{"id":2535,"date":"2022-12-27T00:26:20","date_gmt":"2022-12-26T16:26:20","guid":{"rendered":"http:\/\/0.0.0.0:8801\/?p=2535"},"modified":"2023-01-12T00:27:15","modified_gmt":"2023-01-11T16:27:15","slug":"%e9%a7%ad%e4%be%b5%e8%80%85%e5%88%a9%e7%94%a8%e6%a4%8d%e5%85%a5%e6%9c%a8%e9%a6%ac%e7%9a%84-windows-10-%e5%ae%89%e8%a3%9d%e7%a8%8b%e5%bc%8f%ef%bc%8c%e9%a7%ad%e5%85%a5%e7%83%8f%e5%85%8b%e8%98%ad","status":"publish","type":"post","link":"https:\/\/aict.nkust.edu.tw\/digitrans\/?p=2535","title":{"rendered":"\u99ed\u4fb5\u8005\u5229\u7528\u690d\u5165\u6728\u99ac\u7684 Windows 10 \u5b89\u88dd\u7a0b\u5f0f\uff0c\u99ed\u5165\u70cf\u514b\u862d\u653f\u5e9c\u6240\u5c6c\u7db2\u8def"},"content":{"rendered":"\n<p>\u767c\u5e03\u55ae\u4f4d:TWCERT\/CC \u66f4\u65b0\u65e5\u671f:2022-12-27<\/p>\n\n\n\n<p>\u8cc7\u5b89\u5ee0\u5546 Mandiant \u65e5\u524d\u767c\u8868\u7814\u7a76\u5831\u544a\uff0c\u6307\u51fa\u8a72\u516c\u53f8\u767c\u73fe\u6709\u99ed\u4fb5\u5718\u9ad4\u900f\u904e\u690d\u5165\u60e1\u610f\u8edf\u9ad4\u7684 Windows 10 \u5b89\u88dd ISO \u6a94\uff0c\u653b\u64ca\u70cf\u514b\u862d\u653f\u5e9c\u6240\u5c6c\u55ae\u4f4d\uff0c\u5165\u4fb5\u5176\u5167\u90e8\u7db2\u8def\u7cfb\u7d71\u3002<\/p>\n\n\n\n<p>\u64da Mandiant \u7684\u5831\u544a\u6307\u51fa\uff0c\u9019\u6ce2\u653b\u64ca\u4fc2\u900f\u904e P2P \u6a94\u6848\u5206\u4eab\u7db2\u8def BitTorrent \u7684\u7db2\u7ad9\u9032\u884c\uff1b\u99ed\u4fb5\u8005\u5c07\u6728\u99ac\u60e1\u610f\u8edf\u9ad4\u690d\u5165 Windows 10 \u5b89\u88dd\u5149\u789f\u6620\u50cf\u6a94\uff0c\u85c9\u4ee5\u767c\u52d5\u4f9b\u61c9\u93c8\u653b\u64ca\u3002<\/p>\n\n\n\n<p>Mandiant \u5c07\u9019\u6ce2\u653b\u64ca\u884c\u52d5\u4ee3\u865f\u547d\u540d\u70ba\u300cUNC4166\u300d\u3002\u8a72\u516c\u53f8\u5728\u5206\u6790\u70cf\u514b\u862d\u653f\u5e9c\u53d7\u5230\u653b\u64ca\u7684\u90e8\u5206\u55ae\u4f4d\u5167\u7db2\u6642\uff0c\u767c\u73fe\u88ab\u690d\u5165\u7684\u6728\u99ac\u4e3b\u8981\u4ee5\u7aca\u53d6\u6a5f\u5bc6\u8cc7\u8a0a\u70ba\u4e3b\uff0c\u50b3\u9001\u5230\u99ed\u4fb5\u8005\u63a7\u5236\u4f3a\u670d\u5668\u7684\u8c9f\u8a0a\uff0c\u4e26\u672a\u542b\u6709\u53ef\u7528\u4ee5\u7aca\u53d6\u8ca1\u7269\u7684\u8cc7\u8a0a\uff0c\u4e5f\u4e0d\u542b\u4efb\u4f55\u52d2\u8d16\u5de5\u5177\u6216\u52a0\u5bc6\u8ca8\u5e63\u6316\u7926\u7a0b\u5f0f\u3002<\/p>\n\n\n\n<p>Mandiant \u8aaa\uff0c\u99ed\u4fb5\u8005\u5728\u521d\u6b65\u5165\u4fb5\u53d7\u5bb3\u7cfb\u7d71\u5f8c\uff0c\u96a8\u5373\u9032\u4e00\u6b65\u5e03\u7f72\u591a\u7a2e\u60e1\u610f\u5f8c\u9580 Stowaway\u3001Beacon\u3001Sparepart \u7b49\uff0c\u4ee5\u4fbf\u8b93\u99ed\u4fb5\u8005\u63a7\u5236\u53d7\u99ed\u7cfb\u7d71\u3001\u57f7\u884c\u6307\u4ee4\u8207\u7a0b\u5f0f\u78bc\u3001\u50b3\u9001\u6a94\u6848\u3001\u7aca\u53d6\u8cc7\u8a0a\u5982\u767b\u5165\u5e33\u5bc6\u548c\u9375\u76e4\u8f38\u5165\u7b49\u3002<\/p>\n\n\n\n<p>Mandiant \u4e5f\u767c\u73fe\u4e00\u4e9b\u5728 2022 \u5e74 7 \u6708\u9810\u5148\u6392\u7a0b\u597d\u7684\u5de5\u4f5c\uff0c\u4ee5\u4fbf\u900f\u904e PowerShell \u53d6\u5f97\u99ed\u4fb5\u8005\u4e0b\u9054\u7684\u9032\u4e00\u6b65\u653b\u64ca\u6307\u4ee4\u3002<\/p>\n\n\n\n<p>Mandiant \u5728\u5831\u544a\u4e2d\u6307\u51fa\uff0c\u9019\u6b21\u70cf\u514b\u862d\u653f\u5e9c\u53d7\u5230\u653b\u64ca\u7684\u55ae\u4f4d\uff0c\u904e\u53bb\u4e5f\u66fe\u906d\u5230 APT \u99ed\u4fb5\u5718\u9ad4 APT28 \u7684\u653b\u64ca\u3002<\/p>\n\n\n\n<p>\u5efa\u8b70\u64c1\u6709\u6a5f\u654f\u8cc7\u8a0a\u7684\u5404\u516c\u79c1\u55ae\u4f4d\u6216\u500b\u4eba\uff0c\u5728\u5b89\u88dd\u8edf\u9ad4\u6642\u52d9\u5fc5\u5faa\u6b63\u898f\u7ba1\u9053\uff0c\u4f7f\u7528\u7d93\u9a57\u8b49\u5b89\u5168\u6027\u53ef\u9760\u7684\u6b63\u7248\u8edf\u9ad4\uff0c\u5207\u52ff\u900f\u904e P2P \u6216\u793e\u7fa4\u5e73\u53f0\u9023\u7d50\u5b89\u88dd\u4f86\u8def\u4e0d\u660e\u7684\u76dc\u7248\u8edf\u9ad4\u6216\u6240\u8b02\u7834\u89e3\u5de5\u5177\u3001\u8a3b\u518a\u6a5f\uff0c\u4ee5\u514d\u906d\u5230\u690d\u5165\u60e1\u610f\u8edf\u9ad4\u3002<\/p>\n\n\n\n<p>\u8cc7\u6599\u4f86\u6e90\uff1a<a href=\"https:\/\/www.twcert.org.tw\/tw\/cp-104-6822-ba4f8-1.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.twcert.org.tw\/tw\/cp-104-6822-ba4f8-1.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u767c\u5e03\u55ae\u4f4d:TWCERT\/CC \u66f4\u65b0\u65e5\u671f:2022-12-27 \u8cc7\u5b89\u5ee0\u5546 Mandiant \u65e5\u524d\u767c\u8868\u7814\u7a76\u5831\u544a\uff0c\u6307\u51fa\u8a72\u516c\u53f8\u767c\u73fe\u6709\u99ed\u4fb5\u5718\u9ad4\u900f\u904e\u690d\u5165\u60e1\u610f\u8edf\u9ad4\u7684 Windows 10 \u5b89\u88dd &hellip;<\/p>\n","protected":false},"author":3,"featured_media":2536,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[352],"tags":[512,204],"class_list":["post-2535","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information-security","tag-512","tag-204"],"gutentor_comment":0,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/aict.nkust.edu.tw\/digitrans\/wp-content\/uploads\/2023\/01\/0110-10.jpg?fit=1080%2C1080&ssl=1","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/2535","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2535"}],"version-history":[{"count":1,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/2535\/revisions"}],"predecessor-version":[{"id":2537,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/2535\/revisions\/2537"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/media\/2536"}],"wp:attachment":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2535"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2535"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2535"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}