ÍøÂç ¡°¹Ú×´²¡¶¾¡± |ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÍŽáCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶÓÐû²¼×îÐÂÑо¿±¨¸æ

Ðû²¼Ê±¼ä 2020-03-27

¸Å¿ö


Ëæ×Å¡°ÐÂÐ͹Ú×´²¡¶¾·ÎÑס±ÉÏÉýΪȫÇòÐÔ¹«¹²ÎÀÉúÍ»·¢ÊÂÎñ  £¬¸÷¹úÃñÖÚ¿ªÆôÁË¡°Õ¬¿¹Òß¡¢ÔÆÉúÑÄ¡±Ä£Ê½¡£ÔÚºÜÊÇʱÆÚ  £¬ÍøÂç¿Õ¼äÔÚÈËÃǵÄÒ»Ñùƽ³£ÉúÑıäµÃÔ½·¢²»¿É»òȱ  £¬È»¶øµ±¸÷È˶¼ÔÚ·ÜÁ¦¿¹ÒßµÄͬʱ  £¬´ó×ڵĺڿÍÈ´×îÏÈÒÔ¡°¹Ú×´²¡¶¾¡±ÃûÒå´ÓÊ´ó¹æÄ£µÄÍøÂç¹¥»÷Ô˶¯  £¬³ýÁËÏÖÔÚÒѾ­·¢Ã÷ÒÔ¹Ú×´²¡¶¾ÎªÃû¾ÙÐеÄAPT¹¥»÷¡¢ÀÕË÷²¡¶¾¹¥»÷Ö®Íâ  £¬ÎïÁªÍøÁìÓòÖÐÒÔ¹Ú×´²¡¶¾ÎªÃûµÄÏà¹Ø¹¥»÷Ò²¿ìËÙÉÏÉý¡£


ÕâЩÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾ÒÔ¡°Corona¡±£¨¹Ú×´µÄÓ¢ÎÄ£©¡¢¡°covid¡±£¨¹Ú×´²¡¶¾Ó¢ÎÄËõд£©ÃüÃû  £¬²¢Ê¹ÓÃÎïÁªÍø×°±¸Ëù±£´æµÄÎó²î¾ÙÐÐÈö²¥¡£ÎÒÃÇͨ¹ý¼à²âÊý¾Ý·¢Ã÷  £¬¸ÃÀàÑù±¾µÄÊýÄ¿ÓëÒßÇéÉú³¤·ºÆðÒ»¶¨Ë®Æ½µÄÏà¹ØÐÔ  £¬ºÃ±È½øÈë3Ô·ÝËæ×ÅÈ«ÇòÒßÇéÒ»Á¬ÉýΠ £¬ÒÔ¡°covid¡±ÃüÃûµÄÑù±¾×îÏÈÏÔÖøÔö¶à¡£


ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾Í³¼ÆÆÊÎö


×èÖ¹µ½2020Äê3ÔÂ26ÈÕ  £¬ÎÒÃǵÄÎïÁªÍøÍþвÊý¾Ýƽ̨¹²²¶»ñµ½801¸öÒÔ¹Ú×´²¡¶¾ÃüÃûµÄÑù±¾¡£ÎÒÃÇÕë¶ÔÕâЩÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾¾ÙÐÐÁË·ÂÕæÇéÐζ¯Ì¬ÆÊÎö  £¬Ñù±¾µÄC&CÉÏÏßÂþÑÜÇéÐÎÈçͼ1Ëùʾ¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


ͼ1 ½©Ê¬Ñù±¾C&CÉÏÏßÂþÑÜ


Êý¾ÝÏÔʾ  £¬ÕâÅúÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾Öй²½ü90%µÄÑù±¾ÊÜ¿ØÓÚλÓÚÃÀ¹úµÄ5¸öC&C·þÎñÆ÷  £¬7%λÓÚ¶íÂÞ˹  £¬4%λÓÚºÉÀ¼¡£ÆäÖÐÓÐ6¸öC&C·þÎñÆ÷ÔÚÒßÇéʱ´ú½ÏΪ»îÔ¾  £¬ÇÒ¹ØÁªµÄÑù±¾Á¿½Ï´ó  £¬°üÀ¨X86¡¢ARM¡¢MIPS¡¢PowerPC¡¢SPARC¡¢Renesas SHµÈ¶à¸öƽ̨µÄELFÎļþ¡£Í¨¹ý½øÒ»²½µÄͬԴÐÔÆÊÎö  £¬ÎÒÃǽ«ÕâЩÑùÌìÖ°³ÉÁ½Àà  £¬»®·ÖÃüÃûΪCorona-A¡¢Corona-B  £¬ºóÎĽ«½øÒ»²½Ì½ÌÖËüÃǵÄÊÖÒÕÌصãºÍËùÊô¼Ò×å¡£


ÕâÅú¡°¹Ú×´²¡¶¾¡±Ñù±¾µÄÖ÷ÒªÈö²¥ÊÖ¶ÎÈÔÈ»ÊÇͨ¹ýÄÚÖÃÃÜÂë±¾¾ÙÐÐTelnetÃÜÂ뱬ÆÆ  £¬²¿·ÖÑù±¾Ê¹Óõ½ÁË¡°Redis δÊÚȨ´úÂëÖ´ÐС±µÈ¶à¸öÒÑÖªÎó²îʹÓþÙÐÐÈö²¥¡£ÁíÍâÔÚÎÒÃÇËÝÔ´ÆÊÎöµÄÀú³ÌÖÐ  £¬·¢Ã÷Ïà¹Ø×éÖ¯½üÆÚʹÓÃ×îеÄÎó²îCVE-2020-9054[1]£¨ZyxelÍøÂçÁ¥Êô´æ´¢£¨NAS£©×°±¸£©¿ªÕ¹¹¥»÷Ô˶¯¡£¾ÝÖøÃûÊÓ²ìÖ°Ô±Brian KrebsµÄ˵·¨  £¬¸ÃÎó²îµÄÏà¹ØPOCÔÚµØÏÂÂÛ̳±»ÒÔ2ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ  £¬Í¬Ê±Ò²ÎüÒýÁË´ó×ÚÀÕË÷Èí¼þ¹¥»÷×éÖ¯µÄÐËȤ£¨¿ÉÄÜ»¹ÓëEmotetÓйأ©¡£ÓÉÓÚÎó²îµÄÑÏÖØÐÔ  £¬ÃÀ¹úCERT/CC½«¸ÃÎó²î¶¨ÎªCVSS10·Ö¡£


±í1 Ñù±¾Èö²¥Ê¹ÓõÄ×°±¸Îó²î

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


ÊÖÒÕÆÊÎö


1¡¢Corona-AÀàÑù±¾ÊÖÒÕÆÊÎö


ÔÚ¶ÔCorona-AÀàÑù±¾¾ÙÐÐÕûÌåÆÊÎöºó  £¬ÎÒÃÇ·¢Ã÷ÆäÖеıäÖÖËä¶à  £¬µ«ÖÖÖÖÑù±¾¼äµÄÏàËÆ¶ÈºÜ¸ß  £¬¹ÊÒÔ½üÆÚ»îÔ¾µÄC&C (192[.]3[.]193[.]251)ΪÀý  £¬¶Ô¹ØÁªÑù±¾¾ÙÐÐÄæÏòÆÊÎö  £¬Æä¶àÖּܹ¹µÄÑù±¾¾ù±»ÃüÃûΪ¡°Corona¡±¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ2 Shell¾ç±¾


½©Ê¬³ÌÐòÔËÐкó  £¬Ê×ÏÈ°ó¶¨ÍâµØ¶Ë¿Ú0x22B8£¨8888¶Ë¿Ú£©  £¬ÅþÁ¬C&CµØµãΪ£º192[.]3[.]193[.]251:20¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ3  ¼àÌýÍâµØ¶Ë¿Ú


ͨ¹ýensure_bindº¯ÊýÈ·±£Ñù±¾³ÌÐòÖ»±£´æµ¥ÊµÀýÔËÐС£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ4  ¼ì²éµ¥ÊµÀýÔËÐÐ


Ö´ÐÐbotkillerÄ£¿éÒÔɨ³ýÆäËü±£´æ¾ºÕùµÄÖ÷Á÷½©Ê¬³ÌÐò¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ5 Ö´ÐÐbotkillerÄ£¿é


Ðèɨ³ýµÄ½©Ê¬¼Ò×åºÍ¹ØÁª×Ö·û´®ÈçÏÂͼËùʾ£º


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ6 ɨ³ýµÄÄ¿µÄ¼Ò×å¼°¹ØÁª×Ö·û´®


¶ñÒâ´úÂëÖжദӲ±àÂëÁË¡°Corona¡±Òªº¦´Ê  £¬°üÀ¨ÉÏÏßÊý¾Ý°üºÍÅþÁ¬ÖÐÖ¹µÄÊä³öÏÔʾ£¨½©Ê¬·þÎñ¶Ë¿ÉÄܽ«¡°Corona¡±×÷ΪͨѶЭÒéʶ±ðµÄÒªº¦ÌØÕ÷£©¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ7 Ó²±àÂë¡°Corona¡±Òªº¦´Ê


ÉÏÏß°ü¼°C&C»Ø¸´°üͨѶÁ÷Á¿ÈçÏÂͼËùʾ£º


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ8 TCPͨѶÁ÷Á¿


Ñù±¾µÄproc_cmd()º¯Êý°üÀ¨DDoS¹¥»÷Ä£¿é  £¬ÆäÈÚºÏÁ˶àÖÖ³£¼ûµÄ¹¥»÷ģʽ  £¬°üÀ¨UDP¡¢VSE¡¢HTTP¡¢TCP¡¢STD¡¢XMASµÈ¡£Í¬Ê±ÔÚÕë¶Ô¸ÃC&C¼à¿ØµÄÀú³ÌÖÐ  £¬ÎÒÃÇ·¢Ã÷Æä½üÆÚ·¢¶¯µÄDDoS¹¥»÷Ô˶¯½ÏΪƵÈÔ  £¬Ö÷ҪĿµÄΪÎ÷Å·¹ú¼Ò  £¬²¿·Ö¹¥»÷ʾÀýÈçÏÂͼËùʾ£º


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ9 ¹¥»÷ÇéÐÎʾÀý


»ùÓÚÑù±¾µÄ´úÂë½á¹¹¡¢º¯ÊýÃüÃû¡¢Í¨Ñ¶Á÷Á¿¡¢¹¥»÷ģʽµÈÌØÕ÷  £¬¿ÉÒÔ·¢Ã÷Corona-AÀàÑù±¾ÓëGafgyt¼Ò×åµÄÏàËÆ¶ÈºÜ¸ß  £¬ºÚ¿ÍËä¶ÔͨѶÊý¾ÝµÈÄÚÈÝ°ü×°ÁË¡°Ð¹ڡ±¿´·¨  £¬µ«´úÂëÔÚÕûÌåÉÏÈÔÓëGafgyt¼Ò×åÏà½ü  £¬¿ÉÒÔÒÔΪÊÇGafgyt¼Ò×åµÄ±äÖÖ¡£Corona-AµÄÆäËüÀàÐÍÑù±¾Ò²Í¬Ñù»ùÓÚGafgyt¾ÙÐÐÐÞ¸Ä  £¬Ôڴ˲»×ö׸Êö¡£


2¡¢Corona-BÀàÑù±¾ÊÖÒÕÆÊÎö


Corona-BÀà¶ñÒâÑù±¾µÄ´úÂëÏà½ÏCorona-A¸üΪÖØ´ó  £¬ÇҴ󲿷ÖÑù±¾¾ÙÐÐÁË·ûºÅ°þÀë  £¬¶ÔÄæÏòÆÊÎö»á±¬·¢½Ï´ó×ÌÈÅ¡£¿ÉÊǺڿͰÙÃÜÒ»Êè  £¬ÔÚ´ó×ÚÑù±¾ÖÐ  £¬ÒÀÈ»±£´æ¸öÌåarm¼Ü¹¹µÄÑù±¾°üÀ¨·ûºÅ  £¬¿É¹©Ñо¿ÆÊÎö¡£Í¨¹ý½øÒ»²½µÄÊÓ²ì  £¬ÎÒÃÇ·¢Ã÷Corona-BÀàÑù±¾¼äµÄ²î±ð½Ï´ó  £¬¿ÉÒÔϸ·ÖΪ±äÖÖCorona-B-1ºÍ±äÖÖCorona-B-2¾ÙÐÐÆÊÎö¡£


? Corona-B-1


Corona-B-1µÄ¹ØÁªC&CΪ45[.]84[.]196[.]75  £¬Ïà¹ØÑù±¾Õ¼²¶»ñ×ÜÁ¿µÄ64%  £¬ÊÇÏÖÔÚ·¢Ã÷Ñù±¾Á¿×î´óµÄÎïÁªÍø¡°¹Ú×´²¡¶¾¡±  £¬½üÒ»¸öÔÂʱ¼äÄÚµü´úÁ˶à¸ö°æ±¾¡£ÔÚËÝÔ´ÆÊÎöµÄÀú³ÌÖÐ  £¬ÎÒÃÇ·¢Ã÷Ïà¹Ø×éÖ¯½üÆÚʹÓÃZyxelÍøÂçÁ¥Êô´æ´¢£¨NAS£©×°±¸µÄ×îÐÂÎó²îCVE-2020-9054¿ªÕ¹¹¥»÷Ô˶¯  £¬Ïà¹ØÈëÇÖÁ÷Á¿ÈçÏÂͼËùʾ£º


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ10 Îó²îÈëÇÖÁ÷Á¿


CVE-2020-9054Îó²îÊÇÍøÂç²úÆ·¹©Ó¦ÉÌZyxel½üÆÚÐÞ¸´µÄÒ»¸öÑÏÖصÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î  £¬Îó²îÓ°Ïì¶à¿îNAS×°±¸  £¬¹¥»÷Õß¿ÉÒÔͨ¹ýweblogin.cgi×é¼þ´¥·¢ÏÂÁî×¢Èë²¢¼ÓÔضñÒâ´úÂë¡£


¹¥»÷Àֳɺó»áÖ´ÐÐshell¾ç±¾ÏÂÔزî±ð¼Ü¹¹µÄ½©Ê¬Ñù±¾¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ11 Ö´ÐÐshell¾ç±¾


´ËÀà¶ñÒâÑù±¾Ò²ÔøÒÔ¡°corona¡±×÷Ϊºó׺Ãû¾ÙÐÐÏÂÔØÈö²¥¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ12 ¡°corona¡±ºó׺Ñù±¾


ͨ¹ý½øÒ»²½µÄÆÊÎöÈ·ÈÏ  £¬Corona-B-1ÊÇMirai¼Ò×åµÄбäÖÖMukashi  £¬ËäÈ»´úÂëδ¼¯³ÉÎó²îʹÓÃÄ£¿é  £¬µ«ºÚ¿ÍÓкܴó¿ÉÄÜÔÚʹÓÃCVE-2020-9054Îó²î¾ÙÐй¥»÷²¢Èö²¥¶ñÒâÑù±¾  £¬ÐèÒªÒýÆð¸÷·½ÖØÊÓ¡£


Corona-B-1ÓëÆäËüMirai¼Ò×å²î±ðµÄÊÇ  £¬ÆäÔÚ³õʼ»¯Ä£¿éÖÐ  £¬²¢Î´½ÓÄÉͨÀýµÄxor¼Ó½âÃÜ  £¬¶øÊÇʹÓÃÁË×Ô½ç˵µÄ½âÃÜģʽ¡£Æä²î±ð°æ±¾µÄ½âÃÜËã·¨Ïàͬ  £¬µ«Ô¤ÖüÓÃÜ×Ö·û´®²î±ð  £¬³õʼ¼ÓÃÜ×Ö·û´®Ê¾ÀýÈçÏÂͼËùʾ¡£


(Ñù±¾ad61c361f76026e0b0c1ff1bc62b52e7) :


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ13 ³õʼ¼ÓÃÜ×Ö·û´®


½âÃܺóµÄÏÂÁîºÍ×Ö·û´®»á´æ´¢µ½TableÖй©ºóÐøʹÓà  £¬¶ÔÓ¦ÐÅÏ¢ÈçϱíËùʾ£º


±í2 ½âÃܺóµÄÏÂÁîºÍ×Ö·û´®

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


Corona-B-1µÄɨÃèÄ£¿éscanner_initÔòͬMirai¼Ò×åµÄ´ó´ó¶¼±äÖÖÒ»Ñù  £¬½ÓÄÉTelnet±¬ÆÆ  £¬²¢Ê¹Óòî±ðµÄĬÈÏƾ֤×éºÏ¾ÙÐеǼ¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ14 ɨÃèÁ÷Á¿


Ò»µ©Telnet±¬ÆÆÀÖ³ÉÔò»áÒÔ¡°<host ip addr>:23 <username>:<password>¡±µÄÃûÌý«ÐÅÏ¢Ìá½»¸øC&C¡£


ͬʱ  £¬Corona-B-1»áÊÔͼ·¢ËÍÏÂÁîÖ´ÐÐһЩ²Ù×÷  £¬Èç¡°system¡±¡¢¡°shell¡±µÈĬÈÏÏÂÁî  £¬ Corona-B-1ÔÚ´Ë´¦ÐÂÔöÁË"/bin/busybox CORONA"ÏÂÁî  £¬¿ÉÒÔ½øÒ»²½Ö´ÐÐbusyboxÖеĶñÒâ´úÂ벿¼þ¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ15 ¡°CORONA¡±ÏÂÁî


ÖµµÃ×¢ÖصÄÊÇ  £¬Corona-B-1ÔÚ×îеĴúÂëÖÐɾ³ýÁ˶ԸÃÏÂÁîµÄºóÐø´¦Öóͷ£  £¬Ç°Æڰ汾ͨ¹ýrecv()º¯ÊýÀ´ÎüÊÕºÍÅжϻØÏÔÐÅÏ¢£¨ÈçÈôCORONAÏÂÁî²»±£´æ  £¬busybox½«·µ»Ø¡°CORONA: applet not found¡±£©¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ16 оɰ汾ÏÂÁî´¦Öóͷ£±ÈÕÕ


ÔÚ¹¥»÷ģʽ·½Ãæ  £¬Attack_parsing()º¯ÊýÈÏÕæ´¦Öóͷ£ÓëC&C·þÎñÆ÷µÄÏÂÁî½»»¥  £¬ÏêϸµÄ¿ØÖÆÖ¸ÁîÊý×éÓɳõʼ½âÃÜ»ñµÃ¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ17 ¿ØÖÆÖ¸ÁîÑ¡Ôñ


ϱíΪCorona-B-1Ö§³ÖµÄC&C¿ØÖÆÖ¸Áî¡£


±í3  C&C¿ØÖÆÖ¸Áî

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


ÆäÖÐ  £¬Corona-B-1ÉèÖÃÁ˲¿·ÖÈƹýDDOS·ÀÓùµÄ¹¥»÷ģʽ  £¬ÀýÈçUDP bypass,TCP bypass  £¬ÕâЩÊÖÒÕ×îÔçÀ´×ÔÓÚMiraiµÄDvrhelper±äÖÖ  £¬Ò²Åú×¢Corona-B-1¿ÉÄܼÌÐø½è¼øÁËDvrhelper±äÖֵIJ¿·Ö´úÂë¡£


?Corona-B-2


Corona-B-2µÄ¹ØÁªC&CΪ64[.]227[.]17[.]38  £¬¹¥»÷Õß½«¶àÖּܹ¹µÄ¶ñÒâÑù±¾ÃüÃûΪ¡°covid¡±¡£ÖµµÃ×¢ÖصÄÊÇ  £¬½üÆÚÆä¶ñÒâ´úÂ빦ЧµÄ¸üеü´úºÜÊÇƵÈÔ¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


ͼ18 ·þÎñÆ÷¶ñÒâ´úÂë¸üÐÂÇéÐÎ


Corona-B-2Ñù±¾°üÀ¨Telnet±¬ÆÆ¡¢·´GDBµ÷ÊÔ¡¢½ûÓÿ´ÃŹ·(watchdog)µÈÄ£¿é¹¦Ð§  £¬Ïà½ÏÓÚCorona-B-1  £¬Corona-B-2¸ü¿¿½üÓÚÔ­ÉúµÄMirai¼Ò×塣ͨ¹ý½øÒ»²½±È¶Ô  £¬Æ临ÓÃÁËMiraiµÄ´ó²¿·Ö´úÂë  £¬µ«³õʼ»¯Ä£¿éºÍ¹¥»÷Ä£¿éÓÐËùת±ä¡£


³õʼ»¯Ä£¿é£¨table_init£©µÄtable_keyÓëMiraiµÄĬÈÏÉèÖòî±ð£¨Corona-B-2µÄtable_keyΪ0xDEDEFBAF£©  £¬Ïà¹Ø¼ÓÃÜÊý¾Ý¿ÉÒÔͨ¹ýMiraiÔ´ÂëÖеÄtools/enc.cÄ£¿é¾ÙÐнâÃÜ¡£


¹¥»÷Ä£¿é£¨attack_init£©¹²×éºÏÁË13ÖÖ¹¥»÷·½·¨  £¬Í¨¹ýBindiff¾ÙÐÐоɰæÄÚÇéËÆÐԱȶԺó  £¬ÎÒÃÇ·¢Ã÷ºÚ¿Í×éÖ¯ÔÚÒ»Á¬ÔöÌíºÍ¸üÐÂÑù±¾µÄ¹¥»÷Ä£¿é¡£


°üÀ¨£º


attack_method_nudp

attack_method_udphex

attack_method_udpdnsµÈ¡£


Ò²Åú×¢¸Ã×éÖ¯½üÆڵĹ¥»÷ÓûÍû½ÏÇ¿¡£


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ19 оɰ汾´úÂëÏàËÆÐÔ½ÏÁ¿


×ÛºÏÒÔÉ϶ÔÎïÁªÍø¡°ÒßÇéÑù±¾¡±µÄÆÊÎö  £¬¶àÖÖ¶ñÒâ´úÂë×îÖÕ¶¼¶¨Î»µ½ÁËGafgytºÍMirai¼Ò×åµÄ±äÖÖ  £¬ËµÃ÷ÕâÁ½ÀàÆÕ±éÈö²¥µÄ¼Ò×åÈÔÊÇ´ó×ÚºÚ¿Í¿ª·¢ÐÂÐÍÎïÁªÍø½©Ê¬µÄÊ×Ñ¡¡£Í¬Ê±´ÓÃüÃûÏ°¹ß¡¢¹¥»÷Ä¿µÄ¡¢·þÎñÆ÷¹éÊôµØµÈÒòËØ×ÛºÏÅÐ¶Ï  £¬ÕâÅú¹¥»÷Õß»òÐíÂÊ»áÊǾ³ÍâµÄºÚ¿Í×éÖ¯¡£


Ïà¹ØÑù±¾µÄ¼Ò×å¹éÀàÕûÀíÈçÏÂͼËùʾ£º


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ20 Ñùͬ×å×å¹éÀà


Êܹ¥»÷IPÂþÑÜ


ƾ֤ÎÒÃǵļà²âÊý¾Ý  £¬ÏÖÔÚ¾³ÄÚÊܵ½ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±¹¥»÷µÄ×°±¸IPÁè¼Ý22Íò  £¬Ö÷ҪλÓÚÖйú¾³ÄÚ£¨96.8%£©¡£ÆäÖк£ÄÚÖ÷ÒªÂþÑÜÓڹ㶫Ê¡£¨15.4%£©¡¢Õã½­Ê¡£¨14.2%£©¡¢±±¾©ÊУ¨13.7%£©¡¢½­ËÕÊ¡£¨10.0%£©µÈ¡£¾³ÄÚÊܹ¥»÷IPÂþÑÜͼÈçÏÂËùʾ£º


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ͼ21 Êܹ¥»÷IPλÖÃÂþÑÜͼ


×ܽá


ͨ¹ýÒÔÉÏÆÊÎö¿ÉÒÔ¿´³ö  £¬ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±µÄÀ©É¢ºÍÈ«ÇòÒßÇéÉú³¤ÓÐ×ÅÒ»¶¨µÄÏà¹ØÐÔ¡£ÊÖÒÕÉÏ  £¬Æä´ó²¿·ÖÕվɽÓÄÉÁ˾­µäµÄÎïÁªÍø²¡¶¾GafgytºÍMirai¼Ò×åµÄ¹¥»÷Ä£¿é  £¬¿ÉÊÇÆäÈö²¥µÄĬÈÏÊÖ¶ÎÒÀÈ»ÊÇTelnet±¬ÆÆ  £¬²¿·ÖеÄÑù±¾×îÏÈÍŽáһЩз¢Ã÷µÄÎó²î¾ÙÐÐÀ©É¢Èö²¥¡£±ðµÄ  £¬ÎªÁ˸üÓÐÓõĶÀÍÌ×°±¸×ÊÔ´  £¬ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±»¹ÔöÇ¿Á˶ÔÆäËüÖ÷Á÷½©Ê¬¾ºÕùµÐÊֵķÀ¿ØºÍÆËɱ  £¬¿ÉÒÔɱµô50¶àÖÖÀàÐ͵ÄÎïÁªÍø½©Ê¬Àú³Ì¡£Ò»Ð©Ñù±¾»¹½ÓÄÉÁË×Ô½ç˵µÄ¼Ó½âÃÜÄ£¿é  £¬²¢Ò»Ö±ÔÚ¹¥»÷Ä£¿éÖÐÈÚºÏÐµĹ¥»÷ÀàÐÍ¡£


¸ÃÅúÎïÁªÍø¡°¹Ú×´²¡¶¾¡±¹¥»÷ÊÖ·¨ºÍÌصãÀ´¿´²¢Ã»ÓÐÌ«¶àÐÂÓ±µÄ¹¤¾ß  £¬¿ÉÊÇͨ¹ýʹÓÃÏÖʵÌìϵÄÕæʵÊÂÎñÀ´À©É¢¶ñÒâ¹¥»÷Õâһ˼Ð÷±Ø½«»áºã¾Ã±£´æ¡£¶ÔÐÂÎó²îµÄÎäÆ÷»¯ÒÀÈ»ÊÇÎïÁªÍøºÚ¿ÍÃǵÄÖصã¹ØעƫÏò¡£ºÚ¿Í´Ó·þÎñÆ÷¡¢PC¡¢ÖÇÄÜÊÖ»ú  £¬À©Õ¹ÏòÉãÏñÍ·¡¢Â·ÓÉÆ÷¡¢NAS¡¢¼Ò¾Ó°²·Àϵͳ¡¢ÖÇÄܵçÊÓ¡¢ÖÇÄÜÒÂ×Å×°±¸  £¬ÉõÖÁÊÇÓ¤¶ù¼àÊÓÆ÷  £¬Èκλ¥ÁªÍøÅþÁ¬µÄ×°±¸¶¼²»»á·Å¹ý  £¬ÕâÒ²ÊǺã¾ÃÒÔÀ´ÎïÁªÍø¶ñÒâ´úÂë¼á³Ö¶àƽ̨¼æÈݵÄÔµ¹ÊÔ­ÓÉ¡£ÎïÁªÍøµÄÍþв¹ØÓÚͨË×ÖÎÀíÔ±À´ËµÊǺÜÄѲì¾õµÄ  £¬¾ÍÏñ´¦ÓÚDZÔÚÆÚµÄÊÜѬȾÕßÒ»Ñù  £¬ÎÞ·¨ÊµÊ±·ÀÓùºÍɨ³ý¡£×îºó  £¬ÔÚÒßÇé֮Ϡ £¬ÎÒÃǸüÓ¦¸ÃСÐıðÓÐרÐĵÄÎïÁªÍø¡°¹Ú×´²¡¶¾¡±´ó·ùÀ©É¢  £¬ÕùÈ¡ÔçÈÕսʤÒßÇé  £¬Õ½Ê¤²¡¶¾¡£Òò´ËÎÒÃǽ¨ÒéÓû§£º


( 1 ) ʵʱ¸üÐÂÉý¼¶ÎïÁªÍø×°±¸¹Ì¼þ£»

( 2 ) ¾¡¿ìÌæ»»×°±¸³§É̳õʼÃÜÂë  £¬×¢ÖØ×èÖ¹¿Õ¿ÚÁî»òÈõ¿ÚÁ

( 3 ) ÈçÎÞÐëÒª  £¬¾¡¿ÉÄܲ»Òª½«²úÆ·Ö±½Ó̻¶ÔÚ»¥ÁªÍøÉÏ  £¬Èç±ØÐèÁªÍø  £¬¿É½«×°±¸ÅþÁ¬µ½Ç徲·ÓÉÆ÷»ò·À»ðǽ  £¬¾ÙÐиü¶àµÄ·À»¤£»

( 4 ) ÔöÇ¿ÍøÂç½çÏßÈëÇÖÌá·ÀºÍÖÎÀí  £¬¹Ø±Õ·ÇÐëÒªµÄÍøÂç·þÎñºÍ¶Ë¿Ú  £¬ÈçSSH£¨22£©¡¢Telnet(23)¡¢HTTP/HTTPS £¨80¡¢443£©µÈ¡£


IOCÑùÀý


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢



±¾±¨¸æÓÉCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶÓÓëÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÍŽáÐû²¼