Ò»³¡Ëµ×ß¾Í×ߵġ°Ó¦¼±¡±Ðж¯¡ª¡ªÄ³Ê¯»¯¹«Ë¾ÔâÍڿ󲡶¾Ñ¬È¾ºóµÄ48Сʱ
Ðû²¼Ê±¼ä 2019-05-23¡°µÎÁåÁåÁå~~~¡±c7c7ÓéÀÖÆ½Ì¨¹¤Òµ»¥ÁªÍøÊÂÒµ²¿¹¤³ÌʦµÄµç»°ÏìÆð£¡
¡°ÎÒÃÇÁ½Ì׺áºÓDCSϵͳµÄ²Ù×÷Ô±Õ¾¡¢¹¤³ÌʦվºÍOPCЧÀÍÆ÷µÄÖ÷»úͻȻÀ¶ÆÁ£¡ÖØÐÂÆô¶¯ÏµÍ³ºó£¬£¬£¬£¬ÈÔÈ»ÎÞ·¨»Ö¸´£¬£¬£¬£¬×·Çó½ôÆÈÊÖÒÕÔ®Öú£¡¡±
À´×Ôijʯ»¯¹«Ë¾Òǿز¿µÄÊÂÇéÖ°Ô±µç»°ÀïµÄÉùÒôÒì³£¼±´Ù¡¡
½â¾ö¿Í»§µÄÍøÂçÇå¾²ÎÊÌ⣬£¬£¬£¬¾ÍÊÇc7c7ÓéÀÖÆ½Ì¨Ê¹Ãü£¡
c7c7ÓéÀÖÆ½Ì¨¹¤Òµ»¥ÁªÍøÇå¾²ÊÂÒµ²¿ÁªºÏc7c7ÓéÀÖÆ½Ì¨¼¯ÍÅÆìϳ½ÐÅÁì´´¹«Ë¾Á¬Ã¦×齨5ÈËרÏîС×飬£¬£¬£¬ÓªÒµ¡¢ÊÖÒÕ¡¢²úÆ·ÏßְԱѸËÙ¿ªÆô¾ÈÔ®Ðж¯£¬£¬£¬£¬Ô¶³ÌÖ¸µ¼¿Í»§¾ÙÐÐϵͳ¾ÈÔ®¼°±£»£»£»£»£»£»¤ÏÖ³¡²¡¶¾Ñù±¾Êý¾Ý¡£¡£¡£¡£
5ÔÂ11ÈÕÆÆÏþ1:00
¾ÈÔ®ÊÂÇéÕù·Ö¶àÃ룬£¬£¬£¬Àú¾3¸öСʱµÄÔ¶³ÌÖ§³Öºó£¬£¬£¬£¬»ù±¾È·¶¨ÊÂÎñÔÓÉÓÚMsraMiner²¡¶¾Ñ¬È¾¡£¡£¡£¡£
Ô¶³ÌÖ§³ÖÒ»Á¬¾ÙÐУ¬£¬£¬£¬µ«ÏÖ³¡ÇéÐνÏÁ¿ÌØÊ⣬£¬£¬£¬Ë¼Á¿µ½¹¤¿ØÏµÍ³µÄÖØ´óÐÔ¼°DCSϵͳµÄרҵÐÔ£¬£¬£¬£¬Ó¦¼±ÍŶӾöÒé³Ë×øµ±ÈÕ×îÔ纽°à·ÉÍù¿Í»§ÏÖ³¡¡£¡£¡£¡£
5ÔÂ11ÈÕÔç6:40
Í×Í×µØÒ»³¡Ëµ×ß¾Í×ßµÄÓ¦¼±Ð§ÀÍ¡£¡£¡£¡£
¾ÓÉ48СʱµÄ²»Ð¸Æð¾¢£¬£¬£¬£¬ÏµÍ³»ñµÃÁËÐÞ¸´£¬£¬£¬£¬¿Í»§µÄÉú²úÍêÈ«»Ö¸´ÁËÕý³£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿Í»§¸øÓ¦¼±ÍŶӷ¢À´ÁËÕæ³ÏµÄллÐÅ£¬£¬£¬£¬²¢Ô¼ÇëÉÌÌÖºóÆÚµÄ¼Ó¹Ì²½·¥ÓëÏàÖú¡£¡£¡£¡£
ÊÂÎñÆÊÎö
ƾ֤¶ÔÉó²éÏÖ³¡ÇéÐÎÒÔ¼°ÏµÍ³ÖÐÊý¾ÝÆÊÎö£¬£¬£¬£¬ÍøÂçÖеÄÖ÷»úÈ·ÒÔΪMsraMinerÍڿ󲡶¾µÄ±äÖÖ²¡¶¾Ñ¬È¾£¬£¬£¬£¬´ËÍڿ󲡶¾Ê¹Óá°ÓÀºãÖ®À¶¡±Îó²î¾ÙÐÐÈö²¥£¬£¬£¬£¬ÔÚÈö²¥Àú³ÌÖУ¬£¬£¬£¬ÓÉÓÚÔÚWindows XPϵͳÉÏÎó²îʹÓÃʧ°Ü£¬£¬£¬£¬µ¼Ö»úеÀ¶ÆÁ¡£¡£¡£¡£Æä²¡¶¾ÆÆËðÔÀíΪ£º
Íڿ󲡶¾MsraMine×îбäÖֵIJ¡¶¾Ä¸ÌåÔËÐкóÊÍ·ÅЧÀÍÄ£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬ÊͷŵÄЧÀÍÄ£¿£¿£¿£¿£¿£¿éÃû³ÆËæ»úÆ´¼¯£¬£¬£¬£¬ÌìÉúXXX.dll£¬£¬£¬£¬Ð§ÀÍÃû³ÆºÍÊͷŵÄЧÀÍdllÎļþÃû³ÆÏàͬ¡£¡£¡£¡£
²¡¶¾Ð§ÀÍÃû×Ö»áÆ¾Ö¤ÌìÉúµÄdllÃû×ÖÃüÃû£¬£¬£¬£¬¿ÉÊÇÆäÐÎòһÑùƽ³£¶¼ÎªEnable a commin infterace and object xxxx²¡¶¾Îļþ£¬£¬£¬£¬²¢½«¹¥»÷C:\Windows\NetworkDistribution Ŀ¼ÏÂËùÓÐÎļþ£¨¹¥»÷µÄÖ÷ÒªÎļþ£©£¬£¬£¬£¬Ö÷ÍÚ¿óÎļþC:\Windows\system32\dllhostex.exe£¨»òÆäËû±»×¢ÈëµÄsvchostµÄ×ÓÀú³Ì£©¡£¡£¡£¡£
ÁíÍâÌØÑ¡ÔñÆäÖÐÒ»¸öIPÉó²éÆäËùÓлỰ£¬£¬£¬£¬²¢¶ÔÆäÅþÁ¬¶Ë¿Ú¾ÙÐÐͳ¼Æ£¬£¬£¬£¬³ý445¶Ë¿ÚÍ⣬£¬£¬£¬26931¡¢45560¶Ë¿ÚÅþÁ¬Á¿Õ¼±ÈÒ²Ï൱¿É¹Û£¬£¬£¬£¬²¢ÇҸö˿ڲ»ÊôÓÚÕý³£ÓªÒµËùÐè¶Ë¿Ú¡£¡£¡£¡£Ëæ¼´¶Ô¸ÃÖ÷»úµÄÍâµØÎļþÓëÀú³Ì¾ÙÐÐÊÓ²ìºÍÆÊÎö£¬£¬£¬£¬·¢Ã÷´ó×Ú¶ñÒâÎļþ¡£¡£¡£¡£ ¾Ì«¹ýÎöÅжϣ¬£¬£¬£¬26931¡¢45560Á½¸ö¶Ë¿Ú»®·ÖΪWebserver¶Ë¿ÚºÍ¿ó³ØÅþÁ¬¶Ë¿Ú¡£¡£¡£¡£ÆäÖÐWebserverÌṩÏìÓ¦×é¼þÏÂÔØ£¬£¬£¬£¬ÍÚ¿óÀú³ÌΪ¡°TrustedHostServices.exe¡±¡£¡£¡£¡£
²¡¶¾µÄѬȾÁ÷³ÌΪ£ºÊܺ¦Ö÷»úij¹¤³ÌʦվÖеIJ¡¶¾³ÌÐò°üÀ¨Á½²¿·Ö£¬£¬£¬£¬»®·ÖΪ¹¥»÷³ÌÐòÒÔ¼°¡°ÍÚ¿ó¡±³ÌÐò¡£¡£¡£¡£ÆäÖй¥»÷³ÌÐò»áÊͷųö¡°ÓÀºãÖ®À¶¡±³ÌÐò£¬£¬£¬£¬Í¬Ê±´î½¨webЧÀÍÆ÷£¬£¬£¬£¬Í¨¹ýc7c7ÓéÀÖÆ½Ì¨µÄTSOC-NBA¿ÉÒÔ·¢Ã÷Êܺ¦Ö÷»ú¹¤³ÌʦվÏòÊܺ¦Ö÷»ú²Ù×÷Ô±Õ¾ÒÔ¼°OPCЧÀ͵Ä445¶Ë¿ÚÌᳫ¹¥»÷£¬£¬£¬£¬±»Ñ¬È¾²¡¶¾µÄÖ÷»úÏòÊܺ¦Ö÷»úµÄwebЧÀÍÆ÷26931¶Ë¿ÚÌᳫÏÂÔØÇëÇ󣬣¬£¬£¬
ÇëÇóÄÚÈÝΪMsraReportDataCache32.tlb£¬£¬£¬£¬¸Ã³ÌÐò»áÊͷųö¹¥»÷³ÌÐòÒÔ¼°¡°ÍÚ¿ó¡±³ÌÐò£»£»£»£»£»£»Í¬Ê±£¬£¬£¬£¬ÍÚ¿óÀú³ÌTrusted Host Services . exe¾ÙÐÐÍڿ󣬣¬£¬£¬Óë¿ó³Øxmr.pool. minergate . com: 45560 ½¨ÉèÅþÁ¬£¬£¬£¬£¬³ÌÐòÔËÐÐʱ´ú»á»á¼ûÏìÓ¦µÄdomainÒÔ¾ÙÐгÌÐò¸üÐÂÓë¿ó³ØÅþÁ¬£¬£¬£¬£¬ÔÚÅþÁ¬Ê§°Üºóµ¼ÖÂϵͳÀ¶ÆÁ¡£¡£¡£¡£
½â¾ö¼Æ»®
1¡¢Ó¦¼±´¦Öóͷ££ºÊÖ¹¤É¨³ý
2) ¹Ø±Õ445£¬£¬£¬£¬139£¬£¬£¬£¬135¡¢3389µÈ¶Ë¿ÚЧÀÍ£»£»£»£»£»£»
3) ɾ³ýÐÎòΪEnable a commin infterace and object xxxxµÄЧÀÍ£»£»£»£»£»£»
4) ɾ³ý´ËЧÀͶÔÓ¦µÄ¶¯Ì¬Á´½Ó¿âÎļþ£»£»£»£»£»£»
5) ¿¢ÊÂsvchost.exeÀú³Ì£¨TaskIndexer.exe»òdllhostex.exeÀú³ÌµÄ¸¸Àú³Ì£©£»£»£»£»£»£»
6) ¿¢ÊÂTaskIndexer.exe»òdllhostex.exeÀú³Ì£¬£¬£¬£¬²¢É¾³ýÆäÎļþ£»£»£»£»£»£»
7) ɾ³ýC:\Windows\NetworkDistributionĿ¼ÏÂËùÓÐÎļþ£»£»£»£»£»£»
8) ×°ÖÃɱ¶¾Èí¼þ¼á³Ö·ÀÓù¿ªÆô£¬£¬£¬£¬ÊµÊ±Éý¼¶²¡¶¾¿â¡£¡£¡£¡£
ÊÖ¶¯×°Öá°ÓÀºãÖ®À¶¡±Îó²î²¹¶¡Çë»á¼ûÒÔÏÂÒ³Ãæ£º
https://technet.microsoft.com/zh-cn/library/security/ms17-010.aspx
http://www.catalog.update.microsoft.com/search.aspx?q=kb4012212
ÆäÖÐWinXP£¬£¬£¬£¬Windows Server 2003Óû§Çë»á¼û£º
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4012598
²¿·Ö¹¤¾ß£º
c7c7ÓéÀÖÆ½Ì¨µÄÓÀºãÖ®À¶ÈÈÐÞ¸´¹¤¾ß
c7c7ÓéÀÖÆ½Ì¨PChunter¶ñÒâÈí¼þÊÖ¹¤¼ì²â¹¤¾ß
2¡¢¹¤¿ØÏµÍ³×¨Òµ²éɱ¹¤¾ß
¹¤Òµ¿ØÖÆÏµÍ³ÔÚ·À²¡¶¾½¨ÉèÉÏÆÕ±é±£´æ£º×°±¸ÐÔÄܯձ鯫µÍ¡¢windowsÀϰ汾²Ù×÷ϵͳ¾Ó¶à¡¢Ó²¼þ»òÓªÒµÈí¼þÔÚʵÑé·À²¡¶¾ºó²»µÃÊÜÈκÎÓ°Ïì¡¢·À²¡¶¾Èí¼þ±ØÐèÄܹ»ÓÐÓ÷ÀÓù²¡¶¾µÈÎÊÌ⣬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ÎªÖª×㹤¿ØÐÐÒµ·À²¡¶¾ÐèÇ󣬣¬£¬£¬Ñз¢³ö¾°ÔÆÇå¾²ÄÜÁ¦ÇáÁ¿»¯¹¤¿Ø·À»¤°æ¡£¡£¡£¡£½ÓÄÉÈ«³ÌÎÞÇý¶¯ÎÞhook¡¢Ö»É¨²»É±ÒÔ¼°Àú³Ì/ÍøÂç°×Ãûµ¥µÈÇкϹ¤¿ØÇéÐεĻúÖÆ£¬£¬£¬£¬×ÊÖú¹¤¿ØÆóÒµÔÚ·ÀÓùÖÖÖÖÐÂÐͲ¡¶¾ºÍÈ䳿µÄ¹¥»÷µÄͬʱ£¬£¬£¬£¬Äܹ»¼æ¹Ë¹¤¿Ø×°±¸µÄÎȹÌÔËÐУ¬£¬£¬£¬°ü¹ÜÓû§ÓªÒµ¡£¡£¡£¡£
1) ¼¯ÖйܿأºÍ¨¹ý¾°ÔƼ¶ÁªÖÐ¿ØÆ½Ì¨£¬£¬£¬£¬Ìṩ¿ÉÉìËõµÄ¿çƽ̨²¡¶¾·À»¤£¬£¬£¬£¬¼¯Öйܿظ÷¼¶ÖÖÖÖ·ºÖÕ¶Ë£¬£¬£¬£¬Öª×ãÆóÒµ¼¶Óû§¶Ô·À²¡¶¾Èí¼þͳһÖÎÀíµÄÐèÇ󡣡£¡£¡£
2) º£Á¿ÔƲ飺¿ÉΪÓû§°´Ðè¶¨ÖÆÔÆÖªÊ¶¿â£¬£¬£¬£¬ÖÇÄÜ×ÔÔËÓªÔÆ¶Ë²¡¶¾ÌØÕ÷£¬£¬£¬£¬Ê¹Óû§ÔÚÓµÓеÈͬÓÚ¹«ÓÐÔÆµÄ²¡¶¾²éɱÄÜÁ¦µÄͬʱ£¬£¬£¬£¬ÓÖͨ¹ý˽Óл¯µÄ·½·¨³¹µ×¶Å¾øÊý¾Ýй¶¡£¡£¡£¡£
3) ÖÇÄܼø¶¾£º½«»úеѧϰºÍ´óÊý¾ÝÒªÁìÈÚÈëµ½·À²¡¶¾ÏµÍ³ÖУ¬£¬£¬£¬Äܹ»Îª´óÐÍÓû§ÊµÏÖ×Ô¶¯µÄÑù±¾²¶»ñ¡¢ÑùÌìÖ°Àà¡¢Ñù±¾ÌØÕ÷ÌáÈ¡¡¢²¡¶¾¿â¸üÐÂÁ÷³Ì£¬£¬£¬£¬ÒÔ±ãÄܹ»¿ìËÙÏìÓ¦»¥ÁªÍø²ã³ö²»ÇîµÄÅÌËã»ú²¡¶¾¡£¡£¡£¡£
4) ǿЧÐÔÄÜ£ºÔÚ½µµÍÓû§ÖÕ¶Ë×ÊÔ´ÏûºÄͬʱ£¬£¬£¬£¬Á¬ÏµÈ˹¤ÖÇÄܺʹóÊý¾ÝÊÖÒÕ£¬£¬£¬£¬ÄÜʹ²¡¶¾²éɱ¸üѸËÙ¡¢¸ü¾«×¼¡£¡£¡£¡£Äܹ»ÓÐÓ÷ÀÓù×îÊ¢ÐеIJ¡¶¾Ä¾Âí¡¢ºÚ¿ÍÈëÇÖºÍ0day¡¢APTµÈδ֪Íþв£¬£¬£¬£¬¸üÓÐÀûÓÚʵÑ飬£¬£¬£¬¸üÀû±ã×°ÖúÍά»¤¡£¡£¡£¡£
5) ÖÇÄÜ×Ôѧϰ£ºÍ¨¹ý¼´Ê±È¡Ñù¡¢ÀúÊ·Êý¾ÝÆÊÎö¡¢¶à¹æÔòºÏ²¢µÈ·½·¨½¨ÉèÀú³Ì/ÍøÂç°×Ãûµ¥¹æÔò¡£¡£¡£¡£ÔÚÉ趨±ê×¼×°±¸Ö®ºó£¬£¬£¬£¬¾°ÔÆÖ§³Ö×Ô¶¯µ÷½â¹æÔòÄÚÈÝÒÔ˳ӦӪҵϵͳÉý¼¶Ôì³ÉµÄ°×Ãûµ¥ÁбíÀ©ÈݵÈÐèÇ󣬣¬£¬£¬×ÊÖúÓû§¿ìËÙ½¨ÉèÇкÏ×ÔÉí¹¤¿ØÇéÐεİ×Ãûµ¥¡£¡£¡£¡£
3¡¢Ö÷»ú¼Ó¹Ì
½ÓÄÉc7c7ÓéÀÖÆ½Ì¨µÄ¡°Ìì«‘ÄÚÍøÇ徲Σº¦ÖÎÀíÓëÉó¼ÆÏµÍ³¡±£¬£¬£¬£¬¹¦Ð§Èçͼ£º
Çå¾²ÎÞСÊÂ
Ïò¶·ÕùÔÚÒ»ÏßµÄÓ¦¼±Ð§ÀÍÖ°Ô±Ö¾´£¡


¾©¹«Íø°²±¸11010802024551ºÅ