ÍøÂç ¡°¹Ú×´²¡¶¾¡± |¶«É­Æ½Ì¨ADLabÁªºÏCNCERTÎïÁªÍøÄþ¾²Ñо¿ÍŶÓÐû²¼×îÐÂÑо¿³ÂËß

Ðû²¼Ê±¼ä 2020-03-27

¸Å¿ö


Ëæ×Å¡°ÐÂÐ͹Ú×´²¡¶¾·ÎÑס±ÉÏÉýΪȫÇòÐÔ¹«¹²ÎÀÉúÍ»·¢Ê¼þ £¬¸÷¹úÃñÖÚ¿ªÆôÁË¡°Õ¬¿¹Òß¡¢ÔÆÉú»î¡±Ä£Ê½¡£Ôڷdz£Ê±ÆÚ £¬ÍøÂç¿Õ¼äÔÚÈËÃǵÄÈÕ³£Éú»î±äµÃÔ½·¢²»Ðлòȱ £¬È»¶øµ±¸÷È˶¼ÔÚ·ÜÁ¦¿¹ÒßµÄͬʱ £¬´óÁ¿µÄºÚ¿ÍÈ´¿ªÊ¼ÒÔ¡°¹Ú×´²¡¶¾¡±ÃûÒå´ÓÊ´ó¹æÄ£µÄÍøÂç¹¥»÷»î¶¯ £¬³ýÁËÄ¿Ç°ÒѾ­·¢ÏÖÒÔ¹Ú×´²¡¶¾ÎªÃû½øÐеÄAPT¹¥»÷¡¢ÀÕË÷²¡¶¾¹¥»÷Ö®Íâ £¬ÎïÁªÍøÁìÓòÖÐÒÔ¹Ú×´²¡¶¾ÎªÃûµÄÏà¹Ø¹¥»÷Ò²¿ìËÙÉÏÉý¡£


ÕâЩÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾ÒÔ¡°Corona¡±£¨¹Ú×´µÄÓ¢ÎÄ£©¡¢¡°covid¡±£¨¹Ú×´²¡¶¾Ó¢ÎÄËõд£©ÃüÃû £¬²¢ÀûÓÃÎïÁªÍøÉ豸Ëù´æÔڵĩ¶´½øÐÐÁ÷´«¡£ÎÒÃÇͨ¹ý¼à²âÊý¾Ý·¢ÏÖ £¬¸ÃÀàÑù±¾µÄÊýÁ¿ÓëÒßÇéÉú³¤·ºÆðÒ»¶¨Ë®Æ½µÄÏà¹ØÐÔ £¬ºÃ±È½øÈë3Ô·ÝËæ×ÅÈ«ÇòÒßÇéÁ¬ÐøÉýΠ£¬ÒÔ¡°covid¡±ÃüÃûµÄÑù±¾¿ªÊ¼ÏÔÖøÔö¶à¡£


ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾Í³¼Æ·ÖÎö


½ØÖ¹µ½2020Äê3ÔÂ26ÈÕ £¬ÎÒÃǵÄÎïÁªÍøÍþвÊý¾Ýƽ̨¹²²¶×½µ½801¸öÒÔ¹Ú×´²¡¶¾ÃüÃûµÄÑù±¾¡£ÎÒÃÇÕë¶ÔÕâЩÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾½øÐÐÁË·ÂÕæ»·¾³¶¯Ì¬·ÖÎö £¬Ñù±¾µÄC&CÉÏÏßÂþÑÜÇé¿öÈçͼ1Ëùʾ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ1 ½©Ê¬Ñù±¾C&CÉÏÏßÂþÑÜ


Êý¾ÝÏÔʾ £¬ÕâÅúÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾Öй²½ü90%µÄÑù±¾ÊÜ¿ØÓÚλÓÚÃÀ¹úµÄ5¸öC&C·þÎñÆ÷ £¬7%λÓÚ¶íÂÞ˹ £¬4%λÓÚºÉÀ¼¡£ÆäÖÐÓÐ6¸öC&C·þÎñÆ÷ÔÚÒßÇéÆÚ¼ä½ÏΪ»îÔ¾ £¬ÇÒ¹ØÁªµÄÑù±¾Á¿½Ï´ó £¬°üÂÞX86¡¢ARM¡¢MIPS¡¢PowerPC¡¢SPARC¡¢Renesas SHµÈ¶à¸öƽ̨µÄELFÎļþ¡£Í¨¹ý½øÒ»²½µÄͬԴÐÔ·ÖÎö £¬ÎÒÃǽ«ÕâЩÑùÌìÖ°³ÉÁ½Àà £¬·Ö±ðÃüÃûΪCorona-A¡¢Corona-B £¬ºóÎĽ«½øÒ»²½Ì½¾¿ËüÃǵļ¼ÊõÌصãºÍËùÊô¼Ò×å¡£


ÕâÅú¡°¹Ú×´²¡¶¾¡±Ñù±¾µÄÖ÷ÒªÁ÷´«ÊÖ¶ÎÈÔÈ»ÊÇͨ¹ýÄÚÖÃÃÜÂë±¾½øÐÐTelnetÃÜÂ뱬ÆÆ £¬²¿ÃÅÑù±¾ÀûÓõ½ÁË¡°Redis δÊÚȨ´úÂëÖ´ÐС±µÈ¶à¸öÒÑ֪©¶´ÀûÓýøÐÐÁ÷´«¡£ÁíÍâÔÚÎÒÃÇËÝÔ´·ÖÎöµÄ¹ý³ÌÖÐ £¬·¢ÏÖÏà¹Ø×éÖ¯½üÆÚÀûÓÃ×îеĩ¶´CVE-2020-9054[1]£¨ZyxelÍøÂçÁ¥Êô´æ´¢£¨NAS£©É豸£©¿ªÕ¹¹¥»÷»î¶¯¡£¾ÝÖøÃûÊÓ²ìÈËÔ±Brian KrebsµÄ˵·¨ £¬¸Ã©¶´µÄÏà¹ØPOCÔÚµØÏÂÂÛ̳±»ÒÔ2ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛ £¬Í¬Ê±Ò²ÎüÒýÁË´óÁ¿ÀÕË÷Èí¼þ¹¥»÷×éÖ¯µÄÐËȤ£¨¿ÉÄÜ»¹ÓëEmotetÓйأ©¡£ÓÉÓÚ©¶´µÄÑÏÖØÐÔ £¬ÃÀ¹úCERT/CC½«¸Ã©¶´¶¨ÎªCVSS10·Ö¡£


±í1 Ñù±¾Á÷´«ÀûÓõÄÉ豸©¶´

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼¼Êõ·ÖÎö


1¡¢Corona-AÀàÑù±¾¼¼Êõ·ÖÎö


ÔÚ¶ÔCorona-AÀàÑù±¾½øÐÐÕûÌå·ÖÎöºó £¬ÎÒÃÇ·¢ÏÖÆäÖеıäÖÖËä¶à £¬µ«ÖÖÖÖÑù±¾¼äµÄÏàËƶȺܸß £¬¹ÊÒÔ½üÆÚ»îÔ¾µÄC&C (192[.]3[.]193[.]251)ΪÀý £¬¶Ô¹ØÁªÑù±¾½øÐÐÄæÏò·ÖÎö £¬Æä¶àÖּܹ¹µÄÑù±¾¾ù±»ÃüÃûΪ¡°Corona¡±¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ2 Shell½Å±¾


½©Ê¬·¨Ê½ÔËÐкó £¬Ê×ÏȰ󶨵±µØ¶Ë¿Ú0x22B8£¨8888¶Ë¿Ú£© £¬Á¬½ÓC&CµØַΪ£º192[.]3[.]193[.]251:20¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ3  ¼àÌýµ±µØ¶Ë¿Ú


ͨ¹ýensure_bindº¯ÊýÈ·±£Ñù±¾·¨Ê½Ö»´æÔÚµ¥ÊµÀýÔËÐС£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ4  ¼ì²éµ¥ÊµÀýÔËÐÐ


Ö´ÐÐbotkillerÄ£¿éÒÔÇå³ýÆäËü´æÔÚ¾ºÕùµÄÖ÷Á÷½©Ê¬·¨Ê½¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ5 Ö´ÐÐbotkillerÄ£¿é


ÐèÇå³ýµÄ½©Ê¬¼Ò×åºÍ¹ØÁª×Ö·û´®ÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ6 Çå³ýµÄÄ¿±ê¼Ò×å¼°¹ØÁª×Ö·û´®


¶ñÒâ´úÂëÖжദӲ±àÂëÁË¡°Corona¡±Òªº¦´Ê £¬°üÂÞÉÏÏßÊý¾Ý°üºÍÁ¬½ÓÖжϵÄÊä³öÏÔʾ£¨½©Ê¬·þÎñ¶Ë¿ÉÄܽ«¡°Corona¡±×÷ΪͨÐÅЭÒéʶ´ËÍâÒªº¦ÌØÕ÷£©¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ7 Ó²±àÂë¡°Corona¡±Òªº¦´Ê


ÉÏÏß°ü¼°C&C»Ø¸´°üͨÐÅÁ÷Á¿ÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ8 TCPͨÐÅÁ÷Á¿


Ñù±¾µÄproc_cmd()º¯Êý°üÂÞDDoS¹¥»÷Ä£¿é £¬ÆäÈÚºÏÁ˶àÖÖ³£¼ûµÄ¹¥»÷ģʽ £¬°üÂÞUDP¡¢VSE¡¢HTTP¡¢TCP¡¢STD¡¢XMASµÈ¡£Í¬Ê±ÔÚÕë¶Ô¸ÃC&C¼à¿ØµÄ¹ý³ÌÖÐ £¬ÎÒÃÇ·¢ÏÖÆä½üÆÚ·¢¶¯µÄDDoS¹¥»÷»î¶¯½ÏΪƵ·± £¬Ö÷ҪĿ±êΪŷÃÀ¹ú¼Ò £¬²¿ÃŹ¥»÷ʾÀýÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ9 ¹¥»÷Çé¿öʾÀý


»ùÓÚÑù±¾µÄ´úÂë½á¹¹¡¢º¯ÊýÃüÃû¡¢Í¨ÐÅÁ÷Á¿¡¢¹¥»÷ģʽµÈÌØÕ÷ £¬¿ÉÒÔ·¢ÏÖCorona-AÀàÑù±¾ÓëGafgyt¼Ò×åµÄÏàËƶȺܸß £¬ºÚ¿ÍËä¶ÔͨÐÅÊý¾ÝµÈÄÚÈÝ°ü×°ÁË¡°Ð¹ڡ±¿´·¨ £¬µ«´úÂëÔÚÕûÌåÉÏÈÔÓëGafgyt¼Ò×åÏà½ü £¬¿ÉÒÔÈÏΪÊÇGafgyt¼Ò×åµÄ±äÖÖ¡£Corona-AµÄÆäËüÀàÐÍÑù±¾Ò²Í¬Ñù»ùÓÚGafgyt½øÐÐÐÞ¸Ä £¬Ôڴ˲»×ö׸Êö¡£


2¡¢Corona-BÀàÑù±¾¼¼Êõ·ÖÎö


Corona-BÀà¶ñÒâÑù±¾µÄ´úÂëÏà½ÏCorona-A¸üΪÅÓ´ó £¬ÇÒ´ó²¿ÃÅÑù±¾½øÐÐÁË·ûºÅ°þÀë £¬¶ÔÄæÏò·ÖÎö»á·¢Éú½Ï´ó×ÌÈÅ¡£µ«ÊǺڿͰÙÃÜÒ»Êè £¬ÔÚ´óÁ¿Ñù±¾ÖÐ £¬ÒÀÈ»´æÔÚ¸öÌåarm¼Ü¹¹µÄÑù±¾°üÂÞ·ûºÅ £¬¿É¹©Ñо¿·ÖÎö¡£Í¨¹ý½øÒ»²½µÄÊÓ²ì £¬ÎÒÃÇ·¢ÏÖCorona-BÀàÑù±¾¼äµÄ²îÒì½Ï´ó £¬¿ÉÒÔϸ·ÖΪ±äÖÖCorona-B-1ºÍ±äÖÖCorona-B-2½øÐзÖÎö¡£


? Corona-B-1


Corona-B-1µÄ¹ØÁªC&CΪ45[.]84[.]196[.]75 £¬Ïà¹ØÑù±¾Õ¼²¶×½×ÜÁ¿µÄ64% £¬ÊÇÄ¿Ç°·¢ÏÖÑù±¾Á¿×î´óµÄÎïÁªÍø¡°¹Ú×´²¡¶¾¡± £¬½üÒ»¸öÔÂʱ¼äÄÚµü´úÁ˶à¸ö°æ±¾¡£ÔÚËÝÔ´·ÖÎöµÄ¹ý³ÌÖÐ £¬ÎÒÃÇ·¢ÏÖÏà¹Ø×éÖ¯½üÆÚÀûÓÃZyxelÍøÂçÁ¥Êô´æ´¢£¨NAS£©É豸µÄ×îЩ¶´CVE-2020-9054¿ªÕ¹¹¥»÷»î¶¯ £¬Ïà¹ØÈëÇÖÁ÷Á¿ÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ10 ©¶´ÈëÇÖÁ÷Á¿


CVE-2020-9054©¶´ÊÇÍøÂç²úÎ﹩ӦÉÌZyxel½üÆÚÐÞ¸´µÄÒ»¸öÑÏÖصÄÔ¶³Ì´úÂëÖ´ÐЩ¶´ £¬Â©¶´Ó°Ïì¶à¿îNASÉ豸 £¬¹¥»÷Õß¿ÉÒÔͨ¹ýweblogin.cgi×é¼þ´¥·¢ÃüÁî×¢Èë²¢¼ÓÔضñÒâ´úÂë¡£


¹¥»÷Àֳɺó»áÖ´ÐÐshell½Å±¾ÏÂÔزîÒì¼Ü¹¹µÄ½©Ê¬Ñù±¾¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ11 Ö´ÐÐshell½Å±¾


´ËÀà¶ñÒâÑù±¾Ò²ÔøÒÔ¡°corona¡±×÷Ϊºó׺Ãû½øÐÐÏÂÔØÁ÷´«¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ12 ¡°corona¡±ºó׺Ñù±¾


ͨ¹ý½øÒ»²½µÄ·ÖÎöÈ·ÈÏ £¬Corona-B-1ÊÇMirai¼Ò×åµÄбäÖÖMukashi £¬ËäÈ»´úÂëδ¼¯³É©¶´ÀûÓÃÄ£¿é £¬µ«ºÚ¿ÍÓкܴó¿ÉÄÜÔÚÀûÓÃCVE-2020-9054©¶´½øÐй¥»÷²¢Á÷´«¶ñÒâÑù±¾ £¬ÐèÒªÒýÆð¸÷·½ÖØÊÓ¡£


Corona-B-1ÓëÆäËüMirai¼Ò×å²îÒìµÄÊÇ £¬ÆäÔÚ³õʼ»¯Ä£¿éÖÐ £¬²¢Î´½ÓÄÉͨÀýµÄxor¼Ó½âÃÜ £¬¶øÊÇʹÓÃÁË×Ô½ç˵µÄ½âÃÜģʽ¡£Æä²îÒì°æ±¾µÄ½âÃÜËã·¨Ïàͬ £¬µ«Ô¤ÖüÓÃÜ×Ö·û´®²îÒì £¬³õʼ¼ÓÃÜ×Ö·û´®Ê¾ÀýÈçÏÂͼËùʾ¡£


(Ñù±¾ad61c361f76026e0b0c1ff1bc62b52e7) :


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ13 ³õʼ¼ÓÃÜ×Ö·û´®


½âÃܺóµÄÃüÁîºÍ×Ö·û´®»á´æ´¢µ½TableÖй©ºóÐøʹÓà £¬¶ÔÓ¦ÐÅÏ¢ÈçϱíËùʾ£º


±í2 ½âÃܺóµÄÃüÁîºÍ×Ö·û´®

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Corona-B-1µÄɨÃèÄ£¿éscanner_initÔòͬMirai¼Ò×åµÄ´ó¶àÊý±äÖÖÒ»Ñù £¬½ÓÄÉTelnet±¬ÆÆ £¬²¢Ê¹ÓòîÒìµÄĬÈÏƾ¾Ý×éºÏ½øÐеǼ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ14 ɨÃèÁ÷Á¿


Ò»µ©Telnet±¬ÆÆÀÖ³ÉÔò»áÒÔ¡°<host ip addr>:23 <username>:<password>¡±µÄ¸ñʽ½«ÐÅÏ¢Ìá½»¸øC&C¡£


ͬʱ £¬Corona-B-1»áÊÔͼ·¢ËÍÃüÁîÖ´ÐÐһЩ²Ù×÷ £¬Èç¡°system¡±¡¢¡°shell¡±µÈĬÈÏÃüÁî £¬ Corona-B-1ÔÚ´Ë´¦ÐÂÔöÁË"/bin/busybox CORONA"ÃüÁî £¬¿ÉÒÔ½øÒ»²½Ö´ÐÐbusyboxÖеĶñÒâ´úÂ벿¼þ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ15 ¡°CORONA¡±ÃüÁî


ÖµµÃ×¢ÒâµÄÊÇ £¬Corona-B-1ÔÚ×îеĴúÂëÖÐɾ³ýÁ˶ԸÃÃüÁîµÄºóÐø´¦Öà £¬Ç°Æڰ汾ͨ¹ýrecv()º¯ÊýÀ´½ÓÊÕºÍÅжϻØÏÔÐÅÏ¢£¨ÈçÈôCORONAÃüÁî²»´æÔÚ £¬busybox½«·µ»Ø¡°CORONA: applet not found¡±£©¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ16 оɰ汾ÃüÁî´¦ÖöԱÈ


ÔÚ¹¥»÷ģʽ·½Ãæ £¬Attack_parsing()º¯ÊýÂôÁ¦´¦ÖÃÓëC&C·þÎñÆ÷µÄÃüÁî½»»¥ £¬¾ßÌåµÄ¿ØÖÆÖ¸ÁîÊý×éÓɳõʼ½âÃܵõ½¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ17 ¿ØÖÆÖ¸ÁîÑ¡Ôñ


ϱíΪCorona-B-1Ö§³ÖµÄC&C¿ØÖÆÖ¸Áî¡£


±í3  C&C¿ØÖÆÖ¸Áî

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÆäÖÐ £¬Corona-B-1ÅäÖÃÁ˲¿ÃÅÈƹýDDOS·ÀÓùµÄ¹¥»÷ģʽ £¬ÀýÈçUDP bypass,TCP bypass £¬ÕâЩ¼¼Êõ×îÔçÀ´×ÔÓÚMiraiµÄDvrhelper±äÖÖ £¬Ò²±íÃ÷Corona-B-1¿ÉÄܼ̳нè¼øÁËDvrhelper±äÖֵIJ¿ÃÅ´úÂë¡£


?Corona-B-2


Corona-B-2µÄ¹ØÁªC&CΪ64[.]227[.]17[.]38 £¬¹¥»÷Õß½«¶àÖּܹ¹µÄ¶ñÒâÑù±¾ÃüÃûΪ¡°covid¡±¡£ÖµµÃ×¢ÒâµÄÊÇ £¬½üÆÚÆä¶ñÒâ´úÂ빦ЧµÄ¸üеü´ú·Ç³£Æµ·±¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͼ18 ·þÎñÆ÷¶ñÒâ´úÂë¸üÐÂÇé¿ö


Corona-B-2Ñù±¾°üÂÞTelnet±¬ÆÆ¡¢·´GDBµ÷ÊÔ¡¢½ûÓÿ´ÃŹ·(watchdog)µÈÄ£¿é¹¦Ð§ £¬Ïà½ÏÓÚCorona-B-1 £¬Corona-B-2¸ü½Ó½üÓÚÔ­ÉúµÄMirai¼Ò×塣ͨ¹ý½øÒ»²½±È¶Ô £¬Æ临ÓÃÁËMiraiµÄ´ó²¿ÃÅ´úÂë £¬µ«³õʼ»¯Ä£¿éºÍ¹¥»÷Ä£¿éÓÐËù±ä»¯¡£


³õʼ»¯Ä£¿é£¨table_init£©µÄtable_keyÓëMiraiµÄĬÈÏÅäÖòîÒ죨Corona-B-2µÄtable_keyΪ0xDEDEFBAF£© £¬Ïà¹Ø¼ÓÃÜÊý¾Ý¿ÉÒÔͨ¹ýMiraiÔ´ÂëÖеÄtools/enc.cÄ£¿é½øÐнâÃÜ¡£


¹¥»÷Ä£¿é£¨attack_init£©¹²×éºÏÁË13ÖÖ¹¥»÷·½Ê½ £¬Í¨¹ýBindiff½øÐÐоɰæµ×ϸËÆÐԱȶԺó £¬ÎÒÃÇ·¢ÏÖºÚ¿Í×éÖ¯ÔÚÁ¬ÐøÔö¼ÓºÍ¸üÐÂÑù±¾µÄ¹¥»÷Ä£¿é¡£


°üÂÞ£º


attack_method_nudp

attack_method_udphex

attack_method_udpdnsµÈ¡£


Ò²±íÃ÷¸Ã×éÖ¯½üÆڵĹ¥»÷ÓûÍû½ÏÇ¿¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ19 оɰ汾´úÂëÏàËÆÐÔ±ÈÁ¦


×ÛºÏÒÔÉ϶ÔÎïÁªÍø¡°ÒßÇéÑù±¾¡±µÄ·ÖÎö £¬¶àÖÖ¶ñÒâ´úÂë×îÖÕ¶¼¶¨Î»µ½ÁËGafgytºÍMirai¼Ò×åµÄ±äÖÖ £¬ËµÃ÷ÕâÁ½Àà¹ã·ºÁ÷´«µÄ¼Ò×åÈÔÊÇ´óÁ¿ºÚ¿Í¿ª·¢ÐÂÐÍÎïÁªÍø½©Ê¬µÄÊ×Ñ¡¡£Í¬Ê±´ÓÃüÃûÏ°¹ß¡¢¹¥»÷Ä¿±ê¡¢·þÎñÆ÷¹éÊôµØµÈÒòËØ×ÛºÏÅжÏ £¬ÕâÅú¹¥»÷Õß´ó¸ÅÂÊ»áÊǾ³ÍâµÄºÚ¿Í×éÖ¯¡£


Ïà¹ØÑù±¾µÄ¼Ò×å¹éÀàÕûÀíÈçÏÂͼËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ20 Ñù±¾¼Ò×å¹éÀà


Êܹ¥»÷IPÂþÑÜ


ƾ¾ÝÎÒÃǵļà²âÊý¾Ý £¬Ä¿Ç°¾³ÄÚÊܵ½ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±¹¥»÷µÄÉ豸IPÁè¼Ý22Íò £¬Ö÷ҪλÓÚÖйú¾³ÄÚ£¨96.8%£©¡£ÆäÖйúÄÚÖ÷ÒªÂþÑÜÓڹ㶫Ê¡£¨15.4%£©¡¢Õã½­Ê¡£¨14.2%£©¡¢±±¾©ÊУ¨13.7%£©¡¢½­ËÕÊ¡£¨10.0%£©µÈ¡£¾³ÄÚÊܹ¥»÷IPÂþÑÜͼÈçÏÂËùʾ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ͼ21 Êܹ¥»÷IPλÖÃÂþÑÜͼ


×ܽá


ͨ¹ýÒÔÉÏ·ÖÎö¿ÉÒÔ¿´³ö £¬ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±µÄÀ©É¢ºÍÈ«ÇòÒßÇéÉú³¤ÓÐ×ÅÒ»¶¨µÄÏà¹ØÐÔ¡£¼¼ÊõÉÏ £¬Æä´ó²¿ÃÅ»¹ÊǽÓÄÉÁ˾­µäµÄÎïÁªÍø²¡¶¾GafgytºÍMirai¼Ò×åµÄ¹¥»÷Ä£¿é £¬µ«ÊÇÆäÁ÷´«µÄĬÈÏÊÖ¶ÎÒÀÈ»ÊÇTelnet±¬ÆÆ £¬²¿ÃÅеÄÑù±¾¿ªÊ¼½áºÏһЩз¢Ïֵĩ¶´½øÐÐÀ©É¢Á÷´«¡£´ËÍâ £¬ÎªÁ˸üÓÐЧµÄ¶ÀÕ¼É豸×ÊÔ´ £¬ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±»¹¼ÓÇ¿Á˶ÔÆäËüÖ÷Á÷½©Ê¬¾ºÕù¶ÔÊֵķÀ¿ØºÍÆËɱ £¬¿ÉÒÔɱµô50¶àÖÖÀàÐ͵ÄÎïÁªÍø½©Ê¬½ø³Ì¡£Ò»Ð©Ñù±¾»¹½ÓÄÉÁË×Ô½ç˵µÄ¼Ó½âÃÜÄ£¿é £¬²¢²»Í£ÔÚ¹¥»÷Ä£¿éÖÐÈÚºÏÐµĹ¥»÷ÀàÐÍ¡£


¸ÃÅúÎïÁªÍø¡°¹Ú×´²¡¶¾¡±¹¥»÷ÊÖ·¨ºÍÌصãÀ´¿´²¢Ã»ÓÐÌ«¶àÐÂÆæµÄ¹¤¾ß £¬µ«ÊÇͨ¹ýÀûÓÃÏÖʵÊÀ½çµÄÕæʵʼþÀ´À©É¢¶ñÒâ¹¥»÷Õâһ˼·±Ø½«»áºã¾Ã´æÔÚ¡£¶ÔЩ¶´µÄÎäÆ÷»¯ÒÀÈ»ÊÇÎïÁªÍøºÚ¿ÍÃǵÄÖصã¹ØעƫÏò¡£ºÚ¿Í´Ó·þÎñÆ÷¡¢PC¡¢ÖÇÄÜÊÖ»ú £¬À©Õ¹ÏòÉãÏñÍ·¡¢Â·ÓÉÆ÷¡¢NAS¡¢¼Ò¾Ó°²·Àϵͳ¡¢ÖÇÄܵçÊÓ¡¢ÖÇÄÜ´©×ÅÉ豸 £¬ÉõÖÁÊÇÓ¤¶ù¼àÊÓÆ÷ £¬Èκλ¥ÁªÍøÁ¬½ÓµÄÉ豸¶¼²»»á·Å¹ý £¬ÕâÒ²ÊǺã¾ÃÒÔÀ´ÎïÁªÍø¶ñÒâ´úÂë±£³Ö¶àƽ̨¼æÈݵÄÔ­Òò¡£ÎïÁªÍøµÄÍþв¶ÔÓÚÆÕͨ¹ÜÀíÔ±À´ËµÊǺÜÄѲì¾õµÄ £¬¾ÍÏñ´¦ÓÚDZ·üÆÚµÄÊÜѬȾÕßÒ»Ñù £¬ÎÞ·¨¼°Ê±·ÀÓùºÍÇå³ý¡£×îºó £¬ÔÚÒßÇé֮Ϡ£¬ÎÒÃǸüÓ¦¸Ã¾¯Ìè±ðÓÐÓÃÐĵÄÎïÁªÍø¡°¹Ú×´²¡¶¾¡±´ó·ùÀ©É¢ £¬ÕùÈ¡ÔçÈÕսʤÒßÇé £¬Õ½Ê¤²¡¶¾¡£Òò´ËÎÒÃǽ¨ÒéÓû§£º


( 1 ) ¼°Ê±¸üÐÂÉý¼¶ÎïÁªÍøÉ豸¹Ì¼þ£»

( 2 ) ¾¡¿ì¸ü»»É豸³§É̳õʼÃÜÂë £¬×¢ÒâÖÆÖ¹¿Õ¿ÚÁî»òÈõ¿ÚÁ

( 3 ) ÈçÎÞÐëÒª £¬¾¡¿ÉÄܲ»Òª½«²úÎïÖ±½Ó̻¶ÔÚ»¥ÁªÍøÉÏ £¬Èç±ØÐëÁªÍø £¬¿É½«É豸Á¬½Óµ½Äþ¾²Â·ÓÉÆ÷»ò·À»ðǽ £¬½øÐиü¶àµÄ·À»¤£»

( 4 ) ¼ÓÇ¿ÍøÂç½çÏÞÈëÇÖ·À·¶ºÍ¹ÜÀí £¬¹Ø±Õ·ÇÐëÒªµÄÍøÂç·þÎñºÍ¶Ë¿Ú £¬ÈçSSH£¨22£©¡¢Telnet(23)¡¢HTTP/HTTPS £¨80¡¢443£©µÈ¡£


IOCÑùÀý


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



±¾³ÂËßÓÉCNCERTÎïÁªÍøÄþ¾²Ñо¿ÍŶÓÓ붫ɭƽ̨ADLabÁªºÏÐû²¼