
1 twz Aug 16, 2017 吓死我了,还好不用 XShell |
2 oh Aug 16, 2017 所以要注册三百多个域名吗…… |
3 t6attack Aug 16, 2017 一直没升级,侥幸躲过了后门版本 |
4 ovear Aug 16, 2017 幸好我还在用 15 年的版本。。 |
5 qq292382270 Aug 16, 2017 幸好我做前端... |
6 yksoft1 OP @oh 不需要三百多个,没必要每天换一个。但是用了 DGA 技术生成 C&C 服务器域名的恶意软件一般作者实力雄厚,能随时买起大量域名。国内用这个玩意的恶意软件比较少。 DGA 技术: https://en.wikipedia.org/wiki/Domain_generation_algorithm |
7 crab Aug 16, 2017 连接的服务器域名根据当前时间日期生成-》那不是要注册 N 个域名? |
8 yksoft1 OP |
10 silymore Aug 16, 2017 via iPhone Who is behind this attack? Attribution is hard and the attackers were very careful to not leave obvious traces. However certain techniques were known to be used in another malware like PlugX and Winnti, which were allegedly developed by Chinese-speaking actors. 居然是国产的 |
13 zingl Aug 17, 2017 > certain techniques were known to be used in another malware like PlugX and Winnti, which were allegedly developed by Chinese-speaking actors. 有几楼玻璃心是不是看不懂这句 |
14 lovestudykid Aug 17, 2017 @zingl 人家看懂了,没毛病,这一句就是在没有任何证据的情况下预设立场,暗示是中国人开发的 |
15 Aar0nFr4nk Aug 17, 2017 via iPhone 哇 可怕 还好我用 iTerm2 + fish .. |
16 crab Aug 17, 2017 @yksoft1 https://en.wikipedia.org/wiki/Domain_generation_algorithm chr(((year ^ month ^ day) % 25) + 97) 为什么不是 % 25 ? 这样少了个 z 吧 |
17 wupher Aug 17, 2017 中午回家检查自己的 Windows 笔记本,发现中标了…… 唉,要不要换卡巴斯基呢 它这几招倒是真心学到了,受教 |
18 AresCNZJ Aug 17, 2017 还好用着一年前的版本,懒得每次都去官网下,于是养成了保存安装包的习惯 |
19 J4rod Aug 18, 2017 我擦,中标了?咋解决. |