2020-04-21
°ä²¼¹¦·ò 2020-04-21ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º£º£º |
TCP_ºóÃÅ_Win.BACKSPACE/Lecna_ÏνÓC2·þÎñÆ÷ |
|
°²È«ÀàÐÍ£º£º£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º£º£º |
¼ì²âµ½ºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£ BACKSPACEÊÇÒ»¸öºóÃÅ£¬£¬£¬Ò²¾ÍÊÇ"Lecna"£¬£¬£¬Ö°Äܼ«¶È׳´ó£¬£¬£¬¿ÉÆëÈ«½ÚÖÆ±»Ï°È¾»úе¡£ BACKSPACEÄܹ»ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬ÈçÍÆËã»úÃû³Æ¡¢¡¢ÏµÍ³°æ±¾£¬£¬£¬IPµØÖ·µÈ£¬£¬£¬ÓµÓйý³ÌÖÎÀí¡¢¡¢ÎļþÖÎÀí¡¢¡¢×¢²á±íÖÎÀí¡¢¡¢Ö´ÐкÅÁîµÈ¡£ |
|
¸üй¦·ò£º£º£º |
20200421 |
|
ÊÂÎñÃû³Æ£º£º£º |
TCP_ľÂí_Sidewinder.PreBotModules_ÏνÓC2·þÎñÆ÷ |
|
°²È«ÀàÐÍ£º£º£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º£º£º |
¼ì²âµ½ Sidewinder.PreBotModules ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅ Sidewinder.PreBotModules¡£ PreBotModules ÊÇAPT×éÖ¯"ÏìβÉß"£¨SideWinder¡¢¡¢T-APT-04£©ÓÃc#дµÄÐÅÏ¢ÍøÂçÄ£¿£¿é£¬£¬£¬¸ÃºóÃÅÄ£¿£¿éͨ³£Ê¹ÓÃOfficeµö¶üÎĵµÏ·¢£¬£¬£¬Ö²ÈëÖ÷»úºó»áÍøÂçÊܺ¦Ö÷»úµÄÍÆËã»úÃû¡¢¡¢Óû§Ãû¡¢¡¢MACµØÖ·¡¢¡¢ÆôÓõķþÎñºÍ¹ý³Ì¡¢¡¢¸üв¹¶¡µÈÖ¸ÎÆÐÅÏ¢·¢ËÍÖÁÔ¶³Ì·þÎñÆ÷¡£ |
|
¸üй¦·ò£º£º£º |
20200421 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º£º£º
HTTP_ºóÃÅ_FakeSanforUD_ÏνÓ
°²È«ÀàÐÍ£º£º£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º£º£º
¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFakeSanforUD¡£
ÉîÕÛ·þVPN¿Í»§¶Ë´æÔÚ·ì϶£¬£¬£¬ÔÚÉý¼¶Ê±»áÏÂÔØÖ´ÐÐÃûΪSangforUD.exeµÄ¸üз¨Ê½¡£µ«VPN¿Í»§¶Ë½ö¶ÔSangforUD.exe×öÁ˵¥Ò»µÄ°æ±¾¶Ô±È£¬£¬£¬Ã»ÓÐ×öÈκεݲȫ²é³¡£APT×éÖ¯Darkhotel¹¥ÆÆÁËVPN·þÎñÆ÷£¬£¬£¬´Û¸ÄÉý¼¶ÅäÖÃÎļþ²¢°ÑSangforUD.exe´úÌæÎª¶ñÒâµÄºóÃÅFakeSanforUD¡£
FakeSanforUDÊÇÒ»¸öºóÃÅ£¬£¬£¬Í¨¹ýÏÂÔØÖ´ÐÐshellcode£¬£¬£¬×îÖÕÏÂÔØÖ÷ÌâµÄºóÃŶñÒâ×é¼þthinmon.dll¡£º£º£Ö÷ÌâºóÃÅ×é¼þthinmon.dll»á½âÃÜÔÆ¶ËÏ·¢µÄ±ðµÄÒ»¸ö¼ÓÃÜÎļþSangfor_tmp_1.dat£¬£¬£¬ÒÔ¼ÓÔØ¡¢¡¢Ïß³ÌÆô¶¯¡¢¡¢×¢Èë¹ý³Ì3ÖÖ·½Ê½ÖеÄÒ»ÖÖÆô¶¯datÎļþ £¬£¬£¬×îÖÕÓÉdatÎļþʵÏÖÓë·þÎñÆ÷½»»¥Ö´ÐжñÒâ²Ù×÷¡£
¸üй¦·ò£º£º£º
20200421
ÊÂÎñÃû³Æ£º£º£º
DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÒªÇó
°²È«ÀàÐÍ£º£º£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º£º£º
¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£
¸üй¦·ò£º£º£º
20200421


¾©¹«Íø°²±¸11010802024551ºÅ