NetWireľÂí¿ØÖÆÕß×îÏÈͶ·ÅnCoV-19ÒßÇéÓÕ¶üÎĵµ
2020-03-18
·üӰʵÑéÊÒ·¢Ã÷£¬×îÔç2012Äê·ºÆðµÄÔ¶¿ØÄ¾Âí NetWire£¬½üÆÚÔÚÆäÎĵµÖмÓÈëÁËnCoV-19ÒßÇéÏà¹ØµÄÉ繤ÄÚÈÝ¡£
Ëæ×ÅйڷÎÑײ¡¶¾£¨nCoV-19£©ÔÚÌìϹæÄ£ÄÚµÄÈö²¥£¬¶à¸ö¹ú¼ÊºÚ¿Í×éÖ¯×îÏÈ×¢ÖØµ½ÒßÇé»°ÌâÔÚÉç»á¹¤³Ìѧ·½ÃæµÄÒ×ÓÃÐÔ£¬½«ÒßÇéÏà¹ØµÄÐÅÏ¢ÈÚÈëµ½¹¥»÷Àú³Ìµ±ÖС£
¾ÅÓÎÀÏ¸ç¿Æ¼¼·üӰʵÑéÊÒÔçǰÐû²¼µÄÐÅÏ¢£¨http://blog.nsfocus.net/watch-out-for-hackers-attacked-by-new-crown-virus-pneumonia/£©ÏÔʾ£¬ÒÑÓÐEmotet¡¢FormBookµÈ×ÅÃûľÂíÔÚ¹¥»÷ÖÐʹÓÃÁËÒßÇéÐÅÏ¢×÷ΪÓÕ¶ü¡£
½üÆÚ£¬·üӰʵÑéÊÒ·¢Ã÷£¬NetWireÔ¶¿ØÄ¾Âí¿ØÖÆÕßÒ²×îÏÈʹÓÃnCoV-19ÒßÇéÏà¹ØµÄÓÕ¶üÎĵµÀ´Í¶·ÅľÂí¡£
NetWire£¬ÓÖ³ÆNetWireRC»òRecam£¬ÊÇÒ»¿î×îÔç·ºÆðÔÚ2012ÄêµÄÔ¶¿ØÄ¾Âí£¬Ôø±»ÄáÈÕÀûÑǵĺڿÍÓÃÓÚ¹¥»÷ÆóҵĿµÄ¡£¶àÄêÒÔÀ´£¬NetWireÒ»Ö±ÔÚ¸üа汾£¬²¢ÑÝ»¯³ö¶àÌõ²î±ðµÄ¹¥»÷Á´¡£2019ÄêÆð£¬NetWire½øÈëÐÂÒ»Âֵı¬·¢ÆÚ£¬½èÖúÓÉÓã²æÓʼþºÍÍøÅÌ×齨µÄÀ©É¢ÍøÂç¹ãΪÈö²¥¡£
ÊÂÎñ¼òÊö
·üӰʵÑéÊÒ½üÆÚ²¶»ñµÄ²¿·ÖNetWireÎĵµÑù±¾ÖмÓÈëÁËnCoV-19ÒßÇéµÄÉ繤ÄÚÈÝ¡£
µ±Êܺ¦Õß·¿ª¶ñÒâÓʼþÖеĸ½¼þÎĵµÊ±£¬½«»á¿´µ½ÈçÏÂËùʾµÄÄÚÈÝ£º

ÎĵµÖÐͼƬÏÔʾÁËnCoV-19²¡¶¾µÄÈ«ÇòÈö²¥Í³¼Æ£¬²¢ÇÒÓеØÇøÉϵĹýʧ¡£
¸ÃÎĵµÏÖʵ°üÀ¨cve-2017-11882¹«Ê½±à¼Æ÷Îó²î£¬»áÏÂÔØ²¢Ö´ÐжñÒâ³ÌÐò£¬×îÖÕʹNetWireľÂíÔÚÊܺ¦ÕßÖ÷»úÉÏÔËÐС£
¸ÃNetWireµÄ´óÖ¹¥»÷Á÷³ÌÈçÏ£º

Îó²îrtfÎĵµÔËÐкó£¬Í¨¹ý¶ÌÁ´½Ó»ñÈ¡µ½¶þ½×¶ÎÔØºÉµÄµØµã²¢ÏÂÔØÔËÐУ¬¶þ½×¶ÎÔØºÉ½«½âÃܺóµÄ×Ö·û´®ºÍshellcode×¢Èëµ½windows³ÌÐòieinstal.exeÖÐÔËÐУ¬shellcode»á¼ûGoogleDrive²¢½«NetWireÏÂÔØµ½ÄÚ´æÖÐÖ´ÐС£¸ÃNetWire±äÖÖ×îÖÕÅþÁ¬cnc·þÎñÆ÷79.137.*.103¡£
ÊÂÎñÆÊÎö
rtfÎĵµ
¸ÃÓÕ¶üÎĵµ°üÀ¨¸ß¶È»ìÏýµÄrtf±àÂ룬»á´¥·¢cve-2017-11882Îó²î£º

Îó²î´¥·¢ºó£¬³ÌÐòÌø×ªÖÁshellcodeÔËÐС£shellcodeʹÓó£¼ûµÄGlobalLock˼Ð÷ѰÕÒOleÁ÷¹¤¾ßλÖã¬ËæºóÌø×ªÖÁ¹¤¾ßÖеĵڶþ¶ÎshellcodeÔËÐС£µÚ¶þ¶ÎshellcodeÒà¾Óɸ߶ȻìÏý¡£
¸ÃÎó²îÎĵµµÄ¶ñÒâshellcode×îÖÕÏÂÔØ¶ÌÁ´½Óbit.ly/2T*xW£¨Ä¿½ñ±»ÆÊÎöÖÁhxxp://www.asim*.com/new/Notepad.txt£©ÖеÄÄÚÈݲ¢Ö´ÐУ¬Í¬Ê±ÔÚwordÖÐÏÔʾÎĵµÖи½´øµÄjpegÃûÌÃÒßÇéµØÍ¼¡£
Notepad.txt
¶ñÒârtfÏÂÔØÔËÐеĶþ½×¶ÎÔØºÉNotepad.txtÊÇvb³ÌÐò£¬Ö÷Òª¹¦Ð§ÎªÆô¶¯ºÍ×¢Èëwindows³ÌÐòieinstal.exe£¬×¢ÈëÄÚÈÝΪshellcodeÏ¢ÕùÃܺóµÄ×Ö·û´®ÉèÖÃÏîµÈ¡£
±»×¢ÈëµÄisinstal.exeÔËÐк󣬻ὨÉèÖ¸¶¨Ä¿Â¼USER\\Bagtaler4\\£¬½«¶ñÒâ³ÌÐò±¾Ìå×ªÒÆÖÁĿ¼Ï²¢ÃüÃûΪSamipat8.exe£¬Ö®ºó½¨Éè×¢²á±íÆô¶¯ÏîʵÏÖ³¤ÆÚ»¯£º

Ëæºó³ÌÐò»á¼ûÓ²±àÂëµØµãhxxps://drive.google.com/uc?export=download&id=1kFK*Jz90ÏÂÔØ½âÃܲ¢Ö´ÐÐ×îÖÕ½×¶ÎÔØºÉNetWireÔ¶¿ØÄ¾Âí¡£
½âÃÜÀú³ÌÖÐʹÓÃÁËÒÔϺ¯Êý£º

½âÃÜÂ߼Ϊ³¤¼üÖµÒì»ò£¬Ê¹ÓõÄÒì»ò¼üÓÉshellcodeÌṩ¡£±¾ÀýÖÐÓõ½µÄ½âÃܼü³¤¶ÈΪ0x24A£¬Óɳ¤Îª0x100µÄ¼üÑ»·ÌìÉú£¬ÖµÎª£º
076C3D0F54873230F1AE34A2E026CB21DCF06F35280A6456C631AAC7B4EEFD46B0B7E516FC8DDA379AF9DDA94471746B843A183BD1110D5C6E7C53CE19F4A64D58BD4A60A5D83F8142FF85F3ED771C722D41C042795BB5A71782FBD4C1FB4E9701C4F2674DDEE888EB062EFA95C2C5BCD547698C22625EADBFCDA41F6A45F79EA90E9BB1F6E590D24F50D6003EC829C33A921193CAAC06B424D30825124C9FE80E1543B89E2F38D9F8577F4BE6CFD2C9E298BADD2FB3AFFECCDAB12CBB5248EFB61BECBE0336E1DFA0A127518F197A148BE31EE4D7B9130575245976639DF0F55F669409AB3C892A49A8D09C3720231A33E9C7EA8004BC0B1D2B027D0CA35540076C3D0F54873230F1AE34A2E026CB21DCF06F35280A6456C631AAC7B4EEFD46B0B7E516FC8DDA379AF9DDA94471746B843A183BD1110D5C6E7C53CE19F4A64D58BD4A60A5D83F8142FF85F3ED771C722D41C042795BB5A71782FBD4C1FB4E9701C4F2674DDEE888EB062EFA95C2C5BCD547698C22625EADBFCDA41F6A45F79EA90E9BB1F6E590D24F50D6003EC829C33A921193CAAC06B424D30825124C9FE80E1543B89E2F38D9F8577F4BE6CFD2C9E298BADD2FB3AFFECCDAB12CBB5248EFB61BECBE0336E1DFA0A127518F197A148BE31EE4D7B9130575245976639DF0F55F669409AB3C892A49A8D09C3720231A33E9C7EA8004BC0B1D2B027D0CA35540076C3D0F54873230F1AE34A2E026CB21DCF06F35280A6456C631AAC7B4EEFD46B0B7E516FC8DDA379AF9DDA94471746B843A183BD1110D5C6E7C53CE19F4A64D58BD4A60A5D83F8142FF
NetWire
±»×¢ÈëµÄieinstal³ÌÐò×îÖÕÔÚÄÚ´æÖмÓÔØÁËNetWireľÂí¡£
ľÂí³ÌÐòÅþÁ¬C&CµØµãΪ79.137.*.103:39561,ͨѶ×ñÕÕÒÔÏÂÃûÌÃ:
| 0x00~0x03 | 0x04 | 0x05~ |
| length | cmdbyte | data |
data²¿·ÖʹÓÃaes¼ÓÃÜ£¬¼ÓÃܵÄkeyÓëIVÔÚľÂí³õʼ»¯Ê±Ëæ»úÌìÉú£¬²¢ÔÚÊ×´ÎͨѶʱÉÏ´«¸øC&C£º

ͼÖÐÀ¶É«²¿·ÖΪÐÒéÍ·²¿£¬ºìÉ«²¿·ÖΪ32×Ö½Úkey£¬»ÆÉ«²¿·ÖΪ16×Ö½ÚIV£¬ÂÌÉ«²¿·ÖΪ¼ÓÃÜÀýÎÄ£¬¶ÔÓ¦µÄÃ÷ÎÄÓ²±àÂëÔÚľÂíÎļþÖС£
C&CÊÕµ½Ä¾ÂíÌṩµÄ¼ÓÃܼüºó£¬Ê¹Óô˼ü¼ÓÃÜdata¶ÎÄÚÈÝ£¬ÓëľÂíÒ»Á¬Í¨Ñ¶£º

±¾ÀýÖÐʹÓõÄNetWireľÂíÊǹ¦Ð§½ÏÈ«µÄ±äÖÖ£¬¹²Ö§³Ö57ÖÖ²î±ðµÄÖ¸Á¿É¾ÙÐаüÀ¨Îļþ²Ù×÷¡¢Àú³Ì²Ù×÷¡¢´°¿Ú²Ù×÷¡¢×¢²á±í²Ù×÷¡¢·´µ¯shell¡¢Á÷Á¿×ª·¢¡¢Ä£ÄâÊäÈë¡¢Óû§Æ¾Ö¤ÇÔÈ¡µÈÐÐΪ¡£Ïêϸ¹¦Ð§¼ûÖ¸Áî±í£º
| 0x97 | »ñÈ¡ÊܿضËǰ̨´°¿ÚÃû³ÆºÍ´ý»úʱ¼ä,×÷ΪÐÄÌøÖ¸Áî |
| 0x9B | »ñÈ¡ÊܿضËϵͳÐÅÏ¢£¬°üÀ¨Óû§Ãû¡¢ÅÌËã»úÃû¡¢OS°æ±¾ |
| 0x9C | ÔËÐÐTEMP·¾¶ÏÂÖ¸¶¨³ÌÐò |
| 0x9D | Ö´ÐÐÖ¸¶¨ÃüÁîÐÐ |
| 0x9F | ³ÌÐòÍ˳ö£¨¹Ø±ÕccͨѶ¡¢ÊÍ·Å»¥³âÌå¡¢ÖÐÖ¹Àú³Ì£© |
| 0xA0 | ¹Ø±ÕccͨѶ²¢´ý»ú |
| 0xA1 | ×¢²á±íÕûÀí¡¢³ÌÐòÍ˳ö |
| 0xA2 | ×¢²á±íNetWire¿ØÖÆÏî¸üР|
| 0xA3 | ÏÂÔØÖ¸¶¨urlµÄ³ÌÐòÖÁTEMP·¾¶²¢ÔËÐÐ |
| 0xA4 | »ñÈ¡´ÅÅÌÐÅÏ¢ |
| 0xA6 | »ñȡָ¶¨Ä¿Â¼ÏµÄÎļþʱ¼äÐÅÏ¢ |
| 0xA8 | »ñȡָ¶¨Ä¿Â¼ÏµÄÎļþÊôÐԺͳߴçÐÅÏ¢ |
| 0xAA | ÖÐֹĿ¼±éÀúÏß³Ì |
| 0xAB | »ñȡָ¶¨ÎļþµÄÄÚÈÝ |
| 0xAC | ÏòÒѱê¼ÇµÄÎļþдÈëÄÚÈÝ |
| 0xAD | ¹Ø±ÕÒѱê¼ÇÎļþ |
| 0xAE | ¸´ÖÆÎļþ |
| 0xAF | Ö÷Ïß³ÌÖÐÖ´ÐÐÖ¸¶¨ÃüÁîÐÐ |
| 0xB0 | ÒÆ¶¯Îļþ |
| 0xB1 | ɾ³ýÎļþ |
| 0xB2 | ½¨ÉèÎļþ¼Ð |
| 0xB3 | ɾ³ýÎļþ»òÎļþ¼Ð |
| 0xB4 | »ñȡָ¶¨Ä¿Â¼ÏµÄÎļþÃûºÍÊôÐÔÐÅÏ¢ |
| 0xB5 | ¹Ø±ÕÒѱê¼ÇÎļþ |
| 0xB6 | ·´µ¯shell |
| 0xB7 | дÈë·´µ¯shell |
| 0xB8 | ¹Ø±Õ·´µ¯shell |
| 0xBA | »ñÈ¡ÊܿضËϵͳÏêϸÐÅÏ¢£¬°üÀ¨´¦Öóͷ£Æ÷¡¢ÄÚ´æ¡¢ÁîÅÆµÈ |
| 0xBC | »ñÈ¡ËùÓеǼ»á»°µÄÐÅÏ¢ |
| 0xBE | »ñÈ¡Àú³ÌÁбíºÍÐÅÏ¢ |
| 0xC0 | ¿¢ÊÂÖ¸¶¨Àú³Ì |
| 0xC1 | »ñÈ¡´°¿ÚÁбí |
| 0xC2 | ´°¿Ú²Ù×÷£¬ÓÉÖ¸ÁîÂëÖ¸¶¨ 1¹Ø±Õ´°¿Ú 2Òþ²Ø´°¿Ú 3ÏÔʾ´°¿Ú 4ÉèÖô°¿ÚÎÊÌâ |
| 0xC3 | ÏÂÔØÖ¸¶¨urlµÄ³ÌÐòÖÁÖ¸¶¨Ä¿Â¼²¢ÔËÐÐ |
| 0xC5 | Ä£Äâ°´¼üµ¯Æð |
| 0xC6 | Ä£Äâ°´¼ü°´Ï |
| 0xC7 | Êó±ê°´¼ü̧Æð |
| 0xC8 | ÉèÖÃÊó±êλÖã¬Êó±ê°´¼ü°´Ï |
| 0xC9 | »ñȡĿ½ñÆÁÄ»½ØÍ¼ |
| 0xCC | »ñȡľÂíÔËÐÐÈÕÖ¾ÎļþÐÅÏ¢ |
| 0xCE | »ñȡľÂíÔËÐÐÈÕ־·¾¶ÊôÐÔ |
| 0xCF | ɾ³ýÖ¸¶¨Ä¾ÂíÔËÐÐÈÕÖ¾ |
| 0xD0 | »ñȡָ¶¨Ä¾ÂíÔËÐÐÈÕÖ¾ |
| 0xD3 | »ñȡָ¶¨ä¯ÀÀÆ÷ÖеǼÐÅÏ¢ |
| 0xD4 | »ñȡָ¶¨ä¯ÀÀÆ÷ÖеǼÐÅÏ¢ |
| 0xD5 | »ñÈ¡pidginÕË»§Îļþ |
| 0xD6 | »ñÈ¡pidginÕË»§Îļþ |
| 0xD7 | »ñÈ¡OutlookĬÈÏÉèÖÃÎļþ |
| 0xD8 | »ñÈ¡OutlookĬÈÏÉèÖÃÎļþ |
| 0xD9 | ÏòÖ¸¶¨µØµã×öÁ÷Á¿×ª·¢ |
| 0xDF | »ñȡָ¶¨Ä¿Â¼ÏµÄÎļþÃûºÍÊôÐÔÐÅÏ¢ |
| 0xE2 | ×èֹĿ¼±éÀú |
| 0xE3 | ѹËõÖ¸¶¨Ä¿Â¼ |
| 0xE4 | »ñÈ¡ÊܿضËÖ÷»úÍøÂçÐÅÏ¢ |
| 0xE5 | »ñȡָ¶¨×¢²á±í¼ü±éÀúÐÅÏ¢ |
| 0xE7 | ×¢²á±í²Ù×÷£¬°üÀ¨½¨Éè¡¢¸³Öµ¡¢É¾³ýµÈ |
| 0xE8 | »ñÈ¡ÊܿضËϵͳÐÅÏ¢ |
ÊÂÎñÓ°Ïì
¹ØÁªÊý¾ÝÏÔʾ£¬´Ë´ÎÊÂÎñÖеÄÓòÃûwww.asim*.comÔÚ2019Äê10Ô¾Í×îÏÈÏ·¢NetWireľÂí£¬¶øÊÂÎñÖеÄÍøÅÌÁ´½Ó×Ô2ÔÂ26ÈÕ±»·¢Ã÷ÒÔÀ´ÒѾÔËÐÐÁËÁè¼ÝÁ½ÖÜ¡£±ðµÄ£¬ÎÒÃÇͨ¹ýÊý¾Ý·¢Ã÷£¬×Ô½ñÄêÒÔÀ´NetWireÒѾÏ·¢ÁË25¸ö²î±ðµÄÍøÅÌÁ´½Ó£¬ÆäÖÐÔçÔÚ1ÔÂ9ÈÕµÄÁ´½ÓÖÁ½ñÈÔ¿É»á¼û¡£ÒÔÉÏÐÅϢ֤ʵÁËNetWire¹¥»÷µÄ³¤Ð§ÐÔ¡£
±¾´ÎnCoV-19ÒßÇéÓÕ¶üµÄÈö²¥Åú×¢NetWire¼°Æä±³ºóµÄÕûÌå½øÈëÁËеĻîÔ¾ÆÚ£¬³¤Ð§µÄ¹¥»÷Á´Ê¹µÃÓʼþÓû§½«ÓÐÏ൱³¤µÄʱ¼äÁýÕÖÔÚNetWireµÄ¹¥»÷֮ϡ£

¾ÅÓÎÀϸçÔÆ







