公对公音频线的另一端插入音频线分支器的端口,从而将一个音频设备与音响完成连接。
if((connfd=accept(sockfd,(struct sockaddr *)&their_addr,&sin_size))==-1){//accept函数从倾听套接字的完成连接队列中接收客户端连接请求。
spidermonkey应用在mozilla firefox 1.0-3.0,tracemonkey应用在mozilla firefox 3.5-3.6版本,jaegermonkey应用在mozilla firefox 4.0及后续的版本。
mozilla firefox 39.0.3 (x86 en-us) (hklm\...\mozilla firefox 39.0.3 (x86 en-us)) (version: 39.0.3 - mozilla)。
firewallrules: [udp query user{7bf980d2-21e2-42e5-983e-ef1a47dc2eb3}c:\program files\mozilla firefox\firefox.exe] => (allow) c:\program files\mozilla firefox\firefox.exe。
firewallrules: [tcp query user{84d0d121-ecbd-42a3-8784-f4585e6b748b}c:\program files\mozilla firefox\firefox.exe] => (allow) c:\program files\mozilla firefox\firefox.exe。
开启键盘记录。 写入注册表HKCU\Software\Win32创建keyx,值为字符串类型“1” 生成%temp%\tmpwstz2.ps1文件 调用powershell.exe -executionpolicy bypass –File %temp%\tmpwstz2.ps1
在%TEMP%\q.lnk快捷方式,指向mms://live.mp3quran.net:9976/,并打开访问
由于该恶意程序在通信上并没有任何的安全机制,并且上文中我们已经分析清楚该恶意程序与服务器之间的通信指令。因此,我们可以在本地假设环境进行实际测试,从而验证我们上述分析。
利用nc.exe作为服务器端,端口1338,在hosts下修改torrentfreak.duckdns.org域名指向本机。
在本机直接运行nc.exe –l –p 1338,运行恶意程序后,木马上线并回报相关信息,如下图所示。
输入Process指令,让其枚举进程,结果如下图所示。
其他的命令可以一一进行操作并验证是否与分析一致。
通过上文分析,我们可以初步判断这是一起网络攻击事件。攻击者利用邮件实施攻击,不过技术实力有限,准备不足。鼠标与键盘
初步的结论如下:
本文来自电脑杂谈,转载请注明本文网址:
http://www.pc-fly.com/a/jisuanjixue/article-90405-8.html
看上去听上去是有道理
如果缩头缩脑