2020-06-02

°ä²¼¹¦·ò 2020-06-03

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_ViSystem.Stealer_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ ViSystemľÂí ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËViSystemľÂí ¡£

ViSystemľÂíÊÇÒ»¸öÇÔÃÜÐÍľÂí£¬Ëü»áÇÔÈ¡Êܺ¦Õß±£ÁôÔÚ×ÀÃæµÄÎļþ(.doc¡¢.docx¡¢.pdf¡¢.txt¡¢.json¡¢.rdp)¡¢ä¯ÀÀÆ÷Êý¾Ý(µÇ¼ƾ֤ÐÅÏ¢¡¢Cookie¡¢º¹Çà¼Í¼)¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢FTPÈí¼þµÇ¼ƾ֤µÈ¡£Áí±í£¬ViSystem ¿ÉÄÜÖ´ÐÐÔ¶³Ì·þÎñÆ÷Ï·¢µÄC2Ö¸Áî£¬ÖØÒªÖ¸ÁîÓУº¸üС¢ÏÂÔØÎļþÖ´ÐС£

¸üй¦·ò£º

20200602












ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_CobaltStrike.Stager_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄºóÃÅ Stager ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÆëÈ«½ÚÔìÊܺ¦»úе£¬²¢½øÐкáÏòÒÆ¶¯¡£

CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½Ð­Í¬ºóÉøÈë¹¥»÷¿ò¼Ü¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socket´úÀí¡¢ÌáȨ¡¢´¹µö¡¢Ô¶¿ØÄ¾ÂíµÈÖ°ÄÜ¡£¸Ã¹¤¾ßÏÕЩ¸²¸ÇÁËAPT¹¥»÷Á´ÖÐËù±ØÒªÓõ½µÄ¸÷¸ö¼¼Êõ»·½Ú£¬ÉîÊܺڿÍÃǵÄϲ»¶¡£

¸üй¦·ò£º

20200602














ÊÂÎñÃû³Æ£º

HTTP_Nginx+PHP_fpmÔ¶³ÌºÅÁîÖ´Ðзì϶[CVE-2019-11043]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃNginx+PHP_fpmÔ¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£

¸üй¦·ò£º

20200602









Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_phpStudy¹¥»÷³¢ÊÔ_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½¹¥»÷ÕßÔÚÏòʹÓÃphpStudyµÄÍøÕ¾·¢ËÍÌØ¶¨Êý¾Ý£¬ÒÔ´¥·¢¶ñÒâºóÃÅÖ°ÄÜ¡£

³ÛÃûµÄPHPµ÷ÊÔ»·¾³·¨Ê½¼¯³É°üphpStudyÈí¼þ±»´Û¸ÄÖ²ÈëÁ˺óÃÅ¡£¹¥»÷Õß´úÌæÁËphp_xmlrpc.dllʵÏÖºóÃÅ´úÂëµÄÖ²ÈëºÍפÁô¡£¹¥»÷ÕßÏòʹÓÃÁ˱»´Û¸ÄµÄphpStudyµÄÍøÕ¾·¢ËÍÌØ¶¨Êý¾Ý£¬¼´¿É´¥·¢ºóÃÅÖ´ÐС£ºóÃÅÖ°ÄÜÖØÒªÎªÍøÂçÓû§ÐÅÏ¢¡¢Ö´ÐÐC£¦C¶Ë¹¥»÷ÕßÏ·¢µÄÔ¶³ÌPHP¾ç±¾¡£

¸üй¦·ò£º

20200602











ÊÂÎñÃû³Æ£º

HTTP_Coremail_ÅäÏàÐÅϢй¶·ì϶[CNVD-2019-16798]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÔÚÀûÓÃCoremail_ÅäÏàÐÅϢй¶·ì϶½øÐй¥»÷µÄÐÐΪ¡£

¸üй¦·ò£º

20200602