2020-02-18

°ä²¼¹¦·ò 2020-02-18

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º
TCP_ľÂíºóÃÅ_MoleRAT/Pierogi_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½ Pierogi ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÔ¶¿Ø Pierogi ¡£¡£¡£¡£¡£¡£Pierogi ÊÇÒ»¸ö¼«¶È¸´ÔӵĶàÖ°ÄÜÔ¶¿ØÄ¾Âí £¬£¬ £¬£¬£¬ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£
¸üй¦·ò£º
20200218


ÊÂÎñÃû³Æ£º
HTTP_ľÂíºóÃÅ_APT34_TONEDEAF2.0_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½ TONEDEAF2.0 ľÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËTONEDEAF2.0 ľÂí ¡£¡£¡£¡£¡£¡£ TONEDEAF2.0ÊÇ TONEDEAF ľÂíµÄ¸ß¶ÈÅú¸Ä°æ±¾¡£¡£¡£¡£¡£¡£TONEDEAFÊÇÒ»¸öľÂí £¬£¬ £¬£¬£¬Äܹ»Í¨¹ýHTTPÓëËüµÄCommand and Control·þÎñÆ÷½øÐÐͨѶ £¬£¬ £¬£¬£¬ÒÔ±ã½Ó¹ÜºÍÖ´ÐкÅÁî¡£¡£¡£¡£¡£¡£ TONEDEAF 2.0ÊÇTONEDEAFµÄ¸ß¼¶°æ±¾ £¬£¬ £¬£¬£¬ÓµÓÐÓëԭʼ°æ±¾Ò»ÑùµÄÖ÷ÕÅ £¬£¬ £¬£¬£¬µ«ÓµÓо­¹ý¸Ä½øµÄC2ͨѶºÍ̸ºÍ¾­¹ýÄÚÈÝÐÔÅú¸ÄµÄ´úÂë¿â¡£¡£¡£¡£¡£¡£ÓëԭʼµÄTONEDEAFÏà±È £¬£¬ £¬£¬£¬TONEDEAF 2.0½öÔ̺¬ËÁÒâShellÖ´ÐÐÖ°ÄÜ £¬£¬ £¬£¬£¬²¢ÇÒ²»Ö§³ÖÈκÎÔ¤Ô¼ÒåºÅÁî¡£¡£¡£¡£¡£¡£ËüÒ²¸üÒñ±Î £¬£¬ £¬£¬£¬²¢ÇÒÔ̺¬ÖîÈ綯̬µ¼Èë £¬£¬ £¬£¬£¬×Ö·û´®½âÂëºÍÊܺ¦ÕߺýŪ²½ÖèÖ®ÀàµÄм¼ÇÉ¡£¡£¡£¡£¡£¡£
¸üй¦·ò£º
20200218


ÊÂÎñÃû³Æ£º
UDP_ºóÃÅ_Roboto.Botnet_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½½©Ê¬ÍøÂçRobotoÊÔͼºÍPeerͨѶ¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçRoboto¡£¡£¡£¡£¡£¡£ RobotoÊÇÒ»¸ö»ùÓÚP2PºÍ̸µÄ½©Ê¬ÍøÂç £¬£¬ £¬£¬£¬ÖØÒªÖ§³Ö7ÖÖÖ°ÄÜ£º·´µ¯Shell £¬£¬ £¬£¬£¬×ÔÐ¶ÔØ £¬£¬ £¬£¬£¬»ñÈ¡¹ý³ÌÍøÂçÐÅÏ¢ £¬£¬ £¬£¬£¬»ñÈ¡BotÐÅÏ¢ £¬£¬ £¬£¬£¬Ö´ÐÐϵͳºÅÁî £¬£¬ £¬£¬£¬ÔËÐÐÖ¸¶¨URLÖеļÓÃÜÎļþ £¬£¬ £¬£¬£¬DDoS¹¥»÷µÈ¡£¡£¡£¡£¡£¡£
¸üй¦·ò£º
20200218


 

ÊÂÎñÃû³Æ£º
HTTP_SQLServer_ReportingServices_·´ÐòÁл¯_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2020-0618]
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½Ô´IPÖ÷»úÔÚ¶Ô¿ÉÄÜ´æÔÚ·ì϶(CVE-2020-0618)µÄÒ³ÃæÖ´Ðй¥»÷ SQL Server Reporting Services Ìṩһ×é±¾µØ¹¤¾ßºÍ·þÎñ £¬£¬ £¬£¬£¬ÓÃÓÚ´´½¨¡¢²¿ÊðºÍÖÎÀí±¨±í¡£¡£¡£¡£¡£¡£SQL Server Reporting Services ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶ £¬£¬ £¬£¬£¬½öÐè»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÄܹ»ÏòÊÜÓ°Ïì°æ±¾µÄ Reporting Services Ê·ýÌá½»¾«ÐÄ»ú¹ØµÄÒªÇóÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÔÚ Report Server ·þÎñÕÊ»§¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
¸üй¦·ò£º
20200218