Õý¶ù°Ë¾Ëµ¼¼Êõ¡ª¡ªÒÔEmotetΪÀýÉî¿Ì·ÖÎöCMDºÅÁî»ìºÏ¼¼Êõ
°ä²¼¹¦·ò 2018-12-13CMDºÍPowershellºÅÁîʱʱ±»ÓÃÔÚ¶ñÒâÈí¼þÖÐÖ´ÐжñÒâ¾ç±¾Îļþ£¬²¢Í¨¹ý¾ç±¾»ìºÏ¡¢¼ÓÃÜ»ò±àÂ뷽ʽÀ´ÈƹýAV¼ì²â¡£±¾ÎÄÁоÙÁ½¸öµäÐ͵ÄEmotet´«²¼ÖÐʹÓõĻìºÏCMDºÅÁÀ´Éî¿Ì·ÖÎöCMD.ºÅÁî»ìºÏ¼¼Êõ¡£
ÏÈ¿´Ò»¸ö´ÓDOCÎĵµÇ¶ÈëµÄVBAºê´úÂëÖÐÌáÈ¡µÄCMDºÅÁէһ¿´ÉÏÈ¥£¬ÏñÊÇÎÞÒâ˼µÄÒ»´®×Ö·û£¬×Ðϸ·ÖÎöÆðÀ´±ØÒªÏÈÏàʶһÏÂCMDºÅÁîµÄ»ìºÏ·½Ê½¡£
CMDºÅÁîµÄ»ìºÏ·½Ê½
²åÈëÌØÊâ×Ö·û»ìºÏºÅÁî
×Ö·û¡°^¡±ÊÇCMDºÅÁîÖÐ×î³£¼ûµÄתÒå×Ö·û£¬¸Ã×Ö·û²»Ó°ÏìºÅÁîµÄÖ´ÐС£ÓÉÓÚÔÚcmd»·¾³ÖУ¬ÓÐЩ×Ö·û¾ß±¸ÌØÊâÖ°ÄÜ£¬Èç >¡¢>>°µÊ¾³Á¶¨Ïò£¬| °µÊ¾¹Ü·£¬&¡¢&&¡¢|| °µÊ¾Óï¾äÏνӡ£ËüÃǶ¼ÓÐÌØ¶¨µÄÖ°ÄÜ£¬ÈôÊDZØÒª°ÑËüÃÇ×÷Ϊ×Ö·ûÊä³öµÄ»°£¬echo >¡¢echo |Ö®ÀàµÄд·¨¾Í»á·¸´í¡ª¡ªcmdÚ¹ÊÍÆ÷»á°ÑËüÃÇ×÷ΪӵÓÐÌØÊâÖ°ÄܵÄ×Ö·û¶Ô´ý£¬¶ø²»»á×÷Ϊͨ³£×Ö·û´¦Öã¬Õâ¸öʱ³½£¬¾Í±ØÒª¶ÔÕâÐ©ÌØÊâ×Ö·û×öתÒå´¦ÖãºÔÚÿ¸öÌØÊâ×Ö·ûǰ¼ÓÉÏתÒå×Ö·û^¡£
Òò¶ø£¬ÒªÊä³öÕâÐ©ÌØÊâ×Ö·û£¬¾Í±ØÒªÓà echo ^>¡¢echo ^|¡¢echo ^|^|¡¢echo ^^Ö®ÀàµÄÌåʽÀ´´¦Öá£Áí±í£¬´ËתÒå×Ö·û»¹Äܹ»ÓÃ×÷ÐøÐзûºÅ¡£
¶ººÅ¡°,¡±ºÍ·ÖºÅ ¡°;¡±Äܹ»»¥»»£¬Äܹ»È¡´úºÅÁîÖеĺϷ¨¿Õ¸ñ¡£¶à¸ö¿Õ¸ñÒ²²»Ó°ÏìºÅÁîÖ´ÐС£
³É¶ÔµÄÔ²À¨ºÅ£¨£©Ò²»á³Ê´Ë¿ÌºÅÁî²ÎÊýÖУ¬Ò²²»Ó°ÏìºÅÁîµÄÖ´ÐС£Ô²À¨ºÅ°µÊ¾Ç¶Èë×ÓºÅÁî×飬ͬÑù±»cmd.exe²ÎÊý´¦ÖÃÆ÷½øÐÐÚ¹ÊÍ¡£È磺cmd.exe /c ( ( ((echo Command 1) ) )) &&( ( (((((echo Command 2))))) ) )
ÀûÓÃCMD»·¾³±äÁ¿Æ´½ÓºÅÁî
Cmd.exeÄÚ²¿ºÅÁîÓУº set¡¢assoc £¬ftypeµÈ¡£
SetºÅÁîÓÃÀ´ÏÔʾ¡¢ÉèÖûòɾ³ýcmd.exe»·¾³±äÁ¿¡£ºÅÁîÌåʽ£º
SET [variable=[string]]
variable Ö¸¶¨»·¾³±äÁ¿Ãû¡£
string Ö¸¶¨ÒªÖ¸Åɸø±äÁ¿µÄһϵÁÐ×Ö·û´®¡£
ÔÚºÅÁîÐÐÖÐÊäÈë set£¬»áÁоٳöcmd.exeÖÐËùÓеĻ·¾³±äÁ¿¡£
assoc£ºÎļþÃûÀ©´ó¹ØÁªºÅÁÓÃÓÚÏÔʾºÍÉèÖÃÎļþÃûÀ©´ó¹ØÁª£¬Äܹ»Ö¸¶¨Ä³ÖÖºó׺ÃûµÄÎļþÒÀÕÕÌØ¶¨µÄÀàÐÍÎļþ´ò¿ª»òÖ´ÐС£ºÅÁîÌåʽΪ£ºassoc [.ext[=[fileType]]]
.extÊÇÖ¸£ºÖ¸¶¨Òª¹ØÁªµÄÎļþºó׺Ãû¡£µãºÅ£¨.)ÊDz»ÄÜÊ¡ÂԵģ¬ÈôÊÇÊ¡ÂÔÁËϵͳ½«ÏÔʾ¸Ãºó׺ÃûÎļþµÄ¹ØÁªÐÅÏ¢¡£fileTypeÊÇÖ¸£ºÖ¸¶¨ÓйØÁªµÄÎļþÀàÐÍ¡£ÈôÊÇֻʹÓøòÎÊý£¬½«ÏÔʾ¸ÃÎļþÀàÐ͵ÄÐÅÏ¢¡£·´Ö®£¬¸ÃºÅÁÁгöϵͳע²áµÄËØÓкó׺ÃûÎļþºÍÓйصÄÀàÐÍ¡£
ftype£ºÏÔʾ»òÅú¸ÄÓÃÔÚÎļþÀ©´óÃû¹ØÁªÖеÄÎļþÀàÐÍ£¬Ö¸¶¨Ò»ÖÖÀàÐ͵ÄÎļþĬÈÏÓÃÄĸö·¨Ê½ÔËÐлò´ò¿ª¡£ºÅÁîÌåʽΪ£ºftype [fileType[=[openCommandString]]
cmd.exeµÄ»·¾³±äÁ¿·ÖΪϵͳÒÑÓеĻ·¾³±äÁ¿ºÍ×Ô½ç˵±äÁ¿¡£ÀûÓû·¾³±äÁ¿µÄÖµÖеÄ×Ö·û»ò×Ö·û´®£¬Äܹ»Æ´½Ó³ÉºÚ¿Í±ØÒªµÄcmdºÅÁͬʱÄܹ»Ìӱܾ²Ì¬¼ì²â¡£ÈçϵͳÒÑÓеĻ·¾³±äÁ¿%comspec%±äÁ¿µÄֵĬÒÔΪ£º¡°C:\WINDOWS\system32\cmd.exe¡±£¬setºÅÁîÄܹ»±»±àÂëΪ£º %comspec:~11,1%%comspec:~-1%%comspec:~-13,1%¡£
%VarName:~offset[,length]% ÖØÒªÓÃÓÚ»ñÈ¡»·¾³±äÁ¿VarNameµÄ±äÁ¿Öµ£¬Æ«ÒÆoffset×Ö½ÚÖ®ºó³¤¶ÈΪlength¸ö×Ö½Ú¡£[,length]¿ÉÊ¡ÂÔ¡£
%comspec:~11,1%°µÊ¾È¡comspec±äÁ¿ÖµÖеÄ×Ö·û£¬Ä¬ÈÏϱê´Ó0ÆðÍ·£¬´Óϱê11ÆðÍ·£¬È¡Ò»¸ö×Ö·û£¬¼´Îª¡±s¡±¡£offsetÒ²Ö§³Ö¸ºÊý£¬°µÊ¾·´Ïò±éÀú×Ö·û´®µÄϱꡣ%comspec:~-1%¼´Îª¡°e¡°£¬%comspec:~-13,1%¼´Îª¡±t¡°¡£Èç´Ë±àÂësetºÅÁÄܹ»ÌÓÍѾ²Ì¬¼ì²â¡±set¡°ºÅÁî×Ö·û´®µÄ¼ì²â»úÔì¡£
ͨ³£ÎÒÃÇÒ²Äܹ»×Ô½ç˵һ¸ö»òÕß¶à¸ö»·¾³±äÁ¿£¬ÀûÓû·¾³±äÁ¿ÖµÖеÄ×Ö·û£¬ÌáÈ¡²¢Æ´½Ó³ö×îÖÕÏëÒªµÄcmdºÅÁî¡£Èç:
Cmd /C ¡°set envar=net user && call echo %envar%¡° Äܹ»Æ´½Ó³öcmdºÅÁnet user
Ò²Äܹ»½ç˵¶à¸ö»·¾³±äÁ¿½øÐÐÆ´½ÓºÅÁî´®£¬Ìá¸ß¾²Ì¬·ÖÎöµÄ¸´ÔÓ¶È£º
cmd /c ¡° set envar1=ser&& set envar2=ne&& set envar3=t u&&call echo %envar2%%envar3%%envar1%¡±
cmdºÅÁîµÄ¡°/C¡±²ÎÊý£¬Cmd /C ¡°string¡±°µÊ¾£ºÖ´ÐÐ×Ö·û´®stringÖ¸¶¨µÄºÅÁ¶øºóÖÕÖ¹¡£
¶øÆôÓÃÑÓ³¤µÄ»·¾³±äÁ¿À©´ó£¬Ê±Ê±Ê¹Óà cmd.exeµÄ /V:ON²ÎÊý£¬
/V:ON²ÎÊýÆôÓÃʱ£¬Äܹ»²»Ê¹ÓÃcallºÅÁîÀ´À©´ó±äÁ¿£¬Ê¹Óà %var% »ò !var! À´À©´ó±äÁ¿£¬!var!Äܹ»ÓÃÀ´°ü°ì%var%£¬Ò²¾ÍÊÇÄܹ»Ê¹ÓøÐ̾ºÅ×Ö·ûÀ´´úÌæÔËÐÐʱµÄ»·¾³±äÁ¿Öµ¡£ºóÃæ½éÉÜForÑ»·Ê±»á±ØÒª¿ªÆô/V:²ÎÊýÑÓ³¤±äÁ¿À©´ó·½Ê½¡£
ÀûÓÃForÑ»·Æ´½ÓºÅÁî
ForÑ»·Ê±Ê±±»ÓÃÀ´»ìºÏ´¦ÖÃcmdºÅÁʹµÃcmdºÅÁî¿´ÆðÀ´¸´ÔÓÇÒÄÑÒÔ¼ì²â¡£×î³£ÓõÄForÑ»·²ÎÊýÓÐ /L,/F²ÎÊý¡£
FOR ²ÎÊý %±äÁ¿Ãû IN (ÓйØÎļþ»òºÅÁî) DO Ö´ÐеĺÅÁî
FOR %variable IN (set) DO command [command-parameters]
%variable Ö¸¶¨Ò»¸öµ¥Ò»×Öĸ¿É´úÌæµÄ²ÎÊý¡£ Õâ¸ö±äÁ¿Ãû¿ÉËùÒÔÓ×дa-z»òÕß´óдA-Z,·Ö±æ´óÓ×д,FOR»á°Ñÿ¸ö¶ÁÈ¡µ½µÄÖµ¸³¸ø¸Ã±äÁ¿¡£ÔÚÅú´¦ÖÃÎļþÖУ¬ÒýÓñäÁ¿ÒªÓÃ%%variable£¬ÎÒÃÇÕâÀïÖØÒª½éÉÜÔÚcmd´°¿ÚÖУ¬ÒýÓñäÁ¿ÓÃ%variable¼´¿É¡£(set) Ö¸¶¨Ò»¸ö»òÒ»×éÎļþ¡£Äܹ»Ê¹ÓÃͨÅä·û¡£ ÓйصÄÎļþ»òºÅÁî¡£
command Ö¸¶¨¶Ôÿ¸öÎļþÖ´ÐеĺÅÁî¡£
command-parameters
ÎªÌØ¶¨ÊýÁîÖ¸¶¨²ÎÊý»òºÅÁîÐпª¹Ø¡£
/L ²ÎÊý£º µü´úÊýÖµÁìÓò
for /L %variable in (start,step,end) do command [command-parameters]
¸ÃºÅÁʾÒÔÔöÁ¿´ó¾Ö´ÓÆðÍ·µ½ÊµÏÖµÄÒ»¸öÊý×ÖÐòÁС£Ê¹Óõü´ú±äÁ¿ÉèÖÃÕØÊ¼Öµ(start)£¬¶øºóÖð²½Ö´ÐÐÒ»×éÁìÓòµÄÖµ£¬Ö±µ½¸ÃÖµ³¬¹ýËùÉèÖõÄÖÕÖ¹Öµ (end)¡£/L ½«Í¨¹ý¶ÔstartÓëend½øÐбÈÁ¦À´Ö´Ðеü´ú±äÁ¿¡£ÈôÊÇstartÓ×ÓÚend£¬¾Í»áÖ´ÐиúÅÁ²»È»ºÅÁîÚ¹ÊÍ·¨Ê½Í˳ö´ËÑ»·¡£»¹Äܹ»Ê¹ÓøºµÄ stepÒԵݼõÊýÖµµÄ·½Ê½Öð²½Ö´ÐдËÁìÓòÄÚµÄÖµ¡£ÀýÈ磬(1,1,5) ÌìÉúÐòÁÐ 1 2 3 4 5£¬¶ø (5,-1,1) ÔòÌìÉúÐòÁÐ (5 4 3 2 1)¡£ºÅÁîcmd /C ¡°for /L %i in (1,1,5) do start cmd¡±,»áÖ´Ðдò¿ª5¸öcmd´°¿Ú¡£
/F²ÎÊý£º ÊÇ×î׳´óµÄºÅÁÓÃÀ´´¦ÖÃÎļþºÍһЩºÅÁîµÄÊä³öÁ˾֡£
FOR /F ["options"] %variable IN (file-set) DO command [command-parameters]
FOR /F ["options"] %variable IN ("string") DO command [command-parameters]
FOR /F ["options"] %variable IN ('command') DO command [command-parameters]
(file-set) ΪÎļþÃû£¬for»á˳´Î½«file-setÖеÄÎļþ´ò¿ª£¬²¢ÇÒÔÚ½øÐе½ÏÂÒ»¸öÎļþ֮ǰ½«Ã¿¸öÎļþ¶ÁÈ¡µ½Äڴ棬ÒÀÕÕÿһÐзֳÉÒ»¸öÒ»¸öµÄÔªËØ£¬ºöÂÔ¿ÕȱÐС£
("string")´ú±í×Ö·û´®£¬('command')´ú±íºÅÁî¡£
Èç¹ûÎļþaa.txtÖÐÓÐÈçÏÂÄÚÈÝ£º
µÚ1ÐеÚ1ÁÐ µÚ1ÐеÚ2ÁÐ
µÚ2ÐеÚ1ÁÐ µÚ2ÐеÚ2ÁÐ
ÒªÏë¶Á³öaa.txtÖеÄÄÚÈÝ£¬Äܹ»ÓÃfor /F %i in (aa.txt) do echo %i £¬ÈôÊÇÈ¥µô/F²ÎÊýÔòÖ»»áÊä³öaa.txt£¬²¢²»»á¶ÁÈ¡ÆäÖеÄÄÚÈÝ¡£
ÎÒÃǰÎȡнüµÄEmotetÑù±¾ÏÂÔØÀûÓõÄCMDºÅÁî»ìºÏ£¬À´ÀûÓÃÇ°ÃæµÄ֪ʶÀ´½â»ìºÏ¡£
ÀûÓÃ×Ô½ç˵»·¾³±äÁ¿ºÍForÑ»·»ìºÏ
¸ÃÑù±¾ÖÐÀûÓÃÁËcmd.exe µÄÆôÓÃÑÓ³¤»·¾³±äÁ¿/V:ON²ÎÊý£¬/C²ÎÊý£¬ÀûÓÃsetºÅÁî×Ô½ç˵һ¸ö»·¾³±äÁ¿kpx=lHUwrRfzapaiNzCqHfu:Doc(4YQ0S.1,xk}$) s6dK=mn5/+ygbW-TeP\v2tj{78Mh@;BO'FZ£¬Í¨¹ý&&Æ´½ÓºÅÁ¶øºóÊǸöforÑ»·£º for %G in £¨ÊýÁУ©do set 1q=!1q!!kpx:~ %G, 1!&& if %G== 81 call %1q:~ -377%¡£ÎÒÃÇ×ųÁ·ÖÎöÏÂforºÅÁî¡£ÓÉÓÚÇ°ÃæÊ¹ÓÃÁËÑÓ³¤»·¾³±äÁ¿£¬ËùÒÔÄܹ»Ê¹ÓÃ!1q!!kpx:~ %G, 1!µÄ·½Ê½À´À©´ó±äÁ¿£¬ÔÚÔËÐÐʱ°ü°ì»·¾³±äÁ¿Öµ¡£forµÄÑ»·±äÁ¿ÊÇ%G£¬%G in (ÊýÁÐÖµ)£¬!kpx:~ %G, 1!°µÊ¾È¡»·¾³±äÁ¿kpxÖÐϱêΪ%GµÄÒ»¸ö×Ö·û£¬ÎÒÃÇÄܹ»ÓÃÈçÏÂpython±àÂëʵÏÖ¸ÃÖ°ÄÜ¡£ÊýÁÐÖеĿոñÄܹ»ºöÂÔ£¬ÊýÁÐÖеÄÊýÖµÕýºÃÊÇ377¸ö£¬kpx×Ö·û´®µÄ³¤¶ÈÊÇ72¸ö×Ö·û£¬Ï±êΪ81ÒѾ²»´æÔÚ£¬ËùÒÔµ±Ï±ê%G==81ʱ£¬ÔËÐÐʱ»·¾³±äÁ¿1q=!1q!powershell ¡¡, call %1q:~-377%£¬ËùÒÔÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÊÇforÑ»·±éÀú³öµÄpowershell¡¡ºÅÁî£¬Ç°ÃæµÄ1q=!1q!Êdzõʼ»¯±äÁ¿1q£¬±ØÒª±»È¥µôÒÔÃâÓ°ÏìÕý³£ºÅÁîµÄÖ´ÐУ¬ËùÒÔÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÈÆ¹ýÇ°ÃæµÄ!1q!¡£
Êä³ö£º
ÏÂÔØEmotetµÄÁ´½ÓΪ£º
http://catbayouthaction.com/jKS86a
http://spsystems24.ru/O
http://xn--80abdh8aeoadtg.xn--p1ai/multimedia/hD4lyk7
http://borsehung.pro/pfWq
http://inpart-auto.ru/x2bu
ÀûÓÃcmdϵͳ»·¾³±äÁ¿ºÍForÑ»·»ìºÏ
ÏȽ«»ìºÏcmdºÅÁîÖеÄתÒå×Ö·û¡°^¡±È«ÊýÈ¥µô£¬ÔÙ½«³ýÁ˱äÁ¿@Ö®±íµÄ¶ººÅ¡°,¡±¡¢·ÖºÅ¡°;¡±¡¢ÓÐÓà¿Õ¸ñɾ³ý¡£°ÑÎȱ£Áô±äÁ¿@ÖеĶººÅºÍ·ÖºÅ£¬²»È»Ó°ÏìÊä³öÁ˾֡£
¿É¼ûÀûÓÃÁËcmdµÄϵͳ»·¾³±äÁ¿%comspec%£¬¼´ÊÇcmd.exeµÄÖ´ÐÐõè¾¶¡£ÀûÓÃForÑ»·µÄF²ÎÊý£¬ÔÚºÅÁî'aSsoC .cmd'ÖÐÒÔ×Ö·ûv¡¢f¡¢=Ϊ·Ö¸ô·û£¬È¡µÚ¶þÁм´ÊÇ¡°cmd¡±¡£
fOr /f " delims=vf= tokens=2" %f IN ( 'aSsoC .cmd' ) dO %f ¡£ÆäËûÎÞÒâ˼µÄ×Ö·û´®»á±»cmdºöÂÔ¡£
½Ó×Å×Ô½ç˵ÁËÒ»¸ö»·¾³±äÁ¿@£¬µÅ×ÚÒ»¸ö1460³¤¶ÈµÄ×Ö·û´®¡£¶øºóÀûÓÃForÑ»·µÄ/L²ÎÊý£¬±éÀú±äÁ¿@£ºFOr /L %s In (1459,-4,+3 ) do (( ( (( seT \=!\!!@ :~ %s, 1!))))& iF %s eQU 3 (((CaLl %\ :~ -365% )£¬×Ô½ç˵ÁË»·¾³±äÁ¿¡°\¡±£¬ÀûÓû·¾³±äÁ¿À©´ó·ûºÅ£¡£¬!@ :~ %s, 1!°µÊ¾Ñ»·±äÁ¿%s´Ó1459ÆðÍ·£¬²½³¤Îª-4£¬µ½3ʵÏÖ£¬Ñ»·ÌáÈ¡±äÁ¿@ÖеÄÒ»¸ö×Ö·û£¬³¤¶ÈΪ365¸ö×Ö·û£¬¼´´ÓForÑ»·³Á×é³öµÄºÅÁîÆðÍ·Ö´ÐС£
ÎÒÃDZàдpython¾ç±¾ÊµÏÖForÑ»·Ö°ÄÜ£º
×îÖÕ½âÃܳö¿É¶ÁµÄÄÚǶpowershellºÅÁ
ÏÂÔØEmotetµÄÁ´½ÓΪ£º
http://reitmaier.de/01cedmfXohttp://phoxart.com/sWP0E9
http://panbras.com.br/FHhUYIQ
http://osmanager.com.br/t3HnvWx9x
http://oldwillysforum.com/ChleCkW
²Î¿¼£º
https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/dosfuscation-report.pdf


¾©¹«Íø°²±¸11010802024551ºÅ