2020-08-18

Ðû²¼Ê±¼ä 2020-08-19

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

DNS_ľÂíºóÃÅ_CobaltStrike.Stager_´úÂëÏÂÔØÖ´ÐÐ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄºóÃÅ Stager ÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷ÏÂÔØľÂí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉʹÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úе £¬²¢¾ÙÐкáÏòÒƶ¯¡£

¸üÐÂʱ¼ä£º

20200818



ÊÂÎñÃû³Æ£º

HTTP_APT¹¥»÷_Higaisa_LNKÎļþ¹¥»÷_ÅþÁ¬C2·þÎñÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

Higaisa APTÓ볯Ïʰ뵺ÓйØ £¬ÓÚ2019ÄêÊ×´ÎÅû¶¡£¸ÃС×éµÄÔ˶¯¿ÉÒÔ×·Ëݵ½2016Äê £¬Ö÷ҪʹÓÃľÂí£¨ÀýÈçGh0stºÍPlugX£©ÒÔ¼°Òƶ¯¶ñÒâÈí¼þµÈ¹¤¾ß¡£ÆäÄ¿µÄ°üÀ¨Õþ¸®¹ÙÔ±ºÍÈËȨ×éÖ¯ £¬ÒÔ¼°Ó볯ÏÊÓйصÄÆäËûʵÌå¡£

¸üÐÂʱ¼ä£º

20200818


ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_URLDNS_ʹÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCommonsCollections1µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200818


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win32.Meterpreter_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼÏòÄ¿µÄIPÖ÷»ú´«ÊäºóÃÅ¡£

¸üÐÂʱ¼ä£º

20200818


ɾ³ýÊÂÎñ


1¡¢HTTP_jenkins_fromtwitter_Ô¶³Ì´úÂëÖ´ÐÐÎó²î