03e开头的是个下载者,不过这个家族的主体行为还是老一套,照旧的执行notepad挖矿···挖矿程序被智量内存杀···
相关配置也还是一个base64加密的名为cfg的文件,存放于ProgramData的一个随机文件夹下,解密后如下:
- {
- "api": {
- "id": null,
- "worker-id": null
- },
- "http": {
- "enabled": false
- },
- "autosave": false,
- "version": 1,
- "background": false,
- "colors": true,
- "randomx": {
- "init": 1,
- "numa": true
- },
- "cpu": {
- "enabled": true,
- "huge-pages": true,
- "hw-aes": null,
- "priority": null,
- "memory-pool": false,
- "asm": true,
- "argon2-impl": null,
- "cpu-profile": {
- "threads": 2
- },
- "cn-heavy/0": "cpu-profile",
- "cn-heavy/xhv": "cpu-profile",
- "cn-heavy/tube": "cpu-profile",
- "cn-lite/0": "cpu-profile",
- "cn-lite/1": "cpu-profile",
- "cn": "cpu-profile",
- "cn/r": "cpu-profile",
- "cn/fast": "cpu-profile",
- "cn-gpu": "cpu-profile",
- "cn/half": "cpu-profile",
- "cn/2": "cpu-profile",
- "argon2/chukwa": "cpu-profile",
- "argon2/wrkz": "cpu-profile",
- "rx": "cpu-profile",
- "rx/0": "cpu-profile",
- "rx/loki": "cpu-profile",
- "rx/wow": "cpu-profile",
- "rx/arq": "cpu-profile"
- },
- "donate-level": 0,
- "donate-over-proxy": 0,
- "log-file": null,
- "pools": [
- {
- "algo": null,
- "coin": "monero",
- "url": "xmr.f2pool.com:13531",
- "user": "49RvDCimd2U7DHfaQbqXW6PRvqxdsxLhXJp5LBi7DAZF6zKQSZWpHX9TkmQrRGXmiuBT4MzKcU96KVaZZVUKVNWiBNSVUBC",
- "pass": "x",
- "rig-id": null,
- "nicehash": false,
- "keepalive": true,
- "enabled": true,
- "tls": false,
- "tls-fingerprint": null,
- "daemon": false,
- "self-select": null
- }
- ],
- "print-time": 60,
- "health-print-time": 60,
- "retries": 5,
- "retry-pause": 5,
- "syslog": false,
- "user-agent": null,
- "watch": false
- }
复制代码
剩下两个都是刚刚出sleep就被智量内存防护或主防杀掉(头一次见到主防报MalBehavior.A0但样本却未执行cmd.exe)


|