2020-04-14
Ðû²¼Ê±¼ä 2020-04-14ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º |
HTTP_½©Ê¬ÍøÂç_BlackNet_ÅþÁ¬C2·þÎñÆ÷ |
Çå¾²ÀàÐÍ£º |
Èä³æ²¡¶¾ |
ÊÂÎñÐÎò£º |
¼ì²âµ½½©Ê¬ÍøÂçBlackNetÅþÁ¬Ô¶³Ì·þÎñÆ÷£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»½©Ê¬³ÌÐòBlackNetѬȾ¡£ BlackNetÊÇÒ»¸ö¿ªÔ´µÄWindows½©Ê¬ÍøÂçľÂí£¬ÆäѬȾÖ÷»úºóÄܹ»Ê¹Óñ»Ñ¬È¾µÄ»úе¾ÙÐÐÖÖÖÖDDOS¹¥»÷£¨TCP£¬UDP£¬ARME£¬Slowloris£¬HTTPGet£¬POSTHttp£¬´ø¿í·ººé£©£¬²¢ÇÒ»áÇÔÈ¡±»Ñ¬È¾»úеÖеÄä¯ÀÀÆ÷CookieÒÔ¼°ÉúÑĵÄÕ˺ÅÃÜÂ룬ͬʱÄܹ»¼àÌý¼üÅÌÊäÈëÒÔ¼°ÉÏ´«/ÏÂÔØÎļþ¡£´ËÊÂÎñ±¨¾¯ËµÃ÷Ô´IPËùÔÚÖ÷»úÒѾ±»Ö²ÈëBlackNet£¬Çëʵʱ¶ÔÏà¹ØIPµØµãµÄÖ÷»ú¾ÙÐÐÅŲ顣 |
¸üÐÂʱ¼ä£º |
20200414 |
ÊÂÎñÃû³Æ£º |
TCP_ÏòÈÕ¿û_Ô¶³Ì¹¤¾ßʹÓà |
Çå¾²ÀàÐÍ£º |
Çå¾²Éó¼Æ |
ÊÂÎñÐÎò£º |
¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚÊÔͼʹÓÃÏòÈÕ¿ûÅþÁ¬¶Ô¶Ë×°±¸¡£ ÏòÈÕ¿ûÔ¶³Ì¿ØÖÆÊÇÒ»¿îÃæÏòÆóÒµºÍרҵְԱµÄÔ¶³ÌPCÖÎÀíºÍ¿ØÖƵķþÎñÈí¼þ¡£ÄúÔÚÈκοÉÁ¬È뻥ÁªÍøµÄËùÔÚ£¬¶¼¿ÉÒÔÇáËÉ»á¼ûºÍ¿ØÖÆ×°ÖÃÁËÏòÈÕ¿ûÔ¶³Ì¿ØÖÆ¿Í»§¶ËµÄÔ¶³ÌÖ÷»ú£¬Õû¸öÀú³ÌÍêÈ«¿ÉÒÔͨ¹ýä¯ÀÀÆ÷¾ÙÐУ¬ÎÞÐèÔÙ×°ÖÃÈí¼þ¡£ÏòÈÕ¿ûÔ¶³Ì¿ØÖÆÓµÓÐÎåÃë¿ìËÙ¶øÓÖÇ¿¾¢µÄÄÚÍø´©Í¸¹¦Á¦£¬ÈÚºÏÁË΢ÈíRDPÔ¶³Ì×ÀÃæ(3389)£¬Óû§¿ÉÒÔÇáËÉÔÚÏòÈÕ¿ûÔ¶³Ì×ÀÃæÐæźÍ΢ÈíRDPÐÒéÖÐ×ÔÓÉÇл»£¬ÏíÊÜ×î¼ÑµÄÔ¶³Ì×ÀÃæÌåÑé¡£ |
¸üÐÂʱ¼ä£º |
20200414 |
ÊÂÎñÃû³Æ£º |
UDP_Teamviewer_Ô¶³Ì¹¤¾ßʹÓà |
Çå¾²ÀàÐÍ£º |
Çå¾²Éó¼Æ |
ÊÂÎñÐÎò£º |
¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚÊÔͼʹÓÃTeamViewerÅþÁ¬¶Ô¶Ë×°±¸¡£ TeamViewerÊÇÒ»¸öÄÜÔÚÈκηÀ»ðǽºÍNATÊðÀíµÄºǫ́ÓÃÓÚÔ¶³Ì¿ØÖÆ£¬×ÀÃæ¹²ÏíºÍÎļþ´«ÊäµÄ¼òÆÓÇÒ¿ìËٵĽâ¾ö¼Æ»®¡£ÎªÁËÅþÁ¬µ½Áíһ̨ÅÌËã»ú£¬Ö»ÐèÒªÔÚÁ½Ì¨ÅÌËã»úÉÏͬʱÔËÐÐ TeamViewer ¼´¿É£¬¶ø²»ÐèÒª¾ÙÐÐ×°Öã¨Ò²¿ÉÒÔÑ¡Ôñ×°Öã¬×°Öúó¿ÉÒÔÉèÖÿª»úÔËÐУ©¡£¸ÃÈí¼þµÚÒ»´ÎÆô¶¯ÔÚÁ½Ì¨ÅÌËã»úÉÏ×Ô¶¯ÌìÉúͬ°é ID¡£Ö»ÐèÒªÊäÈëÄãµÄͬ°éµÄIDµ½TeamViewer£¬È»ºó¾Í»áÁ¬Ã¦½¨ÉèÆðÅþÁ¬¡£ |
¸üÐÂʱ¼ä£º |
20200414 |
ÊÂÎñÃû³Æ£º |
TCP_Linux.DDG.Mining.Botnet_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½½©Ê¬ÍøÂçDDGÊÔͼºÍ³¬µÈ½Úµãxhub»òPeer½ÚµãͨѶ¡£Ô´IPËùÔÚÖ÷»ú¶¼±»Ö²ÈëÁ˽©Ê¬ÍøÂçDDG¡£ DDGÊÇÒ»¸ö»îÔ¾ÒѾõÄÍÚ¿ó½©Ê¬ÍøÂ磬רעÓÚɨÃè¿ØÖÆSSH ¶Ë¿Ú¡¢RedisÊý¾Ý¿âºÍOrientDBÊý¾Ý¿â·þÎñÆ÷¡£ËüÖ÷ÒªµÄÓ¯Àû·½·¨ÊÇʹÓ÷þÎñÆ÷ËãÁ¦ÍÚÃÅÂÞ±Ò¡£ |
¸üÐÂʱ¼ä£º |
20200414 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º |
DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃûÆÊÎöÇëÇó |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ |
¸üÐÂʱ¼ä£º |
20200414 |
ÊÂÎñÃû³Æ£º |
TCP_Oracle_WebLogic_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-2551] |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2551£©£¬ÊÔͼͨ¹ýGIOPÐÒé´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£ Îó²î±£´æµÄweblogic°æ±¾: 10.3.6.0.0 12.1.3.0.0 12.2.1.3.0 12.2.1.4.0 ÈôÊDZ»¹¥»÷»úеûÓÐÉý¼¶ÏìÓ¦µÄ²¹¶¡£¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£ |
¸üÐÂʱ¼ä£º |
20200414 |