AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

Joao¶ñÒâÑù±¾ ÊÖÒÕÆÊÎöÓë·À»¤¼Æ»®

2017-08-25

Ðû²¼ÕߣºAG¹«Ë¾¿Æ¼¼

×ÛÊö

×òÈÕ£¬ESETµÄÇå¾²Ñо¿Ô±·¢Ã÷ÁËÒ»¸öÕë¶ÔÓÎÏ·Íæ¼ÒµÄ¶ñÒâÈí¼þ¡£Õâ¸öÃûΪ“Joao”µÄ¶ñÒâÈí¼þ±»·¢Ã÷DZÔÚÔÚµÚÈý·½µÄAeriaÓÎÏ·ÏÂÔØ×°ÖðüÖС£¸Ã¶ñÒâÈí¼þ»áÔÚÓÎÏ·Æô¶¯ºó×ÔÐÐÔÚºǫ́ÔËÐв¢ÇÒ·¢ËÍÊܺ¦Õß»úеµÄÐÅÏ¢¸ø¹¥»÷Õߣ¬°üÀ¨²Ù×÷ϵͳ£¬Óû§ÃûÒÔ¼°¸ÃÓû§µÄȨÏÞÐÅÏ¢£¬Óë´ËÍ¬Ê±Íæ¼ÒÈÔÈ»¿ÉÒÔÕý³£¾ÙÐÐÓÎÏ·¡£¸Ã¶ñÒâÈí¼þ»á¼ÌÐøÔÚÊÜѬȾÓû§µÄ»úеÉÏ×°ÖÃÆäËû¶ñÒâÈí¼þ¡£

Ïà¹ØÁ´½Ó£º

http://www.hackread.com/dangerous-new-malware-joao-hits-gamers-worldwide/

 

Aeria Games

Aeria Games£¬ÒÔǰ³ÆÎªAeria Games and Entertainment£¬ÊÇÒ»¼ÒÔÚÏßÓÎÏ·¿¯ÐÐÉÌ¡£ ¹«Ë¾×ܲ¿Î»Óڵ¹ú°ØÁÖ¡£

Aeria GamesÊÇProSiebenSat.1 MediaµÄ×Ó¹«Ë¾£¬Îª´óÐͶàÈËÔÚÏßÓÎÏ·ÔËÓªÁËÒ»¸ö»¥ÁªÍøÓÎÏ·ÃÅ»§¡£ ËüרעÓÚ¶àÖÖÃûÌõÄÍøÂçÓÎÏ·£¬¿Í»§¶ËÓÎÏ·£¬ä¯ÀÀÆ÷ÓÎÏ·ºÍÊÖ»úÓÎÏ·¡£ Ëü³öÊé±±ÃÀ£¬ÄÏÃÀºÍÅ·ÖÞµÄÓÎÏ·¡£

Èö²¥ÓëѬȾ

“Joao”¶ñÒâÈí¼þͨ¹ýÔڷǹٷ½ÍøÕ¾ÉÏÌṩµÄºÚ¿ÍAeriaÓÎÏ·£¬Óû§ÔÚÉÏÃæÏÂÔØ´Ó¶øÊµÏÖÈö²¥¡£

ÑùÌìÖ°Îö

ÆÊÎöÇéÐÎ

ϵͳ

Windows 7 32bit

ʹÓù¤¾ß

ProcessMonitor Xuetr Wireshark OllyDBG IDA

TAC¼ì²âЧ¹û£º

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

ͼ TAC¼ì²âЧ¹û

Ö÷Òª¹¦Ð§

[1]ÐÅÏ¢ÇÔÈ¡£ºÇÔÈ¡ÅÌËã»úÃû£¬²Ù×÷ϵͳ°æ±¾ºÍÓû§È¨ÏÞÐÅÏ¢¡£

[2]ÍøÂçÐÐΪ£ºÅþÁ¬104.18.48.240·¢ËÍgetÇëÇ󣬯äÖÐvalue×Ö¶ÎÊǼÓÃܺóµÄÓû§ÐÅÏ¢

http://www.apexserver.ws/index.php?route=anticheat&op=validatekey&cid=7&ver=4&value=c9LKpz30qO2-L4mZUktTzhQiySiSOfhzxdwusZP4GCXiQGWr96-7R22jHFA_lny5FtUMlbSI6tiiGCtl5_UuVe0SG-ft8VmlXMa

 

 AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

 

¸Ã¶ñÒâÑù±¾Ê×ÏÈÍøÂç±¾»úÐÅÏ¢£¬°üÀ¨£º×°±¸Ãû£¬Óû§Ãû£¬²Ù×÷ϵͳ°æ±¾ºÍÓû§È¨ÏÞÆ·¼¶¡£

 

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

È»ºó¶ÔÒÔÉÏÐÅÏ¢¾ÙÐмÓÃܱàÂ룬´Ó×ÔÉíÊý¾ÝÖнâÃܳöurl£¬½«¼ÓÃܱàÂëºóµÄ±¾»úÐÅÏ¢Ìí¼ÓÔÚurlµÄvalue×Ö¶ÎÖС£ÅþÁ¬Ô¶³Ì·þÎñÆ÷²¢·¢ËÍgetÇëÇó¡£

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

¸ÃurlÒÑÎÞ·¨»á¼û£¬·µ»ØError 522Ò³Ãæ¡£ÓÉÓÚÎÞ·¨´Ó·þÎñÆ÷ÏÂÔØµ½Êý¾Ý£¬Ñù±¾Ã»ÓнøÒ»²½µÄ¶ñÒâÐÐΪ¡£

¹ØÁªÑùÌìÖ°Îö

ͨ¹ýËÑË÷¶Ô¸ÃÑù±¾µÄ¹ØÁªÑù±¾¾ÙÐÐËÑË÷£¬ÎÒÃÇÕÒµ½ÁËÒ»¸öjoaoµÄ×é¼þ¾ÙÐÐÁ˼òÆÓÆÊÎö¡£¸Ã×é¼þÒ²ÊÇÒ»¸öÏÂÔØÆ÷£¬Ö÷Òª¹¦Ð§ÊÇÏÂÔØÒ»¸öpeÎļþ²¢×¢Èë×ÔËÀºóÖ´ÐС£

¸Ã×é¼þ»áÑ­»·ÊµÑéÅþÁ¬ipΪ95.170.86.186¡¢146.185.136.11¡¢185.35.77.17µÄ53¡¢18000¡¢80¡¢443¡¢8000¡¢25¡¢21¡¢3389¡¢445¶Ë¿Ú¡£Ö±ÖÁÅþÁ¬Àֳɡ£

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

ÅþÁ¬ÀÖ³ÉÏÈÉ̶¨ÒªÉÏ´«ÎļþµÄ¾Þϸ£¬È»ºó×îÏÈÎüÊÕÊý¾Ý£¬¶ÔÎüÊÕµ½µÄÊý¾Ý¾ÙÐнṹÅÐ¶ÏÆäΪpeÎļþºó£¬ÔÚ×ÔÉíÀú³ÌÉêÇë¿Õ¼ä¾ÙÐÐ×¢È룬×îºóŲÓÃCreateRemoteThread¾ÙÐÐÖ´ÐС£

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

 

ÍøÂçÌØÕ÷

1.Ïò104.18.48.240·¢ËÍgetÇëÇ󡣯äÖÐhost×ֶεÄֵΪÓòÃûwww.apexcontrol.ws¡£

2.¹ØÁªÑù±¾ÍøÂçÌØÕ÷£¬ÊµÑé´ÓÒÔÏÂipÏÂÔØ¶ñÒâ´úÂ룺95.170.86.186¡¢146.185.136.11¡¢185.35.77.17¡£

¹¥»÷¶¨Î»

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

 

¼ì²âÒªÁì

Óû§×ÔÎÒ·À»¤

1. Óû§Ó¦¸Ã´Ó¹Ù·½µÄÍøÕ¾¾ÙÐÐÏÂÔØ²Ù×÷£¬×èֹͨ¹ýµÚÈý·½ÍøÕ¾£¬ÒÔ·ÀÏÂÔØµ½¹ÒÂíÈí¼þ£»

2. Óû§¿ÉÒÔ¼à²âGETÇëÇóÖаüÀ¨www.apexcontrol.wsÓòÃûµÄhost×ֶΣ»

3. ×°ÖÃɱ¶¾Èí¼þ£¬±ÜÃâ¶ñÒâÈí¼þµÄѬȾºÍÆÆËð¡£

 

AG¹«Ë¾¿Æ¼¼Ä¾Âíרɱ½â¾ö¼Æ»®

1)  ¶ÌÆÚ·þÎñ£ºAG¹«Ë¾¿Æ¼¼¹¤³ÌʦÏÖ³¡Ä¾ÂíºóÃÅÕûÀí·þÎñ£¨È˹¤·þÎñ+IPS +TAC£©¡£È·±£µÚһʱ¼äÏû³ýÍøÂçÄÚÏà¹ØÎ£º¦µã£¬¿ØÖÆÊÂÎñÓ°Ïì¹æÄ££¬ÌṩÊÂÎñÆÊÎö±¨¸æ¡£

2)  ÖÐÆÚ·þÎñ£ºÌṩ3-6¸öÔµÄΣº¦¼à¿ØÓëѲ¼ì·þÎñ£¨IPS+TAC+È˹¤·þÎñ£©¡£ºã¾Ã¶Ô´Ë¶ñÒâÑù±¾¾ÙÐмì²â£¬±£»¤¿Í»§ÏµÍ³Çå¾²¡£

3)  ºã¾Ã·þÎñ£º»ùÓÚÐÐҵӪҵΣº¦½â¾ö¼Æ»®£¨ÍþвÇ鱨+¹¥»÷ËÝÔ´+רҵÇå¾²·þÎñ£©

×ܽá

Ñù±¾Í¨¹ýÔڷǹٷ½ÍøÕ¾ÉÏÌṩµÄºÚ¿ÍAeriaÓÎÏ·£¬Óû§ÔÚÉÏÃæÏÂÔØ´Ó¶øÊµÏÖÈö²¥¡£Óû§ÐèҪȷÈÏ×°ÖõÄÓÎÏ·³ÌÐòÊÇ·ñ°üÀ¨ÁËÌØÁíÍâdllÎļþ£¬ÓÈÆäÊÇÃûΪ “mskdbe.dll”µÄÎļþ£¬²¢¶Ô×ÅʵʱÕûÀí¡£

¸½Â¼

ÒÔÏÂΣº¦Ö¸±ê£¨IOC£©ÓëJoaoÓйأº

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

?

ÄúµÄÐÅÏ¢

*ÐÕÃû
*ÁªÏµµç»°
*ÓÊÏä
*ËùÔÚÐÐÒµ
*ËùÔÚ¹«Ë¾
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä
?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼