½ÒÆÆ¡°Òøºü¡±ÕæÈÝ £¬ÈÃÍþвÎÞ´¦¶ÝÐÎ

Ðû²¼Ê±¼ä 2024-08-08

±àÕß°´£º


½üÆÚ £¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø±±¶·Çå¾²ÔËÓªÖÐÐÄͨ¹ýÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¼à²âµ½Ò»Æð ¡°(¶¾Êó)ÅþÁ¬C2·þÎñÆ÷¡±¸æ¾¯ÊÂÎñ £¬µÚһʱ¼äÓë²úÆ·Ïß¾ÙÐÐËÝÔ´È¡Ö¤ÆÊÎö £¬È·ÈÏÔ´Í·ÊÇijԱ¹¤×°ÖÃÁËLetsVPN¡£¾­½ð¾¦ÍŶÓÆÊÎöÅÐ¶Ï £¬¸ÃLetsVPN×°Öðü±»À¦°óÁËÒøºüµÄWinOS 4.0Ô¶¿ØºóÃÅ¡£±¾ÎĽ«Ïêϸ½ÒÆÆÕâÒ»ÊÂÎñµÄίÇü £¬ÆÊÎöÆäÖеÄÇå¾²Îó²îÓëΣº¦ £¬ÎªÆóÒµÍøÂçÇå¾²·À»¤Ìṩ¾¯Ê¾Óë½è¼ø¡£


×÷Éõ¡°Òøºü¡±£¿


ÒøºüľÂíÊÇÒ»ÀàÕë¶ÔÌض¨Ä¿µÄȺÌå¾ÙÐд¹ÂÚ¹¥»÷µÄ¶ñÒâÈí¼þ £¬ÆäÖ÷Òª¹¥»÷¹¤¾ß°üÀ¨ÆóÊÂÒµµ¥Î»µÄÖÎÀíÖ°Ô±¡¢²ÆÎñÖ°Ô±¡¢ÏúÊÛÖ°Ô±¡¢½ðÈÚ´ÓÒµÖ°Ô±ÒÔ¼°µçÉÌÂô¼ÒµÈ¡£ÕâÀàľÂíͨ¹ý¶àÖÖÊֶξÙÐÐÈö²¥ £¬¶ÔÊܺ¦ÕßµÄÅÌËã»úϵͳ¾ÙÐпØÖƺÍÇÔÈ¡Òþ˽Êý¾Ý £¬½ø¶øΪºóÐøµÄÕ©Æ­Ô˶¯Ìṩ±ãµ±¡£

¡°Òøºü¡±Èö²¥·½·¨


ÒøºüľÂíÖ÷Ҫͨ¹ýÒÔϼ¸ÖÖ·½·¨¾ÙÐÐÈö²¥£º


1¡¢¼´Ê±Í¨Ñ¶¹¤¾ß£¨IM£©´¹ÂÚ

¹¥»÷Õßͨ¹ýQQ¡¢Î¢Ðŵȼ´Ê±Í¨Ñ¶¹¤¾ß·¢ËÍ´¹ÂÚÎļþ»òÍøÕ¾Á´½Ó £¬ÓÕµ¼Êܺ¦Õßµã»÷²¢¾ÙÐÐÈö²¥¡£ÕâЩÎļþ»òÁ´½Óͨ³ £»áαװ³É¾ßÓÐÓÕµ¼ÐÔµÄÃû³Æ £¬È硰Ч¹ûµ¥¡±¡°×ªÕË֪ͨµ¥¡±µÈ¡£


2¡¢´¹ÂÚÍøÕ¾

¹¥»÷Õß»áαÔìË°Îñ»ú¹Ø¡¢½ðÈÚ»ú¹¹µÈ¹Ù·½ÍøÕ¾µÄ´¹ÂÚÍøÕ¾ £¬Ê¹ÓÃ΢ÐÅ´¹Âڵȷ½·¨¾ÙÐÐÈö²¥¡£ÕâЩÍøվͨ³ £»áÒÔ·¢Æ±¡¢Æ±¾Ý¡¢±¨Ë°¡¢Ë°ÎñÈí¼þµÈÃûÒåÓÕµ¼Êܺ¦ÕßÏÂÔز¢Ö´ÐжñÒâÈí¼þ¡£


3¡¢Î±×°Õý³£Èí¼þ

ÒøºüľÂí»¹»áαװ³É³£ÓÃÈí¼þ £¬ÈçWPS¡¢MS Office¡¢PDF¡¢Î¢ÐÅ¡¢¶¤¶¤µÈÊýÊ®¿îÈí¼þ £¬Í¨¹ýÔÚÖ÷Á÷ËÑË÷ÒýÇæÉϹºÖÃÁ÷Á¿¾ÙÐд¹ÂÚÈö²¥ £¬ÕâÊÇÏÖÔÚÈö²¥Á¿×î´óµÄÒ»ÖÖÈö²¥·½·¨¡£

ÑùÌìÖ°Îö


´Ó¹ÙÍøÏÂÔصÄ×°Öðülest-test.3.1.2.msi £¬±»À¦°óÁËÒøºüWinOS 4.0Ô¶¿ØºóÃÅ £¬¹ÙÍøÁ´½Ó£ºhttps://letpvpn.com¡£ÆÊÎöÈçÏ£º


MSIÎļþ £¬¼´Microsoft InstallerµÄ×°Öðü £¬×¨ÎªWindowsϵͳÉè¼Æ £¬ÓÃÓÚ×°Öá¢Ð¶ÔØ¡¢ÐÞ¸´¼°¸üÐÂÈí¼þ¡£×÷ΪÎļþÃûÌà £¬Ëü²»ÓÉÓû§Ö±½ÓÖ´ÐÐ £¬¶øÊÇÓÉϵͳµÄMS Installer·þÎñ£¨ÔËÐÐÓÚSYSTEMÕË»§£©´¦Öóͷ£¡£ÕâÒ»»úÖƲ»µ«¸¶Óë²Ù×÷ÖÎÀíԱȨÏÞ £¬»¹¿ÉÄÜ´¥¼°SYSTEM×î¸ßȨÏÞ £¬ÊµÏÖ¸ßЧÇå¾²µÄÈí¼þÖÎÀí¡£


1¡¢Í¨¹ýOrca¹¤¾ß £¬Éó²élest-test.3.1.2.msi×°ÖðüÎļþ¡£


ͼƬ1.png


2¡¢Í¨¹ý×°ÖðüÉèÖÃÏêÇéÏÔ×Å¿ÉÒÔ¿´³ö£º×°ÖðüÀïµÄÎļþ¡°__4¡±±»×°ÖÃÉúÑÄΪÎļþÃû¡°1¡± £¬¡°xQJnSaS.exe¡±±»ÉúÑÄΪÎļþÃû¡°XPsdjAV.exe¡±¡£


3¡¢ÔËÐÐlest-test.3.1.2.msi×°ÖðüÖ®ºó £¬×°ÖÃÊͷŵÄÎļþ¡£


ͼƬ2.png


4¡¢ÓëOrca¹¤¾ßÉó²éµÄÏêÇéÍêÈ«¶ÔÓ¦µÄÉÏ £¬ÆäÖС°xQGEJun.exe¡±ÊÇÕæÕýµÄletsvpn×°Öðü £¬ÓÃÀ´ÒÉ»óÊܺ¦Õß¡£


ÊÖÒÕÔ­Àí


¡°XPsdjAV.exe¡±¡°libcurl.dll¡±ºÍ¡°1¡±ÊÇÒÔ°×¼ÓºÚÐÎʽÔËÐеÄWinOS 4.0Ô¶¿Ø¡£ÆäÖÐ £¬¡°XPsdjAV.exe¡±×Ô¼ºÊÇ°×Îļþ £¬ÇÒÓÐÊý×ÖÊðÃû¡£¡°libcurl.dll¡±ÊDZ»¸Ä¶¯µÄ¶ñÒâÎļþ¡£¡°libcurl.dll¡±±»¡°XPsdjAV.exe¡±¼ÓÔØÖ´Ðкó £¬¶ÁÈ¡Îļþ¡°1¡± £¬½âÃܳöWinOS 4.0µÄÔ¶¿Ø½¹µã´úÂë¡£

ͼƬ3.png

ÕâÊÇÒ»Öֵ䷶µÄ"°×¼ÓºÚ"¹¥»÷ģʽ¡£ÔÚÕâÖÖģʽÏ £¬Ðí¶àÖÕ¶Ëɱ¶¾Èí¼þ»áĬÈÏÐÅÍÐÄÇЩ´øÓÐÓÐÓÃÊý×ÖÊðÃûµÄ³ÌÐò £¬ÒÔΪËüÃÇÊÇÇå¾²µÄ¡£È»¶ø £¬¹¥»÷Õß¿ÉÄÜ»áʹÓÃÕâÖÖ»úÖÆÀ´ÊµÏÖËùνµÄ"Ãâɱ"Ч¹û¡£

ÏêϸÀ´Ëµ £¬¹¥»÷Õß¿ÉÄÜ»áʹÓÃÒ»¸ö´øÓÐÊý×ÖÊðÃûÇÒδ±»¸Ä¶¯µÄÕýµ±³ÌÐò£¨ÀýÈç"XPsdjAV.exe"£© £¬À´ÓÕƭɱ¶¾Èí¼þ¡£È»ºó £¬ËûÃÇ¿ÉÄÜ»áÐ޸ĸóÌÐòËùÒÀÀµ²¢Å²ÓõÄDLLÎļþ£¨ÀýÈç"libcurl.dll"£© £¬Ê¹µÃ¶ñÒâµÄDLLÎļþ±»¼ÓÔز¢Ö´ÐС£±ðµÄ £¬¹¥»÷Õß½«½¹µãµÄÔ¶¿Ø´úÂ루ÀýÈçWinOS 4.0£©ÒÔ¼ÓÃÜÐÎʽÉúÑÄÔÚÎļþ"1"ÖÐ £¬ÕâʹµÃɱ¶¾Èí¼þÄÑÒÔ¼ì²âµ½Æä±£´æ¡£


ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½â¾ö¼Æ»®


1¡¢¸ß¼¶Íþв¼ì²â¹æÔò


ÒøºüľÂí¹¥»÷ÊÖ·¨Ëä¶à±ä £¬µ«¾ùÓм£¿ÉÑ­ £¬Ö»ÒªÓй¥»÷¾Í»áÓкۼ£¡£TARÄÚÖþ«×¼¡°á÷ºü¡±Ïà¹Ø¼ì²â¹æÔò £¬Çå¾²Ñо¿ÍŶÓϸÃܸú×Ù×îй¥»÷ÊֶΠ£¬È·±£¼ì²â¹æÔò¾«×¼¼à²â¡£


2¡¢¸ß¼¶É³Ïä¼ì³öÄÜÁ¦


×°±¸ÄÚÖöàɳÏäÇéÐÎ £¬º­¸Çwindow¡¢LinuxµÈÇéÐÎ £¬½ÓÄɾ²Ì¬¡¢Îó²î¡¢ÐÐΪÆÊÎö £¬ÄÚÖ÷´É³Ïä¼ì²â»úÖÆ £¬¶Ô·´É³Ïä¡¢·´¼ì²âµÈÐÐΪ¾ÙÐйæ±Ü £¬ÖÜÈ«¼à²âÑù±¾ÔËÐÐÀú³Ì £¬ÉîÈë·¢Ã÷ÒøºüľÂíµÄÍþвÐж¯¡£


3¡¢¼ÓÃÜÁ÷Á¿Ä£×ÓÆÊÎö


×°±¸Ç¶ÈëAIË㷨ģ×Ó £¬º­¸ÇICMP¡¢DNS¡¢HTTP¡¢HTTPS¡¢WebshellËíµÀÄ£×Ó £¬ÒÔ¡°»úеѧϰ¡¢Í³ÅÌËã·¨¡¢ÍþвÇ鱨¡¢Éî¶È°ü¼ì²â¡±ÎªÊÖÒÕµ××ù £¬¹¹½¨¡°Ê¢ÐÐΪÆÊÎö¡¢ÓòÃûÆÊÎö¡¢Ö¤ÊéÆÊÎö¡¢°üÌØÕ÷ÆÊÎö¡¢ÎÕÊÖÐÅÏ¢ÆÊÎö¡±µÄ¶àÄ£×Ó×ۺϾöÒéϵͳ¡£


4¡¢ÌìãÙAIÖÇÄÜÌ帳ÄÜ


ÌìãÙAIÖÇÄÜÌåÒÔ¡°ÖǼì²â £¬»ÛÊØ»¤¡±ÎªÀíÄî £¬ÒÀ¾Ý²î±ð¼ì²â³¡¾°ÖÇÄÜ»¯µ÷ÀíÖÖÖÖ¼ì²â¹¤¾ßºÍËã·¨ £¬Ê¹ÓÃLLMÍÆÀí×ܽáÄÜÁ¦¶Ô¼ì²âЧ¹û¡°Éî¼Ó¹¤¡± £¬´ó·ù¶ÈÌá¸ß¼ì²â¾«×¼¶ÈºÍÕûÌå¼ì²âÐÔÄÜ £¬×ÊÖúÇå¾²Ö°Ô±¸üºÃµØÏàʶ¹¥»÷ÊÂÎñµÄʵÖÊ¡¢ÈªÔ´ºÍDZÔÚÓ°Ïì¡£


ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©Í¨¹ýÌìãÙAIÖÇÄÜÌ帳Äܵĸ߼¶Íþв¼ì²â¡¢¶ñÒâÎļþ¼ì²â¡¢¼ÓÃÜÁ÷Á¿¼ì²âµÈÊÖÒÕÊÖ¶ÎÖÜÈ«¼à²âÒøºüľÂí £¬ÉîÈ붴²ìDZÔÚÍþв £¬ÓÐÓÃ×èֹΣº¦À©É¢ £¬Îª¿Í»§ÍøÂçÖþÆðÇå¾²·ÀµØ¡£