2019-07-05
Ðû²¼Ê±¼ä 2019-07-06ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
TCP_ºóÃÅ_Win32.Plurox_ÅþÁ¬ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½ºóÃÅPluroxÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPlurox¡£ PluroxÊÇÒ»¸öÄ£¿é»¯µÄºóÃÅ£¬ÔËÐкóÏÂÔØÖîÈçÍÚ¿ó¡¢UPnP¡¢SMBµÈÖݪֲå¼þ¡£SMB²å¼þʹÓÃÓÀºãÖ®À¶Îó²îÈö²¥Plurox¡£ |
|
¸üÐÂʱ¼ä£º |
20190705 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂí_Win.FelipeÇÔÃÜľÂí_ÅþÁ¬ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíWin32.FelipeÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFelipe¡£ FelipeÊÇÒ»¸öÇÔÃÜľÂí£¬ÔËÐкóÉÏ´«ÏµÍ³Ãô¸ÐÐÅÏ¢£¬²¢ÍµÈ¡ÊÜ¿ØÖ÷»úµÄÒøÐп¨ÐÅÏ¢µÈ¡£ |
|
¸üÐÂʱ¼ä£º |
20190705 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_PowershellEmpire_ÅþÁ¬ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½EmpireµÄºóÃÅÄ£¿éÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËEmpireµÄºóÃÅÄ£¿é¡£ EmpireÊÇÒ»¿îÀàËÆMetasploitµÄÉøÍ¸²âÊÔ¿ò¼Ü£¬Ê¹ÓÃPowerShell¾ç±¾×÷Ϊ¹¥»÷ÔØºÉ¡£¿ÉÒÔ¿ìËÙÔÚºóÆÚ°²ÅÅÎó²îʹÓÃÄ£¿é£¬ÄÚÖÃÄ£¿éÓмüÅ̼ͼ¡¢Mimikatz¡¢ÈƹýUAC¡¢ÄÚÍøÉ¨ÃèµÈ¡£ÆäÄÚÖÃÁË»ùÓÚPowerShellµÄºóÃÅÄ£¿é£¬¹¦Ð§ÀàËÆÓÚMeterpreter¡£ |
|
¸üÐÂʱ¼ä£º |
20190705 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
HTTP_Apache_Shiro_1.2.4_·´ÐòÁл¯Îó²î |
|
ÊÂÎñ¼¶±ð£º |
¸ß¼¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPʹÓÃApache_Shiro·´ÐòÁл¯Îó²î¾ÙÐй¥»÷µÄÐÐΪ |
|
¸üÐÂʱ¼ä£º |
20190705 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
ÐÞ¸ÄÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
TCP_ºóÃÅ_KG.Rat_ÅþÁ¬ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£ Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£ KuGou.RatÊÇÒ»¸öºóÃÅ£¬ÅþÁ¬Ô¶³Ì·þÎñÆ÷£¬½ÓÊÜÖ´ÐкڿÍÖ¸Á¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£ÊÔͼ»ñÈ¡Ãô¸Ð£¬Èç¼Í¼°´¼üÐÅÏ¢£¬»ñÈ¡½¹µã´°¿ÚµÄÎÊÌâ¡£ |
|
¸üÐÂʱ¼ä£º |
20190705 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
TCP_ºóÃÅ_Gh0st.DHLAR_ÅþÁ¬ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅDHLAR¡£ Gh0st.DHLARÊÇʹÓÃÒ»¸öƾ֤Gh0stÔ¶¿ØµÄÔ´ÂëÐ޸ĶøÀ´µÄºóÃÅ£¬ÔËÐкó¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£ |
|
¸üÐÂʱ¼ä£º |
20190705 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
TCP_ºóÃÅ_Win32.Ìì·£DDos_ÅþÁ¬ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅÌì·£¡£ Ìì·£ÊÇÒ»¸öDDoSƽ̨£¬ÔËÐк󣬿ÉÒÔ¶ÔÖ¸¶¨Ä¿µÄ»úеÌᳫDDoS¹¥»÷¡£ |
|
¸üÐÂʱ¼ä£º |
20190705 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
TCP_½©Ê¬ÍøÂçMyKingsºóÃÅ_PcStartÅþÁ¬ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíPcStart,MyKingÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄ¶àÖØ½©Ê¬ÍøÂ磬Õû¸ö½©Ê¬ÍøÂçÓÉbotnet.-1/0/1/2/3/4×é³É£¬botnet.0Ö§³ÖÁË´ó¶¼ÆäËû×Ó½©Ê¬ÍøÂçµÄ¹¹½¨Àú³Ì£¬ÆäËû¸÷×ÔÓµÓÐ×ÔÁ¦µÄÉÏÁª¿ØÖƶˡ£Æä¹¦Ð§Óн©Ê¬ÍøÂç¡¢ÊðÀíÍøÂç¡¢ÍÚ¿óÍøÂ硣ͬʱʹÓÃÔ¶¿ØÄ¾Âí£¬ºÚ¿Í¿ÉÒÔÍêÈ«¿ØÖÆÊ§ÏÝÅÌËã»ú£¬¿ØÖÆÖ®ºó¿ÉÒÔ×öÈκÎÊÂÇ飬ÆäÖоÍÓÐÇÔÈ¡Îļþ£¬¼à¿ØÆÁÄ»£¬¼à¿ØÉãÏñÍ·£¬¼àÌýÂó¿Ë·ç¡£ |
|
¸üÐÂʱ¼ä£º |
20190705 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
TCP_½©Ê¬ÍøÂçMyKingsºóÃÅ_PcStartÅþÁ¬ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Îó²îʹÓù¤¾ß°üRigÊÔͼÏÂÔØ¶ñÒâÈí¼þ£¬Ô´IPÖ÷»úÕýÔÚä¯ÀÀµÄÍøÒ³ºÜ¿ÉÄܱ»Ö²ÈëÁ˶ñÒâµÄ¾ç±¾´úÂ룬±»¶¨Ïòµ½Îó²îʹÓù¤¾ß°üRigµÄÒ³Ãæ£¬µ¼ÖÂÏÂÔØ¶ñÒâÈí¼þ¡£ Exploit KitÊÇÎó²îʹÓù¤¾ß°ü£¬Ô¤´ò°üÁË×°ÖóÌÐò¡¢¿ØÖÆÃæ°å¡¢¶ñÒâ´úÂëÒÔ¼°Ï൱ÊýÄ¿µÄ¹¥»÷¹¤¾ß¡£Ò»Ñùƽ³£À´Ëµ£¬Exploit Kit»á°üÀ¨Ò»ÏµÁвî±ðµÄÎó²îʹÓôúÂë¡£¹¥»÷Õß»áÏòÕýµ±µÄÍøÕ¾×¢Èë¶ñÒâµÄ¾ç±¾»ò´úÂ룬ÒÔÖØ¶¨Ïòµ½Exploit KitÒ³Ãæ¡£Êܺ¦Õßä¯ÀÀÍøÒ³Ê±¼´¼ÓÔØExploit KitµÄÖÖÖÖÎó²îʹÓôúÂ룬×îÖÕÏÂÔØÆäËü¶ñÒâÈí¼þ¡£ RigÊÇ2014Äê·ºÆðµÄÒ»¿îExploit Kit¼´Îó²îʹÓù¤¾ß°ü£¬Ö÷ÒªÒÔJava£¬FlashºÍSilverlightÎó²îΪĿµÄ¡£ |
|
¸üÐÂʱ¼ä£º |
20190705 |
|
ĬÈÏÐж¯£º |
ÑïÆú |


¾©¹«Íø°²±¸11010802024551ºÅ