СÐÄ£º½üÆÚÕë¶Ôµç×ÓÔªÆ÷¼þÐÐÒµµÄ¹¥»÷»î¶¯ÆÊÎö

Ðû²¼Ê±¼ä 2021-09-13

Ò»¡¢¸ÅÊö


½üÆÚ£¬£¬£¬£¬ £¬ £¬c7c7ÓéÀÖÆ½Ì¨ADLab²¶»ñµ½¶àÆðÕë¶Ôµç×ÓÔªÆ÷¼þÆóÒµµÄ´¹ÂÚÓʼþ¹¥»÷»î¶¯£¬£¬£¬£¬ £¬ £¬¹¥»÷Ä¿µÄÉæ¼°¶à¼Òµç×ÓÔªÆ÷¼þÐÐÒµµÄÉÏÊй«Ë¾»òÉÏÏÂÓι©Ó¦ÉÌ£¬£¬£¬£¬ £¬ £¬°üÀ¨ÌìÂí΢µç×ӹɷÝÓÐÏÞ¹«Ë¾£¨ÖйúÉîÛÚ£©¡¢ºëÒä¹ú¼Ê¹É·ÝÓÐÏÞ¹«Ë¾£¨Öйų́Í壩¡¢questcomp£¨ÃÀ¹ú¼ÓÀû¸£ÄáÑÇ£©¡¢axitea£¨Òâ´óÀûÃ×À¼£©µÈ¡£¡£¡£¡£¹¥»÷ÕßÒÔ¡°Dretax.inc-Ryan Osborn -INV -034708182958- 2021.24.08¡±¡¢¡°Dretax.inc-Alissa Chung -INV -420511295810- 2021.24.08¡±µÈÐéαµÄ·¢Æ±Æ±¾ÝΪÓʼþÎÊÌâÌᳫÓã²æÊ½´¹ÂÚ¹¥»÷²¢½øÒ»²½ÏòÄ¿µÄ×°±¸Ö²ÈëDridexľÂí£¬£¬£¬£¬ £¬ £¬¹¥»÷ÖÐʹÓÃÁ˺êÒþ²Ø¡¢¶à²ãLoader»ìÏý¼ÓÃÜ¡¢API¶¯Ì¬»ñÈ¡¡¢APIÏòÁ¿Òì³£´¦Öóͷ£Å²ÓõȶàÖÖÊÖÒÕÊֶζԿ¹ÆÊÎö£¬£¬£¬£¬ £¬ £¬Í¬Ê±Æä»ØÁ¬µÄÍøÂç»ù´¡ÉèÊ©¾ù½ÓÄÉCDNºÍP2PÊðÀí½ÚµãÀ´¹æ±Ü×·×ÙÓë¼ì²â¡£¡£¡£¡£


DridexÊÇÒ»¿îÒÔÇÔÈ¡ÒøÐÐÕË»§Æ¾Ö¤ÎªÄ¿µÄ£¬£¬£¬£¬ £¬ £¬¼¯½©Ê¬¡¢ÇÔÃÜľÂí¡¢ÓʼþÈ䳿¡¢ÀÕË÷Èí¼þµÈÖڶ๦ЧÓÚÒ»ÌåµÄ×ÛºÏÐÔÈ䳿²¡¶¾£¬£¬£¬£¬ £¬ £¬ÓÉÓÚÆäÓµÓÐÖØ´óµÄP2P¿ØÖÆ»úÖÆ¡¢¶à²ãÊðÀí¡¢¿ìËÙ±äÒì¡¢ÄÚÍâÍøË«ÇþµÀѬȾ¡¢RSA-AESͨѶ¼ÓÃܵÈÌØµã£¬£¬£¬£¬ £¬ £¬Êܹ¥»÷ÆóÒµÒ»µ©ÖÐÕУ¬£¬£¬£¬ £¬ £¬¿ÉÄÜÒýÆðÄÚÍøÀ©É¢Ñ¬È¾²¢½øÒ»²½Ôì³ÉʧйÃÜ¡¢ÔâÊÜÀÕË÷¹¥»÷¡¢Éú²úÏßÍ£°ÚµÈÑÏÖØµÄЧ¹û¡£¡£¡£¡£


Ëæ×Å¡¶Êý¾ÝÇå¾²·¨¡·µÄÕýʽʵÑ飬£¬£¬£¬ £¬ £¬È«ÐÐÒµ¡¢È«ÁìÓò¶¼»áÊÜÖ®Ó°Ï죬£¬£¬£¬ £¬ £¬ÐèÒª½¨ÉèÍêÉÆµÄÊý¾ÝÇå¾²Õ½ÂÔ¡£¡£¡£¡£µç×ÓÔªÆ÷¼þ¼°°ëµ¼ÌåÐÐÒµ×÷ΪÎÒ¹ú¡°Ê®ËÄÎ塱¶¦Á¦´ó¾ÙÉú³¤µÄÕ½ÂÔÐÂÐ˹¤Òµ£¬£¬£¬£¬ £¬ £¬ÊÇÖ§³ÖÄ¿½ñ¾­¼ÃÉç»áÉú³¤ºÍ°ü¹Ü¹ú¼ÒÇå¾²µÄÕ½ÂÔÐÔ¡¢»ù´¡ÐÔºÍÏȵ¼ÐÔ¹¤Òµ£¬£¬£¬£¬ £¬ £¬Æä¹¤ÒµÁ´Çå¾²ÎȹÌÒâÒåÖØ´ó¡£¡£¡£¡£ºÚ¿Í×éÖ¯Ò»µ©Í¨¹ýÍøÂç¹¥»÷ÈëÇÖµ½Ïà¹ØÆóÒµÄÚ²¿£¬£¬£¬£¬ £¬ £¬Ò»·½Ãæ»áÑÏÖØÍþвµ½ÎÒ¹ú×ÔÖ÷¿É¿ØµÄ¹¤ÒµÁ´Çå¾²ºÍÊý¾ÝÇå¾²£»£»£»ÁíÒ»·½ÃæÒ²¿ÉÄÜÒòÀÕË÷¹¥»÷¡¢Éú²úÏßÖÐÖ¹µÈÔì³ÉÖØ´óµÄ¾­¼ÃËðʧ¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬ £¬ £¬c7c7ÓéÀÖÆ½Ì¨ADLabÌáÐÑÓйص¥Î»¡¢ÆóÓªÒµ±ØÖØÊÓ´ËÀàÍøÂç¹¥»÷»î¶¯²¢ÊµÊ±¾ÙÐÐÇå¾²Ìá·À¡£¡£¡£¡£


¶þ¡¢¹¥»÷ÍþвÆÊÎö


2.1 µç×ÓÔªÆ÷¼þÆóҵƵÔâÍøÂç¹¥»÷

´Ë´Î¹¥»÷»î¶¯Ãé×¼Á˵ç×ÓÔªÆ÷¼þÐÐÒµµÄÏà¹ØÆóÒµ£¬£¬£¬£¬ £¬ £¬ÎÒÃÇÊӲ쵽£¬£¬£¬£¬ £¬ £¬½üÄêÀ´µç×ÓÔªÆ÷¼þ½øÈë¡°ÕÇ¼ÛÆÚ¡±£¬£¬£¬£¬ £¬ £¬Í¬Ê±ÒßÇéµÄ±¬·¢ÓÖ¼ÓËÙÍ»ÆÆÁ˹¤ÒµÁ´µÄ¹©ÐèÆ½ºâ£¬£¬£¬£¬ £¬ £¬Ôì³Éµç×Ó¹©Ó¦Á´²úÆ·Çó¹ýÓÚ¹©£¬£¬£¬£¬ £¬ £¬¼ÛÇ®·èÕÇ¡£¡£¡£¡£Ò»Ð©ºÚ¿Í×éÖ¯ÒÔ´ËΪÆõ»ú£¬£¬£¬£¬ £¬ £¬Ò»ÔÙÕë¶Ôµç×ÓÔªÆ÷¼þÐÐÒµÕö¿ªÍøÂç¹¥»÷´Ó¶øÄ²È¡¸ß¶îÀûÒæ£¬£¬£¬£¬ £¬ £¬ÎÒÃÇͳ¼ÆÁ˽üÒ»ÄêÀ´µç×ÓÔªÆ÷¼þÐÐÒµÔâÊÜÍøÂç¹¥»÷µÄ²¿·ÖÇå¾²ÊÂÎñÈçͼ1Ëùʾ¡£¡£¡£¡£


µç×ÓÔªÆ÷¼þÐÐÒµÔâÊÜÍøÂç¹¥»÷ÊÂÎñ.jpg


ͼ1 ½üÒ»Äêµç×ÓÔªÆ÷¼þÐÐÒµÔâÊÜÍøÂç¹¥»÷ÊÂÎñ


¿ÉÒÔ¿´µ½£¬£¬£¬£¬ £¬ £¬Õë¶Ôµç×ÓÔªÆ÷¼þÐÐÒµµÄ¹¥»÷·½·¨Ö÷Òª¼¯ÖÐÔÚ¼ÓÃÜÊý¾ÝÀÕË÷¡¢Êý¾Ý×ß©ÀÕË÷¡¢¾Ü¾øÐ§À͹¥»÷ÀÕË÷£¨µ¼ÖÂÉú²úÏßЪ¹¤£©µÈ¡£¡£¡£¡£2020Äê7Ô£¬£¬£¬£¬ £¬ £¬È«ÇòÁìÏȵľ§Ô²´ó³§X-FABÐû²¼Í¨¸æ³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬ £¬ £¬µ¼ÖÂËùÓÐITϵͳºÍÆä6¸öÉú²ú»ùµØ¾ù×èÖ¹ÊÂÇ飻£»£»8ÔÂSKº£Á¦Ê¿¡¢LGµç×ÓÔâµ½MazeÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ £¬ £¬µ¼Ö²¿·ÖÖ°Ô±µÄ´ó×Ú×ÊÁÏй¶£¬£¬£¬£¬ £¬ £¬ÇÒSKº£Á¦Ê¿±»ºÚµÄÎļþÖл¹°üÀ¨ÓëÆ»¹û¡¢IBMµÈ¿Í»§¹«Ë¾µÄ´æ´¢Ð¾Æ¬¼ÛǮЭÉÌÓʼþ£»£»£»9Ô£¬£¬£¬£¬ £¬ £¬ÒÔÉ«ÁÐоƬ¾ÞÍ·TowerJazzͻȻÔâÊÜÍøÂç¹¥»÷£¬£¬£¬£¬ £¬ £¬µ¼Ö²¿·ÖϵͳЧÀÍÆ÷ºÍÖÆÔ첿·ÖÔÝÍ£ÔËת£¬£¬£¬£¬ £¬ £¬ÆÈÓÚÉú²úÏßЪ¹¤µÄѹÁ¦£¬£¬£¬£¬ £¬ £¬ÆäÏòºÚ¿ÍÖ§¸¶ÁËÊýÊ®ÍòÃÀÔªµÄ¡°±£ÊÍ·Ñ¡±£¬£¬£¬£¬ £¬ £¬ÒÔ»»È¡ºÚ¿Í¶ÔЧÀÍÆ÷×èÖ¹¹¥»÷£»£»£»12Ô£¬£¬£¬£¬ £¬ £¬¸»Ê¿¿µÄ¸¹«Ë¾ºèº£¼¯ÍÅλÓÚÄ«Î÷¸çµÄ¹¤³§ÔâÓöÀÕË÷Èí¼þ¡°DoppelPaymer¡±¹¥»÷¡£¡£¡£¡£ºÚ¿ÍÇÔÈ¡²¢¼ÓÃÜÁ˲¿·ÖÎļþÊý¾Ý£¬£¬£¬£¬ £¬ £¬²¢ÒªÇó¹«Ë¾Ö§¸¶1804ö±ÈÌØ±ÒÒÔ»ñÈ¡½âÃܹ¤¾ß£¨Æ¾Ö¤µ±ÌìÊм۸ߴï3450ÍòÃÀÔª£©£»£»£»½ñÄê3Ô£¬£¬£¬£¬ £¬ £¬È«Çò×ÅÃûµçÄÔÖÆÔìÉ̺ê»ùÔâÓöREvilÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ £¬ £¬²¢±»Ë÷Òª5000ÍòÃÀÔªÊê½ð£¨Ô¼3.3ÒÚÈËÃñ±Ò£©£¬£¬£¬£¬ £¬ £¬´´ÏÂ×î¸ßÀÕË÷Èí¼þÊê½ð¼Í¼¡£¡£¡£¡£½ñÄê8Ô£¬£¬£¬£¬ £¬ £¬ÎÒÃÇ·¢Ã÷ºÚ¿Í×éÖ¯ÓÖÔÚĦȭ²ÁÕÆ£¬£¬£¬£¬ £¬ £¬×îÏÈÕë¶Ô¶à¼Òµç×ÓÔªÆ÷¼þÆóÒµÌᳫ´¹ÂÚÓʼþ¹¥»÷»î¶¯¡£¡£¡£¡£ºóÎÄÒ²½«Õë¶Ô´Ë´Î¹¥»÷»î¶¯¾ÙÐÐÉîÈëµÄÆÊÎöºÍÏÈÈÝ¡£¡£¡£¡£


2.2 ´Ë´Î¹¥»÷Ä¿µÄ


c7c7ÓéÀÖÆ½Ì¨ADLabͨ¹ý¶Ô´Ë´Î¹¥»÷»î¶¯¾ÙÐÐËÝÔ´ÓëÆÊÎö¹ØÁª£¬£¬£¬£¬ £¬ £¬ÕûÀí³ö²¿·Ö¹¥»÷ÕßʹÓõĴ¹ÂÚÓʼþ£¬£¬£¬£¬ £¬ £¬ÓʼþÐÅÏ¢¼û±í1¡£¡£¡£¡£


´¹ÂÚÓʼþ.jpg


±í1 ÓʼþÐÅÏ¢


ÔÚ½øÒ»²½ÆÊÎöºó£¬£¬£¬£¬ £¬ £¬ÎÒÃÇ·¢Ã÷¹¥»÷ÕßʹÓÃÁ˶¨ÖƵĴ¹ÂÚÓʼþÄ£°å¾ÙÐз¢Æ±Àà´¹ÂÚÓʼþµÄ×Ô¶¯»¯ÌìÉúºÍ¹¥»÷£¬£¬£¬£¬ £¬ £¬²¢Õë¶ÔÓʼþÖÐÉæ¼°·¢ËÍÈË¡¢·¢Æ±ÐòºÅ¡¢·¢Æ±ÈÕÆÚµÈÄÚÈݾÙÐÐÁËËæ»ú»¯´¦Öóͷ£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬ £¬ £¬·¢¼þÈ˵ÄÓÊÏäºó׺±»È«ÐÄαװ³ÉÓ뷢Ʊ¡¢¶©µ¥Ïà¹ØµÄÄÚÈÝ£¬£¬£¬£¬ £¬ £¬ÀýÈçpayment.dretax.com¡¢invoice.dretax.com¡¢order.dretax.com¡¢mail.dretax.com£¬£¬£¬£¬ £¬ £¬ÓʼþÎÊÌâÓ븽¼þÃûÒ²¾ùͨ¹ý¹«Ë¾Ãû£¨Dretax.inc£©¡¢INV£¨invoiceËõд£¬£¬£¬£¬ £¬ £¬ÒëΪ·¢Æ±£©¡¢ÈÕÆÚ¡¢±àºÅ£¨Ëæ»úÌìÉú£©¡¢·¢¼þÈËÃû£¨Ëæ»úÌìÉú£©µÈ¾ÙÐÐ×éºÏαװ£¬£¬£¬£¬ £¬ £¬´¹ÂÚÓʼþÈçͼ2Ëùʾ¡£¡£¡£¡£


´¹ÂÚÓʼþ-ͼʾ.png


ͼ2 ´¹ÂÚÓʼþ


´Ë´Î¹¥»÷Éæ¼°µÄÄ¿µÄ¾ùΪµç×ÓÔªÆ÷¼þÐÐÒµµÄÏà¹Ø¹«Ë¾£¬£¬£¬£¬ £¬ £¬°üÀ¨ÌìÂí΢µç×ӹɷÝÓÐÏÞ¹«Ë¾¡¢ºëÒä¹ú¼Ê¹É·ÝÓÐÏÞ¹«Ë¾¡¢questcomp¡¢axiteaµÈ£¬£¬£¬£¬ £¬ £¬ÓÉÓںڿͲ¢Ã»ÓÐÒÔÌØ¶¨¹ú¼ÒΪ¹¥»÷Ä¿µÄ£¬£¬£¬£¬ £¬ £¬ÒÔÊÇÎÒÃÇÒÔΪÕâÊÇÒ»ÆðÆÕ±éÕë¶Ôµç×ÓÔªÆ÷¼þÐÐÒµµÄ¹¥»÷Ðж¯£¬£¬£¬£¬ £¬ £¬ºÚ¿Í×éÖ¯µÄ½¹µãÄ¿µÄ¿ÉÄÜÊÇÇÔÈ¡µç×ÓÔªÆ÷¼þ¹«Ë¾µÄÉñÃØÊý¾Ý»òÊÖÒÕ×ÊÁÏ£¬£¬£¬£¬ £¬ £¬Í¬Ê±¿ÉÄܽøÒ»²½Í¨¹ý¼ÓÃÜÊý¾ÝÀÕË÷¡¢Êý¾Ý×ß©ÀÕË÷¡¢Ëø¶¨ÏµÍ³ÀÕË÷µÈÊÖ¶ÎÀ´Ä²È¡¸ü¶àµÄ¾­¼ÃÀûÒæ¡£¡£¡£¡£´Ë´Î»î¶¯Éæ¼°µÄ²¿·Ö¹¥»÷Ä¿µÄÐÅÏ¢Èç±í2Ëùʾ¡£¡£¡£¡£


¹¥»÷Ä¿µÄ.jpg


±í2 ¹¥»÷Ä¿µÄÐÅÏ¢


Èý¡¢ÊÖÒÕÆÊÎö


Ôڴ˴ι¥»÷»î¶¯ÖУ¬£¬£¬£¬ £¬ £¬¹¥»÷Õß½«´øÓжñÒ⸽¼þµÄ´¹ÂÚÓʼþͶµÝÖÁµç×ÓÔªÆ÷¼þÆóÒµÔ±¹¤£¬£¬£¬£¬ £¬ £¬Ò»µ©´¹ÂÚÍýÏëÀֳɣ¬£¬£¬£¬ £¬ £¬¶ñÒâºê»áÊͷŲ¢Ö´ÐÐVBScript¾ç±¾£¬£¬£¬£¬ £¬ £¬¸Ã¾ç±¾ÊÇÒ»¸öÏÂÔØÆ÷£¬£¬£¬£¬ £¬ £¬ÊµÑéͨ¹ý̸ÌìÈí¼þDiscordµÄCDNЧÀÍÏÂÔØºÚ¿ÍÍйܵĶñÒâDLLÎļþ£¬£¬£¬£¬ £¬ £¬Í¬Ê±»áÊÍ·ÅÁíÒ»¸öVBScript½ÅÔ­À´¼ÓÔØ¸Ã¶ñÒâDLL¡£¡£¡£¡£¼ÓÔØµÄDLLʵÔòΪDridexľÂíLoader£¬£¬£¬£¬ £¬ £¬ÆäʹÓÃÁ˶à²ã´ò°üµÄ·½·¨¾ÙÐÐÏ·¢£¬£¬£¬£¬ £¬ £¬ÔÚÄÚ´æÖо­ÓÉ2´Î½âÃÜÊÍ·ÅLoaderºó×îÖÕ´ÓC&CЧÀÍÆ÷ÏÂÔØÖ´ÐÐDridexľÂí£¬£¬£¬£¬ £¬ £¬²¢½øÒ»²½ÅþÁ¬ÖÁDridexµÄP2PÊðÀíÍøÂçÖ´ÐжñÒâ²Ù×÷¡£¡£¡£¡£


ÏÂͼչʾÁ˴˴ι¥»÷»î¶¯ÍêÕûµÄÁ÷³Ì£º 


¹¥»÷Á÷³Ìͼ.jpg


ͼ3 ¹¥»÷Á÷³Ìͼ


3.1 ÓÕ¶üÓʼþͶµÝ


¹¥»÷ÕßαװÁ˶à·âÒÔDretax¹«Ë¾£¨ÃÀ¹úÎ÷Èø¿ËÀ­ÃÅÍУ©»á¼ÆÖ°Ô±Îª·¢¼þÈ˵Ĵ¹ÂÚÓʼþ£¬£¬£¬£¬ £¬ £¬ÓʼþÖ÷Ìâ¾ùÓë¡°·¢Æ±ÐÅÏ¢¡±ÓйØ£¬£¬£¬£¬ £¬ £¬ÒÔͼ4ÓʼþΪÀý£¬£¬£¬£¬ £¬ £¬ÊÕ¼þÈËΪÎÒ¹úÌìÂí΢µç×ӹɷÝÓÐÏÞ¹«Ë¾ÃûΪ¡°panpan_cao¡±µÄÔ±¹¤¡£¡£¡£¡£ÓʼþÕýÎÄÖмòÆÓÐÎòÁË·¢Æ±ÐÅÏ¢¼°¿ª¾ß·¢Æ±µÄ»á¼Æ²¿·ÖµÄÁªÏµ·½·¨£¬£¬£¬£¬ £¬ £¬²¢ÌáÐѱ£´æËù¸½µÄ·¢Æ±¡£¡£¡£¡£


 ´¹ÂÚÓʼþ.png


ͼ4 ´¹ÂÚÓʼþ


Óʼþ¸½¼þÊÇÒ»·ÝαװµÄ8Ô·¢Æ±µ¥£¬£¬£¬£¬ £¬ £¬´ÓÓÕ¶üÎĵµ·­¿ªºóµÄÄÚÈÝ£¨Èçͼ5£©À´¿´£¬£¬£¬£¬ £¬ £¬Excel±í¸ñ½ö°üÀ¨Ò»ÕÅͼƬ£¬£¬£¬£¬ £¬ £¬ÄÚÈÝ´óÒâΪ£º¡°´ËÎĵµÊÇÓÉMicrosoft office excelµÄÔçÆÚ°æ±¾½¨É裬£¬£¬£¬ £¬ £¬ÇëÆôÓúêÑ¡ÏîÒÔÏÔʾÎĵµÄÚÈÝ¡±¡£¡£¡£¡£Ò»µ©Êܺ¦Õß±»ÓÕÆ­ÆôÓúêÑ¡Ï£¬£¬£¬ £¬ £¬¶ñÒâºê´úÂë±ã»áÁ¬Ã¦Ö´ÐС£¡£¡£¡£


¶ñÒâÓʼþ.jpg


ͼ5 ¶ñÒâµÄÓʼþ¸½¼þ

3.2 ¶ñÒâºê´úÂëÖ´ÐÐ


ºê´úÂë±»Òþ²ØÔÚÊÂÇé²¾µÄ±í¸ñµ±ÖУ¬£¬£¬£¬ £¬ £¬Ä¬ÈÏ·­¿ªExcelÖ»ÄÜ¿´µ½±íSheet1£¨±íMacro1±»Òþ²Ø£©£¬£¬£¬£¬ £¬ £¬µ±µã»÷¡°ÆôÓúꡱºó£¬£¬£¬£¬ £¬ £¬ÓÉÓÚ±íµÄ״̬±»Òþ²ØÈÔÎÞ·¨¿´µ½£¬£¬£¬£¬ £¬ £¬¿ÉÒÔͨ¹ýÓÒ¼üµ¥»÷Ö÷±íÑ¡Ï×÷·ÏÒþ²ØÑ¡Ïî¡£¡£¡£¡£


´úÂëÖ´ÐÐͼ.png


ͼ6 ×÷·ÏÒþ²ØµÄÊÂÇé±í


´Ëʱ¿ÉÒÔÔÚ±íMacro1Öп´µ½¶ñÒâºê´úÂ룬£¬£¬£¬ £¬ £¬¸Ã¶ñÒâ´úÂë±»»ìÏýºó²ð·ÖÖÁ¶à¸ö±í¸ñÖд洢¡£¡£¡£¡£Óë³£¼ûµÄºê´úÂëÒþ²Ø·½·¨²î±ð£¬£¬£¬£¬ £¬ £¬´ËÀàÒþ²ØÊÖÒÕÎÞ·¨ÔÚVBAProjectÖп´µ½ºê´úÂ룬£¬£¬£¬ £¬ £¬Äܹ»ÔÚÒ»¶¨Ë®Æ½ÉÏ×ÌÈÅÇå¾²ÆÊÎö¡£¡£¡£¡£


½«xlsmÎļþ½âѹËõ£¬£¬£¬£¬ £¬ £¬Í¬Ñù¿ÉÒÔÔÚÆäÖÐ\xl\macrosheets\sheet1.xmlµÄλÖ÷¢Ã÷¸ÃÒþ²ØµÄ¶ñÒâºê´úÂë¡£¡£¡£¡£


Òþ²Ø´úÂë.jpg


ͼ7 Òþ²ØµÄºê´úÂë


¹¥»÷Õß½«¶ñÒâ´úÂëÒÔ10½øÖÆ×Ö·ûµÄÐÎʽ´æ´¢ÔÚµ¥Î»¸ñÄÚ£¨Ã¿¸ö×Ö·û´æ´¢ÔÚ×ÔÁ¦µÄµ¥Î»¸ñÖУ©£¬£¬£¬£¬ £¬ £¬ÏÖʵִÐÐʱͨ¹ýExcelµÄCHAR()º¯Êýת»»Îª×Ö·û´®´úÂëºóÔÙ½øÒ»²½¼ÓÔØ£¬£¬£¬£¬ £¬ £¬´Ó¶øµÖ´ï»ìÏýºÍ¶Ô¿¹Çå¾²¼ì²âµÄÄ¿µÄ¡£¡£¡£¡£½«¾ç±¾È¥»ìÏýºó£¬£¬£¬£¬ £¬ £¬´úÂëµÄÕûÌåŲÓÃÂß¼­Èçͼ8Ëùʾ¡£¡£¡£¡£


´úÂëŲÓÃÂß¼­.jpg


ͼ8 ´úÂëŲÓÃÂß¼­


¶ñÒâ´úÂë»á½¨Éè¡°C:\ProgramData\veqxg.sct¡±Îļþ£¬£¬£¬£¬ £¬ £¬²¢½«J162ÖÁS604µ¥Î»¸ñÄÚµÄÊýÖµÄÚÈÝ£¨Èçͼ9£©×ª»¯ÎªCHARÖµºóдÈëÆäÖУ¬£¬£¬£¬ £¬ £¬È»ºóͨ¹ýÏÂÁîEXEC (MSHTA C:\ProgramData\veqxg.sct)Ö´ÐÐveqxg.sctÎļþ¡£¡£¡£¡£


¶ñÒâ´úÂë.png


ͼ9 ¶ñÒâ´úÂ루ÿ¸ö×Ö·û´æ´¢ÔÚ×ÔÁ¦µÄµ¥Î»¸ñÖУ©

3.3 ¶ñÒâ¡°sct¡±ÎļþÖ´ÐÐ


veqxg.sctÎļþʵÔòΪVBScript¾ç±¾£¬£¬£¬£¬ £¬ £¬¸Ã¾ç±¾»áÔÚͬĿ¼ÏÂÊÍ·ÅÏÂÒ»½×¶ÎµÄVBScript¾ç±¾vaBlOKVbTNVXMTWIJcdR.sct£¬£¬£¬£¬ £¬ £¬Ö®ºó´ÓЧÀÍÆ÷ÏÂÔØºóÐøµÄ¶ñÒâ´úÂëvaBlOKVbTNVXMTWIJcdR.dll£¬£¬£¬£¬ £¬ £¬ÈôÊÇÏÂÔØÀֳɣ¬£¬£¬£¬ £¬ £¬Ôòͨ¹ývaBlOKVbTNVXMTWIJcdR.sct¾ç±¾Ö´ÐкóÐøµÄ¶ñÒâDLL¡£¡£¡£¡£


veqxg.sct¾ç±¾.jpg


ͼ10 veqxg.sct¾ç±¾

ÏÂÔØÁ´½ÓÈç±í3Ëùʾ£º


¶ñÒâDLLÏÂÔØÁ´½Ó.png


¶ñÒâDLLÏÂÔØÁ´½Ó

vaBlOKVbTNVXMTWIJcdR.sct¾ç±¾»á½øÒ»²½Í¨¹ýrundll32.exe Ö´ÐжñÒâDLL£¨²ÎÊýΪCPGenRandom)£¬£¬£¬£¬ £¬ £¬¾­Ì«¹ýÎö£¬£¬£¬£¬ £¬ £¬¸Ã¶ñÒâDLLÊÇDridexľÂíµÄLoader£¬£¬£¬£¬ £¬ £¬ÏÂÎÄÎÒÃǽ«¶ÔDridexľÂí¼°ÆäLoader¾ÙÐÐÏêϸµÄÆÊÎöºÍÏÈÈÝ¡£¡£¡£¡£



¾ç±¾ÐÅÏ¢.png


ͼ11 vaBlOKVbTNVXMTWIJcdR.sct¾ç±¾


3.4 DridexľÂíÆÊÎö


´Ë´ÎµÄDridexʹÓÃÁ˶à²ã´ò°üµÄ·½·¨¾ÙÐÐÏ·¢£¬£¬£¬£¬ £¬ £¬µÚÒ»²ãLoaderÖ´Ðк󣬣¬£¬£¬ £¬ £¬»áʹÓÃshellcodeÔÚÄÚ´æÖнâÃܳöµÚ¶þ²ãLoaderÀ´Ö´ÐУ¬£¬£¬£¬ £¬ £¬µÚ¶þ²ãLoaderÔÙÈ¥¹¥»÷Õß¿ØÖƵÄC&CЧÀÍÆ÷ÏÂÔØDridexľÂí¡£¡£¡£¡£ÕâÁ½¸öLoaderʹÓÃÁ˶¯Ì¬º¯Êý»ñÈ¡ºÍÏòÁ¿Òì³£´¦Öóͷ£À´Å²ÓÃϵͳº¯Êý£¬£¬£¬£¬ £¬ £¬´Ó¶øÌÓ±ÜÇå¾²Èí¼þµÄ²éɱºÍ×ÌÈÅÇå¾²Ö°Ô±µÄÆÊÎö¡£¡£¡£¡£ÒÔÏÂÊÇÏêϸÆÊÎö£º


3.4.1 µÚÒ»²ãLoaderÆÊÎö

¸ÃLoaderµÄ´úÂë¾­ÓÉÁËÕûÊýÔËËã²Ù×÷»ìÏý£¬£¬£¬£¬ £¬ £¬Æäͬʱ»¹Ê¹ÓÃÁ˶¯Ì¬º¯ÊýŲÓõÄÊÖÒÕÀ´Ö´ÐÐϵͳAPI£¬£¬£¬£¬ £¬ £¬ÒÔÔöÌí¾²Ì¬ÆÊÎöµÄÄѶÈ£¬£¬£¬£¬ £¬ £¬ÏÂͼÊǸÃLoaderÔÚIDAÖеIJ¿·Öα´úÂ룺


Loaderµ¼³öº¯Êýα´úÂë.png


ͼ12 Loaderµ¼³öº¯Êýα´úÂë


ÎÒÃÇÁ¬Ïµ¶¯Ì¬µ÷ÊÔÆÊÎö£¬£¬£¬£¬ £¬ £¬·¢Ã÷¸ÃLoaderµÄÄ¿µÄÊÇÔÚÄÚ´æÖнâÃÜÖ´ÐÐÒ»¸öPEÎļþ¡£¡£¡£¡£Õâ¸öÀú³Ìͨ¹ýÁ½½×¶ÎµÄshellcodeÍê³É£º


µÚÒ»½×¶ÎµÄshellcode±»¼ÓÃÜÉúÑÄÔÚ¸ÃLoaderµÄ.rdata¶Î£¬£¬£¬£¬ £¬ £¬LoaderÖ´Ðк󣬣¬£¬£¬ £¬ £¬½«.rdata¶ÎµÄshellcode½âÃܺóдµ½.data¶Î£¬£¬£¬£¬ £¬ £¬È»ºó¶¯Ì¬Å²ÓÃVirtualProtectº¯Êý½«.data¶ÎµÄ¶ÔÓ¦shellocdeÊôÐÔÐÞ¸ÄΪ¿É¶Á¿Éд¿ÉÖ´ÐУ¬£¬£¬£¬ £¬ £¬ÈçÏÂͼËùʾ£º


shellocde.png


ͼ13 ÐÞ¸Ä.data¶ÎµÄÄÚ´æÊôÐÔΪ¿É¶Á¿Éд¿ÉÖ´ÐÐ


Ö®ºó£¬£¬£¬£¬ £¬ £¬loader¾ÍÈ¥Ö´ÐÐ.data¶ÎµÄshellcode´úÂ룬£¬£¬£¬ £¬ £¬ÈçÏÂͼËùʾ£º


 data×Ö¶Î.png


 Í¼14 Ö´ÐÐ.data¶ÎµÄshellcode´úÂë


shellcodeµÄ×îÏÈÊÇÒ»¶Î½âÃÜ´úÂ룬£¬£¬£¬ £¬ £¬ÆäÈÏÕæ½«µÚ¶þ½×¶ÎµÄshellcode½âÃܳöÀ´£¨Ñ­»·Òì»ò½âÃÜshellcode£©£¬£¬£¬£¬ £¬ £¬ÈçÏÂͼËùʾ£º


 ½âÃܵڶþ½×¶ÎµÄshellcode.png


 Í¼15 ½âÃܵڶþ½×¶ÎµÄshellcode


½âÃÜÍê³Éºó£¬£¬£¬£¬ £¬ £¬shellcodeÔÙ¶¯Ì¬Å²ÓÃVirtualAllocº¯ÊýÉêÇëÒ»¶ÎÄڴ棬£¬£¬£¬ £¬ £¬½«½âÃܺóµÄµÚ¶þ½×¶ÎshellcodeдÈ뵽ĿµÄÄڴ棬£¬£¬£¬ £¬ £¬Ö®ºóÌø×ªµ½µÚ¶þ½×¶ÎµÄshellcodeÈ¥Ö´ÐУ¬£¬£¬£¬ £¬ £¬ÈçÏÂͼËùʾ£º


Ö´Ðеڶþ½×¶ÎµÄshellcode.png


 Í¼16 Ö´Ðеڶþ½×¶ÎµÄshellcode


µÚ¶þ½×¶ÎµÄshellcodeÖ´Ðк󣬣¬£¬£¬ £¬ £¬»á¶¯Ì¬Å²ÓÃVirtualAllocº¯ÊýÉêÇëÄڴ棬£¬£¬£¬ £¬ £¬½«¼ÓÃÜÊý¾ÝдÈë¸ÃÄÚ´æºó£¬£¬£¬£¬ £¬ £¬ÔÙ½âÃÜÖ´ÐУ¬£¬£¬£¬ £¬ £¬½âÃÜÖ´ÐеÄpayloadΪһDLLÎļþ£¬£¬£¬£¬ £¬ £¬ÈçÏÂͼËùʾ£º


ÄÚ´æÖнâÃܳöµÄDLLÎļþ.png


 Í¼17 ÄÚ´æÖнâÃܳöµÄDLLÎļþ


3.4.2 µÚ¶þ²ãLoaderÆÊÎö


¸ÃDLLͬÑùÊÇÒ»¸öloader£¬£¬£¬£¬ £¬ £¬ÆäÄ¿µÄÊÇ´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØÏÂÒ»½×¶ÎµÄDridexľÂí¡£¡£¡£¡£¸ÃDLLͬÑùʹÓÃÁ˶¯Ì¬º¯ÊýŲÓõķ½·¨¾ÙÐк¯ÊýŲÓ㬣¬£¬£¬ £¬ £¬Ö»Óе±ÐèҪŲÓÃÄ¿µÄº¯Êýʱ£¬£¬£¬£¬ £¬ £¬¶ñÒâ´úÂë²Å»áʹÓÃFS¼Ä´æÆ÷¼ìË÷¶ÔÓ¦º¯ÊýµÄÏÖʵµØµã£¬£¬£¬£¬ £¬ £¬È»ºóʹÓÃint3Ò쳣ŲÓÃÄ¿µÄº¯Êý£¬£¬£¬£¬ £¬ £¬ÈçÏÂͼËùʾ£º


ʹÓÃint3Ò쳣ŲÓÃÄ¿µÄº¯Êý.png


 Í¼18 ʹÓÃint3Ò쳣ŲÓÃÄ¿µÄº¯Êý


ÕâÖÖº¯ÊýŲÓõÄÔ­ÀíÊÇ£¬£¬£¬£¬ £¬ £¬µ±³ÌÐò±¬·¢Òì³£µÄʱ¼ä£¬£¬£¬£¬ £¬ £¬Ò»¹²ÓÐÁ½ÖÖ´¦Öóͷ£Òì³£µÄ·½·¨¡£¡£¡£¡£Ò»ÖÖÊÇSHE£¨Structured Exception Handling£©£¬£¬£¬£¬ £¬ £¬ÁíÒ»ÖÖÊÇVEH£¨Vectored Exception Handling£©¡£¡£¡£¡£¸ÃDLLʹÓÃÁËVEHµÄ·½·¨Å²ÓÃÄ¿µÄº¯Êý£ºÔÚÔËÐеÄ×îÏÈ£¬£¬£¬£¬ £¬ £¬¶ñÒâ´úÂë»á×¢²áÒ»¸öVEH´¦Öóͷ£³ÌÐò£¨ÈçÏÂͼËùʾ£©£¬£¬£¬£¬ £¬ £¬µ±CPUΪINT3Òý·¢Ò쳣ʱŲÓÃÒì³£´¦Öóͷ£³ÌÐòÒÔ¶ÔÄ¿µÄº¯Êý¾ÙÐÐŲÓᣡ£¡£¡£


º¯ÊýÒì³£.png


 Í¼19 ×¢²áÒì³£´¦Öóͷ£º¯Êý

¸ÃDLLÄÚÖÃÓÐ3¸öC&CЧÀÍÆ÷µØµã£¬£¬£¬£¬ £¬ £¬ÈçϱíËùʾ£º


DLLÄÚÖÃÓÐ3¸öC&CЧÀÍÆ÷µØµã.png


¸ÃDLL»áʵÑéÖð¸öºÍÕâЩC&CЧÀÍÆ÷¾ÙÐÐÅþÁ¬£¬£¬£¬£¬ £¬ £¬Ò»µ©ÅþÁ¬½¨ÉèÀֳɣ¬£¬£¬£¬ £¬ £¬DLL¾Í»áŲÓÃHttpSendRequestWº¯ÊýÏòC&CЧÀÍÆ÷»Ø´«Ä¿µÄÇéÐεļÓÃÜÊý¾Ý£¨ÈçÏÂͼËùʾ£©£¬£¬£¬£¬ £¬ £¬Ö®ºó¸ÃDLL»á´ÓC&CЧÀÍÆ÷ÏÂÔØÏÂÒ»½×¶ÎµÄDridexľÂíÖ´ÐС£¡£¡£¡£


»Ø´«µÄ¼ÓÃÜÊý¾Ý.png


 Í¼20 ÏòC&C»Ø´«µÄ¼ÓÃÜÊý¾Ý


3.4.3 Dridex½¹µãľÂí


ÓÉÓÚÎÒÃÇÔÚÆÊÎöµÄʱ¼ä£¬£¬£¬£¬ £¬ £¬µÚ¶þ²ãLoaderÄ¿½ñδÄܽ«Dridex½¹µãÂíÏÂÔØÏÂÀ´Ö´ÐУ¬£¬£¬£¬ £¬ £¬¿ÉÊÇͨ¹ýËÝÔ´·¢Ã÷Ä¿½ñLoaderÕýÊÇDridex V4ËùʹÓõÄLoader£¬£¬£¬£¬ £¬ £¬×Ô¼ºDridex½¹µãÂí²¢Î´±¬·¢½Ï´óת±ä£¬£¬£¬£¬ £¬ £¬Æä×îÖ÷Òª¹¥»÷ÄÜÁ¦Ö÷ÒªÌåÏÖÔÚÆäÇ¿¶È¶øÎÞаµÄ²å¼þÊÖÒÕÉÏ¡£¡£¡£¡£ÐµĹ¥»÷ÖÐËù½ÓÄɵĶñÒâÓÕ¶üÎĵµ¼°LoaderËæ×źڿÍ×éÖ¯µÄ¸üÌæ¶øÒ»Ö±½ø»¯¡£¡£¡£¡£±¾ÎĽ«²»ÔÙ¶ÔDridexµÄÏêϸÊÖÒÕ¾ÙÐÐÆÊÎö£¬£¬£¬£¬ £¬ £¬Ö»¶ÔDridexµÄ»ù±¾¹¦Ð§ºÍÌØµã¾ÙÐмòÒªµÄÏÈÈÝ¡£¡£¡£¡£ÈçÐèÉîÈëÏàʶDridexľÂí£¬£¬£¬£¬ £¬ £¬¿É×ÐϸÔĶÁc7c7ÓéÀÖÆ½Ì¨ÁíÍâһƪÉî¶ÈÆÊÎö±¨¸æ¡¶¶ãÔÚP2PÈä³æÍøÂç±³ºóµÄÓÄÁ飺DridexÈ䳿ÐÂÐͱäÖÖÌ½ÃØ¡·£¬£¬£¬£¬ £¬ £¬ÎÒÃÇÔÚ±¨¸æÖжÔDridex V4Ëù½ÓÄɵĹ¥»÷ÊÖ·¨£¬£¬£¬£¬ £¬ £¬ÊÖÒÕÊֶΣ¬£¬£¬£¬ £¬ £¬Í¨Ñ¶»úÖÆµÈµÈ×öÁËÖÜÈ«¶øÉîÈëµÄÆÊÎö¡£¡£¡£¡£


DridexÓÖÃûBugat¡¢Cridex¡¢Feodo£¬£¬£¬£¬ £¬ £¬ÓÚ2014ÄêÊ״ηºÆð£¬£¬£¬£¬ £¬ £¬ÊÇÏÖÔÚÈ«Çò»îÔ¾µÄÊÖÒÕ×îÏȽøµÄÒøÐÐľÂíÖ®Ò»£¬£¬£¬£¬ £¬ £¬´Ó·ºÆðÒÔÀ´£¬£¬£¬£¬ £¬ £¬ÆäÒ»Ö±ÔÚÒ»Ö±¸üкÍÑݱ䣬£¬£¬£¬ £¬ £¬Ö±µ½ÏÖÔÚΪֹÈÔÊ®·Ö»îÔ¾¡£¡£¡£¡£¸ÃľÂíµÄÖ÷ҪĿµÄÊÇÇÔÈ¡Êܺ¦ÕßÖ÷»úµÄÒøÐÐÆ¾Ö¤¡£¡£¡£¡£ºÍÕâ´Î¹¥»÷Ò»Ñù£¬£¬£¬£¬ £¬ £¬Æäͨ³£Í¨¹ýÓã²æÊ½´¹ÂÚÓʼþµÄ·½·¨¾ÙÐÐÈö²¥¡£¡£¡£¡£³ýÁËÇÔÈ¡ÒøÐÐÆ¾Ö¤£¬£¬£¬£¬ £¬ £¬Dridexͨ³£»£»£»¹»áÏÂÔØÆäËûµÄ¶ñÒâÄ£¿£¿£¿é£¬£¬£¬£¬ £¬ £¬ÏÖÔÚÒÑÖªµÄ¹¦Ð§Ä£¿£¿£¿éÓÐVNCÄ£¿£¿£¿é¡¢ÆÁÄ»½ØÍ¼Ä£¿£¿£¿é¡¢ÊðÀíÄ£¿£¿£¿é¡¢ÖÐÐÄÈËÄ£¿£¿£¿é¡¢¼üÅ̼ͼÄ£¿£¿£¿é¡¢Æ¾Ö¤ÇÔȡģ¿£¿£¿é¡¢Web×¢ÈëÄ£¿£¿£¿é¡¢ÄÚÍøÑ¬È¾Ä£¿£¿£¿é¡¢ÓʼþÈö²¥Ä£¿£¿£¿é¡¢É³Ïä¼ì²âÄ£¿£¿£¿éµÈ¡£¡£¡£¡£


DridexµÄ¹¥»÷Ä¿µÄ±é²¼Ììϸ÷µØ£¬£¬£¬£¬ £¬ £¬È磺Öйú¡¢ÃÀ¹ú¡¢µÂ¹ú¡¢·¨¹úºÍ¼ÓÄôóµÈ¡£¡£¡£¡£ÒÔÏÂÊÇDridex½ü¼¸ÄêµÄһЩ¹¥»÷ÊÂÎñ£º


2014Äê7Ô£¬£¬£¬£¬ £¬ £¬Seculert¹«Ë¾µÄÇå¾²Ñо¿Ô±·¢Ã÷DridexÇÔÈ¡ÁËÖÁÉÙ5Íò¸öÓÊÏäµÄµÇ¼Õ˺źÍÃÜÂëÐÅÏ¢Áбí£¬£¬£¬£¬ £¬ £¬´ËʱDridexÖ÷ÒªÒÔѬȾµÂ¹úºÍ²¨À¼ÎªÖ÷£¬£¬£¬£¬ £¬ £¬ÆäËûѬȾ¹ýµÄ¹ú¼ÒÓаµØÀû¡¢ÃÀ¹ú¡¢ÈðÊ¿¡¢Ó¢¹ú¡¢Òâ´óÀû¡¢ºÉÀ¼µÈ¡£¡£¡£¡£


2015Äê5Ô£¬£¬£¬£¬ £¬ £¬Dridex×îÏȽ«js¾ç±¾Îļþ×÷ΪÓʼþÈö²¥¸½¼þ¾ÙÐдóÃæ»ýÈö²¥£¬£¬£¬£¬ £¬ £¬¸Ãjs¾ç±¾ÎļþÓÃÓÚÏÂÔØLockyÀÕË÷Èí¼þÖ´ÐС£¡£¡£¡£


2015Äê8Ô£¬£¬£¬£¬ £¬ £¬Ïà¹ØÇå¾²»ú¹¹ÆÊÎöͳ¼Æ£¬£¬£¬£¬ £¬ £¬ÔÚ2015Äê¼ä²»µ½Ò»ÄêµÄʱ¼äÀ£¬£¬£¬ £¬ £¬DridexÒѾ­ÈëÇÖÁ˺á¿ç27¸ö¹ú¼ÒµÄ³ÉǧÉÏÍò¼ÒÆóÒµ£¬£¬£¬£¬ £¬ £¬²¢ÇÒÒѾ­µ¼ÖÂÓ¢¹ú2ÍòÍòÓ¢°õ(ÆäʱºÏ3050ÍòÃÀÔª)ÒÔÉϵľ­¼ÃËðʧ£¬£¬£¬£¬ £¬ £¬ÒÔ¼°ÃÀ¹ú1ÍòÍòÃÀ½ðµÄ¾­¼ÃËðʧ¡£¡£¡£¡£


2015Äê8ÔÂ14ÈÕ£¬£¬£¬£¬ £¬ £¬FBIÁªºÏÇå¾²³§É̵·»ÙÁËDridexЧÀÍÆ÷²¢¾Ð²¶ÁËÒ»ÃûDridexÄ»ºó²Ù¿ØÕß¡£¡£¡£¡£


2016Äê2ÔÂ4ÈÕ£¬£¬£¬£¬ £¬ £¬Dridex±¬·¢ÁËÒ»´ÎÏ·¾çÐÔÊÂÎñ£¬£¬£¬£¬ £¬ £¬ÄǾÍDridexÈ䳿²¡¶¾ºó¶ËЧÀÍÆ÷Òɱ»°×ñ×ÓÈëÇÖ£¬£¬£¬£¬ £¬ £¬ËùÓÐÏÂÔØµÄÄ£¿£¿£¿é±»Ìæ»»³ÉÁËAviraɱ¶¾Èí¼þ¡£¡£¡£¡£


2016Äê9ÔÂ6ÈÕ£¬£¬£¬£¬ £¬ £¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷еÄDridex±äÖÖ×îÏÈÓÃÓÚÇÔÈ¡ÐéÄâÇ®±ÒÈç±ÈÌØ±ÒÇ®°ü¡£¡£¡£¡£


2017Äê4Ô£¬£¬£¬£¬ £¬ £¬ProofpointÑо¿Ö°Ô±ÊӲ쵽Êý°ÙÍò´ÎDridexÈ䳿¹¥»÷£¬£¬£¬£¬ £¬ £¬Æä¹¥»÷ÊÖ·¨ÓëÒÔǰµÄ¹¥»÷ÏàËÆ£¬£¬£¬£¬ £¬ £¬Í¬Ñùͨ¹ýÓʼþЯ´ø¸½¼þµÄÐÎʽ¾ÙÐвþâ±µÄÈö²¥£¬£¬£¬£¬ £¬ £¬Ö»ÊÇÐµĹ¥»÷ÖÐÌí¼ÓÁËͨ¹ýZIP´ò°üµÄvb¾ç±¾Îļþ¡¢PDFÎļþºÍ¿ÉÖ´ÐеÄPEÎļþ¡£¡£¡£¡£


2017Äê5ÔÂ10ÈÕ£¬£¬£¬£¬ £¬ £¬DridexÈ䳿±äÖÖʹÓÃÁËÔ­×Ó×¢ÈëÊÖÒÕ·¢¶¯¹¥»÷£¬£¬£¬£¬ £¬ £¬ÒÔÌÓ±ÜÇå¾²²úÆ·µÄ²éɱ¡£¡£¡£¡£


2017Äê12ÔÂ12ÈÕ£¬£¬£¬£¬ £¬ £¬Ç°Ó¢¹úÒøÐÐÔ±¹¤Ö²ÈëDridexÈ䳿×ÊÖúÁ½Î»ºÚ¿ÍÏ´Ç®£¬£¬£¬£¬ £¬ £¬µ£µ±Ï´Ç®ºÚ¿ÍµÄ˽ÈËÐÅÍÐ˾Àí£¬£¬£¬£¬ £¬ £¬Ê¹ÓÃαÔìµÄÉí·ÝÖ¤¼þ¿ªÉèÁ˶à´ï105¸öÕË»§£¬£¬£¬£¬ £¬ £¬»ã¿îÓëתÕËÁè¼Ý250ÍòÓ¢°÷¡£¡£¡£¡£


2018 Äê 12Ô£¬£¬£¬£¬ £¬ £¬Ä¦¶û¶àÍß¹úÃñAndrey Ghinkul£¬£¬£¬£¬ £¬ £¬ÓÖÃû¡° smilex ¡±£¨ 2017Äê2 Ô£¬£¬£¬£¬ £¬ £¬´ÓÈûÆÖ·˹Òý¶Éµ½ÃÀ¹ú£©Òò·Ö·¢Dridex¶ñÒâÈí¼þ±»ÅÐÐÌ¡£¡£¡£¡£


2019 Äê 6 Ô£¬£¬£¬£¬ £¬ £¬¹¥»÷ÕßʹÓÃSpelevo µÄÎó²îʹÓù¤¾ßͶµÝÒøÐÐľÂíDridex¡£¡£¡£¡£


2019Äê12Ô£¬£¬£¬£¬ £¬ £¬ÃÀ¹úÕþ¸®Ö¸¿ØÁ½¸ö¶íÂÞ˹¹«Ãñ£¨Maksim VºÍIgor Turashev£©°²ÅÅDridex¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬ £¬Á½ÈËÔÚ10ÄêÄÚÇÔÈ¡Áè¼ÝÁË1ÒÚÃÀÔª¡£¡£¡£¡£


2020Äê12ÔÂʱ´ú£¬£¬£¬£¬ £¬ £¬¹¥»÷ÕßͶµÝ·ÂðÑÇÂíÑ·Ãâ·ÑÑÇÂíÑ·ÀñÎ│µÄ´¹ÂÚÓʼþ


2021Äê8Ô£¬£¬£¬£¬ £¬ £¬¹¥»÷ÕßÕë¶Ô¶à¼Òµç×ÓÔªÆ÷¼þÆóÒµÌᳫ´¹ÂÚ¹¥»÷»î¶¯£¬£¬£¬£¬ £¬ £¬°üÀ¨ÌìÂí΢µç×ӹɷÝÓÐÏÞ¹«Ë¾¡¢ºëÒä¹ú¼Ê¹É·ÝÓÐÏÞ¹«Ë¾¡¢questcomp¡¢axiteaµÈ¡£¡£¡£¡£


ËÄ¡¢×ܽá


´Ë´Î¹¥»÷Ö÷ÒªÃé×¼µç×ÓÔªÆ÷¼þÆóÒµµÄÔ±¹¤£¬£¬£¬£¬ £¬ £¬²¢ÇÒÉæ¼°µ½ÎÒ¹úÆóÒµµÄÊý¾ÝÇå¾²£¬£¬£¬£¬ £¬ £¬ÐèÒªÒýÆð¿í´óÆóÊÂÒµµ¥Î»×ã¹»µÄСÐÄ¡£¡£¡£¡£Á¬ÏµDridexľÂíµÄÀúÊ·»î¶¯¼£Ï󣬣¬£¬£¬ £¬ £¬Æä±³ºóµÄ¹¥»÷ÕßÒÔÇÔÃÜ¡¢ÀÕË÷µÈ·½·¨Í¼Ä±¾­¼ÃÀûÒæµÄ¿ÉÄÜÐԽϴ󡣡£¡£¡£DridexÔÚÂÄÀú¶àÄêµÄÉú³¤½ø»¯ºó£¬£¬£¬£¬ £¬ £¬ÒѾ­ÐγÉÁ˼¯È䳿¡¢½©Ê¬¡¢ÇÔÃÜľÂí¡¢ÀÕË÷Èí¼þ¡¢P2PÊðÀíÓÚÒ»ÉíµÄ»ìÏýÐÍÈ䳿²¡¶¾¡£¡£¡£¡£¸ÃÈä³æÍ¬Ê±¾ß±¸ÄÚÍâÍøÀ©É¢¡¢Õý·´ÏìµÄ±Õ»·Ñ¬È¾¡¢C&CЧÀÍÆ÷¼°Í¨Ñ¶Á÷Á¿Òþ²Ø¡¢¶Ô¿¹ÆÊÎö¡¢¿ìËÙ±äÒ졢ģ¿£¿£¿é»¯µÈ¸ß¼¶ÄÜÁ¦£¬£¬£¬£¬ £¬ £¬¹ØÓÚÖÐÕÐÆóÒµ¾ßÓм«´óµÄΣº¦ÐÔ¡£¡£¡£¡£


¼øÓÚDridex½©Ê¬ÍøÂçºã¾Ãͨ¹ý´¹ÂÚÓʼþÒÔ¼°OfficeVBAºê¾ÙÐй¥»÷µÄϰÓÃÊֶΣ¬£¬£¬£¬ £¬ £¬ÎÒÃǽ¨ÒéÆóÊÂÒµµ¥Î»Î´±ØÆÚΪԱ¹¤¾ÙÐÐÇå¾²½ÌÓýÅàѵ£¬£¬£¬£¬ £¬ £¬ÌáÉýÔ±¹¤µÄÇå¾²Ìá·ÀÒâʶ¡£¡£¡£¡£Îñ±Ø×öºÃÓʼþϵͳµÄ·À»¤£¬£¬£¬£¬ £¬ £¬×¢Öز»ÒªËæÒâ·­¿ªÎ´ÖªÈªÔ´µÄµç×ÓÓʼþ£¨ÓÈÆäÊÇ´øÓи½¼þµÄµç×ÓÓʼþ£©¡£¡£¡£¡£ÈôÓÐÐèÒª¿Éͨ¹ý·­¿ªOfficeÎĵµÖеģºÎļþ-Ñ¡Ïî-ÐÅÈÎÖÐÐÄ-ÐÅÈÎÖÐÐÄÉèÖÃ-ºêÉèÖ㬣¬£¬£¬ £¬ £¬½ûÓÃÒ»Çкê´úÂëÖ´ÐС£¡£¡£¡£Ò»µ©ÏµÍ³»òЧÀÍÆ÷·ºÆðÒì³£ÐÐΪ£¬£¬£¬£¬ £¬ £¬ÊµÊ±±¨¸æ²¢ÇëרҵְԱ¾ÙÐÐÅŲ飬£¬£¬£¬ £¬ £¬ÒÔÏû³ýÇå¾²Òþ»¼¡£¡£¡£¡£