{"id":50734,"date":"2017-07-25T09:00:45","date_gmt":"2017-07-25T01:00:45","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=50734"},"modified":"2018-12-19T14:02:28","modified_gmt":"2018-12-19T06:02:28","slug":"%e6%83%a1%e6%84%8f%e7%a8%8b%e5%bc%8f%e5%88%a9%e7%94%a8-yara-%e5%b7%a5%e5%85%b7%e4%bd%9c%e5%bc%84%e8%b3%87%e5%ae%89%e7%a0%94%e7%a9%b6%e4%ba%ba%e5%93%a1","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=50734","title":{"rendered":"\u60e1\u610f\u8edf\u9ad4\u8b58\u5225\u5de5\u5177Yara ,\u7adf\u88ab\u60e1\u610f\u7a0b\u5f0f\u7528\u4f86\u4f5c\u5f04\u8cc7\u5b89\u7814\u7a76\u4eba\u54e1"},"content":{"rendered":"<p>\u5c0d\u7d55\u5927\u591a\u6578\u8cc7\u5b89\u7814\u7a76\u4eba\u54e1\u4f86\u8aaa\uff0cYara \u662f\u4e00\u500b\u975e\u5e38\u5bf6\u8cb4\u7684\u60e1\u610f\u8edf\u9ad4\u8b58\u5225\u5de5\u5177\uff0c\u5b83\u53ef\u5efa\u7acb\u4e00\u4e9b\u898f\u5247\u4f86\u8ffd\u8e64\u60e1\u610f\u7a0b\u5f0f\uff0c\u8b93\u8a31\u591a\u8cc7\u5b89\u7814\u7a76\u4eba\u54e1\u7684\u4f5c\u696d\u6d41\u7a0b\u53ef\u4ee5\u81ea\u52d5\u5316\u3002\u7136\u800c\uff0c\u5118\u7ba1 Yara \u53ef\u9760\u53c8\u597d\u7528\uff0c\u4f46\u537b\u4e0d\u61c9\u7576\u6210\u76e3\u63a7\u6700\u65b0\u60e1\u610f\u7a0b\u5f0f\u8b8a\u7a2e\u7684\u552f\u4e00\u5de5\u5177\u3002<\/p>\n<p>\u7db2\u8def\u4e0a\u53ef\u4ee5\u627e\u5230\u5f88\u591a Yara \u7684\u898f\u5247\uff0c\u5f9e <a href=\"https:\/\/github.com\/Yara-Rules\">Yara-Rules \u5c08\u6848<\/a>\u5230<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=31133\">\u672c\u90e8\u843d\u683c\u6587\u7ae0<\/a>\u6240\u63d0\u4f9b\u7528\u4f86\u5075\u6e2c\u60e1\u610f\u7a0b\u5f0f\u5165\u4fb5\u6307\u6a19 (IOC) \u7684 Yara \u898f\u5247\u90fd\u6709\u3002\u9664\u6b64\u4e4b\u5916\uff0c\u8cc7\u5b89\u7814\u7a76\u4eba\u54e1\u9084\u53ef\u5efa\u7acb\u5c6c\u65bc\u81ea\u5df1\u7684\u898f\u5247\u4f86\u5075\u6e2c\u76ee\u524d\u6b63\u5728\u5c0b\u627e\u7684\u7279\u5b9a\u5a01\u8105\uff0c\u6709\u6642\u5019\u4e26\u4e0d\u6703\u8f38\u7d66\u7db2\u8def\u4e0a\u6240\u63d0\u4f9b\u7684\u898f\u5247\u3002<\/p>\n<p>\u300a\u5ef6\u4f38\u95b1\u8b80\u300b<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=31133\">\u900f\u904e\u5206\u6790Stampado \u52d2\u7d22\u75c5\u6bd2,\u6539\u826f\u60e1\u610f\u8edf\u9ad4\u8fa8\u8b58\u5de5\u5177Yara<\/a><\/p>\n<p>\u7576 Yara \u7684\u67d0\u500b\u898f\u5247\u88ab\u89f8\u767c\u6642\uff0c\u5b83\u6703\u7522\u751f\u8b66\u793a\u4f86\u63d0\u9192\u7814\u7a76\u4eba\u54e1\u63a1\u53d6\u9032\u4e00\u6b65\u884c\u52d5\uff0c\u5305\u62ec\u555f\u52d5\u865b\u64ec\u6a5f\u5668 (VM) \u6216\u9664\u932f\u5668\u548c\u89e3\u8b6f\u5668\u4f86\u67e5\u770b\u88ab\u89c0\u5bdf\u7684\u6a23\u672c\u5230\u5e95\u8a66\u5716\u505a\u4e9b\u4ec0\u9ebc\uff0c\u9019\u5c0d\u8a31\u591a\u8cc7\u5b89\u7814\u7a76\u4eba\u54e1\u4f86\u8aaa\uff0c\u7b97\u662f\u5bb6\u5e38\u4fbf\u98ef\u3002<\/p>\n<p>\u5728<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u76e3\u63a7\u5a01\u8105\u7684\u904e\u7a0b\u7576\u4e2d\uff0c\u6709\u4e00\u500b\u60e1\u610f\u7a0b\u5f0f\u7684\u6a23\u672c (\u8da8\u52e2\u79d1\u6280\u547d\u540d\u70ba JOKE_CYBERAVI) \u89f8\u767c\u4e86\u8a31\u591a\u689d Yara \u898f\u5247\u3002\u6211\u5011\u7b2c\u4e00\u6b21\u767c\u73fe\u9019\u500b\u6a23\u672c\u7684\u6642\u9593\u662f\u5728\u5168\u7403\u6a19\u6e96\u6642\u9593 (UTC) 2017-05-11 14:33:49\u3002\u7576\u67e5\u770b\u8a72\u57f7\u884c\u6a94\u7684 PE \u6a19\u982d\u6642\uff0c\u6211\u5011\u770b\u5230\u5b83\u7684\u6642\u9593\u6233\u8a18\u662f\u5168\u7403\u6a19\u6e96\u6642\u9593 12:57:16\u3002\u63db\u53e5\u8a71\u8aaa\uff0c\u6211\u5011\u662f\u5728\u8a72\u6a94\u6848\u7522\u751f\u51fa\u4f86\u5f8c\u7684 90 \u5206\u9418\u5de6\u53f3\u5c31\u767c\u73fe\u5230\u8a72\u6a94\u6848\u3002\u5168\u90e8\u52a0\u8d77\u4f86\uff0c\u8a72\u6a94\u6848\u6211\u5011\u7e3d\u5171\u5075\u6e2c\u5230 26 \u6b21\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/05\/yara-rickroll-1.jpg\" width=\"1414\" height=\"654\" \/><\/p>\n<p><em>\u5716 1\uff1aJOKE_CYBERAVI \u6a94\u6848\u5c6c\u6027\u3002<\/em><\/p>\n<p>\u4e00\u958b\u59cb\uff0c\u8a72\u6a94\u6848\u770b\u8d77\u4f86\u9084\u883b\u6709\u8da3\u7684\uff0c\u56e0\u70ba\u5b83\u4f3c\u4e4e\u5167\u5efa\u4e86\u67d0\u4e9b\u9632\u9664\u932f\u6a5f\u5236\u3002\u9019\u985e\u6280\u5de7\u901a\u5e38\u662f\u60e1\u610f\u7a0b\u5f0f\u70ba\u4e86\u9632\u6b62\u7814\u7a76\u4eba\u54e1\u5229\u7528\u53cd\u5411\u5de5\u7a0b\u52a0\u4ee5\u7814\u7a76\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/05\/yara-rickroll-2.jpg\" width=\"1104\" height=\"272\" \/><\/p>\n<p><em>\u5716 2\uff1a\u60e1\u610f\u7a0b\u5f0f\u7684\u90e8\u5206\u7a0b\u5f0f\u78bc\u3002<\/em><\/p>\n<p>\u7576\u67e5\u770b\u8a72\u6a94\u6848\u7684 PE \u8cc7\u6e90\u6642\uff0c\u6211\u5011\u767c\u73fe\u5230\u6709\u4e9b\u5947\u602a\uff0c\u5b83\u6709\u4e09\u6bb5\u8cc7\u6e90\uff1aRT_MANIFEST\u3001CYB \u548c LOL\u3002\u6c92\u932f\uff0c\u6709\u500b\u53eb\u505a\u300cLOL\u300d(\u653e\u8072\u5927\u7b11) \u7684\u8cc7\u6e90\u3002<!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/05\/yara-rickroll-3.jpg\" width=\"764\" height=\"214\" \/><\/p>\n<p><em>\u5716 3\uff1a\u60e1\u610f\u7a0b\u5f0f\u6a23\u672c\u4e2d\u7684 PE \u8cc7\u6e90\u3002<\/em><\/p>\n<p>\u300c101\u300d\u9019\u500b\u5340\u6bb5\u5c31\u662f\u690d\u5165\u53d7\u5bb3\u7cfb\u7d71\u4e0a\u57f7\u884c\u7684\u6a94\u6848\u3002\u8ffd\u8e64\u4e00\u4e0b\u60e1\u610f\u7a0b\u5f0f\u78bc\u5c31\u53ef\u767c\u73fe\u9019\u662f\u4e00\u500b\u60e1\u610f\u7a0b\u5f0f\u6240\u64ad\u653e\u7684 .AVI \u6a94\u6848\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/05\/yara-rickroll-5.jpg\" width=\"1191\" height=\"893\" \/><\/p>\n<p><em>\u5716 4\uff1a\u60e1\u610f\u7a0b\u5f0f\u7684\u90e8\u5206\u7a0b\u5f0f\u78bc\u3002<\/em><\/p>\n<p>\u7576\u8a72\u6a94\u6848\u5728 Windows \u4e0a\u64ad\u653e\u6642\uff0c\u6211\u5011\u5f88\u96e3\u770b\u51fa\u8a72\u6a94\u7684\u5167\u5bb9\u662f\u4ec0\u9ebc\uff0c\u56e0\u70ba\u8a72\u7a0b\u5f0f\u6240\u555f\u52d5\u7684\u64ad\u653e\u5668\u4f3c\u4e4e\u9047\u5230\u4e86\u7de8\u78bc\u4e0a\u7684\u554f\u984c\u6216\u5176\u4ed6\u72c0\u6cc1\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/05\/yara-rickroll-5.jpg\" width=\"1191\" height=\"893\" \/><\/p>\n<p><em>\u5716 5\uff1a\u60e1\u610f\u7a0b\u5f0f\u6a23\u672c\u6240\u690d\u5165\u7cfb\u7d71\u7684 .AVI \u6a94\u6848\u3002<\/em><\/p>\n<p>\u7531\u65bc\u60e1\u610f\u7a0b\u5f0f\u6240\u555f\u52d5\u7684\u64ad\u653e\u5668\u7121\u6cd5\u9806\u5229\u64ad\u653e\u8a72 AVI \u6a94\u6848\uff0c\u56e0\u6b64\u6211\u5011\u5c31\u5c07\u8a72\u6a94\u6848\u76f4\u63a5\u62bd\u53d6\u51fa\u4f86\u64ad\u653e\u3002\u7d50\u679c\u7adf\u7136\u767c\u73fe\u662f Rick Astley \u7684\u6b4c\u66f2\u300c<a href=\"https:\/\/www.youtube.com\/watch?v=dQw4w9WgXcQ\">Never Gonna Give You Up<\/a>\u300d\u7684 MV\uff0c\u9019\u986f\u7136\u662f\u99ed\u5ba2\u8981\u7528\u4f86\u9a19\u4eba\u89c0\u8cde\u7684\u5f71\u7247\uff0c\u9019\u5176\u5be6\u662f\u4e00\u7a2e\u53eb\u505a\u300c<a href=\"https:\/\/en.wikipedia.org\/wiki\/Rickrolling\">RickRolling<\/a>\u300d(\u745e\u514b\u6416\u64fa) \u7684\u7db2\u8def\u60e1\u4f5c\u5287\u624b\u6cd5\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/05\/yara-rickroll-6.jpg\" width=\"1168\" height=\"976\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><em>\u5716 6\uff1a\u300cRickrolling\u300d(\u745e\u514b\u6416\u64fa) \u60e1\u4f5c\u5287\u5f71\u7247\u3002<\/em><\/p>\n<p><strong>\u56de\u5473 Rickrolling \u60e1\u4f5c\u5287\u76db\u884c\u7684\u5e74\u4ee3 <\/strong><\/p>\n<p>\u6211\u5011\u4e0d\u78ba\u5b9a\u9019\u662f\u4e0d\u662f\u60e1\u610f\u7a0b\u5f0f\u5728\u8b66\u544a\u8cc7\u5b89\u7814\u7a76\u4eba\u54e1\u96e2\u5b83\u9060\u4e00\u9ede\u3002\u6211\u5011\u66fe\u8a66\u5716\u627e\u51fa PE \u8cc7\u6e90\u7576\u4e2d\u00a0 CYB \u5340\u6bb5\u7684\u7528\u9014\u3002\u4f46\u537b\u627e\u4e0d\u5230\u4efb\u4f55\u547c\u53eb\u5230\u8a72\u5340\u6bb5\u7684\u5730\u65b9\uff0c\u56e0\u6b64\u6211\u5011\u53c8\u9032\u4e00\u6b65\u8ffd\u67e5\u4e86\u4e00\u4e0b\uff0c\u7d50\u679c\u5f88\u5feb\u5c31\u767c\u73fe\u8a72\u6a94\u6848\u7576\u4e2d\u542b\u6709\u524d\u8ff0 Yara \u898f\u5247\u5c08\u6848\u4e2d\u7684\u7d55\u5927\u90e8\u5206\u898f\u5247\uff0c\u4ee5\u53ca\u5176\u4ed6\u4e00\u4e9b\u71b1\u9580\u7684\u898f\u5247\u3002\u5176\u7528\u9014\u986f\u7136\u662f\u70ba\u4e86\u5075\u6e2c\u5927\u5bb6\u6240\u76e3\u63a7\u7684\u898f\u5247\uff0c\u5176\u4e2d\u9084\u5305\u62ec\u4e00\u4e9b\u7121\u6cd5\u5075\u6e2c\u7684 RAT \u9060\u7aef\u5b58\u53d6\u5de5\u5177\u548c Havex \u60e1\u610f\u7a0b\u5f0f\u3002<\/p>\n<p>\u6211\u5011\u8a8d\u70ba\uff0c\u9019\u6709\u53ef\u80fd\u662f\u60e1\u610f\u7a0b\u5f0f\u60f3\u8981\u5075\u6e2c\u67d0\u500b\u4f01\u696d\u6a5f\u69cb\u7528\u5230\u54ea\u4e9b Yara \u898f\u5247\uff0c\u6216\u8005\u53ea\u662f\u55ae\u7d14\u5730\u60e1\u4f5c\u5287\u3002\u4e0d\u7ba1\u662f\u54ea\u4e00\u7a2e\uff0c\u6211\u5011\u5012\u662f\u5f88\u958b\u5fc3\u80fd\u5920\u56de\u5473\u4e00\u4e0b Rickrolling \u60e1\u4f5c\u5287\u76db\u884c\u7684\u5e74\u4ee3 (2008\u5e74)\u3002<\/p>\n<p>\u5118\u7ba1\u9019\u662f\u500b\u883b\u6709\u8da3\u7684\u7df4\u7fd2\uff0c\u5076\u723e\u81ea\u5632\u4e00\u4e0b\u5012\u4e5f\u7121\u59a8\uff0c\u4e0d\u904e\u4e5f\u63d0\u9192\u6211\u5011\u5207\u52ff\u76f2\u76ee\u76f8\u4fe1\u4efb\u4f55\u71b1\u9580\u7684\u6771\u897f\u3002\u5728\u6c92\u6709\u7d93\u904e\u66f4\u7cbe\u5bc6\u7684\u6280\u5de7 (\u5982\u8da8\u52e2\u79d1\u6280 XGen&#x2122; \u9632\u8b77\u7576\u4e2d\u6240\u542b\u7684\u9810\u6e2c\u5f0f\u6a5f\u5668\u5b78\u7fd2) \u6aa2\u67e5\u4e4b\u524d\uff0c\u6700\u597d\u4e0d\u8981\u8cbf\u7136\u8655\u7406\u6216\u65b0\u589e\u60e1\u610f\u7a0b\u5f0f\u6a23\u672c\u3002<\/p>\n<p>\u4ee5\u4e0b\u662f\u672c\u6587\u76f8\u95dc\u7684\u96dc\u6e4a\u78bc\uff1a<\/p>\n<ul>\n<li><strong>SHA256: 827b2f0f5664271ab98aa00dbca85d387ce6d96234608e301007ed5a46d88001<\/strong><\/li>\n<\/ul>\n<p>\u300c\u9644\u9304 A\u300d\u986f\u793a Yara \u57f7\u884c Github \u4e0a Yara-Rules \u5c08\u6848\u4e2d\u7684\u898f\u5247\u6240\u8f38\u51fa\u7684\u7d50\u679c\u3002\u5728\u5404\u898f\u5247\u96c6\u7576\u4e2d\u81f3\u5c11\u627e\u5230 260 \u500b\u76f8\u7b26\u7684\u898f\u5247\u3002<\/p>\n<p><strong>\u9644\u9304 A\uff1a<\/strong><\/p>\n<table  class=\" table table-hover\" width=\"0\">\n<tbody>\n<tr>\n<td width=\"619\">\u898f\u5247<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">_root_040_zip_Folder_deploy<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Ajan_asp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Ajax_PHP_Command_Shell_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">ak74shell_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Antichat_Shell_v1_3_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Antichat_Socks5_Server_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Asmodeus_v0_1_pl<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">aspydrv_asp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Ayyildiz_Tim___AYT__Shell_v_2_1_Biz_html<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">aZRaiLPhp_v1_0_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">backdoor1_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">backdoorfr_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">bdcli100<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">bin_Client<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">BIN_Client<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">BIN_Server<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">binder2_binder2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">by063cli<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">by064cli<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">byshell063_ntboot_2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">c99madshell_v2_0_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Casus15_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">cgi_python_py<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">chinese_spam_echoer<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">CmdAsp_asp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">cmdjsp_jsp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">connectback2_pl<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">connector<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">createP2P<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">csh_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">cyberlords_sql_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">DarkSpy105<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">dbgiis6cli<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">dbgntboot<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Debug_cress<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">DeltaCharlie<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">DestructiveTargetCleaningTool5<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">DestructiveTargetCleaningTool6<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">DestructiveTargetCleaningTool7<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Dive_Shell_1_0___Emperor_Hacking_Team_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Dx_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">EditServer_Webshell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">EditServer_Webshell_2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">EFSO_2_asp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">elmaliseker<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">elmaliseker_asp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">FeliksPack3___PHP_Shells_phpft<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">FeliksPack3___PHP_Shells_ssh<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">FeliksPack3___PHP_Shells_usr<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">FSO_s_casus15_2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">FSO_s_phpinj<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">FSO_s_reader<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">FSO_s_zehir4<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">fuckphpshell_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">h4ntu_shell__powered_by_tsoi_<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Havex_Trojan_PHP_Server<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">HDConfig<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">hidshell_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">hkdoordll<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">hkshell_hkrmv<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">hkshell_hkshell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">HYTop_CaseSwitch_2005<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">HYTop_DevPack_server<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">HYTop_DevPack_upload<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">HYTop2006_rar_Folder_2006<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">icyfox007v1_10_rar_Folder_asp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">IndiaAlfa_One<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">IndiaBravo_generic<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">IndiaBravo_PapaAlfa<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">IndiaBravo_RomeoBravo<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">IndiaBravo_RomeoCharlie<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">IndiaCharlie_One<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">IndiaCharlie_Two<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">installer<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">ironshell_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">jsp_reverse_jsp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">jspshall_jsp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">JspWebshell_1_2_jsp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">kacak_asp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">lamashell_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Lightweight_Backdoor1<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">LightweightBackdoor2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">LightweightBackdoor3<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">LightweightBackdoor4<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">LightweightBackdoor5<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">LightweightBackdoor6<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">LimaCharlie<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">lurm_safemod_on_cgi<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Malwareusedbycyberthreatactor1<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Malwareusedbycyberthreatactor2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Malwareusedbycyberthreatactor3<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Mithril_dllTest<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Mithril_Mithril<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Mithril_v1_45_dllTest<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_php_webshells<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_webshells_0002<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_webshells_0003<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_webshells_0005<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_webshells_0010<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_webshells_0015<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_webshells_0016<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_webshells_0019<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_webshells_0022<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_webshells_0030<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">multiple_webshells_0031<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">mysql_shell_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">MySQL_Web_Interface_Version_0_8_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">ngh_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">NT_Addy_asp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">PapaAlfa<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">PasswordReminder<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Pastebin_Webshell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">perlbot_pl<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">PHANTASMA_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">PHP_Backdoor_Connect_pl_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">php_backdoor_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">PHP_Cloaked_Webshell_SuperFetchExec<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">php_include_w_shell_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">PHP_shell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">PHP_Shell_v1_7<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">pHpINJ_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">phpjackal_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">phpshell17_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">phvayvv_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">ProxyTool1<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">ProxyTool2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">ProxyTool3<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">r57shell_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">rdrbs084<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">rdrbs100<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Reader_asp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">regshell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Rem_View_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">rknt_zip_Folder_RkNT<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">RkNTLoad<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">RomeoCharlie<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">RomeoEcho<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">RomeoJuliettMikeTwo<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">rootshell_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">rst_sql_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">s72_Shell_v1_1_Coding_html<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Safe_Mode_Bypass_PHP_4_4_2_and_PHP_5_1_2_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Safe0ver_Shell__Safe_Mod_Bypass_By_Evilc0der_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">screencap<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">sendmail<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">sh_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">shankar_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">shell_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">shellbot_pl<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">shells_PHP_wso<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">shelltools_g0t_root_Fport<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">shelltools_g0t_root_HideRun<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">shelltools_g0t_root_resolve<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">shelltools_g0t_root_xwhois<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">SierraBravo_packed<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">SierraCharlie<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">sig_2008_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">SimAttacker___Vrsion_1_0_0___priv8_4_My_friend_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">simple_backdoor_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Simple_PHP_BackDooR<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">SimShell_1_0___Simorgh_Security_MGZ_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Sincap_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">small_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">sql_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">STNC_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Str_Win32_Http_API<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Str_Win32_Internet_API<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Str_Win32_Wininet_Library<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Str_Win32_Winsock2_Library<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">svchostdll<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">TangoAlfa<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">telnet_cgi<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">telnetd_pl<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">thelast_orice2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Tool_asp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Unpack_Injectt<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">vanquish<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">vanquish_2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">w3d_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell__findsock_php_findsock_shell_php_reverse_shell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_AK_74_Security_Team_Web_Shell_Beta_Version<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_asp_404<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_ASP_aspydrv<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_asp_EFSO_2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_asp_ice<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_Ayyildiz_Tim___AYT__Shell_v_2_1_Biz<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_b374k_mini_shell_php_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_b374k_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_B374kPHP_B374k<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_bypass_iisuser_p<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_caidao_shell_404<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_caidao_shell_guo<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_caidao_shell_ice_2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_CasuS_1_5<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_cihshell_fix<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_dev_core<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_Dx_Dx<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_Expdoor_com_ASP<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_GetPostpHp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_gfs_sh_r57shell_r57shell127_SnIpEr_SA_xxx<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_ghost_source_icesword_silic<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_go_shell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_h4ntu_shell__powered_by_tsoi_<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_hiddens_shell_v1<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_iMHaPFtp_2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_itsec_PHPJackal_itsecteam_shell_jHn<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_Java_Shell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_lamashell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_MySQL_Web_Interface_Version_0_8<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_PHP_b37<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_php_backdoor<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_PHP_c37<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_php_fbi<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_php_include_w_shell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_php_webshells_matamu<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_php_webshells_MyShell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_php_webshells_NGH<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_php_webshells_pHpINJ<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_phpkit_0_1a_odd<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_phpspy_2005_full_phpspy_2005_lite_phpspy_2006_PHPSPY<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_PhpSpy_Ver_2006<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_qsd_php_backdoor<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_ru24_post_sh<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_safe0ver<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_sig_404super<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_simattacker<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_SimAttacker___Vrsion_1_0_0___priv8_4_My_friend<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_simple_backdoor<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_Simple_PHP_backdoor_by_DK<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshell_cnseay_x<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshell_cnseay02_1<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshells_new_code<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshells_new_con2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshells_new_JSP<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshells_new_pHp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshells_new_PHP1<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshells_new_php2<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshells_new_php5<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshells_new_php6<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshells_new_pppp<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_webshells_new_xxxx<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_WinX_Shell<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">webshell_wsb_idc<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WebShell_zehir4_asp_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">wh_bindshell_py<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WhiskeyAlfa<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WhiskeyDelta<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Win32FertgerHavex<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">Win32OPCHavex<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">WinX_Shell_html<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">wiper_encoded_strings<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">wiper_unique_strings<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">xssshell_db<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">xssshell_save<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">zacosmall_php<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">ZXshell2_0_rar_Folder_nc<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">ZXshell2_0_rar_Folder_zxrecv<\/td>\n<\/tr>\n<tr>\n<td width=\"619\">ZXshell2_0_rar_Folder_ZXshell<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<ul>\n<li>\u539f\u6587\u51fa\u8655\uff1a <a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/yara-used-rickroll-security-researchers\/\">Yara Used to RickRoll Security Researchers<\/a> <strong>\u4f5c\u8005\uff1a<\/strong><a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/author\/shilt\/\">Stephen Hilt (\u8cc7\u6df1\u5a01\u8105\u7814\u7a76\u54e1)<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/t.rend.tw\/?i=Mzc4NQ\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/08\/Windows10Banner-540x90v5.gif\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p style=\"font-size: 8pt;\">\u300a \u60f3\u4e86\u89e3\u66f4\u591a\u95dc\u65bc\u7db2\u8def\u5b89\u5168\u7684\u79d8\u8a23\u548c\u5efa\u8b70\uff0c\u53ea\u8981\u5230<a href=\"https:\/\/www.facebook.com\/trendmicrotaiwan\">\u8da8\u52e2\u79d1\u6280\u7c89\u7d72\u7db2\u9801<\/a> \u6216\u4e0b\u9762\u7684\u6309\u9215\u6309\u8b9a \u300b<\/p>\n<p><iframe loading=\"lazy\" style=\"border: none; overflow: hidden; width: 350px; height: 62px;\" src=\"https:\/\/www.facebook.com\/plugins\/likebox.php?id=255176705131&amp;width=350&amp;connections=0&amp;stream=false&amp;header=false&amp;height=62\" width=\"300\" height=\"150\" frameborder=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p style=\"font-size: 8pt;\"><b><\/b>\u300a\u63d0\u9192\u300b\u5c07\u6ed1\u9f20\u6e38\u6a19\u79fb\u52d5\u5230\u7c89\u7d72\u9801\u53f3\u4e0a\u65b9\u7684<strong>\u300c\u5df2\u8aaa\u8b9a\u300d<\/strong>\u6b04\u4f4d\uff0c\u52fe\u9078<strong>\u300c\u6436\u5148\u770b\u300d<\/strong>\u9078\u9805<strong>,<\/strong>\u6700\u65b0\u8cbc\u6587\u5c31\u6703\u512a\u5148\u986f\u793a\u5728\u52d5\u614b\u6d88\u606f\u9802\u7aef\uff0c\u8b93\u4f60\u4e0d\u6703\u932f\u904e\u4efb\u4f55\u66f4\u65b0\u3002<\/p>\n<p>*\u624b\u6a5f\u7248\u76f4\u63a5\u524d\u5f80\u5c08\u9801\u9996\u9801\uff0c\u4e0b\u62c9\u8ffd\u8e64\u4e2d\uff0c\u5c31\u80fd\u5c07\u7c89\u7d72\u5c08\u9801\u8a2d\u5b9a\u6436\u5148\u770b\u3002<\/p>\n<p>&nbsp;<\/p>\n<p style=\"font-size: 8pt;\">\u25bc \u6b61\u8fce\u52a0\u5165\u8da8\u52e2\u79d1\u6280\u793e\u7fa4\u7db2\u7ad9\u25bc<\/p>\n<p>&nbsp;<\/p>\n<p><strong><a href=\"https:\/\/line.me\/ti\/p\/%40fgt4590r\"><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/biz.line.naver.jp\/line_business\/img\/btn\/addfriends_zh-Hant.png\" alt=\"\u597d\u53cb\u4eba\u6578\" width=\"89\" height=\"30\" border=\"0\" \/><\/a> <\/strong><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2762&amp;name=20111213\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/08\/eNews_images_2015_0161.gif\" alt=\"\" \/><\/a> <a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2764&amp;name=20111213\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/08\/eNews_images_2015_0171.gif\" alt=\"\" \/><\/a> <a href=\"https:\/\/www.trendmicro.tw\/tw\/\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/08\/eNews_images_2015_0131.gif\" alt=\"\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5c0d\u7d55\u5927\u591a\u6578\u8cc7\u5b89\u7814\u7a76\u4eba\u54e1\u4f86\u8aaa\uff0cYara \u662f\u4e00\u500b\u975e\u5e38\u5bf6\u8cb4\u7684\u60e1\u610f\u8edf\u9ad4\u8b58\u5225\u5de5\u5177\uff0c\u5b83\u53ef\u5efa\u7acb\u4e00\u4e9b\u898f\u5247\u4f86\u8ffd\u8e64\u60e1\u610f\u7a0b\u5f0f\uff0c\u8b93\u8a31\u591a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[3347,4126],"tags":[2908,1380,1283,2068],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/50734"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=50734"}],"version-history":[{"count":0,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/50734\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=50734"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=50734"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=50734"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}