{"id":2630,"date":"2023-04-27T20:38:46","date_gmt":"2023-04-27T12:38:46","guid":{"rendered":"https:\/\/blog.billows.com.tw\/?p=2630"},"modified":"2023-04-27T20:40:16","modified_gmt":"2023-04-27T12:40:16","slug":"%e7%a0%94%e7%a9%b6%e7%a8%b1%e4%b8%ad%e5%9c%8bapt%e9%a7%ad%e5%ae%a2%e5%88%a9%e7%94%a8mgbot%e6%83%a1%e6%84%8f%e8%bb%9f%e9%ab%94%e6%94%bb%e6%93%8a%e9%a8%b0%e8%a8%8aqq%ef%bc%8c%e4%bb%a5%e7%9b%a3%e8%a6%96","status":"publish","type":"post","link":"https:\/\/blog.billows.com.tw\/?p=2630","title":{"rendered":"\u7814\u7a76\u7a31\u4e2d\u570bAPT\u99ed\u5ba2\u5229\u7528MgBot\u60e1\u610f\u8edf\u9ad4\u653b\u64ca\u9a30\u8a0aQQ\uff0c\u4ee5\u76e3\u8996\u975e\u71df\u5229\u7d44\u7e54"},"content":{"rendered":"\n<p>\u6839\u64da\u8cc7\u5b89\u516c\u53f8ESET \u7684\u7814\u7a76\uff0c\u540d\u70baEvasive Panda \u7684\u4e2d\u570bAPT\u99ed\u5ba2\u7d44\u7e54\u4ee5\u4e2d\u570b\u975e\u71df\u5229\u7d44\u7e54\u70ba\u76ee\u6a19\uff0c\u5229\u7528\u81ea\u8a02\u7fa9\u7684\u81ea\u5b9a\u7fa9\u5f8c\u9580MgBot\uff0c\u4f5c\u70ba\u9a30\u8a0aQQ \u5373\u6642\u901a\u8a0a\u61c9\u7528\u7a0b\u5f0f\u81ea\u52d5\u66f4\u65b0\u7684\u4e00\u90e8\u5206\uff0c\u4f86\u76e3\u8996\u53d7\u5bb3\u8005\u4e26\u5f9e\u4ed6\u5011\u7684\u8a2d\u5099\u6536\u96c6\u6578\u64da\u3002\u7814\u7a76\u6307\u51fa\u8a72\u6d3b\u52d5\u65bc 2020 \u5e74 11 \u6708\u958b\u59cb\uff0c\u653b\u64ca\u93c8\u65e8\u5728\u5206\u767c MgBot \u60e1\u610f\u8edf\u9ad4\u7684 Windows \u5b89\u88dd\u7a0b\u5f0f\uff0c\u5927\u591a\u6578\u53d7\u5bb3\u8005\u662f\u570b\u969bNGO\uff08\u975e\u653f\u5e9c\u7d44\u7e54\uff09\u7684\u6210\u54e1\uff0c\u5206\u4f48\u5728\u7518\u8085\u3001\u5ee3\u6771\u548c\u6c5f\u8607\u7b49\u7701\u4efd\uff0c\u986f\u793a\u51fa\u76f8\u7576\u5177\u9ad4\u548c\u96c6\u4e2d\u7684\u76ee\u6a19\u3002<\/p>\n\n\n\n<p>\u4e2d\u570b\u570b\u5bb6\u7d1a\u99ed\u5ba2\u7d44\u7e54Evasive Panda\uff0c\u4e5f\u88ab\u7a31\u70ba Bronze Highland \u548c Daggerfly\uff0c\u662f\u4e00\u500b\u81f3\u5c11\u5f9e 2012\u5e74\u958b\u59cb\u6d3b\u8e8d\u7684\u7db2\u8def\u9593\u8adc\u7d44\u7e54\uff0c\u6b64\u524d\u66fe\u91dd\u5c0d\u4e2d\u570b\u5927\u9678\u3001\u9999\u6e2f\u3001\u6fb3\u9580\u3001\u5c3c\u65e5\u5229\u4e9e\u4ee5\u53ca\u6771\u5357\u4e9e\u548c\u6771\u4e9e\u591a\u500b\u570b\u5bb6\u7684\u7d44\u7e54\u548c\u500b\u4eba\u767c\u52d5\u653b\u64ca\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"498\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-30-1024x498.png\" alt=\"\" class=\"wp-image-2631\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-30-1024x498.png 1024w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-30-300x146.png 300w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-30-768x373.png 768w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-30.png 1278w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Photo Credit: ESET<\/figcaption><\/figure>\n\n\n\n<p>ESET \u5831\u544a\u7a31\uff0cMsgBot\u60e1\u610f\u8edf\u9ad4\u8ca0\u8f09\u4f5c\u70ba\u9a30\u8a0a QQ \u8edf\u9ad4\u66f4\u65b0\u5f9e\u5c6c\u65bc\u8edf\u9ad4\u958b\u767c\u5546\u7684\u5408\u6cd5 URL \u548c IP \u5730\u5740\u50b3\u905e\u7d66\u53d7\u5bb3\u8005\uff0c\u9019\u610f\u5473\u8457\u653b\u64ca\u53ef\u80fd\u6709\u5169\u7a2e\u60c5\u6cc1 &#8211; \u4f9b\u61c9\u93c8\u653b\u64ca\u6216\u4e2d\u9593\u4eba (Adversary-in-the-middle AITM) \u653b\u64ca\u3002<\/p>\n\n\n\n<p>\u5728\u7b2c\u4e00\u7a2e\u60c5\u6cc1\u4e0b\uff0cEvasive Panda \u5fc5\u9808\u5165\u4fb5\u9a30\u8a0a QQ \u7684\u66f4\u65b0\u5206\u767c\u4f3a\u670d\u5668\uff0c\u4ee5\u5408\u6cd5\u8edf\u9ad4\u66f4\u65b0\u70ba\u5e4c\u5b50\u5c07\u6728\u99ac\u5316\u61c9\u7528\u7a0b\u5f0f\u201cQQUrlMgr.exe\u201d\u767c\u9001\u7d66\u53d7\u5bb3\u8005\u3002ESET \u6ce8\u610f\u5230\u66f4\u65b0\u7a0b\u5f0f\u7684\u6728\u99ac\u5316\u7248\u672c\u5f9e\u5beb\u6b7b URL\u7684\uff08\u201cupdate.browser.qq[.]com\u201d\uff09\u7372\u53d6\u60e1\u610f\u8edf\u9ad4\uff0c\u4e26\u4f7f\u7528\u8207\u4f3a\u670d\u5668\u63d0\u4f9b\u7684MD5 \u54c8\u5e0c\u5339\u914d\u7684\u5beb\u6b7b\u89e3\u5bc6\u5bc6\u9470\uff0c\u7531\u65bc\u9a30\u8a0a\u4e26\u672a\u56de\u61c9ESET\u7684\u63d0\u554f\uff0c\u8a72\u7db2\u5740\u7684\u5408\u6cd5\u6027\u9084\u6709\u5f85\u78ba\u8a8d\u3002\u6b64\u5916\uff0c\u5206\u6790\u4eba\u54e1\u7121\u6cd5\u5f9e\u4f3a\u670d\u5668\u6aa2\u7d22 XML \u66f4\u65b0\u6578\u64da\u7684\u6a23\u672c\uff0c\u56e0\u6b64\u672a\u80fd\u63ed\u793a\u60e1\u610f\u8edf\u9ad4\u7684\u50b3\u905e\u6a5f\u5236\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"213\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-31-1024x213.png\" alt=\"\" class=\"wp-image-2632\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-31-1024x213.png 1024w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-31-300x62.png 300w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-31-768x160.png 768w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-31-1536x319.png 1536w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2023\/04\/image-31.png 1714w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">\u89c0\u5bdf\u5230\u7684\u60e1\u610f URL\u3001IP \u548c\u6a94\u6848 (Photo Credit: ESET)<\/figcaption><\/figure>\n\n\n\n<p>\u82e5\u5728\u4e2d\u9593\u4eba\u653b\u64ca\u60c5\u6cc1\u4e0b\uff0cESET\u6ce8\u610f\u5230\u8207\u904e\u53bb\u63a1\u7528\u9019\u7a2e\u7b56\u7565\u7684\u6d3b\u52d5\uff0c\u6d89\u53ca\u540d\u70ba LuoYu \u7684\u4e2d\u570b\u99ed\u5ba2\u5718\u968a\uff0c <a href=\"https:\/\/securelist.com\/windealer-dealing-on-the-side\/105946\/\">\u5361\u5df4\u65af\u57fa<\/a>\u4e5f\u57282022 \u5e74 6 \u6708\u8a73\u7d30\u5831\u544a\u4e86\u8a72\u6d3b\u52d5\uff0c\u653b\u64ca\u6d3b\u52d5\u4f7f\u7528 \u201cWinDealer\u201d\u60e1\u610f\u8edf\u9ad4\uff0c\u5f9e\u4e2d\u570b\u96fb\u4fe1\u751f\u6210\u96a8\u6a5f IP \u5730\u5740\u4f86\u57f7\u884c AITM \u6216\u653b\u64ca\u8005\u7aef\u6514\u622a\u3002\u9019\u4e9b IP \u4f3c\u4e4e\u8207\u5728 Evasive Panda \u6d3b\u52d5\u4e2d\u50b3\u9001 MgBot \u60e1\u610f\u8edf\u9ad4\u7684 IP \u7bc4\u570d\u76f8\u540c\u3002<\/p>\n\n\n\n<p>\u96d6\u7136\u6839\u64da\u89c0\u5bdf\u5230\u7684\u5de7\u5408\u548c\u53ef\u80fd\u7684\u89e3\u91cb\uff0c\u9019\u5169\u7a2e\u60c5\u6cc1\u90fd\u662f\u5408\u7406\u7684\uff0c\u4f46 ESET\u7121\u6cd5\u627e\u5230\u660e\u78ba\u7684\u8b49\u64da\uff0c\u8a31\u591a\u554f\u984c\u4ecd\u672a\u5f97\u5230\u89e3\u7b54\u3002<\/p>\n\n\n\n<p>\u5728\u6b64\u6d3b\u52d5\u4e2d\u63d0\u4f9b\u7684 MgBot\u6709\u6548\u8ca0\u8f09(Payloads)\u662f Evasive Panda \u81ea 2012 \u5e74\u958b\u59cb\u71df\u904b\u4ee5\u4f86\u4e00\u76f4\u4f7f\u7528\u7684 C++ Windows \u5f8c\u9580\u3002<\/p>\n\n\n\n<p>ESET \u5831\u544a\u7a31\uff0c\u81eaMalwarebytes \u5728 2020 \u5e74\u5c0dMgBot\u9032\u884c\u5206\u6790\u4ee5\u4f86\uff0c\u8a72\u60e1\u610f\u8edf\u9ad4\u7684\u5b89\u88dd\u7a0b\u5f0f\u3001\u5f8c\u9580\u3001\u529f\u80fd\u548c\u57f7\u884c\u93c8\u57fa\u672c\u4fdd\u6301\u4e0d\u8b8a\u3002<\/p>\n\n\n\n<p>MgBot \u4f7f\u7528\u6a21\u7d44\u5316\u67b6\u69cb\u4f86\u64f4\u5145\u5176\u529f\u80fd\uff0c\u5f9e\u57f7\u884c\u5c08\u9580\u529f\u80fd\u7684 C2 \u63a5\u6536 DLL plugin \u6a21\u7d44\uff0c\u5305\u62ec\uff1a<\/p>\n\n\n\n<p>*\u7279\u5b9a\u9a30\u8a0a\u61c9\u7528\u7a0b\u5f0f\u7684keylogging\u8a18\u9304<\/p>\n\n\n\n<p>*\u5f9e\u786c\u789f\u548c USB\u7b46\u578b\u96a8\u8eab\u789f\u4e2d\u7aca\u53d6\u6a94\u6848<\/p>\n\n\n\n<p>*\u6536\u96c6\u8907\u88fd\u5230\u526a\u8cbc\u677f\u7684\u6587\u672c<\/p>\n\n\n\n<p>*\u6536\u96c6\u8f38\u5165\u548c\u8f38\u51fa\u97f3\u983b\u6d41<\/p>\n\n\n\n<p>*\u5f9e Outlook \u548c Foxmail \u96fb\u5b50\u90f5\u4ef6\u5ba2\u6236\u7aef\u7aca\u53d6\u6191\u8b49<\/p>\n\n\n\n<p>*\u5f9e Chrome\u3001Opera\u3001Firefox\u3001Foxmail\u3001QQBrowser\u3001FileZilla\u3001WinSCP \u7b49\u7aca\u53d6\u6191\u8b49<\/p>\n\n\n\n<p>*\u7aca\u53d6\u5b58\u5132\u7528\u6236\u6b77\u53f2\u6d88\u606f\u7684\u9a30\u8a0aQQ\u6578\u64da\u5eab\u5167\u5bb9<\/p>\n\n\n\n<p>*\u7aca\u53d6\u9a30\u8a0a\u5fae\u4fe1\u8cc7\u6599<\/p>\n\n\n\n<p>*\u5f9e Firefox\u3001Chrome \u548c Edge \u7aca\u53d6 cookies<\/p>\n\n\n\n<p>Evasive Panda APT \u88ab\u767c\u73fe\u91dd\u5c0d\u4e2d\u570b\u7528\u6236\uff0c\u65e8\u5728\u5f9e\u4e2d\u570b\u61c9\u7528\u7a0b\u5f0f\u7aca\u53d6\u6578\u64da\uff0c\u5229\u7528\u4e0d\u660e\u78ba\u7684\u65b9\u6cd5\u5c0d\u9a30\u8a0a QQ \u8edf\u9ad4\u57f7\u884c\u4f9b\u61c9\u93c8\u653b\u64ca\u3002\u9019\u662f\u8a72\u7d44\u7e54\u8d85\u8d8a\u793e\u4ea4\u5de5\u7a0b\u3001\u7db2\u8def\u91e3\u9b5a\u3001SEO \u6295\u6bd2\u7b49\u6a19\u6e96\u611f\u67d3\u65b9\u6cd5\u7684\u6700\u65b0\u7684\u4f8b\u5b50\uff0cESET\u547c\u7c72\u6f5b\u5728\u76ee\u6a19\u9700\u63d0\u9ad8\u8b66\u60d5\u3002<\/p>\n\n\n\n<pre id=\"block-3193d588-331d-44ad-a75a-b04b8c9ee0ab\" class=\"wp-block-preformatted\">\u201c\u8f49\u8cbc\u3001\u5206\u4eab\u6216\u5f15\u7528\u6587\u7ae0\u5167\u5bb9\uff0c\u8acb\u8a3b\u660e\u51fa\u8655\u70ba\u7ae3\u76df\u79d1\u6280<a href=\"https:\/\/www.billows.tech\/\">https:\/\/www.billows.tech\/<\/a>, \u4ee5\u514d\u89f8\u6cd5\u201d<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u6839\u64da\u8cc7\u5b89\u516c\u53f8ESET \u7684\u7814\u7a76\uff0c\u540d\u70baEvasive Panda \u7684\u4e2d\u570bAPT\u99ed\u5ba2\u7d44\u7e54\u4ee5\u4e2d\u570b\u975e\u71df\u5229\u7d44\u7e54\u70ba\u76ee\u6a19\uff0c\u5229\u7528 <a class=\"read-more\" href=\"https:\/\/blog.billows.com.tw\/?p=2630\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[174],"class_list":["post-2630","post","type-post","status-publish","format-standard","hentry","category-6","tag-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/2630","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2630"}],"version-history":[{"count":2,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/2630\/revisions"}],"predecessor-version":[{"id":2634,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/2630\/revisions\/2634"}],"wp:attachment":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2630"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}