2020-08-18

Ðû²¼Ê±¼ä 2020-08-19

ÐÂÔöʼþ


ʼþÃû³Æ£º

DNS_ľÂíºóÃÅ_CobaltStrike.Stager_´úÂëÏÂÔØÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike Éú³ÉµÄºóÃÅ Stager ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØľÂí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úÆ÷£¬²¢½øÐкáÏòÒƶ¯¡£

¸üÐÂʱ¼ä£º

20200818



ʼþÃû³Æ£º

HTTP_APT¹¥»÷_Higaisa_LNKÎļþ¹¥»÷_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

Higaisa APTÓ볯Ïʰ뵺ÓйØ£¬ÓÚ2019ÄêÊ×´ÎÅû¶¡£¸ÃС×éµÄ»î¶¯¿ÉÒÔ×·Ëݵ½2016Ä꣬Ö÷ҪʹÓÃľÂí£¨ÀýÈçGh0stºÍPlugX£©ÒÔ¼°Òƶ¯¶ñÒâÈí¼þµÈ¹¤¾ß¡£ÆäÄ¿±ê°üÂÞÕþ¸®¹ÙÔ±ºÍÈËȨ×éÖ¯£¬ÒÔ¼°Ó볯ÏÊÓйصÄÆäËûʵÌå¡£

¸üÐÂʱ¼ä£º

20200818


ʼþÃû³Æ£º

TCP_Java·´ÐòÁл¯_URLDNS_ÀûÓÃÁ´¹¥»÷

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃCommonsCollections1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200818


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

TCP_ºóÃÅ_Win32.Meterpreter_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼÏòÄ¿µÄIPÖ÷»ú´«ÊäºóÃÅ¡£

¸üÐÂʱ¼ä£º

20200818


ɾ³ýʼþ


1¡¢HTTP_jenkins_fromtwitter_Ô¶³Ì´úÂëÖ´ÐЩ¶´