2019-09-03

Ðû²¼Ê±¼ä 2019-09-02

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Jenkins_Ansible_Tower²å¼þÐÅϢй¶Îó²î[CVE-2019-10310]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_Jenkins_Ansible_Tower²å¼þÐÅϢй¶Îó²î[CVE-2019-10310]¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ÑïÆú










ÊÂÎñÃû³Æ£º

HTTP_ÖйúÒϽ£_AntSword_webshell_ľÂíÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¸ÃÊÂÎñÅú×¢Ô´IPµØµãÖ÷»úÉϵÄÖйúÒϽ£¿£¿£¿£¿£¿£¿Í»§¹æÔòÔÚÏòÄ¿µÄIPµØµãÖ÷»úÉϵÄwebshellЧÀÍÆ÷¶Ë·¢³öÅþÁ¬ÏÂÁî¡£¡£¡£¡£

webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¡£¼òÆÓ˵£¬£¬ £¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬ £¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬ £¬£¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬ £¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬ £¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬ £¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬ £¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬ £¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬ £¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬ £¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ÑïÆú

















ÊÂÎñÃû³Æ£º

HTTP_SCADA_PcVue_Activex_Control²»Çå¾²ÒªÁìŲÓôúÂëÖ´ÐÐÎó²î

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃPcVue Activex¿Ø¼þ²»Çå¾²ÒªÁìŲÓôúÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£

PcVue ActiveX¿Ø¼þÖб£´æ¶à¸ö²»Çå¾²ÒªÁìŲÓÃÎó²î¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ͨ¹ý













ÊÂÎñÃû³Æ£º

HTTP_SCADA_PcVue_Activex_Control²»Çå¾²ÒªÁìŲÓÃÎó²î(SaveObject)

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃPcVue Activex¿Ø¼þ²»Çå¾²ÒªÁìŲÓôúÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£

PcVue ActiveX¿Ø¼þÖб£´æ¶à¸ö²»Çå¾²ÒªÁìŲÓÃÎó²î¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ͨ¹ý


ÊÂÎñÃû³Æ£º

HTTP_SCADA_PcVue_Activex_Control²»Çå¾²ÒªÁìŲÓÃÎó²î(GetExtendedColor)

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃPcVue Activex¿Ø¼þ²»Çå¾²ÒªÁìŲÓôúÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£

PcVue ActiveX¿Ø¼þÖб£´æ¶à¸ö²»Çå¾²ÒªÁìŲÓÃÎó²î¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ͨ¹ý


ÐÞ¸ÄÊÂÎñ

ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_Win32.Neutrino_ÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅNeutrino¡£¡£¡£¡£

NeutrinoÊÇÒ»¸ö½©Ê¬ÍøÂ磬£¬ £¬£¬¹¦Ð§ºÜÊÇǿʢ£¬£¬ £¬£¬ÔËÐкó¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_½©Ê¬ÍøÂç_MiraiXMiner_ÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½½©Ê¬ÍøÂçMiraiXMinerÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMiraiXMiner¡£¡£¡£¡£

MiraiXMinerÊÇÒ»¸öÈÔÈ»»îÔ¾×ŵĽ©Ê¬ÍøÂ磬£¬ £¬£¬ÈÚºÏÁ˶àÖÖÒÑÖª²¡¶¾¼Ò×壬£¬ £¬£¬°üÀ¨Mirai¡¢MyKings¡¢Ô¶¿Ø¡¢ÍÚ¿óµÈ¡£¡£¡£¡£Ê¹ÓÃÓÀºãÖ®À¶Îó²î¡¢±Õ·µçÊÓÎïÁªÍø×°±¸Îó²î¡¢MSSQLÎó²î¡¢RDP±¬ÆÆºÍTelnet±¬ÆÆµÈ·½·¨Èö²¥×ÔÉí¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_Malware_BADNEWS(Patchwork)_ÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBADNEWS¡£¡£¡£¡£

BADNEWS¶ñÒâÈí¼þ¼Ò×å³äµ±ºóÃÅ£¬£¬ £¬£¬Í¨¹ýHTTP¾ÙÐÐͨѶ¡£¡£¡£¡£ Ïò¹¥»÷ÕßÌṩÁËÐí¶àÏÂÁ£¬ £¬£¬ÆäÖаüÀ¨ÏÂÔØºÍÖ´Ðи½¼ÓÐÅÏ¢£¬£¬ £¬£¬ÉÏ´«¸ÐÐËȤµÄÎĵµÒÔ¼°½ØÈ¡×ÀÃæµÄ½ØÍ¼¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HHTTP_ľÂí_ArtraDownloader(ÂûÁ黨)_ÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDownloader.Wills¡£¡£¡£¡£

Downloader.WillsÊÇÒ»¸öÏÂÔØÕߣ¬£¬ £¬£¬ÔËÐк󣬣¬ £¬£¬¿ÉÒÔÏÂÔØÆäËü¶ñÒâÑù±¾£¬£¬ £¬£¬ÈçºóÃŵȡ£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Virut.IrcBot_¿ÉÒɱäÖÖ_ÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíVirut¡£¡£¡£¡£

VirutÊÇÒ»¸ö»ùÓÚircЭÒéµÄ½©Ê¬ÍøÂ磬£¬ £¬£¬ÔËÐкóÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£»£»£»£» £»£»¹¿ÉÒÔÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_IBM_WebSphere_Java·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2015-7450]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃIBM WebSphere Java·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£

WebSphere ÊÇIBM¹«Ë¾¿ª·¢µÄÖÐÐļþ»ù´¡Éèʩƽ̨¡£¡£¡£¡£WebSphere 7 °æ±¾ÔÚ¿ª·¢ÖÐʹÓÃÁË Apache Commons Collections ¿âÖÐµÄ InvokerTransformer À࣬£¬ £¬£¬¸ÃÀà±£´æ Java ·´ÐòÁл¯Îó²î¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄ Java ÐòÁл¯¹¤¾ß£¬£¬ £¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

TCP_WebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-3191]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼʹÓÃWebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20190903

ĬÈÏÐж¯£º

ÑïÆú