2020-06-02
Ðû²¼Ê±¼ä 2020-06-03ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º |
HTTP_ľÂí_ViSystem.Stealer_ÅþÁ¬C2·þÎñÆ÷ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½ ViSystemľÂí ÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËViSystemľÂí ¡£ ViSystemľÂíÊÇÒ»¸öÇÔÃÜÐÍľÂí£¬Ëü»áÇÔÈ¡Êܺ¦ÕßÉúÑÄÔÚ×ÀÃæµÄÎļþ(.doc¡¢.docx¡¢.pdf¡¢.txt¡¢.json¡¢.rdp)¡¢ä¯ÀÀÆ÷Êý¾Ý(µÇ¼ƾ֤ÐÅÏ¢¡¢Cookie¡¢ÀúÊ·¼Í¼)¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢FTPÈí¼þµÇ¼ƾ֤µÈ¡£ÁíÍ⣬ViSystem Äܹ»Ö´ÐÐÔ¶³Ì·þÎñÆ÷Ï·¢µÄC2Ö¸ÁÖ÷ÒªÖ¸ÁîÓУº¸üС¢ÏÂÔØÎļþÖ´ÐС£ |
¸üÐÂʱ¼ä£º |
20200602 |
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_CobaltStrike.Stager_ÅþÁ¬C2·þÎñÆ÷ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄºóÃÅ Stager ÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷ÏÂÔØľÂí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉʹÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úе£¬²¢¾ÙÐкáÏòÒƶ¯¡£ CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½ÐͬºóÉø͸¹¥»÷¿ò¼Ü¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socketÊðÀí¡¢ÌáȨ¡¢´¹ÂÚ¡¢Ô¶¿ØľÂíµÈ¹¦Ð§¡£¸Ã¹¤¾ßÏÕЩÁýÕÖÁËAPT¹¥»÷Á´ÖÐËùÐèÒªÓõ½µÄ¸÷¸öÊÖÒÕ»·½Ú£¬ÉîÊܺڿÍÃǵÄϲ»¶¡£ |
¸üÐÂʱ¼ä£º |
20200602 |
ÊÂÎñÃû³Æ£º |
HTTP_Nginx+PHP_fpmÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-11043] |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃNginx+PHP_fpmÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º |
20200602 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º |
HTTP_ºóÃÅ_phpStudy¹¥»÷ʵÑé_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½¹¥»÷ÕßÔÚÏòʹÓÃphpStudyµÄÍøÕ¾·¢ËÍÌض¨Ãü¾Ý£¬ÒÔ´¥·¢¶ñÒâºóÃŹ¦Ð§¡£ ÖøÃûµÄPHPµ÷ÊÔÇéÐγÌÐò¼¯³É°üphpStudyÈí¼þ±»¸Ä¶¯Ö²ÈëÁ˺óÃÅ¡£¹¥»÷ÕßÌæ»»ÁËphp_xmlrpc.dllʵÏÖºóÃÅ´úÂëµÄÖ²ÈëºÍפÁô¡£¹¥»÷ÕßÏòʹÓÃÁ˱»¸Ä¶¯µÄphpStudyµÄÍøÕ¾·¢ËÍÌض¨Ãü¾Ý£¬¼´¿É´¥·¢ºóÃÅÖ´ÐС£ºóÃŹ¦Ð§Ö÷ҪΪÍøÂçÓû§ÐÅÏ¢¡¢Ö´ÐÐC£¦C¶Ë¹¥»÷ÕßÏ·¢µÄÔ¶³ÌPHP¾ç±¾¡£ |
¸üÐÂʱ¼ä£º |
20200602 |
ÊÂÎñÃû³Æ£º |
HTTP_Coremail_ÉèÖÃÐÅϢй¶Îó²î[CNVD-2019-16798] |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÕýÔÚʹÓÃCoremail_ÉèÖÃÐÅϢй¶Îó²î¾ÙÐй¥»÷µÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º |
20200602 |