{"id":13054,"date":"2015-07-01T09:00:01","date_gmt":"2015-07-01T01:00:01","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=13054"},"modified":"2015-08-28T10:39:30","modified_gmt":"2015-08-28T02:39:30","slug":"%e8%97%8f%e5%9c%a8png%e5%9c%96%e6%aa%94%e5%85%a7%e7%9a%84%e6%9c%a8%e9%a6%ac-%e9%8e%96%e5%ae%9a%e9%86%ab%e7%99%82%e4%bf%9d%e5%81%a5%e6%a5%ad","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=13054","title":{"rendered":"\u85cf\u5728PNG\u5716\u6a94\u5167\u7684\u6728\u99ac, \u9396\u5b9a\u91ab\u7642\u4fdd\u5065\u696d"},"content":{"rendered":"<p><strong>\u7f8e\u570b\u91ab\u7642\u6a5f\u69cb\u53d7Stegoloader\u6728\u99ac\u5f71\u97ff\u6700\u70ba\u56b4\u91cd<\/strong><\/p>\n<p>\u6839\u64da\u89c0\u5bdf\uff0c\u5927\u591a\u6578Stegoloader\u6728\u99ac\uff08\u6700\u8fd1\u6d3b\u8e8d\u5728<a href=\"https:\/\/www.scmagazine.com\/stegoloader-malware-uses-png-files-to-hide-data-stealer\/article\/421280\/\">\u65b0\u805e<\/a>\u4e0a\uff09\u7684\u53d7\u5bb3\u8005\u90fd\u4f86\u81ea\u5317\u7f8e\u7684\u91ab\u7642\u6a5f\u69cb\u3002\u9019\u88ab\u7a31\u70baTROJ_GATAK\u7684\u60e1\u610f\u8edf\u9ad4\u81ea2012\u5e74\u8d77\u5c31\u4e00\u76f4\u6d3b\u8e8d\u8457\uff0c\u5229\u7528\u5716\u50cf\u96b1\u78bc\u8853\uff08Steganography\uff09\u4f86\u5c07\u7d44\u4ef6\u85cf\u5728PNG\u6a94\u5167\u3002<\/p>\n<p><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/02\/anthem-breach1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-11352\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/02\/anthem-breach1.jpg\" alt=\"\u91ab\u7642 \u8cc7\u6599\u5916\u6d29 DLP\" width=\"485\" height=\"485\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/02\/anthem-breach1.jpg 2083w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/02\/anthem-breach1-150x150.jpg 150w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/02\/anthem-breach1-300x300.jpg 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/02\/anthem-breach1-768x768.jpg 768w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/02\/anthem-breach1-1024x1024.jpg 1024w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/02\/anthem-breach1-800x800.jpg 800w\" sizes=\"(max-width: 485px) 100vw, 485px\" \/><\/a><\/p>\n<p>\u7e31\u89c0\u8fd1\u4f86\u7684Stegoloader\u60e1\u610f\u8edf\u9ad4\u53d7\u5bb3\u8005\uff0c\u5728\u904e\u53bb\u4e09\u500b\u6708\u5167\u6240\u770b\u5230\u7684\u5927\u591a\u6578\u53d7\u611f\u67d3\u96fb\u8166\u90fd\u4f86\u81ea\u7f8e\u570b\uff0866.82%\uff09\uff0c\u5176\u6b21\u662f\u667a\u5229\uff089.10%\uff09\u3001\u99ac\u4f86\u897f\u4e9e\uff083.32%\uff09\u3001\u632a\u5a01\uff082.09%\uff09\u53ca\u6cd5\u570b\uff081.71%\uff09\u3002<\/p>\n<p>\u5728\u540c\u4e00\u671f\u9593\uff0c\u53d7\u5230\u5f71\u97ff\u6700\u5927\u7684\u7522\u696d\u662f\u91ab\u7642\u4fdd\u5065\u3001\u91d1\u878d\u548c\u88fd\u9020\u696d\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2015\/06\/steganography-gatak1.jpg\" alt=\"\" width=\"550\" height=\"320\" \/><\/p>\n<p><em>\u57161<\/em><em>\u3001\u904e\u53bb\u4e09\u500b\u6708\u5167\u5404\u7522\u696d\u7684TROJ_GATAK<\/em><em>\u611f\u67d3\u7a0b\u5ea6<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>\u503c\u5f97\u6ce8\u610f\u7684\u662f\uff0c\u6240\u6709\u53d7\u6b64\u60e1\u610f\u8edf\u9ad4\u5f71\u97ff\u7684\u91ab\u7642\u6a5f\u69cb\u90fd\u4f86\u81ea\u5317\u7f8e\u3002<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u7684\u7814\u7a76\u4eba\u54e1\u76ee\u524d\u6b63\u5728\u7814\u7a76\u7db2\u8def\u72af\u7f6a\u5206\u5b50\u5982\u4f55\u53bb\u5229\u7528\u9019\u72c0\u6cc1\u4f86\u9032\u884c\u6709\u7d44\u7e54\u7684\u653b\u64ca\uff0c\u96d6\u7136\u9084\u5728\u5c0b\u627e\u8b49\u64da\u4e2d\u3002<\/p>\n<p>\u6700\u8fd1\u6709\u5e7e\u8d77\u6210\u529f\u7684\u8cc7\u6599\u5916\u6d29\u4e8b\u4ef6\u6d29\u6f0f\u4e86\u6578\u767e\u842c\u7b46\u91ab\u7642\u6a5f\u69cb\u7684\u5ba2\u6236\u8cc7\u6599\uff0c\u50cf\u662f<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cyber-attacks\/millions-affected-in-anthem-breach-healthcare-companies-prime-attack-targets\">Anthem<\/a>\u548c<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cyber-attacks\/premera-blue-cross-data-breach-exposes-11m-patient-records\">Premera Blue Cross<\/a>\u3002\u96d6\u7136\u624d\u51fa\u73fe\u5728\u653b\u64ca\u4e2d\uff0c\u5716\u50cf\u96b1\u78bc\u8853\uff08Steganography\uff09\u53ef\u80fd\u6210\u70ba\u672a\u4f86\u7db2\u8def\u72af\u7f6a\u5206\u5b50\u653b\u64ca\u91ab\u7642\u6a5f\u69cb\u6642\u5916\u6d29\u91ab\u7642\u7d00\u9304\u7684\u65b0\u6280\u8853\u3002<\/p>\n<p>&nbsp;<\/p>\n<p><strong>\u8cc7\u6599\u96b1\u533f\u6280\u8853\uff0c\u9593\u8adc\u7528\u5716\u7247<\/strong><\/p>\n<p>\u5728\u4e4b\u524d\u95dc\u65bc<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=12510\">\u5716\u50cf\u96b1\u78bc\u8853\uff08Steganography\uff09\uff08Steganography\uff09\u548c\u60e1\u610f\u8edf\u9ad4<\/a>\u7684\u6587\u7ae0\u4e2d\uff0c\u6211\u5011\u6307\u51fa\u5728\u5716\u7247\u6a94\u4e2d\u5d4c\u5165\u60e1\u610f\u7a0b\u5f0f\u78bc\u4ee5\u8eb2\u907f\u5075\u6e2c\u7684\u6280\u8853\u6703\u8b8a\u5f97\u66f4\u52a0\u666e\u53ca\uff0c\u7279\u5225\u662f\u6709\u8457\u52e4\u596e\u7684\u60e1\u610f\u8edf\u9ad4\u5718\u9ad4\u5b58\u5728\u3002<\/p>\n<p><strong>TROJ_GATAK<\/strong>\u7684\u518d\u5ea6\u51fa\u73fe\u53ca\u5176\u660e\u986f\u91dd\u5c0d\u67d0\u4e9b\u5730\u5340\u548c\u7522\u696d\u986f\u793a\u51fa\u7db2\u8def\u72af\u7f6a\u5206\u5b50\u5728\u6301\u7e8c\u5730\u8a66\u9a57\u8cc7\u6599\u96b1\u533f\u6280\u8853\uff08Steganography\uff09\u7684\u5275\u610f\u7528\u9014\u4ee5\u64f4\u6563\u5a01\u8105\u3002<\/p>\n<p>\u7576<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u57282014\u5e741\u6708\u7b2c\u4e00\u6b21\u65bc\u90e8\u843d\u683c\u4e2d\u63d0\u5230\u6b64\u60e1\u610f\u8edf\u9ad4\u6642\uff0c<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/troj_gatak.fck\">TROJ_GATAK.FCK<\/a>\u8b8a\u7a2e\u6346\u7d81\u8457\u5404\u7a2e\u61c9\u7528\u7a0b\u5f0f\u7684\u91d1\u9470\u7522\u751f\u5668\uff0c\u800c<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=7227\">\u6700\u7d42\u6703\u5e36\u4f86\u5047\u9632\u6bd2\u8edf\u9ad4<\/a>\u3002<\/p>\n<p>\u800c\u9019\u60e1\u610f\u8edf\u9ad4\u6700\u65b0\u7684\u4e09\u500b\u6a23\u672c\u6700\u7d42\u6703\u5e36\u4f86TROJ_GATAK.SMJV\u3001<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/TROJ_GATAK.SMN\">TROJ_GATAK.SMN<\/a>\u548c<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/TROJ_GATAK.SMP\">TROJ_GATAK.SMP<\/a>\uff08\u5728\u5206\u6790\u4e2d\uff09\u3002<\/p>\n<p>\u8981\u6ce8\u610f\u7684\u662f\uff0c\u9019\u8b8a\u7a2e\u5728\u904e\u53bb\u5e7e\u5e74\u7684\u884c\u70ba\u4fdd\u6301\u4e0d\u8b8a\u3002\u8a72\u60e1\u610f\u8edf\u9ad4\u88ab\u76f8\u4fe1\u5176\u70ba\u91d1\u9470\u7522\u751f\u5668\u6216\u8a3b\u518a\u6a5f\u7684\u4f7f\u7528\u8005\u5f9e\u7db2\u8def\u4e0a\u4e0b\u8f09\u3002\u4e00\u65e6\u4e0b\u8f09\uff0c\u5b83\u507d\u88dd\u6210\u8ddfSkype\u6216Google Talk\u76f8\u95dc\u7684\u6b63\u5e38\u6a94\u6848\u3002\u6700\u7d42\u6703\u4e0b\u8f09\u7167\u7247\uff0c\u5d4c\u5165\u4e86\u5176\u5927\u90e8\u5206\u7684\u529f\u80fd\u3002\u4ee5\u4e0b\u662f\u60e1\u610f\u8edf\u9ad4\u7528\u4f86\u5d4c\u5165\u60e1\u610f\u7d44\u4ef6\u7684\u7167\u7247\u6a23\u672c\uff1a<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2015\/06\/steganography-gatak2.jpg\" alt=\"\" width=\"450\" height=\"705\" \/><\/p>\n<p><em>\u57162<\/em><em>\u3001TROJ_GATAK<\/em><em>\u6240\u4e0b\u8f09\u7684\u5716\u7247\u6a23\u672c<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>\u9019\u60e1\u610f\u8edf\u9ad4\u5177\u5099\u9632\u865b\u64ec\u6a5f\u5668\u548c\u9632\u6a21\u64ec\u529f\u80fd\uff0c\u8b93\u5b83\u53ef\u4ee5\u907f\u514d\u88ab\u5206\u6790\u3002<!--more--><\/p>\n<p>\u904e\u53bb\u4f7f\u7528\u5716\u50cf\u96b1\u78bc\u8853\uff08Steganography\uff09\u7684\u653b\u64ca\u4f7f\u7528\u4e86\u6709\u8da3\u4f46\u5176\u5be6\u6703\u9020\u6210\u50b7\u5bb3\u7684\u5915\u967d\u548c\u8c93\u54aa\u7167\u7247\u4f86\u91dd\u5c0d\u7db2\u8def\u9280\u884c\u5e33\u865f\u3002\u96d6\u7136\u4f7f\u7528\u7167\u7247\u7684\u6280\u8853\u5f88\u8001\u820a\uff0c\u4f46\u5b83\u80fd\u5920\u5e6b\u52a9\u7db2\u8def\u72af\u7f6a\u5206\u5b50\u548c\u5a01\u8105\u5e55\u5f8c\u9ed1\u624b\u4f86\u8eb2\u907f\u5075\u6e2c\u4ecd\u662f\u5b83\u6703\u7e7c\u7e8c\u88ab\u52a0\u4ee5\u4f7f\u7528\u7684\u6709\u529b\u7406\u7531\u3002<\/p>\n<p>&nbsp;<\/p>\n<p><em>\u4ee5\u4e0b\u662f\u5728\u672c\u6587\u4e2d\u6240\u5831\u5c0e\u60e1\u610f\u8edf\u9ad4\u7684\u76f8\u95dcSHA1<\/em><em>\u96dc\u6e4a\u503c\uff1a<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>TROJ_GATAK.SMJV<\/p>\n<ul>\n<li>bce6a9368f7b90caae295f1a3f4d3b55198be2e2<\/li>\n<li>b8db99cf9c646bad027b34a66bb74b8b0bee295a<\/li>\n<li>d5d0a9ecf1601e9e50eef6b2ad25c57b56419cd1<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>TROJ_GATAK.SMN<\/p>\n<ul>\n<li>2d979739fbf4253c601aed4c92f6872885f73f77<\/li>\n<li>11f25bee63a5493f5364e9578fa8db9ed4c4b9c9<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>TROJ_GATAK.SMP<\/p>\n<ul>\n<li>24b2da2aaa97228e0670fc6d5bda037cf127a284<\/li>\n<li>36c00d11e6c51b0174addb5f38e559022bf1a16a<\/li>\n<li>490043a6e903dbd5ddca9c86abba41abeae2edbe<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>\u4f60\u53ef\u4ee5\u5728\u4ee5\u4e0b\u6587\u7ae0\u8b80\u5230\u66f4\u591a\u95dc\u65bc\u8cc7\u6599\u96b1\u533f\u6280\u8853\uff08Steganography\uff09\u7684\u8cc7\u8a0a\uff1a<\/p>\n<ul>\n<li>\u8cc7\u6599\u96b1\u533f\u6280\u8853\uff08Steganography\uff09\u7b2c\u4e00\u90e8\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/steganography-and-malware-why-and-how\/\">\u70ba\u4ec0\u9ebc\u548c\u5982\u4f55\u505a<\/a><\/li>\n<li>\u8cc7\u6599\u96b1\u533f\u6280\u8853\uff08Steganography\uff09\u7b2c\u4e8c\u90e8\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/steganography-and-malware-concealing-code-and-cc-traffic\/\">\u96b1\u85cf\u7a0b\u5f0f\u78bc\u548cC&amp;C\u6d41\u91cf<\/a><\/li>\n<li>\u8cc7\u6599\u96b1\u533f\u6280\u8853\uff08Steganography\uff09\u7b2c\u4e09\u90e8\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/steganography-and-malware-final-thoughts\/\">\u6700\u7d42\u60f3\u6cd5<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&lt; \u66f4\u65b0 &gt;<\/p>\n<p>\u4e0b\u5217\u9375\u76e4\u5074\u9304\u7a0b\u5f0f\uff08\u5075\u6e2c\u70ba<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/TROJ_DROPPER.GTK\">TROJ_DROPPER.GTK<\/a>\uff09\u5df2\u7d93\u78ba\u8a8d\u548c\u6b64\u6b21\u653b\u64ca\u6709\u95dc<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>exe\uff08790528\u4f4d\u5143\uff09<\/li>\n<\/ul>\n<p>SHA1\u503c\uff1aBFE821A91CD7B6E9488D46741630ED91752910CA<\/p>\n<ul>\n<li>exe\uff08865842\u4f4d\u5143\uff09<\/li>\n<\/ul>\n<p>SHA1\u503c\uff1aAF5AE925758B629E594FB8F01EF89D113354A130<\/p>\n<p>&nbsp;<\/p>\n<p>\u6211\u5011\u4e5f\u5c07TROJ_GATAK.SMP\u7684\u96dc\u6e4a\u503c\u52a0\u5230\u4e0a\u9762<\/p>\n<p>&nbsp;<\/p>\n<p>\uff20\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/us-healthcare-organizations-most-affected-by-stegoloader-trojan\/\">US Healthcare Organizations Most Affected by Stegoloader Trojan<\/a>\u4f5c\u8005\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/author\/homerp\/\">Homer Pacag\uff08\u5a01\u8105\u53cd\u61c9\u5de5\u7a0b\u5e2b\uff09<\/a><br \/>\n\u60f3\u4e86\u89e3\u66f4\u591a\u95dc\u65bc\u7db2\u8def\u5b89\u5168\u7684\u79d8\u8a23\u548c\u5efa\u8b70\uff0c\u53ea\u8981\u5230<a href=\"https:\/\/www.facebook.com\/trendmicrotaiwan\">\u8da8\u52e2\u79d1\u6280\u7c89\u7d72\u7db2\u9801<\/a> \u6216\u4e0b\u9762\u7684\u6309\u9215\u6309\u8b9a<\/p>\n<p><iframe loading=\"lazy\" style=\"border: none; overflow: hidden; width: 350px; height: 62px;\" src=\"https:\/\/www.facebook.com\/plugins\/likebox.php?id=255176705131&amp;width=350&amp;connections=0&amp;stream=false&amp;header=false&amp;height=62\" width=\"300\" height=\"150\" frameborder=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p><span style=\"color: red;\"><b>\u300a\u63d0\u9192\u300b<\/b><\/span>\u5728\u7c89\u7d72\u9801\u6a6b\u5e45,\u8b9a\u7684\u53f3\u908a\u4e09\u89d2\u5f62\u9078\u64c7<strong>\u63a5\u6536\u901a\u77e5<\/strong>\u548c<strong>\u65b0\u589e\u5230\u8208\u8da3\u4e3b\u984c\u6e05\u55ae<\/strong>,\u91cd\u8981\u901a\u77e5\u8207\u597d\u5eb7\u4e0d\u6f0f\u63a5<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7f8e\u570b\u91ab\u7642\u6a5f\u69cb\u53d7Stegoloader\u6728\u99ac\u5f71\u97ff\u6700\u70ba\u56b4\u91cd \u6839\u64da\u89c0\u5bdf\uff0c\u5927\u591a\u6578Stegoloader\u6728\u99ac\uff08\u6700\u8fd1\u6d3b\u8e8d\u5728\u65b0 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[8],"tags":[2180,2375,107,2181,1878],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/13054"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13054"}],"version-history":[{"count":0,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/13054\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}