ʵ²â£¡±¦ÔËÀ³¹Ù·½ÍøÕ¾Ìì«‘EDR¹Ø»·¾Ñ»÷¡°º£Á«»¨¡±Ñù±¾

°ä²¼¹¦·ò 2025-11-12

½üÆÚ £¬¸ß¼¶³ÖÐøÐÔÍþв£¨APT£©×éÖ¯¡°º£Á«»¨¡±£¨OceanLotus£©ÔÙ¶È»îÔ¾¡£ÆäͶ·ÅµÄÐÂÐÍÑù±¾Ñ¡È¡¸ß¶ÈÒñ±ÎµÄ¹¥»÷ÊÖ·¨ £¬¶ÔÎÒ¹ú²¿ÃųÁµãÖ¸±êÖ´Ðж¨ÏòÉøÈë £¬¶ÔÆóÒµºÍ»ú¹¹µÄÊý¾Ý°²È«×é³ÉÑϳÁÍþв¡£


¸ÃÑù±¾ÖØÒªÑ¡È¡ÒÔÏÂËÄÀ༼Êõ¼¿Á©£º


Ò»ÊÇÒñ±Î»¯Ö²È룺ÀÄÓúϷ¨MSTÁ÷³Ì £¬¶ã±ÜͨÀý°²È«¼ì²â £»

¶þÊÇÓÆ¾Ã»¯×¤Áô£ºÍ¨¹ý×¢²á±í×ÔÆô¶¯ÏîʵÏÖϵͳ³Ö¾Ã½ÚÔì £»

ÈýÊÇÄڴ滯ִÐУºÑ¡È¡Ä£¿éïοյȼ¼Êõ £¬Æ¥µÐ¶¯¾²Ì¬·ÖÎö £»

ËÄÊÇÄ£¿é»¯Í¨Ñ¶£ºÒÀÀµ¼ÓÃÜÐÄÌø°üÓëC&C·þÎñÆ÷ͨѶ £¬ÊµÏÖÔ¶³Ì²Ù¿Ø¡£


Ãæ¶Ô´ËÀà×éÖ¯ÐÔÇ¿¡¢¼¿Á©Òñ±ÎµÄAPT¹¥»÷ £¬ÊµÏÖ´ÓÈëÇÖ¸ÐÖªµ½ÐÐΪ×è¶ÏµÄÈ«Á´Â··À»¤ £¬ÒѳÉΪÖն˰²È«µÄÖ÷ÌâÌôÕ½¡£


±¾ÎÄ»ùÓÚ±¦ÔËÀ³¹Ù·½ÍøÕ¾Ìì«‘EDR¶Ô¡°º£Á«»¨¡±×îÐÂÑù±¾µÄʵ²â¹ý³Ì £¬½éÉÜÈôºÎÒÀ¸½Æä¡°Î´ÖªÍþв¸ÐÖª¡¢Á¢Ìå·À»¤ÍøÂç¡¢¼±¾çÓ¦¼±ÏìÓ¦¡¢µý±¨Çý¶¯½ø»¯¡±µÈÄÜÁ¦ £¬ÓÐЧӦ¶Ô´ËÀà¸ß¼¶Íþв¡£


ϵͳ´Û¸Äʵʱ¸ÐÖª


¡°º£Á«»¨¡±¹¥»÷ÕßÔËÐкϷ¨µÄWindowsPCHealthCheckSetup.msi×°Öðü £¬¸Ã×°Öðü»áÔÚ%LOCALAPPDATA%Öд´½¨ÃûΪPCHealthCheckµÄÎļþ¼Ð £¬½«×°ÖðüÖеĺϷ¨·¨Ê½PCHealthCheck.exe¸´ÔìÖÁ´Ë¡£¶ø¹¥»÷ÕßÔÚºÅÁîºó°ë²¿ÃŸ½¼ÓµÄmstÎļþ»á±»½âÎö £¬¿ªÊͶñÒâÄ£¿étbs.dllµ½PCHealthCheck.exeµØµãÎļþ¼Ð £¬Í¬Ê±Ôö³¤ÃûΪPCHealthCheckµÄ×ÔÆô¶¯Ïî £¬²¢½«ÆäÖ¸ÏòPCHealthCheck.exeÎļþ¡ £»ùÓڴ˲Ù×÷ £¬¿ÉʵÏֺϷ¨µÄPCHealthCheck.exe¿ª»ú×ÔÆô¶¯ £¬×Ô¶¯¼ÓÔØ¶ñÒâµÄtbs.dllÓë¹¥»÷Õß½øÐÐͨѶ £¬½ÚÔìÊܺ¦Õß»úе¡£


ͼƬ1.png

ͼ1´´½¨ºÏ·¨·¨Ê½ºÍ¶ñÒâDLLÄ£¿é


ͼƬ2.png

ͼ2Ôö³¤³É¹¦µÄ×¢²á±í×ÔÆô¶¯Ïî


Ìì«‘EDRʵʱ¼à¿Ø×¢²á±í×ÔÆô¶¯Ïî¡¢×ÔÆô¶¯Îļþ¼Ó×¢´òË㹤×÷µÈϵͳ¹Ø¼üµØÎ»¸Ä¹Û £¬È·±£¶Ô´ÛתҵΪµÄʵʱÏìÓ¦¡£


Èçͼ3¡¢Í¼4Ëùʾ £¬¹ý³ÌIDΪ2536µÄmsiexec.exe¹ý³Ì½«PCHealthCheck.exeÔö³¤Îª×¢²á±í×ÔÆô¶¯Ïî £¬´¥·¢ÁËÌì«‘EDRϵͳ´Û¸Ä·À»¤Ö°ÄܵÄ×ÔÆô¶¯ÏîÔö³¤¸æ¾¯ £¬ÊµÊ±×½ÄÃÆäÓÆ¾Ã»¯×¤Áô̰ͼ £¬´Ó¹¥»÷Á´µÚÒ»²½¶ôÔìÆäÊæÕ¹¡£


ͼƬ3.png

ͼ3Ìì«‘EDR²úÉú×ÔÆô¶¯ÏîÔö³¤¸æ¾¯


ͼƬ4.png

ͼ4Ìì«‘EDR×ÔÆô¶¯ÏîÔö³¤¸æ¾¯ÏêÇé


¶ñÒâÐÐΪÖÇÄܼø±ðÓë×è¶Ï


¡°º£Á«»¨¡±¹¥»÷ÕßÔÚʹÓÃmsiexec×°ÖÃPCHealthCheckʱ £¬»áÖ¸¶¨ÌØÊâµÄmstÎļþÖ´Ðжî±í²Ù×÷£º¿ªÊͶñÒâÄ£¿étbs.dllµ½PCHealthCheck.exeµØµãÎļþ¼Ð £¬Ôö³¤ÃûΪPCHealthCheckµÄ×ÔÆô¶¯Ïî £¬²¢½«ÆäÖ¸ÏòPCHealthCheck.exeÎļþ¡£


ͼƬ5.png

ͼ5MsiExec.exe½âÎömstÎļþºóµÄдÎļþ¡¢×¢²á±í²Ù×÷


Ìì«‘EDRÒÀ¸½ÄÚÖÃÐÐΪÒýÇæ £¬Äܹ»¶Ô¹ý³ÌµÄÎļþÐÐΪ¡¢×¢²á±íÏîÐÐΪ¡¢¹ý³ÌÐÐΪµÈ½øÐÐ×ÛºÏÆÀ¹À £¬Ò»µ©×ÛºÏÆÀ¹À´ïµ½Ãô¸ÐÐÐΪ¹æ¶¨ãÐÖµ £¬ÔòÅжϸÃÖ´ÐÐÎļþΪ¶ñÒâÎļþ¡£


Èçͼ6¡¢Í¼7Ëùʾ £¬¡°º£Á«»¨¡±¹¥»÷ÕßÔÚʹÓÃmsiexec×°ÖÃPCHealthCheckʱ £¬Ö¸¶¨ÌØÊâµÄmstÎļþÖ´ÐÐÁ˶î±í²Ù×÷¡£Ìì«‘EDR¾ÍÄܹ»»ùÓÚÎļþÐÐΪ¡¢×¢²á±íÐÐΪ·ÖÎöÅж¨¸Ã¹ý³ÌΪAPT32¶ñÒâ¹ý³Ì £¬²úÉúÏàÓ¦µÄµ¯´°¸æ¾¯ £¬ÔڹؼüÁ´Â·ÉÏ×Ô¶¯À¹½Ø¹ý³Ì £¬ÊµÏÖ¡°ÐÐΪ¼¶¡±Ïûɱ¡£


ͼƬ6.png

ͼ6Ìì«‘EDRÐÐΪÒýÇæ¸æ¾¯


ͼƬ7.png

ͼ7Ìì«‘EDRÐÐΪÒýÇæ¸æ¾¯µÄ¾ÙÖ¤ÐÅÏ¢


ÍøÂçÐÐÎªÈ«ÃæÁôºÛÓë¼ì²â


¡°º£Á«»¨¡±Ñù±¾ÓëC&C·þÎñÆ÷³ÉÁ¢»ùÓÚHTTPºÍ̸µÄÍøÂçÏÎ½Ó £¬Ã¿¸ô30Ãë·¢ËÍÒ»´ÎÐÄÌø°ü £¬³¢ÊÔ´ÓC&C·þÎñÆ÷»ñÈ¡Ö÷»úÐÅÏ¢¡¢Ã¶¾Ù¹ý³Ì¡¢ÎļþÉÏ´«ÏÂÔØÒÔ¼°ºÅÁîÖ´ÐеȶñÒâ½ÚÔìÖ¸Áî¡£


ͼƬ8.png

ͼ8¡°º£Á«»¨¡±Ñù±¾·¢ËͼÓÃÜÄÚÈÝ


Ìì«‘EDRÄܹ»ÆëÈ«¼Í¼ÖÕ¶ËËùÓбíÁªÍ¨Ñ¶ÐÐΪ £¬Ô̺¬Í¨Ñ¶IP¡¢¶Ë¿Ú¡¢ºÍ̸µÈ¹Ø¼üÐÅÏ¢ £¬È«Ã渲¸ÇÍøÂçÐÐΪ¹ì¼£¡£


Èçͼ9¡¢Í¼10Ëùʾ £¬Ìì«‘EDR¼à¿Øµ½ÖÕ¶ËÉÏ¡°º£Á«»¨¡±Ñù±¾Óйعý³Ìpchealthcheck.exeÌáÒéÁËTCPÍøÂçÏνÓ139.162.62.239:8001 £¬ÎªºóÐøÍþвËÝÔ´Óë¹ØÁª·ÖÎöÌṩÁËÓÐЧÊý¾ÝÖ§³Ö¡£


ͼƬ9.png

ͼ9Ìì«‘EDR¼à²â¡°º£Á«»¨¡±Ñù±¾ÍøÂçÏνÓÈÕÖ¾


ͼƬ10.png

ͼ10Ìì«‘EDR¼à²â¡°º£Á«»¨¡±Ñù±¾ÍøÂçÏνÓÈÕÖ¾ÏêÇé


³ýÁ˶ÔÍøÂçÐÅÏ¢µÄ¼Í¼ £¬Ìì«‘EDRÓ뱦ÔËÀ³¹Ù·½ÍøÕ¾VenusEyeÍþвµý±¨¿âÉî¶ÈÁª¶¯ £¬Í¨¹ýÈںϱ¾µØ¼ì²âÊý¾ÝÓëÔÆ¶ËÍþвµý±¨ £¬¹¹½¨¶¯Ì¬¸üеķÀ»¤»úÔì £¬³ÖÐø¼ì²â²¢Õмܡ°º£Á«»¨¡±APT¼°Æä±äÖÖ¹¥»÷ £¬ÊµÏÖ°²È«·çÏÕµÄÔç·¢ÏÖ¡¢¿ìÏìÓ¦¡£


ͼƬ11.png

ͼ11Ìì«‘EDR±¾µØµý±¨ÖÓ×°º£Á«»¨¡±ÓйØÍþвµý±¨ÐÅÏ¢


ͼƬ12.png

ͼ12Ìì«‘EDR±¾µØµý±¨ÖÓ×°º£Á«»¨¡±ÓйØÍþвµý±¨ÐÅÏ¢ÏêÇé


Ôڸ߼¶Íþв³ÖÐøÑݽøµÄ²¼¾°Ï £¬ÖÕ¶Ë·À»¤µÄ¹Ø¼üÔÚÓÚ³ÉÁ¢³ÖÐøÓÐЧµÄÆ¥µÐÄÜÁ¦¡£±¦ÔËÀ³¹Ù·½ÍøÕ¾Ìì«‘EDRͨ¹ý¡°¼ì²â¡ª·À»¤¡ªÏìÓ¦¡ªµü´ú¡±¹Ø»·°²Õû¸öϵ £¬¹¹½¨Ò»¸ö¿ÉÄÜ×ÔÎÒÓÅ»¯¡¢¶¯Ì¬µ÷ÕûµÄÖÕ¶Ë·ÀÓù»úÔì £¬Îª¸÷ÀàÖÕ¶ËÓ¦¶Ô¸ß¼¶ÍþвÌṩ¿¿µÃס·®Àé¡£