一. 简介

二. 样本运行流程

三. 分析











3、PowerShell 分析
4、DLL执行
四. IOC文件名:"QD0948945078TQ.doc"
sha256: 27e5abb8149408da077133529e8da246c1003edc20974635d6757e05798d78c5
sha1: 3a7a405ef3df95c1cfa18284749ff885a6430a88
md5: 2b310974bb4a113881471845a109b3de
DLL文件
md5 C:\Users\admin\Kjl48kr\Nqm9ty9\S93E.dll 0a3a2efb412b08e886f9856a5093c6e4
md5 C:\Users\admin\Kjl48kr\Nqm9ty9\S93E.dll 617231616b57a1a09e14cf068d9c8a21
DNS requests
www.starlingtechs.com
Connections
ip 71.72.196.159
HTTP/HTTPS 请求
url https://www.starlingtechs.com/GNM/
url http://71.72.196.159/3xjgiyzod/r2dsukigxsy2d/4r9mzyqmmbgte85/nemcrg565qsoiqnnoa/fgpz1c4ee1mmcc/4wuwc0y5xm79x/
参考链接: