2020-06-02
Ðû²¼Ê±¼ä 2020-06-03ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂí_ViSystem.Stealer_ÅþÁ¬C2ЧÀÍÆ÷ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½ ViSystemľÂí ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËViSystemľÂí ¡£¡£¡£¡£¡£ ViSystemľÂíÊÇÒ»¸öÇÔÃÜÐÍľÂí£¬£¬£¬Ëü»áÇÔÈ¡Êܺ¦ÕßÉúÑÄÔÚ×ÀÃæµÄÎļþ(.doc¡¢.docx¡¢.pdf¡¢.txt¡¢.json¡¢.rdp)¡¢ä¯ÀÀÆ÷Êý¾Ý(µÇ¼ƾ֤ÐÅÏ¢¡¢Cookie¡¢ÀúÊ·¼Í¼)¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢FTPÈí¼þµÇ¼ƾ֤µÈ¡£¡£¡£¡£¡£ÁíÍ⣬£¬£¬ViSystem Äܹ»Ö´ÐÐÔ¶³ÌЧÀÍÆ÷Ï·¢µÄC2Ö¸Á£¬£¬Ö÷ÒªÖ¸ÁîÓУº¸üС¢ÏÂÔØÎļþÖ´ÐС£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200602 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_CobaltStrike.Stager_ÅþÁ¬C2ЧÀÍÆ÷ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄºóÃÅ Stager ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£¡£¡£¡£¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉʹÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úе£¬£¬£¬²¢¾ÙÐкáÏòÒÆ¶¯¡£¡£¡£¡£¡£ CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½ÐͬºóÉøÍ¸¹¥»÷¿ò¼Ü¡£¡£¡£¡£¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socketÊðÀí¡¢ÌáȨ¡¢´¹ÂÚ¡¢Ô¶¿ØÄ¾ÂíµÈ¹¦Ð§¡£¡£¡£¡£¡£¸Ã¹¤¾ßÏÕЩÁýÕÖÁËAPT¹¥»÷Á´ÖÐËùÐèÒªÓõ½µÄ¸÷¸öÊÖÒÕ»·½Ú£¬£¬£¬ÉîÊܺڿÍÃǵÄϲ»¶¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200602 |
|
ÊÂÎñÃû³Æ£º |
HTTP_Nginx+PHP_fpmÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-11043] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃNginx+PHP_fpmÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200602 |
ÐÞ¸ÄÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_ºóÃÅ_phpStudy¹¥»÷ʵÑé_ÅþÁ¬ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½¹¥»÷ÕßÔÚÏòʹÓÃphpStudyµÄÍøÕ¾·¢ËÍÌØ¶¨Ãü¾Ý£¬£¬£¬ÒÔ´¥·¢¶ñÒâºóÃŹ¦Ð§¡£¡£¡£¡£¡£ ÖøÃûµÄPHPµ÷ÊÔÇéÐγÌÐò¼¯³É°üphpStudyÈí¼þ±»¸Ä¶¯Ö²ÈëÁ˺óÃÅ¡£¡£¡£¡£¡£¹¥»÷ÕßÌæ»»ÁËphp_xmlrpc.dllʵÏÖºóÃÅ´úÂëµÄÖ²ÈëºÍפÁô¡£¡£¡£¡£¡£¹¥»÷ÕßÏòʹÓÃÁ˱»¸Ä¶¯µÄphpStudyµÄÍøÕ¾·¢ËÍÌØ¶¨Ãü¾Ý£¬£¬£¬¼´¿É´¥·¢ºóÃÅÖ´ÐС£¡£¡£¡£¡£ºóÃŹ¦Ð§Ö÷ÒªÎªÍøÂçÓû§ÐÅÏ¢¡¢Ö´ÐÐC£¦C¶Ë¹¥»÷ÕßÏ·¢µÄÔ¶³ÌPHP¾ç±¾¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200602 |
|
ÊÂÎñÃû³Æ£º |
HTTP_Coremail_ÉèÖÃÐÅϢй¶Îó²î[CNVD-2019-16798] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÕýÔÚʹÓÃCoremail_ÉèÖÃÐÅϢй¶Îó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200602 |


¾©¹«Íø°²±¸11010802024551ºÅ