·¢²¼Ê±¼ä£º2020-04-14
×÷ÕߣºÎâÓ° Áõ»Ô»Ô

2020ÄêÒÁʼ£¬Ò»ÖÖÃûΪ“COVID-19”µÄÐÂÐ͹Ú×´²¡¶¾ÔÚÈ«ÇòËÁŰ£¬¶øÔÚÍøÂçÊÀ½çÀ²¡¶¾Ò²Ã»ÏÐ×Å¡£½èÖúÓÚÕæÊµÊÀ½çÀïµÄ²¡¶¾ËÁŰ£¬ÍøÂç¹¥»÷Õ߳ûú´«²¥¶ñÒâÈí¼þ£¬´óÅúÓû§“²ÒÔâ¸ÐȾ”¡£ÕâÅú±»¸ÐȾµÄÓû§£¬½èÖúÓÚ“ºÚÓòÃû”µÄ°ïÖú£¬¼ÌÐøÔÚÍøÂç¿Õ¼äÄÚ¶Ô²¡¶¾“ËÁÒâ´«²¥”£¬ÄÇô“ºÚÓòÃû”ÊÇʲô£¬¶ÔÎÒÃÇÓÐʲôӰÏ죬±¾Æª½«Îª¸÷λһһµÀÀ´¡£
ºÚÓòÃûÊÇʲô£¿
“ºÚÓòÃû”Ò»°ãÖ¸µÄÊÇÈçÏÂÁ½ÖÖÀàÐ͵ÄÓòÃû£º
ÕâÀïÎÒÃÇËùÖ¸µÄ“ºÚÓòÃû”ÌØÖ¸µÚ¶þÀ࣬¼´¶ñÒâÈí¼þ£¨ÈçÍڿ󲡶¾¡¢½©Ê¬ÍøÂç¡¢ÀÕË÷²¡¶¾µÈ£©Í¨¹ý“ºÚÓòÃû”ʵÏÖ±»¿ØÖÆÖÕ¶ËÓë¿ØÖÆ·þÎñÆ÷Ö®¼ä±£³ÖͨÐŵÄÓòÃû¡£“ºÚÓòÃû”»¹¿É·ÖΪ¾²Ì¬ºÍ¶¯Ì¬Á½Àà¡£
¾²Ì¬ºÚÓòÃû³£ÓÃÓÚÍÚ¿ó¡¢ÀÕË÷²¡¶¾µÈÍøÂç¹¥»÷ÐÐΪ¡£
¶¯Ì¬ºÚÓòÃû³£ÓÃÓÚ½©Ê¬ÍøÂç»òC&CµÈÍøÂç¹¥»÷ÐÐΪ£¬³£³£Ê¹ÓÃDGAËã·¨(Domain Generate Algorithm)Éú³É¡£
¶Ô¶ñÒâ³ÌÐò¶øÑÔ£¬¹Ì¶¨µÄ¶ñÒâIPµØÖ·¼«Ò×±»°²È«É豸¼ì²â²¢×è¶Ï£¬ÎÞ·¨ÊµÏÖÒþ±ÎÓëÓÐЧµØ¿ØÖÆ¡£ËùÒÔ£¬½©Ê¬ÍøÂçÓëC&C¹¥»÷ÔÚÉèÖöñÒâÈí¼þʱ¼«Á¦±ÜÃâʹÓù̶¨IPµØÖ·×÷Ϊ±»¿ØÖÕ¶ËÓë·þÎñÆ÷¶ËµÄÁ¬½Ó¡£ÔÚ³ÌÐòÖг£³£Ê¹ÓÃDGAËã·¨À´Éú³ÉËæ»úÓòÃû(ºÚÓòÃû)£¬ÒÔÈÆ¹ý³£¼ûµÄ°²È«·À»¤ÊֶΣ¬ÊµÏÖ¶Ô±»¿ØÖƶ˳ÖÐø¡¢ÓÐЧµÄ¿ØÖÆ¡£
ͨ¹ýDGAËã·¨Éú³ÉµÄºÚÓòÃûÔÚ»¥ÁªÍøÖг£³£ÎÞ·¨·ÃÎÊ£¬ÒòΪ¶ñÒâ¹¥»÷ÕßÔÚ¶ñÒâÈí¼þÔËÐÐʱ£¬²Å¶ÔÓòÃû½øÐÐ×¢²á£¬ËùÒÔÎÒÃÇ·¢ÏֵĺÚÓòÃû³£³£ÎÞ·¨Ö±½Ó½øÐзÃÎÊ¡£
ºÚÓòÃûÓëÆÕͨÓòÃûµÄÇø±ðÓÐÄÄЩ£¿
ÏÖÓÃÏÖ×¢²á
ÓÉÓÚ×¢²áÓòÃûÐèÒª·ÑÓ㬹ʶñÒâ¹¥»÷Õß³£³£ÔÚºÚÓòÃû¼Æ»®ÉÏÏßǰ²Å×¢²áÓòÃû£¬ÔÚ´ËʱºÚÓòÃû²Å¿ÉÔÚ»¥ÁªÍø»·¾³ÖзÃÎÊ¡£
ʹÓÃʱ¼ä¶Ì
ÓÉÓÚÏÖÓа²È«·À»¤´ëÊ©¶ÔÍøÂçÁ÷Á¿ÖеÄÐÐΪ½øÐмì²â£¬·¢ÏÖ¿ÉÒÉÇëÇóºó½«ÉÏ´«Ôƶ˰²È«¹ÜÀíÖÐÐÄ¡£ËùÒÔÔÚºÚÓòÃûÉúЧʹÓúó£¬ÏÖÓмì²â¡¢·À»¤É豸¿É¿ìËÙʶ±ð²¢¹ã²¥·À»¤¹æÔòʵÏÖÓÐЧ×è¶Ï£¬ÎªÁ˱ÜÃⳤʱ¼ä¶¯Ì¬ÓòÃûµÄ±©Â¶£¬¶ñÒâ¹¥»÷ʹÓÃÒ»¸öÌØ¶¨ºÚÓòÃûµÄʱ¼ä¶¼²»³¤£¬Í¨¹ýÔÚ1-7Ìì×óÓÒ¡£
ͬһ¿î¶ñÒâÈí¼þÓ²±àÂë¶à¸öºÚÓòÃû
ͬһ¿î¶ñÒâÈí¼þÔÚÖÆ×÷ʱ¿ÉÄÜ»áÄÚÖöà¸öºÚÓòÃû£¬ÒÔÌá¸ß³É¹¦Á¬½Ó½©Ê¬ÍøÂçµÄ¼¸ÂÊ¡£
ºÚÓòÃûµÄ³£¼ûͨÐŹý³ÌÊÇÔõÑùµÄ£¿
µ±Ï»¥ÁªÍø»·¾³ÖУ¬³£³£Ê¹ÓúÚÓòÃûÀ´ÊµÏÖÒþ²Ø½©Ê¬ÍøÂçÖÐÖ÷¿Ø¶ËÕæÊµIP£¬ÒòÆäʹÓÃÓòÃûµÄ¶¯Ì¬ÐÔ£¬¿ÉÈÆ¹ý»ùÓÚÌØÕ÷¼ì²âµÄ°²È«·À»¤É豸·À»¤¹¦ÄÜ¡£
ÒÔ¶¯Ì¬ºÚÓòÃûΪÀý£¬ËµÃ÷ºÚÓòÃûµÄʹÓó¡¾°¼°Ê¹Óùý³Ì¡£

1¡¢¸ÐȾ²¢Éú³ÉËæ»úÓòÃû
¶ñÒâÈËԱͨ¹ý¶ñÒâÓʼþ¡¢ÍøÂçÈëÇÖµÈÊֶΣ¬ÏòÓû§¼ÆËã»úͶ·Å¶ñÒⲡ¶¾£¬ÊÍ·ÅC&C±»¿Ø¶ËÈí¼þ¡£±»¿Ø¶ËÈí¼þ²¿Êðºó£¬¸ù¾ÝDGAËã·¨Éú³ÉÎ±Ëæ»úÓòÃû¡£
2¡¢×¢²áËæ»úÓòÃû£¬±»¿Ø¶Ë·´ÏòÁ¬½ÓÖ÷¿Ø¶Ë
¶ñÒâ¹¥»÷Õß¿ÉÌáǰע²á²¿·ÖºÚÓòÃû£¬ÔÚ¶ñÒâ³ÌÐò¸ÐȾÖն˺óʹÓÃDGAËã·¨Éú³ÉÎ±Ëæ»úÓòÃû³Ø£¬Ê¹ÓóØÖÐÓòÃûÖðÒ»ÏòDNS·þÎñÆ÷ÇëÇó¶ÔÓ¦µÄIPµØÖ·£¬Ö±ÖÁ³É¹¦»ñÈ¡IPµØÖ·ºó¼´½øÐÐC&C»á»°Á¬½Ó£¬½øÐз´ÏòÁ¬½Ó¡£
¶ñÒâ¹¥»÷Õß¿ÉÌáǰע²á²¿·ÖºÚÓòÃû£¬ÔÚ¶ñÒâ³ÌÐò¸ÐȾÖն˺óʹÓÃDGAËã·¨Éú³ÉÎ±Ëæ»úÓòÃû³Ø£¬Ê¹ÓóØÖÐÓòÃûÖðÒ»ÏòDNS·þÎñÆ÷ÇëÇó¶ÔÓ¦µÄIPµØÖ·£¬Ö±ÖÁ³É¹¦»ñÈ¡IPµØÖ·ºó¼´½øÐÐC&C»á»°Á¬½Ó£¬½øÐз´ÏòÁ¬½Ó¡£
¶ÔÓÚÀúÊ·ÉÏ·¢ÏֵĺÚÓòÃûʾÀý£º
ºÚÓòÃûµÄʶ±ð
һЩµÚÈý·½ÍþвÇ鱨¹«¹²Æ½Ì¨¿ÉÒÔ½øÐкÚÓòÃûµÄÐÖúÈ·ÈÏ£¨ÒÔϽØÍ¼ÒÔ΢²½ÔÚÏßÍþвÇ鱨ÉçÇøÎªÀý£©£º


ͬʱ½èÖúÓÚÎÒ˾RG-BDS´óÊý¾Ý°²È«Æ½Ì¨¡¢RG-BDS-TSPÁ÷Á¿Ì½ÕëÒÔ¼°RG-APT¸ß¼¶Íþв¼ì²âϵͳ£¬¾ùÄܵÚһʱ¿Ì·¢ÏÖºÚÓòÃûµÄ½âÎöÓë·ÃÎÊ£¬²¢½øÐи澯¡£
RG-BDS´óÊý¾Ý°²È«Æ½Ì¨Í³Ò»¸æ¾¯£º

RG-BDS-TSPÁ÷Á¿Ì½Õë¸æ¾¯£º

RG-APT¸ß¼¶Íþв¼ì²âϵͳ¸æ¾¯£º

ºÚÓòÃû·À»¤³£¼û³¡¾°
ij¿Í»§´æÔÚ±»¶ñÒâÈí¼þ¸ÐȾµÄÖ÷»ú£¬ÏòÍâÍø·¢ËÍÒì³£µÄºÚÓòÃûÁ¬½ÓÇëÇó£¬É϶ËÔËÓªÉÌ¡¢Éϼ¶µ¥Î»µÈ»ú¹¹·¢ÏÖ¿Í»§´¦´æÔÚµÄÒì³£Á÷Á¿£¬Í¬²½¿Í»§´¦ÀíÒªÇó¡£
³ýÁ˼°Ê±¶ÔÔâÊܶñÒâÈí¼þ¸ÐȾµÄÖ÷»ú½øÐв¡¶¾Çå³ýµÈ°²È«¼Ó¹Ì´ëÊ©Í⣬¿ÉʹÓù«º£²Ê´¬¡¤6600È«ÐÂNGFWµÄDNS¹ýÂ˹¦ÄÜ£¨»òDNSÇåÏ´¹¦ÄÜ£©£¬½øÒ»²½¿ØÖƺÚÓòÃûµÄÒì³£·ÃÎÊ£¬½«Ïà¹Ø·çÏÕ½µÖÁ×îС¡£
³£¼ûÍØÆËÈçÏ£º

ǰÖÃÌõ¼þ˵Ã÷£º
ÔÀí˵Ã÷
¹«º£²Ê´¬¡¤6600È«ÐÂNGFWµÄDNS¹ýÂ˹¦ÄÜ£¬¹ËÃû˼Ò壬·À»ðǽÔÚÄÚ²¿Öж¾Ö÷»ú·ÃÎʺÚÓòÃûʱµÄDNS½»»¥½×¶ÎÆð¿ØÖÆÏÞÖÆ×÷Óá£
ÔÚ·À»ðǽ½øÐÐDNS¹ýÂ˹ý³ÌÖУº
ÒÔ·À»ðǽ¶Ôij¸öÓòÃû£¨¼ÙÉèΪÓòÃûA£©½øÐÐDNS¹ýÂ˵Ť×÷Á÷³ÌµÄÃèÊö£¬¿ÉÓÃÏÂͼ¼òÊö£º

¾ßÌåÅäÖÃ
1¡¢Óû§»ù±¾ÉÏÍøÅäÖãº
¸ù¾Ýʵ¼ÊÐèÇ󣬽«·À»ðǽ²¿Êðµ½ÍøÂçÖУ¬ÊµÏÖ»ù±¾ÉÏÍøÐèÇó£»
2¡¢·À»ðǽÊÚȨע²áÓ뼤»î£º
°´ÕÕ·À»ðǽÊÚȨע²áÁ÷³ÌÍê³É×¢²áÓ뼤»î£¬¼¤»îÍê³ÉºóÈ·±£µ±Ç°É豸ÈÔ´¦ÔÚÊÚȨÓÐЧÆÚÄÚ£¬ÈçÏÂͼËùʾ£º

3¡¢ÅäÖÃDNS¹ýÂËÄ£°å£º
ͨ¹ýWeb ½øÈë ¶ÔÏóÅäÖÃ--DNS¹ýÂËÄ£°å£¬É豸ĬÈÏÒÑÓÐDNSÄ£°å“default”£¬¿Éµã»÷ÓÒÉϽǵÄÔö¼Ó°´Å¥£¬ÐÂÔöÒ»¸öÄ£°å£¬Èç±¾ÀýÔö¼ÓµÄÄ£°å“dns_filter”£º


ÅäÖÃÑ¡Ïî˵Ã÷£º
×è¶Ï·¢Ë͵½botnet C&CµÄDNSÇëÇ󣺷À»ðǽÉ豸ÔÚµ¼ÈëÊÚȨºó£¬»á½«Ôƶ˵ÄBotnetµØÖ·¿â¡¢C&CµØÖ·¿âÏÂÔØµ½±¾µØ£»¿ªÆô´Ë¹¦Äܺ󣬵±DNSÇëÇóµÄÓòÃûÔÚBotnetµØÖ·¿â»òC&C¿âÖУ¬DNSÇëÇó½«Ö±½Ó×è¶Ï£¬²»»á½øÐкóÐø´¦Àí£»
»ùÓÚ°²È«ÖÐÐÄ·ÖÀàµÄ¹ýÂËÆ÷£º½«DNSÇëÇóµÄÓòÃû·¢Ë͵½Ôƶˣ¬Ôƶ˻᷵»ØÇëÇóµÄÓòÃûµÄ·ÖÀàÐÅÏ¢£¬Óû§¿É»ùÓÚ·ÖÀà½á¹û£¬¶Ô²»Í¬µÄ·ÖÀàÖ´Ðв»Í¬µÄ¶¯×÷£»
¾²Ì¬Óò¹ýÂËÆ÷-Óò¹ýÂË£º¿ÉÊÖ¹¤¶¨ÒåÒ»¸öÓòÃûÁÐ±í£¬ÈËΪָ¶¨¶ÔÌØ¶¨ÓòÃûµÄ´¦Àí¶¯×÷£»
¾²Ì¬Óò¹ýÂËÆ÷-ÍⲿIP×è¶ÏÇåµ¥£ºÓëÓò¹ýÂËÀàËÆ£¬¿ÉÊÖ¹¤¶¨ÒåÒ»×éIPÁÐ±í£¬µ±ÓòÃû½âÎö³öµÄµØÖ·ÔڸõØÖ·ÁÐ±í·¶Î§ÄÚ£¬ÈËΪָ¶¨´¦Àí¶¯×÷£»
¿ÉÑ¡Ïî-µ±·¢ÉúÍøÖ··ÖÀà´íÎóʱÔÊÐíDNSÇëÇ󣺿ªÆô´Ë¹¦Äܺ󣬵±ÇëÇóµÄÓòÃû·¢Ë͸øÔƶˣ¬ÔƶËÔÝδ¶ÔÆä½øÐзÖÀ࣬»òÕß·À»ðǽÓëÔÆ¶ËÎÞ·¨Õý³£Í¨ÐÅʱ£¬Óû§µÄDNS½âÎö±¨ÎÄ¿ÉÕý³£×ª·¢£»¹Ø±Õ´Ë¹¦Äܺó£¬Èç³öÏÖÓòÃûûÓзÖÀ࣬»òÔÆ¶ËÁ¬½ÓÒ쳣ʱ£¬DNS±¨ÎĽ«²»½øÐÐת·¢¡£
¿ÉÑ¡Ïî-¼Ç¼ËùÓÐDNS²éѯ¼°ÏàÓ¦ÈÕÖ¾£º¿ªÆô´Ë¹¦Äܺ󣬿Éͬʱ¼Ç¼DNSµÄÇëÇóÓë»Ø¸´ÄÚÈÝ¡£
ÍÆ¼ö±ØÐ뿪ÆôµÄ¹¦ÄÜÑ¡Ï×è¶Ï·¢Ë͵½BotnetC&CµÄDNSÇëÇ󣬻ùÓÚ°²È«ÖÐÐÄ·ÖÀàµÄ¹ýÂËÆ÷£¨Îñ±Ø¸ù¾Ýʵ¼ÊÐèÒª¶ÔÌØ¶¨·ÖÀàµÄ¶¯×÷½øÐÐÐÞ¸ÄÓëÈ·ÈÏ£©£¬¿ÉÑ¡Ïî-µ±·¢ÉúÍøÖ··ÖÀà´íÎóʱÔÊÐíDNSÇëÇó¡£
4¡¢ÅäÖÃSSLÉî¶È¼ì²âÄ£°å
ÔÚ·À»ðǽ6.0Èí¼þ°æ±¾ÉÏ£¬ÎªÁËÌá¸ß°²È«ÐÔ£¬ÔÚ°²È«²ßÂÔ¿ªÆôUTM¹¦ÄÜʱ£¬ÒªÇó±ØÐëÑ¡ÔñSSL/SSHÉî¶È¼ì²âÄ£°å¡£É豸ĬÈÏÒÑÄÚÖÃSSLÉî¶È¼ì²âÄ£°å£¬µ«Ä¬ÈÏÄ£°åÖж¼»á¶ÔSSL¡¢SSHÐÒé½øÐдúÀí¼ì²â£¬ÔÚʵ¼ÊÓ¦ÓÃÖпÉÄܵ¼Ö³öÏÖÒµÎñÒì³£¡£Òò´ËÈçʵ¼Ê³¡¾°ÖÐûÓÐSSL¼ÓÃÜÄÚÈݵĽâÃÜÐèÇó£¬ÐèÒªÖØÐÂÉèÖÃÒ»¸ö²»¼ÓÃܼì²âµÄSSLÄ£°å¡£
ÅäÖ÷½·¨£ºÍ¨¹ýWEB·½Ê½½øÈë ¶ÔÏóÅäÖÃ--SSL/SSHÉî¶È¼ì²âÄ£°å£¬µã»÷ÓÒÉϽÇн¨°´Å¥£¬´´½¨Ò»¸öеÄSSL/SSHÉî¶È¼ì²âÄ£°å£¬ÈçÏÂͼн¨µÄSSL/SSHÉî¶È¼ì²âÄ£°å“no_ssl”£º

н¨µÄÄ£°åÖУ¬½«“¼ì²éËùÓж˿ڔÒÔ¼°“HTTPS”µÈÐÒéºóµÄ¿ªÆôÑ¡ÏîÈ«²¿¹Ø±Õ¼´¿É¡£
5¡¢°²È«²ßÂÔÖе÷ÓÃDNS¹ýÂËÄ£°å
ͨ¹ýWeb½çÃæ£¬ÔÚ²ßÂÔÉèÖÃ--IPv4²ßÂÔÖУ¬¶ÔÏÖÓвßÂÔ½øÐе÷Õû¡£ÈçÏÂͼËùʾ£¬ÔÚ¶ÔÉÏÍøÉÏÍøµÄ“°²È«ÅäÖÔ½øÐÐÉèÖú󣬵÷ÓÃDNS¹ýÂËÄ£°å“dns_filter”ÒÔ¼°SSL/SSHÉî¶È¼ì²âÄ£°å“no_ssl”£º

Ч¹û¼ìÑé
ͨ¹ý·À»ðǽÏÂPC³¢ÊÔ½âÎöºÚÓòÃû£¬²é¿´·À»ðǽ×è¶ÏЧ¹û£¬ÔÚ·À»ðǽÉÏͨ¹ý²é¿´ÈÕÖ¾ÒÔ¼°ÄÚÍâÍø½Ó¿Ú×¥°ü·½Ê½È·ÈÏЧ¹û¡£
1¡¢±¾°¸ÀýÖÐʹÓÓv.y6h.net” “lpp.ackng.com” “loseyourip.com” 3¸öºÚÓòÃû½øÐвâÊÔ£¬£¨ÒÔÏÂÊÇʹÓÃVirusTotal¹¤¾ßÑéÖ¤Ëù²âÊÔµÄ3¸öÓòÃû·çÏÕÐÔ½ØÍ¼£¬È·ÈÏÊôÓڸ߷çÏÕÓòÃû£©£º



2¡¢ÎªÈ·±£Ð§¹û£¬Ç¿ÖƲâÊÔPCʹÓó£¼ûDNS·þÎñÆ÷£¨°¸ÀýÖÐʹÓÃ114.114.114.114 DNS·þÎñÆ÷£©¶Ô·çÏÕÓòÃû½øÐнâÎö



²âÊÔ˵Ã÷£º
a)²ÎÊý“-qt=A”ΪnslookupµÄ²¹³ä²ÎÊý£¬ÒâÎªÇ¿ÖÆ½øÐÐIPv4µÄÓòÃû½âÎö£»
b)ÃüÁî×îºóµÄµØÖ·£¬ÒâÎªÇ¿ÖÆÊ¹ÓøõØÖ·×÷ΪDNS·þÎñÆ÷£»
c)ÿ´Î²âÊÔǰ£¬¾ùʹÓÃÃüÁî“ipconfig /flushdns”Çå¿ÕDNS»º´æ£¬±ÜÃ⻺´æÓ°Ïì²âÊÔ½á¹û¡£
3¡¢·À»ðǽ¶Ë×è¶ÏЧ¹ûÈÕÖ¾£º



·À»ðǽÈÕ־˵Ã÷£º
a)¶¯×÷Ϊ“block”ÇÒÏûÏ¢×Ö¶ÎÏÔʾ“Domain belongs to a denied category in policy”£¬±íÃ÷¸ÃDNS±¨ÎÄÊÇͨ¹ýDNS·ÖÀàÊֶα»×è¶Ï£»
b) ¶¯×÷Ϊ“block”ÇÒÏûÏ¢×Ö¶ÎÏÔʾ“Domain was blocked by dns botnet C&C”±íÃ÷¸ÃDNS±¨ÎÄÊÇÆ¥Åäµ½±¾µØµÄBotnet C&C¿â±»×è¶Ï£»
4¡¢·À»ðǽÄÚÍâÍø±¨ÎÄÇé¿ö£º
£¨½ØÍ¼×ó²àΪ·À»ðǽÄÚÍø¿Ú±¨ÎÄ£¬ÓÒ²àÓзÀ»ðǽÍâÍø¿Ú±¨ÎÄ£©


ÆäËû×¢ÒâÊÂÏî
