{"id":21817,"date":"2023-03-27T12:21:10","date_gmt":"2023-03-27T04:21:10","guid":{"rendered":"https:\/\/docs.pingcode.com\/?p=21817"},"modified":"2023-03-27T12:21:10","modified_gmt":"2023-03-27T04:21:10","slug":"%e5%a4%9a%e7%a7%8d%e7%99%bd%e6%96%87%e4%bb%b6%e5%88%a9%e7%94%a8%ef%bc%8cevilnum%e8%bf%91%e6%9c%9f%e9%92%88%e5%af%b9%e4%bb%a5%e8%89%b2%e5%88%97%e3%80%81%e5%9c%9f%e8%80%b3%e5%85%b6%e5%9c%b0%e5%8c%ba","status":"publish","type":"post","link":"https:\/\/docs.pingcode.com\/info\/21817.html","title":{"rendered":"\u591a\u79cd\u767d\u6587\u4ef6\u5229\u7528\uff0cEvilnum\u8fd1\u671f\u9488\u5bf9\u4ee5\u8272\u5217\u3001\u571f\u8033\u5176\u5730\u533a\u7684\u653b\u51fb\u6d3b\u52a8\u5206\u6790"},"content":{"rendered":"<h2 id=\"h2-1\"><b>\u4e00<\/b><strong>\u653b\u51fb\u4e8b\u4ef6\u6982\u8ff0<\/strong><\/h2>\n<p>Evilnum\u8f83\u65e9\u662fpwncode\u4e8e2018\u5e745\u6708\u62ab\u9732JavaScript\u6076\u610f\u8f6f\u4ef6\u30022020\u5e74\uff0cESET\u5c06\u6076\u610f\u8f6f\u4ef6Evilnum\u80cc\u540e\u7684\u8fd0\u8425\u56e2\u4f19\u8ddf\u8e2a\u4e3a\u9488\u5bf9\u6b27\u6d32\u548c\u4e9a\u6d32\u5730\u533a\u91d1\u878d\u79d1\u6280\u516c\u53f8\u7684APT\u7ec4\u7ec7\u3002\u9664\u91d1\u878d\u9886\u57df\u5916\uff0cEvilnum\u8fd8\u9488\u5bf9\u6e38\u620f\u3001\u7535\u4fe1\u7b49\u5176\u4ed6\u884c\u4e1a\u3002\u8be5\u7ec4\u7ec7\u7684\u653b\u51fb\u624b\u6cd5\u591a\u6837\uff0c\u5305\u62ec\u5229\u7528\u5404\u79cd\u6f0f\u6d1e\u3001\u4f7f\u7528\u6076\u610f\u8f6f\u4ef6\u548c\u9493\u9c7c\u7b49\u624b\u6bb5\u8fdb\u884c\u653b\u51fb\u3002<\/p>\n<p>Evilnum\u7ec4\u7ec7\u5728\u653b\u51fb\u6d3b\u52a8\u4e2d\u90e8\u7f72\u7684\u6076\u610f\u8f6f\u4ef6\u4e3b\u8981\u4e3aMaaS\u6076\u610f\u8f6f\u4ef6\u63d0\u4f9b\u5546Golden Chickens\u7684TerraLoader\u7cfb\u5217\uff1aMore_eggs\u3001TerraPreter\u7b49\uff0c\u76f8\u5173\u4ee3\u7801\u88ab\u53e6\u4e00\u4e2a\u51fa\u4e8e\u7ecf\u6d4e\u52a8\u673a\u7684\u5a01\u80c1\u7ec4\u7ec7Cobalt\u4f7f\u7528\u3002\u8fd9\u4e9b\u6076\u610f\u8f6f\u4ef6\u5177\u6709\u6a21\u5757\u5316\u548c\u7075\u6d3b\u7684\u7279\u6027\uff0c\u53ef\u7528\u4e8e\u6267\u884c\u5404\u79cd\u653b\u51fb\u4efb\u52a1\uff0c\u4f8b\u5982\u7a83\u53d6\u51ed\u636e\u3001\u62e6\u622a\u7f51\u7edc\u6d41\u91cf\u3001\u7a83\u53d6\u654f\u611f\u6570\u636e\u7b49\u3002<\/p>\n<p>\u8fd1\u65e5\uff0c\u5b89\u6052\u730e\u5f71\u5b9e\u9a8c\u5ba4\u6355\u83b7\u4e86Evilnum\u7ec4\u7ec7\u9488\u5bf9\u4ee5\u8272\u5217\u5730\u533a\u7684\u653b\u51fb\u6837\u672c\uff0c\u539f\u59cb\u6587\u4ef6\u4e3a\u5305\u542b\u6709JPG\u6587\u4ef6\u4e0e\u4f2a\u88c5\u6210PNG\u56fe\u7247\u7684LNK\u6587\u4ef6\u7684ZIP\u6587\u4ef6\uff0c\u5176\u4e2dJPG\u6587\u4ef6\u5982\u4e0b\u56fe\uff0c\u4e3a\u82f1\u56fd\u5c45\u6c11Emily Rose\u7684\u62a4\u7167\u4fe1\u606f\uff0cLNK\u5219\u4f2a\u88c5\u6210PNG\u56fe\u50cf\u5f15\u5bfc\u7528\u6237\u70b9\u51fb\u6267\u884c\u3002Evilnum\u6b64\u524d\u5e38\u5229\u7528\u5c45\u6c11\u8eab\u4efd\u8bc1\u4ef6\u4fe1\u606f\u7528\u4f5c\u8bf1\u9975\u6587\u4ef6\u3002<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" alt=\"\" height=\"466\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679550917_641be9c52b3d7aebc1b27.png\" width=\"690\"\/><\/p>\n<p>\u76f8\u5173\u653b\u51fb\u6d41\u7a0b\u5982\u4e0b\u56fe<\/p>\n<p><img decoding=\"async\" alt=\"\" height=\"248\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679550925_641be9cd706107cad0a56.png\" width=\"690\"\/><\/p>\n<h2 id=\"h2-2\"><b>\u4e8c<\/b><strong>\u6076\u610f\u6587\u4ef6\u6267\u884c<\/strong><\/h2>\n<p>1\u3001LNK\u6587\u4ef6<\/p>\n<p>LNK\u6587\u4ef6\u5305\u542b\u4e00\u6bb5\u7ecf\u6df7\u6dc6\u7684CMD\u6307\u4ee4\uff0c\u6307\u4ee4\u6267\u884c\u540e\u5c06\u590d\u5236%windir%\\System32\\ie4uinit.exe\u6587\u4ef6\u5230%tmp%\u76ee\u5f55\uff0c\u5728%tmp%\\ieuinit.inf\u6587\u4ef6\u4e2d\u5199\u5165\u76f8\u5173\u914d\u7f6e\u4fe1\u606f\uff0c\u6700\u540e\u542f\u52a8%tmp%\\ie4uinit.exe\u3002<\/p>\n<p><img decoding=\"async\" alt=\"\" height=\"223\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556631_641c00179768ee96c8c09.png\" width=\"690\"\/><\/p>\n<p>\u5b89\u6052\u4e91\u6c99\u7bb1\u5bf9LNK\u6587\u4ef6\u7684\u8fdb\u7a0b\u4fe1\u606f\u5206\u6790\u5982\u4e0b\uff0cLNK\u6587\u4ef6\u8fd0\u884c\u540e\u5c06\u542f\u52a8ie4uinit.exe\u8fde\u63a5C2\u83b7\u53d6\u540e\u7eed\u6076\u610f\u8d1f\u8f7d\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"331\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556641_641c00211b0b6cfedde60.png\" width=\"690\"\/><\/p>\n<p>2\u3001Javascript\u811a\u672c<\/p>\n<p>LNK\u6587\u4ef6\u6267\u884c\u540e\u5c06\u52a0\u8f7d\u540e\u7eedJavascript\u6307\u4ee4\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"365\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556656_641c003086cbf68cbbc9e.png\" width=\"690\"\/><\/p>\n<p>\u8fdc\u7a0bJavascript\u6307\u4ee4\u8fd0\u884c\u540e\uff0c\u5c06\u89e3\u5bc6\u4ee5\u4e0b3\u4e2a\u6587\u4ef6\u5230\u672c\u5730\uff1a<\/p>\n<p>1\u767d\u6587\u4ef6\uff1a%appdata%\\Microsoft\\msxsl.exe<\/p>\n<p>2PersPays\uff1a%appdata%\\Microsoft\\{\u968f\u673a\u5b57\u7b26}.txt (1758 bytes)<\/p>\n<p>3Pays\uff1a%appdata%\\Microsoft\\{\u968f\u673a\u5b57\u7b26}.txt (27098 bytes)<\/p>\n<p>\u5176\u4e2dPersPays\u6587\u4ef6\u7528\u4e8e\u542f\u52a8\u767d\u6587\u4ef6msxsl.exe\u5e76\u52a0\u8f7dPays\u6709\u6548\u8d1f\u8f7d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"131\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556670_641c003e02918e5517094.png\" width=\"690\"\/><\/p>\n<p>\u9664\u4e86\u91ca\u653e\u6587\u4ef6\u5916\uff0c\u8fdc\u7a0bJavascript\u6307\u4ee4\u8fd8\u901a\u8fc7\u4fee\u6539\u6ce8\u518c\u8868\u952e\u503c\u5b9e\u73b0\u6076\u610f\u4ee3\u7801\u7684\u6301\u4e45\u5316\u9a7b\u7559\u3002<\/p>\n<p><\/p>\n<p>\u6700\u540e\u5c1d\u8bd5\u901a\u8fc7WMI Win32_Process\u521b\u5efacmd\u8fdb\u7a0b\uff0c\u542f\u52a8\u767d\u6587\u4ef6msxsl.exe\u5e76\u52a0\u8f7dPays\u6709\u6548\u8d1f\u8f7d\uff0c\u82e5\u521b\u5efa\u5931\u8d25\uff0c\u5219\u4f7f\u7528WScript.Shell\u542f\u52a8\u76f8\u5e94\u8fdb\u7a0b\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"304\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556678_641c0046b923e44dbb199.png\" width=\"690\"\/><\/p>\n<p>\u91ca\u653e\u5728\u672c\u5730\u7684Pays\u6587\u4ef6\u89e3\u5bc6\u4e0b\u4e00\u9636\u6bb5\u6709\u6548\u8d1f\u8f7d\u7684\u8fc7\u7a0b\u4e0e\u4e0a\u4e00\u9636\u6bb5\u7c7b\u4f3c\uff0c\u5747\u4f7f\u7528basE91\u7b97\u6cd5[1]\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"459\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556687_641c004f574b251aef483.png\" width=\"690\"\/><\/p>\n<p>\u6b64\u5916\uff0c\u4ee3\u7801\u8fd8\u901a\u8fc7WMI\u76d1\u63a7\u8fdb\u7a0b\u6b7b\u4ea1\uff1a<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"368\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556696_641c00583799fecfbb309.png\" width=\"690\"\/><\/p>\n<h2 id=\"h2-3\"><b>\u4e09<\/b><strong>\u6301\u4e45\u5316\u9a7b\u7559<\/strong><\/h2>\n<p>Javascript\u811a\u672c\u8fd0\u884c\u540e\u5c06\u901a\u8fc7\u6ce8\u518c\u8868HKCU\\Environment\\UserInitMprLogonScript\u8bbe\u7f6e\u73af\u5883\u53d8\u91cfcscript \/b \/e:jscript &#8220;%APPDATA%\\Microsoft\\VQKWTAG5IKIFRAUK.txt&#8221;\uff0c\u4ee5\u5b9e\u73b0\u6076\u610f\u4ee3\u7801\u7684\u6301\u4e45\u5316\u9a7b\u7559\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"54\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556708_641c00642720fba7ab677.png\" width=\"690\"\/><\/p>\n<h2 id=\"h2-4\"><b>\u56db<\/b><strong>\u9632\u5fa1\u89c4\u907f\u624b\u6bb5<\/strong><\/h2>\n<p>1\u539f\u59cb\u6837\u672c\u4e3a\u4f2a\u88c5\u6210PNG\u56fe\u7247\u7684LNK\u6587\u4ef6<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"152\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556721_641c0071d533365655ddb.png\" width=\"382\"\/><\/p>\n<p>2\u6076\u610f\u6587\u4ef6\u4e2d\u5305\u542b\u7684cmd\u6307\u4ee4\u4e0eJavascript\u6307\u4ee4\u7b49\u5747\u7ecf\u8fc7\u6df7\u6dc6\u5904\u7406<\/p>\n<p>3cmd\u6307\u4ee4\u901a\u8fc7INF-SCT\u6280\u672f\u6267\u884c\u540e\u7eed\u6709\u6548\u8d1f\u8f7d<\/p>\n<p>INF\u6587\u4ef6\u662f\u4e00\u4e2a\u7eaf\u6587\u672c\u6587\u4ef6\uff0c\u5176\u4e2d\u5305\u542b\u5728Windows\u64cd\u4f5c\u7cfb\u7edf\u4e2d\u5b89\u88c5\u8bbe\u5907\u9a71\u52a8\u7a0b\u5e8f\u548c\u8f6f\u4ef6\u5e94\u7528\u7a0b\u5e8f\u7684\u8bf4\u660e\u3002\u653b\u51fb\u8005\u901a\u8fc7\u52a0\u8f7dINF\u6587\u4ef6\uff0c\u53ef\u4ee5\u6267\u884c\u4f4d\u4e8e\u8fdc\u7a0b\u670d\u52a1\u5668\u4e0a\u7684\u8fdc\u7a0b\u811a\u672c\u7ec4\u4ef6\u6587\u4ef6(SCT)\uff0c\u5e76\u5728\u76ee\u6807\u8ba1\u7b97\u673a\u4e0a\u6267\u884c\u4efb\u610f\u4ee3\u7801\u3002<\/p>\n<p>\u672c\u6b21\u6355\u83b7\u7684Evilnum\u7ec4\u7ec7\u6837\u672c\u901a\u8fc7\u8fd0\u884cie4uinit.exe -basesettings\u6210\u529f\u52a0\u8f7d\u4e86\u540d\u4e3aieuinit.inf\u7684INF\u6587\u4ef6[2]\uff0c\u4ece\u800c\u8fdc\u7a0b\u6267\u884c\u4e86Javascript\u6076\u610f\u4ee3\u7801\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"199\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556732_641c007cf043e9d7c02c1.png\" width=\"690\"\/><\/p>\n<p>4\u5229\u7528msxls.exe\u7ed5\u8fc7AppLocker\u5e94\u7528\u7a0b\u5e8f\u63a7\u5236\u7b56\u7565<\/p>\n<p>msxls.exe\u53ef\u4ee5\u5728\u4e0d\u542f\u52a8MicrosoftExcel\u7684\u60c5\u51b5\u4e0b\u89e3\u6790\u548c\u6267\u884c\u591a\u79cd\u7c7b\u578b\u7684\u811a\u672c\u6587\u4ef6\uff0c\u4f8b\u5982\uff1aVBScript\u3001JavaScript\u3001PowerShell\u3001Python\u811a\u672c\u3001Perl\u811a\u672c\u7b49\u3002\u7531\u4e8emsxls.exe\u662fMicrosoft Excel\u81ea\u5e26\u7684\u5de5\u5177\uff0c\u800c\u4e14\u5728\u9ed8\u8ba4\u60c5\u51b5\u4e0b\u88ab\u5305\u542b\u5728Windows\u64cd\u4f5c\u7cfb\u7edf\u4e2d\uff0c\u6240\u4ee5\u653b\u51fb\u8005\u5229\u7528\u4e86\u5176\u767d\u6587\u4ef6\u5c5e\u6027\u7ed5\u8fc7AppLocker\u7684\u5e94\u7528\u7a0b\u5e8f\u63a7\u5236\u7b56\u7565\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"131\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556741_641c008599a1d9f7329f9.png\" width=\"690\"\/><\/p>\n<h2 id=\"h2-5\"><b>\u4e94<\/b><strong>\u4fe1\u606f\u53d1\u73b0\u4e0e\u4e0a\u4f20<\/strong><\/h2>\n<p>Javascript\u811a\u672c\u68c0\u67e5\u672c\u673a\u662f\u5426\u5b58\u5728\u6ce8\u518c\u6587\u4ef6\uff0c\u82e5\u5b58\u5728\uff0c\u5219\u8bf7\u6c42telemistry[.]net\/get.php?id={\u6587\u4ef6\u5185\u5bb9} \u4ee5\u83b7\u53d6\u540e\u7eed\u6267\u884c\u3002<\/p>\n<p>\u82e5\u4e0d\u5b58\u5728\u6ce8\u518c\u6587\u4ef6\uff0c\u5219\u83b7\u53d6\u4e3b\u673a\u8ba1\u7b97\u673a\u540d\u3001\u7528\u6237\u540d\u3001\u7528\u6237\u6240\u5728\u57df\u4ee5\u53ca\u672c\u673a\u53cd\u75c5\u6bd2\u8f6f\u4ef6\u4fe1\u606f\uff0c\u4ee5&#8221;|&#8221;\u7b26\u8fde\u63a5\uff0c\u8bf7\u6c42telemistry[.]net\/reg.php?g={\u4e3b\u673a\u4fe1\u606f} \u8fdb\u884c\u201c\u6ce8\u518c\u201d\uff0c\u5e76\u5c06\u8fd4\u56de\u5185\u5bb9\u5199\u5165\u6ce8\u518c\u6587\u4ef6\u3002<\/p>\n<p><img decoding=\"async\" alt=\"\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556755_641c009367b5b7e881910.png\"\/><\/p>\n<h2 id=\"h2-6\"><b>\u516d<\/b><strong>\u6837\u672c\u5173\u8054\u5206\u6790<\/strong><\/h2>\n<p>\u730e\u5f71\u5b9e\u9a8c\u5ba4\u89c2\u5bdf\u5230Evilnum\u7ec4\u7ec7\u57df\u540d\u8d44\u4ea7\u4e0a\u5b58\u5728\u591a\u4e2a\u653b\u51fb\u6837\u672c\uff0c\u8fd9\u4e9b\u6837\u672c\u5747\u7528\u4e8e\u540c\u4e00\u653b\u51fb\u6d3b\u52a8\uff0c\u6d3b\u52a8\u7591\u4f3c\u8f83\u65e9\u5f00\u59cb\u4e8e2022\u5e7412\u6708\uff0c\u6301\u7eed\u81f32023\u5e743\u6708\u3002<\/p>\n<table class=\"editor-table-container\" width=\"100%\">\n<tbody>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"30%\">\n<p>FileName<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"66%\">\n<p>Hash<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"30%\">\n<p>Axiance_FullReport_Volume.png.lnk<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"66%\">\n<p>76c84c02b044689e11c71fede9f0b61d<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"30%\">\n<p>screenshots-9201.jpg.zip<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"66%\">\n<p>cf66be681fa44f6a2ed8dc51cc73d0ad<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"30%\">\n<p>Screenshot-9501.JPG.lnk<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"66%\">\n<p>cf53baf5ec89b66224d208c64c39eeb3<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"30%\">\n<p>Screenshot-9502.JPG.lnk<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"66%\">\n<p>f0dc2c2e01e0a7d1425cab539679927e<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"30%\">\n<p>Screenshot-9501.JPG.lnk<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"66%\">\n<p>ea896822cbc2f484be9d385c211322c1<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"30%\">\n<p>Screenshot-9502.JPG.lnk<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"66%\">\n<p>772f58a2bbf689c5b6c8daf9e0445b43<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"30%\">\n<p>Screenshot_0459159441.lnk<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"66%\">\n<p>88101c9a59741278879d3a4d59e96540<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u6211\u4eec\u5bf9\u540c\u6279\u653b\u51fb\u6837\u672c\u8fdb\u884c\u5206\u6790\u540e\u53d1\u73b0\uff0c\u90e8\u5206\u6837\u672c\u540e\u7eed\u4f1a\u4e0b\u53d1Cobalt Strike Beacon\u7ee7\u7eed\u52a0\u8f7d\u540e\u7eed\u8d1f\u8f7d\uff08ukmedia[.]store\/static-directory\/html.mp3\uff09\u6267\u884c\u3002\u622a\u81f3\u5206\u6790\u65f6\u95f4\uff0c\u540e\u7eed\u6587\u4ef6\u5df2\u5931\u6d3b\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"377\" class=\"aligncenter\" src=\"https:\/\/cdn-docs.pingcode.com\/wp-content\/uploads\/2023\/03\/1679556768_641c00a0440933c8ad72b.png\" width=\"690\"\/><\/p>\n<h2 id=\"h2-7\"><b>\u4e03<\/b><strong>\u6d3b\u52a8\u603b\u7ed3<\/strong><\/h2>\n<p>Evilnum\u7ec4\u7ec7\u5728\u6211\u4eec\u6700\u65b0\u53d1\u73b0\u7684\u6d3b\u52a8\u4e2d\uff0c\u4f7f\u7528\u4e86\u6df7\u6dc6cmd\u6307\u4ee4\u542f\u52a8\u767d\u6587\u4ef6\u7684\u65b9\u5f0f\u52a0\u8f7d\u521d\u59cb\u6709\u6548\u8d1f\u8f7d\uff0c\u8be5\u65b9\u5f0f\u5728VT\u5e73\u53f0\u4e0a\u62e5\u6709\u8f83\u597d\u7684\u514d\u6740\u7387\u3002\u540c\u65f6\uff0c\u8be5\u7ec4\u7ec7\u8fd8\u901a\u8fc7\u53e6\u4e00\u767d\u6587\u4ef6msxsl.exe\u7ed5\u8fc7AppLocker\u7684\u5e94\u7528\u7a0b\u5e8f\u63a7\u5236\u7b56\u7565\u540e\u52a0\u8f7d\u6709\u6548\u8d1f\u8f7d\u3002<\/p>\n<p>\u4e3a\u4e86\u9632\u6b62msxls.exe\u88ab\u6ee5\u7528\uff0c\u5b89\u6052\u730e\u5f71\u5b9e\u9a8c\u5ba4\u5efa\u8bae\u7ba1\u7406\u5458\u5728\u7cfb\u7edf\u4e0a\u5b9e\u65bd\u9002\u5f53\u7684\u5b89\u5168\u63a7\u5236\u63aa\u65bd\uff0c\u4f8b\u5982\u7981\u7528msxls.exe\u5de5\u5177\u6216\u9650\u5236\u5176\u6267\u884c\u6743\u9650\uff0c\u4ee5\u786e\u4fdd\u7cfb\u7edf\u7684\u5b89\u5168\u6027\u3002\u9488\u5bf9WMI\u88ab\u6ee5\u7528\u7684\u60c5\u51b5\u540c\u7406\uff0c\u5e94\u9650\u5236WMI\u670d\u52a1\u7684\u8bbf\u95ee\u6743\u9650\u3002\u5176\u4ed6\u9632\u8303\u65b9\u5f0f\u8fd8\u5305\u62ec\u6b63\u786e\u914d\u7f6eAppLocker\u89c4\u5219\uff0c\u53ca\u65f6\u66f4\u65b0\u5e94\u7528\u7a0b\u5e8f\u7b49\u3002<\/p>\n<h2 id=\"h2-8\"><b>\u516b <\/b><strong>ATT&amp;CK\u653b\u51fb\u77e9\u9635 V12<\/strong><\/h2>\n<table class=\"editor-table-container\" width=\"100%\">\n<tbody>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"10%\">\n<p>Tactic<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>ID<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>Name<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>Description<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"4\" width=\"10%\">\n<p>\u6267\u884c<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1059.003<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>Windows Command Shell<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>\u901a\u8fc7cmd.exe\u6267\u884c\u547d\u4ee4<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1059.007<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>JavaScript<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>\u521d\u59cb\u9636\u6bb5\u8d1f\u8f7d\u83b7\u53d6JavaScript\u540e\u7eed\u811a\u672c\u6267\u884c<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1204<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u7528\u6237\u6267\u884c<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>\u53d7\u5bb3\u8005\u88ab\u5f15\u8bf1\u6253\u5f00\u5c06\u5b89\u88c5\u6076\u610fJS\u7ec4\u4ef6\u7684LNK\u6587\u4ef6<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1047<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>Windows\u7ba1\u7406\u5de5\u5177<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>JS\u7ec4\u4ef6\u4f7f\u7528WMI\u83b7\u53d6\u6740\u8f6f\u4ea7\u54c1\u4fe1\u606f<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"10%\">\n<p>\u6301\u4e45\u5316<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1037.001<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u767b\u5f55\u811a\u672c<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>JS\u7ec4\u4ef6\u5c06\u811a\u672c\u8def\u5f84\u6dfb\u52a0\u5230HKCU\\Environment\\UserInitMprLogonScript\u6ce8\u518c\u8868\u9879<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"7\" width=\"10%\">\n<p>\u9632\u5fa1\u95ea\u907f<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1574<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u52ab\u6301\u6267\u884c\u6d41\u7a0b<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>\u901a\u8fc7\u5728ieuinit.inf\u6587\u4ef6\u5199\u5165\u76f8\u5173\u914d\u7f6e\u4f7f\u6076\u610f\u4ee3\u7801\u88ab\u767d\u6587\u4ef6ie4uinit.exe\u52a0\u8f7d<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1553.002<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u4ee3\u7801\u7b7e\u540d<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>Evilnum\u4f7f\u7528\u5408\u6cd5\uff08\u5df2\u7b7e\u540d\uff09\u5e94\u7528\u7a0b\u5e8fmsxsl.exe\u4f5c\u4e3a\u9632\u5fa1\u89c4\u907f\u673a\u5236<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1036.007<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u53cc\u6587\u4ef6\u6269\u5c55\u540d<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>Evilnum\u4f7f\u7528.png.lnk\u6216.jpg.lnk\u7684\u53cc\u6587\u4ef6\u6269\u5c55\u540d\u4f2a\u88c5\u6587\u4ef6\u771f\u5b9e\u7c7b\u578b<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1112<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u4fee\u6539\u6ce8\u518c\u8868<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>Evilnum\u4e3a\u4e86\u5728\u53d7\u635f\u7cfb\u7edf\u4e2d\u6301\u4e45\u5b58\u5728\u4f7f\u7528\u6ce8\u518c\u8868\u7684\u8fd0\u884c\u952e<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1027<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u6df7\u6dc6\u6587\u4ef6\u6216\u4fe1\u606f<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>Evilnum\u6076\u610f\u7ec4\u4ef6\u4e2d\u4f7f\u7528\u5927\u91cf\u4e86\u52a0\u5bc6\u3001\u7f16\u7801\u548c\u6df7\u6dc6<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1027.009<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u5d4c\u5165\u5f0f\u6709\u6548\u8f7d\u8377<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>Evilnum\u5728JS\u811a\u672c\u4e2d\u5d4c\u5165\u4e86\u4e0b\u4e00\u9636\u6bb5\u6709\u6548\u8d1f\u8f7d<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1220<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>XSL\u811a\u672c\u5904\u7406<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>More_eggs\u6076\u610f\u8f6f\u4ef6\u4f7f\u7528msxsl.exe\u4eceXSL\u6587\u4ef6\u8c03\u7528JS\u4ee3\u7801<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"2\" width=\"10%\">\n<p>\u53d1\u73b0<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1518.001<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u5b89\u5168\u8f6f\u4ef6\u53d1\u73b0<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>JS\u7ec4\u4ef6\u4f1a\u641c\u7d22\u5df2\u5b89\u88c5\u7684\u9632\u75c5\u6bd2\u8f6f\u4ef6<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1082<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u7cfb\u7edf\u4fe1\u606f\u53d1\u73b0<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>Evilnum\u5c06\u6709\u5173\u7cfb\u7edf\u7684\u4fe1\u606f\u88ab\u53d1\u9001\u5230C&amp;C\u670d\u52a1\u5668<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"3\" width=\"10%\">\n<p>C&amp;C<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1104<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u591a\u7ea7\u901a\u9053<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>Evilnum\u5176\u5404\u79cd\u7ec4\u4ef6\u4f7f\u7528\u72ec\u7acb\u7684C&amp;C\u670d\u52a1\u5668<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1105<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u8fdc\u7a0b\u6587\u4ef6\u590d\u5236<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>\u4eceC&amp;C\u670d\u52a1\u5668\u4e0a\u4f20\/\u4e0b\u8f7d\u6587\u4ef6<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\" width=\"20%\">\n<p>T1071<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"25%\">\n<p>\u6807\u51c6\u5e94\u7528\u5c42\u534f\u8bae<\/p>\n<\/td>\n<td colspan=\"1\" rowspan=\"1\" width=\"41%\">\n<p>HTTP\u548cHTTPS\u7528\u4e8eC&amp;C<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>\u53c2\u8003\u94fe\u63a5<\/strong><\/p>\n<p>[1] https:\/\/github.com\/Equim-chan\/base91\/<\/p>\n<p>[2] https:\/\/bohops.com\/2018\/03\/10\/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2\/<\/p>\n<p>\u6587\u7ae0\u6765\u81ea\uff1ahttps:\/\/www.freebuf.com\/<\/p>\n","protected":false},"excerpt":{"rendered":"\u4e00\u653b\u51fb\u4e8b\u4ef6\u6982\u8ff0 Evilnum\u8f83\u65e9\u662fpwncode\u4e8e2018\u5e745\u6708\u62ab\u9732JavaScript\u6076\u610f\u8f6f\u4ef6\u30022020\u5e74 [&hellip;]","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[134],"tags":[],"acf":[],"_links":{"self":[{"href":"https:\/\/docs.pingcode.com\/wp-json\/wp\/v2\/posts\/21817"}],"collection":[{"href":"https:\/\/docs.pingcode.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/docs.pingcode.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/docs.pingcode.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/docs.pingcode.com\/wp-json\/wp\/v2\/comments?post=21817"}],"version-history":[{"count":0,"href":"https:\/\/docs.pingcode.com\/wp-json\/wp\/v2\/posts\/21817\/revisions"}],"wp:attachment":[{"href":"https:\/\/docs.pingcode.com\/wp-json\/wp\/v2\/media?parent=21817"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/docs.pingcode.com\/wp-json\/wp\/v2\/categories?post=21817"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/docs.pingcode.com\/wp-json\/wp\/v2\/tags?post=21817"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}