Ò»³¡Ëµ×ß¾Í×ߵġ°Ó¦¼±¡±Ðж¯¡ª¡ªÄ³Ê¯»¯¹«Ë¾ÔâÍڿ󲡶¾Ï°È¾ºóµÄ48Ó×ʱ
°ä²¼¹¦·ò 2019-05-23¡°µÎÁåÁåÁå~~~¡±GA»Æ½ð¼×¹¤Òµ»¥ÁªÍøÊÂÒµ²¿¹¤³ÌʦµÄµç»°ÏìÆð£¡
¡°ÎÒÃÇÁ½Ì׺áºÓDCSϵͳµÄ²Ù×÷Թؾ¡¢¹¤³ÌʦվºÍOPC·þÎñÆ÷µÄÖ÷»úºöÈ»À¶ÆÁ£¡³ÁÐÂÆô¶¯ÏµÍ³ºó£¬ÒÀÈ»ÎÞ·¨¸´Ô£¬×·Çó´¹Î£¼¼ÊõÔöÔ®£¡¡±
À´×Ôijʯ»¯¹«Ë¾Òǿز¿µÄ¹¤×÷ÈËÔ±µç»°ÀïµÄÉùÒôÒì³£¼±´Ù¡¡
½â¾ö¿Í»§µÄÍøÂ簲ȫÎÊÌ⣬¾ÍÊÇGA»Æ½ð¼×ʹÃü£¡
GA»Æ½ð¼×¹¤Òµ»¥ÁªÍø°²È«ÊÂÒµ²¿½áºÏGA»Æ½ð¼×¼¯ÍÅÆìϳ½ÐÅÁì´´¹«Ë¾µ±¼´×齨5ÈËרÏîÓ××飬ҵÎñ¡¢¼¼Êõ¡¢²úÆ·¶úĿԱ»ð¿ì¿ªÆô½Ó¼ÃÐж¯£¬Ô¶³ÌÁìµ¼¿Í»§½øÐÐϵͳ½Ó¼Ã¼°±£»¤ÏÖ³¡²¡¶¾Ñù±¾Êý¾Ý¡£
5ÔÂ11ÈÕÁ賿1:00
½Ó¼Ã¹¤×÷Õù·Ö¶àÃ룬Àú¾3¸öÓ×ʱµÄÔ¶³ÌÖ§³Öºó£¬¸ù»ùÈ·¶¨ÊÂÎñÔÓÉÓÚMsraMiner²¡¶¾Ï°È¾¡£
Ô¶³ÌÖ§³Ö³ÖÐø½øÐУ¬µ«ÏÖ³¡Çé¿ö±ÈÁ¦ÌØÊ⣬˼¿¼µ½¹¤¿ØÏµÍ³µÄ¸´ÔÓÐÔ¼°DCSϵͳµÄרҵÐÔ£¬Ó¦¼±ÍŶӾö¶¨³Ë×øµ±ÈÕ×îÔ纽°à·ÉÍù¿Í»§ÏÖ³¡¡£
5ÔÂ11ÈÕÔç6:40
Í×Í×µØÒ»³¡Ëµ×ß¾Í×ßµÄÓ¦¼±·þÎñ¡£
¾¹ý48Ó×ʱµÄ²»Ð¸ÖÂÁ¦£¬ÏµÍ³µÃµ½Á˽¨¸´£¬¿Í»§µÄ³ö²úÆëÈ«¸´ÔÁËÕý³£¡£¿Í»§¸øÓ¦¼±ÍŶӷ¢À´ÁËÕæ³ÏµÄ¸Ð¼¤ÐÅ£¬²¢Ô¼ÇëÇдèºóÆÚµÄ¼Ó¹Ì´ëÊ©ÓëºÏ×÷¡£
ÊÂÎñ·ÖÎö
ƾ¾Ý¶Ô²é¿´ÏÖ³¡»·¾³ÒÔ¼°ÏµÍ³ÖÐÊý¾Ý·ÖÎö£¬ÍøÂçÖеÄÖ÷»úÈ·ÒÔΪMsraMinerÍڿ󲡶¾µÄ±äÖÖ²¡¶¾Ï°È¾£¬´ËÍڿ󲡶¾ÀûÓá°ÓÀºãÖ®À¶¡±·ì϶½øÐд«²¼£¬ÔÚ´«²¼¹ý³ÌÖУ¬ÓÉÓÚÔÚWindows XPϵͳÉÏ·ì϶ÀûÓÃʧ°Ü£¬µ¼Ö»úеÀ¶ÆÁ¡£Æä²¡¶¾·ÛËéµÀÀíΪ£º
Íڿ󲡶¾MsraMine×îбäÖֵIJ¡¶¾Ä¸ÌåÔËÐкó¿ªÊÍ·þÎñÄ£¿é£¬¿ªÊ͵ķþÎñÄ£¿éÃû³ÆËæ»úÆ´´Õ£¬ÌìÉúXXX.dll£¬·þÎñÃû³ÆºÍ¿ªÊ͵ķþÎñdllÎļþÃû³ÆÒ»Ñù¡£
²¡¶¾·þÎñÃû×Ö»áÆ¾¾ÝÌìÉúµÄdllÃû×Ö¶¨Ãû£¬µ«ÊÇÆäÃèÊöͨ³£¶¼ÎªEnable a commin infterace and object xxxx²¡¶¾Îļþ£¬²¢½«¹¥»÷C:\Windows\NetworkDistribution Ŀ¼ÏÂËùÓÐÎļþ£¨¹¥»÷µÄÖØÒªÎļþ£©£¬Ö÷ÍÚ¿óÎļþC:\Windows\system32\dllhostex.exe£¨»òÆäËû±»×¢ÈëµÄsvchostµÄ×Ó¹ý³Ì£©¡£
Áí±íÌØÑ¡ÔñÆäÖÐÒ»¸öIP²é¿´ÆäÈ«Êý»á»°£¬²¢¶ÔÆäÏνӶ˿ڽøÐÐͳ¼Æ£¬³ý445¶Ë¿Ú±í£¬26931¡¢45560¶Ë¿ÚÏνÓÁ¿Õ¼±ÈÒ²Ï൱¿É¹Û£¬²¢ÇҸö˿ڲ»ÊôÓÚÕý³£ÒµÎñËùÐè¶Ë¿Ú¡£Ëæ¼´¶Ô¸ÃÖ÷»úµÄ±¾µØÎļþÓë¹ý³Ì½øÐе÷²éºÍ·ÖÎö£¬·¢ÏÖ´óÁ¿¶ñÒâÎļþ¡£ ¾¹ý¶ÈÎöÅжϣ¬26931¡¢45560Á½¸ö¶Ë¿Ú±ðÀëΪWebserver¶Ë¿ÚºÍ¿ó³ØÏνӶ˿ڡ£ÆäÖÐWebserverÌṩÏàÓ¦×é¼þÏÂÔØ£¬ÍÚ¿ó¹ý³ÌΪ¡°TrustedHostServices.exe¡±¡£
²¡¶¾µÄϰȾÁ÷³ÌΪ£ºÊܺ¦Ö÷»úij¹¤³ÌʦվÖеIJ¡¶¾·¨Ê½Ô̺¬Á½²¿ÃÅ£¬±ðÀëΪ¹¥»÷·¨Ê½ÒÔ¼°¡°ÍÚ¿ó¡±·¨Ê½¡£ÆäÖй¥»÷·¨Ê½»á¿ªÊͳö¡°ÓÀºãÖ®À¶¡±·¨Ê½£¬Í¬Ê±´î½¨web·þÎñÆ÷£¬Í¨¹ýGA»Æ½ð¼×µÄTSOC-NBAÄܹ»·¢ÏÖÊܺ¦Ö÷»ú¹¤³ÌʦվÏòÊܺ¦Ö÷»ú²Ù×÷ԹؾÒÔ¼°OPC·þÎñµÄ445¶Ë¿ÚÌáÒé¹¥»÷£¬±»Ï°È¾²¡¶¾µÄÖ÷»úÏòÊܺ¦Ö÷»úµÄweb·þÎñÆ÷26931¶Ë¿ÚÌáÒéÏÂÔØÒªÇó£¬
ÒªÇóÄÚÈÝΪMsraReportDataCache32.tlb£¬¸Ã·¨Ê½»á¿ªÊͳö¹¥»÷·¨Ê½ÒÔ¼°¡°ÍÚ¿ó¡±·¨Ê½£»Í¬Ê±£¬ÍÚ¿ó¹ý³ÌTrusted Host Services . exe½øÐÐÍÚ¿ó£¬Óë¿ó³Øxmr.pool. minergate . com: 45560 ³ÉÁ¢Ïνӣ¬·¨Ê½ÔËÐÐÆÚ¼ä»á½Ó¼ûÏàÓ¦µÄdomainÒÔ½øÐз¨Ê½¸üÐÂÓë¿ó³ØÏνӣ¬ÔÚÏνÓʧ°Üºóµ¼ÖÂϵͳÀ¶ÆÁ¡£
½â¾ö¹æ»®
1¡¢Ó¦¼±´¦ÖãºÊÖ¹¤¶Ï¸ù
2) ¹Ø¹Ø445£¬139£¬135¡¢3389µÈ¶Ë¿Ú·þÎñ£»
3) ɾ³ýÃèÊöΪEnable a commin infterace and object xxxxµÄ·þÎñ£»
4) ɾ³ý´Ë·þÎñ¶ÔÓ¦µÄ¶¯Ì¬Á´½Ó¿âÎļþ£»
5) ʵÏÖsvchost.exe¹ý³Ì£¨TaskIndexer.exe»òdllhostex.exe¹ý³ÌµÄ¸¸¹ý³Ì£©£»
6) ʵÏÖTaskIndexer.exe»òdllhostex.exe¹ý³Ì£¬²¢É¾³ýÆäÎļþ£»
7) ɾ³ýC:\Windows\NetworkDistributionĿ¼ÏÂËùÓÐÎļþ£»
8) ×°ÖÃɱ¶¾Èí¼þά³Ö·ÀÓù¿ªÆô£¬ÊµÊ±Éý¼¶²¡¶¾¿â¡£
ÊÖ¶¯×°Öá°ÓÀºãÖ®À¶¡±·ì϶²¹¶¡Çë½Ó¼ûÒÔÏÂÒ³Ãæ£º
https://technet.microsoft.com/zh-cn/library/security/ms17-010.aspx
http://www.catalog.update.microsoft.com/search.aspx?q=kb4012212
ÆäÖÐWinXP£¬Windows Server 2003Óû§Çë½Ó¼û£º
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4012598
²¿Ãʤ¾ß£º
GA»Æ½ð¼×µÄÓÀºãÖ®À¶ÈȽ¨¸´¹¤¾ß
GA»Æ½ð¼×PChunter¶ñÒâÈí¼þÊÖ¹¤¼ì²â¹¤¾ß
2¡¢¹¤¿ØÏµÍ³×¨Òµ²éɱ¹¤¾ß
¹¤Òµ½ÚÔìϵͳÔÚ·À²¡¶¾½¨ÉèÉÏÆÕ±é´æÔÚ£ºÉ豸»úÄܯձ鯫µÍ¡¢windowsÀϰ汾²Ù×÷ϵͳ¾Ó¶à¡¢Ó²¼þ»òÒµÎñÈí¼þÔÚÖ´ÐзÀ²¡¶¾ºó²»µÃÊÜÈκÎÓ°Ïì¡¢·À²¡¶¾Èí¼þ±ØÐë¿ÉÄÜÓÐЧ·ÀÓù²¡¶¾µÈÎÊÌ⣬GA»Æ½ð¼×ΪÂú×㹤¿ØÐÐÒµ·À²¡¶¾ÐèÒª£¬Ñз¢³ö¾°Ôư²È«ÄÜÁ¦ÇáÁ¿»¯¹¤¿Ø·À»¤°æ¡£Ñ¡È¡È«³ÌÎÞÇý¶¯ÎÞhook¡¢Ö»É¨²»É±ÒÔ¼°¹ý³Ì/ÍøÂç°×Ãûµ¥µÈÇкϹ¤¿Ø»·¾³µÄ»úÔ죬ԮÊÖ¹¤¿ØÆóÒµÔÚ·ÀÓù¸÷ÀàÐÂÐͲ¡¶¾ºÍÈ䳿µÄ¹¥»÷µÄͬʱ£¬¿ÉÄÜÁ½È«¹¤¿ØÉ豸µÄ²»±äÔËÐУ¬±£ÏÕÓû§ÒµÎñ¡£
1) ¼¯ÖйܿأºÍ¨¹ý¾°ÔƼ¶ÁªÖÐ¿ØÆ½Ì¨£¬Ìṩ¿ÉÉìËõµÄ¿çƽ̨²¡¶¾·À»¤£¬¼¯Öйܿظ÷¼¶¸÷Àà·ºÖÕ¶Ë£¬Âú×ãÆóÒµ¼¶Óû§¶Ô·À²¡¶¾Èí¼þͳһÖÎÀíµÄÐèÒª¡£
2) º£Á¿ÔƲ飺¿ÉΪÓû§°´Ð趨ÔìÔÆÖªÊ¶¿â£¬ÖÇÄÜ×ÔÔËÓªÔÆ¶Ë²¡¶¾Ìص㣬ʹÓû§ÔÚÕ¼ÓеÈͬÓÚ¹«ÓÐÔÆµÄ²¡¶¾²éɱÄÜÁ¦µÄͬʱ£¬ÓÖͨ¹ý˽Óл¯µÄ·½Ê½³¹µ×¶Å¾øÊý¾Ýй¶¡£
3) ÖÇÄܼø¶¾£º½«»úе½ø½¨ºÍ´óÊý¾Ý²½ÖèÈÚÈëµ½·À²¡¶¾ÏµÍ³ÖУ¬¿ÉÄÜΪ´óÐÍÓû§ÊµÏÖ×Ô¶¯µÄÑù±¾²¶»ñ¡¢Ñù±¾·ÖÀà¡¢Ñù±¾ÌصãÌáÈ¡¡¢²¡¶¾¿â¸üÐÂÁ÷³Ì£¬ÒÔ±ã¿ÉÄܼ±¾çÏìÓ¦»¥ÁªÍø²ã³ö²»ÇîµÄÍÆËã»ú²¡¶¾¡£
4) ǿЧ»úÄÜ£ºÔÚ½µµÍÓû§ÖÕ¶Ë×ÊÔ´¿÷Ëðͬʱ£¬½áºÏÈËΪÖÇÄܺʹóÊý¾Ý¼¼Êõ£¬ÄÜʹ²¡¶¾²éɱ¸üѸ¿ì¡¢¸ü¾«×¼¡£¿ÉÄÜÓÐЧ·ÀÓù×îÊ¢ÐеIJ¡¶¾Ä¾Âí¡¢ºÚ¿ÍÈëÇÖºÍ0day¡¢APTµÈδ֪Íþв£¬¸üÓÐÀûÓÚÖ´ÐУ¬¸ü·½±ã×°ÖúÍÊØ»¤¡£
5) ÖÇÄÜ×Ô½ø½¨£ºÍ¨¹ý¼´Ê±È¡Ñù¡¢º¹ÇàÊý¾Ý·ÖÎö¡¢¶à¹æ¶¨¹é²¢µÈ·½Ê½³ÉÁ¢¹ý³Ì/ÍøÂç°×Ãûµ¥¹æ¶¨¡£ÔÚÉ趨³ß¶ÈÉ豸֮ºó£¬¾°ÔÆÖ§³Ö×Ô¶¯µ÷Õû¹æ¶¨ÄÚÈÝÒÔÊÊÓ¦ÒµÎñϵͳÉý¼¶Ôì³ÉµÄ°×Ãûµ¥ÁбíÀ©ÈݵÈÐèÒª£¬Ô®ÊÖÓû§¼±¾ç³ÉÁ¢ÇкÏ×ÔÉí¹¤¿Ø»·¾³µÄ°×Ãûµ¥¡£
3¡¢Ö÷»ú¼Ó¹Ì
ѡȡGA»Æ½ð¼×µÄ¡°Ìì«‘ÄÚÍø°²È«·çÏÕÖÎÀíÓëÉó¼ÆÏµÍ³¡±£¬Ö°ÄÜÈçͼ£º
°²È«ÎÞÓ×ÊÂ
Ïò·Ü¶·ÔÚÒ»ÏßµÄÓ¦¼±·þÎñÈËÔ±Ö¾´£¡


¾©¹«Íø°²±¸11010802024551ºÅ