关键词
APT、BLINDEAGLE、APT-C-36、钓鱼攻击
盲眼鹰添加到QuasarRAT的一些额外功能包括一个名为“ActivarRDP”(激活RDP)的功能,以及另外两个用于激活和停用系统代理的功能:
ByAV2.py:
mp.py:
8e864940a97206705b29e645a2c2402c2192858357205213567838443572f564 | EML Colombia |
2702ea04dcbbbc3341eeffb494b692e15a50fbd264b1d676b56242aae3dd9001 | PDF Colombia |
f80eb2fcefb648f5449c618e83c4261f977b18b979aacac2b318a47e99c19f64 | PDF Colombia |
68af317ffde8639edf2562481912161cf398f0edba6e06745d90c1359554c76e | LHA (zip file) |
61685ea4dc4ca4d01e0513d5e23ee04fc9758d6b189325b34d5b16da254cc9f4 | EXE |
https://www.mediafire[.]com/file/cfnw8rwufptk5jz/migracioncolombiaprocesopendienteid2036521045875referenciawwwmigraciongovco.LHA/file | LHA download link |
https://gtly[.]to/QvlFV_zgh | Dropper domain |
https://gtly[.]to/cuOv3gNDi | Dropper domain |
https://gtly[.]to/dGBeBqd8z | Dropper domain (Py2EXE) |
laminascol[.]linkpc[.]net | QuasarRAT C2 |
systemwin[.]linkpc[.]net | Meterpreter C2 |
upxsystems[.]com | Ecuador mid-infection C2 |
c63d15fe69a76186e4049960337d8c04c6230e4c2d3d3164d3531674f5f74cdf | wins (inicio0) |
353406209dea860decac0363d590096e2a8717dd37d6b4d8b0272b02ad82472e | wins (PowerShell) |
a03259900d4b095d7494944c50d24115c99c54f3c930bea08a43a8f0a1da5a2e | 0 (Windows 10 Powershell) |
46addee80c4c882b8a6903cced9b6c0130ec327ae8a59c5946bb954ccea64a12 | 0 (Windows 8 Powershell) |
c067869ac346d007a17e2e91c1e04ca0f980e8e9c4fd5c7baa0cb0cc2398fe59 | 0 (Windows 7 Powershell) |
10fd1b81c5774c1cc6c00cc06b3ed181b2d78191c58b8e9b54fa302e4990b13d | ByAV2.py |
c4ff3fb6a02ca0e51464b1ba161c0a7387b405c78ead528a645d08ad3e696b12 | mp.py |
ac1ea54f35fe9107af1aef370e4de4dc504c8523ddaae10d95beae5a3bf67716 | InMemoryMeterpreter |
参考链接:https://research.checkpoint.com/2023/blindeagle-targeting-ecuador-with-sharpened-tools/
编辑|董放明
审校|何双泽、王仁
本文为CNTIC编译整理,不代表本公众号观点,转载请保留出处与链接。联系信息进入公众号后点击“关于我们”可见。