¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¾Íþвͨ¸æ¡¿REvil·çÔÆÔÙÆð£¬APTʽÀÕË÷±¬·¢

2021-05-25

 

Ò».  ÊÂÎñÅä¾°

2021Äê5Ô£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼CERT¼à²âµ½REvil/SodinokibiÀÕË÷¼Ò×åµÄ¶àÆðÔ˶¯£¬REvilΪRansomware Evil£¨ÓÖ³ÆSodinokibi£©µÄËõд£¬ÊÇÒ»¸ö˽ÈËÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯¡£ÓÚ2019Äê4ÔÂÊ״α»·¢Ã÷£¬ÔÚÒ»ÄêÄÚ¾ÍÒѱ»ÓÃÓÚһЩ×ÅÃûÍøÂç¹¥»÷£¬2019Äê8ÔµÄPerCSoft¹¥»÷£¬2020Äê1ÔµÄTravelexÀÕË÷Èí¼þ¹¥»÷£¬¼°2020Äê1ÔµÄGedia Automotive¹¥»÷µÈÊÂÎñ¡£½üÆÚ£¬¸Ã×éÖ¯ÈëÇÖÁËÆ»¹û¹«Ë¾µÄ¹©Ó¦ÉÌ£¬²¢ÇÔÈ¡ÁËÆ»¹û¹«Ë¾¼´½«ÍƳöµÄ²úÆ·ÉñÃØÔ­Àíͼ¡£

´ó¶¼ÍøÂçÇ徲ר¼ÒÒÔΪ£¬REvilÊÇÒÔǰһ¸öÎÛÃûÕÑÖøµ«ÒÑÇýÖðµÄºÚ¿ÍÍÅ»ïGandCrabµÄ·ÖÖ§¡£¸ÃÍÆ²âÔ´ÓÚREvilÔÚGandCrab×èÖ¹ÔËÓªºóÁ¬Ã¦×îÏÈÔ˶¯£¬ÇÒ¶þÕßʹÓõÄÀÕË÷Èí¼þ±£´æ´ó×Ú¹²Ïí´úÂë¡£

 ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

 

¶þ.  ×éÖ¯ÆÊÎö

SodinokibiÔËÓªÉÌͨ³£ÕÐÆ¸ºÚ¿Í¹¥»÷Õß¾ÙÐгõʼÈëÇÖ¡£ËûÃǵĹ¥»÷ÍùÍù´ÓÊìϤµÄÊÖÒÕ×îÏÈ£¬Èç´øÓÐÓã²æÊ½´¹ÂÚÁ´½Ó»ò¸½¼þµÄ¶ñÒâÓʼþ¡¢Ê¹ÓÃÓÐÓÃÕË»§µÄRDP»á¼û¡¢Òѱ»ÈëÇÖµÄwebÍøÕ¾ºÍÎó²îʹÓõÈ¡£²¢ÇÒ»¹»áʹÓÃһЩ¶ÔÄ¿µÄ¾ßÓÐÕë¶ÔÐÔµÄÊÖÒÕ¡£

Sodinokibi¼Ò×å½ÓÄÉÀÕË÷Èí¼þ¼´·þÎñµÄģʽ£¬Òâζ×Å·Ö·¢µÄ¹¥»÷Õß½«ÏòÔËÓªÉÌÖ§¸¶×îа汾µÄʹÓ÷Ñ£¬²¢ÓÉÀÕË÷×é֯ΪËûÃÇÔËÓª»ù´¡ÉèÊ©¡£ÔÚSodinokibiµÄÉèÖÃÖÐÓÐÁ½¸ö×ֶΣ¬½«¸ú×Ù¿Í»§¶ËºÍ°²ÅÅÀÕË÷Èí¼þʱ´úµÄÌØ¶¨¿Í»§¶ËÔ˶¯¡£

 

Èý.  ¹¥»÷ÊÖ·¨ÆÊÎö

Sodinokibi²¡¶¾×Ô¼º²¢²»¾ß±¸×Ô¶¯Èö²¥¹¦Ð§£¬Ö÷ÒªÒÀÀµ¹¥»÷ÕßÊÖ¶¯Èö²¥£¬µ«»áͨ¹ýɨÃè¾ÖÓòÍø¹²Ïí×ÊÔ´£¬ÊµÑé¼ÓÃܹ²ÏíÎļþ¡£ÀÕË÷²¡¶¾ÍÅ»ï¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃÉøÍ¸£¬»ñÈ¡ÄÚÍøÈ¨ÏÞ²¢¿ØÖÆÒªº¦Éú²úÉèÊ©£¨ÀýÈçÓò¿ØÖ÷»ú£©£¬È»ºóͨ¹ýÌØ¶¨·½·¨£¨ÀýÈçÓòÕ½ÂÔ¡¢PsExecÔ¶³ÌÅþÁ¬Ö´Ðеȣ©ÔÚÄÚÍøÖÐÈö²¥¼ÓÃܲ¡¶¾Ö÷Ìå³ÌÐò¡£ÔÚÈëÇÖÀú³ÌÖУ¬¹¥»÷ÕßʹÓÃÁËÐí¶àÀàËÆAPT×éÖ¯µÄÊֶΣ¬ÈçʹÓÃCobaltStrikeµÈÔ¶¿ØÄ¾Âíºã¾ÃפÁô¡¢ÍøÂçÃô¸ÐÎļþ¡¢°×¼ÓºÚʵÏÖÀÕË÷²¡¶¾ÃâɱµÈ¡£

ij°¸ÀýÖУ¬¹¥»÷Õßͨ¹ýpowershellÏÂÁî½ûÓÃWindows DefenderµÄʵʱ±£»¤£º

ͨ¹ý¹²Ïí¿½±´ÓëwmicÏÂÁ½«ÀÕË÷²¡¶¾Ñù±¾¿½±´µ½Ä¿µÄÖ÷»ú²¢Ö´ÐУº

»òÕßͨ¹ýÓò¿ØÏ·¢×éÕ½ÂԵķ½·¨£¬½«ÀÕË÷²¡¶¾Ñù±¾¿½±´µ½Öն˲¢Ö´ÐС£ÀÕË÷²¡¶¾±¾Ìå¾ßÓÐÓÐÓÃÊý×ÖÊðÃû£¬²¢½ÓÄÉÁ˰׼Ӻڵķ½·¨£¬ÌÓ±Üɱ¶¾Èí¼þ²éɱ¡£

¹¥»÷Õß»¹»áʹÓÃpowershell»òMSBUILDÏÂÁîÖ´ÐÐÎļþ¼ÓÔØCobaltStrike Ô¶¿ØÄ¾ÂíÒÔʵÏÖºã¾ÃȨÏÞά³Ö¡£

²¡¶¾×Ô¼º²¢²»¾ß±¸ÏµÍ³×¤Áô¹¦Ð§£¬²»»á¶Áд±»¼ÓÃÜÖն˵ÄÈÎºÎÆô¶¯Ïî¡£µ«ÔÚһЩ°¸ÀýÖз¢Ã÷£¬²¿·Ö¹¥»÷Õßͨ¹ýÅú´¦Öóͷ£µÄ·½·¨Ð½¨×¼Ê±ÍýÏëʹÃüÀ´Ò»Ö±Æô¶¯¼ÓÃܳÌÐò£¬ÒÔ±ãµÖ´ïѬȾÐÂÎļþ¡¢Ð´洢½éÖʵÄÄ¿µÄ¡£

REvil¼Ò×åÔÚÉøÍ¸µÄÀú³ÌÖгýÁËͶ·ÅÀÕË÷²¡¶¾£¬»¹»áÍøÂçÉÏ´«±»¹¥»÷ϵͳµÄÎļþ¡£Ä³°¸ÀýÖУ¬ÀÕË÷ÐÅÌáµ½“ÎÒÃÇ»¹´ÓÄúµÄ·þÎñÆ÷ÏÂÔØÁË´ó×ÚÃô¸ÐÊý¾Ý£¬ÈôÊÇÄú²»¸¶¿î£¬ÎÒÃǽ«»á°ÑÄúµÄÎļþÉÏ´«µ½ÎÒÃǵĹ«¹²²©¿Í”¡£

ÔÚÍâµØ¿ªÆôÍøÂç¹²Ïí£¬²¢Í¨¹ýpsexec¹¤¾ß£¬Ê¹ÓÃͨÓÿÚÁÅúÁ¿½«users.ps1¿½±´µ½Ä¿µÄÖ÷»ú¡£

ʹÓÃpsexecÏÂÁÅúÁ¿Ö´Ðп½±´µ½Ä¿µÄÖ÷»úµÄusers.ps1Îļþ

¹¥»÷Õß»áͨ¹ýpowershell¾ç±¾ËѼ¯ÏµÍ³Ãô¸ÐÎļþ²¢ÉÏ´«¡£¾ç±¾×÷ÓãºÍøÂçÄ¿µÄÖ÷»ú120ÌìÄÚ½¨ÉèµÄÖ¸¶¨ºó׺Îļþ£¬²¢ÉÏ´«µ½Ä¿µÄÖ÷»ú¹²ÏíĿ¼¡£

ͨ¹ý×¢²á±íÐÅÏ¢£¬È·ÈϹ¥»÷Õß×°ÖÃÁËTntDrive¿Í»§¶Ë£¬²¢½«ÔÆ´æ´¢¹¤¾ß¹ÒÔØµ½ÍâµØ´ÅÅÌU(¹¥»÷ÕßÉÏ´«ÎļþµÄ¹²ÏíĿ¼)¡£

 

ËÄ.  CobaltStrikeÆÊÎö

ԭʼpowershell´úÂëʹÓÃpowershell base64±àÂë

½âÂëºóÄÚÈÝÈçÏ£º

¾ÙÐжþ´Î½âÂ룬»ñÈ¡µ½powershellÕæÊµ´úÂ룬¹¦Ð§Îª½«¾ç±¾ÖеÄÊý¾Ý¾ÙÐÐÒì»ò£¬¼ÓÔØµ½ÄÚ´æÖÐÖ´ÐС£´Ë¾ç±¾ÎªCobaltstrike powershellÐÎʽµÄpayload¡£

½«¼ÓÔØµ½ÄÚ´æÖеÄÄÚÈݻָ´³É¶þ½øÖÆÎļþ£¬¿ÉÒÔ»ñÈ¡µ½CS beaconµÄ»ØÁ¬µØµã¡£Í¨¹ý»ØÁ¬µØµã·¢Ã÷£¬´ËshellcodeÊÇCSµÄSMB beacon£¬Ö÷ÒªÓÃÓÚÄÚÍøÉøÍ¸¡£

 

Îå.  ÀÕË÷ÑùÌìÖ°Îö

5.1  Êͷű¾Ìå

Ñù±¾Èë¿ÚÈçÏ£º

»áÊͷųöÒ»¸öexeºÍÒ»¸ödll¹âÔÝʱĿ¼£¬²¢Æô¶¯Àú³ÌMsMpEng.exe

ÊͷŵÄMsMpEng.exeÎļþ×Ô¼ºÎÞ¶ñÒ⹦Ч£¬Ö÷ÒªÓÃÓÚ¸øMpsvc.dllÌṩÔËÐÐÇéÐΣ¬²¡¶¾µÄËùÓÐÐÐΪ¶¼ÔÚ¸ÃdllÎļþÖС£½Ó¿ÚΪMpsvc.dllµÄµ¼³öº¯ÊýServiceCrtMain£º

µ¼³öº¯ÊýServiceCrtMainʹÃüÊÇ

PEÈçÏ£º

»¹Ô­PE±ê¼Ç£¬Ê¹ÓÃPEÎļþÆÊÎöÆ÷¿ÉÕý³£ÆÊÎö£¬µ«µ¼Èë±í±»¼ÓÃÜ£¬ØÊºó·¢Ã÷²¡À±ÊÖ¶¯Å²ÓÃҪʹÓõÄAPI£¨¶¯Ì¬½âÃÜ£©

¸ÃPEÎļþΪ²¡¶¾±¾Ì壬µ½´Ë²¡¶¾±¾ÌåÊÍ·ÅÍê³É¡£

 

²¡¶¾±¾Ìå¸ÅÀÀ

5.2  ²¡¶¾ÉèÖñí

¸ÃÀÕË÷²¡¶¾ÓÐÕÅÉèÖñí£¬¸ÃÉèÖÃ±íµ¥Ö÷Òª¼Í¼Á˲¡¶¾¼ÓÃÜÐÐΪÒÔ¼°ÀÕË÷Îı¾ÈçÏ£º

ÎļþĿ¼ɨ³ý£º"fld":["$windows.~bt","intel","google","windows","torbrowser","$windows.~ws","applicationdata","mozilla","windows.old","perflogs","appdata","msocache","boot",

"systemvolumeinformation","programfiles","programfiles(x86)","$recycle.bin","programdata"],

Îļþɨ³ý£º

"fls":["thumbs.db","bootsect.bak","desktop.ini","ntldr","ntuser.dat","autorun.inf","iconcache.db","boot.ini","bootfont.bin","ntuser.ini","ntuser.dat.log"],
ÎļþÀ©Õ¹Ãûɨ³ý£º"ext":["exe","mod","shs","cpl","idx","diagcfg","ico","nomedia","sys","cmd","key","msp","msstyles","bin","rom","bat","cur","diagcab","ldf","dll","scr","hta","rtp","hlp","theme","msi","com","prf","spl","wpx","deskthemepack","diagpkg","mpa","icns","ps1","drv","ics","nls","adv","msu","cab","lnk","ocx","ani","themepack","icl","msc","386","lock"]},

ÎļþÄ¿Â¼ÒÆ³ý£º"wfld":["backup"],

Í£Ó÷þÎñÇåµ¥£º"prc":["mydesktopqos","thebat","synctime","onenote","mspub","dbsnmp","isqlplussvc","tbirdconfig","oracle","xfssvccon","wordpad","agntsvc","sqbcoreservice","ocautoupds","firefox","msaccess","thunderbird","excel","outlook","encsvc","visio","powerpnt","ocomm","steam","mydesktopservice","ocssd","sql","winword","dbeng50","infopath"]

ɱËÀ·þÎñÇåµ¥£º"svc":["veeam","sql","svc$","backup","sophos","vss","memtas","mepocs"]

ÀÕË÷Îı¾£º

[+] Whats Happen? [+]

Your files are encrypted, and currently unavailable. You can check it: all files on your system has extension u89416xh.

By the way, everything is possible to recover (restore), but you need to follow our instructions. Otherwise, you cant return your data (NEVER).

[+] What guarantees? [+]

......................................

²¢ÇÒ²¡¶¾»áÅжÏËùѬȾÅÌËã»úʹÓõÄÓïÑÔ£¬ÈçÏ£º

ʹÓú¯ÊýGetUserDefaultUILanguage,GetSystemDefaultUILanguage·µ»ØµÄIDºÍÁбí¿òÖеÄID²î±ð£¬ÄÇôΪѬȾĿµÄ£¬Í¨¹ý´Ë´¦À´¿´Ð޸ķÇÄ¿µÄÅÌËã»úÓïÑÔ¿Éɨ³ýѬȾ¸Ã²¡¶¾¡£²¡¶¾»á½¨É軥³âÌåÈ·±£Î¨Ò»ÔËÐУ¬²¡¶¾»á¶à´Î¼ì²é×Ô¼ºµÄ¾ä±úȨÏÞÊÇ·ñΪÖÎÀíԱȨÏÞ£¬ÈôÊÇȨÏÞ²»·ó½«»áÖØÐÂÒÔÖÎÀíԱȨÏÞÖØÐÂÆô¶¯×Ô¼º£¬²¢ÇÒ¼¤»îÏà¹ØÈ¨ÏÞ¡£

5.3  Ö÷Ì幦Ч

5.3.1  ÍâµØ¼ÓÃÜ

²¡¶¾ÏÖʵµÄÐÐΪÊÇÔÚSub_F4476F_Startº¯ÊýÖУ¬ÈçÏ£º

²¡¶¾Ê×ÏÈÇå¿Õ½ÓÄÉÕ¾£¬¹Ø±ÕÇåµ¥ÖеÄÏà¹Ø·þÎñ£¬É±ËÀÇåµ¥ÖÐÀú³Ì£¬È»ºóÔÚ¼¤»îÏà¹ØÈ¨ÏÞµÄÇéÐÎÏ£¬×îÏȼÓÃܹ¦Ð§¡£Ö÷ҪʹÓÃFindFirstFile ºÍFindNextFileÀ´²éÕÒËùÓÐÎļþ£¬Ê¹ÓÃsalsa20+AESµÄËã·¨¾ÙÐÐÎļþ¼ÓÃÜ¡£

ÔÚ¼ÓÃܵÄÀú³ÌÈôÊÇ·¢Ã÷ÎļþΪĿµÄѬȾÎļþ£¬µ«±»Àú³ÌÕ¼Ó㬲¡¶¾»áŲÓÃterminateProcesss¿¢ÊÂÏà¹ØÀú³Ì£¬ÔÙ¾ÙÐмÓÃÜ¡£

¼ÓÃܺ¯ÊýÈçÏ£º

ÍøÂç´ÅÅ̼ÓÃÜ

²¡¶¾Ò²»áͬʱ¶ÔÍøÂç´ÅÅÌÖеÄÎļþ¾ÙÐмÓÃÜ£¬ÈçÏ£º

5.3.2  ÊµÑé¼ÓÃܾÖÓòÍø¹²ÏíÎļþ

ÔÚ¼ÓÃܵÄÀú³ÌÖв¡¶¾ÓÐö¾Ù¾ÖÓòÍøÅÌËã»úµÄÐÐΪ£¬Ö÷ÒªÊDzéÕÒ¾ÖÓòÍø¹²Ïí£¬ÊµÑé¼ÓÃܹ²ÏíÎļþ¡£

 

5.4  ÏÔʾ×ÀÃæÀÕË÷Åä¾°

ÔÚ¼ÓÃܹ¦Ð§Íê³ÉÒÔºó»áͨ¹ýÉèÖÃ×¢²á±íÉèÖÃ×ÀÃæÅ侰ΪÀÕË÷ͼƬ

 

Áù.  ÀÕË÷Èí¼þÌá·À½¨Òé

l  ÔöÇ¿ÆóÒµÔ±¹¤Çå¾²ÒâʶÅàѵ£¬½ûÖ¹Ò×·­¿ªÉúÊèÓʼþ»òÔËÐÐȪԴ²»Ã÷µÄ³ÌÐò£»

l  Ö»¹Üɨ³ýΣÏն˿ڶÔÍ⿪·Å£¬Ê¹ÓÃIPS¡¢·À»ðǽµÈ×°±¸¶ÔΣÏն˿ھÙÐзÀ»¤£¨445¡¢139¡¢3389µÈ£©£»

l  ¿ªÆôWindowsϵͳ·À»ðǽ£¬Í¨¹ýACLµÈ·½·¨£¬¶ÔRDP¼°SMB·þÎñ»á¼û¾ÙÐмӹÌ£»

l  ͨ¹ýWindows×éÕ½ÂÔÉèÖÃÕË»§Ëø¶¨Õ½ÂÔ£¬¶Ô¶Ìʱ¼äÄÚÒ»Á¬Éϰ¶Ê§°ÜµÄÕË»§¾ÙÐÐËø¶¨£»

l  ÔöÇ¿Ö÷»úÕË»§¿ÚÁîÖØÆ¯ºó¼°ÐÞ¸ÄÖÜÆÚÖÎÀí£¬²¢Ö»¹Üɨ³ý·ºÆðͨÓûò¼ÍÂÉ¿ÚÁîµÄÇéÐΣ»

l  ÐÞ¸ÄϵͳÖÎÀíԱĬÈÏÓû§Ãû£¬É¨³ýʹÓÃadmin¡¢administrator¡¢testµÈ³£¼ûÓû§Ãû£»

l  ×°Öþ߱¸×Ô±£»¤µÄ·À²¡¶¾Èí¼þ£¬±ÜÃâ±»ºÚ¿ÍÍ˳ö»ò¿¢ÊÂÀú³Ì£¬²¢ÊµÊ±¸üв¡¶¾¿â£»

l  ʵʱ¸üвÙ×÷ϵͳ¼°ÆäËûÓ¦ÓõĸßΣÎó²îÇå¾²²¹¶¡£»

l  ׼ʱ¶ÔÖ÷ÒªÓªÒµÊý¾Ý¾ÙÐб¸·Ý£¬±ÜÃâÊý¾ÝÆÆËð»òɥʧ¡£

 

Æß.  ²úÆ··À»¤

Õë¶Ô´ËÀàÊÂÎñ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍøÂçÈëÇÖ·À»¤/¼ì²âϵͳ(IPS/IDS)¡¢×ÛºÏÍþв̽Õ루UTS£©ÓëÏÂÒ»´ú·À»ðǽ £¨NF£©ÒÑÐû²¼¹æÔòÉý¼¶°ü¡£ÇëÏà¹ØÓû§Éý¼¶ÖÁ×îа汾¹æÔò£¬ÒÔÐγÉÇå¾²²úÆ··À»¤ÄÜÁ¦¡£²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º

²úÆ·

Éý¼¶°ü°æ±¾

Éý¼¶°üÏÂÔØÁ´½Ó

IPS/IDS¹æÔò°ü

5.6.9.25418

5.6.10.25418

5.6.11.25418

http://update.nsfocus.com/update/listNewipsDetail/v/rule5.6.9

http://update.nsfocus.com/update/listNewipsDetail/v/rule5.6.10

http://update.nsfocus.com/update/listNewipsDetail/v/rule5.6.11

UTS¹æÔò°ü

5.6.10.25418

http://update.nsfocus.com/update/listBsaUtsDetail/v/rule2.0.0

NF¹æÔò°ü

6.0.1.850

6.0.2.850

http://update.nsfocus.com/update/listNewNfDetail/v/rule6.0.1

http://update.nsfocus.com/update/listNewNfDetail/v/rule6.0.2

 

°Ë.  IOCs

835f242dde220cc76ee5544119562268

7d1807850275485397ce2bb218eff159

8cc83221870dd07144e63df594c391d9

Ö÷»úÌØÕ÷£º

%TEMP%\MsMpEng.exe

%TEMP%\Mpsvc.dl

 

ÉùÃ÷

±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾­¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼