首页 > 其他分享 >某中文TG利用的Foundation.dll

某中文TG利用的Foundation.dll

时间:2023-01-14 22:24:47浏览次数:52  
标签:Foundation 27.124 startLogging fde 15628 dll TG

目录

Dll劫持27号导出函数,?startLogging@fde@@YAXPB_W@Z
fde::startLogging

fde::startLogging

image
image

dump

Dump出来是upx压缩,无魔改
image
image

简单分析

c2

? 首次应该是 尝试连接d.nkking.com
image
失败就切换
image

192.168.1.216:15628
180.215.215.5:15628
103.146.13.63:15628
27.124.41.140:15628
103.80.24.52:15628
27.124.42.14:15628
8.210.94.213:15628
1.32.250.227:15628

image

handle

image
image

标签:Foundation,27.124,startLogging,fde,15628,dll,TG
From: https://www.cnblogs.com/DirWang/p/17052678.html

相关文章