2020-04-14

Ðû²¼Ê±¼ä 2020-04-14

ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_½©Ê¬ÍøÂç_BlackNet_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

Èä³æ²¡¶¾

ʼþÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçBlackNetÁ¬½ÓÔ¶³Ì·þÎñÆ÷£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»½©Ê¬·¨Ê½BlackNetѬȾ¡£

BlackNetÊÇÒ»¸ö¿ªÔ´µÄWindows½©Ê¬ÍøÂçľÂí£¬ÆäѬȾÖ÷»úºóÄܹ»ÀûÓñ»Ñ¬È¾µÄ»úÆ÷½øÐÐÖÖÖÖDDOS¹¥»÷£¨TCP£¬UDP£¬ARME£¬Slowloris£¬HTTPGet£¬POSTHttp£¬´ø¿í·ººé£©£¬¶øÇÒ»áÇÔÈ¡±»Ñ¬È¾»úÆ÷ÖеÄä¯ÀÀÆ÷CookieÒÔ¼°Éú´æµÄÕ˺ÅÃÜÂ룬ͬʱÄܹ»¼àÌý¼üÅÌÊäÈëÒÔ¼°ÉÏ´«/ÏÂÔØÎļþ¡£´Ëʼþ±¨¾¯ËµÃ÷Ô´IPËùÔÚÖ÷»úÒѾ­±»Ö²ÈëBlackNet£¬Ç뼰ʱ¶ÔÏà¹ØIPµØÖ·µÄÖ÷»ú½øÐÐÅŲé¡£

¸üÐÂʱ¼ä£º

20200414













ʼþÃû³Æ£º

TCP_ÏòÈÕ¿û_Ô¶³Ì¹¤¾ßʹÓÃ

Äþ¾²ÀàÐÍ£º

Äþ¾²Éó¼Æ

ʼþÃèÊö£º

¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚÊÔͼʹÓÃÏòÈÕ¿ûÁ¬½Ó¶Ô¶ËÉ豸¡£

ÏòÈÕ¿ûÔ¶³Ì¿ØÖÆÊÇÒ»¿îÃæÏòÆóÒµºÍרҵÈËÔ±µÄÔ¶³ÌPC¹ÜÀíºÍ¿ØÖƵķþÎñÈí¼þ¡£ÄúÔÚÈκοÉÁ¬È뻥ÁªÍøµÄËùÔÚ£¬¶¼¿ÉÒÔÇáËÉ·ÃÎʺͿØÖÆ°²×°ÁËÏòÈÕ¿ûÔ¶³Ì¿ØÖÆ¿Í»§¶ËµÄÔ¶³ÌÖ÷»ú£¬Õû¸ö¹ý³ÌÍêÈ«¿ÉÒÔͨ¹ýä¯ÀÀÆ÷½øÐУ¬ÎÞÐèÔÙ°²×°Èí¼þ¡£ÏòÈÕ¿ûÔ¶³Ì¿ØÖÆÓµÓÐÎåÃë¿ìËÙ¶øÓÖÇ¿¾¢µÄÄÚÍø´©Í¸¹¦Á¦£¬ÈÚºÏÁË΢ÈíRDPÔ¶³Ì×ÀÃæ(3389)£¬Óû§¿ÉÒÔÇáËÉÔÚÏòÈÕ¿ûÔ¶³Ì×ÀÃæЭÒéºÍ΢ÈíRDPЭÒéÖÐ×ÔÓÉÇл»£¬ÏíÊÜ×î¼ÑµÄÔ¶³Ì×ÀÃæÌåÑé¡£

¸üÐÂʱ¼ä£º

20200414













ʼþÃû³Æ£º

UDP_Teamviewer_Ô¶³Ì¹¤¾ßʹÓÃ

Äþ¾²ÀàÐÍ£º

Äþ¾²Éó¼Æ

ʼþÃèÊö£º

¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚÊÔͼʹÓÃTeamViewerÁ¬½Ó¶Ô¶ËÉ豸¡£

TeamViewerÊÇÒ»¸öÄÜÔÚÈκηÀ»ðǽºÍNATÊðÀíµÄºǫ́ÓÃÓÚÔ¶³Ì¿ØÖÆ£¬×ÀÃæ¹²ÏíºÍÎļþ´«ÊäµÄ¼òµ¥ÇÒ¿ìËٵĽâ¾ö·½°¸¡£ÎªÁËÁ¬½Óµ½Áíһ̨¼ÆËã»ú£¬Ö»ÐèÒªÔÚÁ½Ì¨¼ÆËã»úÉÏͬʱÔËÐÐ TeamViewer ¼´¿É£¬¶ø²»ÐèÒª½øÐа²×°£¨Ò²¿ÉÒÔÑ¡Ôñ°²×°£¬°²×°ºó¿ÉÒÔÉèÖÿª»úÔËÐУ©¡£¸ÃÈí¼þµÚÒ»´ÎÆô¶¯ÔÚÁ½Ì¨¼ÆËã»úÉÏ×Ô¶¯Éú³É»ï°é ID¡£Ö»ÐèÒªÊäÈëÄãµÄ»ï°éµÄIDµ½TeamViewer£¬È»ºó¾Í»áÁ¢¼´½¨Á¢ÆðÁ¬½Ó¡£

¸üÐÂʱ¼ä£º

20200414












ʼþÃû³Æ£º

TCP_Linux.DDG.Mining.Botnet_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçDDGÊÔͼºÍ³¬¼¶½Úµãxhub»òPeer½ÚµãͨÐÅ¡£Ô´IPËùÔÚÖ÷»ú¶¼±»Ö²ÈëÁ˽©Ê¬ÍøÂçDDG¡£

DDGÊÇÒ»¸ö»îÔ¾ÒѾõÄÍÚ¿ó½©Ê¬ÍøÂ磬רעÓÚɨÃè¿ØÖÆSSH ¶Ë¿Ú¡¢RedisÊý¾Ý¿âºÍOrientDBÊý¾Ý¿â·þÎñÆ÷¡£ËüÖ÷ÒªµÄÓ¯Àû·½Ê½ÊÇÀûÓ÷þÎñÆ÷ËãÁ¦ÍÚÃÅÂÞ±Ò¡£

¸üÐÂʱ¼ä£º

20200414











ÐÞ¸Äʼþ



ʼþÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÇëÇó

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£

¸üÐÂʱ¼ä£º

20200414







ʼþÃû³Æ£º

TCP_Oracle_WebLogic_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-2551]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2020-2551£©£¬ÊÔͼͨ¹ýGIOPЭÒé´«È뾫ÐĽṹµÄ¶ñÒâ´úÂë»òÃüÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£

©¶´´æÔÚµÄweblogic°æ±¾:

10.3.6.0.0

12.1.3.0.0

12.2.1.3.0

12.2.1.4.0

Èç¹û±»¹¥»÷»úÆ÷ûÓÐÉý¼¶ÏàÓ¦µÄ²¹¶¡£¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£

¸üÐÂʱ¼ä£º

20200414