收到未知邮件别乱打开,小心中病毒,曝光这家公司

2023-11-27 11:55:32 +08:00
 kangod

2023 年 11 月 24 日收到一封邮件,我是公司法人,点开看看发票不过分吧?(虽然我从来不管公司的业务) 第一次在 V 站发贴,不知道怎么发图,我发文字算了。

收到邮箱如下:

flourishingmax11 发给 yxxxxx     2023-11-24 09:35 
发件人请求阅读收条,您愿意发送收条吗? <button>发送</button> 
购方名称: 北京 xxxx 信息技术有限公司
开票日期:2023-11-23
发票代码:033022200111
开票金额:978.00 元
发票号码:30297846
发票 PDF:下载发票

点击下载发票,跳转到了一个页面,是一个存储到 QQ 邮箱中转站的 zip 文件,打开 zip 里面是一个chm 文件,点击打开没什么反应,就是屏幕闪烁了一下。我看没什么作用,还手贱多点了几次,还是没什么东西出来,我就没管了。

今天突然发现笔记本电脑摄像头自动打开了,然后我就打开 windows 相机隐私设置,发现有一个应用打开了我的摄像头,是一个svchost.exe文件,鼠标移动到文件上面,还出现了公司信息:杭州诸相网络科技有限公司。

我 google 之后发现这家公司有很大的问题,一份浙江省通信管理局通报存在问题的应用软件名单:

序号 应用名称 应用开发者 应用来源 应用版本 所涉问题
50 虚贝租号 杭州诸相网络科技有限公司 应用宝 2.9.0 违规收集个人信息

还有一则新闻:

近日,家住广州的陈先生向南都记者报料,其 14 岁的孩子近期多次通过“虚贝租号”网站,购买已完成人脸识别的游戏账号,借此绕开防沉迷系统。“虽然每次金额不大,但隔三差五在学习时间花一、两个小时玩游戏,是否会对孩子的学习及身心健康造成影响?”陈先生向南都记者表达了担忧。

这家公司在做什么事情,不用我多说了吧,请大家避雷。

svchost.exe 文件正常是删不掉,系统提示被占用不能删,我进 PE 系统把它删掉了已经,过几天看看还有没有问题吧

13322 次点击
所在节点    信息安全
77 条回复
thinkm
2023-11-27 13:55:03 +08:00
卡巴斯基未报毒
lambdaq
2023-11-27 13:55:46 +08:00
诸相网络啊。。。也是 V 站老熟人了

/t/966984

/t/966243
wdlth
2023-11-27 14:21:14 +08:00
CHM 解压出来是个很大的 HTML ,unescape 后扫描结果是这个:
https://www.virustotal.com/gui/file/d5273546aeacccc35c22c6c48c726619fc8e8faad92632cf2d561da705c58ddb/detection
fzls
2023-11-27 14:39:42 +08:00
你胆子好大,陌生邮件里的福建居然敢下载后并解压双击里面的文件🤣很容易中毒的,很多病毒后缀特意不写 exe ,改成图片之类的后缀
fzls
2023-11-27 14:41:28 +08:00
@wdlth #23 卧槽,一片红啊
R18
2023-11-27 14:44:35 +08:00
InDom
2023-11-27 14:55:08 +08:00
那么,接下来的故事,应该是这样的:

Hi there!

Unfortunately, I need to start our conversation with bad news for you.
Around few months back I managed to get full access to all devices of yours,
which are used by you on a daily basis to browse internet.
Afterwards, I could initiate monitoring and tracking of all your activities on the internet.

I am proud to share the sequence of how it happened:
In the past I bought from hackers the access to various email accounts (today, that is rather a simple thing to do online).
Clearly, it was not hard at all for me to log in to your email account (...).

A week after that, I had already managed to effortlessly install Trojan virus to Operating Systems of all devices that are currently in your use,
and as result gained access to your email.
To be honest, that was not really difficult at all (because you were eagerly opening the links from your inbox emails).
I know, I am a genius. ~-~

With help of that software, I can gain access to all controllers in your devices (such as video camera, keyboard and microphone).
As result, I downloaded to my remote cloud servers all your personal data, photos and other information including web browsing history.
Likewise, I have complete access to all your social networks, messengers, chat history, emails, as well as contacts list.
My intelligent virus unceasingly refreshes its signatures (due to its driver-based nature), and hereby stays unnoticed by your antivirus software.

Herbey, I believe that now you finally start realizing how I could easily remain unnoticed all this while until this very letter...
While collecting information related to you, I had also unveiled that you are a true fan of porn sites.
You truly enjoy browsing through adult sites and watching horny vids, while playing your dirty solo games.
Bingo! I also recorded several filthy scenes with you in the main focus and montaged some dirty videos,
which demonstrate your passionate masturbation and cum sessions.

In case you still don't believe me, all I need is just one-two mouse clicks to make all your unmasking videos become available to your friends,
colleagues, and even relatives.
Well, if you still doubt me, I can easily make recorded videos of your orgasms become a public.
I truly believe that you surely would avoid that from happening, taking in consideration the type of the XXX videos you love watching,
(you are clearly aware of what I mean) it will result in a huge disaster for you.

Well, there is still a way to settle this tricky situation in a peaceful manner:
You will need to transfer $950 USD to my account (refer to Bitcoin equivalent based on the exchange rate at the moment transfer),
so once funds transfer is complete, I will straight away proceed with deleting all that dirty content from servers once and for all.

Afterwards, you can consider that we never met before. You have my honest word,
that all the harmful software will also be deactivated and deleted from all your devices currently in use. Worry not, I keep my promises.
That is truly a win-win solution that comes at a relatively reduced cost,
mostly knowing how much effort I spent on monitoring your profile and traffic for a considerably long time.
In event that you have no idea about means of buying and transferring bitcoins -
don't hesitate to use any search engine for your assistance (e.g., Google, Yahoo, Bing, etc.).

My bitcoin wallet is as follows: xxxxxxxx-xxxxxxxx-xxxxxxxx-xxxxxxxx
An important notice: I have specified my Bitcoin wallet with "-" symbols,
hence once you carry out a transfer, please make sure that you key-in my bitcoin address without "-" to be sure that your funds successfully reach my wallet.
I have allocated 48 hours for you to do that, and the timer started right after you opened this very email (2 days to be exact).

Don't even think of doing anything of the following:
! Abstain from attempting to reply me (this email was created by me inside your inbox page and the return address was generated accordingly).
! Abstain from attempting to get in touch with police or any other security services. Moreover, don't even think of sharing this to you friends.
Once I discover this (apparently, that is absolutely easy for me, taking in consideration that I have complete control over all systems you use) -
kinky video will straight away be made public.
! Don't even think of attempting to find me - that is completely useless. Don't forget that all cryptocurrency transactions remain completely anonymous.
! Don't attempt reinstalling the OS on all your devices or getting rid of them. That won't lead you to success either,
because I have already saved all videos at my remote servers as a backup.

Things you should not be concerned about:
! That your funds transfer won't reach my wallet.
- Worry not, I can see everything, hence after you finish the transfer, I will get a notification right away
(trojan virus of mine uses a remote-control feature, which functions similarly to TeamViewer).
! That I
wdlth
2023-11-27 14:55:38 +08:00
@fzls 这还只是一个 Loader ,真正执行的还在后面。
clorischan
2023-11-27 15:51:02 +08:00
https://imgur.com/a/QsZqLmN.jpg
点下载 WD 直接就给干掉了
twofox
2023-11-27 15:55:10 +08:00

怎么跟我之前看到的新闻一模一样

大概就是你这样,点了邮件,中了病毒
然后,通过远程控制,伪造自己事老板,然后让会计转钱

你既然都是法人了,那么建议你跟手下的人说一下,最近转钱的事情,要当面或者电话确认
twofox
2023-11-27 15:59:03 +08:00
https://www.163.com/dy/article/IK8M0SM80511A5GF.html

想起来了,是在火绒安全公众号看见的,这是新闻原本链接
wdlth
2023-11-27 16:15:39 +08:00
dsb2468
2023-11-27 16:35:00 +08:00
dsb2468
2023-11-27 16:36:59 +08:00
从这个病毒的配置文件来看,属于国内的小黑客(关键字 sb360qunimade )

C:\Users\%USERNAME%\AppData\Local\VirtualStore

Foolish.png=Foolish.png

https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/wps.txt=svchost.exe
https://dlltemasil.oss-cn-hongkong.aliyuncs.com/libcef.dll=libcef.dll
https://platformi.oss-cn-hongkong.aliyuncs.com/Foolish.dat=Foolish.dat
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/ApexFramework_x86.dll=ApexFramework_x86.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/AudioLib.dll=AudioLib.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/CertLib.dll=CertLib.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/CrashRpt1403.dll=CrashRpt1403.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/d3dx9_42.dll=d3dx9_42.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/FreeImage.dll=FreeImage.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/IMProtocol.dll=IMProtocol.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/ImShareUtil.DLL=ImShareUtil.DLL
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/libcrypto-1_1.dll=libcrypto-1_1.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/libcurl.dll=libcurl.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/libexpat.dll=libexpat.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/libogg.dll=libogg.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/libssl-1_1.dll=libssl-1_1.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/libvorbis.dll=libvorbis.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/libvorbisfile.dll=libvorbisfile.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/MSVCP120.dll=MSVCP120.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/MSVCR71.dll=MSVCR71.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/MSVCR90.dll=MSVCR90.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/MSVCR120.dll=MSVCR120.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/Physics.dll=Physics.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/PhysX3_x86.dll=PhysX3_x86.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/PhysX3Cooking_x86.dll=PhysX3Cooking_x86.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/PxFoundation_x86.dll=PxFoundation_x86.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/PxPvdSDK_x86.dll=PxPvdSDK_x86.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/ResLib.dll=ResLib.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/ScanEngine.dll=ScanEngine.dll
https://sb360qunimade.oss-cn-hongkong.aliyuncs.com/steam_api.dll=steam_api.dll
shenjinpeng
2023-11-27 16:40:02 +08:00
身边做财务的朋友已经有几个中招了, 听说是远程控制电脑微信群发 , chm 和 vbe 格式
nocmt
2023-11-27 16:42:02 +08:00
@kangod #3 这... 就这么有勇气?
dsb2468
2023-11-27 17:11:47 +08:00
@wdlth 上面这一堆,免杀做得不错,VT 基本是 0
qiaofanxing
2023-11-27 17:20:56 +08:00
@dsb2468 #37 我用卡巴试了一下,被杀了。有没有胆子大的试试别家的
asm
2023-11-27 17:28:39 +08:00
下载了一坨多益游戏的文件,不过有三个感觉是恶意的。典型的白加黑,先加载 libcef.dll ,之后加载,Foolish.png 和 Foolish.dat 。特别是 libcefl.dll ,算是源码级的免杀了。
Foolish.png 被解密出一个 pe 文件,看 pdb 文件,
E:\2023-TianMa~\TMAir_Ghost10.0_dev_vs2022 标记 v4.5.0\TMAir_Ghost10.0_dev_vs2022\dependencies\include\fmt\core.h

算是 gh0st 的改版的远控了。
这一系列算是这两年特别出名的,银狐干的。这个名字没有个准确的组织,算是这一系列的总成。

重装系统吧。虽然没找到有什么特殊的自启动,毕竟心里安心。
kangod
2023-11-27 17:56:14 +08:00
各位大佬好厉害…涨知识了,已经重装系统了,现在还在安装软件

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/995527

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX