2020-08-18
°ä²¼¹¦·ò 2020-08-19ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | DNS_ľÂíºóÃÅ_CobaltStrike.Stager_´úÂëÏÂÔØÖ´ÐÐ |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄºóÃÅ Stager ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£¡£¡£¡£¡£¡£¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÆëÈ«½ÚÔìÊܺ¦»úе£¬£¬£¬£¬£¬²¢½øÐкáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20200818 |
ÊÂÎñÃû³Æ£º | HTTP_APT¹¥»÷_Higaisa_LNKÎļþ¹¥»÷_ÏνÓC2·þÎñÆ÷ |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | Higaisa APTÓ볯Ïʰ뵺Óйأ¬£¬£¬£¬£¬ÓÚ2019Äê³õ´ÎÅû¶¡£¡£¡£¡£¡£¡£¡£¸ÃÓ××éµÄ»î¶¯Äܹ»×·Òäµ½2016Ä꣬£¬£¬£¬£¬ÖØÒªÊ¹ÓÃľÂí£¨ÀýÈçGh0stºÍPlugX£©ÒÔ¼°Òƶ¯¶ñÒâÈí¼þµÈ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£ÆäÖ¸±êÔ̺¬µ±¾Ö¹ÙÔ±ºÍÈËȨ×éÖ¯£¬£¬£¬£¬£¬ÒÔ¼°Ó볯ÏÊÓÐ¹ØµÄÆäËûʵÌå¡£¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20200818 |
ÊÂÎñÃû³Æ£º | TCP_Java·´ÐòÁл¯_URLDNS_ÀûÓÃÁ´¹¥»÷ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCommonsCollections1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20200818 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_ºóÃÅ_Win32.Meterpreter_ÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÊÔͼÏòÖ÷ÕÅIPÖ÷»ú´«ÊäºóÃÅ¡£¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20200818 |
ɾ³ýÊÂÎñ
1¡¢HTTP_jenkins_fromtwitter_Ô¶³Ì´úÂëÖ´Ðзì϶


¾©¹«Íø°²±¸11010802024551ºÅ