¡°°×Ïó¡±APT×éÖ¯½üÆÚ¶¯Ì¬·ÖÎö»ã±¨
°ä²¼¹¦·ò 2018-03-31¡°°×Ïó¡±±ðÃû¡°Patchwork¡±£¬¡°Ä¦Ú²Ý¡±£¬ÒÉËÆÀ´×ÔÄÏÑÇij¹ú£¬×Ô2012ÄêÒÔÀ´³ÖÐøÕë¶ÔÖйú¡¢°Í»ù˹̹µÈ¹ú½øÐÐÍøÂç¹¥»÷£¬³Ö¾ÃÇÔȡָ±ê¹ú¶ÈµÄ¿ÆÑÓ×¢¾üÊÂ×ÊÁÏ¡£ÓëÆäËû×éÖ¯·ÖÆçµÄÊÇ£¬¸Ã×éÖ¯¼«¶ÈÉÆÓÚÆ¾¾Ý·ÖÆçµÄ¹¥»÷Ö¸±êαÔì·ÖÆç°æ±¾µÄÓйؾüÊ¡¢ÕþÖÎÐÅÏ¢£¬ÒÔ½øÐÐÏÂÒ»²½µÄ¹¥»÷ÉøÈë¡£
2017ÄêϰëÄêÒÔÀ´£¬ÎÒÃÇ·¢ÏÖÁ˶àÆðÓë°×Ïó×éÖ¯ÓйصÄ×îй¥»÷ÊÂÎñ¡£¸Ã×é֯ͨ¹ýÓã²æÊ½´¹µöÓʼþ£¬²¢¹²Í¬Éç»á¹¤³Ìѧ¼¿Á©ÔÚÓʼþÖз¢ËÍ´øÓÐÌåʽ·ì϶ÎĵµµÄÁ´½Ó£¬ÓÕµ¼Êܺ¦È˵ã»÷ÏÂÔØ²¢µã»÷£¬·ì϶´¥·¢³É¹¦ºó£¬»áÏÂÔØQuasar£¬BADNEWSµÈ±äÖÖÔ¶¿ØÄ¾Âí¡£
¹¥»÷ÊÂÎñ·ÖÎö
¹¥»÷ÊÂÎñA
µÚÒ»´Î¼¯Öй¥»÷ÊÂÎñ²úÉúÔÚ2017Äê11Ô·Ý×óÓÒ£¬ÎÒÃÇ¼à¿Øµ½¸Ã×éÖ¯ÌáÒéÁËÂÅ´ÎÓã²æÓʼþ¹¥»÷¡£Óйذ¸ÀýÈçÏ£º
1.ʹÓÃÓʼþͶ·ÅÃûΪChina_Strategic_ChainµÄdocxÎĵµ£¬²¢ÔÚÓʼþÖÐÎĵµÄÚÈݽøÐÐÂÛÊö£¬ÒýÓÕÓû§µã»÷´ò¿ª¡£
2.µ±Óû§´ò¿ª¸ÃÎĵµºó£¬ÏÔʾÌáÐÑÔÚÊäÈëÀ¸ÊäÈëÃÜÂëKEY£¬ÔÙµã»÷×óÉÏ·½µÄͼ±ê¼´¿ÉʵÏÖ½âËø¡£ÏÖʵÉϸÃÊäÈëÀ¸ÎªÎı¾¿ò£¬ÇÒͼ±êΪÄÚǶµÄOLE¶ÔÏ󣬸öÔÏóÔÚµã»÷ºó±ã»á´¥·¢¡£
3. ͨ¹ýÌáÈ¡ÄÚǶµÄOLE¶ÔÏóÄÚÈÝ£¬·¢ÏÔìäÊÇÒ»¸öÃûΪStart_chain_1µÄppsxÌåʽµÄpptÎĵµ£¬µã»÷¼´¿É×Ô¶¯²¥·Åppt¡£
4.¸ÃppsxÎĵ·ûÓÃÁËCVE-2017-0199µÄ·ì϶£¬×Ô¶¯²¥·Åpptºó¼´¿É´¥·¢£¬²¢ÏÂÔØÔËÐÐÒ»¸ösct¾ç±¾¡£
5.sct¾ç±¾½âÃܺó»áŲÓÃPowershellÏÂÔØ²¢ÔËÐÐputty.exeºÍ×Ô¶¯¼ÓÔØStrategic_Chain.pdf£¬ÈÃÓû§ÎóÒÔΪÒѾ´ò¿ªÓйØÎĵµ³É¹¦¡£
6.³ýÉÏÊöÊÂÎñÖ®±í£¬¸Ã×é֯ͨ¹ýÓʼþ»¹·¢ËÍÒ»·âÃûΪEntanglementµÄppsxµÄÎĵµ£¬ÎĵµÍ¬ÑùʹÓÃÁËCVE-2017-0199·ì϶£¬ÀûÓÃÊÖ·¨ÓëµÚһ·¹¥»÷ÊÂÎñÀàËÆ¡£
7.ÓëÆäËû¹¥»÷ÊÂÎñ·ÖÆçµÄÊÇ£¬Óû§´ò¿ª¸ÃppsxÎĵµ²¢´¥·¢·ì϶ºó£¬»áͨ¹ýPowershellÏÂÔØÒ»·ÝÃûΪdecoyµÄppt²¢±»Powerpoint¼ÓÔØÆðÀ´¡£
¹¥»÷ÊÂÎñB
µÚ¶þ´Î¼¯Öй¥»÷ÊÂÎñ²úÉúÔÚ2018Äê3Ô£¬Í¶·ÅµÄÎĵµÖØÒªÀûÓÃCVE-2017-8570·ì϶½øÐй¥»÷£¬ÎĵµÄÚÈÝÒ²´ó¶àºÍÉç»áÕþÖÎÉúÑÄÓйء£
ÉÏÊö¹¥»÷ÎĵµËùʹÓõĹ¥»÷ÊÖ·¨ÆëȫһÑù£¬¶¼Ô̺¬2¸öPackageÀàÐ͵ÄOLE¶ÔÏóºÍ1¸ö½á¹¹»¯´æ´¢ÀàÐ͵ÄOLE¶ÔÏó¡£
ǰÁ½¸öPackageÀàÐ͵ÄOLE¶ÔÏóÀûÓÃPackager.dllµÄ»úÔì£¬ÕÆ¹Ü°ÑÄÚ²¿Ç¶ÈëµÄÎļþ¿ªÊ͵½%TMP%Ŀ¼Ï¡£
×îºóÒ»¸öOLE¶ÔÏóÀûÓÃCVE-2017-8570·ì϶£¬Í¨¹ýScriptlet Moniker´Ó¶ø¼ÓÔØsctÎļþÖеÄÄÚÈÝ¡£
·ì϶´¥·¢³É¹¦ºó£¬×îÖÕ³ÇÊпªÊͲ¢Æô¶¯Ò»¸öÃûΪqratµÄ·¨Ê½¡£
¹¥»÷ÊÂÎñC
ÔÚÏÕЩͬÆÚ£¬°×Ïó×éÖ¯»¹ÌáÒéÁËÁí±í¼¸Æð¹¥»÷ÊÂÎñ£¬ÕâЩ¹¥»÷ÊÂÎñÖØÒªÀûÓÃÁËCVE-2015-2545ºÍCVE-2017-0261·ì϶Îĵµ½øÐд¹µöÓʼþ¹¥»÷¡£Í¶·ÅµÄ·ì϶ÎļþÖÖÉæ¼°Èô¸ÉÖ÷Ì⣬ÆäÖÐÔ̺¬°Í»ù˹̹½¾ü×î½üµÄ¾üÊÂÍÆ½ø»î¶¯£¬Óë°Í»ù˹̹Ô×ÓÄÜίԱ»áÓйصÄÐÅÏ¢µÈ¡£Óйطì϶Îĵµ´¥·¢ºó»á¿ªÊÍа汾µÄBADNEWSϵÁÐľÂí¡£
ľÂí·ÖÎö
ÔÚÉÏÊö¼¸Æð¹¥»÷ÊÂÎñÖУ¬ÏÂÔØ£¨¿ªÊÍ£©µÄľÂíÖØÒªÓÐQuasarRATºÍBADNEWSÁ½ÖÖ¡£
QuasarRATľÂí
ÔÚ¹¥»÷ÊÂÎñAºÍ¹¥»÷ÊÂÎñBÖУ¬ÏÂÔØ£¨¿ªÊÍ£©µÄľÂíΪQuasarRAT¡£
1.¿ªÊ͵ÄľÂí°æ±¾ÐÅϢαÔì³É΢Èí»òQiho 360µÈ¡£
2.QuasarRATľÂíѡȡC#±àд£¬µ«×îз¢ÏֵľÂí±í²ãÔö³¤ÁËÒ»¶ÎLoader´úÂë¡£Loader´úÂëµÄÖØÒªÖ°ÄÜÊÇ·´¼ì²â·´É³ÏäÖ°ÄÜ£¬²¢ÔÚ×îºó¼ÓÔØÔʼQuasarRATľÂí¡£QuasarRATľÂíѡȡ¸ßÇ¿¶È»ìºÏ´¦Öá£
3.ÆäÖØÒªÖ°ÄÜÓÐÒÔϼ¸¸ö²¿ÃÅ£º
4.ÍøÂçϵͳÐÅÏ¢¡£
5.Ñù±¾ÔÚÍøÂçÍêÐÅÏ¢ºó£¬ »á³¢ÊÔÏνÓC&C·þÎñÆ÷¡£
6.×îºó½«ÍøÂçµ½µÄÐé¹¹»·¾³£¬·´²¡¶¾Èí¼þ£¬Ö÷»ú£¬Óû§ÃûµÈÐÅÏ¢·¢Ë͵½C&C·þÎñÆ÷¡£
BADNEWSľÂí
ÔÚ¹¥»÷ÊÂÎñCÖУ¬¿ªÊ͵ÄľÂíΪBADNEWSľÂí¡£
1.ÓйØÎĵµ´¥·¢·ì϶ºó»á¿ªÊÍÈý¸öÎļþ£º
%PROGRAMDATA%\Microsoft\DeviceSync\VMwareCplLauncher.exe
%PROGRAMDATA%\Microsoft\DeviceSync\vmtools.dll
%PROGRAMDATA%\Microsoft\DeviceSync\MSBuild.exe
ÆäÖÐVMwareCplLauncher.exeΪӵÓкϷ¨Êý×ÖÊðÃûµÄÎļþ£¬vmtools.dllΪ¾¹ý´Û¸ÄµÄdll£¬ÓÃÓÚ×îÖÕ¼ÓÔØBADNEWSµÄ×îбäÖÖMSBuild.exe¡£
2.VMwareCplLauncher.exeÔËÐк󣬻á×Ô¶¯¼ÓÔØvmtools.dll£¬vmtools.dllÖ´Ðкó»á´´½¨Ò»¸öÃûΪBaiduUpdateTask1µÄ¹¤×÷´òË㣬¸Ã¹¤×÷´òËãÿ¸ôÒ»·ÖÖÓ»áÖ´ÐÐÒ»´ÎMSBuild.exe¡£
3. MSBuild.exeÖ´Ðк󣬻áÏÂÔØ
hxxps://raw.githubusercontent.com/husngilgit/husnahazrt/master/xml.xml
È¡³ö¡°[[¡±ºÍ¡°]]¡±ÖÐÑëµÄBase64×Ö·û´®£¬¾¹ýÁ½´Îbase64½âÂëºÍÊý´Î½âÃܺóµÃµ½Ñù±¾±ØÒªÏνӵÄC&CµØÖ·¡£
4. Æ´´ÕÖ÷»úÉÏÏßÐÅÏ¢·¢Ë͵½C&C·þÎñÆ÷Ó²±àÂëµØÖ·¡£Ö÷»úÉÏÏßÐÅÏ¢ÌåʽÈçÏ£ºuuid=[UUID] #un=[µÇ¼Ãû]#cn=[ÍÆËã»úÃû]#on=[²Ù×÷ϵͳ°æ±¾] #lan=[IPµØÖ·]#nop=#ver=1.0¡£²¢Ê¹ÓÃAES¼ÓÃÜËã·¨£¨ÃÜÔ¿£ºDD1876848203D9E10ABCEEC07282FF37£©+base64±àÂë·¢Ë͵½//e3e7e71a0b28b5e96cc492e636722f73//4sVKAOvu3D//ABDYot0NxyG.php
5.ÔÚʹÓÃbase64±àÂëºó»¹¶Ô±àÂëºóµÄÊý¾ÝµÄ¹Ì¶¨Æ«ÒƵØÎ»µÄ²åÈ롱=¡±ºÍ¡±&¡±×Ö·û¡£
6.ÍøÂç¿Í»§¶Ë·ÇÒÆ¶¯´ÅÅ̵ÄÃô¸ÐÎļþÁбí
£¨.xls£¬.xlsx£¬.doc£¬.docx£¬.ppt£¬.pptx£¬.pdfµÈ£©£¬²¢±£ÁôΪһʱĿ¼ÏµÄedg499.dat¡£
7.´´½¨Ị̈߳¬½«¼üÅ̼ͼÐÅÏ¢£¬´°¿ÚÐÅÏ¢µÈ±£ÁôΪһʱĿ¼ÏµÄTPX498.dat¡£
8.ÉÏÊö±£ÁôΪdatÎļþµÄÊý¾Ý£¬Í¬ÑùʹÓÃÉÏÊöAES¼ÓÃÜËã·¨+base64±àÂë·¢ËÍ¡£µ«·¢Ë͵ÄÓ²±àÂëµØÖ·±äΪ\e3e7e71a0b28b5e96cc492e636722f73\4sVKAOvu3D\UYEfgEpXAOE.php
×ܽá
°×Ïó×éÖ¯Ä¿Ç°ÖØÒªÍþвָ±êΪ°Í»ù˹̹ºÍÖйúµÄ´óÃæ»ýÖ¸±ê£¬Ô̺¬½ÌÓý¡¢¾üÊ¡¢¿ÆÑÓעýÌåµÈ¸÷ÀàÖ¸±ê¡£ÆäÏȵ¼¹¥»÷¼¿Á©¶àΪÓã²æÊ½´¹µöÓʼþ£¬·¢ËÍ´øÓÐÌåʽ·ì϶ÎĵµµÄÁ´½Ó£¬²¢ÇÒÉÆÓÚαÔìÓйؾüÊ¡¢ÕþÖÎÐÅÏ¢£¬½ÏΪ¾«ÃÜ¡£
Ŀǰ¸Ã×éÖ¯ÒѾ³É³¤ÎªÓнϸ߹¥»÷ÄÜÁ¦µÄÓ×·Ö¶Ó£¬ÇÒʹÓõķì϶µÄÊÖ·¨Ò²±ÈÁ¦ÐÂÏÊ£¬¶ÔÉç»á¹¤³ÌѧµÄ°ÑÄóÏ൱µÄ¾«ÃÕâ´Ó½üÆÚ¶àÆð¹¥»÷ÊÂÎñÖоÍÄܹ»¿´³ö¡£ ¶ÔÓÚÀàËÆ°×ÏóµÄ¹¥»÷×éÖ¯£¬ÓÉÓÚ´ÓÀ´¸ü¶àÒÀÀ·àËÆµç×ÓÓʼþÕâÑùµÄ»¥ÁªÍøÈë¿Ú£¬Æäʵ±¾Äܹ»ºÜºÃµÄ×öµ½·ÀÓù£¬µ«Í¨¹ýÓÕµ¼ÐÔµÄ˵»°È´Äܹ»°ÑÕâЩ·ÀÓù´ëÊ©ÎÞЧ»¯¡£Òò¶ø£¬¼ÓÇ¿¶ÔÈËÔ±µÄ°²È«Ë¼Ïë½ÌÓý£¬Äܹ»ºÜºÃµÄÔ¤·ÀÀàËÆ°²È«ÊÂÎñµÄ²úÉú¡£
ÓйØIOC
rannd.org
brokings.org
crazywomen-dating.com
ifenngnews.com
209.58.185.37
mail.ifenngnews.com
chinapolicyanalysis.org
94.242.249.203
209.58.183.33
¹ØÓڽ𾦰²È«×êÑÐÍŶÓ
½ð¾¦°²È«×êÑÐÍŶÓÊÇGA»Æ½ð¼×¼¯Íżì²â²úÆ·±¾²¿´ÓÊÂרҵ°²È«·ÖÎöµÄ¼¼ÊõÐÍÍŶӣ¬ÖØÒªÖ°ÔðÊǶÔÏÖÓвúÆ·Éϱ¨µÄ°²È«ÊÂÎñ¡¢Ñù±¾Êý¾Ý½øÐÐÍÚ¾ò¡¢·ÖÎö£¬²¢ÏòÓû§ÌṩרҵµÄ·ÖÎö»ã±¨¡£
¹ØÓÚVenusEyeÍþвµý±¨ÖÐÐÄ
VenusEyeÍþвµý±¨ÖÐÐÄ£¨www.venuseye.vip£©ÊÇGA»Æ½ð¼×ÇãÁ¦´òÔìµÄ¼¯Íþвµý±¨ÍøÂç¡¢·ÖÎö¡¢´¦Öᢰ䲼ºÍÀûÓÃΪһÌåµÄÍþвµý±¨ÔÆ·þÎñƽ̨£¬ÌṩÍþвµý±¨Êý¾Ý¡¢ÏµÍ³¡¢¼¼ÊõºÍרҵÄÜÁ¦µÄÊä³ö¡£


¾©¹«Íø°²±¸11010802024551ºÅ