÷Å×°Âñ·üÓë·ÂðÏÝÚå£ºÒøºü×éÖ¯½èOpenClaw×°ÖðüÖ´Ðй¥»÷»î¶¯Éî¶È·ÖÎö
°ä²¼¹¦·ò 2026-03-26¡°ÎªÖÇÄÜʱÆÚÁ¢ÐÅ£¬Îª´´Ð¼ÛÖµ»¤º½¡£¡ª¡ª ±¦ÔËÀ³¹Ù·½ÍøÕ¾¡±
Ëæ×Å¿ªÔ´AI´úÀí¿ò¼ÜOpenClaw£¨¡°ÁúϺ¡±£©µÄ±¬»ð£¬ºÚ²úÍÅ»ï¡°Òøºü¡±Ñ¸ËÙ½èÊÆÌáÒé´¹µö¹¥»÷»î¶¯¡£Í¨¹ýÌìÉú¸ß·Â´¹µöÒ³Ãæ£¬×¢²á·ÂðÓòÃû£¬ÀûÓÃËÑË÷ÒýÇæÓÅ»¯£¨SEO£©ºÍ¸¶·Ñ¸æ°×½«¶ñÒâÁ´½ÓÖö¥£¬ÓÕµ¼Óû§ÏÂÔØ¼Ù×°³É¡°OpenClaw±¾µØ²¿Ê𹤾ߡ±µÄ¶ñÒâ×°Öðü¡£Óû§Ö´ÐжñÒâ×°Öðüºó£¬ÔÚ¿ªÊͳöºÏ·¨×°ÖÃÈí¼þµÄͬʱ£¬°µÖÐÖ´ÐжñÒⷨʽ£¬×îÖÕ¿ªÊͲ¢Ö´ÐÐÔ¶¿ØÄ¾Âí£¬¶ÔÓû§ÍÆËã»ú½øÐнÚÔ죬ʵÏÖÐÅÏ¢ÇÔÈ¡¡¢ÄÚÍøÉøÈë¡¢ºáÏòÒÆ¶¯µÈ¶ñÒâ²Ù×÷¡£¹¥»÷Õßͨ¹ýÕë¶Ô×°ÖÃÁ´Â·µÄͶ¶¾£¬´ï³ÉÁ˶ÔÖ¸±êÖ÷»úÏÕЩ¡°ÁãÃż÷¡±µÄÔ¶³ÌÊÕÊÜ¡£
±¦ÔËÀ³¹Ù·½ÍøÕ¾Íþвµý±¨ÖÐÐÄ£¨VenusEye£©½üÆÚ×·×Ùµ½Òøºü×éÖ¯¶à¸ö·ÂðOpenClawµÄÕ¾µã£¬ÕâЩվµãÉϵĶñÒâ×°ÖðüѡȡÁËÒ»ÑùµÄ¹¥»÷ÊÖ·¨£¬Æ¾¾ÝÑù±¾ÌصãºÍioc¹ØÁª£¬ÕâЩ¹¥»÷»î¶¯¶¼¹éÓÉÓÚÒøºü×éÖ¯¡£ÏÂÎÄÒÔÒ»¸öµäÐ͵ÄÑù±¾ÎªÀý½øÐзÖÎö¡£
Óû§½Ó¼û·ÂÃ°ÍøÕ¾http[:]//ai-openclaw.com.cn/£¬ÄÜ¿´µ½½ÏΪ¾«²ÊµÄÏÂÔØÒ³Ãæ£¬ÈçÏÂͼËùʾ£º

Óû§µã»÷Ò³ÃæÖеġ¸ÏÂÔØOpenClaw¡¹°´Å¥ºó£¬ÏÂÔØÃûΪopealeAi_7beAole-x64.zipµÄѹËõ°ü¡£¸ÃѹËõ°üÄÚÔ̺¬¿ÉÖ´Ðз¨Ê½opealeAi_7beAole-x64.exe£¬ÆäMD5ֵΪff28115a55b9a11d92bbb458efe0b940¡£
Ñù±¾·ÖÎö
Óû§Ö´ÐиöñÒâ×°ÖðüÖ®ºó£¬ÔÚ¿ªÊͳöºÏ·¨×°Ö÷¨Ê½µÄͬʱ£¬»á°µÖÐÖ´ÐжñÒⷨʽ¡£Í¨¹ý²à¼ÓÔØ·½Ê½Ö´ÐжñÒâDLLÄ£¿é£¬¶ÁȡǶÈëÁ˶ñÒâÊý¾ÝµÄpngÎļþ£¬½âÃܳöshellcode²¢Ö´ÐУ¬¾¹ýÁ½²ã½âѹִÐУ¬×îÖÕÖ´ÐÐÓµÓÐÔ¶³Ì½ÚÔìÖ°ÄܵĶñÒâDLL¡£ÕûÌåÖ´ÐÐÁ÷³ÌÈçÏÂͼËùʾ£º

Ôʼ¶ñÒâ×°Öðü
opealeAi_7beAole-x64.exeÊÇÔʼ¶ñÒâ×°Öðü£¬Í¨¹ýInno Setup¹¤¾ß´ò°ü¶ø³É£¬ÔÚ×°Öþ籾ÖÐÖ¸¶¨ÁËÎļþµÄ×°ÖÃõè¾¶£¬²¢Ö¸¶¨ÔÚ×°Öùý³ÌÖÐÖ´ÐÐÃûΪ¡°9k9UV.exe¡±µÄÎļþ¡£ÈçÏÂͼËùʾ£º

Óû§Ö´ÐÐopealeAi_7beAole-x64.exeÖ®ºó£¬»á½«¶à¸öÎļþ¿ªÊ͵½C:\Program Files (x86)\165jut\yPSTYÖС£×°Ö÷¨Ê½ÔÚ×ÀÃæ´´½¨ÃûΪ¡°Claw¡±µÄ¿ì½Ý·½Ê½£¬Ö¸ÏòÎļþC:\Program Files (x86)\165jut\yPSTY\BTM1j\OpenClaw_77b4b0ac.exe£¬ÒԹƻóÊܺ¦Õß¡£BTM1jÎļþ¼ÐÖгýÁËOpenClaw_77b4b0ac.exeÖ®±í£¬»¹ÓÐÒ»¸öͼ±êÎļþ¡£ÈçÏÂͼËùʾ£º

OpenClaw_77b4b0ac.exeÊǹúÄÚij¹«Ë¾¿ª·¢µÄºÏ·¨µÄOpenClaw±¾µØ²¿Ê𹤾ߣ¬ÓµÓÐÓÐЧµÄÊý×ÖÊðÃû£¬ÈçÏÂͼËùʾ£º

ÔËÐи÷¨Ê½£¬»á½øÐÐOpenClawµÄ±¾µØ²¿Êð£¬ÈçÏÂͼËùʾ£º

Ôʼ¶ñÒâ×°Öðü»á½«3¸öÎļþ¿ªÊ͵½dhbZ4Îļþ¼ÐÖУ¬ÈçÏÂͼËùʾ£º

ÆäÖÐBxakJ.MxÊÇpngÌåʽÎļþ£¬Äܹ»Í¨¹ýͼƬ²é¿´Èí¼þÕý³£´ò¿ª¡£ÈçÏÂͼËùʾ£º

BxakJ.MxÖУ¬ÔÚÕý³£Í¼Æ¬Êý¾ÝÖ®ºóǶÈëÁ˶à¸ö¶ñÒâÊý¾Ý¿é£¬Ã¿¸ö¶ñÒâÊý¾Ý¿éΪ0x200C×Ö½Ú£¬ÆäÖÐÊý¾Ý²¿ÃÅÕ¼0x2000×Ö½Ú¡£ÈçÏÂͼËùʾ£º

¶ñÒâDLL
9k9UV.exe»á±»Ôʼ¶ñÒâ×°ÖðüÆô¶¯£¬¸ÃÎļþÊǾ¹ý´Û¸ÄµÄ°×Îļþ£¬·¨Ê½Æô¶¯ºó£¬»á×Ô¶¯¼ÓÔØÍ¬Ä¿Â¼ÏµĶñÒâDLLÄ£¿évTPr.4DH¡£ÔÚ vTPr.4DHÖ´Ðйý³ÌÖУ¬Ê×Ïȶ¨Î»µ±Ç°¹ý³ÌµØµãĿ¼£¬¶ÁÈ¡ÎļþBxakJ.MxÖеĶñÒâÊý¾Ý£¬Í¨¹ýRC4Ëã·¨½âÃܸ÷¸ö¶ñÒâÊý¾Ý¿é²¢½øÐÐÆ´½Ó£¬Ëæºó´´½¨Ï˳Ì(Fiber)£¬ÔÚÏ˳ÌÖн«½âÃܵõ½µÄÃ÷ÎÄ×÷ΪshellcodeÖ´ÐС£ÕûÌåÁ÷³ÌÈçÏÂͼËùʾ£º

´´½¨Ï˳ÌÖ´ÐÐshellcodeÈçÏÂͼËùʾ£º

µÚÒ»²ãpayload
¸ÃshellcodeÓÉÁ½²¿ÃÅ×é³É£¬µÚÒ»²¿ÃÅÊǼÓÔØÆ÷£¬µÚ¶þ²¿ÃÅÊǾ¹ýѹËõµÄDLLÎļþÊý¾Ý¡£¼ÓÔØÆ÷µÄÖ°ÄÜÊÇ´ÓµÚ¶þ²¿ÃÅÊý¾Ý½âѹËõ³öDLLÎļþ£¬²¢½«Æä¼ÓÔØÖ´ÐС£ÈçÏÂͼËùʾ£º

µÚ¶þ²¿ÃŵÄѹËõÊý¾ÝÈçÏÂͼËùʾ£º

DLLÎļþµÄÊý¾ÝѹËõË㷨ΪLZNT1£¬½âѹËõÖ®ºóÈçÏÂͼËùʾ£º

½âѹËõºóµÄDLLÎļþ±àÒ빦·òΪ2026-03-11£¬¸ÃÎļþ¾¹ýVMP¼Ó¿Ç£¬´úÂëÑϳÁ»ìºÏ¡£ÈçÏÂͼËùʾ£º

¸ÃDLLÖØÒªÓÐÒÔÏÂ3¸öÖ°ÄÜ£º
? Ê×ÏȽ«µ±Ç°Îļþ¼Ð¼°ÆäÖеÄÎļþÉèÖÃΪ°µ²ØºÍϵͳÊôÐÔ£»
? ½âÃܳöÔ¶³Ì½ÚÔ취ʽµÄÅäÏàÐÅÏ¢£¬½«ÅäÏàÐÅÏ¢µÄ¸÷×ֶμÓÃܺó½øÐÐBase64±àÂ룻
? ÔÙ½âÃܳöÒ»¶Îshellcode£¬Æ¾¾Ý²Ù×÷ϵͳ°æ±¾Ñ¡Ôñ·ÖÆçµÄ¹ý³Ì½øÐÐ×¢Èë¡£ÔÚWindows7ϵͳÖУ¬½«shellcode×¢È뵱ǰ¹ý³Ì×ÔÉí£»ÔÚWindows10¼°ÒÔÉϰ汾µÄ²Ù×÷ϵͳÖУ¬Ñ¡Ôñϵͳ¹ý³Ì£¨ÀýÈçsihost.exe£©½øÐÐ×¢Èë¡£
×¢Èëµ½¹ý³ÌÖеÄshellcodeÓëÉÏÒ»½×¶ÎµÄshellcodeÀàËÆ£¬Í¬ÑùÓÉÁ½²¿ÃÅ×é³É£¬ÆäÖ°ÄÜͬÑùÊǽâѹËõ³öDLLÎļþ²¢¼ÓÔØÖ´ÐС£
Êý¾ÝѹËõË㷨ͬÑùΪLZNT1£¬½âѹËõǰºóÈçÏÂͼËùʾ£º

¼ÓÔØ¸ÃDLL²¢Ö´ÐÐÆäÈë¿Úº¯Êý£¬½«ÅäÏàÐÅÏ¢×÷Ϊ²ÎÊý´«Èë¡£
×îÖÕpayload
½âѹËõ³öµÄDLLÎļþÊÇ×îÖÕpayload£¬ÆäÖ°ÄÜÊÇÔ¶³Ì½ÚÔ칤¾ß¡£¸ÃDLLµÄ±àÒ빦·òΪ2026-01-08£¬Ò²¾¹ývmp¼Ó¿Ç´¦Öá£ÈçÏÂͼËùʾ£º

ÅäÏàÐÅÏ¢±»×÷Ϊ²ÎÊý´«µÝµ½DLLµÄÈë¿Úº¯Êý£¬ÆäÖÐÔ̺¬IP¡¢¶Ë¿Ú¡¢Ä¾Âí°æ±¾¡¢¹¦·ò´ÁµÈ£¬ÕâЩÐÅÏ¢¾¹ýÒì»ò¼ÓÃܺÍBase64±àÂë¡£²¿ÃÅÄÚÈÝÈçÏÂͼËùʾ£º

ÅäÏàÐÅÏ¢¸÷×ֶεÄÄÚÈݺÍÔ¢ÒâÈçϱíËùʾ£º

¸ÃDLLÆô¶¯ºó£¬Ê×ÏÈÔÚ%ALLUSERSPROFILE%Ï´´½¨ÃûΪ6C9A2AEAD706160111D90B7F3748D150µÄÎļþ¼Ð²¢ÉèÖÃΪ°µ²ØºÍϵͳÊôÐÔ£¬ÔÚÆäÖд´½¨Îļþconfig.ini²¢Ð´ÈëÅäÏàÐÅÏ¢¡£ÈçÏÂͼËùʾ£º

config.iniÎļþµÄÄÚÈݾ¹ýÒì»ò¼ÓÃÜ£¬ÆäÖÐÔ̺¬ip¡¢port¡¢ip1¡¢port1¡¢ip2¡¢port2¡¢versionµÈ×ֶΣ¬ÈçÏÂͼËùʾ£º

¶øºó˳´ÎÏνÓÅäÏàÐÅÏ¢ÖÐÖ¸¶¨µÄ¸÷¸öC2£¬ÈôÊÇÏνÓʧ°Ü£¬ÔòÇл»µ½ÏÂÒ»¸ö¡£ÍøÂçÏνÓÇé¿öÈçÏÂͼËùʾ£º

ÏνÓC2³É¹¦ºó£¬»ñÈ¡±¾»úµÄÍÆËã»úÃû¡¢Óû§Ãû¡¢²Ù×÷ϵͳ°æ±¾¡¢MACµØÖ·¡¢ÄÚÍøIPµØÖ·¡¢µ±Ç°¹¦·ò¡¢TelegramºÍ΢ÐÅ×°ÖÃÇé¿öµÈÐÅÏ¢£¬Ñ¹Ëõ²¢¼ÓÃܺó·¢Ë͵½C2¡£ÍøÂçµÄÐÅÏ¢ÈçÏÂͼËùʾ£º

½«¼ÓÃܺóµÄÊý¾Ý½øÐзâ×°£¬ÔÚÍ·²¿Ôö³¤ÁËÊý¾Ý³¤¶ÈºÍ¹Ì¶¨Öµ0x11¡¢0x22¡¢0x33¡¢0x44£¬×÷ΪÉÏÏß°ü·¢Ë͵½C2¡£¶ÔÓ¦µÄÍøÂçÁ÷Á¿ÈçÏÂͼËùʾ£º

½«ÉÏÏß°üµÄÍøÂçÁ÷Á¿½âÃÜ¡¢½âѹ£¬Äܹ»µÃµ½ÔʼµÄÃ÷ÎÄÐÅÏ¢£¬ÈçÏÂͼËùʾ£º

¶øºó´ÓC2½Ó¹Ü½ÚÔìÖ¸Áî²¢Ö´ÐУ¬ÊµÏÖÔ¶³Ì½ÚÔìÖ°ÄÜ£¬Ô̺¬ÎļþÉÏ´«¡¢ÎļþÏÂÔØ¡¢ÎļþÖ´ÐÓ×¢×°Öòå¼þ¡¢¼üÅ̼ͼ¡¢CMDºÅÁî¡¢ÈÆ¹ýUACµÈ¡£½âÎö½ÚÔìÖ¸Áî²¢Ö´ÐУ¬ÈçÏÂͼËùʾ£º

ÆäÖÐÈÆ¹ýUAC½øÐÐÌáȨÈçÏÂͼËùʾ£º

½Ó¹Üshellcode²¢´´½¨Ïß³ÌÖ´ÐУ¬ÈçÏÂͼËùʾ£º

¹ØÁªÑù±¾
ÎÒÃÇ»¹×·×Ùµ½Òøºü×éÖ¯µÄÁíÒ»¸ö·ÂðOpenClawµÄÕ¾µã https[:]//web-openclaw.com.cn/£¬¸ÃÕ¾µã½çÃæÈçÏÂͼËùʾ£º

´Ó¸ÃÕ¾µãÏÂÔØµÄÎļþÃûΪopenclaw.zip£¬ÆäÖÐÔ̺¬ÃûΪopenclaw.exeµÄ¶ñÒⷨʽ¡£¸Ã¶ñÒⷨʽѡȡÓëÉÏÎÄÒ»ÑùµÄ¹¥»÷ÊÖ·¨ºÍÁ÷³Ì£¬¿ªÊͳöºÏ·¨µÄ¶¹°üv2.2.3°æÒԹƻóÊܺ¦Õß¡£ÈçÏÂͼËùʾ£º

×°Ö÷¨Ê½°µÖпªÊͲ¢Æô¶¯¶ñÒâÄ£¿é£¬×îÖÕÖ´ÐÐÔ¶³Ì½ÚÔ취ʽ¡£C2Ϊ202.95.11.220ºÍyyyndym.icu¡£
·À±¸½¨Òé
ÒøºüÊÇ»îÔ¾ÓÚ¶«ÄÏÑÇÇøÓòµÄÖÐÎĺڻҲúÍÅ»ï£¬ÖØÒªÍ¨¹ý·ÂÃ°ÍøÕ¾ºÍ¼Ù×°ÈȵãÈí¼þ×°ÖðüÖ´Ðд¹µö¹¥»÷£¬Ö¸±êº¸Ç½ðÈÚ¡¢µçÉÌ¡¢½ÌÓý¡¢Éè¼ÆµÈ¶à¸öÐÐÒµ¡£
ΪÓÐЧ·À±¸Òøºü×éÖ¯µÄ¹¥»÷»î¶¯£¬½¨ÒéÓû§×öºÃÒÔÏ´ëÊ©£º
? ͨ¹ý¹Ù·½ÍøÕ¾»ò¿ÉÐÅÀûÓÃÉ̵ê»ñÈ¡Èí¼þ×°Öðü£¬ÇÐÎðµã»÷ËÑË÷ÒýÇæ¸æ°×λÖеÄÁ´½Ó£»
? ×°ÖÃǰÓÒ¼ü²é¿´ÎļþÊôÐÔ£¬È·ÈÏÊý×ÖÊðÃû¿¯Ðз½ÎªÕý¹æÆóÒµ£»
? ×°ÖÃɱ¶¾Èí¼þ²¢ÊµÊ±¸üУ»
? ²¿Êð¾ß±¸´¹µöÍøÕ¾¼ø±ðºÍ¶ñÒâÓòÃûÀ¹½ØÄÜÁ¦µÄÍø¹Ø/·À»ðǽ£»
? Öն˲¿ÊðÖ§³ÖÐÐΪ·ÖÎöÄÜÁ¦µÄ EDR ²úÆ·£¬²¢¿ªÆô¹ý³Ì×¢Èë¡¢ÄÚ´æÄ¾ÂíµÈ¸ß¼¶Íþв¼ì²âÖ°ÄÜ¡£
×ܽá
ÒøºüºÚ²ú×éÖ¯½èOpenClaw£¨¡°ÁúϺ¡±£©±¬»ðÖ®ÊÆÌáÒéµÄ´¹µö¹¥»÷£¬ÊǺڲúÍŻ½èÊÆÈȵ㡢¾«×¼¹¥»÷¡±µÄµäÐͰ¸Àý£¬Æä¹¥»÷Á´Â·ÖÜÃÜ¡¢¼Ù×°ÐÔÇ¿¡¢·çÏÕ¼«´ó£¬²»½öÍþвÓ×ÎÒÓû§µÄÐÅÏ¢°²È«£¬¸ü¶ÔÆóÒµ¡¢¿ÆÑлú¹¹µÈ¸÷ÀàÖ÷ÌåµÄÍøÂ簲ȫ×é³ÉÑϸñÌôÕ½¡£ÕâÒ²ÌáÐÑ¿í´óÓû§£¬ÔÚ×·¸ÏÈȵ㼼Êõ¹¤¾ßʱ£¬Îñ±ØÌá¸ß°²È«¾¯Ì裬ͨ¹ý¹Ù·½Çþ·ÏÂÔØÓйط¨Ê½£¬×ÐϸºËÑéÓòÃûÕæÎ±£¬Ô¤·Àµã»÷İÉúÁ´½Ó£¬Í¬Ê±ÊµÊ±¸üа²È«Èí¼þ¡¢½¨¸´ÏµÍ³·ì϶£¬´ÓÔ´Í··À±¸´ËÀà´¹µö¹¥»÷£¬ÊØ»¤×ÔÉíÐÅÏ¢Óëϵͳ°²È«¡£
IoCs
ÓòÃû
dcleb.com
yyyndym.icu
IP
47.242.9.11
202.95.11.220
MD5
73390ba587e5fd80ae6680480c00b64f (openclawAI 7beAolenc.zip)
ff28115a55b9a11d92bbb458efe0b940 (opealeAi_7beAole-x64.exe)
90dc6ea84b87148ce4eeb723cdc1bf48 (vTPr.4DH£¬¶ñÒâDLLÄ£¿é)
1e3908b4208ba22a4c5297652323841d (openclaw.zip)
e839115ff87a0c12b3b3ec5c4c98a41a (openclaw.exe)
c838a8b4b5f7b8c4fa29beffc23aa016 (9.3x8£¬¶ñÒâDLLÄ£¿é)


¾©¹«Íø°²±¸11010802024551ºÅ