2020-06-02
Ðû²¼Ê±¼ä 2020-06-03ÐÂÔöʼþ
ʼþÃû³Æ£º |
HTTP_ľÂí_ViSystem.Stealer_Á¬½ÓC2·þÎñÆ÷ |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½ ViSystemľÂí ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËViSystemľÂí ¡£ ViSystemľÂíÊÇÒ»¸öÇÔÃÜÐÍľÂí£¬Ëü»áÇÔÈ¡Êܺ¦ÕßÉú´æÔÚ×ÀÃæµÄÎļþ(.doc¡¢.docx¡¢.pdf¡¢.txt¡¢.json¡¢.rdp)¡¢ä¯ÀÀÆ÷Êý¾Ý(µÇ¼ƾ֤ÐÅÏ¢¡¢Cookie¡¢ÀúÊ·¼Ç¼)¡¢¼ÓÃÜ»õ±ÒÇ®°ü¡¢FTPÈí¼þµÇ¼ƾ֤µÈ¡£ÁíÍ⣬ViSystem Äܹ»Ö´ÐÐÔ¶³Ì·þÎñÆ÷Ï·¢µÄC2Ö¸ÁÖ÷ÒªÖ¸ÁîÓУº¸üС¢ÏÂÔØÎļþÖ´ÐС£ |
¸üÐÂʱ¼ä£º |
20200602 |
ʼþÃû³Æ£º |
HTTP_ľÂíºóÃÅ_CobaltStrike.Stager_Á¬½ÓC2·þÎñÆ÷ |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike Éú³ÉµÄºóÃÅ Stager ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úÆ÷£¬²¢½øÐкáÏòÒÆ¶¯¡£ CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½ÐͬºóÉøÍ¸¹¥»÷¿ò¼Ü¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socketÊðÀí¡¢ÌáȨ¡¢µöÓã¡¢Ô¶¿ØÄ¾ÂíµÈ¹¦Ð§¡£¸Ã¹¤¾ß¼¸ºõÁýÕÖÁËAPT¹¥»÷Á´ÖÐËùÐèÒªÓõ½µÄ¸÷¸ö¼¼Êõ»·½Ú£¬ÉîÊܺڿÍÃǵÄϲ°®¡£ |
¸üÐÂʱ¼ä£º |
20200602 |
ʼþÃû³Æ£º |
HTTP_Nginx+PHP_fpmÔ¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2019-11043] |
Äþ¾²ÀàÐÍ£º |
Äþ¾²Â©¶´ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃNginx+PHP_fpmÔ¶³ÌÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º |
20200602 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º |
HTTP_ºóÃÅ_phpStudy¹¥»÷ʵÑé_Á¬½Ó |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½¹¥»÷ÕßÔÚÏòʹÓÃphpStudyµÄÍøÕ¾·¢ËÍÌØ¶¨Êý¾Ý£¬ÒÔ´¥·¢¶ñÒâºóÃŹ¦Ð§¡£ ÖøÃûµÄPHPµ÷ÊÔ»·¾³·¨Ê½¼¯³É°üphpStudyÈí¼þ±»¸Ä¶¯Ö²ÈëÁ˺óÃÅ¡£¹¥»÷ÕßÌæ»»ÁËphp_xmlrpc.dllʵÏÖºóÃÅ´úÂëµÄÖ²ÈëºÍפÁô¡£¹¥»÷ÕßÏòʹÓÃÁ˱»¸Ä¶¯µÄphpStudyµÄÍøÕ¾·¢ËÍÌØ¶¨Êý¾Ý£¬¼´¿É´¥·¢ºóÃÅÖ´ÐС£ºóÃŹ¦Ð§Ö÷ҪΪÊÕ¼¯Óû§ÐÅÏ¢¡¢Ö´ÐÐC£¦C¶Ë¹¥»÷ÕßÏ·¢µÄÔ¶³ÌPHP½Å±¾¡£ |
¸üÐÂʱ¼ä£º |
20200602 |
ʼþÃû³Æ£º |
HTTP_Coremail_ÅäÖÃÐÅϢй¶©¶´[CNVD-2019-16798] |
Äþ¾²ÀàÐÍ£º |
Äþ¾²Â©¶´ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÕýÔÚÀûÓÃCoremail_ÅäÖÃÐÅϢй¶©¶´½øÐй¥»÷µÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º |
20200602 |