Ò»³¡Ëµ×ß¾Í×ߵġ°Ó¦¼±¡±Ðж¯¡ª¡ªÄ³Ê¯»¯¹«Ë¾ÔâÍڿ󲡶¾Ñ¬È¾ºóµÄ48Сʱ
Ðû²¼Ê±¼ä 2019-05-23¡°µÎÁåÁåÁå~~~¡±¶¶È¦Îª¶Ä¶øÉú¹¤Òµ»¥ÁªÍøÊÂÒµ²¿¹¤³ÌʦµÄµç»°ÏìÆð£¡
¡°ÎÒÃÇÁ½Ì׺áºÓDCSϵͳµÄ²Ù×÷Ô±Õ¾¡¢¹¤³ÌʦվºÍOPC·þÎñÆ÷µÄÖ÷»úͻȻÀ¶ÆÁ£¡ÖØÐÂÆô¶¯ÏµÍ³ºó£¬ÈÔÈ»ÎÞ·¨»Ö¸´£¬Ñ°Çó½ô¼±¼¼ÊõÔ®Öú£¡¡±
À´×Ôijʯ»¯¹«Ë¾Òǿز¿µÄÊÂÇéÈËÔ±µç»°ÀïµÄÉùÒôÒì³£¼±´Ù¡¡
½â¾ö¿Í»§µÄÍøÂçÄþ¾²ÎÊÌ⣬¾ÍÊÇÎÒÃǵÄʹÃü£¡
¶¶È¦Îª¶Ä¶øÉú¹¤Òµ»¥ÁªÍøÄþ¾²ÊÂÒµ²¿ÁªºÏ¶¶È¦Îª¶Ä¶øÉú¼¯ÍÅÆìϳ½ÐÅÁì´´¹«Ë¾Á¢¼´×齨5ÈËרÏîС×飬ҵÎñ¡¢¼¼Êõ¡¢²úÎïÏßÈËÔ±»ðËÙ¿ªÆô¾ÈÔ®Ðж¯£¬Ô¶³ÌÖ¸µ¼¿Í»§½øÐÐϵͳ¾ÈÔ®¼°±£»¤ÏÖ³¡²¡¶¾Ñù±¾Êý¾Ý¡£
5ÔÂ11ÈÕÁ賿1:00
¾ÈÔ®ÊÂÇéÕù·Ö¶àÃ룬Àú¾3¸öСʱµÄÔ¶³ÌÖ§³Öºó£¬»ù±¾È·¶¨Ê¼þÔÒòΪMsraMiner²¡¶¾Ñ¬È¾¡£
Ô¶³ÌÖ§³ÖÁ¬Ðø½øÐУ¬µ«ÏÖ³¡Çé¿ö±ÈÁ¦ÌØÊ⣬¿¼Âǵ½¹¤¿ØÏµÍ³µÄÅÓ´óÐÔ¼°DCSϵͳµÄרҵÐÔ£¬Ó¦¼±ÍŶӾö¶¨³Ë×øµ±ÈÕ×îÔ纽°à·ÉÍù¿Í»§ÏÖ³¡¡£
5ÔÂ11ÈÕÔç6:40
Í×Í×µØÒ»³¡Ëµ×ß¾Í×ßµÄÓ¦¼±·þÎñ¡£
¾¹ý48СʱµÄ²»Ð¸Å¬Á¦£¬ÏµÍ³µÃµ½ÁËÐÞ¸´£¬¿Í»§µÄÉú²úÍêÈ«»Ö¸´ÁËÕý³£¡£¿Í»§¸øÓ¦¼±ÍŶӷ¢À´ÁËÕæ³ÏµÄллÐÅ£¬²¢ÑûÇëÉÌÌÖºóÆÚµÄ¼Ó¹Ì´ëÊ©ÓëºÏ×÷¡£

ʼþ·ÖÎö
ƾ¾Ý¶Ô¼ì²ìÏÖ³¡»·¾³ÒÔ¼°ÏµÍ³ÖÐÊý¾Ý·ÖÎö£¬ÍøÂçÖеÄÖ÷»úÈ·ÈÏΪMsraMinerÍڿ󲡶¾µÄ±äÖÖ²¡¶¾Ñ¬È¾£¬´ËÍڿ󲡶¾ÀûÓá°ÓÀºãÖ®À¶¡±Â©¶´½øÐÐÁ÷´«£¬ÔÚÁ÷´«¹ý³ÌÖУ¬ÓÉÓÚÔÚWindows XPϵͳÉÏ©¶´ÀûÓÃʧ°Ü£¬µ¼Ö»úÆ÷À¶ÆÁ¡£Æä²¡¶¾ÆÆ»µÔÀíΪ£º
Íڿ󲡶¾MsraMine×îбäÖֵIJ¡¶¾Ä¸ÌåÔËÐкóÊÍ·Å·þÎñÄ£¿é£¬ÊͷŵķþÎñÄ£¿éÃû³ÆËæ»úÆ´´Õ£¬Éú³ÉXXX.dll£¬·þÎñÃû³ÆºÍÊͷŵķþÎñdllÎļþÃû³ÆÏàͬ¡£

²¡¶¾·þÎñÃû×Ö»áÆ¾¾ÝÉú³ÉµÄdllÃû×ÖÃüÃû£¬µ«ÊÇÆäÃèÊöÒ»°ã¶¼ÎªEnable a commin infterace and object xxxx²¡¶¾Îļþ£¬²¢½«¹¥»÷C:\Windows\NetworkDistribution Ŀ¼ÏÂËùÓÐÎļþ£¨¹¥»÷µÄÖ÷ÒªÎļþ£©£¬Ö÷ÍÚ¿óÎļþC:\Windows\system32\dllhostex.exe£¨»òÆäËû±»×¢ÈëµÄsvchostµÄ×Ó½ø³Ì£©¡£
ÁíÍâÌØÑ¡ÔñÆäÖÐÒ»¸öIP¼ì²ìÆäÈ«²¿»á»°£¬²¢¶ÔÆäÁ¬½Ó¶Ë¿Ú½øÐÐͳ¼Æ£¬³ý445¶Ë¿ÚÍ⣬26931¡¢45560¶Ë¿ÚÁ¬½ÓÁ¿Õ¼±ÈÒ²Ï൱¿É¹Û£¬¶øÇҸö˿ڲ»ÊôÓÚÕý³£ÒµÎñËùÐè¶Ë¿Ú¡£Ëæ¼´¶Ô¸ÃÖ÷»úµÄµ±µØÎļþÓë½ø³Ì½øÐÐÊÓ²ìºÍ·ÖÎö£¬·¢ÏÖ´óÁ¿¶ñÒâÎļþ¡£ ¾¹ý·ÖÎöÅжϣ¬26931¡¢45560Á½¸ö¶Ë¿Ú·Ö±ðΪWebserver¶Ë¿ÚºÍ¿ó³ØÁ¬½Ó¶Ë¿Ú¡£ÆäÖÐWebserverÌṩÏàÓ¦×é¼þÏÂÔØ£¬ÍÚ¿ó½ø³ÌΪ¡°TrustedHostServices.exe¡±¡£
²¡¶¾µÄѬȾÁ÷³ÌΪ£ºÊܺ¦Ö÷»úij¹¤³ÌʦվÖеIJ¡¶¾·¨Ê½°üÂÞÁ½²¿ÃÅ£¬·Ö±ðΪ¹¥»÷·¨Ê½ÒÔ¼°¡°ÍÚ¿ó¡±·¨Ê½¡£ÆäÖй¥»÷·¨Ê½»áÊͷųö¡°ÓÀºãÖ®À¶¡±·¨Ê½£¬Í¬Ê±´î½¨web·þÎñÆ÷£¬Í¨¹ý¶¶È¦Îª¶Ä¶øÉúµÄTSOC-NBA¿ÉÒÔ·¢ÏÖÊܺ¦Ö÷»ú¹¤³ÌʦվÏòÊܺ¦Ö÷»ú²Ù×÷Ô±Õ¾ÒÔ¼°OPC·þÎñµÄ445¶Ë¿ÚÌᳫ¹¥»÷£¬±»Ñ¬È¾²¡¶¾µÄÖ÷»úÏòÊܺ¦Ö÷»úµÄweb·þÎñÆ÷26931¶Ë¿ÚÌᳫÏÂÔØÇëÇó£¬
ÇëÇóÄÚÈÝΪMsraReportDataCache32.tlb£¬¸Ã·¨Ê½»áÊͷųö¹¥»÷·¨Ê½ÒÔ¼°¡°ÍÚ¿ó¡±·¨Ê½£»Í¬Ê±£¬ÍÚ¿ó½ø³ÌTrusted Host Services . exe½øÐÐÍÚ¿ó£¬Óë¿ó³Øxmr.pool. minergate . com: 45560 ½¨Á¢Á¬½Ó£¬·¨Ê½ÔËÐÐÆÚ¼ä»á·ÃÎÊÏàÓ¦µÄdomainÒÔ½øÐз¨Ê½¸üÐÂÓë¿ó³ØÁ¬½Ó£¬ÔÚÁ¬½Óʧ°Üºóµ¼ÖÂϵͳÀ¶ÆÁ¡£
½â¾ö·½°¸
1¡¢Ó¦¼±´¦ÖãºÊÖ¹¤Çå³ý
2) ¹Ø±Õ445£¬139£¬135¡¢3389µÈ¶Ë¿Ú·þÎñ£»
3) ɾ³ýÃèÊöΪEnable a commin infterace and object xxxxµÄ·þÎñ£»
4) ɾ³ý´Ë·þÎñ¶ÔÓ¦µÄ¶¯Ì¬Á´½Ó¿âÎļþ£»
5) ½áÊøsvchost.exe½ø³Ì£¨TaskIndexer.exe»òdllhostex.exe½ø³ÌµÄ¸¸½ø³Ì£©£»
6) ½áÊøTaskIndexer.exe»òdllhostex.exe½ø³Ì£¬²¢É¾³ýÆäÎļþ£»
7) ɾ³ýC:\Windows\NetworkDistributionĿ¼ÏÂËùÓÐÎļþ£»
8) °²×°É±¶¾Èí¼þ±£³Ö·ÀÓù¿ªÆô£¬¼°Ê±Éý¼¶²¡¶¾¿â¡£
ÊÖ¶¯°²×°¡°ÓÀºãÖ®À¶¡±Â©¶´²¹¶¡Çë·ÃÎÊÒÔÏÂÒ³Ãæ£º
https://technet.microsoft.com/zh-cn/library/security/ms17-010.aspx
http://www.catalog.update.microsoft.com/search.aspx?q=kb4012212
ÆäÖÐWinXP£¬Windows Server 2003Óû§Çë·ÃÎÊ£º
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4012598
²¿Ãʤ¾ß£º
¶¶È¦Îª¶Ä¶øÉúµÄÓÀºãÖ®À¶ÈÈÐÞ¸´¹¤¾ß
¶¶È¦Îª¶Ä¶øÉúPChunter¶ñÒâÈí¼þÊÖ¹¤¼ì²â¹¤¾ß
2¡¢¹¤¿ØÏµÍ³×¨Òµ²éɱ¹¤¾ß
¹¤Òµ¿ØÖÆÏµÍ³ÔÚ·À²¡¶¾½¨ÉèÉÏÆÕ±é´æÔÚ£ºÉ豸ÐÔÄܯձ鯫µÍ¡¢windowsÀϰ汾²Ù×÷ϵͳ¾Ó¶à¡¢Ó²¼þ»òÒµÎñÈí¼þÔÚʵʩ·À²¡¶¾ºó²»µÃÊÜÈκÎÓ°Ïì¡¢·À²¡¶¾Èí¼þ±ØÐëÄܹ»ÓÐЧ·ÀÓù²¡¶¾µÈÎÊÌ⣬¶¶È¦Îª¶Ä¶øÉúΪÂú×㹤¿ØÐÐÒµ·À²¡¶¾ÐèÇó£¬Ñз¢³ö¾°ÔÆÄþ¾²ÄÜÁ¦ÇáÁ¿»¯¹¤¿Ø·À»¤°æ¡£½ÓÄÉÈ«³ÌÎÞÇý¶¯ÎÞhook¡¢Ö»É¨²»É±ÒÔ¼°½ø³Ì/ÍøÂç°×Ãûµ¥µÈÇкϹ¤¿Ø»·¾³µÄ»úÖÆ£¬×ÊÖú¹¤¿ØÆóÒµÔÚ·ÀÓùÖÖÖÖÐÂÐͲ¡¶¾ºÍÈ䳿µÄ¹¥»÷µÄͬʱ£¬Äܹ»¼æ¹Ë¹¤¿ØÉ豸µÄÎȶ¨ÔËÐУ¬±£ÕÏÓû§ÒµÎñ¡£
1) ¼¯ÖйܿأºÍ¨¹ý¾°ÔƼ¶ÁªÖÐ¿ØÆ½Ì¨£¬Ìṩ¿ÉÉìËõµÄ¿çƽ̨²¡¶¾·À»¤£¬¼¯Öйܿظ÷¼¶ÖÖÖÖ·ºÖÕ¶Ë£¬Âú×ãÆóÒµ¼¶Óû§¶Ô·À²¡¶¾Èí¼þͳһ¹ÜÀíµÄÐèÇó¡£
2) º£Á¿ÔƲ飺¿ÉΪÓû§°´Ðè¶¨ÖÆÔÆÖªÊ¶¿â£¬ÖÇÄÜ×ÔÔËÓªÔÆ¶Ë²¡¶¾ÌØÕ÷£¬Ê¹Óû§ÔÚÓµÓеÈͬÓÚ¹«ÓÐÔÆµÄ²¡¶¾²éɱÄÜÁ¦µÄͬʱ£¬ÓÖͨ¹ý˽Óл¯µÄ·½Ê½³¹µ×¶Å¾øÊý¾Ýй¶¡£
3) ÖÇÄܼø¶¾£º½«»úÆ÷ѧϰºÍ´óÊý¾ÝÒªÁìÈÚÈëµ½·À²¡¶¾ÏµÍ³ÖУ¬Äܹ»Îª´óÐÍÓû§ÊµÏÖ×Ô¶¯µÄÑù±¾²¶×½¡¢ÑùÌìÖ°Àà¡¢Ñù±¾ÌØÕ÷ÌáÈ¡¡¢²¡¶¾¿â¸üÐÂÁ÷³Ì£¬ÒÔ±ãÄܹ»¿ìËÙÏìÓ¦»¥ÁªÍø²ã³ö²»ÇîµÄ¼ÆËã»ú²¡¶¾¡£
4) ǿЧÐÔÄÜ£ºÔÚ½µµÍÓû§ÖÕ¶Ë×ÊÔ´ÏûºÄͬʱ£¬½áºÏÈ˹¤ÖÇÄܺʹóÊý¾Ý¼¼Êõ£¬ÄÜʹ²¡¶¾²éɱ¸üѸËÙ¡¢¸ü¾«×¼¡£Äܹ»ÓÐЧ·ÀÓù×îÁ÷ÐеIJ¡¶¾Ä¾Âí¡¢ºÚ¿ÍÈëÇÖºÍ0day¡¢APTµÈδ֪Íþв£¬¸üÓÐÀûÓÚʵʩ£¬¸ü·½±ã°²×°ºÍά»¤¡£
5) ÖÇÄÜ×Ôѧϰ£ºÍ¨¹ý¼´Ê±È¡Ñù¡¢ÀúÊ·Êý¾Ý·ÖÎö¡¢¶à¹æÔòºÏ²¢µÈ·½Ê½½¨Á¢½ø³Ì/ÍøÂç°×Ãûµ¥¹æÔò¡£ÔÚÉ趨³ß¶ÈÉ豸֮ºó£¬¾°ÔÆÖ§³Ö×Ô¶¯µ÷Õû¹æÔòÄÚÈÝÒÔÊÊÓ¦ÒµÎñϵͳÉý¼¶Ôì³ÉµÄ°×Ãûµ¥ÁбíÀ©ÈݵÈÐèÇó£¬×ÊÖúÓû§¿ìËÙ½¨Á¢ÇкÏ×ÔÉí¹¤¿Ø»·¾³µÄ°×Ãûµ¥¡£
3¡¢Ö÷»ú¼Ó¹Ì
½ÓÄɶ¶È¦Îª¶Ä¶øÉúµÄ¡°Ìì«‘ÄÚÍøÄþ¾²·çÏÕ¹ÜÀíÓëÉó¼ÆÏµÍ³¡±£¬¹¦Ð§Èçͼ£º

Äþ¾²ÎÞСÊÂ
Ïò·Ü¶·ÔÚÒ»ÏßµÄÓ¦¼±·þÎñÈËÔ±Ö¾´£¡