ʵ²â£¡GA»Æ½ð¼×Ìì«‘EDR¹Ø»·¾Ñ»÷¡°º£Á«»¨¡±Ñù±¾
°ä²¼¹¦·ò 2025-11-12½üÆÚ£¬¸ß¼¶³ÖÐøÐÔÍþв£¨APT£©×éÖ¯¡°º£Á«»¨¡±£¨OceanLotus£©ÔÙ¶È»îÔ¾¡£ÆäͶ·ÅµÄÐÂÐÍÑù±¾Ñ¡È¡¸ß¶ÈÒñ±ÎµÄ¹¥»÷ÊÖ·¨£¬¶ÔÎÒ¹ú²¿ÃųÁµãÖ¸±êÖ´Ðж¨ÏòÉøÈ룬¶ÔÆóÒµºÍ»ú¹¹µÄÊý¾Ý°²È«×é³ÉÑϳÁÍþв¡£
¸ÃÑù±¾ÖØÒªÑ¡È¡ÒÔÏÂËÄÀ༼Êõ¼¿Á©£º
Ò»ÊÇÒñ±Î»¯Ö²È룺ÀÄÓúϷ¨MSTÁ÷³Ì£¬¶ã±ÜͨÀý°²È«¼ì²â£»
¶þÊÇÓÆ¾Ã»¯×¤Áô£ºÍ¨¹ý×¢²á±í×ÔÆô¶¯ÏîʵÏÖϵͳ³Ö¾Ã½ÚÔ죻
ÈýÊÇÄڴ滯ִÐУºÑ¡È¡Ä£¿éïοյȼ¼Êõ£¬Æ¥µÐ¶¯¾²Ì¬·ÖÎö£»
ËÄÊÇÄ£¿é»¯Í¨Ñ¶£ºÒÀÀµ¼ÓÃÜÐÄÌø°üÓëC&C·þÎñÆ÷ͨѶ£¬ÊµÏÖÔ¶³Ì²Ù¿Ø¡£
Ãæ¶Ô´ËÀà×éÖ¯ÐÔÇ¿¡¢¼¿Á©Òñ±ÎµÄAPT¹¥»÷£¬ÊµÏÖ´ÓÈëÇÖ¸ÐÖªµ½ÐÐΪ×è¶ÏµÄÈ«Á´Â··À»¤£¬ÒѳÉΪÖն˰²È«µÄÖ÷ÌâÌôÕ½¡£
±¾ÎÄ»ùÓÚGA»Æ½ð¼×Ìì«‘EDR¶Ô¡°º£Á«»¨¡±×îÐÂÑù±¾µÄʵ²â¹ý³Ì£¬½éÉÜÈôºÎÒÀ¸½Æä¡°Î´ÖªÍþв¸ÐÖª¡¢Á¢Ìå·À»¤ÍøÂç¡¢¼±¾çÓ¦¼±ÏìÓ¦¡¢µý±¨Çý¶¯½ø»¯¡±µÈÄÜÁ¦£¬ÓÐЧӦ¶Ô´ËÀà¸ß¼¶Íþв¡£
ϵͳ´Û¸Äʵʱ¸ÐÖª
¡°º£Á«»¨¡±¹¥»÷ÕßÔËÐкϷ¨µÄWindowsPCHealthCheckSetup.msi×°Öðü£¬¸Ã×°Öðü»áÔÚ%LOCALAPPDATA%Öд´½¨ÃûΪPCHealthCheckµÄÎļþ¼Ð£¬½«×°ÖðüÖеĺϷ¨·¨Ê½PCHealthCheck.exe¸´ÔìÖÁ´Ë¡£¶ø¹¥»÷ÕßÔÚºÅÁîºó°ë²¿ÃŸ½¼ÓµÄmstÎļþ»á±»½âÎö£¬¿ªÊͶñÒâÄ£¿étbs.dllµ½PCHealthCheck.exeµØµãÎļþ¼Ð£¬Í¬Ê±Ôö³¤ÃûΪPCHealthCheckµÄ×ÔÆô¶¯Ï²¢½«ÆäÖ¸ÏòPCHealthCheck.exeÎļþ¡£»ùÓڴ˲Ù×÷£¬¿ÉʵÏֺϷ¨µÄPCHealthCheck.exe¿ª»ú×ÔÆô¶¯£¬×Ô¶¯¼ÓÔØ¶ñÒâµÄtbs.dllÓë¹¥»÷Õß½øÐÐͨѶ£¬½ÚÔìÊܺ¦Õß»úе¡£

ͼ1´´½¨ºÏ·¨·¨Ê½ºÍ¶ñÒâDLLÄ£¿é

ͼ2Ôö³¤³É¹¦µÄ×¢²á±í×ÔÆô¶¯Ïî
Ìì«‘EDRʵʱ¼à¿Ø×¢²á±í×ÔÆô¶¯Ïî¡¢×ÔÆô¶¯Îļþ¼Ó×¢´òË㹤×÷µÈϵͳ¹Ø¼üµØÎ»¸Ä¹Û£¬È·±£¶Ô´ÛתҵΪµÄʵʱÏìÓ¦¡£
Èçͼ3¡¢Í¼4Ëùʾ£¬¹ý³ÌIDΪ2536µÄmsiexec.exe¹ý³Ì½«PCHealthCheck.exeÔö³¤Îª×¢²á±í×ÔÆô¶¯Ï´¥·¢ÁËÌì«‘EDRϵͳ´Û¸Ä·À»¤Ö°ÄܵÄ×ÔÆô¶¯ÏîÔö³¤¸æ¾¯£¬ÊµÊ±×½ÄÃÆäÓÆ¾Ã»¯×¤Áô̰ͼ£¬´Ó¹¥»÷Á´µÚÒ»²½¶ôÔìÆäÊæÕ¹¡£

ͼ3Ìì«‘EDR²úÉú×ÔÆô¶¯ÏîÔö³¤¸æ¾¯

ͼ4Ìì«‘EDR×ÔÆô¶¯ÏîÔö³¤¸æ¾¯ÏêÇé
¶ñÒâÐÐΪÖÇÄܼø±ðÓë×è¶Ï
¡°º£Á«»¨¡±¹¥»÷ÕßÔÚʹÓÃmsiexec×°ÖÃPCHealthCheckʱ£¬»áÖ¸¶¨ÌØÊâµÄmstÎļþÖ´Ðжî±í²Ù×÷£º¿ªÊͶñÒâÄ£¿étbs.dllµ½PCHealthCheck.exeµØµãÎļþ¼Ð£¬Ôö³¤ÃûΪPCHealthCheckµÄ×ÔÆô¶¯Ï²¢½«ÆäÖ¸ÏòPCHealthCheck.exeÎļþ¡£

ͼ5MsiExec.exe½âÎömstÎļþºóµÄдÎļþ¡¢×¢²á±í²Ù×÷
Ìì«‘EDRÒÀ¸½ÄÚÖÃÐÐΪÒýÇæ£¬Äܹ»¶Ô¹ý³ÌµÄÎļþÐÐΪ¡¢×¢²á±íÏîÐÐΪ¡¢¹ý³ÌÐÐΪµÈ½øÐÐ×ÛºÏÆÀ¹À£¬Ò»µ©×ÛºÏÆÀ¹À´ïµ½Ãô¸ÐÐÐΪ¹æ¶¨ãÐÖµ£¬ÔòÅжϸÃÖ´ÐÐÎļþΪ¶ñÒâÎļþ¡£
Èçͼ6¡¢Í¼7Ëùʾ£¬¡°º£Á«»¨¡±¹¥»÷ÕßÔÚʹÓÃmsiexec×°ÖÃPCHealthCheckʱ£¬Ö¸¶¨ÌØÊâµÄmstÎļþÖ´ÐÐÁ˶î±í²Ù×÷¡£Ìì«‘EDR¾ÍÄܹ»»ùÓÚÎļþÐÐΪ¡¢×¢²á±íÐÐΪ·ÖÎöÅж¨¸Ã¹ý³ÌΪAPT32¶ñÒâ¹ý³Ì£¬²úÉúÏàÓ¦µÄµ¯´°¸æ¾¯£¬ÔڹؼüÁ´Â·ÉÏ×Ô¶¯À¹½Ø¹ý³Ì£¬ÊµÏÖ¡°ÐÐΪ¼¶¡±Ïûɱ¡£

ͼ6Ìì«‘EDRÐÐΪÒýÇæ¸æ¾¯

ͼ7Ìì«‘EDRÐÐΪÒýÇæ¸æ¾¯µÄ¾ÙÖ¤ÐÅÏ¢
ÍøÂçÐÐÎªÈ«ÃæÁôºÛÓë¼ì²â
¡°º£Á«»¨¡±Ñù±¾ÓëC&C·þÎñÆ÷³ÉÁ¢»ùÓÚHTTPºÍ̸µÄÍøÂçÏνӣ¬Ã¿¸ô30Ãë·¢ËÍÒ»´ÎÐÄÌø°ü£¬³¢ÊÔ´ÓC&C·þÎñÆ÷»ñÈ¡Ö÷»úÐÅÏ¢¡¢Ã¶¾Ù¹ý³Ì¡¢ÎļþÉÏ´«ÏÂÔØÒÔ¼°ºÅÁîÖ´ÐеȶñÒâ½ÚÔìÖ¸Áî¡£

ͼ8¡°º£Á«»¨¡±Ñù±¾·¢ËͼÓÃÜÄÚÈÝ
Ìì«‘EDRÄܹ»ÆëÈ«¼Í¼ÖÕ¶ËËùÓбíÁªÍ¨Ñ¶ÐÐΪ£¬Ô̺¬Í¨Ñ¶IP¡¢¶Ë¿Ú¡¢ºÍ̸µÈ¹Ø¼üÐÅÏ¢£¬È«Ã渲¸ÇÍøÂçÐÐΪ¹ì¼£¡£
Èçͼ9¡¢Í¼10Ëùʾ£¬Ìì«‘EDR¼à¿Øµ½ÖÕ¶ËÉÏ¡°º£Á«»¨¡±Ñù±¾Óйعý³Ìpchealthcheck.exeÌáÒéÁËTCPÍøÂçÏνÓ139.162.62.239:8001£¬ÎªºóÐøÍþвËÝÔ´Óë¹ØÁª·ÖÎöÌṩÁËÓÐЧÊý¾ÝÖ§³Ö¡£

ͼ9Ìì«‘EDR¼à²â¡°º£Á«»¨¡±Ñù±¾ÍøÂçÏνÓÈÕÖ¾

ͼ10Ìì«‘EDR¼à²â¡°º£Á«»¨¡±Ñù±¾ÍøÂçÏνÓÈÕÖ¾ÏêÇé
³ýÁ˶ÔÍøÂçÐÅÏ¢µÄ¼Í¼£¬Ìì«‘EDRÓëGA»Æ½ð¼×VenusEyeÍþвµý±¨¿âÉî¶ÈÁª¶¯£¬Í¨¹ýÈںϱ¾µØ¼ì²âÊý¾ÝÓëÔÆ¶ËÍþвµý±¨£¬¹¹½¨¶¯Ì¬¸üеķÀ»¤»úÔ죬³ÖÐø¼ì²â²¢Õмܡ°º£Á«»¨¡±APT¼°Æä±äÖÖ¹¥»÷£¬ÊµÏÖ°²È«·çÏÕµÄÔç·¢ÏÖ¡¢¿ìÏìÓ¦¡£

ͼ11Ìì«‘EDR±¾µØµý±¨ÖÓ×°º£Á«»¨¡±ÓйØÍþвµý±¨ÐÅÏ¢

ͼ12Ìì«‘EDR±¾µØµý±¨ÖÓ×°º£Á«»¨¡±ÓйØÍþвµý±¨ÐÅÏ¢ÏêÇé
Ôڸ߼¶Íþв³ÖÐøÑݽøµÄ²¼¾°Ï£¬ÖÕ¶Ë·À»¤µÄ¹Ø¼üÔÚÓÚ³ÉÁ¢³ÖÐøÓÐЧµÄÆ¥µÐÄÜÁ¦¡£GA»Æ½ð¼×Ìì«‘EDRͨ¹ý¡°¼ì²â¡ª·À»¤¡ªÏìÓ¦¡ªµü´ú¡±¹Ø»·°²Õû¸öϵ£¬¹¹½¨Ò»¸ö¿ÉÄÜ×ÔÎÒÓÅ»¯¡¢¶¯Ì¬µ÷ÕûµÄÖÕ¶Ë·ÀÓù»úÔ죬Ϊ¸÷ÀàÖÕ¶ËÓ¦¶Ô¸ß¼¶ÍþвÌṩ¿¿µÃס·®Àé¡£


¾©¹«Íø°²±¸11010802024551ºÅ