大灰狼远控木马分析

<title></title>
RAT
dll
D
ll
F
u
U
p
g
r
ad
rs
haid
r
ag
on
2022-11-06
¨NBSP;
15:21
1.
1.1
F
ile
.
e
x
e
S
i
z
e
:
217088
b
yt
e
s
MD
5:
30
C
13
ED
8030
DDA
8
A
578
E
822
B
60
E
3
B
24
FSHA
1:
A
54
F
9
C
32425
AD
9
FDBA
48938418508
BA
54582
EDE
6
CRC
32:
1
B
8896
E
5
1.2
W
i
n
d
ows
7
X
64
IDA P
ro
OD
2.
N
62.
dll
3.
3.1
.
e
x
e
PE
3.1.1
3.1.2
p
a
y
l
o
ad
p
a
y
l
o
ad
N
62.
dll
N
62.
dll
p
a
y
l
o
ad
p
a
y
l
o
ad
C
:\
P
ro
g
r
a
m
F
ile
s
\
A
pp
P
a
t
h
\
N
62.
dll
p
a
y
l
o
ad
N
62.
dll
p
a
y
l
o
ad
D
ll
F
u
U
p
g
r
ad
rs
d
ump
N
62.
dll
PE
M
Z
N
62.
dll
3.1.2.1
RC
4
RC
4
3.1.2.2
p
a
y
l
o
ad
:
N
62.
dll
PE
i
m
ageba
s
e
s
i
z
e
o
fi
m
age
址地址
dll
3.1.2.3
D
ll
F
u
U
p
g
r
ad
rs
⼿
0
D
ll
F
u
U
p
g
r
ad
rs
D
ll
F
u
U
p
g
r
ad
rs
([
],[
ke
y
])
N
62.
dll
D
ll
F
u
U
p
g
r
ad
rs
3.2
p
a
y
l
o
ad
-
N
62.
dll
D
ump
N
62.
dll
upx
N
62.
dll
N
62.
dll
3.2.1
D
ll
F
u
U
p
g
r
ad
rs
D
ll
F
u
U
p
g
r
ad
rs
D
ll
F
u
U
p
g
r
ad
rs
1

2

3

4

5

6

线
7

s
hell
D
ll
F
u
U
p
g
r
ad
rs
D
ll
F
u
U
p
g
r
ad
rs
O
n
R
ec
v
i
v
e
3.2.2
使
TCP
so
cke
t
h
ost
port
⽂数据
H
ost
:
91.193.102.149
P
ort
:
0
x
51
S
o
cke
t
线
线
r
ec
v
&
O
n
R
ecei
v
e
3.2.3
&
线
线
线
1
2
r
c
4
3
4
O
n
R
ecei
v
e
3.2.4
O
n
R
ec
v
i
v
e
O
n
R
ec
v
i
v
e
O
n
R
ec
v
i
v
e
地址在
D
ll
F
u
U
p
g
r
ad
rs
O
n
R
ec
v
i
v
e
s
hell
O
n
R
ec
v
i
v
e
3.2.4.1
3.2.4.2
线
3.2.4.3
XV
i
D
3.2.4.4
3.2.4.5
3.2.4.6
S
hell
c
m
d
3.2.4.7
4.
4.1
IP
91.193.102.149
P
ort
81(0
x
51)
9090(0
x
2382)
4.2
线
C
&
C
线
3
线

点击关注,共同学习!
安全狗的自我修养

github haidragon

https://github.com/haidragon

posted @ 2022-11-06 15:28  syscallwww  阅读(351)  评论(0编辑  收藏  举报