{"id":5771,"date":"2024-04-12T22:48:12","date_gmt":"2024-04-12T14:48:12","guid":{"rendered":"https:\/\/aict.nkust.edu.tw\/digitrans\/?p=5771"},"modified":"2024-04-14T22:50:38","modified_gmt":"2024-04-14T14:50:38","slug":"%e8%b6%8a%e5%8d%97%e9%a7%ad%e5%ae%a2%e7%b5%84%e7%b9%94%e9%8e%96%e5%ae%9a%e4%ba%9e%e6%b4%b2%e3%80%81%e6%9d%b1%e5%8d%97%e4%ba%9e%e7%94%a8%e6%88%b6%ef%bc%8c%e5%88%a9%e7%94%a8%e6%83%a1%e6%84%8f%e7%a8%8b","status":"publish","type":"post","link":"https:\/\/aict.nkust.edu.tw\/digitrans\/?p=5771","title":{"rendered":"\u8d8a\u5357\u99ed\u5ba2\u7d44\u7e54\u9396\u5b9a\u4e9e\u6d32\u3001\u6771\u5357\u4e9e\u7528\u6236\uff0c\u5229\u7528\u60e1\u610f\u7a0b\u5f0fRotBot\u3001XClient\u7aca\u53d6\u8cc7\u6599"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">2024-04-12 | \u5468\u5cfb\u4f51<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u601d\u79d1\u65d7\u4e0b\u5a01\u8105\u60c5\u5831\u5718\u968a\u63ed\u9732\u53bb\u5e74\u51fa\u73fe\u7684\u8d8a\u5357\u99ed\u5ba2\u7d44\u7e54CoralRaider\uff0c\u6b64\u5718\u968a\u4e3b\u8981\u9396\u5b9a\u5370\u5ea6\u3001\u4e2d\u570b\u3001\u97d3\u570b\u3001\u5b5f\u52a0\u62c9\u3001\u5df4\u57fa\u65af\u5766\u3001\u5370\u5c3c\u3001\u8d8a\u5357\u7b49\u591a\u500b\u570b\u5bb6\uff0c\u76ee\u6a19\u662f\u7aca\u53d6\u53d7\u5bb3\u8005\u7684\u5e33\u5bc6\u8cc7\u6599\u3001\u8ca1\u52d9\u8cc7\u6599\u3001\u793e\u7fa4\u7db2\u7ad9\u5e33\u865f\uff08\u5305\u542b\u4f01\u696d\u53ca\u5ee3\u544a\u5e33\u865f\uff09\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u653b\u64ca\u8005\u5148\u662f\u900f\u904eWindows\u6377\u5f91\u6a94\u6848\uff08LNK\uff09\u767c\u52d5\u653b\u64ca\uff0c\u4e00\u65e6\u4f7f\u7528\u8005\u958b\u555f\u5c0d\u65b9\u63d0\u4f9b\u7684\u6a94\u6848\uff0c\u96fb\u8166\u5c31\u6703\u5f9e\u653b\u64ca\u8005\u63a7\u5236\u7684\u4f3a\u670d\u5668\u4e0b\u8f09HTML\u61c9\u7528\u7a0b\u5f0f\u6a94\u6848\uff08HTA\uff09\uff0c\u6b64\u6a94\u6848\u5d4c\u5165\u7d93\u6df7\u6dc6\u8655\u7406\u7684Visual Basic\u6307\u4ee4\u78bc\uff0c\u8a72\u6307\u4ee4\u78bc\u6703\u5728\u8a18\u61b6\u9ad4\u5167\u57f7\u884cPowerShell\u6307\u4ee4\u78bc\uff0c\u7136\u5f8c\u89f8\u767c\u53e6\u59163\u500b\u6307\u4ee4\u78bc\uff0c\u5c0d\u65bc\u53d7\u5bb3\u96fb\u8166\u74b0\u5883\u9032\u884c\u5075\u5bdf\uff0c\u78ba\u8a8d\u662f\u5426\u70ba\u865b\u64ec\u6a5f\u5668\uff08VM\uff09\u74b0\u5883\uff0c\u4e26\u57f7\u884c\u53cd\u5206\u6790\u6aa2\u67e5\uff0c\u7e5e\u904e\u4f7f\u7528\u8005\u5b58\u53d6\u63a7\u5236\uff08UAC\uff09\u3001\u505c\u7528Windows\u61c9\u7528\u7a0b\u5f0f\u901a\u77e5\uff0c\u6700\u7d42\u690d\u5165\u60e1\u610f\u7a0b\u5f0fQuasarRAT\u8b8a\u7a2eRotBot\u3002<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter is-resized\"><a href=\"https:\/\/i0.wp.com\/s4.itho.me\/sites\/default\/files\/images\/coralraider-flow.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s4.itho.me\/sites\/default\/files\/images\/coralraider-flow.jpg?w=640&#038;ssl=1\" alt=\"\" style=\"width:944px;height:auto\"\/><\/a><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">\u6b64\u60e1\u610f\u7a0b\u5f0f\u555f\u52d5\u5f8c\uff0c\u5c07\u6703\u518d\u5ea6\u57f7\u884c\u5075\u5bdf\uff0c\u4e26\u4e0b\u8f09\u7d44\u614b\u6a94\u6848\u9023\u63a5C2\u3002\u503c\u5f97\u4e00\u63d0\u7684\u662f\uff0c\u5c0d\u65b9\u4f7f\u7528Telegram\u6a5f\u5668\u4eba\u505a\u70baC2\u901a\u8a0a\u7684\u7ba1\u9053\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e0a\u8ff0\u9023\u7dda\u6210\u529f\u5f8c\uff0cRotBot\u5c07\u6703\u628a\u60e1\u610f\u916c\u8f09XClient\u8f09\u5165\u8a18\u61b6\u9ad4\uff0c\u4e26\u57f7\u884c\u5916\u639b\u7a0b\u5f0f\uff0c\u7136\u5f8c\u7aca\u53d6\u53d7\u5bb3\u8005\u7684\u700f\u89bd\u5668\u8cc7\u6599\uff0c\u4e26\u641c\u62ec\u793e\u7fa4\u7db2\u7ad9\u81c9\u66f8\u3001Instagram\u3001\u6296\u97f3\u3001YouTube\u5e33\u865f\uff0c\u4ee5\u53ca\u5f9eTelegram\u3001Discord\u96fb\u8166\u7248\u61c9\u7528\u7a0b\u5f0f\u6536\u96c6\u8cc7\u6599\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u503c\u5f97\u7559\u610f\u7684\u662f\uff0cXClient\u9084\u6703\u7279\u5225\u78ba\u8a8d\u53d7\u5bb3\u8005\u6301\u6709\u7684\u81c9\u66f8\u5e33\u865f\u5c6c\u6027\uff0c\u662f\u5426\u70ba\u4f01\u696d\u5e33\u865f\u6216\u662f\u5ee3\u544a\u5e33\u865f\uff0c\u4e26\u9032\u4e00\u6b65\u6536\u96c6\u8ca1\u52d9\u8cc7\u8a0a\u3001\u597d\u53cb\u540d\u55ae\u7684\u8a73\u7d30\u8cc7\u6599\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u7814\u7a76\u4eba\u54e1\u7279\u5225\u63d0\u5230\uff0c\u5c0d\u65b9\u4f7f\u7528\u4e86\u540d\u70baDead Drop\u7684\u653b\u64ca\u624b\u6cd5\uff0c\u6feb\u7528\u5408\u6cd5\u670d\u52d9\u4ee3\u7ba1C2\u7d44\u614b\u8cc7\u8a0a\uff0c\u800c\u5728\u9032\u884c\u5bc4\u751f\u653b\u64ca\uff08LOLBins\uff09\u7684\u904e\u7a0b\uff0c\u9019\u4e9b\u99ed\u5ba2\u4e5f\u904b\u7528\u4e86Forfiles.exe\u3001FoDHelper.exe\u7b49\u4e0d\u5e38\u898b\u7684\u53ef\u57f7\u884c\u6a94\uff0c\u4f86\u5f9e\u4e8b\u653b\u64ca\u884c\u52d5\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8cc7\u6599\u4f86\u6e90:<a href=\"https:\/\/www.ithome.com.tw\/news\/162264\" data-type=\"link\" data-id=\"https:\/\/www.ithome.com.tw\/news\/162264\">https:\/\/www.ithome.com.tw\/news\/162264<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>2024-04-12 | \u5468\u5cfb\u4f51 \u601d\u79d1\u65d7\u4e0b\u5a01\u8105\u60c5\u5831\u5718\u968a\u63ed\u9732\u53bb\u5e74\u51fa\u73fe\u7684\u8d8a\u5357\u99ed\u5ba2\u7d44\u7e54CoralRaider\uff0c\u6b64\u5718\u968a\u4e3b\u8981\u9396\u5b9a\u5370\u5ea6\u3001\u4e2d\u570b\u3001\u97d3\u570b\u3001\u5b5f\u52a0\u62c9\u3001\u5df4\u57fa\u65af\u5766\u3001\u5370\u5c3c\u3001\u8d8a\u5357\u7b49\u591a\u500b\u570b\u5bb6\uff0c\u76ee\u6a19&hellip;<\/p>\n","protected":false},"author":9,"featured_media":5772,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[352],"tags":[204],"class_list":["post-5771","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information-security","tag-204"],"gutentor_comment":0,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/aict.nkust.edu.tw\/digitrans\/wp-content\/uploads\/2024\/04\/coralraider-flow-156.jpg?fit=960%2C420&ssl=1","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/5771","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5771"}],"version-history":[{"count":1,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/5771\/revisions"}],"predecessor-version":[{"id":5773,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/5771\/revisions\/5773"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/media\/5772"}],"wp:attachment":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5771"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5771"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}