2018-07-13
Ðû²¼Ê±¼ä 2018-07-13ÐÂÔöʼþ
ʼþÃû³Æ£º |
HTTP_ľÂíºóÃÅ_Smurf.fileUpload(Confucius)_Á¬½Ó |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½SmurfÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËSmurf¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
|
|
ʼþÃû³Æ£º |
TCP_ľÂí_Win32.TrickBot_NetworkCollectorModule |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíTrickBot¡£ TrickBotÊÇÒ»¸ö¹¦Ð§Ç¿´óµÄÇÔÃÜľÂí¡£TrickbotÒøÐÐľÂíÖаüÂÞNetwork Collector Module£¬¸ÃÄ£¿é¿ÉÒÔËѼ¯Óû§ÐÅÏ¢ÉÏ´«ÖÁ·þÎñÆ÷¡£ ¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
|
|
ʼþÃû³Æ£º |
HTTP_ľÂíºóÃÅ_Win32.LoadMoney_Á¬½Ó |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½LoadmoneyÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËLoadmoney¡£ LoadmoneyÊÇÒ»¸öľÂíÏÂÔØÕߣ¬ÔËÐкó»áÏÂÔØÆäËü¶ñÒâÑù±¾¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
ʼþÃû³Æ£º |
HTTP_Malware_KardonLoader_Á¬½Ó·þÎñÆ÷ |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½Kardon LoaderÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËKardon Loader¡£ Kardon LoaderÊÇÒ»¸öÈ«¹¦Ð§µÄÏÂÔØÆ÷£¬¿ÉÒÔÏÂÔØºÍ°²×°ÆäËû¶ñÒâÈí¼þ¡£ÀýÈç£¬ÒøÐÐľÂí/ƾ֤ÇÔÈ¡Èí¼þµÈ¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
ʼþÃû³Æ£º |
HTTP_ľÂíºóÃÅ_DanaBot.Downloader_Á¬½Ó |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½DanaBotÊÔͼÏÂÔØºËÐÄMain dll×é¼þ¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDanaBot¡£ DanaBotÊÇÒ»¸öÒøÐÐľÂí£¬°üÂÞÒ»¸öÏÂÔØ×é¼þ¡£ÏÂÔØ×é¼þÔËÐкó»áÏÂÔØºËÐÄMain dll×é¼þ¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
ʼþÃû³Æ£º |
TCP_ľÂíºóÃÅ_DanaBot_Á¬½Ó |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½DanaBotµÄMain dllÊÔͼÏÂÔØÆäËü×é¼þ¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDanaBot¡£ DanaBotÊÇÒ»¸öÒøÐÐľÂí£¬°üÂÞÒ»¸öÏÂÔØ×é¼þ¡£ÏÂÔØ×é¼þÔËÐкó»áÏÂÔØºËÐÄMain dll×é¼þ¡£Main dllÏÂÔØVNC¡¢Stealer¡¢SnifferµÈ×é¼þ£¬Íê³ÉÇÔÃÜ¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
ʼþÃû³Æ£º |
TCP_ºóÃÅ_PoisonIvy_Keepalive_Á¬½Ó2 |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½PoisonIvyµÄÐÄÌø°üÊý¾Ý¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPoison Ivy¡£ Poison IvyÊÇÒ»¸ö±»¹ã·ºÓ¦ÓõÄÔ¶³Ì¿ØÖƹ¤¾ß£¬ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
ʼþÃû³Æ£º |
HTTP_DVR_Ó²Å̼Ïñ»ú_µÇÂ¼ÈÆ¹ý©¶´[CVE-2018-9995] |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ÍøÂçÉ豸¹¥»÷ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃDVRÓ²Å̼Ïñ»úµÇÂ¼ÈÆ¹ý©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼͨ¹ýÀûÓÃDVRÈÆ¹ýµÇ¼©¶´µÇ¼µ½Ó²Å̼Ïñ»úºǫ́£¬·Ç·¨Ê¹ÓÃÊÓÆµ¼à¿Ø×ÊÔ´¡£ DVRÈ«³ÆDigital Video Recorder(Ó²Å̼Ïñ»ú)£¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеÄÖØÒª×é³É²¿ÃÅ¡£¼ì²âµ½Óжà¿îDVRÉ豸´æÔÚµÇÂ¼ÈÆ¹ý©¶´£¬¹¥»÷Õßͨ¹ýÐÞ¸ÄCookie:uid=adminÖ®ºó²¢·ÃÎÊÌØ¶¨DVRµÄ¿ØÖÆÃæ°å£¬·µ»Ø´ËÉ豸µÄÃ÷ÎĹÜÀíԱƾ֤¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
ʼþÃû³Æ£º |
HTTP_anni°²ÄáXVR_ͬÖáÓ²Å̼Ïñ»ú_ÃÜÂëй¶©¶´ |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ÍøÂçÉ豸¹¥»÷ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃXVRͬÖáÓ²Å̼Ïñ»úÃÜÂëй¶©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼͨ¹ýÀûÓÃXVRÃÜÂëй¶©¶´£¬½ø¶øµÇ¼µ½XVRºǫ́£¬·Ç·¨Ê¹ÓÃÊÓÆµ¼à¿Ø×ÊÔ´¡£ XVRͬÖáÓ²Å̼Ïñ»ú£¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеÄÖØÒª×é³É²¿ÃÅ¡£¼ì²âµ½anni°²ÄáÓжà¿îXVRÉ豸´æÔÚÃÜÂëй¶£¬¹¥»÷Õßͨ¹ý·ÃÎÊÖ¸¶¨µÄURL£¬XVRÉ豸¼´¿É·µ»ØµÇ¼ÃÜÂë¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
ʼþÃû³Æ£º |
HTTP_Ê©Ä͵Â_Åɶû¸ßϵÁÐÉãÏñ»ú_Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ÍøÂçÉ豸¹¥»÷ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÊ©Ä͵ÂÅɶû¸ßϵÁÐÉãÏñ»úÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼͨ¹ýÔ¶³ÌÖ´ÐÐÈÎÒâÃüÁʵÑéͨ¹ý¸ÃÉ豸½øÐÐÍÚ¿ó»òÕßDoS¹¥»÷µÈ·Ç·¨ÐÐΪ¡£ Ê©Ä͵¹«Ë¾ÆìϵÄÅɶû¸ßϵÁÐÉãÏñ»úͨ³£±»ÓÃÓÚÖÖÖÖÉÌÒµºÍ¹¤Òµ¼à¿ØÁìÓò£¬¾ßÓнϺõĻ·¾³ÊÊÓ¦ÐÔ¡£PelcoϵÁÐÉãÏñ»ú´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ýPOSTÇëÇóÖеÄenable_leds²ÎÊý×¢ÈëÈÎÒâ´úÂë»òÃüÁ½ø¶øÍêÈ«¿ØÖÆÉãÏñ»ú¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
ʼþÃû³Æ£º |
HTTP_NETGEAR_DGN1000_Ô¶³ÌÃüÁîÖ´ÐЩ¶´ |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ÍøÂçÉ豸¹¥»÷ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÃÀ¹úÍø¼þNETGEAR DGN1000ϵÁзÓÉÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼͨ¹ýÔ¶³ÌÖ´ÐÐÈÎÒâÃüÁʵÑéͨ¹ý¸ÃÉ豸½øÐÐÍÚ¿ó»òÕßDoS¹¥»÷µÈ·Ç·¨ÐÐΪ¡£ ÃÀ¹úÍø¼þNETGEARÊÇÃÀ¹úÖªÃûµÄÆóÒµÉ豸ÌṩÉÌ£¬NETGEAR DGN1000ϵÁзÓÉÆ÷¹ã·º±»²¿ÊðÔÚÈ«Çò¸÷´ó»¥ÁªÍø¹«Ë¾¼°¼ÒÍ¥¡£DGN1000ϵÁзÓÉÆ÷´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ýURLÖеÄcmd²ÎÊý×¢ÈëÈÎÒâ´úÂë»òÃüÁ½ø¶øÍêÈ«¿ØÖÆÂ·ÓÉÆ÷¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
ʼþÃû³Æ£º |
HTTP_NETGEAR_JWNR_ÃÜÂëй¶©¶´ |
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
Äþ¾²ÀàÐÍ£º |
ÍøÂçÉ豸¹¥»÷ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃNETGEAR JWNRϵÁзÓÉÆ÷ÃÜÂëй¶©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼͨ¹ýÀûÓÃJWNRϵÁзÓÉÆ÷ÃÜÂëй¶©¶´£¬½ø¶øµÇ¼µ½Â·ÓÉÆ÷ºǫ́£¬ÍêÈ«¿ØÖÆÕû¸öÍøÂç¡£ XVR ͬÖáÓ²Å̼Ïñ»ú£¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеÄÖØÒª×é³É²¿ÃÅ¡£¼ì²âµ½anni°²ÄáÓжà¿îXVRÉ豸´æÔÚÃÜÂëй¶£¬¹¥»÷Õßͨ¹ý·ÃÎÊÖ¸¶¨µÄURL£¬XVRÉ豸¼´¿É·µ»ØµÇ¼ÃÜÂë¡£ |
¸üÐÂʱ¼ä£º |
20180713 |
ĬÈÏÐж¯£º |
Åׯú |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º |
HTTP_Microsoft_Windows_HTTP_sysÔ¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2015-1635] |
||
ʼþ¼¶±ð£º |
Öм¶Ê¼þ |
||
Äþ¾²ÀàÐÍ£º |
|
||
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýMicrosoft Windows HTTP.sysÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ Http.sysÊÇ´¦ÀíHTTPÇëÇóµÄÄÚºËģʽÇý¶¯·¨Ê½¡£ HTTP.sys´íÎó½âÎö½á¹¹µÄHTTPÇëÇóʱ£¬ÔÚʵÏÖÉÏ´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÀÖ³ÉÀûÓôË©¶´ºó£¬¹¥»÷Õß¿ÉÔÚSystemÕÊ»§ÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂë¡£ |
||
¸üÐÂʱ¼ä£º |
20180713 |
||
ĬÈÏÐж¯£º |
Åׯú |