3、Downeks和Quasar远控木马近期针对政府攻击
标题:Downeks and Quasar RAT Used in Recent Targeted Attacks Against Governments
作者信息:January 30, 2017 4:00 PM By Mashav Sapir, Tomer Bar, Netanel Rimer, Taras Malivanchuk, Yaron Samuel 和 Simon Conant
//BEGIN
Palo Alto Networks Traps Advanced Endpoint Protection recently prevented recent attacks that we believe are part of a campaign linked to DustySky. DustySky is a campaign which others have attributed to the Gaza Cybergang group, a group that targets government interests in the region.
This report shares our researchers’ analysis of the attack and Remote Access Tool (RAT). We also discovered during our research that the RAT Server used by this attacker is itself vulnerable to remote attack, a double-edged sword for these attackers.
美国Palo Alto Networks公司最近阻止了一个据称名为DustySky的攻击,DustySky可能是一个位于加沙的网络犯罪团伙发起的,他们的目标专门针对该地区。
//END
Downeks has static encryption keys hardcoded in the code. These keys are initialized in the “Defaults” class constructor, suggesting that the author of this malware has great affection for stackoverflow:
Downeks在其代码中含有静态的加密秘钥,这些密码都统一在名为Defaults的类结构中被初始化,这显示出恶意代码的作者对栈溢出的青睐!
点评:万马奔腾的时代,马的用途各不相同。 |