È«Ììºò¹¥»÷£ºÎïÁªÍø½©Ê¬ÍøÂçGorillaBot½ÒÃØ

Ðû²¼Ê±¼ä 2025-01-07

µ¼Ó


bevictorΰµÂÓë¹ãÖÝ´óÑ§Íø°²Ñ§Ôº¼à²âµ½Ò»¸ö×Ô³ÆGorillaBotµÄÎïÁªÍø½©Ê¬ÍøÂç¡£¡£¡£±¾ÎÄͨ¹ý¶Ô¸Ã½©Ê¬ÍøÂç¾ÙÐÐÑù±¾ÊÖÒÕÆÊÎö£¬£¬£¬ÖÜÈ«ÏÈÈÝÁËÆä»ù±¾ÐÅÏ¢¡¢¹¥»÷Ä¿µÄ¡¢Èö²¥·½·¨µÈϸ½Ú£¬£¬£¬ÒÔ×÷Ϊ¸÷ÐÐÒµ¼°Ïà¹ØÆóÒµÖÆ¶©ÍøÂçÇå¾²Õ½ÂԵIJο¼¡£¡£¡£


2024Äê9Ô³õ£¬£¬£¬bevictorΰµÂÔÚ¼ÓÈë¹ú¼ÒÖØµãÑз¢ÍýÏëÏîÄ¿¡°´ó¹æÄ£Òì¹¹ÎïÁªÍøÍþв¿É¿Ø²¶»ñÓëÆÊÎöÊÖÒÕ£¨2022YFB3104100£©¡±µÄÑо¿Àú³ÌÖУ¬£¬£¬¼à²âµ½ÁËÒ»¸ö×Ô³ÆGorillaBotµÄÎïÁªÍø½©Ê¬ÍøÂç¡£¡£¡£


×Ô¾õÏÖÒÔÀ´£¬£¬£¬GorillaBot½©Ê¬ÍøÂçÔÚÌᳫÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷·½ÃæÌåÏÖ³öÒì³£» £»£»£»îÔ¾µÄÌ¬ÊÆ¡£¡£¡£Æ¾Ö¤¼à²âͳ¼Æ£¬£¬£¬×èÖ¹9ÔÂ⣬£¬£¬¸Ã½©Ê¬ÍøÂçµÄÏÂÁîÓë¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷ÒÑÏ·¢Áè¼Ý30ÍòÌõ¹¥»÷Ö¸Áî¡£¡£¡£±ðµÄ£¬£¬£¬GorillaBotËù·¢¶¯µÄDDoS¹¥»÷·ºÆð³öÈ«Ììºò¡¢24Сʱ²»ÖÐÖ¹µÄÌØµã£¬£¬£¬²î±ðÓÚһЩÓмÍÂÉ×÷ϢģʽµÄ¹¥»÷ÐÐΪ£¬£¬£¬´Ë´Î¹¥»÷ûÓÐÌåÏÖ³öÈκÎÐÝÏ¢»òÏ÷ÈõµÄ¼£Ï󣬣¬£¬ÏÔʾ³ö¹¥»÷ÕßÒâÔÚºã¾Ãά³Ö¸ßÑ¹Ì¬ÊÆ£¬£¬£¬¶ÔÄ¿µÄÔì³ÉÒ»Á¬ÐÔµÄѹÁ¦ºÍË𺦡£¡£¡£


¹¥»÷Ô˶¯Ò»Ö±Ò»Á¬µ½11ÔÂÏÂÑ®£¬£¬£¬Ê±´úÎÒÃÇÊӲ쵽C2ЧÀÍÆ÷µÄÊýÄ¿Öð½¥ïÔÌ­£¬£¬£¬×îÖÕÏÂÏß¡£¡£¡£È»¶ø£¬£¬£¬µ½ÁË12Ô£¬£¬£¬ÐµÄGorillaBotÑù±¾ÔٴηºÆð£¬£¬£¬²¢Ñ¸ËÙ°²ÅÅÁËÒ»Ì×ȫеÄC2»ù´¡ÉèÊ©£¬£¬£¬ÖØÐ»ָ´²¢Î¬³ÖÁ˸ßÇ¿¶ÈµÄÈ«Ììºò¹¥»÷Ì¬ÊÆ¡£¡£¡£


ͼƬ1.jpg


ÊÖÒÕÆÊÎö


1¡¢»ù±¾ÐÅÏ¢


GorillaBotͬÑù»ùÓÚMirai¾ÙÐеĶþ´Î¿ª·¢¡£¡£¡£ÔÚ9Ô·ݲ¶»ñµÄÑù±¾ÏÕЩÍêÈ«¸´ÓÃÁËMiraiµÄÔ´´úÂ룬£¬£¬²¢ÔÚ´Ë»ù´¡ÉÏÒýÈëÁ˶àÖÖеÄDDoS¹¥»÷ÒªÁ죬£¬£¬ÔöÇ¿ÁËÆä¹¥»÷ÄÜÁ¦¡£¡£¡£´Ó10Ô·Ý×îÏÈ£¬£¬£¬Æä´úÂë×îÏȾÙÐÐÓÅ»¯µ÷½â£¬£¬£¬Ð°汾ÔÚͨѶЭÒéÖÐÒýÈëÁ˼ÓÃܼ°Ð£Ñé»úÖÆ£¬£¬£¬½øÒ»²½ÔöÇ¿ÁËÆä¹¥»÷Ô˶¯µÄÒþ²ØÐԺͿ¹×ÌÈÅÄÜÁ¦£¬£¬£¬²¢ÇÒÒ»Ö±¼á³Öµ½ÁËÏÖÔÚ¡£¡£¡£


ÔËÐк󣬣¬£¬Ëü»áÔÚÆÁÄ»ÉÏ´òÓ¡×Ö·û´®¡°The Gorilla Botnet Cats Came After You!¡±£¬£¬£¬ÕâÒ²ÊÇGorillaBotÃû³ÆµÄÓÉÀ´¡£¡£¡£


GorillaBotÖÂÁ¦ÓÚ¶àÆ½Ì¨ÊÊÅäÊÂÇ飬£¬£¬Ö¼ÔÚÀ©´óÆäDZÔÚѬȾ¹æÄ£¡£¡£¡£×Ô9Ô·ÝÒÔÀ´£¬£¬£¬ËüÒѾ­Ö§³ÖÁ˰üÀ¨arm¡¢misp¡¢x86_64ÒÔ¼°x86ÔÚÄڵĶàÖÖCPU¼Ü¹¹¡£¡£¡£Ëæ×Ű汾µü´ú£¬£¬£¬ÔÚ10Ô·ÝÐÂÔöÁ˶Ômipsel¼Ü¹¹µÄÖ§³Ö£» £»£»£»µ½12Ô£¬£¬£¬ÓÖ½øÒ»²½À©Õ¹ÖÁm68k¡¢sh4ºÍsparcµÈ¸ü¶àÑù»¯µÄ´¦Öóͷ£Æ÷ÀàÐÍ¡£¡£¡£


2¡¢¹¥»÷Ä¿µÄ


×èÖ¹ÏÖÔÚ£¬£¬£¬GorillaBotµÄ¹¥»÷Ô˶¯ÒѾ­²¨¼°È«ÇòÁè¼Ý130¸ö¹ú¼ÒºÍµØÇø¡£¡£¡£Æä¹¥»÷Ä¿µÄÉæ¼°ÖÖÖÖÐÐÒµÁìÓò£¬£¬£¬°üÀ¨µ«²»ÏÞÓÚµçÐÅ¡¢ÔËÓªÉÌ¡¢ÒøÐС¢ÔÆÅÌËãÊý¾ÝÖÐÐÄ¡¢ÓÎÏ·¡¢½ÌÓý¡¢Õþ¸®ÍøÕ¾¡¢²©²ÊµÈ¡£¡£¡£ÓÈÆäÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬ÖйúºÍÃÀ¹úÊǴ˴ι¥»÷Ô˶¯Êܺ¦×îΪÑÏÖØµÄÁ½¸ö¹ú¼Ò¡£¡£¡£


ͼƬ2.jpg


º£ÄÚÓÐ4300¶à¸öÄ¿µÄIP±»¹¥»÷£¬£¬£¬º­¸ÇÌìÏÂËùÓÐÊ¡¼¶ÐÐÕþÇø£¬£¬£¬°üÀ¨¸Û°Ą̈¡£¡£¡£´ÓµØÇøÂþÑÜÀ´¿´£¬£¬£¬Êܺ¦×îÑÏÖØµÄµØÇøÊÇÏã¸Û¡¢Õã½­¡¢¹ã¶«¡¢ºþ±±¡¢½­ËÕµÈÊ¡·Ý¡£¡£¡£


ͼƬ3.jpg


ÁíÍ⣬£¬£¬´Ó¹¥»÷·½·¨À´¿´£¬£¬£¬GorillaBot¸üÇãÏòÓÚÌᳫUDPЭÒéµÄDDoS¹¥»÷£¬£¬£¬Õ¼Õû¸ö¹¥»÷Ô˶¯µÄ42%ÒÔÉÏ¡£¡£¡£°üÀ¨udp_plain¡¢vse¡¢udp_discord¡¢udp_a2s¡¢udp_fivem¡¢udp_openvpn¡£¡£¡£


ͼƬ4.jpg


3¡¢Èö²¥·½·¨


GorillaBotÖ÷ҪʹÓÃTelnetÈõ¿ÚÁî²Â½âµÄ·½·¨À©É¢£¬£¬£¬Í¨¹ýÄÚÖÃÓ²±àÂëµÄ96ÖÖ³£¼ûÈõ¿ÚÁî×éºÏʵÑéδ¾­ÊÚȨ»á¼û×°±¸¡£¡£¡£


ÔÚ9Ô³õµÄÔçÆÚÑù±¾ÖУ¬£¬£¬GorillaBotÔø¶ÌÔݵØÊ¹ÓÃÁËHadoop Yarn RPCδÊÚȨ»á¼ûÎó²îÀ´¾ÙÐÐÈö²¥£¬£¬£¬Ëæºó¸üбãÒÆ³ýÁËÕë¶ÔHadoopÎó²îµÄʹÓôúÂ룬£¬£¬×îÖÕ½ö±£´æÁË»ùÓÚTelnetÈõ¿ÚÁÁ¦ÆÆ½âÕâÒ»¼òÆÓ¸ßЧµÄ¹Å°åÈö²¥ÊֶΡ£¡£¡£


ͼƬ5.jpg


ÐÐΪÆÊÎö


1¡¢³õʼ»¯


ÔÚ2024Äê9ÔµÄÔçÆÚÑù±¾ÖУ¬£¬£¬ÎÒÃÇ·¢Ã÷ÁË´ó×ÚÓëµ÷ÊÔÆ÷¼ì²âÏà¹ØµÄ×Ö·û´®¡£¡£¡£ÕâЩ×Ö·û´®µÄ±£´æÅú×¢¹¥»÷ÕßÓÐÒâͼµØÉè¼ÆÁËÖØ´óµÄÂß¼­À´Ê¶±ðÊÇ·ñ±£´æµ÷ÊÔ¹¤¾ßÕýÔÚ¼à¿Ø»òÐÞ¸ÄÆäÐÐΪ¡£¡£¡£ÒÔÏÂÊÇһЩÔÚÔçÆÚÑù±¾Öз¢Ã÷µÄµä·¶µ÷ÊÔÆ÷¼ì²â×Ö·û´®Ê¾Àý£º


ͼƬ6.jpg


¿ÉÊÇ£¬£¬£¬²¢Î´·¢Ã÷ÕâЩ×Ö·û´®ÓÐÈκÎÏÖʵÒýÓ㬣¬£¬Ò²Î´ÄÜÕÒµ½ÆäËü¼ì²âµ÷ÊÔÆ÷µÄ´úÂë¡£¡£¡£ÕâÅú×¢ËäÈ»GorillaBotµÄ¿ª·¢ÕßËÆºõÓÐÒâͼ¼ÓÈëµ÷ÊÔÆ÷¼ì²â¹¦Ð§£¬£¬£¬µ«Ôڸð汾ÖÐÕâЩ¹¦Ð§¿ÉÄÜ»¹Ã»ÓÐʵÏÖ¡£¡£¡£


×Ô2024Äê10ÔÂÆð£¬£¬£¬GorillaBotÑù±¾ÒýÈëÁËÏÖʵµÄµ÷ÊÔÆ÷¼ì²â»úÖÆ¡£¡£¡£Ê×ÏÈͨ¹ý¼ì²â"/proc/self/status"ÎļþÖеÄ"TracerPid"×Ö¶ÎÀ´¼ì²âµ÷ÊÔÆ÷¡£¡£¡£ÈôÊǼì²âµ½µ÷ÊÔÆ÷ÔòÁ¬Ã¦Í˳öÀú³Ì¡£¡£¡£


ͼƬ7.jpg


¼Ì¶øÍ¨¹ý¼ì²éÎļþ"/proc"ÎļþÊÇ·ñ±£´æ£¬£¬£¬×÷ΪÅжÏÄ¿½ñÇéÐÎÊÇ·ñΪÃÛ¹ÞµÄÒÀ¾Ý¡£¡£¡£


ͼƬ8.jpg


Ëæºó¼ì²écgroupÐÅÏ¢ÖеÄÌØ¶¨×Ö·û´®À´ÅжÏÊÇ·ñÔËÐÐÔÚÈÝÆ÷ÇéÐÎÖУ¬£¬£¬ÌØÊâÊDzéÕÒ°üÀ¨"kubepods"µÄ×Ö·û´®¡£¡£¡£


ͼƬ9.jpg


ΪÁËÈ·±£ÔÚÏµÍ³ÖØÆôºóÈÔÄÜÖ´ÐУ¬£¬£¬GorillaBot½ÓÄÉÁ˽¨ÉèϵͳЧÀ͵ķ½·¨ÊµÏÖ³¤ÆÚ»¯¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬Ëü»áÔÚ/etc/systemd/system/Ŀ¼Ï½¨ÉèÒ»¸öÃûΪcustom.serviceµÄЧÀÍÎļþ£¬£¬£¬Ê¹ÆäÄܹ»ÔÚϵͳÆô¶¯Ê±×Ô¶¯ÔËÐС£¡£¡£


ͼƬ10.jpg


custom.serviceЧÀ͵Ľ¹µã¹¦Ð§ÊÇÏÂÔØÃûΪlol.shµÄ¾ç±¾µ½/tmp/Ŀ¼£¬£¬£¬ÉèÖÃÖ´ÐÐȨÏÞ²¢Ö´ÐС£¡£¡£ÏÂÔØÁ´½ÓÀ´×ÔÓ²±àÂëµÄ×Ö·û´®"kwws=22;:14531;7157:2oro1vk"£¬£¬£¬ÒÀ´Î¼õÈ¥0x03¼´¿É½âÃܳöÏÂÔØÁ´½Ó¡£¡£¡£


ͼƬ11.jpg


ΪÁ˽øÒ»²½È·±£Æä³¤ÆÚÐÔ£¬£¬£¬GorillaBot»¹»á¶ÔÒªº¦ÏµÍ³ÉèÖÃÎļþ(/etc/inittab¡¢/etc/profile¡¢/boot/bootcmd)¾ÙÐÐÐÞ¸ÄÌí¼ÓÏÂÁ£¬£¬ÒÔʵÏÖÔÚϵͳµÄ²î±ðÆô¶¯½×¶Î×Ô¶¯ÏÂÔØ²¢Ö´ÐÐlol.sh¾ç±¾¡£¡£¡£


ͼƬ12.jpg


ÔÚ/etc/init.d/Ŀ¼Ï½¨ÉèÃûΪ"mybinary"»òÕß"system"µÄ¾ç±¾£¬£¬£¬ÉèÖÃËüÔÚϵͳÆô¶¯Ê±Ö´ÐУ¬£¬£¬È¥ÏÂÔØÏÂÔØÖ´ÐÐlol.sh¾ç±¾¡£¡£¡£


ͼƬ13.jpg


±ðµÄ£¬£¬£¬GorillaBot»¹»áʵÑéÔÚ/etc/rc.d/rc.local»ò/etc/rc.conf£¨ÈôÊDz»±£´æ£©ÖÐÌí¼ÓÖ¸Ïò"mybinary"»òÕß"system"µÄÈíÁ´½Ó£¬£¬£¬ÒÔÈ·±£ÔÚϵͳÆô¶¯Ê±×Ô¶¯Ö´Ðиþ籾¡£¡£¡£


ÕâÖÖ¶àÌõÀí¡¢¶à;¾¶µÄ³¤ÆÚ»¯Õ½ÂԼȷ´Ó¦ÁËGorillaBot¿ª·¢Õß¶Ôϵͳ»úÖÆÓкÜÉî¿ÌµÄÃ÷È·£¬£¬£¬Ò²Åú×¢ÎúÖÂÁ¦ÓÚºã¾Ã¿ØÖÆÊÜѬȾÕßµÄ×°±¸¡£¡£¡£


ÉÏÊö°ì·¨Íê³ÉÖ®ºó£¬£¬£¬Ôò½øÈëMiraiÀàÎïÁªÍø½©Ê¬ÍøÂç³£¼ûµÄÖ´ÐÐÁ÷³Ì£º¼àÌý38242¶Ë¿ÚÒÔʵÏÖ¼òµ¥Àú³ÌʵÀý¡¢¿ªÆôtelnetɨÃèµÈ£¬£¬£¬ËæºóºÍC2½¨ÉèͨѶ²¢ÆÚ´ýÖ´ÐÐC2Ï·¢µÄDDoSÏÂÁî¡£¡£¡£


2¡¢C2ЧÀÍÆ÷


9Ô·ݵÄGorillaBotÑù±¾Ó²±àÂë5¸öC2£¬£¬£¬¼õÈ¥0x03¼´¿É½âÃÜ¡£¡£¡£10ÔÂ·ÝÆð£¬£¬£¬ÒýÈëÒ»¸öºÜÊÇÖØ´óµÄ¼ÓÃܺ¯Êýenc_switch£¬£¬£¬ÓÃÀ´½âÃÜC2ЧÀÍÆ÷×Ö·û´®£¬£¬£¬Ã¿¸öC2¶¼ÓÐÒ»¸öµÄÃÜÔ¿¡£¡£¡£


ͼƬ14.jpg


×Åʵ10Ô·ÝÖ®ºóµÄÑù±¾£¬£¬£¬C2ͨѶ¿ªÆô¼ÓÃÜÑéÖ¤£¬£¬£¬¼ÓÃÜҲʹÓÃenc_switchº¯Êý¡£¡£¡£ÏÔÈ»£¬£¬£¬×ÅʵÏÖµÄÊÇijÖֶԳƼÓÃÜËã·¨¡£¡£¡£12Ô·ݵÄÑù±¾Ö»ÓÐÒ»¸öÓ²±àÂëµÄÃ÷ÎÄC2ЧÀÍÆ÷£¬£¬£¬²»ÔÙ¼ÓÃÜC2×Ö·û´®¡£¡£¡£


3¡¢Í¨Ñ¶Ð­Òé


9Ô³õµÄÑù±¾ÍêÈ«¸´¿ÌÁËMiraiµÄͨѶЭÒ飬£¬£¬°üÀ¨ÉÏÏßÊý¾Ý£¬£¬£¬ÐÄÌø°üÒÔ¼°¹¥»÷ÏÂÁîµÈ¸÷·½Ãæ¶¼ºÍMiraiûÓÐÈκÎÇø±ð¡£¡£¡£10ÔÂ·ÝÆð£¬£¬£¬Ñù±¾ÔÚ×ÜÌå±£´æMiraiͨѶЭÒéµÄͬʱ£¬£¬£¬Ð¼ÓÈëÁ˼ÓÃܺÍУÑé»úÖÆ¡£¡£¡£ÒÔÉÏÏßÊý¾ÝÓë¹¥»÷Ö¸ÁîΪÀý¡£¡£¡£


3.1 ÉÏÏßÊý¾Ý


ͼƬ15.jpg


ÅþÁ¬C2Àֳɺ󣬣¬£¬Ê×ÏÈÏòC2·¢ËÍ1×Ö½ÚµÄ0x01¡£¡£¡£C2ÏòBot·µ»Ø4×Ö½ÚµÄËæ»úÊý¾Ý£¬£¬£¬±¾ÀýÊÇ"\x3f\xf3\x05\x62"¡£¡£¡£GorillaBotͨ¹ý¶Ô³Æ¼ÓÃÜËã·¨£¬£¬£¬¼ÓÃÜÉÏÊö4×Ö½ÚÊý¾Ý£¬£¬£¬ÅÌËãÃÜÎĵÄSha256£¬£¬£¬²¢·¢Ë͸øC2¡£¡£¡£C2ÔÚÊÕµ½ÃÜÎĵÄSha256£¬£¬£¬Ð£ÑéÎÞÎóÖ®ºó£¬£¬£¬·µ»Ø1×Ö½ÚµÄ0x01×÷ΪÈÏ֤ͨ¹ýÊý¾Ý¡£¡£¡£ËæºóGorillaBot·¢Ëͱ£´æµÄMiraiЭÒéÊý¾Ý£¬£¬£¬ÖÁ´ËÉÏÏßÀֳɣ¬£¬£¬½øÈëÏ໥·¢ËÍÐÄÌø°üÒÔ¼°Ï·¢DDoSÖ¸Áî½×¶Î¡£¡£¡£´ÓÉÏÏßµ½C2Ï·¢DDoS¹¥»÷Ö¸Á£¬£¬Õû¸ö½»»¥Á÷³ÌÈçÏ£º


ͼƬ16.jpg


3.2 ¹¥»÷Ö¸Áî


×Ô9Ô·ݷºÆðÒÁʼ£¬£¬£¬GorillaBot¾Í½øÈëÒì³£» £»£»£»îÔ¾µÄ¹¥»÷½×¶Î¡£¡£¡£C2ÌìÌìÏ·¢µÄDDoS¹¥»÷Ö¸ÁîÊýÄ¿¾ªÈË£¬£¬£¬µÖ´ï1ÍòÌõÉõÖÁ2ÍòÌõÒÔÉÏ¡£¡£¡£¸üÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬GorillaBotµÄ¹¥»÷ÊÇÈ«ÌìºòµÄ£¬£¬£¬Ò»Ìì24СʱÄÚ¶¼ÔÚ²»ÖÐֹϷ¢¹¥»÷Ö¸Á£¬£¬Ã»ÓÐÈκÎÐÝÏ¢ÖÐֹʱ¼ä¡£¡£¡£


GorillaBotµÄ¹¥»÷Ö¸ÁîÔØºÉÊý¾ÝʹÓð´×Ö½Ú¼Ó0x03µÄ·½·¨¼ÓÃÜ£¬£¬£¬¶Ô¼ÓÃܺóÊý¾ÝµÄÅÌËãSha256£¬£¬£¬×÷ΪУÑéֵʹÓᣡ£¡£


ͼƬ17.jpg

ͼƬ18.jpg


GorillaBotÔÚÎüÊÕµ½DDoS¹¥»÷Ö¸Áîºó£¬£¬£¬ÏÈУÑé¹¥»÷Ö¸ÁîÔØºÉÊý¾ÝµÄSha256£¬£¬£¬Ð£Ñéͨ¹ýÖ®ºó£¬£¬£¬ÔÙ¼õÈ¥0x03½âÃÜ¡£¡£¡£ËæºóŲÓÃattack_parseº¯ÊýÈ¥Ö´ÐС£¡£¡£


ÒÔijDDoS¹¥»÷Ö¸ÁîΪÀý£º


ͼƬ19.jpg


ǰ2×Ö½ÚÊDZ¾Ö¡DDoS¹¥»÷Ö¸ÁîµÄÊý¾Ý³¤¶È¼õÈ¥2£¬£¬£¬Ëæºó32×Ö½ÚÊÇDDoS¹¥»÷Ö¸ÁîÔØºÉÊý¾ÝµÄSha256УÑéÖµ¡£¡£¡£ÉÏͼÂÌÉ«²¿·ÖÊÇSha256УÑéÖµ£¬£¬£¬´ÓÆ«ÒÆ34µ½×îºóÊǵĺìÉ«²¿·ÖÊÇÕæÕýµÄDDoS¹¥»÷Ö¸ÁîÔØºÉÊý¾Ý¡£¡£¡£ÑéÖ¤ÈçÏ£º


ͼƬ20.jpg


DDoS¹¥»÷Ö¸ÁîÔØºÉÊý¾Ý¼õÈ¥0x03¼´¿É½âÃÜ£¬£¬£¬ÈçÏ£º


ͼƬ21.jpg


½âÃܺóµÄDDoS¹¥»÷Ö¸ÁîÔØºÉÊý¾ÝºÍMiraiÍêȫһÖ¡£¡£¡£ÊÂʵÉÏ£¬£¬£¬×ÐϸÊÓ²ì»á·¢Ã÷£¬£¬£¬ÈôÊÇÈ¥µôSha256УÑéºÍ¼ÓÃÜ£¬£¬£¬ËüÍêÈ«¾ÍÊÇMiraiµÄ¹¥»÷Ö¸ÁîÃûÌᣡ£¡£ÉÏÊö¹¥»÷Ö¸Áî¼òÒªÐÎòÈçÏ£º


ͼƬ22.jpg


Òò´Ë£¬£¬£¬ÉÏÊöDDoS¹¥»÷Ö¸Áî¼´ÊÇÏòÖ¸¶¨Ä¿µÄ159.xxx.xxx.29:80£¬£¬£¬Ìᳫattack_udp_vseÀàÐ͵Ĺ¥»÷£¬£¬£¬Ò»Á¬120ÃëÖÓ¡£¡£¡£¹¥»÷Á÷Á¿ÈçÏ£º


ͼƬ23.jpg


ÏÖÔÚ£¬£¬£¬GorillaBotÏÖÔÚ¹²Ö§³Ö20¸ö DDoS¹¥»÷ÀàÐÍ£¬£¬£¬ÈçÏ£º


ͼƬ24.jpg


×ܽá


×èÖ¹ÏÖÔÚ£¬£¬£¬GorillaBot½©Ê¬ÍøÂçÈÔÈ»´¦Óڸ߶ȻîԾ״̬£¬£¬£¬ÌìÌìͨ¹ýC2ЧÀÍÆ÷Ï·¢¿¿½üÒ»ÍòÌõ¹¥»÷Ö¸Á£¬£¬¶ÔÈ«Çò¹æÄ£ÄÚµÄÄ¿µÄIPµØµãÒ»Á¬ÌᳫÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷£¬£¬£¬Ó°ÏìÁË´Ó½ðÈÚµ½¹«¹²Ð§À͵ȶà¸öÒªº¦ÐÐÒµ¡£¡£¡£ËüÈ«Ììºò¡¢ÎÞÖÐÖ¹µØ¶ÔÈ«Çò¸÷µØµÄÄ¿µÄ¾ÙÐй¥»÷£¬£¬£¬²»µ«ÆµÂʸ߲¢ÇÒÁýÕ֯ձ飬£¬£¬ÒѾ­³ÉΪµ±½ñ»¥ÁªÍøÇå¾²ÁìÓòµÄÒ»´óÍþв¡£¡£¡£


±ðµÄ£¬£¬£¬GorillaBotÈÔÔÚÒ»Ö±¸üÐÂÆä´úÂë¿âÒÔ¼á³Ö×îÐµĹ¥»÷ÄÜÁ¦¡£¡£¡£Ö»¹ÜÕâЩ¸üдó¶à¼¯ÖÐÔÚϸ΢֮´¦£¬£¬£¬²¢Î´·ºÆð¸ïÃüÐÔµÄת±ä£¬£¬£¬ÎÒÃÇÈÔ»á¼ÌÐø¸ú×ÙÊӲ죬£¬£¬ÓÈÆäÊÇÆä¹¥»÷Ä¿µÄµÄÑ¡ÔñÒÔ¼°¹¥»÷ÄÜÁ¦µÄ½ø»¯¡£¡£¡£Í¬Ê±£¬£¬£¬Ò²ÌáÐѸ÷»ú¹¹ºÍСÎÒ˽¼ÒÓû§ÔöÇ¿¶ÔÍøÂçÇå¾²·À»¤²½·¥µÄÖØÊÓ£¬£¬£¬Èçʵʱ¸üÐÂÈí¼þ²¹¶¡¡¢Ç¿»¯ÃÜÂëÖÎÀíµÈ£¬£¬£¬ÒÔ½µµÍÔâÊܹ¥»÷µÄΣº¦¡£¡£¡£


IOC


C2£º

45.202.35.64:38242
87.120.84.105:38242
87.120.84.248:38242
87.120.84.249:38242
91.92.246.113:38242
93.123.85.166:38242
94.156.227.234:38242
154.216.17.220:38242
154.216.19.139:38242
185.170.144.84:38242
193.143.1.59:38242
185.208.158.192:38242


LOL Download URL£º

http://87.120.84.247/lol.sh
http://94.156.227.233/lol.sh
http://154.216.19.140/lol.sh
http://pen.gorillafirewall.su/lol.sh
http://193.143.1.70/lol.sh
http://154.216.17.182/lol
http://154.216.17.208/lol
http://154.216.18.173/lol
http://154.216.19.140/lol
http://154.216.19.61/lol
http://154.216.19.99/lol
http://154.216.20.14/lol
http://154.216.20.45/lol
http://185.170.144.49/lol
http://185.208.158.215/lol
http://45.202.35.35/lol
http://45.66.231.26/lol
http://45.88.88.41/lol
http://45.89.247.112/lol
http://46.8.69.32/lol
http://66.63.187.145/lol
http://66.63.187.216/lol
http://87.120.166.20/lol
http://87.120.84.247/lol
http://91.208.197.4/lol
http://91.92.247.42/lol
http://93.123.85.225/lol
http://94.156.177.68/lol
http://94.156.65.232/lol
http://ms-email-recoveryid.line.pm/lol
http://pen.gorillafirewall.su/lol
http://www.protectorkrmnts.info/lol
http://www.xn--girsdom-9ya.com/lol
http://xn--girsdom-9ya.com/lol


SHA256£º

1276a39c595af5b314111387ef58fd3fc11c55e62a140b8a2c4ff0132b648243

23459e531e09663d4fe7b1d3cca93b278eabe438e843f33dea95124fe9bb081d

23c870185f29b1e92dbd10993e944c69dc50fc58cc2ee3e79712c9b5f3dd50d1

2970ffa62f3033c64a781ce28395103f6d0385b2b67988ad554c14c2440a4508

6d44898df317ce936f82196b60c65e1038610ce4e9d4e8ef8151d798af140a0d

3aaee5e38481750900c5949aa54e45acd43a162d009f04ec24893cd2ecb38d73

3c60e9e280de8798ffebfdd361f2fbbafe78c65e4ba0579ae1717684594a2ed5

3905126f5f9f7430dee31c207706852e56292291449b563781bc6ee0b540343a

549627b2ba0ef60640456a03a70e46d4c45726443fd9ac4f48bddb8aab625c9b

78cbf2863748c64ea013c2676744de4090a9029c00aade1b7cf9e698c1f95b56

ec194196bdb79b046a5dfab35a70e301376f29fa841698bf3819850168d0b09f

d339e88fd6b6f2ad713c835639d09022cbc92d55dab8a0a5006c18ca5d8e01a9

ff88b732f6fbcf440c03b1de170ab6d3b489477c93daca5057c5a7344d05f5b2



×¢£º


bevictorΰµÂÊǹú¼ÒÖØµãÑз¢ÍýÏëÏîÄ¿¡°´ó¹æÄ£Òì¹¹ÎïÁªÍøÍþв¿É¿Ø²¶»ñÓëÆÊÎöÊÖÒÕ£¨2022YFB3104100£©¡±¿ÎÌâÒ»¡°Òì¹¹ÎïÁªÍø½©Ê¬ÍøÂçÍþв¸ÐÖªÒªº¦ÊÖÒÕ¼°ÏµÍ³£¨2022YFB3104101£©¡±µÄ½¹µã¼ç¸ºµ¥Î»Ö®Ò»£¬£¬£¬Óë¿ÎÌâËÄ¡°¸ßÖÊÁ¿¹¥»÷Êý¾ÝÓÕ²¶ÓëÆÊÎöÒªº¦ÊÖÒÕ¼°ÏµÍ³£¨2022YFB3104104£©¡±Ç£Í·µ¥Î»º£¿£¿µÍþÊÓÅäºÏÈÏÕæÏîÄ¿ÖеĶñÒâ´úÂëÆÊÎöÊÂÇé¡£¡£¡£ÏîÄ¿¼°¿ÎÌâ¾ùÓɹãÖÝ´óÑ§ÍøÂç¿Õ¼äÇ徲ѧԺǣͷ£¬£¬£¬Ö¼ÔÚ¹¹½¨´ó¹æÄ£ÎïÁªÍø¹¥»÷Íþв×Ô¶¯·À»¤ÄÜÁ¦¡£¡£¡£