2020-08-18

Ðû²¼Ê±¼ä 2020-08-19

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

DNS_ľÂíºóÃÅ_CobaltStrike.Stager_´úÂëÏÂÔØÖ´ÐÐ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄºóÃÅ Stager ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷ÏÂÔØÄ¾Âí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£¡£¡£¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉʹÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úе £¬£¬£¬£¬£¬²¢¾ÙÐкáÏòÒÆ¶¯¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200818



ÊÂÎñÃû³Æ£º

HTTP_APT¹¥»÷_Higaisa_LNKÎļþ¹¥»÷_ÅþÁ¬C2ЧÀÍÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

Higaisa APTÓ볯Ïʰ뵺ÓÐ¹Ø £¬£¬£¬£¬£¬ÓÚ2019ÄêÊ×´ÎÅû¶¡£¡£¡£¡£¸ÃС×éµÄ»î¶¯¿ÉÒÔ×·Ëݵ½2016Äê £¬£¬£¬£¬£¬Ö÷ҪʹÓÃľÂí£¨ÀýÈçGh0stºÍPlugX£©ÒÔ¼°Òƶ¯¶ñÒâÈí¼þµÈ¹¤¾ß¡£¡£¡£¡£ÆäÄ¿µÄ°üÀ¨Õþ¸®¹ÙÔ±ºÍÈËȨ×éÖ¯ £¬£¬£¬£¬£¬ÒÔ¼°Ó볯ÏÊÓÐ¹ØµÄÆäËûʵÌå¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200818


ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_URLDNS_ʹÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCommonsCollections1µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200818


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win32.Meterpreter_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼÏòÄ¿µÄIPÖ÷»ú´«ÊäºóÃÅ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200818


ɾ³ýÊÂÎñ


1¡¢HTTP_jenkins_fromtwitter_Ô¶³Ì´úÂëÖ´ÐÐÎó²î