ÒõÓ°ÖеľÞÊÞ£ºÎïÁªÍø½©Ê¬ÍøÂçAndoryu½üÆÚת±äÆÊÎö
Ðû²¼Ê±¼ä 2023-06-14Z6×ðÁú¿Ê±Óë¹ãÖÝ´óÑ§Íø°²Ñ§Ôº·¢Ã÷ÁËÎïÁªÍø½©Ê¬ÍøÂçAndoryuµÄÐÂÐͱäÖÖAndoryu_V2¡£¡£¡£±¾ÎĽ«´Ó½©Ê¬ÍøÂç¹æÄ£¡¢Èö²¥·½·¨¡¢Ñù±¾ÊÖÒÕÆÊÎöÈý·½Ã棬£¬£¬£¬£¬£¬¶Ô¸Ã½©Ê¬ÍøÂçÈö²¥¡¢Ñ¬È¾¡¢C&C¿ØÖÆ¡¢¹¥»÷È«ÉúÃüÖÜÆÚϸ½ÚµÈ¾ÙÐÐÏÈÈÝ£¬£¬£¬£¬£¬£¬¿É×÷Ϊ¸÷ÐÐÒµ¼°Ïà¹ØÆóÒµÖÆ¶©ÍøÂçÇå¾²Õ½ÂԵIJο¼¡£¡£¡£
2023Äê3ÔÂ⣬£¬£¬£¬£¬£¬Z6×ðÁú¿Ê±ÔÚ¼ÓÈë¹ú¼ÒÖØµãÑз¢ÍýÏëÏîÄ¿¡°´ó¹æÄ£Òì¹¹ÎïÁªÍøÍþв¿É¿Ø²¶»ñÓëÆÊÎöÊÖÒÕ£¨2022YFB3104100£©¡±µÄÑо¿Àú³ÌÖУ¬£¬£¬£¬£¬£¬·¢Ã÷ÁË»ùÓÚSocks5ÐÒéµÄÎïÁªÍø½©Ê¬ÍøÂçAndoryuµÄÐÂÐͱäÖÖ£¨Andoryu_V2£©¡£¡£¡£
Andoryu_V1°æ±¾ÒÑÓÚ½ñÄê2Ô·ݱ»Ê×´Î½ÒÆÆ£¬£¬£¬£¬£¬£¬±¾´ÎÎÒÃǽ«±ÈÕÕÆÊÎöAndoryu_V2°æ±¾ºÍAndoryu_V1°æ±¾£¬£¬£¬£¬£¬£¬Ïêϸ·ºÆð³ö¸Ã½©Ê¬ÍøÂçÈö²¥¡¢Ñ¬È¾¡¢C&C¿ØÖÆ¡¢¹¥»÷È«ÉúÃüÖÜÆÚϸ½Ú¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Í¨¹ý2¸ö¶àÔµļà²âÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷Andoryu_V2°æ±¾ÓÐÐÂÔöʹÓÃCVE-2022-30525¡¢CVE-2023-25717Îó²îµÄÐÐΪ£¬£¬£¬£¬£¬£¬ÐÂÔöÊðÀíЧÀÍÆ÷Áè¼Ý130¸ö£¬£¬£¬£¬£¬£¬·´Ó¦³ö¸Ã½©Ê¬ÍøÂç½øÒ»²½À©ÕŵÄÒâͼ£¬£¬£¬£¬£¬£¬ÐèÒªÔöÇ¿Çå¾²Ìá·À¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬ÎÒÃÇ»¹·¢Ã÷¸Ã½©Ê¬ÍøÂçÓëFbot¿ÉÄܾßÓÐÒ»¶¨µÄ¹ØÁªÐÔ¡£¡£¡£
½©Ê¬ÍøÂç¹æÄ£
¼à²âÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬£¬Andoryu½©Ê¬ÍøÂçÆ½¾ùÈÕÔöÉÏÏß¾³ÄÚÈ⼦Êý£¨IPÊýÅÌË㣩Áè¼Ý1500̨£¬£¬£¬£¬£¬£¬Õý´¦ÓÚÉú³¤³õÆÚ¡£¡£¡£2023Äê4ÔÂβµ½5Ô³õ£¬£¬£¬£¬£¬£¬AndoryuÓÐÒ»´Î½ÏÁ¿´ó¹æÄ£µÄÈö²¥£¬£¬£¬£¬£¬£¬ÈÕ´æ»îÁ¿Áè¼Ý2000¡£¡£¡£

Èö²¥·½·¨
×èÖ¹µ½ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÎÒÃÇÊӲ쵽AndoryuÖ÷ҪʹÓÃNDayÎó²îÈö²¥¡£¡£¡£ËùÓÃÎó²îÁбíÈçÏ£º

2023Äê2ÔÂ-3Ô£¬£¬£¬£¬£¬£¬Andoryu¶àʹÓÃCVE-2021-22205¡¢LILIN DVR RCEÎó²îÈö²¥¡£¡£¡£
2023Äê4Ô£¬£¬£¬£¬£¬£¬Ð¼ÓÈëCVE-2023-25717µÄʹÓ㬣¬£¬£¬£¬£¬Ò»¸öRuckus Wireless×°±¸µÄÎó²î¡£¡£¡£Ê¹ÓÃÀֳɺóÏÂÔØÖ´Ðо籾Îļþruckus.sh£¬£¬£¬£¬£¬£¬ÒÔÖ²ÈëAndoryu¡£¡£¡£
2023Äê5ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬ÎÒÃÇ¼à¿Øµ½¶ÔZyxel·À»ðǽԶ³ÌÏÂÁî×¢ÈëÎó²îCVE-2022-30525µÄʹÓᣡ£¡£

ÔÚ¿ÉÔ¤¼ûµÄδÀ´£¬£¬£¬£¬£¬£¬AndoryuºÜ¿ÉÄÜ»¹»á¼ÓÈëÐÂÎó²îµÄʹÓ㬣¬£¬£¬£¬£¬¸»ºñÆäÎäÆ÷¿â¡£¡£¡£
Ñù±¾ÊÖÒÕÆÊÎö
Andoryu½©Ê¬ÍøÂçÖ§³Ö¶àÖÖCPU¼Ü¹¹£¬£¬£¬£¬£¬£¬°üÀ¨arm¡¢m68k¡¢mips¡¢mpsl¡¢sh4¡¢spcºÍx86µÈ¡£¡£¡£ÒÔÏÂÊÇÖ÷Ҫת±ä±ÈÕÕ£º

ÔÚ±¾ÎÄÖУ¬£¬£¬£¬£¬£¬ÎÒÃÇÖ÷ÒªÒÔ5ÔÂ8ÈÕµÄV2Ñù±¾ÎªÖ÷¾ÙÐÐÆÊÎö£¬£¬£¬£¬£¬£¬²¢´©²åÏÈÈÝV1µ½V2Ñù±¾µÄÖ÷Òªµü´úת±ä¡£¡£¡£ÕâЩת±äµÄϸ½Ú¿ÉÄܰüÀ¨´úÂëÂß¼µÄ΢µ÷¡¢¼ÓÃÜËã·¨µÄµ÷½âµÈ¡£¡£¡£ÕûÌå¶øÑÔ£¬£¬£¬£¬£¬£¬Andoryu½©Ê¬ÍøÂç¼á³ÖÁËÏà¶ÔÎȹ̵Ļù´¡¼Ü¹¹ºÍC2ͨѶģʽ¡£¡£¡£
1¡¢³õʼ»¯
Ϊ¶Ô¿¹É³ºÐµÈÄ£ÄâÇéÐεÄ×Ô¶¯»¯ÆÊÎö£¬£¬£¬£¬£¬£¬ÓëÆäËüÊ¢Ðн©Ê¬ÍøÂçÏàͬ£¬£¬£¬£¬£¬£¬AndoryuÔËÐÐʱÊ×ÏÈ»á¶ÔÆô¶¯²ÎÊý¾ÙÐмì²é£¬£¬£¬£¬£¬£¬ÒÔÈ·±£×ÔÉíµÄÇå¾²ÐÔ¡£¡£¡£ÈôÊDz»Ð¯´ø²ÎÊý£¬£¬£¬£¬£¬£¬ÔòÖ±½ÓÍ˳ö¡£¡£¡£²î±ðÓÚÆäËü¼Ò×åµÄÊÇ£¬£¬£¬£¬£¬£¬AndoryuÔËÐкó»á½«Æô¶¯²ÎÊý·¢ËÍÖÁC2ЧÀÍÆ÷¾ÙÐÐÌØÁíÍâ¶þ´ÎУÑé¡£¡£¡£
µ±²ÎÊý׼ȷʱ£¬£¬£¬£¬£¬£¬Ôò½øÈëÖ´ÐÐÁ÷³Ì£ºÀú³ÌÃûαװ¡¢½âÃÜ×ÊÔ´£¬£¬£¬£¬£¬£¬ËæºóºÍC2½¨ÉèͨѶ²¢ÆÚ´ýÖ´ÐÐC2Ï·¢µÄÖ¸Áî¡£¡£¡£
ÔÚV2°æ±¾ÖлὫÀú³ÌÃûαװ³É"DvrHelper"»òÕß"-bash" £¬£¬£¬£¬£¬£¬V1ÔòΪ"/bin/bash"¡£¡£¡£½âÃÜÃô¸Ð×ÊÔ´V2°æ±¾Ê¹ÓõÄÊÇÒì»ò£¬£¬£¬£¬£¬£¬¶øÔÚV1°æ±¾ÖÐʹÓõÄÊÇijÖÖħ¸Ä°æµÄxxteaËã·¨½âÃÜ£º

ÓÐȤµÄÊÇ£¬£¬£¬£¬£¬£¬×ÊÔ´½âÃÜÊÂÇéÍê³ÉÖ®ºó£¬£¬£¬£¬£¬£¬Andoryu½«ÔÚConsoleÉÏ´òÓ¡½âÃܳöµÄ×Ö·û´®"Project Andoryu (12/30/2022). What color is your botnet" »ò"Andoryu botnet started (12/30/2022)"£¬£¬£¬£¬£¬£¬ÕâÅú×¢AndoryuºÜ¿ÉÄÜÊÇ2022Äê12ÔÂ30ºÅÆô¶¯µÄÏîÄ¿¡£¡£¡£
2¡¢Í¨Ñ¶ÐÒé
¼à²â·¢Ã÷£¬£¬£¬£¬£¬£¬¾ø´ó´ó¶¼AndoryuµÄÑù±¾¾ù²»Ö±½ÓÓëC2¾ÙÐÐͨѶ£¬£¬£¬£¬£¬£¬¶øÊÇͨ¹ýSocks5ÊðÀíЧÀÍÆ÷¾ÙÐÐת·¢£¬£¬£¬£¬£¬£¬·ºÆðÁ½²ã¿ØÖƽṹ¡£¡£¡£5ÔÂ8ºÅµÄV2Ñù±¾Ôø¶ÌÔÝÈ¥³ýSocks5ÊðÀí£¬£¬£¬£¬£¬£¬µ«ØÊºóºÜ¿ìÓÖ»Ö¸´¡£¡£¡£ÔÚV1°æ±¾Ö»ÓÐÒ»¸öÊðÀíЧÀÍÆ÷£¬£¬£¬£¬£¬£¬V2°æ±¾±ãÔöÌíÖÁ130¶à¸ö¡£¡£¡£

ÔÚC2ͨѶ½»»¥ÉÏ£¬£¬£¬£¬£¬£¬AndoryuÓëFodchaºÜÊÇÀàËÆ£¬£¬£¬£¬£¬£¬Í¨¹ý״̬ÂëÇл»ÒÔÖ´Ðвî±ð²Ù×÷£º

Ö÷Ҫ״̬ÈçÏ£º

AndoryuÔÚÓëC2ЧÀÍÆ÷¾ÙÐÐͨѶʱ£¬£¬£¬£¬£¬£¬Ê¹Óö¨³¤Îª2152×Ö½ÚµÄÊý¾Ý½á¹¹·â×°¡£¡£¡£V1ºÍV2¶¼ÊÇÔÆÔÆ£¬£¬£¬£¬£¬£¬ÕûÌå·â×°½á¹¹ÈçÏ£º

ÒÔÉÏÏßÊý¾ÝΪÀý£º

Ê׸ö4×Ö½ÚΪ¹«ÍøIP£»£»£»£´×Ö½ÚËæ»úÊý¾Ý24 52 ae 57£»£»£»2×Ö½Ú20 21ΪÊý¾ÝÀàÐÍ£¬£¬£¬£¬£¬£¬ÌåÏÖΪÉÏÏßÊý¾Ý£»£»£»4a d8 74 50 4d de Ϊxor¼ÓÃܺóµÄÊý¾ÝÄÚÈÝ£¬£¬£¬£¬£¬£¬½âÃܺóÏÖʵΪÆô¶¯²ÎÊý¡£¡£¡£

32×Ö½Úsha256УÑéºÍ5d 7f 05 6e...67 7b 05 68£»£»£»Æ«ÒÆ0x84C´¦ 06 00 00 00 ÌåÏÖpayload³¤¶È£»£»£»Æ«ÒÆ0x854´¦86 0f ΪÄÚ´æ¾Þϸ£¡£¡£¬£¬£¬£¬£¬£¬0x0f86¼´Îª3974M£»£»£»×îºópayloadµÄÒì»òKeyËæ»úÌìÉú£¬£¬£¬£¬£¬£¬²¢ÉúÑÄÔÚÉÏÏßÊý¾ÝµÄÆ«ÒÆ0x861-0x864´¦£¬£¬£¬£¬£¬£¬±¾ÀýÊÇ38 ad 17 3b¡£¡£¡£
ËæºóC2·µ»Ø¼òÖ±ÈÏÊý¾Ý£¬£¬£¬£¬£¬£¬Ç°4×Ö½ÚÊÇC2 µØµã£¬£¬£¬£¬£¬£¬±¾ÀýÊÇ68 ea ef b0¡£¡£¡£Ëæºó4×Ö½ÚÊÇËæ»úÊý¾Ýc7 fc b8 00¡£¡£¡£ÔÙÖ®ºó2×Ö½ÚµÄ20 22´ú±íÊÇÈ·ÈÏÊý¾Ý£¬£¬£¬£¬£¬£¬ÖÁ´Ë£¬£¬£¬£¬£¬£¬AndoryuÉÏÏßÀֳɡ£¡£¡£

3¡¢¹¥»÷Ö¸Áî
AndoryuµÄ¹¥»÷ºÜ»îÔ¾£¬£¬£¬£¬£¬£¬ÎÒÃÇ¼à¿Øµ½Ðí¶à´ÎC2·µ»ØµÄDDoS¹¥»÷ÏÂÁ£¬£¬£¬£¬£¬ÈçÏÂÒ»Àý£º

ÏÂÁîÆÊÎöÈçÏ£º

payloadÒì»ò½âÃܺóΪ"udp-plain 135.xx.xx.xx 60 dport=53 psize=150"£¬£¬£¬£¬£¬£¬ËæºóAndoryuÏò135.xx.xx.xx:53Ìᳫudp-plain DDoS¹¥»÷£º

Andoryu¶ÔC2ÏÂÁîµÄ´¦Öóͷ£º¯ÊýûÓÐÈκÎת±ä£¬£¬£¬£¬£¬£¬ÒÔÏÂÊÇ2ÔºÍ5ÔÂÑù±¾µÄ±ÈÕÕ£º

ÏÖÔÚ£¬£¬£¬£¬£¬£¬Andoryu¹²Ö§³Ö6ÀàÖ¸Á£¬£¬£¬£¬£¬°üÀ¨DDoS¹¥»÷ÏÂÁ£¬£¬£¬£¬£¬ÈçÏ£º

AndoryuÖ§³Ö3ÖÖÐÒé(tcp¡¢udp¡¢icmp)¹²16¸öDDoS¹¥»÷ÀàÐÍ£¬£¬£¬£¬£¬£¬°üÀ¨tcp-raw¡¢tcp-socket¡¢tcp-cnc¡¢tcp-handshake¡¢tcp-ovh¡¢tcp-bypass¡¢udp-plain¡¢udp-game¡¢udp-ovh¡¢udp-raw¡¢udp-vse¡¢udp-dstat¡¢udp-bypass¡¢udp-hex¡¢udp-rhex¡¢icmp-echo¡£¡£¡£

4¡¢ÓëÆäËû¼Ò×åµÄ¹ØÁª
AndoryuºÍC2µÄͨѶ½»»¥ÔÚ´úÂë²ãÃæºÍFodChaºÜÊÇÀàËÆ£¬£¬£¬£¬£¬£¬¶¼ÊÇÒ»¸öÓÀÕæµÄWhileÑ»·£¬£¬£¬£¬£¬£¬Í¨¹ýswitch-case¾ÙÐи÷¸ö½×¶ÎµÄ´¦Öóͷ£¡£¡£¡£µ½ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬ÕâÖÖ·½·¨ÊÇÒÑÖª½©Ê¬ÍøÂçÀïΨ¶þµÄÀý×Ó¡£¡£¡£ÁíÍ⣬£¬£¬£¬£¬£¬Fodcha V3ҲʹÓÃxxtea¼ÓÃÜËã·¨£¬£¬£¬£¬£¬£¬¶øAndoryu V1ÊÇʹÓÃijÖÖħ¸Ä°æµÄxxtea¡£¡£¡£
ÕâËÆºõÅú×¢£¬£¬£¬£¬£¬£¬Á½ÕßÒ²ÐíÓÐijÖÖ¹ØÁª£¬£¬£¬£¬£¬£¬µ«³ýÁËÉÏÊöÁ½µã£¬£¬£¬£¬£¬£¬ÔÝʱûÓиü¶àʵ´¸Ö¤¾Ý¡£¡£¡£²»¹ý£¬£¬£¬£¬£¬£¬AndoryuºÍFbotÓÐÈ·ÇеĹØÁª£¬£¬£¬£¬£¬£¬ËûÃÇÒ»¾Ê¹ÓÃͳһ¸öC2¡£¡£¡£5ÔÂ13ºÅµÄV2Ñù±¾À£¬£¬£¬£¬£¬Í¨¹ýsocks5ÅþÁ¬C2ЧÀÍÆ÷dnsresolve.socialgains.cf:10333¡£¡£¡£

¶øÔÚ5ÔÂ4ºÅ£¬£¬£¬£¬£¬£¬ÎÒÃÇ¼à¿Øµ½ÓÐFbotÑù±¾Ê¹ÓÃdnsresolve.socialgains.cf:61002×÷Ϊ×Ô¼ºµÄC2ЧÀÍÆ÷¡£¡£¡£ÎÒÃÇ»á¼ÌÐø¸ú×ÙÊӲ죬£¬£¬£¬£¬£¬²éÕÒAndoryuºÍÆäËü¼Ò×åµÄ¹ØÁª¡£¡£¡£
5¡¢IoC



¾©¹«Íø°²±¸11010802024551ºÅ