×ðÁú¿­Ê±ADLab£º¶Ô½üÆÚijδ֪ºÚ¿Í×éÖ¯¹¥»÷Ô˶¯×·×ÙÓëÆÊÎö±¨¸æ

Ðû²¼Ê±¼ä 2024-08-30

1.ÆÊÎö¼òÊö


ÔÚÒÑÍù¼¸¸öÔÂÀï £¬×ðÁú¿­Ê±ADLabÂ½Ðø·¢Ã÷Ò»ÅúʹÓÃÉÌҵľÂíremcosRAT¹¥»÷È«Çò¶à¸ö´óÐÍÆóÒµµÄÍøÂç¹¥»÷Ô˶¯ £¬ÕâЩ¹¥»÷Ô˶¯ÊÔͼ½«ÇÔÈ¡µÄÃô¸ÐÊý¾Ý»Ø´«ÖÁÃÀ¹úµÄ¶ą̀C2·þÎñÆ÷ÉÏ £¬ÕâÆäÖб»¹¥»÷µÄÆóÒµ»¹°üÀ¨Ò»¼ÒÖйúÑëÆó¿Ø¹ÉµÄÍâÔËÆóÒµ £¬Í¨¹ý×éÖ¯ËÝÔ´·¢Ã÷ÕâÅú¹¥»÷Ô˶¯²¢²»ÊôÓÚÒÑÖªµÄÈκκڿÍ×éÖ¯(°üÀ¨APT×éÖ¯) £¬Òò´Ë £¬ÎªÁ˽øÒ»²½ÕÆÎոúڿÍ×éÖ¯µÄÔ˶¯ÇéÐÎ £¬ÎÒÃÇ´Ó4Ô·Ý×îÏȶԸúڿÍÏà¹ØµÄÔ˶¯¾ÙÐÐÌØÊâ¹Ø×¢ºÍ×·×Ù £¬Ö±µ½±¾ÎÄÍê³ÉʱÈÔδÓиù¥»÷Ô˶¯µÄÅû¶±¨¸æ¡£


ͨ¹ý³¤Ê±¼äµÄ¹¥»÷Ñù±¾ÍøÂç £¬×îºóÎÒÃÇ»ñµÃÁË¿ç¶È5¸öÔÂʱ¼äµÄ190¶à¸ö¹¥»÷Ñù±¾ £¬ÕâЩ¹¥»÷Ñù±¾ÖÐÓÐ140¶à¸ö¶¼ÊÔͼ»ØÁ¬µ½Î»ÓÚÃÀ¹úµØÇøµÄ¿ØÖÆÏÂÁî·þÎñÆ÷ÉÏ¡£ÆäÖзþÎñÆ÷Ö÷Òª¼¯ÖÐÔÚ173.255.204.62¡¢107.173.4.18ºÍ107.175.229.143¡£Í¨¹ýËÝÔ´ÆÊÎöÈ·¶¨ÕâÅú¹¥»÷Ô˶¯´Ó2024Äê3Ô·ݾÍÒѾ­×îÏÈÁ˶ÔÄ¿µÄÆóÒµ¾ÙÐй¥»÷ £¬ÔÚ½ÓÏÂÀ´µÄ¼¸¸öÔÂÀï¹¥»÷Ô˶¯±äµÃÔ½À´Ô½»îÔ¾ £¬Ö±µ½7Ô·ݵִï»îÔ¾á¯Áëºó £¬8Ô·ݹ¥»÷Ô˶¯ÐìÐì±äÉÙ¡£


ͨ¹ý»ù´¡ÉèÊ©ºÍÑùÌìÖ°Îö·¢Ã÷ £¬ÕâÊÇÒ»¸ö×Ô¶¯»¯Ë®Æ½ºÜÊǸߵĺڿÍ×éÖ¯ £¬ÆäÉõÖÁ¿ÉÄܽ«Õû¸ö¹¥»÷ÖÜÆÚ¶¼¾ÙÐÐÁË×Ô¶¯»¯ £¬ÎÒÃÇ·¢Ã÷¹¥»÷×éÖ¯½«ºÚ¿ÍÓÊÏä×¢²á¡¢ÓòÃû×¢²á¡¢Îó²îʹÓôúÂë¡¢loader¼´Ê±±àÒ롢ľÂíÌìÉú¡¢¹¥»÷Ͷ·ÅµÈÀú³Ì¶¼¾ÙÐÐÁË×Ô¶¯»¯¡£ËäÈ»³ýÁË×Ô¶¯»¯Íâ £¬ºÚ¿Í×éÖ¯Ò²»áƾ֤×ÔÉíÕÆÎÕÄ¿µÄµÄˮƽ¶øÑ¡Ôñ¾ÙÐж¨ÖÆ»¯µÄ¹¥»÷¡£


´Ó¹¥»÷Ä¿µÄÀ´¿´ £¬ÕâÅú¹¥»÷Ô˶¯³ýÁ˹¥»÷ÎÒ¹úijÍâÔËÆóÒµÍâ £¬»¹°üÀ¨Ò»Ð©È«ÇòÐԵĹú¼ÊÉÌÒµÆóÒµÒÔ¼°»¯Ñ§ÖÆÆ·¡¢»úÐµÖÆÔì¡¢½ðÈÚ°ü¹ÜµÈÁìÓòÏà¹ØÆóÒµ¡£ÎÒÃÇ×·×Ùµ½µÄ¹¥»÷Ô˶¯Ö÷ÒªÒÔÓã²æÓʼþºÍÔçÆÚofficeÎó²îΪÖ÷ £¬´ó×ÚÑù±¾µÄÎļþÌØÕ÷ÌåÏÖΪ¸ß¶È×Ô¶¯»¯Éú²úÓë×Ô¶¯»¯Í¶·ÅµÄÌØµã £¬Í¬Ê±Ò»Ð©¹¥»÷ÓʼþÒ²ÌåÏÖ³öÓëÄ¿µÄ²úÆ·ºÍ¿Í»§¹ØÏµÏ¸½ÚÏà¹ØµÄ¸ß¶È¶¨ÖÆ»¯µÄÌØÕ÷¡£Í¶·ÅµÄÇÔÃÜľÂíÖ÷ҪΪ5.1.0 Pro°æ±¾µÄremcosRAT £¬Ïà½ÏÓÚÎÒÃÇ֮ǰÆÊÎöµÄremcosRAT°æ±¾ £¬Ð°汾ÔÊÐíºÚ¿Íͨ¹ýTelegram»úеÈËÓëľÂí¶Ë½»»¥ £¬ÔÆÔÆÒ»À´ £¬ºÚ¿Í¿ÉÒÔʹÓÃÊÖ»ú¡¢Æ½°åµçÄÔµÈÒÆ¶¯×°±¸ËæÊ±ËæµØ¾ÙÐÐľÂí¿ØÖÆ £¬¹¥»÷³¡¾°Ô½·¢ÎÞа¡£


´Ó¶Ô¿¹ÊÖ·¨ÉÏÀ´¿´ £¬¸Ãδ֪ºÚ¿Í×é֯ʹÓÃÁ˶à½×¶ÎÔ¶³Ì¼ÓÔØÊÖÒÕ¡¢»ìÏýÊÖÒÕ¡¢ADÊÖÒÕºÍÀú³ÌïοÕÊÖÒÕÀ´ÌÓ±ÜÁ÷Á¿¼à²âºÍɱ¶¾Èí¼þµÄ²éɱ £¬ÆäÖÐAD£¨ADD-TYPE£©ÊÖÒÕÊÇÒ»ÖÖ½ÏΪÉÙ¼ûµÄÊÖÒÕ £¬ÔÚ»ìÏýµÄpowershell´úÂëÖÐ £¬Æä¾­³£±»ÓÃÀ´ÊµÏÖÒþ²ØµÄ.net³ÌÐò¼¯µÄŲÓà £¬ºÚ¿ÍÔÚ±¾¹¥»÷Ô˶¯ÖÐÓÃÀ´ÊµÏÖÔ¶³Ì¶ñÒâ´úÂëµÄÒþ²ØÏÂÔØ¡£


2.¹¥»÷Ô˶¯ÆÊÎö


ÎÒÃÇÔÚ×·×ÙÕâÅú¹¥»÷Ô˶¯µÄÀú³ÌÖÐ £¬×ܹ²ÍøÂçÁË190¶à·Ý¹¥»÷Ñù±¾ £¬´Óÿ¸ö¹¥»÷Ñù±¾µÄÈëÇÖ·¾¶ÉÏÆÊÎö £¬·¢Ã÷ºÚ¿ÍÖ÷ÒªÓÐÁ½ÖÖ¹¥»÷ÊֶΡ£


µÚÒ»ÖÖÊÇͨ¹ýͶµÝ¶ñÒâµÄ´øÓÐÎó²îʹÓôúÂëµÄofficeÎĵµ£¨xlsºÍdocÎĵµ£©À´¾ÙÐÐ £¬ÆäÖеÄÎó²îʹÓóÌÐò»á´ÓºÚ¿Í·þÎñÆ÷ÉÏÏÂÔØÒ»¸ö´øÓÐJS¾ç±¾µÄhtaÎļþ²¢¼ÓÔØÖ´ÐÐ £¬´ËʱJS¾ç±¾ÄÚÒ»¶Î±»»ìÏýµÄVBS¾ç±¾±ã»á±»ÆôÓà £¬¶øÕâ¶ÎVBSÖ´Ðкó×îÖÕ»áŲÓÃÒ»¶Î±»»ìÏýµÄpowershell´úÂë¡£Õâ¶Îpowershell¾ç±¾½ÓÄÉÁËADÊÖÒÕ £¬ÆäΪĿ½ñ³ÌÐòÌí¼ÓÁËÒ»¸öÐ嵀 .NET ÀàÐÍ £¬¸ÃÀàÐͰüÀ¨Ò»¸ö´Ó urlmon.dll ¶¯Ì¬Á´½Ó¿âÖе¼ÈëµÄ URLDownloadToFile º¯Êý £¬powershellʹÓøú¯Êý´ÓºÚ¿Í·þÎñÆ÷ÉÏÏÂÔØÒ»¸ö±»¶þ½øÖÆ»ìÏý¹ýµÄloader³ÌÐò²¢Ö´ÐÐ £¬¸Ãloader×îÖÕ»á½âÃܲ¢Ö´ÐÐÇÔÃÜľÂíremcosRAT¡£


µÚ¶þÖÖ¹¥»÷ÊÖ·¨¾ÍÊÇÖ±½Ó½«»ìÏý¹ýµÄhtaÎļþ£¨»òÆäÁ´½Ó£©ºÍloader³ÌÐòαװ³ÉΪÕý³£Îļþ/Á´½Ó¸½ÔÚ´¹ÂÚÓʼþÖÐ £¬ÓÕʹĿµÄÖ´ÐÐÓÕ¶üÎĵµ¡£


ÎÒÃÇÏÈÒÔ7ÔÂ25ÈÕµÄÒ»ÆðÓã²æ´¹ÂÚÓʼþ¹¥»÷×îÏÈÀ´¼òÆÓÆÊÎöºÚ¿ÍµÄ¹¥»÷Àú³Ì £¬ÔÚÕû¸ö¹¥»÷ÖÜÆÚÖÐ £¬Óдó×ÚÀàËÆµÄ¹¥»÷Óʼþ £¬Èçͼ1ÕâÑù¡£Õâ¸ö°¸ÀýÀïºÚ¿Í½«·¢¼þÈËαװ³ÉÁËÓ¡¶È¸ßµÈÃæÁÏÖÆÔìÉÌ¡°Raymond¡±Ïà¹ØÊÂÇéÖ°Ô± £¬½«Ò»¸ö¶ñÒâÎļþͶµÝµ½ÎÒ¹úijÍâÔ˹«Ë¾µÄÊÂÇéÖ°Ô±¡£ÓʼþÖ÷ÌâΪ ¡°RFQ¡±£¨±¨¼ÛÇëÇó£© £¬Óʼþ¸½¼þΪ¡°Quotation.xls¡±£¨±¨¼Û.xls£© £¬ÕýÎÄ·­Òë³ÉÖÐÎÄÊÇ¡°Çë²éÊÕ¸½¼þËùÐèÏîÄ¿µÄ±¨¼Ûµ¥ £¬²¢ÒÔ±¨¼Ûµ¥È·ÈÏ £¬ÇëÈ·ÈÏÊÕÌõ¡±¡£


ͼƬ1.png

ͼ1 Õë¶ÔÎÒ¹úijÍâÔ˹«Ë¾µÄ¹¥»÷Óʼþ


ÕâÖÖÒÔ±¨¼ÛΪÓÕ¶üµÄ¹¥»÷ÓʼþÖ÷Ҫͨ¹ýijЩģ°å×Ô¶¯»¯ÌìÉú £¬ÆäÊÊÓùæÄ£½Ï¹ã £¬ÀÖ³ÉÂÊÒ²½Ï¸ß¡£ÕâÖÖÀàËÆµÄ¹¥»÷»òÐíÁ÷³ÌÈçͼ2Ëùʾ£º


ͼƬ2.png

ͼ2 ºÚ¿Í¹¥»÷Á÷³Ìͼ


ºÚ¿ÍÊ×ÏȽ«Ä¾Âí´æ·ÅÓÚ×Ô¼º½¨ÉèµÄÎļþ·þÎñÆ÷ÉÏ £¬ÔÚÉèÖúÃÓʼþpayloadºó £¬Í¨¹ý×Ô¶¯»¯³ÌÐò£¨ÒÔÓʼþÄ£°å¿âÓëÇ鱨¿âÖÐÄ¿µÄÐÅϢΪÒÀ¾Ý£©ÌìÉú¹¥»÷Óʼþ £¬²¢ÏòÄ¿µÄÆóҵͶ·ÅľÂí¡£µ±Êܺ¦ÕßʧÉ÷·­¿ªÓʼþµÄ¸½¼þÎĵµ £¬ÆäÖб»È«ÐĹ¹½¨µÄÎó²îʹÓóÌÐò±ã»á±»´¥·¢ £¬»ñµÃÖ´ÐÐȨÏÞµÄshellcode½ÓÏÂÀ´»áͨ¹ý¶à¼¶¼¶ÁªÏÂÔØ£¨ÎªÁ˱ãÓÚÌӱܲéɱ£© £¬×îºóÀÖ³ÉͶ·ÅľÂíremcosRAT¡£ºÚ¿ÍʹÓøÃľÂí¿ÉÍêÈ«½ÓÊܺͿØÖÆÄ¿µÄÖ÷»ú £¬ÇÒ¿ÉÒÔ¶ÔÄ¿µÄËùÔÚµÄÍøÂç¾ÙÐÐÏÂÒ»²½µÄÈëÇÖ £¬ÒÔ×·Çó¸ü¾ß¼ÛÖµµÄÊý¾Ý¡£ÆäËûÀàËÆ¹¥»÷Èçͼ3Ëùʾ¡£


ͼƬ3.png

ͼ3 ¹ØÁªµ½µÄ²¿·ÖÍøÂç¹¥»÷Óʼþ½ØÍ¼


ÕâһϵÁй¥»÷Ô˶¯ÖÐ £¬ºÚ¿ÍµÄαװ¹¤¾ß»¹°üÀ¨ÎÒ¹úijº£ÔË·þÎñ¼¯ÍÅ¡¢ÎÒ¹úij¹ú¼ÊÎïÁ÷¹«Ë¾¡¢ÃÀ¹úÎïÁ÷¹«Ë¾¡°Expeditors¡±¡¢ÐÂ¼ÓÆÂÎïÁ÷º½Ô˹«Ë¾¡°Interion Pte Ltd¡± µÈʵÌå¡£


±í1.png

±í1 ²¿·Ö¶¨Ïò¹¥»÷ÓʼþÏà¹ØÐÅÏ¢


¹¥»÷Ä¿µÄ»¹°üÀ¨º«¹ú¡°´¬²°È¼ÓÍϵͳ¡¢ÍƽøÏµÍ³ºÍʹÓÃϵͳµÈϵͳ¡±ÊðÀíÉÌ¡°Boema Hi-Tec Ltd¡±¡¢ÖÇÀûÍøÂçÐÅÏ¢ÖÐÐÄ¡°Network Information Center Chile£¨NIC Chile)¡±¡¢ ½Ý¿ËÆø¶¯Ôª¼þ¡¢»ú´²¡¢Ê³Îï¼Ó¹¤×°±¸¹«Ë¾¡°Stransky a Petrzik¡±ÒÔ¼°Ä«Î÷¸ç¡°³ÆÖØ¡¢Ê¶±ðºÍ¼ì²âϵͳ¡±ÖÆÔìÉÌ¡°Grupo IPC¡±µÈÆóÒµ £¬²¿·ÖÊܺ¦ÆóÒµÏà¹ØÐÅÏ¢Èçͼ4¡£


ͼƬ4.png
ͼ4 ²¿·ÖÊܺ¦ÆóÒµÏà¹ØÐÅÏ¢


¶ø¹ØÓÚÒ»Ð©ÌØ¶¨µÄÄ¿µÄ £¬ºÚ¿Í»áƾ֤ÕâЩĿµÄµÄ²î±ðÓªÒµÄÚÈÝºÍÆóÒµÇéÐξÙÐÐÓʼþ¶¨ÖÆ¡£Èçͼ5Ëùʾ£ººÚ¿ÍÉù³Æ×Ô¼ºÀ´×ÔÒ»¸ö±Ã¹¤ÒµÆóÒµ £¬Ïòº«¹ú´¬²°¼Ó¹¤¡¢Æû´¬ÍƽøÏà¹ØÊðÀíÉÌ¡°Boema Hi-Tec Ltd¡±·¢ËÍÁËÖ÷ÌâΪ¡°Inquiry - Pumps & Accessories - (Oasis Pump Indusry LLC)£¨ÅÌÎÊ-±ÃºÍÅä¼þ-ÂÌÖÞ±ÃÒµÓÐÏÞÔðÈι«Ë¾£©¡±µÄÓʼþ £¬ÕýÎÄÖÐÉù³ÆÊÇÒª´Ó¸ÃÆóÒµ¹ºÖÃË®±ÃºÍÅä¼þ²úÆ· £¬¸½¼þΪ¡°Pumps Product List & Drawing Dimensions.xls£¨±Ã²úÆ·Çåµ¥¼°Í¼Ö½³ß´ç£©¡±ÊÇÆäÐèÒªµÄ²úÆ·¹æ¸ñºÍͼֽ³ß´ç¡£ÀàËÆµÄÖ÷ÌâºÍÄÚÈÝÉÐÓС°New Enquiry¡±£¨ÐÂѯÅÌ£©¡¢¡°New Items order¡±£¨ÐÂÏîÄ¿¶©µ¥£©ºÍ¡°PAYMENT¡±£¨¸¶¿î£©µÈ¡£


ͼƬ5.png

ͼ5 ¶¨ÖÆ»¯¹¥»÷ÓʼþʾÀý


3.»ù´¡ÉèÊ©ÆÊÎö


ÔÚÎÒÃÇÒ»Á¬µÄ×·×ÙºÍÆÊÎöºó £¬×ܹ²»ñµÃÁË194¸ö¹¥»÷Ñù±¾ £¬ÕâЩÑùÌìÖ°±ð·ºÆðÔںڿ͹¥»÷µÄ²î±ð½×¶Î £¬ÎÒÃǰÑÕâЩÑù±¾´óÖ·ÖΪËÄ´óÀà £¬ÆäÖеÚÒ»ÀàÊÇʹÓÃofficeÎó²îµÄxlsºÍword¶ñÒâÎĵµ £»µÚ¶þÀàÊÇÄÚǶÓÐjs¾ç±¾µÄhtaÎļþ £»µÚÈýÀàÊÇ´æ´¢ÔÚºÚ¿ÍÎļþÍйܷþÎñÆ÷ÉϵÄremcosRATľÂíµÄloader £»µÚËÄÀàÊÇÓÃÓÚÖ±½Óͨ¹ýÓʼþ¾ÙÐÐľÂíͶµÝµÄѹËõ°üÎļþ¡£


ͨ¹ý×îÖÕÆÊÎöÈ·ÈÏ £¬ºÚ¿ÍÇÔÃÜľÂíµÄ¿ØÖÆÏÂÁî·þÎñÆ÷Ϊ¡°bossnacarpet.com¡±ºÍ¡°vegetachcnc.com¡± £¬ÏÖÔÚÕâÁ½¸öÓòÃû¶¼ÆÊÎöµ½Î»ÓÚÃÀ¹ú73.255.204.62·þÎñÆ÷ÉÏ £¬»Ø´«¶Ë¿ÚΪ2556¡£³ýÁËÓÃÓÚ¿ØÖÆÄ¿µÄÖ÷»úµÄ¿ØÖÆÏÂÁî·þÎñÆ÷Íâ £¬ºÚ¿ÍÉÐÓÐһЩÓÃÓÚ´æ´¢htaºÍremcosRATľÂíloaderµÄÍйܷþÎñÆ÷ £¬´ó²¿·ÖµÄÑù±¾ÍйܷþÎñÆ÷¶¼Î»ÓÚÃÀ¹ú¾³ÄÚ¡£ÕâЩÍйܷþÎñÆ÷Ïà¹ØÐÅÏ¢ÈçÏ¡£


±í2.png

±í2 ¶ñÒâ·þÎñÆ÷IPµØµã


ÇÔÃÜľÂí¿ØÖÆÏÂÁî·þÎñÆ÷ÓòÃû¡°bossnacarpet.com¡±×¢²áÓÚ2023Äê8ÔÂ4ÈÕ £¬¿ÉÊÇһֱδÓÐʹÓÃÖ±µ½2024Äê4ÔÂÆÊÎöµ½ÁË·þÎñÆ÷107.175.229.143¡£´Ó4Ô·ݵ½8Ô·ÝÌæ»»ÁË2´Î·þÎñÆ÷»®·ÖΪ5ÔÂÌæ»»Îª·þÎñÆ÷107.173.4.18 £¬7Ô·ÝÌæ»»Îª·þÎñÆ÷173.255.204.62¡£·þÎñÆ÷173.255.204.62һֱʹÓõ½ÏÖÔÚ¡£


¶ø¿ØÖÆÏÂÁî·þÎñÆ÷ÓòÃû¡°vegetachcnc.com¡±ÊÇ2024Äê3ÔÂ21ÈÕÐÂ×¢²áµÄÓòÃû £¬ÆäÖ±µ½2024Äê7Ô²ű»ÉèÖõ½·þÎñÆ÷107.173.4.18ºÍ·þÎñÆ÷173.255.204.62ÉÏ¡£


±ðµÄ £¬´ÓÕâÁ½¸öÓòÃûµÄ×¢²áÐÅÏ¢À´¿´£¨¼ûͼ6£© £¬ºÚ¿Í¼«ÓпÉÄÜʹÓÃÁË×Ô¶¯»¯×¢²á¹¤¾ßÀ´ÊµÏÖ £¬ÈôÊÇÍÆ²â½¨Éè £¬ÄÇôÎÒÃÇËù·¢Ã÷ÕâÅú¹¥»÷¿ÉÄÜÖ»ÊǸúڿÍ×é֯ijһ¸ö·ÖÖ§¡£


ͼƬ6.png
ͼ6 ÓòÃû×¢²áÐÅÏ¢


ËäÈ»³ýÁËÓòÃû×¢²á±£´æ×Ô¶¯»¯µÄºÛ¼£Íâ £¬¸ÃºÚ¿Í×éÖ¯µÄ¹¥»÷Ñù±¾¿´ÆðÀ´Ò²¾ßÓкÜÇ¿µÄ×Ô¶¯»¯ÌØÕ÷¡£²¿·ÖÎļþÐÅÏ¢Èç±í4Ëùʾ £¬ÔÚÎÒÃÇÍøÂçµ½µÄÑù±¾Öб£´æ´ó×Ú8×Ö½ÚÊ®Áù½øÖÆÃû³ÆµÄÎó²îʹÓÃÎĵµÈç¡°A5570000¡±ºÍ¡°00870000¡±ÀàËÆµÄÐÎʽ £¬ÕâЩ¹¥»÷ÎĵµÎÞÒÉÊǺڿÍͨ¹ý×Ô¼ºµÄ¹¥·Àƽ̨×Ô¶¯»¯ÌìÉúµÄ¶ñÒâÎļþ¡£ÕâÀàÎļþµÄ·ºÆðʱ¼äÖ÷Òª¼¯ÖÐÔÚ2024Äê3Ô·ݵ½8Ô·Ý¡£


±í3.png

±í3 ¶ñÒâÓÕ¶üÎĵµ


±ðµÄÕâÅúÑù±¾ÖеÄһЩdocÎó²îʹÓÃÎļþ·ºÆð³öÒ»ÖÖÏ£ÆæµÄÎļþÃûÐÎʽ £¬ÀàËÆÓÚÎļþ¡°iwanttosxwithudeeolybecauseitrulylovesxwithoumygirlireallymissingu__nowiwantsxwithou.doc £¬ÕâÀàÎļþ¿´ÆðÀ´ÏñÊÇʹÓÃһЩÎÄÕ»òÕßС˵ÄÚÈÝ×÷Ϊ×Öµä £¬Í¨¹ýijÖÖËã·¨×Ô¶¯»¯ÌìÉúµÄÑù±¾ £¬ÕâÀàÎļþÖ÷Òª·ºÆðÔÚ2024Äê3ÔÂÖÁ4ÔÂʱ´ú¡£²¿·ÖÎļþÐÅÏ¢ÈçϱíËùʾ¡£


±í4-1.png

±í4-2.png

±í4-3.png

±í4 ¶ñÒâÓÕ¶üÎĵµ


¹ØÓÚÇ°ÃæÌáµ½µÄµÚ¶þÀàÎļþ²¢Î´¼¸ £¬Èç±í6Ëùʾ¡£ÕâÊǺڿ͹¥»÷·¾¶ÖеÄÒ»ÀàÖÐÐÄÎļþ £¬Ò»²¿·Ö¹¥»÷½«´ËÀàÎļþµÄÁ´½Ó¸½×ÅÔÚ´¹ÂÚÓʼþÖÐ £¬ÓÕʹĿµÄµã»÷ £»Ò»²¿·Öͨ¹ýÎó²îʹÓÃÎĵµ´ÓÔ¶³ÌÏÂÔØÖ´ÐС£ÕâЩÎļþÏÖʵÉÏÊÇһЩ°üÀ¨¶à²ã»ìÏýºÍ±àÂëµÄJavaScript¾ç±¾Îļþ £¬JavaScript¾ç±¾ÎļþÖÐÔÙǶÌ×»ìÏýµÄVBScriptºÍ»ìÏýµÄPowerShellÏÂÁî £¬×îºóʹÓÃPowerShellÏÂÁî´ÓºÚ¿Í·þÎñÆ÷ÉÏÏÂÔØ±»¶þ½øÖÆ»ìÏý¹ýµÄloader³ÌÐò²¢Ö´ÐС£


±í5.png

±í5 ¶ñÒâhtaÎļþ


¶ñÒâhtaÎļþÖ´Ðкó £¬»á´ÓºÚ¿Í·þÎñÆ÷ÉÏÏÂÔØ±»¶þ½øÖÆ»ìÏý¹ýµÄloader³ÌÐò²¢Ö´ÐÐ £¬ÕâЩloader×îÖÕ»á½âÃܲ¢Ö´ÐÐÇÔÃÜľÂíremcosRAT¡£


¶øÕâЩloaderÕýÊÇÎÒÃÇÉÏÃæÌáµ½µÄµÚÈýÀàÑù±¾Îļþ, £¬Èç±í7Ëùʾ £¬ÕâЩ¶ñÒâloaderÎļþÃû´óÖ¿ÉÒÔ·ÖΪÁ½ÀࣺһÀàÊÇαװ³ÉÈç¡°csrss.exe¡±¡¢¡° wininit.exe¡±ÕâÀàϵͳÀú³ÌÃû³Æ £¬ÒÔÒþ²Ø¶ñÒâÐÐΪΪĿµÄ £»Ò»ÀàÊÇÃüÃû³É¡°Quotation.exe¡±¡¢ ¡°RFQ.exe¡±ÕâÀàÃû³ÆÒÔÅäºÏ¹¥»÷ÓʼþÀ´ÓÕʹÊܺ¦ÕßÔËÐС£ÕâЩÎļþµÄ±àÒëʱ¼ä×îÔçΪ2024Äê4ÔÂ16ÈÕ£¨UTC£© £¬×îÐÂΪ2024Äê7ÔÂ23ÈÕ£¨UTC£©¡£


±í6-1.png

±í6-2.png

±í6-3.png

±í6 ¶ñÒâloader³ÌÐò


ͨ¹ý¸Ã±íÎÒÃÇ»¹¿ÉÒÔ¿´³ö £¬ÓÐÐí¶àloader³ÌÐòÔÚ±àÒëºÃºó¾ÍÔںܶÌʱ¼äÀï±ãͶÈëʹÓÃÁË £¬ºÍÎÒÃÇÊӲ쵽µÄʱ¼äºÜÊÇ¿¿½ü £¬ÓеÄ×î¶Ì¾àÀëÉõÖÁ²»µ½°ëСʱ £¬ÕâÏÔÈ»ÊÇͨ¹ý×Ô¶¯»¯µÄľÂí¼´Ê±±àÒ뼴ʱͶ·Åƽ̨ʵÏֵġ£


µÚËÄÀàÎļþÏÖÔÚ·¢Ã÷µÄÒ²²¢Î´¼¸ £¬ÏÖÔÚ»¹ÎÞ·¨ÏÔ×Å¿´³öÆä±£´æ×Ô¶¯»¯ÊµÏֵĺۼ£¡£ºÚ¿Í½«»ìÏý¹ýµÄhtaÎļþ£¨»òÆäÁ´½Ó£©»òloaderαװ³ÉÕý³£Îļþ²¢¾ÙÐдò°ü £¬È»ºó×÷ΪÓʼþ¸½¼þÌí¼Óµ½Óã²æÓʼþÖÐ £¬ÔÙͨ¹ýÓʼþ»°ÊõÓÕʹ¹¥»÷Ä¿µÄ½âѹִÐС£


±í7.png

±í7 ×÷ΪÓʼþ¸½¼þµÄѹËõÎļþ


Òò´Ë £¬ÍŽáÉÏÎĵįÊÎöÀ´¿´ £¬ºÚ¿ÍËÆºõ¾ßÓÐÍêÕûµÄ×Ô¶¯»¯¹¥»÷ƽ̨ £¬Æä¾ßÓкÜÊÇÇ¿µÄ×Ô¶¯»¯ÄÜÁ¦ £¬ÕâЩÄÜÁ¦°üÀ¨×Ô¶¯»¯µÄÓÊÏäÉêÇë¡¢ÓòÃû×¢²á¡¢ÓÕ¶üÎĵµÌìÉú¡¢Ä¾Âíloader¼´Ê±±àÒ롢ľÂíͶ·ÅµÈ¡£


4.¹¥»÷°¸ÀýÆÊÎö


ÎÒÃÇÒԸúڿÍÍÅ»ïÕë¶ÔÎÒ¹úijÍâÔ˹«Ë¾µÄÒ»´ÎÓʼþ¹¥»÷ΪÀý¾ÙÐÐ˵Ã÷¡£Èçͼ7Ëùʾ £¬Ôڴ˴ι¥»÷ÖÐ £¬¹¥»÷ÕßÏÈÔÚ×Ô¼ºµÄ¶ñÒâ·þÎñÆ÷¡°192.3.118.15¡±ºÍ¡°107.173.143.46¡±ÉÏ»®·ÖÉèÖúͰ²ÅźöñÒâÎļþ¡°gdfc.hta¡±ºÍ¡°csrss.exe¡± £¬Ö®ºó £¬¹¥»÷ÕßÏòÎÒ¹úijÍâÔ˹«Ë¾µÄÊÂÇéְԱͶµÝ´øÓжñÒ⸽¼þ¡°Quotation.xls¡±£¨±¨¼Û.xls£©µÄÓʼþ £¬¸ÃxlsÎĵµÊÇЯ´øÓÐÎó²î¡°CVE-2017-0199¡±Ê¹ÓôúÂëµÄ¶ñÒâÎó²îʹÓÃÎļþ £¬Îó²îʹÓôúÂëÒ»µ©Ö´ÐÐ £¬»á¼ÓÔØÖ´ÐÐÊÂÏȰ²ÅŵĶñÒâÎļþ¡°http://192.3.118.15/xampp/mnu/gdfc.hta¡± £¬ ¶ñÒâgdfc.hta°üÀ¨µÄ¶ñÒâ¾ç±¾»áÇëÇó²¢Ö´ÐжñÒâÎļþ¡°http://107.173.143.46/T2307W/csrss.exe¡±¡£csrss.exeΪÉÌҵľÂíremcosRATµÄloader £¬ ÆäÖ´Ðкó £¬»á½âÃÜÆäÖеÄÉÌÒµÔ¶¿ØÄ¾ÂíremcosRAT µ½Êܺ¦ÕßµÄ×°±¸Ö´ÐС£Í¨¹ýÉÏÊöÀú³Ì £¬¹¥»÷Õß×îÖÕÀÖ³ÉÏò¹¥»÷Ä¿µÄͶ·ÅÁËremcosRATÔ¶¿ØÄ¾Âí¡£

ͼƬ7.png

ͼ7 ¹¥»÷Á÷³Ìͼ

4.1 ÓÕ¶üÓʼþͶµÝ


´Ë´Î¹¥»÷ʼÓÚÒ»·âÊÔͼαװ³ÉÓ¡¶È¸ßµÈÃæÁÏÖÆÔìÉÌ¡°Raymond¡±Ïà¹ØÊÂÇéÖ°Ô±µÄ±¨¼ÛÇëÇóÓʼþ£¨¼ûͼ8£© £¬´ËÓʼþÊÇ·¢Ë͸øÎÒ¹úijÍâÔ˹«Ë¾µÄÊÂÇéÖ°Ô±µÄ¡£ÓʼþÖ÷ÌâÊÇ¡°RFQ£¨±¨¼ÛÇëÇ󣩡± £¬¸½¼þÓÕ¶üÎĵµÃû³ÆÎª¡°Quotation.xls£¨±¨¼Û.xls£©¡± £¬ÕýÎÄ·­Òë³ÉÖÐÎÄÊÇ ¡°Çë²éÊÕ¸½¼þËùÐèÏîÄ¿µÄ±¨¼Ûµ¥ £¬²¢ÒÔ±¨¼Ûµ¥È·ÈÏ £¬ÇëÈ·ÈÏÊÕÌõ¡±¡£´ÓÓʼþµÄÖ÷ÌâºÍÕýÎÄÄÚÈÝÀ´¿´ £¬¹¥»÷ÕßÊÇÏëαװ³ÉÓ¡¶È¸ßµÈÃæÁÏÖÆÔìÉÌ¡°Raymond¡±¶ÔÎÒ¹úijÍâÔ˹«Ë¾ÊµÑéÓʼþ¹¥»÷¡£


ͼƬ8.png

ͼ8 ¹¥»÷ÕßͶ·ÅµÄ¹¥»÷Óʼþ


¸½¼þÎĵµ¡°Quotation.xls¡±£¨¼ûͼ9£©ÊÇÒ»¸ö¡°CVE-2017-0199¡±Îó²îʹÓõĶñÒâÎĵµ £¬ÈôÊÇÊܺ¦ÕßÉè±¹ØÁ¬ÄOfficeδʵʱ¸üР£¬¶øÊܺ¦ÕßÓÖÓÉÓÚÊèºö·­¿ªÁ˸ÃÎĵµ £¬Îó²îʹÓôúÂë±ã»áÖ´ÐС£


ͼƬ9.png

ͼ9 ÓÕ¶üxlsÎĵµ


Îó²îʹÓôúÂë»á¼ÓÔØºÍÖ´Ðй¥»÷Õß°²ÅŵĶñÒâhtaÎļþ£º¡°http://192.3.118.15/xampp/mnu/gdfc.hta¡± £¬ gdfc.htaÎļþµÄÄÚÈÝÈçͼ10Ëùʾ £¬¸ÃÎļþÖ»°üÀ¨Ò»¸ö»ìÏý´¦Öóͷ£¹ýµÄJavascript¾ç±¾¡£


ͼƬ10.png

ͼ10 gdfc.htaÎļþ²¿·ÖÄÚÈÝ


Õâ¶Î JavaScript ¾ç±¾Ê¹ÓÃÁË unescape() º¯ÊýÀ´½âÂëÒ»¸ö¾­ÓɱàÂëµÄ×Ö·û´®¡®%3C%73%63%72%69%70%74%20%6C%61%6E%67%75%61%67%65%3D%4A%61%76%61%53%63%72%69%70%74%...... 69%74%65%28%64%29%3B%3C%2F%73%63%72%69%70%74%3E¡¯ £¬²¢Í¨¹ý document.write()ÒªÁ콫½âÂëºóµÄÄÚÈÝÊä³öµ½Ò³ÃæÉÏ¡£Õâ¶Î¾­ÓɱàÂëµÄ×Ö·û´®½âÂëºó¼ûͼ11 £¬ÎÒÃÇÀ´¿´Õâ¶Î´úÂë¶¼¸ÉÁËЩʲô£ºm ±äÁ¿°üÀ¨ÁËÍêÕûµÄ HTML ºÍǶÈëµÄ ¶ñÒâVBScript ´úÂ루Õⲿ·Ö´úÂëʹÓÃÁË JavaScript£© £»unescape(m) º¯ÊýÓÃÓÚ½âÂë m ÖеÄתÒå×Ö·û £¬½«Æä»¹Ô­ÎªÔ­Ê¼Îı¾ £»document.write(d)½«½âÂëºóµÄ HTML ºÍ¶ñÒâ VBScript ´úÂëдÈëµ½ÎĵµÖÐ £¬ÕâÒ»²½Ï൱ÓÚ¶¯Ì¬¼ÓÔØ¶ñÒâ´úÂëµ½Óû§µÄä¯ÀÀÆ÷ÇéÐÎÖС£


ͼƬ11.png

ͼ11 ½âÂëºóµÄ´úÂë½á¹¹


¶ñÒâVBScript ´úÂëÈçͼ12Ëùʾ £¬ÎÒÃÇ¿´µ½Õâ¶Î´úÂë»ìÏýÁ˱äÁ¿ÃûºÍÏÂÁʹÓÃÁ˳¬³¤±äÁ¿Ãû¡°FZmVzmbnJlDsrDPejjREhoSUpLccYGThfiITYHmlYTerSIATfMkpyNZNbIRRjmhWgbmEymiqenIvsgxmwrNLYaeXZijiaptaxmbXnjqXRcpyedgHXEBNUiJUXUhXLWgRSybTIFmCYTdxsJdzwjCoDvqZLzLfGqVOgsqmVJ¡±ºÍ¡°BMheopsbVrJXHOKkrGKTzUVwCTPAsCMcYpVBKRxInxQgxxxJNQGzAmHManmtkLfnoAWzQzvWZLNeeRnjqUjxMjVNGzutUDKfYPYGIjBZFBqBFTwUBnhvlFXGUZbhzaOLDDQDpQeYIpmdbxmXWpqbaweBsgWtZWGnHmnaLp¡±¡£ÕâÑù²Ù×÷¼ÈÌÓ±ÜÁËһЩÇå¾²Èí¼þµÄ¼ì²âÓÖÔöÌíÁËÆÊÎöÖ°Ô±µÄÔĶÁÄѶÈ £¬¿ÉÒÔ˵ÊÇ¡°Ò»Ê¯¶þÄñ¡±¡£Õâ¶Î´úÂëµÄÄ¿µÄÊÇÖ´ÐÐÒ»¸öPowerShellÏÂÁÂÌÉ«²¿·Ö£©¡£


ͼƬ12.png

ͼ12 ¶ñÒâVBScript´úÂë


PowerShellÒªÖ´ÐеÄÏÂÁî½âÂëºóÈçͼ13Ëùʾ £¬Õâ¶Î´úÂëʹÓÃÒ»ÖÖ¡°AT¡±ÊÖÒÕÀ´ÌÓ±Üɱ¶¾Èí¼þµÄÐÐΪ²éɱ¡£ÆäʹÓà Add-Type cmdlet Ìí¼ÓÁËÒ»¸öÐ嵀 .NET ÀàÐÍ¡£Õâ¸öÀàÐͰüÀ¨Ò»¸ö´Ó urlmon.dll ¶¯Ì¬Á´½Ó¿âÖе¼ÈëµÄ URLDownloadToFile º¯Êý £»È»ºóŲÓà URLDownloadToFileº¯Êý £¬´ÓµØµãhttp://107.173.143.46/T2307W/csrss.exe ÏÂÔØÎļþµ½ÍâµØÂ·¾¶ $ENV:APPDATA\winiti.exe £»½Ó×ÅÈþ籾ÔÝÍ£ 3 ÃëÖÓ £¬È·±£ÎļþÏÂÔØÍê³É £»×îºó

Ö´ÐÐÏÂÔØµÄ¿ÉÖ´ÐÐÎļþ¡£ÎÒÃÇ¿ÉÒÔ¿´µ½ £¬Õâ¶Î´úÂëµÄÖ÷Òª¹¦Ð§ÊÇ´ÓÖ¸¶¨µÄ URL ÏÂÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ £¬²¢ÔÚÏÂÔØÍê³ÉºóÔËÐÐËü¡£


ͼƬ13.png

ͼ13 PowerShellÒªÖ´ÐеÄÏÂÁî

4.2 ¶ñÒâ³ÌÐòÆÊÎö


ͨ¹ýÇ°ÃæÏÂÔØ²¢Ö´ÐеĶñÒâ³ÌÐòΪ¡°http://107.173.143.46/T2307W/csrss.exe¡± £¬ ¾­Ì«¹ýÎö £¬ÎÒÃÇ·¢Ã÷csrss.exeÊÇÒ»¸ö¶ñÒâloader £¬ÓÉÓڸöñÒâloader¾­ÓÉÁËÑÏÖØµÄ»ìÏý £¬²¢ÇÒÐí¶àº¯ÊýʹÓÃÁ˶¯Ì¬¼ÓÔØÊÖÒÕ £¬Òò´Ë½öͨ¹ý¾²Ì¬ÆÊÎöÎÒÃǺÜÄÑÖªµÀËüµÄÒªº¦Ö´ÐÐÂß¼­¡£ÍŽᶯ̬ÆÊÎö £¬ÎÒÃÇ·¢Ã÷ £¬¸ÃloaderÔÚÖ´Ðкó»áÔÚÄÚ´æÖнâÃܳöÉÌҵľÂíremcosRAT £¬È»ºóÐÂÆðÒ»¸ö¿þÀÜÀú³ÌÈç¡°msbuild.exe¡± £¬½Ó×ÅʹÓÃÀú³ÌïοÕÊÖÒÕ½«remcosRATľÂí×¢Èëµ½ÐÂÆðµÄ¿þÀÜÀú³Ì¿Õ¼äÖÐÖ´ÐС£Àú³ÌïοÕÊÖÒÕ³£±»¶ñÒâÈí¼þÓÃÓÚ×¢Èë¶ñÒâ´úÂë £¬ÒÔÌÓ±Üɱ¶¾Èí¼þµÄ¼à²âºÍ·ÀÓù»úÖÆ £¬²¢ÔÚÄ¿µÄϵͳÉÏÖ´ÐжñÒâÔ˶¯¡£


loader»áÔÚÄ¿µÄÅÌËã»úÉÏMicrosoft.NET FrameworkµÄ×°ÖÃĿ¼ÏÂÑ¡ÔñÒ»¸öÕýµ±µÄ.NETÏà¹Ø³ÌÐòÈç¡°msbuild.exe¡±¡¢¡° regsvcs.exe¡±¡¢¡° jsc.exe¡±ºÍ¡°installutil.exe¡±µÈ×÷ΪĿµÄÀ´½¨Éè¿þÀÜÀú³Ì¡£Èçͼ14Ëùʾ £¬¶ñÒâloaderÊ×ÏÈʹÓÃCreateProcessWº¯Êý½¨ÉèC:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\msbuild.exeÀú³Ì £¬ÐèÒª×¢ÖØµÄÊÇ £¬Õâ¸öÀú³ÌµÄÖ÷Ï̱߳»ÉèÖÃΪ¹ÒÆð״̬ £¬ÔÚºóÐø×¢ÈëÍê³É¶ñÒâ´úÂëºó £¬loader»áŲÓÃResumeThreadº¯ÊýÀ´»Ö¸´Ä¿µÄÏ̵߳ÄÖ´ÐС£


ͼƬ14.png

ͼ14 ½¨ÉèÄ¿µÄÀú³Ì


½¨ÉèÍê¿þÀÜÀú³Ìºó £¬loaderͨ¹ýŲÓÃZwUnmapViewOfSectionº¯ÊýÀ´×÷·Ï¿þÀÜÀú³ÌÖеÄÄÚ´æÓ³Éä £¬Èçͼ15Ëùʾ¡£


ͼƬ15.png

ͼ15 ×÷·ÏÄ¿µÄÀú³ÌÖеÄÄÚ´æÓ³Éä


½Ó×Å £¬loaderŲÓÃVirtualAllocExº¯ÊýÀ´Îª¿þÀÜÀú³Ì·ÖÅÉÄڴ棨Èçͼ16£© £¬ÎªµÄÊǽ«ºóÐøµÄ¶ñÒâ´úÂëдÈëµ½¿þÀÜÀú³ÌµÄµØµã¿Õ¼ä¡£


ͼƬ16.png

ͼ16 Ϊ¿þÀÜÀú³Ì·ÖÅÉÄÚ´æ


·ÖÅÉÍêÄÚ´æºó £¬loaderÔÙŲÓÃNtWriteVirtualMemoryº¯Êý½«remcosRATµÄPEÍ·×¢Èëµ½¿þÀÜÀú³ÌµØµã¿Õ¼ä £¬Èçͼ17Ëùʾ¡£


ͼƬ17.png

ͼ17 ×¢ÈëremcosRATµÄPEÍ·


×¢ÈëPEÍ·ºó £¬Èçͼ18Ëùʾ £¬loader¼ÌÐø½«remcosRAT µÄ¡°.text¡±section×¢Èëµ½¿þÀÜÀú³Ì¿Õ¼ä¡£½Ó×Å £¬loader»áÒÔͬÑùµÄ·½·¨ÒÀ´Î×¢ÈëremcosRATµÄ¡°.rdata¡±¡¢¡° .data¡±¡¢¡°.tls¡±¡¢¡° .gfids¡±¡¢¡° .rsrc¡±ºÍ¡°.reloc¡±section¡£


ͼƬ18.png

ͼ18 ×¢ÈëremcosRAT µÄ¡°.text¡±section


Èçͼ19Ëùʾ £¬ÔÚÕû¸öremcosRAT¶ñÒâ´úÂë×¢ÈëÍê³Éºó £¬loaderÔòŲÓÃResumeThreadº¯Êý»Ö¸´Ä¿µÄ¿þÀÜÀú³ÌµÄÖ÷Ïß³Ì £¬ÕâÑù £¬remcosRATľÂí¾ÍÔÚÄ¿µÄ¿þÀÜÀú³ÌÖÐÖ´ÐÐÁË¡£


ͼƬ19.png

ͼ19 »Ö¸´¿þÀÜÏß³Ì

4.3 remcosRATľÂí


ͨ¹ýÇ°ÃæµÄÆÊÎö £¬ÎÒÃÇÖªµÀ £¬¶ñÒâloaderͨ¹ýÄÚ´æ½âÃܺÍÀú³ÌïοÕÊÖÒÕ £¬×îÖÕÔÚѬȾװ±¸ÉÏÖ´ÐÐÁËÉÌÒµÔ¶¿ØÄ¾ÂíRemcos RAT £¬Æä°æ±¾ºÅΪ¡°5.1.0 Pro¡±£¨Èçͼ20Ëùʾ£©¡£×Ô2016ÄêÔÚ°µÍøÉϵĵØÏºڿÍÉçÇø×îÏȳöÊÛÒÔÀ´ £¬Remcos RAT·Ç³ £»îÔ¾ £¬»ù±¾ÉÏÿ¸öÔ¶¼»áÐû²¼Á½¸ö×óÓÒµÄа汾¡£¸Ã¹¤¾ßÓÉÒ»¼ÒÃûΪBreaking SecurityµÄ¹«Ë¾¿¯ÐгöÊÛ £¬Æä¾ßÓмüÅ̼ͼ¡¢ÆÁÄ»¼Í¼¡¢Å²ÓÃÉãÏñÍ·ºÍÂó¿Ë·ç¾ÙÐмÏñ¼Òô¡¢Ô¶³ÌÖ´ÐÐShellÏÂÁî¡¢Ô¶³ÌÖ´Ðо籾¡¢ÉÏ´«ÎļþÒÔ¼°ÏÂÔØÎļþ £¬ÎļþÖÎÀí¡¢Àú³ÌÖÎÀí¡¢×¢²á±í²Ù×÷ºÍ×°ÖÃÐ¶ÔØÔ¶¿ØµÈ¹¦Ð§ £¬Ö»ÒªRemcos RAT±»ÀÖ³ÉÖ²È뵽ĿµÄ×°±¸ £¬Æä±³ºóµÄºÚ¿Í±ã¿ÉÍêÈ«¿ØÖÆÄ¿µÄ×°±¸ £¬¶ÔÆä¾ÙÐÐ¼à¿Ø¡¢Êý¾ÝÇÔÈ¡ÉõÖÁÊǸü½øÒ»²½µÄÆÆËðÔ˶¯¡£ÎÒÃÇ´ËǰÔÚ±¨¸æ¡¶¡¾Éî¶È¡¿ADLabÕë¶ÔÐÂÐͺڿÍ×éÖ¯¡°º£¶¾Éß¡±Éî¶È×·×ÙÓëÆÊÎö¡·ºÍ¡¶¹ØÓÚ½üÆÚ¶íÎÚÍøÂç¹¥»÷Ô˶¯×·×ÙÆÊÎö±¨¸æ¡·ÖÐÔø¶ÔÆä¾ÙÐйýÏêϸµÄÊÖÒÕÆÊÎö £¬Ôڴ˲»×ö¹ý¶à׸Êö £¬ÏÂÃæ½ö¶ÔÆäÉèÖÃÎļþ²¿·Ö¾ÙÐмòҪ˵Ã÷¡£


ͼƬ20.png

ͼ20 ×îÖÕÖ´ÐеÄÉÌÒµÔ¶¿ØÄ¾ÂíremcosRAT


Èçͼ21Ëùʾ £¬Remcos RATÔËÐкó»á´Ó×ÔÉí×ÊÔ´ÖнâÃܳöÉèÖÃÐÅÏ¢ £¬ÄÚÀï°üÀ¨C&C·þÎñÆ÷µØµã¡°bossnacarpet.com:2556 £¬vegetachcnc.com:2556¡±¡¢»¥³â¹¤Ç©×Ö¡°chrome-6W1HCC¡±¡¢¼üÅ̼ͼÎļþÃû¡°logs.dat¡±¡¢Licence ID¡°C90245FEC67A6F41723337BDF4A60126¡±ÒÔ¼°ºÍ½ØÍ¼¡¢Â¼ÒôµÈ²Ù×÷Ïà¹ØµÄÆäËûÐÅÏ¢¡£


ͼƬ21.png

ͼ21 ½âÃܳöÀ´µÄÉèÖÃÐÅÏ¢


Ïà½ÏÓھɰ汾 £¬Remcos´Ó v5.0.0°æ±¾×îÏÈÔöÌíÁËÒÆ¶¯¶ËµÄ¿ØÖÆÖ§³Ö £¬Í¼22ÊÇRemcos¹ÙÍøÏÂÏà¹ØµÄ¸üÐÂÏÈÈÝ £¬ÓÉÏÈÈÝ¿ÉÖª £¬Remcos v5.0.0°æ±¾ÔÊÐíºÚ¿Íͨ¹ýTelegram»úеÈËÓëľÂí¶Ë½»»¥ £¬Òò´ËºÚ¿Í¿ÉÒÔͨ¹ýÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔºÍä¯ÀÀÆ÷Íê³É¶ÔÄ¿µÄÖ÷»úµÄ¿ØÖÆ¡£Í¬Ê±Remcos Telegram»úеÈËÖ§³ÖÒÔʵʱ֪ͨµÄ·½·¨ÈúڿÍʵʱÏàʶĿµÄ×°±¸ÔËÐÐÇéÐΡ£


ͼƬ22.png

ͼ22 Remcosй¦Ð§


ͼ23ÊÇRemcos Telegram»úеÈËÖ§³ÖµÄ¿ØÖÆÏÂÁîÁбí £¬ºÚ¿Í¿ÉÒÔͨ¹ýÆäÍê³É¶ÔÄ¿µÄÖ÷»úµÄ¸÷Ïî¿ØÖÆ £¬ÈçÆÁÄ»¼Í¼¡¢Å²ÓÃÉãÏñͷ¼Ïñ¡¢Ô¶³ÌÖ´ÐÐShellÏÂÁî¡¢Ô¶³ÌÖ´Ðо籾¡¢ÏÂÔØºÍÎļþ £¬ä¯ÀÀÆ÷²Ù×÷µÈ¡£


ͼƬ23.png

ͼ23 Remcos Telegram»úеÈË¿ØÖÆÏÂÁî


ËäÈ»Remcos Telegram»úеÈËÖ§³ÖµÄ¿ØÖÆÏÂÁîÏÖÔÚûÓÐԭʼµÄ C2¿ØÖƶ˶à £¬¿ÉÊǽèÖúÓÚTelegramµÄ¿çƽ̨֧³Ö £¬ºÚ¿Í¿ÉÒÔʹÓÃÊÖ»ú¡¢Æ½°åµçÄÔµÈÒÆ¶¯×°±¸ËæÊ±ËæµØ¾ÙÐÐľÂí¿ØÖÆ £¬¼«´óÍØÕ¹Á˺ڿ͵Ĺ¥»÷³¡¾°¡£½èÖúÓÚTelegramµÄʵʱ֪ͨ £¬ºÚ¿Í¿ÉÒÔʵʱÎüÊÕÊÜѬȾװ±¸µÄ״̬¸üкÍ֪ͨ £¬±ãÓÚ×Åʵʱ½ÓÄÉÏÂÒ»²½Ðж¯¡£ÁíÍâ £¬ÓÉÓÚ Telegram ÔÚÍâÑóÊdz£¼ûµÄͨѶ¹¤¾ß £¬Ê¹ÓÃËü¾ÙÐпØÖÆ¿ÉÒÔ¹æ±ÜһЩÇå¾²Èí¼þºÍÍøÂç¼à¿ØµÄ¼ì²â¡£ÕâЩÓÅÊÆÊ¹µÃ Remcos RAT ÔÚ 5.0.0 °æ±¾ºó±äµÃÔ½·¢Ç¿Ê¢ºÍÎÞа £¬½øÒ»²½ÌáÉýÁËÆäÔÚ¶ñÒâÔ˶¯ÖеÄÓ¦ÓüÛÖµ¡£ºÚ¿Í¹ºÖÃаæRemcos¾ÙÐй¥»÷ £¬¿ÉÒÔÆ¾Ö¤ËûÃÇ×Ô¼ºµÄÏêϸÐèÇóÑ¡ÔñºÏÊʵĿØÖÆ·½·¨¡£¶øÕë¶ÔаæRemcosµÄÕâÐ©ÌØÕ÷ £¬Çå¾²Ö°Ô±ºÍ³§ÉÌÐèÒªÒ»Ö±ÌáÉý¼ì²âºÍÏìÓ¦ÄÜÁ¦ £¬½ÓÄɶàÌõÀíµÄ·ÀÓùÕ½ÂÔ £¬²¢¼á³Ö¶Ô×îÐÂÍþвÇ鱨µÄÒ»Á¬¹Ø×¢¡£


5.×Ü ½á


ÎÒÃǾͽü¼¸¸öÔÂÊӲ쵽µÄһϵÁÐʹÓÃÍйÜÔÚ¶à¸öºÚ¿Í·þÎñÆ÷¹ûÕæÂ·¾¶ÉϵĴó×Ú¶ñÒâÎļþ¾ÙÐеÄÍøÂç¹¥»÷Ô˶¯¾ÙÐÐÁËÆÊÎö £¬ÎÒÃǶÔÕâЩ¹¥»÷Ô˶¯Ê¹ÓõĻù´¡ÉèÊ©¡¢¹¥»÷ÎäÆ÷¡¢Ô˶¯ÀúÊ·ºÍ¹¥»÷ÊÖ·¨µÈÐÅÏ¢¾ÙÐÐÁËÖÜÈ«µÄÆÊÎö £¬²¢ÇÒÎÒÃǶÔ×î½ü·ºÆðµÄÒ»´ÎÕë¶ÔÎÒ¹úijÍâÔ˹«Ë¾µÄ¹¥»÷¾ÙÐÐÁËÏêϸµÄÄæÏòÆÊÎö¡£´ÓÕâЩ¹¥»÷Ô˶¯µÄ¹¥»÷Ä¿µÄºÍ¹¥»÷ÊÖ·¨À´¿´ £¬Æä±³ºóµÄ¹¥»÷ÕߺܻòÐíÂÊÉÏÊÇÒ»¸öÒÔ¾­¼ÃÀûÒæÎªÄ¿µÄµÄ·¸·¨ÍŻ¼¸¸öÔÂÀ´ £¬ËûÃÇÒ»·½ÃæÁÙÓÚÖØµãÄ¿µÄ¶¨ÖƶñÒâÎļþ¾ÙÐж¨Ïò¹¥»÷ £¬Ò»·½Ãæ´óÅúÁ¿×Ô¶¯»¯ÌìÉúÓʼþ¡¢Îó²îʹÓÃÎļþºÍloader¾ÙÐйãÈöÍøÊ½µÄ¹¥»÷ £¬ËæºóÇÔȡĿµÄ¹«Ë¾µÄÉÌÒµÉñÃØ¡¢Ö÷Òª¹¤ÒµÊÖÒÕÐÅÏ¢µÈÃô¸ÐÐÅÏ¢ £¬ÒÔʵÏÖÆä¾­¼ÃÀûÒæ £¬Ò²²»É¨³ý¸Ã·¸·¨ÍÅ»ïÒÔÕâЩ¹¥»÷Ä¿µÄÎªÌø°å £¬½øÒ»²½ÏòÏà¹ØÆóÒµµÄÉÏÏÂÓι«Ë¾¡¢ÏàÖúͬ°é¡¢Õþ¸®¸ßУµÈ»ú¹¹¾ÙÐй¥»÷ £¬ÒÔ»ñÈ¡¸ü¶àµÄ¡°¹¥»÷Ч¹û¡±¡£ÕâЩ¹¥»÷²»µ«»á¶ÔÏà¹ØÆóÒµµÄÔËÓªºÍÉùÓþÔì³ÉÑÏÖØÓ°Ïì £¬»¹¿ÉÄܵ¼Ö¹¤ÒµÅä·½¡¢¿Í»§×ÊÁϵȽ¹µãÉæÃÜÊý¾Ýй¶ £¬Ð§¹û²»¿°ÉèÏë¡£


×èÖ¹ÏÖÔÚ £¬¸Ã·¸·¨ÍÅ»ïµÄ¹¥»÷Ô˶¯ÈÔÈ»»îÔ¾ £¬ÈÔ½«Óв»ÉÙ¹«Ë¾»á³ÉΪÆäеÄÁÔÎï £¬ÎÒÃÇ»áÒ»Á¬¹Ø×¢ºÍ¸ú½ø¸ÃºÚ¿ÍÍÅ»ïµÄÏà¹Ø¹¥»÷Ô˶¯¡£


×ðÁú¿­Ê±Æð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©



ADLab½¨ÉèÓÚ1999Äê £¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò» £¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£×èÖ¹ÏÖÔÚ £¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î5000Óà¸ö £¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç»ù´¡Çå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢5GÇå¾²Ñо¿¡¢È˹¤ÖÇÄÜÇå¾²Ñо¿¡¢Òƶ¯Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·Àϵͳ½¨Éè¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£


adlab.jpg