2020-08-25

°ä²¼¹¦·ò 2020-08-26

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_CobaltStrike_WebDelivery.py_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄ ºóÃÅpython¾ç±¾ ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPµØµãµÄÖ÷»ú¿ÉÄÜÖ´ÐÐÁËCobaltStrikeµÄpythonºóÃÅ¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÆëÈ«½ÚÔìÊܺ¦»úе £¬²¢½øÐкáÏòÒÆ¶¯¡£

¸üй¦·ò£º

20200825



ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_CobaltStrike.StagerX64_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄºóÃÅ StagerX64 ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.StagerX64¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÆëÈ«½ÚÔìÊܺ¦»úе £¬²¢½øÐкáÏòÒÆ¶¯¡£

¸üй¦·ò£º

20200825


ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_Samba_Ô¶³Ì´úÂëÖ´Ðзì϶_ÀûÓÃʧ°Ü[CVE-2017-7494][CNNVD-201705-1209]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»ú¶ÔÖ÷ÕÅIPÀûÓÃsamba·ì϶¹¥»÷µÄÐÐΪ¡£

¸üй¦·ò£º

20200825


ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_Samba_Ô¶³Ì´úÂëÖ´Ðзì϶_ÀûÓóɹ¦[CVE-2017-7494][CNNVD-201705-1209]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»ú¶ÔÖ÷ÕÅIPÀûÓÃsamba·ì϶¹¥»÷µÄÐÐΪ¡£

¸üй¦·ò£º

20200825


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Win32.Zebrocy.Downloader(APT28)_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ZebrocyÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËZebrocy¡£

¸üй¦·ò£º

20200825


ÊÂÎñÃû³Æ£º

HTTP_Apache_httpOnly_CookieÐÅϢй¶·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âÔ´IPÖ÷»úÕýÊÔͼͨ¹ýApache HTTP Server "httpOnly" CookieÐÅϢй¶·ì϶¹¥»÷Ö÷ÕÅIPµØÖ·Ö÷»ú¡£

¸üй¦·ò£º

20200825


ÊÂÎñÃû³Æ£º

HTTP_SQLÃýÎóÐÅϢй¶_2

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔIJÀûÓÃÖ÷ÕÅIPÖ÷»úµÄSQLÃýÎóÐÅÏ¢ £¬¿ÉÄÜÔì³ÉÐÅϢй¶¡£

¸üй¦·ò£º

20200825