Õý¶ù°Ë¾ËµÊÖÒÕ¡ª¡ªÒÔEmotetΪÀýÉîÈëÆÊÎöCMDÏÂÁî»ìÏýÊÖÒÕ
Ðû²¼Ê±¼ä 2018-12-13CMDºÍPowershellÏÂÁî¾³£±»ÓÃÔÚ¶ñÒâÈí¼þÖÐÖ´ÐжñÒâ¾ç±¾Îļþ£¬£¬£¬£¬²¢Í¨¹ý¾ç±¾»ìÏý¡¢¼ÓÃÜ»ò±àÂë·½·¨À´ÈƹýAV¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£±¾ÎÄö¾ÙÁ½¸öµä·¶µÄEmotetÈö²¥ÖÐʹÓõĻìÏýCMDÏÂÁ£¬£¬£¬À´ÉîÈëÆÊÎöCMD.ÏÂÁî»ìÏýÊÖÒÕ¡£¡£¡£¡£¡£¡£¡£¡£
ÏÈ¿´Ò»¸ö´ÓDOCÎĵµÇ¶ÈëµÄVBAºê´úÂëÖÐÌáÈ¡µÄCMDÏÂÁ£¬£¬£¬Õ§Ò»¿´ÉÏÈ¥£¬£¬£¬£¬ÏñÊÇÎÞÒâÒåµÄÒ»´®×Ö·û£¬£¬£¬£¬×ÐϸÆÊÎöÆðÀ´ÐèÒªÏÈÏàʶһÏÂCMDÏÂÁîµÄ»ìÏý·½·¨¡£¡£¡£¡£¡£¡£¡£¡£
CMDÏÂÁîµÄ»ìÏý·½·¨
²åÈëÌØÊâ×Ö·û»ìÏýÏÂÁî
×Ö·û¡°^¡±ÊÇCMDÏÂÁîÖÐ×î³£¼ûµÄתÒå×Ö·û£¬£¬£¬£¬¸Ã×Ö·û²»Ó°ÏìÏÂÁîµÄÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÔÚcmdÇéÐÎÖУ¬£¬£¬£¬ÓÐЩ×Ö·û¾ß±¸ÌØÊ⹦Ч£¬£¬£¬£¬Èç >¡¢>>ÌåÏÖÖØ¶¨Ïò£¬£¬£¬£¬| ÌåÏֹܵÀ£¬£¬£¬£¬&¡¢&&¡¢|| ÌåÏÖÓï¾äÅþÁ¬¡£¡£¡£¡£¡£¡£¡£¡£ËüÃǶ¼ÓÐÌØ¶¨µÄ¹¦Ð§£¬£¬£¬£¬ÈôÊÇÐèÒª°ÑËüÃÇ×÷Ϊ×Ö·ûÊä³öµÄ»°£¬£¬£¬£¬echo >¡¢echo |Ö®ÀàµÄд·¨¾Í»áÍÉ»¯¡ª¡ªcmdÚ¹ÊÍÆ÷»á°ÑËüÃÇ×÷Ϊ¾ßÓÐÌØÊ⹦ЧµÄ×Ö·û¿´´ý£¬£¬£¬£¬¶ø²»»á×÷ΪͨË××Ö·û´¦Öóͷ££¬£¬£¬£¬Õâ¸öʱ¼ä£¬£¬£¬£¬¾ÍÐèÒª¶ÔÕâÐ©ÌØÊâ×Ö·û×öתÒå´¦Öóͷ££ºÔÚÿ¸öÌØÊâ×Ö·ûǰ¼ÓÉÏתÒå×Ö·û^¡£¡£¡£¡£¡£¡£¡£¡£
Òò´Ë£¬£¬£¬£¬ÒªÊä³öÕâÐ©ÌØÊâ×Ö·û£¬£¬£¬£¬¾ÍÐèÒªÓà echo ^>¡¢echo ^|¡¢echo ^|^|¡¢echo ^^Ö®ÀàµÄÃûÌÃÀ´´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£¡£ÁíÍ⣬£¬£¬£¬´ËתÒå×Ö·û»¹¿ÉÒÔÓÃ×÷ÐøÐзûºÅ¡£¡£¡£¡£¡£¡£¡£¡£
¶ººÅ¡°,¡±ºÍ·ÖºÅ ¡°;¡±¿ÉÒÔ½»Á÷£¬£¬£¬£¬¿ÉÒÔÈ¡´úÏÂÁîÖеÄÕýµ±¿Õ¸ñ¡£¡£¡£¡£¡£¡£¡£¡£¶à¸ö¿Õ¸ñÒ²²»Ó°ÏìÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£
³É¶ÔµÄÔ²À¨ºÅ£¨£©Ò²»á·ºÆðÔÚÏÂÁî²ÎÊýÖУ¬£¬£¬£¬Ò²²»Ó°ÏìÏÂÁîµÄÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£Ô²À¨ºÅÌåÏÖǶÈë×ÓÏÂÁî×飬£¬£¬£¬Í¬Ñù±»cmd.exe²ÎÊý´¦Öóͷ£Æ÷¾ÙÐÐÚ¹ÊÍ¡£¡£¡£¡£¡£¡£¡£¡£È磺cmd.exe /c ( ( ((echo Command 1) ) )) &&( ( (((((echo Command 2))))) ) )
ʹÓÃCMDÇéÐαäÁ¿Æ´½ÓÏÂÁî
Cmd.exeÄÚÊÖÏÂÁîÓУº set¡¢assoc £¬£¬£¬£¬ftypeµÈ¡£¡£¡£¡£¡£¡£¡£¡£
SetÏÂÁîÓÃÀ´ÏÔʾ¡¢ÉèÖûòɾ³ýcmd.exeÇéÐαäÁ¿¡£¡£¡£¡£¡£¡£¡£¡£ÏÂÁîÃûÌãº
SET [variable=[string]]
variable Ö¸¶¨ÇéÐαäÁ¿Ãû¡£¡£¡£¡£¡£¡£¡£¡£
string Ö¸¶¨ÒªÖ¸Åɸø±äÁ¿µÄһϵÁÐ×Ö·û´®¡£¡£¡£¡£¡£¡£¡£¡£
ÔÚÏÂÁîÐÐÖÐÊäÈë set£¬£¬£¬£¬»áö¾Ù³öcmd.exeÖÐËùÓеÄÇéÐαäÁ¿¡£¡£¡£¡£¡£¡£¡£¡£
assoc£ºÎļþÃûÀ©Õ¹¹ØÁªÏÂÁ£¬£¬£¬ÓÃÓÚÏÔʾºÍÉèÖÃÎļþÃûÀ©Õ¹¹ØÁª£¬£¬£¬£¬¿ÉÒÔÖ¸¶¨Ä³ÖÖºó׺ÃûµÄÎļþÆ¾Ö¤ÌØ¶¨µÄÀàÐÍÎļþ·¿ª»òÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£ÏÂÁîÃûÌÃΪ£ºassoc [.ext[=[fileType]]]
.extÊÇÖ¸£ºÖ¸¶¨Òª¹ØÁªµÄÎļþºó׺Ãû¡£¡£¡£¡£¡£¡£¡£¡£µãºÅ£¨.)ÊDz»¿ÉÊ¡ÂԵ쬣¬£¬£¬ÈôÊÇÊ¡ÂÔÁËϵͳ½«ÏÔʾ¸Ãºó׺ÃûÎļþµÄ¹ØÁªÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£fileTypeÊÇÖ¸£ºÖ¸¶¨Ïà¹ØÁªµÄÎļþÀàÐÍ¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇֻʹÓøòÎÊý£¬£¬£¬£¬½«ÏÔʾ¸ÃÎļþÀàÐ͵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£·´Ö®£¬£¬£¬£¬¸ÃÏÂÁÁгöϵͳע²áµÄËØÓкó׺ÃûÎļþºÍÏà¹ØµÄÀàÐÍ¡£¡£¡£¡£¡£¡£¡£¡£
ftype£ºÏÔʾ»òÐÞ¸ÄÓÃÔÚÎļþÀ©Õ¹Ãû¹ØÁªÖеÄÎļþÀàÐÍ£¬£¬£¬£¬Ö¸¶¨Ò»ÖÖÀàÐ͵ÄÎļþĬÈÏÓÃÄĸö³ÌÐòÔËÐлò·¿ª¡£¡£¡£¡£¡£¡£¡£¡£ÏÂÁîÃûÌÃΪ£ºftype [fileType[=[openCommandString]]
cmd.exeµÄÇéÐαäÁ¿·ÖΪϵͳÒÑÓеÄÇéÐαäÁ¿ºÍ×Ô½ç˵±äÁ¿¡£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÇéÐαäÁ¿µÄÖµÖеÄ×Ö·û»ò×Ö·û´®£¬£¬£¬£¬¿ÉÒÔÆ´½Ó³ÉºÚ¿ÍÐèÒªµÄcmdÏÂÁ£¬£¬£¬Í¬Ê±¿ÉÒÔÌӱܾ²Ì¬¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£ÈçϵͳÒÑÓеÄÇéÐαäÁ¿%comspec%±äÁ¿µÄֵĬÒÔΪ£º¡°C:\WINDOWS\system32\cmd.exe¡±£¬£¬£¬£¬setÏÂÁî¿ÉÒÔ±»±àÂëΪ£º %comspec:~11,1%%comspec:~-1%%comspec:~-13,1%¡£¡£¡£¡£¡£¡£¡£¡£
%VarName:~offset[,length]% Ö÷ÒªÓÃÓÚ»ñÈ¡ÇéÐαäÁ¿VarNameµÄ±äÁ¿Öµ£¬£¬£¬£¬Æ«ÒÆoffset×Ö½ÚÖ®ºó³¤¶ÈΪlength¸ö×Ö½Ú¡£¡£¡£¡£¡£¡£¡£¡£[,length]¿ÉÊ¡ÂÔ¡£¡£¡£¡£¡£¡£¡£¡£
%comspec:~11,1%ÌåÏÖÈ¡comspec±äÁ¿ÖµÖеÄ×Ö·û£¬£¬£¬£¬Ä¬ÈÏϱê´Ó0×îÏÈ£¬£¬£¬£¬´Óϱê11×îÏÈ£¬£¬£¬£¬È¡Ò»¸ö×Ö·û£¬£¬£¬£¬¼´Îª¡±s¡±¡£¡£¡£¡£¡£¡£¡£¡£offsetÒ²Ö§³Ö¸ºÊý£¬£¬£¬£¬ÌåÏÖ·´Ïò±éÀú×Ö·û´®µÄϱꡣ¡£¡£¡£¡£¡£¡£¡£%comspec:~-1%¼´Îª¡°e¡°£¬£¬£¬£¬%comspec:~-13,1%¼´Îª¡±t¡°¡£¡£¡£¡£¡£¡£¡£¡£ÔÆÔƱàÂësetÏÂÁ£¬£¬£¬¿ÉÒÔÌÓ×ß¾²Ì¬¼ì²â¡±set¡°ÏÂÁî×Ö·û´®µÄ¼ì²â»úÖÆ¡£¡£¡£¡£¡£¡£¡£¡£
ͨ³£ÎÒÃÇÒ²¿ÉÒÔ×Ô½ç˵һ¸ö»òÕß¶à¸öÇéÐαäÁ¿£¬£¬£¬£¬Ê¹ÓÃÇéÐαäÁ¿ÖµÖеÄ×Ö·û£¬£¬£¬£¬ÌáÈ¡²¢Æ´½Ó³ö×îÖÕÏëÒªµÄcmdÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£Èç:
Cmd /C ¡°set envar=net user && call echo %envar%¡° ¿ÉÒÔÆ´½Ó³öcmdÏÂÁnet user
Ò²¿ÉÒÔ½ç˵¶à¸öÇéÐαäÁ¿¾ÙÐÐÆ´½ÓÏÂÁî´®£¬£¬£¬£¬Ìá¸ß¾²Ì¬ÆÊÎöµÄÖØÆ¯ºó£º
cmd /c ¡° set envar1=ser&& set envar2=ne&& set envar3=t u&&call echo %envar2%%envar3%%envar1%¡±
cmdÏÂÁîµÄ¡°/C¡±²ÎÊý£¬£¬£¬£¬Cmd /C ¡°string¡±ÌåÏÖ£ºÖ´ÐÐ×Ö·û´®stringÖ¸¶¨µÄÏÂÁ£¬£¬£¬È»ºóÖÕÖ¹¡£¡£¡£¡£¡£¡£¡£¡£
¶øÆôÓÃÑÓ³ÙµÄÇéÐαäÁ¿À©Õ¹£¬£¬£¬£¬¾³£Ê¹Óà cmd.exeµÄ /V:ON²ÎÊý£¬£¬£¬£¬
/V:ON²ÎÊýÆôÓÃʱ£¬£¬£¬£¬¿ÉÒÔ²»Ê¹ÓÃcallÏÂÁîÀ´À©Õ¹±äÁ¿£¬£¬£¬£¬Ê¹Óà %var% »ò !var! À´À©Õ¹±äÁ¿£¬£¬£¬£¬!var!¿ÉÒÔÓÃÀ´È¡´ú%var%£¬£¬£¬£¬Ò²¾ÍÊÇ¿ÉÒÔʹÓÃ̾ϢºÅ×Ö·ûÀ´Ìæ»»ÔËÐÐʱµÄÇéÐαäÁ¿Öµ¡£¡£¡£¡£¡£¡£¡£¡£ºóÃæÏÈÈÝForÑ»·Ê±»áÐèÒª¿ªÆô/V:²ÎÊýÑÓ³Ù±äÁ¿À©Õ¹·½·¨¡£¡£¡£¡£¡£¡£¡£¡£
ʹÓÃForÑ»·Æ´½ÓÏÂÁî
ForÑ»·¾³£±»ÓÃÀ´»ìÏý´¦Öóͷ£cmdÏÂÁ£¬£¬£¬Ê¹µÃcmdÏÂÁî¿´ÆðÀ´ÖØ´óÇÒÄÑÒÔ¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£×î³£ÓõÄForÑ»·²ÎÊýÓÐ /L,/F²ÎÊý¡£¡£¡£¡£¡£¡£¡£¡£
FOR ²ÎÊý %±äÁ¿Ãû IN (Ïà¹ØÎļþ»òÏÂÁî) DO Ö´ÐеÄÏÂÁî
FOR %variable IN (set) DO command [command-parameters]
%variable Ö¸¶¨Ò»¸ö¼òµ¥×Öĸ¿ÉÌæ»»µÄ²ÎÊý¡£¡£¡£¡£¡£¡£¡£¡£ Õâ¸ö±äÁ¿Ãû¿ÉÒÔÊÇСдa-z»òÕß´óдA-Z,Çø·Ö¾Þϸд,FOR»á°Ñÿ¸ö¶ÁÈ¡µ½µÄÖµ¸³¸ø¸Ã±äÁ¿¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÅú´¦Öóͷ£ÎļþÖУ¬£¬£¬£¬ÒýÓñäÁ¿ÒªÓÃ%%variable£¬£¬£¬£¬ÎÒÃÇÕâÀïÖ÷ÒªÏÈÈÝÔÚcmd´°¿ÚÖУ¬£¬£¬£¬ÒýÓñäÁ¿ÓÃ%variable¼´¿É¡£¡£¡£¡£¡£¡£¡£¡£(set) Ö¸¶¨Ò»¸ö»òÒ»×éÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿ÉÒÔʹÓÃͨÅä·û¡£¡£¡£¡£¡£¡£¡£¡£ Ïà¹ØµÄÎļþ»òÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
command Ö¸¶¨¶Ôÿ¸öÎļþÖ´ÐеÄÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
command-parameters
ÎªÌØ¶¨ÃüÁîÖ¸¶¨²ÎÊý»òÏÂÁîÐпª¹Ø¡£¡£¡£¡£¡£¡£¡£¡£
/L ²ÎÊý£º µü´úÊýÖµ¹æÄ£
for /L %variable in (start,step,end) do command [command-parameters]
¸ÃÏÂÁîÌåÏÖÒÔÔöÁ¿ÐÎʽ´Ó×îÏȵ½¿¢ÊµÄÒ»¸öÊý×ÖÐòÁС£¡£¡£¡£¡£¡£¡£¡£Ê¹Óõü´ú±äÁ¿ÉèÖÃÆðʼֵ(start)£¬£¬£¬£¬È»ºóÖð²½Ö´ÐÐÒ»×鹿ģµÄÖµ£¬£¬£¬£¬Ö±µ½¸ÃÖµÁè¼ÝËùÉèÖõÄÖÕÖ¹Öµ (end)¡£¡£¡£¡£¡£¡£¡£¡£/L ½«Í¨¹ý¶ÔstartÓëend¾ÙÐнÏÁ¿À´Ö´Ðеü´ú±äÁ¿¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇstartСÓÚend£¬£¬£¬£¬¾Í»áÖ´ÐиÃÏÂÁ£¬£¬£¬²»È»ÏÂÁîÚ¹ÊͳÌÐòÍ˳ö´ËÑ»·¡£¡£¡£¡£¡£¡£¡£¡£»£»£»£»¹¿ÉÒÔʹÓøºµÄ stepÒԵݼõÊýÖµµÄ·½·¨Öð²½Ö´Ðд˹æÄ£ÄÚµÄÖµ¡£¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬(1,1,5) ÌìÉúÐòÁÐ 1 2 3 4 5£¬£¬£¬£¬¶ø (5,-1,1) ÔòÌìÉúÐòÁÐ (5 4 3 2 1)¡£¡£¡£¡£¡£¡£¡£¡£ÏÂÁîcmd /C ¡°for /L %i in (1,1,5) do start cmd¡±,»áÖ´Ðз¿ª5¸öcmd´°¿Ú¡£¡£¡£¡£¡£¡£¡£¡£
/F²ÎÊý£º ÊÇ×îǿʢµÄÏÂÁ£¬£¬£¬ÓÃÀ´´¦Öóͷ£ÎļþºÍһЩÏÂÁîµÄÊä³öЧ¹û¡£¡£¡£¡£¡£¡£¡£¡£
FOR /F ["options"] %variable IN (file-set) DO command [command-parameters]
FOR /F ["options"] %variable IN ("string") DO command [command-parameters]
FOR /F ["options"] %variable IN ('command') DO command [command-parameters]
(file-set) ΪÎļþÃû£¬£¬£¬£¬for»áÒÀ´Î½«file-setÖеÄÎļþ·¿ª£¬£¬£¬£¬²¢ÇÒÔÚ¾ÙÐе½ÏÂÒ»¸öÎļþ֮ǰ½«Ã¿¸öÎļþ¶ÁÈ¡µ½Äڴ棬£¬£¬£¬Æ¾Ö¤Ã¿Ò»ÐзֳÉÒ»¸öÒ»¸öµÄÔªËØ£¬£¬£¬£¬ºöÂÔ¿ÕȱÐС£¡£¡£¡£¡£¡£¡£¡£
("string")´ú±í×Ö·û´®£¬£¬£¬£¬('command')´ú±íÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
ÈôÊÇÎļþaa.txtÖÐÓÐÈçÏÂÄÚÈÝ£º
µÚ1ÐеÚ1ÁÐ µÚ1ÐеÚ2ÁÐ
µÚ2ÐеÚ1ÁÐ µÚ2ÐеÚ2ÁÐ
ÒªÏë¶Á³öaa.txtÖеÄÄÚÈÝ£¬£¬£¬£¬¿ÉÒÔÓÃfor /F %i in (aa.txt) do echo %i £¬£¬£¬£¬ÈôÊÇÈ¥µô/F²ÎÊýÔòÖ»»áÊä³öaa.txt£¬£¬£¬£¬²¢²»»á¶ÁÈ¡ÆäÖеÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£
ÎÒÃÇѡȡнüµÄEmotetÑù±¾ÏÂÔØÊ¹ÓõÄCMDÏÂÁî»ìÏý£¬£¬£¬£¬À´Ê¹ÓÃÇ°ÃæµÄ֪ʶÀ´½â»ìÏý¡£¡£¡£¡£¡£¡£¡£¡£
ʹÓÃ×Ô½çÌÖÇéÐαäÁ¿ºÍForÑ»·»ìÏý
¸ÃÑù±¾ÖÐʹÓÃÁËcmd.exe µÄÆôÓÃÑÓ³ÙÇéÐαäÁ¿/V:ON²ÎÊý£¬£¬£¬£¬/C²ÎÊý£¬£¬£¬£¬Ê¹ÓÃsetÏÂÁî×Ô½ç˵һ¸öÇéÐαäÁ¿kpx=lHUwrRfzapaiNzCqHfu:Doc(4YQ0S.1,xk}$) s6dK=mn5/+ygbW-TeP\v2tj{78Mh@;BO'FZ£¬£¬£¬£¬Í¨¹ý&&Æ´½ÓÏÂÁ£¬£¬£¬È»ºóÊǸöforÑ»·£º for %G in £¨ÊýÁУ©do set 1q=!1q!!kpx:~ %G, 1!&& if %G== 81 call %1q:~ -377%¡£¡£¡£¡£¡£¡£¡£¡£ÎÒÃÇ×ÅÖØÆÊÎöÏÂforÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÇ°ÃæÊ¹ÓÃÁËÑÓ³ÙÇéÐαäÁ¿£¬£¬£¬£¬ÒÔÊÇ¿ÉÒÔʹÓÃ!1q!!kpx:~ %G, 1!µÄ·½·¨À´À©Õ¹±äÁ¿£¬£¬£¬£¬ÔÚÔËÐÐʱȡ´úÇéÐαäÁ¿Öµ¡£¡£¡£¡£¡£¡£¡£¡£forµÄÑ»·±äÁ¿ÊÇ%G£¬£¬£¬£¬%G in (ÊýÁÐÖµ)£¬£¬£¬£¬!kpx:~ %G, 1!ÌåÏÖÈ¡ÇéÐαäÁ¿kpxÖÐϱêΪ%GµÄÒ»¸ö×Ö·û£¬£¬£¬£¬ÎÒÃÇ¿ÉÒÔÓÃÈçÏÂpython±àÂëʵÏָù¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£ÊýÁÐÖеĿոñ¿ÉÒÔºöÂÔ£¬£¬£¬£¬ÊýÁÐÖеÄÊýÖµÕýºÃÊÇ377¸ö£¬£¬£¬£¬kpx×Ö·û´®µÄ³¤¶ÈÊÇ72¸ö×Ö·û£¬£¬£¬£¬Ï±êΪ81ÒѾ²»±£´æ£¬£¬£¬£¬ÒÔÊǵ±Ï±ê%G==81ʱ£¬£¬£¬£¬ÔËÐÐʱÇéÐαäÁ¿1q=!1q!powershell ¡¡, call %1q:~-377%£¬£¬£¬£¬ÒÔÊÇÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÊÇforÑ»·±éÀú³öµÄpowershell¡¡ÏÂÁ£¬£¬£¬Ç°ÃæµÄ1q=!1q!Êdzõʼ»¯±äÁ¿1q£¬£¬£¬£¬ÐèÒª±»È¥µôÒÔÃâÓ°ÏìÕý³£ÏÂÁîµÄÖ´ÐУ¬£¬£¬£¬ÒÔÊÇÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÈÆ¹ýÇ°ÃæµÄ!1q!¡£¡£¡£¡£¡£¡£¡£¡£
Êä³ö£º
ÏÂÔØEmotetµÄÁ´½ÓΪ£º
http://catbayouthaction.com/jKS86a
http://spsystems24.ru/O
http://xn--80abdh8aeoadtg.xn--p1ai/multimedia/hD4lyk7
http://borsehung.pro/pfWq
http://inpart-auto.ru/x2bu
ʹÓÃcmdϵͳÇéÐαäÁ¿ºÍForÑ»·»ìÏý
ÏȽ«»ìÏýcmdÏÂÁîÖеÄתÒå×Ö·û¡°^¡±ËùÓÐÈ¥µô£¬£¬£¬£¬ÔÙ½«³ýÁ˱äÁ¿@Ö®ÍâµÄ¶ººÅ¡°,¡±¡¢·ÖºÅ¡°;¡±¡¢¶àÓà¿Õ¸ñɾ³ý¡£¡£¡£¡£¡£¡£¡£¡£×¢Öر£´æ±äÁ¿@ÖеĶººÅºÍ·ÖºÅ£¬£¬£¬£¬²»È»Ó°ÏìÊä³öЧ¹û¡£¡£¡£¡£¡£¡£¡£¡£
¿É¼ûʹÓÃÁËcmdµÄϵͳÇéÐαäÁ¿%comspec%£¬£¬£¬£¬¼´ÊÇcmd.exeµÄÖ´Ðз¾¶¡£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃForÑ»·µÄF²ÎÊý£¬£¬£¬£¬ÔÚÏÂÁî'aSsoC .cmd'ÖÐÒÔ×Ö·ûv¡¢f¡¢=ΪÍÑÀë·û£¬£¬£¬£¬È¡µÚ¶þÁм´ÊÇ¡°cmd¡±¡£¡£¡£¡£¡£¡£¡£¡£
fOr /f " delims=vf= tokens=2" %f IN ( 'aSsoC .cmd' ) dO %f ¡£¡£¡£¡£¡£¡£¡£¡£ÆäËûÎÞÒâÒåµÄ×Ö·û´®»á±»cmdºöÂÔ¡£¡£¡£¡£¡£¡£¡£¡£
½Ó×Å×Ô½ç˵ÁËÒ»¸öÇéÐαäÁ¿@£¬£¬£¬£¬¼´ÊÇÒ»¸ö1460³¤¶ÈµÄ×Ö·û´®¡£¡£¡£¡£¡£¡£¡£¡£È»ºóʹÓÃForÑ»·µÄ/L²ÎÊý£¬£¬£¬£¬±éÀú±äÁ¿@£ºFOr /L %s In (1459,-4,+3 ) do (( ( (( seT \=!\!!@ :~ %s, 1!))))& iF %s eQU 3 (((CaLl %\ :~ -365% )£¬£¬£¬£¬×Ô½ç˵ÁËÇéÐαäÁ¿¡°\¡±£¬£¬£¬£¬Ê¹ÓÃÇéÐαäÁ¿À©Õ¹·ûºÅ£¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬!@ :~ %s, 1!ÌåÏÖÑ»·±äÁ¿%s´Ó1459×îÏÈ£¬£¬£¬£¬²½³¤Îª-4£¬£¬£¬£¬µ½3¿¢Ê£¬£¬£¬£¬Ñ»·ÌáÈ¡±äÁ¿@ÖеÄÒ»¸ö×Ö·û£¬£¬£¬£¬³¤¶ÈΪ365¸ö×Ö·û£¬£¬£¬£¬¼´´ÓForÑ»·ÖØ×é³öµÄÏÂÁî×îÏÈÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£
ÎÒÃDZàдpython¾ç±¾ÊµÏÖForÑ»·¹¦Ð§£º
×îÖÕ½âÃܳö¿É¶ÁµÄÄÚǶpowershellÏÂÁ
ÏÂÔØEmotetµÄÁ´½ÓΪ£º
http://reitmaier.de/01cedmfXohttp://phoxart.com/sWP0E9
http://panbras.com.br/FHhUYIQ
http://osmanager.com.br/t3HnvWx9x
http://oldwillysforum.com/ChleCkW
²Î¿¼£º
https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/dosfuscation-report.pdf


¾©¹«Íø°²±¸11010802024551ºÅ