¡¸Íþвͨ¸æ¡¹¹ØÓÚÉîÐÅ·þSSL VPN±»¾³ÍâAPT×é֯ʹÓò¢Ï·¢¶ñÒâ´úÂë
2020-04-07
Ò»¡¢Íþв¸ÅÊö
4ÔÂ6ÈÕ£¬ÉîÐÅ·þ¹Ù·½Ðû²¼Í¨¸æ³Æ£¬Óо³ÍâAPT×é֯ͨ¹ý²»·¨ÊֶοØÖƲ¿·ÖÉîÐÅ·þSSL VPN×°±¸£¬²¢Ê¹Óÿͻ§¶ËÉý¼¶Îó²îÏ·¢¶ñÒâÎļþµ½¿Í»§¶Ë£¬AG¹«Ë¾¿Æ¼¼¶Ô¸ÃÊÂÎñÇ×½ü¹Ø×¢£¬²¢¾ÙÐÐÁËÕûÌåµÄÊáÀíºÍÆÊÎö£¬½¨ÒéÏà¹ØÓû§ÊµÊ±½ÓÄÉ·À»¤ºÍÓ¦¼±²½·¥¡£

±¾´ÎÎó²îΪSSL VPN×°±¸Windows¿Í»§¶ËÉý¼¶Ä£¿éÊðÃûÑéÖ¤»úÖÆµÄȱÏÝ£¬µ«Ê¹ÓøÃÎó²îµÄÌõ¼þΪ±ØÐè»ñÈ¡¿ØÖÆSSL VPN×°±¸µÄȨÏÞ¡£Æ¾Ö¤ÉîÐÅ·þ¹Ù·½µÄÆÊÎö£¬´ËÎó²îʹÓÃÄѶȽϸߡ£¹Ù·½Ô¤¹À£¬ÊÜÓ°ÏìµÄVPN×°±¸ÊýÄ¿ÓÐÏÞ¡£Æ¾Ö¤AG¹«Ë¾¿Æ¼¼Çå¾²·þÎñÍŶӵķ´Ï죬ËäÈ»ÏÖÔÚÒѱ»APT×éÖ¯¹¥ÏݵÄ×°±¸²¢Î´¼¸£¬µ«ÊÜÓ°ÏìµÄVPN°æ±¾ÔÚº£ÄÚÆóÒµÖÐÓ¦ÓÃÊ®·ÖÆÕ±é¡£
²Î¿¼Á´½Ó£º
https://mp.weixin.qq.com/s/lKp_3kPNEycXqfCnVPxoDw
¶þ¡¢Ó°Ïì¹æÄ£
ÏÖÔÚ¹Ù·½ÒÑÈ·ÈÏÒÔÏÂSSL VPN°æ±¾ÊÜÓ°Ïì
- M6.3R1
- M6.1
Èý¡¢·À»¤½¨Òé
3.1 ²úÆ··À»¤
´Ë´Î¹¥»÷Ô˶¯Ïà¹ØIoCÐÅÏ¢ÈçÏ£º
1¡¢C&C£º103.216.221.19
2¡¢ÎļþÃû£ºSangforUD.EXE£¬MD5£ºa32e1202257a2945bf0f878c58490af8,
3¡¢ÎļþÃû£ºSangforUD.EXE£¬MD5£º967fcf185634def5177f74b0f703bdc0
4¡¢ÎļþÃû£ºSangforUD.EXE£¬MD5£ºc5d5cb99291fa4b2a68b5ea3ff9d9f9a
5¡¢ÎļþÃû£ºe58b8de07372b9913ca2fbd3b103bb8f.virus£¬MD5£ºe58b8de07372b9913ca2fbd3b103bb8f
6¡¢ÎļþÃû£ºm.exe£¬MD5£º429be60f0e444f4d9ba1255e88093721
7¡¢ÎļþÃû£º93e9383ae8ad2371d457fc4c1035157d887a84bbfe66fbbb3769c5637de59c75£¬MD5£º18427cdcb5729a194954f0a6b5c0835a
8¡¢ÎļþÃû£ºSANARISOR.EXE£¬MD5£ºa93ece16bf430431f9cae0125701f527
3.1.1 TAC·À»¤
Õë¶Ô´Ë´Î¹¥»÷Ô˶¯ÖеĶñÒâÑù±¾£¬AG¹«Ë¾¿Æ¼¼ÍþвÆÊÎöϵͳ£¨TAC£©ÒѾ¾ß±¸Á˼ì²âÄÜÁ¦£¬Çë°²ÅÅÁËTAC×°±¸µÄÓû§ÊµÊ±¹Ø×¢Ïà¹Ø¸æ¾¯£¬²¢ÉèÖúÃ×è¶ÏÕ½ÂÔ¡£
¶ñÒâÑù±¾£º967fcf185634def5177f74b0f703bdc0

¶ñÒâÑù±¾£ºa32e1202257a2945bf0f878c58490af8

¶ñÒâÑù±¾£ºc5d5cb99291fa4b2a68b5ea3ff9d9f9a

3.1.2 ÍþвÇ鱨ÖÐÐÄ£¨NTI£©
AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄÒÑÖ§³Ö¶Ô¸ÃÊÂÎñµÄIoC¼ì²â£¬¿ÉÒÔ¾«×¼Ê¶±ð¶ñÒâIP¼°¶ñÒâÎļþ£¬½¨ÒéÓû§Ð¡ÐÄÓë¶ñÒâIP 103.216.221.19Ïà¹Ø¸æ¾¯ÐÅÏ¢¡£×èÖ¹±¾Í¨¸æÐû²¼£¬¸ÃC&C·þÎñÆ÷Òѹرա£Óû§¿ÉʹÓÃAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄÐû²¼µÄIoC¾ÙÐмì²â£¬½ÓÄÉרɱ¹¤¾ß¶ÔľÂíÎļþ³¹µ×²éɱ¡£
Éæ¼°µ½¸ÃÊÂÎñµÄC&C·þÎñÆ÷µÄÍþв֪ʶͼÆ×ÈçÏ£º


Éæ¼°µ½¸ÃÊÂÎñµÄ¼¸¸öµä·¶¶ñÒâÎļþÏêÇéÈçÏ£º



3.2 ÆäËû·À»¤½¨Òé
1¡¢¼ì²éVPN·þÎñÆ÷ÈÕÖ¾£¬ºË²éÊÇ·ñ±£´æÖÎÀíÔ±Õ˺ÅÒì³£µÇ¼¡¢%USERPROFILE%\AppData\Roaming\Sangfor\SSL\SangforUPD.exeÎļþ±»Ìæ»»µÈÒì³£ÇéÐΣ»
2¡¢ÏÞÖÆÍâÍø»ò·ÇÐÅÍÐIP»á¼ûVPN·þÎñÆ÷µÄ4430¿ØÖÆÌ¨ÖÎÀí¶Ë¿Ú£¬×è¶ÏºÚ¿ÍÕë¶ÔVPN·þÎñÆ÷ÖÎÀíºǫ́¾ÙÐеĹ¥»÷¡£
3¡¢ÔöÇ¿Õ˺ű£»¤£¬Ê¹ÓøßÇ¿¶ÈµÄÃÜÂ룬±ÜÃâÖÎÀíÔ±ÃÜÂë±»±©Á¦²Â½â¡£
4¡¢VPN·þÎñÆ÷ºÍ¿Í»§ÖÕ¶Ë×°ÖÃÇå¾²Èí¼þ£¬ÊµÊ±²éɱ¶ñÒâ³ÌÐò£¬¿ªÆôʵʱ±£»¤·ÀÓù¡£
5. Çë¹Ø×¢ÉîÐÅ·þ¹«Ë¾µÄ½â¾ö¼Æ»®£¬ÊµÊ±ÐÞ¸´Ïà¹ØÎó²î¡£
¸½Â¼£ºÑùÌìÖ°Îö
ͨ¹ýÉó²éÑù±¾ÄÚǶµÄÊý×ÖÊðÃûÐÅÏ¢£¬¹«Ë¾Ãû³Æ±ê¼Ç³É“Sangfor Technologies Co.,Ltd”£¬µ«ÉîÐÅ·þ¹«Ë¾ÏÖʵӢÎÄÃû³ÆÎª“Sangfor Technologies Inc.”£¬¹¥»÷Õß¶ÔÊðÃû¾ÙÐÐαÔ죬ͨË×ÈËÄÑÒÔÇø·Ö¡£

½¨ÉèĿ¼%USERPROFILE%\AppData\Roaming\Sangfor\SSL\

Ŀ¼½¨ÉèÍê³Éºó½«×ÔÉí¿½±´µ½%USERPROFILE%\AppData\Roaming\Sangfor\SSL\SangforUPD.exe

±éÀúÍâµØÄ¿Â¼£¬»ñÈ¡ËùÓÐÎļþÃû

Á´½ÓÄ¿µÄ·þÎñÆ÷80¶Ë¿Ú£¬Í¨¹ýHTTPÐÒ飬ÒÔPOST·½·¨»Ø´«»ñÈ¡µ½µÄÊý¾Ý

ʹÓÃcom¿â½¨ÉèϵͳÍýÏëʹÃü£¬µÖ´ïȨÏÞά³ÖµÄÄ¿µÄ

Ö´ÐÐϵͳÏÂÁî»ñȡĿµÄϵͳµÄÏà¹ØÐÅÏ¢£¬Ïà¹ØÏÂÁîÈçÏ£º
|
1
2
3
4
5
6
7
8
9
|
systeminfo.exe
ipconfig.exe /all
cmd.exe /c set
net.exe user
HOSTNAME.EXE
net.exe user /domain
net.exe group /domain
tasklist.exe /V
whoami.exe /all
|
Ö´ÐÐϵͳÏÂÁîÏà¹Ø½ØÍ¼ÈçÏ£º








½¨ÉèÑ»·»ñÈ¡À´×Ô·þÎñ¶ËµÄÊý¾Ý


AG¹«Ë¾ÔÆ







