AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¸Íþвͨ¸æ¡¹Vollgar½©Ê¬ÍøÂç

2020-04-01

 

Ò»¡¢Íþв¸ÅÊö

4ÔÂ1ÈÕ £¬Guardicore LabsÍŶÓÐû²¼ÁËÒ»·Ýºã¾Ã¹¥»÷Ô˶¯µÄÆÊÎö±¨¸æ £¬´Ë¹¥»÷Ô˶¯Ö÷ÒªÕë¶ÔÔËÐÐMS-SQL·þÎñµÄWindowsϵͳ¡£ÆÊÎö±¨¸æ³Æ £¬´Ë¹¥»÷Ô˶¯ÖÁÉÙ´Ó2018Äê5ÔÂ×îÏÈ £¬¹¥»÷Õß»áÕë¶ÔÄ¿µÄµÄMS-SQL¾ÙÐб©Á¦²Â½â £¬ÀֳɵǼĿµÄϵͳºó £¬ÔÙÔÚϵͳÖа²ÅźóÃŲ¢ÔËÐÐÔ¶¿Ø¹¤¾ßµÈ¶ñÒâ³ÌÐò¡£ÕâһϵÁеĹ¥»÷Ô˶¯±»ÃüÃûΪ“Vollgar”¡£

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

ͨ¹ý±©Á¦ÆÆ½âÕË»§Éϰ¶ÏµÍ³ÔÙÖ²Èë¶ñÒâ³ÌÐòÊÇÒ»ÖÖÊ®·ÖÆÕ±éµÄ¹¥»÷ÊÖ·¨ £¬µ«±¨¸æÖгÆ £¬ÌìÌìÈÔÓÐ2-3ǧ¸öÊý¾Ý¿âÔÚVollgar¹¥»÷Ô˶¯Öб»¹¥ÏÝ £¬ÆäÖаüÀ¨Öйú¡¢Ó¡¶È¡¢º«¹ú¡¢ÍÁ¶úÆäºÍÃÀ¹úµÈ¹ú¼Ò £¬ÊÜÓ°ÏìµÄÐÐÒµº­¸ÇÒ½ÁÆ¡¢º½¿Õ¡¢IT¡¢µçÐÅ¡¢½ÌÓýµÈ¶à¸öÁìÓò¡£

²Î¿¼Á´½Ó£º

https://www.guardicore.com/2020/04/vollgar-ms-sql-servers-under-attack/

¶þ¡¢Ó°Ïì¹æÄ£

±£´æMS-SQLÈõ¿ÚÁîµÄWindowsϵͳ

Èý¡¢Î£º¦ÅŲé

3.1 detect_vollgar.ps1¾ç±¾×Ô²é

Guardicore LabsÌṩÁËPowerShell×Ô²é¾ç±¾Script – detect_vollgar.ps1 £¬×Ô²é¾ç±¾detect_vollgar.ps1¿ÉʵÏÖÍâµØ¹¥»÷ºÛ¼£¼ì²â £¬¼ì²âÄÚÈÝÈçÏ£º

  1. ÎļþϵͳÖеĶñÒâpayload £»
  2. ¶ñÒâ·þÎñÀú³ÌʹÃüÃû £»
  3. ºóÃÅÓû§Ãû¡£

¾ç±¾ÏÂÔØÁ´½Ó£º

https://github.com/guardicore/labs_campaigns/tree/master/Vollgar

¼ì²â°ì·¨£º

1¡¢ÏÂÔØ×Ô²é¾ç±¾detect_vollgar.ps1ÖÁÍâµØ £¬¾ç±¾ÄÚÈÝÏê¿´·¨Ö·https://github.com/guardicore/labs_campaigns/blob/master/Vollgar/detect_vollgar.ps1

2¡¢“Windows”+“R” £¬ÔÚµ¯³öµÄÔËÐнçÃæËÑË÷PowerShell¡£

3¡¢ÔËÐо籾¡£ÈôÊÇ»ØÏÔÖаüÀ¨“Evidence for Vollgar campaign has been found on this host.”×ÖÑù £¬Ôò˵Ã÷Ä¿½ñϵͳ¿ÉÄÜÒѱ»Ñ¬È¾¡£

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

Èô±£´æÑ¬È¾ÇéÐÎ £¬Çë²Î¿¼ÏÂÁÐÒªÁì¾ÙÐд¦Öóͷ££º

  1. ÒÆ³ý̽²â×Ô²éЧ¹ûÖеĹ¥»÷ºÛ¼£¡£
  2. ÖÕÖ¹¶ñÒâ³ÌÐò

×¢£ºÈô·ºÆðÖ±½ÓÔËÐÐPowerShellʱÌáÐÑ“ÎÞ·¨¼ÓÔØÎļþps1 £¬ÓÉÓÚÔÚ´ËϵͳÖÐեȡִÐо籾¡£ÓйØÏêϸÐÅÏ¢ £¬Çë²ÎÔÄ “get-help about_signing”¡£´ËÌáÐÑÊÇÓÉÓÚûÓÐȨÏÞÖ´Ðиþ籾¡£¿ÉÔËÐÐÈçÏÂÏÂÁîÉó²éÄ¿½ñÖ´ÐÐÕ½ÂÔ£º

ÈôÊÇÏÔʾ“Restricted”ÔòΪ²»ÔÊÐíÖ´ÐÐÈκξ籾¡£

ͨ¹ýÔËÐÐÒÔÏÂÏÂÁî¿ÉÐÞ¸ÄÆäÕ½ÂÔ£º

ÐÞ¸ÄÀֳɺ󼴿ÉʹÓÃPowerShellÖ´Ðо籾

ÈçÐè×÷·Ï¶ÔÆäÕ½ÂÔµÄÐÞ¸Ä £¬¿Éͨ¹ýÔËÐÐÒÔÏÂÏÂÁî¾ÙÐлָ´¡£

3.2 ͨÀý·À»¤½¨Òé

  1. ¹Ø±ÕÊý¾Ý¿âÕ˺ŵǼ·½·¨  ÒÔwindowsÉí·ÝÑéÖ¤·½·¨µÇ¼Êý¾Ý¿â  ²¢ÔÚwindowsÕ½ÂÔÀïÉèÖÃÃÜÂëÇ¿¶È¡£
  2. ÔöÇ¿ÍøÂç½çÏßÈëÇÖÌá·ÀºÍÖÎÀí £¬ÔÚÍøÂçÊÕÖ§¿ÚÉèÖ÷À»ðǽµÈÍøÂçÇå¾²×°±¸ £¬¶Ô²»ÐëÒªµÄͨѶÓèÒÔ×è¶Ï¡£
  3. ¶Ô̻¶ÔÚ»¥ÁªÍøÉϵÄÍøÂç×°±¸¡¢·þÎñÆ÷¡¢²Ù×÷ϵͳºÍÓ¦ÓÃϵͳ¾ÙÐÐÇå¾²ÅŲé £¬°üÀ¨µ«²»ÏÞÎó²îɨÃ衢ľÂí¼à²â¡¢ÉèÖú˲顢WEBÎó²î¼ì²â¡¢ÍøÕ¾ÉøÍ¸²âÊԵȡ£
  4. ÔöÇ¿Çå¾²ÖÎÀí £¬½¨ÉèÍøÂçÇå¾²Ó¦¼±´¦Öóͷ£»úÖÆ £¬ÆôÓÃÍøÂçºÍÔËÐÐÈÕÖ¾Éó¼Æ £¬°²ÅÅÍøÂçÖµÊØ £¬×öºÃ¼à²â²½·¥ £¬ÊµÊ±·¢Ã÷¹¥»÷Σº¦ £¬ÊµÊ±´¦Öóͷ£¡£
?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼ £¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼