ÖÐÎÄ
Ðû²¼Ê±¼ä£º2020-04-14
×÷ÕߣºÎâÓ° Áõ»Ô»Ô

2020ÄêÒÁʼ£¬Ò»ÖÖÃûΪ“COVID-19”µÄÐÂÐ͹Ú×´²¡¶¾ÔÚÈ«ÇòËÁŰ£¬¶øÔÚÍøÂçÌìÏÂÀ²¡¶¾Ò²Ã»ÏÐ×Å¡£½èÖúÓÚÕæÊµÌìÏÂÀïµÄ²¡¶¾ËÁŰ£¬ÍøÂç¹¥»÷Õ߳ûúÈö²¥¶ñÒâÈí¼þ£¬´óÅúÓû§“²ÒÔâѬȾ”¡£ÕâÅú±»Ñ¬È¾µÄÓû§£¬½èÖúÓÚ“ºÚÓòÃû”µÄ×ÊÖú£¬¼ÌÐøÔÚÍøÂç¿Õ¼äÄÚ¶Ô²¡¶¾“ËÁÒâÈö²¥”£¬ÄÇô“ºÚÓòÃû”ÊÇʲô£¬¶ÔÎÒÃÇÓÐʲôӰÏ죬±¾Æª½«ÎªÁÐλÖðÒ»µÀÀ´¡£
ºÚÓòÃûÊÇʲô£¿
“ºÚÓòÃû”Ò»Ñùƽ³£Ö¸µÄÊÇÈçÏÂÁ½ÖÖÀàÐ͵ÄÓòÃû£º
ÕâÀïÎÒÃÇËùÖ¸µÄ“ºÚÓòÃû”ÌØÖ¸µÚ¶þÀ࣬¼´¶ñÒâÈí¼þ£¨ÈçÍڿ󲡶¾¡¢½©Ê¬ÍøÂç¡¢ÀÕË÷²¡¶¾µÈ£©Í¨¹ý“ºÚÓòÃû”ʵÏÖ±»¿ØÖÆÖÕ¶ËÓë¿ØÖÆ·þÎñÆ÷Ö®¼ä¼á³ÖͨѶµÄÓòÃû¡£“ºÚÓòÃû”»¹¿É·ÖΪ¾²Ì¬ºÍ¶¯Ì¬Á½Àà¡£
¾²Ì¬ºÚÓòÃû³£ÓÃÓÚÍÚ¿ó¡¢ÀÕË÷²¡¶¾µÈÍøÂç¹¥»÷ÐÐΪ¡£
¶¯Ì¬ºÚÓòÃû³£ÓÃÓÚ½©Ê¬ÍøÂç»òC&CµÈÍøÂç¹¥»÷ÐÐΪ£¬¾³£Ê¹ÓÃDGAËã·¨(Domain Generate Algorithm)ÌìÉú¡£
¶Ô¶ñÒâ³ÌÐò¶øÑÔ£¬Àο¿µÄ¶ñÒâIPµØÖ·¼«Ò×±»Çå¾²×°±¸¼ì²â²¢×è¶Ï£¬ÎÞ·¨ÊµÏÖÒþ²ØÓëÓÐÓõؿØÖÆ¡£ÒÔÊÇ£¬½©Ê¬ÍøÂçÓëC&C¹¥»÷ÔÚÉèÖöñÒâÈí¼þʱÆð¾¢×èֹʹÓÃÀο¿IPµØÖ·×÷Ϊ±»¿ØÖÕ¶ËÓë·þÎñÆ÷¶ËµÄÅþÁ¬¡£ÔÚ³ÌÐòÖо³£Ê¹ÓÃDGAËã·¨À´ÌìÉúËæ»úÓòÃû(ºÚÓòÃû)£¬ÒÔÈÆ¹ý³£¼ûµÄÇå¾²·À»¤ÊֶΣ¬ÊµÏÖ¶Ô±»¿ØÖƶËÒ»Á¬¡¢ÓÐÓõĿØÖÆ¡£
ͨ¹ýDGAËã·¨ÌìÉúµÄºÚÓòÃûÔÚ»¥ÁªÍøÖо³£ÎÞ·¨»á¼û£¬ÓÉÓÚ¶ñÒâ¹¥»÷ÕßÔÚ¶ñÒâÈí¼þÔËÐÐʱ£¬²Å¶ÔÓòÃû¾ÙÐÐ×¢²á£¬ÒÔÊÇÎÒÃÇ·¢Ã÷µÄºÚÓòÃû¾³£ÎÞ·¨Ö±½Ó¾ÙÐлá¼û¡£
ºÚÓòÃûÓëͨË×ÓòÃûµÄÇø±ðÓÐÄÄЩ£¿
ÏÖÓÃÏÖ×¢²á
ÓÉÓÚ×¢²áÓòÃûÐèÒªÓöȣ¬¹Ê¶ñÒâ¹¥»÷Õß¾³£ÔÚºÚÓòÃûÍýÏëÉÏÏßǰ²Å×¢²áÓòÃû£¬ÔÚ´ËʱºÚÓòÃû²Å¿ÉÔÚ»¥ÁªÍøÇéÐÎÖлá¼û¡£
ʹÓÃʱ¼ä¶Ì
ÓÉÓÚÏÖÓÐÇå¾²·À»¤²½·¥¶ÔÍøÂçÁ÷Á¿ÖеÄÐÐΪ¾ÙÐмì²â£¬·¢Ã÷¿ÉÒÉÇëÇóºó½«ÉÏ´«ÔƶËÇå¾²¹ÜÀíÖÐÐÄ¡£ÒÔÊÇÔÚºÚÓòÃûÉúЧʹÓúó£¬ÏÖÓмì²â¡¢·À»¤×°±¸¿É¿ìËÙʶ±ð²¢¹ã²¥·À»¤¹æÔòʵÏÖÓÐÓÃ×è¶Ï£¬ÎªÁË×èÖ¹³¤Ê±¼ä¶¯Ì¬ÓòÃûµÄ̻¶£¬¶ñÒâ¹¥»÷ʹÓÃÒ»¸öÌØ¶¨ºÚÓòÃûµÄʱ¼ä¶¼²»³¤£¬Í¨¹ýÔÚ1-7Ìì×óÓÒ¡£
ͳһ¿î¶ñÒâÈí¼þÓ²±àÂë¶à¸öºÚÓòÃû
ͳһ¿î¶ñÒâÈí¼þÔÚÖÆ×÷ʱ¿ÉÄÜ»áÄÚÖöà¸öºÚÓòÃû£¬ÒÔÌá¸ßÀÖ³ÉÅþÁ¬½©Ê¬ÍøÂçµÄ¼¸ÂÊ¡£
ºÚÓòÃûµÄ³£¼ûͨѶÀú³ÌÊÇÔõÑùµÄ£¿
µ±Ï»¥ÁªÍøÇéÐÎÖУ¬¾³£Ê¹ÓúÚÓòÃûÀ´ÊµÏÖÒþ²Ø½©Ê¬ÍøÂçÖÐÖ÷¿Ø¶ËÕæÊµIP£¬ÒòÆäʹÓÃÓòÃûµÄ¶¯Ì¬ÐÔ£¬¿ÉÈÆ¹ý»ùÓÚÌØÕ÷¼ì²âµÄÇå¾²·À»¤×°±¸·À»¤¹¦Ð§¡£
ÒÔ¶¯Ì¬ºÚÓòÃûΪÀý£¬ËµÃ÷ºÚÓòÃûµÄʹÓó¡¾°¼°Ê¹ÓÃÀú³Ì¡£

1¡¢Ñ¬È¾²¢ÌìÉúËæ»úÓòÃû
¶ñÒâְԱͨ¹ý¶ñÒâÓʼþ¡¢ÍøÂçÈëÇÖµÈÊֶΣ¬ÏòÓû§ÅÌËã»úͶ·Å¶ñÒⲡ¶¾£¬ÊÍ·ÅC&C±»¿Ø¶ËÈí¼þ¡£±»¿Ø¶ËÈí¼þ°²ÅÅºó£¬Æ¾Ö¤DGAËã·¨ÌìÉúÎ±Ëæ»úÓòÃû¡£
2¡¢×¢²áËæ»úÓòÃû£¬±»¿Ø¶Ë·´ÏòÅþÁ¬Ö÷¿Ø¶Ë
¶ñÒâ¹¥»÷Õß¿ÉÌáǰע²á²¿·ÖºÚÓòÃû£¬ÔÚ¶ñÒâ³ÌÐòѬȾÖն˺óʹÓÃDGAËã·¨ÌìÉúÎ±Ëæ»úÓòÃû³Ø£¬Ê¹ÓóØÖÐÓòÃûÖðÒ»Ö±DNS·þÎñÆ÷ÇëÇó¶ÔÓ¦µÄIPµØÖ·£¬Ö±ÖÁÀֳɻñÈ¡IPµØÖ·ºó¼´¾ÙÐÐC&C»á»°ÅþÁ¬£¬¾ÙÐз´ÏòÅþÁ¬¡£
¶ñÒâ¹¥»÷Õß¿ÉÌáǰע²á²¿·ÖºÚÓòÃû£¬ÔÚ¶ñÒâ³ÌÐòѬȾÖն˺óʹÓÃDGAËã·¨ÌìÉúÎ±Ëæ»úÓòÃû³Ø£¬Ê¹ÓóØÖÐÓòÃûÖðÒ»Ö±DNS·þÎñÆ÷ÇëÇó¶ÔÓ¦µÄIPµØÖ·£¬Ö±ÖÁÀֳɻñÈ¡IPµØÖ·ºó¼´¾ÙÐÐC&C»á»°ÅþÁ¬£¬¾ÙÐз´ÏòÅþÁ¬¡£
¹ØÓÚÀúÊ·ÉÏ·¢Ã÷µÄºÚÓòÃûʾÀý£º
ºÚÓòÃûµÄʶ±ð
һЩµÚÈý·½ÍþвÇ鱨¹«¹²Æ½Ì¨¿ÉÒÔ¾ÙÐкÚÓòÃûµÄÐÖúÈ·ÈÏ£¨ÒÔϽØÍ¼ÒÔ΢²½ÔÚÏßÍþвÇ鱨ÉçÇøÎªÀý£©£º


ͬʱ½èÖúÓÚÎÒ˾RG-BDS´óÊý¾ÝÇ徲ƽ̨¡¢RG-BDS-TSPÁ÷Á¿Ì½ÕëÒÔ¼°RG-APT¸ß¼¶Íþв¼ì²âϵͳ£¬¾ùÄܵÚһʱ¿Ì·¢Ã÷ºÚÓòÃûµÄÆÊÎöÓë»á¼û£¬²¢¾ÙÐи澯¡£
RG-BDS´óÊý¾ÝÇ徲ƽ̨ͳһ¸æ¾¯£º

RG-BDS-TSPÁ÷Á¿Ì½Õë¸æ¾¯£º

RG-APT¸ß¼¶Íþв¼ì²âϵͳ¸æ¾¯£º

ºÚÓòÃû·À»¤³£¼û³¡¾°
ij¿Í»§±£´æ±»¶ñÒâÈí¼þѬȾµÄÖ÷»ú£¬ÏòÍâÍø·¢ËÍÒì³£µÄºÚÓòÃûÅþÁ¬ÇëÇó£¬É϶ËÔËÓªÉÌ¡¢Éϼ¶µ¥Î»µÈ»ú¹¹·¢Ã÷¿Í»§´¦±£´æµÄÒì³£Á÷Á¿£¬Í¬²½¿Í»§´¦Öóͷ£ÒªÇó¡£
³ýÁËʵʱ¶ÔÔâÊܶñÒâÈí¼þѬȾµÄÖ÷»ú¾ÙÐв¡¶¾É¨³ýµÈÇå¾²¼Ó¹Ì²½·¥Í⣬¿ÉʹÓÃ97¹ú¼ÊÈ«ÐÂNGFWµÄDNS¹ýÂ˹¦Ð§£¨»òDNSϴ媹¦Ð§£©£¬½øÒ»²½¿ØÖƺÚÓòÃûµÄÒì³£»á¼û£¬½«Ïà¹ØÎ£º¦½µÖÁ×îС¡£
³£¼ûÍØÆËÈçÏ£º

ǰÖÃÌõ¼þ˵Ã÷£º
ÔÀí˵Ã÷
97¹ú¼ÊÈ«ÐÂNGFWµÄDNS¹ýÂ˹¦Ð§£¬¹ËÃû˼Ò壬·À»ðǽÔÚÄÚ²¿Öж¾Ö÷»ú»á¼ûºÚÓòÃûʱµÄDNS½»»¥½×¶ÎÆð¿ØÖÆÏÞÖÆ×÷Óá£
ÔÚ·À»ðǽ¾ÙÐÐDNS¹ýÂËÀú³ÌÖУº
ÒÔ·À»ðǽ¶Ôij¸öÓòÃû£¨¼ÙÉèΪÓòÃûA£©¾ÙÐÐDNS¹ýÂ˵ÄÊÂÇéÁ÷³ÌµÄÐÎò£¬¿ÉÓÃÏÂͼ¼òÊö£º

ÏêϸÉèÖÃ
1¡¢Óû§»ù±¾ÉÏÍøÉèÖãº
ƾ֤ÏÖʵÐèÇ󣬽«·À»ðǽ°²Åŵ½ÍøÂçÖУ¬ÊµÏÖ»ù±¾ÉÏÍøÐèÇó£»
2¡¢·À»ðǽÊÚȨע²áÓ뼤»î£º
ƾ֤·À»ðǽÊÚȨע²áÁ÷³ÌÍê³É×¢²áÓ뼤»î£¬¼¤»îÍê³ÉºóÈ·±£Ä¿½ñ×°±¸ÈÔ´¦ÔÚÊÚȨÓÐÓÃÆÚÄÚ£¬ÈçÏÂͼËùʾ£º

3¡¢ÉèÖÃDNS¹ýÂËÄ£°å£º
ͨ¹ýWeb ½øÈë ¹¤¾ßÉèÖÃ--DNS¹ýÂËÄ£°å£¬×°±¸Ä¬ÈÏÒÑÓÐDNSÄ£°å“default”£¬¿Éµã»÷ÓÒÉϽǵÄÔöÌí°´Å¥£¬ÐÂÔöÒ»¸öÄ£°å£¬Èç±¾ÀýÔöÌíµÄÄ£°å“dns_filter”£º


ÉèÖÃÑ¡Ïî˵Ã÷£º
×è¶Ï·¢Ë͵½botnet C&CµÄDNSÇëÇ󣺷À»ðǽװ±¸ÔÚµ¼ÈëÊÚȨºó£¬»á½«Ôƶ˵ÄBotnetµØÖ·¿â¡¢C&CµØÖ·¿âÏÂÔØµ½ÍâµØ£»¿ªÆô´Ë¹¦Ð§ºó£¬µ±DNSÇëÇóµÄÓòÃûÔÚBotnetµØÖ·¿â»òC&C¿âÖУ¬DNSÇëÇó½«Ö±½Ó×è¶Ï£¬²»»á¾ÙÐкóÐø´¦Öóͷ££»
»ùÓÚÇå¾²ÖÐÐÄ·ÖÀàµÄ¹ýÂËÆ÷£º½«DNSÇëÇóµÄÓòÃû·¢Ë͵½Ôƶˣ¬Ôƶ˻᷵»ØÇëÇóµÄÓòÃûµÄ·ÖÀàÐÅÏ¢£¬Óû§¿É»ùÓÚ·ÖÀàЧ¹û£¬¶Ô²î±ðµÄ·ÖÀàÖ´Ðвî±ðµÄÐж¯£»
¾²Ì¬Óò¹ýÂËÆ÷-Óò¹ýÂË£º¿ÉÊÖ¹¤½ç˵һ¸öÓòÃûÁÐ±í£¬ÈËΪָ¶¨¶ÔÌØ¶¨ÓòÃûµÄ´¦Öóͷ£Ðж¯£»
¾²Ì¬Óò¹ýÂËÆ÷-ÍⲿIP×è¶ÏÇåµ¥£ºÓëÓò¹ýÂËÀàËÆ£¬¿ÉÊÖ¹¤½ç˵һ×éIPÁÐ±í£¬µ±ÓòÃûÆÊÎö³öµÄµØÖ·ÔڸõØÖ·ÁÐ±í¹æÄ£ÄÚ£¬ÈËΪָ¶¨´¦Öóͷ£Ðж¯£»
¿ÉÑ¡Ïî-µ±±¬·¢ÍøÖ··ÖÀà¹ýʧʱÔÊÐíDNSÇëÇ󣺿ªÆô´Ë¹¦Ð§ºó£¬µ±ÇëÇóµÄÓòÃû·¢Ë͸øÔƶˣ¬ÔƶËÔÝδ¶ÔÆä¾ÙÐзÖÀ࣬»òÕß·À»ðǽÓëÔÆ¶ËÎÞ·¨Õý³£Í¨Ñ¶Ê±£¬Óû§µÄDNSÆÊÎö±¨ÎÄ¿ÉÕý³£×ª·¢£»¹Ø±Õ´Ë¹¦Ð§ºó£¬Èç·ºÆðÓòÃûûÓзÖÀ࣬»òÔÆ¶ËÅþÁ¬Ò쳣ʱ£¬DNS±¨ÎĽ«²»¾ÙÐÐת·¢¡£
¿ÉÑ¡Ïî-¼Í¼ËùÓÐDNSÅÌÎʼ°ÏìÓ¦ÈÕÖ¾£º¿ªÆô´Ë¹¦Ð§ºó£¬¿Éͬʱ¼Í¼DNSµÄÇëÇóÓë»Ø¸´ÄÚÈÝ¡£
ÍÆ¼ö±ØÐ迪ÆôµÄ¹¦Ð§Ñ¡Ï×è¶Ï·¢Ë͵½BotnetC&CµÄDNSÇëÇ󣬻ùÓÚÇå¾²ÖÐÐÄ·ÖÀàµÄ¹ýÂËÆ÷£¨Îñ±ØÆ¾Ö¤ÏÖʵÐèÒª¶ÔÌØ¶¨·ÖÀàµÄÐж¯¾ÙÐÐÐÞ¸ÄÓëÈ·ÈÏ£©£¬¿ÉÑ¡Ïî-µ±±¬·¢ÍøÖ··ÖÀà¹ýʧʱÔÊÐíDNSÇëÇó¡£
4¡¢ÉèÖÃSSLÉî¶È¼ì²âÄ£°å
ÔÚ·À»ðǽ6.0Èí¼þ°æ±¾ÉÏ£¬ÎªÁËÌá¸ßÇå¾²ÐÔ£¬ÔÚÇå¾²Õ½ÂÔ¿ªÆôUTM¹¦Ð§Ê±£¬ÒªÇó±ØÐèÑ¡ÔñSSL/SSHÉî¶È¼ì²âÄ£°å¡£×°±¸Ä¬ÈÏÒÑÄÚÖÃSSLÉî¶È¼ì²âÄ£°å£¬µ«Ä¬ÈÏÄ£°åÖж¼»á¶ÔSSL¡¢SSHÐÒé¾ÙÐдúÀí¼ì²â£¬ÔÚÏÖʵӦÓÃÖпÉÄܵ¼Ö·ºÆðÓªÒµÒì³£¡£Òò´ËÈçÏÖʵ³¡¾°ÖÐûÓÐSSL¼ÓÃÜÄÚÈݵĽâÃÜÐèÇó£¬ÐèÒªÖØÐÂÉèÖÃÒ»¸ö²»¼ÓÃܼì²âµÄSSLÄ£°å¡£
ÉèÖÃÒªÁ죺ͨ¹ýWEB·½·¨½øÈë ¹¤¾ßÉèÖÃ--SSL/SSHÉî¶È¼ì²âÄ£°å£¬µã»÷ÓÒÉϽÇн¨°´Å¥£¬½¨ÉèÒ»¸öеÄSSL/SSHÉî¶È¼ì²âÄ£°å£¬ÈçÏÂͼн¨µÄSSL/SSHÉî¶È¼ì²âÄ£°å“no_ssl”£º

н¨µÄÄ£°åÖУ¬½«“¼ì²éËùÓж˿ڔÒÔ¼°“HTTPS”µÈÐÒéºóµÄ¿ªÆôÑ¡ÏîËùÓйرռ´¿É¡£
5¡¢Çå¾²Õ½ÂÔÖÐŲÓÃDNS¹ýÂËÄ£°å
ͨ¹ýWeb½çÃæ£¬ÔÚÕ½ÂÔÉèÖÃ--IPv4Õ½ÂÔÖУ¬¶ÔÏÖÓÐÕ½ÂÔ¾ÙÐе÷½â¡£ÈçÏÂͼËùʾ£¬ÔÚ¶ÔÉÏÍøÉÏÍøµÄ“Çå¾²ÉèÖÔ¾ÙÐÐÉèÖúó£¬Å²ÓÃDNS¹ýÂËÄ£°å“dns_filter”ÒÔ¼°SSL/SSHÉî¶È¼ì²âÄ£°å“no_ssl”£º

Ч¹ûÄ¥Á·
ͨ¹ý·À»ðǽÏÂPCʵÑéÆÊÎöºÚÓòÃû£¬Éó²é·À»ðǽ×è¶ÏЧ¹û£¬ÔÚ·À»ðǽÉÏͨ¹ýÉó²éÈÕÖ¾ÒÔ¼°ÄÚÍâÍø½Ó¿Ú×¥°ü·½·¨È·ÈÏЧ¹û¡£
1¡¢±¾°¸ÀýÖÐʹÓÓv.y6h.net” “lpp.ackng.com” “loseyourip.com” 3¸öºÚÓòÃû¾ÙÐвâÊÔ£¬£¨ÒÔÏÂÊÇʹÓÃVirusTotal¹¤¾ßÑéÖ¤Ëù²âÊÔµÄ3¸öÓòÃûΣº¦ÐÔ½ØÍ¼£¬È·ÈÏÊôÓÚ¸ßΣº¦ÓòÃû£©£º



2¡¢ÎªÈ·±£Ð§¹û£¬Ç¿ÖƲâÊÔPCʹÓó£¼ûDNS·þÎñÆ÷£¨°¸ÀýÖÐʹÓÃ114.114.114.114 DNS·þÎñÆ÷£©¶ÔΣº¦ÓòÃû¾ÙÐÐÆÊÎö



²âÊÔ˵Ã÷£º
a)²ÎÊý“-qt=A”ΪnslookupµÄÔö²¹²ÎÊý£¬ÒâÎªÇ¿ÖÆ¾ÙÐÐIPv4µÄÓòÃûÆÊÎö£»
b)ÏÂÁî×îºóµÄµØÖ·£¬ÒâÎªÇ¿ÖÆÊ¹ÓøõØÖ·×÷ΪDNS·þÎñÆ÷£»
c)ÿ´Î²âÊÔǰ£¬¾ùʹÓÃÏÂÁî“ipconfig /flushdns”Çå¿ÕDNS»º´æ£¬×èÖ¹»º´æÓ°Ïì²âÊÔЧ¹û¡£
3¡¢·À»ðǽ¶Ë×è¶ÏЧ¹ûÈÕÖ¾£º



·À»ðǽÈÕ־˵Ã÷£º
a)Ðж¯Îª“block”ÇÒÐÂÎÅ×Ö¶ÎÏÔʾ“Domain belongs to a denied category in policy”£¬Åú×¢¸ÃDNS±¨ÎÄÊÇͨ¹ýDNS·ÖÀàÊֶα»×è¶Ï£»
b) Ðж¯Îª“block”ÇÒÐÂÎÅ×Ö¶ÎÏÔʾ“Domain was blocked by dns botnet C&C”Åú×¢¸ÃDNS±¨ÎÄÊÇÆ¥Åäµ½ÍâµØµÄBotnet C&C¿â±»×è¶Ï£»
4¡¢·À»ðǽÄÚÍâÍø±¨ÎÄÇéÐΣº
£¨½ØÍ¼×ó²àΪ·À»ðǽÄÚÍø¿Ú±¨ÎÄ£¬ÓÒ²àÓзÀ»ðǽÍâÍø¿Ú±¨ÎÄ£©


ÆäËû×¢ÖØÊÂÏî
