能力值:
( LV2,RANK:10 )
|
-
-
2 楼
有个叫给力的** 专门卖这个马
一般都是给做游戏的或者淘宝的
从13年才是rundll32这种模式的吧,还会释放Inf文件安装启动项,以前是白加黑的
代码完全抄的别人的,作者就在次论坛
|
能力值:
( LV2,RANK:10 )
|
-
-
3 楼
学习一下。
|
能力值:
( LV4,RANK:50 )
|
-
-
4 楼
请问 枚举进程查找杀软进程后 ,用哪种干杀软的?
|
能力值:
( LV5,RANK:60 )
|
-
-
5 楼
嗯嗯,hook007以前就是白加黑的,经常利用暴风迅雷什么的,现在大都是快捷方式+bat+rundll32
|
能力值:
( LV5,RANK:60 )
|
-
-
6 楼
其实我也纳闷,他枚举之后要干什么,代码中没看出来要干什么,枚举不管有没有杀软都没有后续操作。具体你可以看一下360对其中另一个变种的分析de1K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3u0D9L8$3N6K6i4K6u0W2x3K6j5H3i4K6u0W2j5$3&6Q4x3V1j5K6y4U0m8K6j5h3k6W2i4K6u0r3x3U0l9I4y4q4)9J5c8U0l9&6i4K6u0r3x3e0u0Q4x3V1k6Z5L8$3!0C8x3o6l9%4i4K6g2X3N6s2u0G2K9X3q4F1i4K6u0r3i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1@1i4@1u0n7i4K6V1$3i4@1f1^5i4@1q4q4i4@1p5@1i4@1f1@1i4@1t1^5i4@1u0m8i4@1g2r3i4@1u0o6i4K6W2m8i4@1f1%4i4@1u0n7i4K6V1K6i4@1f1#2i4K6V1H3i4K6R3^5i4@1f1#2i4@1q4p5i4K6V1%4i4@1f1%4i4@1q4o6i4@1p5$3i4@1f1@1i4@1t1^5i4@1t1J5i4@1f1%4i4K6W2o6i4K6S2n7i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1$3i4K6W2o6i4@1p5^5i4@1f1&6i4@1p5&6i4@1q4o6i4@1f1#2i4@1u0m8i4K6V1@1i4@1f1^5i4@1q4r3i4@1p5#2i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1^5i4@1q4r3i4K6V1#2i4@1f1#2i4K6W2n7i4@1u0q4i4@1f1%4i4@1u0n7i4K6V1K6i4@1f1$3i4K6W2p5i4K6W2r3i4@1f1$3i4K6W2p5i4K6R3H3i4@1f1^5i4@1u0p5i4@1q4r3i4@1f1^5i4@1u0r3i4K6W2n7i4@1f1%4i4@1p5^5i4K6S2n7i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1@1i4@1u0r3i4K6W2p5i4@1f1$3i4K6S2m8i4@1p5@1i4@1f1$3i4K6W2o6i4@1p5^5i4@1f1&6i4@1p5&6i4@1q4o6i4@1f1^5i4K6R3%4i4@1q4m8i4@1f1^5i4@1u0m8i4@1q4n7i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1@1i4@1u0p5i4K6R3$3i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1#2i4K6W2o6i4@1p5^5i4@1f1#2i4@1q4q4i4K6W2q4i4@1f1&6i4K6V1&6i4K6R3#2i4@1f1$3i4K6R3@1i4K6W2r3i4@1f1$3i4K6W2r3i4K6V1K6i4@1f1^5i4@1u0r3i4K6R3%4i4@1f1%4i4@1p5^5i4K6S2n7i4@1f1@1i4@1t1^5i4@1q4p5i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1$3i4K6W2o6i4@1p5^5i4@1f1&6i4@1p5&6i4@1q4o6i4@1f1#2i4@1t1&6i4@1t1$3i4@1f1$3i4@1t1J5i4@1p5I4i4@1f1$3i4K6W2o6i4K6R3&6i4@1f1$3i4K6R3&6i4@1p5%4i4@1f1^5i4@1p5I4i4K6S2o6i4@1f1^5i4@1u0r3i4K6V1&6i4@1f1@1i4@1t1^5i4@1q4m8i4@1f1#2i4K6S2m8i4@1p5^5i4@1f1@1i4@1u0p5i4K6W2o6i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1%4i4K6W2n7i4@1q4q4i4@1f1%4i4K6W2m8i4K6R3@1i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1@1i4@1t1^5i4@1u0m8i4@1f1@1i4@1u0m8i4K6R3$3i4@1f1&6i4K6R3I4i4@1u0r3i4@1f1#2i4K6R3#2i4K6S2p5i4@1f1^5i4@1p5%4i4@1p5$3i4@1f1#2i4K6S2r3i4K6V1I4i4@1f1@1i4@1t1^5i4@1u0n7i4@1f1&6i4K6V1^5i4@1t1J5i4@1f1%4i4@1q4p5i4K6V1$3i4@1f1%4i4K6V1#2i4@1p5#2i4@1f1K6i4K6R3H3i4K6R3J5i4@1f1^5i4@1u0r3i4K6V1&6i4@1f1@1i4@1t1^5i4@1q4m8i4@1f1#2i4K6S2r3i4@1q4r3i4@1f1^5i4K6R3K6i4@1u0p5i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1$3i4K6W2o6i4@1p5^5i4@1f1&6i4@1p5&6i4@1q4o6i4@1f1%4i4K6V1@1i4K6W2r3i4@1f1$3i4K6R3^5i4K6V1H3i4@1f1#2i4K6V1&6i4@1p5^5i4@1f1@1i4@1t1^5i4@1q4p5i4@1f1%4i4K6W2m8i4K6R3@1i4@1f1#2i4K6S2r3i4@1q4r3i4@1f1&6i4K6R3H3i4K6R3&6i4@1f1#2i4K6S2m8i4K6W2r3i4@1f1^5i4K6R3K6i4@1u0p5i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1$3i4K6R3^5i4K6V1$3i4@1f1^5i4K6R3H3i4K6R3#2i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1@1i4@1u0p5i4K6W2o6i4@1f1^5i4K6R3H3i4K6R3#2i4@1f1#2i4K6S2q4i4K6R3$3i4@1f1#2i4K6S2r3i4@1t1J5i4@1f1@1i4@1t1^5i4K6S2m8i4@1f1&6i4K6R3I4i4K6V1%4i4@1f1%4i4K6V1#2i4K6V1&6i4@1f1%4i4K6W2m8i4K6R3@1i4@1f1@1i4@1u0n7i4@1p5K6i4@1f1%4i4@1p5H3i4K6R3I4i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1@1i4@1u0p5i4K6R3$3i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1#2i4K6V1H3i4K6S2q4i4@1f1$3i4K6W2p5i4@1p5#2i4@1f1$3i4@1t1J5i4@1p5I4i4@1f1$3i4K6W2o6i4K6R3&6i4@1f1%4i4K6V1@1i4@1p5^5i4@1f1#2i4K6R3^5i4@1t1H3i4@1f1%4i4K6W2n7i4@1t1^5i4@1f1#2i4K6R3#2i4@1t1K6i4@1f1&6i4K6R3H3i4@1u0n7i4@1f1^5i4@1u0q4i4K6V1I4i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1@1i4@1u0p5i4K6R3$3i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1@1i4@1u0n7i4@1p5K6i4@1f1%4i4@1p5H3i4K6R3I4i4@1f1@1i4@1u0n7i4K6S2p5i4@1f1%4i4K6R3@1i4@1t1$3i4@1f1#2i4K6W2o6i4@1p5^5i4@1f1$3i4@1p5H3i4@1t1%4i4@1f1$3i4K6W2o6i4@1q4o6i4@1f1@1i4@1t1^5i4@1q4p5i4@1f1K6i4K6R3H3i4K6R3J5
|
能力值:
( LV3,RANK:20 )
|
-
-
7 楼
把系统中安装的安全软件类型传递给控制端···
|
能力值:
( LV7,RANK:110 )
|
-
-
8 楼
康小泡...
|
能力值:
( LV2,RANK:10 )
|
-
-
9 楼
 大婶,请收下我的膝盖
|
能力值:
( LV4,RANK:50 )
|
-
-
10 楼
mark一下。。。
|
能力值:
( LV2,RANK:10 )
|
-
-
11 楼
顶一下!!!
|
能力值:
( LV3,RANK:30 )
|
-
-
12 楼
康小跑,哈哈
|
能力值:
( LV2,RANK:10 )
|
-
-
13 楼
不错学习了!!!
|
能力值:
( LV2,RANK:10 )
|
-
-
14 楼
非常典型的白加黑远控木马。
|
能力值:
( LV12,RANK:2670 )
|
-
-
15 楼
康小泡?
b24K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6e0f1J5M7r3!0B7K9h3g2Q4x3X3g2U0L8W2)9J5c8Y4c8Z5M7X3g2S2k6q4)9J5k6o6b7H3z5o6f1K6z5q4)9J5k6o6q4Q4x3X3b7I4i4K6u0W2K9s2c8E0L8l9`.`.
|
能力值:
( LV6,RANK:80 )
|
-
-
16 楼
rundll.exe 也能过主动防御???
|
能力值:
( LV2,RANK:10 )
|
-
-
17 楼
rundll 这么脆弱?
|
能力值:
(RANK:20 )
|
-
-
18 楼
兄弟最近在干吗
|
能力值:
(RANK:20 )
|
-
-
19 楼
我没分析道DLL解密temp的过程,求一份详细的分析资料!或者视频
|
能力值:
( LV2,RANK:10 )
|
-
-
20 楼
我只是想问一个问题,通过逆向分析,可以复现木马的源代码么?
|
能力值:
( LV2,RANK:10 )
|
-
-
21 楼
hook007论坛没搜到
|
能力值:
( LV2,RANK:10 )
|
-
-
22 楼
应该是裸奔机子
|
能力值:
(RANK:20 )
|
-
-
23 楼
源码呢??
|
能力值:
( LV2,RANK:10 )
|
-
-
24 楼
七年没上看雪了。安全越来越被重视了
|
能力值:
(RANK:20 )
|
-
-
25 楼
杭州的lx兄弟,最近在干嘛啊。。。
|
|
|