Ò»³¡Ëµ×ß¾Í×ߵġ°Ó¦¼±¡±Ðж¯¡ª¡ªÄ³Ê¯»¯¹«Ë¾ÔâÍڿ󲡶¾Ñ¬È¾ºóµÄ48Сʱ

Ðû²¼Ê±¼ä 2019-05-23
5ÔÂ10ÈÕ22:00


¡°µÎÁåÁåÁå~~~¡±¿­Ê±K66¹¤Òµ»¥ÁªÍøÊÂÒµ²¿¹¤³ÌʦµÄµç»°ÏìÆð£¡

¡°ÎÒÃÇÁ½Ì׺áºÓDCSϵͳµÄ²Ù×÷Ô±Õ¾¡¢¹¤³ÌʦվºÍOPCЧÀÍÆ÷µÄÖ÷»úͻȻÀ¶ÆÁ£¡ÖØÐÂÆô¶¯ÏµÍ³ºó £¬£¬£¬£¬£¬£¬ÈÔÈ»ÎÞ·¨»Ö¸´ £¬£¬£¬£¬£¬£¬×·Çó½ôÆÈÊÖÒÕÔ®Öú£¡¡±

À´×Ôijʯ»¯¹«Ë¾Òǿز¿µÄÊÂÇéÖ°Ô±µç»°ÀïµÄÉùÒôÒì³£¼±´Ù¡­¡­

½â¾ö¿Í»§µÄÍøÂçÇå¾²ÎÊÌâ £¬£¬£¬£¬£¬£¬¾ÍÊÇ¿­Ê±K66ʹÃü£¡

¿­Ê±K66¹¤Òµ»¥ÁªÍøÇå¾²ÊÂÒµ²¿ÁªºÏ¿­Ê±K66¼¯ÍÅÆìϳ½ÐÅÁì´´¹«Ë¾Á¬Ã¦×齨5ÈËרÏîС×é £¬£¬£¬£¬£¬£¬ÓªÒµ¡¢ÊÖÒÕ¡¢²úÆ·ÏßְԱѸËÙ¿ªÆô¾ÈÔ®Ðж¯ £¬£¬£¬£¬£¬£¬Ô¶³ÌÖ¸µ¼¿Í»§¾ÙÐÐϵͳ¾ÈÔ®¼°±£»£»£»¤ÏÖ³¡²¡¶¾Ñù±¾Êý¾Ý¡£¡£¡£


5ÔÂ11ÈÕÆÆÏþ1:00


¾ÈÔ®ÊÂÇéÕù·Ö¶àÃë £¬£¬£¬£¬£¬£¬Àú¾­3¸öСʱµÄÔ¶³ÌÖ§³Öºó £¬£¬£¬£¬£¬£¬»ù±¾È·¶¨ÊÂÎñÔ­ÓÉÓÚMsraMiner²¡¶¾Ñ¬È¾¡£¡£¡£

Ô¶³ÌÖ§³ÖÒ»Á¬¾ÙÐÐ £¬£¬£¬£¬£¬£¬µ«ÏÖ³¡ÇéÐνÏÁ¿ÌØÊâ £¬£¬£¬£¬£¬£¬Ë¼Á¿µ½¹¤¿ØÏµÍ³µÄÖØ´óÐÔ¼°DCSϵͳµÄרҵÐÔ £¬£¬£¬£¬£¬£¬Ó¦¼±ÍŶӾöÒé³Ë×øµ±ÈÕ×îÔ纽°à·ÉÍù¿Í»§ÏÖ³¡¡£¡£¡£


5ÔÂ11ÈÕÔç6:40


Í×Í×µØÒ»³¡Ëµ×ß¾Í×ßµÄÓ¦¼±Ð§ÀÍ¡£¡£¡£
 
¾­ÓÉ48СʱµÄ²»Ð¸Æð¾¢ £¬£¬£¬£¬£¬£¬ÏµÍ³»ñµÃÁËÐÞ¸´ £¬£¬£¬£¬£¬£¬¿Í»§µÄÉú²úÍêÈ«»Ö¸´ÁËÕý³£¡£¡£¡£¿£¿£¿£¿Í»§¸øÓ¦¼±ÍŶӷ¢À´ÁËÕæ³ÏµÄллÐÅ £¬£¬£¬£¬£¬£¬²¢Ô¼ÇëÉÌÌÖºóÆÚµÄ¼Ó¹Ì²½·¥ÓëÏàÖú¡£¡£¡£
 
¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 


ÊÂÎñÆÊÎö


ƾ֤¶ÔÉó²éÏÖ³¡ÇéÐÎÒÔ¼°ÏµÍ³ÖÐÊý¾ÝÆÊÎö £¬£¬£¬£¬£¬£¬ÍøÂçÖеÄÖ÷»úÈ·ÒÔΪMsraMinerÍڿ󲡶¾µÄ±äÖÖ²¡¶¾Ñ¬È¾ £¬£¬£¬£¬£¬£¬´ËÍڿ󲡶¾Ê¹Óá°ÓÀºãÖ®À¶¡±Îó²î¾ÙÐÐÈö²¥ £¬£¬£¬£¬£¬£¬ÔÚÈö²¥Àú³ÌÖÐ £¬£¬£¬£¬£¬£¬ÓÉÓÚÔÚWindows XPϵͳÉÏÎó²îʹÓÃʧ°Ü £¬£¬£¬£¬£¬£¬µ¼Ö»úеÀ¶ÆÁ¡£¡£¡£Æä²¡¶¾ÆÆËðÔ­ÀíΪ£º

Íڿ󲡶¾MsraMine×îбäÖֵIJ¡¶¾Ä¸ÌåÔËÐкóÊÍ·ÅЧÀÍÄ£¿£¿£¿£¿é £¬£¬£¬£¬£¬£¬ÊͷŵÄЧÀÍÄ£¿£¿£¿£¿éÃû³ÆËæ»úÆ´¼¯ £¬£¬£¬£¬£¬£¬ÌìÉúXXX.dll £¬£¬£¬£¬£¬£¬Ð§ÀÍÃû³ÆºÍÊͷŵÄЧÀÍdllÎļþÃû³ÆÏàͬ¡£¡£¡£
 
¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 ²¡¶¾Ð§ÀÍÃû×Ö»áÆ¾Ö¤ÌìÉúµÄdllÃû×ÖÃüÃû £¬£¬£¬£¬£¬£¬¿ÉÊÇÆäÐÎòһÑùƽ³£¶¼ÎªEnable a commin infterace and object xxxx²¡¶¾Îļþ £¬£¬£¬£¬£¬£¬²¢½«¹¥»÷C:\Windows\NetworkDistribution Ŀ¼ÏÂËùÓÐÎļþ£¨¹¥»÷µÄÖ÷ÒªÎļþ£© £¬£¬£¬£¬£¬£¬Ö÷ÍÚ¿óÎļþC:\Windows\system32\dllhostex.exe£¨»òÆäËû±»×¢ÈëµÄsvchostµÄ×ÓÀú³Ì£©¡£¡£¡£
 
ÁíÍâÌØÑ¡ÔñÆäÖÐÒ»¸öIPÉó²éÆäËùÓлỰ £¬£¬£¬£¬£¬£¬²¢¶ÔÆäÅþÁ¬¶Ë¿Ú¾ÙÐÐͳ¼Æ £¬£¬£¬£¬£¬£¬³ý445¶Ë¿ÚÍâ £¬£¬£¬£¬£¬£¬26931¡¢45560¶Ë¿ÚÅþÁ¬Á¿Õ¼±ÈÒ²Ï൱¿É¹Û £¬£¬£¬£¬£¬£¬²¢ÇҸö˿ڲ»ÊôÓÚÕý³£ÓªÒµËùÐè¶Ë¿Ú¡£¡£¡£Ëæ¼´¶Ô¸ÃÖ÷»úµÄÍâµØÎļþÓëÀú³Ì¾ÙÐÐÊÓ²ìºÍÆÊÎö £¬£¬£¬£¬£¬£¬·¢Ã÷´ó×Ú¶ñÒâÎļþ¡£¡£¡£ ¾­Ì«¹ýÎöÅÐ¶Ï £¬£¬£¬£¬£¬£¬26931¡¢45560Á½¸ö¶Ë¿Ú»®·ÖΪWebserver¶Ë¿ÚºÍ¿ó³ØÅþÁ¬¶Ë¿Ú¡£¡£¡£ÆäÖÐWebserverÌṩÏìÓ¦×é¼þÏÂÔØ £¬£¬£¬£¬£¬£¬ÍÚ¿óÀú³ÌΪ¡°TrustedHostServices.exe¡±¡£¡£¡£
 
²¡¶¾µÄѬȾÁ÷³ÌΪ£ºÊܺ¦Ö÷»úij¹¤³ÌʦվÖеIJ¡¶¾³ÌÐò°üÀ¨Á½²¿·Ö £¬£¬£¬£¬£¬£¬»®·ÖΪ¹¥»÷³ÌÐòÒÔ¼°¡°ÍÚ¿ó¡±³ÌÐò¡£¡£¡£ÆäÖй¥»÷³ÌÐò»áÊͷųö¡°ÓÀºãÖ®À¶¡±³ÌÐò £¬£¬£¬£¬£¬£¬Í¬Ê±´î½¨webЧÀÍÆ÷ £¬£¬£¬£¬£¬£¬Í¨¹ý¿­Ê±K66µÄTSOC-NBA¿ÉÒÔ·¢Ã÷Êܺ¦Ö÷»ú¹¤³ÌʦվÏòÊܺ¦Ö÷»ú²Ù×÷Ô±Õ¾ÒÔ¼°OPCЧÀ͵Ä445¶Ë¿ÚÌᳫ¹¥»÷ £¬£¬£¬£¬£¬£¬±»Ñ¬È¾²¡¶¾µÄÖ÷»úÏòÊܺ¦Ö÷»úµÄwebЧÀÍÆ÷26931¶Ë¿ÚÌᳫÏÂÔØÇëÇó £¬£¬£¬£¬£¬£¬

ÇëÇóÄÚÈÝΪMsraReportDataCache32.tlb £¬£¬£¬£¬£¬£¬¸Ã³ÌÐò»áÊͷųö¹¥»÷³ÌÐòÒÔ¼°¡°ÍÚ¿ó¡±³ÌÐò£»£»£»Í¬Ê± £¬£¬£¬£¬£¬£¬ÍÚ¿óÀú³ÌTrusted Host Services . exe¾ÙÐÐÍÚ¿ó £¬£¬£¬£¬£¬£¬Óë¿ó³Øxmr.pool. minergate . com: 45560 ½¨ÉèÅþÁ¬ £¬£¬£¬£¬£¬£¬³ÌÐòÔËÐÐʱ´ú»á»á¼ûÏìÓ¦µÄdomainÒÔ¾ÙÐгÌÐò¸üÐÂÓë¿ó³ØÅþÁ¬ £¬£¬£¬£¬£¬£¬ÔÚÅþÁ¬Ê§°Üºóµ¼ÖÂϵͳÀ¶ÆÁ¡£¡£¡£


½â¾ö¼Æ»®


1¡¢Ó¦¼±´¦Öóͷ££ºÊÖ¹¤É¨³ý



1) ×°Öÿ­Ê±K66רÓС°ÓÀºãÖ®À¶¡±²¹¶¡»òʹÓø½¼þÖеÄÈȲ¹¶¡¹¤¾ß£»£»£»
2) ¹Ø±Õ445 £¬£¬£¬£¬£¬£¬139 £¬£¬£¬£¬£¬£¬135¡¢3389µÈ¶Ë¿ÚЧÀÍ£»£»£»
3) ɾ³ýÐÎòΪEnable a commin infterace and object xxxxµÄЧÀÍ£»£»£»
4) ɾ³ý´ËЧÀͶÔÓ¦µÄ¶¯Ì¬Á´½Ó¿âÎļþ£»£»£»
5) ¿¢ÊÂsvchost.exeÀú³Ì£¨TaskIndexer.exe»òdllhostex.exeÀú³ÌµÄ¸¸Àú³Ì£©£»£»£»
6) ¿¢ÊÂTaskIndexer.exe»òdllhostex.exeÀú³Ì £¬£¬£¬£¬£¬£¬²¢É¾³ýÆäÎļþ£»£»£»
7) ɾ³ýC:\Windows\NetworkDistributionĿ¼ÏÂËùÓÐÎļþ£»£»£»
8) ×°ÖÃɱ¶¾Èí¼þ¼á³Ö·ÀÓù¿ªÆô £¬£¬£¬£¬£¬£¬ÊµÊ±Éý¼¶²¡¶¾¿â¡£¡£¡£
 
ÊÖ¶¯×°Öá°ÓÀºãÖ®À¶¡±Îó²î²¹¶¡Çë»á¼ûÒÔÏÂÒ³Ãæ£º
https://technet.microsoft.com/zh-cn/library/security/ms17-010.aspx
http://www.catalog.update.microsoft.com/search.aspx?q=kb4012212

ÆäÖÐWinXP £¬£¬£¬£¬£¬£¬Windows Server 2003Óû§Çë»á¼û£º
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4012598

²¿·Ö¹¤¾ß£º
¿­Ê±K66µÄÓÀºãÖ®À¶ÈÈÐÞ¸´¹¤¾ß
¿­Ê±K66PChunter¶ñÒâÈí¼þÊÖ¹¤¼ì²â¹¤¾ß


2¡¢¹¤¿ØÏµÍ³×¨Òµ²éɱ¹¤¾ß


¹¤Òµ¿ØÖÆÏµÍ³ÔÚ·À²¡¶¾½¨ÉèÉÏÆÕ±é±£´æ£º×°±¸ÐÔÄܯձ鯫µÍ¡¢windowsÀϰ汾²Ù×÷ϵͳ¾Ó¶à¡¢Ó²¼þ»òÓªÒµÈí¼þÔÚʵÑé·À²¡¶¾ºó²»µÃÊÜÈκÎÓ°Ïì¡¢·À²¡¶¾Èí¼þ±ØÐèÄܹ»ÓÐÓ÷ÀÓù²¡¶¾µÈÎÊÌâ £¬£¬£¬£¬£¬£¬¿­Ê±K66Ϊ֪×㹤¿ØÐÐÒµ·À²¡¶¾ÐèÇó £¬£¬£¬£¬£¬£¬Ñз¢³ö¾°ÔÆÇå¾²ÄÜÁ¦ÇáÁ¿»¯¹¤¿Ø·À»¤°æ¡£¡£¡£½ÓÄÉÈ«³ÌÎÞÇý¶¯ÎÞhook¡¢Ö»É¨²»É±ÒÔ¼°Àú³Ì/ÍøÂç°×Ãûµ¥µÈÇкϹ¤¿ØÇéÐεĻúÖÆ £¬£¬£¬£¬£¬£¬×ÊÖú¹¤¿ØÆóÒµÔÚ·ÀÓùÖÖÖÖÐÂÐͲ¡¶¾ºÍÈ䳿µÄ¹¥»÷µÄͬʱ £¬£¬£¬£¬£¬£¬Äܹ»¼æ¹Ë¹¤¿Ø×°±¸µÄÎȹÌÔËÐÐ £¬£¬£¬£¬£¬£¬°ü¹ÜÓû§ÓªÒµ¡£¡£¡£

1) ¼¯ÖйܿأºÍ¨¹ý¾°ÔƼ¶ÁªÖÐ¿ØÆ½Ì¨ £¬£¬£¬£¬£¬£¬Ìṩ¿ÉÉìËõµÄ¿çƽ̨²¡¶¾·À»¤ £¬£¬£¬£¬£¬£¬¼¯Öйܿظ÷¼¶ÖÖÖÖ·ºÖÕ¶Ë £¬£¬£¬£¬£¬£¬Öª×ãÆóÒµ¼¶Óû§¶Ô·À²¡¶¾Èí¼þͳһÖÎÀíµÄÐèÇ󡣡£¡£

2) º£Á¿ÔƲ飺¿ÉΪÓû§°´Ðè¶¨ÖÆÔÆÖªÊ¶¿â £¬£¬£¬£¬£¬£¬ÖÇÄÜ×ÔÔËÓªÔÆ¶Ë²¡¶¾ÌØÕ÷ £¬£¬£¬£¬£¬£¬Ê¹Óû§ÔÚÓµÓеÈͬÓÚ¹«ÓÐÔÆµÄ²¡¶¾²éɱÄÜÁ¦µÄͬʱ £¬£¬£¬£¬£¬£¬ÓÖͨ¹ý˽Óл¯µÄ·½·¨³¹µ×¶Å¾øÊý¾Ýй¶¡£¡£¡£

3) ÖÇÄܼø¶¾£º½«»úеѧϰºÍ´óÊý¾ÝÒªÁìÈÚÈëµ½·À²¡¶¾ÏµÍ³ÖÐ £¬£¬£¬£¬£¬£¬Äܹ»Îª´óÐÍÓû§ÊµÏÖ×Ô¶¯µÄÑù±¾²¶»ñ¡¢ÑùÌìÖ°Àà¡¢Ñù±¾ÌØÕ÷ÌáÈ¡¡¢²¡¶¾¿â¸üÐÂÁ÷³Ì £¬£¬£¬£¬£¬£¬ÒÔ±ãÄܹ»¿ìËÙÏìÓ¦»¥ÁªÍø²ã³ö²»ÇîµÄÅÌËã»ú²¡¶¾¡£¡£¡£

4) ǿЧÐÔÄÜ£ºÔÚ½µµÍÓû§ÖÕ¶Ë×ÊÔ´ÏûºÄͬʱ £¬£¬£¬£¬£¬£¬Á¬ÏµÈ˹¤ÖÇÄܺʹóÊý¾ÝÊÖÒÕ £¬£¬£¬£¬£¬£¬ÄÜʹ²¡¶¾²éɱ¸üѸËÙ¡¢¸ü¾«×¼¡£¡£¡£Äܹ»ÓÐÓ÷ÀÓù×îÊ¢ÐеIJ¡¶¾Ä¾Âí¡¢ºÚ¿ÍÈëÇÖºÍ0day¡¢APTµÈδ֪Íþв £¬£¬£¬£¬£¬£¬¸üÓÐÀûÓÚʵÑé £¬£¬£¬£¬£¬£¬¸üÀû±ã×°ÖúÍά»¤¡£¡£¡£

5) ÖÇÄÜ×Ôѧϰ£ºÍ¨¹ý¼´Ê±È¡Ñù¡¢ÀúÊ·Êý¾ÝÆÊÎö¡¢¶à¹æÔòºÏ²¢µÈ·½·¨½¨ÉèÀú³Ì/ÍøÂç°×Ãûµ¥¹æÔò¡£¡£¡£ÔÚÉ趨±ê×¼×°±¸Ö®ºó £¬£¬£¬£¬£¬£¬¾°ÔÆÖ§³Ö×Ô¶¯µ÷½â¹æÔòÄÚÈÝÒÔ˳ӦӪҵϵͳÉý¼¶Ôì³ÉµÄ°×Ãûµ¥ÁбíÀ©ÈݵÈÐèÇó £¬£¬£¬£¬£¬£¬×ÊÖúÓû§¿ìËÙ½¨ÉèÇкÏ×ÔÉí¹¤¿ØÇéÐεİ×Ãûµ¥¡£¡£¡£


3¡¢Ö÷»ú¼Ó¹Ì


½ÓÄÉ¿­Ê±K66µÄ¡°Ìì«‘ÄÚÍøÇ徲Σº¦ÖÎÀíÓëÉó¼ÆÏµÍ³¡± £¬£¬£¬£¬£¬£¬¹¦Ð§Èçͼ£º

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ÕâÖ»ÊÇÖÚ¶àÓ¦¼±ÏìÓ¦ÊÂÇéÖеÄÒ»¼þ £¬£¬£¬£¬£¬£¬¿­Ê±K66ʼÖÕ½«¿Í»§µÄÇå¾²·ÅÔÚÊ×λ £¬£¬£¬£¬£¬£¬ÔÚÃæÁÙÍ»·¢µÄÍøÂçÇå¾²ÊÂÎñʱ £¬£¬£¬£¬£¬£¬¼á³ÖÒÔʵʱ¡¢×¨Òµ¡¢ÈÏÕæ¡¢¸ßЧµÄ̬¶È½â¾ö¿Í»§µÄÎÊÌâ £¬£¬£¬£¬£¬£¬Ó®µÃÁ˿ͻ§¼«´óµÄÐÅÈΡ£¡£¡£

Çå¾²ÎÞСÊÂ
Ïò¶·ÕùÔÚÒ»ÏßµÄÓ¦¼±Ð§ÀÍÖ°Ô±Ö¾´£¡