¸æ·¢¡°Òøºü¡¹ØæÈÝ £¬ÈÃÍþвÎÞ´¦ÌÓÐÎ

°ä²¼¹¦·ò 2024-08-08

±àÕß°´£º


½üÆÚ £¬±¦ÔËÀ³¹Ù·½ÍøÕ¾±±¶·°²È«ÔËÓªÖÐÐÄͨ¹ýÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¼à²âµ½Ò»Â· ¡°(¶¾Êó)ÏνÓC2·þÎñÆ÷¡±¸æ¾¯ÊÂÎñ £¬µÚÒ»¹¦·òÓë²úÆ·Ïß½øÐÐËÝԴȡ֤·ÖÎö £¬È·ÈÏÔ´Í·ÊÇijԱ¹¤×°ÖÃÁËLetsVPN¡£¾­½ð¾¦ÍŶӷÖÎöÅж¨ £¬¸ÃLetsVPN×°Öðü±»°ó¸¿ÁËÒøºüµÄWinOS 4.0Ô¶¿ØºóÃÅ¡£±¾ÎĽ«¾ßÌ叿·¢ÕâÒ»ÊÂÎñµÄʼĩ £¬·Ö½âÆäÖеݲȫ·ì϶Óë·çÏÕ £¬ÎªÆóÒµÍøÂ簲ȫ·À»¤Ìṩ¾¯Ê¾Óë½è¼ø¡£


ºÎΪ¡°Òøºü¡± £¿


ÒøºüľÂíÊÇÒ»ÀàÕë¶ÔÌØ¶¨Ö¸±êȺÌå½øÐд¹µö¹¥»÷µÄ¶ñÒâÈí¼þ £¬ÆäÖØÒª¹¥»÷¶ÔÏóÔ̺¬ÆóÊÂÒµµ¥ÔªµÄÖÎÀíÈËÔ±¡¢²ÆÕþÈËÔ±¡¢ÏúÊÛÈËÔ±¡¢½ðÈÚ´ÓÒµÈËÔ±ÒÔ¼°µçÉÌÂô¼ÒµÈ¡£ÕâÀàľÂíͨ¹ý¶àÖÖ¼¿Á©½øÐд«²¼ £¬¶ÔÊܺ¦ÕßµÄÍÆËã»úϵͳ½øÐнÚÔìºÍÇÔÈ¡ÒþÖÔÊý¾Ý £¬½ø¶øÎªºóÐøµÄÚ¿Æ­»î¶¯Ìṩ·½±ã¡£

¡°Òøºü¡±´«²¼·½Ê½


ÒøºüľÂíÖØÒªÍ¨¹ýÒÔϼ¸ÖÖ·½Ê½½øÐд«²¼£º


1¡¢¼´Ê±Í¨Ñ¶¹¤¾ß£¨IM£©´¹µö

¹¥»÷Õßͨ¹ýQQ¡¢Î¢Ðŵȼ´Ê±Í¨Ñ¶¹¤¾ß·¢ËÍ´¹µöÎļþ»òÍøÕ¾Á´½Ó £¬ÓÕµ¼Êܺ¦Õßµã»÷²¢½øÐд«²¼¡£ÕâЩÎļþ»òÁ´½Óͨ³ £»á¼Ù×°³ÉÓµÓÐÓÕµ¼ÐÔµÄÃû³Æ £¬Èç¡°³É¾Íµ¥¡±¡°×ªÕË֪ͨµ¥¡±µÈ¡£


2¡¢´¹µöÍøÕ¾

¹¥»÷Õß»áαÔì˰Îñ»ú¹Ø¡¢½ðÈÚ»ú¹¹µÈ¹Ù·½ÍøÕ¾µÄ´¹µöÍøÕ¾ £¬Ê¹ÓÃ΢ÐÅ´¹µöµÈ·½Ê½½øÐд«²¼¡£ÕâÐ©ÍøÕ¾Í¨³ £»áÒÔ·¢Æ±¡¢µ¥¾Ý¡¢±¨Ë°¡¢Ë°ÎñÈí¼þµÈÃûÒåÓÕµ¼Êܺ¦ÕßÏÂÔØ²¢Ö´ÐжñÒâÈí¼þ¡£


3¡¢¼Ù×°Õý³£Èí¼þ

ÒøºüľÂí»¹»á¼Ù×°³É³£ÓÃÈí¼þ £¬ÈçWPS¡¢MS Office¡¢PDF¡¢Î¢ÐÅ¡¢¶¤¶¤µÈÊýÊ®¿îÈí¼þ £¬Í¨¹ýÔÚÖ÷Á÷ËÑË÷ÒýÇæÉϲɰìÁ÷Á¿½øÐд¹µö´«²¼ £¬ÕâÊÇĿǰ´«²¼Á¿×î´óµÄÒ»ÖÖ´«²¼·½Ê½¡£

Ñù±¾·ÖÎö


´Ó¹ÙÍøÏÂÔØµÄ×°Öðülest-test.3.1.2.msi £¬±»°ó¸¿ÁËÒøºüWinOS 4.0Ô¶¿ØºóÃÅ £¬¹ÙÍøÁ´½Ó£ºhttps://letpvpn.com¡£·ÖÎöÈçÏ£º


MSIÎļþ £¬¼´Microsoft InstallerµÄ×°Öðü £¬×¨ÎªWindowsϵͳÉè¼Æ £¬ÓÃÓÚ×°Öá¢Ð¶ÔØ¡¢½¨¸´¼°¸üÐÂÈí¼þ¡£×÷ΪÎļþÌåʽ £¬Ëü²»ÓÉÓû§Ö±½ÓÖ´ÐÐ £¬¶øÊÇÓÉϵͳµÄMS Installer·þÎñ£¨ÔËÐÐÓÚSYSTEMÕË»§£©´¦Öá£ÕâÒ»»úÔì²»½ö¸³Óè²Ù×÷ÖÎÀíԱȨÏÞ £¬»¹¿ÉÄÜ´¥¼°SYSTEM×î¸ßȨÏÞ £¬ÊµÏÖ¸ßЧ°²È«µÄÈí¼þÖÎÀí¡£


1¡¢Í¨¹ýOrca¹¤¾ß £¬²é¿´lest-test.3.1.2.msi×°ÖðüÎļþ¡£


ͼƬ1.png


2¡¢Í¨¹ý×°ÖðüÅäÖÃÏêÇéÏÔÖøÄܹ»¿´³ö£º×°ÖðüÀïµÄÎļþ¡°__4¡±±»×°Öñ£ÁôΪÎļþÃû¡°1¡± £¬¡°xQJnSaS.exe¡±±»±£ÁôΪÎļþÃû¡°XPsdjAV.exe¡±¡£


3¡¢ÔËÐÐlest-test.3.1.2.msi×°ÖðüÖ®ºó £¬×°ÖÿªÊ͵ÄÎļþ¡£


ͼƬ2.png


4¡¢ÓëOrca¹¤¾ß²é¿´µÄÏêÇéÆëÈ«¶ÔÓ¦µÄÉÏ £¬ÆäÖÓ×°xQGEJun.exe¡±ÊÇÕæÕýµÄletsvpn×°Öðü £¬ÓÃÀ´¹Æ»óÊܺ¦Õß¡£


¼¼ÊõµÀÀí


¡°XPsdjAV.exe¡±¡°libcurl.dll¡±ºÍ¡°1¡±ÊÇÒÔ°×¼ÓºÚ´ó¾ÖÔËÐеÄWinOS 4.0Ô¶¿Ø¡£ÆäÖÐ £¬¡°XPsdjAV.exe¡±×ÔÉíÊǰ×Îļþ £¬ÇÒº±¼û×ÖÊðÃû¡£¡°libcurl.dll¡±ÊDZ»´Û¸ÄµÄ¶ñÒâÎļþ¡£¡°libcurl.dll¡±±»¡°XPsdjAV.exe¡±¼ÓÔØÖ´Ðкó £¬¶ÁÈ¡Îļþ¡°1¡± £¬½âÃܳöWinOS 4.0µÄÔ¶¿ØÖ÷Ìâ´úÂë¡£

ͼƬ3.png

ÕâÊÇÒ»ÖÖµäÐ͵Ä"°×¼ÓºÚ"¹¥»÷ģʽ¡£ÔÚÕâÖÖģʽÏ £¬ºÜ¶àÖÕ¶Ëɱ¶¾Èí¼þ»áĬÈÏÐÅÀµÄÇЩ´øÓÐÓÐЧÊý×ÖÊðÃûµÄ·¨Ê½ £¬ÒÔΪËüÃÇÊǰ²È«µÄ¡£È»¶ø £¬¹¥»÷Õß¿ÉÄÜ»áÀûÓÃÕâÖÖ»úÔìÀ´ÊµÏÖËùνµÄ"Ãâɱ"³ÉЧ¡£

¾ßÌåÀ´Ëµ £¬¹¥»÷Õß¿ÉÄÜ»áʹÓÃÒ»¸ö´øº±¼û×ÖÊðÃûÇÒδ±»´Û¸ÄµÄºÏ·¨·¨Ê½£¨ÀýÈç"XPsdjAV.exe"£© £¬À´ºýŪɱ¶¾Èí¼þ¡£¶øºó £¬ËûÃÇ¿ÉÄÜ»áÅú¸Ä¸Ã·¨Ê½ËùÒÀÀµ²¢Å²ÓõÄDLLÎļþ£¨ÀýÈç"libcurl.dll"£© £¬Ê¹µÃ¶ñÒâµÄDLLÎļþ±»¼ÓÔØ²¢Ö´ÐС£´Ë±í £¬¹¥»÷Õß½«Ö÷ÌâµÄÔ¶¿Ø´úÂ루ÀýÈçWinOS 4.0£©ÒÔ¼ÓÃÜ´ó¾Ö±£ÁôÔÚÎļþ"1"ÖÐ £¬ÕâʹµÃɱ¶¾Èí¼þÄÑÒÔ¼ì²âµ½Æä´æÔÚ¡£


±¦ÔËÀ³¹Ù·½ÍøÕ¾½â¾ö¹æ»®


1¡¢¸ß¼¶Íþв¼ì²â¹æ¶¨


ÒøºüľÂí¹¥»÷ÊÖ·¨Ëä¶à±ä £¬µ«¾ùÓм £¿ÉÑ­ £¬Ö»ÓÐÓй¥»÷¾Í»áÓкۼ£¡£TARÄÚÖþ«×¼¡°á÷ºü¡±Óйؼì²â¹æ¶¨ £¬°²È«×êÑÐÍŶÓçÇÃܸú×Ù×îй¥»÷¼¿Á© £¬È·±£¼ì²â¹æ¶¨¾«×¼¼à²â¡£


2¡¢¸ß¼¶É³Ïä¼ì³öÄÜÁ¦


É豸ÄÚÖöàɳÏä»·¾³ £¬º­¸Çwindow¡¢LinuxµÈ»·¾³ £¬Ñ¡È¡¾²Ì¬¡¢·ì϶¡¢ÐÐΪ·ÖÎö £¬ÄÚÖ÷´É³Ïä¼ì²â»úÔì £¬¶Ô·´É³Ïä¡¢·´¼ì²âµÈÐÐΪ½øÐжã±Ü £¬È«Ãæ¼à²âÑù±¾ÔËÐйý³Ì £¬Éî¿Ì·¢ÏÖÒøºüľÂíµÄÍþв×÷Ϊ¡£


3¡¢¼ÓÃÜÁ÷Á¿Ä£ÐÍ·ÖÎö


É豸ǶÈëAIË㷨ģÐÍ £¬º­¸ÇICMP¡¢DNS¡¢HTTP¡¢HTTPS¡¢WebshellËí·ģÐÍ £¬ÒÔ¡°»úе½ø½¨¡¢Í³ÍÆËã·¨¡¢Íþвµý±¨¡¢Éî¶È°ü¼ì²â¡±Îª¼¼Êõµ××ù £¬¹¹½¨¡°Ê¢ÐÐΪ·ÖÎö¡¢ÓòÃû·ÖÎö¡¢Ö¤Êé·ÖÎö¡¢°üÌØµã·ÖÎö¡¢ÎÕÊÖÐÅÏ¢·ÖÎö¡±µÄ¶àÄ£ÐÍ×ۺϾö²ßϵͳ¡£


4¡¢ÌìãÙAIÖÇÄÜÌ帳ÄÜ


ÌìãÙAIÖÇÄÜÌåÒÔ¡°ÖǼì²â £¬»ÛÊØ»¤¡±ÎªÀíÏë £¬Æ¾¾Ý·ÖÆç¼ì²â³¡¾°ÖÇÄÜ»¯µ÷¶È¸÷Àà¼ì²â¹¤¾ßºÍËã·¨ £¬ÀûÓÃLLMÍÆÀí×ܽáÄÜÁ¦¶Ô¼ì²âÁ˾֡°Éî¼Ó¹¤¡± £¬´ó·ù¶ÈÌá¸ß¼ì²â¾«×¼¶ÈºÍÕûÌå¼ì²â»úÄÜ £¬Ô®ÊÖ°²È«ÈËÔ±¸üºÃµØÏàʶ¹¥»÷ÊÂÎñµÄÐÔÖÊ¡¢ÆðÔ´ºÍDZÔÚÓ°Ïì¡£


ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©Í¨¹ýÌìãÙAIÖÇÄÜÌ帳Äܵĸ߼¶Íþв¼ì²â¡¢¶ñÒâÎļþ¼ì²â¡¢¼ÓÃÜÁ÷Á¿¼ì²âµÈ¼¼Êõ¼¿Á©È«Ãæ¼à²âÒøºüľÂí £¬Éî¿Ì¶´²ìDZÔÚÍþв £¬ÓÐЧԤ·À·çÏÕÀ©É¢ £¬Îª¿Í»§ÍøÂçÖþÆð°²È«·ÀÏß¡£