¡°°×Ïó¡±APT×éÖ¯½üÆÚ¶¯Ì¬·ÖÎö³ÂËß

Ðû²¼Ê±¼ä 2018-03-31

¡°°×Ïó¡±ÓÖÃû¡°Patchwork¡±£¬¡°Ä¦Ú­²Ý¡±£¬ÒÉËÆÀ´×ÔÄÏÑÇij¹ú£¬×Ô2012ÄêÒÔÀ´Á¬ÐøÕë¶ÔÖйú¡¢°Í»ù˹̹µÈ¹ú½øÐÐÍøÂç¹¥»÷£¬ºã¾ÃÇÔȡĿ±ê¹ú¼ÒµÄ¿ÆÑС¢¾üÊÂ×ÊÁÏ¡£ÓëÆäËû×éÖ¯²îÒìµÄÊÇ£¬¸Ã×éÖ¯·Ç³£É󤯾¾Ý²îÒìµÄ¹¥»÷Ä¿±êαÔì²îÒì°æ±¾µÄÏà¹Ø¾üÊ¡¢ÕþÖÎÐÅÏ¢£¬ÒÔ½øÐÐÏÂÒ»²½µÄ¹¥»÷ÉøÍ¸¡£

 

2017ÄêϰëÄêÒÔÀ´£¬ÎÒÃÇ·¢ÏÖÁ˶àÆðÓë°×Ïó×éÖ¯Ïà¹ØµÄ×îй¥»÷ʼþ¡£¸Ã×é֯ͨ¹ýÓã²æÊ½µöÓãÓʼþ£¬²¢ÅäºÏÉç»á¹¤³ÌѧÊÖ¶ÎÔÚÓʼþÖз¢ËÍ´øÓиñʽ©¶´ÎĵµµÄÁ´½Ó£¬ÓÕµ¼Êܺ¦È˵ã»÷ÏÂÔØ²¢µã»÷£¬Â©¶´´¥·¢Àֳɺ󣬻áÏÂÔØQuasar£¬BADNEWSµÈ±äÖÖÔ¶¿ØÄ¾Âí¡£


 ¹¥»÷ʼþ·ÖÎö

 

 ¹¥»÷ʼþA

 

µÚÒ»´Î¼¯Öй¥»÷ʼþ·¢ÉúÔÚ2017Äê11Ô·Ý×óÓÒ£¬ÎÒÃÇ¼à¿Øµ½¸Ã×éÖ¯ÌᳫÁ˶à´ÎÓã²æÓʼþ¹¥»÷¡£Ïà¹Ø°¸ÀýÈçÏ£º

 

1.ʹÓÃÓʼþͶ·ÅÃûΪChina_Strategic_ChainµÄdocxÎĵµ£¬²¢ÔÚÓʼþÖÐÎĵµÄÚÈݽøÐÐÂÛÊö£¬ÒýÓÕÓû§µã»÷´ò¿ª¡£

 

2.µ±Óû§´ò¿ª¸ÃÎĵµºó£¬ÏÔʾÌáʾÔÚÊäÈëÀ¸ÊäÈëÃÜÂëKEY£¬ÔÙµã»÷×óÉÏ·½µÄͼ±ê¼´¿ÉÍê³É½âËø¡£Êµ¼ÊÉϸÃÊäÈëÀ¸ÎªÎı¾¿ò£¬ÇÒͼ±êΪÄÚǶµÄOLE¹¤¾ß£¬¸Ã¹¤¾ßÔÚµã»÷ºó±ã»á´¥·¢¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

3. ͨ¹ýÌáÈ¡ÄÚǶµÄOLE¹¤¾ßÄÚÈÝ£¬·¢ÏÖÆäÊÇÒ»¸öÃûΪStart_chain_1µÄppsx¸ñʽµÄpptÎĵµ£¬µã»÷¼´¿É×Ô¶¯²¥·Åppt¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

4.¸ÃppsxÎĵµÀûÓÃÁËCVE-2017-0199µÄ©¶´£¬×Ô¶¯²¥·Åpptºó¼´¿É´¥·¢£¬²¢ÏÂÔØÔËÐÐÒ»¸ösct½Å±¾¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

5.sct½Å±¾½âÃܺó»áµ÷ÓÃPowershellÏÂÔØ²¢ÔËÐÐputty.exeºÍ×Ô¶¯¼ÓÔØStrategic_Chain.pdf£¬ÈÃÓû§ÎóÒÔΪÒѾ­´ò¿ªÏà¹ØÎĵµÀֳɡ£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

6.³ýÉÏÊöʼþÖ®Í⣬¸Ã×é֯ͨ¹ýÓʼþ»¹·¢ËÍÒ»·âÃûΪEntanglementµÄppsxµÄÎĵµ£¬ÎĵµÍ¬ÑùʹÓÃÁËCVE-2017-0199©¶´£¬ÀûÓÃÊÖ·¨ÓëµÚÒ»Æð¹¥»÷ʼþÀàËÆ¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

7.ÓëÆäËû¹¥»÷ʼþ²îÒìµÄÊÇ£¬Óû§´ò¿ª¸ÃppsxÎĵµ²¢´¥·¢Â©¶´ºó£¬»áͨ¹ýPowershellÏÂÔØÒ»·ÝÃûΪdecoyµÄppt²¢±»Powerpoint¼ÓÔØÆðÀ´¡£

 

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú


 

¹¥»÷ʼþB

 

µÚ¶þ´Î¼¯Öй¥»÷ʼþ·¢ÉúÔÚ2018Äê3Ô£¬Í¶·ÅµÄÎĵµÖ÷ÒªÀûÓÃCVE-2017-8570©¶´½øÐй¥»÷£¬ÎĵµÄÚÈÝÒ²´ó¶àºÍÉç»áÕþÖÎÉú»îÏà¹Ø¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú 


 

 

ÉÏÊö¹¥»÷ÎĵµËùʹÓõĹ¥»÷ÊÖ·¨ÍêÈ«Ïàͬ£¬¶¼°üÂÞ2¸öPackageÀàÐ͵ÄOLE¹¤¾ßºÍ1¸ö½á¹¹»¯´æ´¢ÀàÐ͵ÄOLE¹¤¾ß¡£

ǰÁ½¸öPackageÀàÐ͵ÄOLE¹¤¾ßÀûÓÃPackager.dllµÄ»úÖÆ£¬ÂôÁ¦°ÑÄÚ²¿Ç¶ÈëµÄÎļþÊͷŵ½%TMP%Ŀ¼Ï¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

×îºóÒ»¸öOLE¹¤¾ßÀûÓÃCVE-2017-8570©¶´£¬Í¨¹ýScriptlet Moniker´Ó¶ø¼ÓÔØsctÎļþÖеÄÄÚÈÝ¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

©¶´´¥·¢Àֳɺó£¬×îÖÕ¶¼ÊÐÊͷŲ¢Æô¶¯Ò»¸öÃûΪqratµÄ·¨Ê½¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú


 

¹¥»÷ʼþC

 

ÔÚ¼¸ºõͬÆÚ£¬°×Ïó×éÖ¯»¹ÌᳫÁËÁíÍ⼸Æð¹¥»÷ʼþ£¬ÕâЩ¹¥»÷ʼþÖ÷ÒªÀûÓÃÁËCVE-2015-2545ºÍCVE-2017-0261©¶´Îĵµ½øÐеöÓãÓʼþ¹¥»÷¡£Í¶·ÅµÄ©¶´ÎļþÖÖÉæ¼°Èô¸ÉÖ÷Ì⣬ÆäÖаüÂÞ°Í»ù˹̹½¾ü×î½üµÄ¾üÊ´ٽø»î¶¯£¬Óë°Í»ù˹̹ԭ×ÓÄÜίԱ»áÓйصÄÐÅÏ¢µÈ¡£Ïà¹ØÂ©¶´Îĵµ´¥·¢ºó»áÊÍ·Åа汾µÄBADNEWSϵÁÐľÂí¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 
ľÂí·ÖÎö

 

ÔÚÉÏÊö¼¸Æð¹¥»÷ʼþÖУ¬ÏÂÔØ£¨ÊÍ·Å£©µÄľÂíÖ÷ÒªÓÐQuasarRATºÍBADNEWSÁ½ÖÖ¡£

 

QuasarRATľÂí

 

ÔÚ¹¥»÷ʼþAºÍ¹¥»÷ʼþBÖУ¬ÏÂÔØ£¨ÊÍ·Å£©µÄľÂíΪQuasarRAT¡£

 

1.ÊͷŵÄľÂí°æ±¾ÐÅϢαÔì³É΢Èí»òQiho 360µÈ¡£

 

 

 

2.QuasarRATľÂí½ÓÄÉC#±àд£¬µ«×îз¢ÏֵľÂíÍâ²ãÌí¼ÓÁËÒ»¶ÎLoader´úÂë¡£Loader´úÂëµÄÖ÷Òª¹¦Ð§ÊÇ·´¼ì²â·´É³Ï书Ч£¬²¢ÔÚ×îºó¼ÓÔØÔ­Ê¼QuasarRATľÂí¡£QuasarRATľÂí½ÓÄɸßÇ¿¶È»ìÏý´¦Öá£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

3.ÆäÖ÷Òª¹¦Ð§ÓÐÒÔϼ¸¸ö²¿ÃÅ£º

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

4.ÊÕ¼¯ÏµÍ³ÐÅÏ¢¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

5.Ñù±¾ÔÚÊÕ¼¯ÍêÐÅÏ¢ºó£¬ »áʵÑéÁ¬½ÓC&C·þÎñÆ÷¡£
 

×ðÁú¶¶È¦ - Ϊdu¶øÉú


6.×îºó½«ÊÕ¼¯µ½µÄÐéÄâ»·¾³£¬·´²¡¶¾Èí¼þ£¬Ö÷»ú£¬Óû§ÃûµÈÐÅÏ¢·¢Ë͵½C&C·þÎñÆ÷¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 


 


BADNEWSľÂí

ÔÚ¹¥»÷ʼþCÖУ¬ÊͷŵÄľÂíΪBADNEWSľÂí¡£

1.Ïà¹ØÎĵµ´¥·¢Â©¶´ºó»áÊÍ·ÅÈý¸öÎļþ£º

%PROGRAMDATA%\Microsoft\DeviceSync\VMwareCplLauncher.exe
%PROGRAMDATA%\Microsoft\DeviceSync\vmtools.dll
%PROGRAMDATA%\Microsoft\DeviceSync\MSBuild.exe

ÆäÖÐVMwareCplLauncher.exeΪ¾ßÓкϷ¨Êý×ÖÇ©ÃûµÄÎļþ£¬vmtools.dllΪ¾­¹ý¸Ä¶¯µÄdll£¬ÓÃÓÚ×îÖÕ¼ÓÔØBADNEWSµÄ×îбäÖÖMSBuild.exe¡£

2.VMwareCplLauncher.exeÔËÐк󣬻á×Ô¶¯¼ÓÔØvmtools.dll£¬vmtools.dllÖ´Ðкó»á´´½¨Ò»¸öÃûΪBaiduUpdateTask1µÄÈÎÎñ¼Æ»®£¬¸ÃÈÎÎñ¼Æ»®Ã¿¸ôÒ»·ÖÖÓ»áÖ´ÐÐÒ»´ÎMSBuild.exe¡£

3. MSBuild.exeÖ´Ðк󣬻áÏÂÔØ
hxxps://raw.githubusercontent.com/husngilgit/husnahazrt/master/xml.xml

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

È¡³ö¡°[[¡±ºÍ¡°]]¡±ÖмäµÄBase64×Ö·û´®£¬¾­¹ýÁ½´Îbase64½âÂëºÍÊý´Î½âÃܺóµÃµ½Ñù±¾ÐèÒªÁ¬½ÓµÄC&CµØÖ·¡£

 

4. Æ´´ÕÖ÷»úÉÏÏßÐÅÏ¢·¢Ë͵½C&C·þÎñÆ÷Ó²±àÂëµØÖ·¡£Ö÷»úÉÏÏßÐÅÏ¢¸ñʽÈçÏ£ºuuid=[UUID] #un=[µÇ¼Ãû]#cn=[¼ÆËã»úÃû]#on=[²Ù×÷ϵͳ°æ±¾] #lan=[IPµØÖ·]#nop=#ver=1.0¡£²¢Ê¹ÓÃAES¼ÓÃÜËã·¨£¨ÃÜÔ¿£ºDD1876848203D9E10ABCEEC07282FF37£©+base64±àÂë·¢Ë͵½//e3e7e71a0b28b5e96cc492e636722f73//4sVKAOvu3D//ABDYot0NxyG.php

 

5.ÔÚʹÓÃbase64±àÂëºó»¹¶Ô±àÂëºóµÄÊý¾ÝµÄÀÎ¹ÌÆ«ÒÆÎ»ÖõIJåÈ롱=¡±ºÍ¡±&¡±×Ö·û¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

6.ËѼ¯¿Í»§¶Ë·ÇÒÆ¶¯´ÅÅ̵ÄÃô¸ÐÎļþÁбí
£¨.xls£¬.xlsx£¬.doc£¬.docx£¬.ppt£¬.pptx£¬.pdfµÈ£©£¬²¢Éú´æÎªÁÙʱĿ¼ÏµÄedg499.dat¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 

7.´´½¨Ị̈߳¬½«¼üÅ̼ǼÐÅÏ¢£¬´°¿ÚÐÅÏ¢µÈÉú´æÎªÁÙʱĿ¼ÏµÄTPX498.dat¡£

 

8.ÉÏÊöÉú´æÎªdatÎļþµÄÊý¾Ý£¬Í¬ÑùʹÓÃÉÏÊöAES¼ÓÃÜËã·¨+base64±àÂë·¢ËÍ¡£µ«·¢Ë͵ÄÓ²±àÂëµØÖ·±äΪ\e3e7e71a0b28b5e96cc492e636722f73\4sVKAOvu3D\UYEfgEpXAOE.php
 

×ܽá

°×Ïó×é֯ĿǰÖ÷ÒªÍþвĿ±êΪ°Í»ù˹̹ºÍÖйúµÄ´óÃæ»ýÄ¿±ê£¬°üÂÞ½ÌÓý¡¢¾üÊ¡¢¿ÆÑС¢Ã½ÌåµÈÖÖÖÖÄ¿±ê¡£ÆäÏȵ¼¹¥»÷ÊֶζàΪÓã²æÊ½µöÓãÓʼþ£¬·¢ËÍ´øÓиñʽ©¶´ÎĵµµÄÁ´½Ó£¬¶øÇÒÉó¤Î±ÔìÏà¹Ø¾üÊ¡¢ÕþÖÎÐÅÏ¢£¬½ÏΪ¾«Ï¸¡£

Ŀǰ¸Ã×éÖ¯ÒѾ­Éú³¤ÎªÓнϸ߹¥»÷ÄÜÁ¦µÄС·Ö¶Ó£¬ÇÒʹÓõÄ©¶´µÄÊÖ·¨Ò²±ÈÁ¦ÐÂÓ±£¬¶ÔÉç»á¹¤³ÌѧµÄ°ÑÄóÏ൱µÄ¾«ÃÕâ´Ó½üÆÚ¶àÆð¹¥»÷ʼþÖоͿÉÒÔ¿´³ö¡£ ¶ÔÓÚÀàËÆ°×ÏóµÄ¹¥»÷×éÖ¯£¬ÓÉÓÚÀúÀ´¸ü¶àÒÀÀµÀàËÆµç×ÓÓʼþÕâÑùµÄ»¥ÁªÍøÈë¿Ú£¬Æäʵ±¾¿ÉÒԺܺõÄ×öµ½·ÀÓù£¬µ«Í¨¹ýÓÕµ¼ÐÔµÄÓïÑÔÈ´¿ÉÒÔ°ÑÕâЩ·ÀÓù´ëÊ©ÎÞЧ»¯¡£Òò´Ë£¬¼ÓÇ¿¶ÔÈËÔ±µÄÄþ¾²Ë¼Ïë½ÌÓý£¬¿ÉÒԺܺõÄÖÆÖ¹ÀàËÆÄþ¾²Ê¼þµÄ·¢Éú¡£


Ïà¹ØIOC

rannd.org
brokings.org
crazywomen-dating.com
ifenngnews.com
209.58.185.37
mail.ifenngnews.com
chinapolicyanalysis.org
94.242.249.203
209.58.183.33

 
¹ØÓÚ½ð¾¦Äþ¾²Ñо¿ÍŶÓ

 

½ð¾¦Äþ¾²Ñо¿ÍŶÓÊǶ¶È¦Îª¶Ä¶øÉú¼¯Íżì²â²úÎï±¾²¿´ÓÊÂרҵÄþ¾²·ÖÎöµÄ¼¼ÊõÐÍÍŶÓ£¬Ö÷ÒªÖ°ÔðÊǶÔÏÖÓвúÎïÉϱ¨µÄÄþ¾²Ê¼þ¡¢Ñù±¾Êý¾Ý½øÐÐÍÚ¾ò¡¢·ÖÎö£¬²¢ÏòÓû§ÌṩרҵµÄ·ÖÎö³ÂËß¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú

 


¹ØÓÚVenusEyeÍþвÇ鱨ÖÐÐÄ

 

VenusEyeÍþвÇ鱨ÖÐÐÄ£¨www.venuseye.vip£©ÊǶ¶È¦Îª¶Ä¶øÉúÇãÁ¦´òÔìµÄ¼¯ÍþвÇ鱨ÊÕ¼¯¡¢·ÖÎö¡¢´¦Öá¢Ðû²¼ºÍÓ¦ÓÃΪһÌåµÄÍþвÇé±¨ÔÆ·þÎñƽ̨£¬ÌṩÍþвÇ鱨Êý¾Ý¡¢ÏµÍ³¡¢¼¼ÊõºÍרҵÄÜÁ¦µÄÊä³ö¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú