{"id":6046,"date":"2024-05-23T15:16:26","date_gmt":"2024-05-23T07:16:26","guid":{"rendered":"https:\/\/aict.nkust.edu.tw\/digitrans\/?p=6046"},"modified":"2024-05-29T15:43:24","modified_gmt":"2024-05-29T07:43:24","slug":"%e5%8d%97%e6%b5%b7%e8%bb%8d%e4%ba%8b%e5%96%ae%e4%bd%8d%e8%88%87%e6%94%bf%e5%ba%9c%e6%a9%9f%e9%97%9c%e9%81%ad%e4%b8%ad%e5%9c%8b%e9%a7%ad%e5%ae%a2%e7%b5%84%e7%b9%94unfading-sea-haze%e9%8e%96%e5%ae%9a","status":"publish","type":"post","link":"https:\/\/aict.nkust.edu.tw\/digitrans\/?p=6046","title":{"rendered":"\u5357\u6d77\u8ecd\u4e8b\u55ae\u4f4d\u8207\u653f\u5e9c\u6a5f\u95dc\u906d\u4e2d\u570b\u99ed\u5ba2\u7d44\u7e54Unfading Sea Haze\u9396\u5b9a\uff0c\u6697\u4e2d\u5f9e\u4e8b\u60c5\u5831\u6536\u96c6\u8d85\u904e5\u5e74"},"content":{"rendered":"\n<p>2024-05-23 | \u5468\u5cfb\u4f51<\/p>\n\n\n\n<p>\u8cc7\u5b89\u696d\u8005Bitdefender\u63ed\u9732\u5c08\u9580\u9396\u5b9a\u5357\u6d77\u570b\u5bb6\u653f\u5e9c\u9ad8\u5c64\u7684\u4e2d\u570b\u99ed\u5ba2\u7d44\u7e54Unfading Sea Haze\uff0c\u4ed6\u5011\u78ba\u8a8d\u81f3\u5c11\u67098\u500b\u8ecd\u4e8b\u55ae\u4f4d\u8207\u653f\u5e9c\u6a5f\u95dc\u53d7\u5bb3\uff0c\u76f8\u95dc\u653b\u64ca\u884c\u52d5\u6700\u65e9\u53ef\u8ffd\u6eaf\u52302018\u5e74\uff0c\u63db\u8a00\u4e4b\uff0c\u9019\u4e9b\u99ed\u5ba2\u6697\u4e2d\u6d3b\u52d5\u5df2\u8d85\u904e5\u5e74\u3002<\/p>\n\n\n\n<p>\u7814\u7a76\u4eba\u54e1\u6307\u51fa\uff0c\u6839\u64da\u4ed6\u5011\u627e\u5230\u99ed\u5ba2\u4e0d\u540c\u6642\u671f\u4f7f\u7528\u7684\u4f5c\u6848\u5de5\u5177\uff0c\u5c0d\u65b9\u904b\u7528\u4e86\u6728\u99ac\u7a0b\u5f0fGh0st RAT\u7684\u8b8a\u7a2e\uff0c\u4ee5\u53ca\u591a\u7a2e.NET\u60e1\u610f\u916c\u8f09\uff0c\u653b\u64ca\u904e\u7a0b\u6703\u85c9\u7531\u540d\u70baSharpJSHandler\u7684\u5de5\u5177\u57f7\u884cJavaScript\u7a0b\u5f0f\u78bc\uff0c\u9019\u4e9b\u624b\u6cd5\u4e0d\u50c5\u8b93\u4ed6\u5011\u8a8d\u70baUnfading Sea Haze\u8207\u4e2d\u570b\u6709\u95dc\uff0c\u4e0a\u8ff0\u57f7\u884cJavaScript\u7a0b\u5f0f\u78bc\u7684\u5de5\u5177\uff0c\u4e5f\u51fa\u73fe\u5728\u8207APT41\u6709\u95dc\u7684\u5f8c\u9580\u7a0b\u5f0ffunnyswitch\u3002\u4e0d\u904e\uff0c\u7814\u7a76\u4eba\u54e1\u6307\u51fa\uff0c\u9664\u6b64\u4e4b\u5916\u5169\u7d44\u99ed\u5ba2\u7684\u4f5c\u6848\u5de5\u5177\u4e26\u672a\u51fa\u73fe\u5176\u4ed6\u5171\u901a\u9ede\uff0c\u56e0\u6b64\u4ed6\u5011\u8a8d\u70ba\uff0c\u9019\u662f\u4e2d\u570b\u99ed\u5ba2\u7d44\u7e54\u4e4b\u9593\u5171\u7528\u7a0b\u5f0f\u78bc\u6240\u81f4\u3002<\/p>\n\n\n\n<p>\u7a76\u7adf\u9019\u4e9b\u99ed\u5ba2\u5982\u4f55\u5165\u4fb5\u53d7\u5bb3\u7d44\u7e54\uff1f\u7814\u7a76\u4eba\u54e1\u8868\u793a\u4e8b\u96946\u5e74\u5c0e\u81f4\u8b49\u64da\u7f3a\u4e4f\uff0c\u4e26\u4e0d\u6e05\u695a\u5982\u4f55\u505a\u5230\u3002\u4f46\u4ed6\u5011\u78ba\u8a8d\u5c0d\u65b9\u5728\u9577\u6642\u9593\u7684\u653b\u64ca\u884c\u52d5\u88e1\uff0c\u6703\u591a\u6b21\u91cd\u65b0\u53d6\u5f97\u53d7\u5bb3\u7cfb\u7d71\u7684\u5b58\u53d6\u6b0a\u9650\uff0c\u5176\u4e2d\u4e00\u7a2e\u505a\u6cd5\u662f\u900f\u904e\u91e3\u9b5a\u90f5\u4ef6\u9032\u884c\u3002<\/p>\n\n\n\n<p>\u9019\u4e9b\u91e3\u9b5a\u4fe1\u5167\u542b\u60e1\u610f\u6a94\u6848\uff0c\u5176\u4e2d\u5305\u542b\u507d\u88dd\u6210\u6587\u4ef6\u7684Windows\u6377\u5f91\uff08LNK\uff09\u6a94\u6848\uff0c\u4ed6\u5011\u767c\u73fe\u99ed\u5ba2\u5f9e\u53bb\u5e743\u6708\u81f35\u6708\uff0c\u591a\u6b21\u4ee5\u6b64\u624b\u6cd5\u5617\u8a66\u767c\u52d5\u653b\u64ca\uff0c\u4e26\u85c9\u7531\u63d0\u4f9b\u9632\u6bd2\u8edf\u9ad4Microsoft Defender\u5b89\u88dd\u7a0b\u5f0f\u53ca\u6307\u5f15\uff0c\u6216\u662f\u7576\u6642\u7f8e\u570b\u653f\u6cbb\u8b70\u984c\u505a\u70ba\u8a98\u990c\u3002<\/p>\n\n\n\n<p>\u503c\u5f97\u7559\u610f\u7684\u662f\uff0c\u653b\u64ca\u8005\u6703\u5728LNK\u7684\u547d\u4ee4\u7576\u4e2d\uff0c\u52a0\u5165\u5197\u9577\u7684\u8a3b\u89e3\uff0c\u9019\u9ebc\u505a\u7684\u76ee\u7684\u5f88\u6709\u53ef\u80fd\u662f\u70ba\u4e86\u8ff4\u907f\u5075\u6e2c\u3002<\/p>\n\n\n\n<p>\u4f46\u7279\u5225\u7684\u662f\uff0c\u99ed\u5ba2\u7684\u7a0b\u5f0f\u78bc\u57f7\u884c\u904e\u7a0b\u7576\u4e2d\uff0c\u6703\u7279\u5225\u6aa2\u67e5\u76ee\u6a19\u96fb\u8166\u662f\u5426\u6709ESET\u9632\u6bd2\u8edf\u9ad4\u7684\u6838\u5fc3\u670d\u52d9\u8655\u7406\u7a0b\u5e8fekrn.exe\uff0c\u4e26\u5728\u6c92\u6709\u8a72\u8655\u7406\u7a0b\u5e8f\u7684\u60c5\u6cc1\u4e0b\u624d\u6703\u7e7c\u7e8c\u57f7\u884c\u3002<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><a href=\"https:\/\/i0.wp.com\/s4.itho.me\/sites\/default\/files\/images\/image-png-May-20-2024-04-42-49-1999-PM.png?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s4.itho.me\/sites\/default\/files\/images\/image-png-May-20-2024-04-42-49-1999-PM.png?w=640&#038;ssl=1\" alt=\"\"\/><\/a><\/figure>\n<\/div>\n\n\n<p>\u63a5\u8457\u4ed6\u5011\u57f7\u884cPowerShell\u547d\u4ee4\uff0c\u6feb\u7528\u5fae\u8edf\u7684\u958b\u767c\u5de5\u5177Microsoft Build Engine\uff08MSBuild\uff09\uff0c\u5f9e\u9060\u7aefSMB\u4f3a\u670d\u5668\u4e0a\u641c\u5c0b\u5c08\u6848\u6a94\u6848\uff0c\u85c9\u6b64\u5728\u8a18\u61b6\u9ad4\u57f7\u884c\u99ed\u5ba2\u7684\u60e1\u610f\u7a0b\u5f0f\u78bc\uff0c\u800c\u4e0d\u6703\u5728\u53d7\u5bb3\u96fb\u8166\u7559\u4e0b\u505a\u6848\u75d5\u8de1\u3002\u9019\u4e9b\u60e1\u610f\u7a0b\u5f0f\u78bc\u662f\u540d\u70baSerialPktdoor\u7684\u5f8c\u9580\u7a0b\u5f0f\uff0c\u529f\u80fd\u662f\u80fd\u8b93\u5c0d\u65b9\u9060\u7aef\u64cd\u63a7\u96fb\u8166\u3002<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><a href=\"https:\/\/i0.wp.com\/s4.itho.me\/sites\/default\/files\/images\/image-png-May-20-2024-04-43-30-4481-PM.png?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s4.itho.me\/sites\/default\/files\/images\/image-png-May-20-2024-04-43-30-4481-PM.png?w=640&#038;ssl=1\" alt=\"\"\/><\/a><\/figure>\n<\/div>\n\n\n<p>\u6b64\u5916\uff0c\u653b\u64ca\u8005\u6feb\u7528Windows\u96fb\u8166\u9810\u8a2d\u505c\u7528\u7684\u672c\u6a5f\u7ba1\u7406\u54e1\u5e33\u865fAdministrator\uff0c\u7ac4\u6539\u5176\u5bc6\u78bc\u4e26\u555f\u7528\uff0c\u4f46\u70ba\u4e86\u4e0d\u8b93\u4f7f\u7528\u8005\u5bdf\u89ba\uff0c\u4ed6\u5011\u53c8\u66f4\u52d5\u6a5f\u78bc\uff0c\u8b93\u9019\u500b\u5e33\u865f\u5728\u767b\u5165\u756b\u9762\u96b1\u85cf\u3002<\/p>\n\n\n\n<p>\u4e00\u65e6\u6210\u529f\u5165\u4fb5\uff0c\u9019\u4e9b\u99ed\u5ba2\u5c31\u6703\u85c9\u7531\u9375\u76e4\u5074\u9304\u7a0b\u5f0fxkeylog\u622a\u53d6\u4f7f\u7528\u8005\u8f38\u5165\u7684\u5167\u5bb9\uff0c\u4e26\u900f\u904e\u7aca\u8cc7\u8edf\u9ad4\u3001PowerShell\u6307\u4ee4\u78bc\u6316\u6398\u700f\u89bd\u5668\u5b58\u653e\u7684\u7528\u6236\u8cc7\u6599\u3002<\/p>\n\n\n\n<p>\u5f9e\u53bb\u5e74\u958b\u59cb\uff0c\u5c0d\u65b9\u4e0d\u53ea\u6feb\u7528MSBuild\u8f09\u5165\u524d\u8ff0\u5f8c\u9580\u7a0b\u5f0f\uff0c\u9084\u6703\u90e8\u7f72Gh0st RAT\u8b8a\u7a2e\uff0c\u7814\u7a76\u4eba\u54e1\u770b\u5230SilentGh0st\u3001InsidiousGh0st\u3001TranslucentGh0st\u3001EtherealGh0st\u3001FluffyGh0st\u7b49\u591a\u6b3e\u8b8a\u7a2e\u7a0b\u5f0f\u3002<\/p>\n\n\n\n<p>\u6700\u7d42\u99ed\u5ba2\u900f\u904ecurl\u5de5\u5177\uff0c\u4e26\u5229\u7528FTP\u5354\u5b9a\u5916\u50b3\u7aca\u5f97\u7684\u8cc7\u6599\uff0c\u904e\u7a0b\u4e2d\u6feb\u7528\u52d5\u614b\u7522\u751f\u7684\u5e33\u5bc6\u96b1\u533f\u6d41\u91cf\u3002<\/p>\n\n\n\n<p>\u8cc7\u6599\u4f86\u6e90:<a href=\"https:\/\/www.ithome.com.tw\/news\/163055\" data-type=\"link\" data-id=\"https:\/\/www.ithome.com.tw\/news\/163055\">https:\/\/www.ithome.com.tw\/news\/163055<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>2024-05-23 | \u5468\u5cfb\u4f51 \u8cc7\u5b89\u696d\u8005Bitdefender\u63ed\u9732\u5c08\u9580\u9396\u5b9a\u5357\u6d77\u570b\u5bb6\u653f\u5e9c\u9ad8\u5c64\u7684\u4e2d\u570b\u99ed\u5ba2\u7d44\u7e54Unfading Sea Haze\uff0c\u4ed6\u5011\u78ba\u8a8d\u81f3\u5c11\u67098\u500b\u8ecd\u4e8b\u55ae\u4f4d\u8207\u653f\u5e9c\u6a5f\u95dc\u53d7&hellip;<\/p>\n","protected":false},"author":9,"featured_media":6047,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[352],"tags":[204],"class_list":["post-6046","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information-security","tag-204"],"gutentor_comment":0,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/aict.nkust.edu.tw\/digitrans\/wp-content\/uploads\/2024\/05\/unfading-sea-haze-156.jpg?fit=960%2C420&ssl=1","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/6046","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6046"}],"version-history":[{"count":1,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/6046\/revisions"}],"predecessor-version":[{"id":6048,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/6046\/revisions\/6048"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/media\/6047"}],"wp:attachment":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6046"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6046"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6046"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}