Éî¶ÈÆÊÎö¼°·À»¤£º¼ÓÃÜľÂí¹¥»÷£¬º£Á«»¨£¿
2015-06-15
Ëæ×ÅÄäÃûÕß¹¥»÷ÊÂÎñµÄ¸ú×ÙÆÊÎö×ßÏòÉîÈ룬5ÔÂ28ÈÕ£¬ÓÖһϵÁÐÕë¶ÔÖйúµÄ¹¥»÷ÐÐΪ¸¡³öË®Ãæ¡£Õâ¸ö±»¸÷È˳ÆÎª¡°º£Á«»¨¡±×éÖ¯ËùʵÑéµÄ¹¥»÷£¬Æä¹¥»÷ÌØÕ÷ÊÇÔõÑùµÄ£¬¾¿¾¹ÊÇ´¿´âµÄľÂí£¬ÕÕ¾ÉAPT£¿ËæÖ®¶øÀ´µÄ¹¥·À˼Ð÷»á±¬·¢ÔõÑùµÄת±ä£¿Óû§ÓÖ¸ÃÔõÑùÓ¦¶Ô£¿
±¾±¨¸æÒÔºó´Î¹¥»÷ÊÂÎñÖнػñµÄµä·¶Ä¾ÂíÑù±¾ÈëÊÖ£¬ÆÊÎöÆä¹¥»÷ÐÐΪ£¬±ÈÕÕľÂí¼°APTµÄÌØÕ÷£¬ÎªÓû§Ë¼Ë÷ÏÂÒ»²½µÄÓ¦¶Ô¼Æ»®£¬¸ø³öÁËת±ä˼Ð÷µÄ¹¥·ÀÄ£×Ó£¬Ìá³öδÀ´¹¥·ÀÕ½ÖÐÊäÓ®Åжϱê×¼¼°Éú³¤Æ«Ïò£¬²¢ÍƼöÁËÓ¦¶Ô´Ë´Î¹¥»÷µÄ½â¾ö¼Æ»®¼°ÊµÑé°ì·¨¡£
Ŀ¼
-
¹¥»÷£ºÊÇË£¿
- º£Á«»¨
- ÑùÌìÖ°Îö
-
¹¥»÷£ºÊÇľÂíÕÕ¾ÉAPT
- ľÂíÌØÕ÷
- APTÌØÕ÷
- Òª¹Ø×¢µÄÊÂÇé
-
·À»¤£ºË¼Ð÷ת»»
- ÔõôÃ÷È·
- Ôõô×ö
-
·À»¤£ºNGTP¼Æ»®
- ÍêÕû°²ÅÅ
- ¼ò»¯°²ÅÅ
- ²úÆ·°²ÅÅ
- ÖÕ¶Ë·À»¤
- ÍþвÇ鱨
- ¹ØÓÚAG¹«Ë¾¿Æ¼¼
¹¥»÷£ºÊÇË£¿
AG¹«Ë¾¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÒ»Ö±ÔÚÒ»Á¬¹Ø×¢ÍøÂç¹¥»÷ÊÂÎñ²¢¾ÙÐиú×ÙÆÊÎö£¬ÕâЩ¹¥»÷ÊÂÎñÖÐÓÐÀ´×Ôº£Äڵģ¬Ò²ÓÐÀ´×ÔÍâÑó£¬ÓÌÈçÏÖʵÉç»áÖеĿֲÀÖ÷ÒåÒ»Ñù£¬ÓÐЩÊÂÎñ»áÓÐ×éÖ¯¹ûÕæÈϿɣ¬ºÃ±ÈÄäÃûÕߣ¨Anonymous£©£¬µ«Ò²ÓÐһЩÊÂÎñÊÇûÓÐ×éÖ¯¶ÔÆäÈÏÕæµÄ£¬ÕâЩÊÂÎñAG¹«Ë¾¿Æ¼¼µÄר¼Ò»áÓÃÏà¹ØµÄÄ£×Ó¾ÙÐзÖÀàÑо¿£¬ÆäÖеÄÒ»¸ö²Î¿¼Ö¸±ê¾ÍÊÇÆä¹¥»÷ÐÐΪ¼°Ï°ÓõĹ¥»÷ÐÎʽ¡£
º£Á«»¨
2015Äê5ÔÂ28ÈÕ£¬Ò»ÏµÁÐÕë¶ÔÖйúº£Ê»ú¹¹µÄ¹¥»÷ÐÐΪ¸¡³öË®Ãæ£¬Òµ½çÓд«¹¥»÷ÊÂÎñÉæ¼°30¶à¸ö¹ú¼Ò£¬ÊºóδÓÐ×éÖ¯Éù³Æ¶ÔÕâЩ¹¥»÷ÊÂÎñÈÏÕæ£¬µ«ÆäÖпÉÒÔ¿´µ½µÄÊÇ£¬Ïà¹Øº£Ê»ú¹¹µÄ¹¥»÷´ó´ó¶¼À´×ÔľÂí¡£ÈôÊÇ˵ÕâЩ¹¥»÷ÊÇÀ´×Ôij¸öºÚ¿Í×éÖ¯£¬ÄÇôÕâ¸ö×éÖ¯ÎÞÒÉÊǽÏÁ¿µÍµ÷µÄ£¬µÍµ÷µ½Ã»¿´µ½Æä¹ûÕæµÄÃüÃû¡£¿ÉÄÜÊÇÓÉÓÚÕâЩ¹¥»÷Ä¿µÄ³£Éæ¼°ÖйúµÄº£Ê¼°Ïà¹Ø»ú¹¹£¬Ä³¹«Ë¾½«ÆäÃüÃûΪ¡°º£Á«»¨¡±£¬µ«Ë¼Á¿µ½ÕâЩ¹¥»÷µÄÒ»Ð©ÌØÕ÷£¬1¶à½ÓÄÉľÂí£¬2¶àÕë¶Ôº£Ê»ú¹¹£¬3¹¥»÷ÓÐÒ»¶¨µÄÊýÄ¿£¬4ÈôÊDZ£´æÕâ¸ö×éÖ¯£¬ËûÃǺܵ͵÷£¬ÄÇ¿ÉÄÜʹÓú£Âí£¨Seahorse£©³ÆºôËûÃǸüΪÌùÇС£
ÑùÌìÖ°Îö
AG¹«Ë¾¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÔÚÒ»Ñùƽ³£¼à²âÖлñÈ¡µ½Á˸Ã×éÖ¯µÄһЩľÂíÑù±¾£¬Ë¼Á¿µ½º£ÄÚÓû§µÄʹÓÃϰ¹ß£¬Ñ¡ÔñÁËÒ»¸ö¾ßÓдú±íÐԵļÓÃÜľÂí£¨Encrypting Trojan horse£©¾ÙÐÐÆÊÎö£¬Í¨Ì«¹ýÎö¿ÉÒÔ¿´µ½ÆäÍêÕûµÄÖ´ÐÐÀú³Ì¡£Ñù±¾Í¨³£ÊÇÒ»¸ö¿ÉÖ´ÐÐÎļþ£¬¿ÉÄÜÆäͼ±êÀàËÆword.exe³ÌÐò£¬Ö´Ðкó»áÌìÉúÁ½¸ö½ÏÁ¿µÄÒªº¦µÄÎļþqq.exeÒÔ¼°Bundle.rdbÎļþ¡£
ËæºóÏòIPµØµã193.169.244.73ÌᳫÅþÁ¬
ͨ¹ý×·×Ù¶ÔÓ¦µÄIPµØµã£¬·¢Ã÷ÆäËùÔÚÇøÓò¼°°ó¶¨ÓòÃûÀ´×ÔÎÚ¿ËÀ¼£¬ÏÖÔÚÓòÃûÒ³Ãæ»ñÈ¡ÒѾʧЧ£¬µ«²»É¨³ýÓÐÏà¹ØµÄ·´×·×ÙÊÖÒÕÊֶΡ£¶ø´ÓÒÑÍùµÄÒ»Á¬¸ú×ÙÇéÐÎÀ´¿´£¬ÃÀ¹úºÍÎÚ¿ËÀ¼µÄÓòÃû½Ï¶à¡£
Ñù±¾Õû¸öÍêÕûµÄÖ´ÐÐÀú³ÌÈçÏ£º
1 µã»÷Ö®ºóÑù±¾»áÊͷųöÐÎÈçXXXX.tmpµÄÎļþ²¢ÔËÐУ»
2 ¸ÃÎļþÊ×ÏÈ»áÊÍ·ÅÒ»¸öÕý³£µÄdocÎļþÔËÐУ¬ÓÃÒÔÒÉ»óͨË×Óû§£»
3 È»ºóÊÍÃûΪqq.exeºÍBundle.rdbµÄÁ½¸öÎļþ£»
4 Óû§Ò»µ©ÔËÐÐÁË¡±qq.exe¡±£»
5 Õâ¸öÀî¹í¾Í»á½«Bundle.rdbÎļþ×¢Èëµ½Ò»¸ö½©Ê¬Àú³ÌÖУ»
6 Bundle.rdbʵÏÖÓë¹¥»÷ÕߵķþÎñÆ÷¾ÙÐн»»¥¡£
ÏÂÃæÎÒÃǽ«ÆäÖеÄһЩ׷×ÙµÄÊÖÒÕϸ½Ú·ºÆð³öÀ´£¬Í¨¹ýÕâЩϸ½Ú·ºÆð£¬ÓÐÀûÓÚºóÐø¶Ô¸ÃľÂí¾ÙÐвéɱºÍ·À»¤£¬ÒÔ¼°ÎªÕûÌåÆÊÎö¹¥»÷×éÖ¯µÄÐÐΪÌṩÐÅÏ¢¼°Êý¾ÝÖ§³Ö¡£
ľÂíÑù±¾Èë¿ÚÆÊÎö
Ñù±¾ÐÅÏ¢
´Ó½Ø»ñµÄÑùÔÀ´¿´£¬¸ÃÑù±¾Î±×°ÎªwordÎĵµ£¬ÒýÓÕÓû§È¥µã»÷£¬¶øÈö²¥Í¾¾¶Ò²Ö÷Ҫͨ¹ýÓʼþ´«Ê䣬UÅÌ¿½±´µÈÐÎʽÈö²¥¡£Ïȼì²é¸ÃÑù±¾ÓÐûÓмӿǡ£
Ò²¾ÍÊÇ˵¸ÃÑù±¾²¢Ã»ÓнÓÄɹŰåµÄ¼Ó¿ÇÊÖÒÕÀ´Ìӱܲ鶾Èí¼þµÄ²éɱ£¬¶øÊǽÓÄÉÁËÆäËû¼ÓÃܵķ½·¨À´ÈƹýɨÃè¡£
²éÕÒľÂí³ÌÐòÈë¿Ú
ÉÏͼÊÇIDA·´»ã±àºó£¬½ØÈ¡µÄwinmainº¯ÊýµÄÖ÷Òª²¿·Ö£¬´ÓͼÖиÅÂÔ¿ÉÒÔ¿´³ö¸ÃÑù±¾ÔËÐÐʱ»á¼ì²âÏÂÁî²ÎÊý×îÏȲ¿·ÖÊÇ·ñº¬ÓС±¨Cping¡±×Ö·û´®¡£ÈôÊÇÓиòÎÊý»áÖ±½Ó½øÈëSUB_40CF20º¯ÊýÖÐÔËÐУ»ÈôÊÇûÓиòÎÊý£¬Ö®ºó»á½¨ÉèÔÝʱÎļþ£¬²¢Í¨¹ýCreateProcessWº¯ÊýÒÔÐÂÀú³ÌµÄ·½·¨Æô¶¯¸ÃÔÝʱÎļþ£¨Ò²¾ÍÊÇ×ÓÌ壩¡£
½ÓÏÂÀ´ÎÒÃÇÆÊÎöÁ½¸ö·½Ã棺
-¹Ø×¢¸ÃľÂí£¨Ä¸Ì壩½¨ÉèµÄÊÇʲôÔÝʱÎļþ£¨×ÓÌ壩£¬×ÓÌåµÄÆô¶¯²ÎÊýÊÇʲô£¨Í¼Öиø³öµÄcommandline£© -ÈôÊÇĸÌåûÓвÎÊý¡°¨Cping¡±ÇéÐΣ¬ÔÚsub_40cf20º¯ÊýÄÚÀï×öʲôÐж¯
ĸÌåÖ´ÐÐÀú³Ì
ÆÊÎöĸÌåÈë¿Ú
ÆÊÎöµ½ÕâÀÎÒÃÇÖ»ÖªµÀ¸ÃÑù±¾Òª´øÓС±¨Cping¡±£¬¿ÉÊÇ»¹²»ÖªµÀ¾¿¾¹ÓÐʲô²ÎÊý£»ÄÇôÄÜ×öµÄ¾ÍÊÇÖ±½ÓÔÚÐéÄâ»úÖÐÆô¶¯Ëü£¬²»Ðè´øÓÐÈκβÎÊý£¬Æ¾Ö¤ÎÒÃǵľ²Ì¬ÆÊÎö¿ÉÖª£¬ÕâÖÖÇéÐÎÏ»áÏÈÌìÉúÒ»¸ö×ÓÌ壬Ȼºóͨ¹ýCreateProcessWÀ´Æô¶¯¸Ã×ÓÌå.
Æô¶¯windbg£¬ËäȻ֪µÀÁËĸÌåÄÚÀïÓÐwinmainº¯Êý£¬¿ÉÊÇÔÚûÓзûºÅÎļþµÄÇéÐÎÏÂwindbg»¹²»¿Éʶ±ð³öwinmainÈë¿Úº¯Êý£¬ÒÔÊÇÔÚwindbg¼ÓÔØÄ¸Ìåºó£¬ÐèÒªÕÒµ½Ò»¸ö¶ÏµãÀ´¶¯Ì¬µ÷ÊÔwinmainº¯Êý¡£Í¨¹ýIDA·´»ã±àÖªµÀ£¬ÔÚwinmainº¯ÊýÄÚÀïÏÈÊÇŲÓÃÁËÒ»¸öAPIº¯ÊýGetComputerNameA¡£
ÔÚÔËÐÐGÏÂÁîºÅ»á¶ÏÔÚ´Ë´¦£¬ÈçÏÂͼËùʾ
Éó²é¸Ãº¯ÊýµÄ²ÎÊý
ÓÃGUÏÂÁî¸Ãº¯ÊýÔËÐÐÍê³Éºó£¬¿ÉÒÔ¿´µ½¸Ãº¯ÊýÒѾȡµÃÁËÖ÷»úÃû£¬ÈçÏÂͼ£º
¹ØÓÚÐéÄâ»úϵͳ£º
½ÓÏÂÀ´»á½«´óд×ÖĸÄð³ÉÄð³ÉСд£¬ÈçÏÂͼ
ת»»ºóµÄЧ¹û£º
Ö®ºó»áͨ¹ýCoInitializeº¯Êý¸æËßWindowsÒÔµ¥Ï̵߳ķ½·¨½¨Éècom¹¤¾ß£¬CoInitialize²¢²»×°ÔØCOM ¿â£¬ËüÖ»ÓÃÀ´³õʼ»¯Ä¿½ñỊ̈߳¬ÈÃÏß³Ì×¢²áÒ»¸öÌ×¼þ£¬¶øÏß³ÌÔËÐÐÀú³ÌÖÐÒ»¶¨ÔÚ´ËÌ×¼þ¡£ÈçÏÂͼ£º
ĸÌåÔõÑù±¬·¢×ÓÌå
ÏÂÃæµÄÐж¯¾ÍÊÇÒªÅжÏËüÆô¶¯Ê±ÊÇ·ñ´øÓвÎÊý£¬ÈôÊÇûÓвÎÊý¾Í»áÔÚÔÝʱÎļþ¼Ð½¨ÉèÒ»¸öÎļþ
ÏÔʾ»ñȡĿ½ñÓû§µÄÔÝʱĿ¼£¬Ö®ºó»áÔÚ¸ÃĿ¼Ï±¬·¢Ò»¸öËæ»úÎļþÃû¡£
ÔÚ½¨ÉèÁËÔÝʱÎļþºó£¬½ÓמͻáÏÈ»ñµÃĸÌåÎļþ£¬Í¬Ê±±¬·¢Ò»¸öËæ»ú×Ö·û´®£¬¸ÃËæ»ú×Ö·û´®»á×÷ΪδÀ´×ÓÌåÆô¶¯Ê±²ÎÊý²¿·Ö£¬Ö®ºó½«Êͷű¬·¢µÄ×ÓÌå£¨Ç°ÃæÖ»ÊDZ¬·¢ÔÝʱÎļþ»¹Ã»ÓÐдÈëÊý¾Ý£¬¾ÍÊÇҪдÈëÊý¾Ý£¬Ð´ÈëµÄ´ó²¿·ÖÄÚÈÝÕÕ¾ÉĸÌåµÄÊý¾Ý£©£¬Í¬Ê±Ôڽṹ³öCreateProcessWº¯ÊýÆô¶¯×ÓÌå³ÌÐòʱµÄ²ÎÊý²¿·Ö¡£ÈëÏÂͼ
×ÓÌåÌÓ±Üɱ¶¾Èí¼þ
µ±±¬·¢ÐµÄÎļþʱ£¬É±¶¾Èí¼þͨ³£¶¼ÓÐÓÐËù¾õ²ì£¬ÎªÁËÄÜÌӱܹŰåɱ¶¾Èí¼þµÄ²éɱ£¬ÔÚÌìÉú×ÓÌåʱ£¬Ê¹ÓÃÁ˼ÓÃÜÊÖÒÕ¶Ô×ÓÌå×öÁË¿é¼ÓÃÜ¡£ÏÂÃæÊǺ¯ÊýSUB_40AFF0±¬·¢Ëæ»ú×Ö·û´®µÄÖ÷ÒªÀú³Ì£¬
ÓÉÏÂͼ¿ÉÖª£¬ÔÚ¸´ÖÆÄ¸ÌåÀú³ÌÖжÔĸÌå×Ô¼ºÏÈ×öÁË´¦Öóͷ££¬º¯ÊýSUB_40CEA0ŲÓÃSUB_40CB30£¬¸Ãº¯ÊýÔÚ¸´ÖÆÐ´Èë֮ǰ¶ÔĸÌå×öµÄ´¦Öóͷ££¬Å²ÓÃÀú³ÌºÍ´¦Öóͷ£Àú³ÌÈçÏÂͼ£º
ÓÉÏÂͼ¿ÉÖª£¬ÔÚ¸´ÖÆÄ¸ÌåÀú³ÌÖжÔĸÌå×Ô¼ºÏÈ×öÁË´¦Öóͷ££¬º¯ÊýSUB_40CEA0ŲÓÃSUB_40CB30£¬¸Ãº¯ÊýÔÚ¸´ÖÆÐ´Èë֮ǰ¶ÔĸÌå×öµÄ´¦Öóͷ££¬Å²ÓÃÀú³ÌºÍ´¦Öóͷ£Àú³ÌÈçÏÂͼ£º
×ÓÌåÌÓ±Üɱ¶¾Èí¼þ
µ±±¬·¢ÐµÄÎļþʱ£¬É±¶¾Èí¼þͨ³£¶¼ÓÐÓÐËù¾õ²ì£¬ÎªÁËÄÜÌӱܹŰåɱ¶¾Èí¼þµÄ²éɱ£¬ÔÚÌìÉú×ÓÌåʱ£¬Ê¹ÓÃÁ˼ÓÃÜÊÖÒÕ¶Ô×ÓÌå×öÁË¿é¼ÓÃÜ¡£ÏÂÃæÊǺ¯ÊýSUB_40AFF0±¬·¢Ëæ»ú×Ö·û´®µÄÖ÷ÒªÀú³Ì£¬
ÓÉÏÂͼ¿ÉÖª£¬ÔÚ¸´ÖÆÄ¸ÌåÀú³ÌÖжÔĸÌå×Ô¼ºÏÈ×öÁË´¦Öóͷ££¬º¯ÊýSUB_40CEA0ŲÓÃSUB_40CB30£¬¸Ãº¯ÊýÔÚ¸´ÖÆÐ´Èë֮ǰ¶ÔĸÌå×öµÄ´¦Öóͷ££¬Å²ÓÃÀú³ÌºÍ´¦Öóͷ£Àú³ÌÈçÏÂͼ£º
½ÓÏÂÀ´¾ÍÊÇÒª½¨ÉèÒ»¸ö×ÓÀú³Ì£¨×ÓÌ壩£¬Í¬Ê±¼ì²éÆô¶¯µÄ¸Ã×ÓÌåºÍ²ÎÊý
´ÓÉÏͼ¿ÉÖªcreateprocesswµÚÒ»¸ö²ÎÊýÊÇ¡±c:UsershomeAppDataLocalTempDBE3.tmp¡±µÚ¶þ¸ö²ÎÊýÊÇ¡± ¡°C:UsershomeAppDataLocalTempDBE3.tmp¡± ¨CpingC:ocean est.exe 98A92D9A03B32BBB789802827DD0F5FB245F07A28BE4E9251E55C06A43DAA994A0852C6623D4FEB93139B4A028463B7BF27F727372E5813871AFD7D01AB44430¡±
Ò²¾ÍÊÇ×ÓÌåÃû×Ö½ÐDBE3.tmp£¨ÔÚ¶à´Îµ÷ÊÔÀú³ÌÖУ¬Ã¿´Î±¬·¢µÄÔÝʱÎļþ¶¼·×ÆçÑù£©£¬±¬·¢µÄËæ»ú×Ö·û´®×Åʵ̫³¤ÁË¡£
×ÓÌåÖ´ÐÐÀú³Ì
ÆÊÎö×ÓÌåÈë¿Ú
µ½ÏÖÔÚΪֹ£¬Ä¸ÌåµÄÆô¶¯Àú³Ì»ù±¾ÉÏÆÊÎöÍê³ÉÁË£¬ÎÒÃÇÔÚ×îÏÈ˵µ½ÈôÊÇÓСªping²ÎÊý¼°ÆäËû²¿·Ö£¬»á½øÈëSUB_40CF20º¯Êý¡£ÈçÏÂͼ
ÓÉÓÚÎÒÃDz¢²»ÖªµÀĸÌå²ÎÊýpingºóÃæÏêϸ½ÓʲôÄÚÈÝ£¬ÒÔÊDz»ÓëÆÊÎö¡£×Åʵ²»±Øµ¥¶À½ñÌìÆÊÎöelseºóÃæµÄÄÚÈÝ£¬ÓÉÓÚÎÒÃÇÖªµÀÁË×ÓÌåÖ÷Òª¸´ÖÆÁËĸÌåµÄ³ÌÐò£¬²¢Ìí¼ÓÁË×ÓÌåÆô¶¯Ê±µÄ²ÎÊý£¬Í¨¹ýcreateprocessWº¯ÊýÆô¶¯×ÓÌåʱ£¬×ÓÌå»áÖ±½Ó½øÈëelseÄÚÀÓÉÓÚÏÖÔÚÒѾÓС±¨Cping¡±²ÎÊýÁË¡£ÒÔÊÇÎÒÃÇÆÊÎö×ÓÌå¾Í»áÆÊÎöµ½¸Ã·ÖÖ§¡£
×ÓÌåÆÊÎö£¬ÔÚÉÏÃæÒѾ֪µÀÁË×ÓÌåʱÓÉĸÌ叴֯¶øÀ´£¬²¢ÇÒÔÚ×ÓÌåÆô¶¯Ê±ÒѾÓÐÁ˲ÎÊý£¬Æ¾Ö¤winmainº¯ÊýµÄ´úÂëÁ÷³Ì¿ÉÖª£¬×ÓÌå»á½øÈë
×ÓÌåÈë¿Ú¶¯Ì¬¸ú×Ù
½ÓÏÂÀ´¾ÍÊÇÒª¿´º¯ÊýSUB_40CF20ÄÚÀï×öÁËÄÄЩ²Ù×÷¡£ ÒÔÉÏÃæ»ñµÃµÄ×ÓͼDBE3.tmpΪÀý£¬ÔÚwindbgµ÷ÊÔ´ø²ÎÊýµÄ×ÓÌå¿ÉÒÔÏñÈçÏÂÉèÖÃ
ΪÁËÄܹ»¶¯Ì¬µ÷ÊÔ×Óº¯Êýsub_40CF20£¬ÐèÒªÔڸú¯Êý³ö϶ϵ㣬¿ÉÊÇÓÉÓڸú¯Êý²»ÊDZê×¼µÄAPIº¯Êý£¬ÒÔÊÇҲûÓзûºÅ±í£¬ÕâÑùºÜÄÑÕÒµ½¸Ãº¯ÊýµÄÈë¿ÚµØµã¡£¶Ô´ËÎÒÃÇͨ¹ýÊÓ²ìIDA½ñÌì·´»ã±à´úÂ룬¿ÉÖªsub_40CF20ÔÚCoInitializeºÍmemicmpº¯ÊýÖ®ºó»á±»Å²Óã¬ÒÔÊÇÎÒÃÇ¿ÉÒÔÔÚ±ê×¼API _memicmp»òÊÇËü֮ǰµÄCoInitializeº¯Êý϶ϵ㣬Ȼºó¶¯Ì¬¸ú½øsub_40CF20º¯Êý¼´¿É¡£±¾ÀýÔÚCoInitialize϶ϵã
º¯Êý¶ÏÏÂÀ´ºóµ¥²½¸ú×Ù£¬¸ú½øIDA¾²Ì¬ÆÊÎö_memicmp½ÏÁ¿ÓÐûÓС±¨Cping¡±£¬ÈôÊÇÓеϰ¾Í»áÖ´Ðе½sub_40CF20º¯Êý£¬ÓÉÓÚ×ÓÌåÄÚÀï°üÀ¨Á˸òÎÊý£¬Ò²¾ÍÄÜÖ±½Ó½øÈëelseÄÚÀÉó²éαCºÍ·´»ã±à´úÂë
µ¥²½¶¯Ì¬¸ú×Ùwindbg£¬½øÈëJZ loc_40D6EE
½øÈëelseÄÚÀïÊ×ÏÈsleep(0x7d0)Ö»ÓÐŲÓÃsub_40CF20£¬²¢½«×ÓÌå²ÎÊý×÷Ϊ¸Ã¸Ãº¯ÊýµÄ²ÎÊý´«½øÈ¥£¬¸ú½ø¸Ãº¯Êý
¸Ãº¯ÊýÄÚ²¿×öµÄ²Ù×÷:
ÑéÖ¤×ÓÌå²ÎÊýÖÐÊÇ·ñ°üÀ¨¡± ¡±£¬Ò²¾ÍÊÇ˵ÔÚÆô¶¯×ÓÌåʱ£¬
´Ë´¦²ÎÊýÖ®¼äµÄÖ§½â²»¿ÉÊǿոñ£¬±ØÐèÊÇ¡± ¡± £¬ÌìÉútest.exeÌìÉútest.docxÎĵµ
×ÓÌåÊÍ·ÅdocxÎĵµÀú³Ì
ÉÏÃæËµµ½sub_40BBA0º¯Êý³ÉÁËdocxÎĵµ£¬ÄÇôÊÇÔõôÌìÉúµÄ£¬ÆäŲÓÃÀú³ÌÈçÏÂͼ
Ò²¾ÍÊÇ˵×îÖÕŲÓÃÁ˺¯Êýsub_40B9A0º¯Êý£¬ÄǾͿ´¿´¸Ãº¯ÊýµÄÖ÷ÒªÁ÷³Ì£º
ÉÏͼÊǽØÍ¼¸Ã»¹º¯ÊýµÄÖ÷Òª´úÂ룬´Ó´úÂëÖпÉÖª¸Ãº¯ÊýʹÓÃtest.exe£¬ÌìÉúÁËtest.docxÎĵµ£¬²¢·¿ªÁ˸ÃÎĵµ£¬Õâ¾ÍÊÇΪʲôÈôÊÇÎÒÃǼӲÎÊýÖ±½Ó·¿ªDBE3.tmpÎļþʱ£¬ÌìÉúµÄtest.docxÄܹ»×Ô¶¯·¿ªµÄÔµ¹ÊÔÓÉ¡£
×ÓÌåµÄ·´µ÷ÊÔÊÖÒÕ
ΪÁËÄܹ»±Ü¿ªÐéÄâ»ú¼ì²â»òÊÇÔÚÐéÄâ»úÖе÷ÊÔ£¬×ÓÌåÖмÓÈ붯̬·´µ÷ÊÔÊÖÒÕ£¬ÅжÏÊÇ·ñÓÐÐéÄâ»ú
º¯ÊýŲÓùØÏµÈçÉÏͼËùʾ£¬ÔÚº¯ÊýÄÚÀï×öÁËÐéÄâ»úµÄÅжÏ
´Ó´úÂëÖп´³ö£¬¸Ã×ÓÌå»áÅжÏ×Ô¼ºÊÇ·ñÔÚÐéÄâ»úÖУ»½øÒ»²½¸ú×Ùsub_407260¿´¿´ÅжÏvmwareÄÚÀïÊÇÔõô²Ù×÷µÄ£º
VmwareÎªÕæÖ÷»úÓëÐéÄâ»úÖ®¼äÌṩÁËÏàÏ໥ͬµÄͨѶ»úÖÆ£¬ËüʹÓá°IN¡±Ö¸ÁîÀ´¶ÁÈ¡ÌØ¶¨¶Ë¿ÚµÄÊý¾ÝÒÔ¾ÙÐÐÁ½»úͨѶ£¬µ«ÓÉÓÚINÖ¸ÁîÊôÓÚÌØÈ¨Ö¸ÁÔÚ´¦ÓÚÑÚ»¤Ä£Ê½ÏµÄÕæ»úÉÏÖ´ÐдËÖ¸Áîʱ£¬³ý·ÇȨÏÞÔÊÐí£¬²»È»½«»á´¥·¢ÀàÐÍΪ¡°EXCEPTION_PRIV_INSTRUCTION¡±µÄÒì³££¬¶øÔÚÐéÄâ»úÖв¢²»»á±¬·¢Òì³££¬ÔÚÖ¸¶¨¹¦Ð§ºÅ0A£¨»ñÈ¡VMware°æ±¾£©µÄÇéÐÎÏ£¬Ëü»áÔÚEBXÖзµ»ØÆä°æ±¾ºÅ¡°VMXH¡±¡£
ÌÓ±ÜÐéÄâ»ú¼ì²â»úÖÆ
¾ÓÉÉÏÃæµÄÆÊÎö£¬ÎÒÃÇÖªµÀÁËÔÚÐéÄâÖÐÔËÐлáÖ±½ÓÍ˳ö£¬ÓÉÓÚº¯Êýsub_40B840Ö´ÐÐÍê³Éºó·µ»Øºó£¬·µ»ØÁË1£»Í¬Ê±º¯Êýsub_40B930Ò²¾Í·µ»ØÁË1£»ÕâÑù×ÓÌå¾Í»áÖÕÖ¹ÁËÔËÐУ¬ÈçÏÂͼ
µ«ÎªÁËÔÚÐéÄâ»úÖÐÆÊÎö×ÓÌ壬ÊÖÒÕְԱʹÓö¯Ì¬µ÷ÊÔÊÖÒÕ£¬Ð޸ĴúÂëÁ÷³Ì£¬ÔÚsub_40B930·µ»Øºó£¬Ð޸ķµ»ØÖµÈÃÆä¼ÌÐøÔËÐУ¬ÈçÏÂͼËùʾ
ÕâÑù³ÌÐò¾ÍÄܽøÈëifÓï¾äÄÚÀï¼ÌÐøÔËÐС£½ÓÏÂÀ´×öµÄÊÂÇé¾ÍÊÇÆÊÎö²ÎÊý²¿·ÖµÄËæ»ú×Ö·û´®²¢×ª»¯±àÂë
ÔÚ±àÂëת»»Íê³Éºó£¬×îÏȽâÃÜÎļþ¡£Ç°ÃæËµ¹ý£¬Ä¸ÌåÔÚÌìÉú×ÓÌåʱ»á×ö´¦Öóͷ£ºóÌìÉú×ÓÌ壬¸Ã´¦Öóͷ£¾ÍÊÇ·Ö¿é¼ÓÃܵÄÀú³Ì¡£ÏÂÃæÊÇÏÈÆ¾Ö¤²ÎÊýÖеÄËæ»ú×Ö·û´®ÌìÉú½âÃÜÃØÔ¿£¬È»ºóÔÚ¾ÙÐнâÃÜ¡£
½ÓÏÂÀ´»á±éÀúÀú³ÌÁÐ±í£¬¹Ø±ÕÏà¹ØÀú³Ì¡£ÔÚ½âÃÜÍê³Éºó£¬½øÈ뺯Êýsub_40C6F0ÄÚÀ±éÀúÀú³ÌÁбíÈçÏÂͼ
ͬʱÔÚº¯ÊýÄÚÀïsub_40C6F0ÄÚÀïÍê³ÉÀú³Ì±éÀúÊÂÇ飬Æä×îÖÕŲÓÃÁËsub_40B380
¸ÃÕÕ¾É×îÏÈÏÔʾ±éÀúϵͳÀú³Ì£¬²¢È¡µÃhashÖµ£¬ÓëÖ¸¶¨µÄÖµ½ÏÁ¿£¬ÈôÊÇÏàµÈÔò¹Ø±Õ¸ÃÀú³Ì¡£
ÊÍ·Åqq.exe¼°bundle.rdbÎļþ
ΪÁËÄܹ»ÒÉ»óÓû§£¬Ñù±¾ÔÚÌìÉúÖ´ÐÐÎļþʱ£¬ÌØÒâÃüÃûΪqq.exe;ÔÚŲÓùØÏµÍ¼ÖеÄsub_40B790º¯Êý·µ»Øºó£¬¾Í»áŲÓÃsub_40c260º¯ÊýÌìÉúqq.exeÎļþ£¬ÈçÏÂͼ
¸Ãº¯ÊýÔÚÄÚ²¿Å²ÓÃsub_40BE40À´ÌìÉúQQ.exe
ÊÍ·ÅΪ¹ú¼Ê°æµÄQQ.exe£¬º£ÄÚµÄÓû§Í¨³£²»»áʹÓÃÕâ¸ö°æ±¾£¬²»ÖªµÀÊǹ¥»÷ÕßµÄÊèºöÕÕ¾ÉÓÐÆäËûµÄÄ¿µÄ¡£
Ö®ºóÔÚÔÙ´ÎŲÓøú¯ÊýÌìÉúbundle.rdbÎļþ£¬´«ÈëµÄ²ÎÊý±¬·¢ÁËת±ä

AG¹«Ë¾ÔÆ



























































