÷Å×°Âñ·üÓë·ÂðÏÝÚå£ºÒøºü×éÖ¯½èOpenClaw×°ÖðüÖ´Ðй¥»÷»î¶¯Éî¶È·ÖÎö

°ä²¼¹¦·ò 2026-03-26

¡°ÎªÖÇÄÜʱÆÚÁ¢ÐÅ £¬Îª´´Ð¼ÛÖµ»¤º½¡£¡ª¡ª ±¦ÔËÀ³¹Ù·½ÍøÕ¾¡±


Ëæ×Å¿ªÔ´AI´úÀí¿ò¼ÜOpenClaw£¨¡°ÁúϺ¡±£©µÄ±¬»ð £¬ºÚ²úÍÅ»ï¡°Òøºü¡±Ñ¸ËÙ½èÊÆÌáÒé´¹µö¹¥»÷»î¶¯¡£Í¨¹ýÌìÉú¸ß·Â´¹µöÒ³Ãæ £¬×¢²á·ÂðÓòÃû £¬ÀûÓÃËÑË÷ÒýÇæÓÅ»¯£¨SEO£©ºÍ¸¶·Ñ¸æ°×½«¶ñÒâÁ´½ÓÖö¥ £¬ÓÕµ¼Óû§ÏÂÔØ¼Ù×°³É¡°OpenClaw±¾µØ²¿Ê𹤾ߡ±µÄ¶ñÒâ×°Öðü¡£Óû§Ö´ÐжñÒâ×°Öðüºó £¬ÔÚ¿ªÊͳöºÏ·¨×°ÖÃÈí¼þµÄͬʱ £¬°µÖÐÖ´ÐжñÒⷨʽ £¬×îÖÕ¿ªÊͲ¢Ö´ÐÐÔ¶¿ØÄ¾Âí £¬¶ÔÓû§ÍÆËã»ú½øÐнÚÔì £¬ÊµÏÖÐÅÏ¢ÇÔÈ¡¡¢ÄÚÍøÉøÈë¡¢ºáÏòÒÆ¶¯µÈ¶ñÒâ²Ù×÷¡£¹¥»÷Õßͨ¹ýÕë¶Ô×°ÖÃÁ´Â·µÄͶ¶¾ £¬´ï³ÉÁ˶ÔÖ¸±êÖ÷»úÏÕЩ¡°ÁãÃż÷¡±µÄÔ¶³ÌÊÕÊÜ¡£


±¦ÔËÀ³¹Ù·½ÍøÕ¾Íþвµý±¨ÖÐÐÄ£¨VenusEye£©½üÆÚ×·×Ùµ½Òøºü×éÖ¯¶à¸ö·ÂðOpenClawµÄÕ¾µã £¬ÕâЩվµãÉϵĶñÒâ×°ÖðüѡȡÁËÒ»ÑùµÄ¹¥»÷ÊÖ·¨ £¬Æ¾¾ÝÑù±¾ÌصãºÍioc¹ØÁª £¬ÕâЩ¹¥»÷»î¶¯¶¼¹éÓÉÓÚÒøºü×éÖ¯¡£ÏÂÎÄÒÔÒ»¸öµäÐ͵ÄÑù±¾ÎªÀý½øÐзÖÎö¡£


Óû§½Ó¼û·ÂÃ°ÍøÕ¾http[:]//ai-openclaw.com.cn/ £¬ÄÜ¿´µ½½ÏΪ¾«²ÊµÄÏÂÔØÒ³Ãæ £¬ÈçÏÂͼËùʾ£º


ͼƬ1.png


Óû§µã»÷Ò³ÃæÖеġ¸ÏÂÔØOpenClaw¡¹°´Å¥ºó £¬ÏÂÔØÃûΪopealeAi_7beAole-x64.zipµÄѹËõ°ü¡£¸ÃѹËõ°üÄÚÔ̺¬¿ÉÖ´Ðз¨Ê½opealeAi_7beAole-x64.exe £¬ÆäMD5ֵΪff28115a55b9a11d92bbb458efe0b940¡£


Ñù±¾·ÖÎö


Óû§Ö´ÐиöñÒâ×°ÖðüÖ®ºó £¬ÔÚ¿ªÊͳöºÏ·¨×°Ö÷¨Ê½µÄͬʱ £¬»á°µÖÐÖ´ÐжñÒⷨʽ¡£Í¨¹ý²à¼ÓÔØ·½Ê½Ö´ÐжñÒâDLLÄ £¿é £¬¶ÁȡǶÈëÁ˶ñÒâÊý¾ÝµÄpngÎļþ £¬½âÃܳöshellcode²¢Ö´ÐÐ £¬¾­¹ýÁ½²ã½âѹִÐÐ £¬×îÖÕÖ´ÐÐÓµÓÐÔ¶³Ì½ÚÔìÖ°ÄܵĶñÒâDLL¡£ÕûÌåÖ´ÐÐÁ÷³ÌÈçÏÂͼËùʾ£º


ͼƬ2.png


ԭʼ¶ñÒâ×°Öðü


opealeAi_7beAole-x64.exeÊÇԭʼ¶ñÒâ×°Öðü £¬Í¨¹ýInno Setup¹¤¾ß´ò°ü¶ø³É £¬ÔÚ×°Öþ籾ÖÐÖ¸¶¨ÁËÎļþµÄ×°ÖÃõè¾¶ £¬²¢Ö¸¶¨ÔÚ×°Öùý³ÌÖÐÖ´ÐÐÃûΪ¡°9k9UV.exe¡±µÄÎļþ¡£ÈçÏÂͼËùʾ£º


ͼƬ3.png


Óû§Ö´ÐÐopealeAi_7beAole-x64.exeÖ®ºó £¬»á½«¶à¸öÎļþ¿ªÊ͵½C:\Program Files (x86)\165jut\yPSTYÖС£×°Ö÷¨Ê½ÔÚ×ÀÃæ´´½¨ÃûΪ¡°Claw¡±µÄ¿ì½Ý·½Ê½ £¬Ö¸ÏòÎļþC:\Program Files (x86)\165jut\yPSTY\BTM1j\OpenClaw_77b4b0ac.exe £¬ÒԹƻóÊܺ¦Õß¡£BTM1jÎļþ¼ÐÖгýÁËOpenClaw_77b4b0ac.exeÖ®±í £¬»¹ÓÐÒ»¸öͼ±êÎļþ¡£ÈçÏÂͼËùʾ£º


ͼƬ4.jpg


OpenClaw_77b4b0ac.exeÊǹúÄÚij¹«Ë¾¿ª·¢µÄºÏ·¨µÄOpenClaw±¾µØ²¿Êð¹¤¾ß £¬ÓµÓÐÓÐЧµÄÊý×ÖÊðÃû £¬ÈçÏÂͼËùʾ£º


ͼƬ5.png


ÔËÐи÷¨Ê½ £¬»á½øÐÐOpenClawµÄ±¾µØ²¿Ê𠣬ÈçÏÂͼËùʾ£º


ͼƬ6.png


ԭʼ¶ñÒâ×°Öðü»á½«3¸öÎļþ¿ªÊ͵½dhbZ4Îļþ¼ÐÖÐ £¬ÈçÏÂͼËùʾ£º


ͼƬ7.png


ÆäÖÐBxakJ.MxÊÇpngÌåʽÎļþ £¬Äܹ»Í¨¹ýͼƬ²é¿´Èí¼þÕý³£´ò¿ª¡£ÈçÏÂͼËùʾ£º


ͼƬ8.png


BxakJ.MxÖÐ £¬ÔÚÕý³£Í¼Æ¬Êý¾ÝÖ®ºóǶÈëÁ˶à¸ö¶ñÒâÊý¾Ý¿é £¬Ã¿¸ö¶ñÒâÊý¾Ý¿éΪ0x200C×Ö½Ú £¬ÆäÖÐÊý¾Ý²¿ÃÅÕ¼0x2000×Ö½Ú¡£ÈçÏÂͼËùʾ£º


ͼƬ9.png


¶ñÒâDLL


9k9UV.exe»á±»Ô­Ê¼¶ñÒâ×°ÖðüÆô¶¯ £¬¸ÃÎļþÊǾ­¹ý´Û¸ÄµÄ°×Îļþ £¬·¨Ê½Æô¶¯ºó £¬»á×Ô¶¯¼ÓÔØÍ¬Ä¿Â¼ÏµĶñÒâDLLÄ £¿évTPr.4DH¡£ÔÚ vTPr.4DHÖ´Ðйý³ÌÖÐ £¬Ê×Ïȶ¨Î»µ±Ç°¹ý³ÌµØµãĿ¼ £¬¶ÁÈ¡ÎļþBxakJ.MxÖеĶñÒâÊý¾Ý £¬Í¨¹ýRC4Ëã·¨½âÃܸ÷¸ö¶ñÒâÊý¾Ý¿é²¢½øÐÐÆ´½Ó £¬Ëæºó´´½¨Ï˳Ì(Fiber) £¬ÔÚÏ˳ÌÖн«½âÃܵõ½µÄÃ÷ÎÄ×÷ΪshellcodeÖ´ÐС£ÕûÌåÁ÷³ÌÈçÏÂͼËùʾ£º


ͼƬ10.png


´´½¨Ï˳ÌÖ´ÐÐshellcodeÈçÏÂͼËùʾ£º


ͼƬ11.png


µÚÒ»²ãpayload


¸ÃshellcodeÓÉÁ½²¿ÃÅ×é³É £¬µÚÒ»²¿ÃÅÊǼÓÔØÆ÷ £¬µÚ¶þ²¿ÃÅÊǾ­¹ýѹËõµÄDLLÎļþÊý¾Ý¡£¼ÓÔØÆ÷µÄÖ°ÄÜÊÇ´ÓµÚ¶þ²¿ÃÅÊý¾Ý½âѹËõ³öDLLÎļþ £¬²¢½«Æä¼ÓÔØÖ´ÐС£ÈçÏÂͼËùʾ£º


ͼƬ12.png


µÚ¶þ²¿ÃŵÄѹËõÊý¾ÝÈçÏÂͼËùʾ£º


ͼƬ13.png


DLLÎļþµÄÊý¾ÝѹËõË㷨ΪLZNT1 £¬½âѹËõÖ®ºóÈçÏÂͼËùʾ£º


ͼƬ14.png


½âѹËõºóµÄDLLÎļþ±àÒ빦·òΪ2026-03-11 £¬¸ÃÎļþ¾­¹ýVMP¼Ó¿Ç £¬´úÂëÑϳÁ»ìºÏ¡£ÈçÏÂͼËùʾ£º


ͼƬ15.png


¸ÃDLLÖØÒªÓÐÒÔÏÂ3¸öÖ°ÄÜ£º


? Ê×ÏȽ«µ±Ç°Îļþ¼Ð¼°ÆäÖеÄÎļþÉèÖÃΪ°µ²ØºÍϵͳÊôÐÔ£»

½âÃܳöÔ¶³Ì½ÚÔ취ʽµÄÅäÏàÐÅÏ¢ £¬½«ÅäÏàÐÅÏ¢µÄ¸÷×ֶμÓÃܺó½øÐÐBase64±àÂ룻

ÔÙ½âÃܳöÒ»¶Îshellcode £¬Æ¾¾Ý²Ù×÷ϵͳ°æ±¾Ñ¡Ôñ·ÖÆçµÄ¹ý³Ì½øÐÐ×¢Èë¡£ÔÚWindows7ϵͳÖÐ £¬½«shellcode×¢È뵱ǰ¹ý³Ì×ÔÉí£»ÔÚWindows10¼°ÒÔÉϰ汾µÄ²Ù×÷ϵͳÖÐ £¬Ñ¡Ôñϵͳ¹ý³Ì£¨ÀýÈçsihost.exe£©½øÐÐ×¢Èë¡£


×¢Èëµ½¹ý³ÌÖеÄshellcodeÓëÉÏÒ»½×¶ÎµÄshellcodeÀàËÆ £¬Í¬ÑùÓÉÁ½²¿ÃÅ×é³É £¬ÆäÖ°ÄÜͬÑùÊǽâѹËõ³öDLLÎļþ²¢¼ÓÔØÖ´ÐС£


Êý¾ÝѹËõË㷨ͬÑùΪLZNT1 £¬½âѹËõǰºóÈçÏÂͼËùʾ£º


ͼƬ16.png


¼ÓÔØ¸ÃDLL²¢Ö´ÐÐÆäÈë¿Úº¯Êý £¬½«ÅäÏàÐÅÏ¢×÷Ϊ²ÎÊý´«Èë¡£


×îÖÕpayload


½âѹËõ³öµÄDLLÎļþÊÇ×îÖÕpayload £¬ÆäÖ°ÄÜÊÇÔ¶³Ì½ÚÔ칤¾ß¡£¸ÃDLLµÄ±àÒ빦·òΪ2026-01-08 £¬Ò²¾­¹ývmp¼Ó¿Ç´¦Öá£ÈçÏÂͼËùʾ£º


ͼƬ17.png


ÅäÏàÐÅÏ¢±»×÷Ϊ²ÎÊý´«µÝµ½DLLµÄÈë¿Úº¯Êý £¬ÆäÖÐÔ̺¬IP¡¢¶Ë¿Ú¡¢Ä¾Âí°æ±¾¡¢¹¦·ò´ÁµÈ £¬ÕâЩÐÅÏ¢¾­¹ýÒì»ò¼ÓÃܺÍBase64±àÂë¡£²¿ÃÅÄÚÈÝÈçÏÂͼËùʾ£º


ͼƬ18.png


ÅäÏàÐÅÏ¢¸÷×ֶεÄÄÚÈݺÍÔ¢ÒâÈçϱíËùʾ£º


ͼƬ19.png


¸ÃDLLÆô¶¯ºó £¬Ê×ÏÈÔÚ%ALLUSERSPROFILE%Ï´´½¨ÃûΪ6C9A2AEAD706160111D90B7F3748D150µÄÎļþ¼Ð²¢ÉèÖÃΪ°µ²ØºÍϵͳÊôÐÔ £¬ÔÚÆäÖд´½¨Îļþconfig.ini²¢Ð´ÈëÅäÏàÐÅÏ¢¡£ÈçÏÂͼËùʾ£º


ͼƬ20.png


config.iniÎļþµÄÄÚÈݾ­¹ýÒì»ò¼ÓÃÜ £¬ÆäÖÐÔ̺¬ip¡¢port¡¢ip1¡¢port1¡¢ip2¡¢port2¡¢versionµÈ×Ö¶Î £¬ÈçÏÂͼËùʾ£º


ͼƬ21.png


¶øºó˳´ÎÏνÓÅäÏàÐÅÏ¢ÖÐÖ¸¶¨µÄ¸÷¸öC2 £¬ÈôÊÇÏνÓʧ°Ü £¬ÔòÇл»µ½ÏÂÒ»¸ö¡£ÍøÂçÏνÓÇé¿öÈçÏÂͼËùʾ£º


ͼƬ22.png


ÏνÓC2³É¹¦ºó £¬»ñÈ¡±¾»úµÄÍÆËã»úÃû¡¢Óû§Ãû¡¢²Ù×÷ϵͳ°æ±¾¡¢MACµØÖ·¡¢ÄÚÍøIPµØÖ·¡¢µ±Ç°¹¦·ò¡¢TelegramºÍ΢ÐÅ×°ÖÃÇé¿öµÈÐÅÏ¢ £¬Ñ¹Ëõ²¢¼ÓÃܺó·¢Ë͵½C2¡£ÍøÂçµÄÐÅÏ¢ÈçÏÂͼËùʾ£º


ͼƬ23.png


½«¼ÓÃܺóµÄÊý¾Ý½øÐзâ×° £¬ÔÚÍ·²¿Ôö³¤ÁËÊý¾Ý³¤¶ÈºÍ¹Ì¶¨Öµ0x11¡¢0x22¡¢0x33¡¢0x44 £¬×÷ΪÉÏÏß°ü·¢Ë͵½C2¡£¶ÔÓ¦µÄÍøÂçÁ÷Á¿ÈçÏÂͼËùʾ£º


ͼƬ24.png


½«ÉÏÏß°üµÄÍøÂçÁ÷Á¿½âÃÜ¡¢½âѹ £¬Äܹ»µÃµ½Ô­Ê¼µÄÃ÷ÎÄÐÅÏ¢ £¬ÈçÏÂͼËùʾ£º


ͼƬ25.png


¶øºó´ÓC2½Ó¹Ü½ÚÔìÖ¸Áî²¢Ö´ÐÐ £¬ÊµÏÖÔ¶³Ì½ÚÔìÖ°ÄÜ £¬Ô̺¬ÎļþÉÏ´«¡¢ÎļþÏÂÔØ¡¢ÎļþÖ´ÐÓ×¢×°Öòå¼þ¡¢¼üÅ̼ͼ¡¢CMDºÅÁî¡¢ÈÆ¹ýUACµÈ¡£½âÎö½ÚÔìÖ¸Áî²¢Ö´ÐÐ £¬ÈçÏÂͼËùʾ£º


ͼƬ26.png


ÆäÖÐÈÆ¹ýUAC½øÐÐÌáȨÈçÏÂͼËùʾ£º


ͼƬ27.png


½Ó¹Üshellcode²¢´´½¨Ïß³ÌÖ´ÐÐ £¬ÈçÏÂͼËùʾ£º


ͼƬ28.png


¹ØÁªÑù±¾


ÎÒÃÇ»¹×·×Ùµ½Òøºü×éÖ¯µÄÁíÒ»¸ö·ÂðOpenClawµÄÕ¾µã https[:]//web-openclaw.com.cn/ £¬¸ÃÕ¾µã½çÃæÈçÏÂͼËùʾ£º


ͼƬ29.png


´Ó¸ÃÕ¾µãÏÂÔØµÄÎļþÃûΪopenclaw.zip £¬ÆäÖÐÔ̺¬ÃûΪopenclaw.exeµÄ¶ñÒⷨʽ¡£¸Ã¶ñÒⷨʽѡȡÓëÉÏÎÄÒ»ÑùµÄ¹¥»÷ÊÖ·¨ºÍÁ÷³Ì £¬¿ªÊͳöºÏ·¨µÄ¶¹°üv2.2.3°æÒԹƻóÊܺ¦Õß¡£ÈçÏÂͼËùʾ£º


ͼƬ30.png


×°Ö÷¨Ê½°µÖпªÊͲ¢Æô¶¯¶ñÒâÄ £¿é £¬×îÖÕÖ´ÐÐÔ¶³Ì½ÚÔ취ʽ¡£C2Ϊ202.95.11.220ºÍyyyndym.icu¡£


·À±¸½¨Òé


ÒøºüÊÇ»îÔ¾ÓÚ¶«ÄÏÑÇÇøÓòµÄÖÐÎĺڻҲúÍÅ»ï £¬ÖØÒªÍ¨¹ý·ÂÃ°ÍøÕ¾ºÍ¼Ù×°ÈȵãÈí¼þ×°ÖðüÖ´Ðд¹µö¹¥»÷ £¬Ö¸±êº­¸Ç½ðÈÚ¡¢µçÉÌ¡¢½ÌÓý¡¢Éè¼ÆµÈ¶à¸öÐÐÒµ¡£


ΪÓÐЧ·À±¸Òøºü×éÖ¯µÄ¹¥»÷»î¶¯ £¬½¨ÒéÓû§×öºÃÒÔÏ´ëÊ©£º


? ͨ¹ý¹Ù·½ÍøÕ¾»ò¿ÉÐÅÀûÓÃÉ̵ê»ñÈ¡Èí¼þ×°Öðü £¬ÇÐÎðµã»÷ËÑË÷ÒýÇæ¸æ°×λÖеÄÁ´½Ó£»

×°ÖÃǰÓÒ¼ü²é¿´ÎļþÊôÐÔ £¬È·ÈÏÊý×ÖÊðÃû¿¯Ðз½ÎªÕý¹æÆóÒµ£»

×°ÖÃɱ¶¾Èí¼þ²¢ÊµÊ±¸üУ»

²¿Êð¾ß±¸´¹µöÍøÕ¾¼ø±ðºÍ¶ñÒâÓòÃûÀ¹½ØÄÜÁ¦µÄÍø¹Ø/·À»ðǽ£»

Öն˲¿ÊðÖ§³ÖÐÐΪ·ÖÎöÄÜÁ¦µÄ EDR ²úÆ· £¬²¢¿ªÆô¹ý³Ì×¢Èë¡¢ÄÚ´æÄ¾ÂíµÈ¸ß¼¶Íþв¼ì²âÖ°ÄÜ¡£


×ܽá


ÒøºüºÚ²ú×éÖ¯½èOpenClaw£¨¡°ÁúϺ¡±£©±¬»ðÖ®ÊÆÌáÒéµÄ´¹µö¹¥»÷ £¬ÊǺڲúÍŻ½èÊÆÈȵ㡢¾«×¼¹¥»÷¡±µÄµäÐͰ¸Àý £¬Æä¹¥»÷Á´Â·ÖÜÃÜ¡¢¼Ù×°ÐÔÇ¿¡¢·çÏÕ¼«´ó £¬²»½öÍþвÓ×ÎÒÓû§µÄÐÅÏ¢°²È« £¬¸ü¶ÔÆóÒµ¡¢¿ÆÑлú¹¹µÈ¸÷ÀàÖ÷ÌåµÄÍøÂ簲ȫ×é³ÉÑϸñÌôÕ½¡£ÕâÒ²ÌáÐÑ¿í´óÓû§ £¬ÔÚ×·¸ÏÈȵ㼼Êõ¹¤¾ßʱ £¬Îñ±ØÌá¸ß°²È«¾¯Ìè £¬Í¨¹ý¹Ù·½Çþ·ÏÂÔØÓйط¨Ê½ £¬×ÐϸºËÑéÓòÃûÕæÎ± £¬Ô¤·Àµã»÷İÉúÁ´½Ó £¬Í¬Ê±ÊµÊ±¸üа²È«Èí¼þ¡¢½¨¸´ÏµÍ³·ì϶ £¬´ÓÔ´Í··À±¸´ËÀà´¹µö¹¥»÷ £¬ÊØ»¤×ÔÉíÐÅÏ¢Óëϵͳ°²È«¡£


IoCs


ÓòÃû


dcleb.com

yyyndym.icu


IP


47.242.9.11

202.95.11.220


MD5


73390ba587e5fd80ae6680480c00b64f (openclawAI 7beAolenc.zip)

ff28115a55b9a11d92bbb458efe0b940 (opealeAi_7beAole-x64.exe)

90dc6ea84b87148ce4eeb723cdc1bf48 (vTPr.4DH £¬¶ñÒâDLLÄ £¿é)

1e3908b4208ba22a4c5297652323841d (openclaw.zip)

e839115ff87a0c12b3b3ec5c4c98a41a (openclaw.exe)

c838a8b4b5f7b8c4fa29beffc23aa016 (9.3x8 £¬¶ñÒâDLLÄ £¿é)