2020-08-18

°ä²¼¹¦·ò 2020-08-19

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

DNS_ľÂíºóÃÅ_CobaltStrike.Stager_´úÂëÏÂÔØÖ´ÐÐ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄºóÃÅ Stager ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÆëÈ«½ÚÔìÊܺ¦»úе£¬²¢½øÐкáÏòÒÆ¶¯¡£

¸üй¦·ò£º

20200818



ÊÂÎñÃû³Æ£º

HTTP_APT¹¥»÷_Higaisa_LNKÎļþ¹¥»÷_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

Higaisa APTÓ볯Ïʰ뵺ÓйØ£¬ÓÚ2019Äê³õ´ÎÅû¶¡£¸ÃÓ××éµÄ»î¶¯Äܹ»×·Òäµ½2016Äê£¬ÖØÒªÊ¹ÓÃľÂí£¨ÀýÈçGh0stºÍPlugX£©ÒÔ¼°Òƶ¯¶ñÒâÈí¼þµÈ¹¤¾ß¡£ÆäÖ¸±êÔ̺¬µ±¾Ö¹ÙÔ±ºÍÈËȨ×éÖ¯£¬ÒÔ¼°Ó볯ÏÊÓÐ¹ØµÄÆäËûʵÌå¡£

¸üй¦·ò£º

20200818


ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_URLDNS_ÀûÓÃÁ´¹¥»÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCommonsCollections1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£

¸üй¦·ò£º

20200818


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win32.Meterpreter_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼÏòÖ÷ÕÅIPÖ÷»ú´«ÊäºóÃÅ¡£

¸üй¦·ò£º

20200818


ɾ³ýÊÂÎñ


1¡¢HTTP_jenkins_fromtwitter_Ô¶³Ì´úÂëÖ´Ðзì϶