Ò»¼ü»¹Ô¹¥»÷ÏÖ³¡£¬£¬£¬£¬£¬£¬¿´XDRÔõÑùÖǶ·ÀÕË÷
Ðû²¼Ê±¼ä 2024-07-26ǰÑÔ£º
ÀÕË÷Èí¼þ¹¥»÷ÒѳÉΪÆóÒµÃæÁÙµÄÖ÷ÒªÍøÂçÇå¾²Íþв֮һ£¬£¬£¬£¬£¬£¬Æä¸ßÒþ²ØÐÔ¡¢¸ßÆÆËðÐÔºÍÀÕË÷ÐÔ£¬£¬£¬£¬£¬£¬¸øÊܺ¦Õß´øÀ´ÁËÖØ´óËðʧ¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬Ëæ×ÅÊÖÒÕµÄһֱǰ½ø£¬£¬£¬£¬£¬£¬À©Õ¹¼ì²âÓëÏìÓ¦£¨XDR£©ÏµÍ³Õý³ÉΪµÖÓù´ËÀ๥»÷µÄǿʢÎäÆ÷¡£¡£¡£±¾ÎĽ«Í¨¹ýÏÖʵ°¸Àý£¬£¬£¬£¬£¬£¬Õ¹Ê¾XDRÔõÑù¾«×¼»¹ÔÀÕË÷¹¥»÷ÏÖ³¡£¬£¬£¬£¬£¬£¬ÎªÇå¾²ÔËÓªÖ°Ô±ÌṩÓÐÁ¦Ö§³Ö¡£¡£¡£
2024Äê5Ô£¬£¬£¬£¬£¬£¬Ä³¿Í»§ÏÖ³¡×°ÖõÄEDRͻȻ·¢³öÎļþ±»Òì³£¸Ä¶¯µÄÀÕË÷ÐÐΪ¸æ¾¯£¬£¬£¬£¬£¬£¬Í¬Ê±NDRºÍɳÏäÒ²±¬·¢Á˶à´Î¶ñÒâÐÐΪ¸æ¾¯£¬£¬£¬£¬£¬£¬ÕâÒýÆðÁËÇå¾²ÔËÓªÖ°Ô±µÄÇ×½ü×¢ÖØ¡£¡£¡£
¹¥»÷ÕßÊÇÔõÑù½øÈëÄÚÍøµÄ£¿£¿£¿£¿£¿£¿¶¼ÓÐÄÄЩ×ʲúÊܵ½Ó°Ï죿£¿£¿£¿£¿£¿¸ÃÔõÑùÕûÀí±»¹¥»÷ÕßѬȾ¹ýµÄÖ÷»ú£¿£¿£¿£¿£¿£¿ÃæÁÙÕâÒ»½ôÆÈÇéÐΣ¬£¬£¬£¬£¬£¬ÕâÈý´óÎÊÌâ³ÉΪÁ˿ͻ§Ø½´ýÏàʶµÄ½¹µã¡£¡£¡£
ÒÔÍù½â¾öÕâЩÎÊÌ⣬£¬£¬£¬£¬£¬ÐèҪרҵµÄÑо¿Ö°Ô±¾ÙÐÐÆÊÎöËÝÔ´£¬£¬£¬£¬£¬£¬¿ÉÊDZ¾´Î¹¥»÷Éæ¼°µ½µÄÖ÷»úÖڶ࣬£¬£¬£¬£¬£¬¹¥»÷ÕßÓÖʹÓÃÁ˶àÖÖ¹¥»÷ÊÖ·¨¡£¡£¡£¿£¿£¿£¿£¿£¿´µ½ÕâÃÜÃÜÂéÂéµÄ¸æ¾¯ÊÂÎñºÍ¹ØÁªIP£¬£¬£¬£¬£¬£¬×ÝʹÉí¾°ÙÕ½µÄÑÐÅÐÖ°Ô±Ò²²»½ûÌ¾Æø¡£¡£¡£
µ«ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬£¬£¬ÓÉÓÚ¿Í»§ÏÖ³¡°²ÅÅÁËÌìãÙXDRϵͳ£¬£¬£¬£¬£¬£¬Çå¾²ÔËÓªÖ°Ô±¿ÉÒÔʹÓÃÌìãÙXDRǿʢµÄ¹ÊÊÂÏß»¹Ô¹¦Ð§£¬£¬£¬£¬£¬£¬Í¨¹ýÆä¾ÛºÏ²¢½µÔëÀ´×Ô²î±ðÇå¾²¹¤¾ßµÄ¸æ¾¯ÐÅÏ¢£¬£¬£¬£¬£¬£¬Í¬Ê±Ê¹ÓÃÆä×Ô¶¯»¯È¡Ö¤ÊÖÒÕ£¬£¬£¬£¬£¬£¬»¹Ô³ö¹¥»÷µÄʱ¼äÏߺ͹ÊÊÂÏß¡£¡£¡£

ÈçÉÏͼËùչʾ£¬£¬£¬£¬£¬£¬ÌìãÙXDRµÄÖÇÄܾۺÏÄÜÁ¦£¬£¬£¬£¬£¬£¬¿É½«ÖÚ¶àÊÂÎñ¾ÛºÏ³ÉΪҪº¦¹¥»÷½Úµã£¬£¬£¬£¬£¬£¬²¢Æ¾Ö¤¹ÊÊÂÏß¾ÙÐÐÅÅÁУ¬£¬£¬£¬£¬£¬Ê¹¹ÊÊÂÏßһĿÁËÈ»¡£¡£¡£
´ËǰÔÚ¡¶¿´ÌìãÙAIÖÇÄÜÌåÔõÑù¸³ÄÜXDRʵÏָ߽×ÖÇÄܼÝÊ»¡·Ò»ÎÄÖУ¬£¬£¬£¬£¬£¬ÎÒÃÇÒÑÏÈÈÝ£¬£¬£¬£¬£¬£¬Z6×ðÁú¿Ê±XDRʵÏÖÁËÌìãÙAIÖÇÄÜÌåµÄ¸³ÄÜ£¬£¬£¬£¬£¬£¬¿ÉÒÔ¶ÔÖÖÖÖ¼ì²âµ¥Î»¾ÙÐÐÖÇÄܵ÷Àí£¬£¬£¬£¬£¬£¬ÊµÏÖÖÇÄܸ澯ÆÊÎö¡¢×Ô¶¯ÉúÉíÆÊÎö±¨¸æ¡£¡£¡£ÔÚ±¾´Î¹¥»÷ÊÂÎñ»ØÊ×ÖУ¬£¬£¬£¬£¬£¬ÎÒÃÇÒ²½ÓÄÉÁËÌìãÙAIÖÇÄÜÌå¾ÙÐмòÆÓ×ܽᣬ£¬£¬£¬£¬£¬ÄÚÈݰüÀ¨ÊÜÓ°ÏìµÄÖ÷»úºÍÓû§¡¢¶ñÒâÎļþÒÔ¼°ÍâÁªC2µØµãµÈÒªº¦ÐÅÏ¢¡£¡£¡£
´Ó¹ÊÊÂÏßÖпÉÒÔ¿´µ½£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ5ÔÂ23ÈÕ14:21·Öͨ¹ý±©Á¦ÆÆ½âʹÓÃsaÓû§µÇ¼MSSQLЧÀÍÆ÷¡£¡£¡£Ëæºóͨ¹ýMSSQLÖеÄxp_cmdshellÀ´Ö´ÐÐPowershellÏÂÔØÏÂÁ£¬£¬£¬£¬£¬ÊµÑ齫¶ñÒâÎļþÂ䵨²¢Ö´ÐС£¡£¡£½ô½Ó×Å£¬£¬£¬£¬£¬£¬¹¥»÷Õß×îÏÈʵÑé¾ÙÐкáÏòÒÆ¶¯£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÁ˲î±ðµÄÊÖ·¨¾ÙÐÐÈö²¥¡£¡£¡£ÏêϸÈçÏ£º
1¡¢15:07£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʵÑéʹÓÃSMBÐÒ齫¶ñÒâÎļþͶµÝµ½ÆäËûÖ÷»úÉÏ£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýµã»÷¡°SMB²Ù×÷-Îļþ¸´ÖÆ¡±½ÚµãÀ´Éó²éSMB´«ÊäµÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬Í¬Ê±XDRµÄɳÏäÁª¶¯¹¦Ð§Ò²»á½«¶ÔÓ¦Ñù±¾µÄÔËÐÐЧ¹ûչʾÔÚÏ·½¡£¡£¡£

2¡¢15:11£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʵÑéͨ¹ýimpacket¹¤¾ßÖеÄsmbexec¾ç±¾ÔÚÊܺ¦ÕßÖ÷»úÉÏÖ´ÐÐÏÂÁ£¬£¬£¬£¬£¬µã»÷¶ÔÓ¦µÄ¡°ÏÂÁîÖ´ÐС±½Úµã£¬£¬£¬£¬£¬£¬¿ÉÉó²éµ½¹¥»÷ÕßÖ´ÐеÄÿÌõÖ¸Áî¡£¡£¡£

ͨ¹ýÖ´ÐÐÏêÇéºÍÀú³ÌÊ÷£¬£¬£¬£¬£¬£¬¿ÉÒÔÅжϹ¥»÷ÕßʵÑéʹÓÃDESKTOP-EVWZQ36/adminµÄÓû§Æ¾Ö¤£¬£¬£¬£¬£¬£¬Í¨¹ýÔ¶³ÌЧÀÍÀ´Ö´ÐÐÏÂÁî¡£¡£¡£ÔÀíΪʹÓÃecho½«ÏÂÁîдÈë%SYSTEMROOT%Îļþ¼ÐÏÂËæ»úÃû³ÆµÄbatÖУ¬£¬£¬£¬£¬£¬ËæºóÖ´Ðв¢É¾³ý¡£¡£¡£
3¡¢17:52£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÄÚÍøÊ¹ÓÃÓÀºãϵÁÐÎó²îѬȾ¸ü¶àµÄÖ÷»ú£¬£¬£¬£¬£¬£¬²¢ÊµÑéÖ²ÈëºóÃÅ¡£¡£¡£XDRµÄ×Ô¶¯»¯È¡Ö¤¹¦Ð§Í¨¹ý½«ÓÀºãÖ®À¶µÄshellcodeÉÏ´«µ½É³ÏäÖУ¬£¬£¬£¬£¬£¬×îÖÕʶ±ðµ½¹¥»÷ÕßʵÑéÖ²ÈëCobaltStrike¡£¡£¡£

×îºó£¬£¬£¬£¬£¬£¬Ê¹ÓÃÌìãÙXDRµÄÁª¶¯ÏìÓ¦¹¦Ð§£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Ñ¸ËÙ´¦Öóͷ£ÁËËùÓÐÖ÷»úÏà¹ØÎ£º¦Ïî²¢½«C2¼ÓÈëÁË·À»ðǽºÚÃûµ¥£¬£¬£¬£¬£¬£¬¿Í»§×îÌåÌùµÄÈý¸öÎÊÌâÒ²¶¼ÓÈжø½â¡£¡£¡£
±¾°¸Àý³ä·ÖչʾÁËÌìãÙXDRÔÚÓ¦¶ÔÀÕË÷Èí¼þ¹¥»÷ÖеÄÖ÷Òª×÷Óᣡ£¡£Í¨¹ý¹¥»÷ÐÐΪ×Ô¶¯»¯È¡Ö¤¡¢É³ÏäÁª¶¯ÒÔ¼°¹ÊÊÂÏß»¹Ô¡¢Ê±¼äÏß»¹ÔµÈ¹¦Ð§£¬£¬£¬£¬£¬£¬ÌìãÙXDR²»µ«¼ò»¯ÁËÇå¾²ÆÊÎöÖ°Ô±µÄÊÂÇéÁ÷³Ì£¬£¬£¬£¬£¬£¬»¹Ìá¸ßÁËÓ¦¶ÔÍøÂçÍþвµÄЧÂʺÍ׼ȷÐÔ£¬£¬£¬£¬£¬£¬Èù¥»÷ÐÐΪÎÞËù¶ÝÐΡ£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ