Joao¶ñÒâÑù±¾ ÊÖÒÕÆÊÎöÓë·À»¤¼Æ»®
2017-08-25
×ÛÊö
×òÈÕ£¬ESETµÄÇå¾²Ñо¿Ô±·¢Ã÷ÁËÒ»¸öÕë¶ÔÓÎÏ·Íæ¼ÒµÄ¶ñÒâÈí¼þ¡£Õâ¸öÃûΪ“Joao”µÄ¶ñÒâÈí¼þ±»·¢Ã÷DZÔÚÔÚµÚÈý·½µÄAeriaÓÎÏ·ÏÂÔØ×°ÖðüÖС£¸Ã¶ñÒâÈí¼þ»áÔÚÓÎÏ·Æô¶¯ºó×ÔÐÐÔÚºǫ́ÔËÐв¢ÇÒ·¢ËÍÊܺ¦Õß»úеµÄÐÅÏ¢¸ø¹¥»÷Õߣ¬°üÀ¨²Ù×÷ϵͳ£¬Óû§ÃûÒÔ¼°¸ÃÓû§µÄȨÏÞÐÅÏ¢£¬Óë´ËÍ¬Ê±Íæ¼ÒÈÔÈ»¿ÉÒÔÕý³£¾ÙÐÐÓÎÏ·¡£¸Ã¶ñÒâÈí¼þ»á¼ÌÐøÔÚÊÜѬȾÓû§µÄ»úеÉÏ×°ÖÃÆäËû¶ñÒâÈí¼þ¡£
Ïà¹ØÁ´½Ó£º
http://www.hackread.com/dangerous-new-malware-joao-hits-gamers-worldwide/
Aeria Games
Aeria Games£¬ÒÔǰ³ÆÎªAeria Games and Entertainment£¬ÊÇÒ»¼ÒÔÚÏßÓÎÏ·¿¯ÐÐÉÌ¡£ ¹«Ë¾×ܲ¿Î»Óڵ¹ú°ØÁÖ¡£
Aeria GamesÊÇProSiebenSat.1 MediaµÄ×Ó¹«Ë¾£¬Îª´óÐͶàÈËÔÚÏßÓÎÏ·ÔËÓªÁËÒ»¸ö»¥ÁªÍøÓÎÏ·ÃÅ»§¡£ ËüרעÓÚ¶àÖÖÃûÌõÄÍøÂçÓÎÏ·£¬¿Í»§¶ËÓÎÏ·£¬ä¯ÀÀÆ÷ÓÎÏ·ºÍÊÖ»úÓÎÏ·¡£ Ëü³öÊé±±ÃÀ£¬ÄÏÃÀºÍÅ·ÖÞµÄÓÎÏ·¡£
Èö²¥ÓëѬȾ
“Joao”¶ñÒâÈí¼þͨ¹ýÔڷǹٷ½ÍøÕ¾ÉÏÌṩµÄºÚ¿ÍAeriaÓÎÏ·£¬Óû§ÔÚÉÏÃæÏÂÔØ´Ó¶øÊµÏÖÈö²¥¡£
ÑùÌìÖ°Îö
ÆÊÎöÇéÐÎ
|
ϵͳ |
Windows 7 32bit |
|
ʹÓù¤¾ß |
ProcessMonitor Xuetr Wireshark OllyDBG IDA |
TAC¼ì²âЧ¹û£º

ͼ TAC¼ì²âЧ¹û
Ö÷Òª¹¦Ð§
[1]ÐÅÏ¢ÇÔÈ¡£ºÇÔÈ¡ÅÌËã»úÃû£¬²Ù×÷ϵͳ°æ±¾ºÍÓû§È¨ÏÞÐÅÏ¢¡£
[2]ÍøÂçÐÐΪ£ºÅþÁ¬104.18.48.240·¢ËÍgetÇëÇ󣬯äÖÐvalue×Ö¶ÎÊǼÓÃܺóµÄÓû§ÐÅÏ¢
http://www.apexserver.ws/index.php?route=anticheat&op=validatekey&cid=7&ver=4&value=c9LKpz30qO2-L4mZUktTzhQiySiSOfhzxdwusZP4GCXiQGWr96-7R22jHFA_lny5FtUMlbSI6tiiGCtl5_UuVe0SG-ft8VmlXMa

¸Ã¶ñÒâÑù±¾Ê×ÏÈÍøÂç±¾»úÐÅÏ¢£¬°üÀ¨£º×°±¸Ãû£¬Óû§Ãû£¬²Ù×÷ϵͳ°æ±¾ºÍÓû§È¨ÏÞÆ·¼¶¡£

È»ºó¶ÔÒÔÉÏÐÅÏ¢¾ÙÐмÓÃܱàÂ룬´Ó×ÔÉíÊý¾ÝÖнâÃܳöurl£¬½«¼ÓÃܱàÂëºóµÄ±¾»úÐÅÏ¢Ìí¼ÓÔÚurlµÄvalue×Ö¶ÎÖС£ÅþÁ¬Ô¶³Ì·þÎñÆ÷²¢·¢ËÍgetÇëÇó¡£

¸ÃurlÒÑÎÞ·¨»á¼û£¬·µ»ØError 522Ò³Ãæ¡£ÓÉÓÚÎÞ·¨´Ó·þÎñÆ÷ÏÂÔØµ½Êý¾Ý£¬Ñù±¾Ã»ÓнøÒ»²½µÄ¶ñÒâÐÐΪ¡£
¹ØÁªÑùÌìÖ°Îö
ͨ¹ýËÑË÷¶Ô¸ÃÑù±¾µÄ¹ØÁªÑù±¾¾ÙÐÐËÑË÷£¬ÎÒÃÇÕÒµ½ÁËÒ»¸öjoaoµÄ×é¼þ¾ÙÐÐÁ˼òÆÓÆÊÎö¡£¸Ã×é¼þÒ²ÊÇÒ»¸öÏÂÔØÆ÷£¬Ö÷Òª¹¦Ð§ÊÇÏÂÔØÒ»¸öpeÎļþ²¢×¢Èë×ÔËÀºóÖ´ÐС£
¸Ã×é¼þ»áÑ»·ÊµÑéÅþÁ¬ipΪ95.170.86.186¡¢146.185.136.11¡¢185.35.77.17µÄ53¡¢18000¡¢80¡¢443¡¢8000¡¢25¡¢21¡¢3389¡¢445¶Ë¿Ú¡£Ö±ÖÁÅþÁ¬Àֳɡ£

ÅþÁ¬ÀÖ³ÉÏÈÉ̶¨ÒªÉÏ´«ÎļþµÄ¾Þϸ£¬È»ºó×îÏÈÎüÊÕÊý¾Ý£¬¶ÔÎüÊÕµ½µÄÊý¾Ý¾ÙÐнṹÅÐ¶ÏÆäΪpeÎļþºó£¬ÔÚ×ÔÉíÀú³ÌÉêÇë¿Õ¼ä¾ÙÐÐ×¢È룬×îºóŲÓÃCreateRemoteThread¾ÙÐÐÖ´ÐС£

ÍøÂçÌØÕ÷
1.Ïò104.18.48.240·¢ËÍgetÇëÇ󡣯äÖÐhost×ֶεÄֵΪÓòÃûwww.apexcontrol.ws¡£
2.¹ØÁªÑù±¾ÍøÂçÌØÕ÷£¬ÊµÑé´ÓÒÔÏÂipÏÂÔØ¶ñÒâ´úÂ룺95.170.86.186¡¢146.185.136.11¡¢185.35.77.17¡£
¹¥»÷¶¨Î»

¼ì²âÒªÁì
Óû§×ÔÎÒ·À»¤
1. Óû§Ó¦¸Ã´Ó¹Ù·½µÄÍøÕ¾¾ÙÐÐÏÂÔØ²Ù×÷£¬×èֹͨ¹ýµÚÈý·½ÍøÕ¾£¬ÒÔ·ÀÏÂÔØµ½¹ÒÂíÈí¼þ£»
2. Óû§¿ÉÒÔ¼à²âGETÇëÇóÖаüÀ¨www.apexcontrol.wsÓòÃûµÄhost×ֶΣ»
3. ×°ÖÃɱ¶¾Èí¼þ£¬±ÜÃâ¶ñÒâÈí¼þµÄѬȾºÍÆÆËð¡£
¾ÅÓÎÀÏ¸ç¿Æ¼¼Ä¾Âíרɱ½â¾ö¼Æ»®
1) ¶ÌÆÚ·þÎñ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼¹¤³ÌʦÏÖ³¡Ä¾ÂíºóÃÅÕûÀí·þÎñ£¨È˹¤·þÎñ+IPS +TAC£©¡£È·±£µÚһʱ¼äÏû³ýÍøÂçÄÚÏà¹ØÎ£º¦µã£¬¿ØÖÆÊÂÎñÓ°Ïì¹æÄ££¬ÌṩÊÂÎñÆÊÎö±¨¸æ¡£
2) ÖÐÆÚ·þÎñ£ºÌṩ3-6¸öÔµÄΣº¦¼à¿ØÓëѲ¼ì·þÎñ£¨IPS+TAC+È˹¤·þÎñ£©¡£ºã¾Ã¶Ô´Ë¶ñÒâÑù±¾¾ÙÐмì²â£¬±£»¤¿Í»§ÏµÍ³Çå¾²¡£
3) ºã¾Ã·þÎñ£º»ùÓÚÐÐҵӪҵΣº¦½â¾ö¼Æ»®£¨ÍþвÇ鱨+¹¥»÷ËÝÔ´+רҵÇå¾²·þÎñ£©
×ܽá
Ñù±¾Í¨¹ýÔڷǹٷ½ÍøÕ¾ÉÏÌṩµÄºÚ¿ÍAeriaÓÎÏ·£¬Óû§ÔÚÉÏÃæÏÂÔØ´Ó¶øÊµÏÖÈö²¥¡£Óû§ÐèҪȷÈÏ×°ÖõÄÓÎÏ·³ÌÐòÊÇ·ñ°üÀ¨ÁËÌØÁíÍâdllÎļþ£¬ÓÈÆäÊÇÃûΪ “mskdbe.dll”µÄÎļþ£¬²¢¶Ô×ÅʵʱÕûÀí¡£
¸½Â¼
ÒÔÏÂΣº¦Ö¸±ê£¨IOC£©ÓëJoaoÓйأº


¾ÅÓÎÀϸçÔÆ







