ʱ¼ä£º2022-01-18 ×÷ÕߣºÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐÄ
Åä¾°
SideCopy×éÖ¯ÖÁÉÙ×Ô2019ÄêÒÔÀ´Ò»Ö±ÔÚÔ˶¯£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÄÏÑǹú¼ÒµÄ¹ú·À¾üºÍÎä×°²½¶ÓÖ°Ô±¡¢Â½ÎäʿԱ¾ÙÐÐÇÔÃÜÔ˶¯¡£¡£¡£¡£¡£¸Ã×é֯ͨ¹ýÄ£ÄâÏìβÉßAPTµÄ¹¥»÷ÊÖ·¨À´×ª´ï×Ô¼ºµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬²¢ÒԴ˵ִïÒÉ»óÇå¾²Ö°Ô±µÄÄ¿µÄ¡£¡£¡£¡£¡£
2021Äê11ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐĺìÓêµÎÍŶÓÊ״η¢Ã÷SideCopy×é֯ʹÓÃÓÉPython´ò°üµÄ˫ƽ̨¹¥»÷ÎäÆ÷[1]£¬£¬£¬£¬£¬£¬£¬Ô˶¯ÖÐʹÓõijõʼ¹¥»÷Ñù±¾ÊÇÒ»¸ö°üÀ¨Linux×ÀÃæÆô¶¯ÎļþµÄѹËõ°ü£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþÔÚÖ´ÐÐÖ®ºó»áÏÂÔØ²¢²¥·ÅεÏ×Üͳ½²»°ÊÓÆµÒÔÒÉ»óÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬Í¬Ê±ÏÂÔØÒ»¸öÓÃÓÚÏÂÔØRATµÄ¾ç±¾²¢Ö´ÐС£¡£¡£¡£¡£
¾ÆÊÎö£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ¿ÉÒÔÈ·ÈϸÃRATÊÇÒ»¿îÖ§³ÖWindowsºÍLinux˫ƽ̨µÄÔ¶¿Ø¹¤¾ß¡£¡£¡£¡£¡£Í¨¹ýC&C¹ØÁª·¢Ã÷£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÎäÆ÷¿âÖл¹°üÀ¨MacOSƽ̨µÄBellaRAT¡£¡£¡£¡£¡£Ö®ºóÎÒÃÇÔöÇ¿Á˶ԸÃ×éÖ¯µÄÒ»Á¬¹Ø×¢¼°×·×Ù¡£¡£¡£¡£¡£
2021Äê12ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÔٴβ¶»ñSideCopyAPT×éÖ¯ÒÔÓ¡¶È¹ú·ÀÕÕÁϳ¤×¹»úÏà¹ØÊÂÎñΪÓÕ¶ü¾ÙÐеĹ¥»÷[2]¡£¡£¡£¡£¡£ÓÕ¶üÎĵµÊ¹ÓÃÔ¶³ÌÄ£°å×¢È룬£¬£¬£¬£¬£¬£¬Ô¶³Ì¼ÓÔØ²¢Ö´Ðк¬ÓжñÒâDDEÓò´úÂëµÄÎĵµÎļþ£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¶ñÒâÓò´úÂëÏÂÔØvbs¾ç±¾µ½±¾»úÖ´ÐÐÏ·¢ºóÐø¶ñÒâ´úÂë¡£¡£¡£¡£¡£
¸ÅÊö
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬ºìÓêµÎÍŶÓÑо¿Ö°Ô±ÔÚÒ»Ñùƽ³£Íþвá÷ÁÔÖÐÔٴβ¶»ñµ½Ò»ÀýÕë¶ÔLinuxƽ̨µÄ¹¥»÷Ñù±¾¡£¡£¡£¡£¡£ÓëÉϴβî±ðµÄÊÇ£¬£¬£¬£¬£¬£¬£¬´Ë´Î²¶»ñÑù±¾ÓÉGoÓïÑÔ±àд¶ø²»ÊÇPython£¬£¬£¬£¬£¬£¬£¬¸ÃÑù±¾¹¦Ð§½ÏΪ¼òµ¥£¬£¬£¬£¬£¬£¬£¬½öʵÏÖÁ˶ÔÄ¿µÄÊܺ¦ÕßÖ÷»úĿ¼µÄɨÃèºÍÇÔÈ¡¡£¡£¡£¡£¡£Òź¶µÄÊÇ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚC2ʧЧ£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇûÓлñÈ¡µ½ÍêÕûµÄ¹¥»÷Á´£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°¸üÉîÈëµÄÑо¿ÆÊÎö¡£¡£¡£¡£¡£
Ñù±¾ÐÅÏ¢
±¾´Î²¶»ñµ½µÄÑù±¾¾ùΪLinux64λϵͳµÄELFÎļþ¡£¡£¡£¡£¡£±¾ÎĽ«´Ë´Î²¶»ñµ½µÄÑùÌìְΪÁ½À࣬£¬£¬£¬£¬£¬£¬Á½ÀàÑù±¾ÔÚ»ù±¾½á¹¹¡¢¹¦Ð§ÉϼòªÏàËÆ£¬£¬£¬£¬£¬£¬£¬²î±ðÖ®´¦ÔÚÓÚµÚÒ»ÀàÑù±¾»ñÈ¡Á˱¾»úIPµØµã²¢¾ÙÐÐÁ˳¤ÆÚ»¯²Ù×÷¡£¡£¡£¡£¡£ÏêϸÐÅÏ¢ÈçÏ£º
ÏêϸÆÊÎö
Ê×ÏÈÒÔµÚÒ»ÀàÑù±¾£¬£¬£¬£¬£¬£¬£¬¼´²»°üÀ¨³¤ÆÚ»¯²Ù×÷µÄÑù±¾34d9dff0aa80f6ea7eea6f491d493fa3ΪÀý¾ÙÐÐÆÊÎö¡£¡£¡£¡£¡£
Ñù±¾ÔËÐк󽫻ñȡĿ½ñÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ö÷Ŀ¼£¬£¬£¬£¬£¬£¬£¬²¢ÅжÏÊÇ·ñ±£´æ“/tmp/lists.txt”Îļþ¡£¡£¡£¡£¡£

Èô“/tmp/lists.txt”Îļþ²»±£´æ£¬£¬£¬£¬£¬£¬£¬ÔòÑù±¾½«»áÏȱéÀúÖ÷Ŀ¼ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚ/tmpĿ¼Ï½¨Éèlists.txt£¬£¬£¬£¬£¬£¬£¬²¢½«Ð§¹û´æ·ÅÔÚÄÚÀ£¬£¬£¬£¬£¬£¬ÉÏ´«C2Ϊ207.180.243[.]186:8062¡£¡£¡£¡£¡£
Èô“/tmp/lists.txt”±£´æÔòÌø¹ýÖ÷Ŀ¼±éÀú£¬£¬£¬£¬£¬£¬£¬Ö±½Ó½øÈëÏÂÒ»²½²Ù×÷¡£¡£¡£¡£¡£

±éÀúµÄЧ¹ûÈçÏ£º

ÓÃÓÚÉÏ´«C2µÄ²¿·Ö£º

Ö®ºó£¬£¬£¬£¬£¬£¬£¬¼ÌÐøÉ¨Ãè/home/Ŀ¼Ï´øÌض¨À©Õ¹ÃûµÄÎļþ£¬£¬£¬£¬£¬£¬£¬²¢½¨Éè/tmp/temp.txt£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ´æ·ÅÉÏ´«ÎļþµÄ¼Í¼£¬£¬£¬£¬£¬£¬£¬Ö®ºó½«É¨ÃèЧ¹ûÖðÒ»ÉÏ´«C2£¬£¬£¬£¬£¬£¬£¬ÉÏ´«Íê³Éºó±ã¿¢Ê³ÌÐò¡£¡£¡£¡£¡£


Ñù±¾ËùɨÃèµÄÀ©Õ¹Ãû°üÀ¨.css¡¢.csv¡¢.doc¡¢.egm¡¢.gif¡¢.htm¡¢.jpg¡¢.mjs¡¢.odt¡¢.oef¡¢.pdf¡¢.png¡¢.ppt¡¢.sdd¡¢.sec¡¢.svg¡¢.txt¡¢.xls¡¢.xmlµÈ¡£¡£¡£¡£¡£
Á½ÀàÑù±¾µÄ²î±ðÖ®´¦
µÚ¶þÀàÑù±¾ÓëµÚÒ»ÀàÑù±¾µÄ²î±ðÖ®´¦ÔÚÓÚ£º
1.Ñù±¾ÔËÐкóÊ×ÏÈÏòapi.ipify.org·¢ËÍGETÇëÇó»ñÈ¡ÊÜѬȾϵͳµÄIPµØµã£¬£¬£¬£¬£¬£¬£¬Ö®ºóÔÙ¾ÙÐлñÈ¡Óû§ÐÅÏ¢µÄ²Ù×÷£»£»£»£»£»£»

2.ÔÚ»ñÈ¡µ½Óû§ÐÅÏ¢Ö®ºó£¬£¬£¬£¬£¬£¬£¬Ñù±¾»áͨ¹ý“/.config/autostart/”Ŀ¼ʵÏÖ¿ª»ú×ÔÆô£¬£¬£¬£¬£¬£¬£¬»ñµÃ³¤ÆÚ»¯¡£¡£¡£¡£¡£


Ö®ºóµÄÁ÷³Ì±ãÓëµÚÒ»ÀàÑù±¾ÍêÈ«Ïàͬ¡£¡£¡£¡£¡£×îÖÕÅþÁ¬µ½µÄC2Ϊ164.68.108[.]153:8062¡£¡£¡£¡£¡£
¹ØÁªÆÊÎö
ÎÒÃÇÔÚÆÊÎöÀú³ÌÖз¢Ã÷£¬£¬£¬£¬£¬£¬£¬µÚÒ»ÀàÑù±¾Ê¹ÓõÄC2£º207.180.243[.]186£¬£¬£¬£¬£¬£¬£¬Óë¡¶Ó¡¶È¹ú·ÀÕÕÁϳ¤×¹»ú£ºSideCopyAPT×éÖ¯³Ã»ðÂÓ¶á¡·[2]Ò»ÎÄÖжñÒâPowerShell¾ç±¾ÇëÇóµÄC2Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÏÂͼΪÎÄÖÐÑù±¾Ö´ÐÐÁ÷³Ì£º

ƾ֤¹¥»÷Á÷³ÌÀ´¿´£¬£¬£¬£¬£¬£¬£¬SideCopy×é֯ʹÓÃ207.180.243[.]186Ï·¢ºóÐø¹¥»÷×é¼þ¡£¡£¡£¡£¡£¶ø±¾´Î²¶»ñµÄÑù±¾¹¦Ð§¼òÆÓ£¬£¬£¬£¬£¬£¬£¬ºÜÏñijÌõ¹¥»÷Á´ÖÐʹÓõÄijһ×é¼þ¡£¡£¡£¡£¡£ËäÈ»¡¶SideCopyAPT×éÖ¯³Ã»ðÂÓ¶á¡·Ò»ÎÄÖÐÅû¶µÄÊÇÕë¶ÔWindowsƽ̨µÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ«ÎÒÃÇÍÆ²â¸Ã×éÖ¯¿ÉÄÜÔÚͳһʱÆÚ×îÏȲ߻®Õë¶ÔLinuxƽ̨µÄ¹¥»÷¡£¡£¡£¡£¡£
Æä´Îͨ¹ýÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÎļþÉî¶ÈÆÊÎöƽ̨¿ÉÖª±¾ÎÄÖÐÑù±¾µÄÏÂÔØÁ´½ÓΪ“hxxp://assessment.mojochamps[.]com/uploads/v/filename”¡£¡£¡£¡£¡£

¸ÃÏÂÔØÁ´½ÓÓë´ËǰÎÒÃÇÅû¶µÄSideCopy¹¥»÷Ô˶¯ÖеÄÓÕ¶üÎĵµÏÂÔØÁ´½Ó“hxxp://assessment.mojochamps[.]com/images/Jointness.docx”¡¢“hxxp://assessment.mojochamps[.]com/uploads/v/3.php”ËùÊôÓòÃû¾ùÏàͬ¡£¡£¡£¡£¡£

ÍŽá֮ǰµÄÁ½ÆªÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷SideCopy×éÖ¯ÔçÔÚ11Ô¾ÍÈëÇÖÁËÕýµ±ÍøÕ¾“hxxp://assessment.mojochamps[.]com”£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÓÃÓÚ¹ÒÔØÓÕ¶üÎĵµ¼°Ïà¹Ø¶ñÒâºóÐøÔØºÉ¡£¡£¡£¡£¡£²»ÄÑ¿´³ö£¬£¬£¬£¬£¬£¬£¬SideCopy×é֯ͨ¹ýÕâÒ»ÍøÕ¾Í¬Ê±¾ÙÐÐÁËWindows¡¢LinuxÁ½¸öƽ̨µÄ¹¥»÷Ô˶¯¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÎÒÃDZ¾´Î²¶»ñµ½µÄLinuxÑù±¾ÔÙ´ÎÓ¡Ö¤Á˸ù¥»÷ÍŻォ¹¥»÷ÄÜÁ¦ÁýÕÖ°üÀ¨Linux¡¢WindowsµÈ¶à¸öƽ̨µÄÒâͼ£¬£¬£¬£¬£¬£¬£¬ÇÒΪ´ËÔÚÒ»Ö±Éú³¤ÐµĹ¥»÷ÎäÆ÷¡£¡£¡£¡£¡£
×ܽá
SideCopy×÷Ϊ½üÄê²Å±»Åû¶µÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬£¬ÔÚ2021ϰëÄê½øÈë¸ß¶È»îÔ¾µÄ״̬¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷SideCopy×éÖ¯²»ÔÙÖª×ãÓÚʹÓÃÍøÂçÉÏ¿ªÔ´µÄ´úÂë¼°¹¤¾ß£¬£¬£¬£¬£¬£¬£¬¶øÊÇÊÔͼÉú³¤Æä¹¥»÷ÄÜÁ¦£¬£¬£¬£¬£¬£¬£¬¸üÐÂÆäÎäÆ÷¿â¡£¡£¡£¡£¡£Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐÄ»á¶ÔÆä¾ÙÐкã¾ÃµÄËÝÔ´ºÍ¸ú½ø£¬£¬£¬£¬£¬£¬£¬ÊµÊ±·¢Ã÷Çå¾²Íþв²¢¿ìËÙÏìÓ¦´¦Öóͷ£¡£¡£¡£¡£¡£
´Ë´Î²¶»ñµÄÑù±¾Ö÷ÒªÕë¶ÔÄÏÑǵØÇø¿ªÕ¹¹¥»÷Ô˶¯£¬£¬£¬£¬£¬£¬£¬º£ÄÚÓû§²»ÊÜÆäÓ°Ïì¡£¡£¡£¡£¡£Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶÓÌáÐÑ¿í´óÓû§£¬£¬£¬£¬£¬£¬£¬ÇÐÎ𷿪É罻ýÌå·ÖÏíµÄȪԴ²»Ã÷µÄÁ´½Ó£¬£¬£¬£¬£¬£¬£¬²»µã»÷Ö´ÐÐδ֪ȪԴµÄÓʼþ¸½¼þ£¬£¬£¬£¬£¬£¬£¬²»ÔËÐÐÎÊÌâ¿äÕŵÄδ֪Îļþ£¬£¬£¬£¬£¬£¬£¬²»×°Ö÷ÇÕý¹æÍ¾¾¶ÈªÔ´µÄAPP¡£¡£¡£¡£¡£×öµ½ÊµÊ±±¸·ÝÖ÷ÒªÎļþ£¬£¬£¬£¬£¬£¬£¬¸üÐÂ×°Öò¹¶¡¡£¡£¡£¡£¡£
ÈôÐèÔËÐУ¬£¬£¬£¬£¬£¬£¬×°ÖÃȪԴ²»Ã÷µÄÓ¦Ó㬣¬£¬£¬£¬£¬£¬¿ÉÏÈͨ¹ýÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÎļþÉî¶ÈÆÊÎöƽ̨£¨https://sandbox.ti.qianxin.com/sandbox/page£©¾ÙÐÐÅб𡣡£¡£¡£¡£ÏÖÔÚÒÑÖ§³Ö°üÀ¨Windows¡¢°²×¿Æ½Ì¨ÔÚÄڵĶàÖÖÃûÌÃÎļþÉî¶ÈÆÊÎö¡£¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬»ùÓÚÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐĵÄÍþвÇ鱨Êý¾ÝµÄÈ«Ïß²úÆ·£¬£¬£¬£¬£¬£¬£¬°üÀ¨Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ƽ̨£¨TIP£©¡¢ÌìÇæ¡¢ÌìÑ۸߼¶Íþв¼ì²âϵͳ¡¢Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!NGSOC¡¢Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Ì¬ÊÆ¸ÐÖªµÈ£¬£¬£¬£¬£¬£¬£¬¶¼ÒѾ֧³Ö¶Ô´ËÀ๥»÷µÄ׼ȷ¼ì²â¡£¡£¡£¡£¡£

IOCs
MD5
5fd6fc76b3ec2f5c97a44bf7bd3de972
34d9dff0aa80f6ea7eea6f491d493fa3
64149e187f678f3131746d2975b8a8dc
fea8b786f469e723e8fdb7ed630ba850
C2
164.68.108[.]153:8062
207.180.243[.]186:8062
URL
http://207.180.243[.]186:8062/one
http://164.68.108[.]153:8062/one
²Î¿¼Á´½Ó
[1]https://ti.qianxin.com/blog/articles/Sidecopy-dual-platform-weapon/
[2]https://ti.qianxin.com/blog/articles/SideCopy-APT-Group-Takes-Advantage-of-the-Fire/
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
¿ì½Ý´°¿Ú
ÆìÏÂÍøÕ¾
¹ØÓÚÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!
95015ЧÀÍÈÈÏß
΢ÐŹ«ÖÚºÅ
Á¬Ã¦²¦´ò