2020-04-14
Ðû²¼Ê±¼ä 2020-04-14ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_½©Ê¬ÍøÂç_BlackNet_ÅþÁ¬C2ЧÀÍÆ÷ |
|
Çå¾²ÀàÐÍ£º |
È䳿²¡¶¾ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½½©Ê¬ÍøÂçBlackNetÅþÁ¬Ô¶³ÌЧÀÍÆ÷£¬£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»½©Ê¬³ÌÐòBlackNetѬȾ¡£¡£ BlackNetÊÇÒ»¸ö¿ªÔ´µÄWindows½©Ê¬ÍøÂçľÂí£¬£¬ÆäѬȾÖ÷»úºóÄܹ»Ê¹Óñ»Ñ¬È¾µÄ»úе¾ÙÐÐÖÖÖÖDDOS¹¥»÷£¨TCP£¬£¬UDP£¬£¬ARME£¬£¬Slowloris£¬£¬HTTPGet£¬£¬POSTHttp£¬£¬´ø¿í·ººé£©£¬£¬²¢ÇÒ»áÇÔÈ¡±»Ñ¬È¾»úеÖеÄä¯ÀÀÆ÷CookieÒÔ¼°ÉúÑĵÄÕ˺ÅÃÜÂ룬£¬Í¬Ê±Äܹ»¼àÌý¼üÅÌÊäÈëÒÔ¼°ÉÏ´«/ÏÂÔØÎļþ¡£¡£´ËÊÂÎñ±¨¾¯ËµÃ÷Ô´IPËùÔÚÖ÷»úÒѾ±»Ö²ÈëBlackNet£¬£¬Çëʵʱ¶ÔÏà¹ØIPµØµãµÄÖ÷»ú¾ÙÐÐÅŲ顣¡£ |
|
¸üÐÂʱ¼ä£º |
20200414 |
|
ÊÂÎñÃû³Æ£º |
TCP_ÏòÈÕ¿û_Ô¶³Ì¹¤¾ßʹÓà |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Éó¼Æ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚÊÔͼʹÓÃÏòÈÕ¿ûÅþÁ¬¶Ô¶Ë×°±¸¡£¡£ ÏòÈÕ¿ûÔ¶³Ì¿ØÖÆÊÇÒ»¿îÃæÏòÆóÒµºÍרҵְԱµÄÔ¶³ÌPCÖÎÀíºÍ¿ØÖƵÄЧÀÍÈí¼þ¡£¡£ÄúÔÚÈκοÉÁ¬È뻥ÁªÍøµÄËùÔÚ£¬£¬¶¼¿ÉÒÔÇáËÉ»á¼ûºÍ¿ØÖÆ×°ÖÃÁËÏòÈÕ¿ûÔ¶³Ì¿ØÖƿͻ§¶ËµÄÔ¶³ÌÖ÷»ú£¬£¬Õû¸öÀú³ÌÍêÈ«¿ÉÒÔͨ¹ýä¯ÀÀÆ÷¾ÙÐУ¬£¬ÎÞÐèÔÙ×°ÖÃÈí¼þ¡£¡£ÏòÈÕ¿ûÔ¶³Ì¿ØÖÆÓµÓÐÎåÃë¿ìËÙ¶øÓÖÇ¿¾¢µÄÄÚÍø´©Í¸¹¦Á¦£¬£¬ÈÚºÏÁË΢ÈíRDPÔ¶³Ì×ÀÃæ(3389)£¬£¬Óû§¿ÉÒÔÇáËÉÔÚÏòÈÕ¿ûÔ¶³Ì×ÀÃæÐæÅºÍ΢ÈíRDPÐÒéÖÐ×ÔÓÉÇл»£¬£¬ÏíÊÜ×î¼ÑµÄÔ¶³Ì×ÀÃæÌåÑé¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200414 |
|
ÊÂÎñÃû³Æ£º |
UDP_Teamviewer_Ô¶³Ì¹¤¾ßʹÓà |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Éó¼Æ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚÊÔͼʹÓÃTeamViewerÅþÁ¬¶Ô¶Ë×°±¸¡£¡£ TeamViewerÊÇÒ»¸öÄÜÔÚÈκηÀ»ðǽºÍNATÊðÀíµÄºǫ́ÓÃÓÚÔ¶³Ì¿ØÖÆ£¬£¬×ÀÃæ¹²ÏíºÍÎļþ´«ÊäµÄ¼òÆÓÇÒ¿ìËٵĽâ¾ö¼Æ»®¡£¡£ÎªÁËÅþÁ¬µ½Áíһ̨ÅÌËã»ú£¬£¬Ö»ÐèÒªÔÚÁ½Ì¨ÅÌËã»úÉÏͬʱÔËÐÐ TeamViewer ¼´¿É£¬£¬¶ø²»ÐèÒª¾ÙÐÐ×°Öã¨Ò²¿ÉÒÔÑ¡Ôñ×°Ö㬣¬×°Öúó¿ÉÒÔÉèÖÿª»úÔËÐУ©¡£¡£¸ÃÈí¼þµÚÒ»´ÎÆô¶¯ÔÚÁ½Ì¨ÅÌËã»úÉÏ×Ô¶¯ÌìÉúͬ°é ID¡£¡£Ö»ÐèÒªÊäÈëÄãµÄͬ°éµÄIDµ½TeamViewer£¬£¬È»ºó¾Í»áÁ¬Ã¦½¨ÉèÆðÅþÁ¬¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200414 |
|
ÊÂÎñÃû³Æ£º |
TCP_Linux.DDG.Mining.Botnet_ÅþÁ¬ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½½©Ê¬ÍøÂçDDGÊÔͼºÍ³¬µÈ½Úµãxhub»òPeer½ÚµãͨѶ¡£¡£Ô´IPËùÔÚÖ÷»ú¶¼±»Ö²ÈëÁ˽©Ê¬ÍøÂçDDG¡£¡£ DDGÊÇÒ»¸ö»îÔ¾ÒѾõÄÍÚ¿ó½©Ê¬ÍøÂ磬£¬×¨×¢ÓÚɨÃè¿ØÖÆSSH ¶Ë¿Ú¡¢RedisÊý¾Ý¿âºÍOrientDBÊý¾Ý¿âЧÀÍÆ÷¡£¡£ËüÖ÷ÒªµÄÓ¯Àû·½·¨ÊÇʹÓÃЧÀÍÆ÷ËãÁ¦ÍÚÃÅÂÞ±Ò¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200414 |
ÐÞ¸ÄÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃûÆÊÎöÇëÇó |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200414 |
|
ÊÂÎñÃû³Æ£º |
TCP_Oracle_WebLogic_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-2551] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2551£©£¬£¬ÊÔͼͨ¹ýGIOPÐÒé´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£ Îó²î±£´æµÄweblogic°æ±¾: 10.3.6.0.0 12.1.3.0.0 12.2.1.3.0 12.2.1.4.0 ÈôÊDZ»¹¥»÷»úеûÓÐÉý¼¶ÏìÓ¦µÄ²¹¶¡£¡£¬£¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200414 |


¾©¹«Íø°²±¸11010802024551ºÅ