<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>网络安全研究宅基地</title>
    <link>https://wechat2rss.xlab.app/feed/a54132c52ec3e562fc896bf803a7fe0aa277bab7.xml</link>
    <description>安恒研究院的一群技术宅&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (网络安全研究宅基地)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/0T8yO33zeegIYLSdibPPqZzGjbE8Pgov5p3PWSvNp3pUcbLuNeMXFDZAjXOLSFrMkmzXvBG3uWMc/0</url>
      <title>网络安全研究宅基地</title>
      <link>https://wechat2rss.xlab.app/feed/a54132c52ec3e562fc896bf803a7fe0aa277bab7.xml</link>
    </image>
    <item>
      <title>恒脑·2025年度纪行：一场奔赴“AI定义安全”的壮阔旅程</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247497384&amp;idx=1&amp;sn=968f5398c67ad27287e50df8e36269cb</link>
      <description>驶过6站，抵达1个新时代</description>
      <content:encoded><![CDATA[<p><span>恒脑</span> <span>2026-02-05 16:32</span> <span style="display: inline-block;">浙江</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8c8993b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FhjMxAcnJicXcuhmRd2BwO8fJmy32op6x3liaxaxnZYyCaicDE3nqS4o7lYdjhnvJnTenhMe17XgTtjlR0cX1j4ibVp1BW20ng4th6licmX34FESE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>驶过6站，抵达1个新时代</p>
  <p style="line-height: 1em;" data-pm-slice="0 0 []" nodeleaf=""><img alt="图片" class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.2777777777777778" style="height: auto !important;visibility: visible !important;width: 676.992px !important;" data-type="other" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0c38f2f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fmc7Mmwou4T80KsMmxBtGSfhFMqDlick5aBXnmREbkZ2osGbIJze4yq4iaUTJx9WIh75sW1lQEvuhCibfPJkLf5GZw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26wxfrom%3D13%26wx_lazy%3D1%26tp%3Dwxpic%23imgIndex%3D0"/></p><div style="width: 100%;" data-mid="" data-mpa-action-id="mkp4haaj1rn2" data-pm-slice="0 0 []"><div data-mid="" style="width: 100%;background: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=32b3dc67&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FVicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA%2F640%3Fwxfrom%3D14%26tp%3Dwxpic%23imgIndex%3D3&#34;) 0% 0% / 375px 250px repeat rgb(208, 4, 24);" data-lazy-bgimg="https://mmbiz.qpic.cn/mmbiz_gif/VicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA/640" data-src="https://mmbiz.qpic.cn/mmbiz_gif/VicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA/640#imgIndex=3" data-sec-load-status="2"><div style="width: 100%;text-align: center;" data-mid=""><div style="width: 100%;" data-mid="" data-mpa-action-id="mkp4haaj1rn2" data-pm-slice="0 0 []"><div data-mid="" style="width: 100%;background: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=675e6698&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FVicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA%2F640%3Fwxfrom%3D14%26tp%3Dwxpic%23imgIndex%3D4&#34;) 0% 0% / 375px 250px repeat rgb(208, 4, 24);" data-lazy-bgimg="https://mmbiz.qpic.cn/mmbiz_gif/VicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA/640" data-src="https://mmbiz.qpic.cn/mmbiz_gif/VicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA/640#imgIndex=4" data-sec-load-status="2"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;width: 100%;padding: 0px 13px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;background: #FFE8B6;border-radius: 4px;padding: 11px;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><div style="width: 100%;margin-top: 12px;" data-mid="" data-mpa-action-id="ml7nho04223f" data-pm-slice="0 0 []"><p style="text-align: left;line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="" mpa-font-style="ml7nhnzhb2w" style="font-size: 15px;">尊敬的各位伙伴：</span></font></span></p><p style="text-align: left;line-height: 1em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="text-align: left;line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7nhnzhah9" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">2025年，</span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">恒脑安全智能体</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">如同一列高速行进的创新列车，穿越技术山脉，驶过市场平原，在</span></font><font face="微软雅黑"><span leaf="">AI浪潮翻涌的壮阔时代里，完成了一次意义非凡的“年度之旅”。我们以<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">“</span></span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">让安全更智能</span></span></font></span></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="" mpa-font-style="ml7nhnzh141x" style="font-size: 15px;"><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">”</span>为永恒的罗盘，在每个关键站点刻下里程碑。现在，诚邀您一同回顾这段充满突破与承载的精彩行程。</span></font></span></p><p style="text-align: left;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="2" alt="图片" class="rich_pages wxw-img" data-ratio="0.562037037037037" data-s="300,640" data-type="png" data-w="1080" style="height: auto !important;visibility: visible !important;width: 629.023px !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/QsTClNuIiapGCKfibACsTwME0xvuJlvSF8ibtbhlMDz3Ap8LXib1KFpD00VB6OQjQuicibmwPbRsq96X9Hr3e0mpqSZomhpLqtctqWoj5awQeX7kQ/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="530" data-cropsely2="298" data-imgfileid="503162164" src="https://wechat2rss.xlab.app/img-proxy/?k=0b644c45&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FQsTClNuIiapGCKfibACsTwME0xvuJlvSF8ibtbhlMDz3Ap8LXib1KFpD00VB6OQjQuicibmwPbRsq96X9Hr3e0mpqSZomhpLqtctqWoj5awQeX7kQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26wxfrom%3D13%26tp%3Dwxpic%23imgIndex%3D1"/></p></div></div></div></div></div></div></div></div><div data-mpa-category="模板" style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 12px;" data-mid="" data-mpa-template="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-start;margin-left: -25px;margin-bottom: -33.7px;z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=056ca100&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2ibtxZl39Z6bPcH9hSs7tkaBSbibsdVYicOzpVl2A48VBWjzvIUBjZRCEYACPBQbtP4aupYRyKM1TcBO9RMlACykQ%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D2"/></p><div style="text-align: center;background: #FF6B1A;border: 1px solid #FFE6C7;border-left: 0px;border-right: 0px;padding: 0px 2px;" data-mid=""><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFE8B6;line-height: 31.5px;" data-mid=""><span leaf="">始发站-趋势瞭望台｜关键词：乘势</span></p></div><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-end;margin-right: -24.6px;margin-top: -33.7px;transform: rotateY(180deg);z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=6450c89e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FWS7wz8sKD6JAAduGpe1iabd3aWutjUiaR1eticGeJWeB2qDQuDYJY08Z6xFfNJRficahVdHicPzPvDz7c5aAkXvNufw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D3"/></p></div><div style="display: flex;justify-content: center;align-items: center;width: 100%;justify-content: space-between;" data-mid=""><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-left: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=0c791961&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fj7EHyxjQLM0wxfHxBmMBej0MKfW3PriaFGWoBLxQfAbT7uervUXQStCPt7YU0WicuhiaLmrpsbmcoaaQTuCHRfKQg%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D4"/></p><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-right: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=4aac029e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fia7Qpzsib2yQrw6fEKxYBqcZFGM3eFySWABXhyCQ6PKdmibSoYa8ktHqk0NTMibpibr4ZGTf7IMOiaoAZGadDTsBOdFQ%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D5"/></p></div></div></div><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;width: 100%;padding: 0px 13px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><p style="width: 90px;height: 29px;display: flex;justify-content: center;align-self: flex-end;margin-right: -16px;margin-bottom: -12px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.32222222222222224" data-type="png" data-w="180" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 90px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=cfa7feac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOZB22jwBib1UPOic3RiauONJseduddbiaAiacxCZTbZ8JOB2qrOyIHzm6ibw6SAvODoVwePvjV1bvJLbZL9SHINLia3xA%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D6"/></p><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;background: #FFE8B6;border-radius: 4px;padding: 11px;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><div style="width: 100%;margin-top: 12px;" data-mid=""><p data-mpa-action-id="ml7nmy9m1a74" data-pm-slice="0 0 []" style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="" mpa-font-style="ml7nmy95g12" style="font-size: 15px;">旅程始于对时代的深刻洞察。</span></font></span><span mpa-font-style="ml7nmy95brv" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"></font></span></span></p><p data-mpa-action-id="ml7nmy9m1a74" data-pm-slice="0 0 []" style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7nmy95brv" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">从国务院</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">人工智能</span></font><font face="微软雅黑"><span leaf="">+行动意见</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">，</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">到中共中央十五五规划建议，再到近期</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">央视发布</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">的</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">人工智能十大趋势。</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">其中，<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">“</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">应用主流化：AI智能体全面走进场景”与“安全与对抗白热化：安全与治理将成为AI发展的重要保障”</span>，精准描绘了我们正奔赴的远方。</span></font></span></span></p><p data-mpa-action-id="ml7nmy9m1a74" data-pm-slice="0 0 []" style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7nmy95brv" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"></font></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-s="300,640" data-type="png" data-w="1080" style="height: auto !important;visibility: visible !important;width: 629.023px !important;" type="block" data-imgfileid="503162116" src="https://wechat2rss.xlab.app/img-proxy/?k=8b6dc535&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FQsTClNuIiapHmeHwytjwvdbzicJELpib3rnf4vhlFuKmqyGk4ZKONuerKCsIvv8jcfquZ3rtibT780PC47ndNwSnQ9jro0QnZlgh4KxfW5c2nz4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D7"/></p><p data-mpa-action-id="ml7nmy9m1a74" data-pm-slice="0 0 []" style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7nmy95brv" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"></font></span></span></p><p data-mpa-action-id="ml7nmy9m1a74" data-pm-slice="0 0 []" style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7nmy95brv" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">恒脑以此为契机，顺势而上，锚定</span></font><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">“</span></span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">定义中国安全智能体应用标杆</span></span></font></span></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="" mpa-font-style="ml7nmy95t5y" style="font-size: 15px;"><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">”</span>的年度主题，鸣笛启程。</span></font></span></p></div></div></div></div></div><div data-mpa-category="模板" style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 12px;" data-mid="" data-mpa-template="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-start;margin-left: -25px;margin-bottom: -33.7px;z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=fac423d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FR0a5g0KVSLDuUK8vtjQ09uLmhRHCV5jbzlx6PBruacgpZKxVeKM957H3KqPyLaGXCic4g989dF5G6NSeNfYoqgA%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D8"/></p><div style="text-align: center;background: #FF6B1A;border: 1px solid #FFE6C7;border-left: 0px;border-right: 0px;padding: 0px 2px;" data-mid=""><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFE8B6;line-height: 31.5px;" data-mid="" data-mpa-action-id="mkp51rz8wah" data-pm-slice="0 0 []"><span leaf="">第一站-技术进化 | 关键词：升维</span></p></div><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-end;margin-right: -24.6px;margin-top: -33.7px;transform: rotateY(180deg);z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=98b0158c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FA2R99ck4ALvG0ib4DT8X6pdXb1OCRlic6UMNbBRBFFcbol02hYXygpjq6UBlEibu2MnZicicpUof5kFmib8HCJTv1y0g%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D9"/></p></div><div style="display: flex;justify-content: center;align-items: center;width: 100%;justify-content: space-between;" data-mid=""><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-left: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=3adc7c9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8rcmFtOQdBF5pyxT4e13Nk3DwjvywrHD5RRvia6raut6Vgw1El6RcUdWKRwj22T6gxve7ZeibSEMf8unX9z6AayA%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D10"/></p><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-right: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=46117f83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F3Pncqzn0sXg98YXlkFWUfHgPOkial0A7MWjOicLcEJlBngGXbTESjocsrNYNo1GYbzWuKjfPkODu7g8VtwOwb3Iw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D11"/></p></div></div></div><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;width: 100%;padding: 0px 13px;" data-mid="" data-mpa-template="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><p style="width: 90px;height: 29px;display: flex;justify-content: center;align-self: flex-end;margin-right: -16px;margin-bottom: -12px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.32222222222222224" data-type="png" data-w="180" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 90px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=da51df73&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOZB22jwBib1UPOic3RiauONJseduddbiaAiacxCZTbZ8JOB2qrOyIHzm6ibw6SAvODoVwePvjV1bvJLbZL9SHINLia3xA%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D12"/></p><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;background: #FFE8B6;border-radius: 4px;padding: 11px;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><div style="width: 100%;margin-top: 12px;" data-mid=""><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">这是恒脑能力蜕变的基石。我们完成了从</span></font><font face="微软雅黑"><span leaf="">“工具”到“平台”，最终迈向“AI定义安全”时代的核心跃迁。</span></font></span></p><p style="line-height: 1em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">1.0站台 (2023)： 安全垂域大模型基座，以“小恒智聊”开创安全智能问答新交互，奠定AI+安全认知基础。</span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="2" alt="图片" class="rich_pages wxw-img" data-ratio="0.562037037037037" data-s="300,640" data-type="png" data-w="1080" style="height: auto !important;visibility: visible !important;width: 629.023px !important;" type="block" data-imgfileid="503162085" src="https://wechat2rss.xlab.app/img-proxy/?k=f8e901dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zXA7cOZ7jKsib8Fpbh8FOoic1ZXjBLfK1aibUsgvQUX1qKns03duCzhvP6ZMooOvuroXE7fA0ibUMrWA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D13"/></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">2.0站台 (2024)：推出业界首个聚焦安全领域的智能体——数据分类分级智能体，并以此为起点，基于其构建实践，抽象形成安全智能体开发平台。依托零代码/低代码创建能力，首次打通“AI模型”到“可落地、可复用、可运营的安全工程平台”全链路。 </span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="2" alt="图片" class="rich_pages wxw-img" data-ratio="0.562037037037037" data-s="300,640" data-type="png" data-w="1080" style="height: auto !important;visibility: visible !important;width: 629.023px !important;" type="block" data-imgfileid="503162182" src="https://wechat2rss.xlab.app/img-proxy/?k=c237203a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FQsTClNuIiapFB3zp6bibvFPPuicQOfyQAmSzia1L8ROYC3CNPvlycYuUVhLcDericFHAPiblDXLMeicoT3VmYDnGyib8T5sNMXDFYjhsXR4PNzjkrwI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D14"/></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;" data-mpa-action-id="ml7om2mx1gon" data-pm-slice="0 0 []"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">3.0里程碑 (2025)： 抵达 “多智能体自主协同” 新大陆，实现从“人类主导、AI辅助”到 </span><span style="color: rgb(217, 33, 66);font-weight: bold;font-size: 15px;" mpa-font-style="ml7om2ht1ewf"><span leaf="">“</span></span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;font-size: 15px;" mpa-font-style="ml7om2htkth"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">AI主导、人类监督</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span mpa-font-style="ml7om2ht1t03" style="font-size: 15px;"><span style="color: rgb(217, 33, 66);font-weight: bold;"><span leaf="">”</span></span><span leaf=""> 的</span></span><span leaf="">战略升维，具备完整的“感知-决策-执行”闭环能力。这是本次旅程中<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">最具颠覆性</span>的技术奇观。</span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="2" alt="图片" class="rich_pages wxw-img" data-ratio="0.562037037037037" data-s="300,640" data-type="png" data-w="1080" style="height: auto !important;visibility: visible !important;width: 629.023px !important;" type="block" data-imgfileid="503162086" src="https://wechat2rss.xlab.app/img-proxy/?k=c3b93707&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FQsTClNuIiapEBxh89WySnicNFY2HFFibRxEHibBTY9Sk6GPd3vqibMjjwRic1eLEtNFkea5IibrjbVmyygv9A0Zqo6P77rLRnSaxAA0ANNIYibm176I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D15"/></p></div></div></div></div></div><div data-mpa-category="模板" style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 12px;" data-mid="" data-mpa-template="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-start;margin-left: -25px;margin-bottom: -33.7px;z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e19ca693&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FaI5wpyhlK1Gpef7MOWT4miaAOLlCPabYkJNpIqnnkFdMMmFe3ALKS5tGYY5ffw4MMSUbkVibgNUTCKOEibccLUNtw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D16"/></p><div style="text-align: center;background: #FF6B1A;border: 1px solid #FFE6C7;border-left: 0px;border-right: 0px;padding: 0px 2px;" data-mid=""><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFE8B6;line-height: 31.5px;" data-mid=""><span leaf="" mpa-font-style="mkp43ecv5o5" style="font-size: 15px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify; line-height: 2em; margin-left: 16px; margin-right: 16px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">第二站-权威认证｜关键词：领航</span></p></div><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-end;margin-right: -24.6px;margin-top: -33.7px;transform: rotateY(180deg);z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9195d0c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FB6MWZF3sicLmj1H4SKNgxS9vWbcNEibmpBS9ojwIXGnmXSNicsKERVe0TnRL7niaGOtiavTepzI6WYETfdSNsPNyHCw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D17"/></p></div><div style="display: flex;justify-content: center;align-items: center;width: 100%;justify-content: space-between;" data-mid=""><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-left: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=cdde5831&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fwb9rOxMU4pLHABlZBGdAhayVjrxNpBW730QRy48XRzpMLODylEQ7BDrCze7dpxL0Z2nLTrfl6Rn9nQdkNFEyxg%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D18"/></p><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-right: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=eee37e9b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fjuvv8FtMXDwtntA2RrncmSfy71FNNBneOIs6pYZspRReY9ztDDiavzibCCQibHOSicac6iaWL0ibutc1nXBKT3xjAydQ%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D19"/></p></div></div></div><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;width: 100%;padding: 0px 13px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []" data-mpa-action-id="mkp5hov2crm"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><p style="width: 90px;height: 29px;display: flex;justify-content: center;align-self: flex-end;margin-right: -16px;margin-bottom: -12px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.32222222222222224" data-type="png" data-w="180" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 90px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=bd19ae4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOZB22jwBib1UPOic3RiauONJseduddbiaAiacxCZTbZ8JOB2qrOyIHzm6ibw6SAvODoVwePvjV1bvJLbZL9SHINLia3xA%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D20"/></p><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;background: #FFE8B6;border-radius: 4px;padding: 11px;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><div style="width: 100%;margin-top: 12px;" data-mid="" data-mpa-action-id="ml7ossb81hw0" data-pm-slice="0 0 []"><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="" mpa-font-style="ml7ossaf205l" style="font-size: 15px;">在行业标高的衡量下，恒脑稳居潮头，收获了满满的认可</span></font><font face="微软雅黑"><span leaf="" mpa-font-style="ml7ossaf1u44" style="font-size: 15px;">“勋章”。</span></font></span></p><p style="line-height: 1em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7ossaf1jmc" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">IDC领导者象限</span>：在</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">中国</span></font><font face="微软雅黑"><span leaf="">AI赋能</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">数据发现与分类分级、大模型智能托管安全服务能力两项评估中，</span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">均位列市场第一</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">。</span></font></span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7ossaf243p" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">全景覆盖认可</span>：入围《中国安全智能体市场概览》报告<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">全部</span></span></font><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">7个应用场景</span>，彰显</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">安全场景覆盖</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">全</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">面</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">实力。</span></font></span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7ossafbmz" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">全球首位</span></span></font><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">AI选手“参赛”</span>：作为</span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">全球首位</span></span></font><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">AI选手</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">出征</span></font><font face="微软雅黑"><span leaf="">“天府杯”国际</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">网络安全</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">大赛，并夺得漏洞防护赛第三名，</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">一只安全领域的</span></font><font face="微软雅黑"><span leaf="">“</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">阿尔法狗</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">”</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">横空出世</span></font></span></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="" mpa-font-style="ml7ossafzhp" style="font-size: 15px;">。</span></font></span></p></li></ul></div></div></div></div></div><div data-mpa-category="模板" style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 12px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-start;margin-left: -25px;margin-bottom: -33.7px;z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=b204d91a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FaI5wpyhlK1Gpef7MOWT4miaAOLlCPabYkJNpIqnnkFdMMmFe3ALKS5tGYY5ffw4MMSUbkVibgNUTCKOEibccLUNtw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D21"/></p><div style="text-align: center;background: #FF6B1A;border: 1px solid #FFE6C7;border-left: 0px;border-right: 0px;padding: 0px 2px;" data-mid=""><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFE8B6;line-height: 31.5px;" data-mid=""><span leaf="" mpa-font-style="mkp43ecv1v4c" style="font-size: 15px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-action-id&#34;:&#34;mkp4haaj1rn2&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; background: url(https://mmbiz.qpic.cn/mmbiz_gif/VicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA/0) repeat #D00418; background-size: 375px 250px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%; padding: 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;ProseMirror-selectednode&#34;,&#34;data-mpa-action-id&#34;:&#34;mkp5hov2crm&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%; background: #FFE8B6; border-radius: 4px; padding: 11px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; margin-top: 12px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify; line-height: 2em; margin-left: 16px; margin-right: 16px;&#34;,&#34;data-pm-slice&#34;:&#34;2 2 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">第三站-市场征战｜关键词：扎根</span></p></div><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-end;margin-right: -24.6px;margin-top: -33.7px;transform: rotateY(180deg);z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2961b2d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FB6MWZF3sicLmj1H4SKNgxS9vWbcNEibmpBS9ojwIXGnmXSNicsKERVe0TnRL7niaGOtiavTepzI6WYETfdSNsPNyHCw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D22"/></p></div><div style="display: flex;justify-content: center;align-items: center;width: 100%;justify-content: space-between;" data-mid=""><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-left: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=0f4f5792&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fwb9rOxMU4pLHABlZBGdAhayVjrxNpBW730QRy48XRzpMLODylEQ7BDrCze7dpxL0Z2nLTrfl6Rn9nQdkNFEyxg%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D23"/></p><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-right: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d1f98918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fjuvv8FtMXDwtntA2RrncmSfy71FNNBneOIs6pYZspRReY9ztDDiavzibCCQibHOSicac6iaWL0ibutc1nXBKT3xjAydQ%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D24"/></p></div></div></div><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;width: 100%;padding: 0px 13px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []" data-mpa-action-id="mkp5hov2crm"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><p style="width: 90px;height: 29px;display: flex;justify-content: center;align-self: flex-end;margin-right: -16px;margin-bottom: -12px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.32222222222222224" data-type="png" data-w="180" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 90px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2141d473&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOZB22jwBib1UPOic3RiauONJseduddbiaAiacxCZTbZ8JOB2qrOyIHzm6ibw6SAvODoVwePvjV1bvJLbZL9SHINLia3xA%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D25"/></p><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;background: #FFE8B6;border-radius: 4px;padding: 11px;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><div style="width: 100%;margin-top: 12px;" data-mid="" data-mpa-action-id="ml7p15u619i2" data-pm-slice="0 0 []"><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="" mpa-font-style="ml7p15su1h7c" style="font-size: 15px;">回顾</span></font><font face="微软雅黑"><span leaf="" mpa-font-style="ml7p15sv214z" style="font-size: 15px;">25年，</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 15px;" mpa-font-style="ml7p15sv160z"><font face="微软雅黑"><span leaf="">恒脑的足迹已深深扎根于中国数字经济的广袤土壤，遍地开花。</span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 15px;" mpa-font-style="ml7p15sv160z"><font face="微软雅黑"></font></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7p15sve4i" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">行业深耕</span>：覆盖政府、金融、运营商等</span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">14大关键行业</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">，形成核心支柱。</span></font></span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7p15svuws" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">全域覆盖</span>：业务遍及</span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">全国</span></span></font><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">31个省市</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">，多个省份实现</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">跨越式</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">增长。</span></font></span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7p15svsqm" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">价值绽放</span>：</span><span leaf="">从数据分类分级、告警研判等“杀手级”智能体的口碑破局，到威胁建模、恶意邮件、代码审计、API安全等垂直场景的密集占位，<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">订阅增长引擎</span>全速启动，<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">商业价值实现硬核闭环</span>。</span></font></span></span></p></li></ul></div></div></div></div></div><div data-mpa-category="模板" style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 12px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []" data-mpa-action-id="mkp5mpuo1k8q"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-start;margin-left: -25px;margin-bottom: -33.7px;z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=8ec522b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FaI5wpyhlK1Gpef7MOWT4miaAOLlCPabYkJNpIqnnkFdMMmFe3ALKS5tGYY5ffw4MMSUbkVibgNUTCKOEibccLUNtw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D26"/></p><div style="text-align: center;background: #FF6B1A;border: 1px solid #FFE6C7;border-left: 0px;border-right: 0px;padding: 0px 2px;" data-mid=""><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFE8B6;line-height: 31.5px;" data-mid=""><span leaf="" mpa-font-style="mkp43ecv1qpj" style="font-size: 15px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-action-id&#34;:&#34;mkp4haaj1rn2&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; background: url(https://mmbiz.qpic.cn/mmbiz_gif/VicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA/0) repeat #D00418; background-size: 375px 250px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%; padding: 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;ProseMirror-selectednode&#34;,&#34;data-mpa-action-id&#34;:&#34;mkp5hov2crm&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%; background: #FFE8B6; border-radius: 4px; padding: 11px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; margin-top: 12px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify; line-height: 2em; margin-left: 16px; margin-right: 16px;&#34;,&#34;data-pm-slice&#34;:&#34;2 2 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">第四站-价值兑现｜关键词：实战 </span></p></div><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-end;margin-right: -24.6px;margin-top: -33.7px;transform: rotateY(180deg);z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=879dcc29&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FB6MWZF3sicLmj1H4SKNgxS9vWbcNEibmpBS9ojwIXGnmXSNicsKERVe0TnRL7niaGOtiavTepzI6WYETfdSNsPNyHCw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D27"/></p></div><div style="display: flex;justify-content: center;align-items: center;width: 100%;justify-content: space-between;" data-mid=""><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-left: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=1a5c1528&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fwb9rOxMU4pLHABlZBGdAhayVjrxNpBW730QRy48XRzpMLODylEQ7BDrCze7dpxL0Z2nLTrfl6Rn9nQdkNFEyxg%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D28"/></p><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-right: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=dd37579d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fjuvv8FtMXDwtntA2RrncmSfy71FNNBneOIs6pYZspRReY9ztDDiavzibCCQibHOSicac6iaWL0ibutc1nXBKT3xjAydQ%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D29"/></p></div></div></div><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;width: 100%;padding: 0px 13px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []" data-mpa-action-id="ml7p9ei41huq"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><p style="width: 90px;height: 29px;display: flex;justify-content: center;align-self: flex-end;margin-right: -16px;margin-bottom: -12px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.32222222222222224" data-type="png" data-w="180" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 90px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=3bd8b69e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOZB22jwBib1UPOic3RiauONJseduddbiaAiacxCZTbZ8JOB2qrOyIHzm6ibw6SAvODoVwePvjV1bvJLbZL9SHINLia3xA%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D30"/></p><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;background: #FFE8B6;border-radius: 4px;padding: 11px;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><div style="width: 100%;margin-top: 12px;" data-mid="" data-mpa-action-id="ml6d0if61mny" data-pm-slice="0 0 []"><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">这里是我们旅程意义的集中体现，每一个客户成功，都是一座闪亮的</span></font><font face="微软雅黑"><span leaf="">“价值灯塔”。</span></font></span></p><p style="line-height: 1em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">亚冬会：</span></font><font face="微软雅黑"><span leaf="">2025年哈尔滨亚冬会，恒脑安全智能体<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">“以AI对抗AI”</span>，</span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">从容应对</span></font></span><span leaf="">境外挑战，取得全胜战绩，成为<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">全球重大活动AI安保首个可复制样板</span>，获央视专题报道。执委会信息技术部对安恒信息率先将</span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;font-size: 14pt;"><font face="微软雅黑"><span leaf="" mpa-font-style="ml7p6lijafe" style="font-size: 15px;" data-mpa-action-id="ml7p6ljh202w" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">安全智能体能力深度融入赛事网络安全保障工作</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">进行了高度肯定，并给予感谢信。</span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;text-align: center;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf=""><img alt="图片" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503161547" data-ratio="1.3333333333333333" data-s="300,640" type="block" data-type="png" data-w="1080" style="width: 465.69px !important;flex-basis: auto;background-color: transparent;height: auto !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=4bffa36d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zzWCaicK1LPbSTJDDcicxleNan0MOib8fMZJZicGSiauZgNUdSBe0OhsJufmfLNanhMPia4YNtJA4Eb3eQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D31"/></span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="font-weight: bold;">行业灯塔矩阵：</span></span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">北汽福田</span>：</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">AI调度安全能力，</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">构建跨维度协同联防的数据安全整体防护体系。</span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">中国数谷</span>：赋能数据要素安全流通，</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">实现</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">数据</span></font><font face="微软雅黑"><span leaf="">“供得出”、“流得动”、“用的好”。</span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">海亮集团</span>：以</span></font><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">“开箱即用”智能体</span>加速集团数智化转型。</span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">渤海证券</span>：破解金融安全运营三大难题，构建</span></font><font face="微软雅黑"><span leaf="">“智能研判-自动处置-专业辅助”的闭环体系</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">，</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="">树立智能闭环新标杆。</span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">福建师范大学</span>：打造高校网络安全</span></font><font face="微软雅黑"><span leaf="">AI应用省级典型应用场景。</span></font></span></p></div></div></div><div style="display: flex;justify-content: center;align-items: center;width: 100%;justify-content: space-between;" data-mid=""><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-left: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=a546d8f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fwb9rOxMU4pLHABlZBGdAhayVjrxNpBW730QRy48XRzpMLODylEQ7BDrCze7dpxL0Z2nLTrfl6Rn9nQdkNFEyxg%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D32"/></p><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-right: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2e1844e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fjuvv8FtMXDwtntA2RrncmSfy71FNNBneOIs6pYZspRReY9ztDDiavzibCCQibHOSicac6iaWL0ibutc1nXBKT3xjAydQ%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D33"/></p></div></div></div><div data-mpa-category="模板" style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 12px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []" data-mpa-action-id="mkp5mpuo1k8q"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-start;margin-left: -25px;margin-bottom: -33.7px;z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=b604c690&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FaI5wpyhlK1Gpef7MOWT4miaAOLlCPabYkJNpIqnnkFdMMmFe3ALKS5tGYY5ffw4MMSUbkVibgNUTCKOEibccLUNtw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D34"/></p><div style="text-align: center;background: #FF6B1A;border: 1px solid #FFE6C7;border-left: 0px;border-right: 0px;padding: 0px 2px;" data-mid=""><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFE8B6;line-height: 31.5px;" data-mid=""><span leaf="" mpa-font-style="mkp43ecv1qpj" style="font-size: 15px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-action-id&#34;:&#34;mkp4haaj1rn2&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; background: url(https://mmbiz.qpic.cn/mmbiz_gif/VicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA/0) repeat #D00418; background-size: 375px 250px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%; padding: 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;ProseMirror-selectednode&#34;,&#34;data-mpa-action-id&#34;:&#34;mkp5hov2crm&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%; background: #FFE8B6; border-radius: 4px; padding: 11px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; margin-top: 12px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify; line-height: 2em; margin-left: 16px; margin-right: 16px;&#34;,&#34;data-pm-slice&#34;:&#34;2 2 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">第五站-生态与荣誉｜关键词：合作 </span></p></div><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-end;margin-right: -24.6px;margin-top: -33.7px;transform: rotateY(180deg);z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=f4d1a4f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FB6MWZF3sicLmj1H4SKNgxS9vWbcNEibmpBS9ojwIXGnmXSNicsKERVe0TnRL7niaGOtiavTepzI6WYETfdSNsPNyHCw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D35"/></p></div><div style="display: flex;justify-content: center;align-items: center;width: 100%;justify-content: space-between;" data-mid=""><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-left: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=0d45bc8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fwb9rOxMU4pLHABlZBGdAhayVjrxNpBW730QRy48XRzpMLODylEQ7BDrCze7dpxL0Z2nLTrfl6Rn9nQdkNFEyxg%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D36"/></p><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-right: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=adcafc66&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fjuvv8FtMXDwtntA2RrncmSfy71FNNBneOIs6pYZspRReY9ztDDiavzibCCQibHOSicac6iaWL0ibutc1nXBKT3xjAydQ%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D37"/></p></div></div></div><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;width: 100%;padding: 0px 13px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []" data-mpa-action-id="ml7plomj1cct"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><p style="width: 90px;height: 29px;display: flex;justify-content: center;align-self: flex-end;margin-right: -16px;margin-bottom: -12px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.32222222222222224" data-type="png" data-w="180" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 90px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=55f7928a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOZB22jwBib1UPOic3RiauONJseduddbiaAiacxCZTbZ8JOB2qrOyIHzm6ibw6SAvODoVwePvjV1bvJLbZL9SHINLia3xA%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D38"/></p><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;background: #FFE8B6;border-radius: 4px;padding: 11px;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><div style="width: 100%;margin-top: 12px;" data-mid="" data-mpa-action-id="ml7pj12h1oza" data-pm-slice="0 0 []"><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span leaf="" mpa-font-style="ml7pj11w1wtd" style="font-size: 15px;">这一路旅程，我们满载荣誉。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="2" alt="图片" class="rich_pages wxw-img" data-ratio="0.562037037037037" data-s="300,640" data-type="png" data-w="1080" style="height: auto !important;visibility: visible !important;width: 629.023px !important;" type="block" data-imgfileid="503162099" src="https://wechat2rss.xlab.app/img-proxy/?k=097480fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FQsTClNuIiapE8ItrFrqcZOLj4yCpOCgbxuXZLwXDsRibDCQeH0PVJMDnqicXrUR5Qx3JOibC8FkmNGCDmkLhWvBxrm81rgXmlw5VXz5gciaZVZhI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D39"/></p><div data-mpa-dynamic-material="t" data-mpa-dynamic-enable-color-list="t" data-mpa-dynamic-zoom="0.85" data-mpa-template="t" data-mpa-dynamic-material-category="middleCenteredSpacedSlide" data-mpa-category="动态" mpa-from-tpl="t" style="" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="svg" data-mpa-action-id="ml7ro70zi42"><div style="width:100%;" data-mpa-main="" data-mpa-ratio="origin" data-mpa-button-text="←左右滑动查看更多→
Slide for more photos" data-mpa-adsorb="true" mpa-from-tpl="t"><div style="padding: 12px;text-align: center;max-height: 78px;overflow-x: hidden;overflow-y: auto;isolation: isolate;scroll-behavior: smooth;scrollbar-width: thin;-webkit-scrollbar-width: thin;line-height: 0;pointer-events: visible;box-sizing: border-box;font-size: 12px;font-family: PingFangSC-Regular, PingFang SC;color: #999;line-height: 18px;" mpa-from-tpl="t"><p><span leaf="">←左右滑动查看更多→</span><span leaf=""><br/></span><span leaf="">Slide for more photos</span></p></div></div></div><p style="text-align: justify;line-height: 2em;margin-left: 16px;margin-right: 16px;"><span leaf="" mpa-font-style="mkp43ecw9md" style="font-size: 15px;">在国产算力生态合作方面，我们取得显著成果，在前期完成<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">华为昇腾</span>认证的基础上，新获得<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">海光DCU、</span></span><span leaf="" mpa-font-style="mkp43ecw9md" style="font-size: 15px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-action-id&#34;:&#34;mkp4haaj1rn2&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mid&#34;:&#34;&#34;,&#34;style&#34;:&#34;width: 100%;background: url(\&#34;https://mmbiz.qpic.cn/mmbiz_gif/VicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA/640\&#34;) repeat #D00418;background-size: 375px 250px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding: 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;data-mpa-action-id&#34;:&#34;mkp5hov2crm&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;background: #FFE8B6;border-radius: 4px;padding: 11px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;margin-top: 12px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify;line-height: 2em;margin-left: 16px;margin-right: 16px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">CPU兼容性认证</span>，恒脑安全智能体一体机入选<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">首届光合组织年度十大成果</span>。</span></p><p style="text-align: justify;line-height: 2em;margin-left: 16px;margin-right: 16px;"><span leaf="" mpa-font-style="mkp43ecw24s9" style="font-size: 15px;">1.昇腾技术认证书</span></p><p style="text-align: justify;line-height: 2em;margin-left: 16px;margin-right: 16px;"><span leaf="" mpa-font-style="mkp43ecw1lqq" style="font-size: 15px;">2.海光DCU/CPU生态兼容性认证</span></p><p style="text-align: justify;line-height: 2em;margin-left: 16px;margin-right: 16px;"><span leaf="" mpa-font-style="mkp43ecw19cm" style="font-size: 15px;">3.恒脑入选首届光合组织人工智能创新大会年度十大成果。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="png" data-w="1080" style="height: auto !important;visibility: visible !important;width: 629.023px !important;" type="block" data-imgfileid="503161837" src="https://wechat2rss.xlab.app/img-proxy/?k=d1ed59af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zGqcR6NFInMWYAMllLhz5QF9QOn86oUXLztUt77CA5NfiaNtSxxS1FWliayj2jj01nsCUnIk8ibfB7Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D40"/></p></div></div></div></div></div><div data-mpa-category="模板" style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 12px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []" data-mpa-action-id="mkp6gu47at9"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid=""><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-start;margin-left: -25px;margin-bottom: -33.7px;z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=07c398b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FaI5wpyhlK1Gpef7MOWT4miaAOLlCPabYkJNpIqnnkFdMMmFe3ALKS5tGYY5ffw4MMSUbkVibgNUTCKOEibccLUNtw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D41"/></p><div style="text-align: center;background: #FF6B1A;border: 1px solid #FFE6C7;border-left: 0px;border-right: 0px;padding: 0px 2px;" data-mid=""><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #FFE8B6;line-height: 31.5px;" data-mid=""><span leaf="" mpa-font-style="mkp43ecw7ng" style="font-size: 15px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-action-id&#34;:&#34;mkp4haaj1rn2&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mid&#34;:&#34;&#34;,&#34;style&#34;:&#34;width: 100%;background: url(\&#34;https://mmbiz.qpic.cn/mmbiz_gif/VicRoVFkt2gkGksmQxEQAlTgP3vg5WesMpNxSDISVVc7tMbCzQGUx8kmNvCzic6ElbticBickHfxCOHfBGXUgib3IHA/640\&#34;) repeat #D00418;background-size: 375px 250px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%; padding: 0px 13px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;data-mpa-action-id&#34;:&#34;mkp5hov2crm&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%; background: #FFE8B6; border-radius: 4px; padding: 11px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: flex-start; align-items: center; flex-direction: column; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; margin-top: 12px;&#34;,&#34;data-mid&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify; line-height: 2em; margin-left: 16px; margin-right: 16px;&#34;,&#34;data-pm-slice&#34;:&#34;2 2 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">旅途总结</span></p></div><p style="width: 25px;height: 34px;display: flex;justify-content: center;align-self: flex-end;margin-right: -24.6px;margin-top: -33.7px;transform: rotateY(180deg);z-index: 1;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.36" data-type="png" data-w="50" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 25px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=69485a79&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FB6MWZF3sicLmj1H4SKNgxS9vWbcNEibmpBS9ojwIXGnmXSNicsKERVe0TnRL7niaGOtiavTepzI6WYETfdSNsPNyHCw%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D42"/></p></div><div style="display: flex;justify-content: center;align-items: center;width: 100%;justify-content: space-between;" data-mid=""><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-left: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=105cb802&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fwb9rOxMU4pLHABlZBGdAhayVjrxNpBW730QRy48XRzpMLODylEQ7BDrCze7dpxL0Z2nLTrfl6Rn9nQdkNFEyxg%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D43"/></p><p style="width: 17px;height: 23px;display: flex;justify-content: center;margin-right: -33px;margin-top: -15px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="1.8823529411764706" data-type="png" data-w="34" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 12.2135px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=73797eaa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Fjuvv8FtMXDwtntA2RrncmSfy71FNNBneOIs6pYZspRReY9ztDDiavzibCCQibHOSicac6iaWL0ibutc1nXBKT3xjAydQ%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D44"/></p></div></div></div><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;width: 100%;padding: 0px 13px;" data-mid="" data-mpa-template="t" data-pm-slice="0 0 []" data-mpa-action-id="mkp5hov2crm"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><p style="width: 90px;height: 29px;display: flex;justify-content: center;align-self: flex-end;margin-right: -16px;margin-bottom: -12px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.32222222222222224" data-type="png" data-w="180" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 90px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=1e475e9b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOZB22jwBib1UPOic3RiauONJseduddbiaAiacxCZTbZ8JOB2qrOyIHzm6ibw6SAvODoVwePvjV1bvJLbZL9SHINLia3xA%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D45"/></p><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;background: #FFE8B6;border-radius: 4px;padding: 11px;" data-mid=""><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid=""><div style="width: 100%;margin-top: 12px;" data-mid="" data-mpa-action-id="ml7pnehip2j" data-pm-slice="0 0 []"><p style="text-align: center;" nodeleaf=""><img alt="图片" class="rich_pages wxw-img" data-aistatus="2" data-imgfileid="503162089" data-ratio="0.562037037037037" data-s="300,640" type="block" data-type="png" data-w="1080" style="height: auto !important;visibility: visible !important;width: 629.023px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9b8ebe74&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FQsTClNuIiapEutdAreKbHWp50Mhftrp5L5vCbyVnrXA6et2XCibqHzWiacViam5icaxUeSVBPQqq7vB2kBXOFSrN2GkRgABdZz0KV1F6porO5jicE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D46"/></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="" mpa-font-style="ml7pnegunf8" style="font-size: 15px;">2025年，恒脑的列车穿越<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;"> “技术升维”</span> 的山谷，登顶<span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;"> “行业领航” </span>的高峰，在 <span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">“市场扎根” </span>的原野上播种希望，于 <span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">“价值实战” </span>的城市中点亮灯塔，最终在 “生态</span></font></span><span mpa-font-style="ml7pnegully" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">合作</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">” 的殿堂里收获荣耀。</span></font></span></span></p><p style="line-height: 1em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7pnegully" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"></font></span></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7pneguaqm" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">这不仅仅是一份年度总结，更是一份关于信心、突破与承诺的旅程报告。我们深信，安全的下一个时代，</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">将</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">由智能体定义。而恒脑，</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">将继续践行</span></font><font face="微软雅黑"><span leaf="">“</span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">AI对抗AI，AI管理AI</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">”，向着</span></font></span><span style="font-family: 微软雅黑;color: rgb(0, 0, 255);font-weight: normal;"><font face="微软雅黑"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">安全可信的数字世界</span></span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">载誉前行</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">。</span></font></span></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7pnegu6h1" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">下一站，未来已来。</span></font></span></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7pnegu6h1" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">让我们继续</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">携手</span></font></span><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"><span leaf="">同行，共赴下一段更精彩的征程。</span></font></span></span></p><p style="line-height: 1em;margin-left: 16px;margin-right: 16px;"><span mpa-font-style="ml7pnegu6h1" style="font-size: 15px;"><span style="font-family: 微软雅黑;font-weight: normal;"><font face="微软雅黑"></font></span></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;text-align: right;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 15px;" mpa-font-style="ml7pnegub8m"><font face="微软雅黑"><span leaf="">安恒信息</span></font><font face="微软雅黑"><span leaf="">·恒脑团队 </span></font></span></p><p style="line-height: 2em;margin-left: 16px;margin-right: 16px;text-align: right;"><span style="font-family: 微软雅黑;font-weight: normal;font-size: 11pt;"><font face="微软雅黑"><span leaf="" mpa-font-style="ml7pnegux97" style="font-size: 15px;">乙巳年岁末</span></font></span></p></div></div></div></div></div><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" data-mpa-template="t"><p style="display: flex;justify-content: center;align-items: center;width: 69px;height: 16px;" data-mid="" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img" data-ratio="0.2318840579710145" data-type="png" data-w="138" style="display: block;background-color: transparent;height: auto !important;visibility: visible !important;width: 68.9974px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=47c19bdc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FialBxqqGR0ibLRmFvjdsFEqb5eQh9Apj5pZqAu54I0CNs8MMzibWp6TpIwicicGevb7uVL1AvXU4ibRAAa3mKHNJIYcg%2F640%3Fwx_fmt%3Dpng%26tp%3Dwxpic%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D47"/></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1173dbbd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247497384%26idx%3D1%26sn%3D968f5398c67ad27287e50df8e36269cb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 05 Feb 2026 16:32:00 +0800</pubDate>
    </item>
    <item>
      <title>“熟人”发来的退税链接？小心“银狐”盗刷陷阱</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247497330&amp;idx=1&amp;sn=7780f0f95ebdc4e3caf0ba66709eebcd</link>
      <description>“熟人”骗局？“银狐”威胁体发起的钓鱼攻击活动</description>
      <content:encoded><![CDATA[<p>
<span>猎影实验室</span> <span>2025-06-09 11:30</span> <span style="display: inline-block;">浙江</span>
</p>

<p>“熟人”骗局？“银狐”威胁体发起的钓鱼攻击活动</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=41803897&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia85QGnbQkKueUR1iaB2bLMmV5gyQ8ibHrmWPyVrLVYUyWtdicxl4mV6UBw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 100%;border: 1px solid rgba(0, 0, 0, 0);padding: 20px;background-color: rgba(0, 0, 0, 0);box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013651" class="rich_pages wxw-img" data-ratio="0.2777778" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=b53f5e89&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia9bbfEsliau7nP0PtE3VuOD5cbGTng3w1x3UTsdBDjnTvG92P4j203mA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(119, 177, 247);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgb(119, 177, 247);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 9px 0px 10px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 13px 9px 4px;border-color: rgb(232, 234, 246) rgb(232, 234, 246) rgba(255, 255, 255, 0);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">一、事件概述</span></span></strong></p></div></div></div></div></div></div></div><div style="font-size: 15px;line-height: 2;padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期，安恒信息猎影实验室观测到多起由“银狐”威胁体发起的钓鱼攻击活动。该木马主要</span><span style="color: rgb(214, 60, 60);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">通过仿冒网站的SEO投毒和钓鱼邮件进行传播</span></strong><span leaf="">。</span><strong style="box-sizing: border-box;"><span leaf="">一旦用户中招</span></strong></span><span leaf="">，攻击者会在受害主机上植入ValleyRAT/HackBrian RAT远控木马，</span><span style="color: rgb(214, 60, 60);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">并劫持用户正在运行的微信、钉钉等社交或办公软件，冒用受害者身份向联系人散布虚假的“退税”、“补贴”等诱饵链接</span></strong></span><span leaf="">。点击者如信以为真填写银行卡信息，其存款最终将被攻击者通过POS机</span><span style="color: rgb(214, 60, 60);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">盗刷</span></strong></span><span leaf="">。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本文将对近期活跃的“银狐”威胁体攻击链条进行详细剖析与披露。若您或身边人员发现类似可疑活动，请</span><span style="color: rgb(214, 60, 60);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">务必高度警惕，谨防财产损失</span></strong></span><span leaf="">！</span></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(119, 177, 247);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgb(119, 177, 247);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 9px 0px 10px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 13px 9px 4px;border-color: rgb(232, 234, 246) rgb(232, 234, 246) rgba(255, 255, 255, 0);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">二、银狐攻击活动分析</span></span></strong></p></div></div></div></div></div></div></div><div style="font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本次银狐威胁体攻击活动链路大致如图：</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013653" class="rich_pages wxw-img" data-ratio="0.6546296" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=fbb9fd36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia8aCXuVNpAStPyjU1j3JcnfHYpickzguoFvsXLJ0icREpiaZiaNSatFttXQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgba(1, 0, 0, 0);box-sizing: border-box;"><span leaf="">攻击流程可大致分为三个阶段，分别是：木马投放阶段、木马加载阶段和信息收集阶段。</span></span><span leaf=""><br/></span></p></div><div style="margin: 10px 0px;box-sizing: border-box;"><div style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><div style="z-index: 1;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><div style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><div style="display: inline-block;border: 1px solid rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1</span></strong></p></div></div><div style="text-align: center;margin: 0px;box-sizing: border-box;"><p style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><div style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><div style="z-index: 3;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-position: 50% 50% !important;background-size: 100% 100% !important;box-sizing: border-box;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneV0icmAOqad0Pueo2ribgsiaialy8yhWf9mfEVKAUrc002UL7yV2NBz7Pk1mbB3BQBgBuaf4bmiaXzXJw/640?wx_fmt=gif&amp;from=appmsg&#34;);"><div style="text-align: justify;color: rgb(62, 62, 62);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">木马投放阶段</span></strong></p></div></div></div></div></div></div></div></div></div></div><div style="font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">木马投放阶段主要通过两种方式，第一种为SEO投毒，攻击者通过购买某个软件的搜索引擎排名（常见为WPS、钉钉、向日葵等），当用户想要下载相应软件时，往往会因其排名靠前而点击进入攻击者构造的钓鱼网站。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013654" class="rich_pages wxw-img" data-ratio="0.5740741" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=0ca89134&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiamKn8baXgHAgj85OmmLWbl9ibGoXsaQDibqbOe2SnBQVNFCVKKb55poGA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013655" class="rich_pages wxw-img" data-ratio="0.5203704" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=a47e9e3f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaKv9HnqHouiccbzHic2zYWI7LhU07nG62eRicibKicVEfS6yzq6qBr2XHCgg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">另一种投放方式为发送包含恶意文件或恶意链接的电子邮件，安全意识薄弱的人员往往会信以为真，并点击邮件中的恶意链接或文件。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013652" class="rich_pages wxw-img" data-ratio="0.5703704" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=abd4a532&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaNOrtW47b89nqBmDwmLuVK7MBHhaziacynCp4EOK57jusC0Z0FUIH7FA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013658" class="rich_pages wxw-img" data-ratio="0.4990741" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=084f5aa3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia4uxM7eD8fSzVicPhYU09rsJHxFtvhnYsZ6rryIkXoWtia34IgmLn5YAA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013659" class="rich_pages wxw-img" data-ratio="0.4351852" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=3ad3017d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaAmKnnic7XXuy7FqKMwib24lv5CTPMNAF7DYbnibqwosC6CTw4El5r3XCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgba(1, 0, 0, 0);box-sizing: border-box;"><span leaf="">邮件中的恶意文件经常通过替换文档图标、双扩展名等方式迷惑用户。</span></span><span leaf=""><br/></span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;border-style: dotted;border-width: 1px;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013660" class="rich_pages wxw-img" data-ratio="0.6314815" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=a84fa302&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiajj9ccosBEW0pIjyxR83Ze2ftdQbjKWIG2H96RT5oSfcF1cQquicBzVg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0px;box-sizing: border-box;"><div style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><div style="z-index: 1;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><div style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><div style="display: inline-block;border: 1px solid rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2</span></strong></p></div></div><div style="text-align: center;margin: 0px;box-sizing: border-box;"><p style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><div style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><div style="z-index: 3;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-position: 50% 50% !important;background-size: 100% 100% !important;box-sizing: border-box;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneV0icmAOqad0Pueo2ribgsiaialy8yhWf9mfEVKAUrc002UL7yV2NBz7Pk1mbB3BQBgBuaf4bmiaXzXJw/640?wx_fmt=gif&amp;from=appmsg&#34;);"><div style="text-align: justify;color: rgb(62, 62, 62);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">木马加载阶段</span></strong></p></div></div></div></div></div></div></div></div></div></div><div style="font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">木马加载阶段主要任务为绕过安全监测，成功将远控木马执行。银狐威胁体通常采用以下几种方式加载远控木马：</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;box-sizing: border-box;"><div style="min-height: 40px;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td rowspan="2" data-colwidth="18.0000%" width="18.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px;background-color: rgb(236, 39, 31);box-sizing: border-box;"><div style="font-size: 12px;color: rgb(255, 255, 255);text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">白利用与内存加载技术</span></span></strong></p></div></td><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;box-sizing: border-box;"><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">伪装合法程序</span></p></div></td><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;box-sizing: border-box;"><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">运行具有合法代码签名的文件，这些白程序本身无害，但会加载同目录下的恶意加密文件，后者在内存中解密为恶意DLL并执行。</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;background-color: rgb(249, 235, 230);box-sizing: border-box;"><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">无落地文件</span></p></div></td><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;background-color: rgb(249, 235, 230);box-sizing: border-box;"><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过向云服务请求获取加密的木马文件，接收数据直接加载到内存执行</span></p></div></td></tr><tr style="box-sizing: border-box;"><td rowspan="3" data-colwidth="18.0000%" width="18.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px;background-color: rgb(251, 133, 129);box-sizing: border-box;"><div style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">进程注入与伪装技术</span></p></div></td><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;box-sizing: border-box;"><div style="text-align: justify;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">进程shellcode注入</span></p></div></td><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;box-sizing: border-box;"><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">将shellcode写入内存后，通过创建线程或直接调用的方式执行恶意代码。</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;background-color: rgb(249, 235, 230);box-sizing: border-box;"><div style="text-align: justify;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">反射dll注入</span></p></div></td><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;background-color: rgb(249, 235, 230);box-sizing: border-box;"><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">将dll文件和加载dll所需的代码写入进程，运行加载代码从而执行恶意代码。</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;box-sizing: border-box;"><div style="text-align: justify;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">APC注入</span></p></div></td><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;box-sizing: border-box;"><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">将目标DLL路径或自定义代码写入目标进程内存，</span><span style="box-sizing: border-box;"><span leaf="">为目标线程分配APC队列项，当目标线程进入可警告状态时执行注入的代码。</span></span></p></div></td></tr><tr style="box-sizing: border-box;"><td rowspan="2" data-colwidth="18.0000%" width="18.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px;background-color: rgb(236, 39, 31);box-sizing: border-box;"><div style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">滥用系统机制绕过安全防护</span></p></div></td><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;background-color: rgb(249, 235, 230);box-sizing: border-box;"><div style="text-align: justify;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">提升权限</span></p></div></td><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;background-color: rgb(249, 235, 230);box-sizing: border-box;"><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过系统或软件漏洞绕或UAC提升自身权限</span></p></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;box-sizing: border-box;"><div style="text-align: justify;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">结束安全软件</span></p></div></td><td data-colwidth="41.0000%" width="41.0000%" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;padding: 5px 10px;box-sizing: border-box;"><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遍历主机进程，如果进程名出现在预设的杀毒软件名单中，则结束进程。</span></p></div></td></tr></tbody></table></p></div></div></div><div style="font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期银狐威胁体使用的最为常见的远控木马为ValleyRAT，也称HackBrian RAT，该远控软件运行时会解密出配置信息，目前观察到的解密方式包括反转字符串和base64编码。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013657" class="rich_pages wxw-img" data-ratio="0.1240741" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=cfc4ac96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaL2dzKYDgtlUicj4xQwvQxFEqyL1z707K5wVLAWRshV8CC917wlRvuQg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013656" class="rich_pages wxw-img" data-ratio="0.2269504" data-s="300,640" data-type="png" data-w="987" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=89c337c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia2u0mxAj1UIib5fqlOX9H8KHyY6UB0BWicvSA353nvMciaLNQdnRwYGORQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013661" class="rich_pages wxw-img" data-ratio="0.2502523" data-s="300,640" data-type="png" data-w="991" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=5716f49e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiagiacQwVGMBIqMC9Xrwpx6Ux9GCn4yzuB9nEAZlf1100TEcya75CjZug%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgba(1, 0, 0, 0);box-sizing: border-box;"><span leaf="">ValleyRAT运行具有以下功能：</span></span><span leaf=""><br/></span></p></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(228, 93, 47);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;color: rgb(245, 245, 245);width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">命令代码</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(228, 93, 47);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;color: rgb(245, 245, 245);width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">功能描述</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x00</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加载插件</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x01</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">加载插件并将其写入注册表项 HKCU\Console\1{客户端 MD5 ID}</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x02</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭与C2服务器的连接</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x03</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">获取当前活动窗口的标题和用户屏幕的截图</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x04</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">屏幕截图</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x05</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">写入并执行文件</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x06</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">从URL下载并执行文件</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x07</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">更新注册表</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x08</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">查找具有特定可执行文件名的进程</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x09</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">向C2服务器返回硬编码字节 0x13</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x0a</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">发送用户屏幕上特定区域的截图</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x0b</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">清除应用程序、安全和系统事件日志</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x0c</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">重启恶意软件进程</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x0d</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">终止恶意软件进程</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x0e</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">强制注销系统</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x0f</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">强制重启系统</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x10</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">强制关闭系统</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x11</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">更新加载插件</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0x12</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">更新当前配置并将其写入 HKCU\Console\IpDate</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0xc9</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">与命令0x03相同，但截图的发送取决于命令参数中指定的标志</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">0xca</span></p></div></div></td><td data-colwidth="76.3700%" width="76.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">禁止系统自动进入睡眠状态</span></p></div></div></td></tr></tbody></table></p></div><div style="margin: 10px 0px;box-sizing: border-box;"><div style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><div style="z-index: 1;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><div style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><div style="display: inline-block;border: 1px solid rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3</span></strong></p></div></div><div style="text-align: center;margin: 0px;box-sizing: border-box;"><p style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><div style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><div style="z-index: 3;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div data-cacheurl="" data-remoteid="" style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-position: 50% 50% !important;background-size: 100% 100% !important;box-sizing: border-box;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneV0icmAOqad0Pueo2ribgsiaialy8yhWf9mfEVKAUrc002UL7yV2NBz7Pk1mbB3BQBgBuaf4bmiaXzXJw/640?wx_fmt=gif&amp;from=appmsg&#34;);"><div style="text-align: justify;color: rgb(62, 62, 62);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">信息收集阶段</span></strong></p></div></div></div></div></div></div></div></div></div></div><div style="color: rgb(62, 62, 62);font-size: 14px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;background-color: rgba(1, 0, 0, 0);box-sizing: border-box;"><span leaf="">在成功获取受害主机控制权限后，攻击者将在系统中操作微信、钉钉或邮箱等通信软件，以受害者的身份在受害者的社交圈进一步钓鱼，常见的一种方式是在群组中传播恶意软件或链接。</span></span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;border-style: double;border-width: 2px;border-color: rgb(255, 255, 255);box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013665" class="rich_pages wxw-img" data-ratio="1.0443038" data-s="300,640" data-type="png" data-w="948" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=068acf37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaKWFtibS3aW9DXLLWZYvRJWEuqwMFkaMK1DbMEvveusA7ZMwe8gAicXsQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013663" class="rich_pages wxw-img" data-ratio="1.1800487" data-s="300,640" data-type="png" data-w="822" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=c397d8c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaJSH9XD8EpPrATECP6oVmgR7rvpP3TPgsgBEtpMGrShDiaAuGOzicYPpw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="background-color: rgba(1, 0, 0, 0);box-sizing: border-box;"><span leaf="">点击链接看到攻击者伪造的政府公文和二维码。</span></span><span leaf=""><br/></span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;border-style: dotted;border-width: 1px;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013662" class="rich_pages wxw-img" data-ratio="1.5297806" data-s="300,640" data-type="png" data-w="638" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=45a17751&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaraKl0guUnKKia4D89zj45ia5Zx4Ar3YUoOWKL8cfbHpZ4sWLm8cnCeCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="color: rgb(62, 62, 62);font-size: 14px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">扫码后将进入攻击者伪造的填写个人信息界面，这一过程将引导受害者填写姓名、身份证、手机号、银行卡号及密码、短信验证码等敏感信息。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;border-style: dotted;border-width: 2px;border-color: rgb(0, 0, 0);box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013664" class="rich_pages wxw-img" data-ratio="1.6219336" data-s="300,640" data-type="png" data-w="693" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=19542b8c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaGGlztj2RpcGKtWVvicelcZEJAT6dEia5iaVtAaQj85Tu2UDy06uU7jt7g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="color: rgb(62, 62, 62);line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;background-color: rgba(1, 0, 0, 0);box-sizing: border-box;"><span leaf="">攻击者将通过这些信息绑定Apple Pay，并通过POS机刷走银行卡余额。</span></span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;border-style: dotted;border-width: 1px;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013668" class="rich_pages wxw-img" data-ratio="1.1145833" data-s="300,640" data-type="png" data-w="576" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=76e1728a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaHCmn8T5z0QFNzSeJbZOAianpGpbDic9VjMz64UbfgBghyBhv9C01ewnQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: dashed;border-width: 1px 1px 1px 0px;border-color: rgb(119, 177, 247);border-top-right-radius: 285px;border-bottom-right-radius: 285px;overflow: hidden;padding: 3px 3px 3px 0px;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top-right-radius: 140px;border-bottom-right-radius: 140px;overflow: hidden;background-color: rgb(119, 177, 247);padding: 0px 17px 0px 0px;box-sizing: border-box;"><div style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;padding: 0px 9px 0px 10px;box-sizing: border-box;"><div style="text-align: center;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 13px 9px 4px;border-color: rgb(232, 234, 246) rgb(232, 234, 246) rgba(255, 255, 255, 0);box-sizing: border-box;"><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(255, 255, 255);font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">三、活动总结</span></span></strong></p></div></div></div></div></div></div></div><div style="font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">银狐威胁体展现了一条完整的、极具欺骗性的网络犯罪链条。它的危害不仅在于其技术手段的隐蔽性，更在于它对我们信任的日常工具和人际关系的恶意利用。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这提醒我们：</span><strong style="box-sizing: border-box;"><span leaf="">面对网上突如其来的“好事”，尤其是熟人发来的涉及金钱操作的链接，务必保持高度警惕，多方核实（如直接电话联系对方或官方渠道确认）；同时，坚持安装并及时更新可靠的安全软件，修补系统漏洞，不随意点击不明链接或打开可疑邮件附件，是守护个人财产和信息安全最基本、也最有效的防线。</span></strong></p></div><div style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;isolation: isolate;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><p style="background-color: rgb(214, 60, 60);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;align-self: stretch;height: auto;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="transform: rotateY(180deg);-webkit-transform: rotateY(180deg);-moz-transform: rotateY(180deg);-o-transform: rotateY(180deg);box-sizing: border-box;"><p style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="transform: rotateX(180deg) rotateY(180deg);-webkit-transform: rotateX(180deg) rotateY(180deg);-moz-transform: rotateX(180deg) rotateY(180deg);-o-transform: rotateX(180deg) rotateY(180deg);box-sizing: border-box;"><p style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 auto;align-self: stretch;min-width: 10%;max-width: 100%;height: auto;background-color: rgb(214, 60, 60);border-width: 0px;box-sizing: border-box;"><div style="line-height: 1.4;color: rgb(255, 255, 255);padding: 0px 10px;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">防范建议</span></strong></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;align-self: stretch;height: auto;line-height: 0;padding: 0px;box-sizing: border-box;"><div style="box-sizing: border-box;"><p style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);box-sizing: border-box;"><p style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><p style="background-color: rgb(214, 60, 60);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div><div style="text-align: left;margin: 0px;box-sizing: border-box;"><div style="padding: 0px;text-align: justify;font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">安恒信息产品和服务能够对此类恶意攻击在多环节、全链路进行检测和防御。</span></strong></p></div></div><div style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><p style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody><tr style="box-sizing: border-box;"><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(228, 93, 47);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;color: rgb(245, 245, 245);width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">产品或服务</span></p></div></div></td><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(228, 93, 47);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;color: rgb(245, 245, 245);width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">检测环节</span></p></div></div></td><td data-colwidth="46.3700%" width="46.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(228, 93, 47);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;color: rgb(245, 245, 245);width: 100%;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">简介</span></p></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013666" class="rich_pages wxw-img" data-ratio="0.5625" data-s="300,640" data-type="png" data-w="64" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=b6bd04bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaaNSI6TRVIKVSIepoVzOJ5wMGFnZNGgOzLQBd0E0vq13s0E3JoXPEMA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安恒恒脑-恶意邮件研判智能体</span></p></div></div></div></td><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">全链路</span></p></div></div></td><td data-colwidth="46.3700%" width="46.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安恒恒脑-恶意邮件研判智能体依托恒脑安全垂域大模型能力，可对邮件内容进行语义理解和意图识别，结合二维码识别、附件研判、图片OCR等处理模块，实现了对钓鱼邮件、泄密邮件等多种异常邮件的有效判别，并给出异常点解读，可有效提高异常邮件识别的准确率，降低安全风险。</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">钓鱼邮件检测示例：</span></p></div><div style="line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013670" class="rich_pages wxw-img" data-ratio="0.513369" data-s="300,640" data-type="png" data-w="561" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=8ff6b8d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia9yibEh2rG2EQkKBJ6hQpGpwCRzxY6FyJpmshrMzj3fWc9lnZGYNlicYQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013667" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="61" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=488b425b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaXhldtyMhicF8blrXjGWRNytWJyIFxduvJHIBlEoEWJd2Wibrf6NOiczzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: justify;font-size: 12px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">明御APT攻击预警平台</span></p></div></div></div></td><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">流量测</span></p></div></div></td><td data-colwidth="46.3700%" width="46.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">明御APT攻击预警平台是流量威胁检测、恶意文件检测、分析溯源、联动响应于一体的高级威胁预警系统，基于丰富的特征库、全面的检测策略、精准的深度分析模型等规则检测，结合智能机器学习、动态沙箱、语义分析及威胁情报等高级威胁检测技术，能实时发现用户网络中的各种已知威胁和未知威胁，支持包含各类恶意代码攻击、远程控制、WEB攻击、邮件攻击、漏洞利用、隧道通信等在内的多种攻击类型检测。</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">银狐检测示例：</span></p></div><div style="line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013669" class="rich_pages wxw-img" data-ratio="0.2428571" data-s="300,640" data-type="png" data-w="560" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=642b790f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaBNn0Dib6EblgibmJ5jth028YibsVFhVicicfhd4NZicDA1kWvibiaURKarVaEw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013671" class="rich_pages wxw-img" data-ratio="1.047619" data-s="300,640" data-type="png" data-w="63" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=aa862556&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaoxCzyBnDmd0Y2cnGkAN0EnXv6CkibPQjSO0ZS2Du22o2wRr5tucBLWw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 12px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安恒终端安全管理系统（办公智盾）</span></p></div></div></div></td><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">终端测</span></p></div></div></td><td data-colwidth="46.3700%" width="46.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">办公智盾提出新一代的终端一体化安全防护理念和解决方案，超越传统思维，从单一终端安全，变成人员、终端、网络、应用、数据全方位一体化安全。办公智盾基于模块化设计理念，集多种安全模块于一体，融合了准入、零信任、防病毒、数据防泄漏、数字水印、文件加密、主机审计、桌面管理等十多种业务，全面兼容Windows、Linux、MacOS、UOS、麒麟等主流操作系统，一个平台，一个终端，统一管理。满足用户核心应用景，包括远程接入场景、威胁入侵防护场景、商业秘密保护场景、桌面管控场景。</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">银狐检测示例：</span></p></div><div style="line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013674" class="rich_pages wxw-img" data-ratio="0.5602837" data-s="300,640" data-type="png" data-w="564" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=b32e7d30&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaHiclDysTqXTnzL7hUrjDPjdG2aicQGCWTRSO0NGfz7C2rONcjmB2X2ZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013673" class="rich_pages wxw-img" data-ratio="0.7222222" data-s="300,640" data-type="png" data-w="72" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=6ad9f155&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia7rMPPSC1Dib74WC5xK5WVAS8YNsM0OToHT6I4Xeo5Qc4B9dQbYZiagZQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 12px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">XDR安全大脑（AXDR）</span></p></div></div></div></td><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">全链路</span></p></div></div></td><td data-colwidth="46.3700%" width="46.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安恒信息XDR安全大脑，又名：AiLPHA 高级威胁检测与分析系统（AXDR），聚焦终端侧和网络侧主动威胁检测和精准防护，依托强大的AI告警研判与精准事件分析能力，能够深度还原攻击链路，以安全场景为驱动，实现快速的响应处置，真正做到 “场景驱动、开箱即用、精准分析、极简运营”，助力政企数字化安全健康发展。XDR通过关联网络、终端的告警和日志，实现银狐木马攻击链路的可视化，精准溯源恶意进程，达到快速的响应和处置。</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全事件攻击链路分析示例：</span></p></div><div style="line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013675" class="rich_pages wxw-img" data-ratio="0.426025" data-s="300,640" data-type="png" data-w="561" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=d889d839&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiatKQNSdCWnl403LLxSG6ZAgTPwLK14aQtfT9whYlTlhviaKl70gEr86Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></td></tr><tr style="box-sizing: border-box;"><td data-colwidth="30.0000%" width="30.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none solid dashed none;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013672" class="rich_pages wxw-img" data-ratio="1.0769231" data-s="300,640" data-type="png" data-w="78" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=516759a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaAfH2fY8P2Vufoajibx8sDPqicBhrSBicJmAFwYHGu088Mfctr2l8mtUVQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 12px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安恒威胁情报数据</span></p></div></div></div></td><td data-colwidth="20.0000%" width="20.0000%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;width: 100%;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;box-sizing: border-box;"><div style="font-size: 12px;width: 100%;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">全链路</span></p></div></div></td><td data-colwidth="46.3700%" width="46.3700%" style="border-width: 0px 0px 1px;border-color: rgb(62, 62, 62) rgb(62, 62, 62) rgb(202, 198, 198);border-style: none none dashed;background-color: rgb(247, 247, 247);padding: 5px;box-sizing: border-box;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安恒威胁情报具备超过10亿条入侵检测IP情报的实时监测能力、300万条失陷检测情报的精准识别能力、10亿条文件hash样本的恶意代码检测能力，以及5000万条恶意URL的风险识别能力，具备完整的威胁分析字段和阻断等级判定能力。在漏洞预警方面，拥有35万条漏洞数据的风险发现、分析与预警能力，能够从可利用性、影响程度等维度进行应急响应级别划分。威胁组织画像能力覆盖600多种组织及3000+恶意家族的TTP攻击矩阵分析，具备攻击技术识别和关联分析能力。</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">银狐情报示例：</span></p></div><div style="line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013677" class="rich_pages wxw-img" data-ratio="0.3125" data-s="300,640" data-type="png" data-w="560" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=4f40013d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia03dicia84toYou1GUuy4NWR0n1f6rqicPtxZOo2WcPYrfIQmCOvVNorLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></td></tr></tbody></table></p></div><div style="text-align: left;margin: 0px;box-sizing: border-box;"><div style="padding: 0px;text-align: justify;font-size: 15px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">此外用户可通过云沙盒：</span><strong style="box-sizing: border-box;"><span leaf=""><a href="https://sandbox.dbappsecurity.com.cn/" target="_blank">https://sandbox.dbappsecurity.com.cn/</a></span></strong><span leaf=""> 对可疑文件进行威胁研判并下载分析报告。或用沙箱打开不明来源的未知文件，在虚拟环境中进行内容预览，免于主机失陷、受到木马或病毒文件攻击。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">也可在安恒星图平台：</span><strong style="box-sizing: border-box;"><span leaf=""><a href="https://starmap.dbappsecurity.com.cn/ " target="_blank">https://starmap.dbappsecurity.com.cn/ </a></span></strong><span leaf="">进行情报查询和分析。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><br/></span></p></div></div><div style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><div style="z-index: 1;box-sizing: border-box;"><div style="text-align: center;margin: 10px 0px -10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 30px;height: auto;box-sizing: border-box;" nodeleaf=""><img data-imgfileid="100013676" class="rich_pages wxw-img" data-ratio="1.0266667" data-s="300,640" data-type="png" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=189eca4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia2GSf5psltODQ4CQ4nkwjDiaBL4V0dTa5FFMosxWg4WH3siaCE07tFakQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 11px;border-color: rgb(228, 93, 47);padding: 18px 19px 19px;box-sizing: border-box;"><div style="margin: 0px;box-sizing: border-box;"><div style="font-size: 12px;line-height: 2;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">IOC</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://duqingmei@eoevuchjymbbj[.]cn/?btg.com.cn" target="_blank">https://duqingmei@eoevuchjymbbj[.]cn/?btg.com.cn</a></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://riedv[.]cn/vip.jpg" target="_blank">https://riedv[.]cn/vip.jpg</a></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://molifm[.]cn?20250527326626.zip" target="_blank">https://molifm[.]cn?20250527326626.zip</a></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://chzkzhm[.]cn?2025055410423.zip" target="_blank">https://chzkzhm[.]cn?2025055410423.zip</a></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">cce4cb4e41b01e309d22f10ecc29f607</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">103.12.149[.]123</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">38.49.40[.]130</span></p></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100013680" data-ratio="0.2777778" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d63c38b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia3qfticIcv9twsP4eye6tTBFicdqmu35U9leicRdQ4rqnGwXNqOALvraSA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=4d4df75b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia9bbfEsliau7nP0PtE3VuOD5cbGTng3w1x3UTsdBDjnTvG92P4j203mA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8c97f655&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia8aCXuVNpAStPyjU1j3JcnfHYpickzguoFvsXLJ0icREpiaZiaNSatFttXQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=fe7ef078&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaialy8yhWf9mfEVKAUrc002UL7yV2NBz7Pk1mbB3BQBgBuaf4bmiaXzXJw%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ae01310e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiamKn8baXgHAgj85OmmLWbl9ibGoXsaQDibqbOe2SnBQVNFCVKKb55poGA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b5da8ed5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaKv9HnqHouiccbzHic2zYWI7LhU07nG62eRicibKicVEfS6yzq6qBr2XHCgg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d1d2b9b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaNOrtW47b89nqBmDwmLuVK7MBHhaziacynCp4EOK57jusC0Z0FUIH7FA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=18cea06b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia4uxM7eD8fSzVicPhYU09rsJHxFtvhnYsZ6rryIkXoWtia34IgmLn5YAA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=211ba604&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaAmKnnic7XXuy7FqKMwib24lv5CTPMNAF7DYbnibqwosC6CTw4El5r3XCg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d4d3a52d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiajj9ccosBEW0pIjyxR83Ze2ftdQbjKWIG2H96RT5oSfcF1cQquicBzVg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=fe7ef078&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaialy8yhWf9mfEVKAUrc002UL7yV2NBz7Pk1mbB3BQBgBuaf4bmiaXzXJw%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f15318c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaL2dzKYDgtlUicj4xQwvQxFEqyL1z707K5wVLAWRshV8CC917wlRvuQg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=28cd28a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia2u0mxAj1UIib5fqlOX9H8KHyY6UB0BWicvSA353nvMciaLNQdnRwYGORQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9ea30eef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiagiacQwVGMBIqMC9Xrwpx6Ux9GCn4yzuB9nEAZlf1100TEcya75CjZug%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=fe7ef078&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaialy8yhWf9mfEVKAUrc002UL7yV2NBz7Pk1mbB3BQBgBuaf4bmiaXzXJw%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a3ea6999&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaKWFtibS3aW9DXLLWZYvRJWEuqwMFkaMK1DbMEvveusA7ZMwe8gAicXsQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=55168b61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaJSH9XD8EpPrATECP6oVmgR7rvpP3TPgsgBEtpMGrShDiaAuGOzicYPpw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=21af7e83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaraKl0guUnKKia4D89zj45ia5Zx4Ar3YUoOWKL8cfbHpZ4sWLm8cnCeCg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=09dff5e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaGGlztj2RpcGKtWVvicelcZEJAT6dEia5iaVtAaQj85Tu2UDy06uU7jt7g%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0bb7c29e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaHCmn8T5z0QFNzSeJbZOAianpGpbDic9VjMz64UbfgBghyBhv9C01ewnQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=791d1962&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaaNSI6TRVIKVSIepoVzOJ5wMGFnZNGgOzLQBd0E0vq13s0E3JoXPEMA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f9a281a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia9yibEh2rG2EQkKBJ6hQpGpwCRzxY6FyJpmshrMzj3fWc9lnZGYNlicYQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=838dd375&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaXhldtyMhicF8blrXjGWRNytWJyIFxduvJHIBlEoEWJd2Wibrf6NOiczzA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=4d74b4e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaBNn0Dib6EblgibmJ5jth028YibsVFhVicicfhd4NZicDA1kWvibiaURKarVaEw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a1bb4858&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaoxCzyBnDmd0Y2cnGkAN0EnXv6CkibPQjSO0ZS2Du22o2wRr5tucBLWw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5e841eae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaHiclDysTqXTnzL7hUrjDPjdG2aicQGCWTRSO0NGfz7C2rONcjmB2X2ZA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8c1ca665&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia7rMPPSC1Dib74WC5xK5WVAS8YNsM0OToHT6I4Xeo5Qc4B9dQbYZiagZQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=fa583e37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiatKQNSdCWnl403LLxSG6ZAgTPwLK14aQtfT9whYlTlhviaKl70gEr86Q%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a6e4c9c6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaiaAfH2fY8P2Vufoajibx8sDPqicBhrSBicJmAFwYHGu088Mfctr2l8mtUVQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7b2d2d78&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia03dicia84toYou1GUuy4NWR0n1f6rqicPtxZOo2WcPYrfIQmCOvVNorLQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=22356acf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia2GSf5psltODQ4CQ4nkwjDiaBL4V0dTa5FFMosxWg4WH3siaCE07tFakQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=660278f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneV0icmAOqad0Pueo2ribgsiaia3qfticIcv9twsP4eye6tTBFicdqmu35U9leicRdQ4rqnGwXNqOALvraSA%2F640%3Fwx_fmt%3Dgif"/></p>



<p><a href="2247497330">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=152df783&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247497330%26idx%3D1%26sn%3D7780f0f95ebdc4e3caf0ba66709eebcd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 09 Jun 2025 11:30:00 +0800</pubDate>
    </item>
    <item>
      <title>以“毒云藤”为例：“台独”势力网络间谍活动解析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247497232&amp;idx=1&amp;sn=195d95daebc80da85c655a658dbe66d2</link>
      <description>高调打击“台独”的网络活动</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2025-03-18 11:24</span> <span style="display: inline-block;">浙江</span>
</p>

<p>高调打击“台独”的网络活动</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=37341ee7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4NklAhibXyHPkI3c2ZCXwus5pUhhtQBjYGSk40kFYzlAicGCqOskyIiaSw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 16px;color: rgb(62, 62, 62);"><section style="margin-right: 0%;margin-left: 0%;"><section style="display: inline-block;width: 100%;border-width: 1px;border-style: solid;border-color: rgba(0, 0, 0, 0);padding: 20px;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013567" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=86e67709&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp478iatqcUy2elKG0BPDm3tXAP7ly50iaylOaGPpzOic1LIve1TpmEdoTibw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>1</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4T3QzNBFhPMmUKOdGJS4L5qF2WwuH49RSbibStx5r8VEOKIyZdV9ialsA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>引言</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">网络安全作为国家安全的重要组成部分，没有网络安全就没有国家安全，就没有经济社会稳定运行。长期以来，“台独”势力持续对大陆实施网络攻击和渗透活动。近日，国家安全部公开了4名台湾资通电军（以下简称“资通电军”）成员的身份信息，并表示查获资通电军在用的数十个网攻平台，发现其针对大陆重要领域实施攻击窃密的新动向，并全部核查处置，斩断窃密“黑手”。台湾资通电军自2017年6月成立以来，便充当“台独”分裂势力的爪牙，无所不用其极地对大陆开展网络攻击渗透活动。</p></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>2</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4T3QzNBFhPMmUKOdGJS4L5qF2WwuH49RSbibStx5r8VEOKIyZdV9ialsA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>资通电军是何背景</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">台湾资通电军，全称为资讯通信电子部队，成立于2017年6月，并设立资讯通信军指挥部，主要承担电子作战、信息作战、网络作战及军线维护管理等职能，是台湾当局对大陆实施网络作战的主力。台湾省当局将其视为对抗大陆军事压力的“非对称战力”之一。2016年蔡英文上台后，强调所谓的“国防自主”，资通电军的设立则被认为是这一战略的延伸。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013569" data-ratio="0.6671875" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=089f7d50&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4mzOecetlPicMCIx6WAhUoeibfysyb31QkO9wdG8VlCqYYH0ibYicNhjXfQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;font-size: 12px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">图 资讯通信军指挥部成立典礼照</span><br/></p></section><p><br/></p><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">台湾资通电军一经成立，便对大陆大肆开展各类网络渗透破坏活动，是危害网络空间安全的毒瘤。台湾资通电军专门组建网络战联队，并雇佣社会黑客、网安公司作为外协力量，执行民进党当局下达的网络作战指令，开展窃密、破坏、反宣活动。惯用的手段包括：渗透关键基础设施、向重点单位和组织发送钓鱼和反宣电子邮件、潜伏在主流社交媒体平台，豢养大量“机器人”账号、操纵舆情走向，误导大陆和台湾民众认知等。自2023年起，又以“匿名者64”组织等名义，在网络社交媒体平台散布虚假消息，竭力为民进党当局谋“独”行径张目。</p></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>3</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4T3QzNBFhPMmUKOdGJS4L5qF2WwuH49RSbibStx5r8VEOKIyZdV9ialsA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>技术解析：以“毒云藤”为代表的</strong></p><p><strong>“台独”网络攻击活动</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">安恒信息长期追踪分析来自中国台湾省方向的网络攻击活动和威胁情报。从2007年开始，台湾省APT组织“毒云藤”就长期针对国内国防、政府、科技和教育领域的重要机构实施网络间谍攻击活动。</p><p style="word-break: break-all;"><br/></p><p style="word-break: break-all;">“毒云藤”组织的攻击频率非常密集。根据安恒信息的持续追踪监控，仅在半年内，就追踪到数十起不同主题的、相对独立的“毒云藤”组织的攻击行为。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: double;border-width: 2px;border-color: rgb(255, 255, 255);"><img class="rich_pages wxw-img" data-imgfileid="100013570" data-ratio="0.9972222222222222" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=39ee083b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4c8YTicCpHWjribHicTiahUibdEftDJhv4pkQz6toribic3ConrUATGuhibfuQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 14px;line-height: 2;"><p style="word-break: break-all;text-align: center;"><span style="font-size: 12px;">表格1 毒云藤组织画像</span></p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;"><section style="min-height: 40px;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="text-align: center;font-size: 14px;color: rgb(255, 255, 255);"><p><strong>组织名称</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">毒云藤</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">组织别名</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">APT-C-01、GreenSpot、毒云藤、绿斑、穷奇、白海豚</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">简介</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">毒云藤，又名绿斑、APT-C-01等，是一个长期针对国内国防、政府、科技和教育领域的重要机构实施网络间谍攻击活动的APT团伙，最早可以追溯到2007年。该组织惯用鱼叉式钓鱼网络攻击，会选取与攻击目标贴合的诱饵内容进行攻击活动，惯用的主题包括通知、会议材料、研究报告等或是采用攻击时间段时事主题。除了附件投递木马外，毒云藤还惯用钓鱼网站钓鱼，窃取目标的账户密码，进而获得更多重要信息。该组织主要关注方向包括：海事、军工、涉台两岸关系、中美关系等。</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>组织归属</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">中国台湾</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>目标地域</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">中国</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>首次发现</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">2017</p></section></td></tr></tbody></table></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">该组织惯用鱼叉式钓鱼网络攻击和钓鱼网站作为初始访问攻击手段，会选取与攻击目标贴合的诱饵内容进行攻击活动，惯用的主题包括通知、会议材料、研究报告等或是采用攻击时间段时事主题。例如下图为“毒云藤”组织曾经使用过的，以中国某技术博览会为主题的钓鱼文件：</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: dotted;border-width: 2px;border-color: rgb(0, 0, 0);"><img class="rich_pages wxw-img" data-imgfileid="100013568" data-ratio="0.5805555555555556" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4fbd90d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4R0aTnWCT2TBpIhRiaIpeOtweW3OC6mqWicLQYibLYE49LHiaThWC8Y4H8w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="line-height: 2;"><p style="word-break: break-all;"><span style="font-size: 15px;background-color: rgba(1, 0, 0, 0);">除此之外，还使用带有漏洞的文档、伪装的二进制可执行程序、伪装的自解压程序，使用多种远控木马，主要包含Poison Ivy、ZxShell等。如下图是“毒云藤”组织使用的伪装为文件夹图标的EXE可执行木马：</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013566" data-ratio="0.22777777777777777" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=80eb36a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4KmvSBap2XT9A29KdibawJbS2nbx4RN63UtBvGHOQucvWBjuIG1iblS7g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">除了附件投递木马外，毒云藤还惯用钓鱼网站钓鱼，窃取目标的账户密码，进而获得更多重要信息。例如，在2024年，安恒信息猎影实验室发现毒云藤通过伪装“全国车辆交通违章查询”系统进行钓鱼攻击。诱导目标填写网易邮箱账号密码，提交后实则将账户信息传输给后台记录，根据账户密码进一步实施后续威胁行为。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013572" data-ratio="0.5092592592592593" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=cdcd275f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4ibQIpGfuQoib3NStwdsFPtVdkdD9ibjqe3u3iakibDFKiaQqJ2n1taULgb0g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p>该组织还仿冒北京大学国家发展研究院的钓鱼网站，同样其意在窃取相关人员的账户密码以进行后续攻击活动。域名为<a href="https://server.jihing[.]com，该域名解析到45.79.118[.]216:" target="_blank">https://server.jihing[.]com，该域名解析到45.79.118[.]216:</a></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: dotted;border-width: 1px;"><img data-imgfileid="100013571" data-ratio="0.4358736059479554" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1076" src="https://wechat2rss.xlab.app/img-proxy/?k=36b2503e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4SThlGgQy0CVFLDlkR3khNOJIiboByljibfRGtQYiaAPurrnUn0sBZHmibw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 12px;text-align: center;line-height: 2;"><p>仿冒的北京大学相关网站</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013573" data-ratio="0.42314814814814816" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=448ec398&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4H6m74ECGMRlDsXZm10uP29Rib5R6uDUCnLg4ANUPib1D6iajhOj2fLmzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">将受害者输入的账号密码发送至<a href="https://server.jihing.com/login[.]php后，跳转至正常页面:" target="_blank">https://server.jihing.com/login[.]php后，跳转至正常页面:</a></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013575" data-ratio="0.4287037037037037" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=853f7545&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp48JLLnusYQERttRAzzhEWeEsScrIHv8LWNxqQgjibBEF9cRNwhH1bN0A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">毒云藤依托于其特殊背景面向国防军工、科技、政府等领域持续攻击。攻击手法上看稍显单一，同一攻击形式已经使用了较长时间，就如网页钓鱼活动，看似单一，却极具迷惑性，如若针对不同目标，或仍能够发挥一定效果，尤其是当毒云藤对目标进行深入调研，构制出专门针对贴合目标的钓鱼页面和主题，真假不一定能够轻易分辨，不可掉以轻心。</p></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>4</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4T3QzNBFhPMmUKOdGJS4L5qF2WwuH49RSbibStx5r8VEOKIyZdV9ialsA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>总结</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">台湾的“台独”势力妄图构建对大陆网络攻击渗透、窃密、破坏的网络战能力，终将是蚍蜉撼树、自不量力。国家安全部公开4名资通电军成员身份，是大陆对“台独”网络活动的一次高调打击，体现了在网络安全和国家主权问题上的强硬态度。</p><p style="word-break: break-all;"><br/></p><p style="word-break: break-all;">在网络空间安全对抗中，随着网络空间成为政治博弈的新战场，APT攻击已成为某些国家和地区达成政治、经济目标的重要工具。这些攻击往往精心策划，针对性强，能够在长时间内悄无声息地窃取信息或造成破坏，对国家安全和社会稳定构成严重威胁。面对这一挑战，强化网络安全防护体系、提高识别和抵御APT攻击的安全能力显得尤为重要。</p></section><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: center;margin-top: 10px;margin-bottom: -10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 30px;height: auto;"><img data-imgfileid="100013574" data-ratio="1.0266666666666666" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="300" src="https://wechat2rss.xlab.app/img-proxy/?k=176d36a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4w8kEQQEseia24rtJ6WWj95IX0WTNYOpW6FJxtgDN4YgzS6XchsL4O6w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-bottom: 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 11px;border-color: rgb(228, 93, 47);padding: 18px 19px 19px;"><section style=""><section style="font-size: 12px;line-height: 2;"><p style="word-break: break-all;"><strong>IOC</strong></p><p>server.ji****[.]com</p><p>mail.pk****[.]com</p><p>search*****for126[.]com</p><p>ip138*****safty126[.]com</p></section></section></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013580" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=e3a6ace8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvnd2xYrZ1jQJIZggmcicovvp4zeYwm3WWBnhZ0bsIXJxZkwCRSInosqSycJgEiaVXDa9pLq2icuPbiaTGg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247497232">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9fa11fd3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247497232%26idx%3D1%26sn%3D195d95daebc80da85c655a658dbe66d2%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 18 Mar 2025 11:24:00 +0800</pubDate>
    </item>
    <item>
      <title>仿冒域名与新型攻击链：Patchwork组织针对中国的网络攻势研究</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247497213&amp;idx=1&amp;sn=16ee7a8455569f805593d7b89a0d2d73</link>
      <description>攻击手法复杂且隐蔽，需引起高度警惕</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2025-03-04 11:19</span> <span style="display: inline-block;">浙江</span>
</p>

<p>攻击手法复杂且隐蔽，需引起高度警惕</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=62799754&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6uNVV1ezNBet4Q8B1OXYianmKsPZiahCFKbfLOSSVy9le0dDPrV3dwDWA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 16px;color: rgb(62, 62, 62);"><section style="margin-right: 0%;margin-left: 0%;"><section style="display: inline-block;width: 100%;border-width: 1px;border-style: solid;border-color: rgba(0, 0, 0, 0);padding: 20px;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013540" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2798a44e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6uva3znD5PdnqIiaqf6f7F5x5XWu2gIzPephyNAP6RzZia8AUwV1bXiatg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>1</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneGHCaW9bytStwsaBN67ho6lybvjrSpALYCzeqEDuztPrPJnB89Ms7GVYnmcxDM0LlPfPwyV1wJJA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>事件概述</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">近年来，高级持续性威胁（APT）组织针对特定地区和行业的攻击活动日益频繁，其中Patchwork组织（又称Dropping Elephant、APT-C-09）因其长期针对中国、巴基斯坦、孟加拉国等南亚地区的外交、教育、科技领域进行网络攻击而备受关注。该组织以高度定制化的攻击工具和复杂的攻击链著称，常利用社会工程学手段（如钓鱼邮件、伪装文档）诱骗目标运行恶意负载，进而窃取敏感信息或部署后门程序。</p><p style="word-break: break-all;"><br/></p><p style="word-break: break-all;">Patchwork组织的攻击活动通常具有明确的地缘政治和经济目的，其攻击目标多为政府机构、科研单位及高等教育机构。近年来，该组织不断更新其攻击手法，结合多种技术手段（如白加黑、加密Shellcode、远程脚本加载）以规避安全检测。此外，其攻击基础设施中大量仿冒国内单位的域名也表明，Patchwork组织在攻击准备阶段投入了大量资源，以增强攻击的隐蔽性和成功率。</p><p style="word-break: break-all;"><br/></p><p style="word-break: break-all;">在此背景下，我们对Patchwork组织近期发起的恶意攻击活动进行了深入分析，揭示了两条主要攻击链及其技术细节。攻击链一（LNK-&gt;PDF+Loader-&gt;BadNews）主要针对国内目标，通过诱骗用户运行LNK文件，分阶段下载PDF文件、白文件、恶意DLL及加密Shellcode，最终解密并执行Patchwork组织的专属特马BadNews。攻击链二（LNK-&gt;PS-&gt;白+黑+加密负载-&gt;Shellcode Loader-&gt;Havoc框架）则利用LNK文件加载远程Powershell脚本，通过复杂的白加黑技术及加密负载，最终解密并加载Havoc框架以实现攻击目的。</p><p style="word-break: break-all;"><br/></p><p style="word-break: break-all;">通过对攻击链二样本的关联分析，我们发现该组织的攻击活动不仅限于国内，还涉及南亚地区，例如针对孟加拉国的钓鱼邮件攻击。此外，攻击者还使用包含OLE对象的DOCX文件加载LNK文件，进一步扩展了攻击面。资产分析显示，Patchwork组织注册了大量仿冒国内单位的域名，主要涉及外交、教育、科技等领域，表明其攻击目标具有高度针对性。</p><p style="word-break: break-all;"><br/></p><p style="word-break: break-all;">本报告详细剖析了攻击链的技术实现、样本关联及资产信息，为防御此类攻击提供了重要参考。Patchwork组织的攻击手法复杂且隐蔽，需引起相关单位的高度警惕，并采取针对性的防护措施。</p></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>2</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneGHCaW9bytStwsaBN67ho6lybvjrSpALYCzeqEDuztPrPJnB89Ms7GVYnmcxDM0LlPfPwyV1wJJA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>样本分析</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">根据攻击活动中加载的文件类型及最终攻击负载的不同，我们将近期捕获的样本分为两类攻击链。第一类攻击主要针对国内用户，最终加载的特马为BadNews<a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247497001&amp;idx=1&amp;sn=bf11de770fea2d96d4f3c08dfd7e038f&amp;scene=21#wechat_redirect" textvalue="（该特马在我们此前报告中已有详细分析，本文不再赘述）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">（该特马在我们此前报告中已有详细分析，本文不再赘述）</a>。第二类攻击主要针对南亚地区，但通过对相关资产的测绘分析，我们发现该组织仍在积极筹备针对我国的攻击活动，显示出其持续的地缘政治意图。</p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(248, 249, 253);min-width: 10%;flex: 0 0 auto;height: auto;padding: 15px;align-self: flex-start;"><section style="margin: -17px 0% -11px;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 9px 7px 0px;border-color: rgb(251, 133, 129) rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><strong>攻击链1：LNK-&gt;PDF+Loader-&gt;BadNews</strong></p></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">在该攻击链模式下，我们捕获到的样本如下：</p><p style="word-break: break-all;"><br/></p><p style="word-break: break-all;"><strong>样本一：</strong>以“国家重点研发计划重点专项项目实施工作方案”为诱饵，引诱目标运行LNK文件，执行后下载PDF文件、白文件、恶意DLL文件以及加密的Shellcode数据，此样本中我们未捕获到后续文件。</p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;"><section style="min-height: 40px;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">文件名</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">国家重点研发计划重点专项项目实施工作方案.pdf.lnk</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">Hash</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">4010952725284d1c5d198f28cc35764d7621590c163bf489791f023592784a53</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>URL</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">hxxps://ados.fyicompsol.xyz/lkasedb_4edsw/hsvdcxsew-3dsw</p><p style="word-break: break-all;">hxxps://kens.fyicompsol.xyz/aloetdg_74dfs/asgdneu9_lfd2</p><p style="word-break: break-all;">hxxps://rkde.fyicompsol.xyz/jsgdevdw_3ed/hdbdewsq1_sc3</p><p style="word-break: break-all;">hxxps://kila.fyicompsol.xyz/kfdgbcws_rf4/dcsxwer32khd_esf</p></section></td></tr></tbody></table></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><strong>样本二：</strong>该文件以“2025年‘硕博连读’选拔评审成绩（军队计划）”为诱饵，引诱目标运行LNK文件，执行流程与上相同，后续加载Patchwork特马BadNews。</p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;"><section style="min-height: 40px;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="text-align: center;font-size: 14px;color: rgb(255, 255, 255);"><p><strong>文件名</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">Military_Plan_Shuo_Reading.pdf.lnk</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">Hash</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">9f27d7b82a70ba3d8ff1ad9f26acf8245a45cf80fbe0c3cf9f026814167e8dc6</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><span style="font-size: 14px;"><strong>文件下载</strong></span></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">hxxps://liuyi.neectar.info/hsdverd_3ed5d/mdswsourt_4rfs</p><p style="word-break: break-all;">hxxps://tian.neectar.info/lksderdd_4dferd/jhdfer3s_jh3de</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>特马回连</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">hxxps://hongbaow.info/1WrCVzW4kSDNbNTt/cqWf4vQlofzqFkc7.php</p></section></td></tr></tbody></table></section></section></section></section><section style="font-size: 14px;line-height: 2;"><p style="word-break: break-all;"><span style="font-size: 15px;background-color: rgba(1, 0, 0, 0);">相关诱饵文件如下</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: double;border-width: 2px;border-color: rgb(255, 255, 255);"><img class="rich_pages wxw-img" data-imgfileid="100013539" data-ratio="0.6817391304347826" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="575" src="https://wechat2rss.xlab.app/img-proxy/?k=183dd629&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6PCGkgUcTqoej33Rgz4OzHXyZDfnIBOdVUh0CuFDItZOR06h5oHjia7Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 14px;line-height: 2;"><p style="word-break: break-all;"><strong>样本三：</strong>以“中国气象局人工影响天气中心文件”为话题，引诱目标运行LNK文件，执行流程与上相同，后续同样加载Patchwork特马BadNews。</p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;"><section style="min-height: 40px;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="text-align: center;font-size: 14px;color: rgb(255, 255, 255);"><p><strong>文件名</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">Innovation_Team.pdf.lnk</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">Hash</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">acbcb6448447ad4a5c0dae7e3e44be5383c3bd6bb246f4889feae4731259bd32</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">文件下载</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">hxxps://kupes.fourays.info/tgsfdjerpERAF4562_yhfd/kshdjfl</p><p style="word-break: break-all;">hxxps://jdkupes.fourays.info/yjsgdjflas845ui/hjksfdgwrepsd</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>特马回连</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">hxxps://foxinfo.org/1WrCVzW4kSDNbNTt/cqWf4vQlofzqFkc7.php</p></section></td></tr></tbody></table></section></section></section></section><section style="font-size: 14px;line-height: 2;"><p style="word-break: break-all;">相关诱饵文件如下</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: dotted;border-width: 2px;border-color: rgb(0, 0, 0);"><img data-imgfileid="100013542" data-ratio="0.651" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1000" src="https://wechat2rss.xlab.app/img-proxy/?k=ea59638e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6KEPXicB4GAPiaBc5VHAAlll3Q6ib4kg0GyAkvbeXUH6QWJWxibdtZJAic1Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(248, 249, 253);min-width: 10%;flex: 0 0 auto;height: auto;padding: 15px;align-self: flex-start;"><section style="margin: -17px 0% -11px;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 9px 7px 0px;border-color: rgb(251, 133, 129) rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><strong>攻击链2：LNK-&gt;PS-&gt;白+黑+加密负载-&gt;解密出Shellcode Loader-&gt;加载Havoc框架</strong></p></section></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013541" data-ratio="0.4185185185185185" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=32322fb3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6LCveibw33uQ1DOC0EZH7BZQV9kibicDUdxtPVApEYoo5jO8lMvzTFIQOw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="line-height: 2;"><p><span style="font-size: 15px;background-color: rgba(1, 0, 0, 0);">我们捕获Patchwork使用Havoc框架的初始阶段样本信息如下：</span></p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;"><section style="min-height: 40px;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">文件名</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">DH-Report76.pdf.lnk</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">Hash</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">207b27f4f17802dc951b6300eaeeaed181ee7567526325f940e66242f54d3add</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>ITW</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">hxxps://army-mil.zapto.org/webdav/DH-Report76.pdf.lnk</p></section></td></tr></tbody></table></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">该LNK文件托管在URL：</span><br/></p><p>hxxps://army-mil.zapto.org/webdav/DH-Report76.pdf.lnk，该域名来自动态域名服务提供商zapto.org，文件运行后将执行远程文件f.ps1</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013538" data-ratio="0.1882510013351135" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="749" src="https://wechat2rss.xlab.app/img-proxy/?k=d54f490e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6pvdbuT5oVrDJmbBSamtNjEg279ZibM1TK5nFgz1Wpic0ibZYrcPrVXkEg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">f.ps1脚本包含指令执行后将下载远程文件sppc.dll、onelog.dll到本地，复制本机phoneactivate.exe文件到%Temp%目录并更名为word.exe，最后在开机自启目录创建快捷方式实现持久化，启动&#34;word.exe&#34;。该文件启动后将加载sppc.dll恶意DLL文件</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013547" data-ratio="0.319" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1000" src="https://wechat2rss.xlab.app/img-proxy/?k=7ffbe2e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6EibhwtZ3CFyjOia4ibDvxgicslNlhJZriakW5m5IBFDUuwUzWjXZTiaLf6eQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">下载文件信息如下：</p></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(228, 93, 47);padding-right: 5px;padding-left: 5px;" width="30.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;color: rgb(245, 245, 245);"><p><strong>文件名</strong></p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(228, 93, 47);padding-right: 5px;padding-left: 5px;" width="66.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;color: rgb(245, 245, 245);"><p><strong>Hash</strong></p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="30.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">sppc.dll</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="66.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">fe3659fe8ceedc9acbd84eca852f06feeb235e9fe83fa6da2383d17f6e0108c5</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="30.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">onelog.dll</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="66.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">2a09b5f1429eb2b6049e374200cb39d7075dd962098adb6b61b0bafbcee9b487</p></section></section></section></td></tr></tbody></table></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">sppc.dll文件用于DLL劫持，由白文件phoneactivate.exe加载，加载后将读取onelog.dll文件</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013543" data-ratio="0.10953058321479374" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="703" src="https://wechat2rss.xlab.app/img-proxy/?k=b2f735c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6lM9ygKj54MpHJvWmziaY3UI9eNcwib8XIYDPCbDEME6kYYqPWWlShXpg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013546" data-ratio="0.32148900169204736" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="591" src="https://wechat2rss.xlab.app/img-proxy/?k=d7007420&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6aTyyicRnh67M6uZa2CHGPqYeuWo6Y4p5rgfHCc8QViaU83OmIdiaeWGCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">sppc.dll调用SystemFunction033进行解密，用于解密有效载荷的密钥是nbmavjzjlsbpixbddwqqmkqrdejdihrq</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013544" data-ratio="0.3176470588235294" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="595" src="https://wechat2rss.xlab.app/img-proxy/?k=4efe4aa1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6HiccF9Vx3TgYqMsWUp6KPUmaiaGvQSLW1LGX5C0LlabNtExWvkvtRlUA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">解密后的onelog.dll包含Shellcode加载器以及下一阶段DLL</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013545" data-ratio="0.23963133640552994" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="651" src="https://wechat2rss.xlab.app/img-proxy/?k=b14aeb43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6Tr2QpcVOElr1Zaems4TvHADyx1CpfTQ3WdAOT8E0gqJY69zsicdzibiag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013548" data-ratio="0.22085889570552147" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="652" src="https://wechat2rss.xlab.app/img-proxy/?k=668c0d21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6SkL7mVuce94U5TtficYxrV6PnBvlQxFb08vBpHL7HbAvhxicTcTWWoFA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">Shellcode加载器通过实现DJB2算法来解析API函数</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013549" data-ratio="0.7688603531300161" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="623" src="https://wechat2rss.xlab.app/img-proxy/?k=8c9abcf2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho632HlEFA50AiclmTxDyb9h3Z7g7FD89icPbhknnag2VR0tKskX5SXNWDg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">最终有效负载为Havoc框架，其配置信息如下</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013552" data-ratio="0.841324200913242" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="876" src="https://wechat2rss.xlab.app/img-proxy/?k=42479c77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6vN8HPxXjycX1cdcPndIuXI2Kia7JzBbQA83s14hhVq9W3YvaWo7ibRUA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>3</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneGHCaW9bytStwsaBN67ho6lybvjrSpALYCzeqEDuztPrPJnB89Ms7GVYnmcxDM0LlPfPwyV1wJJA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>关联</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">依据提取的样本特征，我们在狩猎平台上发现的其他关联文件如</p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(248, 249, 253);min-width: 10%;flex: 0 0 auto;height: auto;padding: 15px;align-self: flex-start;"><section style="margin: -17px 0% -11px;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 9px 7px 0px;border-color: rgb(251, 133, 129) rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><strong>样本一：钓鱼邮件+RAR附件+LNK/PDF</strong></p></section></section></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-top-style: none;border-bottom-style: none;border-left-style: none;background-color: rgb(236, 84, 11);padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="text-align: center;padding-right: 5px;padding-left: 5px;font-size: 12px;color: rgb(255, 255, 255);"><p><strong>文件名</strong></p></section></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-top-style: none;border-bottom-style: none;border-left-style: none;background-color: rgb(236, 84, 11);padding: 0px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="text-align: center;padding-right: 5px;padding-left: 5px;font-size: 12px;color: rgb(255, 255, 255);"><p><strong>Hash</strong></p></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">Fraudulent Transaction of 5000 BDT.msg</p></section></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;word-break: break-all;">b65c9453ee78321defb63ed2ccdffd0e2df3177f12e66185c1ef2e8ba298d800</p></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-width: 0px;border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(248, 243, 240);padding: 3px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;word-break: break-all;">Transactions_of_5000_BDT.rar</p></section></section></td><td colspan="1" rowspan="1" style="border-width: 0px;border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(248, 243, 240);padding: 3px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;word-break: break-all;">909db58a782dfbe605b0e6047b9bd056377deb75d64d0cb9cefbcf11d3195318</p></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;word-break: break-all;">Transaction_of_7350_BDT.pdf.lnk</p></section></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;word-break: break-all;">136dd864f5772a6567aff34fcbe6f0665b7cc04b2d486004c370f410bee259b1</p></section></section></td></tr></tbody></table></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">样本一为上传自孟加拉国的钓鱼邮件，邮件收件人为孟加拉国财政部金融机构部联合秘书Kamrul Hoque Maruf先生，邮件描述了发件人疑似遭遇的诈骗交易，并请求银行调查及退款，附件为交易详情。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img data-imgfileid="100013551" data-ratio="0.4652173913043478" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="920" src="https://wechat2rss.xlab.app/img-proxy/?k=a6ad13fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho67njcapbTmNAz0KJibRVKru1YAFYibBCaaRQQs8hDfP4ORW5V7sppLwsw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">附件包含PDF文件与LNK文件，LNK文件名为Transaction_of_7350_BDT.pdf.lnk，在引诱目标运行后，将执行远程Powershell脚本，并打开本地同名的PDF文件</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img class="rich_pages wxw-img" data-imgfileid="100013550" data-ratio="0.19733333333333333" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=4386a9a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho643EDia7UgRwTCqmWpqOxJ8koeApCpya1VHjs7FicQtlknia8Nic8IfbY7A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">PDF文件内容为邮件中提到的交易记录。</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;width: 80%;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100013553" data-ratio="1.4034229828850855" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="409" src="https://wechat2rss.xlab.app/img-proxy/?k=486702a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6Jmicohp4JTpUUzUTzb7pOGibaTsl0CZoxwtSxuhMSAp5JoHuPx9LX4JQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">其远程执行的脚本疑似使用LLM生成，主要功能为下载远程文件到本地</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img class="rich_pages wxw-img" data-imgfileid="100013556" data-ratio="0.5757931844888367" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="851" src="https://wechat2rss.xlab.app/img-proxy/?k=7ca534d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6pGcMbyNRiaynqcxZFYnPbJic2lVWQVH4ddhFxwxD5weHbnxKpcEKXSdA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p><span style="background-color: rgba(1, 0, 0, 0);"></span>下载文件信息如下：<span style="background-color: rgba(1, 0, 0, 0);"></span></p></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(228, 93, 47);padding-right: 5px;padding-left: 5px;" width="30.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;color: rgb(245, 245, 245);"><p><strong>文件名</strong></p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(228, 93, 47);padding-right: 5px;padding-left: 5px;" width="66.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;color: rgb(245, 245, 245);"><p><strong>Hash</strong></p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="30.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">sspicli.dll</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="66.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">7498a07f903486473cce83fbf16b88009765af98326e1ebef4c48f103b874f65</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="30.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">windowskernel32.dll</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="66.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">90f43a20a956b5d2e7b73cd3c2a6896a3af032414a297a23d0f07ef2f1016b17</p></section></section></section></td></tr></tbody></table></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">与上述样本相同的是，此文件加载流程仍为白+黑加载Shellcode执行。不同的是，该样本未下载用于DLL劫持的可执行文件，其直接将恶意DLL文件及加密数据下载到了OneDrive目录，以便在OneDrive.exe启动时直接加载恶意负载。</span></p><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);"><br/></span></p><p style="word-break: break-all;">此样本在通信中使用的域名（uat-updates.gateway.ceair.com.81-cn.info）中包含的cn、ceair（中国东方航空）等缩写，表明攻击者可能将中国作为主要目标之一。该域名解析到IP：47.236.170.136，该IP绑定的域名自2024年3月开始活跃，主要针对中国、巴基斯坦的政府、外交、教育等领域，涉及仿冒国内单位的域名如下：</p></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(228, 93, 47);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;color: rgb(245, 245, 245);"><p><strong>域名</strong></p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(228, 93, 47);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;color: rgb(245, 245, 245);"><p><strong>仿冒目标</strong></p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">sysu.edu.cn.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="2" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">中山大学</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>cas.sysu.edu.cn.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.mfa.gov.cn.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="2" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">中华人民共和国外交部</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mfa.gov.cn.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>updates.moe.gov.cn.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="4" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>中华人民共和国教育部</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">cloud.moe.gov.cn.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">moe.gov.cn.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">cfibdupdates.moe.gov.cn.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">crec-bangladesh.ddns.net </p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>中国中铁</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">boc.cn.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="2" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>中国银行</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">boc-cn.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">ustc.edu.cn.coremail.login.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>中国科学技术大学</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.spacechina.com.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="3" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>中国航天科技集团</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.mail.spacechina.com.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">spacechina.com.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">ciecc.com.cn.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="2" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>中国国际工程咨询有限公司</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">corporate-social-activity-updates.ciecc.com.cn.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">internal-portal.ceair.com.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="4" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>中国东方航空</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">ceair.com.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">gateway.ceair.com.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">uat-updates.gateway.ceair.com.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">cfau.edu.cn.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="2" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>外交学院</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.cfau.edu.cn.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>tsinghua.edu.cn.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="2" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>清华大学</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.tsinghua.edu.cn.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">nju.edu.cn.81-cn.info</p></section></section></section></td><td colspan="1" rowspan="2" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>南京大学</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.nju.edu.cn.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.hust.edu.cn.81-cn.info</p></section></section></section></td><td colspan="1" rowspan="2" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>华中科技大学</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hust.edu.cn.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">smmu.edu.cn.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="2" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>海军军医大学</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.smmu.edu.cn.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">nudt.edu.cn.81-cn.info </p></section></section></section></td><td colspan="1" rowspan="3" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>国防科技大学</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.nudt.edu.cn.81-cn.info </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail-nudt.sytes.net </p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">pku.edu.cn.81-cn.info</p></section></section></section></td><td colspan="1" rowspan="3" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>北京大学</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">updates.pku.edu.cn.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">events.updates.pku.edu.cn.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="70.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail-cscec.ddns.net</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="26.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p>中国建筑集团</p></section></section></section></td></tr></tbody></table></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">针对性不强及仿冒邮箱登录的域名如下</p></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(228, 93, 47);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;color: rgb(245, 245, 245);"><p><strong>域名</strong></p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">com.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">cn.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">com.cn.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">edu.cn.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">gov.cn.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">login.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">coremail.login.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">cn.coremail.login.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">edu.cn.coremail.login.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">fileserver.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">81-cn.ddns.net</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">cmclient-downloader.serveirc.com</p></section></section></section></td></tr></tbody></table></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">针对巴基斯坦的域名如下</p></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(228, 93, 47);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;color: rgb(245, 245, 245);"><p><strong>域名</strong></p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">pac.gov.pk.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">incidence.pac.gov.pk.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">securityreport.incidence.pac.gov.pk.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">gov.pk.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hit.gov.pk.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.hit.gov.pk.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">gov.pk.login.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mofa.gov.pk.login.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mail.mofa.gov.pk.login.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">pk.81-cn.info</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="96.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-style: solid;border-width: 0px 1px 0px 0px;border-color: rgb(62, 62, 62) rgb(202, 198, 198) rgb(62, 62, 62) rgb(62, 62, 62);align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">pk.login.81-cn.info</p></section></section></section></td></tr></tbody></table></section></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(248, 249, 253);min-width: 10%;flex: 0 0 auto;height: auto;padding: 15px;align-self: flex-start;"><section style="margin: -17px 0% -11px;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 9px 7px 0px;border-color: rgb(251, 133, 129) rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><strong>样本二：DOCX+OLE对象+LNK</strong></p></section></section></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(228, 93, 47);padding-right: 5px;padding-left: 5px;" width="30.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;color: rgb(245, 245, 245);"><p><strong>文件名</strong></p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(228, 93, 47);padding-right: 5px;padding-left: 5px;" width="66.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;color: rgb(245, 245, 245);"><p><strong>Hash</strong></p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="30.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">Scam_Transaction_of_7350_BDT.docx</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="66.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">44f7c5e8855fc2c9a0026183759f99635d7b89eee46dc904d5618123ed217435</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="30.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">Scam_Transaction_of_7350_BDT.pdf.lnk</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding-right: 5px;padding-left: 5px;" width="66.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">623767715bd1a33c41e2de8ab3af341e629105132c3434f454cf249f98adbfd7</p></section></section></section></td></tr></tbody></table></section></section><section style="line-height: 2;"><p style="word-break: break-all;"><span style="font-size: 15px;background-color: rgba(1, 0, 0, 0);">样本二同样上传自孟加拉国，其初始攻击负载是DOCX，文件内容与钓鱼邮件内容相似，均描述了孟加拉塔卡欺诈交易，并请求相关部门追回。</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013555" data-ratio="0.652794292508918" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="841" src="https://wechat2rss.xlab.app/img-proxy/?k=c328e371&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6H42PbGIHEib8nwrF4FgRZKw92V3c1FlccnzeiaPuCOReoowJdgia0HTcQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);font-size: 15px;">DOCX文档中嵌入了Shell.Explorer.1 OLE对象， 此样本中的OLE对象充当嵌入式Internet Explorer，用户双击后将运行远程文件：hxxp://47.76.135.130/microsoft-365-ms/ZONE2/Scam_Transaction_of_7350_BDT.pdf.lnk</span><br/></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013557" data-ratio="0.4636150234741784" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="852" src="https://wechat2rss.xlab.app/img-proxy/?k=cf273ec9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6uykcr9S7EXLDFON29gqiaNqRHOxcyia7dMiaiaLjAicWqKLuv0pVDwHmz5g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);font-size: 15px;">该IP可关联到文件</span><br/></p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;"><section style="min-height: 40px;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">文件名</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">Strengthening of Government Video Conferencing Platform Project (1st Revised) (1).pdf.searchConnector-ms</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">Hash</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">1ca3de5b90d293c3ac0f36da128b513037dda0223096e1026315e97c2793766e</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>URL</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">hxxp://47.76.135.130/dashboard_login/zoomflank</p></section></td></tr></tbody></table></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">该LNK文件同样执行远程Powershell脚本，后下载DLL文件与加密数据，并通过白+黑的方式加载运行</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013554" data-ratio="0.22654155495978553" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="746" src="https://wechat2rss.xlab.app/img-proxy/?k=1c02c51f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6r3Ev22iapwaia25HcBzIpFO7xUx6wib0icWvADML7W3WezRDv4jAFfsgug%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013559" data-ratio="0.3123359580052493" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="762" src="https://wechat2rss.xlab.app/img-proxy/?k=a61e1c53&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6FH7k2S61bwicmBE4icFdCYruxMhMwVlL8y9qLJApuH9C8AtzmDhlU19g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(248, 249, 253);min-width: 10%;flex: 0 0 auto;height: auto;padding: 15px;align-self: flex-start;"><section style="margin: -17px 0% -11px;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 9px 7px 0px;border-color: rgb(251, 133, 129) rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><strong>样本三：针对巴基斯坦的LNK文件</strong></p></section></section></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;"><section style="min-height: 40px;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">文件名</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">CyberNet2025.lnk</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">Hash</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">eebf4a5104d75f8f6536e592d4c7945d56f8431059f2cab980756d9b9e96f0fc</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="18.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>URL</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="82.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">hxxp://wandering-pond-e7f4.foxiproxi.workers.dev/download/BTRC.ps1</p></section></td></tr></tbody></table></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p>我们未捕获到关于此样本的后续文件。</p></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>5</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneGHCaW9bytStwsaBN67ho6lybvjrSpALYCzeqEDuztPrPJnB89Ms7GVYnmcxDM0LlPfPwyV1wJJA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);"><p><strong>活动总结</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">Patchwork组织的攻击活动展现了一定的技术复杂性和针对性。长期以来，该组织不仅针对国内目标，还将攻击范围扩展至南亚地区，利用钓鱼邮件、恶意文档及仿冒域名等多种手段实施攻击。其攻击手法结合了社会工程学、加密技术和多阶段加载策略，成功规避了部分安全检测，显示出较强的隐蔽性和适应性。</p><p style="word-break: break-all;"><br/></p><p style="word-break: break-all;">相关单位需提高警惕，加强对钓鱼邮件、恶意文档及异常网络流量的监测，同时定期更新威胁情报，以有效防御此类高级持续性威胁。</p></section><section style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;isolation: isolate;"><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;"><section style="margin-right: 0%;margin-left: 0%;"><section style="background-color: rgb(214, 60, 60);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;align-self: stretch;height: auto;line-height: 0;"><section style="transform: perspective(0px);transform-style: flat;"><section style="transform: rotateY(180deg);"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: perspective(0px);transform-style: flat;"><section style="transform: rotateX(180deg) rotateY(180deg);"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 auto;align-self: stretch;min-width: 10%;height: auto;background-color: rgb(214, 60, 60);border-width: 0px;"><section style="line-height: 1.4;color: rgb(255, 255, 255);padding-right: 10px;padding-left: 10px;font-size: 12px;"><p><strong>防范建议</strong></p></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;align-self: stretch;height: auto;line-height: 0;"><section style=""><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="transform: perspective(0px);transform-style: flat;"><section style="transform: rotateX(180deg);"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;"><section style="margin-right: 0%;margin-left: 0%;"><section style="background-color: rgb(214, 60, 60);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="text-align: left;"><section style="text-align: justify;font-size: 15px;line-height: 2;"><p style="word-break: break-all;margin-bottom: 15px;">目前安恒信息研究院安全数据部已具备相关威胁检测能力，对应产品已完成IoC情报的集成。针对该事件中的最新IoC情报，以下产品的版本可自动完成更新，若无法自动更新则请联系技术人员手动更新：</p><p style="word-break: break-all;margin-bottom: 15px;">1.   AiLPHA分析平台V5.0.0及以上版本</p><p style="word-break: break-all;margin-bottom: 15px;">2.   APT设备V2.0.67及以上版本</p><p style="word-break: break-all;margin-bottom: 15px;">3.   EDR产品V2.0.17及以上版本</p><p style="word-break: break-all;">安恒云沙盒已集成了该事件中的样本特征。用户可通过云沙盒：<a href="https://ti.dbappsecurity.com.cn/sandbox，对可疑文件进行免费分析，并下载分析报告。" target="_blank">https://ti.dbappsecurity.com.cn/sandbox，对可疑文件进行免费分析，并下载分析报告。</a></p></section></section><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: center;margin-top: 10px;margin-bottom: -10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 30px;height: auto;"><img data-imgfileid="100013558" data-ratio="1.0266666666666666" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="300" src="https://wechat2rss.xlab.app/img-proxy/?k=f21671f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6QW2mA3GiadulJVdylSC30sF5wSGr3C82VeGYo7zWefK1micZ9QItPKWA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-bottom: 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 11px;border-color: rgb(228, 93, 47);padding: 18px 19px 19px;"><section style=""><section style="font-size: 12px;line-height: 2;"><p style="word-break: break-all;"><strong>IOC</strong></p><p>4010952725284d1c5d198f28cc35764d7621590c163bf489791f023592784a53</p><p>hxxps://ados.fyicompsol.xyz/lkasedb_4edsw/hsvdcxsew-3dsw</p><p>hxxps://kens.fyicompsol.xyz/aloetdg_74dfs/asgdneu9_lfd2</p><p>hxxps://rkde.fyicompsol.xyz/jsgdevdw_3ed/hdbdewsq1_sc3</p><p>hxxps://kila.fyicompsol.xyz/kfdgbcws_rf4/dcsxwer32khd_esf</p><p>9f27d7b82a70ba3d8ff1ad9f26acf8245a45cf80fbe0c3cf9f026814167e8dc6</p><p>hxxps://liuyi.neectar.info/hsdverd_3ed5d/mdswsourt_4rfs</p><p>hxxps://tian.neectar.info/lksderdd_4dferd/jhdfer3s_jh3de</p><p>c12deb8079c75ef4b96f4af778fbb811a5c766f0560d57d63d6772fbe76b6b33</p><p>hxxps://hongbaow.info/1WrCVzW4kSDNbNTt/cqWf4vQlofzqFkc7.php</p><p>acbcb6448447ad4a5c0dae7e3e44be5383c3bd6bb246f4889feae4731259bd32</p><p>hxxps://kupes.fourays.info/tgsfdjerpERAF4562_yhfd/kshdjfl</p><p>hxxps://jdkupes.fourays.info/yjsgdjflas845ui/hjksfdgwrepsd</p><p>c526878565f4ef7a95252e910c1ce494fb8ea7a0f80576ea2ad28ad1d5015894</p><p>hxxps://foxinfo.org/1WrCVzW4kSDNbNTt/cqWf4vQlofzqFkc7.php</p><p>207b27f4f17802dc951b6300eaeeaed181ee7567526325f940e66242f54d3add</p><p>hxxps://army-mil.zapto.org/webdav/DH-Report76.pdf.lnk</p><p>hxxp://army-mil.b-cdn.net/onelog.dll</p><p>hxxp://army-mil.b-cdn.net/sppc.dll</p><p>hxxp://army-mil.b-cdn.net/f.ps1</p><p>hxxps://47.250.118.131/</p><p>fe3659fe8ceedc9acbd84eca852f06feeb235e9fe83fa6da2383d17f6e0108c5</p><p>2a09b5f1429eb2b6049e374200cb39d7075dd962098adb6b61b0bafbcee9b487</p><p>b65c9453ee78321defb63ed2ccdffd0e2df3177f12e66185c1ef2e8ba298d800</p><p>909db58a782dfbe605b0e6047b9bd056377deb75d64d0cb9cefbcf11d3195318</p><p>136dd864f5772a6567aff34fcbe6f0665b7cc04b2d486004c370f410bee259b1</p><p>hxxp://uat-updates.gateway.ceair.com.81-cn.info/sspicli.dll</p><p>hxxp://uat-updates.gateway.ceair.com.81-cn.info/windowskernel32.dll</p><p>7498a07f903486473cce83fbf16b88009765af98326e1ebef4c48f103b874f65</p><p>90f43a20a956b5d2e7b73cd3c2a6896a3af032414a297a23d0f07ef2f1016b17</p><p>47.236.170.136</p><p>44f7c5e8855fc2c9a0026183759f99635d7b89eee46dc904d5618123ed217435</p><p>623767715bd1a33c41e2de8ab3af341e629105132c3434f454cf249f98adbfd7</p><p>hxxp://47.76.135.130/microsoft-365-ms/ZONE2/Scam_Transaction_of_7350_BDT.pdf.lnk</p><p>1ca3de5b90d293c3ac0f36da128b513037dda0223096e1026315e97c2793766e</p><p>hxxp://47.76.135.130/dashboard_login/zoomflank</p><p>eebf4a5104d75f8f6536e592d4c7945d56f8431059f2cab980756d9b9e96f0fc</p><p>hxxp://wandering-pond-e7f4.foxiproxi.workers.dev/download/BTRC.ps1</p></section></section></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013562" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=86cd4cca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneGHCaW9bytStwsaBN67ho6z5928cUb3ichgCIghpw2NSzM9VCe0fNZdEn4qu5WqQmpJ9TTedLxSVg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247497213">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c39ba330&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247497213%26idx%3D1%26sn%3D16ee7a8455569f805593d7b89a0d2d73%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 04 Mar 2025 11:19:00 +0800</pubDate>
    </item>
    <item>
      <title>AI明星DeepSeek被“黑化”：恶意软件伪装成热门工具在网络上传播</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247497126&amp;idx=1&amp;sn=f4e87d127c25618c829e4a87e4d53647</link>
      <description>已发生多起！恶意软件仿冒DeepSeek进行传播</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2025-02-12 14:53</span> <span style="display: inline-block;">浙江</span>
</p>

<p>已发生多起！恶意软件仿冒DeepSeek进行传播</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4f4e368d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAbuDibBN2niaZqUBgl0nqG7wPdic9xY4DAicQibPVSkJcU2XywMRg1Qn5ufw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 16px;color: rgb(62, 62, 62);"><section style="margin-right: 0%;margin-left: 0%;"><section style="display: inline-block;width: 100%;border-width: 1px;border-style: solid;border-color: rgba(0, 0, 0, 0);padding: 20px;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013459" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=29a2ae54&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAOZ5xjpeCS1wibkymxe93iafUrWmdTLibykAylXfsxQUuJHctbuNcOSia6g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(181, 220, 234);padding: 4px 13px;min-width: 5%;height: auto;"><section style="text-align: justify;"><p><strong>概述</strong></p></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-bottom: 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgba(193, 214, 243, 0.2);"><section style="transform: perspective(0px);transform-style: flat;"><section style="margin-top: -7px;line-height: 1;transform: rotateX(180deg);"><section style="width: 0px;display: inline-block;border-left: 0.6em solid rgb(181, 220, 234);border-bottom: 0.6em solid rgb(181, 220, 234);border-top: 0.6em solid transparent !important;border-right: 0.6em solid transparent !important;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;margin-bottom: 15px;">DeepSeek作为近期人工智能领域备受关注的热点之一，其软件产品已被攻击者仿冒，或被用作话题诱饵，引诱目标用户运行。攻击者通过仿冒知名软件，更容易获取用户的信任，从而大大提高了恶意软件的传播成功率。</p><p style="word-break: break-all;">近日，安恒猎影实验室发现多起恶意软件仿冒DeepSeek进行传播的事件。攻击者利用DeepSeek在人工智能领域的知名度，通过伪造官方网站、捆绑软件、伪装更新程序等方式，诱导用户下载并安装恶意软件。这些恶意软件会窃取用户数据、破坏系统，甚至植入后门程序，对用户隐私和系统安全构成严重威胁。</p></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>1</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAxyBwEtDfnUyIxPMeqemI8opJumLY5VYTLcibc0zNT6Iz3ZNS1W6xLWg/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>多平台伪装利用</strong></p></section></section></section></section></section></section></section></section></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;"><section style="display: inline-block;width: 22px;height: 35px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 2px 0px 2px 2px;border-color: rgb(13, 80, 199) rgb(97, 163, 246) rgb(13, 80, 199) rgb(13, 80, 199);"><section style="text-align: justify;"><p><br/></p></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;height: auto;margin-right: -10px;margin-left: -10px;"><section style=""><section style="font-size: 15px;text-align: justify;"><p><strong style="text-align: center;">Android平台</strong></p></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;"><section style="display: inline-block;width: 22px;height: 35px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 2px 2px 2px 0px;border-color: rgb(13, 80, 199) rgb(13, 80, 199) rgb(13, 80, 199) rgb(97, 163, 246);"><section style="text-align: justify;"><p><br/></p></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">我们捕获到的运行于Android平台的示例样本信息如下<strong style="background-color: rgba(1, 0, 0, 0);"></strong></p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;"><section style="min-height: 40px;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="text-align: center;font-size: 14px;color: rgb(255, 255, 255);"><p><strong>文件Hash</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="">64ced28d55551ae426f2b9b9cce2403c</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">ITW Url</span></strong><br/></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="">hxxps://deepsek.cfd/DeepSeek.apk</p></section></td></tr></tbody></table></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">程序运行后会提示进行更新操作，实际为执行恶意apk程序安装操作</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013458" data-ratio="0.46153846153846156" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="559" src="https://wechat2rss.xlab.app/img-proxy/?k=112d66ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAFsCtdSgMTJjicGrpvPcrdQhicRLicMad4M6O8vyd8pEKHc5H9YicmTJgFQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">程序首先在Assets目录下查找后缀名为.cat的文件，该cat文件实际为恶意APK文件</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013460" data-ratio="0.6454248366013072" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="612" src="https://wechat2rss.xlab.app/img-proxy/?k=7d410557&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAyIQIaBwpo2kbRngp9VebxXicyibtkEOcjnwb1knkf3LdxaYOyGAoaUZw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013456" data-ratio="0.23962516733601072" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="747" src="https://wechat2rss.xlab.app/img-proxy/?k=ec84e2d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAFERXygLM865odiaf5VhOCQ0SmAUWu1mzdk7gmiaLv1ortAdspFpOmseg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">找到该文件之后，重命名为“verify.apk”，然后进行安装操作，安装的包名为“com.vgsupervision_kit29”。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013457" data-ratio="0.23861566484517305" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="549" src="https://wechat2rss.xlab.app/img-proxy/?k=6dafc066&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpA5AXNQKtXCEkvw6icxQulusUFqrVicbEUoVvCk0qWCrL13sfRNjldHYyg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013464" data-ratio="0.4519832985386221" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="958" src="https://wechat2rss.xlab.app/img-proxy/?k=f41e8536&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAkw4aZXd9RFQ4Q1758QrDCJdUdELPkOlDqWtvj7OxaibtRORSc86TQUA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">成功安装后下次打开本程序会直接打开安装的恶意程序</p></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;border-color: rgb(62, 62, 62);"><img data-imgfileid="100013462" data-ratio="0.1794871794871795" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="819" src="https://wechat2rss.xlab.app/img-proxy/?k=c463bc62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAiaU2VW10RAlib8iaulKzLgP4QoyxVPebrva3Vkbr6QgeJw4OvmYcCMmOQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">恶意程序被安装后仍然伪装为DeepSeek应用程序</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013461" data-ratio="0.6262975778546713" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="289" src="https://wechat2rss.xlab.app/img-proxy/?k=d1fce3af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAhGWqWzBKpnU6uMF8uPQJLhzjkW6yxktib4WdfRK5dd6l2uPTFeXtpnw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">运行后界面显示为DeepSeek官方网站，具有极强的迷惑性</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013465" data-ratio="1.9448275862068964" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="435" src="https://wechat2rss.xlab.app/img-proxy/?k=79e2ec9b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAEPHfbJDDnEZa4jyFoVgJZ8WiaG5EXwRQhrln5E5sH4iaQAXrg2JUoTvg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">而在恶意程序内部申请了多种权限对设备进行全方位的监视</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;border-color: rgb(255, 255, 255);"><img data-imgfileid="100013463" data-ratio="0.5665137614678899" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="872" src="https://wechat2rss.xlab.app/img-proxy/?k=2f546b17&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAJfA3CiaxkV1GR5RxWvk5jJ6jJ1iaPIhnnwbbrCicwQyVuZMT8kJics9McQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">利用这些权限，恶意程序可以对如短信、通知、通话记录、手机联系人、应用信息等敏感内容进行监控并发送至服务器。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013466" data-ratio="0.21294117647058824" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="850" src="https://wechat2rss.xlab.app/img-proxy/?k=abbcbfdb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAuyjzGiaOgx8vWLzfDicSQMrttUs5uuYYOPudem7S6e15R6Beweiatzd3g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013470" data-ratio="0.7964959568733153" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="742" src="https://wechat2rss.xlab.app/img-proxy/?k=e52bc23a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpArHr60ookJHNgLYyd9Ds5dLicDn8ruEB5OYd2KjNoqa23cDgejL9iaw3g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p><br/></p><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">并且与恶意软件进行通信的服务器域名为DGA生成域名</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013469" data-ratio="0.5861182519280206" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="778" src="https://wechat2rss.xlab.app/img-proxy/?k=a2dc6945&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAkMbYicVw2icNichgQdabB2tE6ia21b7vHSEGUILqZISj5Nn1DOYAOQIjyQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p><br/></p><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">此外，该任意软件还具有丰富的指令执行功能，可以远程实现发送短信、键盘记录、启动程序、访问指定链接等等。</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013467" data-ratio="0.7496617050067659" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="739" src="https://wechat2rss.xlab.app/img-proxy/?k=23e27712&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAlDiaUTAGNMWZ0aaCPnm6j5B7U1d434xaROCbgpP4DFlMZmpSwL7Audg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;"><section style="display: inline-block;width: 22px;height: 35px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 2px 0px 2px 2px;border-color: rgb(13, 80, 199) rgb(97, 163, 246) rgb(13, 80, 199) rgb(13, 80, 199);"><section style="text-align: justify;"><p><br/></p></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;height: auto;margin-right: -10px;margin-left: -10px;"><section style=""><section style="text-align: justify;font-size: 15px;"><p><strong style="text-align: center;">Windows平台</strong></p></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;"><section style="display: inline-block;width: 22px;height: 35px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 2px 2px 2px 0px;border-color: rgb(13, 80, 199) rgb(13, 80, 199) rgb(13, 80, 199) rgb(97, 163, 246);"><section style="text-align: justify;"><p><br/></p></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">我们捕获到的运行于Windows平台示例样本信息如下</p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;"><section style="min-height: 40px;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="text-align: center;font-size: 14px;color: rgb(255, 255, 255);"><p><strong>文件Hash</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">2df80283a8c95b24b9c057bc8274c14b</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">文件名</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">DeepSeekSetup.msi</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">ITW URL</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">hxxp://5.61.50.177/files/DeepSeekSetup.msi</p><p style="word-break: break-all;">hxxp://5.61.58.167/files/DeepSeekSetup.msi</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>IP归属地</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">5.61.50.177【荷兰 北荷兰省 阿姆斯特丹】</p><p style="word-break: break-all;">5.61.58.167【荷兰 北荷兰省 阿姆斯特丹】</p></section></td></tr></tbody></table></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">其中MSI安装包中包含恶意DLL文件CZPgtmlLgThm.dll</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013468" data-ratio="0.07733812949640288" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="556" src="https://wechat2rss.xlab.app/img-proxy/?k=5811dcc8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAMFZFribUGKVU3ib9SZvHdPqhH0VAzX4ayDtaa6GM1yAVM2GO7UfsaURA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;margin-bottom: 15px;"><span style="background-color: rgba(1, 0, 0, 0);">经分析，该DLL文件为近期流行的BumbleBee恶意软件加载器，加载器执行后，将在内存加载有效负载，连接远程服务器等待后续指令。</span></p><p style="margin-bottom: 15px;">其IP可关联到其他仿冒OneDrive安装包的攻击活动。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013474" data-ratio="0.1" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=44206b4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAdKRFYVgXJrcEk9ibtBxMUxw4asg0buib5ibI4wA1VHk6teqcKHBPGCgpw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p>另一仿冒DeepSeek的恶意软件如下</p></section><section style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;border-width: 1px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;border-style: solid;border-color: rgb(236, 39, 31);align-self: flex-start;flex: 0 0 auto;"><section style="min-height: 40px;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="text-align: center;font-size: 14px;color: rgb(255, 255, 255);"><p><strong>文件Hash</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">061a8f66ec2f86f9668c0c157ed54b6c</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">文件名</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">deepseek.exe</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">文件图标</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013473" data-ratio="1" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="48" src="https://wechat2rss.xlab.app/img-proxy/?k=100519f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAQibQfsqrTiby9ZD87TuWQjq08RJrBJWhRBiamHvelhDtXS5VKiaD05HQMg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 21px;color: rgb(255, 255, 255);text-align: center;"><p><strong><span style="font-size: 14px;">连接IP</span></strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(249, 235, 230);" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">82.197.67.174</p></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;padding-right: 5px;padding-left: 5px;background-color: rgb(236, 39, 31);" width="25.0000%"><section style="font-size: 14px;color: rgb(255, 255, 255);text-align: center;"><p><strong>IP归属地</strong></p></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;" width="75.0000%"><section style="text-align: justify;font-size: 14px;"><p style="word-break: break-all;">82.197.67.174【美国 纽约州 奥兰治堡】</p></section></td></tr></tbody></table></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">该样本在最初上传到VT平台时，仅有一家安全厂商可检测</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013472" data-ratio="0.2540160642570281" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="996" src="https://wechat2rss.xlab.app/img-proxy/?k=2fe929cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAYfhL6ibOx6MibNjCdF036aF9GtsuxWL8UiaPqiaQBBW7bGiaAX61SG5yI0A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">IP可关联到仿冒SoraAI的应用</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013471" data-ratio="0.13060817547357925" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1003" src="https://wechat2rss.xlab.app/img-proxy/?k=952ea2cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAuSP7GHGLVSfGdSEgjm4icaeLPMnuS1St6sCHDKGUXxvv16zJsvPT9pw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>2</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvndrcT2xZKEWR9dYIJfcVgpAxyBwEtDfnUyIxPMeqemI8opJumLY5VYTLcibc0zNT6Iz3ZNS1W6xLWg/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>防范措施</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">为应对此类威胁，用户应仅从DeepSeek官方渠道下载软件，警惕来源不明的邮件、链接和附件，并安装并定期更新杀毒软件。此次恶意软件仿冒DeepSeek传播事件，反映了网络安全威胁的复杂性和隐蔽性。用户和企业需提高警惕，采取有效措施防范类似攻击。同时，此类事件也为人工智能行业的网络安全防护敲响了警钟，未来需进一步加强技术防范和用户教育。</p></section><p><br/></p><section style="text-align: left;"><section style="text-align: justify;font-size: 15px;line-height: 2;"><p style="word-break: break-all;">目前安全数据部已具备相关威胁检测能力，对应产品已完成IoC情报的集成。针对该事件中的最新IoC情报，以下产品的版本可自动完成更新，若无法自动更新则请联系技术人员手动更新：</p></section></section><p><br/></p><section style="margin-right: 0%;margin-bottom: 10px;margin-left: 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;"><section style="margin: 5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;vertical-align: top;width: 12%;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;text-align: center;font-size: 9px;"><section style="display: inline-block;border-width: 2px;border-style: dotted;border-color: rgb(249, 174, 165);width: 1.6em;height: 1.6em;border-radius: 0.3em;background-color: rgb(249, 174, 165);font-size: 14px;line-height: 1.5em;color: rgb(139, 89, 89);"><p>1</p></section></section></section><section style="display: inline-block;vertical-align: top;width: 88%;padding-left: 5px;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;"><section style="line-height: 2;font-size: 15px;letter-spacing: 1px;"><p style="word-break: break-all;">AiLPHA分析平台V5.0.0及以上版本</p></section></section></section></section><section style="margin: 10px 0% 5px;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;vertical-align: top;width: 12%;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;text-align: center;font-size: 9px;"><section style="display: inline-block;border-width: 2px;border-style: dotted;border-color: rgb(249, 174, 165);width: 1.6em;height: 1.6em;border-radius: 0.3em;background-color: rgb(249, 174, 165);font-size: 14px;line-height: 1.5em;color: rgb(139, 89, 89);"><p>2</p></section></section></section><section style="display: inline-block;vertical-align: top;width: 88%;padding-left: 5px;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;"><section style="line-height: 2;font-size: 14px;letter-spacing: 1px;"><p style="word-break: break-all;">APT设备V2.0.67及以上版本</p></section></section></section></section><section style="margin: 10px 0% 5px;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;vertical-align: top;width: 12%;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;text-align: center;font-size: 9px;"><section style="display: inline-block;border-width: 2px;border-style: dotted;border-color: rgb(249, 174, 165);width: 1.6em;height: 1.6em;border-radius: 0.3em;background-color: rgb(249, 174, 165);font-size: 14px;line-height: 1.5em;color: rgb(139, 89, 89);"><p>3</p></section></section></section><section style="display: inline-block;vertical-align: top;width: 88%;padding-left: 5px;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;"><section style="line-height: 2;font-size: 14px;letter-spacing: 1px;"><p style="word-break: break-all;">EDR产品V2.0.17及以上版本</p></section></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;margin-top: 20px;margin-bottom: 20px;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: middle;min-width: 10%;flex: 0 0 auto;height: auto;background-color: rgb(225, 40, 47);padding: 7px;align-self: center;"><section style=""><section style="color: rgb(255, 255, 255);text-align: justify;font-size: 14px;line-height: 2;letter-spacing: 1px;padding-right: 10px;padding-left: 10px;"><p> ● 安恒云沙盒已集成了该事件中的样本特征：</p></section></section><section style="transform: perspective(0px);transform-style: flat;"><section style="transform: rotateX(180deg);margin-top: -4px;margin-bottom: -19px;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 15px 0px 0px 12px;border-color: rgba(231, 83, 54, 0) rgba(231, 83, 54, 0) rgba(231, 83, 54, 0) rgb(225, 40, 47);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="text-align: left;"><section style="padding-right: 10px;padding-left: 10px;text-align: justify;font-size: 14px;line-height: 2;letter-spacing: 1px;"><p>      用户可通过云沙盒：</p><p><a href="https://sandbox.dbappsecurity.com.cn/" target="_blank">https://sandbox.dbappsecurity.com.cn/</a><span style="background-color: rgba(1, 0, 0, 0);">，对可疑文件进行免费分析，并下载分析报告。</span></p></section></section><section style="text-align: left;justify-content: flex-start;margin-top: 20px;margin-bottom: 20px;display: flex;flex-flow: row;transform: translate3d(10px, 0px, 0px);"><section style="display: inline-block;width: auto;vertical-align: middle;min-width: 10%;flex: 0 0 auto;height: auto;background-color: rgb(225, 40, 47);padding: 7px;align-self: center;"><section style=""><section style="color: rgb(255, 255, 255);text-align: justify;"><p> ● IOC：</p></section></section><section style="transform: perspective(0px);transform-style: flat;"><section style="transform: rotateX(180deg);margin-top: -4px;margin-bottom: -19px;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 15px 0px 0px 12px;border-color: rgba(231, 83, 54, 0) rgba(231, 83, 54, 0) rgba(231, 83, 54, 0) rgb(225, 40, 47);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">64ced28d55551ae426f2b9b9cce2403c</p><p style="word-break: break-all;">hxxps://deepsek.cfd/DeepSeek.apk</p><p style="word-break: break-all;">2df80283a8c95b24b9c057bc8274c14b</p><p style="word-break: break-all;">hxxp://5.61.50.177/files/DeepSeekSetup.msi</p><p style="word-break: break-all;">hxxp://5.61.58.167/files/DeepSeekSetup.msi</p><p style="word-break: break-all;">061a8f66ec2f86f9668c0c157ed54b6c</p><p style="word-break: break-all;">82.197.67.174</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013475" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=c5e851fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvndrcT2xZKEWR9dYIJfcVgpACWdolyDCUFDQJXLtIFrJPj6I5EJibiayIvTgSictTx244zuXwlPqfNtcw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247497126">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f387855d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247497126%26idx%3D1%26sn%3Df4e87d127c25618c829e4a87e4d53647%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 12 Feb 2025 14:53:00 +0800</pubDate>
    </item>
    <item>
      <title>《2024年度漏洞态势分析报告》重磅出炉！文末扫码下载</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247497075&amp;idx=1&amp;sn=1d041504e40dfbb400c230c0dcbb1bd0</link>
      <description>全年漏洞数据的关键特征回顾，网络漏洞的发展趋势以及潜在风险点</description>
      <content:encoded><![CDATA[<p>
<span>安恒信息</span> <span>2025-01-07 09:06</span> <span style="display: inline-block;">浙江</span>
</p>

<p>全年漏洞数据的关键特征回顾，网络漏洞的发展趋势以及潜在风险点</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5887b7f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvndYtHibLX1DTfLShMh6TVz2AcqI9VcN5QVa66tGGJzJ0ev4ksoTBACLnsA9bZVicGyywGCyhwjJXVHw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><img class="rich_pages wxw-img js_darkmode__0" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="161" data-imgfileid="100013405" data-ratio="0.2777777777777778" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: var(--articleFontsize);letter-spacing: 0.578px;color: rgb(255, 255, 255);text-align: center;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;width: 577.995px !important;visibility: visible !important;" data-type="other" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=62dbd02b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3wcAnwz5Wia43nYlGWM5teehx8nTITl8WiaLUlBafQibbzm2ibkia8ZhLo1icjMQ4EU9D9kv0C42ANobAwg%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-size: 15px;line-height: 2;color: rgb(62, 62, 62);visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;outline: 0px;text-align: center;line-height: 0;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 677px;height: auto;visibility: visible;"><img class="rich_pages wxw-img" data-imgfileid="100013407" data-ratio="0.086" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 676.992px !important;visibility: visible !important;" data-type="png" data-w="500" src="https://wechat2rss.xlab.app/img-proxy/?k=e87e1c18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZagPVkzy7dgaXLDLtTiaxkhJiaKRClOqiakO3s0mpjF3ia0PPOofYhfeibxw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="-webkit-tap-highlight-color: transparent;margin-top: -1px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;visibility: visible;"><section data-lazy-bgimg="https://mmbiz.qpic.cn/sz_mmbiz_png/icVz8RbowK3zuHReTScEmWRaqWrcRjC4ZCpKafDvKHVDVEG6IZLTzfDc2LaM5qmDLk7Ye5OYwCgZKRujA3b0T1A/640?wx_fmt=png&amp;from=appmsg" data-fail="0" style="-webkit-tap-highlight-color: transparent;padding-right: 32px;padding-bottom: 27px;padding-left: 36px;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icVz8RbowK3zuHReTScEmWRaqWrcRjC4ZCpKafDvKHVDVEG6IZLTzfDc2LaM5qmDLk7Ye5OYwCgZKRujA3b0T1A/640?wx_fmt=png&#34;);background-position: 50% 50%;visibility: visible;background-size: 100% 100% !important;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;">随着网络空间应用的普及，网络安全面临的挑战也日益复杂且严峻。安恒研究院基于对2024年度漏洞数据的全面统计与深入分析，倾力推出<strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);visibility: visible;">《</span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;letter-spacing: 0.034em;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);letter-spacing: 0.578px;text-decoration-style: solid;text-decoration-color: rgb(190, 28, 18);visibility: visible;">2024年度漏洞态势分析报告</span></strong><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.034em;visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);visibility: visible;">》（以下简称“报告”）。</span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.034em;visibility: visible;">该漏洞报告全面回顾全年漏洞数据的关键特征，全方位解析网络漏洞的发展趋势以及潜在风险点。</span></p></section></section></section></section><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 677px;height: auto;visibility: visible;"><img class="rich_pages wxw-img" data-imgfileid="100013406" data-ratio="0.084" data-s="300,640" data-type="png" data-w="500" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 676.992px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=72b3d518&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4Z0zKT1d9AjfrsEiaaXmHWicDzTicib2RsoY3UibbG3eXjOk92sLfia0RWLStw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"/></p><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;width: 677px;flex-flow: column;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;z-index: 1;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: -9px;outline: 0px;text-align: center;line-height: 0;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 24px;height: auto;visibility: visible;"><img class="rich_pages wxw-img" data-imgfileid="100013403" data-ratio="1.0266666666666666" data-s="300,640" data-type="png" data-w="300" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 23.9974px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9689b287&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZHOR84u9mB8Fuw2PyIaKgRMqwF4hT8Z1VMH8m1OvzNU3XygvDZCPFSQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section></section></section><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;padding: 10px 18px;outline: 0px;display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgba(254, 229, 189, 0.48);min-width: 5%;height: auto;border-radius: 107px;overflow: hidden;visibility: visible;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(249, 141, 32);visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;">2024年度漏洞数据统计与分析</strong></p></section></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;">报告从主流漏洞库入手，<strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);">对公开披露的漏洞数据进行系统梳理，</span></strong>包括总体数量、各危害等级漏洞数据统计、厂商分布等内容，揭示漏洞数量的变化趋势，以及漏洞等级分布情况、漏洞产生原因以及漏洞背后可能带来的安全隐患。</p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;text-align: center;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.292px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100013404" data-ratio="0.5689455388180765" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 609.284px !important;visibility: visible !important;" data-type="png" data-w="863" src="https://wechat2rss.xlab.app/img-proxy/?k=dc7a70d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4Ziaic5xFdxd5Jbjg0tWPrbd3aa92tszart6L0jNqSlNaNONVibbp4uZNRg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;">已公开披露漏洞数据等级分布</p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;">通过对漏洞产生原因数据的统计与分析，安恒研究院发现随着软件系统复杂性和规模的增加，<strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);">安全问题会更多地出现在设计阶段，</span></strong>设计错误的比例可能进一步上升。</p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;text-align: center;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.292px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100013411" data-ratio="0.5365853658536586" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 609.284px !important;visibility: visible !important;" data-type="png" data-w="820" src="https://wechat2rss.xlab.app/img-proxy/?k=56c98933&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZeZMdZDgIScNnbVwBwFHBv94Q05AOqSFpy8WmHLiaw6StTgsjYbxe7Nw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;">2024年度漏洞产生原因分布（注：数据来源CNVD）</p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;">从上述漏洞产生原因分布图中可以得出设计阶段问题占主导，<strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);">设计错误占比高反映出系统在早期设计阶段缺乏全面考量，</span></strong>导致系统开发阶段未对安全问题进行重视出现较多漏洞。</p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;">其次输入问题较多，<strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);">开发人员在编码过程中对用户输入缺乏严格处理，</span></strong>而这类输入问题漏洞通常是攻击者的突破口。报告在基于这些已公开披露的漏洞数据的基础上，对未来可能面临的网络安全风险点进行了预测与漏洞趋势分析。</p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;width: 677px;flex-flow: column;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;z-index: 1;"><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: -9px;outline: 0px;text-align: center;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 24px;height: auto;"><img data-imgfileid="100013410" data-ratio="1.0266666666666666" data-s="300,640" data-type="png" data-w="300" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 23.9974px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9689b287&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZHOR84u9mB8Fuw2PyIaKgRMqwF4hT8Z1VMH8m1OvzNU3XygvDZCPFSQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section></section></section><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="-webkit-tap-highlight-color: transparent;padding: 10px 18px;outline: 0px;display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgba(254, 229, 189, 0.48);min-width: 5%;height: auto;border-radius: 107px;overflow: hidden;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(249, 141, 32);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;">2024年度CWE排行榜解读</strong></p></section></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;word-break: break-all;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);">报告中对2024年度CWE Top25榜单进行了深度解读，</span></strong>从各漏洞类型的排名浮动出发，对当下网络安全的威胁分布进行了详尽分析。</p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.292px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100013409" data-ratio="1.1025299600532623" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 609.284px !important;visibility: visible !important;" data-type="png" data-w="751" src="https://wechat2rss.xlab.app/img-proxy/?k=b76d8409&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZkT9SKSe0E4ox1C53CBjc5BF70JDO5tnzLOp3mjsfV75e3qjzRm6q6A%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.292px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100013412" data-ratio="0.6949152542372882" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 609.284px !important;visibility: visible !important;" data-type="png" data-w="767" src="https://wechat2rss.xlab.app/img-proxy/?k=4fec3a4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4Z1xW77fUYlEp74MJm6IyoRsMvWpE7K64h3WiavO4fibaftBAohlP88V9A%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;">2024年度CWE Top25排行榜单</p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;width: 677px;flex-flow: column;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;z-index: 1;"><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: -9px;outline: 0px;text-align: center;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 24px;height: auto;"><img data-imgfileid="100013408" data-ratio="1.0266666666666666" data-s="300,640" data-type="png" data-w="300" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 23.9974px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9689b287&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZHOR84u9mB8Fuw2PyIaKgRMqwF4hT8Z1VMH8m1OvzNU3XygvDZCPFSQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section></section></section><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="-webkit-tap-highlight-color: transparent;padding: 10px 18px;outline: 0px;display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgba(254, 229, 189, 0.48);min-width: 5%;height: auto;border-radius: 107px;overflow: hidden;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(249, 141, 32);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;">2024年度漏洞预警回顾</strong></p></section></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;">报告对安恒信息CERT2024年度漏洞预警数据进行回顾与统计，并从中提取出年度严重漏洞。</p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;">1.GitLab存在任意密码重置漏洞（CVE-2023-7028|DM-202312-003214）</strong></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;">用户帐户密码重置电子邮件可以发送到未经验证的电子邮件地址，攻击者可将重置帐户密码的邮件发送到未经验证的邮箱，在无需用户交互的情况下通过密码重置进行帐户接管。</p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;">2.GeoServer存在远程代码执行漏洞（CVE-2024-36401|DM-202405-004663）</strong></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;">由于不安全地将属性名称评估为XPath表达式，多个OGC请求参数允许未经身份验证的用户通过针对默认 GeoServer 安装的特制输入执行任意代码。</p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);">3.VMware vCenter Server堆溢出漏洞（CVE-2024-37079|DM-202406-000059）</span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;">具有vCenter Server网络访问权限的攻击者能够通过发送特制的数据包来触发该漏洞，从而可能导致远程代码执行。</p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;">......</p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.034em;">基于上述数据对预警漏洞类型的分布进行统计与趋势预测，并总结了未来需要着重关注的漏洞利用类型。</span></p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;width: 677px;flex-flow: column;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;z-index: 1;"><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: -9px;outline: 0px;text-align: center;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 24px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100013417" data-ratio="1.0266666666666666" data-s="300,640" data-type="png" data-w="300" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 23.9974px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9689b287&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZHOR84u9mB8Fuw2PyIaKgRMqwF4hT8Z1VMH8m1OvzNU3XygvDZCPFSQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section></section></section><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="-webkit-tap-highlight-color: transparent;padding: 10px 18px;outline: 0px;display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgba(254, 229, 189, 0.48);min-width: 5%;height: auto;border-radius: 107px;overflow: hidden;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(249, 141, 32);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;">2024年攻防演练高危漏洞回顾</strong></p></section></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;">2024年攻防演练期间，安恒信息CERT对在野漏洞进行了全面监测，新增在野漏洞档案共计227条，其中一级漏洞档案114条，二级漏洞档案111条，经研判后，累计对111个漏洞发布漏洞预警，<strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);">报告基于上述数据整理了2024年度攻防演练期间常见的漏洞类型分布概况。</span></strong></p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;text-align: center;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.292px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100013415" data-ratio="0.5689455388180765" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 609.284px !important;visibility: visible !important;" data-type="png" data-w="863" src="https://wechat2rss.xlab.app/img-proxy/?k=01356593&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZU7N75ibAkLCgFfctM70U8IGI4nozibcIOCGAQDzmcV0SJZtH3ZUUnSOg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;">2024年度攻防演练在野漏洞预警类型分布</p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;width: 677px;flex-flow: column;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;z-index: 1;"><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: -9px;outline: 0px;text-align: center;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 24px;height: auto;"><img data-imgfileid="100013414" data-ratio="1.0266666666666666" data-s="300,640" data-type="png" data-w="300" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 23.9974px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9689b287&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZHOR84u9mB8Fuw2PyIaKgRMqwF4hT8Z1VMH8m1OvzNU3XygvDZCPFSQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section></section></section><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="-webkit-tap-highlight-color: transparent;padding: 10px 18px;outline: 0px;display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgba(254, 229, 189, 0.48);min-width: 5%;height: auto;border-radius: 107px;overflow: hidden;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(249, 141, 32);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;">AI安全隐患与未来趋势分析</strong></p></section></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 15px;outline: 0px;word-break: break-all;">近年来，人工智能技术以飞快的步伐不断进步，以大模型为基础的各种技术应用的兴起，也为计算机安全领域带来了诸多新的风险和挑战，<strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);">模型安全性也因此成为了人工智能安全的关键构成部分。</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;word-break: break-all;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(190, 28, 18);">本报告对2024年度较为高危的LLM漏洞进行了整理，</span></strong>并对OWASP LLM Top10安全威胁展开详尽解读与举例，罗列了LLM应用过程中可能面临的风险场景，并给出了可靠的LLM安全治理框架建设建议供用户参考。</p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013416" data-ratio="0.3800403225806452" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 676.992px !important;visibility: visible !important;" data-type="png" data-w="992" src="https://wechat2rss.xlab.app/img-proxy/?k=3e5814d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZhMupibZrOULNUJia7fOH9qzDGIcqZ6N9CPCphFJ7YzL2UFodSTFnUJog%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013413" data-ratio="0.16330645161290322" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 676.992px !important;visibility: visible !important;" data-type="png" data-w="992" src="https://wechat2rss.xlab.app/img-proxy/?k=aa58a18f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZWpJvBzPicBrRz8l8WP6l9oAAO04D9xp4H5Kk4UiczgOtQXTicxvHPUOicw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;font-size: 12px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;">OWASP Top10排行</p></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(246, 243, 255);"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><section data-lazy-bgimg="https://mmbiz.qpic.cn/sz_mmbiz_png/icVz8RbowK3zuHReTScEmWRaqWrcRjC4ZBrLEkaWtKGEzdkc0lUXv3I1k7iaibSdb5ZlVYlZlARTuMp1NYrm5766g/640?wx_fmt=png&amp;from=appmsg" data-fail="0" style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: repeat-x;background-attachment: scroll;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icVz8RbowK3zuHReTScEmWRaqWrcRjC4ZBrLEkaWtKGEzdkc0lUXv3I1k7iaibSdb5ZlVYlZlARTuMp1NYrm5766g/640?wx_fmt=png&#34;);background-position: 0% 0%;background-size: auto 14.8342% !important;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;"><section style="-webkit-tap-highlight-color: transparent;padding: 21px;outline: 0px;display: inline-block;width: 677px;vertical-align: top;align-self: flex-start;flex: 0 0 auto;"><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="-webkit-tap-highlight-color: transparent;padding-right: 10px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;border-style: solid;border-width: 0px 1px 0px 0px;border-right-color: rgb(70, 127, 244);align-self: center;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(70, 127, 244);"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;">下载方式</strong></p></section></section><section style="-webkit-tap-highlight-color: transparent;padding-left: 9px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;height: auto;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(70, 127, 244);font-size: 12px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 2em;text-align: justify;text-indent: 0em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(70, 127, 244);font-size: 12px;letter-spacing: 0.578px;">2024年度漏洞态势分析报告</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(70, 127, 244);font-size: 12px;letter-spacing: 0.034em;"></span></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(70, 127, 244);font-size: 12px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p></section></section></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: center;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;">扫描下方二维码，即可下载查看报告全文！</p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="color: rgb(255, 0, 0);"><strong>亦可点击</strong></span><span style="color: rgb(255, 0, 0);text-decoration: underline;"><strong>原文链接</strong></span><span style="color: rgb(255, 0, 0);"><strong>，前往</strong></span><span style="color: rgb(255, 0, 0);text-decoration: underline;"><strong>安全星图平台</strong></span><span style="color: rgb(255, 0, 0);"><strong>直接在</strong></span><span style="color: rgb(255, 0, 0);text-decoration: underline;"><strong>文末下载</strong></span></p></section><section style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br/></p></section><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 20px;outline: 0px;text-align: center;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 317.5px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100013420" data-ratio="1" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 317.5px !important;visibility: visible !important;" data-type="png" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=1caf628d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4Z3ywk0KCWWLX49CStYkxVKFAIHT38CfEDMc9tKNfjyLAqtqiafc4Yx9w%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section></section></section><section style="-webkit-tap-highlight-color: transparent;margin-top: -16px;outline: 0px;line-height: 0;"><section style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013419" data-ratio="0.16004540295119182" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;width: 676.992px !important;visibility: visible !important;" data-type="png" data-w="881" src="https://wechat2rss.xlab.app/img-proxy/?k=1729f39e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3zuHReTScEmWRaqWrcRjC4ZKkS0ho3Y5LHlPLSGfwSxsd6opEWI9iceHaaianEuiba19P3iaRia9QyToKA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section></section></section></section></section><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;"><br style="-webkit-tap-highlight-color: transparent;outline: 0px;"/></p></section><section style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;color: rgb(62, 62, 62);font-size: 15px;letter-spacing: 0.578px;text-align: left;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);line-height: 2;"><section style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><img class="rich_pages wxw-img __bg_gif" data-imgfileid="100013422" data-ratio="1" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;letter-spacing: 0.544px;caret-color: rgba(0, 0, 0, 0);font-family: system-ui, -apple-system, system-ui, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;visibility: visible !important;width: 240px !important;" data-type="gif" data-w="240" src="https://wechat2rss.xlab.app/img-proxy/?k=2e77adf5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FicVz8RbowK3yEfgqaJ4nxoES6ggmVq7icUa5WvlGfMttCbpAPMkSMR3BZXmYLJRhVoxSoxhiaXPticcr2PiaibWAScOQ%2F640%3Fwx_fmt%3Dgif%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp"/></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://starmap.dbappsecurity.com.cn/info/9559">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5dcc4dae&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247497075%26idx%3D1%26sn%3D1d041504e40dfbb400c230c0dcbb1bd0%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 07 Jan 2025 09:06:00 +0800</pubDate>
    </item>
    <item>
      <title>以研发计划为诱饵，Patchwork组织近期针对国内的攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247497001&amp;idx=1&amp;sn=bf11de770fea2d96d4f3c08dfd7e038f</link>
      <description>猎影实验室捕获到Patchwork组织，针对国内科研相关的工作人员的钓鱼攻击。</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2024-12-04 11:01</span> <span style="display: inline-block;">浙江</span>
</p>

<p>猎影实验室捕获到Patchwork组织，针对国内科研相关的工作人员的钓鱼攻击。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=79f107d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FVZJndD7xbnNiatNryCIGS5LwnnibXpM9icSUILE9M3hT1noqUKeIjVzGg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 16px;color: rgb(62, 62, 62);"><section style="margin-right: 0%;margin-left: 0%;"><section style="display: inline-block;width: 100%;border-width: 1px;border-style: solid;border-color: rgba(0, 0, 0, 0);padding: 20px;box-shadow: rgba(0, 0, 0, 0) 0px 0px 0px;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013321" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=22a5e0b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7F5QPSJohp8eqDUg5GckkzXoI028R5E16ZNFEAIgYBxyfgKP21ErVlBA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>1</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FRdL6apdEfULx6dB4oSldicDZLqodQ9sVbPyZ3WmdTfmeGib9AIDKCOdA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>概述</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;margin-bottom: 15px;text-indent: 2em;">Patchwork组织又名Hangover、Dropping Elephant，最早披露于2013年。最早攻击活动可以追溯到2009年，主要针对中国、巴基斯坦等亚洲地区和国家进行网络间谍活动。在针对中国地区的攻击中，其主要针对政府机构、科研教育领域进行攻击。具有Windows、Android、macOS 多系统攻击的能力。</p><p style="word-break: break-all;margin-bottom: 15px;text-indent: 2em;">近日，安恒猎影实验室在日常威胁情报狩猎中捕获了Patchwork APT组织的攻击样本，相关样本以“国家重点研发计划‘工程科学与综合交叉’重点专项 2025项目指南建议表”为话题，针对国内科研相关的工作人员进行钓鱼攻击。</p><p style="word-break: break-all;text-indent: 2em;">相关攻击活动以LNK文件作为初始攻击负载，引诱目标运行后，将下载PDF文件及EXE、DLL文件到本地，自动打开PDF文件以降低目标防备心理，并设置计划任务运行白文件。白文件运行后加载恶意DLL文件，在内存中多次解密加载执行Patchwork组织特马BadNews。此外我们发现该组织域名仿冒多个正常网站。</p></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(62, 62, 62);background-color: rgb(62, 62, 62);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>2</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FRdL6apdEfULx6dB4oSldicDZLqodQ9sVbPyZ3WmdTfmeGib9AIDKCOdA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;"><p><strong>样本诱饵</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">本次捕获样本释放到本地的诱饵文件如下，内容为“国家重点研发计划‘工程科学与综合交叉’重点专项 2025项目指南建议表”</p></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;border-color: rgb(62, 62, 62);"><img class="rich_pages wxw-img" data-imgfileid="100013323" data-ratio="0.575" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f2744cb4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FNz9beF5iaDyTUoPsBvCFHWia7zPK9BjicMibNiaBvEibicmgCRqm8xRMK2a6g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 14px;line-height: 2;"><p style="word-break: break-all;"><span style="font-size: 15px;background-color: rgba(1, 0, 0, 0);">关联到的其他样本释放诱饵文件主题如下为巴基斯坦国际航空有限公司伊斯兰堡售票处内部审计情况</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: double;border-width: 2px;border-color: rgb(255, 255, 255);"><img data-imgfileid="100013322" data-ratio="0.7" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7142ab6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7Fnjtx9hRke2BPR3yuuJgibdOzzw5q5hyGpWwJrEYyVgKnRQoQibNu5ib2A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 14px;line-height: 2;"><p style="word-break: break-all;"><span style="font-size: 15px;">另一诱饵文件为：巴基斯坦第一大数据和通信网络提供商Zong的登录ID及密码</span><br/></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 2px;border-color: rgb(255, 255, 255);"><img data-imgfileid="100013319" data-ratio="0.23553162853297444" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="743" src="https://wechat2rss.xlab.app/img-proxy/?k=7f6932d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FictY1XY21Em38fE3UIWQ5WtYBjN01iahsmmaziacdsfumfVJ7ZibpKKYibg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>3</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FRdL6apdEfULx6dB4oSldicDZLqodQ9sVbPyZ3WmdTfmeGib9AIDKCOdA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);"><p><strong>攻击流程</strong></p></section></section></section></section></section></section></section></section></section></section><section style="line-height: 2;"><p><span style="font-size: 15px;background-color: rgba(1, 0, 0, 0);">原始样本为LNK文件，执行后攻击流程如下：</span></p></section><section style="margin-right: 0%;margin-bottom: 10px;margin-left: 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;"><section style="margin: 5px 0%;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;vertical-align: top;width: 12%;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;text-align: center;font-size: 9px;"><section style="display: inline-block;border-width: 2px;border-style: dotted;border-color: rgb(249, 174, 165);width: 1.6em;height: 1.6em;border-radius: 0.3em;background-color: rgb(249, 174, 165);font-size: 14px;line-height: 1.5em;color: rgb(139, 89, 89);"><p>1</p></section></section></section><section style="display: inline-block;vertical-align: top;width: 88%;padding-left: 5px;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;"><section style="line-height: 2;font-size: 15px;"><p style="word-break: break-all;">文件运行后使用Invoke-WebRequest命令分别从指定的URL下载PDF及EXE/DLL文件，并将其保存到指定的本地路径（具体URL见附录IOC）；</p></section></section></section></section><section style="margin: 10px 0% 5px;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;vertical-align: top;width: 12%;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;text-align: center;font-size: 9px;"><section style="display: inline-block;border-width: 2px;border-style: dotted;border-color: rgb(249, 174, 165);width: 1.6em;height: 1.6em;border-radius: 0.3em;background-color: rgb(249, 174, 165);font-size: 14px;line-height: 1.5em;color: rgb(139, 89, 89);"><p>2</p></section></section></section><section style="display: inline-block;vertical-align: top;width: 88%;padding-left: 5px;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;"><section style="line-height: 2;font-size: 15px;"><p style="word-break: break-all;">运行PDF文件并复制PE文件到指定目录，复制PDF文件到当前目录；</p></section></section></section></section><section style="margin: 10px 0% 5px;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;vertical-align: top;width: 12%;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;text-align: center;font-size: 9px;"><section style="display: inline-block;border-width: 2px;border-style: dotted;border-color: rgb(249, 174, 165);width: 1.6em;height: 1.6em;border-radius: 0.3em;background-color: rgb(249, 174, 165);font-size: 14px;line-height: 1.5em;color: rgb(139, 89, 89);"><p>3</p></section></section></section><section style="display: inline-block;vertical-align: top;width: 88%;padding-left: 5px;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;"><section style="line-height: 2;font-size: 15px;"><p style="word-break: break-all;">创建名为WinUpdate的计划任务以运行后续负载；</p></section></section></section></section></section></section><section style="margin: 10px 0% 5px;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;vertical-align: top;width: 12%;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;text-align: center;font-size: 9px;"><section style="display: inline-block;border-width: 2px;border-style: dotted;border-color: rgb(249, 174, 165);width: 1.6em;height: 1.6em;border-radius: 0.3em;background-color: rgb(249, 174, 165);font-size: 14px;line-height: 1.5em;color: rgb(139, 89, 89);"><p>4</p></section></section></section><section style="display: inline-block;vertical-align: top;width: 88%;padding-left: 5px;align-self: flex-start;flex: 0 0 auto;"><section style="margin-right: 0%;margin-left: 0%;"><section style="line-height: 2;font-size: 15px;"><p style="word-break: break-all;">删除运行过程中产生的中间文件。</p></section></section></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img data-imgfileid="100013320" data-ratio="0.12186788154897495" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="878" src="https://wechat2rss.xlab.app/img-proxy/?k=65095040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7F9v9QyzukH82pnkeZrGQuj6X17GzfV8jo1k3mS8WbbDO0STv7gCysiag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;margin-bottom: 15px;"><span style="background-color: rgba(1, 0, 0, 0);">下载的可执行文件将通过白+黑的方式加载恶意DLL文件。白文件和恶意DLL文件包含的证书信息分别如下：其中恶意DLL文件的证书早在今年3月的攻击活动就曾被Patchwork组织使用过。</span></p></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section style="display: inline-block;vertical-align: top;width: 50%;align-self: flex-start;flex: 0 0 auto;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013324" data-ratio="1.0168674698795181" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="415" src="https://wechat2rss.xlab.app/img-proxy/?k=a6158d59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FiaNJ2nToFfdOsaBzANhPZd15NHKe6JDSIwTCnYico6YCDC0sOpTBwsmg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section></section><section style="display: inline-block;vertical-align: top;width: 50%;align-self: flex-start;flex: 0 0 auto;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013328" data-ratio="1.0242718446601942" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="412" src="https://wechat2rss.xlab.app/img-proxy/?k=74952390&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FXerw7cPdObHOh0iaKjUiaQ6lhQYOJRtD9182cqPHjOSZjCQd9DFOIzcQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">DLL文件被加载之后，将从自身读取一段数据解密为Shellcode，通过创建新线程加载</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013325" data-ratio="0.4666666666666667" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=eb28b9db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7F8vpwgSsdX3mrAu73aXO29JKyP33lMhkzpGdorQ4kjcAHeMDkMRQ7xw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">Shellcode执行后会在内存中再次解密出一个PE文件</span><br/></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013327" data-ratio="0.8951612903225806" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="868" src="https://wechat2rss.xlab.app/img-proxy/?k=841d1d6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7Fwzn7j9ibx8FLnsZUoo7Xo0ibJ2xXXVxYeR5hcFpqaBKrwAL9Wyw8hInA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">然后通过复制、抹去文件头等操作，最后在内存中加载</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013326" data-ratio="0.5822784810126582" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="869" src="https://wechat2rss.xlab.app/img-proxy/?k=1ddec906&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7Fv4RScGmfsrb0Kz6KlptCtRUTIaspu42tZiaChEAbMzJwR1NHDh9EbQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">最后在内存中加载的Shellcode实际是Patchwork组织的常用特马BadNews。该负载运行后首先创建名为&#34;gqfffhj&#34;的互斥体</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013330" data-ratio="0.10804597701149425" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=029875ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FjSDrZepojMFa6udqKSf47JsYDgN0NxEUfk1iadFbFqAb0ZrWwjrZ3FA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">获取UUID，根据UUID和文件路径编码生成字符串</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013331" data-ratio="0.08850574712643679" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=2c1765ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FHPUAgQNicgq47nXGiaF7ic9ZxCoet75ymJk5G5Zlj9lmuxdIXccq8g6dg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p>获取操作系统版本，重复上述操作</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013333" data-ratio="0.1377726750861079" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="871" src="https://wechat2rss.xlab.app/img-proxy/?k=5108c224&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FIEDBd1Y7dnr7eglPd0ZkOssgH2XDE4BCexJiatVD7iaIGxH4XDicR8MZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">获取其他信息，如UserName、内外网IP及IP所在国家，依据获取到的信息+文件路径进行两次编码加密</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013329" data-ratio="0.17701149425287357" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=f489eb97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7F4YBmKpyORg5ufoRzU2fTDpkzvFXZI475z5NqLj2luzvHjSgAia23nFQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p>将所有加密后的信息拼接</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013332" data-ratio="0.47701149425287354" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=1e153f0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7Ffia7U81nvibs4bebaAGwVtlu7kgLS6X47KdjuDwvtXJevAUXIXicMiahyQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">以POST的方式发送至C2：hxxps://weixein.info/1WrCVzW4kSDNbNTt/cqWf4vQlofzqFkc7.php</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013338" data-ratio="0.14942528735632185" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=dd194d70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7F6eLDxAkvfo8ibq8jeZH4gz49FjCm8c5AUOgfq4knRreic7IaPCnjSefg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013334" data-ratio="0.21954022988505748" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=33c82c9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FmJX9704kZfqib29mH0XBMS3fa00sHKccON2iaVnHCyVTuYF351Kq6lZg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img data-imgfileid="100013335" data-ratio="0.18735632183908046" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=04c74c86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FXjJNsicCMmiapEFtXwYU42SCgu8pVcCNgkricB7x1icvoqd8Y8WIEo8jTw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">C2返回指令以&#34;$&#34;符分割，包含的部分指令及功能如下</span><br/></p></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-top-style: none;border-bottom-style: none;border-left-style: none;background-color: rgb(236, 84, 11);" width="33.0000%"><section style="margin: 5px 0%;"><section style="text-align: center;padding-right: 5px;padding-left: 5px;font-size: 12px;color: rgb(255, 255, 255);"><p>指令</p></section></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62) rgb(255, 255, 255) rgb(62, 62, 62) rgb(62, 62, 62);border-top-style: none;border-bottom-style: none;border-left-style: none;background-color: rgb(236, 84, 11);" width="66.8100%"><section style="margin: 5px 0%;"><section style="text-align: center;padding-right: 5px;padding-left: 5px;font-size: 12px;color: rgb(255, 255, 255);"><p>含义</p></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">3hdfghd1</p></section></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">读取指定文件，加密后上传至C2</p></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-width: 0px;border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(248, 243, 240);padding: 3px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">3gjdfghj6</p></section></section></td><td colspan="1" rowspan="1" style="border-width: 0px;border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(248, 243, 240);padding: 3px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">创建cmd进程执行指定指令，并将执行结果加密上传</p></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">3fgjfhg4</p></section></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">遍历文件及目录</p></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(248, 243, 240);padding: 3px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">3gnfjhk7</p></section></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(248, 243, 240);padding: 3px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">从指定URL下载后续负载保存到本地执行</p></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">3ngjfng5</p></section></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">仅下载文件</p></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(248, 243, 240);padding: 3px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="text-align: center;padding-right: 5px;padding-left: 5px;font-size: 12px;"><p>3fghnbj2</p></section></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(248, 243, 240);padding: 3px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">屏幕截图，加密回传</p></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="33.0000%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">frgt45f</p></section></section></td><td colspan="1" rowspan="1" style="border-color: rgb(62, 62, 62);border-style: none;background-color: rgb(246, 218, 204);padding: 3px;" width="66.8100%"><section style="margin: 5px 0%;"><section style="padding-right: 5px;padding-left: 5px;font-size: 12px;"><p style="text-align: center;">创建线程执行cmd指令</p></section></section></td></tr></tbody></table></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">● 3hdfghd1：读取指定文件，加密后上传至C</span><span style="background-color: rgba(1, 0, 0, 0);">2</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img data-imgfileid="100013336" data-ratio="0.6517241379310345" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=ac9e520f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FxqKN6CELHibM8wJfhNukvvfTXsMkvYESSEias4QIQ1xtXyC60UPXxxBw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p>●  3gjdfghj6：创建cmd进程执行指定指令，并将执行结果加密上传</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img data-imgfileid="100013337" data-ratio="0.21839080459770116" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=45667d57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FvicZJrNibNdJbwUSHJk0MbHic7G1sMzbvObewEbMthcev2vCHqqZiaia5zQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p><span style="background-color: rgba(1, 0, 0, 0);">●  3fgjfhg4：遍历文件及目录</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img class="rich_pages wxw-img" data-imgfileid="100013343" data-ratio="0.12873563218390804" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=28c1eb40&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FlAHlkYk7Ebnt77rhEpIVTnCMcSPZoOSvyO0d4fxNw4L1icvfgVMCRRg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p><span style="background-color: rgba(1, 0, 0, 0);">●  3gnfjhk7：从指定URL下载后续负载保存到本地执行</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img data-imgfileid="100013342" data-ratio="0.6758620689655173" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=37d2cc68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FZkYhXhicyZGKiap8KJFN0YWB3tEvFpOIehYH9DlqBlFRcIKK0lib6ScWg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p><span style="background-color: rgba(1, 0, 0, 0);">●  3ngjfng5：仅下载文件</span><br/></p><p><span style="background-color: rgba(1, 0, 0, 0);">●  3fghnbj2：屏幕截图</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img data-imgfileid="100013340" data-ratio="0.30344827586206896" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=e9613118&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FmZYwfwyKnMxFuJXl4EFoK6cnyfdmdZVpib3sTlMibKxBCNdfclYmhFFw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;"><p><span style="background-color: rgba(1, 0, 0, 0);">●  frgt45f：创建线程执行cmd指令</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img data-imgfileid="100013339" data-ratio="0.32873563218390806" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="870" src="https://wechat2rss.xlab.app/img-proxy/?k=40352923&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7F5acGtfpyibK0AeQsEla49QzEwF27B8k3zI9ugVVIPmPY3zMWZWJeM8A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>4</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FRdL6apdEfULx6dB4oSldicDZLqodQ9sVbPyZ3WmdTfmeGib9AIDKCOdA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);"><p><strong>关联拓展</strong></p></section></section></section></section></section></section></section></section></section></section><section style="line-height: 2;"><p style="word-break: break-all;"><span style="font-size: 15px;background-color: rgba(1, 0, 0, 0);">我们的狩猎规则捕获的Patchwork组织近期的其他攻击样本如下</span></p></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="61.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;"><strong>文件Hash</strong></p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="35.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;"><strong>文件名</strong></p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="61.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">36c3aa180b8466d94b34397d786c913cc83bb33dbb1d6cc3bda0c83bd2392122</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="35.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">SMSAPI_Gateway.pdf.lnk</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="61.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">30024cadaf9aead441d926132c2a83aa478aa153e02a5b248b4c0dec33fcab94</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="35.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">Internal_Audit_Report.pdf.lnk</p></section></section></section></td></tr></tbody></table></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;margin-bottom: 10px;"><span style="background-color: rgba(1, 0, 0, 0);">两个LNK文件均上传自巴基斯坦，与本文分析的LNK文件连接的二级域名相同，释放的白+黑文件一致，仅在诱饵文件上有所不同。</span></p><p>此外，我们的狩猎规则还命中到该组织使用AsyncRAT的攻击链与本文相似的其他加载器。其中涉及的证书信息如下：</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img data-imgfileid="100013341" data-ratio="0.9951690821256038" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="414" src="https://wechat2rss.xlab.app/img-proxy/?k=e714fa07&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7F1Im2SCuplfNtXianu5vpCJrGARpw7T6VvFiaEDUXibHNqVZIk17w73dQw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>5</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FRdL6apdEfULx6dB4oSldicDZLqodQ9sVbPyZ3WmdTfmeGib9AIDKCOdA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);"><p><strong>域名分析</strong></p></section></section></section></section></section></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 4px;"><section style="display: inline-block;width: 33%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 0px 0px 1px;border-bottom-color: rgba(255, 72, 28, 0.71);"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin-bottom: 4px;"><section style="display: inline-block;vertical-align: top;width: auto;align-self: stretch;flex: 0 0 auto;background-image: linear-gradient(90deg, rgb(233, 32, 43) 13%, rgb(255, 129, 27) 88%);min-width: 5%;height: auto;line-height: 1;"><section style="transform: rotateY(46deg);"><section style="margin-top: 3px;text-align: center;"><section style="font-size: 13px;color: rgb(255, 255, 255);"><p><strong>1</strong></p></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: stretch;line-height: 0;"><section style="text-align: center;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 19px 0px 0px 10px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgba(255, 72, 28, 0.71);"><section style="text-align: justify;"><p><br/></p></section></section></section></section></section></section></section><p><strong>weixein.info</strong></p><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 4px;margin-bottom: 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.17);padding: 15px;"><section style="text-align: justify;font-size: 15px;line-height: 2;"><p style="word-break: break-all;">域名注册于2024年11月8日，主页面仿冒加拿大新闻网站Global News，点击任意新闻均会跳转至官方网站globalnews.ca</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img data-imgfileid="100013344" data-ratio="0.43148148148148147" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=92d8f934&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7F6odTicYmNqRX8IWsHfeHnJtBpCia2ZJF2mp4sv7XmjrwWOJTvG07GuIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: justify;font-size: 15px;line-height: 2;"><p style="word-break: break-all;"><span style="background-color: rgba(1, 0, 0, 0);">该域名解析到的IP：91.245.255.60曾在24年7月绑定域名mingyn.org，经网络资产测绘，该域名同样为Patchwork组织资产。</span><br/></p></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 4px;"><section style="display: inline-block;width: 33%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;border-style: solid;border-width: 0px 0px 1px;border-bottom-color: rgba(255, 72, 28, 0.71);"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin-bottom: 4px;"><section style="display: inline-block;vertical-align: top;width: auto;align-self: stretch;flex: 0 0 auto;background-image: linear-gradient(90deg, rgb(233, 32, 43) 13%, rgb(255, 129, 27) 88%);min-width: 5%;height: auto;line-height: 1;"><section style="transform: rotateY(46deg);"><section style="margin-top: 3px;text-align: center;"><section style="font-size: 13px;color: rgb(255, 255, 255);"><p><strong>2</strong></p></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: stretch;line-height: 0;"><section style="text-align: center;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 19px 0px 0px 10px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgba(255, 72, 28, 0.71);"><section style="text-align: justify;"><p><br/></p></section></section></section></section></section></section></section><p><strong>sheicen.info</strong></p><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 4px;margin-bottom: 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 1px;border-color: rgba(62, 62, 62, 0.17);padding: 15px;"><section style="text-align: justify;font-size: 15px;line-height: 2;"><p style="word-break: break-all;">该域名是我们捕获的Patchwork众多恶意负载之一连接到的C2域名，我们通过网络资产测绘，发现了该组织于2024年11月25日注册的最新域名youdoa.info，该域名解析到146.70.113.198。目前未发现有关联样本。其主页仿冒北欧航空SAS，点击任意链接即跳转至官网flysas.com</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 1px;"><img data-imgfileid="100013345" data-ratio="0.4361111111111111" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2036ac59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FqoFKILt1Undic6J8F0VWWiblraSXqRSZR1laG46VFj5VnNWDszHRbGJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section></section></section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 1;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;"><section style="font-size: 19px;text-align: center;margin-bottom: 2px;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);"><p><strong>6</strong></p></section></section><section style="text-align: center;"><section style="background-color: rgb(205, 234, 245);height: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="display: flex;width: 100%;flex-flow: column;"><section style="z-index: 3;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;height: auto;padding-right: 10px;padding-left: 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvneQ9bDln4eD9CWmicYTOtV7FRdL6apdEfULx6dB4oSldicDZLqodQ9sVbPyZ3WmdTfmeGib9AIDKCOdA/640?wx_fmt=gif&amp;from=appmsg&#34;);background-position: 50% 50% !important;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);"><p><strong>IOC</strong></p></section></section></section></section></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;margin-bottom: 15px;">本次攻击活动中的文件Hash</p><p style="word-break: break-all;margin-bottom: 15px;">12cf713242ae7eb11eceddbcc535f562f16e5be645f07a87e805e7f4f81b362a</p><p style="word-break: break-all;margin-bottom: 15px;">7250c63c0035065eeae6757854fa2ac3357bab9672c93b77672abf7b6f45920a</p><p style="word-break: break-all;margin-bottom: 15px;">通过基础设施及样本特征关联到的文件Hash</p><p style="word-break: break-all;margin-bottom: 15px;">b66434960ea4669d66ddefa173b10207dd4d6bbc5c46f55b9c9e7706fd16f18e</p><p style="word-break: break-all;margin-bottom: 15px;">8143a7df9e65ecc19d5f5e19cdb210675fa16a940382c053724420f2bae4c8bd</p><p style="word-break: break-all;margin-bottom: 15px;">858f47433bbbac47ca53e2b525669ab130c460b3f1b2c8269cf1ee8e47477f1e</p><p style="word-break: break-all;margin-bottom: 15px;">0dbf54244cb9c115e59f9951c6450f91b684d6d5ec5e1a27be397b3b96ef5430</p><p style="word-break: break-all;margin-bottom: 15px;">c01a763ce686f464d2d633f16ddb37e2032b91c10f36e3f187760fb6d7374223</p><p style="word-break: break-all;margin-bottom: 15px;">74ce1c5bfdfd095a974b5457aa13cb2912fd2f3fe00558793bdb02907dbfd3ce</p><p style="word-break: break-all;margin-bottom: 15px;">报告涉及URL及说明</p></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;"><strong>URL</strong></p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;"><strong>说明</strong></p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://atus.toproid.xyz/klhju_rdf_gd/ktdfersfr</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">下载文件到本地C:\Users \Public\Project_Guideline.pdf</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://zon.toproid.xyz/pfetc_ksr_lo/jyuecvdgt</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">下载文件到本地C:\Users\Public\ WerFaultSecure.exe</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://zon.toproid.xyz/aewbf_jsd_td/ktrgdysvt</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">下载文件到本地C:\Users\Public\wer.dll</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://weixein.info/1WrCVzW4kSDNbNTt/cqWf4vQlofzqFkc7.php</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">窃密信息上传及后续负载下载地址</p></section></section></section></td></tr></tbody></table></section></section><section style="font-size: 15px;line-height: 2;"><p style="word-break: break-all;">通过基础设施及样本特征关联到的URL及说明</p></section><section style="min-height: 40px;margin: 10px 0%;"><section style="width: 100%;margin-right: auto;margin-bottom: -10px;margin-left: auto;"><table width="100%"><tbody><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;"><strong>URL</strong></p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;"><strong>说明</strong></p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://maticdoc.toproid.xyz/htrdtgf/jyftdrst</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">下载疑似测试文件</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://mpa.toproid.xyz/h9jUs_hR8_hs/kR9d4HrfE</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">白文件下载地址</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://uiop.taobaoo.info/hjds45jh/jdkshf</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">恶意DLL文件下载地址</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://sheicen.info/1WrCVzW4kSDNbNTt/cqWf4vQlofzqFkc7.php</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">恶意DLL文件回连地址</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxp://ader.taobaoo.info/Pmnt_sheth_shr_gd/ketsuwshe.bin</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">恶意DLL文件后续负载下载地址</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">172.81.62.199</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">C2/回连IP</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://plete.toproid.xyz/U7h6G_g5R_d9/h9A3_4jJu</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">PDF诱饵文件下载地址</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://plete.toproid.xyz/iu8Y7_t5r_t9/ju5U9JuI9</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">PDF诱饵文件下载地址</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://tected.toproid.xyz/j4Rj7_s6T_hY/u5eTre4rT</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">白文件下载地址</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://tected.toproid.xyz/iwredt_et4_4fh/y6wTyd5Rt</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">恶意DLL文件下载地址</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">hxxps://stealthcomm.org/YcKOjLMxiwCZfSS/comrCVPEffFiPvF.php</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">恶意DLL文件回连地址</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">mingyn.org</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">网络资产测绘</p></section></section></section></td></tr><tr><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right-width: 0px;border-left: 0px none rgb(62, 62, 62);border-right-color: rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="51.3700%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">youdoa.info</p></section></section></section></td><td colspan="1" rowspan="1" style="border-top: 0px none rgb(62, 62, 62);border-right: 0px none rgb(62, 62, 62);border-left: 0px none rgb(62, 62, 62);border-bottom-color: rgb(202, 198, 198);border-bottom-style: dashed;background-color: rgb(247, 247, 247);padding: 5px;" width="45.0000%"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: 100%;vertical-align: middle;border-right: 1px solid rgb(202, 198, 198);border-top-right-radius: 0px;align-self: center;flex: 0 0 auto;"><section style="font-size: 12px;"><p style="word-break: break-all;">网络资产测绘</p></section></section></section></td></tr></tbody></table></section></section><p><br/></p><section style="display: flex;flex-flow: row;margin: 10px 0%;text-align: center;justify-content: center;isolation: isolate;"><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;"><section style="margin-right: 0%;margin-left: 0%;"><section style="background-color: rgb(214, 60, 60);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;align-self: stretch;height: auto;line-height: 0;"><section style="transform: perspective(0px);transform-style: flat;"><section style="transform: rotateY(180deg);"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: perspective(0px);transform-style: flat;"><section style="transform: rotateX(180deg) rotateY(180deg);"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 auto;align-self: stretch;min-width: 10%;height: auto;background-color: rgb(214, 60, 60);border-width: 0px;"><section style="line-height: 1.4;color: rgb(255, 255, 255);padding-right: 10px;padding-left: 10px;font-size: 12px;"><p><strong>防范建议</strong></p></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;align-self: stretch;height: auto;line-height: 0;"><section style=""><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="transform: perspective(0px);transform-style: flat;"><section style="transform: rotateX(180deg);"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 4px 2px;border-color: rgb(214, 60, 60) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(214, 60, 60);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;"><section style="margin-right: 0%;margin-left: 0%;"><section style="background-color: rgb(214, 60, 60);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="text-align: left;"><section style="text-align: justify;font-size: 15px;line-height: 2;"><p style="word-break: break-all;margin-bottom: 15px;">目前安全数据部已具备相关威胁检测能力，对应产品已完成IoC情报的集成。针对该事件中的最新IoC情报，以下产品的版本可自动完成更新，若无法自动更新则请联系技术人员手动更新：</p><p style="word-break: break-all;margin-bottom: 15px;">1.   AiLPHA分析平台V5.0.0及以上版本</p><p style="word-break: break-all;margin-bottom: 15px;">2.   APT设备V2.0.67及以上版本</p><p style="word-break: break-all;margin-bottom: 15px;">3.   EDR产品V2.0.17及以上版本</p><p style="word-break: break-all;">安恒云沙盒已集成了该事件中的样本特征。用户可通过云沙盒：<a href="https://sandbox.dbappsecurity.com.cn/，对可疑文件进行免费分析，并下载分析报告。" target="_blank">https://sandbox.dbappsecurity.com.cn/，对可疑文件进行免费分析，并下载分析报告。</a></p></section></section><p><br/></p><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;"><section style="vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100013348" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;width: 100%;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=6852def7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneQ9bDln4eD9CWmicYTOtV7Fpk4rbL0vXPVrGHswoXDiczFsaog2jebiaiaBzuh7B0siaB9vFHWT7goyPg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247497001">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=60955833&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247497001%26idx%3D1%26sn%3Dbf11de770fea2d96d4f3c08dfd7e038f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 04 Dec 2024 11:01:00 +0800</pubDate>
    </item>
    <item>
      <title>海莲花组织以南海的法律制度等为话题的攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496792&amp;idx=1&amp;sn=21f61c3f386e0d36b16d47284f62d2c0</link>
      <description>近日，猎影实验室捕获到OceanLotus（海莲花）针对境内的攻击活动</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2024-11-11 11:15</span> <span style="display: inline-block;">浙江</span>
</p>

<p>近日，猎影实验室捕获到OceanLotus（海莲花）针对境内的攻击活动</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=75a54d2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4n5mBPmBJO2cgC69w1HVkibGyEjSUia4NVxz3QFUicYbSE4024UabMSqNg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 15px;padding: 0px 15px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);"><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013112" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e7f633d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4OiabvPgl1LoEjMKd3BGJaeDcgNaYn08Lx34heeJmuo2VVRBTzp0tPMw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">1</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4IDC4QMOwZictUibQMmYrx6akOAb0ibqytUXTpInoawBbVKQozVKlN0xicw/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">事件概述</strong></p></section></section></section></section></section></section></section></section></section></section><section style="padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">OceanLotus又名APT32、海莲花，是具有东南亚国家背景的APT组织。该组织自2015年披露以来，持续活跃至今，主要针对周边国家：中国、柬埔寨、泰国、老挝进行国家级网络间谍活动。其目标行业包括政府、金融、海事机构、海域建设部门、航运企业、科研院所和境内高校。</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">近日，猎影实验室捕获到OceanLotus（海莲花）针对境内的攻击活动，活动延续此前的攻击目标与攻击手法，即仍然通过鱼叉式网络钓鱼邮件针对国内海事机构。攻击活动流程大致如下：</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">1.   该鱼叉式网络钓鱼邮件附件为包含有MSC文件的压缩包文件，其中MSC文件伪装成DOCX文件引诱目标用户点击；</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">2.   MSC文件运行后将读取自身释放诱饵文档、白文件Warp.exe以及恶意DLL文件7z.dll，其中诱饵文档之一的内容为适用于南海的两种法律制度研究；</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">3.   恶意DLL文件由白文件Warp.exe加载后，将在内存中解密多层Shellcode，最终执行CobaltStrikeBeacon，连接到C2服务器，并等待后续指令下发。</p></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">2</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4IDC4QMOwZictUibQMmYrx6akOAb0ibqytUXTpInoawBbVKQozVKlN0xicw/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">诱饵文件</strong></p></section></section></section></section></section></section></section></section></section></section><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">三个MSC文件释放的诱饵文件分别如下：</p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">1.  适用于南海的两种法律制度研究</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013114" data-ratio="0.42693110647181626" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="958" src="https://wechat2rss.xlab.app/img-proxy/?k=e8cbbc55&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4iby7EWQLhLlnCDK0yP2JvNlXxtLibJgzMicZQZzubAGuYlYyXSicDLicpicw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">2.  匿名审稿专家回执</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013111" data-ratio="0.6020583190394511" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="583" src="https://wechat2rss.xlab.app/img-proxy/?k=44b9d5d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4fe6lq5zfAMGZuezDibfgrjIMVm3l4toLdOmYKQ3z2hjZyKAricHsT5vg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">3.  《国际论坛》匿名审稿专家邀请函</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013113" data-ratio="0.4342379958246347" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="958" src="https://wechat2rss.xlab.app/img-proxy/?k=908bc756&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4hHgdpoxuZE8gt1HamaP5lXYbbvia5wpya87CBIGrutDJL3LZleWdIPg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">3</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4IDC4QMOwZictUibQMmYrx6akOAb0ibqytUXTpInoawBbVKQozVKlN0xicw/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">样本分析</strong></p></section></section></section></section></section></section></section></section></section></section><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">MSC文件启动</strong></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">XML格式的MSC文件中存在有可疑的Javascript指令</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013110" data-ratio="0.07497116493656286" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="867" src="https://wechat2rss.xlab.app/img-proxy/?k=e93240f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4icBCmAK2H0ku996PKfTQWfOwobLelXqUeia9coaImR6RdWliaefkcF3eA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">其执行的内容经解码后如下，主要功能为加载XML中嵌入的VBScript执行</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013118" data-ratio="0.699205448354143" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="881" src="https://wechat2rss.xlab.app/img-proxy/?k=34f4e4f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4giaMDy3xH4viaN1zeIJicrQXHvyJYpusicaEaY46QJUWSWXNs9aXjBrahg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">VBScript脚本</strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">VBScript脚本加载后主要释放三个文件：白文件Warp.exe、恶意DLL文件7z.dll到目录C:\Program Files\Cloudflare，以及诱饵文件“适用于南海的两种法律制度研究（稿件）.docx”到目录%Temp%</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013116" data-ratio="0.19347319347319347" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="858" src="https://wechat2rss.xlab.app/img-proxy/?k=d2270d4a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic41R6wg52vOzBIlibNfXraJiatjH5ok1CavYr61bqQBMFZefAbMskOubQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">释放文件来自源文件，名为CONSOLE_TREE、CONSOLE_MENU、以及CONSOLE_PANE的标签，通过Base64解码后写入对应的文件路径</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013119" data-ratio="0.6806526806526807" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="858" src="https://wechat2rss.xlab.app/img-proxy/?k=9d3d9531&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4fsrG7xslQOqKDHBicrBgpJkqacpwRI5icm9zNZtWCvVR9p94G5OM7wWw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">最后打开诱饵文件、带参数&#34;t 8.8.8.8&#34;启动白文件Warp.exe</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013115" data-ratio="0.09132947976878612" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=9e1f6133&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4h53KUV1gJVrj2yj1YoiacV7dgRY2xgR14yJIDsxECkCPJSgOSDVYiaPQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">DLL文件侧载</strong></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">DLL文件侧载是一种利用程序加载DLL文件进行恶意操作的攻击技术，正常情况下，应用程序会依赖系统提供的动态链接库（DLL）执行特定功能。攻击者则通过修改或替换这些DLL文件，使应用程序加载恶意代码。</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">利用DLL文件劫持是OceanLotus组织常用的一种攻击手法，该组织在历史攻击活动中劫持过的白文件包括：WinWord.exe（Word主程序）、MicrosoftUpdate.exe（微软升级程序）、SoftManager.exe（360软件管理器）、GoogleUpdate.exe（谷歌更新程序）、LenovoDrvTray.exe（联想驱动管理程序）、RasTlsc.exe（赛门铁克产品组件）、LenovoDesk.exe（联想桌面应用）等。</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">此次捕获到OceanLotus使用的恶意DLL文件7z.dll由Warp.exe侧加载，其中Warp.exe证书信息如下：</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013117" data-ratio="1.1631016042780749" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="374" src="https://wechat2rss.xlab.app/img-proxy/?k=5a21c7ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4rBajmZdE5a7L0gIOgL4ZibHpibUhdzWzI5kk5sR2j9b0YibPIwY1CUHKw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">白文件加载7z.dll后，获取其导出表GetNumberOfMethods进行调用</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013122" data-ratio="0.21468926553672316" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="708" src="https://wechat2rss.xlab.app/img-proxy/?k=7399f21b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4YickRvfV9G69hm1FgOCEP8xopOxBrKMIWCNfx0VaiaIEonAygGAXjaww%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">首先解密出字符串“cloudflare.warp.process”，并以此为名创建互斥体</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013123" data-ratio="0.09855072463768116" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="690" src="https://wechat2rss.xlab.app/img-proxy/?k=27865afc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4ew6maBe1MmRZwKHgr3ZtCR58ruP8TU3epuBMUXAZfklMflcibhnFr6w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">接着获取一组API函数地址用于获取命令行参数并进行验证</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013124" data-ratio="0.6526772793053546" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="691" src="https://wechat2rss.xlab.app/img-proxy/?k=e4809e0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4RCqcFUbasyfSP2HKIoqGRSJbTpLYBlPUjthDsXotXsuJvthK8UW4AQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">随后创建命名管道ntsvcs用于进程间通信</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013121" data-ratio="0.26811594202898553" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="690" src="https://wechat2rss.xlab.app/img-proxy/?k=03041fb8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4LwjXH6ftqjERRjankvRmbkicFc4Gu8p1djdNkAicmnpricXI6Bh5K3SDg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">使用ReadFile、WriteFile从/向管道读取/写入数据</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013120" data-ratio="0.24347826086956523" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="690" src="https://wechat2rss.xlab.app/img-proxy/?k=d8ceaa7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4BDsSUY2fesNoWgsEdCVoS4A5Avo3zml1SvW23Qe1hUQHZdJJh2dtHg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">获取Chakra.JsProjectWinRTNamespeace函数的内存，并通过VirtualProtect更改其属性为读写权限</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013127" data-ratio="0.5194630872483221" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="745" src="https://wechat2rss.xlab.app/img-proxy/?k=70970946&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4lqglztqZ0xZjcJe2EQT1vyg2e1rcRSicUqXRLfTnbXNZInJ3vichADbQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">随后将Shellcode写入该内存，再次通过VirtualProtect更改其属性为可执行</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013128" data-ratio="0.5188172043010753" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="744" src="https://wechat2rss.xlab.app/img-proxy/?k=753ca69c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic47Rp2TFibWjkD1cleWIAicibY4LI1YFAXqXl9C5klOaYQT7b0jmg1wCUtw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">最终内存中加载的有效负载仍为Cobalt Strike Beacon</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013129" data-ratio="0.7002688172043011" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="744" src="https://wechat2rss.xlab.app/img-proxy/?k=8a7df1c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4WKk6JicwThB0vIH3hibcAzhsp14BoDVq1zWLRY7EWWibrB5EyiciaPXZh6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">4</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4IDC4QMOwZictUibQMmYrx6akOAb0ibqytUXTpInoawBbVKQozVKlN0xicw/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">规避手段</strong></p></section></section></section></section></section></section></section></section></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">1.   MSC文件图标设置为Word图标，在默认隐藏文件后缀的主机上真假难辨</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013125" data-ratio="0.14249037227214378" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="779" src="https://wechat2rss.xlab.app/img-proxy/?k=89a823dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic45E2Syj5Dic07UorqE17KU0vtajTrDWA5STwWTGc2Jp8DngibYJC4rtoA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013126" data-ratio="0.13872832369942195" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=e39d083d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4y5IDXp5CoRFr1uK625yJ9ouptgEN3H6aDsNAuXkvg3ic5REKxtpS6rg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">2.   MSC文件在携带PE文件资源时使用了Base64编码，以规避静态检测</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013130" data-ratio="0.15028901734104047" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=254e76d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4z2avknRMjyAlBegzlzDtfQKp89AjPvvQ2XQ0mXlwqTsSBuib07y8XOw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">3.   恶意DLL文件通过带有合法数字签名的白文件加载，逃避杀软动态检测</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013131" data-ratio="0.12485549132947976" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=9c956843&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4uOHaWq65IL0zRUCqXX8PficIJLBwukbOfXUynOrrORB9l9tocYp2O2g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">5</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4IDC4QMOwZictUibQMmYrx6akOAb0ibqytUXTpInoawBbVKQozVKlN0xicw/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">C2连接</strong></p></section></section></section></section></section></section></section></section></section></section><section style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;padding: 0px;box-sizing: border-box;">解密出C2域名及请求路径，建立通信后接收后续远控指令</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013133" data-ratio="0.17086092715231788" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="755" src="https://wechat2rss.xlab.app/img-proxy/?k=77520b97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4dr0ueIicNiclxOx4E2ortrRKI8gChLY1RmuYoKmp3gjwbK2wp7gBYLlQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;">安恒云沙箱可直接跑出本次海莲花样本连接域名：office.enucuzalanadi.net，解析到IP159.223.49.98</p></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013132" data-ratio="0.49248554913294795" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=9074e6a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4xHcg8xBTwA6NHZgAx25v6Q5l507lKCDlrnIX5VGDgteJcX9fHNz1NA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">6</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4IDC4QMOwZictUibQMmYrx6akOAb0ibqytUXTpInoawBbVKQozVKlN0xicw/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">远控指令</strong></p></section></section></section></section></section></section></section></section></section></section><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">此次攻击活动最终阶段的远控指令通过CobaltStrike Beacon下发。Cobalt Strike Beacon是一款非常受攻击者青睐的红队渗透测试框架。有数据表明，2018年至今，60%以上的网络犯罪及APT活动均涉及使用Cobalt Strike，部分APT例如SolarWinds供应链攻击事件背后的APT29、常年针对我国海事机构的OceanLotus、Winnti等都将该工具纳入自身武器库中。Cobalt Strike功能强大，负载类型丰富，4.2版本已支持多达100+远控指令，包括Shell执行、文件操作、执行加载器、内网侦察、横向移动、持久性等</p><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013134" data-ratio="0.09490740740740741" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="864" src="https://wechat2rss.xlab.app/img-proxy/?k=987d0046&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4x4wjKiaGCIJErVoFJ3NibechYCdypqgt4ZCMYAQ2nibOSBx3dVmF1Szsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">7</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4IDC4QMOwZictUibQMmYrx6akOAb0ibqytUXTpInoawBbVKQozVKlN0xicw/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">关联分析</strong></p></section></section></section></section></section></section></section></section></section></section><section style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">此次攻击活动存在如下特征，与OceanLotus历史攻击活动特征高度重合。</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">1.  活动针对国内海事机构及相关人员；</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">2.  活动使用伪装成DOCX文件的恶意MSC文件作为邮件附件下发；</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">3.  释放的后续负载仍为白+黑的启动方式；</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">4.  后续在内存中加载的Shellcode加载CobaltStrikeBeacon。</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">此外，公开来源的威胁情报已将本次活动最后阶段CobaltStrikeBeacon连接到的C2标记为APT组织海莲花资产，由此可以看出海莲花组织活动广泛，需要用户警惕此类钓鱼邮件攻击。</p></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">5</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4IDC4QMOwZictUibQMmYrx6akOAb0ibqytUXTpInoawBbVKQozVKlN0xicw/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">活动总结</strong></p></section></section></section></section></section></section></section></section></section></section><section style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">OceanLotus组织自披露以来，长期处于活跃状态，其擅长制作针对中国的钓鱼邮件，且多年来一直热衷于DLL文件侧载的攻击方式。猎影实验室提醒广大用户朋友，不运行未知来源的邮件附件。如有需要鉴别的未知来源样本，可以投递至安恒云沙箱查看判别结果后再进行后续操作。猎影实验室将持续对全球APT组织进行持续跟踪，专注发现并披露各类威胁事件。</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">目前安全数据部已具备相关威胁检测能力，对应产品已完成IoC情报的集成。针对该事件中的最新IoC情报，以下产品的版本可自动完成更新，若无法自动更新则请联系技术人员手动更新：</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">1.   AiLPHA分析平台V5.0.0及以上版本</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">2.   APT设备V2.0.67及以上版本</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">3.   EDR产品V2.0.17及以上版本</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">安恒云沙盒已集成了该事件中的样本特征。用户可通过云沙盒：<a href="https://sandbox.dbappsecurity.com.cn/，对可疑文件进行免费分析，并下载分析报告。" target="_blank">https://sandbox.dbappsecurity.com.cn/，对可疑文件进行免费分析，并下载分析报告。</a></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013139" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=d9ec1ce5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvncdA7xvIJPTuTYq0xRtMgic4U9VW5IX7yXica3UoQrDFItT0FsPeMlZtYSDZoMCF1Zkj2udaGk12l3w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496792">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2b29127d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496792%26idx%3D1%26sn%3D21f61c3f386e0d36b16d47284f62d2c0%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 11 Nov 2024 11:15:00 +0800</pubDate>
    </item>
    <item>
      <title>2024年人工智能技术赋能网络安全应用测试结果重磅发布！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496720&amp;idx=1&amp;sn=32838d83f97ffef7db9a4d1c3c66462d</link>
      <description>2024年国家网安周主论坛现场，人工智能技术赋能网络安全应用测试结果重磅发布，安恒信息入选恶意软件检测、网络安全告警日志降噪两大场景，在恶意软件检测场景中安恒信息位列榜首！</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2024-09-09 13:59</span> <span style="display: inline-block;">浙江</span>
</p>

<p>2024年国家网安周主论坛现场，人工智能技术赋能网络安全应用测试结果重磅发布，安恒信息入选恶意软件检测、网络安全告警日志降噪两大场景，在恶意软件检测场景中安恒信息位列榜首！</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=206ddc51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnc9D3TQzUPJmJH4LicAcHqNcB6Bibou0MogXHmwDI8psMPiaf7QQeicDKgFkibpYZMBHibCyGoibcdOXsp3Q%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div id="js_image_content" class="image_content "><h1 class="rich_media_title ">2024年人工智能技术赋能网络安全应用测试结果重磅发布！</h1>    <!----> <!----> <!----> <div class="wx_album_area js_album_wrap " style=""></div> <div class="rich_media_tool "><div class="rich_media_info weui-flex policy_tips js_ad_policy_tips tips_global_primary "><div class="media_tool_meta tips_global_primary meta_primary ">素材来源官方媒体/网络新闻</div></div></div> </div>


<p><img src="https://mmbiz.qpic.cn/mmbiz_jpg/AvAjnOiazvnc9D3TQzUPJmJH4LicAcHqNcjPeHibUZbpBbic3lRhShH7YqbKzsjq9iaht2BSZTicY1oxZKv6dnfvhmmw/0?wx_fmt=jpeg"/></p>
<p><img src="https://mmbiz.qpic.cn/mmbiz_jpg/AvAjnOiazvnc9D3TQzUPJmJH4LicAcHqNcJ1tyj9DHTQzbppjZ6XOGI6bwxiaker3ncFIhkHhKQbULQ1pWNBuTUWw/0?wx_fmt=jpeg"/></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1b992a6e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496720%26idx%3D1%26sn%3D32838d83f97ffef7db9a4d1c3c66462d%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 09 Sep 2024 13:59:00 +0800</pubDate>
    </item>
    <item>
      <title>韩国“伪猎者”APT组织利用多款国产化软件漏洞对中国的攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496709&amp;idx=1&amp;sn=0629689057d2e4c43b1adf59fb75f46a</link>
      <description>安恒猎影实验室捕获到一起“伪猎者”APT组织的攻击</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2024-08-12 10:48</span> <span style="display: inline-block;">浙江</span>
</p>

<p>安恒猎影实验室捕获到一起“伪猎者”APT组织的攻击</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=cb9da587&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKEvrfJhPNUJgFlG1WN2198eSL13OnKpF0a5xuy3xibv1EolvNyYLDc3A%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 15px;padding: 0px 15px;line-height: 2;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013030" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=359a9c4b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKN7pyhSuACEhz4ictp6KoYf3LNCN51e2nxGR1HQPDbckwu1l5zyjlEvQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">1</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnc0Dem0nBze869OURJnj2sKs7UMP2Zr0TzVWsxic46qGPiaiafCHamelGkMMVwem1LnM18xfcDsonb0Q/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">事件背景</strong></p></section></section></section></section></section></section></section></section></section></section><section style="padding: 0px;box-sizing: border-box;"><p style="text-indent: 2em;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">随着信息技术的不断发展和普及，国产化软件已经成为我国信息化建设的重要组成部分。然而，在享受国产化软件带来的便利的同时，我们也面临着来自各种攻击威胁的挑战。</p><p style="text-indent: 2em;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">尤其是国产化的办公应用、知名软件，已广泛覆盖各个企业单位，境外攻击者早已盯牢这些阵地，想以此为突破口，以其利益相关者为目标实施间谍窃密和监控活动。</p><p style="text-indent: 2em;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">猎影实验室在高级威胁对抗过程中，曾多次发现了境外黑客组织实施APT攻击的情况。前段时间，安恒猎影实验室捕获到一起“伪猎者”APT组织的攻击，在深入研究过程中，我们发现该组织已掌握多个国产化0day武器，如WPS 0day漏洞只需根据诱导点击一次，就足以使目标失陷；Foxmail 0day漏洞，用户使用客户端打开邮件时，无需其它任何操作，就可以执行恶意代码进而控制目标；126邮箱/163邮箱XSS漏洞，被攻击者用来隐蔽的窃取用户邮箱的Cookies，从而使攻击者无需密码即可登录邮箱，进而窃取邮箱内的信件，或者利用该邮箱向其他人发送钓鱼邮件等。</p><p style="text-indent: 2em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">利用此类漏洞进行攻击，表现出了其对我国目标的针对性，通过排查分析，我们发现其意图针对包括我国多个涉外政府部门、以及多个行业人员实施攻击窃密活动，且这些人员都与中韩关系相关。经过缜密的溯源分析，结合“伪猎者”组织背景，我们确定该攻击来自于韩国，其目的为窃取我国中韩相关情报。</p></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">2</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnc0Dem0nBze869OURJnj2sKs7UMP2Zr0TzVWsxic46qGPiaiafCHamelGkMMVwem1LnM18xfcDsonb0Q/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">0day漏洞武器分析</strong></p></section></section></section></section></section></section></section></section></section></section><section style="box-sizing: border-box;"><p style="text-indent: 0em;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">在本次攻击过程中，攻击者使用的漏洞，或是Windows平台下，中国大陆地区流行的办公软件漏洞：WPS表格漏洞和Foxmail邮件程序漏洞，或是中国大陆地区广泛使用的163邮箱的漏洞。</p><p style="text-indent: 0em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">这些漏洞<strong style="box-sizing: border-box;">对大陆地区用户针对性强，影响范围广泛</strong>；所用漏洞是逻辑漏洞，<strong style="box-sizing: border-box;">漏洞触发稳定</strong>，危险程度高。</p></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">WPS 0day漏洞</strong></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="text-indent: 0em;box-sizing: border-box;">该漏洞为1-click点击逻辑漏洞，只需要用户点击表格中的图片即可触发漏洞。</span></p><p style="text-indent: 0em;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">攻击样本的后缀名为et，虽然后缀为et，但实际内容为mhtml格式。攻击者在表格中插入两个图片，并通过这两个图片来触发漏洞。</p><p style="text-indent: 0em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="text-indent: 2em;box-sizing: border-box;">第</span><span style="text-indent: 2em;box-sizing: border-box;">一个图片为指向恶意链接的空白图片，在样本执行后会自动下载恶意文件并存储在特定目录。</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013028" data-ratio="0.17897371714643304" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="799" src="https://wechat2rss.xlab.app/img-proxy/?k=caaa4549&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKqTuvJGwZXOF8JZ04jDEQ7lv4cLibicianWghSx8UlTv2MmlUlTuyCehEg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;text-indent: 0em;margin: 0px;padding: 0px;box-sizing: border-box;">被下载的木马样本，会保存到%Temp%/wps/INetCache/下，以特定hash文件名存储。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013029" data-ratio="0.31851851851851853" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e83661ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKdzvdvVDc2wOJeQiaM3kTsDXE9ol3I499bm1mjgzydibDRyPnaCgAngsQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="box-sizing: border-box;"><p style="text-indent: 0em;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">第二个图片，是指向WPS“轻办公”链接的诱饵图片，通过诱饵图片诱导用户点击，触发WPS恶意的“轻办公”链接执行特马。</p><p style="text-indent: 0em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="text-indent: 0em;box-sizing: border-box;">例</span><span style="text-indent: 0em;box-sizing: border-box;">如图为以知名邮件服务器软件Coremail为主题的诱饵图片。</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 80%;height: auto;box-sizing: border-box;"><img data-imgfileid="100013031" data-ratio="0.4925925925925926" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0eaf94c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sK9U4woLcj79A0RrUwkQnDGS0bDytIDvZtrXh80PMf67pRmUU96JwfmQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="box-sizing: border-box;"><p style="text-indent: 0em;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">“轻办公”链接中，带有一个名为token的字段，该字段为要执行的命令通过某种算法得到。</p><p style="text-indent: 0em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">攻击者破解了WPS的token生成逻辑，从而能够构造出“合法”的恶意“轻办公”链接，并借助其执行恶意操作。该“轻办公”链接经过解码后，可以看出其功能是运行之前下载的文件。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013032" data-ratio="0.34629629629629627" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1e968ec9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKATlANRO0QNndzm7P9HJMX3dguollODG2RiaJUzPss3VewAbu44cBEEQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="text-indent: 0em;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">WPS程序会调用wpscloudsvr.exe来执行“轻办公”命令，最终通过promecefpluginhost.exe负责命令的执行，加载前一阶段下载好的载荷文件。</p><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013035" data-ratio="0.25277777777777777" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6186571b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sK9jA52ibTy3HlQoswDA4iaAP4iayuwf2Ricm8NOPvOH59yRWvKbPib4bIQIg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">漏洞利用过程可以见下图所示：</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100013037" data-ratio="0.39814814814814814" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=10ee67d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKaiaHR1MmXE9uYnDb2ET5S8pNiaS8RjOiaSZmExNdm27HovYghBaLoCYzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">Foxmail邮件程序零点击0day漏洞</strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="text-indent: 2em;box-sizing: border-box;">该漏洞是Foxmail的一个远程代码执行漏洞，黑客使用自定义邮件客户端向受害者发送一封特殊构造的邮件，受害者使用Windows系统的Foxmail客户端打开此类邮件时，会自动执行邮件中的恶意脚本代码，从而启动邮件附件中的木马文件，<strong style="box-sizing: border-box;">无需任何点击</strong>。</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013034" data-ratio="0.4888888888888889" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3db92350&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKde4VOaRVA5OiaibST6uujGCBRnhMpRpGB3nESX8arCUfAuAKWiczDNiaGQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="box-sizing: border-box;"><p style="text-indent: 0em;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">攻击者构造了两个恶意附件，Foxmail在邮件解析时，由于验证缺失会导致恶意代码被执行，从而执行邮件附带的两个恶意附件。</p><p style="text-indent: 0em;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="text-indent: 2em;box-sizing: border-box;">这两个</span><span style="text-indent: 2em;box-sizing: border-box;">附件的功能分别如下：</span></p><p style="text-indent: 0em;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">（1）第一个附件为JS脚本文件，恶意代码注入执行后时优先执行它。首先它实现隐藏Foxmail的附件栏功能，使受害者在查看邮件时看不见附件，让其误以为邮件没有附件，从而放松警惕；然后会在等待100ms后，模拟鼠标左键双击的动作，执行第二个附件。</p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">（2）第二个附件为“伪猎者”APT组织特种木马，由第一个脚本附件模拟点击触发。</p></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">邮箱XSS漏洞</strong></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">该漏洞是126/163邮箱某网页的一个XSS漏洞，具体属于一个“反射式”XSS漏洞。</p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">该攻击的具体过程如为：攻击者发送带有XSS漏洞链接的钓鱼邮件给受害者；之后，诱导受害者打开带有XSS漏洞的126邮箱链接，触发XSS漏洞，导致恶意代码执行。恶意代码执行，获取当前页面（126邮箱页面）的Cookies，之后构造一个Get请求，将Cookies作为参数，传递给攻击者控制的服务器，从而窃取了用户的Cookies。同时，我们发现，回传的服务器为一个.kr域名，属于韩国。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013033" data-ratio="0.13055555555555556" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d23c0079&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKe1e4vDJ2OtSOKjxYmpT5fQWd32ia5EbYVicjxmV2XphDcUcAjOG6ljsQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="text-indent: 0em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">攻击者可以利用窃取的Cookies，登录被攻击者的126邮箱，窃取邮件，或者向其他用户发送钓鱼邮件等。</p><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">3</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnc0Dem0nBze869OURJnj2sKs7UMP2Zr0TzVWsxic46qGPiaiafCHamelGkMMVwem1LnM18xfcDsonb0Q/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">木马载荷与攻击流程分析</strong></p></section></section></section></section></section></section></section></section></section></section><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">攻击流程</strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="text-indent: 2em;box-sizing: border-box;">攻击者发送与中韩关系相关的钓鱼邮件，包括利用前面所述的0day漏洞，从而触发恶意载荷。</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013036" data-ratio="1.0231481481481481" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d641d30a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKHPP8gRApwPCuRxtmzSNiaEZ90jety7W68TcP6NkCkMxHFTjUwIV1iamg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">使用被攻陷邮箱作为跳板</strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">在对钓鱼邮件收件人和发现人的信息统计中，我们清理出一条使用被攻陷邮箱作为跳板，进行进一步攻击的攻击链路，如下图所示：</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013042" data-ratio="0.5990740740740741" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=62331d9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKicT13ctTOb8RusKvaoCJTiaGlibh2Qw7QianwzcKMF7qltgiaM0l6ztSLNg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;box-sizing: border-box;"><p style="text-indent: 0em;text-align: justify;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">以上图为例，攻击者在获取邮箱A的控制权后，长时间潜伏监控，精心挑选邮箱A联系人列表中，与韩国相关的重要中方人士，定向发送定制化含漏洞利用的钓鱼邮件对相关人员进行攻击，攻击目标非常明确。</p></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">主木马载荷分析</strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">WPS漏洞和Foxmail漏洞所投递的载荷，都是同一种木马文件。该木马是一个dll文件。运行后，会滥用合法的windows的照片库查看器组件shimgvw.dll，通过其中的函数ImageView_Fullscreen，从远程服务器上下载文件eqlist.txt和mylink.tmp。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013040" data-ratio="0.1527777777777778" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=85e25d61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sK0K6fVFwcIRZf3X6RC4Tl56iawPQYib1suTKLMO2Orhiba0ibxy78DyICog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">文件eqlist.txt中保存了加密数据。该木马所使用的加密算法，是一个经过修改的base64编码算法。样本随后会将该文件解密，并释放出两个后续载荷文件，保存到%appdata%\\Microsoft\\Crypto\\crypt86.da和%localappdata%\\Microsoft\\Proofs\\profapii.da。</p><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013039" data-ratio="0.22614840989399293" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="849" src="https://wechat2rss.xlab.app/img-proxy/?k=d37cb999&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKf9uuQf8FvtPmIxo9gdTUHbElPe8Dn0MLNPL4xzomBV4rMH4Dl9drJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">mylink.tmp是一个lnk文件，木马会将其复制到%temp%\\mylink.lnk，并创建计划任务CLSUpdateService，滥用合法系统程序pcalua.exe执行该文件。</p><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013041" data-ratio="0.46574074074074073" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=069595e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKpxqHYWTWD9ngEqmc4ZGiaK3Oe3mhdfJG4icGqPot74E03XmkpChb0yTQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">mylink.tmp的功能是将之前释放的文件crypt86.da和profapii.da分别重命名为crypt86.dat和profapii.dat，并劫持系统COM组件0b91a74b-ad7c-4a9d-b563-29eef9167172，利用该COM组件执行crypt86.dat。</p><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013038" data-ratio="0.07692307692307693" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1053" src="https://wechat2rss.xlab.app/img-proxy/?k=99045d48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKZLzcqGbDalQiaEHJRH3XflXB5Sw9YWqz0z1dWXYO1durX3rToQ9EvoA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">子crypt86.dat模块模块</strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">crypt86.dat是一个dll文件。文件中的字符串，使用与之前相同的修改版base64算法进行编码。Dll文件执行后，解密需要加载的API名称，然后获取受害者主机名称和用户名等信息，并与字符串hebei进行拼接。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013044" data-ratio="0.19143239625167335" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="747" src="https://wechat2rss.xlab.app/img-proxy/?k=ba843573&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKOicO1P5L3r5K89ribm6GticUnhrTLibrWHwjQPibvTb4BlQJJNbKRhg0AaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">样本解密出内置的C2地址<a href="http://104.xxx.xxx.112/cache，并将之前拼接的字符串进行编码后，作为UA，对该地址进行访问。该地址返回的数据，以“ref”作为起始字符。样本从该数据中，提取出下一步需要访问的地址的路径X" target="_blank">http://104.xxx.xxx.112/cache，并将之前拼接的字符串进行编码后，作为UA，对该地址进行访问。该地址返回的数据，以“ref”作为起始字符。样本从该数据中，提取出下一步需要访问的地址的路径X</a></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">之后，样本解密出下一阶段C2地址<a href="http://104.xxx.xxx.112/list/，并根据上一阶段获取到的路径X，拼接出一个cab文件的地址，例如http://104.xxx.xxx.112/list/0.cab，然后进行访问。" target="_blank">http://104.xxx.xxx.112/list/，并根据上一阶段获取到的路径X，拼接出一个cab文件的地址，例如http://104.xxx.xxx.112/list/0.cab，然后进行访问。</a></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013043" data-ratio="0.36" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="725" src="https://wechat2rss.xlab.app/img-proxy/?k=593635c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKBpdLqWuOrrrLkM7ylGIh4tepGsq8WYLeY1pYYz7lqSgp9xUNicIXuJg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">该地址返回的内容不是一个cab文件，而是加密的数据。数据解密后如下图所示，该数据用于调用profapii.dat文件中的导出函数mscuicrypt，并包含需要传递给mscuicrypt函数的参数。</p><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013045" data-ratio="0.16111111111111112" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=076cbe23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKOYUedJEhekhDdlmKu4516YQ6kx4Srb3IgUYNVtSibg7xXE2joNsCNDw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">该数据中，包含有profapii.dat文件的完整路径，该路径中包含受害人的用户名。通过资产测绘，我们获取了多个C2服务器的加密配置。</p><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013047" data-ratio="0.6583333333333333" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a90084ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKoiaXB6Cb54HHmLycK8KuSw5gkra7OYs9icOhbqSJzzTX5U0KOxbOwsZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">经过我们对多个不同数据的对比发现，不同受害人执行的命令也不同。因此可以推测出，该数据是攻击者针对每个受害人定制化生成的，可能与攻击所达到的不同阶段有关。</p><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013046" data-ratio="0.2796296296296296" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5ef22b68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKVM9DLyCfaRuBIryzEfNicF3kgBspOKHX4V4CU05eRdD0MEpqHCKB4xw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">若获取cab内容失败，样本还会尝试访问<a href="https://bitbucket.org/xxxxx/refresh/downloads/update.txt，获取profapii.dat文件的执行参数。" target="_blank">https://bitbucket.org/xxxxx/refresh/downloads/update.txt，获取profapii.dat文件的执行参数。</a></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">之后，crypt86.dat便会根据获取到的路径和参数，执行profapii.dat的导出函数mscuicrypt。</p></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">子profapii.dat模块分析</strong></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">该dll只有一个导出函数mscuicrypt。该函数的功能，是解密传入的参数，从中获取指令、路径等信息，并执行不同的操作。经过分析，该函数可执行的操作共有三种。</p><p style="margin: 0px 0px 15px;text-indent: 2em;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">1. 从参数中，解密出一个远程地址和一个本地路径，从远程地址下载文件，并进行解密后，保存在本地路径下</p><p style="text-indent: 2em;margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">2. 从参数中，解密出一个本地路径，并加载执行。这个路径通常是“%appdata%\Microsoft\Windows\Templates\samtamples.dat”</p><p style="text-indent: 2em;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">3. 从参数中，解密出一个远程路径和一个本地路径。对本地路径下的文件进行遍历，获取所有文件名，拼接上特殊的字符后，进行加密，并设置为UA字符串，连接远程路径</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013050" data-ratio="0.26666666666666666" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3955973a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKt7jCooEfEN7m9U6bCXmiaEYmxfcrnBMgeoz8fQpgFvROH2roH9Z5d2A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">4</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnc0Dem0nBze869OURJnj2sKs7UMP2Zr0TzVWsxic46qGPiaiafCHamelGkMMVwem1LnM18xfcDsonb0Q/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">攻击溯源归因分析</strong></p></section></section></section></section></section></section></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">通过对这批邮件收件人、发件人等信息的收集分析，以及邮件涉及的木马行为的溯源，我们可以确定，这批钓鱼邮件，属于“伪猎者”APT组织针对我国涉韩相关人员的攻击活动样本，并且攻击来自于韩国。</p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">攻击水平高</strong></p><p style="margin: 0px 0px 15px;text-indent: 2em;white-space: normal;padding: 0px;box-sizing: border-box;">1. 仅在我们捕获到的样本中，就发现了攻击者使用了三个重量级的0day漏洞，合理推测，其漏洞储备，尤其是针对中国大陆地区进行攻击的漏洞储备，可能非常丰富。这需要丰富的资金支持和强大的技术能力。</p><p style="margin: 0px 0px 15px;text-indent: 2em;white-space: normal;padding: 0px;box-sizing: border-box;">2. 攻击者对不同的攻击对象，针对性生成钓鱼邮件，说明其组织实力强大，人员数量多，能够对不同的攻击对象进行针对性操作。</p><p style="margin: 0px 0px 15px;text-indent: 2em;white-space: normal;padding: 0px;box-sizing: border-box;">3. 在木马运行后，攻击者针对不同的主机，下发不同的攻击命令，这也是攻击者是有组织性，团队作战，有足够的精力来进行针对性操作的体现。</p><p style="text-indent: 2em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">4. 整个攻击过程中涉及到的远程服务器地址，从发件IP到各个阶段的数十个C2服务器，全部都是VPN或托管主机，说明该组织具有强大的资金支持来购买如此多的资产，且反溯源意识强。</p></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">与“伪猎者”组织的关联</strong></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">通过对木马样本的分析与关联，我们发现这批钓鱼邮件使用的木马，与之前披露的“伪猎者”APT所使用的木马，有着极高的相似度。</p><p style="margin: 0px 0px 15px;text-indent: 2em;white-space: normal;padding: 0px;box-sizing: border-box;">1. 使用的名称相同：释放的文件名、创建的计划任务名称、导出函数名称等；</p><p style="margin: 0px 0px 15px;text-indent: 2em;white-space: normal;padding: 0px;box-sizing: border-box;">2. 攻击手法相同：例如都利用COM劫持，运行恶意载荷、都使用cab文件来进行通信等；</p><p style="margin: 0px 0px 15px;text-indent: 2em;white-space: normal;padding: 0px;box-sizing: border-box;">3. 与“伪猎者”组织使用相同的特殊方式来拼接受害者信息，都为“Hebei,用户名;计算机名;profile路径”的方式。</p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">因此，可以确定这些钓鱼邮件为“伪猎者”APT组织的攻击邮件。</p></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><section style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">韩国相关证据</strong></p><p style="text-indent: 2em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">1. 在样本分析过程中，部分木马带有PDB字符串，且PDB字符串中带有韩文字符：</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013049" data-ratio="0.26545086119554206" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="987" src="https://wechat2rss.xlab.app/img-proxy/?k=04852780&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKTsKkkAGXjKCV71NQONPpRwP8ZvK6eKjTic64sSESB4hiaYDuk4dqZxgw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><p style="text-indent: 2em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">2. 在归属于“伪猎者”APT组织使用的攻击样本中，我们发现一个伪装FireEye相关的钓鱼文档，该文档疑似攻击者在做攻击前测试准备，我们发现其文档中东亚语言类别为ko-KR，即韩文：</p><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013048" data-ratio="0.07685185185185185" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=83609fab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sKomrzLH3rxPrf9ZGoib33f0oW3hn52ia8ME2bibEV1EbDvOyicY8Vgl6TOg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="box-sizing: border-box;"><p style="margin: 0px 0px 15px;text-indent: 2em;white-space: normal;padding: 0px;box-sizing: border-box;">3. 通过对钓鱼邮件收件人信息进行归纳总结，我们发现这批钓鱼邮件的收件人，通常都是与韩国有关联的中国公民或组织，包括政府公职人员、中韩贸易相关人员、民间组织、学者等；同时，攻击者在获取邮箱权限后，定向攻击的目标，也是与韩国相关的重要中方人士，针对性明显。</p><p style="margin: 0px 0px 15px;text-indent: 2em;white-space: normal;padding: 0px;box-sizing: border-box;">4. 部分受害者所处的城市，是地理位置距离韩国较近，与韩国交流较为频繁，或者对韩国有外贸往来等政策的城市。</p><p style="margin: 0px 0px 15px;text-indent: 2em;white-space: normal;padding: 0px;box-sizing: border-box;">5. 此次攻击所属的“伪猎者”组织，与“虎木槿”APT组织，共享部分基础设施，而“虎木槿”组织，是来自韩国的“DarkHotel”组织的一部分。</p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">结合此次攻击事件的高技术水平，雄厚的资金实力，与韩国有关的证据，以及“伪猎者”组织与韩国的关系，我们认定，此次攻击来自于韩国。</p></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 18px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 9px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">5</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnc0Dem0nBze869OURJnj2sKs7UMP2Zr0TzVWsxic46qGPiaiafCHamelGkMMVwem1LnM18xfcDsonb0Q/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">防范建议</strong></p></section></section></section></section></section></section></section></section></section></section><section style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2em;margin: 0px 0px 15px;text-align: justify;white-space: normal;padding: 0px;box-sizing: border-box;">软件漏洞向来是APT组织对目标进行攻击，运行木马的入口点。及时对系统、软件进行升级，可以大大减少被攻击者利用漏洞进行攻击的可能性。截至目前，该组织所利用的WPS漏洞和Foxmail漏洞都已修复，用户可通过官方网站，升级安装最新版软件来避免被这两个漏洞攻击，也可以选择安装安恒信息办公智盾进行防护。</p><p style="text-indent: 2em;margin: 0px 0px 15px;text-align: justify;white-space: normal;padding: 0px;box-sizing: border-box;">安恒信息办公智盾是面向办公网场景，解决复杂办公环境带来的接入管理难、入侵防护差、秘密保护虚、终端管理弱等痛点问题的综合性、一体化的安全“全家桶”产品！融合零信任、防病毒、主机审计、弱点检测、文件加密保护、数据防泄漏、基线检查、资产盘点、桌面管理、主机防火墙、隐形水印、绿色上网、网络准入、虚拟桌面等多种业务。</p><p style="text-indent: 2em;margin: 0px 0px 15px;text-align: justify;white-space: normal;padding: 0px;box-sizing: border-box;">目前安全数据部已具备相关威胁检测能力，对应产品已完成IoC情报的集成。<span style="text-indent: 2em;box-sizing: border-box;">安恒信息产品已集成能力：针对该事件中的最新IoC情报，以下产品的版本可自动完成更新，若无法自动更新则请联系技术人员手动更新：</span></p><p style="text-indent: 2em;margin: 0px 0px 15px;text-align: justify;white-space: normal;padding: 0px;box-sizing: border-box;">（1）AiLPHA分析平台V5.0.0及以上版本</p><p style="text-indent: 2em;margin: 0px 0px 15px;text-align: justify;white-space: normal;padding: 0px;box-sizing: border-box;">（2）AiNTA设备V1.2.2及以上版本</p><p style="text-indent: 2em;margin: 0px 0px 15px;text-align: justify;white-space: normal;padding: 0px;box-sizing: border-box;">（3）AXDR平台V2.0.3及以上版本</p><p style="text-indent: 2em;margin: 0px 0px 15px;text-align: justify;white-space: normal;padding: 0px;box-sizing: border-box;">（4）APT设备V2.0.67及以上版本</p><p style="text-indent: 2em;margin: 0px 0px 15px;text-align: justify;white-space: normal;padding: 0px;box-sizing: border-box;">（5）EDR产品V2.0.17及以上版本</p><p style="text-indent: 2em;margin: 0px 0px 15px;text-align: justify;white-space: normal;padding: 0px;box-sizing: border-box;">安恒信息再次提醒广大用户，请谨慎对待互联网中来历不明的文件，如有需要，请上传至安恒云沙箱<a href="https://sandbox.dbappsecurity.com.cn，进行后续判断。" target="_blank">https://sandbox.dbappsecurity.com.cn，进行后续判断。</a></p><p style="text-indent: 2em;margin: 0px 0px 15px;text-align: justify;white-space: normal;padding: 0px;box-sizing: border-box;">安恒云沙箱反馈与合作请联系：    </p><p style="text-indent: 2em;text-align: justify;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">sandbox@dbappsecurity.com.cn</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100013052" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=7f987ff0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvnc0Dem0nBze869OURJnj2sK8TYA3ib3HraiaUFvHSoBlWWVPtMvI0ickltWOladiaNO9T1EnaIHu9NYDw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496709">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5ce722f5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496709%26idx%3D1%26sn%3D0629689057d2e4c43b1adf59fb75f46a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 12 Aug 2024 10:48:00 +0800</pubDate>
    </item>
    <item>
      <title>FaCai团伙利用APT技术针对国内的攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496635&amp;idx=1&amp;sn=53104d45c7d1d651669eabbf8aa9790c</link>
      <description>利用MSC文件针对国内用户的攻击活动</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2024-07-23 11:13</span> <span style="display: inline-block;">浙江</span>
</p>

<p>利用MSC文件针对国内用户的攻击活动</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=1d017b54&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytqMQnQIuKo64GeTvKpccYw69FoI0MCwQruzpxxnrhLibzftlZypv57DQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012972" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c04876d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytUFMsic9IsoRJSlD1ib51rZCTd73knquEjPjImRj1FksdOBA0ZtHkEzqQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">1</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytENSybsmKhxdnhTrtEX65HmPh6uhbLbWDKXkGKoH7tEOOXKIMxDibDicQ/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">概述</strong></p></section></section></section></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">自微软默认禁用了来自互联网的文档中的Office宏之后，其他类型的恶意负载如JavaScript、MSI文件、LNK对象和ISO文件的使用量就开始急剧上升。然而此类恶意代码容易被杀毒软件查杀，有很高的被检测到的可能性。于是攻击者寻求利用新的、未公开的感染手段来获得访问权限，同时规避检测。</p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">近日，朝鲜威胁行为者Kimsuky在活动中利用了MSC文件，该文件在初次上传到VirusTotal平台时，检出为恶意样本的引擎为零。随后，国外安全人员将此类利用特定技术执行任意代码的MSC文件称为GrimResource。</p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">安恒研究院猎影实验室在日常威胁情报狩猎中捕获了同类型利用MSC文件针对国内用户的攻击活动。此类MSC文件利用apds.dll库中存在的XSS漏洞，在mmc.exe的上下文中执行任意Javascript代码，最终加载多阶段负载，实现对本机的远程控制攻击。</p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">安恒研究院猎影实验室在对相关恶意样本进行溯源关联后发现，该样本疑似来自国内黑产团伙“FaCai”，该团伙于2024年4月披露，主要使用魔改的Gh0st远控木马，通信流量包含大量“6666.6”字符串特征。该团伙在初期主要使用伪装成文档的PE文件直接引诱目标运行，中期逐渐转向使用MSI文件。近日，MSC文件利用初兴，我们便捕获到了来自该团伙的多枚MSC攻击样本。</p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">本次捕获的MSC样本加载流程如下：</p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012970" data-ratio="0.5017341040462427" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=3e63516a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytazIYyL7BgfibyNpLU0g9gFAm5MvfxKEib8M0n1mmmOusQ6ae3fgEuFqQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">2</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytENSybsmKhxdnhTrtEX65HmPh6uhbLbWDKXkGKoH7tEOOXKIMxDibDicQ/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">样本分析</strong></p></section></section></section></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">原始样本为MSC文件，其利用apds.dll库中存在的XSS漏洞，在mmc.exe的上下文中执行任意Javascript代码。</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012969" data-ratio="0.10867052023121387" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=87ac8fe6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytXJliakLZb2P7xprvIpicSL2SFfibnTPSnLAROumWibWNY9Ekgoia25rAOdg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">MSC文件包含的Javascript经Obfuscator混淆，包含大量无效难读的代码。去混淆后的结果如下，代码将请求hxxp://154.82.92.201/0day.js进一步执行</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012968" data-ratio="0.44046242774566474" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=47b1009f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytPlZO5v3zGhfQ6iaOINJINzBCDM93FxeNdXoiaEupGTfJLcysFsXyBl4g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">Javascript经去混淆，解密部分字符串后，部分代码如下，其将继续请求hxxp://154.82.92.201/0day.xsl执行</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012971" data-ratio="0.24393063583815028" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=b46d08fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytWGNp018ZiaLD5FFicgkTnbWBz4FVL9kkiabm8upcRsqOLshIDtSwkJF1g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">XML文件中包含Base64编码后的PE文件，通过反序列化后加载至内存执行</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012973" data-ratio="0.20578034682080926" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=b7e88e69&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytwzbicw1Mb3SIZg0yHxFzmRicAH10FOQxhPKFYiaYzVy91QBCTR2Mrh1Wg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">PE文件名为TestAssembly.dll，包含PDB路径：C:\Users\Administrator\Desktop\Msc\乌云\x道 - 154.82.92.201\GadgetToJScript\TestAssembly\obj\Debug\TestAssembly.pdb</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012976" data-ratio="0.1905564924114671" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="593" src="https://wechat2rss.xlab.app/img-proxy/?k=21a0d1a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytL4nlG11woZiaHY7gAsle19ahWUwGGkhZK3dgu1iaQlWN7d62YyXvI6icQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">文件运行后，将访问x道翻译的下载页面，并下载x道翻译的安装包到本地。此举意在迷惑用户，让用户认为运行了真的x道翻译安装软件。</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012974" data-ratio="0.4554913294797688" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=eb5722e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytQKKyex7zc0XhT2BowIlx87nricAXNiaJlmc6KsHHzs1VgJ9a9iaW0HHAg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">同时该文件还将创建名为Wd的计划任务，用于在用户登录时启动本地文件：C:\\Users\\Public\\Music\\Wd\\Wd.exe</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012975" data-ratio="0.33179190751445087" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=cafbda26&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytcf0eiaEDu0AW0n4uicI7CB5CaLEnyEEJsd3BWgWRepwibQKiaN2U8j3Avw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">接着该加载器将下载一系列用于运行后续的环境依赖，如Bandzip组件、Python组件以及AutoHotkey等。并使用Bandzip解压Py.7z文件</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012977" data-ratio="0.4531791907514451" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=603af694&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytpyZNOXaQg5l3ia7j9QBFdJkljupIZcv3L5jicgA5BtfTOYNoNO0ROkwg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">最后运行Wd.exe以及使用python运行code.jpg文件包含的代码</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012979" data-ratio="0.3202312138728324" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=6cd19594&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytF6lkGVp5fXDoM93icMoJeCW0ADQrzxxCOmWC9ONIicG5jE2PAexicEgMQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">code.jpg文件包含的代码将继续下载Shellcode执行，其请求的远程地址如下hxxp://comc0m.com/dan/154.82.92.201.bin</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012978" data-ratio="0.20346820809248556" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=0d9a9fb5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33yt2gM6ribOks9ktP5ezmqrKjnHlEh3R1eia8vVKOmG93cDBGT5QwguzFJg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">最终在本地加载的Shellcode为Winos组件（Gh0st魔改的远控木马），C2地址为154.82.92.201，端口1688</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012980" data-ratio="0.29132947976878615" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=cf8b808e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33yt7cVdgI32pt2Gibecww5xshYXpJGmPyfaNfia5uRTs1b4dRhbGR8bbCGQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">安恒云沙箱识别出该恶意木马的归属家族为Gh0st，并捕获到的流量特征中包含大量“6666.6”字符串特征</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012981" data-ratio="0.49248554913294795" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=50f29aa5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytLSUpumHibMKVUibhacmKGrc3r4c5A4okIYgYUviccPNMwDMlDmllKndQg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">3</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytENSybsmKhxdnhTrtEX65HmPh6uhbLbWDKXkGKoH7tEOOXKIMxDibDicQ/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">溯源关联</strong></p></section></section></section></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">我们捕获到的同源MSC文件如下，其中youdaofanyiDD.msc同本文分析的YoudaoDict-Setup-installe-LDZ.msc一致，均为伪装x道翻译软件下载安装包；Setup.msc仿冒Chrome浏览器下载站；教育行业数据a.msc文件未设置正常网页访问。</span></p></section></section><section style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><section style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;" width="100%"><tbody style="box-sizing: border-box;"><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:32.classicTable1:0" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:32.classicTable1:0.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">文件名</strong></p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:32.classicTable1:0.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">第一阶段回连地址</strong></p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:32.classicTable1:1" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:32.classicTable1:1.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: left;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">youdaofanyiDD.msc</p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:32.classicTable1:1.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">hxxp://laicai168.com/0day.xsl</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:32.classicTable1:2" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:32.classicTable1:2.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">抖音千粉企业号3F.msc</p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">教育行业数据a.msc</p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:32.classicTable1:2.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">hxxp://118.107.42.233/0day.xsl</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:32.classicTable1:3" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:32.classicTable1:3.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: left;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">Setup.msc</p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:32.classicTable1:3.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">hxxp://154.91.65.103/0day.xsl</p></section></section></td></tr></tbody></table></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">此次捕获的MSC文件与FaCai团伙活动的相似性及归因：</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">1.  作为针对国内用户的攻击活动，初始阶段均采用x道翻译软件安装包为诱饵；</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">2.  攻击链均涉及Windows脚本执行工具AutoHotkey.exe、python执行环境；</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">3.  Payload下载域名均为comc0m.com；</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">4.  最终加载的木马均为魔改的Gh0st远控木马；</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">5.  加密通信流量反复出现字符串“6666.6”，且通信端口域名多为6、8的组合，通信域名或PE文件包含“facai”、“laicai”字符串。</span></p></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">4</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytENSybsmKhxdnhTrtEX65HmPh6uhbLbWDKXkGKoH7tEOOXKIMxDibDicQ/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">防范建议</strong></p></section></section></section></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="font-size: 15px;line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">猎影实验室提醒广大用户朋友，不运行未知来源的邮件附件。如有需要鉴别的未知来源样本，可以投递至安恒云沙箱查看判别结果后再进行后续操作。猎影实验室将持续对全球APT组织进行持续跟踪，专注发现并披露各类威胁事件。</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">目前安全数据部已具备相关威胁检测能力，对应产品已完成IoC情报的集成。针对该事件中的最新IoC情报，以下产品的版本可自动完成更新，若无法自动更新则请联系技术人员手动更新：</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">1.   AiLPHA分析平台V5.0.0及以上版本</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">2.   AiNTA设备V1.2.2及以上版本</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">3.   AXDR平台V2.0.3及以上版本</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">4.   APT设备V2.0.67及以上版本</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">5.   EDR产品V2.0.17及以上版本</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">安恒云沙盒已集成了海量威胁情报及样本特征。用户可通过云沙盒：<a href="https://sandbox.dbappsecurity.com.cn/对可疑文件进行威胁研判并下载分析报告。或用沙箱打开不明来源的未知文件，在虚拟环境中进行内容预览，免于主机失陷、受到木马或病毒文件攻击。" target="_blank">https://sandbox.dbappsecurity.com.cn/对可疑文件进行威胁研判并下载分析报告。或用沙箱打开不明来源的未知文件，在虚拟环境中进行内容预览，免于主机失陷、受到木马或病毒文件攻击。</a></p></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012982" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=53ce56d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvnfPvWbsShXiaTYKdr29Q33ytxcXkGOpdCueo7gWA8hBdOKO4mF9ZLSo1hOx52txosNn8AxJo6iaPXsQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496635">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b9c6464d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496635%26idx%3D1%26sn%3D53104d45c7d1d651669eabbf8aa9790c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 23 Jul 2024 11:13:00 +0800</pubDate>
    </item>
    <item>
      <title>Patchwork APT以中国高校信息办通知为诱饵的攻击事件分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496557&amp;idx=1&amp;sn=90cc17870fb180eb80394c4be1d93f79</link>
      <description>Patchwork APT以中国高校信息办通知为诱饵的攻击事件分析</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2024-07-11 15:46</span> <span style="display: inline-block;">浙江</span>
</p>

<p>Patchwork APT以中国高校信息办通知为诱饵的攻击事件分析</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=24802b83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3iclwtMFvkOibuVXSNUIQ7Q6EsseE9qNqHmk6SngKnx7vTO5iaFpdUJUpqw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012893" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=de2354a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icJcGqYK0qtkPmTwgm0rpNBhgUDGMvxs4PRywWClKTZicNQ69eVibgKr1Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">1</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icJsySVmGXcZTbY3NibMcd8rYqbw0cVDLvCpVGoicslRriaN0HAyNTS6eQA/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">概述</strong></p></section></section></section></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">Patchwork组织又名Hangover、Dropping Elephant，最早披露于2013年。最早攻击活动可以追溯到2009年，主要针对中国、巴基斯坦等亚洲地区和国家进行网络间谍活动。在针对中国地区的攻击中，其主要针对政府机构、科研教育领域进行攻击。具有Windows、Android、macOS 多系统攻击的能力。</span></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">近日，安恒研究院猎影实验室在日常威胁情报狩猎中捕获了Patchwork APT组织的攻击样本，相关样本以“关于中国某大学统一电子签章平台上线试运行的通知”为话题，针对国内教育单位的工作人员进行钓鱼攻击。相关攻击活动以LNK文件作为初始攻击负载，引诱目标运行后，将下载PDF文件及EXE文件到本地，自动打开PDF文件以降低目标防备心理，并设置计划任务运行恶意EXE文件。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">值得注意的是，Patchwork组织自23年12月开始使用编程语言Rust编写恶意软件以逃避杀软检测，截至24年6月，我们已经捕获了6起使用Rust负载的攻击活动。其中不乏国内军事、水利、教育相关的目标，我们将此类加载器命名为RustyNet Loader。除Rust语言外，Patchwork还在活动中积极使用Golang、C#等语言编写的恶意软件。</span></p></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">2</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icJsySVmGXcZTbY3NibMcd8rYqbw0cVDLvCpVGoicslRriaN0HAyNTS6eQA/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">样本诱饵</strong></p></section></section></section></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">本次捕获样本释放到本地的诱饵文件如下，内容为“关于中国某大学统一电子签章平台上线试运行的通知”</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012892" data-ratio="0.9337837837837838" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="740" src="https://wechat2rss.xlab.app/img-proxy/?k=34dc8b3f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icwOOsfBoXKKNy50Rsn3iaNLXria5uZkiciaotV7FBsu73hxjerpGnAn0vTw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">此外，我们通过该组织的网络基础设施关联到另一疑似针对我国事业单位的诱饵文件如下：</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012889" data-ratio="0.45709281961471104" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="571" src="https://wechat2rss.xlab.app/img-proxy/?k=75c76c5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3ic5dfbiahmicclJzV2OVwmBflDLwEoshQb7IQ396bBtEdicemgHtJaPn3pw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">3</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icJsySVmGXcZTbY3NibMcd8rYqbw0cVDLvCpVGoicslRriaN0HAyNTS6eQA/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">样本攻击流程</strong></p></section></section></section></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">原始样本为LNK文件，执行后攻击流程如下：</span></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">1.  文件运行后使用Invoke-WebRequest命令分别从指定的URL下载PDF及ISO文件，并将其保存到指定的本地路径（具体URL见附录IOC）；</span></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">2.  运行PDF文件并挂载ISO文件，复制ISO文件内容到指定目录，复制PDF文件到当前目录；</span></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">3.  创建名为EdgeUpdateTask的计划任务以运行后续负载；</span></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">4.  删除运行过程中产生的ISO及其他文件。</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012891" data-ratio="0.24277456647398843" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=1e3ba26f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3iceyI2vPYicgnic3XH0icl7SAtD4oPJjicfRRpelznw8sO17bIkaxvwbX24A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">ISO文件中包含Rust语言编写的加载器，运行后将进一步请求远程资源文件</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012890" data-ratio="0.2731034482758621" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="725" src="https://wechat2rss.xlab.app/img-proxy/?k=03d33d25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icecKxiar9HmNkZnSbqD11rGk7HI2B1ZyWUODs1cXFgf5oMG4ysdYeWaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">并在内存中加载执行执行</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012894" data-ratio="0.42482758620689653" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="725" src="https://wechat2rss.xlab.app/img-proxy/?k=77176340&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3ic16gL5fPpJH6TWy9BNXarYYow3y2ROfuibHhakMUmrMSu2tmicMY3Yxqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">Shellcode在内存加载后，将再次分配内存空间，解密后续负载执行</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012897" data-ratio="0.38265895953757223" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=261631bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icW9wc02PcgozIUo9J31v7jeK3s7n8dwoNYMyaG959oReMDw5GLXpJWA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">最终有效负载为C#语言编写，其功能包括窃取本机信息发送，接收C2指令执行。其中主函数执行逻辑如下：</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012898" data-ratio="0.5907514450867052" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=a57cbb87&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icAXpEdcXNPBl9vqdxxYqyqJP3fabUURk2zfQjf9JWrXHql2eaiaOmFLA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">使用本机UUID、系统版本及时间戳生成序列号，随后使用序列号在服务器进行“注册”，注册第一阶段发送simpleid={编码后的序列号}&amp;fiiir=bhiii&amp;uqid=</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012895" data-ratio="0.4554913294797688" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=dbb1c2a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icBEJP5tyKoANfPM4r93ia3Vq9ibM8ENf6W5e1jbdyY20drn93NyeoxR9A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">注册第二阶段发送本机mac地址、用户名、是否为admin权限等其他信息</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012896" data-ratio="0.5965317919075145" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=333f6f6b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3ic7drlclGx7S4mib55T5z6YiarNprx5kFIttWIOJNnjQpjEU2qvnpGWRVA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">获取C2服务器回传指令，判断指令长度，若大于2则进行指令解析。如果指令中包含字符串“lksfjdgjkxv”，则进入指令执行，部分远控指令如下：</span></p></section></section><section style="line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012899" data-ratio="0.3398843930635838" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=1da3eb36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icQ61tCfShgRTmiaydPtd2cjX8CiaU5r40l5OGOoZOOibCaXLv1VGhiaR43w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">最后上传指令执行结果到C2服务器。</span></p></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 1;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: bottom;width: 38px;align-self: flex-end;flex: 0 0 auto;height: auto;padding: 0px;margin: 0px;box-sizing: border-box;"><section style="font-size: 19px;text-align: center;margin: 0px 0px 2px;box-sizing: border-box;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(0, 0, 0);background-color: rgb(0, 0, 0);width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 10px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">4</strong></p></section></section><section style="text-align: center;margin: 0px;box-sizing: border-box;"><section style="background-color: rgb(205, 234, 245);height: 4px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;"><section style="z-index: 3;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 50% 50%;background-repeat: no-repeat;background-attachment: scroll;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;margin: 0px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_gif/AvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3icJsySVmGXcZTbY3NibMcd8rYqbw0cVDLvCpVGoicslRriaN0HAyNTS6eQA/640?wx_fmt=gif&amp;from=appmsg&#34;);box-sizing: border-box;background-size: 100% 100% !important;"><section style="text-align: justify;color: rgb(0, 0, 0);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">关联</strong></p></section></section></section></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="font-size: 15px;line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">通过本次捕获样本请求域名，我们关联到了如下域名及URL，其中域名均为疑似针对国内的攻击活动使用。</p></section></section><section style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><section style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;"><tbody style="box-sizing: border-box;"><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:28.classicTable1:0" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:28.classicTable1:0.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="221"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">域名</strong></p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:28.classicTable1:0.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="234"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">目标</strong></p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:28.classicTable1:1" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:28.classicTable1:1.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="NaN"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: left;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">centling.nihaoucloud.org</p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:28.classicTable1:1.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="234"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">伪装成中国IT公司</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:28.classicTable1:2" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:28.classicTable1:2.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="NaN"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: left;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">hengtian.nihaoucloud.org</p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:28.classicTable1:2.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="234"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">伪装成中国企业</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:28.classicTable1:3" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:28.classicTable1:3.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="NaN"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: left;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">weibo.nihaoucloud.org</p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:28.classicTable1:3.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="234"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">伪装成中国社交网络平台</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:28.classicTable1:4" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:28.classicTable1:4.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="NaN"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: left;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">xinhuanet.nihaoucloud.org</p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:28.classicTable1:4.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="234"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">伪装成国内新闻网站</p></section></section></td></tr></tbody></table></section></section><section style="margin: 10px 0px;box-sizing: border-box;"><section style="font-size: 15px;line-height: 2;padding: 0px 15px;box-sizing: border-box;"><section style="word-break: break-all;white-space: normal;margin: 16px 0px 0px;padding: 0px;box-sizing: border-box;">相关URL及托管的恶意负载如下</section></section></section><section style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;"><section style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;" width="100%"><tbody style="box-sizing: border-box;"><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:30.classicTable1:0" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:30.classicTable1:0.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">URL</strong></p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:30.classicTable1:0.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">托管文件</strong></p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:30.classicTable1:1" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:30.classicTable1:1.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="text-align: left;padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><a href="https://hengtian.nihaoucloud.org/gtw2jh43/css.txt" target="_blank">https://hengtian.nihaoucloud.org/gtw2jh43/css.txt</a></p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:30.classicTable1:1.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="font-size: 14px;text-align: center;padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">WebShell</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:30.classicTable1:2" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:30.classicTable1:2.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="text-align: left;padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><a href="https://weibo.nihaoucloud.org/akowutbuu753dtRWq21jk/odiworukdjo2375kjkl1lk87hl0" target="_blank">https://weibo.nihaoucloud.org/akowutbuu753dtRWq21jk/odiworukdjo2375kjkl1lk87hl0</a></p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:30.classicTable1:2.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="text-align: center;padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">Golang恶意软件</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:30.classicTable1:3" style="box-sizing: border-box;"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:30.classicTable1:3.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="text-align: left;padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><a href="https://xinhuanet.nihaoucloud.org/koqiiwyekj5458bj32uoiWQ21/kjtw83nkQ" target="_blank">https://xinhuanet.nihaoucloud.org/koqiiwyekj5458bj32uoiWQ21/kjtw83nkQ</a></p></section></section></td><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:30.classicTable1:3.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;"><section style="text-align: center;padding: 0px 5px;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">PDF诱饵文件</p></section></section></td></tr></tbody></table></section></section><section style="text-align: center;margin-bottom: 10px;line-height: 0;box-sizing: border-box;margin-top: 24px;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012903" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=88fef43f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvndr2Fy6Fsqxf6DZcadmUib3iceHgtZC82mIIp0ejDk750NwtyxEYZObAdGgG6MMh7e1xSiaPucEK2Crg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496557">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b86abc54&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496557%26idx%3D1%26sn%3D90cc17870fb180eb80394c4be1d93f79%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 11 Jul 2024 15:46:00 +0800</pubDate>
    </item>
    <item>
      <title>2024西湖论剑・AI引领数字安全新浪潮专题会议成功举办</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496533&amp;idx=1&amp;sn=120fe524475e094961ef776f3e131563</link>
      <description>共同探讨AI引领数字安全新质生产力的发展之道</description>
      <content:encoded><![CDATA[<p>
<span>安恒信息</span> <span>2024-05-20 10:51</span> <span style="display: inline-block;">浙江</span>
</p>

<p>共同探讨AI引领数字安全新质生产力的发展之道</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=9f14c530&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnfQqCibenBLZox4T7g7PuibuPLkYXIPeuYnvPa6pAJQ36RnmVF1Yq7OGt0tJoWne7ApRz4CHPSYtGzg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p data-mpa-powered-by="yiban.io" style="margin-bottom: 0px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;"><img class="rich_pages wxw-img" data-imgfileid="100012863" data-ratio="0.2777777777777778" style="outline: 0px;letter-spacing: 0.578px;visibility: visible !important;width: 676.997px !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9ecf45a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FicVz8RbowK3y6lN0n6DKQQY4LWF2ibvIyZbwmFPmQeFib1fm4AFejPz2FMMTC3B4pPpUU3gNpgXIQjFUuXBW7katw%2F640%3Fwx_fmt%3Dother%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1%26tp%3Dwebp"/></p><section style="margin-bottom: 0px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 15px;line-height: 2;visibility: visible;"><section style="margin-top: 16px;margin-bottom: 16px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;visibility: visible;"><section style="outline: 0px;display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 0%;border-style: solid;border-width: 0px 0px 0px 6px;border-color: rgb(86, 165, 215) rgb(86, 165, 215) rgb(86, 165, 215) rgb(13, 80, 201);height: auto;"><section style="margin-bottom: -6px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-6px, 0px, 0px);"><section style="outline: 0px;display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 0%;height: auto;line-height: 0;align-self: flex-end;"><section style="outline: 0px;"><section style="outline: 0px;display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 6px 0px 0px 6px;border-color: rgb(0, 202, 254) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0);"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section><section style="outline: 0px;display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 6px;border-color: rgb(132, 108, 65) rgb(132, 108, 65) rgb(0, 202, 254);line-height: 0;min-width: 5%;height: auto;"><section style="outline: 0px;text-align: center;"><section style="outline: 0px;display: inline-block;width: 15px;height: 15px;vertical-align: top;overflow: hidden;"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section></section></section><section style="margin-right: -21px;margin-left: -21px;padding: 20px;outline: 0px;display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 100 100 0%;background-color: rgb(235, 242, 250);height: auto;"><section style="outline: 0px;text-align: justify;"><p style="margin-bottom: 15px;outline: 0px;">5月18日，<strong style="outline: 0px;"><span style="outline: 0px;color: rgb(190, 28, 18);">2024西湖论剑·AI引领数字安全新浪潮专题会议</span></strong>成功召开。业界精英围绕AI+安全，共同探讨AI引领数字安全新质生产力的发展之道，解锁未来无限奥秘。</p><p style="outline: 0px;">中国网络空间安全协会副理事长、中国网络空间安全协会人工智能安全治理专业委员会主任卢卫，浙江省杭州市科学技术协会党组成员、副主席王菊红，浙江移动信息技术与数据管理部总经理、中国移动集团首席专家王晓征，浙江移动信息安全部总经理王延长，杭州市科协学会管理部（科技创新部）部长余勇平，海亮集团轮值总裁何文天，<span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 15px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(235, 242, 250);">安恒信息董事长范渊，</span>上海市大数据中心基础设施部副部长靳玲，中国科学技术大学网络空间安全学院执行院长俞能海，天津大学信息与网络中心主任于瑞国，杭州市人工智能协会秘书长赵星伦，以及相关行业领导和企业专家出席论坛，教育部新工科联盟网络空间安全工委会主任委员、俄罗斯国家工程院外籍院士胡瑞敏主持论坛。</p></section><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100012864" data-ratio="0.6666666666666666" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 626.753px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6763f579&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibSibTZUo04m21QicSXh3UOkibINh6wEaibZichOVbaBQDQ4ADbXSic15SQnMg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: justify;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">教育部新工科联盟网络空间安全工委会主任委员、俄罗斯国家工程院外籍院士胡瑞敏主持论坛</p></section><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;"><img class="rich_pages wxw-img" data-imgfileid="100012865" data-ratio="0.6666666666666666" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 626.753px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3aa44267&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibhaPweiaql8EB5WhkzXiae6MctHqER2Ls2m13ShqcXibbQR3ibsXjuicGVww%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: justify;font-size: 12px;"><p style="outline: 0px;">中国网络空间安全协会副理事长、中国网络空间安全协会人工智能安全治理专业委员会主任卢卫出席</p></section></section><section style="outline: 0px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><section style="outline: 0px;transform: perspective(0px);transform-style: flat;"><section style="outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;transform: rotateX(180deg) rotateY(180deg);"><section style="outline: 0px;display: inline-block;width: auto;vertical-align: bottom;align-self: flex-end;flex: 0 0 0%;border-style: solid;border-width: 0px 0px 0px 6px;border-color: rgb(86, 165, 215) rgb(86, 165, 215) rgb(86, 165, 215) rgb(13, 80, 201);height: auto;"><section style="margin-bottom: -6px;outline: 0px;justify-content: flex-start;display: flex;flex-flow: row;transform: translate3d(-6px, 0px, 0px);"><section style="outline: 0px;display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 0%;height: auto;line-height: 0;align-self: flex-end;"><section style="outline: 0px;"><section style="outline: 0px;display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 6px 0px 0px 6px;border-color: rgb(0, 202, 254) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0);"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section><section style="outline: 0px;display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 6px;border-color: rgb(132, 108, 65) rgb(132, 108, 65) rgb(0, 202, 254);line-height: 0;min-width: 5%;height: auto;"><section style="outline: 0px;text-align: center;"><section style="outline: 0px;display: inline-block;width: 15px;height: 15px;vertical-align: top;overflow: hidden;"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section></section></section></section></section></section></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="outline: 0px;display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;"><section style="outline: 0px;transform: perspective(0px);transform-style: flat;"><section style="outline: 0px;text-align: left;transform: rotateX(180deg);"><section style="outline: 0px;display: inline-block;width: 125.052px;height: 7px;vertical-align: top;overflow: hidden;background-image: linear-gradient(90deg, rgb(26, 201, 156) 0%, rgba(63, 198, 215, 0) 100%);"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section><section style="outline: 0px;text-align: justify;color: rgb(62, 62, 62);font-size: 16px;"><p style="outline: 0px;"><strong style="outline: 0px;">AI引领，构建数字安全新质生产力</strong></p></section><section style="outline: 0px;transform: perspective(0px);transform-style: flat;"><section style="outline: 0px;text-align: left;transform: rotateY(180deg);"><section style="outline: 0px;display: inline-block;width: 125.052px;height: 7px;vertical-align: top;overflow: hidden;background-image: linear-gradient(90deg, rgb(26, 201, 156) 0%, rgba(63, 198, 215, 0) 100%);"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section></section></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;">2023年以来，人工智能蓬勃发展，为数字安全领域带来了全新的生态环境和产业格局。我们在拥抱AI的同时，也不能不严防AI可能带来的数据泄露、深度伪造等风险。<strong style="outline: 0px;"><span style="outline: 0px;color: rgb(190, 28, 18);">以AI对AI，以AI管AI，</span></strong>成为推动人工智能与网络安全技术的深度融合，构建数字安全新质生产力，为经济社会发展和国家安全提供有力保障的必然选择。</p><p style="outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 2em;">CCF计算机安全专业委员会常务副主任、公安部第一研究所副所长于锐在视频致辞中表示，人工智能的飞速发展以及AI技术的广泛应用对数字安全带来了全新的挑战与机遇，数据安全、算法安全、隐私保护等问题日益凸显。对于如何在享受技术红利的同时，构建更加坚固的数字安全屏障，实现传统网络与数据安全的革命性升级，打造新型的AI+网络和数据安全体系，<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 2em;color: rgb(190, 28, 18);">他提出四点建议：</span></strong>一是加强协同创新，共建安全生态；二是开展技术革新，驱动安全升级；三是加大法规引领，保障健康发展；四是强化人才培养，强化安全根基。</span></p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012867" data-ratio="0.6666666666666666" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1653ad88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibojDQ8xDNJHZYJtprEG3oTs0SUBJHLicdeKicypIWnI3dlckVW4MFyGdg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="padding-right: 15px;padding-left: 15px;outline: 0px;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">CCF计算机安全专业委员会常务副主任、公安部第一研究所副所长于锐视频致辞</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 0em;">俞能海教授发表《生成式人工智能安全与新质数字资产》主题演讲时指出，人工智能向生成式跨越，全面提升理解能力，AIGC不断取得突破，多模态大模型快速发展，<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 0em;color: rgb(190, 28, 18);">人工智能安全的保障将成为人工智能可靠可控应用的重要基础。</span></strong>为规避AIGC风险，不能单纯依赖智能算法，而是将人创造能力与AI的生成能力有效结合。</span></p><p style="outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 0em;">对此，俞教授建议从<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 0em;color: rgb(190, 28, 18);">三个维度</span></strong>进行：一是利用AIGC合成内容鉴别，应对AI的恶意应用；二是通过大模型纠偏，提升AI的安全能力；三是借助生成式模型水印，保护AI赋能的系统。</span></p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012866" data-ratio="0.6657407407407407" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7315e79e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibWrCDvJrfGPaoy0GGfZn3XBH2Tb1LLH09G8tINaAUSPOn32D4Yic6icgg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">中国科学技术大学网络空间安全学院执行院长俞能海</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 0em;">安永（中国）企业咨询有限公司合伙人王坚在《AI大模型技术演进及应用》的主题演讲中指出，未来AI大模型技术演进路线可能沿着<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 0em;color: rgb(190, 28, 18);">六大维度</span></strong>发展：</span></p></section><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section data-lazy-bgimg="https://mmbiz.qpic.cn/sz_mmbiz_png/icVz8RbowK3xuead6iaXpwQuRtlXGNhGwib04kDwMib2nHKnnlQnHZMmXroSNQlfJxR7MHMzj2SicaQibXUNnuVc96GA/640?wx_fmt=png&amp;from=appmsg" data-fail="0" style="padding: 15px;outline: 0px;display: inline-block;width: 676.997px;vertical-align: top;background-position: 0% 0%;background-repeat: repeat;background-attachment: scroll;align-self: flex-start;flex: 0 0 auto;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icVz8RbowK3xuead6iaXpwQuRtlXGNhGwib04kDwMib2nHKnnlQnHZMmXroSNQlfJxR7MHMzj2SicaQibXUNnuVc96GA/640?wx_fmt=png&#34;);background-size: 35.9822% !important;"><section style="outline: 0px;color: rgb(73, 89, 112);text-align: justify;"><p style="outline: 0px;">一、模型规模的增长，大模型参数数量激增；</p><p style="outline: 0px;">二、多模态学习，能够处理多种数据类型的应用和场景；</p><p style="outline: 0px;">三、提高模型训练和推理的效率和可持续性；</p><p style="outline: 0px;">四、提升模型决策过程的透明度和可解释性，减少“黑箱”现象；</p><p style="outline: 0px;">五、使模型具备连续学习能力，避免灾难性遗忘，适应动态环境中的新数据和变化；</p><p style="outline: 0px;">六、确保模型在恶意攻击下的稳定性和安全性，增强鲁棒性。</p></section></section></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012869" data-ratio="0.6666666666666666" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=809cabea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibYcU6zCicgbhvEicMrLkyuGQDe0EZTt6Ps2r7e6DUHMgrQBhLzicorFSUg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">安永（中国）企业咨询有限公司合伙人王坚</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="outline: 0px;display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;"><section style="outline: 0px;transform: perspective(0px);transform-style: flat;"><section style="outline: 0px;text-align: left;transform: rotateX(180deg);"><section style="outline: 0px;display: inline-block;width: 131.094px;height: 7px;vertical-align: top;overflow: hidden;background-image: linear-gradient(90deg, rgb(26, 201, 156) 0%, rgba(63, 198, 215, 0) 100%);"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section><section style="outline: 0px;text-align: justify;color: rgb(62, 62, 62);font-size: 16px;"><p style="outline: 0px;"><strong style="outline: 0px;">Al+安全，探索安全行业的创新未来</strong></p></section><section style="outline: 0px;transform: perspective(0px);transform-style: flat;"><section style="outline: 0px;text-align: left;transform: rotateY(180deg);"><section style="outline: 0px;display: inline-block;width: 131.094px;height: 7px;vertical-align: top;overflow: hidden;background-image: linear-gradient(90deg, rgb(26, 201, 156) 0%, rgba(63, 198, 215, 0) 100%);"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section></section></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;">当前安全产业，从技术角度存在安全天平和能力鸿沟等问题，AI时代下的数据安全、内容安全、业务安全、供应链安全等安全问题尤为突出。</p><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;">在此背景下，杭州人工智能学会副秘书长、安恒信息研究院院长王欣在《Al之于安全行业的应用探索》的主题演讲中提出，<strong style="outline: 0px;"><span style="outline: 0px;color: rgb(190, 28, 18);">AI+安全一定是安全未来发展的巨大方向。</span></strong></p><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;">王欣指出，人工智能创立之初即是模拟、延伸和扩展人的智能理论、方法、技术和应用系统的一门技术学科。大模型的涌现能力，相比于过往人工智能技术，在<strong style="outline: 0px;"><span style="outline: 0px;color: rgb(190, 28, 18);">理解指令、理解例子、思维链能力和快速学习能力</span></strong>四个维度得到了更多的能力增强，分享了过去在数据安全、安全运营等多个场景下的安全大模型实践经验。</p><p style="outline: 0px;text-indent: 0em;">王欣认为，AI之于安全，其真正的AI能力只发挥了不足5%，<strong style="outline: 0px;"><span style="outline: 0px;color: rgb(190, 28, 18);">同时他对AI之于安全的应用趋势做出了八大预判：</span></strong></p></section><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;"><section data-lazy-bgimg="https://mmbiz.qpic.cn/sz_mmbiz_png/icVz8RbowK3xuead6iaXpwQuRtlXGNhGwib04kDwMib2nHKnnlQnHZMmXroSNQlfJxR7MHMzj2SicaQibXUNnuVc96GA/640?wx_fmt=png&amp;from=appmsg" data-fail="0" style="padding: 15px;outline: 0px;display: inline-block;width: 676.997px;vertical-align: top;background-position: 0% 0%;background-repeat: repeat;background-attachment: scroll;align-self: flex-start;flex: 0 0 auto;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_png/icVz8RbowK3xuead6iaXpwQuRtlXGNhGwib04kDwMib2nHKnnlQnHZMmXroSNQlfJxR7MHMzj2SicaQibXUNnuVc96GA/640?wx_fmt=png&#34;);background-size: 35.9822% !important;"><section style="outline: 0px;color: rgb(73, 89, 112);text-align: justify;"><p style="outline: 0px;">一、大模型为核心的AI智能体（AI Agents）将成为安全产业的标配，越来越多的AI Native工具将成为Agent的“手和脚”；</p><p style="outline: 0px;">二、在AI智能体的影响下，自适应安全架构将得到全新升级；</p><p style="outline: 0px;">三、在AI智能体的影响下，机器人流程自动化将与许多安全业务相结合；</p><p style="outline: 0px;">四、AI智能体将重塑安全工作协同方式；</p><p style="outline: 0px;">五、AI多模态技术的不断演进，舆论战、信息战、涉网新型犯罪将率先应用AI技术获得技术“红利”，监管将面临前所未有的挑战；</p><p style="outline: 0px;">六、安全攻防将进入全新阶段，智能攻击与智能防御成为新的技术博弈领域，AI原生的蠕虫病毒或将席卷全球；</p><p style="outline: 0px;">七、AI时代下的数据安全、内容安全、业务安全、供应链安全等安全问题尤为突出，将会给AI产业应用和发展带来挑战；</p><p style="outline: 0px;">八、AI时代带来安全产品的全面升级革新，能力原子化、接口标准化将快速推进。</p></section></section></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012872" data-ratio="0.6657407407407407" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4fe148d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibsYozlBJBkf9zliaTwpaFuc2AztcBSNymKLXzOjJ3wIEx3PVAtU7Q8Sg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">杭州人工智能学会副秘书长、安恒信息研究院院长王欣</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="outline: 0px;display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;"><section style="outline: 0px;transform: perspective(0px);transform-style: flat;"><section style="outline: 0px;text-align: left;transform: rotateX(180deg);"><section style="outline: 0px;display: inline-block;width: 124.08px;height: 7px;vertical-align: top;overflow: hidden;background-image: linear-gradient(90deg, rgb(26, 201, 156) 0%, rgba(63, 198, 215, 0) 100%);"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section><section style="outline: 0px;text-align: justify;color: rgb(62, 62, 62);font-size: 16px;"><p style="outline: 0px;"><strong style="outline: 0px;">实践为先，为行业智能化转型打样</strong></p></section><section style="outline: 0px;transform: perspective(0px);transform-style: flat;"><section style="outline: 0px;text-align: left;transform: rotateY(180deg);"><section style="outline: 0px;display: inline-block;width: 124.08px;height: 7px;vertical-align: top;overflow: hidden;background-image: linear-gradient(90deg, rgb(26, 201, 156) 0%, rgba(63, 198, 215, 0) 100%);"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section></section></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 0em;">天津大学信网中心主任于瑞国在《天津大学算力与网络安全融合建设》的主题演讲中介绍了天津大学响应国家大力推进超算、人工智能平台建设的政策引导，建设校级算力资源共享平台，有效支撑面向重大项目或课题的开发与创新，服务AI for Science的成功经验。</span></p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012871" data-ratio="0.6666666666666666" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=38ad9a7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibicvIvGymoGf2zKSCtsqNDoceffJmnElJDibj7Uf6R8xXIDouedEo2uBg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">天津大学信网中心主任于瑞国</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 2em;">安恒信息隐私计算事业部总经理陶立峰带来《基于机密计算的大模型训练和推理数据围栏》的主题演讲，介绍了如何在大模型训练和推理时，解决数据既要利用又要保护的矛盾需求，以及保护模型安全的双重难题。</span></p><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 2em;">安恒信息在隐私计算的基础之上，<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 2em;color: rgb(190, 28, 18);">将大模型训练与推理能力支持起来，</span></strong>以确保大模型的训练数据能在更安全、可信、可靠的环境当中得以训练，模型也能在更安全的环境下去部署与应用。</span></p><p style="outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 2em;">陶立峰表示，通过将可信执行环境、机密计算与大模型训练框架结合，构建基于机密计算的大模型训练与推理的数据围栏，再结合全流程的加密、授权与审计、审批等管控手段，<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 2em;color: rgb(190, 28, 18);">就能够实现基于场景的最小化数据授权，</span></strong>同时确保数据在受控环境之下不会被滥用。</span></p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012868" data-ratio="0.6666666666666666" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=901dec71&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibg4KBIhc8bIbIIAsrhs5yMEPp3zxsxUKM4VRUW1URlxjennZyGtM2tQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">安恒信息隐私计算事业部总经理陶立峰</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 0em;">针对大模型开发及大规模AI计算系统的挑战，安恒信息正式发布了<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 0em;color: rgb(190, 28, 18);">昇腾-恒脑推理一体机，</span></strong>全流程加速大模型的创新与落地，</span></p><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;">在对人工智能高性能计算的不懈追求中，<strong style="outline: 0px;"><span style="outline: 0px;color: rgb(190, 28, 18);">安恒信息与华为昇腾团队经历了长期深入的合作与共创历程。</span></strong>基于昇腾软硬件生态，安恒恒脑取得了一系列重要成就，同时，也率先完成了多代昇腾硬件适配。一体机融合了安恒信息自主研发的恒脑·安全垂域大模型和华为昇腾业界领先的AI计算能力,在全流程加速大模型创新应用的同时，也彰显了双方在人工智能领域的持续创新能力。 </p><p style="outline: 0px;text-indent: 0em;">安恒信息生态合作部总经理吴伟京与华为制造与大企业军团解决方案副总裁余倬共同出席仪式。<strong style="outline: 0px;"><span style="outline: 0px;color: rgb(190, 28, 18);">双方未来将在安恒-华为战略合作的框架下继续加强合作，</span></strong>在大模型技术、软硬件生态、云端服务等领域开拓创新,共同推动智能化数字安全的进步。</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012870" data-ratio="0.6666666666666666" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4b92d08e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibdiaxciaQTnEOS60xuCBWW0UEUQqqpNkLYn2bicM9wkbs18Ltia9PK6kwDA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">昇腾-恒脑推理一体机正式发布</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="outline: 0px;text-indent: 0em;word-break: break-all;"><span style="outline: 0px;text-indent: 2em;">安恒信息研究院创新业务部总经理姚龙飞在《恒脑2.0智能体核心和自动化革新》主题演讲中提出，<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 2em;color: rgb(190, 28, 18);">大模型的下半场应是智能体的大爆发。</span></strong>他以恒脑·安全垂域大模型为例，介绍了<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 2em;color: rgb(190, 28, 18);">安恒信息以智能体为核心驱动产品、业务进行结合的探索与应用。</span></strong>目前，安恒信息将RPA的思想进行了充分的理解之后融入智能体框架设计，并在安恒信息的数据分类分级产品、AiLPHA告警研判、DLP、API、SOAR等产品中广泛应用，实现了不同场景下的能力大幅提升。</span></p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012875" data-ratio="0.6675925925925926" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=58cfebe9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibYPRTJjwOOBU4ytQ0CvibJHa3GHvQic7g8RiamxsiaiarnZ29PZfayFgqNow%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">安恒信息研究院创新业务部总经理姚龙飞</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 0em;">海亮集团数字创新部部长孙雯带来《海亮集团大模型应用于数据安全的探索与实践》主题演讲，分享了海亮集团正在不同的业务场景探索AI大模型的应用，特别在数据安全领域已取得一定成果。她说，随着企业边界不断扩大，场景越来越复杂，传统的安全防护正逐步失效。</span></p><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 0em;">与此同时，企业的数据随着数字化转型深入变得越来越值钱，数据泄露风险与日俱增。为此，海亮集团构建了“113N”安全能力建设框架，从“事前-事中-事后”做好端到端防护，实现外抵攻击、内防泄露的目标，以安全护航数字化转型。</span></p><p style="outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 0em;">孙雯表示，<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 0em;color: rgb(190, 28, 18);">海亮集团将与安恒信息携手，</span></strong>基于安恒恒脑的专业能力，海亮丰富的业务场景和多领域行业数据沉淀，<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 0em;color: rgb(190, 28, 18);">锻炼出更多适配于不同企业、聚焦于不同行业的智能体。</span></strong></span><br style="outline: 0px;"/></p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012876" data-ratio="0.6657407407407407" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=62d544c6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwib1F9AdFnPu8t38VRiaN7ys9wpMibfevV89Xk9ZMRiajACcvAt3EqfwQuQg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">海亮集团数字创新部部长孙雯</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 2em;">在随后举行的<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 2em;color: rgb(190, 28, 18);">海亮-安恒联合创新实验室揭牌仪式</span></strong>上，在海亮集团轮值总裁何文天、安恒信息董事长范渊的共同见证下，安恒信息研究院院长王欣和海亮集团数字创新部部长孙雯共同为联合创新实验室揭牌。</span></p><p style="outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 2em;">未来，双方依托安恒信息恒脑安全大模型及生态资源，结合海亮集团丰富的行业数据及数据安全实践，共同构建数据安全领域解决方案，推进国家、行业、团体等数据安全标准规范的研制，探索大模型+数据安全的应用落地，打造国内大模型+数据安全的先进标杆案例，形成产业合力。</span></p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012874" data-ratio="0.6666666666666666" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=75804102&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibia4xaxtkhMj8RUPyQMvFPwQOGJtlMFhotxxHQnEMUOVMXL2xZepAywg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">海亮-安恒联合创新实验室揭牌仪式</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 0em;">火山引擎大模型安全产品研发负责人郭建新在《大模型安全内部实践分享》中，<strong style="outline: 0px;"><span style="outline: 0px;text-indent: 0em;color: rgb(190, 28, 18);">总结了大模型应用的四个风险点，</span></strong>分别是模型输出异常、对话机制、数据安全和系统安全。对此，火山引擎方舟平台以业务安全和底座安全为核心，构建了“一矛”“一盾”“一沙箱”的解决方案确保大模型应用安全。</span></p></section><section style="outline: 0px;font-size: 12px;"><p style="outline: 0px;text-align: center;"><br style="outline: 0px;"/></p></section><section style="outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><section style="outline: 0px;display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;"><section style="outline: 0px;transform: perspective(0px);transform-style: flat;"><section style="outline: 0px;text-align: left;transform: rotateX(180deg);"><section style="outline: 0px;display: inline-block;width: 133.316px;height: 7px;vertical-align: top;overflow: hidden;background-image: linear-gradient(90deg, rgb(26, 201, 156) 0%, rgba(63, 198, 215, 0) 100%);"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section><section style="outline: 0px;text-align: justify;color: rgb(62, 62, 62);font-size: 16px;"><p style="outline: 0px;"><strong style="outline: 0px;">AI论剑，共议安全和发展的平衡之道</strong></p></section><section style="outline: 0px;transform: perspective(0px);transform-style: flat;"><section style="outline: 0px;text-align: left;transform: rotateY(180deg);"><section style="outline: 0px;display: inline-block;width: 133.316px;height: 7px;vertical-align: top;overflow: hidden;background-image: linear-gradient(90deg, rgb(26, 201, 156) 0%, rgba(63, 198, 215, 0) 100%);"><section style="outline: 0px;text-align: justify;"><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section></section></section></section></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;">随着人工智能技术的蓬勃发展，到底哪些行业或领域在引入大模型技术后将会有显著的效果和光明的发展前景？安全和发展该如何平衡？未来可能出现哪些全新的应用场景或商业模式？</p><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;">在杭州人工智能学会副秘书长、浙江传媒学院媒体工程学院讲师王亚奇的主持下，教育部新工科联盟网络空间安全工委会主任委员、俄罗斯国家工程院外籍院士胡瑞敏，阿里研究院数据经济研究中心副主任王峥，华为制造与大企业军团解决方案副总裁余倬，安恒信息研究院副院长税雪飞<strong style="outline: 0px;"><span style="outline: 0px;color: rgb(190, 28, 18);">围绕“大模型在各行业的应用潜力与安全影响”</span></strong>展开激烈碰撞。</p><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;">胡瑞敏总结了大模型落地场景的三要素：数据资源足够丰富、高端人才极度紧缺、效率提升需求急迫；满足这三要素的行业和领域适合应用大模型进行赋能和增益。</p><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;">余倬分享了华为自身经验，表示大模型在to B场景下的提质增效已有诸多应用成效，要抓住合适的场景进行深耕以提高生产力。</p><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;">王峥认为，AI应用从微软AI助手到现在更多的AI 智能体，体现了机器在规划、决策和执行能力的提升。在中长期看，大模型技术的发展趋势是在人类可控的前提下，提升机器的自主性。</p><p style="outline: 0px;text-indent: 0em;">税雪飞认为从全球主流大模型发展近况看，大模型已经到了应用落地的快速爬坡时期；在安全领域，攻击方和防守方在应用大模型上的对抗已经开始，安恒信息也在推进应用大模型和智能体构筑新一代的安全防线。</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012877" data-ratio="0.6675925925925926" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d8e4e304&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibFWeou6E5asko6ob723ZM1VibzibOJWa2ib9HvQt6O2mBPiaiaqDNa3ibsY8Q%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;color: rgb(106, 106, 106);"><p style="outline: 0px;">圆桌对话：AI论剑——大模型在各行业的应用潜力于安全影响</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 2em;">最后，CSA大中华区研究院副院长黄连金带来《生成式AI应用的安全挑战》的直播演讲，指出生成式AI的安全挑战主要包括影子AI、自动化和可拓展的威胁与零日漏洞、安全工具集成、恶意工具、大模型聚合导致的数据泄露，以及使用AI导致原先的权限策略问题更加凸显等。介绍了2024AI安全产业图谱的整体调研情况。</span><br style="outline: 0px;"/></p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;line-height: 0;"><section style="outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 609.288px;height: auto;"><img class="rich_pages wxw-img" data-imgfileid="100012873" data-ratio="0.6675925925925926" data-s="300,640" style="outline: 0px;vertical-align: middle;width: 609.288px !important;visibility: visible !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b6e389a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibcEQs9zGwE3BekcdkN9BAWw4eQic9hvgiaQGWoYX7y29h2fVPHicEDytIQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></section></section><section style="outline: 0px;text-align: center;font-size: 12px;"><p style="outline: 0px;">黄连金《生成式AI应用的安全挑战》直播演讲</p></section><p style="outline: 0px;"><br style="outline: 0px;"/></p><section style="padding-right: 15px;padding-left: 15px;outline: 0px;"><p style="margin-bottom: 15px;outline: 0px;text-indent: 0em;"><span style="outline: 0px;text-indent: 0em;">本次“AI引领数字安全新浪潮专题会议”由浙江省科学技术协会指导，杭州市科学技术协会主办，杭州市人工智能学会、中国计算机学会计算机安全专业委员会、云安全联盟大中华区、西电杭州研究院、安恒信息承办。</span></p><p style="outline: 0px;"><br style="outline: 0px;"/></p></section></section><p style="margin-bottom: 0px;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;"><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="246" data-galleryid="" data-imgfileid="100012879" data-ratio="0.4255555555555556" data-s="300,640" style="outline: 0px;letter-spacing: 0.578px;text-align: center;width: 577.986px !important;visibility: visible !important;" data-type="jpeg" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=d35a509b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FicVz8RbowK3xuead6iaXpwQuRtlXGNhGwibBxOGYE8cicfcLQ7Q3C1gOOyNL9EoWPCj1hoBst8QgFseaYntTH5ibIew%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496533">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=055a59ab&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496533%26idx%3D1%26sn%3D120fe524475e094961ef776f3e131563%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 20 May 2024 10:51:00 +0800</pubDate>
    </item>
    <item>
      <title>传承的力量，安恒信息00后登上国际安全顶会BlackHat！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496509&amp;idx=1&amp;sn=661df1cfac4483b0cc6294cdc60652e5</link>
      <description>BlackHat Asia 2024精彩回顾</description>
      <content:encoded><![CDATA[<p>
<span>安恒信息研究院</span> <span>2024-04-19 11:26</span> <span style="display: inline-block;">浙江</span>
</p>

<p>BlackHat Asia 2024精彩回顾</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=fd3df897&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnfOY66iasMdebpLZIB5cZ9iaaicr1ZVcib95RooUnUdx02eDbIXtWPFHNiaKzvC5icRdeRsfInbzMUPtSTA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012855" data-ratio="0.2777777777777778" data-s="300,640" width="100%" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=d4ed0054&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnfOY66iasMdebpLZIB5cZ9iaaO6EQiaLqISDRmSKmiayABjvmzKNRjhib4ov2BvJRFrsbHVJK9n0r9kB5w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">日前，全球顶尖安全技术会议BlackHat Asia在新加坡召开，安恒信息研究院安全研究员Yingqi Shi、Mingjia Liu和安全专家Quan Jin受邀参会并作主题演讲。</p><section style="margin: 0px 0px 24px;white-space: normal;padding: 0px;box-sizing: border-box;">作为全球安全届的盛会，BlackHat素以议题审核严苛而在业界闻名，每一届的议题申报通过率极低，而BlackHat Asia作为BlackHat三大主会场之一，竞争也异常激烈，入选议题含金量极高。</section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;transform: translate3d(15px, 0px, 0px);-webkit-transform: translate3d(15px, 0px, 0px);-moz-transform: translate3d(15px, 0px, 0px);-o-transform: translate3d(15px, 0px, 0px);box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 4px;border-bottom-color: rgb(13, 80, 199);min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 4px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 2px 2px 0px;border-color: rgb(255, 205, 104) rgb(255, 205, 104) rgb(97, 163, 246);padding: 0px 12px;box-sizing: border-box;"><section style="text-align: center;margin: 4px 0px 0px;box-sizing: border-box;"><section style="text-align: justify;font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">议题介绍</strong></p></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;padding: 0px 15px;box-sizing: border-box;"><section style="word-break: break-all;margin: 24px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">在这场国际盛会中，安恒信息研究院的安全研究员Yingqi Shi、Mingjia Liu、Guoxian和安全专家Quan Jin受邀发表演讲，他们以《A Glimpse Into The Protocol: Fuzz Windows RDP Client For Fun And Profit》为主题，向与会者展示了他们对Windows远程桌面协议的最新研究成果。<br style="box-sizing: border-box;"/></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 95%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012856" data-ratio="0.6666666666666666" data-s="300,640" width="100%" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=6d5ce2d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnfOY66iasMdebpLZIB5cZ9iaaHIjfwnsVlYmtVg2NopJaBP0ibYPyAD1VniaEuEp7QRVDBicsAXkWFlP6A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section></section><section style="font-size: 15px;line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">目前，该议题的演讲PPT已经在BlackHat官网公开，有兴趣的读者请点击文末<span style="box-sizing: border-box;color: rgb(0, 82, 255);">“阅读原文”</span>了解更多精彩内容。<br style="box-sizing: border-box;"/></p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;letter-spacing: 0.578px;text-decoration: none;">安全专家Quan Jin曽多次登上<span style="font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;">BlackHat、HITB、Geekpwn等国际安全峰会</span>，在<span style="font-size: 15px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">在二进制安全研究界<span style="font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;">享有盛誉</span>，现如今，他</span></span><span style="letter-spacing: 0.578px;">以丰富的经验和深厚的专业知识，引领着00后代表Yingqi Shi和Mingjia Liu走向国际舞台。</span><span style="letter-spacing: 0.578px;"></span></p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">作为00后代表，Yingqi Shi和Mingjia Li正以其卓越的才华和不懈的努力，在网络安全领域崭露头角，成为该行业的新星。他们不仅代表着00后群体的活力与创新精神，更是中国网络安全事业的新兴支柱。</p><section style="word-break: break-all;white-space: normal;margin: 0px 0px 24px;padding: 0px;box-sizing: border-box;">安恒信息研究院拥有大量如Yingqi Shi、Mingjia Liu、Guoxian、Quan Jin一样的安全研究员，他们用独特的视角和先进的技术，推动着中国乃至全球网络安全领域的发展。</section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;transform: translate3d(15px, 0px, 0px);-webkit-transform: translate3d(15px, 0px, 0px);-moz-transform: translate3d(15px, 0px, 0px);-o-transform: translate3d(15px, 0px, 0px);box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 0px 0px 4px;border-bottom-color: rgb(13, 80, 199);min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 4px;box-sizing: border-box;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 2px 2px 0px;border-color: rgb(255, 205, 104) rgb(255, 205, 104) rgb(97, 163, 246);padding: 0px 12px;box-sizing: border-box;"><section style="text-align: center;margin: 4px 0px 0px;box-sizing: border-box;"><section style="text-align: justify;font-size: 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">传承的力量</strong></p></section></section></section></section></section></section><section style="font-size: 15px;line-height: 2;padding: 0px 15px;box-sizing: border-box;"><section style="margin: 24px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">自2005年，安恒信息董事长范渊先生受邀参加Black Hat并发表主题演讲以来，这已是安恒信息第四次登上BlackHat的舞台。</section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="box-sizing: border-box;color: rgb(0, 82, 255);"><strong style="box-sizing: border-box;">从第一个登上Black Hat进行演讲的中国人，到中国网络安全最年轻的力量</strong></span>，安恒信息始终怀着一股信念、一份赤诚，挑战未知、突破一切，以其卓越的专业技能和对网络安全的深刻洞察，为中国乃至世界的网络安全事业贡献更多的智慧和力量。</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 95%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012857" data-ratio="0.6314814814814815" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c63d5194&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnfOY66iasMdebpLZIB5cZ9iaad9pEloPvYdazCRITKfqdZ9ibiaVkWFO4ThxWNjm0FzyI9j2SiayibRsKZQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px 0px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: middle;width: 50%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><section style="margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012854" data-ratio="0.562962962962963" data-s="300,640" width="100%" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=5c25fbbd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnfOY66iasMdebpLZIB5cZ9iaaLOjqyicdQy38vicboVPnuczH9unVtQzH4PPj7Ky1B84RogAZicIAKujGQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section></section></section><section style="display: inline-block;vertical-align: middle;align-self: center;flex: 0 0 auto;width: 45%;height: auto;box-sizing: border-box;"><section style="text-align: right;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 21px;border-color: rgb(95, 156, 239);width: 90%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012853" data-ratio="0.562962962962963" data-s="300,640" width="100%" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=74ef8d72&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnfOY66iasMdebpLZIB5cZ9iaac6XCzic1QZ0pK8rVhdrrCXTr1Z7PLEg9BviaxXLQP8aY79P0lxmEEHTQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section></section></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><section style="display: inline-block;vertical-align: middle;width: 50%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><section style="text-align: left;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;border-style: solid;border-width: 21px;border-color: rgb(95, 156, 239);width: 90%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012859" data-ratio="0.5879629629629629" data-s="300,640" width="100%" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=9d16c3f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnfOY66iasMdebpLZIB5cZ9iaaAXVQzJjUdibKsdaLq9yVHQUK57MLciaqZGibxjxw4bgwQAeMp58qZsSCQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section></section></section><section style="display: inline-block;width: 45%;vertical-align: middle;align-self: center;flex: 0 0 auto;height: auto;box-sizing: border-box;"><section style="margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012858" data-ratio="0.5611111111111111" data-s="300,640" width="100%" data-type="jpeg" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=5596b605&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvnfOY66iasMdebpLZIB5cZ9iaarRqMxJGdHIElaKYIQEV10V3wYu4KNiaMWpKiaSh4rEv8C49dxIibVXzvQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section></section></section></section><section style="font-size: 15px;line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">展望未来，安恒信息研究院将继续精进技术、不断创新，以打造国际一流的安全企业研究院为目标。面向数字经济时代，洞悉技术发展趋势与重大机会，推进原子化安全能力建设，打造创新应用场景，提升工程技术效能，为安恒信息的高质量、高增长发展持续注入源动力，筑造数字经济时代的安全屏障。<br style="box-sizing: border-box;"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">感谢您的关注，让我们共同期待安恒信息研究院在未来的国际舞台上创造更多辉煌！</p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 93%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012860" data-ratio="0.278125" data-s="300,640" width="100%" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=15c20d77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvnfOY66iasMdebpLZIB5cZ9iaaJuJXcqCVx8SwTib0PrjpkWn1UvKsDgLdnn3iawSgVibCZUAgyjibibL8urA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://www.blackhat.com/asia-24/briefings/schedule/index.html#a-glimpse-into-the-protocol-fuzz-windows-rdp-client-for-fun-and-profit-37629">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=eb4fd465&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496509%26idx%3D1%26sn%3D661df1cfac4483b0cc6294cdc60652e5%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 19 Apr 2024 11:26:00 +0800</pubDate>
    </item>
    <item>
      <title>“奔赴AI”｜擅长AI、善用AI，共赴智能未来</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496477&amp;idx=1&amp;sn=148b33bb55a9a420577256f77c4bceaa</link>
      <description>全员AI，奔赴未来</description>
      <content:encoded><![CDATA[<p>
<span>米fan</span> <span>2024-04-01 16:35</span> <span style="display: inline-block;">浙江</span>
</p>

<p>全员AI，奔赴未来</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=bc5e94a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zYjNG0Lzs6KgSlQWK2uqbibhdtmVok6MxLic1v4FaZYDJSV9XhtAQWnOA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="background-color: rgba(95, 156, 239, 0.17);box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;margin-bottom: 0px;" data-mpa-powered-by="yiban.io"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.44074074074074077" data-s="300,640" width="100%" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=bb8a3f92&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zDbeebgJsqvtPoJqWhgqwqL8sHeOzDYADtk8YsJoIqWD11sXMeAb3pg%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">🌱</p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 14px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(12, 34, 127);box-sizing: border-box;">Hi，各位</span></strong></span></p></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 98%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;padding: 6px 20px;margin: 0px;height: auto;box-sizing: border-box;"><section style="display: flex;width: 100%;flex-flow: column;box-sizing: border-box;" powered-by="xiumi.us"><section style="z-index: 1;box-sizing: border-box;" powered-by="xiumi.us"><section style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(8, 127, 218);min-width: 5%;max-width: 100%;height: auto;padding: 5px 22px;border-top-left-radius: 20px;border-bottom-right-radius: 20px;overflow: hidden;box-sizing: border-box;"><section style="text-align: justify;font-size: 15px;color: rgb(255, 255, 255);letter-spacing: 3px;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">奔赴AI·第二届创新创造大赛</strong></p></section></section></section></section></section><section style="margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.6675925925925926" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=b84f7f55&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zfMGYtdK0hSXO2zA9y98Rbej7zDicGbnrKavMHCMNz3OcicEq9oYDGDHA%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="margin: 10px 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;font-size: 14px;color: rgb(0, 0, 0);line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1339em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">2024年3月28日，安恒信息迎来了一场青春与智慧的盛宴——<strong style="box-sizing: border-box;">“第二届安恒青年技术创新创造大赛”</strong>。本次大赛以<span style="color: rgb(25, 81, 164);box-sizing: border-box;"><strong style="box-sizing: border-box;">“奔赴AI”</strong></span>为主题，旨在激发青年员工的创新潜能，通过人工智能技术提升安全产品竞争力和企业办公效率，展现了安恒青年的活力与创造力。</p><p style="text-indent: 2.1339em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">本次大赛得到了安恒党委、经营管理委员会、总裁办的有力指导，以及安恒团委、人力资源部的主办支持，中央研究院、市场部、UED研发部等部门的协办。这不仅体现了安恒公司对青年人才培养的重视，也展现了公司各部门之间的紧密合作与协同发展。</p></section></section><section style="justify-content: center;display: flex;flex-flow: row;margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;margin: 0px 10px 0px 0px;border-width: 0px;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(25, 81, 164);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;line-height: 0;z-index: 3;box-sizing: border-box;"><section style="text-align: left;margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 16px;height: 16px;vertical-align: top;overflow: hidden;background-color: rgba(255, 255, 255, 0);border-width: 1px;border-radius: 26px;border-style: solid;border-color: rgb(25, 81, 164);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;margin: 0px 0px 0px -8px;line-height: 0;box-sizing: border-box;"><section style="text-align: left;margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 16px;height: 16px;vertical-align: top;overflow: hidden;background-color: rgb(251, 228, 151);border-width: 0px;border-radius: 26px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;margin: 0px 0px 0px 10px;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(25, 81, 164);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 250px;height: 52px;vertical-align: top;overflow: hidden;background-position: 50% 50%;background-repeat: no-repeat;background-size: contain;background-attachment: scroll;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/pCupt7KeWTlq4umu62VholyEBuFmU89uOG3pkOZpicjOgUwUtngibYsbTsovbKtVAvaG6bXS4eiaxicdiaafCQIicTOg/640?wx_fmt=png&#34;);box-sizing: border-box;"><section style="margin: 12px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;border-width: 2px;border-style: solid;border-color: transparent;font-size: 18px;color: rgb(245, 246, 248);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;">01 全员AI，奔赴未来</span></strong></p></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><section style="margin: 0px 0px -30px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.2196969696969697" data-s="300,640" data-w="792" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=6f2c0eb7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FpCupt7KeWTlq4umu62VholyEBuFmU89udE7ZaBpMJB0eQnJ5f65EUvYap60OnhHHibQHTYF2pTLibsl27fc7Emjg%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 0% 0%;background-repeat: repeat-y;background-size: 100%;background-attachment: scroll;padding: 0px 30px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/pCupt7KeWTlq4umu62VholyEBuFmU89uywooCwp4aCmSYzdZk9iarsJSF4wWVppBGrbtCKn3FUnGvSETx91qQwQ/640?wx_fmt=png&#34;);box-sizing: border-box;"><section style="text-align: center;margin: 10px 0px -5.0005%;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;border-style: solid;border-width: 10px;border-color: rgb(245, 246, 248);box-shadow: rgb(0, 0, 0) 5px 5px 6px 0px;box-sizing: border-box;"><img data-ratio="0.6675925925925926" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=a8f870f9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zGicwYpQ4BvKYkF45oBnhMb8yWdc7PKJU43XOdY2JQCEZEib9oSsuz5mg%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="margin: 5% 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">在决赛的开始，安恒信息董事长Frank以满怀激情的致辞，为这场智慧的角逐揭开了序幕。他强调：“AI技术是时代趋势，‘奔赴AI’是时代的选择。”无论是参赛选手，还是公司全员，都应当积极主动地加入AI技术的学习与探索中，<span style="color: rgb(25, 81, 164);box-sizing: border-box;"><strong style="box-sizing: border-box;">人人都应当“利用好AI宝贵的未来⼀百天成⻓机遇期，做时代的最前沿感知者，贡献者，受益者。”</strong></span></p></section></section></section></section><section style="margin: -20px 0px 0px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.18181818181818182" data-s="300,640" data-w="792" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=ac362fce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FpCupt7KeWTlq4umu62VholyEBuFmU89uW6Gfj2NuXhAhjN6NWicV7a0HV0L5YHqGuqo5ODRsvOL6LTUa5mfLibDA%2F640%3Fwx_fmt%3Dpng"/></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 250px;height: 52px;vertical-align: top;overflow: hidden;background-position: 50% 50%;background-repeat: no-repeat;background-size: contain;background-attachment: scroll;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/pCupt7KeWTlq4umu62VholyEBuFmU89uOG3pkOZpicjOgUwUtngibYsbTsovbKtVAvaG6bXS4eiaxicdiaafCQIicTOg/640?wx_fmt=png&#34;);box-sizing: border-box;"><section style="margin: 12px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;border-width: 2px;border-style: solid;border-color: transparent;padding: 0.1em 0.3em;font-size: 18px;color: rgb(245, 246, 248);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;">02 玩转AI，创新未来</span></strong></p></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><section style="margin: 0px 0px -30px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.2196969696969697" data-s="300,640" data-w="792" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=6f2c0eb7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FpCupt7KeWTlq4umu62VholyEBuFmU89udE7ZaBpMJB0eQnJ5f65EUvYap60OnhHHibQHTYF2pTLibsl27fc7Emjg%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 0% 0%;background-repeat: repeat-y;background-size: 100%;background-attachment: scroll;padding: 0px 30px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/pCupt7KeWTlq4umu62VholyEBuFmU89uywooCwp4aCmSYzdZk9iarsJSF4wWVppBGrbtCKn3FUnGvSETx91qQwQ/640?wx_fmt=png&#34;);box-sizing: border-box;"><section style="text-align: center;margin: 10px 0px -5.0005%;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;border-style: solid;border-width: 10px;border-color: rgb(245, 246, 248);box-shadow: rgb(0, 0, 0) 5px 5px 6px 0px;box-sizing: border-box;"><img data-ratio="0.6675925925925926" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=81e902f9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zcvuwzTf0dA8TuVJOHecibYuTR9JWcFeMf8mf3ib1NicuQbCDo1JrjMLicw%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">本次大赛面向公司各部门的青年员工，鼓励他们积极参与，展现自己的才华和创意。<strong style="box-sizing: border-box;"><span style="color: rgb(25, 81, 164);box-sizing: border-box;">在这个平台上，青年员工们不仅能够学习到最新的AI技术，还能够与来自不同部门的同事交流思想，碰撞出创新的火花。</span></strong></p><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">历时一个多月的准备与选拔，近百支队伍踊跃报名，经过层层筛选，最终有20强队伍脱颖而出。3月28日下午，这些队伍在线下评选中展开了激烈的角逐，<span style="color: rgb(25, 81, 164);box-sizing: border-box;"><strong style="box-sizing: border-box;">他们用独特的创意和专业的技术，向评委和观众展示了他们的AI项目。</strong></span></p></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: 54%;align-self: center;flex: 0 0 auto;height: auto;margin: 0px 10px 0px 0px;box-sizing: border-box;"><section style="margin: 0px 0px 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.9986149584487535" data-s="300,640" data-w="722" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=ed8de7c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zBVjicUKo9MSthicemXptfqnAtzJ2GGUGJv1kWq4r7pHyjXHoibToPEq8w%2F640%3Fwx_fmt%3Djpeg"/></section></section></section><section style="display: inline-block;vertical-align: middle;width: 45%;align-self: center;flex: 0 0 auto;height: auto;box-sizing: border-box;"><section style="margin: 0px 0px 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.6102719033232629" data-s="300,640" data-w="993" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=1c4450af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zboA0QMSOZ1RtjagRicdK11WBkiaAndMr6RVTAfcfqoYg6qoe1ib040a8g%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="margin: 0px 0px 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.6046296296296296" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=8d91ac7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zmzmpTBu84hA2hEiac2ukJV8x9Iib7Z7l62F7frRg41IOcpqHRgLdSzjg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="text-align: center;margin: -5px 0px 5px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.6675925925925926" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=b9ada2c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zQXgHYYiaGT3uibQUXrhKSKCstR6j8iagia7ADvQOactCfPNdxb7tcIK08Q%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="margin: 5% 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="text-indent: 2.1429em;box-sizing: border-box;">这些项目不仅涵盖了安全产品的创新，也包括了办公自动化、数据分析等多个领域，<strong style="box-sizing: border-box;">每一个项目都是对AI技术的新鲜尝试，也是对公司“AI战略”的生动诠释。</strong></span></p></section></section><section style="margin: 10px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;overflow: hidden;align-self: flex-start;line-height: 0;box-sizing: border-box;"><svg viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xmlns="http://www.w3.org/2000/svg" style="pointer-events: none;display: block;-webkit-tap-highlight-color: transparent;user-select: none;box-sizing: border-box;-webkit-user-select: none;"><g transform="translate(540 360.5)" style="box-sizing: border-box;"><g style="box-sizing: border-box;"><g transform="translate(-540 -360.5)" style="box-sizing: border-box;"><g style="box-sizing: border-box;"><g transform="translate(-1100 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zP2ibWryLenrDJG7721aRCrVDqzibV7ARH6ibglWJy1stYzU4D3xKa0lhA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zsQaxXDa2nQIKh0CibKHMxSHTj5mFdKy8a2E03g2Wojye9mpBSUiaaib6A/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zP2ibWryLenrDJG7721aRCrVDqzibV7ARH6ibglWJy1stYzU4D3xKa0lhA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><animateTransform type="translate" attributeName="transform" begin="0s" dur="18" calcMode="spline" fill="freeze" values="0 0;0 0;0 0;-1100 0;-1100 0;-1100 0;-1100 0;-2200 0;-2200 0;-2200 0;-2200 0;-3300 0;-3300 0;-3300 0;-3300 0;-4400 0;-4400 0;-4400 0;-4400 0;-5500 0;-5500 0;-5500 0;-5500 0;-6600 0;-6600 0;-6600 0;-6600 0;-7700 0;-7700 0;-7700 0;-7700 0;-8800 0;-8800 0;-8800 0;-8800 0;-9900 0;-9900 0" keyTimes="0;0.06;0.07;0.09;0.11;0.17;0.18;0.21;0.22;0.28;0.29;0.32;0.33;0.39;0.41;0.43;0.44;0.50;0.52;0.54;0.56;0.61;0.63;0.65;0.67;0.72;0.74;0.76;0.78;0.83;0.85;0.87;0.89;0.94;0.96;0.98;1.00" keySplines="0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0" repeatCount="indefinite" style="box-sizing: border-box;"></animateTransform><rect style="pointer-events: painted;box-sizing: border-box;" width="1080" height="721" fill="transparent"></rect><g transform="translate(0 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zDNcKxVgia8T1I8wxyfCarcJgOLoTEryNGiaKFpUt77MVoGo15QkESGUA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zP2ibWryLenrDJG7721aRCrVDqzibV7ARH6ibglWJy1stYzU4D3xKa0lhA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zDNcKxVgia8T1I8wxyfCarcJgOLoTEryNGiaKFpUt77MVoGo15QkESGUA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(1100 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zR5nDLRx9WORkr3N8BWWT2VASvsug8NO32W3qsgV6uP4MRbxpHV79gA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zDNcKxVgia8T1I8wxyfCarcJgOLoTEryNGiaKFpUt77MVoGo15QkESGUA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zR5nDLRx9WORkr3N8BWWT2VASvsug8NO32W3qsgV6uP4MRbxpHV79gA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(2200 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zynEibaKv2CxqTIicibvow4od3Jq84KeBzFibDQZxyELh35ejrDUsq1iaEIQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zR5nDLRx9WORkr3N8BWWT2VASvsug8NO32W3qsgV6uP4MRbxpHV79gA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zynEibaKv2CxqTIicibvow4od3Jq84KeBzFibDQZxyELh35ejrDUsq1iaEIQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(3300 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1ztVcxiaDlqCmzuTJOy4qmdibvOuBoVniazp4Ua0ckhqJs6Wswib4GOsSOjQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zynEibaKv2CxqTIicibvow4od3Jq84KeBzFibDQZxyELh35ejrDUsq1iaEIQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1ztVcxiaDlqCmzuTJOy4qmdibvOuBoVniazp4Ua0ckhqJs6Wswib4GOsSOjQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(4400 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zSfwpM2EQQqCupLEBN2OyicBhroj3iaZAW3uC8oWDc73cibbIeKA5JEnPw/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1ztVcxiaDlqCmzuTJOy4qmdibvOuBoVniazp4Ua0ckhqJs6Wswib4GOsSOjQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zSfwpM2EQQqCupLEBN2OyicBhroj3iaZAW3uC8oWDc73cibbIeKA5JEnPw/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(5500 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zhRl6kZ5ewaXBxkIDgLXqvAaZrVZicW3eoxzqiaqrr2d9KlsLibckiab69w/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zSfwpM2EQQqCupLEBN2OyicBhroj3iaZAW3uC8oWDc73cibbIeKA5JEnPw/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zhRl6kZ5ewaXBxkIDgLXqvAaZrVZicW3eoxzqiaqrr2d9KlsLibckiab69w/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(6600 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zy30YqklPOrUb11cWMqzGjJ1ZtTb2Xd01JCriciaqht7o3SAVD42hc8hA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zhRl6kZ5ewaXBxkIDgLXqvAaZrVZicW3eoxzqiaqrr2d9KlsLibckiab69w/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zy30YqklPOrUb11cWMqzGjJ1ZtTb2Xd01JCriciaqht7o3SAVD42hc8hA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(7700 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zsQaxXDa2nQIKh0CibKHMxSHTj5mFdKy8a2E03g2Wojye9mpBSUiaaib6A/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zy30YqklPOrUb11cWMqzGjJ1ZtTb2Xd01JCriciaqht7o3SAVD42hc8hA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zsQaxXDa2nQIKh0CibKHMxSHTj5mFdKy8a2E03g2Wojye9mpBSUiaaib6A/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(8800 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zP2ibWryLenrDJG7721aRCrVDqzibV7ARH6ibglWJy1stYzU4D3xKa0lhA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zsQaxXDa2nQIKh0CibKHMxSHTj5mFdKy8a2E03g2Wojye9mpBSUiaaib6A/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zP2ibWryLenrDJG7721aRCrVDqzibV7ARH6ibglWJy1stYzU4D3xKa0lhA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(9900 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zDNcKxVgia8T1I8wxyfCarcJgOLoTEryNGiaKFpUt77MVoGo15QkESGUA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zP2ibWryLenrDJG7721aRCrVDqzibV7ARH6ibglWJy1stYzU4D3xKa0lhA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zDNcKxVgia8T1I8wxyfCarcJgOLoTEryNGiaKFpUt77MVoGo15QkESGUA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(11000 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zR5nDLRx9WORkr3N8BWWT2VASvsug8NO32W3qsgV6uP4MRbxpHV79gA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zDNcKxVgia8T1I8wxyfCarcJgOLoTEryNGiaKFpUt77MVoGo15QkESGUA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zR5nDLRx9WORkr3N8BWWT2VASvsug8NO32W3qsgV6uP4MRbxpHV79gA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g></g></g><animateTransform type="scale" attributeName="transform" begin="0s" additive="sum" calcMode="spline" fill="freeze" dur="18" keyTimes="0;0.06;0.07;0.09;0.11;0.17;0.18;0.21;0.22;0.28;0.29;0.32;0.33;0.39;0.41;0.43;0.44;0.50;0.52;0.54;0.56;0.61;0.63;0.65;0.67;0.72;0.74;0.76;0.78;0.83;0.85;0.87;0.89;0.94;0.96;0.98;1.00" values="1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1" keySplines="0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0" repeatCount="indefinite" style="box-sizing: border-box;"></animateTransform></g></g></svg></section></section><section style="margin: 5% 0px 5px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="text-indent: 2.1429em;box-sizing: border-box;">在AI技术的应用下，30人天的工作量仅需10余人天即可完成，参赛队伍对于AI的精彩演绎不仅赢得了现场观众的热烈掌声，更点燃了每一位安恒信息人对AI技术的热爱与追求。</span><br style="box-sizing: border-box;"/></p></section></section><section style="text-align: center;margin: 10px 0px -5.0005%;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;border-style: solid;border-width: 10px;border-color: rgb(245, 246, 248);box-shadow: rgb(0, 0, 0) 5px 5px 6px 0px;box-sizing: border-box;"><img data-ratio="0.6675925925925926" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=9a5fa34a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zBJI9ibhpGZPghCE3rpavr9yYdtW10wWBhluqllY6hLgJ9pBibv8GIjjw%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section><section style="margin: -40px 0px 0px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.18181818181818182" data-s="300,640" data-w="792" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=ac362fce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FpCupt7KeWTlq4umu62VholyEBuFmU89uW6Gfj2NuXhAhjN6NWicV7a0HV0L5YHqGuqo5ODRsvOL6LTUa5mfLibDA%2F640%3Fwx_fmt%3Dpng"/></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 250px;height: 52px;vertical-align: top;overflow: hidden;background-position: 50% 50%;background-repeat: no-repeat;background-size: contain;background-attachment: scroll;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/pCupt7KeWTlq4umu62VholyEBuFmU89uOG3pkOZpicjOgUwUtngibYsbTsovbKtVAvaG6bXS4eiaxicdiaafCQIicTOg/640?wx_fmt=png&#34;);box-sizing: border-box;"><section style="margin: 12px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;border-width: 2px;border-style: solid;border-color: transparent;padding: 0.1em 0.3em;font-size: 18px;color: rgb(245, 246, 248);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;">03 应用AI，沉淀经验</span><br style="box-sizing: border-box;"/></strong></p></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><section style="margin: 0px 0px -30px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.2196969696969697" data-s="300,640" data-w="792" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=6f2c0eb7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FpCupt7KeWTlq4umu62VholyEBuFmU89udE7ZaBpMJB0eQnJ5f65EUvYap60OnhHHibQHTYF2pTLibsl27fc7Emjg%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 0% 0%;background-repeat: repeat-y;background-size: 100%;background-attachment: scroll;padding: 0px 30px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/pCupt7KeWTlq4umu62VholyEBuFmU89uywooCwp4aCmSYzdZk9iarsJSF4wWVppBGrbtCKn3FUnGvSETx91qQwQ/640?wx_fmt=png&#34;);box-sizing: border-box;"><section style="text-align: center;margin: 10px 0px 5%;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;border-style: solid;border-width: 10px;border-color: rgb(245, 246, 248);box-shadow: rgb(0, 0, 0) 5px 5px 6px 0px;box-sizing: border-box;"><img data-ratio="0.6675925925925926" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=ee0c55ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zu6ThXHXib3CkEJb3XpSRyzb0Sib0E70OloW8ezXTxrhIyxSomuDAiaABg%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="margin: 2px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;overflow: hidden;align-self: flex-start;line-height: 0;box-sizing: border-box;"><svg viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xmlns="http://www.w3.org/2000/svg" style="pointer-events: none;display: block;-webkit-tap-highlight-color: transparent;user-select: none;box-sizing: border-box;-webkit-user-select: none;"><g transform="translate(540 360.5)" style="box-sizing: border-box;"><g style="box-sizing: border-box;"><g transform="translate(-540 -360.5)" style="box-sizing: border-box;"><g style="box-sizing: border-box;"><g transform="translate(-1100 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zWKjoLYWpQo4GJdft9f55zfbLwNhKiaVWGgjFTLyYjxNTWKq5q9Y4mEg/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1z6CQOlua8pfNNkLaW0wCvA7QfQ29v0t6J46Jh8jKLdWPf8Xm4VX3Slw/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zWKjoLYWpQo4GJdft9f55zfbLwNhKiaVWGgjFTLyYjxNTWKq5q9Y4mEg/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><animateTransform type="translate" attributeName="transform" begin="0s" dur="17.5" calcMode="spline" fill="freeze" values="0 0;0 0;0 0;-1100 0;-1100 0;-1100 0;-1100 0;-2200 0;-2200 0;-2200 0;-2200 0;-3300 0;-3300 0;-3300 0;-3300 0;-4400 0;-4400 0;-4400 0;-4400 0;-5500 0;-5500 0;-5500 0;-5500 0;-6600 0;-6600 0;-6600 0;-6600 0;-7700 0;-7700 0" keyTimes="0;0.11;0.12;0.13;0.14;0.26;0.27;0.28;0.29;0.40;0.41;0.42;0.43;0.54;0.55;0.56;0.57;0.69;0.69;0.71;0.71;0.83;0.84;0.85;0.86;0.97;0.98;0.99;1.00" keySplines="0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0" repeatCount="indefinite" style="box-sizing: border-box;"></animateTransform><rect style="pointer-events: painted;box-sizing: border-box;" width="1080" height="721" fill="transparent"></rect><g transform="translate(0 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zA1oBQDu0HfO8FA7vUwmaicbwPC7rMb3Efj5Zv63wjCZ0SOf0crm58tA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zWKjoLYWpQo4GJdft9f55zfbLwNhKiaVWGgjFTLyYjxNTWKq5q9Y4mEg/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zA1oBQDu0HfO8FA7vUwmaicbwPC7rMb3Efj5Zv63wjCZ0SOf0crm58tA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(1100 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zObCibRq80apEsEKkJM3GF9VibPDIibYR9YwIlhM4ECicJibbbUZXcFcLmvA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zA1oBQDu0HfO8FA7vUwmaicbwPC7rMb3Efj5Zv63wjCZ0SOf0crm58tA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zObCibRq80apEsEKkJM3GF9VibPDIibYR9YwIlhM4ECicJibbbUZXcFcLmvA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(2200 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zWicJgic0lOaw3wNpib2KVbx0LQUQsgexIhlZY2dmq6oZ2bNzd1mYnGRzw/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zObCibRq80apEsEKkJM3GF9VibPDIibYR9YwIlhM4ECicJibbbUZXcFcLmvA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zWicJgic0lOaw3wNpib2KVbx0LQUQsgexIhlZY2dmq6oZ2bNzd1mYnGRzw/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(3300 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zqbzJHibb7f2iaNNNZnwibJ8palNoSfl5SfmRycfM7xLibx1cuyZwKgs7qQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zWicJgic0lOaw3wNpib2KVbx0LQUQsgexIhlZY2dmq6oZ2bNzd1mYnGRzw/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zqbzJHibb7f2iaNNNZnwibJ8palNoSfl5SfmRycfM7xLibx1cuyZwKgs7qQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(4400 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zghIuPIxhKWE5mD4YI3NyuxSneDcbXGeRgvX94qDM2Ewg27HLPAPibiaQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zqbzJHibb7f2iaNNNZnwibJ8palNoSfl5SfmRycfM7xLibx1cuyZwKgs7qQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zghIuPIxhKWE5mD4YI3NyuxSneDcbXGeRgvX94qDM2Ewg27HLPAPibiaQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(5500 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1z6CQOlua8pfNNkLaW0wCvA7QfQ29v0t6J46Jh8jKLdWPf8Xm4VX3Slw/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zghIuPIxhKWE5mD4YI3NyuxSneDcbXGeRgvX94qDM2Ewg27HLPAPibiaQ/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1z6CQOlua8pfNNkLaW0wCvA7QfQ29v0t6J46Jh8jKLdWPf8Xm4VX3Slw/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(6600 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zWKjoLYWpQo4GJdft9f55zfbLwNhKiaVWGgjFTLyYjxNTWKq5q9Y4mEg/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1z6CQOlua8pfNNkLaW0wCvA7QfQ29v0t6J46Jh8jKLdWPf8Xm4VX3Slw/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zWKjoLYWpQo4GJdft9f55zfbLwNhKiaVWGgjFTLyYjxNTWKq5q9Y4mEg/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(7700 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zA1oBQDu0HfO8FA7vUwmaicbwPC7rMb3Efj5Zv63wjCZ0SOf0crm58tA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zWKjoLYWpQo4GJdft9f55zfbLwNhKiaVWGgjFTLyYjxNTWKq5q9Y4mEg/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zA1oBQDu0HfO8FA7vUwmaicbwPC7rMb3Efj5Zv63wjCZ0SOf0crm58tA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g><g transform="translate(8800 0)" style="box-sizing: border-box;"><g transform="translate(0 -741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zObCibRq80apEsEKkJM3GF9VibPDIibYR9YwIlhM4ECicJibbbUZXcFcLmvA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 0)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zA1oBQDu0HfO8FA7vUwmaicbwPC7rMb3Efj5Zv63wjCZ0SOf0crm58tA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g><g transform="translate(0 741)" style="box-sizing: border-box;"><foreignObject width="100%" height="100%" x="0" y="0" style="box-sizing: border-box;"><svg space="default" style="width: 100%;background-position: 0% 0%;background-repeat: no-repeat;background-size: 100%;background-attachment: scroll;-webkit-tap-highlight-color: transparent;user-select: none;visibility: visible;pointer-events: none;background-image: url(&#34;https://mmbiz.qpic.cn/sz_mmbiz_jpg/RNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zObCibRq80apEsEKkJM3GF9VibPDIibYR9YwIlhM4ECicJibbbUZXcFcLmvA/640?wx_fmt=jpeg&#34;);box-sizing: border-box;-webkit-user-select: none;" viewBox="0 0 1080 721" xlink="http://www.w3.org/1999/xlink" xml="" xmlns="http://www.w3.org/2000/svg"></svg></foreignObject></g></g></g></g><animateTransform type="scale" attributeName="transform" begin="0s" additive="sum" calcMode="spline" fill="freeze" dur="17.5" keyTimes="0;0.11;0.12;0.13;0.14;0.26;0.27;0.28;0.29;0.40;0.41;0.42;0.43;0.54;0.55;0.56;0.57;0.69;0.69;0.71;0.71;0.83;0.84;0.85;0.86;0.97;0.98;0.99;1.00" values="1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1;1;0.7;0.7;1" keySplines="0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0;0.421 0 0.581 1.0" repeatCount="indefinite" style="box-sizing: border-box;"></animateTransform></g></g></svg></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="margin: -5.0005% 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">奔赴AI颁奖典礼及项目分享会于3月31日上午举行，公司董事长Frank在颁奖典礼上总结此次奔赴AI的丰硕成果。<span style="color: rgb(25, 81, 164);box-sizing: border-box;"><strong style="box-sizing: border-box;">他强调了AI战略的重要性，并提出了“不进则退”的警示，呼吁大家改变思维，以积极的态度提升效率。</strong></span></p></section></section><section style="text-align: center;margin: 10px 0px -5.0005%;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;border-style: solid;border-width: 10px;border-color: rgb(245, 246, 248);box-shadow: rgb(0, 0, 0) 5px 5px 6px 0px;box-sizing: border-box;"><img data-ratio="0.6675925925925926" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=df8d85be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zoYjA96wqRYXxHGtnico2WliaYugrAs9pAHiaZuhYJxY0amZ2YiaUAAibsOQ%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="margin: 5% 0px 5px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(25, 81, 164);box-sizing: border-box;"><strong style="box-sizing: border-box;">正如Frank所说，AI应用要在“事上磨、事上练、事上见”，每一项AI项目硕果都需落地到实际网络安全业务中，为业务发展、客户服务提质增效。</strong></span></p></section></section><section style="text-align: center;margin: 10px 0px 20px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.6675925925925926" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=53309edb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zxXygIaMmiaydohVsZgZ72xckg2Fic4C8G4LWtwSmYpmXuiatGG2m2C27w%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="text-indent: 2.1429em;box-sizing: border-box;">本次大赛不仅是一场技术的较量，更是一次人才的发掘和项目的孵化。通过这次活动，大家对于AI技术有了更深刻的理解和感受，同时也涌现出了许多优秀的AI人才和项目。<strong style="box-sizing: border-box;">这些人才和项目将成为公司未来发展的重要支撑，推动安恒在网络安全领域取得更多的突破和成就。</strong></span><br style="box-sizing: border-box;"/></p></section></section><section style="text-align: center;margin: 10px 0px -5.0005%;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;border-style: solid;border-width: 10px;border-color: rgb(245, 246, 248);box-shadow: rgb(0, 0, 0) 5px 5px 6px 0px;box-sizing: border-box;"><img data-ratio="0.6675925925925926" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=c0ea8918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zRSnqHwxZvKKH6FhlURGEtIAmMUp9CQUcGVibOpvsMiciaIus8tk8vSxrg%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="margin: 5% 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">在随后的分享环节中，安恒研究院副院长税雪飞围绕<span style="color: rgb(25, 81, 164);box-sizing: border-box;"><strong style="box-sizing: border-box;">“AI战略”和“大模型产业及AI技术的最新动态”</strong></span>进行了深入的分享和交流。</p></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="0.6675925925925926" data-s="300,640" data-w="1080" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=8142a7b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zkDeu5fYLROPD6PY7zS0uuXmvSOjoWD7T7kgegrc2yhM0Y66xbdX7rA%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: 50%;align-self: flex-start;flex: 0 0 auto;padding: 0px 10px 0px 0px;box-sizing: border-box;"><section style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="1.495850622406639" data-s="300,640" data-w="482" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=e7e6b6bc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1ztZQKibIMZzmI0zzk94YQiceqROVGTibW2hat8ff2u4qxDW6A0YFibtDZ2A%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="transform: translate3d(35px, 0px, 0px);-webkit-transform: translate3d(35px, 0px, 0px);-moz-transform: translate3d(35px, 0px, 0px);-o-transform: translate3d(35px, 0px, 0px);margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="height: 1px;background-image: linear-gradient(rgb(31, 110, 215), rgb(3, 14, 45));box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section><section style="display: inline-block;vertical-align: top;width: 50%;align-self: flex-start;flex: 0 0 auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="1.495850622406639" data-s="300,640" data-w="482" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=3a6594f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1z01lZQtQaXicvKpxE5h0xscXWDMJdPObNUJ9MhTYcbibFVic9FgybI30dQ%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: 50%;align-self: flex-start;flex: 0 0 auto;padding: 0px 10px 0px 0px;box-sizing: border-box;"><section style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="1.495850622406639" data-s="300,640" data-w="482" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=074c7bc5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zHu4L1vMwqTaUhgkducn6jdMyK744qFXMyZwNicnmETu9uVRBnGp8yDg%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section><section style="display: inline-block;vertical-align: top;width: 50%;align-self: flex-start;flex: 0 0 auto;padding: 0px 0px 0px 10px;box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="transform: translate3d(-35px, 0px, 0px);-webkit-transform: translate3d(-35px, 0px, 0px);-moz-transform: translate3d(-35px, 0px, 0px);-o-transform: translate3d(-35px, 0px, 0px);margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="height: 1px;background-image: linear-gradient(to right, rgb(3, 14, 45), rgb(31, 110, 215));box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="text-align: center;margin: 0px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-ratio="1.495850622406639" data-s="300,640" data-w="482" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=3b5c750e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zFxBDzXbqe5QX0upqQiaeKa7uibo3biayrXibuibO10Ed7vU8Bu3WMIoZ4kA%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="margin: -5.0005% 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(25, 81, 164);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="text-indent: 2.1429em;box-sizing: border-box;">案例分享环节</span></strong></span><span style="text-indent: 2.1429em;box-sizing: border-box;">更是精彩纷呈，各位获奖选手详细介绍了AI技术在实际工作中的应用，不仅展现了安恒青年的创新活力，也为公司的长远发展注入了新的活力。</span></p></section></section></section></section><section style="margin: -20px 0px 0px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.18181818181818182" data-s="300,640" width="100%" data-w="792" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=ac362fce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FpCupt7KeWTlq4umu62VholyEBuFmU89uW6Gfj2NuXhAhjN6NWicV7a0HV0L5YHqGuqo5ODRsvOL6LTUa5mfLibDA%2F640%3Fwx_fmt%3Dpng"/></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 250px;height: 52px;vertical-align: top;overflow: hidden;background-position: 50% 50%;background-repeat: no-repeat;background-size: contain;background-attachment: scroll;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/pCupt7KeWTlq4umu62VholyEBuFmU89uOG3pkOZpicjOgUwUtngibYsbTsovbKtVAvaG6bXS4eiaxicdiaafCQIicTOg/640?wx_fmt=png&#34;);box-sizing: border-box;"><section style="margin: 12px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;border-width: 2px;border-style: solid;border-color: transparent;padding: 0.1em 0.3em;font-size: 18px;color: rgb(245, 246, 248);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;">04 把握前沿，主动学习</span></strong><br style="box-sizing: border-box;"/></p></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 90%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;box-sizing: border-box;"><section style="margin: 0px 0px -30px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.2196969696969697" data-s="300,640" width="100%" data-w="792" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=6f2c0eb7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FpCupt7KeWTlq4umu62VholyEBuFmU89udE7ZaBpMJB0eQnJ5f65EUvYap60OnhHHibQHTYF2pTLibsl27fc7Emjg%2F640%3Fwx_fmt%3Dpng"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-position: 0% 0%;background-repeat: repeat-y;background-size: 100%;background-attachment: scroll;padding: 0px 30px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/pCupt7KeWTlq4umu62VholyEBuFmU89uywooCwp4aCmSYzdZk9iarsJSF4wWVppBGrbtCKn3FUnGvSETx91qQwQ/640?wx_fmt=png&#34;);box-sizing: border-box;"><section style="text-align: center;margin: 10px 0px -5.0005%;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;border-style: solid;border-width: 10px;border-color: rgb(245, 246, 248);box-shadow: rgb(0, 0, 0) 5px 5px 6px 0px;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.6675925925925926" data-s="300,640" width="100%" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=93a90545&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zePfLd9nVy2Bia4tZVgkz3prerIAt5PjgXLCpk9YRs9EdBKjg5xb0anA%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="margin: 5% 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(25, 81, 164);box-sizing: border-box;">“奔赴AI”大赛不只是技术的较量，它更是一场文化的交融与思想的碰撞。</span></strong>它不仅展现了安恒信息人对AI技术的无限热忱，也映射出公司对创新精神和人才培育的深切重视。通过这样的活动，<strong style="box-sizing: border-box;"><span style="color: rgb(25, 81, 164);box-sizing: border-box;">我们不仅窥见了AI技术在网络安全等众多领域的广泛应用，更感受到了公司在AI浪潮中勇立潮头的决心与信念。</span></strong></p></section></section><section style="text-align: center;margin: 10px 0px -5.0005%;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;border-style: solid;border-width: 10px;border-color: rgb(245, 246, 248);box-shadow: rgb(0, 0, 0) 5px 5px 6px 0px;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.6675925925925926" data-s="300,640" width="100%" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=1620c4bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zjdVknWAk3Hic49PAmt6mwOzyUNkddL8OuKo1qnicbQWGs6IXYXwGnOeQ%2F640%3Fwx_fmt%3Djpeg"/></section></section><section style="margin: 5% 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;color: rgb(58, 66, 94);font-size: 14px;line-height: 2;letter-spacing: 1px;box-sizing: border-box;"><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p><p style="text-indent: 2.1429em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">随着“AI战略”的不断深化，安恒信息技术股份有限公司将持续加大AI技术的投入与研发力度，培育更多AI领域的佼佼者。让我们共同期待，<strong style="box-sizing: border-box;">在不久的将来，安恒信息将在AI的引领下，实现更多的技术突破和业务飞跃，为网络安全事业贡献更多的智慧与力量。</strong></p></section></section></section></section><section style="margin: -20px 0px 0px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.18181818181818182" data-s="300,640" width="100%" data-w="792" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=ac362fce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FpCupt7KeWTlq4umu62VholyEBuFmU89uW6Gfj2NuXhAhjN6NWicV7a0HV0L5YHqGuqo5ODRsvOL6LTUa5mfLibDA%2F640%3Fwx_fmt%3Dpng"/></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 97%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-bottom: 3px solid rgb(0, 99, 197);padding: 10px 12px 8px;height: auto;box-sizing: border-box;"><section style="justify-content: center;display: flex;flex-flow: row;margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;margin: 0px 10px 0px 0px;border-width: 0px;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(25, 81, 164);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;line-height: 0;z-index: 3;box-sizing: border-box;"><section style="text-align: left;margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 16px;height: 16px;vertical-align: top;overflow: hidden;background-color: rgba(255, 255, 255, 0);border-width: 1px;border-radius: 26px;border-style: solid;border-color: rgb(25, 81, 164);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;margin: 0px 0px 0px -8px;line-height: 0;box-sizing: border-box;"><section style="text-align: left;margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 16px;height: 16px;vertical-align: top;overflow: hidden;background-color: rgb(251, 228, 151);border-width: 0px;border-radius: 26px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;margin: 0px 0px 0px 10px;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(25, 81, 164);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;font-size: 14px;color: rgb(58, 66, 94);line-height: 2;letter-spacing: 2px;padding: 0px 10px;box-sizing: border-box;"><p style="text-indent: 2.2679em;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">在这个充满挑战与机遇的时代，安恒信息技术股份有限公司正以开放的胸怀和创新的意志，拥抱AI，奔赴未来。<span style="color: rgb(25, 81, 164);box-sizing: border-box;"><strong style="box-sizing: border-box;">让我们携手并进，在AI的浪潮中乘风破浪，共绘智能科技的辉煌篇章！</strong></span></p></section></section></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 70%;height: auto;box-sizing: border-box;"><img data-ratio="0.278125" data-s="300,640" data-w="640" width="100%" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=911cafc0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zdoClqEhDvfVuyuCnImN1wrt6Nq7TWXDv3mX65ibgVaUEYfvvlQNcFicQ%2F640%3Fwx_fmt%3Dgif"/></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="display: flex;flex-flow: row;margin: 10px 0% 0px;text-align: left;justify-content: flex-start;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-end;padding: 0px 2px;box-sizing: border-box;"><section style="margin: 10px 0% 2px;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 17px;color: rgb(58, 66, 94);padding: 0px;line-height: 1;letter-spacing: 5px;text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">往期回顾</strong></p></section></section><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(58, 66, 94);height: 3px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="margin: 2px 0% 0px;text-align: center;line-height: 0.8;font-size: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="width: 0px;display: inline-block;border-top: 0.8em solid rgb(58, 66, 94);border-left: 0.7em solid transparent !important;border-right: 0.7em solid transparent !important;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 100 100 0%;align-self: flex-end;height: auto;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(202, 29, 24);height: 3px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="margin: 2px 0% 0px;text-align: center;line-height: 0.8;font-size: 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="width: 0px;display: inline-block;border-top: 0.8em solid rgba(255, 255, 255, 0);border-left: 0.7em solid transparent !important;border-right: 0.7em solid transparent !important;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;" width="100%"><tbody style="box-sizing: border-box;"><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:33.classicTable1:0" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:33.classicTable1:0.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;box-sizing: border-box;padding: 0px;" width="100.0000%"><section style="box-sizing: border-box;"><section style="display: flex;flex-flow: row;margin: 10px 0% 0px;justify-content: flex-start;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;height: auto;flex: 0 0 auto;align-self: center;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="font-size: 20px;color: rgb(202, 29, 24);line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">01</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><section style="color: rgb(140, 140, 140);font-size: 13px;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(224, 224, 224);box-sizing: border-box;">｜</span><a href="https://mp.weixin.qq.com/s?__biz=MzUzOTQzMjA2Ng==&amp;mid=2247531056&amp;idx=1&amp;sn=7d0a89b37055afb2421294c5c1aa240a&amp;chksm=facabfddcdbd36cba1b318142b4a6fc105912dca7e4fe1313bed31962911f4c5f3f6ec19f97a&amp;token=1149641431&amp;lang=zh_CN&amp;scene=21#wechat_redirect" target="_blank" style="box-sizing: border-box;" data-linktype="2"><span style="box-sizing: border-box;"><span style="font-family: &#34;Noto Sans CJK SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;box-sizing: border-box;">王牌青年 | </span><span style="box-sizing: border-box;"> </span><span style="box-sizing: border-box;">当一位UI设计师想成为哆啦A梦</span></span></a></p></section></section></section><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(224, 224, 224);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:33.classicTable1:1" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:33.classicTable1:1.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;box-sizing: border-box;padding: 0px;" width="100.0000%"><section style="box-sizing: border-box;"><section style="display: flex;flex-flow: row;margin: 10px 0% 0px;justify-content: flex-start;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;height: auto;flex: 0 0 auto;align-self: center;box-sizing: border-box;"><section style="font-size: 20px;color: rgb(202, 29, 24);line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">02</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><section style="color: rgb(140, 140, 140);font-size: 13px;font-family: &#34;Noto Sans CJK SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(224, 224, 224);box-sizing: border-box;">｜</span><a href="https://mp.weixin.qq.com/s?__biz=MzUzOTQzMjA2Ng==&amp;mid=2247531001&amp;idx=1&amp;sn=2f50f357137d52d43c1a4baff627a01d&amp;chksm=facabc14cdbd350299a5d8954eaafb88a646f4f4331778cf521d88a3fc91c4f813bffc35f085&amp;token=1149641431&amp;lang=zh_CN&amp;scene=21#wechat_redirect" target="_blank" style="box-sizing: border-box;" data-linktype="2"><span style="box-sizing: border-box;">文化周报 | </span><span style="box-sizing: border-box;">五彩的！专属于安恒人的亚运瞬间</span></a></p></section></section></section><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(224, 224, 224);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:33.classicTable1:2" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:33.classicTable1:2.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: none;box-sizing: border-box;padding: 0px;" width="100.0000%"><section style="box-sizing: border-box;"><section style="display: flex;flex-flow: row;margin: 10px 0% 0px;justify-content: flex-start;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;height: auto;flex: 0 0 auto;align-self: center;box-sizing: border-box;"><section style="font-size: 20px;color: rgb(202, 29, 24);line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">03</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;align-self: center;height: auto;box-sizing: border-box;"><section style="color: rgb(140, 140, 140);font-size: 13px;font-family: &#34;Noto Sans CJK SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(224, 224, 224);box-sizing: border-box;">｜</span><a href="https://mp.weixin.qq.com/s?__biz=MzUzOTQzMjA2Ng==&amp;mid=2247530900&amp;idx=1&amp;sn=eb511bae3ff5069b826bad99de4c74c8&amp;chksm=facabc79cdbd356f8386d9bf45bc7dbc6ca175895961a8fcd6b6177a5badc2521849411217e4&amp;token=1544509756&amp;lang=zh_CN&amp;scene=21#wechat_redirect" target="_blank" style="box-sizing: border-box;" data-linktype="2"><span style="box-sizing: border-box;">文化周报｜夸夸奋战在亚运的女孩子们</span></a></p></section></section></section><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(224, 224, 224);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></td></tr></tbody></table></section></section><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us"><br style="box-sizing: border-box;"/></p><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-ratio="0.42592592592592593" data-s="300,640" width="100%" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=fc6f1498&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FRNPW5wLsX0kHsgT8NuDiaVHbgSQSZXI1zhVJvd771gJgT0YCjLH92x9hzBiaG1JZgVib66ry1yYoYr9TnAC2vtuhQ%2F640%3Fwx_fmt%3Dpng"/></section></section></section><p style="display: none;margin-bottom: 0px;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247496477">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b128e38a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496477%26idx%3D1%26sn%3D148b33bb55a9a420577256f77c4bceaa%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 01 Apr 2024 16:35:00 +0800</pubDate>
    </item>
    <item>
      <title>猎影追踪：新勒索家族出现，Donex公布多名受害者信息</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496475&amp;idx=1&amp;sn=11562f4abdade09264d5b00a3bb76973</link>
      <description>近日，安恒信息猎影实验室在威胁狩猎中捕获到一款名为Donex的新勒索家族样本</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2024-03-08 10:00</span> <span style="display: inline-block;">浙江</span>
</p>

<p>近日，安恒信息猎影实验室在威胁狩猎中捕获到一款名为Donex的新勒索家族样本</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=9bacb77a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQNlR8wJFR561fRIiaz1SJ2ia8whv0IQMOMPAdb8dWLUX11xDGZfyD3Fcg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 15px;line-height: 2;padding-left: 15px;padding-right: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012812" data-ratio="0.2777777777777778" data-s="300,640" width="100%" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=802eec2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQRG8GngOicHxZoPS2YvnFVK2LCSBql4VMcC1csScrzwS6UsEvPWYpOXg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 15px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);padding: 10px;background-color: rgb(239, 239, 239);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us">近日，安恒信息猎影实验室在威胁狩猎中捕获到一款名为Donex的新勒索家族样本。截止目前该网站已公布涉及多个国家共计5名受害者的信息。</p></section></section><section style="line-height: 0;text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img data-imgfileid="100012809" data-ratio="0.42803030303030304" data-s="300,640" width="100%" data-type="png" data-w="264" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=30df68e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQz0bD9eEXJqeqrbcKicFaXZKic78DRDvBeia7l622OW53t7YuSZ5Xf2QWA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 20px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px 0%;box-sizing: border-box;"><section style="display: inline-block;width: 15px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(69, 119, 218);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: rotateZ(315deg);-webkit-transform: rotateZ(315deg);-moz-transform: rotateZ(315deg);-o-transform: rotateZ(315deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 4px 0% 5px;box-sizing: border-box;"><section style="display: inline-block;width: 14px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(74, 187, 168);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px;font-size: 17px;text-align: center;color: rgb(102, 102, 102);line-height: 2;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">新勒索家族出现：Donex</strong></p></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">近日，安恒信息猎影实验室在威胁狩猎中捕获到一款名为Donex的新勒索家族样本。</p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">经分析，Donex勒索采用双重勒索策略，除加密文件外，还窃取敏感数据并在暗网搭建了专门的数据泄露网站用于胁迫受害者支付赎金。</p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012811" data-ratio="0.5028901734104047" data-s="300,640" width="100%" data-type="png" data-w="865" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=7e369436&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQ84eWpZgyXJialobKkAoTfjS9xHiauwFblWVbMd2Hiaic8TqZmj2Tw0vvUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 15px;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">样本分析截图</p></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">Donex采用AES和RSA组合的方式加密文件，加密的文件附加随机生成的后缀名，每个加密目录创建名为Readme.{后缀名}.txt的勒索信文件。</p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012810" data-ratio="0.26473988439306356" data-s="300,640" width="100%" data-type="png" data-w="865" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=206bcebb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQOszFFBUFpwmibuQbkh1JpAqDwxcfWgxHoicopHrjW21jwWVzPiccYDbYA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 15px;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">加密目录截图</p></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">在勒索信中提及了勒索组织名称Donex，并给出了联系方式和数据泄露博客网站。<br style="box-sizing: border-box;"/></p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012813" data-ratio="0.4929742388758782" data-s="300,640" width="100%" data-type="png" data-w="854" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=7b09e207&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQO4LRHQicbdHajaObCjZzlMHbjgnrIAWz6ZqZ7SuBtic0q1dODMZ2V1Vg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 15px;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">勒索信内容截图</p></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">截止3月6日，在Donex勒索的暗网博客上一共有5位受害者信息，最早的勒索受害者信息为2024年2月22日上传。<br style="box-sizing: border-box;"/></p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012814" data-ratio="0.46983758700696054" data-s="300,640" width="100%" data-type="png" data-w="862" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=c34b9dcf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQspogLtkb4dvCZOMwIibeP2amiaicg8rZFyKtdDwgibFwBCJZl6S65bRtgg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 15px;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">Donex五位受害者信息</p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012817" data-ratio="0.9282051282051282" data-s="300,640" width="100%" data-type="png" data-w="780" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=dfaa4c56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQHdeI69U6Ribpdgv6VW6wnZj1A4Eg3nmPm2uhwgWSI8uJvp2vlS1M6mw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 15px;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">泄露的部分信息截图</p></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 20px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px 0%;box-sizing: border-box;"><section style="display: inline-block;width: 15px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(69, 119, 218);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: rotateZ(315deg);-webkit-transform: rotateZ(315deg);-moz-transform: rotateZ(315deg);-o-transform: rotateZ(315deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 4px 0% 5px;box-sizing: border-box;"><section style="display: inline-block;width: 14px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(74, 187, 168);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px;font-size: 17px;text-align: center;color: rgb(102, 102, 102);line-height: 2;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">猎影观点：疑似Darkrace组织品牌重塑</strong></p></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">在最早公布的受害者信息截图中含有2024年1月份的数据信息，结合我们捕获到的样本创建时间是2024年2月18日，从中可以看出该勒索组织在年初1-2月成功展开了数次的勒索攻击活动。</p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012816" data-ratio="0.5474537037037037" data-s="300,640" width="100%" data-type="png" data-w="864" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=f20679de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQkxyb5Cq2TtZ9TLNufKAtnGgQTaQCMMCyvvocQMhCfjiaoszmP5M9zug%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">经横向对比，我们发现Donex组织样本与2023年短暂出现的Darkrace勒索家族样本的代码存在高度相似性，并且勒索信样式风格重叠。</p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">Darkrace勒索最早在2023年5月被发现，这是一种与LockBit勒索软件具有相似特征的勒索软件变体。该勒索出现时间很短，仅在2023年5月底至6月中旬期间公布了10名受害者后就关闭了暗网的博客站点。</p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">我们推测Donex可能是Darkrace勒索组织的品牌重塑或者勒索软件制作者存在一定的关联性。</strong></p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012818" data-ratio="0.24867724867724866" data-s="300,640" width="100%" data-type="png" data-w="945" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=2ff0ed3c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQPXCwEM2WORGHyoBT5FgQDJLg6DpzAMFaKTLUJGbicQatK3bUASLoR2A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 15px;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">Darkrace勒索的加密文件</p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012815" data-ratio="0.5630952380952381" data-s="300,640" width="100%" data-type="png" data-w="840" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=2c995af5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQEojZyft8qnIgVibXicHAZDDGtsmmDo4RSh1WJicvia0k6JXCmUc3FwlVcQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 15px;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">Darkrace的勒索信截图</p></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 20px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px 0%;box-sizing: border-box;"><section style="display: inline-block;width: 15px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(69, 119, 218);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: rotateZ(315deg);-webkit-transform: rotateZ(315deg);-moz-transform: rotateZ(315deg);-o-transform: rotateZ(315deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 4px 0% 5px;box-sizing: border-box;"><section style="display: inline-block;width: 14px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(74, 187, 168);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px;font-size: 17px;text-align: center;color: rgb(102, 102, 102);line-height: 2;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">防范建议</strong></p></section></section></section></section><section style="padding: 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">目前安全数据部已具备相关威胁检测能力，对应产品已完成IoC情报的集成。针对该事件中的最新IoC情报，以下产品的版本可自动完成更新，若无法自动更新则请联系技术人员手动更新：</p></section><section style="margin: 0px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">1. AiLPHA分析平台V5.0.0及以上版本</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">2. AiNTA设备V1.2.2及以上版本</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">3. AXDR平台V2.0.3及以上版本</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">4. APT设备V2.0.67及以上版本</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">5. EDR产品V2.0.17及以上版本</p></section></section><section style="padding: 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">安恒云沙箱已集成了海量威胁情报及样本特征。<br style="box-sizing: border-box;"/></p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">用户可通过云沙箱<span style="color: rgb(62, 62, 62);box-sizing: border-box;">：</span><span style="color: rgb(62, 62, 62);box-sizing: border-box;"><a href="https://sandbox.dbappsecurity.com.cn/对可疑文件进行威胁研判并下载分析报告。" target="_blank">https://sandbox.dbappsecurity.com.cn/对可疑文件进行威胁研判并下载分析报告。</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">或用沙箱打开不明来源的未知文件，在虚拟环境中进行内容预览，免于主机失陷、受到木马或病毒文件攻击。</p></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012821" data-ratio="0.5063583815028901" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=6bb58f59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQQRyoibSobOicUOnZ4DjD9VgpEz9oJdevOB7vkuBGH6qOyQ6rsWamib7oA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="padding: 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-image: linear-gradient(-90deg, rgb(9, 55, 147) 0%, rgb(69, 119, 218) 100%);padding: 9px 21px;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: justify;font-size: 18px;color: rgb(255, 255, 255);box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">下载方式</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;padding: 0px 9px 0px 12px;margin: 0px;box-sizing: border-box;"><section style="margin: 0.5em 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(245, 245, 245);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 11px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">猎影追踪</p></section></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 0px 1px 1px;border-color: rgb(69, 119, 218);padding: 7px;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;transform: rotateX(180deg) rotateY(180deg);-webkit-transform: rotateX(180deg) rotateY(180deg);-moz-transform: rotateX(180deg) rotateY(180deg);-o-transform: rotateX(180deg) rotateY(180deg);margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 3px 3px 8px;border-style: solid;border-width: 0px 2px 2px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 28px;height: 8px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 0px 1px 1px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: justify;color: rgb(62, 62, 62);box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section><section style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;padding: 6px 21px;box-sizing: border-box;"><section style="margin: 0px;text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">《APT37利用朝鲜政治话题针对韩国的攻击活动分析报告》为安恒研究院猎影实验室独家发布，<span style="color: rgb(69, 119, 218);box-sizing: border-box;"><strong style="box-sizing: border-box;">如对此研究感兴趣或欲了解报告更多详细，请前往下载。</strong></span></p></section></section><section style="margin-top: 10px;margin-bottom: 10px;line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;box-sizing: border-box;"><span style="width: 0px;display: inline-block;opacity: 0.6;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span><span style="width: 0px;display: inline-block;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span> </section><section style="display: inline-block;vertical-align: top;line-height: 1.2;padding-left: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">方式一：扫描下方二维码即可下载</strong></p></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012826" data-ratio="1" data-s="300,640" style="" data-type="png" data-w="195" src="https://wechat2rss.xlab.app/img-proxy/?k=f4af77e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQLIPEKvhzLR9MXcL06O96L7oKHRVuZg01ibyPrz7xE0F3eKt9JcFOhUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></section><section style="margin-top: 10px;margin-bottom: 10px;line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;box-sizing: border-box;"><span style="width: 0px;display: inline-block;opacity: 0.6;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span><span style="width: 0px;display: inline-block;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span> </section><section style="display: inline-block;vertical-align: top;line-height: 1.2;padding-left: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">方式二：点击文末“阅读原文”即可下载</strong></p></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 12px;"><a href="https://app-martech.dbappsecurity.com.cn/svip/sapIndex/SapSourceData?pf_uid=17709_1776&amp;sid=324&amp;source=1&amp;pf_type=3&amp;channel_id=8987&amp;channel_name=%E5%AE%89%E6%81%92%E7%A0%94%E7%A9%B6%E9%99%A2&amp;tag_id=2824468d92446b27" target="_blank">https://app-martech.dbappsecurity.com.cn/svip/sapIndex/SapSourceData?pf_uid=17709_1776&amp;sid=324&amp;source=1&amp;pf_type=3&amp;channel_id=8987&amp;channel_name=%E5%AE%89%E6%81%92%E7%A0%94%E7%A9%B6%E9%99%A2&amp;tag_id=2824468d92446b27</a></span></p></section><section style="margin-top: 10px;margin-bottom: 10px;line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;box-sizing: border-box;"><span style="width: 0px;display: inline-block;opacity: 0.6;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span><span style="width: 0px;display: inline-block;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span> </section><section style="display: inline-block;vertical-align: top;line-height: 1.2;padding-left: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">方式三：联系安恒信息当地商务人员获取</strong></p></section></section></section></section><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 3px 3px 8px;border-style: solid;border-width: 0px 2px 2px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 28px;height: 8px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 0px 1px 1px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: justify;color: rgb(62, 62, 62);box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: stretch;margin: 0px;z-index: 1;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px;line-height: 0;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 20px;height: auto;box-sizing: border-box;"><img data-imgfileid="100012819" data-ratio="1" data-s="300,640" width="100%" data-type="svg" data-w="150" style="vertical-align: middle;max-width: 100%;width: 100%;height: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=a156212a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F0T8yO33zeegIYLSdibPPqZwKyriarU4deooluypYjPI8n4MfDCbVeVInGqwAwFiaW96do3wXNoJkQaJaicF31gUR7zibDn38cvlyf%2F640%3Fwx_fmt%3Dsvg%26from%3Dappmsg"/></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: stretch;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 10px 55px 0px 20px;margin: 0px -45px 0px -20px;background-color: rgb(223, 229, 235);box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 2px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-image: linear-gradient(90deg, rgb(107, 186, 216) 0%, rgb(69, 119, 218) 100%);padding: 2px 20px;border-radius: 50px;overflow: hidden;box-sizing: border-box;"><section style="text-align: center;color: rgb(255, 255, 255);letter-spacing: 2px;box-sizing: border-box;" powered-by="xiumi.us"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;">关于猎影追踪系列报告</span></strong></p></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;margin: 0px;overflow: hidden;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px;line-height: 0;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012820" data-ratio="1" data-s="300,640" width="100%" data-type="svg" data-w="150" style="vertical-align: middle;max-width: 100%;width: 100%;height: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=86202b1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F0T8yO33zeegIYLSdibPPqZwKyriarU4deoJXSHUiba0T5HGjUntUkBs7l8OWfVMtgDebgIWzaBChenvO6nmto7YPZZibTFPueXE6%2F640%3Fwx_fmt%3Dsvg%26from%3Dappmsg"/></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(223, 229, 235);padding: 20px;border-top-right-radius: 10px;border-bottom-left-radius: 10px;border-bottom-right-radius: 10px;overflow: hidden;box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">猎影追踪系列报告旨在提供有价值的网络安全信息和洞察，包含对网络安全领域最新的威胁趋势、漏洞发现、攻击手法以及防御策略等内容。该报告还基于猎影实验室的研究成果和实战经验，针对不同的安全问题提出可依循、可执行的建议，帮助企业提升自身的安全防护能力，更好地应对不断变化的网络安全挑战。</p></section></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012822" data-ratio="0.278125" data-s="300,640" width="100%" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=646e3a99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvndzOZsKNS1En7hO0561afqQE8DBNHOCZR2XRhhkrGwjT61bnB4jOvciarmF48Qc3vkaowZpGOTmicjg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://app-martech.dbappsecurity.com.cn/resources/ResourcePc/ResourcePcInfo?pf_uid=17709_1776%5cx26amp;id=324%5cx26amp;source=1%5cx26amp;pf_type=3%5cx26amp;channel_id=8987%5cx26amp;channel_name=%E5%AE%89%E6%81%92%E7%A0%94%E7%A9%B6%E9%99%A2%5cx26amp;tag_id=2824468d92446b27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=35123eda&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496475%26idx%3D1%26sn%3D11562f4abdade09264d5b00a3bb76973%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 Mar 2024 10:00:00 +0800</pubDate>
    </item>
    <item>
      <title>猎影追踪：APT37利用朝鲜政治话题针对韩国的攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496455&amp;idx=1&amp;sn=0e3af7d734671a41c9d796e7f33b085d</link>
      <description>APT37组织多次利用朝鲜相关政治话题诱饵，向目标用户下发ROKRAT木马窃取信息</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2024-03-04 10:10</span> <span style="display: inline-block;">浙江</span>
</p>

<p>APT37组织多次利用朝鲜相关政治话题诱饵，向目标用户下发ROKRAT木马窃取信息</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=549d97ed&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvncfuL8We9icho9o4B6oHGO1T6m15Qxlh7Z4CXSJQA03QQohx6UM6MSs2MPtiaN9Jia0BCzpkCNQgDSIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 15px;line-height: 2;padding-left: 15px;padding-right: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012800" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fccd50be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncfuL8We9icho9o4B6oHGO1Tnm492wMdPxjeuo4zhpIzDWK5KqSvxkVyEl0y24EPeIacqAv81AJlIg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 15px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);padding: 10px;background-color: rgb(239, 239, 239);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us">近日，安恒信息猎影实验室在日常威胁狩猎中发现APT37组织多次利用朝鲜相关政治话题诱饵，向目标用户下发ROKRAT木马窃取信息。</p></section></section><section style="line-height: 0;text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012801" data-ratio="0.42803030303030304" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="264" src="https://wechat2rss.xlab.app/img-proxy/?k=6ab1a092&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncfuL8We9icho9o4B6oHGO1TmbicTy7iaELdB7eZic9Y01J7DcJW5D4K0EFRE72tM7F363Pw7Toiam43BQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 20px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px 0%;box-sizing: border-box;"><section style="display: inline-block;width: 15px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(69, 119, 218);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: rotateZ(315deg);-webkit-transform: rotateZ(315deg);-moz-transform: rotateZ(315deg);-o-transform: rotateZ(315deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 4px 0% 5px;box-sizing: border-box;"><section style="display: inline-block;width: 14px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(74, 187, 168);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px;font-size: 17px;text-align: center;color: rgb(102, 102, 102);line-height: 2;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">针对韩国的APT组织</strong></p></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">APT37组织又名Group123、InkySquid、Operation Daybreak、Operation Erebus、Reaper Group、Red Eyes、ScarCruft、Venus 121。</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">该组织至少从2012年开始活跃，主要针对韩国的公共和私营部门。2017年，APT37将其目标扩展到朝鲜半岛之外，包括日本、越南和中东，并扩展到更广泛的垂直行业，包括化学、电子、制造、航空航天、汽车和医疗保健实体。</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">2023年，APT37组织开始针对国内用户进行网络钓鱼，涉及Windows和Android平台。</p></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 20px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px 0%;box-sizing: border-box;"><section style="display: inline-block;width: 15px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(69, 119, 218);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: rotateZ(315deg);-webkit-transform: rotateZ(315deg);-moz-transform: rotateZ(315deg);-o-transform: rotateZ(315deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 4px 0% 5px;box-sizing: border-box;"><section style="display: inline-block;width: 14px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(74, 187, 168);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px;font-size: 17px;text-align: center;color: rgb(102, 102, 102);line-height: 2;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">样本信息</strong></p></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">我们捕获的两条较为攻击样本如下：<br style="box-sizing: border-box;"/></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(69, 119, 218);box-sizing: border-box;"><strong style="box-sizing: border-box;">样本一：(安全专栏)安全机构不应对反国家势力束手无策.zip</strong></span></p></section></section><section style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;" width="100%"><tbody style="box-sizing: border-box;"><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:7.classicTable1:0" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:7.classicTable1:0.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">文件名</p></section></section></td><td colspan="2" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:7.classicTable1:0.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">(안보칼럼) 반국가세력에안보기관이무기력해서는안된다.zip</p><p style="margin: 0px;padding: 0px;box-sizing: border-box;">(安全专栏)安全机构不应对反国家势力束手无策.zip</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:7.classicTable1:1" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:7.classicTable1:1.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">文件hash</p></section></section></td><td colspan="2" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:7.classicTable1:1.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">5127bf820b33e4491a93165cfdd25be4</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:7.classicTable1:2" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:7.classicTable1:2.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">文件格式</p></section></section></td><td colspan="2" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:7.classicTable1:2.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">zip</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:7.classicTable1:3" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:7.classicTable1:3.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">文件大小</p></section></section></td><td colspan="2" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:7.classicTable1:3.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">221.43MB</p></section></section></td></tr></tbody></table></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">样本一中释放的诱饵为韩国国家安全与统一研究所高级研究员、檀国大学行政法研究生院兼职教授、21世纪战略研究所所长发布的专栏文章，文章讨论了朝鲜敌意的加剧以及对外部渗透和间谍活动的担忧。</p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012802" data-ratio="0.4046242774566474" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=f88e8451&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncfuL8We9icho9o4B6oHGO1TSbSYgdXRm5XzmiccibGpXtled9DwcjErHd9ibCYSvpkibLejWL8LLbrtpA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="color: rgb(69, 119, 218);box-sizing: border-box;">样本二：对朝鲜的贡献(1).zip</strong><br style="box-sizing: border-box;"/></p></section></section><section style="min-height: 40px;margin: 10px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="width: 100%;margin: 0px auto -10px;box-sizing: border-box;"><table style="border-collapse: collapse;box-sizing: border-box;margin-bottom: 10px;" width="100%"><tbody style="box-sizing: border-box;"><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:11.classicTable1:0" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:11.classicTable1:0.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">文件名</p></section></section></td><td colspan="2" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:11.classicTable1:0.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">북한지기고문 (1).zip</p><p style="margin: 0px;padding: 0px;box-sizing: border-box;">对朝鲜的贡献(1).zip</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:11.classicTable1:1" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:11.classicTable1:1.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">文件hash</p></section></section></td><td colspan="2" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:11.classicTable1:1.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">29f494e0a66158a808b39299267c5c53</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:11.classicTable1:2" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:11.classicTable1:2.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">文件格式</p></section></section></td><td colspan="2" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:11.classicTable1:2.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">zip</p></section></section></td></tr><tr opera-tn-ra-comp="_$.pages:0.layers:0.comps:11.classicTable1:3" style="box-sizing: border-box;" powered-by="xiumi.us"><td colspan="1" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:11.classicTable1:3.td@@0" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="33.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">文件大小</p></section></section></td><td colspan="2" rowspan="1" opera-tn-ra-cell="_$.pages:0.layers:0.comps:11.classicTable1:3.td@@1" style="border-width: 1px;border-color: rgb(62, 62, 62);border-style: solid;box-sizing: border-box;padding: 0px;" width="67.0000%"><section style="margin: 5px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;padding: 0px 5px;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">53.62 MB</p></section></section></td></tr></tbody></table></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">样本2具有多个诱饵，为朝鲜研究所研究员以及社会人士发表的各类朝鲜政治话题的文章，推测该样本用于攻击朝鲜政治主题相关研究人员。</p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012799" data-ratio="0.3774230330672748" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="877" src="https://wechat2rss.xlab.app/img-proxy/?k=e790546a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncfuL8We9icho9o4B6oHGO1Tia7SibSnmKbP1dhw0nR8YwK5364KCtOHvXfVjiaszz1GpjqiaWcm2OqcYw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 20px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px 0%;box-sizing: border-box;"><section style="display: inline-block;width: 15px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(69, 119, 218);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: rotateZ(315deg);-webkit-transform: rotateZ(315deg);-moz-transform: rotateZ(315deg);-o-transform: rotateZ(315deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 4px 0% 5px;box-sizing: border-box;"><section style="display: inline-block;width: 14px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(74, 187, 168);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px;font-size: 17px;text-align: center;color: rgb(102, 102, 102);line-height: 2;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">思考总结</strong></p></section></section></section></section><section style="padding: 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">随着近期朝鲜领导人提出“北南关系再也不是同族关系、同质关系，而且完全固定为敌对的两个国家关系、战争中的两个交战国关系”，朝韩关系骤然紧张。</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">APT37组织多年来持续性的对韩国发起攻击，持续恶化的两国关系不仅为该组织提供了更多的攻击动机，韩国民众对于朝韩关系关注度的上升也有利于该组织使用鱼叉式钓鱼邮件等方式进行攻击。</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">从本次捕获的攻击样本来看，该组织的核心攻击木马较一年前无太大变化，仅通过改变诱饵文件以及木马加载方式来提高攻击成功率。</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">这种简单快捷的攻击方式虽然可快速发起攻击，但也存在易被安全产品检测的问题，因此该组织在不断提高压缩包的大小以逃避检测。随着两国关系的持续紧张，相信未来该组织会进行更多类似的攻击活动。</p></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 20px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px 0%;box-sizing: border-box;"><section style="display: inline-block;width: 15px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(69, 119, 218);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: rotateZ(315deg);-webkit-transform: rotateZ(315deg);-moz-transform: rotateZ(315deg);-o-transform: rotateZ(315deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 4px 0% 5px;box-sizing: border-box;"><section style="display: inline-block;width: 14px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(74, 187, 168);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px;font-size: 17px;text-align: center;color: rgb(102, 102, 102);line-height: 2;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">防范建议</strong></p></section></section></section></section><section style="padding: 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">目前安全数据部已具备相关威胁检测能力，对应产品已完成IoC情报的集成。针对该事件中的最新IoC情报，以下产品的版本可自动完成更新，若无法自动更新则请联系技术人员手动更新：</p></section><section style="margin: 0px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">1. AiLPHA分析平台V5.0.0及以上版本</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">2. AiNTA设备V1.2.2及以上版本</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">3. AXDR平台V2.0.3及以上版本</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">4. APT设备V2.0.67及以上版本</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">5. EDR产品V2.0.17及以上版本</p></section></section><section style="padding: 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">安恒云沙箱已集成了海量威胁情报及样本特征。<br style="box-sizing: border-box;"/></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">用户可通过云沙箱：<a href="https://sandbox.dbappsecurity.com.cn/对可疑文件进行威胁研判并下载分析报告。或用沙箱打开不明来源的未知文件，在虚拟环境中进行内容预览，免于主机失陷、受到木马或病毒文件攻击。" target="_blank">https://sandbox.dbappsecurity.com.cn/对可疑文件进行威胁研判并下载分析报告。或用沙箱打开不明来源的未知文件，在虚拟环境中进行内容预览，免于主机失陷、受到木马或病毒文件攻击。</a></p></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-image: linear-gradient(-90deg, rgb(9, 55, 147) 0%, rgb(69, 119, 218) 100%);padding: 9px 21px;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: justify;font-size: 18px;color: rgb(255, 255, 255);box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">下载方式</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;padding: 0px 9px 0px 12px;margin: 0px;box-sizing: border-box;"><section style="margin: 0.5em 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(245, 245, 245);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 11px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">猎影追踪</p></section></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 0px 1px 1px;border-color: rgb(69, 119, 218);padding: 7px;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;transform: rotateX(180deg) rotateY(180deg);-webkit-transform: rotateX(180deg) rotateY(180deg);-moz-transform: rotateX(180deg) rotateY(180deg);-o-transform: rotateX(180deg) rotateY(180deg);margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 3px 3px 8px;border-style: solid;border-width: 0px 2px 2px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 28px;height: 8px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 0px 1px 1px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: justify;color: rgb(62, 62, 62);box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section><section style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;padding: 6px 21px;box-sizing: border-box;"><section style="margin: 0px;text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">《APT37利用朝鲜政治话题针对韩国的攻击活动分析报告》为安恒研究院猎影实验室独家发布，<span style="color: rgb(69, 119, 218);box-sizing: border-box;"><strong style="box-sizing: border-box;">如对此研究感兴趣或欲了解报告更多详细，请前往下载。</strong></span></p></section></section><section style="margin-top: 10px;margin-bottom: 10px;line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;box-sizing: border-box;"><span style="width: 0px;display: inline-block;opacity: 0.6;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span><span style="width: 0px;display: inline-block;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span> </section><section style="display: inline-block;vertical-align: top;line-height: 1.2;padding-left: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">方式一：扫描下方二维码即可下载</strong></p></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012806" data-ratio="1" data-s="300,640" style="" data-type="png" data-w="195" src="https://wechat2rss.xlab.app/img-proxy/?k=5c01cbfe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncfuL8We9icho9o4B6oHGO1TLdGjlibs5jRs4UPxjufXo3yFPEj72EeXl4unS9ckWMlSfibdyHpzATog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></section><section style="margin-top: 10px;margin-bottom: 10px;line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;box-sizing: border-box;"><span style="width: 0px;display: inline-block;opacity: 0.6;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span><span style="width: 0px;display: inline-block;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span> </section><section style="display: inline-block;vertical-align: top;line-height: 1.2;padding-left: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">方式二：点击下方链接或文末“阅读原文”即可下载</strong></p></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 12px;"><a href="https://app-martech.dbappsecurity.com.cn/resources/ResourcePc/ResourcePcInfo?pf_uid=17709_1776&amp;id=321&amp;source=1&amp;pf_type=3&amp;channel_id=8987&amp;channel_name=%E5%AE%89%E6%81%92%E7%A0%94%E7%A9%B6%E9%99%A2&amp;tag_id=2824468d92446b27" target="_blank">https://app-martech.dbappsecurity.com.cn/resources/ResourcePc/ResourcePcInfo?pf_uid=17709_1776&amp;id=321&amp;source=1&amp;pf_type=3&amp;channel_id=8987&amp;channel_name=%E5%AE%89%E6%81%92%E7%A0%94%E7%A9%B6%E9%99%A2&amp;tag_id=2824468d92446b27</a></span></p></section><section style="margin-top: 10px;margin-bottom: 10px;line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;box-sizing: border-box;"><span style="width: 0px;display: inline-block;opacity: 0.6;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span><span style="width: 0px;display: inline-block;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span> </section><section style="display: inline-block;vertical-align: top;line-height: 1.2;padding-left: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">方式三：联系安恒信息当地商务人员获取</strong></p></section></section></section></section><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 3px 3px 8px;border-style: solid;border-width: 0px 2px 2px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 28px;height: 8px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 0px 1px 1px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: justify;color: rgb(62, 62, 62);box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: stretch;margin: 0px;z-index: 1;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px;line-height: 0;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 20px;height: auto;box-sizing: border-box;"><img data-imgfileid="100012798" data-ratio="1" data-s="300,640" width="100%" data-type="svg" data-w="150" style="vertical-align: middle;max-width: 100%;width: 100%;height: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=5165f837&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F0T8yO33zeegIYLSdibPPqZ27uoFlJ5icf9OEE3hCCoj8bJW1kZnftc2P8umQ2U5ibPXYI9e3hyw2E3osgmicToaHypmgTOFILedI%2F640%3Fwx_fmt%3Dsvg%26from%3Dappmsg"/></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: stretch;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 10px 55px 0px 20px;margin: 0px -45px 0px -20px;background-color: rgb(223, 229, 235);box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 2px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-image: linear-gradient(90deg, rgb(107, 186, 216) 0%, rgb(69, 119, 218) 100%);padding: 2px 20px;border-radius: 50px;overflow: hidden;box-sizing: border-box;"><section style="text-align: center;color: rgb(255, 255, 255);letter-spacing: 2px;box-sizing: border-box;" powered-by="xiumi.us"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;">关于猎影追踪系列报告</span></strong></p></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;margin: 0px;overflow: hidden;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px;line-height: 0;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;box-sizing: border-box;"><img data-imgfileid="100012803" data-ratio="1" data-s="300,640" width="100%" data-type="svg" data-w="150" style="vertical-align: middle;max-width: 100%;width: 100%;height: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=e08c0ce5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F0T8yO33zeegIYLSdibPPqZ27uoFlJ5icf96mQScHL35nxypgN52sbmdvwibOnNnvPicJnNGf541ia3maczAtgLM47ibn4ecRFmBIrS%2F640%3Fwx_fmt%3Dsvg%26from%3Dappmsg"/></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(223, 229, 235);padding: 20px;border-top-right-radius: 10px;border-bottom-left-radius: 10px;border-bottom-right-radius: 10px;overflow: hidden;box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">猎影追踪系列报告旨在提供有价值的网络安全信息和洞察，包含对网络安全领域最新的威胁趋势、漏洞发现、攻击手法以及防御策略等内容。该报告还基于猎影实验室的研究成果和实战经验，针对不同的安全问题提出可依循、可执行的建议，帮助企业提升自身的安全防护能力，更好地应对不断变化的网络安全挑战。</p></section></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012804" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=4888d815&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvncfuL8We9icho9o4B6oHGO1TAibIepmOKKduKhRrWtiagyfMXERpVnmg2SVBXgpCp6Z5bJMjGqyMOnIQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://app-martech.dbappsecurity.com.cn/svip/sapIndex/SapSourceData?pf_uid=17709_1776%5cx26amp;sid=321%5cx26amp;source=1%5cx26amp;pf_type=3%5cx26amp;channel_id=8987%5cx26amp;channel_name=%E5%AE%89%E6%81%92%E7%A0%94%E7%A9%B6%E9%99%A2%5cx26amp;tag_id=2824468d92446b27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=090b6fb2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496455%26idx%3D1%26sn%3D0e3af7d734671a41c9d796e7f33b085d%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 04 Mar 2024 10:10:00 +0800</pubDate>
    </item>
    <item>
      <title>全球最为猖獗的勒索组织LockBit遭到执法部门打击，或将取缔</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496427&amp;idx=1&amp;sn=5ef6d80e38d4722a3bf6293b5de1b2e9</link>
      <description>英方宣称重创LockBit勒索软件组织</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2024-02-21 17:26</span> <span style="display: inline-block;">浙江</span>
</p>

<p>英方宣称重创LockBit勒索软件组织</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4cd411e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvncKgsCs1ia12ZptcNuRztqGAia2h6M7Ficnn0GjRd9X12ABrWjsPpVZicpFYkIdDDg1Uxa4leWWZgJbMg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012772" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=58de6d79&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncKgsCs1ia12ZptcNuRztqGAkUYZzGCxpPxnRwFNDf7MFm1MC9OlOnu19S8ONuFHVnlTd0G0xrfKyg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 15px 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;box-sizing: border-box;"><section style="margin: 10px 0px;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgba(0, 0, 0, 0.04);border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);align-self: flex-start;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;padding: 0px 13px;box-sizing: border-box;"><section style="transform: rotateZ(12deg);-webkit-transform: rotateZ(12deg);-moz-transform: rotateZ(12deg);-o-transform: rotateZ(12deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;justify-content: center;margin: -20px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(69, 119, 218);padding: 20px 13px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><section style="transform: rotateZ(348deg);-webkit-transform: rotateZ(348deg);-moz-transform: rotateZ(348deg);-o-transform: rotateZ(348deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="color: rgb(255, 255, 255);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">01</strong></p></section></section></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;padding: 6px 15px 6px 6px;box-sizing: border-box;"><section style="color: rgb(62, 62, 62);box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="background-color: rgba(0, 0, 0, 0);text-decoration-thickness: auto;text-decoration-style: solid;text-decoration-color: rgb(62, 62, 62);box-sizing: border-box;">英方宣称重创LockBit勒索软件组织</span></strong></p></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">2024年2月20日，英国国家犯罪局（NCA)发布消息称，在国际多部门的联合执法下，开展了代号为“克洛诺斯行动”的专项工作，日前重创了LockBit勒索软件组织，对该组织及其附属机构造成了灾难性的打击。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">目前，LockBit 勒索软件组织Tor域名显示了宣布执法机构执行活动的网页。它以 LockBit格式展示，表明他们可以完全控制LockBit勒索软件组织的基础设施。</span></p></section></section><section style="line-height: 0;text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 93%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012771" data-ratio="0.5218579234972678" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="732" src="https://wechat2rss.xlab.app/img-proxy/?k=595f6369&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncKgsCs1ia12ZptcNuRztqGA46XBCeiaVJkDQcnFMXFg4ib7elpKokjwVLmW5O6Q2T4qgMA04ofUzAcg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">执法机构还表示，已经抓捕了2名LockBit勒索组织成员，并冻结200多个相关加密货币账号。他们关闭了荷兰、德国、芬兰、法国、瑞士、澳大利亚、美国和英国的34台服务，从扣押的基础设施中获取了1000多个密钥，得以帮助受害者恢复受影响的系统。此外透露，他们将在本周内陆续发布有关LockBit组织的更多情报。</span></p></section></section><section style="margin: 15px 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;box-sizing: border-box;"><section style="margin: 10px 0px;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgba(0, 0, 0, 0.04);border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);align-self: flex-start;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;padding: 0px 13px;box-sizing: border-box;"><section style="transform: rotateZ(12deg);-webkit-transform: rotateZ(12deg);-moz-transform: rotateZ(12deg);-o-transform: rotateZ(12deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;justify-content: center;margin: -20px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(69, 119, 218);padding: 20px 13px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><section style="transform: rotateZ(348deg);-webkit-transform: rotateZ(348deg);-moz-transform: rotateZ(348deg);-o-transform: rotateZ(348deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="color: rgb(255, 255, 255);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">02</strong></p></section></section></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;padding: 6px 15px 6px 6px;box-sizing: border-box;"><section style="color: rgb(62, 62, 62);box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="background-color: rgba(0, 0, 0, 0);text-decoration-thickness: auto;text-decoration-style: solid;text-decoration-color: rgb(62, 62, 62);box-sizing: border-box;">LockBit犯罪记录盘点</span></strong></p></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">LockBit是世界上最为活跃的勒索组织，</span><span style="font-size: 15px;color: rgb(69, 119, 218);box-sizing: border-box;">已针对2000多名受害者发起过攻击</span><span style="font-size: 15px;box-sizing: border-box;">，提出总计数亿美元的赎金要求，</span><span style="font-size: 15px;color: rgb(69, 119, 218);box-sizing: border-box;">并已收到超过1.2亿美元的赎金付款</span><span style="font-size: 15px;color: rgb(69, 119, 218);box-sizing: border-box;">。</span><br style="box-sizing: border-box;"/></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">LockBit最早在2019年以勒索及服务的运营模式出现，其中加密器被授权给附属公司，这些附属公司实施攻击，以换取赎金收益的一部分。</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">该组织一直积极实施勒索攻击活动，发起了包括针对波音公司、英国皇家邮政等在内的众多重大勒索攻击事件。</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">LockBit在全球范围内勒索攻击活动频繁，影响广泛，众多大型跨国企业和政府部门都受到波及。</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;color: rgb(69, 119, 218);box-sizing: border-box;">以下是我们整理的部分2023年以来的重大攻击事件和目标：</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">1、2023年1月，LockBit攻击了英国皇家邮政，迫使迫使国际邮政服务陷入停摆。</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">2、2023年2月，全球电源产品制造商Phihong遭到LockBit勒索攻击，要求受害者支付50万美元的赎金。</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">3、2023年6月，LockBit宣称入侵了全球半导体制造巨头台积电的供应商，向其索要高达7000万美元的巨额赎金。</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">4、2023年7月，日本最大港口名古屋港口码头遭到LockBit的攻击，所有集装箱码头运营均已中断。</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">5、2023年10月，LockBit向全球知名IT解决方案供应商CDW所要8000万美元的赎金。</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">6、2023年11月，LockBit窃取并公布了美国波音公司43GB内部数据。</span></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">7、2024年1月，LockBit 勒索软件组织声称对2023年11月美国Capital Health保健公司的网络攻击负责，并威胁泄露被盗数据和谈判聊天记录。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">8、2024年2月，LockBit声称勒索软件袭击了佐治亚州富尔顿县，并发布25个屏幕截图，证明他们已访问该县的系统并窃取了敏感数据。</span></p></section></section><section style="margin: 15px 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;box-sizing: border-box;"><section style="margin: 10px 0px;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgba(0, 0, 0, 0.04);border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);align-self: flex-start;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;padding: 0px 13px;box-sizing: border-box;"><section style="transform: rotateZ(12deg);-webkit-transform: rotateZ(12deg);-moz-transform: rotateZ(12deg);-o-transform: rotateZ(12deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;justify-content: center;margin: -20px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(69, 119, 218);padding: 20px 13px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><section style="transform: rotateZ(348deg);-webkit-transform: rotateZ(348deg);-moz-transform: rotateZ(348deg);-o-transform: rotateZ(348deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="color: rgb(255, 255, 255);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">03</strong></p></section></section></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;padding: 6px 15px 6px 6px;box-sizing: border-box;"><section style="color: rgb(62, 62, 62);box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="background-color: rgba(0, 0, 0, 0);text-decoration-thickness: auto;text-decoration-style: solid;text-decoration-color: rgb(62, 62, 62);box-sizing: border-box;">执法行动复盘</span></strong></p></section></section></section></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">2月20日，英国国家犯罪局（NCA)在其官网上公布他们查封了LockBit的Tor网站并获取了一系列基础设施和情报。</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">克洛诺斯行动占据LockBit在暗网的博客网站后，在其页面上显示了多个与LockBit以往类似的标志性风格图案，例如在展示相关执法部门的信息，以及网页加载动画，甚至在受害者信息中标记LockBit管理员Lockbitsupp，极显嘲讽意味和胜利姿态。</p></section></section><section style="line-height: 0;text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 93%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012773" data-ratio="0.4668335419274093" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="799" src="https://wechat2rss.xlab.app/img-proxy/?k=500bca00&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncKgsCs1ia12ZptcNuRztqGAJbI57Pj0S2eGrFsITJjcPVNTicl3Gibh4KAKHN033dlYtEnqGJSNy0ZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 12px;box-sizing: border-box;">LockBit暗网博客目前的主页</span><br style="box-sizing: border-box;"/></p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012769" data-ratio="0.4463350785340314" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="764" src="https://wechat2rss.xlab.app/img-proxy/?k=84971a86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncKgsCs1ia12ZptcNuRztqGAwGlsDl5wA1RlU39jMaTVGQxcpianGg9vJqeZhDBLPial76iaJ1faankIw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 12px;box-sizing: border-box;">博客子页面</span><br style="box-sizing: border-box;"/></p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012770" data-ratio="0.5156069364161849" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=a67ec729&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncKgsCs1ia12ZptcNuRztqGA7eB5qf41RZ0ua5sHBRrwV5jxmVLRBmCHPLOia9J9O2jgrltgKcOGF8g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;line-height: 2;padding: 0px 15px;font-size: 12px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">公布获取的源代码、管理面板截图</p></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;font-size: 15px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">日本警方、NCA 和联邦调查局 (FBI) 在欧洲刑警组织的支持下开发了 LockBit3.0勒索软件解密工具，但尚未透露该工具的适用范围。<br style="box-sizing: border-box;"/></p></section></section><section style="line-height: 0;text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 93%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012774" data-ratio="0.5508241758241759" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="728" src="https://wechat2rss.xlab.app/img-proxy/?k=963c532f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvncKgsCs1ia12ZptcNuRztqGAE8p9pLA9dgUAlVA7UibC9S3ozqzBaRK97aPibwHqUrgZxrxvulIreKGw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">英美等政府的执法部门将在本周内陆续发布掌握的LockBit情报信息，目前透露的情报汇总主要如下：<br style="box-sizing: border-box;"/></p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">1.   英国NCA公布了 Lockbit 后端的敏感信息：管理面板、博客后端和博客源码等</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">2.   美国政府公布了对与 Lockbit 勒索软件组织有关的两名个人的起诉：Artur Sungatov 和 Ivan Kondratyev</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">3.   执法部门联合日本合作伙伴发布了Lockbit解密工具</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">4.   在波兰和乌克兰共逮捕了2名LockBit组织成员</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">5.   执法部门于2024年2月21日公布有关 Lockbit 的 StealBit 数据泄露工具的信息</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">6.   执法部门于2024年2月21日公布 Lockbit 附属基础设施</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">7.   执法部门与SecureWorks 将于2024年2月22日披露有关 Lockbit tradecraft 的信息</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">8. 执法机构将于2024年2月23日公布有关 Lockbit 加密货币和货币运营的敏感信息</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">9. 执法部门计划于2024年2月23日公布 Lockbit 勒索软件组织管理机构的身份</p></section></section><section style="margin: 15px 0px;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;box-sizing: border-box;"><section style="margin: 10px 0px;text-align: justify;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;background-color: rgba(0, 0, 0, 0.04);border-width: 0px;border-style: none;border-color: rgb(62, 62, 62);align-self: flex-start;box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;padding: 0px 13px;box-sizing: border-box;"><section style="transform: rotateZ(12deg);-webkit-transform: rotateZ(12deg);-moz-transform: rotateZ(12deg);-o-transform: rotateZ(12deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;justify-content: center;margin: -20px 0px;display: flex;flex-flow: row;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(69, 119, 218);padding: 20px 13px;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: flex-start;box-sizing: border-box;"><section style="transform: rotateZ(348deg);-webkit-transform: rotateZ(348deg);-moz-transform: rotateZ(348deg);-o-transform: rotateZ(348deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="color: rgb(255, 255, 255);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">04</strong></p></section></section></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;padding: 6px 15px 6px 6px;box-sizing: border-box;"><section style="color: rgb(62, 62, 62);box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="background-color: rgba(0, 0, 0, 0);text-decoration-thickness: auto;text-decoration-style: solid;text-decoration-color: rgb(62, 62, 62);box-sizing: border-box;">思考总结</span></strong></p></section></section></section></section></section></section></section><section style="line-height: 2;padding: 0px 15px;font-size: 15px;box-sizing: border-box;" powered-by="xiumi.us"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="box-sizing: border-box;">过去一年，已有一些勒索组织如Hive、Ragnar Locker、BlackCat受到了破坏甚至取缔，一系列行动鼓舞并振奋了网络犯罪执法的信心。</span><span style="box-sizing: border-box;">此次针对LockBit的执法行动对勒索攻击等网络犯罪活动是一次强有力的威慑，具有重大意义。</span></p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="box-sizing: border-box;">然而，勒索攻击的态势并未消减。一些新兴勒索组织，例如AKira、Rhysida相继崛起，使得整体威胁格局更加错综复杂。</span></p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">同时<span style="box-sizing: border-box;">，一个庞大勒索组织的彻底瓦解是长期持续对抗的结果，在该过程中可能孕育出新的犯罪团伙，例如此前的conti勒索组织消亡后出现了多个新的勒索团伙分支，表明斗争形势依然严峻。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="box-sizing: border-box;">在面对勒索攻击等网络威胁时，打击和防御需同步进行。这次行动的成功将有助于加强全球网络安全体系，确保网络空间的安全和稳定。</span></p></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012775" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=d73c84fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvncKgsCs1ia12ZptcNuRztqGAdnVk9cgt5tybcEuLqtLicth6WNickwRBdoleITlMyfibfXI5gOAnZe8FA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496427">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=aa39014a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496427%26idx%3D1%26sn%3D5ef6d80e38d4722a3bf6293b5de1b2e9%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 21 Feb 2024 17:26:00 +0800</pubDate>
    </item>
    <item>
      <title>恒脑·体验中心小程序注册邀请开放啦！（文末领定制红包封面🧧）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496414&amp;idx=1&amp;sn=73ea42c233aee54378851f34c41f82da</link>
      <description>文末获取恒脑体验中心内测邀请信息及龙年定制红包封面福利</description>
      <content:encoded><![CDATA[<p>
<span>安恒信息研究院</span> <span>2024-02-05 16:26</span> <span style="display: inline-block;">浙江</span>
</p>

<p>文末获取恒脑体验中心内测邀请信息及龙年定制红包封面福利</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=dd66f7ce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvneuRnjEUODoqeWOibzyZeOOwAHtogydTiaiaS6p4ic16nx0sw5Wwoa2CRR5SYjFWVygO1wQKaIokek5dw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="box-sizing: border-box;font-style: normal;text-align: justify;font-size: 16px;"><section style="font-weight: 400;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012751" data-ratio="0.2777777777777778" data-s="300,640" width="100%" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=1f4b58f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvneuRnjEUODoqeWOibzyZeOOw6uZ8kBfqIBEVmwCiaZXAryyBHN97yJnLD9WI6mW820EgomjIISTibjEg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="font-weight: 400;font-size: 15px;line-height: 2;padding: 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">基于恒脑·安全垂域大模型，恒脑·体验中心面向用户提供7x24小时安全咨询体验服务，用户可用自然语言向智能助手小恒提出真实问题，即可获得答案，享受小恒全天候贴身守护。</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;">感谢各位领导、朋友一路关心与支持</span>，恒脑·体验中心现已上线<strong style="box-sizing: border-box;"><span style="color: rgb(69, 119, 218);box-sizing: border-box;">【小恒智聊】、【智能辅助】、【告警研判驾驶舱】</span></strong>三大模块，并支持<strong style="box-sizing: border-box;">网页端</strong>和<strong style="box-sizing: border-box;">移动端</strong>双模式<span style="letter-spacing: 0.034em;">。</span><span style="letter-spacing: 0.034em;">Ask、A</span><span style="letter-spacing: 0.034em;">nswer、Act，仅需三步就能体验未来网络安全！</span></p></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012762" data-ratio="0.46555555555555556" data-s="300,640" style="" data-type="jpeg" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=8de29276&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvneuRnjEUODoqeWOibzyZeOOw516Mfk0IwXy3SEO7UBPtQbWzUum7KmuHfCK8Iv9gCZ2Ql2eANRibiaSw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><section style="font-weight: 400;text-align: center;font-size: 12px;color: rgb(160, 160, 160);line-height: 2;padding: 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><p style="margin: 0px;padding: 0px;box-sizing: border-box;">文末获取恒脑体验中心注册邀请信息及微信红包封面福利</p></section><section style="font-weight: 400;text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 10px 15px;box-sizing: border-box;"><section style="justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top: 1px solid rgb(238, 70, 61);border-bottom: 1px solid rgb(238, 70, 61);min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><section style="font-size: 20px;color: rgb(238, 70, 61);letter-spacing: 2px;box-sizing: border-box;" powered-by="xiumi.us"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">恒脑·体验中心使用攻略</strong></p></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section style="font-weight: 400;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="vertical-align: middle;display: inline-block;line-height: 0;width: 93%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-backh="229" data-backw="538" data-imgfileid="100012750" data-ratio="0.4255555555555556" data-s="300,640" width="100%" data-type="jpeg" data-w="900" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto;" src="https://wechat2rss.xlab.app/img-proxy/?k=4015e751&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvneuRnjEUODoqeWOibzyZeOOwo31RHicicS7alm3uiaDZydEia37Cic2uqKQWxD3GGpXDgdKYxv1licUib2krQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section></section><section style="font-weight: 400;margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">早上8点，小恒化身</span><strong style="box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">安全运营专家</span></strong><span style="font-size: 15px;box-sizing: border-box;">，开启新一天的日常巡检。</span><span style="font-size: 15px;letter-spacing: 0.034em;">基于恒脑安全推理能力，体验安全智能诊疗、报文研判、恶意PowerShell分析等威胁要素确定，联动产品，总结安全事件。</span></p></section></section><p style="font-weight: 400;text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="1066" data-backw="518" data-imgfileid="100012755" data-ratio="2.0574324324324325" data-s="300,640" style="width: 100%;height: auto;" data-type="gif" data-w="592" src="https://wechat2rss.xlab.app/img-proxy/?k=b306cccc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneuRnjEUODoqeWOibzyZeOOw4zMsLQepOuu85yBl9TbmodiauC8AFL1lZtSdA1OODzdkQMrfILoibrEg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><section style="font-weight: 400;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">（所用素材均为小恒智聊小程序真实反馈内容）<br style="box-sizing: border-box;"/></p></section><section style="font-weight: 400;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 93%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-backh="229" data-backw="538" data-imgfileid="100012749" data-ratio="0.4255555555555556" data-s="300,640" width="100%" data-type="jpeg" data-w="900" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto;" src="https://wechat2rss.xlab.app/img-proxy/?k=a2fea354&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvneuRnjEUODoqeWOibzyZeOOwQ9xia7gJUJXEHKxgpteZCalDdZbwIvYI7JicpUqqUibraeqUj8hWicxT3Q%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section></section><section style="font-weight: 400;margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">下午3点，小恒马不停蹄赶去与</span><strong style="box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">解决方案专家</span></strong><span style="font-size: 15px;box-sizing: border-box;">一起开会，</span><strong style="box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"></span></strong><span style="font-size: 15px;box-sizing: border-box;">依据网络安全底座知识，根据安全行业逻辑，生产完备解决方案，辅助安全设计工作。</span></p></section></section><p style="font-weight: 400;text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="1189" data-backw="578" data-imgfileid="100012756" data-ratio="2.0574324324324325" data-s="300,640" style="width: 100%;height: auto;" data-type="gif" data-w="592" src="https://wechat2rss.xlab.app/img-proxy/?k=59f01298&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneuRnjEUODoqeWOibzyZeOOwX4zHRckUk3Rqat2jWeIWHEOjFIb78Vw0Rkh1w0xaTvlPc6t68Onkiaw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><section style="font-weight: 400;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">（所用素材均为小恒智聊小程序真实反馈内容）</p></section><section style="font-weight: 400;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 93%;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-backh="229" data-backw="538" data-imgfileid="100012753" data-ratio="0.4255555555555556" data-s="300,640" width="100%" data-type="jpeg" data-w="900" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto;" src="https://wechat2rss.xlab.app/img-proxy/?k=8081712a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvneuRnjEUODoqeWOibzyZeOOwnicuQJOk7EUt8XXAtyk8VR6gouDiaVunEohQSrbxTia0crqicvDic5Q20DA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 15px;line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">晚上10点，小恒启动<strong>渗透测试</strong>流程，赋能安全检测工作关键环节痛点，提升渗透测试人员素养，闭环检测报告。</p></section></section><p style="font-weight: 400;text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-backh="1189" data-backw="578" data-imgfileid="100012757" data-ratio="2.0574324324324325" data-s="300,640" style="width: 100%;height: auto;" data-type="gif" data-w="592" src="https://wechat2rss.xlab.app/img-proxy/?k=f91ea987&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneuRnjEUODoqeWOibzyZeOOwSUyOwzBe81bzW2KYCov5ULfIYbX91hCGMnpOxuQicz7yROGSXyY0hOQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><section style="font-weight: 400;font-size: 12px;color: rgb(160, 160, 160);box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">（所用素材均为小恒智聊小程序真实反馈内容）</p></section><section style="font-weight: 400;margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="line-height: 2;padding: 0px 15px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">除上述场景外，恒脑·体验中心还支持<strong style="box-sizing: border-box;">漏洞挖掘、安全培训、反诈科普、安全研究</strong>等业务需求，只要您需要，智能助手小恒就在您身边。发挥您的想象力，体验AI无限可能性，让我们共同探索下一代网络安全范式吧！</span><br style="box-sizing: border-box;"/></p></section></section><section style="font-weight: 400;text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 10px 15px;box-sizing: border-box;"><section style="justify-content: center;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-top: 1px solid rgb(238, 70, 61);border-bottom: 1px solid rgb(238, 70, 61);min-width: 5%;max-width: 100%;height: auto;padding: 5px 0px;box-sizing: border-box;"><section style="font-size: 20px;color: rgb(238, 70, 61);letter-spacing: 2px;box-sizing: border-box;" powered-by="xiumi.us"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">注册邀请现已开放</strong></p></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 5px;box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(238, 70, 61);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section style="font-weight: 400;line-height: 2;padding: 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">恒脑·体验中心注册邀请现已开放！您将有机会成为首批体验我们全新智能助手小恒的幸运用户！作为特邀用户，您将享受到以下特权：</span></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">1. 免费体验最新功能；</span></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">2. 参与产品改进和反馈意见；</span></p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">3. 获得专属技术支持和个性化服务。</span></p><p style="text-align: center;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">此次注册邀请，</span></p><p style="text-align: center;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">我们特别提供了<span style="color: rgb(69, 119, 218);box-sizing: border-box;"><strong style="box-sizing: border-box;">66个免费试用名额</strong></span>，</span></p><p style="text-align: center;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">让您尽情体验AI带来的便利和高效。</span></p><p style="text-align: center;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">联系安恒信息当地行销即可申请免费试用名额哦～</span><br style="box-sizing: border-box;"/></p><p style="text-align: center;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">另外，安恒研究院给各位准备了，</span></p><p style="text-align: center;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">龙年限量红包封面~</span></p><section class="mp_redpacket_iframe_wrp"><mp-common-redpacket class="js_redpacketcover redpackage_iframe js_uneditable custom_select_card" data-pluginname="redpacketcover" data-w="286" data-ratio="1.5664335664335665" data-name="%E5%AE%89%E6%81%92%E4%BF%A1%E6%81%AF" data-receiveimg="https%3A%2F%2Fmmcomm.qpic.cn%2Fwx_redskin%2F8u7e7nUNWI7B4k5OHV2JkylepO4YyicVN1dW9FVdjbZtNmK2uQy9Twv9kOhibzrHA9%2F" data-synthetic="0" data-coveruri="-hSVdOalx5b2WlFB" data-bizuin="3520125904" data-orderid="14319576116355137653" data-openimg="https%3A%2F%2Fmmcomm.qpic.cn%2Fwx_redskin%2F8u7e7nUNWI7B4k5OHV2JkylepO4YyicVN1dW9FVdjbZseShIC6gZ7qBvjHTvFVM42%2F" data-errortype=""></mp-common-redpacket></section><p style="text-align: center;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"></span></p><p style="text-align: center;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">颠覆性技术孕育新质生产力，</span></p><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;">AI让世界更美好！</span></p><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;box-sizing: border-box;"><br/></span></p></section><section style="font-weight: 400;text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012754" data-ratio="0.278125" data-s="300,640" width="100%" data-type="gif" data-w="640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=834e54e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvneuRnjEUODoqeWOibzyZeOOw5Au1icoX4ibMfImibsZGDeoPysMsaToubRLhXl5Ez0j50W83vSg1kDJQg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496414">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fd13cad7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496414%26idx%3D1%26sn%3D73ea42c233aee54378851f34c41f82da%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 05 Feb 2024 16:26:00 +0800</pubDate>
    </item>
    <item>
      <title>猎影追踪：APT-LY-1009使用VenomRAT以及Telegram Bot针对亚美尼亚政府的攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyMDEyNTkwNA==&amp;mid=2247496393&amp;idx=1&amp;sn=a3cf9475e36ccd17ea339bb8156c3587</link>
      <description>近日，安恒信息猎影实验室在日常威胁狩猎过程中发现一例上传自亚美尼亚的恶意LNK文件</description>
      <content:encoded><![CDATA[<p>
原创 <span>猎影实验室</span> <span>2024-02-02 11:20</span> <span style="display: inline-block;">浙江</span>
</p>

<p>近日，安恒信息猎影实验室在日常威胁狩猎过程中发现一例上传自亚美尼亚的恶意LNK文件</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=ed79ca1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAvAjnOiazvndEsK6WPejDZH7wws1YpUq1nyS40o2q7IzWw6jTUI1nsj2rh6XCsm2YibPGV4mnhyAy08yGuDsDsbw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-size: 15px;line-height: 2;padding-left: 15px;padding-right: 15px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;"><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012736" data-ratio="0.2777777777777778" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=394a83a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnefHkkjl1Gxic4maiawljK3p0KLs04OcfPK9iauialCqJHj1icCgu8uVtSpC1WGBicDz2ogAEPAB2S4nHSg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="margin: 15px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;border-width: 1px;border-style: solid;border-color: rgb(192, 200, 209);padding: 10px;background-color: rgb(239, 239, 239);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;" powered-by="xiumi.us">近日，安恒信息猎影实验室在在日常威胁狩猎过程中发现一例上传自亚美尼亚的恶意LNK文件，文件运行后将加载远程HTA文件，执行多段脚本指令，下载恶意文件加载器，并释放诱饵文件，最终在内存中加载开源远控木马Venom RAT。</p></section></section><section style="line-height: 0;text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012733" data-ratio="0.42803030303030304" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="264" src="https://wechat2rss.xlab.app/img-proxy/?k=35d388e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnefHkkjl1Gxic4maiawljK3p0RbicibImDhZUh8fejuroIVRiaiaRRIDKNrhFolByiaYYib56QSN9g6wOTlhA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 20px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px 0%;box-sizing: border-box;"><section style="display: inline-block;width: 15px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(69, 119, 218);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: rotateZ(315deg);-webkit-transform: rotateZ(315deg);-moz-transform: rotateZ(315deg);-o-transform: rotateZ(315deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 4px 0% 5px;box-sizing: border-box;"><section style="display: inline-block;width: 14px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(74, 187, 168);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px;font-size: 17px;text-align: center;color: rgb(102, 102, 102);line-height: 2;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">针对亚美尼亚共和国政府的APT组织</strong></p></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">在2023年9月，猎影实验室首次捕获亚美尼亚首都耶烈万上传的包含有恶意宏代码的文档，宏代码运行后将下载用于执行脚本指令的恶意文件，最后在内存中加载Venom RAT。</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">鉴于23年9月与今年1月捕获的两条攻击链的目标相似性、攻击武器一致性，以及网络基础设施存在的关联性，我们认为该组织可以作为未知威胁组织进行跟踪及披露，并将此事件背后的威胁组织标记为<strong style="box-sizing: border-box;">APT-LY-1009（暗爪鹰、Darkclaw Eagle）</strong>并进行跟踪。</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">除开源恶意软件Venom RAT的使用外，我们还在APT-LY-1009的网络资产上发现了其用于窃取目标主机信息，进行上传下载的Telegram Bot。</p><p style="margin: 0px 0px 15px;word-break: break-all;white-space: normal;padding: 0px;box-sizing: border-box;">根据样本中包含的PDB路径，我们将该信息窃取器命名为<strong style="box-sizing: border-box;">Mohlat Stealer</strong>。该组织开发并使用了C#、Rust两个版本的Mohlat，部分还使用UPX进行了加壳。</p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">跟踪发现，APT-LY-1009（暗爪鹰、Darkclaw Eagle）的几次攻击活动均针对亚美尼亚共和国政府工作人员。</p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012734" data-ratio="0.6184971098265896" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=533b9f48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnefHkkjl1Gxic4maiawljK3p0DQ8MJTNUMR6CPh1BXiasYsIdB47ebvXboCY9HH5EiaicmibWpcKUEaUJmw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 20px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="transform: rotateZ(45deg);-webkit-transform: rotateZ(45deg);-moz-transform: rotateZ(45deg);-o-transform: rotateZ(45deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px 0%;box-sizing: border-box;"><section style="display: inline-block;width: 15px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(69, 119, 218);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="transform: rotateZ(315deg);-webkit-transform: rotateZ(315deg);-moz-transform: rotateZ(315deg);-o-transform: rotateZ(315deg);box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 4px 0% 5px;box-sizing: border-box;"><section style="display: inline-block;width: 14px;height: 4px;vertical-align: top;overflow: hidden;background-color: rgb(74, 187, 168);border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px 0%;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px;font-size: 17px;text-align: center;color: rgb(102, 102, 102);line-height: 2;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">攻击链复盘</strong></p></section></section></section></section><section style="margin: 10px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="padding: 0px 15px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">我们捕获的两条较为完整攻击链如下：<br style="box-sizing: border-box;"/></p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="color: rgb(69, 119, 218);box-sizing: border-box;"><strong style="box-sizing: border-box;">2023年9月攻击活动：</strong></span></p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">钓鱼邮件附件DOC文件，带有恶意宏代码，运行后请求远程服务器，下载用于执行Powershell的EXE文件，Powershell指令执行后，进一步下载Loader，最终在内存解密加载Venom RAT。</p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;"><span style="color: rgb(69, 119, 218);box-sizing: border-box;"><strong style="box-sizing: border-box;">2024年1月攻击活动：</strong></span></p><p style="word-break: break-all;margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">LNK文件运行后执行远程VBScript代码，其中包含一段Base64编码后的Powershell指令，执行加载下一阶段Powershell指令，随后下载Loader，最终在内存中解密运行Venom RAT。</p><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">除上述攻击链外，我们还通过其网络基础设施关联到其他由亚美尼亚提交的钓鱼URL链接。其中有文件与上述攻击链中的诱饵文件同名，有文件运行后以亚美尼亚政府职位空缺公告为诱饵，最后下发的恶意组件包括C#与Rust两个版本，均链接至Telegram Bot，目标为窃取用户主机文件。</p></section></section><section style="line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012735" data-ratio="0.5919075144508671" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=1fa0c2c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnefHkkjl1Gxic4maiawljK3p0hXtwx0ibg8I8rCJmreVh8tBKTDiax23VzOytrT8lv5PiaiahNgflZhRA8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-image: linear-gradient(-90deg, rgb(9, 55, 147) 0%, rgb(69, 119, 218) 100%);padding: 9px 21px;box-sizing: border-box;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: justify;font-size: 18px;color: rgb(255, 255, 255);box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">下载方式</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;flex: 100 100 0%;height: auto;align-self: center;padding: 0px 9px 0px 12px;margin: 0px;box-sizing: border-box;"><section style="margin: 0.5em 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="background-color: rgb(245, 245, 245);height: 1px;box-sizing: border-box;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: center;box-sizing: border-box;"><section style="margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="font-size: 11px;color: rgb(255, 255, 255);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(255, 255, 255);font-size: 11px;letter-spacing: 0.578px;text-decoration: none;">扫码or复制网址</span></p></section></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 15px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;border-style: solid;border-width: 0px 1px 1px;border-color: rgb(69, 119, 218);padding: 7px;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;transform: rotateX(180deg) rotateY(180deg);-webkit-transform: rotateX(180deg) rotateY(180deg);-moz-transform: rotateX(180deg) rotateY(180deg);-o-transform: rotateX(180deg) rotateY(180deg);margin: 0px;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 3px 3px 8px;border-style: solid;border-width: 0px 2px 2px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 28px;height: 8px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 0px 1px 1px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: justify;color: rgb(62, 62, 62);box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section><section style="justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;padding: 6px 21px;box-sizing: border-box;"><section style="margin: 0px;text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: justify;box-sizing: border-box;"><p style="margin: 0px 0px 15px;white-space: normal;padding: 0px;box-sizing: border-box;">《APT-LY-1009使用VenomRAT以及Telegram Bot针对亚美尼亚政府的攻击活动分析》报告为安恒研究院猎影实验室独家发布，<span style="color: rgb(69, 119, 218);box-sizing: border-box;"><strong style="box-sizing: border-box;">如对此研究感兴趣或欲了解报告更多详细，请前往下载。</strong></span></p></section></section><section style="margin-top: 10px;margin-bottom: 10px;line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;box-sizing: border-box;"><span style="width: 0px;display: inline-block;opacity: 0.6;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span><span style="width: 0px;display: inline-block;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span> </section><section style="display: inline-block;vertical-align: top;line-height: 1.2;padding-left: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">方式一：扫描下方二维码即可下载</strong></p></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012731" data-ratio="1" data-s="300,640" style="width: 195px;height: auto;" data-type="png" data-w="195" src="https://wechat2rss.xlab.app/img-proxy/?k=f3ed2bd9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAvAjnOiazvnefHkkjl1Gxic4maiawljK3p0wDfsZSgps1eiaM3EExWicfluEpolicnics5jfib5VFwuxbJicRMLNiaqW1ukg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></section><section style="margin-top: 10px;margin-bottom: 10px;line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;box-sizing: border-box;"><span style="width: 0px;display: inline-block;opacity: 0.6;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span><span style="width: 0px;display: inline-block;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span> </section><section style="display: inline-block;vertical-align: top;line-height: 1.2;padding-left: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">方式二：点击文末“阅读原文”或<strong><span style="font-size: 15px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">复制下方网址链接至浏览器打开</span></strong></strong></p></section></section><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 15px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://app-martech.dbappsecurity.com.cn/resources/ResourcePc/ResourcePcInfo?pf_uid=17709_1776&amp;id=317&amp;source=1&amp;pf_type=3&amp;channel_id=8987&amp;channel_name=%E5%AE%89%E6%81%92%E7%A0%94%E7%A9%B6%E9%99%A2&amp;tag_id=2824468d92446b27" target="_blank">https://app-martech.dbappsecurity.com.cn/resources/ResourcePc/ResourcePcInfo?pf_uid=17709_1776&amp;id=317&amp;source=1&amp;pf_type=3&amp;channel_id=8987&amp;channel_name=%E5%AE%89%E6%81%92%E7%A0%94%E7%A9%B6%E9%99%A2&amp;tag_id=2824468d92446b27</a></span></p></section><section style="margin-top: 10px;margin-bottom: 10px;line-height: 1;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;box-sizing: border-box;"><span style="width: 0px;display: inline-block;opacity: 0.6;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span><span style="width: 0px;display: inline-block;border-left: 0.6em solid rgb(69, 119, 218);border-top: 0.5em solid transparent !important;border-bottom: 0.5em solid transparent !important;box-sizing: border-box;"> </span> </section><section style="display: inline-block;vertical-align: top;line-height: 1.2;padding-left: 3px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;">方式三：联系安恒信息当地商务人员获取</strong></p></section></section></section></section><section style="text-align: right;justify-content: flex-end;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;line-height: 0;padding: 0px 3px 3px 8px;border-style: solid;border-width: 0px 2px 2px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: center;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 28px;height: 8px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 0px 1px 1px 0px;border-color: rgb(95, 151, 250) rgb(69, 119, 218) rgb(69, 119, 218) rgb(95, 151, 250);box-sizing: border-box;"><section style="text-align: justify;color: rgb(62, 62, 62);box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><br style="box-sizing: border-box;"/></p></section></section></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: stretch;margin: 0px;z-index: 1;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px;line-height: 0;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 20px;height: auto;box-sizing: border-box;"><img data-imgfileid="100012732" data-ratio="1" data-s="300,640" width="100%" data-type="svg" data-w="150" style="vertical-align: middle;max-width: 100%;width: 100%;height: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=1bd1b676&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F0T8yO33zeegIYLSdibPPqZicVfWmSSSrQXc8E8gjVsZmFsDcKc1GY53N7aCeP1fYdsvgYg8KmJdZsy3MzkLLJxNiczONWuibkg9G%2F640%3Fwx_fmt%3Dsvg%26from%3Dappmsg"/></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: stretch;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 10px 55px 0px 20px;margin: 0px -45px 0px -20px;background-color: rgb(223, 229, 235);box-sizing: border-box;"><section style="justify-content: flex-start;display: flex;flex-flow: row;margin: 2px 0px 0px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-image: linear-gradient(90deg, rgb(107, 186, 216) 0%, rgb(69, 119, 218) 100%);padding: 2px 20px;border-radius: 50px;overflow: hidden;box-sizing: border-box;"><section style="text-align: center;color: rgb(255, 255, 255);letter-spacing: 2px;box-sizing: border-box;" powered-by="xiumi.us"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;">关于《猎影追踪》系列报告</span></strong></p></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;min-width: 5%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;margin: 0px;overflow: hidden;box-sizing: border-box;"><section style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;" powered-by="xiumi.us"><section style="text-align: center;margin: 0px;line-height: 0;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);box-sizing: border-box;"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012737" data-ratio="1" data-s="300,640" width="100%" data-type="svg" data-w="150" style="vertical-align: middle;max-width: 100%;width: 100%;height: 100%;box-sizing: border-box;" src="https://wechat2rss.xlab.app/img-proxy/?k=cc4d9109&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F0T8yO33zeegIYLSdibPPqZicVfWmSSSrQX4fHicvhfFubhtic5uT9f9jCiblbmTOUuicEArnHVt7dv5DicrYZePNiaZ6PWibyTR5KWVF8%2F640%3Fwx_fmt%3Dsvg%26from%3Dappmsg"/></section></section></section></section></section><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;" powered-by="xiumi.us"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(223, 229, 235);padding: 20px;border-top-right-radius: 10px;border-bottom-left-radius: 10px;border-bottom-right-radius: 10px;overflow: hidden;box-sizing: border-box;"><section style="text-align: justify;box-sizing: border-box;" powered-by="xiumi.us"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;">《猎影追踪》系列报告旨在提供有价值的网络安全信息和洞察，包含对网络安全领域最新的威胁趋势、漏洞发现、攻击手法以及防御策略等内容。该报告还基于猎影实验室的研究成果和实战经验，针对不同的安全问题提出可依循、可执行的建议，帮助企业提升自身的安全防护能力，更好地应对不断变化的网络安全挑战。</p></section></section></section><section style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;" powered-by="xiumi.us"><section style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;"><img class="rich_pages wxw-img" data-imgfileid="100012738" data-ratio="0.278125" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=4f285479&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAvAjnOiazvnefHkkjl1Gxic4maiawljK3p0UeNWhNudiaYCZo834JLAJNrJS7bNp1T3bab6Z0BF5JibUXOAWTgPQKSw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://app-martech.dbappsecurity.com.cn/resources/ResourcePc/ResourcePcInfo?pf_uid=17709_1776%5cx26amp;id=317%5cx26amp;source=1%5cx26amp;pf_type=3%5cx26amp;channel_id=8987%5cx26amp;channel_name=%E5%AE%89%E6%81%92%E7%A0%94%E7%A9%B6%E9%99%A2%5cx26amp;tag_id=2824468d92446b27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=263e60d2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyMDEyNTkwNA%3D%3D%26mid%3D2247496393%26idx%3D1%26sn%3Da3cf9475e36ccd17ea339bb8156c3587%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 02 Feb 2024 11:20:00 +0800</pubDate>
    </item>
  </channel>
</rss>