¸ÅÊö
1¡¢ÆÊÎöÔ´Æð
CNCERT¶Ô¼à²â·¢Ã÷µÄº£Á¿¹¥»÷ÊÂÎñ¾ÙÐÐ×ÛºÏÆÊÎö£¬£¬£¬£¬ÍÚ¾òÖÖÖÖ¹¥»÷×ÊÔ´ÔÚÐÐΪ¡¢¹éÊôµÈ·½ÃæµÄÏàËÆÐÔ¹ØÏµ£¬£¬£¬£¬½ø¶ø½«ÍøÂç¹¥»÷ÊÂÎñת»»Îª¡°¹¥»÷ÍŻµÄÊӽǣ¬£¬£¬£¬²¢¶Ô¸÷¹¥»÷ÍÅ»ï¾ÙÐкã¾Ã¸ú×Ù¡£¡£¡£¡£¡£
½üÆÚ£¬£¬£¬£¬CNCERTÓëׯÏÐÓÎÏ·¹«Ë¾ÁªºÏÆÊÎöÍÚ¾òµÄij¸öÍÅ»ï¾ÍⲿÇ鱨±È¶Ô±ê¶¨Îª¡°8220¡±ÍÚ¿óÍŻ¡£¡£¡£¡£Í¨¹ýCNCERTµÄÊý¾Ý·¢Ã÷£¬£¬£¬£¬¸ÃÍÅ»ï½üÆÚÔÚ»¥ÁªÍøÉϽÏΪ»îÔ¾£¬£¬£¬£¬Ò»Á¬Í¨¹ýTsunami½©Ê¬ÍøÂç¾ÙÐпØÖÆÑ¬È¾£¬£¬£¬£¬ÇÒÆäÕÆÎÕµÄÍÚ¿óľÂíÒ²ÔÚÒ»Á¬µü´ú£¬£¬£¬£¬Ò»Ö±ÔöÇ¿Æä¶ñÒâÍÚ¿óµÄ˳ӦÄÜÁ¦¡£¡£¡£¡£¡£
2¡¢¡°8220¡±ºÚ¿Í¹¥»÷ÍÅ»ï½üÆÚ»îÔ¾ÇéÐÎ
¡°8220¡±ÍÅ»ïÊÇ×Ô2017ÄêÒÔÀ´Ò»Á¬»îÔ¾µÄÍÚ¿óÍŻ£¬£¬£¬¸ÃÍÅ»ïÉÆÓÚʹÓ÷´ÐòÁл¯¡¢Î´ÊÚȨ»á¼ûµÈÎó²î¹¥»÷WindowsºÍLinuxЧÀÍÆ÷£¬£¬£¬£¬Ëæºóͨ¹ýÏÂÔØ½©Ê¬ÍøÂç³ÌÐò¡¢ÍÚ¿ó³ÌÐò¡¢¶Ë¿ÚɨÃ蹤¾ßµÈ¶ÔÖ÷»ú¾ÙÐпØÖƺͶñÒâʹÓᣡ£¡£¡£¡£
ÏÖÔÚÍÚ¿óÊǸÃÍÅ»ïÖ÷Òª»îÔ¾ÁìÓò£¬£¬£¬£¬Æ¾Ö¤CNCERT½üÆÚ³éÑù¼à²â£¬£¬£¬£¬¸ÃÍÅ»ïÉøÍ¸ÁË4ǧ̨×óÓÒµÄ×°±¸²¢Èö²¥ÍÚ¿óľÂí¡£¡£¡£¡£¡£Õë¶Ô²î±ð²Ù×÷ϵͳ£¬£¬£¬£¬¡°8220¡±ÍÅ»ïÖ´ÐлáÏìÓ¦µÄ³ÌÐòÄ£¿£¿£¿£¿é£ºÔÚLinuxƽ̨ÊͷŵÄľÂí³ÌÐò»á¹Ø±Õ·À»ðǽ¡¢É±ËÀ¾ºÕùµÐÊÖ³ÌÐò¡¢ÏÂÔØ¶ñÒâÔØºÉ£¬£¬£¬£¬²¢Ö´ÐÐÓÉ¿ªÔ´ÍÚ¿ó³ÌÐòXMRig¸Ä±àµÄÍÚ¿ó³ÌÐò£¬£¬£¬£¬½ø¶ø¿ØÖÆÖ÷»úʵÑé¶ñÒâÍÚ¿ó;ÔÚWindowsƽ̨µÄ¶ñÒâ³ÌÐòͨ¹ý½âÃܶñÒâÔØºÉÏÂÔØµØµã£¬£¬£¬£¬Ð£ÑéÇ®°ü¼°¿ó³ØµØµã£¬£¬£¬£¬½¨ÉèÏß³ÌʹÃüÌìÉú¿ó³ØÉèÖÃÎļþ£¬£¬£¬£¬×îÖÕ½¨Éè¿ì½Ý·½·¨×ÔÆô¶¯ÏîÀ´³¤ÆÚ»¯ÔËÐÐÍÚ¿ó³ÌÐò¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬CNCERT½üÆÚ¼à²â¸ú×Ù·¢Ã÷£¬£¬£¬£¬¸ÃÍÅ»ï½üÆÚÒ»Á¬Èö²¥Tsunami½©Ê¬ÍøÂç³ÌÐò£¬£¬£¬£¬Æ¾Ö¤ÏÖÔÚ³éÑùЧ¹ûÆÊÎö£¬£¬£¬£¬±»¸ÃÍÅ»ï¿ØÖÆµÄTsunami½©Ê¬ÍøÂçÊÜ¿ØÖ÷»úIPÊýÄ¿Áè¼Ýǧ̨¡£¡£¡£¡£¡£Tsunami½©Ê¬³ÌÐòµÄÖ÷Òª¹¦Ð§ÎªÔ¶³Ì¿ØÖÆ¡¢DDoS¹¥»÷ºÍÆäËû¶ñÒâÐÐΪ£¬£¬£¬£¬Òò´Ë8220ÍÅ»ï³ý¶ñÒâÍÚ¿óÍ⣬£¬£¬£¬Ò²¿ÉÌᳫDDoS¹¥»÷£¬£¬£¬£¬ÒѲ»µ«´¿ÊÇ¿ªÕ¹¶ñÒâÍÚ¿óµÄºÚ¿ÍÍŻ¡£¡£¡£¡£
CNCERT½¨Ò飬£¬£¬£¬¶Ô̻¶ÔÚ¹«ÍøÉϵÄÓ¦ÓÃЧÀÍʹÓøßÇ¿¶È¿ÚÁî¼°ÈÏÖ¤»úÖÆ£¬£¬£¬£¬°´ÆÚ¶ÔЧÀÍÆ÷¾ÙÐмӹ̣¬£¬£¬£¬¾¡ÔçÐÞ¸´Ð§ÀÍÆ÷Ïà¹Ø¸ßΣÎó²î£¬£¬£¬£¬ÊµÊ±¸üв¹¶¡¡£¡£¡£¡£¡£µ±·¢Ã÷Ö÷»ú±£´æÍÚ¿óľÂí¼°½©Ê¬ÍøÂç³ÌÐòʱ£¬£¬£¬£¬Îñ±ØÁ¬Ã¦¾ÙÐÐÈ«·½Î»µÄ¼ì²é´¦Öóͷ£¡£¡£¡£¡£¡£
½üÆÚ¹¥»÷×ÊÔ´ÍÚ¾òÆÊÎö
1¡¢ÍÅ»ï×ÊԴͼÆ×
ÏÂͼΪCNCERTÍÚ¾ò³öÀ´µÄ¸ÃÍÅ»ï½üÆÚµÄ¹¥»÷×ÊԴͼÆ×£¬£¬£¬£¬°üÀ¨Ñù±¾¡¢¶ñÒâÑù±¾ÏÂÔØµØµãµÈ¡£¡£¡£¡£¡£

2¡¢¶ñÒâÑù±¾ÏÂÔØµØµãÆÊÎö
¶ÔÏÖÔÚ²¶»ñµ½µÄ8220ÍÅ»ïµÄ·ÅÂíURL¾ÙÐÐÆÊÎö£¬£¬£¬£¬·¢Ã÷¸ÃÍÅ»ïµÄ¶ñÒâÑù±¾ÏÂÔØµØµãÔÚ·¾¶ÉÏÆ«ºÃʹÓÃbashirc.i686¡¢masscan¡¢x64b¡¢scan¡¢hxxµÈ×Ö·û´®£¬£¬£¬£¬ÈçϱíËùʾ£º
±í£º²¿·Ö¶ñÒâÑù±¾ÏÂÔØµØµã¼°¶ÔÓ¦Îļþ·¾¶Æ«ºÃ±í
¶ñÒâÑù±¾ÏÂÔØµØµã¾ÙÀý Îļþ·¾¶Æ«ºÃ
http://80.71.158.96/bashirc.i686 bashirc.i686
http://a.oracleservice.top/bashirc.i686
http://194.38.20.31/masscan masscan
http://80.71.158.96/masscan
http://bash.givemexyz.in/x64b x64b
http://89.41.182.160 /x64b
http://80.71.158.96/scan scan
http://bash.givemexyz.in/scan
http://80.71.158.96/hxx hxx
http://89.41.182.160/hxx
http://89.41.182.160/x86_64 x86_64
http://185.157.160.214/x86_64
3¡¢¶ñÒâÑùͬ×å×åÆÊÎö
×èÖ¹ÏÖÔÚ£¬£¬£¬£¬²¶»ñµ½¸ÃÍÅ»ïµÄ¶ñÒâÑùͬ×å×å¼°±äÖÖÈçϱíËùʾ¡£¡£¡£¡£¡£
±í£º¶ñÒâÑùͬ×å×å¡¢¹¦Ð§¡¢ÖÖÀà
Ñùͬ×å×å Ñù±¾¹¦Ð§ ÖÖÀà
Tsunami Ô¶³Ì¿ØÖÆ¡¢DDoS¹¥»÷ºÍÆäËû¶ñÒâÐÐΪ 6Àà
CoinMiner ÏÂÔØ¶ñÒâÔØºÉ¡¢Ö´ÐÐÍÚ¿ó 10Àà
Portscan ¶Ë¿ÚɨÃè 1Àà
3.1¡¢Tsunami½©Ê¬ÍøÂç³ÌÐòÆÊÎö
TsunamiÊÇÊ¢ÐеĽ©Ê¬ÍøÂç³ÌÐò¼Ò×å¡£¡£¡£¡£¡£¸Ã³ÌÐòµÄC2ЧÀÍÆ÷ÓëÊÜ¿ØÖ÷»úÖ®¼äͨ¹ýIRCÐÒé¾ÙÐпØÖƺÍͨѶ£¬£¬£¬£¬Æä¹¦Ð§°üÀ¨Ô¶³Ì¿ØÖÆ¡¢DDoS¹¥»÷ºÍÆäËû¶ñÒâÐÐΪ¡£¡£¡£¡£¡£CNCERTÏÖÔÚ¼ì²âµ½8220ÍÅ»ïʹÓõĸüÒ×åµÄ¶ñÒâÑù±¾¹²¼Æ6ÖÖ£¬£¬£¬£¬ÈçϱíËùʾ£º
±í£ºTsunami¼Ò×åµÄ¶ñÒâÑù±¾Ãû¡¢MD5
¶ñÒâÑù±¾Ãû Ñù±¾MD5 C2µØµã
x32b ee48aa6068988649e41febfa0e3b2169 c4k.xpl.pwndns.pw¡¢104.244.75.25
bashirc.i686 0ba9e6dcfc7451e386704b2846b7e440 51.255.171.23
bashirc.x86_64 63a86932a5bad5da32ebd1689aa814b3 51.255.171.23
x64b c4d44eed4916675dd408ff0b3562fb1f 104.244.75.25
ox44oh2x9.dll 9e935bedb7801200b407febdb793951e 104.168.71.132
3z8a7kr4z.dll b2755fc18ae77bc86322409e82a02753 104.168.71.132
¸ÃÀཀྵ³ÌÐòͨ¹ýÏò±»¿ØÖÆ×°±¸·¢ËÍÖÖÖÖÖ¸ÁîÏÂÁ£¬£¬£¬À´Ìᳫ¶ÔÓ¦µÄDDOS¹¥»÷µÄ¹¦Ð§£¬£¬£¬£¬Í¬Ê±¸Ã³ÌÐò»¹Ìṩ¹¦Ð§Ö¸Á£¬£¬£¬Àý¡°GET¡±ÎļþÏÂÔØ¹¦Ð§¡£¡£¡£¡£¡£
3.2¡¢CoinMinerÍÚ¿óÑùÌìÖ°Îö
8220ÍÚ¿óÍÅ»ïÔÚWindowsÓëLinux˫ƽ̨¾ù¿É¾ÙÐжñÒâÔØºÉÏÂÔØ¼°Íڿ󣬣¬£¬£¬²¢ÇÒÔÚ²î±ðµÄƽ̨ÉèÖÃÏìÓ¦µÄ¿ó³ØµØµã¡£¡£¡£¡£¡£
? Linuxƽ̨
²¶»ñµ½¸ÃÍÅ»ïÔÚLinuxƽ̨ÉϵÄľÂí£¬£¬£¬£¬ÈçϱíËùʾ£º
±í£ºLinuxƽ̨¶ñÒâÑù±¾ÐÅÏ¢
¶ñÒâÎļþÃû Ñù±¾MD5 ²¡¶¾Ãû
7ff1601a0291bd214573956dcda33230.virus 7ff1601a0291bd214573956dcda33230 Trojan.Linux.CoinMiner.Botnet
dbused dc3d2e17df6cef8df41ce8b0eba99291 Virus.Linux.CoinMiner
X86_x64 eb2f5e1b8f818cf6a7dafe78aea62c93 Trojan.Linux.CoinMiner.Botnet
i686 101ce170dafe1d352680ce0934bfb37e Trojan.Linux.CoinMiner.Botnet
Linuxƽ̨ÏÂµÄ¿ó³Ø¼°Ç®°üµØµãÈçϱíËùʾ¡£¡£¡£¡£¡£
±í£º¿ó³Ø¼°Ç®°üµØµã
¿ó³ØµØµã Ç®°üµØµã
c4k-rx0.pwndns.pw 46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ
146.59.198.38
pool.supportxmr.com
? Windowsƽ̨
²¶»ñµ½¸ÃÍÅ»ïÈçÏÂÔÚWindosƽ̨ÉϵÄľÂí£¬£¬£¬£¬ÈçϱíËùʾ£º
±í£ºWindowsƽ̨¶ñÒâÑù±¾ÐÅÏ¢
¶ñÒâÎļþÃû Ñù±¾MD5 ²¡¶¾Ãû
mywindows.exe 08e7d711e13e1e95bbd5dc576d90f372 Trojan.Win32.CoinMiner.Botnet
oracleservice.exe 0958fa69ba0e6645c42215c5325d8f76 Trojan.Win32.8220.Coinminer
oracleservice.exe 6e7c0ff683d771875cd7edd2ed7b72e2 Trojan.Win32.8220.Coinminer
oracleservice.exe 2559e97c13e731d9f37b1630dff2bb1e Trojan.Win32.8220.Coinminer
oracleservice.exe b2d3f97fa0a66683e217b1f06ec9c4c8 Trojan.Win32.8220.Coinminer
xmrig.exe f0cf1d3d9ed23166ff6c1f3deece19b4 Virus.Win32.CoinMiner
ϱíΪ4¸öÑù±¾ÊӲ쵽µÄ·ºÆðʱ¼äÒÔ¼°Ñù±¾ÎļþµÄ´óС£¡£¡£¡£¡£¬£¬£¬£¬Óɴ˿ɿ´³ö£¬£¬£¬£¬ÔÚ¶ñÒâÍÚ¿ó·½Ã棬£¬£¬£¬¸ÃÍÅ»ï¾ßÓнÏΪһÁ¬µÄ¸üÐÂÄÜÁ¦¡£¡£¡£¡£¡£
±í£º²î±ðÑù±¾·ºÆðʱ¼äµÄת±äÇéÐÎ
Ñù±¾MD5 ×îÔç·ºÆðʱ¼ä ×îÍí·ºÆðʱ¼ä Îļþ¾Þϸ
0958fa69ba0e6645c42215c5325d8f76 2021/10/25 2021/11/10 2234368
6e7c0ff683d771875cd7edd2ed7b72e2 2021/11/14 2022/1/21 2234368
2559e97c13e731d9f37b1630dff2bb1e 2022/1/20 2022/3/26 2468864
b2d3f97fa0a66683e217b1f06ec9c4c8 2022/3/26
2467328
Windowsƽ̨ÏÂµÄ¿ó³Ø¼°Ç®°üµØµãÈçϱíËùʾ¡£¡£¡£¡£¡£
±í£ºWindowsƽ̨ÏÂÍÚ¿ó³ÌÐòµÄ¿ó³Ø¼°Ç®°üµØµã
¿ó³ØµØµã Ç®°üµØµã
xmr.givemexyz.in 46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ
198.23.214.117:8080
212.114.52.24:8080
3.3¡¢Portscan¶Ë¿ÚɨÃèľÂíÆÊÎö
¸ÃÍÅ»ï½ÓÄɶ˿ÚɨÃèÊÖ¶ÎÀ´·¢Ã÷ÆäËû¿ÉÓÃ×ÊÔ´£¬£¬£¬£¬Ö®ºóÔÙ¾ÙÐй¥»÷±¬ÆÆµÈϵÁÐÐÐΪ¡£¡£¡£¡£¡£ÒÔTrojan.Win32.PortScanΪÀý£¬£¬£¬£¬Ïà¹ØÆÊÎöÈçÏ¡£¡£¡£¡£¡£
¶ñÒâ³ÌÐòÊ×ÏÈ»áÅжϴ«ÈëÖµÊÇ·ñСÓÚ¼´ÊÇ2£¬£¬£¬£¬ÈôÊÇÊÇ£¬£¬£¬£¬¾Í»áÍ˳ö³ÌÐò£¬£¬£¬£¬ÓÉÓڸóÌÐòÖ»Ö§³ÖRedHat linux¡£¡£¡£¡£¡£ÈôÊÇÐÞ¸ÄÕâÀïµÄ´«ÈëÖµ£¬£¬£¬£¬ºóÐøÒÀ¾É»áÍ˳ö£¬£¬£¬£¬²¢²»¿É¶¯Ì¬µ÷ÊÔ£¬£¬£¬£¬¹ÊºóÐøÄÚÈÝΪ¾²Ì¬ÆÊÎö¡£¡£¡£¡£¡£
4¡¢IP¼°ÓòÃû×ÊÔ´ÆÊÎö
ÏÖÔÚ²¶»ñµÄ8220¹¥»÷ÍÅ»ïµÄIPÀàÐ͵Ĺ¥»÷×ÊÔ´£¬£¬£¬£¬Ö÷ÒªÂþÑÜÃÀ¹ú¡¢ÎÚ¿ËÀ¼µÈ¹ú¼Ò¡£¡£¡£¡£¡£
±í£ºIPÀàÐ͵ÄÍÅ»ï×ÊÔ´
IP IP¹¦Ð§ ËùÊô¹ú¼Ò ËùÊôµØÇø
194.38.20.31 ·ÅÂíЧÀÍÆ÷IP ÎÚ¿ËÀ¼ »ù¸¨
80.71.158.96 ·ÅÂíЧÀÍÆ÷IP ÎÚ¿ËÀ¼ µÚÄô²®Âޱ˵ÃÂÞ·ò˹¿ËÖÝ
45.61.184.118 ·ÅÂíЧÀÍÆ÷IP ÃÀ¹ú ·ðÂÞÀï´ïÖÝ Âõ°¢ÃÜ
212.114.52.24 ·ÅÂíЧÀÍÆ÷IP µÂ¹ú ºÚÉÖÝ ÃÀÒòºÓÅÏ·¨À¼¿Ë¸£
209.141.59.139 ·ÅÂíЧÀÍÆ÷IP ÃÀ¹ú ÄÚ»ª´ïÖÝ À˹ά¼Ó˹
89.41.182.160 ·ÅÂíЧÀÍÆ÷IP ÂÞÂíÄáÑÇ ²¼¼ÓÀÕË¹ÌØ
205.185.118.119 ·ÅÂíЧÀÍÆ÷IP ÃÀ¹ú ÄÚ»ª´ïÖÝ À˹ά¼Ó˹
91.198.77.78 ·ÅÂíЧÀÍÆ÷IP ºÉÀ¼ °¢Ä·Ë¹Ìص¤
104.244.75.25 C2 ¬ɱ¤ ¬ɱ¤Çø
51.255.171.23 C2 ·¨¹ú ÉÏ·¨À¼Î÷´óÇø
104.168.71.132 C2 ÃÀ¹ú ŦԼÖÝ
ÏÖÔÚ²¶»ñµÄ8220¹¥»÷ÍÅ»ïµÄÓòÃûÀàÐ͹¥»÷×ÊÔ´ÈçϱíËùʾ¡£¡£¡£¡£¡£
±í£ºÓòÃûÀàÐ͵ÄÍÅ»ï×ÊÔ´
ÓòÃû ÓòÃû¹¦Ð§ ×¢²áʱ¼ä ÓâÆÚʱ¼ä ×¢²áÉÌ
bash.givemexyz.in ·ÅÂíÓòÃû 2020/9/25 2022/9/25 TucowsInc.
a.oracleservice.top ·ÅÂíÓòÃû 2021/11/3 2022/11/3 TucowsInc.
c4k.xpl.pwndns.pw C2ÓòÃû 2019/3/7 2023/3/7 Sarek
¶ñÒâÑù±¾Èö²¥¼°Ñ¬È¾¿ØÖÆÆÊÎö
1¡¢Èö²¥ÃæÆÊÎö
ΪCNCERT³éÑù¼à²â·¢Ã÷µÄ½üÆÚ¸ÃÍÅ»ï¶ñÒâÑù±¾Èö²¥¹æÄ£µÄ»îÔ¾ÇéÐΡ£¡£¡£¡£¡£ÔÚ½üÆÚ£¬£¬£¬£¬µ¥ÈÕ¶ÔÉÏǧ̨Ö÷»úÀÖ³ÉʵÑéÎó²î¹¥»÷£¬£¬£¬£¬²¢ÏÂÔØÍÚ¿ó¡¢½©Ê¬ÍøÂç³ÌÐòµÈ¶ñÒâÑù±¾¡£¡£¡£¡£¡£
³éÑù¼à²â·¢Ã÷£¬£¬£¬£¬ÉÏÊöÍÅ»ïÈö²¥Ä¿µÄIPËùÔÚµØÇøÖ÷Òª¼¯ÖÐÔÚ±±¾©¡¢¹ã¶«¡¢ÉϺ£µÈÊ¡·Ý¶¼»á£¬£¬£¬£¬ÇøÓòÕ¼±ÈͼÈçÏÂËùʾ£º
2¡¢Tsunami½©Ê¬ÍøÂç¿ØÖÆÇéÐÎÆÊÎö
CNCERT¶ÔÍÅ»ï¿ØÖÆµÄTsunami½©Ê¬ÍøÂç¾ÙÐгéÑù¼à²â£¬£¬£¬£¬ÔÚ2022Äê1ÔÂÖÁ4Ô£¬£¬£¬£¬¹²³éÑù·¢Ã÷ÊܿصÄÖ÷»úIPµØµã½ü2000¸ö¡£¡£¡£¡£¡£ÏÂͼΪÖðÈÕѬȾµÄÖ÷»úIPÊýÄ¿ÇéÐΡ£¡£¡£¡£¡£
ÆäÖУ¬£¬£¬£¬±±¾©¡¢ÖØÇì¡¢ÉϺ£Ñ¬È¾µÄÊܵ½¸ÃÍÅ»ïÕÆÎÕµÄTsunami½©Ê¬ÍøÂç¿ØÖÆµÄÖ÷»úIPÊýÄ¿×î¶à£¬£¬£¬£¬»®·ÖΪ432¸ö¡¢298¸ö¡¢269¸ö¡£¡£¡£¡£¡£ÊÜ¿ØÖ÷»úµØIPµØÀíλÖÃÂþÑÜÇéÐÎÈçÏ¡£¡£¡£¡£¡£
¼à²â·¢Ã÷£¬£¬£¬£¬¸ÃÍÅ»ï¿ØÖÆµÄ½©Ê¬ÍøÂçÊÜ¿ØÖ÷»úIPÀàÐÍÖУ¬£¬£¬£¬¾³ÄÚ¼ÒÍ¥ºÍ¾³ÄÚIDC»®·ÖÕ¼39.21%¡¢36.21%¡£¡£¡£¡£¡£ÆäÖÐIDCÀàÐ͵ÄIP²»ÉÙ¡£¡£¡£¡£¡£
¡°8220¡±ÍÅ»ïÑù±¾¾ÙÀýÆÊÎö
1¡¢Tsunami½©Ê¬ÍøÂç³ÌÐòÆÊÎö
¸Ã³ÌÐòÔÚÔËÐÐʱÊ×ÏÈͨ¹ý»ñÈ¡×ÖµäÎļþÀïµÄÊý¾Ý£¬£¬£¬£¬Ëæ»úÌìÉúÒÔÏÂÐÅÏ¢£º
nick = XJZGGP
ident = ECGLO
user = GDID
chan = ¡°#.br¡±
key = ¡°ircbot456@¡±
server = 0
ÔÚ½¨ÉèÅþÁ¬ÒԺ󣬣¬£¬£¬ÏòÄ¿µÄ·¢ËÍÒ»´®Àο¿ÃûÌõÄÊý¾Ý£¬£¬£¬£¬Êý¾ÝÄÚÈÝΪ֮ǰ»ñÈ¡µÄÄÚÈÝ¡£¡£¡£¡£¡£
·¢ËÍÊý¾Ý°üÄÚÈݺ󣬣¬£¬£¬ÆÚ´ýÎüÊÕ¹¥»÷ÕߵĿØÖÆÏÂÁ£¬£¬£¬ÎüÊÕµ½µÄÊý¾ÝÈçÏ£º
Ö®ºó»áƾ֤ÎüÊÕ²î±ðµÄÖ¸Á£¬£¬£¬¿ÉÌᳫ²î±ð·½·¨µÄDDoS¹¥»÷£¬£¬£¬£¬Àý¡°PAN¡±´ú±íSyn flood¹¥»÷£¬£¬£¬£¬¡°UDP¡±´ú±íudp flood¹¥»÷£¬£¬£¬£¬ÈçÏÂͼ£º
2¡¢CoinMinerÍÚ¿óÑùÌìÖ°Îö
? Linuxƽ̨
ÒÔÏÂΪÁ½¸öÑù±¾¾ÙÀýÆÊÎö¡£¡£¡£¡£¡£
¶ñÒâÑù±¾Ò»£ºLinuxÔØºÉÏÂÔØ³ÌÐò7ff1601a0291bd214573956dcda33230.virus
¸ÃÑù±¾µÄÖ÷Òª¹¦Ð§ÊǹرշÀ»ðǽ¡¢²âÊÔÅþÁ¬¿ó³ØµÈµØµã¡¢Ö´ÐÐÏÂÔØ¶ñÒâÔØºÉ¡¢É±ËÀ¾ºÕùµÐÊÖµÄÍÚ¿ó³ÌÐòµÈ¡£¡£¡£¡£¡£
Ê×ÏÈ£¬£¬£¬£¬¹Ø±Õselinux·À»ðǽ£¬£¬£¬£¬²¢½«Àú³ÌµÄÎļþÊýÄ¿ÐÞ¸ÄΪ50000£¬£¬£¬£¬ÈçÏÂͼ£º
Ö®ºó£¬£¬£¬£¬»®·Ö¶Ôpool.supportxmr.com(¿ó³Ø)¡¢bash.givemexyz.in£¨ÔغÉÏÂÔØÁ´½ÓÓòÃû£©Ìᳫping²âÊÔ¡£¡£¡£¡£¡£Èç²âÊÔÕý³££¬£¬£¬£¬Ôò×îÏÈÏÂÔØ¶ñÒâÔØºÉ£¬£¬£¬£¬²¢½«ÏÂÔØÎļþÖØÃüÃûΪdbused¡£¡£¡£¡£¡£
×îºóɱËÀ¾ºÕùµÐÊÖµÄÍÚ¿ó³ÌÐò£¬£¬£¬£¬×î´ó»¯Ê¹ÓÃϵͳ×ÊÔ´£¬£¬£¬£¬ÈçÏÂͼ£º
¶ñÒâÑù±¾¶þ£ºLinuxÍÚ¿ó³ÌÐòdbused
ÍÚ¿ó³ÌÐò½ÓÄÉ¿ªÔ´ÍÚ¿ó³ÌÐòXMRig±àÒë¶ø³É£¬£¬£¬£¬Ñù±¾±»¼ÓÁËupx¿Ç£¬£¬£¬£¬²¢Ê¹ÓÃÌØÊâ×Ö·û´®¡°pwnrig¡±¾ÙÐбê¼Ç¡£¡£¡£¡£¡£XMRig±àÒëºóÈçÏÂͼËùʾ£º
ÉèÖÃ¿ó³ØµØµãÐÅÏ¢¡£¡£¡£¡£¡£
ÉèÖÃ¿ó³ØµÄÕË»§ÃÜÂëÐÅÏ¢¡£¡£¡£¡£¡£
ÉèÖÃCPU×î´óÏ̼߳°ÄÚ´æ³Ø´óС£¡£¡£¡£¡£¬£¬£¬£¬ÒÔ¸ßЧÂÊÔËÐС£¡£¡£¡£¡£
×îºó¾ÙÐÐÍڿ󣬣¬£¬£¬¿É¿´µ½ÍÚ¿óÁ÷Á¿¡£¡£¡£¡£¡£
? Windowsƽ̨
ÒÔÏ»®·ÖÆÊÎöµÚÒ»ºÍµÚ¶þµ½Îå¸öÑù±¾¡£¡£¡£¡£¡£
¶ñÒâÑù±¾Ò»£ºWindowsÍÚ¿ó³ÌÐòmywindows.exe
¸ÃľÂíÖ÷Òª¹¦Ð§Îª½âÃܳöÏÂÔØ¶ñÒâÔØºÉµÄURL¡¢½¨Éè¶àÏß³ÌÌìÉú¿ó³ØÐÅÏ¢ÉèÖÃÎļþ¡¢ÉèÖÃÍÚ¿ó³ÌÐò×ÔÆô¶¯ÏîµÈ¡£¡£¡£¡£¡£
¸ÃľÂí³ÌÐò³õʼ»¯Ö®ºóÊ×ÏȽâÃܳö¶ñÒâÔØºÉÏÂÔØµØµãURL,ÈçÏÂͼËùʾ£º
ͨ¹ý×Ô½ç˵Ëã·¨»®·Ö¶ÔÇ®°üµØµã¡¢¿ó³ØµØµãÅÌËãÏìÓ¦Öµ£¬£¬£¬£¬Ö®ºó¶ÔÁ½¸öÖµ¾ÙÐÐУÑ飬£¬£¬£¬ÈôÊDz»Ïàͬ£¬£¬£¬£¬¾Í»áÍ˳ö³ÌÐò£¬£¬£¬£¬ÈçÏÂͼËùʾ£º
ËæºóÌìÉúALmRPARcYNÎļþ¼Ð£¬£¬£¬£¬ÔÙͨ¹ý½¨ÉèÏß³ÌʹÃü£¬£¬£¬£¬¿½±´×ÔÉí´æ·ÅÔÚ¸ÃʹÃüĿ¼Ï£¬£¬£¬£¬²¢ÌìÉú¾ÓÉbase64±àÂëµÄcfgÉèÖÃÎļþ£¬£¬£¬£¬ÎļþÄÚÈÝΪ¿ó³ØÐÅÏ¢£¬£¬£¬£¬ÈçÏÂͼ£º
Ö®ºó£¬£¬£¬£¬ÔÚÆô¶¯ÏîÖн¨ÉèÒ»¸öInternet ¿ì½Ý·½·¨(.url)£¬£¬£¬£¬ÓÃÓÚ×ÔÆô¶¯ÔËÐУ¬£¬£¬£¬ÈçÏÂͼËùʾ£º
¶ñÒâÑù±¾¶þÖÁÎ壺WindowsÍÚ¿ó³ÌÐòoracleservice.exe
ÏÖÔÚ²¶»ñµ½¸ÃÍÅ»ïÃûΪoracleservice.exe µÄÑù±¾¹¥»÷4¸ö£¬£¬£¬£¬¾ùΪTrojan.Win32.8220.CoinminerÍÚ¿óľÂí¡£¡£¡£¡£¡£³ý°üÀ¨ÏàͬµÄ´úÂ벿·ÖÍ⣬£¬£¬£¬Ò»Ö±Ò»Á¬µü´úת±äÖУ¬£¬£¬£¬ÆäÖÐÏàͬµÄ´úÂëÈçÏÂͼËùʾ£º
¶Ô²ßºÍ½¨Òé
¡ñ ¶Ô̻¶ÔÚ¹«ÍøÉϵÄÓ¦ÓÃЧÀÍʹÓøßÇ¿¶È¿ÚÁî¼°ÈÏÖ¤»úÖÆ£¬£¬£¬£¬×èÖ¹¶à¸öЧÀÍʹÓÃÏàͬ¿ÚÁî¡£¡£¡£¡£¡£
¡ñ °´ÆÚ¶ÔЧÀÍÆ÷¾ÙÐмӹ̣¬£¬£¬£¬¾¡ÔçÐÞ¸´Ð§ÀÍÆ÷Apache Struts¡¢Tomcat¡¢WebLogicµÈÏà¹Ø¸ßΣÎó²î£¬£¬£¬£¬ÈôÓÐÌõ¼þÎñ±Ø×°ÖÃЧÀÍÆ÷¶ËµÄÇå¾²Èí¼þ¡£¡£¡£¡£¡£
¡ñ ʵʱ¸üв¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬½¨Ò鿪Æô×Ô¶¯¸üй¦Ð§×°ÖÃϵͳ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬Ð§ÀÍÆ÷Ӧʵʱ¸üÐÂϵͳ²¹¶¡¡£¡£¡£¡£¡£
¡ñ ±ÈÕÕÏà¹ØIOC£¬£¬£¬£¬·¢Ã÷ÊÇ·ñ±£´æÖ÷»ú±»¿ØÐÐΪ¡£¡£¡£¡£¡£
¡ñ µ±·¢Ã÷Ö÷»ú±£´æÍÚ¿óľÂí¼°½©Ê¬ÍøÂç³ÌÐòʱ£¬£¬£¬£¬Îñ±ØÁ¬Ã¦¾ÙÐÐÈ«·½Î»µÄ¼ì²é´¦Öóͷ£¡£¡£¡£¡£¡£
¸½Â¼£ºIOC
1¡¢¶ñÒâÑù±¾ÏÂÔØµØµã
http[:]//80.71.158.96/bashirc.i686
http[:]//a.oracleservice.top/bashirc.i686
http[:]//89.41.182.160/bashirc.i686
http[:]//45.61.184.118/bashirc.i686
http[:]//bash.givemexyz.in/bashirc.i686
http[:]//209.141.59.139/bashirc.i686
http[:]//205.185.118.119/bashirc.i686
http[:]//185.157.160.214/bashirc.i686
http[:]//91.198.77.78/bashirc.i686
http[:]//bash.givemexyz.in/i686
http[:]//a.oracleservice.top/i686
http[:]//194.38.20.31/i686
http[:]//89.41.182.160/i686
http[:]//209.141.59.139/i686
http[:]//bash.givemexyz.in/xms.x86_64
http[:]//a.oracleservice.top/x86_64
http[:]//80.71.158.96/x86_64
http[:]//209.141.59.139/x86_64
http[:]//45.61.184.118/x86_64
http[:]//194.38.20.31/x86_64
http[:]//185.157.160.214/x86_64
http[:]//91.198.77.78/x86_64
http[:]//205.185.118.119/x86_64
http[:]//185.101.107.92/x86_64
http[:]//89.41.182.160/x86_64
http[:]//45.61.184.118/x86_64
http[:]//209.141.59.139/x86_64
http[:]//194.38.20.31/sshpass
http[:]//bash.givemexyz.in/x32b
http[:]//89.41.182.160/x32b
http[:]//a.oracleservice.top/x32b
http[:]//80.71.158.96/x32b
http[:]//bash.givemexyz.in/x64b
http[:]//89.41.182.160/x64b
http[:]//80.71.158.96/x64b
http[:]//a.oracleservice.top/x64b
http[:]//80.71.158.96/hxx
http[:]//89.41.182.160/hxx
http[:]//209.141.59.139/hxx
http[:]//bash.givemexyz.in/hxx
http[:]//209.141.59.139:80
http[:]//89.41.182.160:80
http[:]//194.38.20.31:80
http[:]//205.185.118.119:80
http[:]//209.141.59.139:80
http[:]//185.157.160.214:80
http[:]//80.71.158.96/masscan
http[:]//194.38.20.31/masscan
http[:]//194.38.20.31/banner
http[:]//bash.givemexyz.in/banner
http[:]//194.38.20.31/mywindows.exe
http[:]//89.41.182.160/mywindows.exe
http[:]//a.oracleservice.top/mywindows.exe
http[:]//209.141.59.139/scan
http[:]//89.41.182.160/scan
http[:]//bash.givemexyz.in/scan
http[:]//a.oracleservice.top/scan
http[:]//205.185.118.119/scan
http[:]//194.38.20.31/scan
http[:]//80.71.158.96/scan
http[:]//194.38.20.31/scan2
http[:]//205.185.118.119/scan2
http[:]//89.41.182.160/eii.py
http[:]//194.38.20.31/eii.py
http[:]//205.185.118.119/oracleservice.exe
http[:]//80.71.158.96/oracleservice.exe
http[:]//194.38.20.31/oracleservice.exe
http[:]//89.41.182.160/wxm.exe
http[:]//80.71.158.96/wxm.exe
http[:]//209.141.59.139/wxm.exe
http[:]//194.38.20.31/wxm.exe
http[:]//205.185.118.119/wxm.exe
2¡¢¶ñÒâÑù±¾MD5
ee48aa6068988649e41febfa0e3b2169
0ba9e6dcfc7451e386704b2846b7e440
63a86932a5bad5da32ebd1689aa814b3
c4d44eed4916675dd408ff0b3562fb1f
b42183f226ab540fb07dd46088b382cf
7ff1601a0291bd214573956dcda33230
9e935bedb7801200b407febdb793951e
b2755fc18ae77bc86322409e82a02753
08e7d711e13e1e95bbd5dc576d90f372
eb2f5e1b8f818cf6a7dafe78aea62c93
101ce170dafe1d352680ce0934bfb37e
dc3d2e17df6cef8df41ce8b0eba99291
f0cf1d3d9ed23166ff6c1f3deece19b4
0958fa69ba0e6645c42215c5325d8f76
6e7c0ff683d771875cd7edd2ed7b72e2
2559e97c13e731d9f37b1630dff2bb1e
b2d3f97fa0a66683e217b1f06ec9c4c8
3¡¢·ÅÂíÓòÃû
a.oracleservice.top
bash.givemexyz.in
oracleservice.top
givemexyz.in
4¡¢C2µØµã
c4k.xpl.pwndns.pw
104.244.75.25
51.255.171.23
104.168.71.132
5¡¢Ñù±¾ÏÂÔØÐ§ÀÍÆ÷IP
194.38.20.31
80.71.158.96
45.61.184.118
212.114.52.24
209.141.59.139
89.41.182.160
205.185.118.119
91.198.77.78

¾©¹«Íø°²±¸ 11010802026257ºÅ