СÐÄ£º½üÆÚÕë¶Ôµç×ÓÔªÆ÷¼þÐÐÒµµÄ¹¥»÷Ô˶¯ÆÊÎö
Ðû²¼Ê±¼ä 2021-09-13Ò»¡¢¸ÅÊö
½üÆÚ£¬£¬£¬£¬£¬bevictorΰµÂADLab²¶»ñµ½¶àÆðÕë¶Ôµç×ÓÔªÆ÷¼þÆóÒµµÄ´¹ÂÚÓʼþ¹¥»÷Ô˶¯£¬£¬£¬£¬£¬¹¥»÷Ä¿µÄÉæ¼°¶à¼Òµç×ÓÔªÆ÷¼þÐÐÒµµÄÉÏÊй«Ë¾»òÉÏÏÂÓι©Ó¦ÉÌ£¬£¬£¬£¬£¬°üÀ¨ÌìÂí΢µç×ӹɷÝÓÐÏÞ¹«Ë¾£¨ÖйúÉîÛÚ£©¡¢ºëÒä¹ú¼Ê¹É·ÝÓÐÏÞ¹«Ë¾£¨Öйų́Í壩¡¢questcomp£¨ÃÀ¹ú¼ÓÀû¸£ÄáÑÇ£©¡¢axitea£¨Òâ´óÀûÃ×À¼£©µÈ¡£¡£¡£¡£¡£¹¥»÷ÕßÒÔ¡°Dretax.inc-Ryan Osborn -INV -034708182958- 2021.24.08¡±¡¢¡°Dretax.inc-Alissa Chung -INV -420511295810- 2021.24.08¡±µÈÐéαµÄ·¢Æ±Æ±¾ÝΪÓʼþÎÊÌâÌᳫÓã²æÊ½´¹ÂÚ¹¥»÷²¢½øÒ»²½ÏòÄ¿µÄ×°±¸Ö²ÈëDridexľÂí£¬£¬£¬£¬£¬¹¥»÷ÖÐʹÓÃÁ˺êÒþ²Ø¡¢¶à²ãLoader»ìÏý¼ÓÃÜ¡¢API¶¯Ì¬»ñÈ¡¡¢APIÏòÁ¿Òì³£´¦Öóͷ£Å²ÓõȶàÖÖÊÖÒÕÊֶζԿ¹ÆÊÎö£¬£¬£¬£¬£¬Í¬Ê±Æä»ØÁ¬µÄÍøÂç»ù´¡ÉèÊ©¾ù½ÓÄÉCDNºÍP2PÊðÀí½ÚµãÀ´¹æ±Ü×·×ÙÓë¼ì²â¡£¡£¡£¡£¡£
DridexÊÇÒ»¿îÒÔÇÔÈ¡ÒøÐÐÕË»§Æ¾Ö¤ÎªÄ¿µÄ£¬£¬£¬£¬£¬¼¯½©Ê¬¡¢ÇÔÃÜľÂí¡¢ÓʼþÈ䳿¡¢ÀÕË÷Èí¼þµÈÖڶ๦ЧÓÚÒ»ÌåµÄ×ÛºÏÐÔÈ䳿²¡¶¾£¬£¬£¬£¬£¬ÓÉÓÚÆäÓµÓÐÖØ´óµÄP2P¿ØÖÆ»úÖÆ¡¢¶à²ãÊðÀí¡¢¿ìËÙ±äÒì¡¢ÄÚÍâÍøË«ÇþµÀѬȾ¡¢RSA-AESͨѶ¼ÓÃܵÈÌØµã£¬£¬£¬£¬£¬Êܹ¥»÷ÆóÒµÒ»µ©ÖÐÕУ¬£¬£¬£¬£¬¿ÉÄÜÒýÆðÄÚÍøÀ©É¢Ñ¬È¾²¢½øÒ»²½Ôì³ÉʧйÃÜ¡¢ÔâÊÜÀÕË÷¹¥»÷¡¢Éú²úÏßÍ£°ÚµÈÑÏÖØµÄЧ¹û¡£¡£¡£¡£¡£
Ëæ×Å¡¶Êý¾ÝÇå¾²·¨¡·µÄÕýʽʵÑ飬£¬£¬£¬£¬È«ÐÐÒµ¡¢È«ÁìÓò¶¼»áÊÜÖ®Ó°Ï죬£¬£¬£¬£¬ÐèÒª½¨ÉèÍêÉÆµÄÊý¾ÝÇå¾²Õ½ÂÔ¡£¡£¡£¡£¡£µç×ÓÔªÆ÷¼þ¼°°ëµ¼ÌåÐÐÒµ×÷ΪÎÒ¹ú¡°Ê®ËÄÎ塱¶¦Á¦´ó¾ÙÉú³¤µÄÕ½ÂÔÐÂÐ˹¤Òµ£¬£¬£¬£¬£¬ÊÇÖ§³ÖÄ¿½ñ¾¼ÃÉç»áÉú³¤ºÍ°ü¹Ü¹ú¼ÒÇå¾²µÄÕ½ÂÔÐÔ¡¢»ù´¡ÐÔºÍÏȵ¼ÐÔ¹¤Òµ£¬£¬£¬£¬£¬Æä¹¤ÒµÁ´Çå¾²ÎȹÌÒâÒåÖØ´ó¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯Ò»µ©Í¨¹ýÍøÂç¹¥»÷ÈëÇÖµ½Ïà¹ØÆóÒµÄÚ²¿£¬£¬£¬£¬£¬Ò»·½Ãæ»áÑÏÖØÍþвµ½ÎÒ¹ú×ÔÖ÷¿É¿ØµÄ¹¤ÒµÁ´Çå¾²ºÍÊý¾ÝÇå¾²£»£»£»£»£»£»ÁíÒ»·½ÃæÒ²¿ÉÄÜÒòÀÕË÷¹¥»÷¡¢Éú²úÏßÖÐÖ¹µÈÔì³ÉÖØ´óµÄ¾¼ÃËðʧ¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬bevictorΰµÂADLabÌáÐÑÓйص¥Î»¡¢ÆóÓªÒµ±ØÖØÊÓ´ËÀàÍøÂç¹¥»÷Ô˶¯²¢ÊµÊ±¾ÙÐÐÇå¾²Ìá·À¡£¡£¡£¡£¡£
¶þ¡¢¹¥»÷ÍþвÆÊÎö
2.1 µç×ÓÔªÆ÷¼þÆóҵƵÔâÍøÂç¹¥»÷
´Ë´Î¹¥»÷Ô˶¯Ãé×¼Á˵ç×ÓÔªÆ÷¼þÐÐÒµµÄÏà¹ØÆóÒµ£¬£¬£¬£¬£¬ÎÒÃÇÊӲ쵽£¬£¬£¬£¬£¬½üÄêÀ´µç×ÓÔªÆ÷¼þ½øÈë¡°ÕÇ¼ÛÆÚ¡±£¬£¬£¬£¬£¬Í¬Ê±ÒßÇéµÄ±¬·¢ÓÖ¼ÓËÙÍ»ÆÆÁ˹¤ÒµÁ´µÄ¹©ÐèÆ½ºâ£¬£¬£¬£¬£¬Ôì³Éµç×Ó¹©Ó¦Á´²úÆ·Çó¹ýÓÚ¹©£¬£¬£¬£¬£¬¼ÛÇ®·èÕÇ¡£¡£¡£¡£¡£Ò»Ð©ºÚ¿Í×éÖ¯ÒÔ´ËΪÆõ»ú£¬£¬£¬£¬£¬Ò»ÔÙÕë¶Ôµç×ÓÔªÆ÷¼þÐÐÒµÕö¿ªÍøÂç¹¥»÷´Ó¶øÄ²È¡¸ß¶îÀûÒæ£¬£¬£¬£¬£¬ÎÒÃÇͳ¼ÆÁ˽üÒ»ÄêÀ´µç×ÓÔªÆ÷¼þÐÐÒµÔâÊÜÍøÂç¹¥»÷µÄ²¿·ÖÇå¾²ÊÂÎñÈçͼ1Ëùʾ¡£¡£¡£¡£¡£
ͼ1 ½üÒ»Äêµç×ÓÔªÆ÷¼þÐÐÒµÔâÊÜÍøÂç¹¥»÷ÊÂÎñ
¿ÉÒÔ¿´µ½£¬£¬£¬£¬£¬Õë¶Ôµç×ÓÔªÆ÷¼þÐÐÒµµÄ¹¥»÷·½·¨Ö÷Òª¼¯ÖÐÔÚ¼ÓÃÜÊý¾ÝÀÕË÷¡¢Êý¾Ý×ß©ÀÕË÷¡¢¾Ü¾øÐ§À͹¥»÷ÀÕË÷£¨µ¼ÖÂÉú²úÏßЪ¹¤£©µÈ¡£¡£¡£¡£¡£2020Äê7Ô£¬£¬£¬£¬£¬È«ÇòÁìÏȵľ§Ô²´ó³§X-FABÐû²¼Í¨¸æ³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂËùÓÐITϵͳºÍÆä6¸öÉú²ú»ùµØ¾ù×èÖ¹ÊÂÇ飻£»£»£»£»£»8ÔÂSKº£Á¦Ê¿¡¢LGµç×ÓÔâµ½MazeÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬µ¼Ö²¿·ÖÖ°Ô±µÄ´ó×Ú×ÊÁÏй¶£¬£¬£¬£¬£¬ÇÒSKº£Á¦Ê¿±»ºÚµÄÎļþÖл¹°üÀ¨ÓëÆ»¹û¡¢IBMµÈ¿Í»§¹«Ë¾µÄ´æ´¢Ð¾Æ¬¼ÛÇ®ÐÉÌÓʼþ£»£»£»£»£»£»9Ô£¬£¬£¬£¬£¬ÒÔÉ«ÁÐоƬ¾ÞÍ·TowerJazzͻȻÔâÊÜÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼Ö²¿·ÖϵͳЧÀÍÆ÷ºÍÖÆÔ첿·ÖÔÝÍ£ÔËת£¬£¬£¬£¬£¬ÆÈÓÚÉú²úÏßЪ¹¤µÄѹÁ¦£¬£¬£¬£¬£¬ÆäÏòºÚ¿ÍÖ§¸¶ÁËÊýÊ®ÍòÃÀÔªµÄ¡°±£ÊÍ·Ñ¡±£¬£¬£¬£¬£¬ÒÔ»»È¡ºÚ¿Í¶ÔЧÀÍÆ÷×èÖ¹¹¥»÷£»£»£»£»£»£»12Ô£¬£¬£¬£¬£¬¸»Ê¿¿µÄ¸¹«Ë¾ºèº£¼¯ÍÅλÓÚÄ«Î÷¸çµÄ¹¤³§ÔâÓöÀÕË÷Èí¼þ¡°DoppelPaymer¡±¹¥»÷¡£¡£¡£¡£¡£ºÚ¿ÍÇÔÈ¡²¢¼ÓÃÜÁ˲¿·ÖÎļþÊý¾Ý£¬£¬£¬£¬£¬²¢ÒªÇó¹«Ë¾Ö§¸¶1804ö±ÈÌØ±ÒÒÔ»ñÈ¡½âÃܹ¤¾ß£¨Æ¾Ö¤µ±ÌìÊм۸ߴï3450ÍòÃÀÔª£©£»£»£»£»£»£»½ñÄê3Ô£¬£¬£¬£¬£¬È«Çò×ÅÃûµçÄÔÖÆÔìÉ̺ê»ùÔâÓöREvilÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬²¢±»Ë÷Òª5000ÍòÃÀÔªÊê½ð£¨Ô¼3.3ÒÚÈËÃñ±Ò£©£¬£¬£¬£¬£¬´´ÏÂ×î¸ßÀÕË÷Èí¼þÊê½ð¼Í¼¡£¡£¡£¡£¡£½ñÄê8Ô£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ºÚ¿Í×éÖ¯ÓÖÔÚĦȲÁÕÆ£¬£¬£¬£¬£¬×îÏÈÕë¶Ô¶à¼Òµç×ÓÔªÆ÷¼þÆóÒµÌᳫ´¹ÂÚÓʼþ¹¥»÷Ô˶¯¡£¡£¡£¡£¡£ºóÎÄÒ²½«Õë¶Ô´Ë´Î¹¥»÷Ô˶¯¾ÙÐÐÉîÈëµÄÆÊÎöºÍÏÈÈÝ¡£¡£¡£¡£¡£
2.2 ´Ë´Î¹¥»÷Ä¿µÄ
bevictorΰµÂADLabͨ¹ý¶Ô´Ë´Î¹¥»÷Ô˶¯¾ÙÐÐËÝÔ´ÓëÆÊÎö¹ØÁª£¬£¬£¬£¬£¬ÕûÀí³ö²¿·Ö¹¥»÷ÕßʹÓõĴ¹ÂÚÓʼþ£¬£¬£¬£¬£¬ÓʼþÐÅÏ¢¼û±í1¡£¡£¡£¡£¡£
±í1 ÓʼþÐÅÏ¢
ÔÚ½øÒ»²½ÆÊÎöºó£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷¹¥»÷ÕßʹÓÃÁ˶¨ÖƵĴ¹ÂÚÓʼþÄ£°å¾ÙÐз¢Æ±Àà´¹ÂÚÓʼþµÄ×Ô¶¯»¯ÌìÉúºÍ¹¥»÷£¬£¬£¬£¬£¬²¢Õë¶ÔÓʼþÖÐÉæ¼°·¢ËÍÈË¡¢·¢Æ±ÐòºÅ¡¢·¢Æ±ÈÕÆÚµÈÄÚÈݾÙÐÐÁËËæ»ú»¯´¦Öóͷ£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬·¢¼þÈ˵ÄÓÊÏäºó׺±»È«ÐÄαװ³ÉÓ뷢Ʊ¡¢¶©µ¥Ïà¹ØµÄÄÚÈÝ£¬£¬£¬£¬£¬ÀýÈçpayment.dretax.com¡¢invoice.dretax.com¡¢order.dretax.com¡¢mail.dretax.com£¬£¬£¬£¬£¬ÓʼþÎÊÌâÓ븽¼þÃûÒ²¾ùͨ¹ý¹«Ë¾Ãû£¨Dretax.inc£©¡¢INV£¨invoiceËõд£¬£¬£¬£¬£¬ÒëΪ·¢Æ±£©¡¢ÈÕÆÚ¡¢±àºÅ£¨Ëæ»úÌìÉú£©¡¢·¢¼þÈËÃû£¨Ëæ»úÌìÉú£©µÈ¾ÙÐÐ×éºÏαװ£¬£¬£¬£¬£¬´¹ÂÚÓʼþÈçͼ2Ëùʾ¡£¡£¡£¡£¡£
ͼ2 ´¹ÂÚÓʼþ
´Ë´Î¹¥»÷Éæ¼°µÄÄ¿µÄ¾ùΪµç×ÓÔªÆ÷¼þÐÐÒµµÄÏà¹Ø¹«Ë¾£¬£¬£¬£¬£¬°üÀ¨ÌìÂí΢µç×ӹɷÝÓÐÏÞ¹«Ë¾¡¢ºëÒä¹ú¼Ê¹É·ÝÓÐÏÞ¹«Ë¾¡¢questcomp¡¢axiteaµÈ£¬£¬£¬£¬£¬ÓÉÓںڿͲ¢Ã»ÓÐÒÔÌØ¶¨¹ú¼ÒΪ¹¥»÷Ä¿µÄ£¬£¬£¬£¬£¬ÒÔÊÇÎÒÃÇÒÔΪÕâÊÇÒ»ÆðÆÕ±éÕë¶Ôµç×ÓÔªÆ÷¼þÐÐÒµµÄ¹¥»÷Ðж¯£¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯µÄ½¹µãÄ¿µÄ¿ÉÄÜÊÇÇÔÈ¡µç×ÓÔªÆ÷¼þ¹«Ë¾µÄÉñÃØÊý¾Ý»òÊÖÒÕ×ÊÁÏ£¬£¬£¬£¬£¬Í¬Ê±¿ÉÄܽøÒ»²½Í¨¹ý¼ÓÃÜÊý¾ÝÀÕË÷¡¢Êý¾Ý×ß©ÀÕË÷¡¢Ëø¶¨ÏµÍ³ÀÕË÷µÈÊÖ¶ÎÀ´Ä²È¡¸ü¶àµÄ¾¼ÃÀûÒæ¡£¡£¡£¡£¡£´Ë´ÎÔ˶¯Éæ¼°µÄ²¿·Ö¹¥»÷Ä¿µÄÐÅÏ¢Èç±í2Ëùʾ¡£¡£¡£¡£¡£
±í2 ¹¥»÷Ä¿µÄÐÅÏ¢
Èý¡¢ÊÖÒÕÆÊÎö
Ôڴ˴ι¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬¹¥»÷Õß½«´øÓжñÒ⸽¼þµÄ´¹ÂÚÓʼþͶµÝÖÁµç×ÓÔªÆ÷¼þÆóÒµÔ±¹¤£¬£¬£¬£¬£¬Ò»µ©´¹ÂÚÍýÏëÀֳɣ¬£¬£¬£¬£¬¶ñÒâºê»áÊͷŲ¢Ö´ÐÐVBScript¾ç±¾£¬£¬£¬£¬£¬¸Ã¾ç±¾ÊÇÒ»¸öÏÂÔØÆ÷£¬£¬£¬£¬£¬ÊµÑéͨ¹ý̸ÌìÈí¼þDiscordµÄCDNЧÀÍÏÂÔØºÚ¿ÍÍйܵĶñÒâDLLÎļþ£¬£¬£¬£¬£¬Í¬Ê±»áÊÍ·ÅÁíÒ»¸öVBScript½ÅÔÀ´¼ÓÔØ¸Ã¶ñÒâDLL¡£¡£¡£¡£¡£¼ÓÔØµÄDLLʵÔòΪDridexľÂíLoader£¬£¬£¬£¬£¬ÆäʹÓÃÁ˶à²ã´ò°üµÄ·½·¨¾ÙÐÐÏ·¢£¬£¬£¬£¬£¬ÔÚÄÚ´æÖоÓÉ2´Î½âÃÜÊÍ·ÅLoaderºó×îÖÕ´ÓC&CЧÀÍÆ÷ÏÂÔØÖ´ÐÐDridexľÂí£¬£¬£¬£¬£¬²¢½øÒ»²½ÅþÁ¬ÖÁDridexµÄP2PÊðÀíÍøÂçÖ´ÐжñÒâ²Ù×÷¡£¡£¡£¡£¡£
ÏÂͼչʾÁ˴˴ι¥»÷Ô˶¯ÍêÕûµÄÁ÷³Ì£º
ͼ3 ¹¥»÷Á÷³Ìͼ
3.1 ÓÕ¶üÓʼþͶµÝ
¹¥»÷ÕßαװÁ˶à·âÒÔDretax¹«Ë¾£¨ÃÀ¹úÎ÷Èø¿ËÀÃÅÍУ©»á¼ÆÖ°Ô±Îª·¢¼þÈ˵Ĵ¹ÂÚÓʼþ£¬£¬£¬£¬£¬ÓʼþÖ÷Ìâ¾ùÓë¡°·¢Æ±ÐÅÏ¢¡±Óйأ¬£¬£¬£¬£¬ÒÔͼ4ÓʼþΪÀý£¬£¬£¬£¬£¬ÊÕ¼þÈËΪÎÒ¹úÌìÂí΢µç×ӹɷÝÓÐÏÞ¹«Ë¾ÃûΪ¡°panpan_cao¡±µÄÔ±¹¤¡£¡£¡£¡£¡£ÓʼþÕýÎÄÖмòÆÓÐÎòÁË·¢Æ±ÐÅÏ¢¼°¿ª¾ß·¢Æ±µÄ»á¼Æ²¿·ÖµÄÁªÏµ·½·¨£¬£¬£¬£¬£¬²¢ÌáÐѱ£´æËù¸½µÄ·¢Æ±¡£¡£¡£¡£¡£
ͼ4 ´¹ÂÚÓʼþ
Óʼþ¸½¼þÊÇÒ»·ÝαװµÄ8Ô·¢Æ±µ¥£¬£¬£¬£¬£¬´ÓÓÕ¶üÎĵµ·¿ªºóµÄÄÚÈÝ£¨Èçͼ5£©À´¿´£¬£¬£¬£¬£¬Excel±í¸ñ½ö°üÀ¨Ò»ÕÅͼƬ£¬£¬£¬£¬£¬ÄÚÈÝ´óÒâΪ£º¡°´ËÎĵµÊÇÓÉMicrosoft office excelµÄÔçÆÚ°æ±¾½¨É裬£¬£¬£¬£¬ÇëÆôÓúêÑ¡ÏîÒÔÏÔʾÎĵµÄÚÈÝ¡±¡£¡£¡£¡£¡£Ò»µ©Êܺ¦Õß±»ÓÕÆÆôÓúêÑ¡Ï£¬£¬£¬£¬¶ñÒâºê´úÂë±ã»áÁ¬Ã¦Ö´ÐС£¡£¡£¡£¡£
ͼ5 ¶ñÒâµÄÓʼþ¸½¼þ
3.2 ¶ñÒâºê´úÂëÖ´ÐÐ
ºê´úÂë±»Òþ²ØÔÚÊÂÇé²¾µÄ±í¸ñµ±ÖУ¬£¬£¬£¬£¬Ä¬ÈÏ·¿ªExcelÖ»ÄÜ¿´µ½±íSheet1£¨±íMacro1±»Òþ²Ø£©£¬£¬£¬£¬£¬µ±µã»÷¡°ÆôÓúꡱºó£¬£¬£¬£¬£¬ÓÉÓÚ±íµÄ״̬±»Òþ²ØÈÔÎÞ·¨¿´µ½£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÓÒ¼üµ¥»÷Ö÷±íÑ¡Ï×÷·ÏÒþ²ØÑ¡Ïî¡£¡£¡£¡£¡£
ͼ6 ×÷·ÏÒþ²ØµÄÊÂÇé±í
´Ëʱ¿ÉÒÔÔÚ±íMacro1Öп´µ½¶ñÒâºê´úÂ룬£¬£¬£¬£¬¸Ã¶ñÒâ´úÂë±»»ìÏýºó²ð·ÖÖÁ¶à¸ö±í¸ñÖд洢¡£¡£¡£¡£¡£Óë³£¼ûµÄºê´úÂëÒþ²Ø·½·¨²î±ð£¬£¬£¬£¬£¬´ËÀàÒþ²ØÊÖÒÕÎÞ·¨ÔÚVBAProjectÖп´µ½ºê´úÂ룬£¬£¬£¬£¬Äܹ»ÔÚÒ»¶¨Ë®Æ½ÉÏ×ÌÈÅÇå¾²ÆÊÎö¡£¡£¡£¡£¡£
½«xlsmÎļþ½âѹËõ£¬£¬£¬£¬£¬Í¬Ñù¿ÉÒÔÔÚÆäÖÐ\xl\macrosheets\sheet1.xmlµÄλÖ÷¢Ã÷¸ÃÒþ²ØµÄ¶ñÒâºê´úÂë¡£¡£¡£¡£¡£
ͼ7 Òþ²ØµÄºê´úÂë
¹¥»÷Õß½«¶ñÒâ´úÂëÒÔ10½øÖÆ×Ö·ûµÄÐÎʽ´æ´¢ÔÚµ¥Î»¸ñÄÚ£¨Ã¿¸ö×Ö·û´æ´¢ÔÚ×ÔÁ¦µÄµ¥Î»¸ñÖУ©£¬£¬£¬£¬£¬ÏÖʵִÐÐʱͨ¹ýExcelµÄCHAR()º¯Êýת»»Îª×Ö·û´®´úÂëºóÔÙ½øÒ»²½¼ÓÔØ£¬£¬£¬£¬£¬´Ó¶øµÖ´ï»ìÏýºÍ¶Ô¿¹Çå¾²¼ì²âµÄÄ¿µÄ¡£¡£¡£¡£¡£½«¾ç±¾È¥»ìÏýºó£¬£¬£¬£¬£¬´úÂëµÄÕûÌåŲÓÃÂß¼Èçͼ8Ëùʾ¡£¡£¡£¡£¡£
ͼ8 ´úÂëŲÓÃÂß¼
¶ñÒâ´úÂë»á½¨Éè¡°C:\ProgramData\veqxg.sct¡±Îļþ£¬£¬£¬£¬£¬²¢½«J162ÖÁS604µ¥Î»¸ñÄÚµÄÊýÖµÄÚÈÝ£¨Èçͼ9£©×ª»¯ÎªCHARÖµºóдÈëÆäÖУ¬£¬£¬£¬£¬È»ºóͨ¹ýÏÂÁîEXEC (MSHTA C:\ProgramData\veqxg.sct)Ö´ÐÐveqxg.sctÎļþ¡£¡£¡£¡£¡£
ͼ9 ¶ñÒâ´úÂ루ÿ¸ö×Ö·û´æ´¢ÔÚ×ÔÁ¦µÄµ¥Î»¸ñÖУ©
3.3 ¶ñÒâ¡°sct¡±ÎļþÖ´ÐÐ
veqxg.sctÎļþʵÔòΪVBScript¾ç±¾£¬£¬£¬£¬£¬¸Ã¾ç±¾»áÔÚͬĿ¼ÏÂÊÍ·ÅÏÂÒ»½×¶ÎµÄVBScript¾ç±¾vaBlOKVbTNVXMTWIJcdR.sct£¬£¬£¬£¬£¬Ö®ºó´ÓЧÀÍÆ÷ÏÂÔØºóÐøµÄ¶ñÒâ´úÂëvaBlOKVbTNVXMTWIJcdR.dll£¬£¬£¬£¬£¬ÈôÊÇÏÂÔØÀֳɣ¬£¬£¬£¬£¬Ôòͨ¹ývaBlOKVbTNVXMTWIJcdR.sct¾ç±¾Ö´ÐкóÐøµÄ¶ñÒâDLL¡£¡£¡£¡£¡£
ͼ10 veqxg.sct¾ç±¾
ÏÂÔØÁ´½ÓÈç±í3Ëùʾ£º
¶ñÒâDLLÏÂÔØÁ´½Ó
vaBlOKVbTNVXMTWIJcdR.sct¾ç±¾»á½øÒ»²½Í¨¹ýrundll32.exe Ö´ÐжñÒâDLL£¨²ÎÊýΪCPGenRandom)£¬£¬£¬£¬£¬¾Ì«¹ýÎö£¬£¬£¬£¬£¬¸Ã¶ñÒâDLLÊÇDridexľÂíµÄLoader£¬£¬£¬£¬£¬ÏÂÎÄÎÒÃǽ«¶ÔDridexľÂí¼°ÆäLoader¾ÙÐÐÏêϸµÄÆÊÎöºÍÏÈÈÝ¡£¡£¡£¡£¡£
ͼ11 vaBlOKVbTNVXMTWIJcdR.sct¾ç±¾
3.4 DridexľÂíÆÊÎö
´Ë´ÎµÄDridexʹÓÃÁ˶à²ã´ò°üµÄ·½·¨¾ÙÐÐÏ·¢£¬£¬£¬£¬£¬µÚÒ»²ãLoaderÖ´Ðк󣬣¬£¬£¬£¬»áʹÓÃshellcodeÔÚÄÚ´æÖнâÃܳöµÚ¶þ²ãLoaderÀ´Ö´ÐУ¬£¬£¬£¬£¬µÚ¶þ²ãLoaderÔÙÈ¥¹¥»÷Õß¿ØÖƵÄC&CЧÀÍÆ÷ÏÂÔØDridexľÂí¡£¡£¡£¡£¡£ÕâÁ½¸öLoaderʹÓÃÁ˶¯Ì¬º¯Êý»ñÈ¡ºÍÏòÁ¿Òì³£´¦Öóͷ£À´Å²ÓÃϵͳº¯Êý£¬£¬£¬£¬£¬´Ó¶øÌÓ±ÜÇå¾²Èí¼þµÄ²éɱºÍ×ÌÈÅÇå¾²Ö°Ô±µÄÆÊÎö¡£¡£¡£¡£¡£ÒÔÏÂÊÇÏêϸÆÊÎö£º
3.4.1 µÚÒ»²ãLoaderÆÊÎö
¸ÃLoaderµÄ´úÂë¾ÓÉÁËÕûÊýÔËËã²Ù×÷»ìÏý£¬£¬£¬£¬£¬Æäͬʱ»¹Ê¹ÓÃÁ˶¯Ì¬º¯ÊýŲÓõÄÊÖÒÕÀ´Ö´ÐÐϵͳAPI£¬£¬£¬£¬£¬ÒÔÔöÌí¾²Ì¬ÆÊÎöµÄÄѶȣ¬£¬£¬£¬£¬ÏÂͼÊǸÃLoaderÔÚIDAÖеIJ¿·Öα´úÂ룺
ͼ12 Loaderµ¼³öº¯Êýα´úÂë
ÎÒÃÇÁ¬Ïµ¶¯Ì¬µ÷ÊÔÆÊÎö£¬£¬£¬£¬£¬·¢Ã÷¸ÃLoaderµÄÄ¿µÄÊÇÔÚÄÚ´æÖнâÃÜÖ´ÐÐÒ»¸öPEÎļþ¡£¡£¡£¡£¡£Õâ¸öÀú³Ìͨ¹ýÁ½½×¶ÎµÄshellcodeÍê³É£º
µÚÒ»½×¶ÎµÄshellcode±»¼ÓÃÜÉúÑÄÔÚ¸ÃLoaderµÄ.rdata¶Î£¬£¬£¬£¬£¬LoaderÖ´Ðк󣬣¬£¬£¬£¬½«.rdata¶ÎµÄshellcode½âÃܺóдµ½.data¶Î£¬£¬£¬£¬£¬È»ºó¶¯Ì¬Å²ÓÃVirtualProtectº¯Êý½«.data¶ÎµÄ¶ÔÓ¦shellocdeÊôÐÔÐÞ¸ÄΪ¿É¶Á¿Éд¿ÉÖ´ÐУ¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º
ͼ13 ÐÞ¸Ä.data¶ÎµÄÄÚ´æÊôÐÔΪ¿É¶Á¿Éд¿ÉÖ´ÐÐ
Ö®ºó£¬£¬£¬£¬£¬loader¾ÍÈ¥Ö´ÐÐ.data¶ÎµÄshellcode´úÂ룬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º
ͼ14 Ö´ÐÐ.data¶ÎµÄshellcode´úÂë
shellcodeµÄ×îÏÈÊÇÒ»¶Î½âÃÜ´úÂ룬£¬£¬£¬£¬ÆäÈÏÕæ½«µÚ¶þ½×¶ÎµÄshellcode½âÃܳöÀ´£¨Ñ»·Òì»ò½âÃÜshellcode£©£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º
ͼ15 ½âÃܵڶþ½×¶ÎµÄshellcode
½âÃÜÍê³Éºó£¬£¬£¬£¬£¬shellcodeÔÙ¶¯Ì¬Å²ÓÃVirtualAllocº¯ÊýÉêÇëÒ»¶ÎÄڴ棬£¬£¬£¬£¬½«½âÃܺóµÄµÚ¶þ½×¶ÎshellcodeдÈ뵽ĿµÄÄڴ棬£¬£¬£¬£¬Ö®ºóÌø×ªµ½µÚ¶þ½×¶ÎµÄshellcodeÈ¥Ö´ÐУ¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º
ͼ16 Ö´Ðеڶþ½×¶ÎµÄshellcode
µÚ¶þ½×¶ÎµÄshellcodeÖ´Ðк󣬣¬£¬£¬£¬»á¶¯Ì¬Å²ÓÃVirtualAllocº¯ÊýÉêÇëÄڴ棬£¬£¬£¬£¬½«¼ÓÃÜÊý¾ÝдÈë¸ÃÄÚ´æºó£¬£¬£¬£¬£¬ÔÙ½âÃÜÖ´ÐУ¬£¬£¬£¬£¬½âÃÜÖ´ÐеÄpayloadΪһDLLÎļþ£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º
ͼ17 ÄÚ´æÖнâÃܳöµÄDLLÎļþ
3.4.2 µÚ¶þ²ãLoaderÆÊÎö
¸ÃDLLͬÑùÊÇÒ»¸öloader£¬£¬£¬£¬£¬ÆäÄ¿µÄÊÇ´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØÏÂÒ»½×¶ÎµÄDridexľÂí¡£¡£¡£¡£¡£¸ÃDLLͬÑùʹÓÃÁ˶¯Ì¬º¯ÊýŲÓõķ½·¨¾ÙÐк¯ÊýŲÓ㬣¬£¬£¬£¬Ö»Óе±ÐèҪŲÓÃÄ¿µÄº¯Êýʱ£¬£¬£¬£¬£¬¶ñÒâ´úÂë²Å»áʹÓÃFS¼Ä´æÆ÷¼ìË÷¶ÔÓ¦º¯ÊýµÄÏÖʵµØµã£¬£¬£¬£¬£¬È»ºóʹÓÃint3Ò쳣ŲÓÃÄ¿µÄº¯Êý£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º
ͼ18 ʹÓÃint3Ò쳣ŲÓÃÄ¿µÄº¯Êý
ÕâÖÖº¯ÊýŲÓõÄÔÀíÊÇ£¬£¬£¬£¬£¬µ±³ÌÐò±¬·¢Òì³£µÄʱ¼ä£¬£¬£¬£¬£¬Ò»¹²ÓÐÁ½ÖÖ´¦Öóͷ£Òì³£µÄ·½·¨¡£¡£¡£¡£¡£Ò»ÖÖÊÇSHE£¨Structured Exception Handling£©£¬£¬£¬£¬£¬ÁíÒ»ÖÖÊÇVEH£¨Vectored Exception Handling£©¡£¡£¡£¡£¡£¸ÃDLLʹÓÃÁËVEHµÄ·½·¨Å²ÓÃÄ¿µÄº¯Êý£ºÔÚÔËÐеÄ×îÏÈ£¬£¬£¬£¬£¬¶ñÒâ´úÂë»á×¢²áÒ»¸öVEH´¦Öóͷ£³ÌÐò£¨ÈçÏÂͼËùʾ£©£¬£¬£¬£¬£¬µ±CPUΪINT3Òý·¢Ò쳣ʱŲÓÃÒì³£´¦Öóͷ£³ÌÐòÒÔ¶ÔÄ¿µÄº¯Êý¾ÙÐÐŲÓᣡ£¡£¡£¡£
ͼ19 ×¢²áÒì³£´¦Öóͷ£º¯Êý
¸ÃDLLÄÚÖÃÓÐ3¸öC&CЧÀÍÆ÷µØµã£¬£¬£¬£¬£¬ÈçϱíËùʾ£º
¸ÃDLL»áʵÑéÖð¸öºÍÕâЩC&CЧÀÍÆ÷¾ÙÐÐÅþÁ¬£¬£¬£¬£¬£¬Ò»µ©ÅþÁ¬½¨ÉèÀֳɣ¬£¬£¬£¬£¬DLL¾Í»áŲÓÃHttpSendRequestWº¯ÊýÏòC&CЧÀÍÆ÷»Ø´«Ä¿µÄÇéÐεļÓÃÜÊý¾Ý£¨ÈçÏÂͼËùʾ£©£¬£¬£¬£¬£¬Ö®ºó¸ÃDLL»á´ÓC&CЧÀÍÆ÷ÏÂÔØÏÂÒ»½×¶ÎµÄDridexľÂíÖ´ÐС£¡£¡£¡£¡£
ͼ20 ÏòC&C»Ø´«µÄ¼ÓÃÜÊý¾Ý
3.4.3 Dridex½¹µãľÂí
ÓÉÓÚÎÒÃÇÔÚÆÊÎöµÄʱ¼ä£¬£¬£¬£¬£¬µÚ¶þ²ãLoaderÄ¿½ñδÄܽ«Dridex½¹µãÂíÏÂÔØÏÂÀ´Ö´ÐУ¬£¬£¬£¬£¬¿ÉÊÇͨ¹ýËÝÔ´·¢Ã÷Ä¿½ñLoaderÕýÊÇDridex V4ËùʹÓõÄLoader£¬£¬£¬£¬£¬×Ô¼ºDridex½¹µãÂí²¢Î´±¬·¢½Ï´óת±ä£¬£¬£¬£¬£¬Æä×îÖ÷Òª¹¥»÷ÄÜÁ¦Ö÷ÒªÌåÏÖÔÚÆäÇ¿¶È¶øÎÞаµÄ²å¼þÊÖÒÕÉÏ¡£¡£¡£¡£¡£ÐµĹ¥»÷ÖÐËù½ÓÄɵĶñÒâÓÕ¶üÎĵµ¼°LoaderËæ×źڿÍ×éÖ¯µÄ¸üÌæ¶øÒ»Ö±½ø»¯¡£¡£¡£¡£¡£±¾ÎĽ«²»ÔÙ¶ÔDridexµÄÏêϸÊÖÒÕ¾ÙÐÐÆÊÎö£¬£¬£¬£¬£¬Ö»¶ÔDridexµÄ»ù±¾¹¦Ð§ºÍÌØµã¾ÙÐмòÒªµÄÏÈÈÝ¡£¡£¡£¡£¡£ÈçÐèÉîÈëÏàʶDridexľÂí£¬£¬£¬£¬£¬¿É×ÐϸÔĶÁbevictorΰµÂÁíÍâһƪÉî¶ÈÆÊÎö±¨¸æ¡¶¶ãÔÚP2PÈä³æÍøÂç±³ºóµÄÓÄÁ飺DridexÈ䳿ÐÂÐͱäÖÖÌ½ÃØ¡·£¬£¬£¬£¬£¬ÎÒÃÇÔÚ±¨¸æÖжÔDridex V4Ëù½ÓÄɵĹ¥»÷ÊÖ·¨£¬£¬£¬£¬£¬ÊÖÒÕÊֶΣ¬£¬£¬£¬£¬Í¨Ñ¶»úÖÆµÈµÈ×öÁËÖÜÈ«¶øÉîÈëµÄÆÊÎö¡£¡£¡£¡£¡£
DridexÓÖÃûBugat¡¢Cridex¡¢Feodo£¬£¬£¬£¬£¬ÓÚ2014ÄêÊ״ηºÆð£¬£¬£¬£¬£¬ÊÇÏÖÔÚÈ«Çò»îÔ¾µÄÊÖÒÕ×îÏȽøµÄÒøÐÐľÂíÖ®Ò»£¬£¬£¬£¬£¬´Ó·ºÆðÒÔÀ´£¬£¬£¬£¬£¬ÆäÒ»Ö±ÔÚÒ»Ö±¸üкÍÑݱ䣬£¬£¬£¬£¬Ö±µ½ÏÖÔÚΪֹÈÔÊ®·Ö»îÔ¾¡£¡£¡£¡£¡£¸ÃľÂíµÄÖ÷ҪĿµÄÊÇÇÔÈ¡Êܺ¦ÕßÖ÷»úµÄÒøÐÐÆ¾Ö¤¡£¡£¡£¡£¡£ºÍÕâ´Î¹¥»÷Ò»Ñù£¬£¬£¬£¬£¬Æäͨ³£Í¨¹ýÓã²æÊ½´¹ÂÚÓʼþµÄ·½·¨¾ÙÐÐÈö²¥¡£¡£¡£¡£¡£³ýÁËÇÔÈ¡ÒøÐÐÆ¾Ö¤£¬£¬£¬£¬£¬Dridexͨ³£»£»£»£»£»£»¹»áÏÂÔØÆäËûµÄ¶ñÒâÄ£¿£¿é£¬£¬£¬£¬£¬ÏÖÔÚÒÑÖªµÄ¹¦Ð§Ä£¿£¿éÓÐVNCÄ£¿£¿é¡¢ÆÁÄ»½ØÍ¼Ä£¿£¿é¡¢ÊðÀíÄ£¿£¿é¡¢ÖÐÐÄÈËÄ£¿£¿é¡¢¼üÅ̼Í¼ģ¿£¿é¡¢Æ¾Ö¤ÇÔȡģ¿£¿é¡¢Web×¢ÈëÄ£¿£¿é¡¢ÄÚÍøÑ¬È¾Ä£¿£¿é¡¢ÓʼþÈö²¥Ä£¿£¿é¡¢É³Ïä¼ì²âÄ£¿£¿éµÈ¡£¡£¡£¡£¡£
DridexµÄ¹¥»÷Ä¿µÄ±é²¼Ììϸ÷µØ£¬£¬£¬£¬£¬È磺Öйú¡¢ÃÀ¹ú¡¢µÂ¹ú¡¢·¨¹úºÍ¼ÓÄôóµÈ¡£¡£¡£¡£¡£ÒÔÏÂÊÇDridex½ü¼¸ÄêµÄһЩ¹¥»÷ÊÂÎñ£º
2014Äê7Ô£¬£¬£¬£¬£¬Seculert¹«Ë¾µÄÇå¾²Ñо¿Ô±·¢Ã÷DridexÇÔÈ¡ÁËÖÁÉÙ5Íò¸öÓÊÏäµÄµÇ¼Õ˺źÍÃÜÂëÐÅÏ¢ÁÐ±í£¬£¬£¬£¬£¬´ËʱDridexÖ÷ÒªÒÔѬȾµÂ¹úºÍ²¨À¼ÎªÖ÷£¬£¬£¬£¬£¬ÆäËûѬȾ¹ýµÄ¹ú¼ÒÓаµØÀû¡¢ÃÀ¹ú¡¢ÈðÊ¿¡¢Ó¢¹ú¡¢Òâ´óÀû¡¢ºÉÀ¼µÈ¡£¡£¡£¡£¡£
2015Äê5Ô£¬£¬£¬£¬£¬Dridex×îÏȽ«js¾ç±¾Îļþ×÷ΪÓʼþÈö²¥¸½¼þ¾ÙÐдóÃæ»ýÈö²¥£¬£¬£¬£¬£¬¸Ãjs¾ç±¾ÎļþÓÃÓÚÏÂÔØLockyÀÕË÷Èí¼þÖ´ÐС£¡£¡£¡£¡£
2015Äê8Ô£¬£¬£¬£¬£¬Ïà¹ØÇå¾²»ú¹¹ÆÊÎöͳ¼Æ£¬£¬£¬£¬£¬ÔÚ2015Äê¼ä²»µ½Ò»ÄêµÄʱ¼äÀ£¬£¬£¬£¬DridexÒѾÈëÇÖÁ˺á¿ç27¸ö¹ú¼ÒµÄ³ÉǧÉÏÍò¼ÒÆóÒµ£¬£¬£¬£¬£¬²¢ÇÒÒѾµ¼ÖÂÓ¢¹ú2ÍòÍòÓ¢°õ(ÆäʱºÏ3050ÍòÃÀÔª)ÒÔÉϵľ¼ÃËðʧ£¬£¬£¬£¬£¬ÒÔ¼°ÃÀ¹ú1ÍòÍòÃÀ½ðµÄ¾¼ÃËðʧ¡£¡£¡£¡£¡£
2015Äê8ÔÂ14ÈÕ£¬£¬£¬£¬£¬FBIÁªºÏÇå¾²³§É̵·»ÙÁËDridexЧÀÍÆ÷²¢¾Ð²¶ÁËÒ»ÃûDridexÄ»ºó²Ù¿ØÕß¡£¡£¡£¡£¡£
2016Äê2ÔÂ4ÈÕ£¬£¬£¬£¬£¬Dridex±¬·¢ÁËÒ»´ÎÏ·¾çÐÔÊÂÎñ£¬£¬£¬£¬£¬ÄǾÍDridexÈ䳿²¡¶¾ºó¶ËЧÀÍÆ÷Òɱ»°×ñ×ÓÈëÇÖ£¬£¬£¬£¬£¬ËùÓÐÏÂÔØµÄÄ£¿£¿é±»Ìæ»»³ÉÁËAviraɱ¶¾Èí¼þ¡£¡£¡£¡£¡£
2016Äê9ÔÂ6ÈÕ£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷еÄDridex±äÖÖ×îÏÈÓÃÓÚÇÔÈ¡ÐéÄâÇ®±ÒÈç±ÈÌØ±ÒÇ®°ü¡£¡£¡£¡£¡£
2017Äê4Ô£¬£¬£¬£¬£¬ProofpointÑо¿Ö°Ô±ÊӲ쵽Êý°ÙÍò´ÎDridexÈ䳿¹¥»÷£¬£¬£¬£¬£¬Æä¹¥»÷ÊÖ·¨ÓëÒÔǰµÄ¹¥»÷ÏàËÆ£¬£¬£¬£¬£¬Í¬Ñùͨ¹ýÓʼþЯ´ø¸½¼þµÄÐÎʽ¾ÙÐвþâ±µÄÈö²¥£¬£¬£¬£¬£¬Ö»ÊÇÐµĹ¥»÷ÖÐÌí¼ÓÁËͨ¹ýZIP´ò°üµÄvb¾ç±¾Îļþ¡¢PDFÎļþºÍ¿ÉÖ´ÐеÄPEÎļþ¡£¡£¡£¡£¡£
2017Äê5ÔÂ10ÈÕ£¬£¬£¬£¬£¬DridexÈ䳿±äÖÖʹÓÃÁËÔ×Ó×¢ÈëÊÖÒÕ·¢¶¯¹¥»÷£¬£¬£¬£¬£¬ÒÔÌÓ±ÜÇå¾²²úÆ·µÄ²éɱ¡£¡£¡£¡£¡£
2017Äê12ÔÂ12ÈÕ£¬£¬£¬£¬£¬Ç°Ó¢¹úÒøÐÐÔ±¹¤Ö²ÈëDridexÈ䳿×ÊÖúÁ½Î»ºÚ¿ÍÏ´Ç®£¬£¬£¬£¬£¬µ£µ±Ï´Ç®ºÚ¿ÍµÄ˽ÈËÐÅÍÐ˾Àí£¬£¬£¬£¬£¬Ê¹ÓÃαÔìµÄÉí·ÝÖ¤¼þ¿ªÉèÁ˶à´ï105¸öÕË»§£¬£¬£¬£¬£¬»ã¿îÓëתÕËÁè¼Ý250ÍòÓ¢°÷¡£¡£¡£¡£¡£
2018 Äê 12Ô£¬£¬£¬£¬£¬Ä¦¶û¶àÍß¹úÃñAndrey Ghinkul£¬£¬£¬£¬£¬ÓÖÃû¡° smilex ¡±£¨ 2017Äê2 Ô£¬£¬£¬£¬£¬´ÓÈûÆÖ·˹Òý¶Éµ½ÃÀ¹ú£©Òò·Ö·¢Dridex¶ñÒâÈí¼þ±»ÅÐÐÌ¡£¡£¡£¡£¡£
2019 Äê 6 Ô£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃSpelevo µÄÎó²îʹÓù¤¾ßͶµÝÒøÐÐľÂíDridex¡£¡£¡£¡£¡£
2019Äê12Ô£¬£¬£¬£¬£¬ÃÀ¹úÕþ¸®Ö¸¿ØÁ½¸ö¶íÂÞ˹¹«Ãñ£¨Maksim VºÍIgor Turashev£©°²ÅÅDridex¶ñÒâÈí¼þ£¬£¬£¬£¬£¬Á½ÈËÔÚ10ÄêÄÚÇÔÈ¡Áè¼ÝÁË1ÒÚÃÀÔª¡£¡£¡£¡£¡£
2020Äê12ÔÂʱ´ú£¬£¬£¬£¬£¬¹¥»÷ÕßͶµÝ·ÂðÑÇÂíÑ·Ãâ·ÑÑÇÂíÑ·ÀñÎ│µÄ´¹ÂÚÓʼþ
2021Äê8Ô£¬£¬£¬£¬£¬¹¥»÷ÕßÕë¶Ô¶à¼Òµç×ÓÔªÆ÷¼þÆóÒµÌᳫ´¹ÂÚ¹¥»÷Ô˶¯£¬£¬£¬£¬£¬°üÀ¨ÌìÂí΢µç×ӹɷÝÓÐÏÞ¹«Ë¾¡¢ºëÒä¹ú¼Ê¹É·ÝÓÐÏÞ¹«Ë¾¡¢questcomp¡¢axiteaµÈ¡£¡£¡£¡£¡£
ËÄ¡¢×ܽá
´Ë´Î¹¥»÷Ö÷ÒªÃé×¼µç×ÓÔªÆ÷¼þÆóÒµµÄÔ±¹¤£¬£¬£¬£¬£¬²¢ÇÒÉæ¼°µ½ÎÒ¹úÆóÒµµÄÊý¾ÝÇå¾²£¬£¬£¬£¬£¬ÐèÒªÒýÆð¿í´óÆóÊÂÒµµ¥Î»×ã¹»µÄСÐÄ¡£¡£¡£¡£¡£Á¬ÏµDridexľÂíµÄÀúÊ·Ô˶¯¼£Ï󣬣¬£¬£¬£¬Æä±³ºóµÄ¹¥»÷ÕßÒÔÇÔÃÜ¡¢ÀÕË÷µÈ·½·¨Í¼Ä±¾¼ÃÀûÒæµÄ¿ÉÄÜÐԽϴ󡣡£¡£¡£¡£DridexÔÚÂÄÀú¶àÄêµÄÉú³¤½ø»¯ºó£¬£¬£¬£¬£¬ÒѾÐγÉÁ˼¯È䳿¡¢½©Ê¬¡¢ÇÔÃÜľÂí¡¢ÀÕË÷Èí¼þ¡¢P2PÊðÀíÓÚÒ»ÉíµÄ»ìÏýÐÍÈ䳿²¡¶¾¡£¡£¡£¡£¡£¸ÃÈä³æÍ¬Ê±¾ß±¸ÄÚÍâÍøÀ©É¢¡¢Õý·´ÏìµÄ±Õ»·Ñ¬È¾¡¢C&CЧÀÍÆ÷¼°Í¨Ñ¶Á÷Á¿Òþ²Ø¡¢¶Ô¿¹ÆÊÎö¡¢¿ìËÙ±äÒ졢ģ¿£¿é»¯µÈ¸ß¼¶ÄÜÁ¦£¬£¬£¬£¬£¬¹ØÓÚÖÐÕÐÆóÒµ¾ßÓм«´óµÄΣº¦ÐÔ¡£¡£¡£¡£¡£
¼øÓÚDridex½©Ê¬ÍøÂçºã¾Ãͨ¹ý´¹ÂÚÓʼþÒÔ¼°OfficeVBAºê¾ÙÐй¥»÷µÄϰÓÃÊֶΣ¬£¬£¬£¬£¬ÎÒÃǽ¨ÒéÆóÊÂÒµµ¥Î»Î´±ØÆÚΪԱ¹¤¾ÙÐÐÇå¾²½ÌÓýÅàѵ£¬£¬£¬£¬£¬ÌáÉýÔ±¹¤µÄÇå¾²Ìá·ÀÒâʶ¡£¡£¡£¡£¡£Îñ±Ø×öºÃÓʼþϵͳµÄ·À»¤£¬£¬£¬£¬£¬×¢Öز»ÒªËæÒâ·¿ªÎ´ÖªÈªÔ´µÄµç×ÓÓʼþ£¨ÓÈÆäÊÇ´øÓи½¼þµÄµç×ÓÓʼþ£©¡£¡£¡£¡£¡£ÈôÓÐÐèÒª¿Éͨ¹ý·¿ªOfficeÎĵµÖеģºÎļþ-Ñ¡Ïî-ÐÅÈÎÖÐÐÄ-ÐÅÈÎÖÐÐÄÉèÖÃ-ºêÉèÖ㬣¬£¬£¬£¬½ûÓÃÒ»Çкê´úÂëÖ´ÐС£¡£¡£¡£¡£Ò»µ©ÏµÍ³»òЧÀÍÆ÷·ºÆðÒì³£ÐÐΪ£¬£¬£¬£¬£¬ÊµÊ±±¨¸æ²¢ÇëרҵְԱ¾ÙÐÐÅŲ飬£¬£¬£¬£¬ÒÔÏû³ýÇå¾²Òþ»¼¡£¡£¡£¡£¡£