細節描述: |
該後門程式以其他惡意軟體丟棄的文件或用戶訪問惡意站點時在不知不覺中下載的文件的形式到達系統。
安裝它會放置下列檔案:
-
- %User Temp%\pyclient.cmd → Detected as
Backdoor.BAT.DEVILSHADOW.THEAABO
- %User Temp%\cmd_shell.exe → Detected
as?Trojan.Win32.DEVILSHADOW.THEAABO
- %User Profile%\boot-startup.vbs → Detected as
Trojan.BAT.DEVILSHADOW.THEAABO
- %User Profile%\new_script.txt → Detected as
Trojan.JS.DEVILSHADOW.THEAABO
- %User Profile%\shell.bat → Detected as
Trojan.BAT.DEVILSHADOW.THEAABO
- %User Temp%\zoom.exe → Legitimate Zoom Installer
- %User Profile%\node.exe → Legitimate node.exe
- %System Root%\botnet\client_id_file → contains generated_id
- %System Root%\botnet\bot_id_{Generated ID} {Hostname} {IP
Address} {Client} → Client Identifier
- %System Root%\botnet\botnet_start.vbs
- %System Root%\botnet\wget.js
- %System Root%\botnet\pyclient.cmd → Copy of the one in
%User Temp%
- %System Root%\botnet\scexec-win32.exe
- %System Root%\botnet\scexec-win64.exe
- %System Root%\botnet\Rar.exe
- %System Root%\botnet\K7firewall.exe
- %System Root%\botnet\unzip.exe
- %System Root%\botnet\webcam.exe
- %System Root%\botnet\execute.vbs
- %User Temp%\av → contains result of Anti-Virus Query
-
- %System%\cmd.exe /c %User Temp%\pyclient.cmd
- %System%\cmd.exe /c %User Temp%\cmd_shell.exe
- %System%\cmd.exe /c %User Temp%\zoom.exe
- %System%\cmd.exe /c cd %userprofile% & attrib +s +h +a
*.vbs & attrib +s +h +a *.bat & reg add
Hkey_CURRENT_USER\software\microsoft\windows\currentversion\run /v
bootstartup /t reg_sz /d %userprofile%\boot-startup.vbs /f &
shell.bat
- %System%\cmd.exe /c “Tasklist /FI WINDOWTITLE eq D3ViL
ShaDow”
- %System%\cmd.exe /c “Tasklist /FI WINDOWTITLE eq
Administrator: D3ViL ShaDow”
- %System%\cmd.exe attrib +s +h +a %System Root%\botnet
- %System%\cmd.exe copy /y %User Temp%\pyclient.cmd %System
Root%\botnet\pyclient.cmd
- %System%\cmd.exe reg add
hkcu\software\microsoft\windows\currentversion\run /v botnet /t reg_sz
/d C:\botnet\botnet_start.vbs /f
- %System%\cmd.exe ping www.google.com -n 1
- %System&\cmd.exe unzip.exe -ox python_client.zip
- %System%\cmd.exe %System%\WScript.exe %System
Root%\botnet\botnet_start.vbs
- %System%\cmd.exe copy /y %System%\cmd.exe
%Public%\explorer.exe
- %System%\cmd.exe %User Profile%\node.exe new_script.txt
- %Public%\explorer.exe
- %System&\cmd.exe wmic /namespace:\root\securitycemter2
path antivirusproduct GET displayName, productState,
pathToSignedProductExe
-
- 自動啟動技術它會新增下列登錄項目,使其在每次系統啟動時自動執行:
-
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runbootstartup
= %User Profile%\boot-startup.vbs
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runbotnet
= %System Root%\botnet\botnet_start.vbs
-
- 後門程式程序它會執行遠端惡意使用者指定的下列命令:
-
- Update/Reset/Terminate Client (Self)
- Load Client Modules (Self)
- Log Keystrokes
- Take Screenshots
- Record Desktop
- Operate Webcam
- Operate CMD
- Install Programming Languages
- Download/Upload/Execute Files
- Install and Operate Ngrok
- Install and Operate WinVNC
- List and Modify AutoStart Registries
- List, Add and Start Scheduled Tasks
- Check and Elevate User Privileges
- Execute Shellcode and Scripts
- Harvest the Following Information:
- Process List
- Drive List
- Directories and Files List
- System Info
- Startup Items
- AntiVirus Info
- Locally Stored Credentials
-
- https://hosting303.{BLOCKED}hostapp.com
- madleets.{BLOCKED}s.net:4444
- https://raw.{BLOCKED}usercontent.com/DevilBot000/Tools/master/unzip.exe
→ %System Root%\botnet\unzip.exe
- https://raw.{BLOCKED}usercontent.com/DevilBot000/Tools/master/python_client.zip
→ %System Root%\botnet\python_client.zip
|