-

   rss_drweb_viruses

 - e-mail

 

 -

 LiveInternet.ru:
: 30.09.2009
: 711
: 1
: 1

:


, 02 2021 . 09:00 +

PDF

2 2021

2020 - . , . , . , , , APT-.

, APT- 2017 . BackDoor.Farfli.130 , Gh0st RAT. , 2019 Trojan.Mirage.12, 2020 BackDoor.Siggen2.3268.

2019, BackDoor.Skeye.1. , 2019 Skeye .

2019 FireEye . , 2020 , DNS- BackDoor.DNSep.1, BackDoor.PlugX.

, 2017 BackDoor.RemShell.24. Positive Technologies Operation Taskmasters. , , APT- .

#drweb

?

APT- . , 2015 .

APT-, , TA428, Proofpoint Operation Lag Time IT. :

  1. BackDoor.DNSep BackDoor.Cotx ;
  2. BackDoor.Skeye.1 Trojan.Loader.661 , TA428;
  3. , , , TA428.

. Skeye APT- PoisonIvy:

#drweb

Skeye Cotx:

#drweb

DNSep Cotx , .

Logtu, . Skeye atob[.]kommesantor[.]com. BackDoor.Skeye.1 BackDoor.Logtu.1 BackDoor.Mikroceen.11.

PDF- Dr.Web.

BackDoor.DNSep.1 BackDoor.Cotx.1

, Cotx DNSep , .

, , :

struct st_arg
{
  _BYTE cmd;
  st_string arg;
};

, , arg |.

BackDoor.Cotx.1 , BackDoor.DNSep.1, , .

. , Cotx Unicode, DNSep ANSI.

BackDoor.DNSep.1 BackDoor.Cotx.1
#drweb #drweb
#drweb #drweb
#drweb #drweb
#drweb #drweb

, DNSep Cotx. , , DNSep TA428. , DNSep TA428.

Skeye, Mikroceen, Logtu

Skeye , Logtu. BackDoor.Logtu.1 BackDoor.Mikroceen.11.

.

  • BackDoor.Mikroceen.11 %d-%d-%d %d:%d:%d \r\n %TEMP%\WZ9Jan10.TMP, . 2f80f51188dc9aea697868864d88925d64c26abc 7B296FB0.CAB;
  • BackDoor.Logtu.1 [%d-%02d-%02d %02d:%02d:%02d] \n\n\n %TEMP%\rar.tmp XOR 0x31;
  • BackDoor.Skeye.1 %4d/%02d/%02d %02d:%02d:%02d\t\t\n %TEMP%\wcrypt32.dll.

:

  • ;
  • Logtu Mikroceen ;
  • , ;
  • .

, . , . , :

  • ;
  • ;
  • ;
  • .

-

3 . , -, .

- BackDoor.Mikroceen.11:

  • %WINDIR%\debug\netlogon.cfg;
  • -;
  • 80, 8080, 3128, 9080 TCP-.

#drweb

-:

#drweb

:

#drweb

- BackDoor.Logtu.1:

  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer;
  • HKU SID ;
  • WinHTTP API WinHttpGetProxyForUrl google.com.

#drweb

- BackDoor.Skeye.1:

  • HKCU Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer;
  • HKU SID ;
  • 80, 8080, 3128, 9080 TCP-.

#drweb

. .

#drweb

Logtu Mikroceen , . .

BackDoor.Mikroceen.11 BackDoor.Logtu.1
SHA1 Id SHA1 id
ce21f798119dbcb7a63f8cdf070545abb09f25ba intl0113 029735cb604ddcb9ce85de92a6096d366bd38a24 intpz0220
0eb2136c5ff7a92706bc9207da32dd85691eeed5 hisa5.si4 7b652e352a6d2a511f226e4d0cc22f093e052ad8 retail2007
2f80f51188dc9aea697868864d88925d64c26abc josa5w5n 1c5e5fd53fc2ee778342a5cae3ac2eb0ac345ed7 retail
2e50c075343ab20228a8c0c094722bbff71c4a2a enc0225 00ddcc200d1031b8639026532c0087bfcc4520c9 716demo
3bd16f11b5b3965a124a6fc3286297e5cfe77715 520299 b599797746ae8ccf7907cf88de232faa30ec95e6 gas-zhi
5eecdf63e85833e712a1ff88df1341bbf32f4ab8 Strive 2d672d7818a56029b337e8792935195d53576a9d jjlk
bd308f4d1a32096a3b90cfdae45bbc5c13e5e801 R0916
b1be4b2f874c8309f553acce90287c8c6bb2b6b1 frsl.1ply
21ffd24b8074d7cffdf4cc339d1fa8fe892eba27 Wdv
8fbec09e646311a285aee06b3dd45ccf58928703 intz726
19921cc47b3de003186e65fd12b82235030f060d 122764
0f70251abc8c64cbc7b24995c3d32927514d0a4b V20180224
149947544ca4f7baa5bc3d00b080d0e943d8036b SOE
e7f5a33b33e023a82ac9eee6ed40e4a38ce95277 int815
b4790eec7daa9f931bed43a53f66168b477599a7 UOE
ab660a3ac46d563c756463bd1b64cc45f347a1f7 B.Z11NOV20D
d0181759a175fbcc60975983b351f88970f484f9 299520
7a63fc9db2bc1e9b1ef793723d5877e6b4c566b8 WinVideo
13779006d0dafbe4b27bd282230df299eef2b8dc SSLSSL
f53c77695a162c78c68f693f57f65752d17f6030 int007server
924341cab6106ef993b506193e6786e459936069 intl1211
8ebf78c84cd7f66ca8708467a28d83658bcf6710 intl821
f2856d7d138430e164f83662e251ee311950d83c intl821

, TEST test.

BackDoor.Logtu.1 (9ea2488f07bf3edda23d9b7759c2d0c3c8501f92):

#drweb

BackDoor.Mirkoceen.11 (81bb895a833594013bc74b429fb1f24f9ec9df26):

#drweb

, :

  • ;
  • ;
  • .

, . APT- 2017 .

. , .

, . , . . , . .

http://feedproxy.google.com/~r/drweb/viruses/~3/IYUfcdnNHag/


: [1] []
 

:
: 

: ( )

:

  URL