Õý¶ù°Ë¾­Ëµ¼¼Êõ¡ª¡ªÒÔEmotetΪÀýÉî¿Ì·ÖÎöCMDºÅÁî»ìºÏ¼¼Êõ

°ä²¼¹¦·ò 2018-12-13
EmotetÒ»¿î³ÛÃûµÄÒøÐÐľÂí £¬³õ´Î³öÏÖÓÚ2014ÄêÄêÖС£¸ÃľÂíÖØÒªÍ¨¹ýÀ¬»øÓʼþµÄ·½Ê½´«²¼Ï°È¾Ö¸±êÓû§ £¬½ñÄêÒÀÈ»·Ç³£»îÔ¾ £¬²¢ÇÒ²»Ðݱ䶯´«²¼»¨Ç» £¬Ñ¡È¡Ô½À´Ô½¸´ÔӵĻìºÏ±àÂëÀ´¶ã±Ü¼ì²â¡£
    
CMDºÍPowershellºÅÁîʱʱ±»ÓÃÔÚ¶ñÒâÈí¼þÖÐÖ´ÐжñÒâ¾ç±¾Îļþ £¬²¢Í¨¹ý¾ç±¾»ìºÏ¡¢¼ÓÃÜ»ò±àÂ뷽ʽÀ´ÈƹýAV¼ì²â¡£±¾ÎÄÁоÙÁ½¸öµäÐ͵ÄEmotet´«²¼ÖÐʹÓõĻìºÏCMDºÅÁî £¬À´Éî¿Ì·ÖÎöCMD.ºÅÁî»ìºÏ¼¼Êõ¡£

ÏÈ¿´Ò»¸ö´ÓDOCÎĵµÇ¶ÈëµÄVBAºê´úÂëÖÐÌáÈ¡µÄCMDºÅÁî £¬Õ§Ò»¿´ÉÏÈ¥ £¬ÏñÊÇÎÞÒâ˼µÄÒ»´®×Ö·û £¬×Ðϸ·ÖÎöÆðÀ´±ØÒªÏÈÏàʶһÏÂCMDºÅÁîµÄ»ìºÏ·½Ê½¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


 


 Ò¼

CMDºÅÁîµÄ»ìºÏ·½Ê½


 
 ²åÈëÌØÊâ×Ö·û»ìºÏºÅÁî 
 
×Ö·û¡°^¡±ÊÇCMDºÅÁîÖÐ×î³£¼ûµÄתÒå×Ö·û £¬¸Ã×Ö·û²»Ó°ÏìºÅÁîµÄÖ´ÐС£ÓÉÓÚÔÚcmd»·¾³ÖÐ £¬ÓÐЩ×Ö·û¾ß±¸ÌØÊâÖ°ÄÜ £¬Èç >¡¢>>°µÊ¾³Á¶¨Ïò £¬| °µÊ¾¹Ü· £¬&¡¢&&¡¢|| °µÊ¾Óï¾äÏνÓ¡£ËüÃǶ¼ÓÐÌØ¶¨µÄÖ°ÄÜ £¬ÈôÊDZØÒª°ÑËüÃÇ×÷Ϊ×Ö·ûÊä³öµÄ»° £¬echo >¡¢echo |Ö®ÀàµÄд·¨¾Í»á·¸´í¡ª¡ªcmdÚ¹ÊÍÆ÷»á°ÑËüÃÇ×÷ΪӵÓÐÌØÊâÖ°ÄܵÄ×Ö·û¶Ô´ý £¬¶ø²»»á×÷Ϊͨ³£×Ö·û´¦Öà £¬Õâ¸öʱ³½ £¬¾Í±ØÒª¶ÔÕâÐ©ÌØÊâ×Ö·û×öתÒå´¦ÖãºÔÚÿ¸öÌØÊâ×Ö·ûǰ¼ÓÉÏתÒå×Ö·û^¡£

Òò¶ø £¬ÒªÊä³öÕâÐ©ÌØÊâ×Ö·û £¬¾Í±ØÒªÓà echo ^>¡¢echo ^|¡¢echo ^|^|¡¢echo ^^Ö®ÀàµÄÌåʽÀ´´¦Öá£Áí±í £¬´ËתÒå×Ö·û»¹Äܹ»ÓÃ×÷ÐøÐзûºÅ¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¶ººÅ¡°,¡±ºÍ·ÖºÅ ¡°;¡±Äܹ»»¥»» £¬Äܹ»È¡´úºÅÁîÖеĺϷ¨¿Õ¸ñ¡£¶à¸ö¿Õ¸ñÒ²²»Ó°ÏìºÅÁîÖ´ÐС£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


³É¶ÔµÄÔ²À¨ºÅ£¨£©Ò²»á³Ê´Ë¿ÌºÅÁî²ÎÊýÖÐ £¬Ò²²»Ó°ÏìºÅÁîµÄÖ´ÐС£Ô²À¨ºÅ°µÊ¾Ç¶Èë×ÓºÅÁî×é £¬Í¬Ñù±»cmd.exe²ÎÊý´¦ÖÃÆ÷½øÐÐÚ¹ÊÍ¡£È磺cmd.exe /c ( ( ((echo Command 1) ) )) &&( ( (((((echo Command 2))))) ) )
 
 ÀûÓÃCMD»·¾³±äÁ¿Æ´½ÓºÅÁî 
 
Cmd.exeÄÚ²¿ºÅÁîÓУº set¡¢assoc  £¬ftypeµÈ¡£

SetºÅÁîÓÃÀ´ÏÔʾ¡¢ÉèÖûòɾ³ýcmd.exe»·¾³±äÁ¿¡£ºÅÁîÌåʽ£º
SET [variable=[string]]
  variable  Ö¸¶¨»·¾³±äÁ¿Ãû¡£
  string    Ö¸¶¨ÒªÖ¸Åɸø±äÁ¿µÄһϵÁÐ×Ö·û´®¡£

ÔÚºÅÁîÐÐÖÐÊäÈë set £¬»áÁоٳöcmd.exeÖÐËùÓеĻ·¾³±äÁ¿¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


assoc£ºÎļþÃûÀ©´ó¹ØÁªºÅÁî £¬ÓÃÓÚÏÔʾºÍÉèÖÃÎļþÃûÀ©´ó¹ØÁª £¬Äܹ»Ö¸¶¨Ä³ÖÖºó׺ÃûµÄÎļþÒÀÕÕÌØ¶¨µÄÀàÐÍÎļþ´ò¿ª»òÖ´ÐС£ºÅÁîÌåʽΪ£ºassoc [.ext[=[fileType]]] 

.extÊÇÖ¸£ºÖ¸¶¨Òª¹ØÁªµÄÎļþºó׺Ãû¡£µãºÅ£¨.)ÊDz»ÄÜÊ¡Â﵀ £¬ÈôÊÇÊ¡ÂÔÁËϵͳ½«ÏÔʾ¸Ãºó׺ÃûÎļþµÄ¹ØÁªÐÅÏ¢¡£fileTypeÊÇÖ¸£ºÖ¸¶¨ÓйØÁªµÄÎļþÀàÐÍ¡£ÈôÊÇֻʹÓøòÎÊý £¬½«ÏÔʾ¸ÃÎļþÀàÐ͵ÄÐÅÏ¢¡£·´Ö® £¬¸ÃºÅÁÁгöϵͳע²áµÄËØÓкó׺ÃûÎļþºÍÓйصÄÀàÐÍ¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ftype£ºÏÔʾ»òÅú¸ÄÓÃÔÚÎļþÀ©´óÃû¹ØÁªÖеÄÎļþÀàÐÍ £¬Ö¸¶¨Ò»ÖÖÀàÐ͵ÄÎļþĬÈÏÓÃÄĸö·¨Ê½ÔËÐлò´ò¿ª¡£ºÅÁîÌåʽΪ£ºftype [fileType[=[openCommandString]]

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


cmd.exeµÄ»·¾³±äÁ¿·ÖΪϵͳÒÑÓеĻ·¾³±äÁ¿ºÍ×Ô½ç˵±äÁ¿¡£ÀûÓû·¾³±äÁ¿µÄÖµÖеÄ×Ö·û»ò×Ö·û´® £¬Äܹ»Æ´½Ó³ÉºÚ¿Í±ØÒªµÄcmdºÅÁî £¬Í¬Ê±Äܹ»Ìӱܾ²Ì¬¼ì²â¡£ÈçϵͳÒÑÓеĻ·¾³±äÁ¿%comspec%±äÁ¿µÄֵĬÒÔΪ£º¡°C:\WINDOWS\system32\cmd.exe¡± £¬setºÅÁîÄܹ»±»±àÂëΪ£º %comspec:~11,1%%comspec:~-1%%comspec:~-13,1%¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


%VarName:~offset[,length]% ÖØÒªÓÃÓÚ»ñÈ¡»·¾³±äÁ¿VarNameµÄ±äÁ¿Öµ £¬Æ«ÒÆoffset×Ö½ÚÖ®ºó³¤¶ÈΪlength¸ö×Ö½Ú¡£[,length]¿ÉÊ¡ÂÔ¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


%comspec:~11,1%°µÊ¾È¡comspec±äÁ¿ÖµÖеÄ×Ö·û £¬Ä¬ÈÏϱê´Ó0ÆðÍ· £¬´Óϱê11ÆðÍ· £¬È¡Ò»¸ö×Ö·û £¬¼´Îª¡±s¡±¡£offsetÒ²Ö§³Ö¸ºÊý £¬°µÊ¾·´Ïò±éÀú×Ö·û´®µÄϱê¡£%comspec:~-1%¼´Îª¡°e¡° £¬%comspec:~-13,1%¼´Îª¡±t¡°¡£Èç´Ë±àÂësetºÅÁî £¬Äܹ»ÌÓÍѾ²Ì¬¼ì²â¡±set¡°ºÅÁî×Ö·û´®µÄ¼ì²â»úÔì¡£

ͨ³£ÎÒÃÇÒ²Äܹ»×Ô½ç˵һ¸ö»òÕß¶à¸ö»·¾³±äÁ¿ £¬ÀûÓû·¾³±äÁ¿ÖµÖеÄ×Ö·û £¬ÌáÈ¡²¢Æ´½Ó³ö×îÖÕÏëÒªµÄcmdºÅÁî¡£Èç:
Cmd /C ¡°set envar=net user && call echo %envar%¡° Äܹ»Æ´½Ó³öcmdºÅÁnet user
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ò²Äܹ»½ç˵¶à¸ö»·¾³±äÁ¿½øÐÐÆ´½ÓºÅÁî´® £¬Ìá¸ß¾²Ì¬·ÖÎöµÄ¸´ÔÓ¶È£º
cmd /c ¡° set envar1=ser&& set envar2=ne&& set envar3=t u&&call echo %envar2%%envar3%%envar1%¡±
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


cmdºÅÁîµÄ¡°/C¡±²ÎÊý £¬Cmd /C ¡°string¡±°µÊ¾£ºÖ´ÐÐ×Ö·û´®stringÖ¸¶¨µÄºÅÁî £¬¶øºóÖÕÖ¹¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¶øÆôÓÃÑÓ³¤µÄ»·¾³±äÁ¿À©´ó £¬Ê±Ê±Ê¹Óà cmd.exeµÄ /V:ON²ÎÊý £¬
/V:ON²ÎÊýÆôÓÃʱ £¬Äܹ»²»Ê¹ÓÃcallºÅÁîÀ´À©´ó±äÁ¿ £¬Ê¹Óà %var% »ò !var! À´À©´ó±äÁ¿ £¬!var!Äܹ»ÓÃÀ´°ü°ì%var% £¬Ò²¾ÍÊÇÄܹ»Ê¹ÓøÐ̾ºÅ×Ö·ûÀ´´úÌæÔËÐÐʱµÄ»·¾³±äÁ¿Öµ¡£ºóÃæ½éÉÜForÑ­»·Ê±»á±ØÒª¿ªÆô/V:²ÎÊýÑÓ³¤±äÁ¿À©´ó·½Ê½¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

 
 ÀûÓÃForÑ­»·Æ´½ÓºÅÁî 
 
ForÑ­»·Ê±Ê±±»ÓÃÀ´»ìºÏ´¦ÖÃcmdºÅÁî £¬Ê¹µÃcmdºÅÁî¿´ÆðÀ´¸´ÔÓÇÒÄÑÒÔ¼ì²â¡£×î³£ÓõÄForÑ­»·²ÎÊýÓÐ /L,/F²ÎÊý¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


FOR ²ÎÊý %±äÁ¿Ãû IN (ÓйØÎļþ»òºÅÁî) DO Ö´ÐеĺÅÁî

FOR %variable IN (set) DO command [command-parameters]

%variable Ö¸¶¨Ò»¸öµ¥Ò»×Öĸ¿É´úÌæµÄ²ÎÊý¡£ Õâ¸ö±äÁ¿Ãû¿ÉËùÒÔÓ×дa-z»òÕß´óдA-Z,·Ö±æ´óÓ×д,FOR»á°Ñÿ¸ö¶ÁÈ¡µ½µÄÖµ¸³¸ø¸Ã±äÁ¿¡£ÔÚÅú´¦ÖÃÎļþÖÐ £¬ÒýÓñäÁ¿ÒªÓÃ%%variable £¬ÎÒÃÇÕâÀïÖØÒª½éÉÜÔÚcmd´°¿ÚÖÐ £¬ÒýÓñäÁ¿ÓÃ%variable¼´¿É¡£
(set)      Ö¸¶¨Ò»¸ö»òÒ»×éÎļþ¡£Äܹ»Ê¹ÓÃͨÅä·û¡£ ÓйصÄÎļþ»òºÅÁî¡£
command    Ö¸¶¨¶Ôÿ¸öÎļþÖ´ÐеĺÅÁî¡£ 
command-parameters 
             ÎªÌض¨ÊýÁîÖ¸¶¨²ÎÊý»òºÅÁîÐпª¹Ø¡£
/L ²ÎÊý£º µü´úÊýÖµÁìÓò
for /L %variable in (start,step,end) do command [command-parameters]

¸ÃºÅÁʾÒÔÔöÁ¿´ó¾Ö´ÓÆðÍ·µ½ÊµÏÖµÄÒ»¸öÊý×ÖÐòÁС£Ê¹Óõü´ú±äÁ¿ÉèÖÃÕØÊ¼Öµ(start) £¬¶øºóÖð²½Ö´ÐÐÒ»×éÁìÓòµÄÖµ £¬Ö±µ½¸ÃÖµ³¬¹ýËùÉèÖõÄÖÕÖ¹Öµ (end)¡£/L ½«Í¨¹ý¶ÔstartÓëend½øÐбÈÁ¦À´Ö´Ðеü´ú±äÁ¿¡£ÈôÊÇstartÓ×ÓÚend £¬¾Í»áÖ´ÐиúÅÁî £¬²»È»ºÅÁîÚ¹ÊÍ·¨Ê½Í˳ö´ËÑ­»·¡£»¹Äܹ»Ê¹ÓøºµÄ stepÒԵݼõÊýÖµµÄ·½Ê½Öð²½Ö´ÐдËÁìÓòÄÚµÄÖµ¡£ÀýÈç £¬(1,1,5) ÌìÉúÐòÁÐ 1 2 3 4 5 £¬¶ø (5,-1,1) ÔòÌìÉúÐòÁÐ (5 4 3 2 1)¡£ºÅÁîcmd /C ¡°for /L %i in (1,1,5) do start cmd¡±,»áÖ´Ðдò¿ª5¸öcmd´°¿Ú¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


/F²ÎÊý£º ÊÇ×î׳´óµÄºÅÁî £¬ÓÃÀ´´¦ÖÃÎļþºÍһЩºÅÁîµÄÊä³öÁ˾Ö¡£
FOR /F ["options"] %variable IN (file-set) DO command [command-parameters]
FOR /F ["options"] %variable IN ("string") DO command [command-parameters]
FOR /F ["options"] %variable IN ('command') DO command [command-parameters]
(file-set) ΪÎļþÃû £¬for»á˳´Î½«file-setÖеÄÎļþ´ò¿ª £¬²¢ÇÒÔÚ½øÐе½ÏÂÒ»¸öÎļþ֮ǰ½«Ã¿¸öÎļþ¶ÁÈ¡µ½ÄÚ´æ £¬ÒÀÕÕÿһÐзֳÉÒ»¸öÒ»¸öµÄÔªËØ £¬ºöÂÔ¿ÕȱÐС£
("string")´ú±í×Ö·û´® £¬('command')´ú±íºÅÁî¡£
Èç¹ûÎļþaa.txtÖÐÓÐÈçÏÂÄÚÈÝ£º
µÚ1ÐеÚ1ÁÐ µÚ1ÐеÚ2ÁР
µÚ2ÐеÚ1ÁÐ µÚ2ÐеÚ2ÁÐ
ÒªÏë¶Á³öaa.txtÖеÄÄÚÈÝ £¬Äܹ»ÓÃfor /F %i in (aa.txt) do echo %i  £¬ÈôÊÇÈ¥µô/F²ÎÊýÔòÖ»»áÊä³öaa.txt £¬²¢²»»á¶ÁÈ¡ÆäÖеÄÄÚÈÝ¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



ÏÈ´ÓÀ¨ºÅÖ´ÐÐ £¬ÓÉÓÚº¬ÓвÎÊý/F,ËùÒÔfor»áÏÈ´ò¿ªaa.txt £¬¶øºó¶Á³öaa.txtÀïÃæµÄËùÓÐÄÚÈÝ £¬°ÑËü×÷Ϊһ¸ö¼¯ÖÐ £¬²¢ÇÒÒÔÿһÐÐ×÷Ϊһ¸öÔªËØ¡£ÓÉÉÏͼ¿É¼û £¬²¢Ã»ÓÐÊä³öµÚ¶þÁеÄÄÚÈÝ £¬Ô­ÒòÊÇÈôÊÇûÓÐÖ¸¶¨¡°delims=·ûºÅÁÐ±í¡¹Øâ¸ö¿ª¹Ø £¬ÄÇôfor /FÓï¾ä»áĬÈÏÒÔ¿Õ¸ñ¼ü»òTab¼ü×÷Ϊ·Ö¸ô·û¡£For /FÊÇÒÔÐÐΪµ¥ÔªÀ´´¦ÖÃÎı¾ÎļþµÄ £¬ÈôÊÇÎÒÃÇÏë°ÑÿһÐÐÔÙ·Ö»¯³É¸üÓ×µÄÄÚÈÝ £¬¾ÍʹÓÃdelimsºÍtokensÑ¡Ïî¡£delimsÓÃÀ´Í¨ÖªforÿһÐÐÓÃʲô×÷Ϊ·Ö¸ô·û £¬Ä¬ÈÏ·Ö¸ô·ûÊǿոñºÍTab¼ü¡£for /F ¡°delims= ¡° %i in (aa.txt) do echo %i ,½«delimsÉèÖÃΪ¿Õ¸ñ £¬Êǽ«Ã¿¸öÔªËØÒÔ¿Õ¸ñÔ׸î £¬Ä¬ÈÏֻȡÔ׸îÖ®ºóµÄµÚÒ»¸öÔªËØ¡£ÈôÊÇÎÒÃÇÏëµÃµ½µÚ¶þÁÐÊý¾Ý £¬¾ÍÒªÓõ½tokens=2 £¬À´Ö¸¶¨Í¨¹ýdelims½«Ã¿Ò»ÐзֳɸüÓ×µÄÔªËØÊ± £¬ÒªÈ¡³öÄÄÒ»¸ö»òÄöÔªËØ:for /F ¡°tokens=2 delims= ¡° %i in (aa.txt) do echo %i¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

 ·¡
ÏÖʵÑù±¾·ÖÎö
 
ÎÒÃǰÎȡнüµÄEmotetÑù±¾ÏÂÔØÀûÓõÄCMDºÅÁî»ìºÏ £¬À´ÀûÓÃÇ°ÃæµÄ֪ʶÀ´½â»ìºÏ¡£
 
 ÀûÓÃ×Ô½ç˵»·¾³±äÁ¿ºÍForÑ­»·»ìºÏ 
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¸ÃÑù±¾ÖÐÀûÓÃÁËcmd.exe µÄÆôÓÃÑÓ³¤»·¾³±äÁ¿/V:ON²ÎÊý £¬/C²ÎÊý £¬ÀûÓÃsetºÅÁî×Ô½ç˵һ¸ö»·¾³±äÁ¿kpx=lHUwrRfzapaiNzCqHfu:Doc(4YQ0S.1,xk}$) s6dK=mn5/+ygbW-TeP\v2tj{78Mh@;BO'FZ £¬Í¨¹ý&&Æ´½ÓºÅÁî £¬¶øºóÊǸöforÑ­»·£º for %G in £¨ÊýÁУ©do set     1q=!1q!!kpx:~  %G,    1!&& if %G==  81  call  %1q:~    -377%¡£ÎÒÃÇ×ųÁ·ÖÎöÏÂforºÅÁî¡£ÓÉÓÚÇ°ÃæÊ¹ÓÃÁËÑÓ³¤»·¾³±äÁ¿ £¬ËùÒÔÄܹ»Ê¹ÓÃ!1q!!kpx:~  %G,    1!µÄ·½Ê½À´À©´ó±äÁ¿ £¬ÔÚÔËÐÐʱ°ü°ì»·¾³±äÁ¿Öµ¡£forµÄÑ­»·±äÁ¿ÊÇ%G £¬%G in (ÊýÁÐÖµ) £¬!kpx:~ %G, 1!°µÊ¾È¡»·¾³±äÁ¿kpxÖÐϱêΪ%GµÄÒ»¸ö×Ö·û £¬ÎÒÃÇÄܹ»ÓÃÈçÏÂpython±àÂëʵÏÖ¸ÃÖ°ÄÜ¡£ÊýÁÐÖеĿոñÄܹ»ºöÂÔ £¬ÊýÁÐÖеÄÊýÖµÕýºÃÊÇ377¸ö £¬kpx×Ö·û´®µÄ³¤¶ÈÊÇ72¸ö×Ö·û £¬Ï±êΪ81ÒѾ­²»´æÔÚ £¬ËùÒÔµ±Ï±ê%G==81ʱ £¬ÔËÐÐʱ»·¾³±äÁ¿1q=!1q!powershell ¡­¡­, call %1q:~-377% £¬ËùÒÔÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÊÇforÑ­»·±éÀú³öµÄpowershell¡­¡­ºÅÁî £¬Ç°ÃæµÄ1q=!1q!Êdzõʼ»¯±äÁ¿1q £¬±ØÒª±»È¥µôÒÔÃâÓ°ÏìÕý³£ºÅÁîµÄÖ´ÐÐ £¬ËùÒÔÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÈÆ¹ýÇ°ÃæµÄ!1q!¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Êä³ö£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÏÂÔØEmotetµÄÁ´½ÓΪ£º
http://catbayouthaction.com/jKS86a
http://spsystems24.ru/O
http://xn--80abdh8aeoadtg.xn--p1ai/multimedia/hD4lyk7
http://borsehung.pro/pfWq
http://inpart-auto.ru/x2bu

 ÀûÓÃcmdϵͳ»·¾³±äÁ¿ºÍForÑ­»·»ìºÏ 

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÏȽ«»ìºÏcmdºÅÁîÖеÄתÒå×Ö·û¡°^¡±È«ÊýÈ¥µô £¬ÔÙ½«³ýÁ˱äÁ¿@Ö®±íµÄ¶ººÅ¡°,¡±¡¢·ÖºÅ¡°;¡±¡¢ÓÐÓà¿Õ¸ñɾ³ý¡£°ÑÎȱ£Áô±äÁ¿@ÖеĶººÅºÍ·ÖºÅ £¬²»È»Ó°ÏìÊä³öÁ˾Ö¡£

 ¿É¼ûÀûÓÃÁËcmdµÄϵͳ»·¾³±äÁ¿%comspec% £¬¼´ÊÇcmd.exeµÄÖ´ÐÐõè¾¶¡£ÀûÓÃForÑ­»·µÄF²ÎÊý £¬ÔÚºÅÁî'aSsoC .cmd'ÖÐÒÔ×Ö·ûv¡¢f¡¢=Ϊ·Ö¸ô·û £¬È¡µÚ¶þÁм´ÊÇ¡°cmd¡±¡£
fOr  /f  " delims=vf=  tokens=2"  %f  IN  ( 'aSsoC  .cmd' ) dO  %f  ¡£ÆäËûÎÞÒâ˼µÄ×Ö·û´®»á±»cmdºöÂÔ¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


½Ó×Å×Ô½ç˵ÁËÒ»¸ö»·¾³±äÁ¿@ £¬µÅ×ÚÒ»¸ö1460³¤¶ÈµÄ×Ö·û´®¡£¶øºóÀûÓÃForÑ­»·µÄ/L²ÎÊý £¬±éÀú±äÁ¿@£ºFOr /L %s In (1459,-4,+3 ) do (( ( (( seT \=!\!!@ :~ %s, 1!))))& iF %s eQU 3 (((CaLl %\ :~ -365% ) £¬×Ô½ç˵ÁË»·¾³±äÁ¿¡°\¡± £¬ÀûÓû·¾³±äÁ¿À©´ó·ûºÅ£¡ £¬!@ :~ %s, 1!°µÊ¾Ñ­»·±äÁ¿%s´Ó1459ÆðÍ· £¬²½³¤Îª-4 £¬µ½3ʵÏÖ £¬Ñ­»·ÌáÈ¡±äÁ¿@ÖеÄÒ»¸ö×Ö·û £¬³¤¶ÈΪ365¸ö×Ö·û £¬¼´´ÓForÑ­»·³Á×é³öµÄºÅÁîÆðÍ·Ö´ÐС£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÎÒÃDZàдpython¾ç±¾ÊµÏÖForÑ­»·Ö°ÄÜ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×îÖÕ½âÃܳö¿É¶ÁµÄÄÚǶpowershellºÅÁ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



ÏÂÔØEmotetµÄÁ´½ÓΪ£º

http://reitmaier.de/01cedmfXo
http://phoxart.com/sWP0E9
http://panbras.com.br/FHhUYIQ
http://osmanager.com.br/t3HnvWx9x
http://oldwillysforum.com/ChleCkW

 Èþ
×ܽá
 
CMDµÄºÅÁî»ìºÏǧ±äÍò»¯ £¬Î¨Ò»µÄÖ÷ÕžÍÊÇÌÓ±ÜɳÏäµÄ¾²Ì¬»ò¶¯Ì¬¼ì²â £¬Ôö³¤·ÖÎöÄѶÈ¡£Íò±ä²»ÀëÆä×Ú £¬Ö»ÓаÑÎÕÁËcmdºÅÁîµÄ¸ù»ùÓïÂÉÀýÔò²¢´¿ÊìʹÓà £¬Ä¿Ç°¶ñÒâÑù±¾µÄ¸÷Ààcmd»ìºÏºÅÁî¶¼Äܹ»Ó­Èжø½â £¬½ø¶øÊµÏÖ¶Ô¸ÃÀàÑù±¾µÄ¼ø±ð¼ì²âºÍ·À±¸¡£
 
²Î¿¼£º 
https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/dosfuscation-report.pdf