Ò»³¡Ëµ×ß¾Í×ߵġ°Ó¦¼±¡±Ðж¯¡ª¡ªÄ³Ê¯»¯¹«Ë¾ÔâÍڿ󲡶¾Ï°È¾ºóµÄ48Ó×ʱ

°ä²¼¹¦·ò 2019-05-23
5ÔÂ10ÈÕ22:00


¡°µÎÁåÁåÁå~~~¡±GA»Æ½ð¼×¹¤Òµ»¥ÁªÍøÊÂÒµ²¿¹¤³ÌʦµÄµç»°ÏìÆð£¡

¡°ÎÒÃÇÁ½Ì׺áºÓDCSϵͳµÄ²Ù×÷Թؾ¡¢¹¤³ÌʦվºÍOPC·þÎñÆ÷µÄÖ÷»úºöÈ»À¶ÆÁ£¡³ÁÐÂÆô¶¯ÏµÍ³ºó£¬ÒÀÈ»ÎÞ·¨¸´Ô­£¬×·Çó´¹Î£¼¼ÊõÔöÔ®£¡¡±

À´×Ôijʯ»¯¹«Ë¾Òǿز¿µÄ¹¤×÷ÈËÔ±µç»°ÀïµÄÉùÒôÒì³£¼±´Ù¡­¡­

½â¾ö¿Í»§µÄÍøÂ簲ȫÎÊÌ⣬¾ÍÊÇGA»Æ½ð¼×ʹÃü£¡

GA»Æ½ð¼×¹¤Òµ»¥ÁªÍø°²È«ÊÂÒµ²¿½áºÏGA»Æ½ð¼×¼¯ÍÅÆìϳ½ÐÅÁì´´¹«Ë¾µ±¼´×齨5ÈËרÏîÓ××飬ҵÎñ¡¢¼¼Êõ¡¢²úÆ·¶úĿԱ»ð¿ì¿ªÆô½Ó¼ÃÐж¯£¬Ô¶³ÌÁìµ¼¿Í»§½øÐÐϵͳ½Ó¼Ã¼°±£»¤ÏÖ³¡²¡¶¾Ñù±¾Êý¾Ý¡£


5ÔÂ11ÈÕÁ賿1:00


½Ó¼Ã¹¤×÷Õù·Ö¶àÃ룬Àú¾­3¸öÓ×ʱµÄÔ¶³ÌÖ§³Öºó£¬¸ù»ùÈ·¶¨ÊÂÎñÔ­ÓÉÓÚMsraMiner²¡¶¾Ï°È¾¡£

Ô¶³ÌÖ§³Ö³ÖÐø½øÐУ¬µ«ÏÖ³¡Çé¿ö±ÈÁ¦ÌØÊ⣬˼¿¼µ½¹¤¿ØÏµÍ³µÄ¸´ÔÓÐÔ¼°DCSϵͳµÄרҵÐÔ£¬Ó¦¼±ÍŶӾö¶¨³Ë×øµ±ÈÕ×îÔ纽°à·ÉÍù¿Í»§ÏÖ³¡¡£


5ÔÂ11ÈÕÔç6:40


Í×Í×µØÒ»³¡Ëµ×ß¾Í×ßµÄÓ¦¼±·þÎñ¡£
 
¾­¹ý48Ó×ʱµÄ²»Ð¸ÖÂÁ¦£¬ÏµÍ³µÃµ½Á˽¨¸´£¬¿Í»§µÄ³ö²úÆëÈ«¸´Ô­ÁËÕý³£¡£¿Í»§¸øÓ¦¼±ÍŶӷ¢À´ÁËÕæ³ÏµÄ¸Ð¼¤ÐÅ£¬²¢Ô¼ÇëÇдèºóÆÚµÄ¼Ó¹Ì´ëÊ©ÓëºÏ×÷¡£
 
GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 


ÊÂÎñ·ÖÎö


ƾ¾Ý¶Ô²é¿´ÏÖ³¡»·¾³ÒÔ¼°ÏµÍ³ÖÐÊý¾Ý·ÖÎö£¬ÍøÂçÖеÄÖ÷»úÈ·ÒÔΪMsraMinerÍڿ󲡶¾µÄ±äÖÖ²¡¶¾Ï°È¾£¬´ËÍڿ󲡶¾ÀûÓá°ÓÀºãÖ®À¶¡±·ì϶½øÐд«²¼£¬ÔÚ´«²¼¹ý³ÌÖУ¬ÓÉÓÚÔÚWindows XPϵͳÉÏ·ì϶ÀûÓÃʧ°Ü£¬µ¼Ö»úеÀ¶ÆÁ¡£Æä²¡¶¾·ÛËéµÀÀíΪ£º

Íڿ󲡶¾MsraMine×îбäÖֵIJ¡¶¾Ä¸ÌåÔËÐкó¿ªÊÍ·þÎñÄ£¿é£¬¿ªÊ͵ķþÎñÄ£¿éÃû³ÆËæ»úÆ´´Õ£¬ÌìÉúXXX.dll£¬·þÎñÃû³ÆºÍ¿ªÊ͵ķþÎñdllÎļþÃû³ÆÒ»Ñù¡£
 
GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 ²¡¶¾·þÎñÃû×Ö»áÆ¾¾ÝÌìÉúµÄdllÃû×Ö¶¨Ãû£¬µ«ÊÇÆäÃèÊöͨ³£¶¼ÎªEnable a commin infterace and object xxxx²¡¶¾Îļþ£¬²¢½«¹¥»÷C:\Windows\NetworkDistribution Ŀ¼ÏÂËùÓÐÎļþ£¨¹¥»÷µÄÖØÒªÎļþ£©£¬Ö÷ÍÚ¿óÎļþC:\Windows\system32\dllhostex.exe£¨»òÆäËû±»×¢ÈëµÄsvchostµÄ×Ó¹ý³Ì£©¡£
 
Áí±íÌØÑ¡ÔñÆäÖÐÒ»¸öIP²é¿´ÆäÈ«Êý»á»°£¬²¢¶ÔÆäÏνӶ˿ڽøÐÐͳ¼Æ£¬³ý445¶Ë¿Ú±í£¬26931¡¢45560¶Ë¿ÚÏνÓÁ¿Õ¼±ÈÒ²Ï൱¿É¹Û£¬²¢ÇҸö˿ڲ»ÊôÓÚÕý³£ÒµÎñËùÐè¶Ë¿Ú¡£Ëæ¼´¶Ô¸ÃÖ÷»úµÄ±¾µØÎļþÓë¹ý³Ì½øÐе÷²éºÍ·ÖÎö£¬·¢ÏÖ´óÁ¿¶ñÒâÎļþ¡£ ¾­¹ý¶ÈÎöÅжÏ£¬26931¡¢45560Á½¸ö¶Ë¿Ú±ðÀëΪWebserver¶Ë¿ÚºÍ¿ó³ØÏνӶ˿Ú¡£ÆäÖÐWebserverÌṩÏàÓ¦×é¼þÏÂÔØ£¬ÍÚ¿ó¹ý³ÌΪ¡°TrustedHostServices.exe¡±¡£
 
²¡¶¾µÄϰȾÁ÷³ÌΪ£ºÊܺ¦Ö÷»úij¹¤³ÌʦվÖеIJ¡¶¾·¨Ê½Ô̺¬Á½²¿ÃÅ£¬±ðÀëΪ¹¥»÷·¨Ê½ÒÔ¼°¡°ÍÚ¿ó¡±·¨Ê½¡£ÆäÖй¥»÷·¨Ê½»á¿ªÊͳö¡°ÓÀºãÖ®À¶¡±·¨Ê½£¬Í¬Ê±´î½¨web·þÎñÆ÷£¬Í¨¹ýGA»Æ½ð¼×µÄTSOC-NBAÄܹ»·¢ÏÖÊܺ¦Ö÷»ú¹¤³ÌʦվÏòÊܺ¦Ö÷»ú²Ù×÷ԹؾÒÔ¼°OPC·þÎñµÄ445¶Ë¿ÚÌáÒé¹¥»÷£¬±»Ï°È¾²¡¶¾µÄÖ÷»úÏòÊܺ¦Ö÷»úµÄweb·þÎñÆ÷26931¶Ë¿ÚÌáÒéÏÂÔØÒªÇó£¬

ÒªÇóÄÚÈÝΪMsraReportDataCache32.tlb£¬¸Ã·¨Ê½»á¿ªÊͳö¹¥»÷·¨Ê½ÒÔ¼°¡°ÍÚ¿ó¡±·¨Ê½£»Í¬Ê±£¬ÍÚ¿ó¹ý³ÌTrusted Host Services . exe½øÐÐÍÚ¿ó£¬Óë¿ó³Øxmr.pool. minergate . com: 45560 ³ÉÁ¢ÏνÓ£¬·¨Ê½ÔËÐÐÆÚ¼ä»á½Ó¼ûÏàÓ¦µÄdomainÒÔ½øÐз¨Ê½¸üÐÂÓë¿ó³ØÏνÓ£¬ÔÚÏνÓʧ°Üºóµ¼ÖÂϵͳÀ¶ÆÁ¡£


½â¾ö¹æ»®


1¡¢Ó¦¼±´¦ÖãºÊÖ¹¤¶Ï¸ù



1) ×°ÖÃGA»Æ½ð¼×רÓÓ×°ÓÀºãÖ®À¶¡±²¹¶¡»òʹÓø½¼þÖеÄÈȲ¹¶¡¹¤¾ß£»
2) ¹Ø¹Ø445£¬139£¬135¡¢3389µÈ¶Ë¿Ú·þÎñ£»
3) ɾ³ýÃèÊöΪEnable a commin infterace and object xxxxµÄ·þÎñ£»
4) ɾ³ý´Ë·þÎñ¶ÔÓ¦µÄ¶¯Ì¬Á´½Ó¿âÎļþ£»
5) ʵÏÖsvchost.exe¹ý³Ì£¨TaskIndexer.exe»òdllhostex.exe¹ý³ÌµÄ¸¸¹ý³Ì£©£»
6) ʵÏÖTaskIndexer.exe»òdllhostex.exe¹ý³Ì£¬²¢É¾³ýÆäÎļþ£»
7) ɾ³ýC:\Windows\NetworkDistributionĿ¼ÏÂËùÓÐÎļþ£»
8) ×°ÖÃɱ¶¾Èí¼þά³Ö·ÀÓù¿ªÆô£¬ÊµÊ±Éý¼¶²¡¶¾¿â¡£
 
ÊÖ¶¯×°Öá°ÓÀºãÖ®À¶¡±·ì϶²¹¶¡Çë½Ó¼ûÒÔÏÂÒ³Ãæ£º
https://technet.microsoft.com/zh-cn/library/security/ms17-010.aspx
http://www.catalog.update.microsoft.com/search.aspx?q=kb4012212

ÆäÖÐWinXP£¬Windows Server 2003Óû§Çë½Ó¼û£º
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4012598

²¿Ãʤ¾ß£º
GA»Æ½ð¼×µÄÓÀºãÖ®À¶ÈȽ¨¸´¹¤¾ß
GA»Æ½ð¼×PChunter¶ñÒâÈí¼þÊÖ¹¤¼ì²â¹¤¾ß


2¡¢¹¤¿ØÏµÍ³×¨Òµ²éɱ¹¤¾ß


¹¤Òµ½ÚÔìϵͳÔÚ·À²¡¶¾½¨ÉèÉÏÆÕ±é´æÔÚ£ºÉ豸»úÄܯձ鯫µÍ¡¢windowsÀϰ汾²Ù×÷ϵͳ¾Ó¶à¡¢Ó²¼þ»òÒµÎñÈí¼þÔÚÖ´ÐзÀ²¡¶¾ºó²»µÃÊÜÈκÎÓ°Ïì¡¢·À²¡¶¾Èí¼þ±ØÐë¿ÉÄÜÓÐЧ·ÀÓù²¡¶¾µÈÎÊÌ⣬GA»Æ½ð¼×ΪÂú×㹤¿ØÐÐÒµ·À²¡¶¾ÐèÒª£¬Ñз¢³ö¾°Ôư²È«ÄÜÁ¦ÇáÁ¿»¯¹¤¿Ø·À»¤°æ¡£Ñ¡È¡È«³ÌÎÞÇý¶¯ÎÞhook¡¢Ö»É¨²»É±ÒÔ¼°¹ý³Ì/ÍøÂç°×Ãûµ¥µÈÇкϹ¤¿Ø»·¾³µÄ»úÔ죬ԮÊÖ¹¤¿ØÆóÒµÔÚ·ÀÓù¸÷ÀàÐÂÐͲ¡¶¾ºÍÈ䳿µÄ¹¥»÷µÄͬʱ£¬¿ÉÄÜÁ½È«¹¤¿ØÉ豸µÄ²»±äÔËÐУ¬±£ÏÕÓû§ÒµÎñ¡£

1) ¼¯ÖйܿأºÍ¨¹ý¾°ÔƼ¶ÁªÖÐ¿ØÆ½Ì¨£¬Ìṩ¿ÉÉìËõµÄ¿çƽ̨²¡¶¾·À»¤£¬¼¯Öйܿظ÷¼¶¸÷Àà·ºÖÕ¶Ë£¬Âú×ãÆóÒµ¼¶Óû§¶Ô·À²¡¶¾Èí¼þͳһÖÎÀíµÄÐèÒª¡£

2) º£Á¿ÔƲ飺¿ÉΪÓû§°´Ð趨ÔìÔÆÖªÊ¶¿â£¬ÖÇÄÜ×ÔÔËÓªÔÆ¶Ë²¡¶¾Ìص㣬ʹÓû§ÔÚÕ¼ÓеÈͬÓÚ¹«ÓÐÔÆµÄ²¡¶¾²éɱÄÜÁ¦µÄͬʱ£¬ÓÖͨ¹ý˽Óл¯µÄ·½Ê½³¹µ×¶Å¾øÊý¾Ýй¶¡£

3) ÖÇÄܼø¶¾£º½«»úе½ø½¨ºÍ´óÊý¾Ý²½ÖèÈÚÈëµ½·À²¡¶¾ÏµÍ³ÖУ¬¿ÉÄÜΪ´óÐÍÓû§ÊµÏÖ×Ô¶¯µÄÑù±¾²¶»ñ¡¢Ñù±¾·ÖÀà¡¢Ñù±¾ÌصãÌáÈ¡¡¢²¡¶¾¿â¸üÐÂÁ÷³Ì£¬ÒÔ±ã¿ÉÄܼ±¾çÏìÓ¦»¥ÁªÍø²ã³ö²»ÇîµÄÍÆËã»ú²¡¶¾¡£

4) ǿЧ»úÄÜ£ºÔÚ½µµÍÓû§ÖÕ¶Ë×ÊÔ´¿÷Ëðͬʱ£¬½áºÏÈËΪÖÇÄܺʹóÊý¾Ý¼¼Êõ£¬ÄÜʹ²¡¶¾²éɱ¸üѸ¿ì¡¢¸ü¾«×¼¡£¿ÉÄÜÓÐЧ·ÀÓù×îÊ¢ÐеIJ¡¶¾Ä¾Âí¡¢ºÚ¿ÍÈëÇÖºÍ0day¡¢APTµÈδ֪Íþв£¬¸üÓÐÀûÓÚÖ´ÐУ¬¸ü·½±ã×°ÖúÍÊØ»¤¡£

5) ÖÇÄÜ×Ô½ø½¨£ºÍ¨¹ý¼´Ê±È¡Ñù¡¢º¹ÇàÊý¾Ý·ÖÎö¡¢¶à¹æ¶¨¹é²¢µÈ·½Ê½³ÉÁ¢¹ý³Ì/ÍøÂç°×Ãûµ¥¹æ¶¨¡£ÔÚÉ趨³ß¶ÈÉ豸֮ºó£¬¾°ÔÆÖ§³Ö×Ô¶¯µ÷Õû¹æ¶¨ÄÚÈÝÒÔÊÊÓ¦ÒµÎñϵͳÉý¼¶Ôì³ÉµÄ°×Ãûµ¥ÁбíÀ©ÈݵÈÐèÒª£¬Ô®ÊÖÓû§¼±¾ç³ÉÁ¢ÇкÏ×ÔÉí¹¤¿Ø»·¾³µÄ°×Ãûµ¥¡£


3¡¢Ö÷»ú¼Ó¹Ì


ѡȡGA»Æ½ð¼×µÄ¡°Ìì«‘ÄÚÍø°²È«·çÏÕÖÎÀíÓëÉó¼ÆÏµÍ³¡±£¬Ö°ÄÜÈçͼ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ÕâÖ»ÊǶà¶àÓ¦¼±ÏìÓ¦¹¤×÷ÖеÄÒ»¼þ£¬GA»Æ½ð¼×ʼÖÕ½«¿Í»§µÄ°²È«·ÅÔÚÊ×룬ÔÚÃæ¶ÔÍ»·¢µÄÍøÂ簲ȫÊÂÎñʱ£¬¶ÔÖÅÒÔʵʱ¡¢×¨Òµ¡¢µ±Õæ¡¢¸ßЧµÄ̬¶È½â¾ö¿Í»§µÄÎÊÌ⣬ӮµÃÁ˿ͻ§¼«´óµÄÐÅÀµ¡£

°²È«ÎÞÓ×ÊÂ
Ïò·Ü¶·ÔÚÒ»ÏßµÄÓ¦¼±·þÎñÈËÔ±Ö¾´£¡