Õý¶ù°Ë¾­ËµÊÖÒÕ¡ª¡ªÒÔEmotetΪÀýÉîÈëÆÊÎöCMDÏÂÁî»ìÏýÊÖÒÕ

Ðû²¼Ê±¼ä 2018-12-13
EmotetÒ»¿îÖøÃûµÄÒøÐÐľÂí £¬£¬£¬£¬£¬ £¬Ê״ηºÆðÓÚ2014ÄêÄêÖС£¡£¡£¡£¡£¡£¸ÃľÂíÖ÷Ҫͨ¹ýÀ¬»øÓʼþµÄ·½·¨Èö²¥Ñ¬È¾Ä¿µÄÓû§ £¬£¬£¬£¬£¬ £¬½ñÄêÈÔÈ»ºÜÊÇ»£» £»£»£»£»îÔ¾ £¬£¬£¬£¬£¬ £¬²¢ÇÒһֱת±äÈö²¥ÃûÌà £¬£¬£¬£¬£¬ £¬½ÓÄÉÔ½À´Ô½ÖØ´óµÄ»ìÏý±àÂëÀ´Ìӱܼì²â¡£¡£¡£¡£¡£¡£
    
CMDºÍPowershellÏÂÁî¾­³£±»ÓÃÔÚ¶ñÒâÈí¼þÖÐÖ´ÐжñÒâ¾ç±¾Îļþ £¬£¬£¬£¬£¬ £¬²¢Í¨¹ý¾ç±¾»ìÏý¡¢¼ÓÃÜ»ò±àÂë·½·¨À´ÈƹýAV¼ì²â¡£¡£¡£¡£¡£¡£±¾ÎÄö¾ÙÁ½¸öµä·¶µÄEmotetÈö²¥ÖÐʹÓõĻìÏýCMDÏÂÁî £¬£¬£¬£¬£¬ £¬À´ÉîÈëÆÊÎöCMD.ÏÂÁî»ìÏýÊÖÒÕ¡£¡£¡£¡£¡£¡£

ÏÈ¿´Ò»¸ö´ÓDOCÎĵµÇ¶ÈëµÄVBAºê´úÂëÖÐÌáÈ¡µÄCMDÏÂÁî £¬£¬£¬£¬£¬ £¬Õ§Ò»¿´ÉÏÈ¥ £¬£¬£¬£¬£¬ £¬ÏñÊÇÎÞÒâÒåµÄÒ»´®×Ö·û £¬£¬£¬£¬£¬ £¬×ÐϸÆÊÎöÆðÀ´ÐèÒªÏÈÏàʶһÏÂCMDÏÂÁîµÄ»ìÏý·½·¨¡£¡£¡£¡£¡£¡£

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


 


 Ò¼

CMDÏÂÁîµÄ»ìÏý·½·¨


 
 ²åÈëÌØÊâ×Ö·û»ìÏýÏÂÁî 
 
×Ö·û¡°^¡±ÊÇCMDÏÂÁîÖÐ×î³£¼ûµÄתÒå×Ö·û £¬£¬£¬£¬£¬ £¬¸Ã×Ö·û²»Ó°ÏìÏÂÁîµÄÖ´ÐС£¡£¡£¡£¡£¡£ÓÉÓÚÔÚcmdÇéÐÎÖÐ £¬£¬£¬£¬£¬ £¬ÓÐЩ×Ö·û¾ß±¸ÌØÊ⹦Ч £¬£¬£¬£¬£¬ £¬Èç >¡¢>>ÌåÏÖÖØ¶¨Ïò £¬£¬£¬£¬£¬ £¬| ÌåÏֹܵÀ £¬£¬£¬£¬£¬ £¬&¡¢&&¡¢|| ÌåÏÖÓï¾äÅþÁ¬¡£¡£¡£¡£¡£¡£ËüÃǶ¼ÓÐÌØ¶¨µÄ¹¦Ð§ £¬£¬£¬£¬£¬ £¬ÈôÊÇÐèÒª°ÑËüÃÇ×÷Ϊ×Ö·ûÊä³öµÄ»° £¬£¬£¬£¬£¬ £¬echo >¡¢echo |Ö®ÀàµÄд·¨¾Í»áÍÉ»¯¡ª¡ªcmdÚ¹ÊÍÆ÷»á°ÑËüÃÇ×÷Ϊ¾ßÓÐÌØÊ⹦ЧµÄ×Ö·û¿´´ý £¬£¬£¬£¬£¬ £¬¶ø²»»á×÷ΪͨË××Ö·û´¦Öóͷ£ £¬£¬£¬£¬£¬ £¬Õâ¸öʱ¼ä £¬£¬£¬£¬£¬ £¬¾ÍÐèÒª¶ÔÕâÐ©ÌØÊâ×Ö·û×öתÒå´¦Öóͷ££ºÔÚÿ¸öÌØÊâ×Ö·ûǰ¼ÓÉÏתÒå×Ö·û^¡£¡£¡£¡£¡£¡£

Òò´Ë £¬£¬£¬£¬£¬ £¬ÒªÊä³öÕâÐ©ÌØÊâ×Ö·û £¬£¬£¬£¬£¬ £¬¾ÍÐèÒªÓà echo ^>¡¢echo ^|¡¢echo ^|^|¡¢echo ^^Ö®ÀàµÄÃûÌÃÀ´´¦Öóͷ£¡£¡£¡£¡£¡£¡£ÁíÍâ £¬£¬£¬£¬£¬ £¬´ËתÒå×Ö·û»¹¿ÉÒÔÓÃ×÷ÐøÐзûºÅ¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¶ººÅ¡°,¡±ºÍ·ÖºÅ ¡°;¡±¿ÉÒÔ½»Á÷ £¬£¬£¬£¬£¬ £¬¿ÉÒÔÈ¡´úÏÂÁîÖеÄÕýµ±¿Õ¸ñ¡£¡£¡£¡£¡£¡£¶à¸ö¿Õ¸ñÒ²²»Ó°ÏìÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


³É¶ÔµÄÔ²À¨ºÅ£¨£©Ò²»á·ºÆðÔÚÏÂÁî²ÎÊýÖÐ £¬£¬£¬£¬£¬ £¬Ò²²»Ó°ÏìÏÂÁîµÄÖ´ÐС£¡£¡£¡£¡£¡£Ô²À¨ºÅÌåÏÖǶÈë×ÓÏÂÁî×é £¬£¬£¬£¬£¬ £¬Í¬Ñù±»cmd.exe²ÎÊý´¦Öóͷ£Æ÷¾ÙÐÐÚ¹ÊÍ¡£¡£¡£¡£¡£¡£È磺cmd.exe /c ( ( ((echo Command 1) ) )) &&( ( (((((echo Command 2))))) ) )
 
 Ê¹ÓÃCMDÇéÐαäÁ¿Æ´½ÓÏÂÁî 
 
Cmd.exeÄÚÊÖÏÂÁîÓУº set¡¢assoc £¬£¬£¬£¬£¬ £¬ftypeµÈ¡£¡£¡£¡£¡£¡£

SetÏÂÁîÓÃÀ´ÏÔʾ¡¢ÉèÖûòɾ³ýcmd.exeÇéÐαäÁ¿¡£¡£¡£¡£¡£¡£ÏÂÁîÃûÌãº
SET [variable=[string]]
  variable  Ö¸¶¨ÇéÐαäÁ¿Ãû¡£¡£¡£¡£¡£¡£
  string    Ö¸¶¨ÒªÖ¸Åɸø±äÁ¿µÄһϵÁÐ×Ö·û´®¡£¡£¡£¡£¡£¡£

ÔÚÏÂÁîÐÐÖÐÊäÈë set £¬£¬£¬£¬£¬ £¬»áö¾Ù³öcmd.exeÖÐËùÓеÄÇéÐαäÁ¿¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


assoc£ºÎļþÃûÀ©Õ¹¹ØÁªÏÂÁî £¬£¬£¬£¬£¬ £¬ÓÃÓÚÏÔʾºÍÉèÖÃÎļþÃûÀ©Õ¹¹ØÁª £¬£¬£¬£¬£¬ £¬¿ÉÒÔÖ¸¶¨Ä³ÖÖºó׺ÃûµÄÎļþÆ¾Ö¤ÌØ¶¨µÄÀàÐÍÎļþ·­¿ª»òÖ´ÐС£¡£¡£¡£¡£¡£ÏÂÁîÃûÌÃΪ£ºassoc [.ext[=[fileType]]] 

.extÊÇÖ¸£ºÖ¸¶¨Òª¹ØÁªµÄÎļþºó׺Ãû¡£¡£¡£¡£¡£¡£µãºÅ£¨.)ÊDz»¿ÉÊ¡Â﵀ £¬£¬£¬£¬£¬ £¬ÈôÊÇÊ¡ÂÔÁËϵͳ½«ÏÔʾ¸Ãºó׺ÃûÎļþµÄ¹ØÁªÐÅÏ¢¡£¡£¡£¡£¡£¡£fileTypeÊÇÖ¸£ºÖ¸¶¨Ïà¹ØÁªµÄÎļþÀàÐÍ¡£¡£¡£¡£¡£¡£ÈôÊÇֻʹÓøòÎÊý £¬£¬£¬£¬£¬ £¬½«ÏÔʾ¸ÃÎļþÀàÐ͵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£·´Ö® £¬£¬£¬£¬£¬ £¬¸ÃÏÂÁÁгöϵͳע²áµÄËØÓкó׺ÃûÎļþºÍÏà¹ØµÄÀàÐÍ¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ftype£ºÏÔʾ»òÐÞ¸ÄÓÃÔÚÎļþÀ©Õ¹Ãû¹ØÁªÖеÄÎļþÀàÐÍ £¬£¬£¬£¬£¬ £¬Ö¸¶¨Ò»ÖÖÀàÐ͵ÄÎļþĬÈÏÓÃÄĸö³ÌÐòÔËÐлò·­¿ª¡£¡£¡£¡£¡£¡£ÏÂÁîÃûÌÃΪ£ºftype [fileType[=[openCommandString]]

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


cmd.exeµÄÇéÐαäÁ¿·ÖΪϵͳÒÑÓеÄÇéÐαäÁ¿ºÍ×Ô½ç˵±äÁ¿¡£¡£¡£¡£¡£¡£Ê¹ÓÃÇéÐαäÁ¿µÄÖµÖеÄ×Ö·û»ò×Ö·û´® £¬£¬£¬£¬£¬ £¬¿ÉÒÔÆ´½Ó³ÉºÚ¿ÍÐèÒªµÄcmdÏÂÁî £¬£¬£¬£¬£¬ £¬Í¬Ê±¿ÉÒÔÌӱܾ²Ì¬¼ì²â¡£¡£¡£¡£¡£¡£ÈçϵͳÒÑÓеÄÇéÐαäÁ¿%comspec%±äÁ¿µÄֵĬÒÔΪ£º¡°C:\WINDOWS\system32\cmd.exe¡± £¬£¬£¬£¬£¬ £¬setÏÂÁî¿ÉÒÔ±»±àÂëΪ£º %comspec:~11,1%%comspec:~-1%%comspec:~-13,1%¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


%VarName:~offset[,length]% Ö÷ÒªÓÃÓÚ»ñÈ¡ÇéÐαäÁ¿VarNameµÄ±äÁ¿Öµ £¬£¬£¬£¬£¬ £¬Æ«ÒÆoffset×Ö½ÚÖ®ºó³¤¶ÈΪlength¸ö×Ö½Ú¡£¡£¡£¡£¡£¡£[,length]¿ÉÊ¡ÂÔ¡£¡£¡£¡£¡£¡£

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


%comspec:~11,1%ÌåÏÖÈ¡comspec±äÁ¿ÖµÖеÄ×Ö·û £¬£¬£¬£¬£¬ £¬Ä¬ÈÏϱê´Ó0×îÏÈ £¬£¬£¬£¬£¬ £¬´Óϱê11×îÏÈ £¬£¬£¬£¬£¬ £¬È¡Ò»¸ö×Ö·û £¬£¬£¬£¬£¬ £¬¼´Îª¡±s¡±¡£¡£¡£¡£¡£¡£offsetÒ²Ö§³Ö¸ºÊý £¬£¬£¬£¬£¬ £¬ÌåÏÖ·´Ïò±éÀú×Ö·û´®µÄϱê¡£¡£¡£¡£¡£¡£%comspec:~-1%¼´Îª¡°e¡° £¬£¬£¬£¬£¬ £¬%comspec:~-13,1%¼´Îª¡±t¡°¡£¡£¡£¡£¡£¡£ÔÆÔƱàÂësetÏÂÁî £¬£¬£¬£¬£¬ £¬¿ÉÒÔÌÓ×ß¾²Ì¬¼ì²â¡±set¡°ÏÂÁî×Ö·û´®µÄ¼ì²â»úÖÆ¡£¡£¡£¡£¡£¡£

ͨ³£ÎÒÃÇÒ²¿ÉÒÔ×Ô½ç˵һ¸ö»òÕß¶à¸öÇéÐαäÁ¿ £¬£¬£¬£¬£¬ £¬Ê¹ÓÃÇéÐαäÁ¿ÖµÖеÄ×Ö·û £¬£¬£¬£¬£¬ £¬ÌáÈ¡²¢Æ´½Ó³ö×îÖÕÏëÒªµÄcmdÏÂÁî¡£¡£¡£¡£¡£¡£Èç:
Cmd /C ¡°set envar=net user && call echo %envar%¡° ¿ÉÒÔÆ´½Ó³öcmdÏÂÁnet user
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ò²¿ÉÒÔ½ç˵¶à¸öÇéÐαäÁ¿¾ÙÐÐÆ´½ÓÏÂÁî´® £¬£¬£¬£¬£¬ £¬Ìá¸ß¾²Ì¬ÆÊÎöµÄÖØÆ¯ºó£º
cmd /c ¡° set envar1=ser&& set envar2=ne&& set envar3=t u&&call echo %envar2%%envar3%%envar1%¡±
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


cmdÏÂÁîµÄ¡°/C¡±²ÎÊý £¬£¬£¬£¬£¬ £¬Cmd /C ¡°string¡±ÌåÏÖ£ºÖ´ÐÐ×Ö·û´®stringÖ¸¶¨µÄÏÂÁî £¬£¬£¬£¬£¬ £¬È»ºóÖÕÖ¹¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¶øÆôÓÃÑÓ³ÙµÄÇéÐαäÁ¿À©Õ¹ £¬£¬£¬£¬£¬ £¬¾­³£Ê¹Óà cmd.exeµÄ /V:ON²ÎÊý £¬£¬£¬£¬£¬ £¬
/V:ON²ÎÊýÆôÓÃʱ £¬£¬£¬£¬£¬ £¬¿ÉÒÔ²»Ê¹ÓÃcallÏÂÁîÀ´À©Õ¹±äÁ¿ £¬£¬£¬£¬£¬ £¬Ê¹Óà %var% »ò !var! À´À©Õ¹±äÁ¿ £¬£¬£¬£¬£¬ £¬!var!¿ÉÒÔÓÃÀ´È¡´ú%var% £¬£¬£¬£¬£¬ £¬Ò²¾ÍÊÇ¿ÉÒÔʹÓÃ̾ϢºÅ×Ö·ûÀ´Ìæ»»ÔËÐÐʱµÄÇéÐαäÁ¿Öµ¡£¡£¡£¡£¡£¡£ºóÃæÏÈÈÝForÑ­»·Ê±»áÐèÒª¿ªÆô/V:²ÎÊýÑÓ³Ù±äÁ¿À©Õ¹·½·¨¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

 
 Ê¹ÓÃForÑ­»·Æ´½ÓÏÂÁî 
 
ForÑ­»·¾­³£±»ÓÃÀ´»ìÏý´¦Öóͷ£cmdÏÂÁî £¬£¬£¬£¬£¬ £¬Ê¹µÃcmdÏÂÁî¿´ÆðÀ´ÖØ´óÇÒÄÑÒÔ¼ì²â¡£¡£¡£¡£¡£¡£×î³£ÓõÄForÑ­»·²ÎÊýÓÐ /L,/F²ÎÊý¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


FOR ²ÎÊý %±äÁ¿Ãû IN (Ïà¹ØÎļþ»òÏÂÁî) DO Ö´ÐеÄÏÂÁî

FOR %variable IN (set) DO command [command-parameters]

%variable Ö¸¶¨Ò»¸ö¼òµ¥×Öĸ¿ÉÌæ»»µÄ²ÎÊý¡£¡£¡£¡£¡£¡£ Õâ¸ö±äÁ¿Ãû¿ÉÒÔÊÇСдa-z»òÕß´óдA-Z,Çø·Ö¾Þϸд,FOR»á°Ñÿ¸ö¶ÁÈ¡µ½µÄÖµ¸³¸ø¸Ã±äÁ¿¡£¡£¡£¡£¡£¡£ÔÚÅú´¦Öóͷ£ÎļþÖÐ £¬£¬£¬£¬£¬ £¬ÒýÓñäÁ¿ÒªÓÃ%%variable £¬£¬£¬£¬£¬ £¬ÎÒÃÇÕâÀïÖ÷ÒªÏÈÈÝÔÚcmd´°¿ÚÖÐ £¬£¬£¬£¬£¬ £¬ÒýÓñäÁ¿ÓÃ%variable¼´¿É¡£¡£¡£¡£¡£¡£
(set)      Ö¸¶¨Ò»¸ö»òÒ»×éÎļþ¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔʹÓÃͨÅä·û¡£¡£¡£¡£¡£¡£ Ïà¹ØµÄÎļþ»òÏÂÁî¡£¡£¡£¡£¡£¡£
command    Ö¸¶¨¶Ôÿ¸öÎļþÖ´ÐеÄÏÂÁî¡£¡£¡£¡£¡£¡£ 
command-parameters 
             ÎªÌض¨ÃüÁîÖ¸¶¨²ÎÊý»òÏÂÁîÐпª¹Ø¡£¡£¡£¡£¡£¡£
/L ²ÎÊý£º µü´úÊýÖµ¹æÄ£
for /L %variable in (start,step,end) do command [command-parameters]

¸ÃÏÂÁîÌåÏÖÒÔÔöÁ¿ÐÎʽ´Ó×îÏȵ½¿¢ÊµÄÒ»¸öÊý×ÖÐòÁС£¡£¡£¡£¡£¡£Ê¹Óõü´ú±äÁ¿ÉèÖÃÆðʼֵ(start) £¬£¬£¬£¬£¬ £¬È»ºóÖð²½Ö´ÐÐÒ»×鹿ģµÄÖµ £¬£¬£¬£¬£¬ £¬Ö±µ½¸ÃÖµÁè¼ÝËùÉèÖõÄÖÕÖ¹Öµ (end)¡£¡£¡£¡£¡£¡£/L ½«Í¨¹ý¶ÔstartÓëend¾ÙÐнÏÁ¿À´Ö´Ðеü´ú±äÁ¿¡£¡£¡£¡£¡£¡£ÈôÊÇstartСÓÚend £¬£¬£¬£¬£¬ £¬¾Í»áÖ´ÐиÃÏÂÁî £¬£¬£¬£¬£¬ £¬²»È»ÏÂÁîÚ¹ÊͳÌÐòÍ˳ö´ËÑ­»·¡£¡£¡£¡£¡£¡£»£» £»£»£»£»¹¿ÉÒÔʹÓøºµÄ stepÒԵݼõÊýÖµµÄ·½·¨Öð²½Ö´Ðд˹æÄ£ÄÚµÄÖµ¡£¡£¡£¡£¡£¡£ÀýÈç £¬£¬£¬£¬£¬ £¬(1,1,5) ÌìÉúÐòÁÐ 1 2 3 4 5 £¬£¬£¬£¬£¬ £¬¶ø (5,-1,1) ÔòÌìÉúÐòÁÐ (5 4 3 2 1)¡£¡£¡£¡£¡£¡£ÏÂÁîcmd /C ¡°for /L %i in (1,1,5) do start cmd¡±,»áÖ´Ðз­¿ª5¸öcmd´°¿Ú¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


/F²ÎÊý£º ÊÇ×îǿʢµÄÏÂÁî £¬£¬£¬£¬£¬ £¬ÓÃÀ´´¦Öóͷ£ÎļþºÍһЩÏÂÁîµÄÊä³öЧ¹û¡£¡£¡£¡£¡£¡£
FOR /F ["options"] %variable IN (file-set) DO command [command-parameters]
FOR /F ["options"] %variable IN ("string") DO command [command-parameters]
FOR /F ["options"] %variable IN ('command') DO command [command-parameters]
(file-set) ΪÎļþÃû £¬£¬£¬£¬£¬ £¬for»áÒÀ´Î½«file-setÖеÄÎļþ·­¿ª £¬£¬£¬£¬£¬ £¬²¢ÇÒÔÚ¾ÙÐе½ÏÂÒ»¸öÎļþ֮ǰ½«Ã¿¸öÎļþ¶ÁÈ¡µ½ÄÚ´æ £¬£¬£¬£¬£¬ £¬Æ¾Ö¤Ã¿Ò»ÐзֳÉÒ»¸öÒ»¸öµÄÔªËØ £¬£¬£¬£¬£¬ £¬ºöÂÔ¿ÕȱÐС£¡£¡£¡£¡£¡£
("string")´ú±í×Ö·û´® £¬£¬£¬£¬£¬ £¬('command')´ú±íÏÂÁî¡£¡£¡£¡£¡£¡£
ÈôÊÇÎļþaa.txtÖÐÓÐÈçÏÂÄÚÈÝ£º
µÚ1ÐеÚ1ÁÐ µÚ1ÐеÚ2ÁР
µÚ2ÐеÚ1ÁÐ µÚ2ÐеÚ2ÁÐ
ÒªÏë¶Á³öaa.txtÖеÄÄÚÈÝ £¬£¬£¬£¬£¬ £¬¿ÉÒÔÓÃfor /F %i in (aa.txt) do echo %i £¬£¬£¬£¬£¬ £¬ÈôÊÇÈ¥µô/F²ÎÊýÔòÖ»»áÊä³öaa.txt £¬£¬£¬£¬£¬ £¬²¢²»»á¶ÁÈ¡ÆäÖеÄÄÚÈÝ¡£¡£¡£¡£¡£¡£

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾



ÏÈ´ÓÀ¨ºÅÖ´ÐÐ £¬£¬£¬£¬£¬ £¬ÓÉÓÚº¬ÓвÎÊý/F,ÒÔÊÇfor»áÏÈ·­¿ªaa.txt £¬£¬£¬£¬£¬ £¬È»ºó¶Á³öaa.txtÄÚÀïµÄËùÓÐÄÚÈÝ £¬£¬£¬£¬£¬ £¬°ÑËü×÷Ϊһ¸öÜöÝÍ £¬£¬£¬£¬£¬ £¬²¢ÇÒÒÔÿһÐÐ×÷Ϊһ¸öÔªËØ¡£¡£¡£¡£¡£¡£ÓÉÉÏͼ¿É¼û £¬£¬£¬£¬£¬ £¬²¢Ã»ÓÐÊä³öµÚ¶þÁеÄÄÚÈÝ £¬£¬£¬£¬£¬ £¬Ôµ¹ÊÔ­ÓÉÊÇÈôÊÇûÓÐÖ¸¶¨¡°delims=·ûºÅÁÐ±í¡±Õâ¸ö¿ª¹Ø £¬£¬£¬£¬£¬ £¬ÄÇôfor /FÓï¾ä»áĬÈÏÒÔ¿Õ¸ñ¼ü»òTab¼ü×÷ΪÍÑÀë·û¡£¡£¡£¡£¡£¡£For /FÊÇÒÔÐÐΪµ¥Î»À´´¦Öóͷ£Îı¾ÎļþµÄ £¬£¬£¬£¬£¬ £¬ÈôÊÇÎÒÃÇÏë°ÑÿһÐÐÔÙÆÊÎö³É¸üСµÄÄÚÈÝ £¬£¬£¬£¬£¬ £¬¾ÍʹÓÃdelimsºÍtokensÑ¡Ïî¡£¡£¡£¡£¡£¡£delimsÓÃÀ´¸æËßforÿһÐÐÓÃʲô×÷ΪÍÑÀë·û £¬£¬£¬£¬£¬ £¬Ä¬ÈÏÍÑÀë·ûÊǿոñºÍTab¼ü¡£¡£¡£¡£¡£¡£for /F ¡°delims= ¡° %i in (aa.txt) do echo %i ,½«delimsÉèÖÃΪ¿Õ¸ñ £¬£¬£¬£¬£¬ £¬Êǽ«Ã¿¸öÔªËØÒÔ¿Õ¸ñÖ§½â £¬£¬£¬£¬£¬ £¬Ä¬ÈÏֻȡ֧½âÖ®ºóµÄµÚÒ»¸öÔªËØ¡£¡£¡£¡£¡£¡£ÈôÊÇÎÒÃÇÏë»ñµÃµÚ¶þÁÐÊý¾Ý £¬£¬£¬£¬£¬ £¬¾ÍÒªÓõ½tokens=2 £¬£¬£¬£¬£¬ £¬À´Ö¸¶¨Í¨¹ýdelims½«Ã¿Ò»ÐзֳɸüСµÄÔªËØÊ± £¬£¬£¬£¬£¬ £¬ÒªÈ¡³öÄÄÒ»¸ö»òÄöÔªËØ:for /F ¡°tokens=2 delims= ¡° %i in (aa.txt) do echo %i¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

 ·¡
ÏÖʵÑùÌìÖ°Îö
 
ÎÒÃÇѡȡнüµÄEmotetÑù±¾ÏÂÔØÊ¹ÓõÄCMDÏÂÁî»ìÏý £¬£¬£¬£¬£¬ £¬À´Ê¹ÓÃÇ°ÃæµÄ֪ʶÀ´½â»ìÏý¡£¡£¡£¡£¡£¡£
 
 Ê¹ÓÃ×Ô½çÌÖÇéÐαäÁ¿ºÍForÑ­»·»ìÏý 
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¸ÃÑù±¾ÖÐʹÓÃÁËcmd.exe µÄÆôÓÃÑÓ³ÙÇéÐαäÁ¿/V:ON²ÎÊý £¬£¬£¬£¬£¬ £¬/C²ÎÊý £¬£¬£¬£¬£¬ £¬Ê¹ÓÃsetÏÂÁî×Ô½ç˵һ¸öÇéÐαäÁ¿kpx=lHUwrRfzapaiNzCqHfu:Doc(4YQ0S.1,xk}$) s6dK=mn5/+ygbW-TeP\v2tj{78Mh@;BO'FZ £¬£¬£¬£¬£¬ £¬Í¨¹ý&&Æ´½ÓÏÂÁî £¬£¬£¬£¬£¬ £¬È»ºóÊǸöforÑ­»·£º for %G in £¨ÊýÁУ©do set     1q=!1q!!kpx:~  %G,    1!&& if %G==  81  call  %1q:~    -377%¡£¡£¡£¡£¡£¡£ÎÒÃÇ×ÅÖØÆÊÎöÏÂforÏÂÁî¡£¡£¡£¡£¡£¡£ÓÉÓÚÇ°ÃæÊ¹ÓÃÁËÑÓ³ÙÇéÐαäÁ¿ £¬£¬£¬£¬£¬ £¬ÒÔÊÇ¿ÉÒÔʹÓÃ!1q!!kpx:~  %G,    1!µÄ·½·¨À´À©Õ¹±äÁ¿ £¬£¬£¬£¬£¬ £¬ÔÚÔËÐÐʱȡ´úÇéÐαäÁ¿Öµ¡£¡£¡£¡£¡£¡£forµÄÑ­»·±äÁ¿ÊÇ%G £¬£¬£¬£¬£¬ £¬%G in (ÊýÁÐÖµ) £¬£¬£¬£¬£¬ £¬!kpx:~ %G, 1!ÌåÏÖÈ¡ÇéÐαäÁ¿kpxÖÐϱêΪ%GµÄÒ»¸ö×Ö·û £¬£¬£¬£¬£¬ £¬ÎÒÃÇ¿ÉÒÔÓÃÈçÏÂpython±àÂëʵÏָù¦Ð§¡£¡£¡£¡£¡£¡£ÊýÁÐÖеĿոñ¿ÉÒÔºöÂÔ £¬£¬£¬£¬£¬ £¬ÊýÁÐÖеÄÊýÖµÕýºÃÊÇ377¸ö £¬£¬£¬£¬£¬ £¬kpx×Ö·û´®µÄ³¤¶ÈÊÇ72¸ö×Ö·û £¬£¬£¬£¬£¬ £¬Ï±êΪ81ÒѾ­²»±£´æ £¬£¬£¬£¬£¬ £¬ÒÔÊǵ±Ï±ê%G==81ʱ £¬£¬£¬£¬£¬ £¬ÔËÐÐʱÇéÐαäÁ¿1q=!1q!powershell ¡­¡­, call %1q:~-377% £¬£¬£¬£¬£¬ £¬ÒÔÊÇÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÊÇforÑ­»·±éÀú³öµÄpowershell¡­¡­ÏÂÁî £¬£¬£¬£¬£¬ £¬Ç°ÃæµÄ1q=!1q!Êdzõʼ»¯±äÁ¿1q £¬£¬£¬£¬£¬ £¬ÐèÒª±»È¥µôÒÔÃâÓ°ÏìÕý³£ÏÂÁîµÄÖ´ÐÐ £¬£¬£¬£¬£¬ £¬ÒÔÊÇÈ¡1q±äÁ¿µÄ-377ϱêÕýºÃÈÆ¹ýÇ°ÃæµÄ!1q!¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Êä³ö£º

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÏÂÔØEmotetµÄÁ´½ÓΪ£º
http://catbayouthaction.com/jKS86a
http://spsystems24.ru/O
http://xn--80abdh8aeoadtg.xn--p1ai/multimedia/hD4lyk7
http://borsehung.pro/pfWq
http://inpart-auto.ru/x2bu

 Ê¹ÓÃcmdϵͳÇéÐαäÁ¿ºÍForÑ­»·»ìÏý 

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÏȽ«»ìÏýcmdÏÂÁîÖеÄתÒå×Ö·û¡°^¡±ËùÓÐÈ¥µô £¬£¬£¬£¬£¬ £¬ÔÙ½«³ýÁ˱äÁ¿@Ö®ÍâµÄ¶ººÅ¡°,¡±¡¢·ÖºÅ¡°;¡±¡¢¶àÓà¿Õ¸ñɾ³ý¡£¡£¡£¡£¡£¡£×¢Öر£´æ±äÁ¿@ÖеĶººÅºÍ·ÖºÅ £¬£¬£¬£¬£¬ £¬²»È»Ó°ÏìÊä³öЧ¹û¡£¡£¡£¡£¡£¡£

 ¿É¼ûʹÓÃÁËcmdµÄϵͳÇéÐαäÁ¿%comspec% £¬£¬£¬£¬£¬ £¬¼´ÊÇcmd.exeµÄÖ´Ðз¾¶¡£¡£¡£¡£¡£¡£Ê¹ÓÃForÑ­»·µÄF²ÎÊý £¬£¬£¬£¬£¬ £¬ÔÚÏÂÁî'aSsoC .cmd'ÖÐÒÔ×Ö·ûv¡¢f¡¢=ΪÍÑÀë·û £¬£¬£¬£¬£¬ £¬È¡µÚ¶þÁм´ÊÇ¡°cmd¡±¡£¡£¡£¡£¡£¡£
fOr  /f  " delims=vf=  tokens=2"  %f  IN  ( 'aSsoC  .cmd' ) dO  %f  ¡£¡£¡£¡£¡£¡£ÆäËûÎÞÒâÒåµÄ×Ö·û´®»á±»cmdºöÂÔ¡£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


½Ó×Å×Ô½ç˵ÁËÒ»¸öÇéÐαäÁ¿@ £¬£¬£¬£¬£¬ £¬¼´ÊÇÒ»¸ö1460³¤¶ÈµÄ×Ö·û´®¡£¡£¡£¡£¡£¡£È»ºóʹÓÃForÑ­»·µÄ/L²ÎÊý £¬£¬£¬£¬£¬ £¬±éÀú±äÁ¿@£ºFOr /L %s In (1459,-4,+3 ) do (( ( (( seT \=!\!!@ :~ %s, 1!))))& iF %s eQU 3 (((CaLl %\ :~ -365% ) £¬£¬£¬£¬£¬ £¬×Ô½ç˵ÁËÇéÐαäÁ¿¡°\¡± £¬£¬£¬£¬£¬ £¬Ê¹ÓÃÇéÐαäÁ¿À©Õ¹·ûºÅ£¡ £¬£¬£¬£¬£¬ £¬!@ :~ %s, 1!ÌåÏÖÑ­»·±äÁ¿%s´Ó1459×îÏÈ £¬£¬£¬£¬£¬ £¬²½³¤Îª-4 £¬£¬£¬£¬£¬ £¬µ½3¿¢Ê £¬£¬£¬£¬£¬ £¬Ñ­»·ÌáÈ¡±äÁ¿@ÖеÄÒ»¸ö×Ö·û £¬£¬£¬£¬£¬ £¬³¤¶ÈΪ365¸ö×Ö·û £¬£¬£¬£¬£¬ £¬¼´´ÓForÑ­»·ÖØ×é³öµÄÏÂÁî×îÏÈÖ´ÐС£¡£¡£¡£¡£¡£
 
918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÎÒÃDZàдpython¾ç±¾ÊµÏÖForÑ­»·¹¦Ð§£º

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


×îÖÕ½âÃܳö¿É¶ÁµÄÄÚǶpowershellÏÂÁ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾



ÏÂÔØEmotetµÄÁ´½ÓΪ£º

http://reitmaier.de/01cedmfXo
http://phoxart.com/sWP0E9
http://panbras.com.br/FHhUYIQ
http://osmanager.com.br/t3HnvWx9x
http://oldwillysforum.com/ChleCkW

 Èþ
×ܽá
 
CMDµÄÏÂÁî»ìÏýǧ±äÍò»¯ £¬£¬£¬£¬£¬ £¬Î¨Ò»µÄÄ¿µÄ¾ÍÊÇÌÓ±ÜɳÏäµÄ¾²Ì¬»ò¶¯Ì¬¼ì²â £¬£¬£¬£¬£¬ £¬ÔöÌíÆÊÎöÄѶÈ¡£¡£¡£¡£¡£¡£Íò±ä²»ÀëÆä×Ú £¬£¬£¬£¬£¬ £¬Ö»ÒªÕÆÎÕÁËcmdÏÂÁîµÄ»ù±¾Óï¹æÔòÔò²¢ÊìÁ·Ê¹Óà £¬£¬£¬£¬£¬ £¬ÏÖÔÚ¶ñÒâÑù±¾µÄÖÖÖÖcmd»ìÏýÏÂÁî¶¼¿ÉÒÔÓ­Èжø½â £¬£¬£¬£¬£¬ £¬½ø¶øÊµÏÖ¶Ô¸ÃÀàÑù±¾µÄʶ±ð¼ì²âºÍÌá·À¡£¡£¡£¡£¡£¡£
 
²Î¿¼£º 
https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/dosfuscation-report.pdf