者向乌克兰韦尔霍维纳区国家管理局的工作人员投递带有恶意附件“Заборгованість
абонента.zip”的邮件，“Заборгованість
абонента.zip”文件解压后包含名称为“Заборгованість
абонента.doc”的恶意doc文档，该恶意doc文档包含有恶意宏代码，受害者打开该恶意文档并启用宏后，恶意宏代码便会执行。恶意宏代码会从恶意服务器SMB共享文件夹地址“\\89.23.98.22\LN\GB.exe”请求事先部署在其上的恶意程序GB.exe执行，</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">GB.exe执行后会从托管服务提供商“Bitbucket”下载恶意Loader“</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">wsuscr.exe”执行，wsuscr.exe执行后，会解密其中的商业远控木马remcosRAT
到受害者的设备执行。通过上述过程，攻击者最终成功向攻击目标投放了remcosRAT远控木马。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135573" data-ratio="0.38981481481481484" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1d0105f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vm2mkhTyKJATpUJkT7iaSG5MqRHbDbQVRn0cxG292iaRic7sYgBqyPwQjw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图13 攻击流程图</span><o:p></o:p></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(0, 82, 255);">4.1 诱饵邮件投递</span></strong><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">此次攻击始于一封试图伪装成乌克兰电信公司“Kyivstar”的债务催收邮件（见图14），此邮件是发送给乌克兰韦尔霍维纳区国家管理局的工作人员的。邮件标题是“Заборгованість
за договором Київстар（Kyivstar合同下的债务）”，附件诱饵文档名称为“Заборгованість абонента.zip（认购人的债务.zip）”，正文大意是
“您好，您在合同编号下有逾期债务：通信服务038208716。如果在 2023 年 12 月 29 日之前未偿还债务，Kyivstar 将不得不起诉您以在法庭上追讨债务。有关您帐户的详细信息，请参阅附件。由于
Kyivstar 隐私政策的变化和个人数据的保存，为附件设置了以下访问代码：558732”，很显然，正文这样写是为了增加这份邮件的可信度。不过，我们注意到了一个乌龙：该恶意邮件的发送人邮箱冒用了乌克兰独立法医鉴定研究所“NISE”的邮箱，而从邮件的主题和正文内容来看，攻击者是想伪装成乌克兰电信公司“Kyivstar”实施邮件攻击。这个乌龙应该是来自攻击者的疏忽大意。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135574" data-ratio="0.6814814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c54b4bd7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vsGrS4ibLZPNvHySy49oLe4y9ZLr84yXJW1jM5jByicQQt7guBzOXIkfg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图14 攻击者投放的攻击邮件</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">附件“Заборгованість
абонента.zip”解压后包含一个名称为&#34; Заборгованість абонента.doc （认购人的债务.doc）&#34;的恶意文档，见图15。该恶意文档提示用户，要查看具体内容，需要启用宏，当用户启用宏后，恶意宏代码就执行了。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135575" data-ratio="1.0666666666666667" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6df3927d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vo1APTibqWu9PSbkFqRmEDlsOclcXAxkGgLIibro7zyaQwTibuoiacMhdvQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图15 诱饵doc文档</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">如图16所示，这是该恶意文档包含的恶意VBA宏代码，该宏代码并不复杂：该段代码在文档被打开时执行，其作用是打开指定的SMB共享文件夹路径““\\89.23.98.22\LN\”，并执行指定的可执行文件“\\89.23.98.22\LN\GB.exe”，同时在执行完成后使用VBScript通过PowerShell停止explorer.exe进程并隐藏命令行窗口。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135576" data-ratio="0.5416666666666666" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9e836403&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vYKzj9IQhg7ib9O7J1drke2OAX4txdPHfBx1ec78rBPuUekZXyvtLDfw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图16 恶意宏代码</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">GB.exe是一个自解压程序，其包含两个文件，分别为res
.bat和test2.exe（见图17）。我们接下来分析res.bat和</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">test2.</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">exe这两个文件。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135577" data-ratio="0.32037037037037036" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5db730b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vA08qMSAR6xbypibIxjAQu3epANd3tjb8MusrgCeaiagWh2MjogxD33iaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图17 GB.exe自解压程序包含的文件</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">res.bat文件内容如图18，其首先使用xcopy命令将test2.exe文件复制到%temp%\persistent2\test2.exe路径下，然后使用PowerShell将一个Base64字符串解码并执行，为了方便说明，我们将这段Base64字符串命名为str1_
Base64。str1_ Base64解码后如图19所示，其主要做了两件事，第一件事是解码一个Base64字符串并执行（该Base64字符串是由内嵌的byte数组内存解压获得，我们将该Base64字符串命名为str2_
Base64），第二件事是从地址</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">https://bitbucket.org/olegovich-007/777/downloads/wsuscr.exe</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">下载恶意程序wsuscr.exe，保存为%appdata%wsuscr.exe并执行。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135578" data-ratio="0.07407407407407407" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c507c0f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1v2vye3pic7v2CcsfHXCqhtJNUAcJejJPJeicib7DskkKpGgSRVdsJibKmxw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图18 res.bat内容</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135579" data-ratio="0.3055555555555556" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d7562663&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vhtvnBbSy5mfhOwV0yyARFGof3bqFMFN7icI966hOkwwLTg1QSOia6e9g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图19 str1_ Base64解码后的内容</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">第一件事究竟做了什么呢？str2_ Base64解码后的内容见图20，可以看到，其目的是以UAC-bypass的方式执行前面释放的恶意程序%temp%\persistent2\test2.exe 。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135580" data-ratio="0.06574074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=24194207&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vpfFaiczFOUq4ibpsQLGvPNxMicmGibAmFRMKHPLCyfugkrqoHuTZibqV9yw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图20 str2_ Base64解码后的内容</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">如图21，test2.exe也是一个自解压程序，其包含“test2.bat”文件，</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">test2.bat</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">文件内容如图22，其中绿底字符串Base64解码后为“$pwd = &#34;Add-MpPreference
-ExclusionPath C:\&#34; $pwd | Invoke-Expression”，test2.bat整个文件的执行逻辑是：检查用户的权限，并在具备足够权限的情况下，将路径 C:\ 添加到 </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Windows Defender </span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">的排除路径列表中，以避免对该路径下的文件进行扫描和处理。结合后面分析可知，该脚本的目的是避免Windows
Defender查杀攻击者下载执行的恶意文件“%appdata%wsuscr.exe”。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135581" data-ratio="0.2851851851851852" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=915d9960&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1v7FzLMoHQW0NKPHMntWWZe2o9NP9ut6U6ab7CBMjNvY3iby0uc6emCfw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图21 test2.exe自解压程序包含的文件</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135582" data-ratio="0.32407407407407407" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=66e931ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vbWS3mJzZXlm0reQUqcSHTfAIpXezqr3tc7Q7NNicOiaiaZibocPTLnJ94Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图22 test2.bat文件内容</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">整个GB.exe文件我们就分析完了，总结起来其实很简单，其作用就是从地址</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">https://bitbucket.org/olegovich-007/777/downloads/wsuscr.exe</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">下载恶意程序wsuscr.exe，保存为%appdata%wsuscr.exe并执行，同时避免Windows Defender对”C:\”路径的查杀。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">wsuscr.exe执行后，会解密其中的商业远控木马remcosRAT
到受害者的设备执行。通过上述过程，攻击者最终成功向攻击目标投放了remcosRAT远控木马。</span><o:p></o:p></p><h3 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(0, 82, 255);">4.2 恶意程序分析</span></strong><o:p></o:p></h3><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">通过前面下载并执行的恶意程序wsuscr.exe是一个C#编写的恶意Loader，该Loader经过了严重的混淆，仅通过静态分析我们很难知道它的执行逻辑。结合动态分析，我们发现，为了对抗静态分析，该Loader将运行中要用到的大量API名称加密存储在了资源文件中，Loader执行后，会从其资源文件中解密出这些API名称备用。之后，该Loader会在内存中解密出商业木马remcosRAT，然后新起一个Loader自身进程，并使用进程挖空技术将remcosRAT木马注入到新起的Loader进程中执行。进程挖空技术常被恶意软件用于注入恶意代码，以逃避杀毒软件的监测和防御机制，并在目标系统上执行恶意活动。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">相较于2023年11月30那次攻击使用的Loader，2023年12月21日使用Loader的混淆强度明显增加了，图23是前一次Loader中，创建API委托的相关代码，图24是这次Loader相同功能代码片段的截图，通过对比我们可以看出，相较于前一次Loader，这次Loader的混淆称得上面目全非。虽然混淆强度增加了，但Loader本身的功能和逻辑没有变化，为了方便解释，我们后文用前一次Loader进行说明。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135583" data-ratio="0.18333333333333332" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4977f968&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vWdiaGreRHM52W9iceLnstHKIVflpDIEh4PEzFibnX7vqzicLHS3RuFengg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图23 前一次攻击使用的Loader截图</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135584" data-ratio="0.9796296296296296" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6ff23529&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1v1BmYWUejUkY5z9ZKUicqAXP5zI8lo5d0XicEWc2t63ezk3FMY8ZQia6Pw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图24 这次攻击使用的Loader截图</span><o:p></o:p></p><h4 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">4.2.1 解密字符串</span></strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h4><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Loader执行后会从名称为&#34;{f6e9f20a-731f-4616-a745-55d319eb064a}&#34;的资源中读取数据存储到一个byte数组里（见图25）</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135585" data-ratio="0.22592592592592592" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=756a47d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vV1m3tZuvaePgibMmxOKJiaomvDpL1mf3np4BuqUnm4p3cZbcdQgjZxZw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图25 从资源中读取数据</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">解密后的数据见图26所示，这些数据是由多个base64编码的字符串组成，最前面一个字节是该编码字符串的长度。这些base64编码后的数据在Loader后续执行中会用到，如字符串“QXNzZW1ibHkgaGFzIGJlZW4gdGFtcGVyZWQ=”base64解码之后是用于提示的字符串“Assembly
has been tampered”，字符串“UkhsdVlXMXBZMFJzYkVsdWRtOXJaUT09”两次base64解码之后为API调用字符串“DynamicDllInvoke”。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135586" data-ratio="0.49444444444444446" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=53a7389f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vEUxcIxEyRbq3eBcurzicBsoKwn1RK1lNO2SPFEv7Fvec9fxicAB78ic0g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图26 解密后的数据</span><o:p></o:p></p><h4 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">4.2.2 解密存放的remcosRAT木马</span></strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h4><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">接着Loader从其资源中读取名称为“nkkghrF”的加密数据并使用异或操作和一系列加、减和取模运算进行解密，最终解密出一恶意PE文件（见图27）。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135588" data-ratio="0.36944444444444446" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;text-wrap: wrap;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=73ea8727&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1v9HyGv5M5DeDSKcSbmNcJzdqvYaO4ZIBXdoInZuVJiah3LQbnczcYk4A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图27 解密出恶意PE文件</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">我们将解密后的恶意PE文件使用IDA静态分析，可以看到，该恶意PE文件实际上是商业远控木马remcosRAT（见图28），从图中我们可以看到，其版本号为“4.9.3 Pro”。后面Loader会使用进程挖空技术将该remcosRAT木马注入到新起的Loader进程中去执行。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135589" data-ratio="0.4740740740740741" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fccdc55c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vLNNKNQOjWKuyhzVz8v16AkgjNarCuuo336Oje0X7vJDiatIFPBYFVnw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图28解密的恶意PE为商业远控木马remcosRAT</span><o:p></o:p></p><h4 style="margin-bottom: 8px;text-indent: 0em;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">4.2.3 创建进程挖空技术相关API的委托</span></strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h4><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">在实施进程挖空操作之前，恶意Loader会先创建进程挖空操作相关的API的委托，以备后面使用进程挖空操作将remcosRAT远控木马写入新起的Loader进程中执行。首先，Loader会从前面解密的数据中查找进程挖空操作相关的一系列API的Base64值，然后Base64解码，接着调用DynamicDllInvoke动态加载函数和Invoke调用等函数，最后使用“Delegate.CreateDelegate”函数创建进程挖空操作相关的一系列API的委托（见图29）。</span><o:p></o:p></p><p><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135590" data-ratio="0.35462962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ea0ab913&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vQUabWao52D4cURQCow7GEe3wyiciaDNictQsPZAdbzZrVTIGzicPJOCVrw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图29创建进程挖空操作相关API的委托</span><o:p></o:p></p><p style="text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">这里一共涉及11个API，我们将它们列到表4中，创建的这些API委托用于后面进程挖空操作，将remcosRAT远控木马写入新起的Loader进程中执行。</span><o:p></o:p></p><table cellspacing="0" cellpadding="0"><tbody><tr><td width="312" valign="top" style="border-top-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-top-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left-color: rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 14px;"><strong><span style="color: white;">API名称</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="302" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;"><p><span style="font-size: 14px;"><strong><span style="font-size: 14px;color: white;">所在库</span></strong><strong><span style="font-size: 14px;color: white;"><o:p></o:p></span></strong></span></p></td></tr><tr><td width="287" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;word-break: break-all;"><p><span style="font-size: 12px;">Wow64GetThreadContext</span><o:p></o:p></p></td><td width="282" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">kernel32.dll</span><o:p></o:p></p></td></tr><tr><td width="312" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">GetThreadContext</span><o:p></o:p></p></td><td width="277" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">kernel32.dll</span><o:p></o:p></p></td></tr><tr><td width="312" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">ReadProcessMemory</span><o:p></o:p></p></td><td width="302" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">kernel32.dll</span><o:p></o:p></p></td></tr><tr><td width="312" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">VirtualAllocEx</span><o:p></o:p></p></td><td width="302" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">kernel32.dll</span><o:p></o:p></p></td></tr><tr><td width="312" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">WriteProcessMemory</span><o:p></o:p></p></td><td width="302" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">kernel32.dll</span><o:p></o:p></p></td></tr><tr><td width="312" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">Wow64SetThreadContext</span><o:p></o:p></p></td><td width="302" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">kernel32.dll</span><o:p></o:p></p></td></tr><tr><td width="312" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">SetThreadContext</span><o:p></o:p></p></td><td width="302" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">kernel32.dll</span><o:p></o:p></p></td></tr><tr><td width="312" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">ResumeThread</span><o:p></o:p></p></td><td width="302" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">kernel32.dll</span><o:p></o:p></p></td></tr><tr><td width="312" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;word-break: break-all;"><p><span style="font-size: 12px;">CreateProcessAsUser</span><o:p></o:p></p></td><td width="302" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;"><p><span style="font-size: 12px;">advapi32.dll</span><o:p></o:p></p></td></tr></tbody></table><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">表4 进程挖空操作用到的相关API</span><span lang="EN-US"><o:p></o:p></span></p><h4 style="text-indent: 0em;margin-bottom: 8px;"><strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">4.2.4 使用进程挖空技术执行remcosRAT</span></strong><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h4><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">完成了创建如上进程挖空操作相关的API的委托后，恶意Loader便会利用这一系列API将前面解密后的remcosRAT远控木马写入目标进程并执行。</span></p><p style="text-indent: 2em;margin-bottom: 8px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);">首先，恶意Loader会调用</span>CreateProcessAsUser<span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;background-color: rgb(255, 255, 255);">函数启动新进程（见图30），通过调用CreateProcessAsUser函数，恶意Loader以当前用户的身份创建新进程，并使用恶意Loader自身路径“C:\Users\[username]\Desktop\loader.exe”来执行新进程。这样做后就在当前用户的上下文中启动一个新的恶意Loader进程。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135591" data-ratio="0.28888888888888886" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d1c166dc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vCV0naBnppq7iab3bSMia1kHzn2Ypm95WrzUmic1mf9UJG6TX5iauWM4GRw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图30启动新进程</span><span style="text-indent: 0em;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">然后恶意Loader会通过检查IntPtr.Size是否等于4来判断当前系统是32位还是64位。如果IntPtr.Size不等于4，说明当前系统是64位，则使用Wow64GetThreadContext函数来保存目标进程的线程上下文信息；如果IntPtr.Size等于4，说明当前系统是32位，则使用GetThreadContext函数来保存目标进程的线程上下文信息（见图31）。保存的目标进程的线程上下文信息用于后面的恢复目标进程的线程上下文操作。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135592" data-ratio="0.22777777777777777" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0b4e315d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vHSibUo6DNp9uFMl3thhkJqDsHiaPmZ3FVW4ONIhaV9KLXNjEAnKopmqQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图31保存线程上下文信息</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">如图32，恶意Loader使用VirtualAllocEx函数在新起的进程空间中申请内存，申请内存的起始地址为0x400000，申请的内存大小为0x00082000，第四个参数为12288（0x3000），代表内存分配的类型为“MEM_COMMIT | MEM_RESERVE”，最后一个参数为64（0x40），代表内存保护属性为“RWE”。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135593" data-ratio="0.537962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fd6e198c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vXgrnoC2EBZTDrYSan7AQiaMuGm0b5Le84bIP1QSFLYYiboibiaTuEdt4Nw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">图</span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">32 </span><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">申请内存</span><span style="text-indent: 0em;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">接下来，恶意Loader会解析前面解密出的商业远控木马remcosRAT的PE结构，并使用WriteProcessMemory函数将其PE结构的各个section依次写入刚才申请的内存空间中（见图33）。</span><span style="text-indent: 0em;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135594" data-ratio="0.4462962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=80f7eb38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vO9VMhOKF16HTibVyNSsdhjpwlQb3OFDPcHoFS2icEWBeyxsHPK4cFytw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图33 将remcosRAT的各个section依次写入内存空间中</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">将remcosRAT远控木马写入目标进程后，恶意Loader会恢复目标进程的线程上下文信息（见图34），恢复之前同样会通过检查IntPtr.Size是否等于4来判断当前系统是32位还是64位，从而选择使用Wow64SetThreadContext或SetThreadContext函数来恢复。</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">恢复完目标进程的线程上下文信息后，恶意Loader最后调用ResumeThread函数来恢复目标进程的线程执行。这样一系列操作后，写入到目标进程中的remcosRAT远控木马就会执行。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135595" data-ratio="0.24074074074074073" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3e77ce93&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vHNAOibiaMiac84MDkYkNwVHGL1GfUQDgOlSkADo5j3x5vicbUtXWtYIgNw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图34 设置线程上下文信息并恢复线程执行</span><o:p></o:p></p><h3 style="text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(0, 82, 255);"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">4.3 remcosRAT木马</span></strong></span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span><o:p></o:p></h3><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">通过前面的分析，我们知道，恶意Loader通过内存解密和进程挖空技术，最终在感染设备上执行了商业远控木马Remcos
RAT，其版本号为“4.9.3 Pro”（如图35所示）。自2016年在暗网上的地下黑客社区开始出售以来，Remcos RAT非常活跃，基本上每个月都会发布两个左右的新版本。该工具由一家名为Breaking Security的公司发行出售，其具有键盘记录、屏幕记录、调用摄像头和麦克风进行录像录音、远程执行Shell命令、远程执行脚本、上传文件以及下载文件等功能。我们此前在报告</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649615525&amp;idx=1&amp;sn=972046bb870e2c9b4a59aa17b63e3661&amp;chksm=830631b5b471b8a3748144ca3a0c3d89f878ff6bdb84f4edcd201d650f10ea76bccc21f89ac1&amp;scene=21#wechat_redirect" textvalue="《【深度】ADLab针对新型黑客组织“海毒蛇”深度追踪与分析》" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">《</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">【深度】ADLab针对新型黑客组织“海毒蛇”深度追踪与分析</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">》</span></a><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">中曾对其进行过详细的技术分析，在此不做过多赘述，下面仅对其配置文件部分和C2命令部分进行简要说明。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135596" data-ratio="0.4685185185185185" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=95704195&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vpNcffpKbXMJ6stfU4IfdRI3Ipm2jJ4YFHuibEwM5YDPk7V4w8q8WK2Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图35 最终执行的商业远控木马remcosRAT</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">如图36所示，Remcos RAT运行后会从自身资源中解密出配置信息，里面包括C&amp;C服务器地址“45.87.155.41:8080，45.87.155.41:465，45.87.155.41:54550，45.87.155.41:80，45.87.154.153:80，45.87.154.153:8080，101.99.75.16:8080，101.99.75.16:80，101.99.75.16:465，101.99.75.145:465，101.99.75.145:80，94.131.102.115:80，94.131.102.117:80，94.131.102.119:80，94.131.102.122:80，94.131.102.124:80”、互斥对象名“dvwsus-SFNWWW”、键盘记录文件名“logs.dat”、Licence ID“5639D40461DCDD07011A2B87AD3C9EDD”以及和截图、录音等操作相关的其他信息。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135597" data-ratio="1.0862068965517242" data-s="300,640" style="" data-type="png" data-w="1044" src="https://wechat2rss.xlab.app/img-proxy/?k=599e2fdb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1v7ccx3Yyxbs8rzlnCLgXMFwq7BWpRKYDWYeBQroM4f0bPO9icNRPx0sg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 8px;text-align: center;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">图36解密出来的配置信息</span><o:p></o:p></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">Remcos RAT在感染主机执行并成功上线后，会等待C&amp;C服务器下发控制指令以执行恶意功能，其解析C&amp;C服务器控制指令的代码片段见图37。这些控制指令的功能包括执行文件管理、进程管理、键盘记录、屏幕记录、调用摄像头和麦克风进行录像录音、远程执行Shell命令、远程执行脚本、上传下载文件，注册表操作、安装卸载远控等,我们将主要的控制命令和功能描述列在表5中。</span><o:p></o:p></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135598" data-ratio="1.0935185185185186" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ff44c45f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nSugBthhAFXhzU4j4ibVTk1vLCggjZMtlsz7j0hdBEzCcPvwGRsuZE6douhjrw8icC1m8icDvqJB79Bw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;">图37 Remcos RAT解析控制指令的代码片段</span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:13.0pt;"><td width="197" valign="top" style="border-top-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-top-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left-color: rgb(68, 114, 196);border-right: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 14px;"><strong><span style="color: white;">控制命令</span></strong><strong><span style="color: white;"><o:p></o:p></span></strong></span></p></td><td width="487" valign="top" style="border-top-width: 1pt;border-right-width: 1pt;border-bottom-width: 1pt;border-top-color: rgb(68, 114, 196);border-right-color: rgb(68, 114, 196);border-bottom-color: rgb(68, 114, 196);border-left: none;background: rgb(68, 114, 196);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 14px;"><strong><span style="font-size: 14px;color: white;">功能描述</span></strong><strong><span style="font-size: 14px;color: white;"><o:p></o:p></span></strong></span></p></td></tr><tr style="mso-yfti-irow:1;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x01<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">获取受感染主机最顶端程序标题<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:2;height:13.0pt;"><td width="177" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x03<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="397" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">收集受感染主机所有已安装软件的相关信息，包括其软件供应商信息、版本信息、安装的路径信息、安装的日期等<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:3;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x06</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">收集受感染主机所有正在运行的进程信息<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;height:12.4pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">0x07<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">结束指定的进程<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:5;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x08</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">枚举所有的窗口并获取窗口标题<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:6;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x09<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">关闭指定的窗口<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:7;height:12.4pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">0x0A,
  0x0B, 0xAD<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">显示/隐藏指定的窗口<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:8;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x0C<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">获取指定窗口的PID<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:9;height:12.4pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">0x0D<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">执行指定的命令行命令<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:10;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x12</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">收集键盘信息<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:11;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x13</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">启动在线键盘记录器</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:12;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x14</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">停止在线键盘记录器</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:13;height:12.4pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">0x15，0x16<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">读取指定的文件并将其发送到C&amp;C服务器<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:14;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x17</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">删除指定的文件或路径</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:15;height:12.4pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">0x18<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">清除Firefox、Chrome等浏览器的登陆信息和cookie信息<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:16;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x1B</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">控制受感染设备摄像头</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:17;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x1D</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">记录受感染主机周围的声音信息并发送到C&amp;C服务器</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:18;height:12.4pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">0x1E</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">停止记录受感染主机周围声音信息</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:19;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x20</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">删除指定文件</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:20;height:12.4pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">0x21</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="12"><p><span style="font-size: 12px;">结束木马自身进程</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:21;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x22</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">卸载自身，同时会移除木马产生的相关文件<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:22;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x23</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">执行vbs脚本来重启自身</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:23;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x24<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">更新木马，该命令会从指定的URL下载文件并执行<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:24;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x26</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">在受感染主机显示信息</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:25;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x27</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">注销用户，关闭系统或重启感染主机</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:26;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x28<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">获取受感染主机剪切板数据<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:27;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x29，0x2A<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">清空受感染主机剪切板<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:28;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x2B</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">创建一个共享内存来共享数据</span><o:p></o:p></p></td></tr><tr style="mso-yfti-irow:29;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x2C<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">从指定的URL下载数据并将数据共享到创建的共享内存中<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:30;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x30<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">连接给定的服务器并与之通信<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:31;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x31</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">在注册表中保存用户名<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:32;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x32</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">设置代理<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:33;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x34<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">执行服务控制，包括更改指定服务配置，启动、暂停、终止指定服务，将指定的服务状态返回给C&amp;C服务器<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:34;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x8F<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">枚举指定路径的文件，并将文件列表发送给C&amp;C服务器<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:35;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x92</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">设置受感染主机桌面图片风格<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:36;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x94<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">修改指定窗口标题<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:37;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x95<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">获取实时物理内存状态并报告给C&amp;C服务器<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:38;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0x9E<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">在感染主机播放警告声音<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:39;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0xA3<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">控制受感染主机播放或者停止音频文件<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:40;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0xAB<o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">在受感染主机上提权，并将结果返回到C&amp;C服务器<o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:41;mso-yfti-lastrow:yes;height:13.0pt;"><td width="197" valign="top" style="border-right-width: 1pt;border-bottom-width: 1pt;border-left-width: 1pt;border-right-color: rgb(142, 170, 219);border-bottom-color: rgb(142, 170, 219);border-left-color: rgb(142, 170, 219);border-top: none;background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">0xAC</span><span style="font-size: 12px;"><o:p></o:p><strong><o:p></o:p></strong></span></p></td><td width="487" valign="top" style="border-top: none;border-left: none;border-bottom-width: 1pt;border-bottom-color: rgb(142, 170, 219);border-right-width: 1pt;border-right-color: rgb(142, 170, 219);background: rgb(217, 226, 243);padding: 0cm 5.4pt;" height="13"><p><span style="font-size: 12px;">在受感染主机显示弹出菜单</span><o:p></o:p></p></td></tr></tbody></table><p><span style="background-color: rgb(255, 255, 255);color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;">表5 C&amp;C服务器的主要控制命令和功能描述</span><span lang="EN-US"><o:p></o:p></span></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">可见，只要Remcos RAT被成功植入到目标设备，其背后的黑客便可完全控制这台设备，对其进行监控、数据窃取甚至是破坏活动。</span><o:p></o:p></p><p style="text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><strong>0</strong><strong data-original-title="" title="">5</strong></p><p><br/></p><p><strong data-brushtype="text">总 结</strong></p><p><br/></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;margin-bottom: 8px;"><br/></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">在过去的将近两年时间里，俄乌战争从最开始的俄方声称的“军事特别行动”，到后来的乌克兰全面反攻，再到如今的拉锯战和消耗战，俄乌双方都在这场战争中投入了巨大的人力、物力和财力。前线战场之外，网络空间的对抗也一直在持续，我们对近期俄乌网络战下来自俄罗斯的黑客组织的最新攻击活动进行了分析，通过以上分析我们可以看到，该黑客组织此次对乌克兰国家卫生服务局、农业政策和粮食部、战略产业部、韦尔霍维纳区国家管理局、扎波罗热市议会、卡米安市议会和乌克兰塑料包装解决方案供应商“RETAL”以及乌克兰银行“Agroprosperis
Bank”等实体进行网络攻击很可能是为了窃取乌方的医疗和粮食等战略物资的调配情况和乌方的作战情报信息，以辅助俄方在前线战场上进行攻击或防御方面做决策。我们对此次攻击中俄方黑客组织使用的基础设施、攻击目标等方面进行了全面的分析，并对最近出现的一次攻击活动进行了详细的分析。从我们分析的结果来看，俄方黑客组织使用的核心恶意文件服务器来自俄罗斯，结合我们2023年6月底的分析，再次说明，在针对乌方的网络攻击中，俄方黑客不再遮遮掩掩。</span><o:p></o:p></p><p style="margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);">俄乌战争持续将近两年，双方都损失惨重，同时伴随着西方国家的普遍参与，俄乌战争已经发展成俄罗斯与北约之间的战争。2023年10月，以哈冲突爆发，美国不得不分出精力应对以色列和巴勒斯坦的战局，这使得俄乌战争的走向愈加不确定。我们将会持续关注俄乌战争和俄乌网络战下该黑客组织的相关基础设施变化以对该组织的动向进行持续追踪。</span></p><p style="text-indent: 0em;margin-bottom: 8px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><strong>0</strong><strong data-original-title="" title="">6</strong></p><p><br/></p><p><strong data-brushtype="text">IOC</strong></p><p><br/></p><p style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;"><br/></p><h2 style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(0, 82, 255);"><strong style="outline: 0px;"><span style="outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">6.1 域名</span></strong></span><o:p style="outline: 0px;"></o:p></h2><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">https://npddocs.com/</span><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span><o:p style="outline: 0px;"></o:p></p><h2 style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);"><strong style="outline: 0px;"><span style="outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;color: rgb(0, 82, 255);">6.2 URL</span></strong><o:p style="outline: 0px;"></o:p></h2><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">https://npddocs.com/ssu.gov.ua/docs/file/util/0/d12934-0202334.doc</span><o:p></o:p></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">https://bitbucket.org/olegovich-007/777/downloads/wsuscr.exe</span></p><h2 style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);"><span style="outline: 0px;color: rgb(0, 82, 255);"><strong style="outline: 0px;"><span style="outline: 0px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">6.3 IP</span></strong></span><o:p style="outline: 0px;"></o:p></h2><p><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">89.23.98.22</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.199:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.199:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.199:21</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.199:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.190:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.18:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.25:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.60:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.79:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.90:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">95.214.26.99:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.102:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.102:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.102:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.101:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.103:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.19:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.19:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.19:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.212:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.218:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.92.218:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.190:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.191:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.192:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.193:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.193:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.194:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.195:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.196:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.196:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.197:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.197:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.198:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.199:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">185.65.105.15:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">69.46.15.167:2220</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">45.87.155.41:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">45.87.155.41:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">45.87.155.41:54550</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">45.87.155.41:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">45.87.154.153:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">45.87.154.153:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.75.16:8080</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.75.16:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.75.16:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.75.145:465</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">101.99.75.145:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">94.131.102.115:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">94.131.102.117:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">94.131.102.119:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">94.131.102.122:80</span><o:p></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span style="outline: 0px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">94.131.102.124:80</span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><o:p style="outline: 0px;"></o:p></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;text-wrap: wrap;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><br/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 15px;"><strong style="outline: 0px;"><span style="outline: 0px;letter-spacing: 2px;">参考链接：</span></strong></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><span style="font-size: 14px;outline: 0px;color: rgb(136, 136, 136);">[1] https://cert.gov.ua/article/6276567</span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 14px;">[2] https://cert.gov.ua/article/6276824</span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p><br/></p><p><br/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="outline: 0px;line-height: 1.8;"></span></p><p><br/></p><p style="outline: 0px;letter-spacing: 0.544px;"><br/></p><p><br/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截止目前，ADLab已通过CVE累计发布安全漏洞近1200个，通过 CNVD/CNNVD/NVDB累计发布安全漏洞4000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="outline: 0px;">5G安全研究、<span style="outline: 0px;">人工智能安全研究、</span></span></span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">移动与物联网安全研究、</span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">工控安全研究、信创安全研究、</span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">云安全研究、</span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="outline: 0px;letter-spacing: 1.5px;">。</span></span><span style="outline: 0px;"></span></p><p><br/></p><p style="outline: 0px;letter-spacing: 0.544px;"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br/></p><p style="outline: 0px;letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135514" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 282px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=acf4e31d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Djpeg%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/><span style="font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Fri, 19 Jan 2024 17:55:30 +0800</pubDate>
    </item>
    <item>
      <title>Glibc权限提升漏洞“Looney Tunables”分析（CVE-2023-4911）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAwNTI1NDI3MQ==&amp;mid=2649619208&amp;idx=1&amp;sn=656b180f2cf3447f40e9fdbc6d8f35e1&amp;chksm=83062618b471af0e734eb53ab15befbe81e4bcb84549343a63f038a051c779088c527797f0c2&amp;scene=58&amp;subscene=0#rd</link>
      <description>近日，Qualys公司Threat Research Unit披露了一个Glibc漏洞，Glibc库在处理环境变量时存在缓冲区溢出，可导致本地权限提升。该漏洞影响各种Linux 发行版，包括 Fedora、Ubuntu、Debian 等。</description>
      <content:encoded><![CDATA[<p>
<span>启明星辰</span> <span>2024-01-16 17:07</span> <span style="display: inline-block;">北京</span>
</p>

<p>近日，Qualys公司Threat Research Unit披露了一个Glibc漏洞，Glibc库在处理环境变量时存在缓冲区溢出，可导致本地权限提升。该漏洞影响各种Linux 发行版，包括 Fedora、Ubuntu、Debian 等。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=7954d02c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FXGicR9TOl8nQMVCVzd9paGrt8faqnuV1AvQktgdcQhcRyVxWRIeSoib8SYYiaHUqw2sUibBjQPmOsf9RnCnpLWQTsg%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="outline: 0px;visibility: visible;"><span style="outline: 0px;letter-spacing: 0.544px;font-size: 14px;visibility: visible;">更多安全资讯和分析文章请关注启明星辰ADLab微信公众号及官方网站（adlab.venustech.com.cn）</span></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br style="outline: 0px;visibility: visible;"/></p><p><br/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;margin-bottom: 0px;"><br/></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">近日，Qualys公司Threat Research Unit披露了一个Glibc漏洞，Glibc库在处理环境变量的时候存在缓冲区溢出漏洞，可导致本地权限提升。该漏洞影响各种Linux 发行版，包括 Fedora、Ubuntu、Debian 等。</span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p><strong>0</strong><strong data-original-title="" title="" data-num="2">1</strong></p><p><strong data-brushtype="text">漏洞分析</strong></p><p><br/></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">根据披露的信息，漏洞存在于ld.so动态链接器对环境变量的处理过程中。使用ldd命令查看系统程序的加载器，例如：ldd /bin/ls，可以看到实际加载器为/lib64/ld-linux-x86-64.so.2。</span><o:p></o:p></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="go"><code><span class="code-snippet_outer">$ ldd /bin/ls</span></code><code><span class="code-snippet_outer">    linux-vdso.so<span class="code-snippet__number">.1</span> (<span class="code-snippet__number">0x00007ffe2935d</span>000)</span></code><code><span class="code-snippet_outer">    libselinux.so<span class="code-snippet__number">.1</span> =&gt; /lib/x86_64-linux-gnu/libselinux.so<span class="code-snippet__number">.1</span> (<span class="code-snippet__number">0x00007f</span>088ec45000)</span></code><code><span class="code-snippet_outer">    libc.so<span class="code-snippet__number">.6</span> =&gt; /lib/x86_64-linux-gnu/libc.so<span class="code-snippet__number">.6</span> (<span class="code-snippet__number">0x00007f088ea1d</span>000)</span></code><code><span class="code-snippet_outer">    libpcre2<span class="code-snippet__number">-8.s</span>o<span class="code-snippet__number">.0</span> =&gt; /lib/x86_64-linux-gnu/libpcre2<span class="code-snippet__number">-8.s</span>o<span class="code-snippet__number">.0</span> (<span class="code-snippet__number">0x00007f</span>088e986000)</span></code><code><span class="code-snippet_outer">    /lib64/ld-linux-x86<span class="code-snippet__number">-64.s</span>o<span class="code-snippet__number">.2</span> (<span class="code-snippet__number">0x00007f</span>088eca8000)</span></code></pre><p style="text-align: justify;margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);">漏洞存在于加载器的parse_tunables函数中，该函数由tunables_init函数调用，tunables_init函数负责处理 GLIBC_TUNABLES 环境变量，使开发人员能够动态调整运行时库的行为。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">void</span> __tunables_init (<span class="code-snippet__keyword">char</span> **envp)</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer"> <span class="code-snippet__keyword">char</span> *envname = <span class="code-snippet__literal">NULL</span>;</span></code><code><span class="code-snippet_outer"> <span class="code-snippet__keyword">char</span> *envval = <span class="code-snippet__literal">NULL</span>;</span></code><code><span class="code-snippet_outer"> <span class="code-snippet__keyword">size_t</span> len = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer"> <span class="code-snippet__keyword">char</span> **prev_envp = envp;</span></code><code><span class="code-snippet_outer"> </span></code><code><span class="code-snippet_outer"> maybe_enable_malloc_check ();</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"> <span class="code-snippet__keyword">while</span> ((envp = get_next_env (envp, &amp;envname, &amp;len, &amp;envval,</span></code><code><span class="code-snippet_outer">          &amp;prev_envp)) != <span class="code-snippet__literal">NULL</span>)   #获取环境变量</span></code><code><span class="code-snippet_outer">  {</span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">if</span> TUNABLES_FRONTEND == TUNABLES_FRONTEND_valstring</span></span></code><code><span class="code-snippet_outer">   <span class="code-snippet__keyword">if</span> (tunable_is_name (GLIBC_TUNABLES, envname))</span></code><code><span class="code-snippet_outer">  {</span></code><code><span class="code-snippet_outer">   <span class="code-snippet__keyword">char</span> *new_env = tunables_strdup (envname);</span></code><code><span class="code-snippet_outer">   <span class="code-snippet__keyword">if</span> (new_env != <span class="code-snippet__literal">NULL</span>)</span></code><code><span class="code-snippet_outer">   parse_tunables (new_env + len + <span class="code-snippet__number">1</span>, envval);  #漏洞程序</span></code><code><span class="code-snippet_outer">   <span class="code-snippet__comment">/* Put in the updated envval.  */</span></span></code><code><span class="code-snippet_outer">   *prev_envp = new_env;</span></code><code><span class="code-snippet_outer">   <span class="code-snippet__keyword">continue</span>;</span></code><code><span class="code-snippet_outer">  }</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);"></span></p><p style="text-align: justify;margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);">代码中，get_next_env函数从保存的环境变量中逐个提取环境变量信息。tunable_is_name (GLIBC_TUNABLES, envname)函数负责查找“GLIBC_TUNABLES”的环境变量，找到该变量后将其保存到tunables_strdup函数申请的空间中，并返回缓冲区地址保存到new_env指针。由于此时malloc程序还没初始化，所以tunables_strdup调用__minimal_malloc分配地址，minimal_malloc() 实际上调用 mmap() 来获取内存。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">char</span> *</span></code><code><span class="code-snippet_outer">tunables_strdup (<span class="code-snippet__keyword">const</span> <span class="code-snippet__keyword">char</span> *<span class="code-snippet__keyword">in</span>)</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">  size_t i = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">while</span> (<span class="code-snippet__keyword">in</span>[i++] != <span class="code-snippet__string">&#39;\0&#39;</span>);</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">char</span> *<span class="code-snippet__keyword">out</span> = __minimal_malloc (i + <span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__comment">/* For most of the tunables code, we ignore user errors.  However,</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     this is a system error - and running out of memory at program</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">     startup should be reported, so we do.  */</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">if</span> (<span class="code-snippet__keyword">out</span> == NULL)</span></code><code><span class="code-snippet_outer">    _dl_fatal_printf (<span class="code-snippet__string">&#34;failed to allocate memory to process tunables\n&#34;</span>);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">while</span> (i-- &gt; <span class="code-snippet__number">0</span>)</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">out</span>[i] = <span class="code-snippet__keyword">in</span>[i];</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">return</span> <span class="code-snippet__keyword">out</span>;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">endif</span></span></span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);"></span></p><p style="text-align: justify;margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);">随后调用parse_tunables方法处理 new_env 中的数据，下面对代码进行详细分析。以“tunable1=tunable2=AAA”参数为例。进入第一个while（true），首先找到第一个&#34;=&#34;之后的参数，然后将p指向第一个参数的值“tunable2=AAA”。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="go"><code><span class="code-snippet_outer">while (p[<span class="code-snippet__built_in">len</span>] != <span class="code-snippet__string">&#39;=&#39;</span> &amp;&amp; p[<span class="code-snippet__built_in">len</span>] != <span class="code-snippet__string">&#39;:&#39;</span> &amp;&amp; p[<span class="code-snippet__built_in">len</span>] != <span class="code-snippet__string">&#39;\0&#39;</span>)</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">len</span>++;</span></code><code><span class="code-snippet_outer">    ...</span></code><code><span class="code-snippet_outer">p += <span class="code-snippet__built_in">len</span> + <span class="code-snippet__number">1</span>;</span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">len</span>=<span class="code-snippet__number">0</span>;</span></code></pre><p style="text-align: justify;margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);">然后，开始第二次循环检索，此时没有对错误格式输入的第二个等号进行检索，直接定位到参数的结尾，这时len的长度为&#34;tunable2=AAA&#34;的长度。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li></ul><pre class="code-snippet__js" data-lang="go"><code><span class="code-snippet_outer">while (p[<span class="code-snippet__built_in">len</span>] != <span class="code-snippet__string">&#39;:&#39;</span> &amp;&amp; p[<span class="code-snippet__built_in">len</span>] != <span class="code-snippet__string">&#39;\0&#39;</span>)</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">len</span>++;</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);"></span></p><p style="text-align: justify;margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);">随后在for循环中将tunable1后面所有的数据全部拷贝到tunestr，此时缓冲区已经被占满。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">size_t</span> i = <span class="code-snippet__number">0</span>; i &lt; <span class="code-snippet__keyword">sizeof</span> (tunable_list) / <span class="code-snippet__keyword">sizeof</span> (<span class="code-snippet__keyword">tunable_t</span>); i++)</span></code><code><span class="code-snippet_outer">    {</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__keyword">tunable_t</span> *cur = &amp;tunable_list[i];</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">      <span class="code-snippet__keyword">if</span> (tunable_is_name (cur-&gt;name, name))</span></code><code><span class="code-snippet_outer">        {</span></code><code><span class="code-snippet_outer">          <span class="code-snippet__comment">/* If we are in a secure context (AT_SECURE) then ignore the</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">         tunable unless it is explicitly marked as secure.  Tunable</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">         values take precedence over their envvar aliases.  We write</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">         the tunables that are not SXID_ERASE back to TUNESTR, thus</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">         dropping all SXID_ERASE tunables and any invalid or</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">         unrecognized tunables.  */</span></span></code><code><span class="code-snippet_outer">          <span class="code-snippet__keyword">if</span> (__libc_enable_secure)</span></code><code><span class="code-snippet_outer">        {</span></code><code><span class="code-snippet_outer">          <span class="code-snippet__keyword">if</span> (cur-&gt;security_level != TUNABLE_SECLEVEL_SXID_ERASE)</span></code><code><span class="code-snippet_outer">            {</span></code><code><span class="code-snippet_outer">              <span class="code-snippet__keyword">if</span> (off &gt; <span class="code-snippet__number">0</span>)</span></code><code><span class="code-snippet_outer">            tunestr[off++] = <span class="code-snippet__string">&#39;:&#39;</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">              <span class="code-snippet__keyword">const</span> <span class="code-snippet__keyword">char</span> *n = cur-&gt;name;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">              <span class="code-snippet__keyword">while</span> (*n != <span class="code-snippet__string">&#39;\0&#39;</span>)</span></code><code><span class="code-snippet_outer">            tunestr[off++] = *n++;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">              tunestr[off++] = <span class="code-snippet__string">&#39;=&#39;</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">              <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">size_t</span> j = <span class="code-snippet__number">0</span>; j &lt; len; j++)</span></code><code><span class="code-snippet_outer">            tunestr[off++] = value[j];</span></code><code><span class="code-snippet_outer">            }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">          <span class="code-snippet__keyword">if</span> (cur-&gt;security_level != TUNABLE_SECLEVEL_NONE)</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__keyword">break</span>;</span></code><code><span class="code-snippet_outer">        }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">          value[len] = <span class="code-snippet__string">&#39;\0&#39;</span>;</span></code><code><span class="code-snippet_outer">          tunable_initialize (cur, value);</span></code><code><span class="code-snippet_outer">          <span class="code-snippet__keyword">break</span>;</span></code><code><span class="code-snippet_outer">        }</span></code><code><span class="code-snippet_outer">    }</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);"></span></p><p style="text-align: justify;margin-bottom: 8px;text-indent: 2em;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);">最后一个判断，如果p[len]!=&#39;\0&#39;，则将p指向下一个参数。但是由上文可知，此时p[len]==&#39;\0&#39;，所以进入第二个循环，此时p指向第二个参数的值“tunable2=AAA“。再重复上面的拷贝过程中会造成缓冲区溢出，溢出字节为“AAA”。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li></ul><pre class="code-snippet__js" data-lang="go"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">if</span> (p[<span class="code-snippet__built_in">len</span>] != <span class="code-snippet__string">&#39;\0&#39;</span>)</span></code><code><span class="code-snippet_outer">    p += <span class="code-snippet__built_in">len</span> + <span class="code-snippet__number">1</span>;</span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(255, 255, 255);"></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><o:p><br/></o:p></p><p><strong>0</strong><strong data-original-title="" title="" data-num="2">2</strong></p><p><strong data-brushtype="text">权限提升</strong></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">下面介绍如何劫持程序的环境变量，修改glibc动态链接库路径，并且使其加载修改过的libc.so.6文件，达到提权的目的。</span><o:p></o:p></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">首先，看一下这部分程序申请空间的过程，根据调试，tunables_init初始化中第一次获取GLIBC_TUNABLES环境变量会调用minimal_malloc来申请内存。申请内存的位置0x7f8b545cd2e0 位于/usr/local/lib/ld-linux-x86-64.so.2缓冲区中，此时距离ld-linux-x86-64.so.2程序空间末尾距离为0xd20。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="go"><code><span class="code-snippet_outer">pwndbg&gt; b __GI___tunables_init</span></code><code><span class="code-snippet_outer">pwndbg&gt; b *<span class="code-snippet__number">0x7f8b545aad5d</span>         #通过计算得到</span></code><code><span class="code-snippet_outer">Breakpoint <span class="code-snippet__number">4</span> at <span class="code-snippet__number">0x7f8b545aad5d</span>: file dl-tunables.c, line <span class="code-snippet__number">52.</span></span></code><code><span class="code-snippet_outer">pwndbg&gt; c</span></code><code><span class="code-snippet_outer">Continuing.</span></code><code><span class="code-snippet_outer">Thread <span class="code-snippet__number">3.1</span> <span class="code-snippet__string">&#34;test&#34;</span> hit Breakpoint <span class="code-snippet__number">4</span>, <span class="code-snippet__number">0x00007f8b545aad5d</span> in tunables_strdup (in=&lt;optimized out&gt;) at dl-tunables.c:<span class="code-snippet__number">52</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__number">52</span>    char *out = __minimal_malloc (i + <span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">pwndbg&gt; ni</span></code><code><span class="code-snippet_outer">pwndbg&gt; i r</span></code><code><span class="code-snippet_outer">rax            <span class="code-snippet__number">0x7f8b545cd</span>2e0      </span></code><code><span class="code-snippet_outer">pwndbg&gt; vmmap</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__number">0x7f</span>8b54595000     <span class="code-snippet__number">0x7f</span>8b54597000 r--p     <span class="code-snippet__number">2000</span>      <span class="code-snippet__number">0</span> /usr/local/lib/ld-linux-x86<span class="code-snippet__number">-64.s</span>o<span class="code-snippet__number">.2</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__number">0x7f</span>8b54597000     <span class="code-snippet__number">0x7f</span>8b545be000 r-xp    <span class="code-snippet__number">27000</span>   <span class="code-snippet__number">2000</span> /usr/local/lib/ld-linux-x86<span class="code-snippet__number">-64.s</span>o<span class="code-snippet__number">.2</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__number">0x7f</span>8b545be000     <span class="code-snippet__number">0x7f</span>8b545c9000 r--p     b000  <span class="code-snippet__number">29000</span> /usr/local/lib/ld-linux-x86<span class="code-snippet__number">-64.s</span>o<span class="code-snippet__number">.2</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__number">0x7f</span>8b545ca000     <span class="code-snippet__number">0x7f</span>8b545ce000 rw-p     <span class="code-snippet__number">4000</span>  <span class="code-snippet__number">34000</span> /usr/local/lib/ld-linux-x86<span class="code-snippet__number">-64.s</span>o<span class="code-snippet__number">.2</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__number">0x7ff</span>ca3e3e000     <span class="code-snippet__number">0x7ff</span>ca4440000 rw-p   <span class="code-snippet__number">602000</span>      <span class="code-snippet__number">0</span> [stack]</span></code><code><span class="code-snippet_outer"><span class="code-snippet__number">0xffffffffff</span>600000 <span class="code-snippet__number">0xffffffffff</span>601000 --xp     <span class="code-snippet__number">1000</span>      <span class="code-snippet__number">0</span> [vsyscall]</span></code><code><span class="code-snippet_outer">pwndbg&gt; hex(<span class="code-snippet__number">0x7f</span>8b545ce000<span class="code-snippet__number">-0x7f8b545cd</span>2e0)</span></code><code><span class="code-snippet_outer"> <span class="code-snippet__number">0x000d</span>20</span></code></pre><p><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">第一次申请空间会分配到0xd20这部分空间，但是如果在申请0xd00大小的空间之后。程序再次调用minimal_malloc函数来申请空间，将会调用mmap()程序从内核申请可用空间。这里以申请0x200大小的空间为例，可以看到内核分配了大小为0x2000的空间。经过调试后可知，后续使用minimal_malloc申请的空间也会从这一块空间中分配，这也就让利用该漏洞有了可能。</span><o:p></o:p></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer">pwndbg&gt; c</span></code><code><span class="code-snippet_outer">Continuing.</span></code><code><span class="code-snippet_outer">Thread <span class="code-snippet__number">3.1</span> <span class="code-snippet__string">&#34;test&#34;</span> hit Breakpoint <span class="code-snippet__number">4</span>, <span class="code-snippet__number">0x00007f8b545aad5d</span> <span class="code-snippet__function"><span class="code-snippet__keyword">in</span> <span class="code-snippet__title">tunables_strdup</span> (<span class="code-snippet__params"><span class="code-snippet__keyword">in</span>=&lt;optimized <span class="code-snippet__keyword">out</span>&gt;</span>) at dl-tunables.c:52</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">52    <span class="code-snippet__keyword">char</span> *<span class="code-snippet__keyword">out</span></span> = __minimal_malloc (i + <span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">pwndbg&gt; ni</span></code><code><span class="code-snippet_outer"><span class="code-snippet__number">0x00007f8b545aad62</span>  <span class="code-snippet__number">52</span>    <span class="code-snippet__keyword">char</span> *<span class="code-snippet__keyword">out</span> = __minimal_malloc (i + <span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">pwndbg&gt; i r</span></code><code><span class="code-snippet_outer">rax            <span class="code-snippet__number">0x7f8b5458d000</span>      </span></code><code><span class="code-snippet_outer">pwndbg&gt; vmmap</span></code><code><span class="code-snippet_outer">LEGEND: STACK | HEAP | CODE | DATA | RWX | RODATA</span></code><code><span class="code-snippet_outer"> Start          End            Perm     Size  Offset        File</span></code><code><span class="code-snippet_outer"> <span class="code-snippet__number">0x403000</span>      <span class="code-snippet__number">0x405000</span>       rw-p   <span class="code-snippet__number">2000</span>   <span class="code-snippet__number">4000</span> /home/kpy/test</span></code><code><span class="code-snippet_outer"> <span class="code-snippet__number">0x7f8b5458d000</span> <span class="code-snippet__number">0x7f8b5458f000</span> rw-p   <span class="code-snippet__number">2000</span>   <span class="code-snippet__number">0</span>    [anon_7f8b5458d]</span></code></pre><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">在tunables_init初始化完成后紧接着会在dl-object.c 的__dl_new_object函数中申请缓冲区来存储struct link_map结构体，由于此时glibc的calloc的函数还未初始化，所以此时还是调用minimal_malloc函数来申请空间。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">new</span> = (<span class="code-snippet__keyword">struct</span> link_map *) calloc (<span class="code-snippet__keyword">sizeof</span> (*<span class="code-snippet__keyword">new</span>) + audit_space</span></code><code><span class="code-snippet_outer">                    + <span class="code-snippet__keyword">sizeof</span> (<span class="code-snippet__keyword">struct</span> link_map *)</span></code><code><span class="code-snippet_outer">                    + <span class="code-snippet__keyword">sizeof</span> (*newname) + libname_len, <span class="code-snippet__number">1</span>);</span></code></pre><p><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">根据调试信息，此时申请的空间位于GLIBC_TUNABLES环境变量后面，也就是说，溢出刚好能覆盖struct
link_map结构体的内容。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer">pwndbg&gt; c</span></code><code><span class="code-snippet_outer">Continuing.</span></code><code><span class="code-snippet_outer">Thread <span class="code-snippet__number">3.1</span> <span class="code-snippet__string">&#34;test&#34;</span> hit Breakpoint <span class="code-snippet__number">4</span>, <span class="code-snippet__number">0x00007f8b545aad5d</span> <span class="code-snippet__function"><span class="code-snippet__keyword">in</span> <span class="code-snippet__title">tunables_strdup</span> (<span class="code-snippet__params"><span class="code-snippet__keyword">in</span>=&lt;optimized <span class="code-snippet__keyword">out</span>&gt;</span>) at dl-tunables.c:52</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">52    <span class="code-snippet__keyword">char</span> *<span class="code-snippet__keyword">out</span></span> = __minimal_malloc (i + <span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">pwndbg&gt; ni </span></code><code><span class="code-snippet_outer"><span class="code-snippet__number">0x00007f8b545aad62</span>  <span class="code-snippet__number">52</span>    <span class="code-snippet__keyword">char</span> *<span class="code-snippet__keyword">out</span> = __minimal_malloc (i + <span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">pwndbg&gt; i r</span></code><code><span class="code-snippet_outer">rax            <span class="code-snippet__number">0x7f8b5458d210</span>      <span class="code-snippet__number">140236392288784</span></span></code><code><span class="code-snippet_outer">pwndbg&gt; vmmap</span></code><code><span class="code-snippet_outer"><span class="code-snippet__number">0x403000</span>       <span class="code-snippet__number">0x405000</span>     rw-p  <span class="code-snippet__number">2000</span>  <span class="code-snippet__number">4000</span> /home/kpy/test</span></code><code><span class="code-snippet_outer"><span class="code-snippet__number">0x7f8b5458d000</span> <span class="code-snippet__number">0x7f8b5458f000</span> rw-p  <span class="code-snippet__number">2000</span>    <span class="code-snippet__number">0</span> [anon_7f8b5458d]</span></code></pre><p><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">接下来，考虑需要覆盖结构体的哪个成员变量。根据link_map结构体信息，发现一个非常有意思的成员变量link_map-&gt;l_info[DT_RPATH]，这是一个指向小型 (16B) Elf64_Dyn 结构的指针。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="properties"><code><span class="code-snippet_outer"><span class="code-snippet__meta">pwndbg&gt;</span> <span class="code-snippet__string">p *((struct link_map *) $rax)</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">$1</span> = <span class="code-snippet__string">{</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_addr</span> = <span class="code-snippet__string">4774451407232463713,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_name</span> = <span class="code-snippet__string">0x4242424242424242 &lt;error: Cannot access memory at address 0x4242424242424242&gt;,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_ld</span> = <span class="code-snippet__string">0x4242424242424242,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_next</span> = <span class="code-snippet__string">0x4242424242424242,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_prev</span> = <span class="code-snippet__string">0x4242424242424242,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_real</span> = <span class="code-snippet__string">0x4242424242424242,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_ns</span> = <span class="code-snippet__string">4774451407313060418,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_libname</span> = <span class="code-snippet__string">0x4242424242424242,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_info</span> = <span class="code-snippet__string">{0x4242424242424242 &lt;repeats 49 times&gt;, 0x696c673a42424242, 0x6f6c6c616d2e6362, 0x74736166786d2e63, 0x3d, 0x0 &lt;repeats 24 times&gt;},</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_phdr</span> = <span class="code-snippet__string">0x7ffcfffff010,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_entry</span> = <span class="code-snippet__string">0,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_phnum</span> = <span class="code-snippet__string">0,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_ldnum</span> = <span class="code-snippet__string">0,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_searchlist</span> = <span class="code-snippet__string">{</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">r_list</span> = <span class="code-snippet__string">0x0,</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">r_nlist</span> = <span class="code-snippet__string">0</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">}</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_local_scope</span> = <span class="code-snippet__string">{0x0, 0x2e6362696c673a00},</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_file_id</span> = <span class="code-snippet__string">{</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">dev</span> = <span class="code-snippet__string">7867334929274397037,</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">ino</span> = <span class="code-snippet__string">67570361263736</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">},</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">...</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_relro_addr</span> = <span class="code-snippet__string">0,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_relro_size</span> = <span class="code-snippet__string">0,</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">l_serial</span> = <span class="code-snippet__string">0</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">}</span></span></code></pre><p><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">控制该指针变量即可以控制用户程序的动态链接库路径。具体代码在_dl_init_paths（elf/dl-load.c）函数中，当动态链接器加载共享库时会执行该部分代码。代码首先检查 DT_RPATH 成员变量是否存在，如果存在，则从该节中读取 RPATH 信息，并将其解析为一组目录路径，存储在l-&gt;l_rpath_dirs.dirs 中。如果 RPATH 为空，则设置 l-&gt;l_rpath_dirs.dirs = </span><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">(void*)-1，</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">表示路径</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">查找失败</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">if</span> (l-&gt;l_info[DT_RPATH])</span></code><code><span class="code-snippet_outer">    {</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__comment">/* Allocate room for the search path and fill in information</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">         from RPATH.  */</span></span></code><code><span class="code-snippet_outer">      decompose_rpath (&amp;l-&gt;l_rpath_dirs,</span></code><code><span class="code-snippet_outer">               (<span class="code-snippet__keyword">const</span> void *) (D_PTR (l, l_info[DT_STRTAB])</span></code><code><span class="code-snippet_outer">                       + l-&gt;l_info[DT_RPATH]-&gt;d_un.d_val),</span></code><code><span class="code-snippet_outer">               l, <span class="code-snippet__string">&#34;RPATH&#34;</span>);</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__comment">/* During rtld init the memory is allocated by the stub</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">         malloc, prevent any attempt to free it by the normal</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">         malloc.  */</span></span></code><code><span class="code-snippet_outer">      l-&gt;l_rpath_dirs.malloced = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__keyword">else</span></span></code><code><span class="code-snippet_outer">    l-&gt;l_rpath_dirs.dirs = (void *) <span class="code-snippet__number">-1</span>;</span></code><code><span class="code-snippet_outer">    }</span></code></pre><p><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">在上面代码调用decompose_rpath时，代码对 l-&gt;l_rpath_dirs 进行了内存分配和初始化，其中l-&gt;l_info[DT_STRTAB] 和l-&gt;l_info[DT_RPATH]-&gt;d_un.d_val 分别指向DT_STRTAB表和偏移。</span><o:p></o:p></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">DT_STRTAB表地址在实际程序su的0xFF0处，通过该地址加上偏移，就能得到程序调用的动态链接库路径。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135548" data-ratio="0.35833333333333334" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ae3b73f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTv4gbJPgBFQpPSAM4yfk23NAfmb4NvKYScw81OHro9QnNy27chcpZsSbMXt2LU27MWKibiaEQ91XSw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">一般在suid的程序中DT_STRTAB表附近都会有下图中类似的字符，以引号字符“为例，也就是如果将 l-&gt;l_info[DT_RPATH]-&gt;d_un.d_val 设置为-0x14，就能计算出目录为引号字符“的路径，只要在引号字符“目录中设置修改过的libc.so.6，</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">就能</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">让被攻击的程序调用错误的动态链接库，获取</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">root权限</span><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135549" data-ratio="0.41759259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2107d520&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTv4gbJPgBFQpPSAM4yfk23PsHTctLEaNKxsmSib1vsH92XKkh9YRYkblXwgZMu39ibGRuOmOicJWXNg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">在实际开发时，如何将l_info[DT_RPATH]设置为指向0x14的地址？在上文中有提到，最开始的环境变量保存在堆栈中，所以这里将l_info[DT_RPATH]地址覆盖为栈地址。但是通常拥有SUID权限的程序都开启了PIE保护，堆栈中没有稳定可用的地址。但是由于漏洞可以反复触发，所以使用Stack
Spray。在 Linux 上，堆栈会在 16GB 区域中随机化，环境变量字符串最多可以占用 6MB。假如我们填充6M大小的环境变量，在 最多16GB / 6MB = 2730 次尝试后，就很有可能列举出指向0x14的地址。经过2000多次的尝试，提权成功。</span></p><p><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="502135550" data-ratio="0.6101851851851852" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0b18c0a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FXGicR9TOl8nTv4gbJPgBFQpPSAM4yfk23nDYnpCPQvGHMibBnN304AAP4Kou37HjfxicFuljjQBqWy98kmAzicar2A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"><br/></span></p><p><strong>0</strong><strong data-original-title="" title="" data-num="2">3</strong></p><p><strong data-brushtype="text">补丁分析</strong></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">下面是ubuntu对该漏洞的修复代码，可以看到在代码后面增加了一条判断语句if
(p[len] == &#39;\0&#39;)，如果p[len]==\0,则执行break，跳出循环，不会继续复制，防止了缓冲区溢出。</span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;">补丁链接 </span><span style="color: rgb(136, 136, 136);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;">https://ubuntu.com/security/notices/USN-6409-1</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer">+-<span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span></span></code><code><span class="code-snippet_outer">++__attribute__ ((noinline)) <span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span></span></code><code><span class="code-snippet_outer">+ parse_tunables (<span class="code-snippet__keyword">char</span> *tunestr, <span class="code-snippet__keyword">char</span> *valstring)</span></code><code><span class="code-snippet_outer">+ {</span></code><code><span class="code-snippet_outer">+   <span class="code-snippet__keyword">if</span> (tunestr == NULL || *tunestr == <span class="code-snippet__string">&#39;\0&#39;</span>)</span></code><code><span class="code-snippet_outer">+@@ <span class="code-snippet__number">-187</span>,<span class="code-snippet__number">11</span> +<span class="code-snippet__number">187</span>,<span class="code-snippet__number">7</span> @@ parse_tunables (<span class="code-snippet__keyword">char</span> *tunestr, <span class="code-snippet__keyword">char</span> *val</span></code><code><span class="code-snippet_outer">+       <span class="code-snippet__comment">/* If we reach the end of the string before getting a valid name-value</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">+    pair, bail out.  */</span></span></code><code><span class="code-snippet_outer">+       <span class="code-snippet__keyword">if</span> (p[len] == <span class="code-snippet__string">&#39;\0&#39;</span>)</span></code><code><span class="code-snippet_outer">+-  {</span></code><code><span class="code-snippet_outer">+-    <span class="code-snippet__keyword">if</span> (__libc_enable_secure)</span></code><code><span class="code-snippet_outer">+-      tunestr[off] = <span class="code-snippet__string">&#39;\0&#39;</span>;</span></code><code><span class="code-snippet_outer">+-    <span class="code-snippet__keyword">return</span>;</span></code><code><span class="code-snippet_outer">+-  }</span></code><code><span class="code-snippet_outer">++  <span class="code-snippet__keyword">break</span>;</span></code><code><span class="code-snippet_outer">+ </span></code><code><span class="code-snippet_outer">+       <span class="code-snippet__comment">/* We did not find a valid name-value pair before encountering the</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">+    colon.  */</span></span></code><code><span class="code-snippet_outer">+@@ <span class="code-snippet__number">-251</span>,<span class="code-snippet__number">9</span> +<span class="code-snippet__number">247</span>,<span class="code-snippet__number">16</span> @@ parse_tunables (<span class="code-snippet__keyword">char</span> *tunestr, <span class="code-snippet__keyword">char</span> *val</span></code><code><span class="code-snippet_outer">+       }</span></code><code><span class="code-snippet_outer">+   }</span></code><code><span class="code-snippet_outer">+ </span></code><code><span class="code-snippet_outer">+-      <span class="code-snippet__keyword">if</span> (p[len] != <span class="code-snippet__string">&#39;\0&#39;</span>)</span></code><code><span class="code-snippet_outer">+-  p += len + <span class="code-snippet__number">1</span>;</span></code><code><span class="code-snippet_outer">++      <span class="code-snippet__comment">/* We reached the end while processing the tunable string.  */</span></span></code><code><span class="code-snippet_outer">++      <span class="code-snippet__keyword">if</span> (p[len] == <span class="code-snippet__string">&#39;\0&#39;</span>)</span></code><code><span class="code-snippet_outer">++  <span class="code-snippet__keyword">break</span>;</span></code><code><span class="code-snippet_outer">++</span></code><code><span class="code-snippet_outer">++      p += len + <span class="code-snippet__number">1</span>;</span></code><code><span class="code-snippet_outer">+     }</span></code><code><span class="code-snippet_outer">++</span></code><code><span class="code-snippet_outer">++  <span class="code-snippet__comment">/* Terminate tunestr before we leave.  */</span></span></code><code><span class="code-snippet_outer">++  <span class="code-snippet__keyword">if</span> (__libc_enable_secure)</span></code><code><span class="code-snippet_outer">++    tunestr[off] = <span class="code-snippet__string">&#39;\0&#39;</span>;</span></code><code><span class="code-snippet_outer">+ }</span></code><code><span class="code-snippet_outer">+ <span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">endif</span></span></span></code></pre><p><br/></p><p><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;"></span></p><p><strong>0</strong><strong data-original-title="" title="" data-num="2">4</strong></p><p><strong data-brushtype="text">修复建议</strong></p><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><span style="outline: 0px;line-height: 25.95px;color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;visibility: visible;">在ubuntu系统中可以运行下面的命令进行升级，提高系统安全性。</span></p><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li></ul><pre class="code-snippet__js" data-lang="apache"><code><span class="code-snippet_outer"><span class="code-snippet__comment"># apt-get update</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># apt-get upgrade libc6</span></span></code></pre><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"> </span></p><p><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 1.5px;text-align: center;text-indent: 28px;"><br/></span></p><p style="margin-bottom: 8px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);text-indent: 2em;visibility: visible;"><br/></p><p><br style="outline: 0px;"/></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 15px;"><strong style="outline: 0px;"><span style="outline: 0px;letter-spacing: 2px;">参考链接：</span></strong></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;"></span><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;"></span><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;">[1]https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt<span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 12px;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);"></span></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;">[2]https://paper.seebug.org/3090/</span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;">[3]https://www.uptycs.com/blog/cve-2023-4911-looney-tunables-glibc-exploit</span><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;"></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 12px;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">[4]https://blog.csdn.net/canpool/article/details/121942562</span></span></p><p style="outline: 0px;text-align: left;line-height: 1.5em;"><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;"><span style="color: rgb(136, 136, 136);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 12px;letter-spacing: 0.544px;text-align: left;text-wrap: wrap;background-color: rgb(255, 255, 255);">[5]https://github.com/leesh3288/CVE-2023-4911<br/></span></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;"></span></p><p><span style="outline: 0px;color: rgb(136, 136, 136);font-size: 12px;letter-spacing: 0.544px;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;text-align: center;"><span style="outline: 0px;line-height: 1.8;font-size: 14px;">启明星辰积极防御实验室（ADLab）</span><span style="outline: 0px;line-height: 1.8;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p><br style="outline: 0px;"/></p><p style="outline: 0px;"><span style="outline: 0px;letter-spacing: 1px;font-size: 14px;"><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">ADLab成立于1999年，是中国安全行业最早成立的攻防技术研究实验室之一，微软MAPP计划核心成员，“黑雀攻击”概念首推者。截止目前，ADLab已通过CVE累计发布安全漏洞近1200个，通过 CNVD/CNNVD/NVDB累计发布安全漏洞4000余个，持续保持国际网络安全领域一流水准。实验室研究方向涵盖基础安全研究、<span style="outline: 0px;">5G安全研究、<span style="color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">人工智能安全研究、</span></span></span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">移动与物联网安全研究、</span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">工控安全研究、信创安全研究、</span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">云安全研究、</span><span style="outline: 0px;color: rgb(96, 93, 93);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1px;text-wrap: wrap;background-color: rgb(255, 255, 255);">无线安全研究、高级威胁研究、攻防体系建设。研究成果应用于产品核心技术研究、国家重点科技项目攻关、专业安全服务等</span><span style="outline: 0px;letter-spacing: 1.5px;">。</span></span><span style="outline: 0px;"></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br style="outline: 0px;"/></p><p style="outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><br style="outline: 0px;"/><img class="rich_pages wxw-img" data-imgfileid="502135502" data-ratio="1.1205673758865249" data-s="300,640" style="outline: 0px;background-color: rgb(238, 237, 235);background-position: 50% 50%;background-repeat: no-repeat;background-size: 22px;border-color: rgb(238, 237, 235);border-style: solid;border-width: 1px;display: initial;visibility: visible !important;width: 282px !important;" data-type="jpeg" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=acf4e31d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FXGicR9TOl8nRnsug2VpgvvxBBiam1QbQzzn0ibjIedibQzCZp3TzUgPVZDAicLZyWNVjia3ibCScpE6mKj165jfQib99VQ%2F640%3Fwx_fmt%3Djpeg%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>




]]></content:encoded>
      <pubDate>Tue, 16 Jan 2024 17:07:09 +0800</pubDate>
    </item>
  </channel>
</rss>