¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

ȫжñÒâÈí¼þVPNFilter¿ØÖÆÈ«ÇòÖÁÉÙ50ÍòÌ¨ÍøÂç×°±¸

2018-05-29

Ðû²¼Õߣº¾ÅÓÎÀÏ¸ç¿Æ¼¼

¿ËÈÕ£¬ÓÐÒ»¿îÃûΪVPNFilterµÄ¶ñÒâÈí¼þ±»·¢Ã÷ѬȾÁËÖÁÉÙ50ÍòµÄÍøÂç×°±¸£¬TalosÍŶÓÔÚ½ü¼¸¸öÔÂÀ´Ò»Ö±ÔÚÓë¸÷ÍþвÇ鱨³§É̺ÍÖ´·¨»ú¹¹ÏàÖú£¬Í¨¹ýÑо¿ºó·¢Ã÷£¬Õâ¿î¶ñÒâÈí¼þÊ®·ÖÏȽø£¬¿ÉÄÜÊÇÓɹú¼Ò×ÊÖú»òÓë¹ú¼Ò¼¶±ðµÄ¹¥»÷ÕßÌᳫµÄ£¬ÊÇÒ»ÖÖÏȽøµÄÄ£¿é»¯¶ñÒâÈí¼þϵͳ£¨modular malware system£©¡£ ±¾ÎÄÕ¹ÏÖÁ˸öñÒâÈí¼þµÄÊÖÒÕϸ½Ú²¢Ìá³öÁË·À»¤²½·¥¡£


¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾


ËäÈ»ÏÖÔÚÑо¿»¹Ã»ÓÐÍêÈ«Íê³É£¬¿ÉÊǹûÕæµÄÐÅÏ¢Ó¦¸Ã»áÓÐÖúÓÚÊÜÓ°ÏìµÄ¿Í»§¿ÉÒÔʵʱµÄ½ÓÄÉ·À»¤²½·¥¡£ ÖµµÃÒ»ÌáµÄÊÇ£¬¸Ã¶ñÒâÈí¼þµÄ´úÂëÓëBlackEnergy¶ñÒâÈí¼þÓÐÏàËÆµÄ´úÂëÆ¬¶Ï£¬BlackEnergy¶ñÒâÈí¼þÒ»¾­Õë¶ÔÎÚ¿ËÀ¼×°±¸Ìᳫ¹ý¶à´Î´ó¹æÄ£¹¥»÷¡£ ËäÈ»»¹ÎÞ·¨Íêȫһ¶¨£¬µ«VPNFilter×÷ΪһÖÖDZÔ򵀮ÆËðÐÔ¶ñÒâÈí¼þ£¬Ê¹ÓÃÌØ±ðµÄCC£¨Command & control£©²½·¥£¬ÕýÔÚÒÔ¾ªÈ˵ÄËÙÂÊ×Ô¶¯Ñ¬È¾ÎÚ¿ËÀ¼Ö÷»ú¡£×ÛºÏÕâЩÒòËØ£¬ÏÖÔÚËäÈ»»¹Ã»ÓÐÍêÈ«ÆÊÎöÍê³É£¬µ«Ðû²¼ÏÖÔÚµÄЧ¹û¿ÉÒԺܺõÄ×ÊÖú¸÷·½½ÓÄÉÏìÓ¦µÄ·À»¤²½·¥¡£


¸Ã¶ñÒâÈí¼þµÄÆÆËðÄÜÁ¦ºÍÓ°Ïì¹æÄ£¶¼ÊÇÖµµÃ×¢ÖØµÄ£¬ÔÚTalos ÓëÆäÏàÖúͬ°éµÄͳ¼ÆÏ£¬È«ÇòÖÁÉÙ54¸ö¹ú¼Ò/µØÇøÊÜÓ°Ï죬ѬȾµÄ×°±¸ÊýÄ¿ÖÁÉÙΪ500000¡£ ÊÜVPNFilterÓ°ÏìµÄÒÑ֪װ±¸ÓÐСÐͺͼÒÍ¥°ì¹«ÊÒ£¨SOHO£©¿Õ¼äÖеÄLinksys£¬MikroTik£¬NETGEARºÍTP-LinkÍøÂç×°±¸ÒÔ¼°QNAPÍøÂ總¼Ó´æ´¢£¨NAS£©×°±¸¡£ ÏÖÔÚûÓÐÆäËû¹©Ó¦ÉÌ£¬°üÀ¨Ë¼¿Æ£¨Cisco£©£¬±»ÊӲ쵽±»VPNFilterѬȾ¡£ ÕâÖÖ¶ñÒâÈí¼þÔÚÍøÂçÉè±¹ØÁ¬ÄÐÐΪÓÈÆäÁîÈ˹Ø×¢£¬ÓÉÓÚVPNFilter¶ñÒâÈí¼þµÄ×é¼þ¿ÉÒÔÇÔÈ¡ÍøÕ¾Ö¤Êé²¢¼à¿ØModbus SCADAЭÒé¡£ ×îºó£¬¶ñÒâÈí¼þ¾ßÓÐÆÆËðÐÔÄÜÁ¦£¬¿ÉÄܵ¼ÖÂÊÜѬȾµÄ×°±¸ÎÞ·¨Ê¹Óã¬Õâ¿ÉÄÜ»áÔÚ¸öÌåÊܺ¦Õß»úеÉÏ´¥·¢»òÕûÌå´¥·¢£¬Òò´ËÓпÉÄÜÇжÏÈ«ÇòÊýÊ®ÍòÊܺ¦ÕߵĻ¥ÁªÍø½ÓÈë¡£


ÁíÍ⣬ÊܸöñÒâÈí¼þ¹¥»÷µÄ×°±¸ºÜÄѾÙÐзÀ»¤¡£ ÓÉÓÚËüÃǾ­³£Î»ÓÚÍøÂçµÄÍâΧ£¬Ã»ÓÐÈëÇÖ±£»¤ÏµÍ³£¨IPS£©£¬²¢ÇÒͨ³£Ã»ÓпÉÓõĻùÓÚÖ÷»úµÄ±£»¤ÏµÍ³£¬Èç·À²¡¶¾£¨AV£©Èí¼þ¡£ ÏÖÔÚÑо¿Ö°Ô±»¹ÎÞ·¨È·ÈÏѬȾÊÇÔõÑù¾ÙÐеÄ£¬µ«´ó´ó¶¼×°±¸£¬ÓÈÆäÊǾɰ汾£¬¶¼±£´æÒÑÖªµÄ¹ûÕæµÄÎó²î£¬ÕâʹµÃ¹¥»÷ÕߵĹ¥»÷±äµÃÈÝÒ×ÁËÐí¶àÒ²µ¼ÖÂÁË×Ô2016ÄêÒÔÀ´ÕâÖÖÍþвµÄÇÄÈ»ÔöÌí¡£


Ö´Ðа취


VPNFilterÊÇÒ»¸ö¶à½×¶ÎµÄ£¬Ä£¿é»¯µÄ£¬¾ßÓжàÖÖ¹¦Ð§µÄ£¬¿ÉÖ§³ÖÇé±¨ÍøÂçºÍÆÆËðÐÔÍøÂç¹¥»÷²Ù×÷µÄ¶ñÒâÈí¼þ¡£


µÚÒ»½×¶Î¶ñÒâÈí¼þͨ¹ýÖØÐÂÆô¶¯¶øÒ»Á¬±£´æ£¬ÕâÓë´ó´ó¶¼ÆäËûÕë¶ÔÎïÁªÍø×°±¸µÄ¶ñÒâÈí¼þ²î±ð£¬ÓÉÓÚ¶ñÒâÈí¼þͨ³£ÎÞ·¨ÔÚ×°±¸ÖØÐÂÆô¶¯ºó´æ»î¡£ ½×¶Î1µÄÖ÷ҪĿµÄÊÇ»ñµÃ³¤ÆÚµÄפ×ãµã£¬²¢Äܹ»°²ÅźóÐøµÄ¶ñÒâÈí¼þ¡£½×¶Î1ʹÓöà¸öÈßÓàC&C£¨C2£©»úÖÆÀ´·¢Ã÷Ä¿½ñ½×¶Î°²ÅÅ·þÎñÆ÷µÄIPµØµã£¬Ê¹µÃÕâÖÖ¶ñÒâÈí¼þºÜÊÇǿʢ²¢ÇÒÄܹ»´¦Öóͷ£²»¿ÉÕ¹ÍûµÄC2»ù´¡Éèʩת±ä¡£


µÚ¶þ½×¶ÎµÄ¶ñÒâÈí¼þ²»»áÔÚÖØÐÂÆô¶¯ºóÒ»Á¬±£´æ£¬ËüÓµÓÐÇé±¨ÍøÂçÆ½Ì¨µÄ¹¦Ð§£¬ÀýÈçÎļþÍøÂ磬ÏÂÁîÖ´ÐУ¬Êý¾Ýй¶ºÍ×°±¸ÖÎÀí¡£ ¿ÉÊÇ£¬½×¶Î2µÄijЩ°æ±¾»¹¾ßÓÐ×Ô»Ù¹¦Ð§£¬¿ÉÁýÕÖ×°±¸¹Ì¼þµÄÒªº¦²¿·Ö²¢ÖØÐÂÆô¶¯×°±¸£¬Ê¹ÆäÎÞ·¨Ê¹ÓᣠÏÖÔÚ¾­Ñо¿Ö°Ô±ÆÊÎö£¬¸Ã×Ô»Ù¹¦Ð§ºÜ¿ÉÄܻᱻ°²Åŵ½ËùÓÐÊÜѬȾµÄ×°±¸ÉÏ¡£

±ðµÄ£¬µÚ¶þ½×¶ÎµÄ¶ñÒâÈí¼þ»¹ÓµÓжà¸ö²å¼þ×÷ΪºóÐøµÄµÚÈý½×¶ÎÄ£¿é £¬Ìṩ¸½¼Ó¹¦Ð§¡£×èÖ¹ÏÖÔÚ£¬¹²ÓÐÁ½¸ö²å¼þÄ£¿é£ºÓÃÓÚÍøÂçͨ¹ý×°±¸µÄÁ÷Á¿µÄÊý¾Ý°üÐá̽Æ÷£¬°üÀ¨ÇÔÈ¡ÍøÕ¾Ö¤ÊéºÍ¼àÊÓModbus SCADAЭÒéÒÔ¼°ÔÊÐí½×¶Î2ͨ¹ýTor¾ÙÐÐͨѶµÄͨѶÄ£¿é¡£


TradecraftÌÖÂÛ


TalosÈÏÕæÆÀ¹Àºó£¬ÒÔΪÕâÖÖ¶ñÒâÈí¼þÊÇÓÃÀ´½¨ÉèÒ»¸öÆÕ±éµÄ£¬ÄÑÒÔ×·×ٵģ¬¿ÉÓÃÓÚÖª×ã¹¥»÷ÕߵĶàÖÖÐèÇóµÄƽ̨¡£ ÓÉÓÚÊÜÓ°ÏìµÄ×°±¸ÓÉÆóÒµ»òСÎÒ˽¼ÒÕýµ±ÓµÓУ¬Òò´Ë´ÓÊÜѬȾװ±¸¾ÙÐеĶñÒâÔ˶¯¿ÉÄܻᵼÖÂÎÞ·¨È·ÈϹ¥»÷µÄ׼ȷ±¬·¢µØÇø¡£ Í¬Ê±£¬ÄÚÖÃÓÚ¶ñÒâÈí¼þ¸÷¸ö½×¶ÎºÍ²å¼þµÄ¹¦Ð§ºÜÊÇÎÞа£¬¿ÉÒÔʹ¹¥»÷ÕßÒÔ¶àÖÖ·½·¨Ê¹ÓÃ×°±¸¡£


APTµÄÄ»ºóÖ°Ô±£¬°üÀ¨Ãñ×å¹ú¼Ò£¬½«Æð¾¢Ê¹ÆäÍøÂçÔ˶¯µÄ¹éÊôÅжϱäµÃ¼«ÆäÄÑÌ⣬³ý·ÇΪÁËÖª×ãËûÃÇ×Ô¼ºÒ»Ð©ÆæÒìµÄÐèÇ󣬲Żá¹ûÕæÐû¸æ¹éÊô¡£ Îª´Ë£¬¹¥»÷ÕßʹÓÃÁ˶àÖÖÊÖÒÕ£¬°üÀ¨ÓÉËûÈËÓµÓеÄÅäºÏ»ù´¡ÉèÊ©À´Ö´ÐÐÆä²Ù×÷¡£ ÔÚÅþÁ¬µ½×îÖÕÊܺ¦ÕßµÄÖÕ¶Ë×°±¸Ö®Ç°£¬¹¥»÷Õß¿ÉÒÔÇáËÉʹÓÃÊÜѬȾµÄ×°±¸×÷ΪÖÐת£¬ÒÔ±ã»ìÏýËüÃǵÄÕæÊµÎ»Öá£


¶ñÒâÈí¼þÒ²¿ÉÒÔÓÃÀ´ÍøÂç×°±¸µÄÊý¾Ý¡£ ³ýÁË´¿´âµÄÊý¾ÝÍøÂ磬¹¥»÷Õß¿ÉÄÜÒ²»áÆÀ¹À¸Ã×°±¸ËùÔÚÍøÂçµÄDZÔÚ¼ÛÖµ¡£ÈôÊǹ¥»÷ÕßÅжϸÃ×°±¸ÍøÈ·ÊµÓмÛÖµ£¬¿ÉÄÜ»áÑ¡Ôñ¼ÌÐøÍøÂçÐÅÏ¢²¢ÇÒÅþÁ¬µ½×°±¸ËùÔÚµÄÍøÂçÀ´»ñÈ¡¸ü¶àÐÅÏ¢¡£ ×èÖ¹ÏÖÔÚ£¬Ñо¿Ö°Ô±ÉÐδ»ñµÃÄܹ»½øÒ»²½Ê¹ÓÃ×°±¸Ëù·þÎñµÄÍøÂçµÄµÚÈý½×¶Î²å¼þ£¬¿ÉÊǼòÖ±·¢Ã÷Á˸ù¦Ð§²å¼þ±£´æµÄºÛ¼££¬¹¥»÷Õß¿ÉÒÔºÜÇáËɵĽ²Õâ¸ö¹¦Ð§¼ÓÈ뵽ģ¿é»¯µÄ¶ñÒâÈí¼þÖС£


×îºó£¬¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓá°kill¡±ÏÂÁîʹѬȾµÄ×°±¸¾ÙÐдó¹æÄ£µÄÆÆËðÐÔ¹¥»÷£¬Õâ»áµ¼Ö²¿·Ö»òËùÓÐÎïÀí×°±¸ÎÞ·¨Ê¹Óᣠ¸ÃÏÂÁî·ºÆðÔÚÊӲ쵽µÄÐí¶à½×¶Î2Ñù±¾ÖУ¬µ«Ò²¿ÉÒÔͨ¹ýʹÓÃËùÓн׶Î2Ñù±¾Öеġ°exec¡±ÏÂÁîÀ´´¥·¢¡£ ÔÚ´ó´ó¶¼ÇéÐÎÏ£¬´ó´ó¶¼Êܺ¦ÕßÎÞ·¨»Ö¸´´ËÏÓÉÓÚ»Ö¸´ËùÐèÒªµÄÊÖÒÕÄÜÁ¦£¬×¨ÓÐÊÖÒÕ»òһЩ¹¤¾ßͨ³£ÊÇÆ½Ì¨Óû§ËùûÓеÄ¡£ Õâ¾ÍʹµÃÇéÐαäµÃÊ®·ÖΣ¼±£¬ÆÈʹÑо¿Ö°Ô±ÃǾÙÐиü¶àµÄÑо¿¡£


ÊӲ쵽µÄ¶ñÒâÐÐΪ


ÔÚ5Ô³õ£¬Ñо¿Ö°Ô±Í¨¹ýɨÃèÊӲ쵽¸ÃÍþÐ²Éæ¼°È«Çò¡£ËæºóÔÚ¶Ë¿Ú23802000ºÍ8080ÉϾÙÐÐTCPɨÃèÊÜѬȾװ±¸£¬ÕâЩ¶Ë¿ÚÅú×¢Îú¸Ã¶ñÒâÈí¼þÔÚɨÃèÆäËûMikrotikºÍQNAP NAS×°±¸£¬Õë¶Ô100¶à¸ö¹ú¼Ò/µØÇø¡£ ÕâЩÊܺ¦ÕßÖеÄÐí¶àIPËÆºõºÜÃ÷È·µÄÌåÏÖÆäÊý¾Ýй¶µÄÐÐΪ¡£


×îºó£¬ÔÚ5ÔÂ8ÈÕ£¬TalosÍŶÓÊӲ쵽VPNFilterѬȾÐÐΪ¼±¾çÔöÌí¡£ ÏÕЩËùÓÐеÄÊܺ¦Õß¶¼Î»ÓÚÎÚ¿ËÀ¼¡£ »¹ÖµµÃ×¢ÖØµÄÊÇ£¬´ó´ó¶¼ÎÚ¿ËÀ¼Ñ¬È¾¹²ÏíÁËÀ´×ÔÌìÏÂÆäËûµØ·½µÄ×ÔÁ¦µÚ2½×¶ÎC2»ù´¡ÉèÊ©£¬IP 46.151.209 [¡£] 33¡£ ÔÚÕâÒ»µãÉÏ£¬Ñо¿Ö°Ô±Òâʶµ½BlackEnergyºÍVPNFilterÖ®¼äµÄ´úÂëÖØµþ£¬Æ¾Ö¤Ö®Ç°ÎÚ¿ËÀ¼µÄ¹¥»÷£¬ÕâÒ»ÂÖ¹¥»÷ºÜ¿ÉÄܼ´½«±¬·¢¡£ ÔÚ5ÔÂ17ÈÕ£¬ÎÚ¿ËÀ¼µÄÊÜѬȾװ±¸Ôٴδó·ùÔöÌí£¬¼øÓÚÕâЩÒòËØ£¬TalosÍŶӾöÒéÌáǰ¹ûÕæÑо¿Ð§¹û¡£


ÊÖÒÕϸ½Ú


ʹÓÃ


ÏÖÔÚ£¬Ñо¿Ö°Ô±»¹Ã»·¢Ã÷¹¥»÷ÕßÊÇÔõÑùʹÓÃÕâЩÊÜѬȾµÄ×°±¸µÄ£¬¿ÉÊǼøÓÚÕâЩװ±¸¶¼±£´æ¹ûÕæµÄÎó²î£¬ÍƲâVPNFilter²»ÐèÒªÆäËûµÄ0-day¹¥»÷ÊÖÒÕ¡£


½×¶Î1¼ÓÔØÆ÷


VPNFilterµÄ½×¶Î1¶ñÒâÈí¼þ»áѬȾ»ùÓÚBusyboxºÍLinuxÔËÐй̼þµÄ×°±¸£¬²¢Õë¶Ô¶àÖÖCPU¼Ü¹¹¾ÙÐбàÒë¡£ ÕâЩµÚÒ»½×¶Î¶þ½øÖÆÎļþµÄÖ÷ҪĿµÄÊÇÕÒµ½Ò»Ì¨Ìṩ¸üÖÜÈ«µÄµÚ¶þ½×¶ÎµÄ·þÎñÆ÷£¬²¢ÏÂÔØ²¢Î¬»¤ÊÜѬȾװ±¸µÄÏÂÒ»½×¶ÎµÄ³¤ÆÚÐÔ¡£ ËüÄܹ»Ð޸ķÇÒ×ʧÐÔÉèÖÃÄڴ棨NVRAM£©Öµ²¢½«Æä×ÔÉíÌí¼Óµ½Linux×÷Òµµ÷Àí³ÌÐòcrontabÖÐÒÔʵÏÖ³¤ÆÚÐÔ£¬ÕâÓëÒÔǰµÄÎïÁªÍø¶ñÒâÈí¼þÓÐËù²î±ð¡£


TalosÆÊÎöÁËÓÃÓÚMIPSºÍx86´¦Öóͷ£Æ÷µÄÑù±¾¡£ C2ͨѶºÍÆäËû¶ñÒâÈí¼þÏÂÔØÍ¨¹ýTor»òSSL¼ÓÃÜÅþÁ¬¾ÙÐС£ ËäÈ»¶þ½øÖÆÎļþ×Ô¼ºÔÚ±»°þÀëÖ®ºó²»»á±»»ìÏý£¬µ«Ä³Ð©×Ö·û´®ÒÔ¼ÓÃÜÐÎʽ´æ´¢£¬²¢ÇÒ½öÔÚÔËÐÐʱ½âÃÜ¡£ ÔÚ¾²Ì¬ÆÊÎöÖУ¬½âÃܳÌÐò¿´ÆðÀ´ÓëRC4ºÜÊÇÏàËÆ£¬µ«¿´ÆðÀ´¶ñÒâÈí¼þ×÷ÕßµÃÔÚ³õʼ»¯s-boxʱ³öÁË´í¡£ ÔÚÖû»°ì·¨ÖУ¬Öµ±»Òì»ò£¬µ«Î´½»Á÷¡£ ¶ÔRC4ʵÑéÇéÐÎµÄÆÊÎöÅú×¢£¬ËüÓëBlackEnergyÖÐʹÓõÄÖ´·¨»ú¹¹Ïàͬ£¬ ²¢ÒÔΪӦ¸ÃÀ´×Ô¹ú¼Ò¼¶±ðµÄÐÐΪ¡£


Ò»µ©¶ñÒâÈí¼þÍê³É³õʼ»¯£¬Ëü¾Í×îÏÈ´ÓÖÖ×ÓURLÏÂÔØÏà¹ØÒ³Ãæ¡£ ÔÚMIPSʾÀý»º´æºÍx86ʾÀýÖУ¬³ýÒ»¸öURLÖ®ÍâµÄËùÓÐURL¶¼Ö¸ÏòͼÏñ¹²ÏíÖ÷»úPhotobucket.com¡£ ¶ñÒâÈí¼þ´ÓURLËùÒýÓõĿâÖÐÏÂÔØµÚÒ»¸öÓ³Ïñ£¬È»ºó¼ÌÐøÌáÈ¡ÏÂÔØ·þÎñÆ÷µÄIPµØµã¡£ IPµØµãÊÇ´ÓEXIFÐÅÏ¢ÖеÄÁù¸öGPSγ¶ÈºÍ¾­¶ÈÕûÊýÖµÖÐÌáÈ¡µÄ¡£


ÈôÊǽ׶Î1ÎÞ·¨ÅþÁ¬»ò´ÓPhotobucketÖеÄͼÏñIPµØµãÏÂÔØÍ¼Ïñ»òÀֳɻñÈ¡IPµØµã£¬Ôò¶ñÒâÈí¼þ»áÈ¥±¸·ÝµÄÓòtoknowall [¡£] comÏÂÔØÍ¼Ïñ²¢ÊµÑéÏàͬµÄÀú³Ì¡£


ÈôÊǶԱ¸·ÝÓòµÄʵÑéʧ°Ü£¬Ôò½×¶Î1½«·­¿ªÒ»¸öÕìÌýÆ÷£¨listener£©£¬¸ÃÕìÌýÆ÷ÆÚ´ýÌØ¶¨µÄ´¥·¢°ü·­¿ªÅþÁ¬£¬ÒÔ±ãÑÝÔ±½»»¥ÅþÁ¬µ½×°±¸¡£ µ±ÕìÌýÆ÷·­¿ªÊ±£¬Ëü»á´Óapi.ipify [¡£] orgÖмì²éÆä¹«¹²IP²¢½«Æä´æ´¢ÒÔ¹©ÒÔºó½ÏÁ¿¡£ È»ºó£¬µ±ÈκÎÊý¾Ý°üµÖ´ïÈκζ˿Úʱ£¬¼àÌýÆ÷Ö´ÐÐһϵÁмì²éÀ´Ê¶±ð´¥·¢Êý¾Ý°ü¡£ ÈôÊÇÊý¾Ý°üÇкÏÔ¤½ç˵µÄÒ»×é±ê×¼£¬Ëü½«´ÓÊý¾Ý°üÖÐÌáÈ¡IPµØµã²¢ÊµÑé¾ÙÐеÚ2½×¶ÎÏÂÔØ¡£


listenerÐÐΪ£º

  • ¼ì²éËùÓÐÉèÖÃÁËSYN±ê¼ÇµÄTCP / IPv4Êý¾Ý°ü
  • ¼ì²éÄ¿µÄIPÊÇ·ñÓëÕìÌýÆ÷·­¿ªÊ±ÕÒµ½µÄÄÚÈÝÆ¥Å䣍ע֨£ºÈôÊÇÕìÌýÆ÷δÄÜ´Óipify [¡£] org»ñÈ¡IP£¬Ëü½«Ìø¹ý´Ë¼ì²é£©
  • È·±£Êý¾Ý°üÓа˸ö»ò¸ü¶à×Ö½Ú
  • ɨÃè×Ö½Ú x0c x15 x22 x2bµÄÊý¾Ý
  • ½ô½ÓÔÚ¸Ã4×Ö½Ú±ê¼ÇÖ®ºóµÄ×Ö½Ú±»Ú¹ÊÍΪIP£¬Òò´Ë x01 x02 x03 x04±äΪ- > 1.2.3 [¡£] 4
  • ÏòµÚ2½×¶ÎµÄѰ³£ºô½ÐÐÂÊÕµ½µÄIP
  • È·ÈϽ׶Î2ÖÁÉÙΪ1001×Ö½Ú£¨×¢ÖØ£ºÕâ±ÈÆäËû±ê×¢ÒªÁìСµÃ¶à£¬ÒªÇó½×¶Î2Ϊ100000»ò¸ü¶à£©


½×¶Î2£¨·ÇÒ»Á¬£©


½×¶Î2¶ñÒâÈí¼þÊ×ÏÈͨ¹ý½¨ÉèÄ£¿éÎļþ¼Ð£¨/ var / run / vpnfilterm£©ºÍÊÂÇéĿ¼£¨/ var / run / vpnfilterw£©À´ÉèÖÃÊÂÇéÇéÐΡ£ Ö®ºó£¬Ëü½«ÔËÐÐÔÚÒ»¸öÑ­»·ÖУ¬Ê×ÏȵִïC&C·þÎñÆ÷£¬È»ºóÖ´ÐдÓC&CÖмìË÷µÄÏÂÁî¡£ ÏÂÁîÃûʹÓÃÓë½×¶Î1ÖÐÏàͬµÄRC4º¯Êý¾ÙÐмÓÃÜ¡£ÐÒÔ˵ÄÊÇ£¬½ÏÔç°æ±¾µÄx86½×¶Î2ʾÀýºÜÊÇÏêϸ£¬²¢ÇÒµ÷ÊÔ´òÓ¡ÁËËüÖ´ÐеÄËùÓа취¡£ ½Ïа汾µÄx86ºÍMIPSÑù±¾ÔÚ½×¶Î2Öв»°üÀ¨µ÷ÊÔ´òÓ¡¡£


x86ʾÀý¿ÉÒÔÖ´ÐÐÒÔϲÙ×÷£º

  • kill£ºÓÃÁãÁýÕÖ/ dev / mtdblock0µÄǰ5000¸ö×Ö½Ú£¬È»ºóÖØÆô×°±¸£¨ÓÐÓÃµØ¶ÔÆä¾ÙÐÐˢУ©¡£
  • exec£ºÖ´ÐÐÒ»¸öshellÏÂÁî»ò²å¼þ¡£
  • tor£ºÉèÖÃTorÉèÖñê¼Ç£¨0»ò1£©¡£
  • ¸´ÖÆ£º½«Îļþ´Ó¿Í»§¶Ë¸´ÖƵ½·þÎñÆ÷¡£
  • seturl£ºÉèÖÃÄ¿½ñÉèÖÃÃæ°åµÄURL¡£
  • ÊðÀí£ºÉèÖÃÄ¿½ñµÄÊðÀíURL¡£
  • ¶Ë¿Ú£ºÉèÖÃÄ¿½ñµÄÊðÀí¶Ë¿Ú¡£
  • delay£ºÉèÖÃÖ÷Ñ­»·Ö´ÐÐÖ®¼äµÄÑÓ³Ù¡£
  • ÖØÆô£ºÈôÊÇ×°±¸Æô¶¯Áè¼Ý256Ã룬ÔòÖØÐÂÆô¶¯×°±¸£¬²¢ÔÚ²ÎÊýÖÐÖ¸¶¨ÌìÉúÃû³Æ¡£
  • ÏÂÔØ£º½«URLÏÂÔØµ½Îļþ¡£Õâ¿ÉÒÔÓ¦ÓÃÓÚËùÓÐ×°±¸»òÖ»ÊÇÒ»¸öÌØ¶¨µÄ¹¹½¨Ãû³Æ¡£


MIPSʾÀý¾ßÓÐÒÔϸ½¼Ó²Ù×÷£º

  • ×èÖ¹£ºÖÕÖ¹¶ñÒâÈí¼þÀú³Ì¡£
  • relay£ºx86°æ±¾µÄ\`delay\`ÏÂÁîµÄƴд¹ýʧ°æ±¾¡£


ÔÚ×°ÖÃTorÄ£¿é֮ǰ£¬½×¶Î2»á½«ÆäÉèÖÃÖд洢µÄÒ»¸ö»ò¶à¸öIP×÷ΪSOCKS5ÊðÀí·þÎñÆ÷ʹÓ㬲¢ÊµÑéÓëÆäÉèÖÃÖÐÕÒµ½µÄ¿ØÖÆÃæ°å¾ÙÐÐͨѶ¡£ Óë½×¶Î1Ò»Ñù£¬¶ñÒâÈí¼þÓëÊðÀíÖ®¼äµÄͨѶ½«Í¨¹ýÑéÖ¤µÄSSLÅþÁ¬¾ÙÐÐÅþÁ¬¡£ µ±×°ÖÃTorÄ£¿éʱ£¬Ëü½«Í¨¹ýÄ£¿éÌṩµÄÍâµØSOCKS5ÊðÀíͨ¹ýͨË×µÄHTTPÅþÁ¬µ½.onionÓòÃû¡£


¶ñÒâÈí¼þ½«ÇëÇó±àÂë³ÉÒ»¸öJSON¹¤¾ß£¬È»ºóÒÔbase64±àÂë²¢·¢Ë͵½HTTP POST²ÎÊý¡°me¡±ÖеÄ·¾¶/bin32/update.php¡£


½×¶Î3£¨·ÇÒ»Á¬£©


Ñо¿Ö°Ô±ÒѾ­ÆÊÎöÁ˶ñÒâÈí¼þµÄÁ½¸ö²å¼þÄ£¿é£¬Ò»¸öÊý¾Ý°üÐá̽Æ÷ºÍÒ»¸öÔÊÐí¶ñÒâÈí¼þͨ¹ýTor¾ÙÐÐͨѶµÄͨѶ²å¼þ£¬ÒÔ¼°¼¸¸ö»¹Î´±»·¢Ã÷µÄÄ£¿é¡£ ÔÚTalos»ñÈ¡µÄ×î³õÑù±¾ÖУ¬ÓÐÒ»¸öMIPS½×¶Î2µÄ²å¼þ£¬ËüÊÇÒ»¸öÊý¾Ý°üÐá̽Æ÷¡£ Ëüͨ¹ýԭʼÌ×½Ó×Ö×èµ²ËùÓÐÍøÂçÁ÷Á¿£¬²¢²éÕÒHTTP»ù×Ô¼º·ÝÑéÖ¤ÖÐʹÓõÄ×Ö·û´®¡£ ±ðµÄ£¬Ëüרßú×ÙModbus TCP / IPÊý¾Ý°ü¡£ ÌìÉúµÄÈÕÖ¾Îļþ°²ÅÅÔÚµÚ2½×¶ÎµÄÊÂÇéĿ¼/ var / run / vpnfilterwÖС£ ÕâʹµÃ¹¥»÷Õß¿ÉÒÔÏàʶ£¬²¶»ñ²¢¸ú×ÙÁ÷¾­×°±¸µÄÁ÷Á¿¡£


Tor²å¼þÄ£¿é²¿·ÖÁ´½Óµ½½×¶Î2£¬µ«ÓÐÒ»¸öµ¥¶ÀµÄTor¿ÉÖ´ÐÐÎļþ£¬¸ÃÎļþ±»ÏÂÔØµ½/ var / run / tor²¢ÔËÐÐÔÚÓë½×¶Î2ÊèÉ¢µÄÀú³ÌÖС£Tor¶þ½øÖÆÎļþ¿´ÆðÀ´Ïñ±ê×¼µÄTor¿Í»§¶Ë£¬¾²Ì¬Á´½ÓºÍ°þÀë¶þ½øÖƵÄÐÎʽ¡£ ËüÔÚ/ var / run / torrcÖн¨ÉèÒ»¸öÉèÖÃÎļþ£¬²¢ÔÚ/ var / run / tordÖн¨ÉèÒ»¸öÊÂÇéĿ¼¡£


·À»¤²½·¥


ÓÉÓÚÊÜÓ°ÏìµÄ×°±¸µÄÐÔ×Ó£¬Õë¶Ô´ËÍþв¾ÙÐзÀÓùºÜÊÇÄÑÌâ¡£ ËûÃÇÖеĴó´ó¶¼Ö±½ÓÅþÁ¬µ½»¥ÁªÍø£¬ËûÃǺÍDZÔڵĹ¥»÷ÕßÖ®¼äûÓÐÇå¾²×°±¸»ò·þÎñ¡£ ÓÉÓÚ´ó´ó¶¼ÊÜÓ°ÏìµÄ×°±¸¶¼¾ßÓÐÒÑÖªµÄÎó²î£¬ÕâÒ»ÊÂʵ½øÒ»²½¼Ó¾çÁË·À»¤µÄÄѶÈ¡£ ÁíÍ⣬´ó´ó¶¼×°±¸Ã»ÓÐÄÚÖõķ´¶ñÒâÈí¼þ¹¦Ð§¡£ ÕâʹµÃ¸ÃÍþвºÜÊÇÄÑÒÔµÖÏû£¬×èµ²¶ñÒâÈí¼þ£¬Ïû³ýÎó²î»ò×èÖ¹ÍþвµÄʱ»ú¼«ÆäÓÐÏÞ¡£


Ö»¹ÜÃæÁÙÕâЩÌôÕ½£¬TalosÍŶÓÕë¶ÔÓë´ËÍþв¹ØÁªµÄ×°±¸¹ûÕæÒÑÖªµÄÎó²î£¬¿ª·¢²¢°²ÅÅÁËÁè¼Ý100¸öSnortÊðÃû¡£ ÕâЩ¹æÔòÒѾ­°²ÅÅÔÚ¹«¹²Snort¼¯ÖУ¬ÈκÎÈ˶¼¿ÉÒÔʹÓÃÕâЩ¹æÔòÀ´×ÊÖú±£»¤ËûÃǵÄ×°±¸¡£ ±ðµÄ£¬¶ñÒâµÄÓòÃû/ IPÒѱ»ÁÐÈëºÚÃûµ¥¡£ Talos¾Í¸ÃÍþвÓëLinksys£¬Mikrotik£¬Netgear£¬TP-LinkºÍQNAP¾ÙÐÐÁËÏàͬ¡£


½¨ÒéÓû§½ÓÄÉÒÔϲ½·¥£º

  • SOHO·ÓÉÆ÷ºÍ/»òNAS×°±¸µÄÓû§½«ËüÃǻָ´³ö³§Ä¬ÈÏÉèÖò¢ÖØÐÂÆô¶¯£¬ÒÔÏû³ýDZÔ򵀮ÆËðÐÔ½×¶Î2ºÍ½×¶Î3µÄ¶ñÒâÈí¼þ¡£
  • ÌṩSOHO·ÓÉÆ÷µÄ»¥ÁªÍø·þÎñÌṩÉÌ´ú±í¿Í»§ÖØÐÂÆô¶¯Â·ÓÉÆ÷¡£
  • ÈôÊÇÄúÓÐÈκÎÒÑÖª»òÒÉËÆÊÜ´ËÍþвӰÏìµÄ×°±¸£¬ÓëÖÆÔìÉÌÏàÖúºÜÊÇÖ÷Òª£¬ÒÔÈ·±£ÄúµÄ×°±¸¾ßÓÐ×îеÄÐÞ²¹³ÌÐò°æ±¾¡£ÈôÊDz»ÊÇ£¬ÔòÓ¦Á¬Ã¦Ó¦ÓøüеÄÐÞ²¹³ÌÐò¡£
  • »¥ÁªÍø·þÎñÌṩÉÌÆð¾¢ÓëËûÃǵĿͻ§ÏàÖú£¬ÒÔÈ·±£ËûÃǵÄ×°±¸Éý¼¶¸üе½×îеĹ̼þ/Èí¼þ°æ±¾¡£


ÓÉÓÚ¹¥»÷Õß¿ÉÄܽÓÄÉÆÆËðÐÔÐж¯£¬Òò´Ë½¨Òé¸÷ÈËÉóÉ÷¿´´ýËùÓÐSOHO»òNAS×°±¸²¢½ÓÄÉÕâЩ²½·¥£¬ÎÞÂÛ×°±¸ÊÇ·ñÒÑÖªÊܸöñÒâÈí¼þÓ°Ïì¡£


½áÂÛ


VPNFilterÊÇÒ»ÖÖÆÕ±é£¬Ç¿Ê¢£¬¹¦Ð§Ç¿Ê¢ÇÒΣÏÕµÄÍþв Æä¸ß¶ÈÄ£¿é»¯µÄ¿ò¼ÜÔÊÐí¹¥»÷Õß¶ÔÆä¾ÙÐпìËٸı䣬ÌṩÇé±¨ÍøÂçºÍºÍÆäËû·þÎñ¡£


VPNFilterµÄÆÆËðÐÔÄÜÁ¦ÖµµÃ¹Ø×¢¡£ ¹¥»÷ÕßʹÓÃÊÜѬȾµÄÓû§×°±¸À´ÑÚÊÎËûÃǵÄ×Ù¼££¬¶ø²»µ«½öÊÇɾ³ý¶ñÒâÈí¼þµÄºÛ¼££¬Í¬Ê±£¬¹¥»÷Õß¿ÉÄÜËæÊ±ÔËÐС°kill¡±ÏÂÁ¿ÉÄܻᵼÖ³ÉǧÉÏÍòµÄ×°±¸ÎÞ·¨Ê¹Ó㬵¼ÖÂÈ«ÇòÊýÊ®ÍòÊܺ¦ÕßÎÞ·¨»á¼û»¥ÁªÍø£¬»òÕßÔÚÌØ¶¨ÇøÓòÏÞÖÆÓû§µÄÍøÂçʹÓá£


ËäÈ»¶ÔÎïÁªÍø×°±¸µÄ¹¥»÷²¢²»ÊÇʲôÐÂÏÊÊ£¬µ«ÕâЩװ±¸Õý±»¹ú¼Ò¼¶±ðµÄÍŶÓÓÃÓÚ¾ÙÐÐÍøÂçÆÆËð£¬Õâ¼Ó¾çÁ˸÷·½³§ÉÌ´¦Öóͷ£´ËÎÊÌâµÄ½ôÆÈÐÔ¡£


²Î¿¼Á´½Ó£º

https://blog.talosintelligence.com/2018/05/VPNFilter.html

https://www.fortinet.com/blog/threat-research/defending-against-the-new-vpnfilter-botnet.html


IOCs


ÈçǰËùÊö£¬ÎÒÃǸ߶ÈÏÓÒÉÏÖÔÚ»¹Ã»ÓÐÒâʶµ½Õâ¸ö¶ñÒâÈí¼þÉÐÓÐÆäËûIOCºÍ°æ±¾¡£ ÏÂÃæµÄIOCÇåµ¥°üÀ¨ÁËÆù½ñËùÖªµÀµÄÇéÐΡ£


ÒÑÖªµÄC2ÓòºÍIP

ÓëµÚÒ»½×¶ÎÏà¹Ø

µÄphotobucket [¡£] COM /Óû§/ nikkireed11 /¿â
µÄphotobucket [¡£] COM /Óû§/ kmila302 /¿â
µÄphotobucket [¡£] COM /Óû§/ lisabraun87 /¿â
µÄphotobucket [¡£] COM /Óû§/ eva_green1 /¿â
µÄphotobucket [¡£] COM /Óû§/ monicabelci4 /¿â
µÄphotobucket [¡£] COM /Óû§/ katyperry45 /¿â
µÄphotobucket [¡£] COM /Óû§/ saragray1 /¿â
µÄphotobucket [¡£] COM /Óû§/ millerfred /¿â
µÄphotobucket [¡£] COM /Óû§/ jeniferaniston1 /¿â
µÄphotobucket [¡£] COM /Óû§/ amandaseyfried1 /¿â
µÄphotobucket [¡£] COM /Óû§/ suwe8 /¿â
µÄphotobucket [¡£] COM /Óû§/ bob7301 /¿â
toknowall [¡£] COM


ÓëµÚ¶þ½×¶ÎÏà¹Ø


91.121.109 [¡£] 209
217.12.202 [¡£] 40
94.242.222 [¡£] 68
82.118.242 [¡£] 124
46.151.209 [¡£] 33
217.79.179 [¡£] 14
91.214.203 [¡£] 144
95.211.198 [¡£] 231
195.154.180 [¡£] 60
5.149.250 [¡£] 54
91.200.13 [¡£] 76
94.185.80 [¡£] 82
62.210.180 [¡£] 229
zuh3vcyskd4gipkm [¡£]Ñó´Ð/ bin32ÖÐ/ update.php


ÒÑÖªµÄÎļþ¹þÏ£

µÚÒ»½×¶Î¶ñÒâÈí¼þ


50ac4fcd3fbc8abcaa766449841b3a0a684b3e217fc40935f1ac22c34c58a9ec
0e0094d9bd396a6594da8e21911a3982cd737b445f591581560d766755097d92


µÚ¶þ½×¶Î¶ñÒâÈí¼þ


9683b04123d7e9fe4c8c26c69b09c2233f7e1440f828837422ce330040782d17
d6097e942dd0fdc1fb28ec1814780e6ecc169ec6d24f9954e71954eedbc4c70e
4b03288e9e44d214426a02327223b5e516b1ea29ce72fa25a2fcef9aa65c4b0b
9eb6c779dbad1b717caa462d8e040852759436ed79cc2172692339bc62432387
37e29b0ea7a9b97597385a12f525e13c3a7d02ba4161a6946f2a7d978cc045b4
776cb9a7a9f5afbaffdd4dbd052c6420030b2c7c3058c1455e0a79df0e6f7a1d
8a20dc9538d639623878a3d3d18d88da8b635ea52e5e2d0c2cce4a8c5a703db1
0649fda8888d701eb2f91e6e0a05a2e2be714f564497c44a3813082ef8ff250b


µÚÈý½×¶Î²å¼þ


f8286e29faa67ec765ae0244862f6b7914fcdde10423f96595cb84ad5cc6b344
afd281639e26a717aead65b1886f98d6d6c258736016023b4e59de30b7348719


×ÔÊðÃûÖ¤ÊéÖ¸ÎÆ

d113ce61ab1e4bfcb32fb3c53bd3cdeee81108d02d3886f6e2286e0b6a006747
c52b3901a26df1680acbfb9e6184b321f0b22dd6c4bb107e5e071553d375c851
f372ebe8277b78d50c5600d0e2af3fe29b1e04b5435a7149f04edd165743c16d
be4715b029cbd3f8e2f37bc525005b2cb9cad977117a26fac94339a721e3f2a5
27af4b890db1a611d0054d5d4a7d9a36c9f52dffeb67a053be9ea03a495a9302
110da84f31e7868ad741bcb0d9f7771a0bb39c44785055e6da0ecc393598adc8
fb47ba27dceea486aab7a0f8ec5674332ca1f6af962a1724df89d658d470348f
b25336c2dd388459dec37fa8d0467cf2ac3c81a272176128338a2c1d7c083c78
cd75d3a70e3218688bdd23a0f618add964603736f7c899265b1d8386b9902526
110da84f31e7868ad741bcb0d9f7771a0bb39c44785055e6da0ecc393598adc8
909cf80d3ef4c52abc95d286df8d218462739889b6be4762a1d2fac1adb2ec2b
044bfa11ea91b5559f7502c3a504b19ee3c555e95907a98508825b4aa56294e4
c0f8bde03df3dec6e43b327378777ebc35d9ea8cfe39628f79f20b1c40c1b412
8f1d0cd5dd6585c3d5d478e18a85e7109c8a88489c46987621e01d21fab5095d
d5dec646c957305d91303a1d7931b30e7fb2f38d54a1102e14fd7a4b9f6e0806
c0f8bde03df3dec6e43b327378777ebc35d9ea8cfe39628f79f20b1c40c1b412


ÒÑÖªÊÜÓ°ÏìµÄ×°±¸

ÒÑÖªÏÂÁÐ×°±¸ÊÜ´ËÍþвµÄÓ°Ïì¡£ Æ¾Ö¤ÕâÏîÑо¿µÄ¹æÄ££¬ÎÒÃǵÄÊÓ²ìÐí¶à¶¼ÊÇÒ£Ô¶µÄ£¬¶ø²»ÊÇÔÚ×°±¸ÉÏ£¬Òò´ËÔÚÐí¶àÇéÐÎϺÜÄÑÈ·¶¨ÏêϸµÄ°æ±¾ºÅºÍÄ£×Ó¡£ Ó¦¸ÃÖ¸³öµÄÊÇ£¬ËùÓÐÕâЩװ±¸¶¼ÓйûÕæµÄÒÑÖªÎó²î¡£

¼øÓÚÎÒÃǶÔÕâÖÖÍþвµÄÊӲ죬ÎÒÃǸ߶È×ÔÐÅµØÆÀ¹À´ËÁÐ±í²»ÍêÕû£¬ÆäËû×°±¸¿ÉÄÜÊܵ½Ó°Ïì¡£


LINKSYS DEVICES£º

E1200
E2500
WRVS4400N


MIKROTIK ROUTEROSÊÊÓÃÓÚÔÆ½¹µã·ÓÉÆ÷µÄ°æ±¾£º

1016
1036
1072


NETGEAR×°±¸£º

DGN2200
R6400
R7000
R8000
WNR1000
WNR2000


ÍþÁªÍ¨×°±¸£º

TS251
TS439 Pro


ÆäËûÔËÐÐQTSÈí¼þµÄQNAP NAS×°±¸


TP-LINK×°±¸£º

R600VPN


VPNFILTERÌØ¶¨µÄSNORT¼ì²â£º

45563 45564 46782 46783


SNORT¹æÔò¿É±ÜÃâÊÜѬȾװ±¸ÖеÄÒÑÖªÎó²î£º

25589 26276 26277 26278 26279 29830 29831 44743 46080 46081 46082 46083 46084 46085 46086 46287 46121 46122 46123 46124 41445 44971 46297 46298 46299 46300 46301 46305 46306 46307 46308 46309 46310 46315 46335 46340 46311 46342 46376 46377 37963 45555 46076 40063 44643 44790 26275 35734 41095 41096 41504 41698 41699 41700 41748 41749 41750 41751 44687 44688 44698 44699 45001 46312 46313 46314 46317 46318 46322 46323 40866 40907 45157


CLAMAVÊðÃû£º

Unix.Trojan.Vpnfilter-6425811-0
Unix.Trojan.Vpnfilter-6425812-0
Unix.Trojan.Vpnfilter-6550590-0
Unix.Trojan.Vpnfilter-6550591-0
Unix.Trojan.Vpnfilter-6550592-0


Éù Ã÷

±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾­¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£


¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼

±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£

»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£

±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊÐÉúÒ⣬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£


 


?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼