¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

Éî¶ÈÆÊÎö¼°·À»¤£º¼ÓÃÜľÂí¹¥»÷ £¬º£Á«»¨£¿

2015-06-15

Ðû²¼Õߣº¾ÅÓÎÀÏ¸ç¿Æ¼¼

Ëæ×ÅÄäÃûÕß¹¥»÷ÊÂÎñµÄ¸ú×ÙÆÊÎö×ßÏòÉîÈë £¬5ÔÂ28ÈÕ £¬ÓÖһϵÁÐÕë¶ÔÖйúµÄ¹¥»÷ÐÐΪ¸¡³öË®Ãæ¡£Õâ¸ö±»¸÷È˳ÆÎª¡°º£Á«»¨¡±×éÖ¯ËùʵÑéµÄ¹¥»÷ £¬Æä¹¥»÷ÌØÕ÷ÊÇÔõÑùµÄ £¬¾¿¾¹ÊÇ´¿´âµÄľÂí £¬ÕÕ¾ÉAPT£¿ËæÖ®¶øÀ´µÄ¹¥·À˼Ð÷»á±¬·¢ÔõÑùµÄת±ä£¿Óû§ÓÖ¸ÃÔõÑùÓ¦¶Ô£¿

±¾±¨¸æÒÔºó´Î¹¥»÷ÊÂÎñÖнػñµÄµä·¶Ä¾ÂíÑù±¾ÈëÊÖ £¬ÆÊÎöÆä¹¥»÷ÐÐΪ £¬±ÈÕÕľÂí¼°APTµÄÌØÕ÷ £¬ÎªÓû§Ë¼Ë÷ÏÂÒ»²½µÄÓ¦¶Ô¼Æ»® £¬¸ø³öÁËת±ä˼Ð÷µÄ¹¥·ÀÄ£×Ó £¬Ìá³öδÀ´¹¥·ÀÕ½ÖÐÊäÓ®Åжϱê×¼¼°Éú³¤Æ«Ïò £¬²¢ÍƼöÁËÓ¦¶Ô´Ë´Î¹¥»÷µÄ½â¾ö¼Æ»®¼°ÊµÑé°ì·¨¡£



Ŀ¼

  • ¹¥»÷£ºÊÇË­£¿

    • º£Á«»¨
    • ÑùÌìÖ°Îö
  • ¹¥»÷£ºÊÇľÂíÕÕ¾ÉAPT

    • ľÂíÌØÕ÷
    • APTÌØÕ÷
    • Òª¹Ø×¢µÄÊÂÇé
  • ·À»¤£ºË¼Ð÷ת»»

    • ÔõôÃ÷È·
    • Ôõô×ö
  • ·À»¤£ºNGTP¼Æ»®
    • ÍêÕû°²ÅÅ
    • ¼ò»¯°²ÅÅ
    • ²úÆ·°²ÅÅ
    • ÖÕ¶Ë·À»¤
  • ÍþвÇ鱨
  • ¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼

¹¥»÷£ºÊÇË­£¿

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÒ»Ö±ÔÚÒ»Á¬¹Ø×¢ÍøÂç¹¥»÷ÊÂÎñ²¢¾ÙÐиú×ÙÆÊÎö £¬ÕâЩ¹¥»÷ÊÂÎñÖÐÓÐÀ´×Ôº£ÄÚµÄ £¬Ò²ÓÐÀ´×ÔÍâÑó £¬ÓÌÈçÏÖʵÉç»áÖеĿֲÀÖ÷ÒåÒ»Ñù £¬ÓÐЩÊÂÎñ»áÓÐ×éÖ¯¹ûÕæÈÏ¿É £¬ºÃ±ÈÄäÃûÕߣ¨Anonymous£© £¬µ«Ò²ÓÐһЩÊÂÎñÊÇûÓÐ×éÖ¯¶ÔÆäÈÏÕæµÄ £¬ÕâЩÊÂÎñ¾ÅÓÎÀÏ¸ç¿Æ¼¼µÄר¼Ò»áÓÃÏà¹ØµÄÄ£×Ó¾ÙÐзÖÀàÑо¿ £¬ÆäÖеÄÒ»¸ö²Î¿¼Ö¸±ê¾ÍÊÇÆä¹¥»÷ÐÐΪ¼°Ï°ÓõĹ¥»÷ÐÎʽ¡£

º£Á«»¨

2015Äê5ÔÂ28ÈÕ £¬Ò»ÏµÁÐÕë¶ÔÖйúº£Ê»ú¹¹µÄ¹¥»÷ÐÐΪ¸¡³öË®Ãæ £¬Òµ½çÓд«¹¥»÷ÊÂÎñÉæ¼°30¶à¸ö¹ú¼Ò £¬ÊºóδÓÐ×éÖ¯Éù³Æ¶ÔÕâЩ¹¥»÷ÊÂÎñÈÏÕæ £¬µ«ÆäÖпÉÒÔ¿´µ½µÄÊÇ £¬Ïà¹Øº£Ê»ú¹¹µÄ¹¥»÷´ó´ó¶¼À´×ÔľÂí¡£ÈôÊÇ˵ÕâЩ¹¥»÷ÊÇÀ´×Ôij¸öºÚ¿Í×éÖ¯ £¬ÄÇôÕâ¸ö×éÖ¯ÎÞÒÉÊǽÏÁ¿µÍµ÷µÄ £¬µÍµ÷µ½Ã»¿´µ½Æä¹ûÕæµÄÃüÃû¡£¿ÉÄÜÊÇÓÉÓÚÕâЩ¹¥»÷Ä¿µÄ³£Éæ¼°ÖйúµÄº£Ê¼°Ïà¹Ø»ú¹¹ £¬Ä³¹«Ë¾½«ÆäÃüÃûΪ¡°º£Á«»¨¡± £¬µ«Ë¼Á¿µ½ÕâЩ¹¥»÷µÄÒ»Ð©ÌØÕ÷ £¬1¶à½ÓÄÉľÂí £¬2¶àÕë¶Ôº£Ê»ú¹¹ £¬3¹¥»÷ÓÐÒ»¶¨µÄÊýÄ¿ £¬4ÈôÊDZ£´æÕâ¸ö×éÖ¯ £¬ËûÃǺܵ͵÷ £¬ÄÇ¿ÉÄÜʹÓú£Âí£¨Seahorse£©³ÆºôËûÃǸüΪÌùÇС£

1

ÑùÌìÖ°Îö

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÔÚÒ»Ñùƽ³£¼à²âÖлñÈ¡µ½Á˸Ã×éÖ¯µÄһЩľÂíÑù±¾ £¬Ë¼Á¿µ½º£ÄÚÓû§µÄʹÓÃϰ¹ß £¬Ñ¡ÔñÁËÒ»¸ö¾ßÓдú±íÐԵļÓÃÜľÂí£¨Encrypting Trojan horse£©¾ÙÐÐÆÊÎö £¬Í¨Ì«¹ýÎö¿ÉÒÔ¿´µ½ÆäÍêÕûµÄÖ´ÐÐÀú³Ì¡£Ñù±¾Í¨³£ÊÇÒ»¸ö¿ÉÖ´ÐÐÎļþ £¬¿ÉÄÜÆäͼ±êÀàËÆword.exe³ÌÐò £¬Ö´Ðкó»áÌìÉúÁ½¸ö½ÏÁ¿µÄÒªº¦µÄÎļþqq.exeÒÔ¼°Bundle.rdbÎļþ¡£

2

ËæºóÏòIPµØµã193.169.244.73ÌᳫÅþÁ¬

3

ͨ¹ý×·×Ù¶ÔÓ¦µÄIPµØµã £¬·¢Ã÷ÆäËùÔÚÇøÓò¼°°ó¶¨ÓòÃûÀ´×ÔÎÚ¿ËÀ¼ £¬ÏÖÔÚÓòÃûÒ³Ãæ»ñÈ¡ÒѾ­Ê§Ð§ £¬µ«²»É¨³ýÓÐÏà¹ØµÄ·´×·×ÙÊÖÒÕÊֶΡ£¶ø´ÓÒÑÍùµÄÒ»Á¬¸ú×ÙÇéÐÎÀ´¿´ £¬ÃÀ¹úºÍÎÚ¿ËÀ¼µÄÓòÃû½Ï¶à¡£

4


Ñù±¾Õû¸öÍêÕûµÄÖ´ÐÐÀú³ÌÈçÏ£º


1   µã»÷Ö®ºóÑù±¾»áÊͷųöÐÎÈçXXXX.tmpµÄÎļþ²¢ÔËÐÐ £»
2   ¸ÃÎļþÊ×ÏÈ»áÊÍ·ÅÒ»¸öÕý³£µÄdocÎļþÔËÐÐ £¬ÓÃÒÔÒÉ»óͨË×Óû§ £»
3   È»ºóÊÍÃûΪqq.exeºÍBundle.rdbµÄÁ½¸öÎļþ £»
4   Óû§Ò»µ©ÔËÐÐÁË¡±qq.exe¡± £»
5   Õâ¸öÀî¹í¾Í»á½«Bundle.rdbÎļþ×¢Èëµ½Ò»¸ö½©Ê¬Àú³ÌÖÐ £»
6   Bundle.rdbʵÏÖÓë¹¥»÷ÕߵķþÎñÆ÷¾ÙÐн»»¥¡£

5

ÏÂÃæÎÒÃǽ«ÆäÖеÄһЩ׷×ÙµÄÊÖÒÕϸ½Ú·ºÆð³öÀ´ £¬Í¨¹ýÕâЩϸ½Ú·ºÆð £¬ÓÐÀûÓÚºóÐø¶Ô¸ÃľÂí¾ÙÐвéɱºÍ·À»¤ £¬ÒÔ¼°ÎªÕûÌåÆÊÎö¹¥»÷×éÖ¯µÄÐÐΪÌṩÐÅÏ¢¼°Êý¾ÝÖ§³Ö¡£

ľÂíÑù±¾Èë¿ÚÆÊÎö

Ñù±¾ÐÅÏ¢

6

7

´Ó½Ø»ñµÄÑùÔ­À´¿´ £¬¸ÃÑù±¾Î±×°ÎªwordÎĵµ £¬ÒýÓÕÓû§È¥µã»÷ £¬¶øÈö²¥Í¾¾¶Ò²Ö÷Ҫͨ¹ýÓʼþ´«Êä £¬UÅÌ¿½±´µÈÐÎʽÈö²¥¡£Ïȼì²é¸ÃÑù±¾ÓÐûÓмӿÇ¡£

8

Ò²¾ÍÊÇ˵¸ÃÑù±¾²¢Ã»ÓнÓÄɹŰåµÄ¼Ó¿ÇÊÖÒÕÀ´Ìӱܲ鶾Èí¼þµÄ²éɱ £¬¶øÊǽÓÄÉÁËÆäËû¼ÓÃܵķ½·¨À´ÈƹýɨÃè¡£

²éÕÒľÂí³ÌÐòÈë¿Ú

9

ÉÏͼÊÇIDA·´»ã±àºó £¬½ØÈ¡µÄwinmainº¯ÊýµÄÖ÷Òª²¿·Ö £¬´ÓͼÖиÅÂÔ¿ÉÒÔ¿´³ö¸ÃÑù±¾ÔËÐÐʱ»á¼ì²âÏÂÁî²ÎÊý×îÏȲ¿·ÖÊÇ·ñº¬ÓС±¨Cping¡±×Ö·û´®¡£ÈôÊÇÓиòÎÊý»áÖ±½Ó½øÈëSUB_40CF20º¯ÊýÖÐÔËÐÐ £»ÈôÊÇûÓиòÎÊý £¬Ö®ºó»á½¨ÉèÔÝʱÎļþ £¬²¢Í¨¹ýCreateProcessWº¯ÊýÒÔÐÂÀú³ÌµÄ·½·¨Æô¶¯¸ÃÔÝʱÎļþ£¨Ò²¾ÍÊÇ×ÓÌ壩¡£
½ÓÏÂÀ´ÎÒÃÇÆÊÎöÁ½¸ö·½Ã棺

-¹Ø×¢¸ÃľÂí£¨Ä¸Ì壩½¨ÉèµÄÊÇʲôÔÝʱÎļþ£¨×ÓÌ壩 £¬×ÓÌåµÄÆô¶¯²ÎÊýÊÇʲô£¨Í¼Öиø³öµÄcommandline£© -ÈôÊÇĸÌåûÓвÎÊý¡°¨Cping¡±ÇéÐÎ £¬ÔÚsub_40cf20º¯ÊýÄÚÀï×öʲôÐж¯

ĸÌåÖ´ÐÐÀú³Ì

ÆÊÎöĸÌåÈë¿Ú

ÆÊÎöµ½ÕâÀï £¬ÎÒÃÇÖ»ÖªµÀ¸ÃÑù±¾Òª´øÓС±¨Cping¡± £¬¿ÉÊÇ»¹²»ÖªµÀ¾¿¾¹ÓÐʲô²ÎÊý £»ÄÇôÄÜ×öµÄ¾ÍÊÇÖ±½ÓÔÚÐéÄâ»úÖÐÆô¶¯Ëü £¬²»Ðè´øÓÐÈκβÎÊý £¬Æ¾Ö¤ÎÒÃǵľ²Ì¬ÆÊÎö¿ÉÖª £¬ÕâÖÖÇéÐÎÏ»áÏÈÌìÉúÒ»¸ö×ÓÌå £¬È»ºóͨ¹ýCreateProcessWÀ´Æô¶¯¸Ã×ÓÌå.

Æô¶¯windbg £¬ËäȻ֪µÀÁËĸÌåÄÚÀïÓÐwinmainº¯Êý £¬¿ÉÊÇÔÚûÓзûºÅÎļþµÄÇéÐÎÏÂwindbg»¹²»¿Éʶ±ð³öwinmainÈë¿Úº¯Êý £¬ÒÔÊÇÔÚwindbg¼ÓÔØÄ¸Ìåºó £¬ÐèÒªÕÒµ½Ò»¸ö¶ÏµãÀ´¶¯Ì¬µ÷ÊÔwinmainº¯Êý¡£Í¨¹ýIDA·´»ã±àÖªµÀ £¬ÔÚwinmainº¯ÊýÄÚÀïÏÈÊÇŲÓÃÁËÒ»¸öAPIº¯ÊýGetComputerNameA¡£

10

ÔÚÔËÐÐGÏÂÁîºÅ»á¶ÏÔÚ´Ë´¦ £¬ÈçÏÂͼËùʾ

11

Éó²é¸Ãº¯ÊýµÄ²ÎÊý

12

ÓÃGUÏÂÁî¸Ãº¯ÊýÔËÐÐÍê³Éºó £¬¿ÉÒÔ¿´µ½¸Ãº¯ÊýÒѾ­È¡µÃÁËÖ÷»úÃû £¬ÈçÏÂͼ£º

13

¹ØÓÚÐéÄâ»úϵͳ£º

14

½ÓÏÂÀ´»á½«´óд×ÖĸÄð³ÉÄð³ÉСд £¬ÈçÏÂͼ

0

ת»»ºóµÄЧ¹û£º

16

Ö®ºó»áͨ¹ýCoInitializeº¯Êý¸æËßWindowsÒÔµ¥Ï̵߳ķ½·¨½¨Éècom¹¤¾ß £¬CoInitialize²¢²»×°ÔØCOM ¿â £¬ËüÖ»ÓÃÀ´³õʼ»¯Ä¿½ñÏß³Ì £¬ÈÃÏß³Ì×¢²áÒ»¸öÌ×¼þ £¬¶øÏß³ÌÔËÐÐÀú³ÌÖÐÒ»¶¨ÔÚ´ËÌ×¼þ¡£ÈçÏÂͼ£º

17

ĸÌåÔõÑù±¬·¢×ÓÌå

ÏÂÃæµÄÐж¯¾ÍÊÇÒªÅжÏËüÆô¶¯Ê±ÊÇ·ñ´øÓвÎÊý £¬ÈôÊÇûÓвÎÊý¾Í»áÔÚÔÝʱÎļþ¼Ð½¨ÉèÒ»¸öÎļþ

18

ÏÔʾ»ñȡĿ½ñÓû§µÄÔÝʱĿ¼ £¬Ö®ºó»áÔÚ¸ÃĿ¼Ï±¬·¢Ò»¸öËæ»úÎļþÃû¡£

19

ÔÚ½¨ÉèÁËÔÝʱÎļþºó £¬½ÓמͻáÏÈ»ñµÃĸÌåÎļþ £¬Í¬Ê±±¬·¢Ò»¸öËæ»ú×Ö·û´® £¬¸ÃËæ»ú×Ö·û´®»á×÷ΪδÀ´×ÓÌåÆô¶¯Ê±²ÎÊý²¿·Ö £¬Ö®ºó½«Êͷű¬·¢µÄ×ÓÌå£¨Ç°ÃæÖ»ÊDZ¬·¢ÔÝʱÎļþ»¹Ã»ÓÐдÈëÊý¾Ý £¬¾ÍÊÇҪдÈëÊý¾Ý £¬Ð´ÈëµÄ´ó²¿·ÖÄÚÈÝÕÕ¾ÉĸÌåµÄÊý¾Ý£© £¬Í¬Ê±Ôڽṹ³öCreateProcessWº¯ÊýÆô¶¯×ÓÌå³ÌÐòʱµÄ²ÎÊý²¿·Ö¡£ÈëÏÂͼ

20

×ÓÌåÌÓ±Üɱ¶¾Èí¼þ

µ±±¬·¢ÐµÄÎļþʱ £¬É±¶¾Èí¼þͨ³£¶¼ÓÐÓÐËù¾õ²ì £¬ÎªÁËÄÜÌӱܹŰåɱ¶¾Èí¼þµÄ²éɱ £¬ÔÚÌìÉú×ÓÌåʱ £¬Ê¹ÓÃÁ˼ÓÃÜÊÖÒÕ¶Ô×ÓÌå×öÁË¿é¼ÓÃÜ¡£ÏÂÃæÊǺ¯ÊýSUB_40AFF0±¬·¢Ëæ»ú×Ö·û´®µÄÖ÷ÒªÀú³Ì £¬

21

ÓÉÏÂͼ¿ÉÖª £¬ÔÚ¸´ÖÆÄ¸ÌåÀú³ÌÖжÔĸÌå×Ô¼ºÏÈ×öÁË´¦Öóͷ£ £¬º¯ÊýSUB_40CEA0ŲÓÃSUB_40CB30 £¬¸Ãº¯ÊýÔÚ¸´ÖÆÐ´Èë֮ǰ¶ÔĸÌå×öµÄ´¦Öóͷ£ £¬Å²ÓÃÀú³ÌºÍ´¦Öóͷ£Àú³ÌÈçÏÂͼ£º

22

23

ÓÉÏÂͼ¿ÉÖª £¬ÔÚ¸´ÖÆÄ¸ÌåÀú³ÌÖжÔĸÌå×Ô¼ºÏÈ×öÁË´¦Öóͷ£ £¬º¯ÊýSUB_40CEA0ŲÓÃSUB_40CB30 £¬¸Ãº¯ÊýÔÚ¸´ÖÆÐ´Èë֮ǰ¶ÔĸÌå×öµÄ´¦Öóͷ£ £¬Å²ÓÃÀú³ÌºÍ´¦Öóͷ£Àú³ÌÈçÏÂͼ£º

24

×ÓÌåÌÓ±Üɱ¶¾Èí¼þ

µ±±¬·¢ÐµÄÎļþʱ £¬É±¶¾Èí¼þͨ³£¶¼ÓÐÓÐËù¾õ²ì £¬ÎªÁËÄÜÌӱܹŰåɱ¶¾Èí¼þµÄ²éɱ £¬ÔÚÌìÉú×ÓÌåʱ £¬Ê¹ÓÃÁ˼ÓÃÜÊÖÒÕ¶Ô×ÓÌå×öÁË¿é¼ÓÃÜ¡£ÏÂÃæÊǺ¯ÊýSUB_40AFF0±¬·¢Ëæ»ú×Ö·û´®µÄÖ÷ÒªÀú³Ì £¬

25

ÓÉÏÂͼ¿ÉÖª £¬ÔÚ¸´ÖÆÄ¸ÌåÀú³ÌÖжÔĸÌå×Ô¼ºÏÈ×öÁË´¦Öóͷ£ £¬º¯ÊýSUB_40CEA0ŲÓÃSUB_40CB30 £¬¸Ãº¯ÊýÔÚ¸´ÖÆÐ´Èë֮ǰ¶ÔĸÌå×öµÄ´¦Öóͷ£ £¬Å²ÓÃÀú³ÌºÍ´¦Öóͷ£Àú³ÌÈçÏÂͼ£º

26

27

½ÓÏÂÀ´¾ÍÊÇÒª½¨ÉèÒ»¸ö×ÓÀú³Ì£¨×ÓÌ壩 £¬Í¬Ê±¼ì²éÆô¶¯µÄ¸Ã×ÓÌåºÍ²ÎÊý

28

29

´ÓÉÏͼ¿ÉÖªcreateprocesswµÚÒ»¸ö²ÎÊýÊÇ¡±c:UsershomeAppDataLocalTempDBE3.tmp¡±µÚ¶þ¸ö²ÎÊýÊÇ¡± ¡°C:UsershomeAppDataLocalTempDBE3.tmp¡± ¨CpingC:ocean est.exe 98A92D9A03B32BBB789802827DD0F5FB245F07A28BE4E9251E55C06A43DAA994A0852C6623D4FEB93139B4A028463B7BF27F727372E5813871AFD7D01AB44430¡±

Ò²¾ÍÊÇ×ÓÌåÃû×Ö½ÐDBE3.tmp£¨ÔÚ¶à´Îµ÷ÊÔÀú³ÌÖÐ £¬Ã¿´Î±¬·¢µÄÔÝʱÎļþ¶¼·×ÆçÑù£© £¬±¬·¢µÄËæ»ú×Ö·û´®×Åʵ̫³¤ÁË¡£

×ÓÌåÖ´ÐÐÀú³Ì

ÆÊÎö×ÓÌåÈë¿Ú

µ½ÏÖÔÚΪֹ £¬Ä¸ÌåµÄÆô¶¯Àú³Ì»ù±¾ÉÏÆÊÎöÍê³ÉÁË £¬ÎÒÃÇÔÚ×îÏÈ˵µ½ÈôÊÇÓСªping²ÎÊý¼°ÆäËû²¿·Ö £¬»á½øÈëSUB_40CF20º¯Êý¡£ÈçÏÂͼ

30

ÓÉÓÚÎÒÃDz¢²»ÖªµÀĸÌå²ÎÊýpingºóÃæÏêϸ½ÓʲôÄÚÈÝ £¬ÒÔÊDz»ÓëÆÊÎö¡£×Åʵ²»±Øµ¥¶À½ñÌìÆÊÎöelseºóÃæµÄÄÚÈÝ £¬ÓÉÓÚÎÒÃÇÖªµÀÁË×ÓÌåÖ÷Òª¸´ÖÆÁËĸÌåµÄ³ÌÐò £¬²¢Ìí¼ÓÁË×ÓÌåÆô¶¯Ê±µÄ²ÎÊý £¬Í¨¹ýcreateprocessWº¯ÊýÆô¶¯×ÓÌåʱ £¬×ÓÌå»áÖ±½Ó½øÈëelseÄÚÀï £¬ÓÉÓÚÏÖÔÚÒѾ­ÓС±¨Cping¡±²ÎÊýÁË¡£ÒÔÊÇÎÒÃÇÆÊÎö×ÓÌå¾Í»áÆÊÎöµ½¸Ã·ÖÖ§¡£
×ÓÌåÆÊÎö £¬ÔÚÉÏÃæÒѾ­ÖªµÀÁË×ÓÌåʱÓÉĸÌ叴֯¶øÀ´ £¬²¢ÇÒÔÚ×ÓÌåÆô¶¯Ê±ÒѾ­ÓÐÁ˲ÎÊý £¬Æ¾Ö¤winmainº¯ÊýµÄ´úÂëÁ÷³Ì¿ÉÖª £¬×ÓÌå»á½øÈë

31

×ÓÌåÈë¿Ú¶¯Ì¬¸ú×Ù

½ÓÏÂÀ´¾ÍÊÇÒª¿´º¯ÊýSUB_40CF20ÄÚÀï×öÁËÄÄЩ²Ù×÷¡£ ÒÔÉÏÃæ»ñµÃµÄ×ÓͼDBE3.tmpΪÀý £¬ÔÚwindbgµ÷ÊÔ´ø²ÎÊýµÄ×ÓÌå¿ÉÒÔÏñÈçÏÂÉèÖÃ

32

ΪÁËÄܹ»¶¯Ì¬µ÷ÊÔ×Óº¯Êýsub_40CF20 £¬ÐèÒªÔڸú¯Êý³ö϶ϵã £¬¿ÉÊÇÓÉÓڸú¯Êý²»ÊDZê×¼µÄAPIº¯Êý £¬ÒÔÊÇҲûÓзûºÅ±í £¬ÕâÑùºÜÄÑÕÒµ½¸Ãº¯ÊýµÄÈë¿ÚµØµã¡£¶Ô´ËÎÒÃÇͨ¹ýÊÓ²ìIDA½ñÌì·´»ã±à´úÂë £¬¿ÉÖªsub_40CF20ÔÚCoInitializeºÍmemicmpº¯ÊýÖ®ºó»á±»Å²Óà £¬ÒÔÊÇÎÒÃÇ¿ÉÒÔÔÚ±ê×¼API _memicmp»òÊÇËü֮ǰµÄCoInitializeº¯Êý϶ϵã £¬È»ºó¶¯Ì¬¸ú½øsub_40CF20º¯Êý¼´¿É¡£±¾ÀýÔÚCoInitialize϶ϵã

33

º¯Êý¶ÏÏÂÀ´ºóµ¥²½¸ú×Ù £¬¸ú½øIDA¾²Ì¬ÆÊÎö_memicmp½ÏÁ¿ÓÐûÓС±¨Cping¡± £¬ÈôÊÇÓеϰ¾Í»áÖ´Ðе½sub_40CF20º¯Êý £¬ÓÉÓÚ×ÓÌåÄÚÀï°üÀ¨Á˸òÎÊý £¬Ò²¾ÍÄÜÖ±½Ó½øÈëelseÄÚÀï £¬Éó²éαCºÍ·´»ã±à´úÂë

34

35

µ¥²½¶¯Ì¬¸ú×Ùwindbg £¬½øÈëJZ loc_40D6EE

36

½øÈëelseÄÚÀïÊ×ÏÈsleep(0x7d0)Ö»ÓÐŲÓÃsub_40CF20 £¬²¢½«×ÓÌå²ÎÊý×÷Ϊ¸Ã¸Ãº¯ÊýµÄ²ÎÊý´«½øÈ¥ £¬¸ú½ø¸Ãº¯Êý

37

¸Ãº¯ÊýÄÚ²¿×öµÄ²Ù×÷:

38

ÑéÖ¤×ÓÌå²ÎÊýÖÐÊÇ·ñ°üÀ¨¡± ¡± £¬Ò²¾ÍÊÇ˵ÔÚÆô¶¯×ÓÌåʱ £¬

39

´Ë´¦²ÎÊýÖ®¼äµÄÖ§½â²»¿ÉÊǿոñ £¬±ØÐèÊÇ¡± ¡± £¬ÌìÉútest.exeÌìÉútest.docxÎĵµ

40

×ÓÌåÊÍ·ÅdocxÎĵµÀú³Ì

ÉÏÃæËµµ½sub_40BBA0º¯Êý³ÉÁËdocxÎĵµ £¬ÄÇôÊÇÔõôÌìÉúµÄ £¬ÆäŲÓÃÀú³ÌÈçÏÂͼ

41

Ò²¾ÍÊÇ˵×îÖÕŲÓÃÁ˺¯Êýsub_40B9A0º¯Êý £¬ÄǾͿ´¿´¸Ãº¯ÊýµÄÖ÷ÒªÁ÷³Ì£º

42

ÉÏͼÊǽØÍ¼¸Ã»¹º¯ÊýµÄÖ÷Òª´úÂë £¬´Ó´úÂëÖпÉÖª¸Ãº¯ÊýʹÓÃtest.exe £¬ÌìÉúÁËtest.docxÎĵµ £¬²¢·­¿ªÁ˸ÃÎĵµ £¬Õâ¾ÍÊÇΪʲôÈôÊÇÎÒÃǼӲÎÊýÖ±½Ó·­¿ªDBE3.tmpÎļþʱ £¬ÌìÉúµÄtest.docxÄܹ»×Ô¶¯·­¿ªµÄÔµ¹ÊÔ­ÓÉ¡£

43

×ÓÌåµÄ·´µ÷ÊÔÊÖÒÕ

ΪÁËÄܹ»±Ü¿ªÐéÄâ»ú¼ì²â»òÊÇÔÚÐéÄâ»úÖе÷ÊÔ £¬×ÓÌåÖмÓÈ붯̬·´µ÷ÊÔÊÖÒÕ £¬ÅжÏÊÇ·ñÓÐÐéÄâ»ú

44

º¯ÊýŲÓùØÏµÈçÉÏͼËùʾ £¬ÔÚº¯ÊýÄÚÀï×öÁËÐéÄâ»úµÄÅжÏ

45

´Ó´úÂëÖп´³ö £¬¸Ã×ÓÌå»áÅжÏ×Ô¼ºÊÇ·ñÔÚÐéÄâ»úÖÐ £»½øÒ»²½¸ú×Ùsub_407260¿´¿´ÅжÏvmwareÄÚÀïÊÇÔõô²Ù×÷µÄ£º

46

VmwareÎªÕæÖ÷»úÓëÐéÄâ»úÖ®¼äÌṩÁËÏàÏ໥ͬµÄͨѶ»úÖÆ £¬ËüʹÓá°IN¡±Ö¸ÁîÀ´¶ÁÈ¡ÌØ¶¨¶Ë¿ÚµÄÊý¾ÝÒÔ¾ÙÐÐÁ½»úͨѶ £¬µ«ÓÉÓÚINÖ¸ÁîÊôÓÚÌØÈ¨Ö¸Áî £¬ÔÚ´¦ÓÚ± £»¤Ä£Ê½ÏµÄÕæ»úÉÏÖ´ÐдËÖ¸Áîʱ £¬³ý·ÇȨÏÞÔÊÐí £¬²»È»½«»á´¥·¢ÀàÐÍΪ¡°EXCEPTION_PRIV_INSTRUCTION¡±µÄÒì³£ £¬¶øÔÚÐéÄâ»úÖв¢²»»á±¬·¢Òì³£ £¬ÔÚÖ¸¶¨¹¦Ð§ºÅ0A£¨»ñÈ¡VMware°æ±¾£©µÄÇéÐÎÏ £¬Ëü»áÔÚEBXÖзµ»ØÆä°æ±¾ºÅ¡°VMXH¡±¡£

ÌÓ±ÜÐéÄâ»ú¼ì²â»úÖÆ

¾­ÓÉÉÏÃæµÄÆÊÎö £¬ÎÒÃÇÖªµÀÁËÔÚÐéÄâÖÐÔËÐлáÖ±½ÓÍ˳ö £¬ÓÉÓÚº¯Êýsub_40B840Ö´ÐÐÍê³Éºó·µ»Øºó £¬·µ»ØÁË1 £»Í¬Ê±º¯Êýsub_40B930Ò²¾Í·µ»ØÁË1 £»ÕâÑù×ÓÌå¾Í»áÖÕÖ¹ÁËÔËÐÐ £¬ÈçÏÂͼ

47

µ«ÎªÁËÔÚÐéÄâ»úÖÐÆÊÎö×ÓÌå £¬ÊÖÒÕְԱʹÓö¯Ì¬µ÷ÊÔÊÖÒÕ £¬Ð޸ĴúÂëÁ÷³Ì £¬ÔÚsub_40B930·µ»Øºó £¬Ð޸ķµ»ØÖµÈÃÆä¼ÌÐøÔËÐÐ £¬ÈçÏÂͼËùʾ

48

ÕâÑù³ÌÐò¾ÍÄܽøÈëifÓï¾äÄÚÀï¼ÌÐøÔËÐС£½ÓÏÂÀ´×öµÄÊÂÇé¾ÍÊÇÆÊÎö²ÎÊý²¿·ÖµÄËæ»ú×Ö·û´®²¢×ª»¯±àÂë

49

ÔÚ±àÂëת»»Íê³Éºó £¬×îÏȽâÃÜÎļþ¡£Ç°ÃæËµ¹ý £¬Ä¸ÌåÔÚÌìÉú×ÓÌåʱ»á×ö´¦Öóͷ£ºóÌìÉú×ÓÌå £¬¸Ã´¦Öóͷ£¾ÍÊÇ·Ö¿é¼ÓÃܵÄÀú³Ì¡£ÏÂÃæÊÇÏÈÆ¾Ö¤²ÎÊýÖеÄËæ»ú×Ö·û´®ÌìÉú½âÃÜÃØÔ¿ £¬È»ºóÔÚ¾ÙÐнâÃÜ¡£

50

½ÓÏÂÀ´»á±éÀúÀú³ÌÁбí £¬¹Ø±ÕÏà¹ØÀú³Ì¡£ÔÚ½âÃÜÍê³Éºó £¬½øÈ뺯Êýsub_40C6F0ÄÚÀï £¬±éÀúÀú³ÌÁбíÈçÏÂͼ

51

ͬʱÔÚº¯ÊýÄÚÀïsub_40C6F0ÄÚÀïÍê³ÉÀú³Ì±éÀúÊÂÇé £¬Æä×îÖÕŲÓÃÁËsub_40B380

52

¸ÃÕÕ¾É×îÏÈÏÔʾ±éÀúϵͳÀú³Ì £¬²¢È¡µÃhashÖµ £¬ÓëÖ¸¶¨µÄÖµ½ÏÁ¿ £¬ÈôÊÇÏàµÈÔò¹Ø±Õ¸ÃÀú³Ì¡£

53

54

55

ÊÍ·Åqq.exe¼°bundle.rdbÎļþ

ΪÁËÄܹ»ÒÉ»óÓû§ £¬Ñù±¾ÔÚÌìÉúÖ´ÐÐÎļþʱ £¬ÌØÒâÃüÃûΪqq.exe;ÔÚŲÓùØÏµÍ¼ÖеÄsub_40B790º¯Êý·µ»Øºó £¬¾Í»áŲÓÃsub_40c260º¯ÊýÌìÉúqq.exeÎļþ £¬ÈçÏÂͼ

56

¸Ãº¯ÊýÔÚÄÚ²¿Å²ÓÃsub_40BE40À´ÌìÉúQQ.exe

57

ÊÍ·ÅΪ¹ú¼Ê°æµÄQQ.exe £¬º£ÄÚµÄÓû§Í¨³£²»»áʹÓÃÕâ¸ö°æ±¾ £¬²»ÖªµÀÊǹ¥»÷ÕßµÄÊèºöÕÕ¾ÉÓÐÆäËûµÄÄ¿µÄ¡£

58

Ö®ºóÔÚÔÙ´ÎŲÓøú¯ÊýÌìÉúbundle.rdbÎļþ £¬´«ÈëµÄ²ÎÊý±¬·¢ÁËת±ä

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼ £¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼