ÆÆ¿Ç¶ø³ö£ºÈ«ÐÂÎïÁªÍø½©Ê¬ÍøÂçAuthBot¸¡³öË®Ãæ
Ðû²¼Ê±¼ä 2023-08-07ÍòÀû¹ú¼Ê¹ÙÍøÓë¹ãÖÝ´óÑ§Íø°²Ñ§Ôº·¢Ã÷ÁËÒ»¸öеÄÎïÁªÍø½©Ê¬ÍøÂ磬£¬£¬²¢½«ÆäÃüÃûΪAuthBot¡£¡£¡£¡£¡£¡£¡£±¾ÎÄͨ¹ý¶Ô¸Ã½©Ê¬ÍøÂç¾ÙÐÐÑù±¾ÊÖÒÕÆÊÎö£¬£¬£¬ÖÜÈ«ÏÈÈÝÁËÆäÖ´ÐÐÁ÷³Ì¡¢Í¨Ñ¶ÐÒé¡¢¿ØÖÆÏÂÁîµÈϸ½Ú£¬£¬£¬ÒÔ×÷Ϊ¸÷ÐÐÒµ¼°Ïà¹ØÆóÒµÖÆ¶©ÍøÂçÇå¾²Õ½ÂԵIJο¼¡£¡£¡£¡£¡£¡£¡£
2023Äê7ÔÂ⣬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøÔÚ¼ÓÈë¹ú¼ÒÖØµãÑз¢ÍýÏëÏîÄ¿¡°´ó¹æÄ£Òì¹¹ÎïÁªÍøÍþв¿É¿Ø²¶»ñÓëÆÊÎöÊÖÒÕ£¨2022YFB3104100£©¡±µÄÑо¿Àú³ÌÖУ¬£¬£¬·¢Ã÷ÁËÒ»¸öеÄÎïÁªÍø½©Ê¬ÍøÂç¼Ò×å¡£¡£¡£¡£¡£¡£¡£ÔÚVirusTotalÉÏ£¬£¬£¬´ó²¿·Öɱ¶¾ÒýÇæ½«Æäʶ±ðΪMirai»òÕßGafgyt¡£¡£¡£¡£¡£¡£¡£¾ÓÉÏêϸÆÊÎö£¬£¬£¬È·ÈÏÍêȫûÓи´ÓÃMirai¡¢GafgytµÄÈκÎÔ´´úÂë¡£¡£¡£¡£¡£¡£¡£
¼øÓÚÑù±¾°üÀ¨×Ö·û´®AuthBot£¬£¬£¬ÇÒ»á¼ÓÃÜ×÷ΪÉÏÏßÊý¾Ý·¢Ë͸øC2£¬£¬£¬ÎÒÃǽ«ÆäÃüÃûΪAuthBot¡£¡£¡£¡£¡£¡£¡£AuthBotÉè¼ÆÁË×Ô½ç˵¼ÓÃÜËã·¨ÓÃÓÚ¼ÓÃܺÍC2µÄͨѶ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬Æä¹¦Ð§²¢²»ÍêÉÆ£¬£¬£¬Ö»ÊµÏÖÁËÐÄÌøµÈÓÐÏÞ¹¦Ð§£¬£¬£¬²¢²»°üÀ¨DDoS¹¥»÷µÈ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
ÓÐÀíÓÉÏàÐÅ£¬£¬£¬ÎÒÃÇÕýÔÚ¼ûÖ¤Ò»¸öÈ«ÐÂÎïÁªÍø½©Ê¬ÍøÂçµÄ¡°ÆÆ¿Ç¶ø³ö¡±¡£¡£¡£¡£¡£¡£¡£
Ñù±¾ÊÖÒÕÆÊÎö
ÏÖÔÚAuthBotÖ»Ö§³Öamd64£¬£¬£¬ÔÝʱû·¢Ã÷ÆäËüCPU¼Ü¹¹µÄÑù±¾¡£¡£¡£¡£¡£¡£¡£AuthBot½ÓÄÉUPX¼Ó¿Ç£¬£¬£¬²¢¸Ä¶¯UPX»ÃÊýÀ´¶Ô¿¹Íѿǡ£¡£¡£¡£¡£¡£¡£½«UPX»ÃÊý¡°YTS\x99¡±ÖØÐ¸ÄΪ¡°UPX!¡±£¬£¬£¬¼´¿ÉÀÖ³ÉÍѿǡ£¡£¡£¡£¡£¡£¡£

1¡¢Ö´ÐÐÁ÷³Ì
ºÍ´ó´ó¶¼½©Ê¬ÍøÂç²î±ð£¬£¬£¬AuthBot»áÊ×ÏÈÅþÁ¬C2£¬£¬£¬ÅþÁ¬Ê§°ÜÍ˳öÀú³Ì¡£¡£¡£¡£¡£¡£¡£ÔÚºÍC2½¨ÉèͨѶ֮ºó£¬£¬£¬²ÅÖ´ÐÐÆäËü²Ù×÷£¬£¬£¬ÈçÐÞ¸Ä×ÔÉíÀú³ÌÃûµÈ¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÓÉÓÚËüÓ²±àÂëµÄ¼ÓÃÜ×Ö·û´®ÐèÒªÓõ½C2·µ»ØµÄÃÜÔ¿À´½âÃÜ¡£¡£¡£¡£¡£¡£¡£AuthBotµÄC2µØµãÖ±½ÓʹÓöþ½øÖƾÙÐи³Öµ£¬£¬£¬¶ø·Ç×Ö·û´®¡£¡£¡£¡£¡£¡£¡£

ÔÚºÍC2ЧÀÍÆ÷½¨ÉèͨѶ֮ºó£¬£¬£¬Ö´ÐÐÆô¶¯Á÷³Ì£º½âÃÜ×Ö·û´®×ÊÔ´¡¢·¢ËÍCPU¼Ü¹¹Ãû³Æµ½C2ЧÀÍÆ÷¡¢Àú³ÌÃûαװ¡¢×Ô¿½±´ÖÁ/usr/bin/BoxBusy¡£¡£¡£¡£¡£¡£¡£
Ëæºó½øÈëÑ»·£¬£¬£¬Ö´ÐÐselectº¯Êý£¬£¬£¬ÎüÊÕÖ´ÐÐC2Ï·¢µÄÖ¸Áî¡£¡£¡£¡£¡£¡£¡£ÐèÒªÖ¸³öµÄÊÇ£¬£¬£¬ÔÚÑ»·º¯ÊýÀ£¬£¬AuthBot»á»ñÈ¡¸¸Àú³ÌËù·¿ªµÄÎļþÃû³Æ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇËù·¿ªµÄÎļþÃû³Æ°üÀ¨¡°/proc/¡±»òÕß¡°socket:[¡±£¬£¬£¬Ôò°Ñ¸¸Àú³ÌÃû³Æ¼ÓÃÜ·¢Ë͸øC2£¬£¬£¬Í¬Ê±ÊµÑékill¸¸Àú³Ì¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÔÚʵÑé¼ì²âµ÷ÊÔÆ÷»òÕßɳÏäɳÏäÇéÐÎÌØÕ÷¡£¡£¡£¡£¡£¡£¡£
2¡¢Í¨Ñ¶ÐÒé
AuthBotºÍC2µÄͨѶÐÒé²¢²»Öش󣬣¬£¬Ö»ÐèÒª4ÂÖ¼´¿ÉÓëC2½¨ÉèͨѶ¡£¡£¡£¡£¡£¡£¡£AuthBotºÍC2µÄͨѶÊý¾Ý¾ÓÉÁ½²ã¼ÓÃÜ£¬£¬£¬Íâ²ãÊÇÒì»ò£¬£¬£¬ÄÚ²ã½ÓÄÉÆä×Ô¼ºÊµÏÖµÄÊýѧÔËËã·½·¨¼ÓÃÜ£¬£¬£¬Ïêϸ¼Ó¡¢½âÃÜËã·¨µÄα´úÂë»®·ÖÈçÏ£º


ÒÔÏÂÊÇÔËÐÐÑù±¾ÏÖʵÁ÷Á¿£º

Step1£ºBot¡úC2
AuthBotÌìÉú8µ½15×Ö½ÚµÄËæ»ú×Ö·û´®×÷ΪXORÃÜÔ¿£¬£¬£¬ÓÃÓÚºóÐøÍ¨Ñ¶¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£½Ó×ÅÒì»ò¼ÓÃÜ×Ö·û´®"AuthBot "£¬£¬£¬°ÑXORÃÜÔ¿×Ö·û´®ºÍÃÜÎÄÆ´½ÓÆðÀ´£¬£¬£¬²¢Ê¹ÓÃ×Ô½ç˵Ëã·¨¼ÓÃÜËüÃÇ£¬£¬£¬·¢ËÍÖÁC2¡£¡£¡£¡£¡£¡£¡£


ÒÔÉÏÊö½ØÍ¼ÀïµÄÊý¾ÝΪÀý£¬£¬£¬¡°a78f928fa5a799979d9daa908e8f9b28421a160d431e256f¡±¾ÓÉÄÚ²ãËã·¨½âÃܺóÊÇ¡°7763666375776B696F6F786462636D203616120B37181F49¡±¡£¡£¡£¡£¡£¡£¡£

Step2£ºC2¡úBot
C2·µ»Ø17×Ö½Ú¼ÓÃÜÊý¾Ý£¬£¬£¬¾ÓÉÒì»òºÍ×Ô½ç˵Ëã·¨½âÃܺóΪ¡°Accepted GoAwayMr¡±¡£¡£¡£¡£¡£¡£¡£Ç°8×Ö½Ú¡°Accepted¡±Åú×¢ÅþÁ¬C2Àֳɣ¬£¬£¬ ¡°GoAwayMr¡±Í¬ÑùÊÇÃÜÔ¿£¬£¬£¬ÓÃÓÚ½âÃÜ×ÔÉí¼ÓÃÜ×Ö·û´®¡£¡£¡£¡£¡£¡£¡£

ÒÔÉÏÊö½ØÍ¼ÀïµÄÊý¾ÝΪÀý£¬£¬£¬¡°12ece9f2d5d3faf94704e501c5eec604c1¡±¾ÓÉÒì»ò½âÃÜÖ®ºó£¬£¬£¬ÊÇ¡°658f8f91a0a49190286b9d65a78dab73a2¡±¡£¡£¡£¡£¡£¡£¡£

¡°658f8f91a0a49190286b9d65a78dab73a2¡±¾ÓÉ×Ô½ç˵Ëã·¨½âÃܺóÕýÊÇ¡°Accepted GoAwayMr¡±¡£¡£¡£¡£¡£¡£¡£×Ô½ç˵Ëã·¨½âÃÜÈçÏ£º

Step3£ºBot¡úC2
AuthBotÆ´½ÓCPU¼Ü¹¹×Ö·û´®¡°x86_64¡±ºÍ¡°yarn¡±£¬£¬£¬¾ÓÉÁ½²ã¼ÓÃÜ·¢Ë͸øC2¡£¡£¡£¡£¡£¡£¡£

Step4£ºBot¡úC2
AuthBotÏòC2·¢ËÍ×ÔÉíÀú³ÌµÄһЩȨÏÞÐÅÏ¢µÈ£¬£¬£¬ÈçÊÇ·ñ¶Ô/usr/bin/Ŀ¼ÓÐдȨÏÞ£¬£¬£¬ÊÇ·ñΪrootȨÏÞÔËÐеȡ£¡£¡£¡£¡£¡£¡£È¨ÏÞÊý¾ÝÖ»¾ÓÉÁËXOR¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£XOR½âÃÜÈçÏ£º

ÆäÖÐÊ××Ö½ÚΪÊÇÓ²±àÂëµÄ\x04£¬£¬£¬µÚ¶þ×Ö½Ú\x00ÌåÏÖÊÇrootȨÏÞÔËÐУ¬£¬£¬µÚÈý×Ö½ÚÊÇÓ²±àÂëµÄ\x01£¬£¬£¬µÚ4×Ö½Ú\x00ÌåÏÖ¶Ô/usr/bin/Ŀ¼ÓÐдȨÏÞ¡£¡£¡£¡£¡£¡£¡£ÆäÓà8×Ö½ÚÊÇ\x00¡£¡£¡£¡£¡£¡£¡£
ÖÁ´Ë£¬£¬£¬AuthBotÉÏÏßÀֳɣ¬£¬£¬×îÏÈÆÚ´ýÖ´ÐÐC2Ï·¢µÄÖ¸Áî¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚΪֹ£¬£¬£¬Ö»ÊÕµ½¹ýC2·µ»ØµÄÁ½×Ö½ÚÐÄÌøÊý¾Ý\x76\x63£¬£¬£¬Òì»ò½âÃܺóÊÇ\x01\x00¡£¡£¡£¡£¡£¡£¡£ÐÄÌøÊý¾ÝºÍ¿ØÖÆÏÂÁîÊý¾Ý¶¼ÊÇÖ»ÓÐÒ»²ãXORÒì»ò¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£
3¡¢¿ØÖÆÏÂÁî
ÏÖÔÚ£¬£¬£¬AuthBotÖ»Ö§³Ö°üÀ¨ÐÄÌøÔÚÄÚµÄ3Àà¿ØÖÆÏÂÁî¡£¡£¡£¡£¡£¡£¡£
1¡¢IPµØµãÏ·¢£ºµ±C2·µ»ØµÄÊý¾Ý³¤¶È´óÓÚ10×Ö½Ú£¬£¬£¬½«Æ«ÒÆ1ÆðʼµÄÊý¾ÝÆÊÎöΪip:portÐÎʽµÄ×Ö·û´®²¢ÉúÑÄ£¬£¬£¬ÖÁ¶àÉúÑÄ4¸ö¡£¡£¡£¡£¡£¡£¡£¸ÃÏÂÁîÏÖÔÚÖ»ÓÃÀ´²âÊÔÑù±¾¶ÔIPµÄÆÊÎöÊÇ·ñ׼ȷ£¬£¬£¬ºóÐøºÜ¿ÉÄÜÓÃÓÚÆÊÎöDDoS¹¥»÷Ä¿µÄ»ò»ØÁ¬C2ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£
2¡¢ÐÄÌø£ºµ±C2·µ»ØµÄÊý¾Ý³¤¶ÈСÓÚ¼´ÊÇ10×Ö½Ú²¢ÇÒÊ××Ö½ÚΪ\x01£¬£¬£¬ÔòÈ϶¨ÊÇÐÄÌø°ü£¬£¬£¬Ö±½Ó·µ»ØC2ÏàͬµÄÐÄÌø°üÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
3¡¢É¾³ýIPµØµã£ºµ±C2·µ»ØµÄÊý¾Ý³¤¶ÈСÓÚ¼´ÊÇ10×Ö½Ú²¢ÇÒÊ××Ö½ÚΪ\x00£¬£¬£¬É¾³ý¶ÔÓ¦ÒÑÉúÑĵÄIPµØµã¡£¡£¡£¡£¡£¡£¡£
×ܽá
×ܵÄÀ´¿´£¬£¬£¬AuthBotµÄ¹¦Ð§»¹ºÜ²»ÍêÉÆ£¬£¬£¬²»°üÀ¨DDoS¹¥»÷¹¦Ð§£¬£¬£¬Ò²Ã»ÓÐÏÂÔØ¡¢shellµÈÆäËü¹¦Ð§¡£¡£¡£¡£¡£¡£¡£²¢ÇÒ¹ØÓÚ·ÇÐÄÌø°üµÄÁíÍâÁ½Àà¿ØÖÆÏÂÁ£¬£¬ºÜÄÑÃ÷È·¹¥»÷ÕßµÄÕæÊµÒâͼ¡£¡£¡£¡£¡£¡£¡£
²»¹ýÕÕ¾ÉÓÐһЩÁÁµã£¬£¬£¬ºÃ±ÈÐÂÓ±µÄÁ½´Î¼ÓÃÜ£¬£¬£¬ÓÈÆäÊÇͨ¹ýC2·µ»ØµÄÃÜÔ¿À´½âÃÜ×ÔÉí¼ÓÃÜ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ËüµÄ´úÂëÀïÒ²¿´²»³ö³£¼û½©Ê¬ÍøÂç¶ÔMirai¡¢Gafgyt´úÂëµÄ¸´Óᣡ£¡£¡£¡£¡£¡£
Òò´Ë£¬£¬£¬ÎÒÃÇÒÔΪAuthBotÊÇȫеÄÎïÁªÍø½©Ê¬ÍøÂ磬£¬£¬µ«»¹Ö»ÊǸոսµÉúµÄ³õ¼¶½×¶Î¡£¡£¡£¡£¡£¡£¡£ÎÒÃÇ»áÒ»Á¬¼à¿ØAuthBotеÄÑݱäÉú³¤¡£¡£¡£¡£¡£¡£¡£
IOC
C2£º
190[.]10[.]8[.]179:8008
MD5£º
7fd6f1ffceb010e4607198d1d4a527c3


¾©¹«Íø°²±¸11010802024551ºÅ