ÍøÂç ¡°¹Ú×´²¡¶¾¡± |c7c7ÓéÀÖÆ½Ì¨ADLabÁªºÏCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶÓÐû²¼×îÐÂÑо¿±¨¸æ

Ðû²¼Ê±¼ä 2020-03-27

¸Å¿ö


Ëæ×Å¡°ÐÂÐ͹Ú×´²¡¶¾·ÎÑס±ÉÏÉýΪȫÇòÐÔ¹«¹²ÎÀÉúÍ»·¢ÊÂÎñ£¬£¬ £¬£¬£¬£¬¸÷¹úÃñÖÚ¿ªÆôÁË¡°Õ¬¿¹Òß¡¢ÔÆÉúÑÄ¡±Ä£Ê½¡£¡£¡£¡£ÔÚºÜÊÇʱÆÚ£¬£¬ £¬£¬£¬£¬ÍøÂç¿Õ¼äÔÚÈËÃǵÄÒ»Ñùƽ³£ÉúÑıäµÃÔ½·¢²»¿É»òȱ£¬£¬ £¬£¬£¬£¬È»¶øµ±¸÷È˶¼ÔÚ·ÜÁ¦¿¹ÒßµÄͬʱ£¬£¬ £¬£¬£¬£¬´ó×ڵĺڿÍÈ´×îÏÈÒÔ¡°¹Ú×´²¡¶¾¡±ÃûÒå´ÓÊ´ó¹æÄ£µÄÍøÂç¹¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬³ýÁËÏÖÔÚÒѾ­·¢Ã÷ÒÔ¹Ú×´²¡¶¾ÎªÃû¾ÙÐеÄAPT¹¥»÷¡¢ÀÕË÷²¡¶¾¹¥»÷Ö®Í⣬£¬ £¬£¬£¬£¬ÎïÁªÍøÁìÓòÖÐÒÔ¹Ú×´²¡¶¾ÎªÃûµÄÏà¹Ø¹¥»÷Ò²¿ìËÙÉÏÉý¡£¡£¡£¡£


ÕâЩÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾ÒÔ¡°Corona¡±£¨¹Ú×´µÄÓ¢ÎÄ£©¡¢¡°covid¡±£¨¹Ú×´²¡¶¾Ó¢ÎÄËõд£©ÃüÃû£¬£¬ £¬£¬£¬£¬²¢Ê¹ÓÃÎïÁªÍø×°±¸Ëù±£´æµÄÎó²î¾ÙÐÐÈö²¥¡£¡£¡£¡£ÎÒÃÇͨ¹ý¼à²âÊý¾Ý·¢Ã÷£¬£¬ £¬£¬£¬£¬¸ÃÀàÑù±¾µÄÊýÄ¿ÓëÒßÇéÉú³¤·ºÆðÒ»¶¨Ë®Æ½µÄÏà¹ØÐÔ£¬£¬ £¬£¬£¬£¬ºÃ±È½øÈë3Ô·ÝËæ×ÅÈ«ÇòÒßÇéÒ»Á¬ÉýΣ¬£¬ £¬£¬£¬£¬ÒÔ¡°covid¡±ÃüÃûµÄÑù±¾×îÏÈÏÔÖøÔö¶à¡£¡£¡£¡£


ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾Í³¼ÆÆÊÎö


×èÖ¹µ½2020Äê3ÔÂ26ÈÕ£¬£¬ £¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ÎïÁªÍøÍþвÊý¾Ýƽ̨¹²²¶»ñµ½801¸öÒÔ¹Ú×´²¡¶¾ÃüÃûµÄÑù±¾¡£¡£¡£¡£ÎÒÃÇÕë¶ÔÕâЩÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾¾ÙÐÐÁË·ÂÕæÇéÐζ¯Ì¬ÆÊÎö£¬£¬ £¬£¬£¬£¬Ñù±¾µÄC&CÉÏÏßÂþÑÜÇéÐÎÈçͼ1Ëùʾ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ1 ½©Ê¬Ñù±¾C&CÉÏÏßÂþÑÜ


Êý¾ÝÏÔʾ£¬£¬ £¬£¬£¬£¬ÕâÅúÎïÁªÍø¡°¹Ú×´²¡¶¾¡±Ñù±¾Öй²½ü90%µÄÑù±¾ÊÜ¿ØÓÚλÓÚÃÀ¹úµÄ5¸öC&CЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬7%λÓÚ¶íÂÞ˹£¬£¬ £¬£¬£¬£¬4%λÓÚºÉÀ¼¡£¡£¡£¡£ÆäÖÐÓÐ6¸öC&CЧÀÍÆ÷ÔÚÒßÇéʱ´ú½ÏΪ»îÔ¾£¬£¬ £¬£¬£¬£¬ÇÒ¹ØÁªµÄÑù±¾Á¿½Ï´ó£¬£¬ £¬£¬£¬£¬°üÀ¨X86¡¢ARM¡¢MIPS¡¢PowerPC¡¢SPARC¡¢Renesas SHµÈ¶à¸öƽ̨µÄELFÎļþ¡£¡£¡£¡£Í¨¹ý½øÒ»²½µÄͬԴÐÔÆÊÎö£¬£¬ £¬£¬£¬£¬ÎÒÃǽ«ÕâЩÑùÌìÖ°³ÉÁ½À࣬£¬ £¬£¬£¬£¬»®·ÖÃüÃûΪCorona-A¡¢Corona-B£¬£¬ £¬£¬£¬£¬ºóÎĽ«½øÒ»²½Ì½ÌÖËüÃǵÄÊÖÒÕÌØµãºÍËùÊô¼Ò×å¡£¡£¡£¡£


ÕâÅú¡°¹Ú×´²¡¶¾¡±Ñù±¾µÄÖ÷ÒªÈö²¥ÊÖ¶ÎÈÔÈ»ÊÇͨ¹ýÄÚÖÃÃÜÂë±¾¾ÙÐÐTelnetÃÜÂë±¬ÆÆ£¬£¬ £¬£¬£¬£¬²¿·ÖÑù±¾Ê¹Óõ½ÁË¡°Redis δÊÚȨ´úÂëÖ´ÐС±µÈ¶à¸öÒÑÖªÎó²îʹÓþÙÐÐÈö²¥¡£¡£¡£¡£ÁíÍâÔÚÎÒÃÇËÝÔ´ÆÊÎöµÄÀú³ÌÖУ¬£¬ £¬£¬£¬£¬·¢Ã÷Ïà¹Ø×éÖ¯½üÆÚʹÓÃ×îеÄÎó²îCVE-2020-9054[1]£¨ZyxelÍøÂçÁ¥Êô´æ´¢£¨NAS£©×°±¸£©¿ªÕ¹¹¥»÷»î¶¯¡£¡£¡£¡£¾ÝÖøÃûÊÓ²ìÖ°Ô±Brian KrebsµÄ˵·¨£¬£¬ £¬£¬£¬£¬¸ÃÎó²îµÄÏà¹ØPOCÔÚµØÏÂÂÛ̳±»ÒÔ2ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ£¬£¬ £¬£¬£¬£¬Í¬Ê±Ò²ÎüÒýÁË´ó×ÚÀÕË÷Èí¼þ¹¥»÷×éÖ¯µÄÐËȤ£¨¿ÉÄÜ»¹ÓëEmotetÓйأ©¡£¡£¡£¡£ÓÉÓÚÎó²îµÄÑÏÖØÐÔ£¬£¬ £¬£¬£¬£¬ÃÀ¹úCERT/CC½«¸ÃÎó²î¶¨ÎªCVSS10·Ö¡£¡£¡£¡£


±í1 Ñù±¾Èö²¥Ê¹ÓõÄ×°±¸Îó²î

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ÊÖÒÕÆÊÎö


1¡¢Corona-AÀàÑù±¾ÊÖÒÕÆÊÎö


ÔÚ¶ÔCorona-AÀàÑù±¾¾ÙÐÐÕûÌåÆÊÎöºó£¬£¬ £¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ÆäÖеıäÖÖËä¶à£¬£¬ £¬£¬£¬£¬µ«ÖÖÖÖÑù±¾¼äµÄÏàËÆ¶ÈºÜ¸ß£¬£¬ £¬£¬£¬£¬¹ÊÒÔ½üÆÚ»îÔ¾µÄC&C (192[.]3[.]193[.]251)ΪÀý£¬£¬ £¬£¬£¬£¬¶Ô¹ØÁªÑù±¾¾ÙÐÐÄæÏòÆÊÎö£¬£¬ £¬£¬£¬£¬Æä¶àÖּܹ¹µÄÑù±¾¾ù±»ÃüÃûΪ¡°Corona¡±¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ2 Shell¾ç±¾


½©Ê¬³ÌÐòÔËÐк󣬣¬ £¬£¬£¬£¬Ê×ÏȰó¶¨ÍâµØ¶Ë¿Ú0x22B8£¨8888¶Ë¿Ú£©£¬£¬ £¬£¬£¬£¬ÅþÁ¬C&CµØµãΪ£º192[.]3[.]193[.]251:20¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ3  ¼àÌýÍâµØ¶Ë¿Ú


ͨ¹ýensure_bindº¯ÊýÈ·±£Ñù±¾³ÌÐòÖ»±£´æµ¥ÊµÀýÔËÐС£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ4  ¼ì²éµ¥ÊµÀýÔËÐÐ


Ö´ÐÐbotkillerÄ£¿ £¿£¿£¿éÒÔɨ³ýÆäËü±£´æ¾ºÕùµÄÖ÷Á÷½©Ê¬³ÌÐò¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ5 Ö´ÐÐbotkillerÄ£¿ £¿£¿£¿é


Ðèɨ³ýµÄ½©Ê¬¼Ò×åºÍ¹ØÁª×Ö·û´®ÈçÏÂͼËùʾ£º


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ6 ɨ³ýµÄÄ¿µÄ¼Ò×å¼°¹ØÁª×Ö·û´®


¶ñÒâ´úÂëÖжദӲ±àÂëÁË¡°Corona¡±Òªº¦´Ê£¬£¬ £¬£¬£¬£¬°üÀ¨ÉÏÏßÊý¾Ý°üºÍÅþÁ¬ÖÐÖ¹µÄÊä³öÏÔʾ£¨½©Ê¬Ð§ÀͶ˿ÉÄܽ«¡°Corona¡±×÷ΪͨѶЭÒéʶ±ðµÄÒªº¦ÌØÕ÷£©¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ7 Ó²±àÂë¡°Corona¡±Òªº¦´Ê


ÉÏÏß°ü¼°C&C»Ø¸´°üͨѶÁ÷Á¿ÈçÏÂͼËùʾ£º


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ8 TCPͨѶÁ÷Á¿


Ñù±¾µÄproc_cmd()º¯Êý°üÀ¨DDoS¹¥»÷Ä£¿ £¿£¿£¿é£¬£¬ £¬£¬£¬£¬ÆäÈÚºÏÁ˶àÖÖ³£¼ûµÄ¹¥»÷ģʽ£¬£¬ £¬£¬£¬£¬°üÀ¨UDP¡¢VSE¡¢HTTP¡¢TCP¡¢STD¡¢XMASµÈ¡£¡£¡£¡£Í¬Ê±ÔÚÕë¶Ô¸ÃC&C¼à¿ØµÄÀú³ÌÖУ¬£¬ £¬£¬£¬£¬ÎÒÃÇ·¢Ã÷Æä½üÆÚ·¢¶¯µÄDDoS¹¥»÷»î¶¯½ÏΪƵÈÔ£¬£¬ £¬£¬£¬£¬Ö÷ҪĿµÄΪÎ÷Å·¹ú¼Ò£¬£¬ £¬£¬£¬£¬²¿·Ö¹¥»÷ʾÀýÈçÏÂͼËùʾ£º


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ9 ¹¥»÷ÇéÐÎʾÀý


»ùÓÚÑù±¾µÄ´úÂë½á¹¹¡¢º¯ÊýÃüÃû¡¢Í¨Ñ¶Á÷Á¿¡¢¹¥»÷ģʽµÈÌØÕ÷£¬£¬ £¬£¬£¬£¬¿ÉÒÔ·¢Ã÷Corona-AÀàÑù±¾ÓëGafgyt¼Ò×åµÄÏàËÆ¶ÈºÜ¸ß£¬£¬ £¬£¬£¬£¬ºÚ¿ÍËä¶ÔͨѶÊý¾ÝµÈÄÚÈݰü×°ÁË¡°Ð¹ڡ±¿´·¨£¬£¬ £¬£¬£¬£¬µ«´úÂëÔÚÕûÌåÉÏÈÔÓëGafgyt¼Ò×åÏà½ü£¬£¬ £¬£¬£¬£¬¿ÉÒÔÒÔΪÊÇGafgyt¼Ò×åµÄ±äÖÖ¡£¡£¡£¡£Corona-AµÄÆäËüÀàÐÍÑù±¾Ò²Í¬Ñù»ùÓÚGafgyt¾ÙÐÐÐ޸쬣¬ £¬£¬£¬£¬Ôڴ˲»×ö׸Êö¡£¡£¡£¡£


2¡¢Corona-BÀàÑù±¾ÊÖÒÕÆÊÎö


Corona-BÀà¶ñÒâÑù±¾µÄ´úÂëÏà½ÏCorona-A¸üÎªÖØ´ó£¬£¬ £¬£¬£¬£¬ÇҴ󲿷ÖÑù±¾¾ÙÐÐÁË·ûºÅ°þÀ룬£¬ £¬£¬£¬£¬¶ÔÄæÏòÆÊÎö»á±¬·¢½Ï´ó×ÌÈÅ¡£¡£¡£¡£¿ÉÊǺڿͰÙÃÜÒ»Ê裬£¬ £¬£¬£¬£¬ÔÚ´ó×ÚÑù±¾ÖУ¬£¬ £¬£¬£¬£¬ÒÀÈ»±£´æ¸öÌåarm¼Ü¹¹µÄÑù±¾°üÀ¨·ûºÅ£¬£¬ £¬£¬£¬£¬¿É¹©Ñо¿ÆÊÎö¡£¡£¡£¡£Í¨¹ý½øÒ»²½µÄÊӲ죬£¬ £¬£¬£¬£¬ÎÒÃÇ·¢Ã÷Corona-BÀàÑù±¾¼äµÄ²î±ð½Ï´ó£¬£¬ £¬£¬£¬£¬¿ÉÒÔϸ·ÖΪ±äÖÖCorona-B-1ºÍ±äÖÖCorona-B-2¾ÙÐÐÆÊÎö¡£¡£¡£¡£


? Corona-B-1


Corona-B-1µÄ¹ØÁªC&CΪ45[.]84[.]196[.]75£¬£¬ £¬£¬£¬£¬Ïà¹ØÑù±¾Õ¼²¶»ñ×ÜÁ¿µÄ64%£¬£¬ £¬£¬£¬£¬ÊÇÏÖÔÚ·¢Ã÷Ñù±¾Á¿×î´óµÄÎïÁªÍø¡°¹Ú×´²¡¶¾¡±£¬£¬ £¬£¬£¬£¬½üÒ»¸öÔÂʱ¼äÄÚµü´úÁ˶à¸ö°æ±¾¡£¡£¡£¡£ÔÚËÝÔ´ÆÊÎöµÄÀú³ÌÖУ¬£¬ £¬£¬£¬£¬ÎÒÃÇ·¢Ã÷Ïà¹Ø×éÖ¯½üÆÚʹÓÃZyxelÍøÂçÁ¥Êô´æ´¢£¨NAS£©×°±¸µÄ×îÐÂÎó²îCVE-2020-9054¿ªÕ¹¹¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬Ïà¹ØÈëÇÖÁ÷Á¿ÈçÏÂͼËùʾ£º


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ10 Îó²îÈëÇÖÁ÷Á¿


CVE-2020-9054Îó²îÊÇÍøÂç²úÆ·¹©Ó¦ÉÌZyxel½üÆÚÐÞ¸´µÄÒ»¸öÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬ £¬£¬£¬£¬Îó²îÓ°Ïì¶à¿îNAS×°±¸£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýweblogin.cgi×é¼þ´¥·¢ÏÂÁî×¢Èë²¢¼ÓÔØ¶ñÒâ´úÂë¡£¡£¡£¡£


¹¥»÷Àֳɺó»áÖ´ÐÐshell¾ç±¾ÏÂÔØ²î±ð¼Ü¹¹µÄ½©Ê¬Ñù±¾¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ11 Ö´ÐÐshell¾ç±¾


´ËÀà¶ñÒâÑù±¾Ò²ÔøÒÔ¡°corona¡±×÷Ϊºó׺Ãû¾ÙÐÐÏÂÔØÈö²¥¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ12 ¡°corona¡±ºó׺Ñù±¾


ͨ¹ý½øÒ»²½µÄÆÊÎöÈ·ÈÏ£¬£¬ £¬£¬£¬£¬Corona-B-1ÊÇMirai¼Ò×åµÄбäÖÖMukashi£¬£¬ £¬£¬£¬£¬ËäÈ»´úÂëδ¼¯³ÉÎó²îʹÓÃÄ£¿ £¿£¿£¿é£¬£¬ £¬£¬£¬£¬µ«ºÚ¿ÍÓкܴó¿ÉÄÜÔÚʹÓÃCVE-2020-9054Îó²î¾ÙÐй¥»÷²¢Èö²¥¶ñÒâÑù±¾£¬£¬ £¬£¬£¬£¬ÐèÒªÒýÆð¸÷·½ÖØÊÓ¡£¡£¡£¡£


Corona-B-1ÓëÆäËüMirai¼Ò×å²î±ðµÄÊÇ£¬£¬ £¬£¬£¬£¬ÆäÔÚ³õʼ»¯Ä£¿ £¿£¿£¿éÖУ¬£¬ £¬£¬£¬£¬²¢Î´½ÓÄÉͨÀýµÄxor¼Ó½âÃÜ£¬£¬ £¬£¬£¬£¬¶øÊÇʹÓÃÁË×Ô½ç˵µÄ½âÃÜģʽ¡£¡£¡£¡£Æä²î±ð°æ±¾µÄ½âÃÜËã·¨Ïàͬ£¬£¬ £¬£¬£¬£¬µ«Ô¤ÖüÓÃÜ×Ö·û´®²î±ð£¬£¬ £¬£¬£¬£¬³õʼ¼ÓÃÜ×Ö·û´®Ê¾ÀýÈçÏÂͼËùʾ¡£¡£¡£¡£


(Ñù±¾ad61c361f76026e0b0c1ff1bc62b52e7) :


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ13 ³õʼ¼ÓÃÜ×Ö·û´®


½âÃܺóµÄÏÂÁîºÍ×Ö·û´®»á´æ´¢µ½TableÖй©ºóÐøÊ¹Ó㬣¬ £¬£¬£¬£¬¶ÔÓ¦ÐÅÏ¢ÈçϱíËùʾ£º


±í2 ½âÃܺóµÄÏÂÁîºÍ×Ö·û´®

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


Corona-B-1µÄɨÃèÄ£¿ £¿£¿£¿éscanner_initÔòͬMirai¼Ò×åµÄ´ó´ó¶¼±äÖÖÒ»Ñù£¬£¬ £¬£¬£¬£¬½ÓÄÉTelnet±¬ÆÆ£¬£¬ £¬£¬£¬£¬²¢Ê¹Óòî±ðµÄĬÈÏÆ¾Ö¤×éºÏ¾ÙÐеǼ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ14 ɨÃèÁ÷Á¿


Ò»µ©Telnet±¬ÆÆÀÖ³ÉÔò»áÒÔ¡°<host ip addr>:23 <username>:<password>¡±µÄÃûÌý«ÐÅÏ¢Ìá½»¸øC&C¡£¡£¡£¡£


ͬʱ£¬£¬ £¬£¬£¬£¬Corona-B-1»áÊÔͼ·¢ËÍÏÂÁîÖ´ÐÐһЩ²Ù×÷£¬£¬ £¬£¬£¬£¬Èç¡°system¡±¡¢¡°shell¡±µÈĬÈÏÏÂÁ£¬ £¬£¬£¬£¬ Corona-B-1ÔÚ´Ë´¦ÐÂÔöÁË"/bin/busybox CORONA"ÏÂÁ£¬ £¬£¬£¬£¬¿ÉÒÔ½øÒ»²½Ö´ÐÐbusyboxÖеĶñÒâ´úÂ벿¼þ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ15 ¡°CORONA¡±ÏÂÁî


ÖµµÃ×¢ÖØµÄÊÇ£¬£¬ £¬£¬£¬£¬Corona-B-1ÔÚ×îеĴúÂëÖÐɾ³ýÁ˶ԸÃÏÂÁîµÄºóÐø´¦Öóͷ££¬£¬ £¬£¬£¬£¬Ç°ÆÚ°æ±¾Í¨¹ýrecv()º¯ÊýÀ´ÎüÊÕºÍÅжϻØÏÔÐÅÏ¢£¨ÈçÈôCORONAÏÂÁî²»±£´æ£¬£¬ £¬£¬£¬£¬busybox½«·µ»Ø¡°CORONA: applet not found¡±£©¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ16 оɰ汾ÏÂÁî´¦Öóͷ£±ÈÕÕ


ÔÚ¹¥»÷ģʽ·½Ã棬£¬ £¬£¬£¬£¬Attack_parsing()º¯ÊýÈÏÕæ´¦Öóͷ£ÓëC&CЧÀÍÆ÷µÄÏÂÁî½»»¥£¬£¬ £¬£¬£¬£¬ÏêϸµÄ¿ØÖÆÖ¸ÁîÊý×éÓɳõʼ½âÃÜ»ñµÃ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ17 ¿ØÖÆÖ¸ÁîÑ¡Ôñ


ϱíΪCorona-B-1Ö§³ÖµÄC&C¿ØÖÆÖ¸Áî¡£¡£¡£¡£


±í3  C&C¿ØÖÆÖ¸Áî

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ÆäÖУ¬£¬ £¬£¬£¬£¬Corona-B-1ÉèÖÃÁ˲¿·ÖÈÆ¹ýDDOS·ÀÓùµÄ¹¥»÷ģʽ£¬£¬ £¬£¬£¬£¬ÀýÈçUDP bypass,TCP bypass£¬£¬ £¬£¬£¬£¬ÕâЩÊÖÒÕ×îÔçÀ´×ÔÓÚMiraiµÄDvrhelper±äÖÖ£¬£¬ £¬£¬£¬£¬Ò²Åú×¢Corona-B-1¿ÉÄܼÌÐø½è¼øÁËDvrhelper±äÖֵIJ¿·Ö´úÂë¡£¡£¡£¡£


?Corona-B-2


Corona-B-2µÄ¹ØÁªC&CΪ64[.]227[.]17[.]38£¬£¬ £¬£¬£¬£¬¹¥»÷Õß½«¶àÖּܹ¹µÄ¶ñÒâÑù±¾ÃüÃûΪ¡°covid¡±¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬ £¬£¬£¬£¬½üÆÚÆä¶ñÒâ´úÂ빦ЧµÄ¸üеü´úºÜÊÇÆµÈÔ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ͼ18 ЧÀÍÆ÷¶ñÒâ´úÂë¸üÐÂÇéÐÎ


Corona-B-2Ñù±¾°üÀ¨Telnet±¬ÆÆ¡¢·´GDBµ÷ÊÔ¡¢½ûÓÿ´ÃŹ·(watchdog)µÈÄ£¿ £¿£¿£¿é¹¦Ð§£¬£¬ £¬£¬£¬£¬Ïà½ÏÓÚCorona-B-1£¬£¬ £¬£¬£¬£¬Corona-B-2¸ü¿¿½üÓÚÔ­ÉúµÄMirai¼Ò×å¡£¡£¡£¡£Í¨¹ý½øÒ»²½±È¶Ô£¬£¬ £¬£¬£¬£¬Æä¸´ÓÃÁËMiraiµÄ´ó²¿·Ö´úÂ룬£¬ £¬£¬£¬£¬µ«³õʼ»¯Ä£¿ £¿£¿£¿éºÍ¹¥»÷Ä£¿ £¿£¿£¿éÓÐËùת±ä¡£¡£¡£¡£


³õʼ»¯Ä£¿ £¿£¿£¿é£¨table_init£©µÄtable_keyÓëMiraiµÄĬÈÏÉèÖòî±ð£¨Corona-B-2µÄtable_keyΪ0xDEDEFBAF£©£¬£¬ £¬£¬£¬£¬Ïà¹Ø¼ÓÃÜÊý¾Ý¿ÉÒÔͨ¹ýMiraiÔ´ÂëÖеÄtools/enc.cÄ£¿ £¿£¿£¿é¾ÙÐнâÃÜ¡£¡£¡£¡£


¹¥»÷Ä£¿ £¿£¿£¿é£¨attack_init£©¹²×éºÏÁË13ÖÖ¹¥»÷·½·¨£¬£¬ £¬£¬£¬£¬Í¨¹ýBindiff¾ÙÐÐоɰæÄÚÇéËÆÐԱȶԺ󣬣¬ £¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ºÚ¿Í×éÖ¯ÔÚÒ»Á¬ÔöÌíºÍ¸üÐÂÑù±¾µÄ¹¥»÷Ä£¿ £¿£¿£¿é¡£¡£¡£¡£


°üÀ¨£º


attack_method_nudp

attack_method_udphex

attack_method_udpdnsµÈ¡£¡£¡£¡£


Ò²Åú×¢¸Ã×éÖ¯½üÆÚµÄ¹¥»÷ÓûÍû½ÏÇ¿¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ19 оɰ汾´úÂëÏàËÆÐÔ½ÏÁ¿


×ÛºÏÒÔÉ϶ÔÎïÁªÍø¡°ÒßÇéÑù±¾¡±µÄÆÊÎö£¬£¬ £¬£¬£¬£¬¶àÖÖ¶ñÒâ´úÂë×îÖÕ¶¼¶¨Î»µ½ÁËGafgytºÍMirai¼Ò×åµÄ±äÖÖ£¬£¬ £¬£¬£¬£¬ËµÃ÷ÕâÁ½ÀàÆÕ±éÈö²¥µÄ¼Ò×åÈÔÊÇ´ó×ÚºÚ¿Í¿ª·¢ÐÂÐÍÎïÁªÍø½©Ê¬µÄÊ×Ñ¡¡£¡£¡£¡£Í¬Ê±´ÓÃüÃûϰ¹ß¡¢¹¥»÷Ä¿µÄ¡¢Ð§ÀÍÆ÷¹éÊôµØµÈÒòËØ×ÛºÏÅжÏ£¬£¬ £¬£¬£¬£¬ÕâÅú¹¥»÷Õß»òÐíÂÊ»áÊǾ³ÍâµÄºÚ¿Í×éÖ¯¡£¡£¡£¡£


Ïà¹ØÑù±¾µÄ¼Ò×å¹éÀàÕûÀíÈçÏÂͼËùʾ£º


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ20 Ñùͬ×å×å¹éÀà


Êܹ¥»÷IPÂþÑÜ


ƾ֤c7c7ÓéÀÖÆ½Ì¨¼à²âÊý¾Ý£¬£¬ £¬£¬£¬£¬ÏÖÔÚ¾³ÄÚÊܵ½ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±¹¥»÷µÄ×°±¸IPÁè¼Ý22Íò£¬£¬ £¬£¬£¬£¬Ö÷ҪλÓÚÖйú¾³ÄÚ£¨96.8%£©¡£¡£¡£¡£ÆäÖк£ÄÚÖ÷ÒªÂþÑÜÓڹ㶫Ê¡£¡£¡£¡£¨15.4%£©¡¢Õã½­Ê¡£¡£¡£¡£¨14.2%£©¡¢±±¾©ÊУ¨13.7%£©¡¢½­ËÕÊ¡£¡£¡£¡£¨10.0%£©µÈ¡£¡£¡£¡£¾³ÄÚÊܹ¥»÷IPÂþÑÜͼÈçÏÂËùʾ£º


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ21 Êܹ¥»÷IPλÖÃÂþÑÜͼ


×ܽá


ͨ¹ýÒÔÉÏÆÊÎö¿ÉÒÔ¿´³ö£¬£¬ £¬£¬£¬£¬ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±µÄÀ©É¢ºÍÈ«ÇòÒßÇéÉú³¤ÓÐ×ÅÒ»¶¨µÄÏà¹ØÐÔ¡£¡£¡£¡£ÊÖÒÕÉÏ£¬£¬ £¬£¬£¬£¬Æä´ó²¿·ÖÕվɽÓÄÉÁ˾­µäµÄÎïÁªÍø²¡¶¾GafgytºÍMirai¼Ò×åµÄ¹¥»÷Ä£¿ £¿£¿£¿é£¬£¬ £¬£¬£¬£¬¿ÉÊÇÆäÈö²¥µÄĬÈÏÊÖ¶ÎÒÀÈ»ÊÇTelnet±¬ÆÆ£¬£¬ £¬£¬£¬£¬²¿·ÖеÄÑù±¾×îÏÈÁ¬ÏµÒ»Ð©Ð·¢Ã÷µÄÎó²î¾ÙÐÐÀ©É¢Èö²¥¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬ÎªÁ˸üÓÐÓõĶÀÍÌ×°±¸×ÊÔ´£¬£¬ £¬£¬£¬£¬ÎïÁªÍø¡°¹Ú×´²¡¶¾¡±»¹ÔöÇ¿ÁË¶ÔÆäËüÖ÷Á÷½©Ê¬¾ºÕùµÐÊֵķÀ¿ØºÍÆËɱ£¬£¬ £¬£¬£¬£¬¿ÉÒÔɱµô50¶àÖÖÀàÐ͵ÄÎïÁªÍø½©Ê¬Àú³Ì¡£¡£¡£¡£Ò»Ð©Ñù±¾»¹½ÓÄÉÁË×Ô½ç˵µÄ¼Ó½âÃÜÄ£¿ £¿£¿£¿é£¬£¬ £¬£¬£¬£¬²¢Ò»Ö±ÔÚ¹¥»÷Ä£¿ £¿£¿£¿éÖÐÈÚºÏÐµĹ¥»÷ÀàÐÍ¡£¡£¡£¡£


¸ÃÅúÎïÁªÍø¡°¹Ú×´²¡¶¾¡±¹¥»÷ÊÖ·¨ºÍÌØµãÀ´¿´²¢Ã»ÓÐÌ«¶àÐÂÓ±µÄ¹¤¾ß£¬£¬ £¬£¬£¬£¬¿ÉÊÇͨ¹ýʹÓÃÏÖʵÌìϵÄÕæÊµÊÂÎñÀ´À©É¢¶ñÒâ¹¥»÷Õâһ˼Ð÷±Ø½«»áºã¾Ã±£´æ¡£¡£¡£¡£¶ÔÐÂÎó²îµÄÎäÆ÷»¯ÒÀÈ»ÊÇÎïÁªÍøºÚ¿ÍÃǵÄÖØµã¹Ø×¢Æ«Ïò¡£¡£¡£¡£ºÚ¿Í´ÓЧÀÍÆ÷¡¢PC¡¢ÖÇÄÜÊÖ»ú£¬£¬ £¬£¬£¬£¬À©Õ¹ÏòÉãÏñÍ·¡¢Â·ÓÉÆ÷¡¢NAS¡¢¼Ò¾Ó°²·Àϵͳ¡¢ÖÇÄܵçÊÓ¡¢ÖÇÄÜÒÂ×Å×°±¸£¬£¬ £¬£¬£¬£¬ÉõÖÁÊÇÓ¤¶ù¼àÊÓÆ÷£¬£¬ £¬£¬£¬£¬Èκλ¥ÁªÍøÅþÁ¬µÄ×°±¸¶¼²»»á·Å¹ý£¬£¬ £¬£¬£¬£¬ÕâÒ²ÊǺã¾ÃÒÔÀ´ÎïÁªÍø¶ñÒâ´úÂë¼á³Ö¶àƽ̨¼æÈݵÄÔµ¹ÊÔ­ÓÉ¡£¡£¡£¡£ÎïÁªÍøµÄÍþв¹ØÓÚͨË×ÖÎÀíÔ±À´ËµÊǺÜÄѲì¾õµÄ£¬£¬ £¬£¬£¬£¬¾ÍÏñ´¦ÓÚDZÔÚÆÚµÄÊÜѬȾÕßÒ»Ñù£¬£¬ £¬£¬£¬£¬ÎÞ·¨ÊµÊ±·ÀÓùºÍɨ³ý¡£¡£¡£¡£×îºó£¬£¬ £¬£¬£¬£¬ÔÚÒßÇé֮ϣ¬£¬ £¬£¬£¬£¬ÎÒÃǸüÓ¦¸ÃСÐıðÓÐרÐĵÄÎïÁªÍø¡°¹Ú×´²¡¶¾¡±´ó·ùÀ©É¢£¬£¬ £¬£¬£¬£¬ÕùÈ¡ÔçÈÕսʤÒßÇ飬£¬ £¬£¬£¬£¬Õ½Ê¤²¡¶¾¡£¡£¡£¡£Òò´ËÎÒÃǽ¨ÒéÓû§£º


( 1 ) ʵʱ¸üÐÂÉý¼¶ÎïÁªÍø×°±¸¹Ì¼þ£»£» £»

( 2 ) ¾¡¿ìÌæ»»×°±¸³§É̳õʼÃÜÂ룬£¬ £¬£¬£¬£¬×¢ÖØ×èÖ¹¿Õ¿ÚÁî»òÈõ¿ÚÁ£» £»

( 3 ) ÈçÎÞÐëÒª£¬£¬ £¬£¬£¬£¬¾¡¿ÉÄܲ»Òª½«²úÆ·Ö±½Ó̻¶ÔÚ»¥ÁªÍøÉÏ£¬£¬ £¬£¬£¬£¬Èç±ØÐèÁªÍø£¬£¬ £¬£¬£¬£¬¿É½«×°±¸ÅþÁ¬µ½Ç徲·ÓÉÆ÷»ò·À»ðǽ£¬£¬ £¬£¬£¬£¬¾ÙÐиü¶àµÄ·À»¤£»£» £»

( 4 ) ÔöÇ¿ÍøÂç½çÏßÈëÇÖÌá·ÀºÍÖÎÀí£¬£¬ £¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÍøÂçЧÀͺͶ˿Ú£¬£¬ £¬£¬£¬£¬ÈçSSH£¨22£©¡¢Telnet(23)¡¢HTTP/HTTPS £¨80¡¢443£©µÈ¡£¡£¡£¡£


IOCÑùÀý


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú



±¾±¨¸æÓÉCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶÓÓëc7c7ÓéÀÖÆ½Ì¨ADLabÁªºÏÐû²¼