{"id":674,"date":"2022-09-21T17:19:05","date_gmt":"2022-09-21T09:19:05","guid":{"rendered":"http:\/\/www.aqwu.net\/wp\/?p=674"},"modified":"2022-09-21T17:19:05","modified_gmt":"2022-09-21T09:19:05","slug":"%e9%80%86%e5%90%91%e5%b7%a5%e7%a8%8b%e6%81%b6%e6%84%8f%e8%bd%af%e4%bb%b6%ef%bc%8cghidra-%e7%ac%ac-3-%e9%83%a8%e5%88%86%ef%bc%9a%e5%88%86%e6%9e%90-wannacry-%e5%8b%92%e7%b4%a2%e8%bd%af%e4%bb%b6","status":"publish","type":"post","link":"https:\/\/www.aqwu.net\/wp\/?p=674","title":{"rendered":"\u9006\u5411\u5de5\u7a0b\u6076\u610f\u8f6f\u4ef6\uff0cGhidra \u7b2c 3 \u90e8\u5206\uff1a\u5206\u6790 WannaCry \u52d2\u7d22\u8f6f\u4ef6"},"content":{"rendered":"\n<p>\u66f4\u65b0\u65e5\u671f\uff1a2021 \u5e74 11 \u6708 30 \u65e5<\/p>\n\n\n\n<p id=\"viewer-foo\">\u6b22\u8fce\u56de\u6765\uff0c\u6211\u6709\u62b1\u8d1f\u7684\u7f51\u7edc\u6218\u58eb\uff01<\/p>\n\n\n\n<p>\u539f\u6587\u94fe\u63a5\uff1ahttps:\/\/www.hackers-arise.com\/post\/reverse-engineering-malware-ghidra-part-3-analyzing-the-wannacry-ransomware<\/p>\n\n\n\n<p id=\"viewer-e20ja\">\u9006\u5411\u5de5\u7a0b\u662f\u6700\u53d7\u6b22\u8fce\u548c\u6700\u6709\u4ef7\u503c\u7684\u7f51\u7edc\u5b89\u5168\/\u4fe1\u606f\u5b89\u5168\u6280\u80fd\u4e4b\u4e00\u3002\u5f88\u5c11\u6709\u4eba\u53d1\u5c55\u81ea\u5df1\u7684\u6280\u80fd\u6c34\u5e73\u4ee5\u7cbe\u901a\u8fd9\u79cd\u5907\u53d7\u8ffd\u6367\u7684\u6280\u80fd\u3002Ghidra \u662f\u7f8e\u56fd\u95f4\u8c0d\u673a\u6784 NSA \u63d0\u4f9b\u7684\u4e00\u79cd\u76f8\u5bf9\u8f83\u65b0\u4e14\u514d\u8d39\u7684\u9006\u5411\u5de5\u7a0b\u5de5\u5177\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_3f788787e095445daaa79ea24a655eee~mv2.png\/v1\/fill\/w_360,h_484,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/6a4a49_3f788787e095445daaa79ea24a655eee~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-dnpbo\">\u5728\u672c\u6559\u7a0b\u4e2d\uff0c\u6211\u4eec\u5c06\u7814\u7a76\u6700\u81ed\u540d\u662d\u8457\u7684\u4f5c\u54c1\u4e4b\u4e00<\/p>\n\n\n\n<p id=\"viewer-593lu\">\u5386\u53f2\u4e0a\u7684\u6076\u610f\u8f6f\u4ef6<\/p>\n\n\n\n<p id=\"viewer-dn312\">\u52d2\u7d22\u8f6f\u4ef6\uff0cWannaCry\u3002\u5b83\u611f\u67d3\u4e86\u8d85\u8fc7 300,000 \u53f0\u8ba1\u7b97\u673a<\/p>\n\n\n\n<p id=\"viewer-fu2qg\">\u5982\u679c\u4e0d\u662f\u4e00\u4e2a\u4eba Marcus Hutchens aka MalwareTech \u7684\u5de5\u4f5c\u548c\u6280\u80fd\uff0c\u53ef\u80fd\u4f1a\u9020\u6210\u4e25\u91cd\u7834\u574f\u3002Marcus Hutchens \u83b7\u5f97\u4e86\u8be5\u6076\u610f\u8f6f\u4ef6\u7684\u526f\u672c\uff0c\u5e76\u7acb\u5373\u5f00\u59cb\u68c0\u67e5\u5176\u4ee3\u7801\u3002\u5728\u5176\u4e2d\uff0c\u4ed6\u53d1\u73b0\u4e86\u901a\u5e38\u88ab\u79f0\u4e3a\u201ckillswitch\u201d\u7684\u4e1c\u897f\u3002\u5b9e\u9645\u4e0a\uff0c\u4ed6\u53d1\u73b0\u7684\u662f\u7528\u4e8e\u8be5\u52d2\u7d22\u8f6f\u4ef6\u7684\u547d\u4ee4\u548c\u63a7\u5236 (C&amp;C) \u7684 URL\u3002\u5f53\u4ed6\u610f\u8bc6\u5230\u8fd9\u4e2a URL \u8fd8\u6ca1\u6709\u88ab\u6ce8\u518c\u65f6\uff0c\u4ed6\u5c31\u6ce8\u518c\u4e86\u3002\u901a\u8fc7\u8fd9\u6837\u505a\uff0c\u4ed6\u62d2\u7edd\u4e86\u52d2\u7d22\u8f6f\u4ef6\u4f5c\u8005\u5bf9\u5176\u6076\u610f\u8f6f\u4ef6\u7684\u63a7\u5236\u6743\uff0c\u4ece\u800c\u62ef\u6551\u4e86\u4e92\u8054\u7f51\uff01<\/p>\n\n\n\n<p id=\"viewer-4aiij\">\u5728\u8fd9\u91cc\uff0c\u6211\u4eec\u5c06\u7814\u7a76\u5bfb\u627e URL \u7684\u6076\u610f\u8f6f\u4ef6\u7684\u521d\u59cb\u611f\u67d3\u5411\u91cf\uff0c\u5e76\u5c1d\u8bd5\u4e86\u89e3\u5b83\u662f\u5982\u4f55\u542f\u52a8\u5176\u6076\u610f\u6d3b\u52a8\u7684\u3002<\/p>\n\n\n\n<p id=\"viewer-8fu4c\">\u5728\u5f00\u59cb\u672c\u6559\u7a0b\u4e4b\u524d\uff0c\u6211\u5efa\u8bae\u60a8\u9605\u8bfb\uff1b<\/p>\n\n\n\n<p id=\"viewer-fjk1f\"><u><a href=\"http:\/\/www.aqwu.net\/wp\/?p=669\" target=\"_blank\" rel=\"noreferrer noopener\">\u9006\u5411\u5de5\u7a0b\u6076\u610f\u8f6f\u4ef6\uff1aGhidra\uff0c\u7b2c 1 \u90e8\u5206<\/a><\/u><\/p>\n\n\n\n<p id=\"viewer-9d89a\"><u><a href=\"http:\/\/www.aqwu.net\/wp\/?p=671\" target=\"_blank\" rel=\"noreferrer noopener\">\u9006\u5411\u5de5\u7a0b\u6076\u610f\u8f6f\u4ef6\uff1aGhidra\uff0c\u7b2c 2 \u90e8\u5206<\/a><\/u><\/p>\n\n\n\n<p id=\"viewer-93lh8\">\u6b64\u5916\uff0c\u60a8\u4f1a\u5f88\u9ad8\u5174\u9605\u8bfb\uff1b<\/p>\n\n\n\n<p id=\"viewer-1duqm\"><a href=\"http:\/\/www.aqwu.net\/wp\/?p=333\" target=\"_blank\" rel=\"noreferrer noopener\"><u>\u9006\u5411\u5de5\u7a0b\uff0c\u7b2c 4 \u90e8\u5206\uff1aWindows \u5185\u90e8\u7ed3\u6784<\/u><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"viewer-ed7lj\"><strong>\u7b2c 1 \u6b65\uff1a\u51c6\u5907\u73af\u5883\u5e76\u5b89\u88c5 Ghidra<\/strong><\/h2>\n\n\n\n<p id=\"viewer-a1kdf\">\u5bf9\u4e8e\u672c\u6559\u7a0b\uff0c\u6211\u5efa\u8bae\u60a8\u4f7f\u7528\u5e26\u6709 Kali \u6216\u5176\u4ed6\u64cd\u4f5c\u7cfb\u7edf\u7684 VM\u3002\u8fd9\u662f\u4e3a\u4e86\u786e\u4fdd\u60a8\u4e0d\u4f1a\u610f\u5916\u5730\u5c06 WannaCcy \u91ca\u653e\u5230\u60a8\u7684\u5176\u4ed6\u7cfb\u7edf\u6216\u7f51\u7edc\u4e2d\uff08\u8fd9\u901a\u5e38\u662f\u4f7f\u7528\u6076\u610f\u8f6f\u4ef6\u65f6\u7684\u597d\u4e60\u60ef\uff09\u3002\u63a5\u4e0b\u6765\uff0c\u4e0b\u8f7d WannaCry\u3002\u60a8\u53ef\u4ee5\u4ece\u8bb8\u591a\u5730\u65b9\u83b7\u53d6\u5b83\uff0c\u4f8b\u5982 VirusTotal\u3002<\/p>\n\n\n\n<p id=\"viewer-eshj5\">\u786e\u4fdd\u60a8\u5728 Ghidra \u76ee\u5f55\u4e2d\u5e76\u542f\u52a8 Ghidra\u3002<\/p>\n\n\n\n<p id=\"viewer-5r6d1\"><strong>kali > sudo .\/ghidraRunn<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_6775e94e458f4bd29d58329d1cb19e13~mv2.png\/v1\/fill\/w_740,h_144,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/6a4a49_6775e94e458f4bd29d58329d1cb19e13~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-ca67\">\u5f53 Ghidra \u542f\u52a8\u65f6\uff0c\u901a\u8fc7\u5355\u51fb<strong>File &gt; New Project<\/strong>\u6253\u5f00\u4e00\u4e2a\u9879\u76ee\u3002<\/p>\n\n\n\n<p id=\"viewer-30n74\">\u7136\u540e\u5c06 WannaCry \u52d2\u7d22\u8f6f\u4ef6\u6587\u4ef6\u62d6\u653e\u5230 Dragon \u6216\u8f6c\u5230<strong>File -> Import File\u3002<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_b1078a7ed5ad4d04af99ad83cc473a4a~mv2.png\/v1\/fill\/w_740,h_403,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/6a4a49_b1078a7ed5ad4d04af99ad83cc473a4a~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-cisrj\">\u5bfc\u5165\u6587\u4ef6\u540e\uff0c\u60a8\u5c06\u770b\u5230\u5982\u4e0b\u6240\u793a\u7684\u5c4f\u5e55\uff0c\u5176\u4e2d\u5305\u542b\u6587\u4ef6\u7684\u6240\u6709\u8be6\u7ec6\u4fe1\u606f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_b81bccf787ae4ed7a1535f34b3d44514~mv2.png\/v1\/fill\/w_740,h_550,al_c,q_90,usm_0.66_1.00_0.01,enc_auto\/6a4a49_b81bccf787ae4ed7a1535f34b3d44514~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_8f640abb5cdb43a699b3c561ea8ac663~mv2.png\/v1\/fill\/w_740,h_205,al_c,lg_1,q_85,enc_auto\/6a4a49_8f640abb5cdb43a699b3c561ea8ac663~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-79u8q\">\u63a5\u4e0b\u6765\uff0c\u60a8\u5c06\u770b\u5230\u4e00\u4e2a\u8be6\u7ec6\u8bf4\u660e\u5206\u6790\u9009\u9879\u7684\u5c4f\u5e55\u3002\u4fdd\u7559\u6240\u6709\u9ed8\u8ba4\u503c\u5e76\u6dfb\u52a0<strong>\u53cd\u7f16\u8bd1\u5668\u53c2\u6570 ID<\/strong>\uff08\u8fd9\u5c06\u4e3a\u51fd\u6570\u521b\u5efa\u53c2\u6570\u548c\u5c40\u90e8\u53d8\u91cf\u3002\u5b83\u53ef\u4ee5\u4e3a\u5927\u6587\u4ef6\u7684\u5206\u6790\u589e\u52a0\u76f8\u5f53\u591a\u7684\u65f6\u95f4\uff0c\u4f46\u5bf9\u4e8e WannaCry \u6765\u8bf4\u8fd9\u4e0d\u4f1a\u5bfc\u81f4\u4efb\u4f55\u95ee\u9898\uff09\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_40249533f6314d2886034d82d277f1fb~mv2.png\/v1\/fill\/w_740,h_376,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/6a4a49_40249533f6314d2886034d82d277f1fb~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-9omj2\">\u5728 Ghidra \u5206\u6790 WannaCry \u65f6\uff0c\u60a8\u53ef\u80fd\u4f1a\u6536\u5230\u4ee5\u4e0b\u9519\u8bef\u6d88\u606f\u3002\u4e0d\u7528\u62c5\u5fc3\uff0c\u53ea\u9700\u5355\u51fb<strong>OK<\/strong>\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_9715181a1ce347058a107d4d48cdf584~mv2.png\/v1\/fill\/w_740,h_342,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/6a4a49_9715181a1ce347058a107d4d48cdf584~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-3ir8g\">\u73b0\u5728\uff0c\u60a8\u5e94\u8be5\u62e5\u6709 Ghidra \u7684\u4ee5\u4e0b\u7528\u6237\u754c\u9762\uff0c\u5176\u4e2d\u5305\u542b\u6765\u81ea WannaCry \u7684\u6570\u636e\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_406bf6a45a004860b0d496ec23b270b9~mv2.png\/v1\/fill\/w_740,h_434,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/6a4a49_406bf6a45a004860b0d496ec23b270b9~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"viewer-djhpo\"><strong>\u6b65\u9aa4 #2\uff1a\u627e\u5230 Main() \u51fd\u6570<\/strong><\/h2>\n\n\n\n<p id=\"viewer-b8gvc\">\u4e0b\u4e00\u6b65\u662f\u5bfb\u627e\u542f\u52a8 WannaCry \u8fd9\u4e2a\u6076\u610f\u8f6f\u4ef6\u7684\u51fd\u6570\u3002\u6b63\u5982\u6211\u4eec\u5728\u5c06\u6076\u610f\u8f6f\u4ef6\u52a0\u8f7d\u5230 Ghidra \u65f6\u6240\u6307\u51fa\u7684\uff0cWannaCry \u662f\u4e00\u4e2a\u4fbf\u643a\u5f0f\u53ef\u6267\u884c\u6587\u4ef6 (PE)\u3002\u6bcf\u4e2a Windows \u7a0b\u5e8f\u90fd\u6709\u4e00\u4e2a\u5165\u53e3\u70b9\uff0c\u901a\u5e38\u547d\u540d\u4e3a WinMain \u6216 wWinMain\u3002\u8bf7\u53c2\u9605\u4e0b\u9762\u7684 Microsoft \u6587\u6863\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_1eb20fb158524f5fa67c8225b139037a~mv2.png\/v1\/fill\/w_740,h_414,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/6a4a49_1eb20fb158524f5fa67c8225b139037a~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-eq668\">\u5f53\u6211\u4eec\u8f6c\u5230\u7b26\u53f7\u6811\u5e76\u5c55\u5f00\u51fd\u6570\u6587\u4ef6\u5939\u65f6\uff0c\u6211\u4eec\u770b\u4e0d\u5230 WinMain \u6216 wWinMain \u51fd\u6570\uff0c\u4f46\u6211\u4eec\u770b\u5230\u4e86\u4e00\u4e2a\u5165\u53e3\u51fd\u6570\u3002\u8fd9\u53ef\u80fd\u4e0e WinMain() \u5177\u6709\u76f8\u540c\u7684\u76ee\u7684\u3002\u8ba9\u6211\u4eec\u68c0\u67e5\u4e00\u4e0b\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_4662a13b30474f4fba81a9db3477548a~mv2.png\/v1\/fill\/w_358,h_717,al_c,lg_1,q_85,enc_auto\/6a4a49_4662a13b30474f4fba81a9db3477548a~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-66fpt\">\u53cc\u51fb\u5b83\uff0c\u5b83\u5c06\u540c\u65f6\u51fa\u73b0\u5728\u5217\u8868\u7a97\u53e3\u548c<strong>\u53cd\u7f16\u8bd1<\/strong>\u7a97\u53e3\u4e2d\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_b29656866354412286c41139cf4aa9f2~mv2.png\/v1\/fill\/w_740,h_367,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/6a4a49_b29656866354412286c41139cf4aa9f2~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"viewer-6b7g2\"><\/h2>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"viewer-amkn8\"><strong>\u6b65\u9aa4#3\uff1a\u627e\u5230\u201ckillswitch\u201d<\/strong><\/h2>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"viewer-5g8ud\"><\/h2>\n\n\n\n<p id=\"viewer-c0pn4\">\u73b0\u5728\uff0c\u5411\u4e0b\u626b\u63cf Decompile \u7a97\u53e3\uff0c\u6211\u4eec\u53ef\u4ee5\u770b\u5230\u8be5\u51fd\u6570\u8c03\u7528\u4e86\u53e6\u4e00\u4e2a\u51fd\u6570 FUN_00408140\u3002\u53cc\u51fb\u5b83\u6765\u5206\u6790\u5b83\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_11f53e5aac1045cabe80672ddf022681~mv2.png\/v1\/fill\/w_740,h_258,al_c,lg_1,q_85,enc_auto\/6a4a49_11f53e5aac1045cabe80672ddf022681~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-bp7uo\">\u51e0\u4e4e\u7acb\u5373\uff0c\u60a8\u5e94\u8be5\u4f1a\u5728\u5217\u8868\u7a97\u53e3\u548c\u53cd\u7f16\u8bd1\u7a97\u53e3\u4e2d\u770b\u5230\u4f3c\u4e4e\u662f URL \u7684\u5185\u5bb9\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_18c401ce55fe48f5b9888ba92babc34c~mv2.png\/v1\/fill\/w_740,h_375,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/6a4a49_18c401ce55fe48f5b9888ba92babc34c~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-a050a\">\u5b83\u4f3c\u4e4e\u5c06 URL \u653e\u5165\u540d\u4e3a<strong>puVar3<\/strong>\u7684\u53d8\u91cf\u4e2d\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_09cfec383328461e91eb13f409c23f97~mv2.png\/v1\/fill\/w_740,h_219,al_c,q_85,usm_0.66_1.00_0.01,enc_auto\/6a4a49_09cfec383328461e91eb13f409c23f97~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-3bpnk\">\u8fdb\u4e00\u6b65\u5411\u4e0b\u626b\u63cf\u53cd\u7f16\u8bd1\u5668\uff0c\u6211\u4eec\u53ef\u4ee5\u770b\u5230\u5bf9<strong>InternetOpenUrlA<\/strong>\u51fd\u6570\u7684\u5f15\u7528\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_dff8703b89a74bcea1e0dc61617a1008~mv2.png\/v1\/fill\/w_740,h_64,al_c,lg_1,q_85,enc_auto\/6a4a49_dff8703b89a74bcea1e0dc61617a1008~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-dg5uj\">\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7 Microsoft Technet \u641c\u7d22\uff0c\u53d1\u73b0<strong>InternetOpenUrlA<\/strong>\u51fd\u6570\u6b63\u5982\u60a8\u6240\u671f\u671b\u7684\u90a3\u6837\uff0c\u5b83\u8c03\u7528\u5e76\u6253\u5f00\u6307\u5b9a\u7684 URL\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_c947b7ed9d8349edbfdfe357680671c0~mv2.png\/v1\/fill\/w_740,h_533,al_c,q_90,usm_0.66_1.00_0.01,enc_auto\/6a4a49_c947b7ed9d8349edbfdfe357680671c0~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-8q7e1\"><strong>\u5728InternetOpenUrlA<\/strong>\u4e0b\u65b9\uff0c\u6211\u4eec\u770b\u5230\u51e0\u884c\u4f7f\u7528<strong>InternetCloseHandle<\/strong>\u3002\u8fd9\u4e9b\u6307\u5b9a\u5982\u679c iVar2 \u4e3a 0 \uff0c\u5219\u5173\u95ed\u53e5\u67c4\u5e76\u8fd0\u884c<strong>FUN_00408090<\/strong>\uff0c\u5426\u5219\u5173\u95ed\u53e5\u67c4\u5e76\u7ec8\u6b62\u7a0b\u5e8f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_81a31e44775a4fecbc80478b10dcf769~mv2.png\/v1\/fill\/w_594,h_316,al_c,lg_1,q_85,enc_auto\/6a4a49_81a31e44775a4fecbc80478b10dcf769~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-7378o\">\u8fd9\u662f Marcus Hutchins \u5728\u7b2c\u4e00\u6b21\u68c0\u67e5\u548c\u5206\u6790 WannaCry \u65f6\u6ce8\u610f\u5230\u7684\u3002\u8fd9\u662f\u547d\u4ee4\u548c\u63a7\u5236 (C&amp;C) URL \u7684 URL\u3002\u5982\u679c\u7a0b\u5e8f\u5c1d\u8bd5\u8bbf\u95ee URL \u5e76\u8fd4\u56de 0\uff0c\u5219\u7a0b\u5e8f\u81ea\u52a8\u7ec8\u6b62\u3002\u5982\u679c\u5b83\u6ca1\u6709\u7ec8\u6b62\uff0c\u5219\u6267\u884c<strong>FUN_00408140\u3002<\/strong>\u8ba9\u6211\u4eec\u5173\u6ce8<strong>FUN_00408140\u3002<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"viewer-adk67\"><strong>\u7b2c 4 \u6b65\uff1a\u987a\u5176\u81ea\u7136<\/strong><\/h2>\n\n\n\n<p id=\"viewer-b52db\">\u5728\u4e0b\u4e00\u6b65\u4e2d\uff0c\u8ba9\u6211\u4eec\u6309\u7167<strong>FUN_00408140 \u7684\u6d41\u7a0b\u8fdb\u884c\u64cd\u4f5c\u3002<\/strong>\u8f6c\u5230 Ghidra \u9876\u90e8\u7684 Window \u9009\u9879\u5361\uff0c\u7136\u540e\u5355\u51fb<strong>Function Graph<\/strong>\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_8416b736e0714018acbe4f91539bf12a~mv2.png\/v1\/fill\/w_740,h_414,al_c,lg_1,q_85,enc_auto\/6a4a49_8416b736e0714018acbe4f91539bf12a~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-4t2rf\">\u6b63\u5982\u60a8\u5728\u4e0a\u9762\u770b\u5230\u7684\uff0cGhidra \u4e3a\u6211\u4eec\u63d0\u4f9b\u4e86\u4e00\u4e2a\u6613\u4e8e\u9605\u8bfb\u7684\u6765\u81ea\u8be5\u51fd\u6570\u7684\u6d41\u56fe\uff0c\u5305\u62ec\u4e0a\u6e38\u548c\u4e0b\u6e38\u3002\u53ef\u4ee5\u770b\u5230<strong>\u5165\u53e3<\/strong>\u51fd\u6570\u662f FUN 00408140 \u7684\u4e0a\u6e38\uff0c\u4e0b\u6e38\u662f<strong>InternetOpenA<\/strong>\u3001<strong>InternetOpenUrlA<\/strong>\u3001<strong>InternetCloseHandle<\/strong>\u548c<strong>FUN_00408090<\/strong><\/p>\n\n\n\n<p id=\"viewer-74tcr\">\u56de\u5230\u53cd\u7f16\u8bd1\u7a97\u53e3\uff0c\u8ba9\u6211\u4eec\u53cc\u51fb<strong>FUN_00408090<\/strong>\u6765\u5c1d\u8bd5\u786e\u5b9a\u5b83\u7684\u4f5c\u7528\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_b613a3c0414d4d8b8daaf8cb86d23075~mv2.png\/v1\/fill\/w_594,h_316,al_c,lg_1,q_85,enc_auto\/6a4a49_b613a3c0414d4d8b8daaf8cb86d23075~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-amcg3\">\u53cd\u7f16\u8bd1\u7a97\u53e3\u5e94\u5982\u4e0b\u6240\u793a\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_8e90343d1b1b4c71b78032fcdfbce9d3~mv2.png\/v1\/fill\/w_740,h_693,al_c,q_90,usm_0.66_1.00_0.01,enc_auto\/6a4a49_8e90343d1b1b4c71b78032fcdfbce9d3~mv2.png\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-4q08o\">\u8bf7\u6ce8\u610f\uff0c\u53cd\u7f16\u8bd1\u5668\u663e\u793a\u6076\u610f\u8f6f\u4ef6\u4f1a\u5c1d\u8bd5<strong>OpenServiceA<\/strong>\u3002\u8fd9\u5305\u62ec\u6253\u5f00<strong>mssecv2.0_004312fc<\/strong>\u7684\u53c2\u6570\u3002\u8fd9\u4f3c\u4e4e\u6253\u5f00\u4e86 Microsoft \u5b89\u5168\u670d\u52a1\u3002\u73b0\u5728\u8fd9\u5f88\u6709\u8da3&#8230;<\/p>\n\n\n\n<p id=\"viewer-8p3mj\">\u5f53\u6211\u4eec\u641c\u7d22\u5fae\u8f6f\u7684 Technet \u65f6\uff0c\u6211\u4eec\u53d1\u73b0\u6ca1\u6709\u8fd9\u6837\u7684\u670d\u52a1\u5b58\u5728\u3002\u8be5\u6076\u610f\u8f6f\u4ef6\u6b63\u5728\u542f\u52a8\u4e00\u9879\u4f3c\u4e4e\u662f\u5408\u6cd5\u7684 Microsoft \u5b89\u5168\u670d\u52a1\u7684\u65b0\u670d\u52a1\uff0c\u4ee5\u63a9\u76d6\u5176\u771f\u5b9e\u6027\u8d28\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"viewer-ad5sc\"><strong>\u6982\u62ec<\/strong><\/h2>\n\n\n\n<p id=\"viewer-djvj\">Wannacry \u52d2\u7d22\u8f6f\u4ef6\u6709\u53ef\u80fd\u5728 2017 \u5e74\u5bf9\u4e92\u8054\u7f51\u9020\u6210\u6bc1\u706d\u6027\u6253\u51fb\u3002\u5b83\u5229\u7528\u6700\u8fd1\u53d1\u5e03\u7684 EternalBlue \u6f0f\u6d1e\u8fdb\u5165\u8ba1\u7b97\u673a\u7cfb\u7edf\uff0c\u7136\u540e\u52a0\u5bc6\u6240\u6709\u6570\u636e\uff0c\u76f4\u5230\u4ed6\u4eec\u652f\u4ed8\u8d4e\u91d1\u3002\u663e\u7136\uff0c\u7531\u671d\u9c9c\u5728 Windows \u7cfb\u7edf\u4fee\u8865\u4e4b\u524d\u4ed3\u4fc3\u53d1\u5e03\u5b83\uff0c\u4ed6\u4eec\u672a\u80fd\u63a9\u76d6\u6216\u6df7\u6dc6\u6076\u610f\u8f6f\u4ef6\uff0c\u6700\u91cd\u8981\u7684\u662f\uff0c\u672a\u80fd\u6ce8\u518c\u547d\u4ee4\u548c\u63a7\u5236\u57df\u3002\u611f\u8c22 Marcus Hutchins\uff0c\u4ed6\u68c0\u6d4b\u5230\u201c\u6740\u622e\u5f00\u5173\u201d\u5e76\u89e3\u9664\u4e86\u8fd9\u79cd\u53ef\u80fd\u4f7f\u4eba\u8870\u5f31\u7684\u52d2\u7d22\u8f6f\u4ef6\uff0c\u4ece\u800c\u51cf\u8f7b\u4e86\u5b83\u7684\u5f71\u54cd\u3002<\/p>\n\n\n\n<p id=\"viewer-chvgt\">\u65e2\u7136\u60a8\u6709\u80fd\u529b\u505a\u540c\u6837\u7684\u4e8b\u60c5\uff0c\u4e5f\u8bb8\u60a8\u5c06\u6210\u4e3a\u4e0b\u4e00\u4e2a\u62ef\u6551\u4e92\u8054\u7f51\u7684\u4eba\uff1f<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u66f4\u65b0\u65e5\u671f\uff1a2021 \u5e74 11 \u6708 30 \u65e5 \u6b22\u8fce\u56de\u6765\uff0c\u6211\u6709\u62b1\u8d1f\u7684\u7f51\u7edc\u6218\u58eb\uff01 \u539f\u6587\u94fe\u63a5\uff1ahttps:\/\/www. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[86,90,43],"tags":[154,93,155],"class_list":["post-674","post","type-post","status-publish","format-standard","hentry","category-kali","category-reverse-engineering-malware","category-infoarticle","tag-ghidra","tag-reverse-engineering-malware","tag-wannacry"],"views":1159,"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/674","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=674"}],"version-history":[{"count":1,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/674\/revisions"}],"predecessor-version":[{"id":675,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/674\/revisions\/675"}],"wp:attachment":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=674"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=674"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=674"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}