2020-06-02
°ä²¼¹¦·ò 2020-06-03ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂí_ViSystem.Stealer_ÏνÓC2·þÎñÆ÷ |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½ ViSystemľÂí ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËViSystemľÂí ¡£ ViSystemľÂíÊÇÒ»¸öÇÔÃÜÐÍľÂí£¬Ëü»áÇÔÈ¡Êܺ¦Õß±£ÁôÔÚ×ÀÃæµÄÎļþ(.doc¡¢.docx¡¢.pdf¡¢.txt¡¢.json¡¢.rdp)¡¢ä¯ÀÀÆ÷Êý¾Ý(µÇ¼ƾ֤ÐÅÏ¢¡¢Cookie¡¢º¹Çà¼Í¼)¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢FTPÈí¼þµÇ¼ƾ֤µÈ¡£Áí±í£¬ViSystem ¿ÉÄÜÖ´ÐÐÔ¶³Ì·þÎñÆ÷Ï·¢µÄC2Ö¸Áî£¬ÖØÒªÖ¸ÁîÓУº¸üС¢ÏÂÔØÎļþÖ´ÐС£ |
|
¸üй¦·ò£º |
20200602 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_CobaltStrike.Stager_ÏνÓC2·þÎñÆ÷ |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄºóÃÅ Stager ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÆëÈ«½ÚÔìÊܺ¦»úе£¬²¢½øÐкáÏòÒÆ¶¯¡£ CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½ÐͬºóÉøÈë¹¥»÷¿ò¼Ü¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socket´úÀí¡¢ÌáȨ¡¢´¹µö¡¢Ô¶¿ØÄ¾ÂíµÈÖ°ÄÜ¡£¸Ã¹¤¾ßÏÕЩ¸²¸ÇÁËAPT¹¥»÷Á´ÖÐËù±ØÒªÓõ½µÄ¸÷¸ö¼¼Êõ»·½Ú£¬ÉîÊܺڿÍÃǵÄϲ»¶¡£ |
|
¸üй¦·ò£º |
20200602 |
|
ÊÂÎñÃû³Æ£º |
HTTP_Nginx+PHP_fpmÔ¶³ÌºÅÁîÖ´Ðзì϶[CVE-2019-11043] |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃNginx+PHP_fpmÔ¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£ |
|
¸üй¦·ò£º |
20200602 |
Åú¸ÄÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_ºóÃÅ_phpStudy¹¥»÷³¢ÊÔ_ÏÎ½Ó |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½¹¥»÷ÕßÔÚÏòʹÓÃphpStudyµÄÍøÕ¾·¢ËÍÌØ¶¨Êý¾Ý£¬ÒÔ´¥·¢¶ñÒâºóÃÅÖ°ÄÜ¡£ ³ÛÃûµÄPHPµ÷ÊÔ»·¾³·¨Ê½¼¯³É°üphpStudyÈí¼þ±»´Û¸ÄÖ²ÈëÁ˺óÃÅ¡£¹¥»÷Õß´úÌæÁËphp_xmlrpc.dllʵÏÖºóÃÅ´úÂëµÄÖ²ÈëºÍפÁô¡£¹¥»÷ÕßÏòʹÓÃÁ˱»´Û¸ÄµÄphpStudyµÄÍøÕ¾·¢ËÍÌØ¶¨Êý¾Ý£¬¼´¿É´¥·¢ºóÃÅÖ´ÐС£ºóÃÅÖ°ÄÜÖØÒªÎªÍøÂçÓû§ÐÅÏ¢¡¢Ö´ÐÐC£¦C¶Ë¹¥»÷ÕßÏ·¢µÄÔ¶³ÌPHP¾ç±¾¡£ |
|
¸üй¦·ò£º |
20200602 |
|
ÊÂÎñÃû³Æ£º |
HTTP_Coremail_ÅäÏàÐÅϢй¶·ì϶[CNVD-2019-16798] |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÔÚÀûÓÃCoremail_ÅäÏàÐÅϢй¶·ì϶½øÐй¥»÷µÄÐÐΪ¡£ |
|
¸üй¦·ò£º |
20200602 |


¾©¹«Íø°²±¸11010802024551ºÅ