2020-08-25

Ðû²¼Ê±¼ä 2020-08-26

ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_CobaltStrike_WebDelivery.py_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike Éú³ÉµÄ ºóÃÅpython½Å±¾ ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄÜÖ´ÐÐÁËCobaltStrikeµÄpythonºóÃÅ¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úÆ÷£¬²¢½øÐкáÏòÒÆ¶¯¡£

¸üÐÂʱ¼ä£º

20200825



ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_CobaltStrike.StagerX64_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike Éú³ÉµÄºóÃÅ StagerX64 ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.StagerX64¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úÆ÷£¬²¢½øÐкáÏòÒÆ¶¯¡£

¸üÐÂʱ¼ä£º

20200825


ʼþÃû³Æ£º

TCP_Äþ¾²Â©¶´_Samba_Ô¶³Ì´úÂëÖ´ÐЩ¶´_ÀûÓÃʧ°Ü[CVE-2017-7494][CNNVD-201705-1209]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄIPÀûÓÃsamba©¶´¹¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200825


ʼþÃû³Æ£º

TCP_Äþ¾²Â©¶´_Samba_Ô¶³Ì´úÂëÖ´ÐЩ¶´_ÀûÓÃÀÖ³É[CVE-2017-7494][CNNVD-201705-1209]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄIPÀûÓÃsamba©¶´¹¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200825


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_Win32.Zebrocy.Downloader(APT28)_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½ZebrocyÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËZebrocy¡£

¸üÐÂʱ¼ä£º

20200825


ʼþÃû³Æ£º

HTTP_Apache_httpOnly_CookieÐÅϢй¶©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âÔ´IPÖ÷»úÕýÊÔͼͨ¹ýApache HTTP Server "httpOnly" CookieÐÅϢй¶©¶´¹¥»÷Ä¿µÄIPµØÖ·Ö÷»ú¡£

¸üÐÂʱ¼ä£º

20200825


ʼþÃû³Æ£º

HTTP_SQL´íÎóÐÅϢй¶_2

Äþ¾²ÀàÐÍ£º

CGI¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼÀûÓÃÄ¿µÄIPÖ÷»úµÄSQL´íÎóÐÅÏ¢£¬¿ÉÄÜÔì³ÉÐÅϢй¶¡£

¸üÐÂʱ¼ä£º

20200825