|
本帖最后由 abcdwf 于 2025-7-8 13:21 编辑
隔了很久才拦截到一条
- 时间 操作 说明 次数
- 2025-07-08 13:04:38 [已拦截] 远程桌面弱口令攻击,攻击者:150.223.56.35 防护 1 次
- 检测到远程桌面暴力破解,攻击者:150.223.56.35
- 2025-07-08 10:38:22 [已拦截] 远程桌面弱口令攻击,攻击者:175.6.185.74 防护 1 次
- 检测到远程桌面暴力破解,攻击者:175.6.185.74
- 2025-07-08 10:17:58 [已拦截] 远程桌面弱口令攻击,攻击者:124.70.75.103 防护 1 次
- 检测到远程桌面暴力破解,攻击者:124.70.75.103
- 2025-07-08 10:09:00 [已拦截] 远程桌面弱口令攻击,攻击者:81.71.49.93 防护 3 次
- 检测到远程桌面暴力破解,攻击者:81.71.49.93
- 2025-07-08 09:47:30 [已拦截] 远程桌面弱口令攻击,攻击者:45.134.26.142 防护 2 次
- 检测到远程桌面暴力破解,攻击者:45.134.26.142
- 2025-07-08 09:12:58 [已拦截] 远程桌面弱口令攻击,攻击者:47.103.20.37 防护 1 次
- 检测到远程桌面暴力破解,攻击者:47.103.20.37
- 2025-07-08 08:48:52 [已拦截] 远程桌面弱口令攻击,攻击者:111.231.19.187 防护 1 次
- 检测到远程桌面暴力破解,攻击者:111.231.19.187
- 2025-07-08 08:20:56 [已拦截] 远程桌面弱口令攻击,攻击者:175.6.71.74 防护 1 次
- 检测到远程桌面暴力破解,攻击者:175.6.71.74
复制代码
Wireshark 请求记录:
- No. Time Source Destination Protocol Length Info
- 4700 3907.126776 150.223.56.35 172.28.48.25 TCP 66 49511 → 65230 [SYN, ECE, CWR] Seq=0 Win=64240 Len=0 MSS=1460 WS=256 SACK_PERM
- Frame 4700: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface \Device\NPF_{CEB012EB-97C5-44ED-83D5-F65B8A3CE223}, id 0
- Ethernet II, Src: ee:ff:ff:ff:ff:ff (ee:ff:ff:ff:ff:ff), Dst: Xensourc_2c:58:13 (00:16:3e:2c:58:13)
- Internet Protocol Version 4, Src: 150.223.56.35, Dst: 172.28.48.25
- Transmission Control Protocol, Src Port: 49511, Dst Port: 65230, Seq: 0, Len: 0
- Source Port: 49511
- Destination Port: 65230
- [Stream index: 180]
- [Conversation completeness: Complete, WITH_DATA (63)]
- [TCP Segment Len: 0]
- Sequence Number: 0 (relative sequence number)
- Sequence Number (raw): 860961686
- [Next Sequence Number: 1 (relative sequence number)]
- Acknowledgment Number: 0
- Acknowledgment number (raw): 0
- 1000 .... = Header Length: 32 bytes (8)
- Flags: 0x0c2 (SYN, ECE, CWR)
- Window: 64240
- [Calculated window size: 64240]
- Checksum: 0x9909 [unverified]
- [Checksum Status: Unverified]
- Urgent Pointer: 0
- Options: (12 bytes), Maximum segment size, No-Operation (NOP), Window scale, No-Operation (NOP), No-Operation (NOP), SACK permitted
- [Timestamps]
- No. Time Source Destination Protocol Length Info
- 4704 3907.160981 150.223.56.35 172.28.48.25 TCP 60 49511 → 65230 [ACK] Seq=1 Ack=1 Win=1573632 Len=0
- Frame 4704: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) on interface \Device\NPF_{CEB012EB-97C5-44ED-83D5-F65B8A3CE223}, id 0
- Ethernet II, Src: ee:ff:ff:ff:ff:ff (ee:ff:ff:ff:ff:ff), Dst: Xensourc_2c:58:13 (00:16:3e:2c:58:13)
- Internet Protocol Version 4, Src: 150.223.56.35, Dst: 172.28.48.25
- Transmission Control Protocol, Src Port: 49511, Dst Port: 65230, Seq: 1, Ack: 1, Len: 0
- Source Port: 49511
- Destination Port: 65230
- [Stream index: 180]
- [Conversation completeness: Complete, WITH_DATA (63)]
- [TCP Segment Len: 0]
- Sequence Number: 1 (relative sequence number)
- Sequence Number (raw): 860961687
- [Next Sequence Number: 1 (relative sequence number)]
- Acknowledgment Number: 1 (relative ack number)
- Acknowledgment number (raw): 829451830
- 0101 .... = Header Length: 20 bytes (5)
- Flags: 0x010 (ACK)
- Window: 6147
- [Calculated window size: 1573632]
- [Window size scaling factor: 256]
- Checksum: 0x1dd4 [unverified]
- [Checksum Status: Unverified]
- Urgent Pointer: 0
- [Timestamps]
- [SEQ/ACK analysis]
- No. Time Source Destination Protocol Length Info
- 4705 3907.161234 150.223.56.35 172.28.48.25 TLSv1.2 73 Ignored Unknown Record
- Frame 4705: 73 bytes on wire (584 bits), 73 bytes captured (584 bits) on interface \Device\NPF_{CEB012EB-97C5-44ED-83D5-F65B8A3CE223}, id 0
- Ethernet II, Src: ee:ff:ff:ff:ff:ff (ee:ff:ff:ff:ff:ff), Dst: Xensourc_2c:58:13 (00:16:3e:2c:58:13)
- Internet Protocol Version 4, Src: 150.223.56.35, Dst: 172.28.48.25
- Transmission Control Protocol, Src Port: 49511, Dst Port: 65230, Seq: 1, Ack: 1, Len: 19
- Source Port: 49511
- Destination Port: 65230
- [Stream index: 180]
- [Conversation completeness: Complete, WITH_DATA (63)]
- [TCP Segment Len: 19]
- Sequence Number: 1 (relative sequence number)
- Sequence Number (raw): 860961687
- [Next Sequence Number: 20 (relative sequence number)]
- Acknowledgment Number: 1 (relative ack number)
- Acknowledgment number (raw): 829451830
- 0101 .... = Header Length: 20 bytes (5)
- Flags: 0x018 (PSH, ACK)
- Window: 6147
- [Calculated window size: 1573632]
- [Window size scaling factor: 256]
- Checksum: 0x0bba [unverified]
- [Checksum Status: Unverified]
- Urgent Pointer: 0
- [Timestamps]
- [SEQ/ACK analysis]
- TCP payload (19 bytes)
- Transport Layer Security
- No. Time Source Destination Protocol Length Info
- 4713 3907.205814 150.223.56.35 172.28.48.25 TLSv1.2 183 Client Hello
- Frame 4713: 183 bytes on wire (1464 bits), 183 bytes captured (1464 bits) on interface \Device\NPF_{CEB012EB-97C5-44ED-83D5-F65B8A3CE223}, id 0
- Ethernet II, Src: ee:ff:ff:ff:ff:ff (ee:ff:ff:ff:ff:ff), Dst: Xensourc_2c:58:13 (00:16:3e:2c:58:13)
- Internet Protocol Version 4, Src: 150.223.56.35, Dst: 172.28.48.25
- Transmission Control Protocol, Src Port: 49511, Dst Port: 65230, Seq: 20, Ack: 20, Len: 129
- Source Port: 49511
- Destination Port: 65230
- [Stream index: 180]
- [Conversation completeness: Complete, WITH_DATA (63)]
- [TCP Segment Len: 129]
- Sequence Number: 20 (relative sequence number)
- Sequence Number (raw): 860961706
- [Next Sequence Number: 149 (relative sequence number)]
- Acknowledgment Number: 20 (relative ack number)
- Acknowledgment number (raw): 829451849
- 0101 .... = Header Length: 20 bytes (5)
- Flags: 0x018 (PSH, ACK)
- Window: 6147
- [Calculated window size: 1573632]
- [Window size scaling factor: 256]
- Checksum: 0x9728 [unverified]
- [Checksum Status: Unverified]
- Urgent Pointer: 0
- [Timestamps]
- [SEQ/ACK analysis]
- TCP payload (129 bytes)
- Transport Layer Security
- No. Time Source Destination Protocol Length Info
- 4717 3907.245359 150.223.56.35 172.28.48.25 TLSv1.2 236 Client Key Exchange, Change Cipher Spec, Encrypted Handshake Message
- Frame 4717: 236 bytes on wire (1888 bits), 236 bytes captured (1888 bits) on interface \Device\NPF_{CEB012EB-97C5-44ED-83D5-F65B8A3CE223}, id 0
- Ethernet II, Src: ee:ff:ff:ff:ff:ff (ee:ff:ff:ff:ff:ff), Dst: Xensourc_2c:58:13 (00:16:3e:2c:58:13)
- Internet Protocol Version 4, Src: 150.223.56.35, Dst: 172.28.48.25
- Transmission Control Protocol, Src Port: 49511, Dst Port: 65230, Seq: 149, Ack: 1181, Len: 182
- Source Port: 49511
- Destination Port: 65230
- [Stream index: 180]
- [Conversation completeness: Complete, WITH_DATA (63)]
- [TCP Segment Len: 182]
- Sequence Number: 149 (relative sequence number)
- Sequence Number (raw): 860961835
- [Next Sequence Number: 331 (relative sequence number)]
- Acknowledgment Number: 1181 (relative ack number)
- Acknowledgment number (raw): 829453010
- 0101 .... = Header Length: 20 bytes (5)
- Flags: 0x018 (PSH, ACK)
- Window: 6143
- [Calculated window size: 1572608]
- [Window size scaling factor: 256]
- Checksum: 0x1f91 [unverified]
- [Checksum Status: Unverified]
- Urgent Pointer: 0
- [Timestamps]
- [SEQ/ACK analysis]
- TCP payload (182 bytes)
- Transport Layer Security
- No. Time Source Destination Protocol Length Info
- 4722 3907.282470 150.223.56.35 172.28.48.25 TLSv1.2 187 Application Data
- Frame 4722: 187 bytes on wire (1496 bits), 187 bytes captured (1496 bits) on interface \Device\NPF_{CEB012EB-97C5-44ED-83D5-F65B8A3CE223}, id 0
- Ethernet II, Src: ee:ff:ff:ff:ff:ff (ee:ff:ff:ff:ff:ff), Dst: Xensourc_2c:58:13 (00:16:3e:2c:58:13)
- Internet Protocol Version 4, Src: 150.223.56.35, Dst: 172.28.48.25
- Transmission Control Protocol, Src Port: 49511, Dst Port: 65230, Seq: 331, Ack: 1288, Len: 133
- Source Port: 49511
- Destination Port: 65230
- [Stream index: 180]
- [Conversation completeness: Complete, WITH_DATA (63)]
- [TCP Segment Len: 133]
- Sequence Number: 331 (relative sequence number)
- Sequence Number (raw): 860962017
- [Next Sequence Number: 464 (relative sequence number)]
- Acknowledgment Number: 1288 (relative ack number)
- Acknowledgment number (raw): 829453117
- 0101 .... = Header Length: 20 bytes (5)
- Flags: 0x018 (PSH, ACK)
- Window: 6142
- [Calculated window size: 1572352]
- [Window size scaling factor: 256]
- Checksum: 0x9948 [unverified]
- [Checksum Status: Unverified]
- Urgent Pointer: 0
- [Timestamps]
- [SEQ/ACK analysis]
- TCP payload (133 bytes)
- Transport Layer Security
- No. Time Source Destination Protocol Length Info
- 4727 3907.318009 150.223.56.35 172.28.48.25 TLSv1.2 731 Application Data
- Frame 4727: 731 bytes on wire (5848 bits), 731 bytes captured (5848 bits) on interface \Device\NPF_{CEB012EB-97C5-44ED-83D5-F65B8A3CE223}, id 0
- Ethernet II, Src: ee:ff:ff:ff:ff:ff (ee:ff:ff:ff:ff:ff), Dst: Xensourc_2c:58:13 (00:16:3e:2c:58:13)
- Internet Protocol Version 4, Src: 150.223.56.35, Dst: 172.28.48.25
- Transmission Control Protocol, Src Port: 49511, Dst Port: 65230, Seq: 464, Ack: 1533, Len: 677
- Source Port: 49511
- Destination Port: 65230
- [Stream index: 180]
- [Conversation completeness: Complete, WITH_DATA (63)]
- [TCP Segment Len: 677]
- Sequence Number: 464 (relative sequence number)
- Sequence Number (raw): 860962150
- [Next Sequence Number: 1141 (relative sequence number)]
- Acknowledgment Number: 1533 (relative ack number)
- Acknowledgment number (raw): 829453362
- 0101 .... = Header Length: 20 bytes (5)
- Flags: 0x018 (PSH, ACK)
- Window: 6147
- [Calculated window size: 1573632]
- [Window size scaling factor: 256]
- Checksum: 0xeab5 [unverified]
- [Checksum Status: Unverified]
- Urgent Pointer: 0
- [Timestamps]
- [SEQ/ACK analysis]
- TCP payload (677 bytes)
- Transport Layer Security
- No. Time Source Destination Protocol Length Info
- 4786 3908.345344 150.223.56.35 172.28.48.25 TCP 60 49511 → 65230 [FIN, ACK] Seq=1141 Ack=1618 Win=1573632 Len=0
- Frame 4786: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) on interface \Device\NPF_{CEB012EB-97C5-44ED-83D5-F65B8A3CE223}, id 0
- Ethernet II, Src: ee:ff:ff:ff:ff:ff (ee:ff:ff:ff:ff:ff), Dst: Xensourc_2c:58:13 (00:16:3e:2c:58:13)
- Internet Protocol Version 4, Src: 150.223.56.35, Dst: 172.28.48.25
- Transmission Control Protocol, Src Port: 49511, Dst Port: 65230, Seq: 1141, Ack: 1618, Len: 0
- Source Port: 49511
- Destination Port: 65230
- [Stream index: 180]
- [Conversation completeness: Complete, WITH_DATA (63)]
- [TCP Segment Len: 0]
- Sequence Number: 1141 (relative sequence number)
- Sequence Number (raw): 860962827
- [Next Sequence Number: 1142 (relative sequence number)]
- Acknowledgment Number: 1618 (relative ack number)
- Acknowledgment number (raw): 829453447
- 0101 .... = Header Length: 20 bytes (5)
- Flags: 0x011 (FIN, ACK)
- Window: 6147
- [Calculated window size: 1573632]
- [Window size scaling factor: 256]
- Checksum: 0x130e [unverified]
- [Checksum Status: Unverified]
- Urgent Pointer: 0
- [Timestamps]
- [SEQ/ACK analysis]
复制代码
|
-
-
buhuo.zip
3.11 MB, 下载次数: 1, 下载积分: 金钱 -1
wireshark捕获数据
|