{"id":73300,"date":"2022-07-12T09:00:00","date_gmt":"2022-07-12T01:00:00","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=73300"},"modified":"2022-07-11T11:10:26","modified_gmt":"2022-07-11T03:10:26","slug":"%e6%96%b0%e7%9a%84-havanacrypt-%e5%8b%92%e7%b4%a2%e7%97%85%e6%af%92%e5%81%87%e6%89%ae%e6%88%90-google-software-update-%e6%87%89%e7%94%a8%e7%a8%8b%e5%bc%8f%ef%bc%8c%e4%bd%bf%e7%94%a8-microsoft","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=73300","title":{"rendered":"\u65b0\u7684 HavanaCrypt \u52d2\u7d22\u75c5\u6bd2\u5047\u626e\u6210 Google Software Update \u61c9\u7528\u7a0b\u5f0f\uff0c\u4f7f\u7528 Microsoft \u4ee3\u7ba1\u670d\u52d9 IP \u4f4d\u5740\u4f5c\u70ba C&#038;C \u4f3a\u670d\u5668"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\"><\/h1>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u6700\u8fd1<a href=\"https:\/\/t.rend.tw\/?i=OTQzMw\">\u8da8\u52e2\u79d1\u6280<\/a>\u767c\u73fe\u4e00\u500b\u65b0\u7684<a href=\"\u52d2\u7d22\u75c5\u6bd2%20Ransomware\">\u52d2\u7d22\u75c5\u6bd2 Ransomware<\/a>\u5bb6\u65cf (\u8da8\u52e2\u79d1\u6280\u547d\u540d\u70ba\u300cHavanaCrypt\u300d)\uff0c\u5b83\u6703\u5047\u626e\u6210\u4e00\u500b Google Software Update \u61c9\u7528\u7a0b\u5f0f\uff0c\u4e26\u4f7f\u7528 Microsoft \u7db2\u7ad9\u4ee3\u7ba1\u670d\u52d9\u7684 IP \u4f4d\u5740\u4f5c\u70ba\u5176\u5e55\u5f8c\u64cd\u7e31 (C&amp;C) \u4f3a\u670d\u5668\u4f86\u8eb2\u907f\u5075\u6e2c\u3002<\/p><\/blockquote>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/06\/ransom-4.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"660\" height=\"280\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/06\/ransom-4.jpg\" alt=\"\" class=\"wp-image-50585\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/06\/ransom-4.jpg 660w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/06\/ransom-4-300x127.jpg 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/06\/ransom-4-600x255.jpg 600w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/06\/ransom-4-30x13.jpg 30w\" sizes=\"(max-width: 660px) 100vw, 660px\" \/><\/a><\/figure>\n\n\n\n<p><a href=\"http:\/\/blog.trendmicro.com.tw\/?p=12412\">\u52d2\u7d22\u75c5\u6bd2<\/a>\u96d6\u7136\u4e0d\u662f\u4ec0\u9ebc\u65b0\u7684\u767c\u660e\uff0c\u4f46\u81f3\u4eca\u4ecd\u662f\u5168\u4e16\u754c\u6700\u56b4\u91cd\u7684\u7db2\u8def\u8cc7\u5b89\u5a01\u8105\u4e4b\u4e00\u3002\u4e8b\u5be6\u4e0a\uff0c\u6839\u64da\u8da8\u52e2\u79d1\u6280 Smart Protection Network&#x2122; \u5168\u7403\u5a01\u8105\u60c5\u5831\u7db2\u7684\u8cc7\u6599\uff0c2022 \u5e74\u7b2c 1 \u5b63\uff0c\u6211\u5011\u5728\u96fb\u5b50\u90f5\u4ef6\u3001\u7db2\u5740\u8207\u6a94\u6848\u4e09\u500b\u9632\u8b77\u5c64\u4e0a\u7e3d\u5171\u5075\u6e2c\u4e26\u6514\u622a\u4e86&nbsp;<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-by-the-numbers\/lockbit-conti-and-blackcat-lead-pack-amid-rise-in-active-raas-and-extortion-groups-ransomware-in-q1-2022\">\u8d85\u904e 440 \u842c\u6b21\u52d2\u7d22\u75c5\u6bd2\u5a01\u8105<\/a>\uff0c\u8f03 2021 \u5e74\u7b2c 4 \u5b63\u6574\u9ad4\u52d2\u7d22\u75c5\u6bd2\u5a01\u8105\u6578\u91cf\u6210\u9577 37%\u3002<\/p>\n\n\n\n<p>\u52d2\u7d22\u75c5\u6bd2\u4e4b\u6240\u4ee5\u6703\u5982\u6b64\u7316\u7357\uff0c\u4e3b\u8981\u539f\u56e0\u5c31\u5728\u65bc\u5b83\u6703\u4e0d\u65b7\u6f14\u8b8a\u3002\u5b83\u6703\u96a8\u6642\u8b8a\u63db\u624b\u6cd5\u8207\u4f0e\u5006\u4f86\u8a98\u9a19\u4e0d\u77e5\u60c5\u53d7\u5bb3\u8005\u4ee5\u5165\u4fb5\u4f01\u696d\u74b0\u5883\u3002\u4f8b\u5982\u4eca\u5e74\uff0c\u6211\u5011\u770b\u5230\u4e00\u4e9b\u52d2\u7d22\u75c5\u6bd2\u5047\u626e\u6210<a href=\"https:\/\/www.techradar.com\/news\/these-fake-windows-10-updates-will-land-you-with-a-ransomware-infection\">Windows 10<\/a>\u3001<a href=\"https:\/\/tech.co\/news\/fake-chrome-microsoft-edge-update-ransomware\">Google Chrome \u53ca Microsoft Exchange \u66f4\u65b0<\/a>\u4f86\u8a98\u9a19\u4e0d\u77e5\u60c5\u53d7\u5bb3\u8005\u4e0b\u8f09\u60e1\u610f\u6a94\u6848\u3002<\/p>\n\n\n\n<p>\u6700\u8fd1\u6211\u5011\u767c\u73fe\u4e00\u500b\u65b0\u7684\u52d2\u7d22\u75c5\u6bd2\u5bb6\u65cf\u540c\u6a23\u4e5f\u662f\u4f7f\u7528\u985e\u4f3c\u4f0e\u5006\uff0c\u5b83\u6703\u5047\u626e\u6210\u4e00\u500b Google Software Update \u61c9\u7528\u7a0b\u5f0f\uff0c\u4e26\u4f7f\u7528 Microsoft \u7db2\u7ad9\u4ee3\u7ba1\u670d\u52d9\u7684 IP \u4f4d\u5740\u4f5c\u70ba\u5176\u5e55\u5f8c\u64cd\u7e31 (C&amp;C) \u4f3a\u670d\u5668\u4f86\u8eb2\u907f\u5075\u6e2c\u3002\u6839\u64da\u6211\u5011\u7684\u7814\u7a76\u986f\u793a\uff0c\u9019\u500b\u52d2\u7d22\u75c5\u6bd2\u6703\u5728\u5176\u52a0\u5bc6\u904e\u7a0b\u4e2d\u4f7f\u7528 .NET System.Threading \u547d\u540d\u7a7a\u9593\u4e2d\u7528\u4f86\u5c07\u5de5\u4f5c\u6392\u5165\u57f7\u884c\u4f47\u5217\u7684 <a href=\"https:\/\/docs.microsoft.com\/en-us\/dotnet\/api\/system.threading.threadpool.queueuserworkitem?view=net-6.0#system-threading-threadpool-queueuserworkitem(system-threading-waitcallback)\">QueueUserWorkItem<\/a>&nbsp; \u51fd\u5f0f\uff0c\u4ee5\u53ca\u958b\u653e\u539f\u59cb\u78bc\u5bc6\u78bc\u7ba1\u7406\u8edf\u9ad4 <a href=\"https:\/\/keepass.info\/\">KeePass Password Safe<\/a> \u7684\u6a21\u7d44\u3002<\/p>\n\n\n\n<p>\u672c\u6587\u5c07\u5f9e\u6280\u8853\u9762\u6df1\u5165\u5206\u6790\u9019\u500b\u6211\u5011\u547d\u540d\u70ba\u300cHavanaCrypt\u300d\u7684\u6700\u65b0\u52d2\u7d22\u75c5\u6bd2\u5bb6\u65cf\u8207\u5176\u611f\u67d3\u6280\u5de7\u3002<\/p>\n\n\n\n<!--more-->\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h1 class=\"wp-block-heading\">\u9032\u5165\u7cfb\u7d71<\/h1>\n\n\n\n<p><br>HavanaCrypt \u6703\u5047\u626e\u6210 Google Software Update \u61c9\u7528\u7a0b\u5f0f\u4f86\u9032\u5165\u7cfb\u7d71\u3002<\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-28.png\"><img loading=\"lazy\" decoding=\"async\" width=\"327\" height=\"241\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-28.png\" alt=\"\" class=\"wp-image-73301\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-28.png 327w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-28-300x221.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-28-30x22.png 30w\" sizes=\"(max-width: 327px) 100vw, 327px\" \/><\/a><figcaption>\u5716 1\uff1aHavanaCrypt \u57f7\u884c\u6a94\u8a73\u7d30\u8cc7\u8a0a\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u6b64\u60e1\u610f\u7a0b\u5f0f\u662f\u4e00\u500b\u4f7f\u7528 .NET \u7d44\u8b6f\u7684\u61c9\u7528\u7a0b\u5f0f\uff0c\u4e26\u4f7f\u7528\u958b\u653e\u539f\u59cb\u78bc .NET \u52a0\u5bc6\u7de8\u78bc\u8edf\u9ad4 <a href=\"https:\/\/github.com\/obfuscar\/obfuscar\">Obfuscar<\/a> \u4f86\u4fdd\u8b77\u5176 .NET assembly \u4e2d\u7684\u7a0b\u5f0f\u78bc\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-29.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"637\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-29-1024x637.png\" alt=\"\" class=\"wp-image-73302\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-29-1024x637.png 1024w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-29-300x187.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-29-768x478.png 768w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-29-30x19.png 30w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-29.png 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption>\u5716 2\uff1a\u4f7f\u7528 Detect It Easy \u5de5\u5177\u6240\u770b\u5230\u7684 HavanaCrypt \u57f7\u884c\u6a94\u5c6c\u6027\u8cc7\u6599 (\u8a72\u5de5\u5177\u53ef\u7528\u4f86\u67e5\u770b\u6a94\u6848\u7684\u985e\u578b)\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u6b64\u5916\uff0c\u9019\u500b\u60e1\u610f\u7a0b\u5f0f\u9084\u5177\u5099\u591a\u7a2e\u53cd\u5236\u865b\u64ec\u74b0\u5883\u7684\u6280\u5de7\uff0c\u85c9\u6b64\u9632\u6b62\u7814\u7a76\u4eba\u54e1\u5728\u865b\u64ec\u74b0\u5883\u7576\u4e2d\u5c0d\u5b83\u9032\u884c\u5206\u6790\u3002\u70ba\u4e86\u5206\u6790\u9019\u500b\u6a23\u672c\u4e26\u89e3\u958b\u5176\u7a0b\u5f0f\u78bc\uff0c\u6211\u5011\u4f7f\u7528\u4e86 <a href=\"https:\/\/github.com\/de4dot\/de4dot\">de4dot<\/a> \u548c <a href=\"https:\/\/github.com\/DarkObb\/DeObfuscar-Static\">DeObfuscar<\/a> \u9019\u985e\u5de5\u5177\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-30.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"180\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-30.png\" alt=\"\" class=\"wp-image-73303\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-30.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-30-300x150.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-30-30x15.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 3\uff1aHavanaCrypt \u52d2\u7d22\u75c5\u6bd2\u539f\u672c\u7d93\u904e\u52a0\u5bc6\u7de8\u78bc\u7684\u7a0b\u5f0f\u78bc\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-31.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"143\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-31.png\" alt=\"\" class=\"wp-image-73304\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-31.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-31-300x119.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-31-30x12.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 4\uff1aHavanaCrypt \u52d2\u7d22\u75c5\u6bd2\u89e3\u958b\u5f8c\u7684\u7a0b\u5f0f\u78bc\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>\u5728\u57f7\u884c\u6642\uff0cHavanaCrypt \u6703\u4f7f\u7528 ShowWindow \u51fd\u5f0f\u4e26\u50b3\u5165 0 (SW_HIDE) \u4f5c\u70ba\u53c3\u6578\u4f86\u96b1\u85cf\u5b83\u7684\u8996\u7a97\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-32.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"152\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-32.png\" alt=\"\" class=\"wp-image-73305\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-32.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-32-300x127.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-32-30x13.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 5\uff1aHavanaCrypt \u4f7f\u7528 ShowWindow \u51fd\u5f0f\u4f86\u96b1\u85cf\u5176\u8996\u7a97\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u63a5\u8457\uff0cHavanaCrypt \u6703\u6aa2\u67e5\u7cfb\u7d71\u767b\u9304\u7684 AutoRun \u6a5f\u78bc\uff0c\u770b\u770b\u300cGoogleUpdate\u300d\u9019\u500b\u6a5f\u78bc\u662f\u5426\u5b58\u5728\u3002\u5982\u679c\u4e0d\u5b58\u5728\uff0c\u5c31\u7e7c\u7e8c\u57f7\u884c\u5176\u60e1\u610f\u884c\u70ba\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-33.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"152\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-33.png\" alt=\"\" class=\"wp-image-73306\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-33.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-33-300x127.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-33-30x13.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 6\uff1aHavanaCrypt \u7528\u4f86\u6aa2\u67e5\u7cfb\u7d71\u767b\u9304\u6a5f\u78bc\u7684\u51fd\u5f0f\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u63a5\u8457\uff0c\u5b83\u6703\u6aa2\u67e5\u81ea\u5df1\u662f\u5426\u5728\u865b\u64ec\u74b0\u5883\u4e2d\u57f7\u884c\uff0c\u5982\u679c\u662f\uff0c\u5c31\u6703\u7d42\u6b62\u57f7\u884c\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h1 class=\"wp-block-heading\">\u865b\u64ec\u74b0\u5883\u53cd\u5236<\/h1>\n\n\n\n<p><br>HavanaCrypt \u6703\u5c0d\u53d7\u5bb3\u7cfb\u7d71\u9032\u884c\u56db\u9805\u6aa2\u67e5\u4f86\u770b\u770b\u5b83\u662f\u5426\u70ba\u4e00\u53f0\u865b\u64ec\u6a5f\u5668\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-34.png\"><img loading=\"lazy\" decoding=\"async\" width=\"468\" height=\"154\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-34.png\" alt=\"\" class=\"wp-image-73307\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-34.png 468w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-34-300x99.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-34-30x10.png 30w\" sizes=\"(max-width: 468px) 100vw, 468px\" \/><\/a><figcaption><br>\u5716 7\uff1aHavanaCrypt \u7528\u4f86\u53cd\u5236\u865b\u64ec\u74b0\u5883\u7684\u51fd\u5f0f\u3002<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-35.png\"><img loading=\"lazy\" decoding=\"async\" width=\"828\" height=\"1024\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-35-828x1024.png\" alt=\"\" class=\"wp-image-73308\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-35-828x1024.png 828w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-35-242x300.png 242w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-35-768x950.png 768w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-35-24x30.png 24w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-35.png 889w\" sizes=\"(max-width: 828px) 100vw, 828px\" \/><\/a><figcaption>\u5716 8\uff1aHavanaCrypt \u5b8c\u6574\u7684\u865b\u64ec\u74b0\u5883\u53cd\u5236\u7a0b\u5f0f\u78bc\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>\u7b2c\u4e00\uff0c\u5b83\u6703\u6aa2\u67e5\u865b\u64ec\u6a5f\u5668\u6240\u4f7f\u7528\u7684\u4e00\u4e9b\u670d\u52d9\u662f\u5426\u5b58\u5728\uff0c\u4f8b\u5982\uff1a<a href=\"https:\/\/docs.vmware.com\/en\/VMware-Tools\/12.0.0\/com.vmware.vsphere.vmwaretools.doc\/GUID-28C39A00-743B-4222-B697-6632E94A8E72.html\">VMWare Tools<\/a> \u548c <a href=\"https:\/\/docs.oracle.com\/cd\/E88353_01\/html\/E37851\/vmmouse-4.html\">vmmouse<\/a>\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-36.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"192\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-36.png\" alt=\"\" class=\"wp-image-73309\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-36.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-36-300x160.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-36-30x16.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 9\uff1aHavanaCrypt \u6703\u6aa2\u67e5\u7684\u670d\u52d9\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u7b2c\u4e8c\uff0c\u5b83\u6703\u6aa2\u67e5\u4e00\u4e9b\u865b\u64ec\u6a5f\u5668\u5e38\u6709\u7684\u6a94\u6848\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-37.png\"><img loading=\"lazy\" decoding=\"async\" width=\"297\" height=\"360\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-37.png\" alt=\"\" class=\"wp-image-73310\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-37.png 297w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-37-248x300.png 248w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-37-25x30.png 25w\" sizes=\"(max-width: 297px) 100vw, 297px\" \/><\/a><figcaption>\u5716 10\uff1aHavanaCrypt \u6703\u6aa2\u67e5\u865b\u64ec\u6a5f\u5668\u76f8\u95dc\u7684\u6a94\u6848\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>\u7b2c\u4e09\uff0c\u5b83\u6703\u6aa2\u67e5\u865b\u64ec\u6a5f\u5668\u4f7f\u7528\u7684\u57f7\u884c\u6a94\u540d\u7a31\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-38.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"126\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-38.png\" alt=\"\" class=\"wp-image-73311\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-38.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-38-300x105.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-38-30x11.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 11\uff1aHavanaCrypt \u6703\u6aa2\u67e5\u865b\u64ec\u6a5f\u5668\u7684\u57f7\u884c\u6a94\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u6700\u5f8c\uff0c\u5b83\u6703\u6aa2\u67e5\u96fb\u8166\u7684\u7db2\u8def\u5361 (MAC) \u4f4d\u5740\uff0c\u6838\u5c0d\u5b83\u7684\u524d\u5c0e\u5b57\u5143 (prefix)\uff0c\u4e5f\u5c31\u662f\u6a5f\u69cb\u8b58\u5225\u78bc (OUI ) \u662f\u5426\u5c6c\u65bc\u4e00\u4e9b\u5e38\u898b\u7684\u865b\u64ec\u6a5f\u5668\u6240\u6709\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-39.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"107\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-39.png\" alt=\"\" class=\"wp-image-73312\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-39.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-39-300x89.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-39-30x9.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 12\uff1aHavanaCrypt \u6703\u6aa2\u67e5\u6a5f\u69cb\u8b58\u5225\u78bc (OUI)\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-table\"><table  class=\" table table-hover\" ><tbody><tr><td>\u7bc4\u570d\u6216\u524d\u5c0e\u5b57\u5143<\/td><td>\u7522\u54c1<\/td><\/tr><tr><td>00:05:69<\/td><td>VMware ESX \u548c VMware GSX Server<\/td><\/tr><tr><td>00:0C:29<\/td><td>\u7368\u7acb\u7684 VMware vSphere\u3001VMware Workstation \u53ca VMware Horizon<\/td><\/tr><tr><td>00:1C:14<\/td><td>VMWare<\/td><\/tr><tr><td>00:50:56<\/td><td>VMware vSphere\u3001VMware Workstation \u548c VMware ESX Server<\/td><\/tr><tr><td>08:00:27<\/td><td>Oracle VirtualBox 5.2<\/td><\/tr><\/tbody><\/table><figcaption>\u8868 1\uff1a\u865b\u64ec\u6a5f\u5668\u7684 OUI \u7bc4\u570d\u6216\u524d\u5c0e\u5b57\u5143\u3002<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>\u5728\u78ba\u5b9a\u53d7\u5bb3\u7684\u96fb\u8166\u4e0d\u662f\u4e00\u53f0\u865b\u64ec\u6a5f\u5668\u4e4b\u5f8c\uff0cHavanaCrypt \u63a5\u8457\u6703\u5f9e 20[.]227[.]128[.]33 \u9019\u500b IP \u4f4d\u5740\u4e0b\u8f09\u4e00\u500b\u540d\u70ba\u300c2.txt\u300d\u7684\u6a94\u6848 (\u6b64\u4f4d\u5740\u662f\u4e00\u500b Microsoft \u7db2\u7ad9\u4ee3\u7ba1\u670d\u52d9\u7684 IP \u4f4d\u5740)\uff0c\u7136\u5f8c\u5c07\u6a94\u6848\u5132\u5b58\u6210\u6279\u6b21\u6a94 (.bat)\uff0c\u6a94\u540d\u7531 20 \u5230 25 \u500b\u96a8\u6a5f\u5b57\u5143\u7d44\u6210\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-40.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"271\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-40.png\" alt=\"\" class=\"wp-image-73313\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-40.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-40-300x226.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-40-30x23.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 13\uff1aMicrosoft \u7db2\u7ad9\u4ee3\u7ba1\u670d\u52d9 IP \u4f4d\u5740\u8a73\u7d30\u5167\u5bb9\u3002<br>(\u5716\u7247\u4f86\u6e90\uff1a\u00a0<a href=\"http:\/\/www.abuseipdb\/\">AbuseIPDB<\/a>)<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>\u63a5\u8457\uff0c\u5b83\u6703\u4f7f\u7528\u300c\u547d\u4ee4\u63d0\u793a\u5b57\u5143\u300d(cmd.exe) \u4f86\u57f7\u884c\u9019\u500b\u6279\u6b21\u6a94\uff0c\u4e26\u50b3\u5165\u300c\/c start\u300d\u4f5c\u70ba\u53c3\u6578\u3002\u6279\u6b21\u6a94\u4e2d\u5305\u542b\u4e00\u4e9b\u8a2d\u5b9a Windows Defender \u6383\u63cf\u504f\u597d\u7684\u6307\u4ee4\uff0c\u8b93\u5b83\u5141\u8a31\u4efb\u4f55\u5728\u300c%Windows%\u300d\u548c\u300c%User%\u300d\u76ee\u9304\u4e2d\u5075\u6e2c\u5230\u7684\u5a01\u8105\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-41.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"106\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-41.png\" alt=\"\" class=\"wp-image-73314\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-41.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-41-300x88.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-41-30x9.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 14\uff1a\u8ca0\u8cac\u4e0b\u8f09\u4e26\u57f7\u884c\u6279\u6b21\u6a94\u7684\u51fd\u5f0f\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-42.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"77\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-42.png\" alt=\"\" class=\"wp-image-73315\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-42.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-42-300x64.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-42-30x6.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 15\uff1a\u4f4d\u65bc Microsoft \u7db2\u7ad9\u4ee3\u7ba1\u670d\u52d9 IP \u4f4d\u5740\u7684 Base64 \u7de8\u78bc\u300c2.txt\u300d\u6a94\u6848\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-43.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"144\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-43.png\" alt=\"\" class=\"wp-image-73316\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-43.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-43-300x120.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-43-30x12.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 16\uff1a\u5f9e Microsoft \u7db2\u7ad9\u4ee3\u7ba1\u670d\u52d9 IP \u4f4d\u5740\u4e0b\u8f09\u4e26\u5df2\u89e3\u78bc\u7684\u6279\u6b21\u6a94\u6848\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u9664\u6b64\u4e4b\u5916\uff0cHavanaCrypt \u9084\u6703\u7d42\u6b62\u53d7\u5bb3\u96fb\u8166\u4e0a\u67d0\u4e9b\u57f7\u884c\u4e2d\u7684\u8655\u7406\u7a0b\u5e8f\uff1a<\/p>\n\n\n\n<ul><li><strong>agntsvc<\/strong><\/li><li><strong>axlbridge<\/strong><\/li><li><strong>ccevtmgr<\/strong><\/li><li><strong>ccsetmgr<\/strong><\/li><li><strong>contoso1<\/strong><\/li><li><strong>culserver<\/strong><\/li><li><strong>culture<\/strong><\/li><li><strong>dbeng50<\/strong><\/li><li><strong>dbeng8<\/strong><\/li><li><strong>dbsnmp<\/strong><\/li><li><strong>dbsrv12<\/strong><\/li><li><strong>defwatch<\/strong><\/li><li><strong>encsvc<\/strong><\/li><li><strong>excel<\/strong><\/li><li><strong>fdlauncher<\/strong><\/li><li><strong>firefoxconfig<\/strong><\/li><li><strong>httpd<\/strong><\/li><li><strong>infopath<\/strong><\/li><li><strong>isqlplussvc<\/strong><\/li><li><strong>msaccess<\/strong><\/li><li><strong>msdtc<\/strong><\/li><li><strong>msdtsrvr<\/strong><\/li><li><strong>msftesql<\/strong><\/li><li><strong>msmdsrv<\/strong><\/li><li><strong>mspub<\/strong><\/li><li><strong>mssql<\/strong><\/li><li><strong>mssqlserver<\/strong><\/li><li><strong>mydesktopqos<\/strong><\/li><li><strong>mydesktopservice<\/strong><\/li><li><strong>mysqld<\/strong><\/li><li><strong>mysqld-nt<\/strong><\/li><li><strong>mysqld-opt<\/strong><\/li><li><strong>ocautoupds<\/strong><\/li><li><strong>ocomm<\/strong><\/li><li><strong>ocssd<\/strong><\/li><li><strong>onenote<\/strong><\/li><li><strong>oracle<\/strong><\/li><li><strong>outlook<\/strong><\/li><li><strong>powerpnt<\/strong><\/li><li><strong>qbcfmonitorservice<\/strong><\/li><li><strong>qbdbmgr<\/strong><\/li><li><strong>qbidpservice<\/strong><\/li><li><strong>qbupdate<\/strong><\/li><li><strong>qbw32<\/strong><\/li><li><strong>quickboooks.fcs<\/strong><\/li><li><strong>ragui<\/strong><\/li><li><strong>rtvscan<\/strong><\/li><li><strong>savroam<\/strong><\/li><li><strong>sqbcoreservice<\/strong><\/li><li><strong>sqladhlp<\/strong><\/li><li><strong>sqlagent<\/strong><\/li><li><strong>sqlbrowser<\/strong><\/li><li><strong>sqlserv<\/strong><\/li><li><strong>sqlserveragent<\/strong><\/li><li><strong>sqlservr<\/strong><\/li><li><strong>sqlwriter<\/strong><\/li><li><strong>steam<\/strong><\/li><li><strong>supervise<\/strong><\/li><li><strong>synctime<\/strong><\/li><li><strong>tbirdconfig<\/strong><\/li><li><strong>thebat<\/strong><\/li><li><strong>thebat64<\/strong><\/li><li><strong>thunderbird<\/strong><\/li><li><strong>tomcat6<\/strong><\/li><li><strong>vds<\/strong><\/li><li><strong>visio<\/strong><\/li><li><strong>vmware-converter<\/strong><strong><\/strong><\/li><li><strong>vmware-usbarbitator64<\/strong><strong><\/strong><\/li><li><strong>winword<\/strong><\/li><li><strong>word<\/strong><\/li><li><strong>wordpad<\/strong><\/li><li><strong>wrapper<\/strong><\/li><li><strong>wxserver<\/strong><\/li><li><strong>wxserverview<\/strong><\/li><li><strong>xfssvccon<\/strong><\/li><li><strong>zhudongfangyu<\/strong><\/li><li><strong>zhundongfangyu<\/strong><\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-44.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"166\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-44.png\" alt=\"\" class=\"wp-image-73317\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-44.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-44-300x138.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-44-30x14.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 17\uff1aHavanaCrypt \u6703\u7d42\u6b62\u7684\u8655\u7406\u7a0b\u5e8f\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u503c\u5f97\u6ce8\u610f\u7684\u662f\uff0c\u4e0a\u5217\u6e05\u55ae\u7576\u4e2d\u5305\u542b\u4e86\u67d0\u4e9b\u8cc7\u6599\u5eab\u61c9\u7528\u7a0b\u5f0f\u7684\u8655\u7406\u7a0b\u5e8f\uff0c\u5982\uff1aMicrosoft SQL Server \u548c MySQL\u3002\u9084\u6709\u4e00\u4e9b\u684c\u9762\u61c9\u7528\u7a0b\u5f0f\uff0c\u5982 Microsoft Office \u548c Steam \u4e5f\u6703\u88ab\u7d42\u6b62\u3002<\/p>\n\n\n\n<p>\u7576\u9019\u4e9b\u8655\u7406\u7a0b\u5e8f\u90fd\u7d42\u6b62\u4e4b\u5f8c\uff0cHavanaCrypt \u6703\u6aa2\u67e5\u7cfb\u7d71\u4e0a\u7684\u6240\u6709\u78c1\u789f\uff0c\u522a\u9664\u6240\u6709\u7cfb\u7d71\u5099\u4efd\uff0c\u4e26\u5c07\u5176\u6700\u5927\u5132\u5b58\u7a7a\u9593\u8abf\u6574\u6210 401 MB\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-45.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"194\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-45.png\" alt=\"\" class=\"wp-image-73318\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-45.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-45-300x162.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-45-30x16.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 18\uff1aHavanaCrypt \u6703\u522a\u9664\u7cfb\u7d71\u5099\u4efd\uff0c\u4e26\u5c07\u5176\u6700\u5927\u5132\u5b58\u7a7a\u9593\u8abf\u6574\u6210 401 MB\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>\u6b64\u5916\u4e5f\u6703\u900f\u904e Windows Management Instrumentation (WMI) \u4f86\u6aa2\u67e5\u7cfb\u7d71\u9084\u539f\u9ede\uff0c\u4e26\u4f7f\u7528 SRRemoveRestorePoint \u4f86\u5c07\u5b83\u5011\u522a\u9664\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-46.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"58\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-46.png\" alt=\"\" class=\"wp-image-73319\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-46.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-46-300x48.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-46-30x5.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption><br>\u5716 19\uff1aHavanaCrypt \u6703\u900f\u904e WMI \u522a\u9664\u7cfb\u7d71\u9084\u539f\u9ede\u3002<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>\u63a5\u8457\uff0c\u5b83\u6703\u5c07\u81ea\u5df1\u8907\u88fd\u5230\u300c%ProgramData%\u300d\u548c\u300c%StartUp%\u300d\u8cc7\u6599\u593e\uff0c\u4e26\u4e14\u66f4\u540d\u70ba .exe \u6a94\u6848\uff0c\u6a94\u540d\u70ba 10 \u5230 15 \u500b\u96a8\u6a5f\u5b57\u5143\u3002\u4e26\u5c07\u6a94\u6848\u5c6c\u6027\u8a2d\u70ba\u300c\u96b1\u85cf\u300d\u548c\u300c\u7cfb\u7d71\u6a94\u6848\u300d\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-47.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"88\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-47.png\" alt=\"\" class=\"wp-image-73320\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-47.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-47-300x73.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-47-30x7.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption><br>\u5716 20\uff1aHavanaCrypt \u5c07\u81ea\u5df1\u8907\u88fd\u5230\u300c%ProgramData%\u300d\u548c\u300c%StartUp%\u300d\u8cc7\u6599\u593e\u3002<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-48.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"110\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-48.png\" alt=\"\" class=\"wp-image-73321\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-48.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-48-300x92.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-48-30x9.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 21\uff1aHavanaCrypt \u5c07\u6a94\u6848\u5c6c\u6027\u8a2d\u70ba\u300c\u96b1\u85cf\u300d\u548c\u300c\u7cfb\u7d71\u6a94\u6848\u300d\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>\u540c\u6642\uff0cHavanaCrypt \u4e5f\u6703\u5728\u300c%User Startup%\u300d\u8cc7\u6599\u593e\u4e2d\u690d\u5165\u4e00\u500b\u540d\u70ba\u300cvallo.bat\u300d\u7684\u6a94\u6848\uff0c\u88e1\u9762\u5305\u542b\u4e00\u4e9b\u7528\u4f86\u505c\u7528\u300c\u5de5\u4f5c\u7ba1\u7406\u54e1\u300d\u7684\u51fd\u5f0f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-49.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"85\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-49.png\" alt=\"\" class=\"wp-image-73322\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-49.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-49-300x71.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-49-30x7.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 22\uff1aHavanaCrypt \u5728\u300c%User Startup%\u300d\u8cc7\u6599\u593e\u4e2d\u690d\u5165\u300cvallo.bat\u300d\u6a94\u6848\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-50.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"35\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-50.png\" alt=\"\" class=\"wp-image-73323\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-50.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-50-300x29.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-50-30x3.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption><br>\u5716 23\uff1avallo.bat \u6a94\u6848\u7684\u5167\u5bb9\u3002<\/figcaption><\/figure>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h1 class=\"wp-block-heading\">\u8490\u96c6\u96fb\u8166\u8cc7\u8a0a<\/h1>\n\n\n\n<p>HavanaCrypt \u4f7f\u7528 QueueUserWorkItem \u51fd\u5f0f\u4f86\u5c07\u67d0\u4e9b\u5de5\u4f5c\u8207\u52a0\u5bc6\u57f7\u884c\u7dd2\u6392\u5165\u4f47\u5217\u3002\u7576\u57f7\u884c\u7dd2\u96c6\u5340 (thread pool) \u6709\u7a7a\u9592\u7684\u57f7\u884c\u7dd2\u6642\uff0c\u5c31\u6703\u57f7\u884c\u6392\u5165\u4f47\u5217\u7684\u5de5\u4f5c\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-51.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"543\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-51-1024x543.png\" alt=\"\" class=\"wp-image-73324\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-51-1024x543.png 1024w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-51-300x159.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-51-768x407.png 768w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-51-30x16.png 30w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-51.png 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption>\u5716 24\uff1aHavanaCrypt \u4f7f\u7528 QueueUserWorkItem \u51fd\u5f0f\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u6b64\u5916\u4e5f\u4f7f\u7528 DebuggerStepThrough \u5c6c\u6027\u4f86\u8b93\u7a0b\u5f0f\u78bc\u5728\u9664\u932f\u6642\u6703\u4ee5\u6574\u500b\u51fd\u5f0f\u70ba\u55ae\u4f4d\u4f86\u57f7\u884c\uff0c\u800c\u975e\u9010\u884c\u57f7\u884c\u3002\u6240\u4ee5\u82e5\u8981\u9010\u884c\u5206\u6790\u9019\u500b\u51fd\u5f0f\uff0c\u5c31\u5fc5\u9808\u6e05\u9664\u9019\u500b\u5c6c\u6027\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-52.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"104\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-52.png\" alt=\"\" class=\"wp-image-73325\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-52.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-52-300x87.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-52-30x9.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 25\uff1aHavanaCrypt \u8a2d\u5b9a\u4e86 DebuggerStepThrough \u5c6c\u6027\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u5728 HavanaCrypt \u958b\u59cb\u57f7\u884c\u52a0\u5bc6\u4e4b\u524d\uff0c\u5b83\u6703\u5148\u8490\u96c6\u67d0\u4e9b\u8cc7\u8a0a\u4e26\u50b3\u9001\u7d66 C&amp;C \u4f3a\u670d\u5668 (20[.]227[.]128[.]33\/index.php)\uff0c\u9019\u4e9b\u8cc7\u8a0a\u5305\u62ec UID\u3001\u91d1\u9470\u548c\u65e5\u671f\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">UID<\/h2>\n\n\n\n<p>UID \u542b\u6709\u96fb\u8166\u7cfb\u7d71\u7368\u4e00\u7121\u4e8c\u7684\u8b58\u5225\u8cc7\u8a0a\uff0c\u5982\u540c\u6307\u7d0b\u4e00\u6a23\u3002HavanaCrypt \u6703\u8490\u96c6\u5404\u7a2e\u96fb\u8166\u8cc7\u8a0a\uff0c\u7136\u5f8c\u4f9d\u7167\u4e0b\u5217\u683c\u5f0f\u5c07\u8cc7\u8a0a\u62fc\u6e4a\u5728\u4e00\u8d77\uff0c\u518d\u8f49\u63db\u6210 SHA-256 \u96dc\u6e4a\u78bc\uff1a<\/p>\n\n\n\n<p>[{Number of Cores}{ProcessorID}{Name}{SocketDesignation}] BIOS Information [{Manufacturer}{BIOS Name}{Version}] Baseboard Information [{Name}]<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-53.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"839\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-53-1024x839.png\" alt=\"\" class=\"wp-image-73326\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-53-1024x839.png 1024w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-53-300x246.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-53-768x629.png 768w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-53-30x25.png 30w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-53.png 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption><br>\u5716 26\uff1aHavanaCrypt \u7528\u4f86\u8490\u96c6\u96fb\u8166\u8cc7\u8a0a\u7684\u51fd\u5f0f\u3002<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-54.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"62\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-54.png\" alt=\"\" class=\"wp-image-73327\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-54.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-54-300x52.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-54-30x5.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 27\uff1aHavanaCrypt \u5c07\u8490\u96c6\u5230\u7684\u8cc7\u8a0a\u8f49\u6210\u4e00\u500b SHA-256 \u96dc\u6e4a\u78bc\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u4ee5\u4e0b\u662f HavanaCrypt \u6240\u8490\u96c6\u7684\u8cc7\u8a0a\uff1a<\/p>\n\n\n\n<ul><li><strong>\u8655\u7406\u5668\u6838\u5fc3\u6578\u91cf<\/strong><\/li><li><strong>\u8655\u7406\u5668\u8b58\u5225\u78bc (ID)<\/strong><\/li><li><strong>\u8655\u7406\u5668\u540d\u7a31<\/strong><\/li><li><strong>\u63d2\u69fd\u578b\u865f<\/strong><\/li><li><strong>\u4e3b\u6a5f\u677f\u88fd\u9020\u5546<\/strong><\/li><li><strong>\u4e3b\u6a5f\u677f\u540d\u7a31<\/strong><\/li><li><strong>BIOS \u7248\u672c<\/strong><\/li><li><strong>\u7522\u54c1\u7de8\u865f<\/strong><\/li><\/ul>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">\u91d1\u9470\u548c\u65e5\u671f<\/h2>\n\n\n\n<p><br>HavanaCrypt \u00a0\u6703\u5c07\u300cindex.php\u300d\u9019\u4e32\u5b57\u63db\u6210\u300cham.php\u300d\u7136\u5f8c\u767c\u9001 GET \u8acb\u6c42\u5230 C&amp;C \u4f3a\u670d\u5668 (hxxp[:]\/\/20[.]227[.]128[.]33\/ham.php)\uff0c\u4e26\u5c07 User Agent \u8a2d\u6210\u300cHavana\/1.0\u300d\u3002<\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-55.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"62\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-55.png\" alt=\"\" class=\"wp-image-73328\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-55.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-55-300x52.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-55-30x5.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 28\uff1aHavanaCrypt \u767c\u9001 GET \u8acb\u6c42\u5230 C&amp;C \u4f3a\u670d\u5668\u7684\u51fd\u5f0f\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-56.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"127\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-56.png\" alt=\"\" class=\"wp-image-73329\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-56.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-56-300x106.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-56-30x11.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 29\uff1a\u6211\u5011\u4f7f\u7528\u7db2\u9801\u9664\u932f\u5de5\u5177 Fiddler \u5f9e 20[.]227[.]128[.]33\/ham.php \u6536\u5230\u7684\u56de\u61c9\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>HavanaCrypt \u6703\u4f7f\u7528 Base64 \u4f86\u89e3\u78bc\u4f86\u81ea ham.php \u7684\u56de\u61c9\uff0c\u4e26\u4f7f\u7528\u4ee5\u4e0b\u53c3\u6578\u4f86\u57f7\u884c AES \u89e3\u5bc6\uff1a<\/p>\n\n\n\n<ul><li><strong>Aes.key: d8045c7174c2649e96e68a01a5d77f7dec4846ebebb7ed04fa8b1325c14d84b0 (<\/strong><strong>\u300cHOLAKiiaa##~~@#!2100\u300d\u9019\u4e32\u5b57\u7684 SHA-256 \u7de8\u78bc)<\/strong><strong><\/strong><\/li><li><strong>Aes.IV: 16 \u500b 00 \u4f4d\u5143\u7d44<\/strong><\/li><\/ul>\n\n\n\n<p>HavanaCrypt \u63a5\u8457\u5c07\u8f38\u51fa\u5b58\u653e\u5728\u5169\u500b\u4e0d\u540c\u9663\u5217\u7576\u4e2d\uff0c\u7528\u300c\u2013\u300d\u5206\u9694\u3002\u7b2c\u4e00\u500b\u9663\u5217\u5b58\u653e\u91d1\u9470\uff0c\u7b2c\u4e8c\u500b\u9663\u5217\u5b58\u653e\u65e5\u671f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-57.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"115\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-57.png\" alt=\"\" class=\"wp-image-73330\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-57.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-57-300x96.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-57-30x10.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 30\uff1aHavanaCrypt \u7684 AES \u89e3\u5bc6\u53c3\u6578\u8d77\u59cb\u5316\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-58.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"198\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-58.png\" alt=\"\" class=\"wp-image-73331\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-58.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-58-300x165.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-58-30x17.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 31\uff1aHavanaCrypt \u57f7\u884c AES \u89e3\u5bc6\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>\u6211\u5011\u4f7f\u7528\u53e6\u4e00\u500b\u5177\u5099\u52a0\u89e3\u5bc6\u529f\u80fd\u7684\u7db2\u9801\u5de5\u5177 <a href=\"https:\/\/gchq.github.io\/CyberChef\/\">CyberChef<\/a> \u4f86\u6a21\u4eff HavanaCrypt \u5c07 20[.]227[.]128[.]33\/ham.php \u7684\u56de\u61c9\u89e3\u5bc6\uff1a<\/p>\n\n\n\n<ul><li><strong>\u8f38\u51fa\uff1a d388ed2139d0703b7c2a810b09e513652eb9402c92304addd34679e21a826537-1655449622<\/strong><\/li><li><strong>\u91d1\u9470\uff1ad388ed2139d0703b7c2a810b09e513652eb9402c92304addd34679e21a826537<\/strong><\/li><li><strong>\u65e5\u671f\uff1a1655449622<\/strong><\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-59.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"392\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-59-1024x392.png\" alt=\"\" class=\"wp-image-73332\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-59-1024x392.png 1024w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-59-300x115.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-59-768x294.png 768w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-59-30x11.png 30w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-59.png 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption>\u5716 32\uff1a\u6211\u5011\u4f7f\u7528 CyberChef \u7a0b\u5f0f\u6a21\u64ec HavanaCrypt \u7684\u89e3\u5bc6\u52d5\u4f5c\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u5728\u8490\u96c6\u5b8c\u6240\u6709\u5fc5\u8981\u7684\u96fb\u8166\u8cc7\u8a0a\u4e4b\u5f8c\uff0cHavanaCrypt \u6703\u4f7f\u7528 POST \u8acb\u6c42\u5c07\u8cc7\u8a0a\u767c\u9001\u5230\uff1ahxxp:\/\/20[.]227[.]128[.]33\/index.php\uff0c\u4e26\u5c07 User Agent \u8a2d\u6210\u300cHavana\/1.0\u300d\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-60.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"100\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-60-1024x100.png\" alt=\"\" class=\"wp-image-73333\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-60-1024x100.png 1024w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-60-300x29.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-60-768x75.png 768w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-60-30x3.png 30w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-60.png 1430w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption>\u5716 33\uff1a\u6211\u5011\u4f7f\u7528 Fiddler \u64f7\u53d6\u5230 HavanaCrypt \u767c\u9001\u5230 hxxp[:]20[.]227[.]128[.]33\/index[.]php \u7684\u00a0 POST \u8acb\u6c42\u3002<\/figcaption><\/figure>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u8acb\u6c42\u767c\u9001\u6210\u529f\u6642\uff0cHavanaCrypt \u6703\u5728\u56de\u61c9\u4e2d\u6536\u5230\u52a0\u5bc6\u91d1\u9470\u3001\u79c1\u5bc6\u91d1\u9470\u53ca\u5176\u4ed6\u8a73\u7d30\u8cc7\u8a0a\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-61.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"307\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-61-1024x307.png\" alt=\"\" class=\"wp-image-73334\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-61-1024x307.png 1024w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-61-300x90.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-61-768x230.png 768w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-61-30x9.png 30w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-61.png 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption>\u5716 34\uff1a\u6211\u5011\u4f7f\u7528 Fiddler \u6536\u5230\u4f86\u81ea hxxp[:]20[.]227[.]128[.]33\/index[.]php \u7684\u56de\u61c9\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>HavanaCrypt \u6703\u6aa2\u67e5\u300chava.info\u300d\u9019\u500b\u6a94\u6848\u662f\u5426\u5df2\u5b58\u5728\u65bc\u300c%AppDataLocal%\/Google\/Google Software Update\/1.0.0.0\u300d\u76ee\u9304\u3002\u5982\u679c\u627e\u4e0d\u5230\u9019\u500b\u6a94\u6848\uff0c\u5c31\u6703\u7522\u751f hava.info \u6a94\u6848\uff0c\u88e1\u9762\u542b\u6709 HavanaCrypt \u4f7f\u7528 RSACryptoServiceProvider \u51fd\u5f0f\u7522\u751f\u7684 RSA \u91d1\u9470\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-62.png\"><img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"252\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-62.png\" alt=\"\" class=\"wp-image-73335\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-62.png 480w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-62-300x158.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-62-30x16.png 30w\" sizes=\"(max-width: 480px) 100vw, 480px\" \/><\/a><figcaption>\u5716 35\uff1a\u6211\u5011\u4f7f\u7528 HIEW (\u4e00\u500b 16 \u9032\u4f4d\u7de8\u8f2f\u5668) \u67e5\u770b hava.info \u6a94\u6848\u5167\u5bb9\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-63.png\"><img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"198\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-63.png\" alt=\"\" class=\"wp-image-73336\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-63.png 480w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-63-300x124.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-63-30x12.png 30w\" sizes=\"(max-width: 480px) 100vw, 480px\" \/><\/a><figcaption>\u5716 36\uff1aHavanaCrypt \u4f7f\u7528 RSACryptoServiceProvider \u51fd\u5f0f\u7522\u751f\u4e00\u500b RSA \u91d1\u9470\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h1 class=\"wp-block-heading\">\u52a0\u5bc6\u884c\u70ba<\/h1>\n\n\n\n<p><br>\u6211\u5011\u767c\u73fe HavanaCrypt \u6703\u4f7f\u7528 KeePass Password Safe \u7684\u6a21\u7d44\u4f86\u57f7\u884c\u52a0\u5bc6\u884c\u70ba\u3002\u5c24\u5176\uff0c\u5b83\u6703\u4f7f\u7528 CryptoRandom \u51fd\u5f0f\u4f86\u7522\u751f\u52a0\u5bc6\u6240\u9700\u7684\u96a8\u6a5f\u91d1\u9470\u3002HavanaCrypt \u6240\u4f7f\u7528\u7684\u51fd\u5f0f\u8207 <a href=\"https:\/\/github.com\/aramrami\/KeePass-2.41\/blob\/master\/KeePassLib\/Cryptography\/CryptoRandom.cs\">GitHub<\/a> \u4e0a\u7684 KeePass Password Safe \u6a21\u7d44\u660e\u986f\u76f8\u4f3c\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-64.png\"><img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"222\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-64.png\" alt=\"\" class=\"wp-image-73337\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-64.png 480w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-64-300x139.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-64-30x14.png 30w\" sizes=\"(max-width: 480px) 100vw, 480px\" \/><\/a><figcaption>\u5716 37\uff1aHavanaCrypt \u7528\u65bc\u7522\u751f\u96a8\u6a5f\u4f4d\u5143\u7d44\u7684\u51fd\u5f0f\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-65.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-65.png\" alt=\"\" class=\"wp-image-73338\" width=\"312\" height=\"360\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-65.png 312w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-65-260x300.png 260w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-65-26x30.png 26w\" sizes=\"(max-width: 312px) 100vw, 312px\" \/><\/a><figcaption>\u5716 38\uff1a\u53d6\u81ea GitHub \u7684 KeePass Password Safe \u7a0b\u5f0f\u78bc\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>HavanaCrypt \u6703\u5c07\u6a94\u6848\u52a0\u5bc6\uff0c\u4e26\u4f7f\u7528\u300c.Havana\u300d\u70ba\u526f\u6a94\u540d\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-66.png\"><img loading=\"lazy\" decoding=\"async\" width=\"468\" height=\"265\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-66.png\" alt=\"\" class=\"wp-image-73339\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-66.png 468w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-66-300x170.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-66-30x17.png 30w\" sizes=\"(max-width: 468px) 100vw, 468px\" \/><\/a><figcaption>\u5716 39\uff1aHavanaCrypt \u7684\u52a0\u5bc6\u884c\u70ba\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>\u5728\u52a0\u5bc6\u6642\uff0c\u5b83\u6703\u907f\u958b\u67d0\u4e9b\u526f\u6a94\u540d\u7684\u6a94\u6848\uff0c\u5305\u62ec\u526f\u6a94\u540d\u300c.Havana\u300d\u7684\u6a94\u6848\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-67.png\"><img loading=\"lazy\" decoding=\"async\" width=\"360\" height=\"71\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-67.png\" alt=\"\" class=\"wp-image-73340\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-67.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-67-300x59.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-67-30x6.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 40\uff1aHavanaCrypt \u7528\u4f86\u907f\u958b\u67d0\u4e9b\u526f\u6a94\u540d\u7684\u51fd\u5f0f\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-68.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-68.png\" alt=\"\" class=\"wp-image-73341\" width=\"360\" height=\"133\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-68.png 360w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-68-300x111.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-68-30x11.png 30w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/a><figcaption>\u5716 41\uff1aHavanaCrypt \u5728\u52a0\u5bc6\u6642\u6703\u907f\u958b\u7684\u526f\u6a94\u540d\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>\u6b64\u5916\uff0cHavanaCrypt \u4e5f\u6703\u907f\u958b\u67d0\u4e9b\u76ee\u9304\u4e2d\u7684\u6a94\u6848\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-69.png\"><img loading=\"lazy\" decoding=\"async\" width=\"349\" height=\"305\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-69.png\" alt=\"\" class=\"wp-image-73342\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-69.png 349w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-69-300x262.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-69-30x26.png 30w\" sizes=\"(max-width: 349px) 100vw, 349px\" \/><\/a><figcaption>\u5716 42\uff1aHavanaCrypt \u5728\u52a0\u5bc6\u6642\u6703\u907f\u958b\u7684\u4e00\u4e9b\u76ee\u9304\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-70.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-70.png\" alt=\"\" class=\"wp-image-73343\" width=\"336\" height=\"259\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-70.png 336w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-70-300x231.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-70-30x23.png 30w\" sizes=\"(max-width: 336px) 100vw, 336px\" \/><\/a><figcaption>\u5716 43\uff1aHavanaCrypt \u7528\u4f86\u907f\u958b\u67d0\u4e9b\u76ee\u9304\u7684\u51fd\u5f0f\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-71.png\"><img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"264\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-71.png\" alt=\"\" class=\"wp-image-73344\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-71.png 480w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-71-300x165.png 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-71-30x17.png 30w\" sizes=\"(max-width: 480px) 100vw, 480px\" \/><\/a><figcaption>\u5716 44\uff1a\u4e00\u4e9b\u5df2\u88ab HavanaCrypt \u52a0\u5bc6\u7684\u6a94\u6848\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>\u5728\u52a0\u5bc6\u671f\u9593\uff0cHavanaCrypt \u6703\u7522\u751f\u4e00\u500b\u540d\u70ba\u300cfoo.txt\u300d\u7684\u6587\u5b57\u6a94\uff0c\u88e1\u9762\u8a18\u9304\u4e86\u6240\u6709\u6a94\u6848\u5df2\u88ab\u52a0\u5bc6\u7684\u76ee\u9304\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-72.png\"><img loading=\"lazy\" decoding=\"async\" width=\"408\" height=\"480\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-72.png\" alt=\"\" class=\"wp-image-73345\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-72.png 408w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-72-255x300.png 255w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2022\/07\/image-72-26x30.png 26w\" sizes=\"(max-width: 408px) 100vw, 408px\" \/><\/a><figcaption>\u5716 45\uff1afoo.txt \u6587\u5b57\u6a94\u4e2d\u8a18\u9304\u8457\u6240\u6709\u6a94\u6848\u5df2\u88ab\u52a0\u5bc6\u7684\u76ee\u9304\u3002<\/figcaption><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h1 class=\"wp-block-heading\">\u7d50\u8ad6\u8207\u8da8\u52e2\u79d1\u6280\u89e3\u6c7a\u65b9\u6848<\/h1>\n\n\n\n<p><br>HavanaCrypt \u52d2\u7d22\u75c5\u6bd2\u6703\u5047\u626e\u6210 Google Software Update \u61c9\u7528\u7a0b\u5f0f\u4f86\u8a98\u9a19\u4f7f\u7528\u8005\u57f7\u884c\u60e1\u610f\u7a0b\u5f0f\u3002\u6b64\u5916\uff0c\u5b83\u9084\u5177\u5099\u4e00\u4e9b\u53cd\u5236\u865b\u64ec\u74b0\u5883\u7684\u6280\u5de7\uff0c\u5305\u62ec\u6aa2\u67e5\u865b\u64ec\u6a5f\u5668\u76f8\u95dc\u7684\u8655\u7406\u7a0b\u5e8f\u3001\u6a94\u6848\u8207\u670d\u52d9\u3002<\/p>\n\n\n\n<p>\u7136\u800c\uff0c\u4f7f\u7528 Microsoft \u7db2\u7ad9\u4ee3\u7ba1\u670d\u52d9\u4f86\u7576\u6210 C&amp;C \u4f3a\u670d\u5668\u5c0d\u52d2\u7d22\u75c5\u6bd2\u4f86\u8aaa\u4e26\u4e0d\u5e38\u898b\uff0c\u800c\u4e14\u99ed\u5ba2\u53ef\u80fd\u4e5f\u5c07\u5b83\u7576\u6210\u6b63\u5e38\u7684\u7db2\u7ad9\u4ee3\u7ba1\u670d\u52d9\u4f86\u4f7f\u7528\u4ee5\u63a9\u4eba\u8033\u76ee\u3002\u9664\u4e86 C&amp;C \u4f3a\u670d\u5668\u4e0d\u5c0b\u5e38\u4e4b\u5916\uff0cHavanaCrypt\u5728\u52a0\u5bc6\u968e\u6bb5\u9084\u4f7f\u7528\u4e86\u5408\u6cd5\u8edf\u9ad4 (KeePass Password Safe) \u7684\u6a21\u7d44\u3002<\/p>\n\n\n\n<p>\u672a\u4f86\uff0c\u6b64\u52d2\u7d22\u75c5\u6bd2\u96c6\u5718\u5f88\u53ef\u80fd\u6253\u7b97\u7528 Tor \u700f\u89bd\u5668\u4f86\u9032\u884c\u901a\u8a0a\uff0c\u56e0\u70ba\u5b83\u5728\u52a0\u5bc6\u6642\u6703\u907f\u958b Tor \u7684\u76ee\u9304\u3002\u53e6\u4e00\u500b\u503c\u5f97\u6ce8\u610f\u7684\u9ede\u662f HavanaCrypt \u4e5f\u6703\u5c07 foo.txt \u9019\u500b\u6587\u5b57\u6a94\u52a0\u5bc6\uff0c\u800c\u4e14\u4e0d\u6703\u7559\u4e0b\u52d2\u7d22\u8a0a\u606f\u3002\u9019\u53ef\u80fd\u610f\u5473\u8457 HavanaCrypt \u4ecd\u5728\u958b\u767c\u968e\u6bb5\uff0c\u5118\u7ba1\u5982\u6b64\uff0c\u6211\u5011\u4ecd\u8981\u5728\u5b83\u9032\u4e00\u6b65\u6f14\u5316\u4e26\u9020\u6210\u66f4\u5927\u640d\u5bb3\u4e4b\u524d\u5c31\u52a0\u4ee5\u5075\u6e2c\u4e26\u6514\u622a\u3002<\/p>\n\n\n\n<p>\u4f01\u696d\u548c\u4e00\u822c\u4f7f\u7528\u8005\u53ef\u63a1\u7528\u4e0b\u5217\u591a\u5c64\u5f0f\u9632\u79a6\u4f86\u5075\u6e2c\u52d2\u7d22\u75c5\u6bd2\uff0c\u4e0d\u8b93\u99ed\u5ba2\u6709\u6a5f\u6703\u767c\u52d5\u653b\u64ca\uff1a<\/p>\n\n\n\n<ul><li><strong>Trend Micro Vision One<\/strong>&#x2122; <strong>\u63d0\u4f9b\u4e86\u591a\u5c64\u5f0f\u9632\u8b77\u8207\u884c\u70ba\u5075\u6e2c\uff0c\u53ef\u63d0\u65e9\u6514\u622a\u53ef\u7591\u884c\u70ba\u8207\u5de5\u5177\uff0c\u4e0d\u8b93\u52d2\u7d22\u75c5\u6bd2\u6709\u6a5f\u6703\u9020\u6210\u7834\u58de\u3002<\/strong><\/li><li><strong>Trend Micro Apex One<\/strong>&#x2122; <strong>\u53ef\u9032\u4e00\u6b65\u63d0\u4f9b\u81ea\u52d5\u5316\u5a01\u8105\u5075\u6e2c\u53ca\u56de\u61c9\uff0c\u9632\u7bc4\u7121\u6a94\u6848\u5f0f\u5a01\u8105\u8207\u52d2\u7d22\u75c5\u6bd2\u7b49\u9032\u968e\u653b\u64ca\uff0c\u4fdd\u969c\u7aef\u9ede\u5b89\u5168\u3002<\/strong><\/li><\/ul>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u5165\u4fb5\u6307\u6a19\u8cc7\u6599<\/h1>\n\n\n\n<p><strong>\u6a94\u6848<\/strong><\/p>\n\n\n\n<style>\n   table {border-collapse:collapse; table-layout:fixed; width:310px;}\n   table td {border:solid 1px ; width:100px; word-wrap:break-word;}\n   <\/style>\n<figure class=\"wp-block-table\"><table  class=\" table table-hover\" ><tbody><tr><td>SHA-256<\/td><td>\u8da8\u52e2\u79d1\u6280\u5075\u6e2c\u540d\u7a31<\/td><td>\u8aaa\u660e<\/td><\/tr><tr><td>b37761715d5a2405a3fa75abccaf6bb15b7298673aaad91a158725be3c518a87&nbsp;<\/td><td>Ransom.MSIL.HAVANACRYPT.THFACBB<\/td><td>\u52a0\u5bc6\u7de8\u78bc\u5f8c\u7684 HAVANACRYPT \u52d2\u7d22\u75c5\u6bd2\u3002&nbsp;<\/td><\/tr><tr><td>bf58fe4f2c96061b8b01e0f077e0e891871ff22cf2bc4972adfa51b098abb8e0&nbsp;<\/td><td>Ransom.MSIL.HAVANACRYPT.THFACBB<\/td><td>\u89e3\u958b\u5f8c\u7684 HAVANACRYPT \u52d2\u7d22\u75c5\u6bd2\u3002&nbsp;<\/td><\/tr><tr><td>aa75211344aa7f86d7d0fad87868e36b33db1c46958b5aa8f26abefbad30ba17&nbsp;<\/td><td>Ransom.MSIL.HAVANACRYPT.THFBABB<\/td><td>\u89e3\u958b\u5f8c\u7684 HAVANACRYPT \u52d2\u7d22\u75c5\u6bd2\u3002&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>\u7db2\u5740<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table  class=\" table table-hover\" ><tbody><tr><td>http:\/\/20[.]227[.]128[.]33\/2.txt<\/td><\/tr><tr><td>http:\/\/20[.]227[.]128[.]33\/index.php<\/td><\/tr><tr><td>http:\/\/20[.]227[.]128[.]33\/ham.php<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/g\/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html\"> Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&amp;C Server<\/a> \u4f5c\u8005\uff1aNathaniel Morales\u3001Monte de Jesus\u3001Ivan Nicole Chavez\u3001Bren Matthew Ebriega \u8207 Joshua Paul Ignacio<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6700\u8fd1\u8da8\u52e2\u79d1\u6280\u767c\u73fe\u4e00\u500b\u65b0\u7684\u52d2\u7d22\u75c5\u6bd2 Ransomware\u5bb6\u65cf (\u8da8\u52e2\u79d1\u6280\u547d\u540d\u70ba\u300cHavanaCrypt\u300d)\uff0c\u5b83\u6703 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[1268,2266,906,4384],"tags":[2344,2559,4179],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/73300"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=73300"}],"version-history":[{"count":1,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/73300\/revisions"}],"predecessor-version":[{"id":73346,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/73300\/revisions\/73346"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=73300"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=73300"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=73300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}