÷ÈÓ°Âñ·üÓë·ÂðÏÝÚ壺£ºÒøºü×éÖ¯½èOpenClaw×°ÖðüÖ´Ðй¥»÷»î¶¯Éî¶È·ÖÎö

°ä²¼¹¦·ò 2026-03-26

¡°ÎªÖÇÄÜʱÆÚÁ¢ÐÅ£¬Îª´´Ð¼ÛÖµ»¤º½¡£¡ª¡ª OG¶«·½Ìü¡±


Ëæ×Å¿ªÔ´AI´úÀí¿ò¼ÜOpenClaw£¨¡°ÁúϺ¡±£©µÄ±¬»ð£¬ºÚ²úÍÅ»ï¡°Òøºü¡±Ñ¸ËÙ½èÊÆÌáÒé´¹µö¹¥»÷»î¶¯¡£Í¨¹ýÌìÉú¸ß·Â´¹µöÒ³Ãæ£¬×¢²á·ÂðÓòÃû£¬ÀûÓÃËÑË÷ÒýÇæÓÅ»¯£¨SEO£©ºÍ¸¶·Ñ¸æ°×½«¶ñÒâÁ´½ÓÖö¥£¬ÓÕµ¼Óû§ÏÂÔØ¼Ù×°³É¡°OpenClaw±¾µØ²¿Ê𹤾ߡ±µÄ¶ñÒâ×°Öðü¡£Óû§Ö´ÐжñÒâ×°Öðüºó£¬ÔÚ¿ªÊͳöºÏ·¨×°ÖÃÈí¼þµÄͬʱ£¬°µÖÐÖ´ÐжñÒⷨʽ£¬×îÖÕ¿ªÊͲ¢Ö´ÐÐÔ¶¿ØÄ¾Âí£¬¶ÔÓû§ÍÆËã»ú½øÐнÚÖÆ£¬ÊµÏÖÐÅÏ¢ÇÔÈ¡ ¡¢¡¢ÄÚÍøÉøÈë ¡¢¡¢ºáÏòÒÆ¶¯µÈ¶ñÒâ²Ù×÷¡£¹¥»÷Õßͨ¹ýÕë¶Ô×°ÖÃÁ´Â·µÄͶ¶¾£¬´ï³ÉÁ˶ÔÖ¸±êÖ÷»úÏÕЩ¡°ÁãÃż÷¡±µÄÔ¶³ÌÊÕÊÜ¡£


OG¶«·½ÌüÍþвµý±¨ÖÐÐÄ£¨VenusEye£©½üÆÚ×·×Ùµ½Òøºü×éÖ¯¶à¸ö·ÂðOpenClawµÄÕ¾µã£¬ÕâЩվµãÉϵĶñÒâ×°ÖðüѡȡÁËÒ»ÑùµÄ¹¥»÷ÊÖ·¨£¬Æ¾¾ÝÑù±¾ÌصãºÍioc¹ØÁª£¬ÕâЩ¹¥»÷»î¶¯¶¼¹éÓÉÓÚÒøºü×éÖ¯¡£ÏÂÎÄÒÔÒ»¸öµäÐ͵ÄÑù±¾ÎªÀý½øÐзÖÎö¡£


Óû§½Ó¼û·ÂÃ°ÍøÕ¾http[:]//ai-openclaw.com.cn/£¬ÄÜ¿´µ½½ÏΪ¾«²ÊµÄÏÂÔØÒ³Ãæ£¬ÈçÏÂͼËùʾ£º£º


ͼƬ1.png


Óû§µã»÷Ò³ÃæÖеġ¸ÏÂÔØOpenClaw¡¹°´Å¥ºó£¬ÏÂÔØÃûΪopealeAi_7beAole-x64.zipµÄѹËõ°ü¡£¸ÃѹËõ°üÄÚÔ̺¬¿ÉÖ´Ðз¨Ê½opealeAi_7beAole-x64.exe£¬ÆäMD5ֵΪff28115a55b9a11d92bbb458efe0b940¡£


Ñù±¾·ÖÎö


Óû§Ö´ÐиöñÒâ×°ÖðüÖ®ºó£¬ÔÚ¿ªÊͳöºÏ·¨×°Ö÷¨Ê½µÄͬʱ£¬»á°µÖÐÖ´ÐжñÒⷨʽ¡£Í¨¹ý²à¼ÓÔØ·½Ê½Ö´ÐжñÒâDLLÄ£¿£¿é£¬¶ÁȡǶÈëÁ˶ñÒâÊý¾ÝµÄpngÎļþ£¬½âÃܳöshellcode²¢Ö´ÐУ¬¾­¹ýÁ½²ã½âѹִÐУ¬×îÖÕÖ´ÐÐÓµÓÐÔ¶³Ì½ÚÖÆÖ°ÄܵĶñÒâDLL¡£ÕûÌåÖ´ÐÐÁ÷³ÌÈçÏÂͼËùʾ£º£º


ͼƬ2.png


ԭʼ¶ñÒâ×°Öðü


opealeAi_7beAole-x64.exeÊÇԭʼ¶ñÒâ×°Öðü£¬Í¨¹ýInno Setup¹¤¾ß´ò°ü¶ø³É£¬ÔÚ×°Öþ籾ÖÐÖ¸¶¨ÁËÎļþµÄ×°ÖÃõè¾¶£¬²¢Ö¸¶¨ÔÚ×°Öùý³ÌÖÐÖ´ÐÐÃûΪ¡°9k9UV.exe¡±µÄÎļþ¡£ÈçÏÂͼËùʾ£º£º


ͼƬ3.png


Óû§Ö´ÐÐopealeAi_7beAole-x64.exeÖ®ºó£¬»á½«¶à¸öÎļþ¿ªÊ͵½C:\Program Files (x86)\165jut\yPSTYÖС£×°Ö÷¨Ê½ÔÚ×ÀÃæ´´½¨ÃûΪ¡°Claw¡±µÄ¿ì½Ý·½Ê½£¬Ö¸ÏòÎļþC:\Program Files (x86)\165jut\yPSTY\BTM1j\OpenClaw_77b4b0ac.exe£¬ÒԹƻóÊܺ¦Õß¡£BTM1jÎļþ¼ÐÖгýÁËOpenClaw_77b4b0ac.exeÖ®Í⣬»¹ÓÐÒ»¸öͼ±êÎļþ¡£ÈçÏÂͼËùʾ£º£º


ͼƬ4.jpg


OpenClaw_77b4b0ac.exeÊǹúÄÚij¹«Ë¾¿ª·¢µÄºÏ·¨µÄOpenClaw±¾µØ²¿Ê𹤾ߣ¬ÓµÓÐÓÐЧµÄÊý×ÖÊðÃû£¬ÈçÏÂͼËùʾ£º£º


ͼƬ5.png


ÔËÐи÷¨Ê½£¬»á½øÐÐOpenClawµÄ±¾µØ²¿Êð£¬ÈçÏÂͼËùʾ£º£º


ͼƬ6.png


ԭʼ¶ñÒâ×°Öðü»á½«3¸öÎļþ¿ªÊ͵½dhbZ4Îļþ¼ÐÖУ¬ÈçÏÂͼËùʾ£º£º


ͼƬ7.png


ÆäÖÐBxakJ.MxÊÇpngÌåʽÎļþ£¬Äܹ»Í¨¹ýͼƬ²é¿´Èí¼þÕý³£´ò¿ª¡£ÈçÏÂͼËùʾ£º£º


ͼƬ8.png


BxakJ.MxÖУ¬ÔÚÕý³£Í¼Æ¬Êý¾ÝÖ®ºóǶÈëÁ˶à¸ö¶ñÒâÊý¾Ý¿é£¬Ã¿¸ö¶ñÒâÊý¾Ý¿éΪ0x200C×Ö½Ú£¬ÆäÖÐÊý¾Ý²¿ÃÅÕ¼0x2000×Ö½Ú¡£ÈçÏÂͼËùʾ£º£º


ͼƬ9.png


¶ñÒâDLL


9k9UV.exe»á±»Ô­Ê¼¶ñÒâ×°ÖðüÆô¶¯£¬¸ÃÎļþÊǾ­¹ý´Û¸ÄµÄ°×Îļþ£¬·¨Ê½Æô¶¯ºó£¬»á×Ô¶¯¼ÓÔØÍ¬Ä¿Â¼ÏµĶñÒâDLLÄ£¿£¿évTPr.4DH¡£ÔÚ vTPr.4DHÖ´Ðйý³ÌÖУ¬Ê×Ïȶ¨Î»µ±Ç°¹ý³ÌµØµãĿ¼£¬¶ÁÈ¡ÎļþBxakJ.MxÖеĶñÒâÊý¾Ý£¬Í¨¹ýRC4Ëã·¨½âÃܸ÷¸ö¶ñÒâÊý¾Ý¿é²¢½øÐÐÆ´½Ó£¬Ëæºó´´½¨Ï˳Ì(Fiber)£¬ÔÚÏ˳ÌÖн«½âÃܵõ½µÄÃ÷ÎÄ×÷ΪshellcodeÖ´ÐС£ÕûÌåÁ÷³ÌÈçÏÂͼËùʾ£º£º


ͼƬ10.png


´´½¨Ï˳ÌÖ´ÐÐshellcodeÈçÏÂͼËùʾ£º£º


ͼƬ11.png


µÚÒ»²ãpayload


¸ÃshellcodeÓÉÁ½²¿ÃÅ×é³É£¬µÚÒ»²¿ÃÅÊǼÓÔØÆ÷£¬µÚ¶þ²¿ÃÅÊǾ­¹ýѹËõµÄDLLÎļþÊý¾Ý¡£¼ÓÔØÆ÷µÄÖ°ÄÜÊÇ´ÓµÚ¶þ²¿ÃÅÊý¾Ý½âѹËõ³öDLLÎļþ£¬²¢½«Æä¼ÓÔØÖ´ÐС£ÈçÏÂͼËùʾ£º£º


ͼƬ12.png


µÚ¶þ²¿ÃŵÄѹËõÊý¾ÝÈçÏÂͼËùʾ£º£º


ͼƬ13.png


DLLÎļþµÄÊý¾ÝѹËõË㷨ΪLZNT1£¬½âѹËõÖ®ºóÈçÏÂͼËùʾ£º£º


ͼƬ14.png


½âѹËõºóµÄDLLÎļþ±àÒ빦·òΪ2026-03-11£¬¸ÃÎļþ¾­¹ýVMP¼Ó¿Ç£¬´úÂëÑÏÖØ»ìºÏ¡£ÈçÏÂͼËùʾ£º£º


ͼƬ15.png


¸ÃDLLÖØÒªÓÐÒÔÏÂ3¸öÖ°ÄÜ£º£º


? Ê×ÏȽ«µ±Ç°Îļþ¼Ð¼°ÆäÖеÄÎļþÉèÖÃΪ°µ²ØºÍϵͳÊôÐÔ£»

½âÃܳöÔ¶³Ì½ÚÖÆ·¨Ê½µÄÅäÏàÐÅÏ¢£¬½«ÅäÏàÐÅÏ¢µÄ¸÷×ֶμÓÃܺó½øÐÐBase64±àÂ룻

ÔÙ½âÃܳöÒ»¶Îshellcode£¬Æ¾¾Ý²Ù×÷ϵͳ°æ±¾Ñ¡Ôñ·ÖÆçµÄ¹ý³Ì½øÐÐ×¢Èë¡£ÔÚWindows7ϵͳÖУ¬½«shellcode×¢È뵱ǰ¹ý³Ì×ÔÉí£»ÔÚWindows10¼°ÒÔÉϰ汾µÄ²Ù×÷ϵͳÖУ¬Ñ¡Ôñϵͳ¹ý³Ì£¨ÀýÈçsihost.exe£©½øÐÐ×¢Èë¡£


×¢Èëµ½¹ý³ÌÖеÄshellcodeÓëÉÏÒ»½×¶ÎµÄshellcodeÀàËÆ£¬Í¬ÑùÓÉÁ½²¿ÃÅ×é³É£¬ÆäÖ°ÄÜͬÑùÊǽâѹËõ³öDLLÎļþ²¢¼ÓÔØÖ´ÐС£


Êý¾ÝѹËõË㷨ͬÑùΪLZNT1£¬½âѹËõǰºóÈçÏÂͼËùʾ£º£º


ͼƬ16.png


¼ÓÔØ¸ÃDLL²¢Ö´ÐÐÆäÈë¿Úº¯Êý£¬½«ÅäÏàÐÅÏ¢×÷Ϊ²ÎÊý´«Èë¡£


×îÖÕpayload


½âѹËõ³öµÄDLLÎļþÊÇ×îÖÕpayload£¬ÆäÖ°ÄÜÊÇÔ¶³Ì½ÚÖÆ¹¤¾ß¡£¸ÃDLLµÄ±àÒ빦·òΪ2026-01-08£¬Ò²¾­¹ývmp¼Ó¿Ç´¦Öá£ÈçÏÂͼËùʾ£º£º


ͼƬ17.png


ÅäÏàÐÅÏ¢±»×÷Ϊ²ÎÊý´«µÝµ½DLLµÄÈë¿Úº¯Êý£¬ÆäÖÐÔ̺¬IP ¡¢¡¢¶Ë¿Ú ¡¢¡¢Ä¾Âí°æ±¾ ¡¢¡¢¹¦·ò´ÁµÈ£¬ÕâЩÐÅÏ¢¾­¹ýÒì»ò¼ÓÃܺÍBase64±àÂë¡£²¿ÃÅÄÚÈÝÈçÏÂͼËùʾ£º£º


ͼƬ18.png


ÅäÏàÐÅÏ¢¸÷×ֶεÄÄÚÈݺÍÔ¢ÒâÈçϱíËùʾ£º£º


ͼƬ19.png


¸ÃDLLÆô¶¯ºó£¬Ê×ÏÈÔÚ%ALLUSERSPROFILE%Ï´´½¨ÃûΪ6C9A2AEAD706160111D90B7F3748D150µÄÎļþ¼Ð²¢ÉèÖÃΪ°µ²ØºÍϵͳÊôÐÔ£¬ÔÚÆäÖд´½¨Îļþconfig.ini²¢Ð´ÈëÅäÏàÐÅÏ¢¡£ÈçÏÂͼËùʾ£º£º


ͼƬ20.png


config.iniÎļþµÄÄÚÈݾ­¹ýÒì»ò¼ÓÃÜ£¬ÆäÖÐÔ̺¬ip ¡¢¡¢port ¡¢¡¢ip1 ¡¢¡¢port1 ¡¢¡¢ip2 ¡¢¡¢port2 ¡¢¡¢versionµÈ×ֶΣ¬ÈçÏÂͼËùʾ£º£º


ͼƬ21.png


¶øºó˳´ÎÏνÓÅäÏàÐÅÏ¢ÖÐÖ¸¶¨µÄ¸÷¸öC2£¬ÈôÊÇÏνÓʧ°Ü£¬ÔòÇл»µ½ÏÂÒ»¸ö¡£ÍøÂçÏνÓÇé¿öÈçÏÂͼËùʾ£º£º


ͼƬ22.png


ÏνÓC2³É¹¦ºó£¬»ñÈ¡±¾»úµÄÍÆËã»úÃû ¡¢¡¢Óû§Ãû ¡¢¡¢²Ù×÷ϵͳ°æ±¾ ¡¢¡¢MACµØÖ· ¡¢¡¢ÄÚÍøIPµØÖ· ¡¢¡¢µ±Ç°¹¦·ò ¡¢¡¢TelegramºÍ΢ÐÅ×°ÖÃÇé¿öµÈÐÅÏ¢£¬Ñ¹Ëõ²¢¼ÓÃܺó·¢Ë͵½C2¡£ÍøÂçµÄÐÅÏ¢ÈçÏÂͼËùʾ£º£º


ͼƬ23.png


½«¼ÓÃܺóµÄÊý¾Ý½øÐзâ×°£¬ÔÚÍ·²¿Ôö³¤ÁËÊý¾Ý³¤¶ÈºÍ¹Ì¶¨Öµ0x11 ¡¢¡¢0x22 ¡¢¡¢0x33 ¡¢¡¢0x44£¬×÷ΪÉÏÏß°ü·¢Ë͵½C2¡£¶ÔÓ¦µÄÍøÂçÁ÷Á¿ÈçÏÂͼËùʾ£º£º


ͼƬ24.png


½«ÉÏÏß°üµÄÍøÂçÁ÷Á¿½âÃÜ ¡¢¡¢½âѹ£¬Äܹ»µÃµ½Ô­Ê¼µÄÃ÷ÎÄÐÅÏ¢£¬ÈçÏÂͼËùʾ£º£º


ͼƬ25.png


¶øºó´ÓC2½Ó¹Ü½ÚÖÆÖ¸Áî²¢Ö´ÐУ¬ÊµÏÖÔ¶³Ì½ÚÖÆÖ°ÄÜ£¬Ô̺¬ÎļþÉÏ´« ¡¢¡¢ÎļþÏÂÔØ ¡¢¡¢ÎļþÖ´ÐÐ ¡¢¡¢×°Öòå¼þ ¡¢¡¢¼üÅ̼ͼ ¡¢¡¢CMDºÅÁî ¡¢¡¢ÈƹýUACµÈ¡£½âÎö½ÚÖÆÖ¸Áî²¢Ö´ÐУ¬ÈçÏÂͼËùʾ£º£º


ͼƬ26.png


ÆäÖÐÈÆ¹ýUAC½øÐÐÌáȨÈçÏÂͼËùʾ£º£º


ͼƬ27.png


½Ó¹Üshellcode²¢´´½¨Ïß³ÌÖ´ÐУ¬ÈçÏÂͼËùʾ£º£º


ͼƬ28.png


¹ØÁªÑù±¾


ÎÒÃÇ»¹×·×Ùµ½Òøºü×éÖ¯µÄÁíÒ»¸ö·ÂðOpenClawµÄÕ¾µã https[:]//web-openclaw.com.cn/£¬¸ÃÕ¾µã½çÃæÈçÏÂͼËùʾ£º£º


ͼƬ29.png


´Ó¸ÃÕ¾µãÏÂÔØµÄÎļþÃûΪopenclaw.zip£¬ÆäÖÐÔ̺¬ÃûΪopenclaw.exeµÄ¶ñÒⷨʽ¡£¸Ã¶ñÒⷨʽѡȡÓëÉÏÎÄÒ»ÑùµÄ¹¥»÷ÊÖ·¨ºÍÁ÷³Ì£¬¿ªÊͳöºÏ·¨µÄ¶¹°üv2.2.3°æÒԹƻóÊܺ¦Õß¡£ÈçÏÂͼËùʾ£º£º


ͼƬ30.png


×°Ö÷¨Ê½°µÖпªÊͲ¢Æô¶¯¶ñÒâÄ£¿£¿é£¬×îÖÕÖ´ÐÐÔ¶³Ì½ÚÖÆ·¨Ê½¡£C2Ϊ202.95.11.220ºÍyyyndym.icu¡£


·À±¸½¨Òé


ÒøºüÊÇ»îÔ¾ÓÚ¶«ÄÏÑÇÇøÓòµÄÖÐÎĺڻҲúÍÅ»ï£¬ÖØÒªÍ¨¹ý·ÂÃ°ÍøÕ¾ºÍ¼Ù×°ÈȵãÈí¼þ×°ÖðüÖ´Ðд¹µö¹¥»÷£¬Ö¸±êº­¸Ç½ðÈÚ ¡¢¡¢µçÉÌ ¡¢¡¢½ÌÓý ¡¢¡¢Éè¼ÆµÈ¶à¸öÐÐÒµ¡£


ΪÓÐЧ·À±¸Òøºü×éÖ¯µÄ¹¥»÷»î¶¯£¬½¨ÒéÓû§×öºÃÒÔÏ´ëÊ©£º£º


? ͨ¹ý¹Ù·½ÍøÕ¾»ò¿ÉÐÅÀûÓÃÉ̵ê»ñÈ¡Èí¼þ×°Öðü£¬ÇÐÎðµã»÷ËÑË÷ÒýÇæ¸æ°×λÖеÄÁ´½Ó£»

×°ÖÃǰÓÒ¼ü²é¿´ÎļþÊôÐÔ£¬È·ÈÏÊý×ÖÊðÃû¿¯Ðз½ÎªÕý¹æÆóÒµ£»

×°ÖÃɱ¶¾Èí¼þ²¢ÊµÊ±¸üУ»

²¿Êð¾ß±¸´¹µöÍøÕ¾¼ø±ðºÍ¶ñÒâÓòÃûÀ¹½ØÄÜÁ¦µÄÍø¹Ø/·À»ðǽ£»

Öն˲¿ÊðÖ§³ÖÐÐΪ·ÖÎöÄÜÁ¦µÄ EDR ²úÆ·£¬²¢¿ªÆô¹ý³Ì×¢Èë ¡¢¡¢ÄÚ´æÄ¾ÂíµÈ¸ß¼¶Íþв¼ì²âÖ°ÄÜ¡£


×ܽá


ÒøºüºÚ²ú×éÖ¯½èOpenClaw£¨¡°ÁúϺ¡±£©±¬»ðÖ®ÊÆÌáÒéµÄ´¹µö¹¥»÷£¬ÊǺڲúÍŻ½èÊÆÈȵ㠡¢¡¢¾«×¼¹¥»÷¡±µÄµäÐͰ¸Àý£¬Æä¹¥»÷Á´Â·ÖÜÃÜ ¡¢¡¢¼Ù×°ÐÔÇ¿ ¡¢¡¢Î£º£º¦¼«´ó£¬²»½öÍþвСÎÒÓû§µÄÐÅÏ¢°²È«£¬¸ü¶ÔÆóÒµ ¡¢¡¢¿ÆÑлú¹¹µÈ¸÷ÀàÖ÷ÌåµÄÍøÂ簲ȫ×é³ÉÑϸñÌôÕ½¡£ÕâÒ²ÌáÐÑ¿í´óÓû§£¬ÔÚ×·¸ÏÈȵ㼼Êõ¹¤¾ßʱ£¬Îñ±ØÌá¸ß°²È«¾¯Ì裬ͨ¹ý¹Ù·½ÇþµÀÏÂÔØÓйط¨Ê½£¬×ÐϸºËÑéÓòÃûÕæÎ±£¬Ô¤·Àµã»÷İÉúÁ´½Ó£¬Í¬Ê±ÊµÊ±¸üа²È«Èí¼þ ¡¢¡¢ÐÞ¸´ÏµÍ³·ì϶£¬´ÓÔ´Í··À±¸´ËÀà´¹µö¹¥»÷£¬ÊØ»¤×ÔÉíÐÅÏ¢Óëϵͳ°²È«¡£


IoCs


ÓòÃû


dcleb.com

yyyndym.icu


IP


47.242.9.11

202.95.11.220


MD5


73390ba587e5fd80ae6680480c00b64f (openclawAI 7beAolenc.zip)

ff28115a55b9a11d92bbb458efe0b940 (opealeAi_7beAole-x64.exe)

90dc6ea84b87148ce4eeb723cdc1bf48 (vTPr.4DH£¬¶ñÒâDLLÄ£¿£¿é)

1e3908b4208ba22a4c5297652323841d (openclaw.zip)

e839115ff87a0c12b3b3ec5c4c98a41a (openclaw.exe)

c838a8b4b5f7b8c4fa29beffc23aa016 (9.3x8£¬¶ñÒâDLLÄ£¿£¿é)