2020-06-02

Ðû²¼Ê±¼ä 2020-06-03

ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_ľÂí_ViSystem.Stealer_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½ ViSystemľÂí ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËViSystemľÂí ¡£

ViSystemľÂíÊÇÒ»¸öÇÔÃÜÐÍľÂí£¬Ëü»áÇÔÈ¡Êܺ¦ÕßÉú´æÔÚ×ÀÃæµÄÎļþ(.doc¡¢.docx¡¢.pdf¡¢.txt¡¢.json¡¢.rdp)¡¢ä¯ÀÀÆ÷Êý¾Ý(µÇ¼ƾ֤ÐÅÏ¢¡¢Cookie¡¢ÀúÊ·¼Ç¼)¡¢¼ÓÃÜ»õ±ÒÇ®°ü¡¢FTPÈí¼þµÇ¼ƾ֤µÈ¡£ÁíÍ⣬ViSystem Äܹ»Ö´ÐÐÔ¶³Ì·þÎñÆ÷Ï·¢µÄC2Ö¸ÁÖ÷ÒªÖ¸ÁîÓУº¸üС¢ÏÂÔØÎļþÖ´ÐС£

¸üÐÂʱ¼ä£º

20200602












ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_CobaltStrike.Stager_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike Éú³ÉµÄºóÃÅ Stager ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úÆ÷£¬²¢½øÐкáÏòÒÆ¶¯¡£

CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½Ð­Í¬ºóÉøÍ¸¹¥»÷¿ò¼Ü¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socketÊðÀí¡¢ÌáȨ¡¢µöÓã¡¢Ô¶¿ØÄ¾ÂíµÈ¹¦Ð§¡£¸Ã¹¤¾ß¼¸ºõÁýÕÖÁËAPT¹¥»÷Á´ÖÐËùÐèÒªÓõ½µÄ¸÷¸ö¼¼Êõ»·½Ú£¬ÉîÊܺڿÍÃǵÄϲ°®¡£

¸üÐÂʱ¼ä£º

20200602














ʼþÃû³Æ£º

HTTP_Nginx+PHP_fpmÔ¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2019-11043]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃNginx+PHP_fpmÔ¶³ÌÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200602









ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_ºóÃÅ_phpStudy¹¥»÷ʵÑé_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½¹¥»÷ÕßÔÚÏòʹÓÃphpStudyµÄÍøÕ¾·¢ËÍÌØ¶¨Êý¾Ý£¬ÒÔ´¥·¢¶ñÒâºóÃŹ¦Ð§¡£

ÖøÃûµÄPHPµ÷ÊÔ»·¾³·¨Ê½¼¯³É°üphpStudyÈí¼þ±»¸Ä¶¯Ö²ÈëÁ˺óÃÅ¡£¹¥»÷ÕßÌæ»»ÁËphp_xmlrpc.dllʵÏÖºóÃÅ´úÂëµÄÖ²ÈëºÍפÁô¡£¹¥»÷ÕßÏòʹÓÃÁ˱»¸Ä¶¯µÄphpStudyµÄÍøÕ¾·¢ËÍÌØ¶¨Êý¾Ý£¬¼´¿É´¥·¢ºóÃÅÖ´ÐС£ºóÃŹ¦Ð§Ö÷ҪΪÊÕ¼¯Óû§ÐÅÏ¢¡¢Ö´ÐÐC£¦C¶Ë¹¥»÷ÕßÏ·¢µÄÔ¶³ÌPHP½Å±¾¡£

¸üÐÂʱ¼ä£º

20200602











ʼþÃû³Æ£º

HTTP_Coremail_ÅäÖÃÐÅϢй¶©¶´[CNVD-2019-16798]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÕýÔÚÀûÓÃCoremail_ÅäÖÃÐÅϢй¶©¶´½øÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200602