2018-06-22
Ðû²¼Ê±¼ä 2018-06-22ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º |
HTTP_ºóÃÅ_Win32.Kazuar_ÅþÁ¬ |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËKazuar¡£KazuarÊÇAPT×éÖ¯Turla¿ª·¢Ê¹ÓõÄÒ»¸öºóÃÅ£¬¹¦Ð§ºÜÊÇÇ¿Ê¢£¬ÔËÐкóÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£ |
¸üÐÂʱ¼ä£º |
20180622 |
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
ÊÂÎñÃû³Æ£º |
TCP_ºóÃÅ_Win32.Duuzer(HiddenCobra)_ÅþÁ¬ |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDuuzer¡£DuuzerÊÇAPT×éÖ¯Hidden CobraËùʹÓõĺóÃÅ£¬¹¦Ð§ºÜÊÇÇ¿Ê¢¡£ÔËÐк󣬿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£ |
¸üÐÂʱ¼ä£º |
20180622 |
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
ÊÂÎñÃû³Æ£º |
TCP_Malware_VPNFilter_GetCC |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½VPNFilterÊÔͼͨ¹ýSYNËíµÀ¼¼Êõ»ñÈ¡C&CµÄIPµØµã¡£¸Ã¶ñÒâÈí¼þͨ¹ýʹÓ÷ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽµÈÎïÁªÍø×°±¸Îó²î¾ÙÐÐÆÕ±éµÄѬȾºÍÈö²¥¡£ |
¸üÐÂʱ¼ä£º |
20180622 |
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
ÊÂÎñÃû³Æ£º |
TCP_Malware_Akdoor.R228914_ÅþÁ¬·þÎñÆ÷ |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½Akdoor.R228914ÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£¶ñÒâÈí¼þAkdoor.R228914ÊÇÒ»¸ö¼òÆӵĺóÃÅ£¬Í¨¹ýÏÂÁîÌáÐÑ·ûÖ´ÐÐÏÂÁî¡£ ËüÓÐÒ»¸öÆæÒìµÄÏÂÁîºÍ¿ØÖÆÐÒé¡£ |
¸üÐÂʱ¼ä£º |
20180622 |
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
ÊÂÎñÃû³Æ£º |
TCP_ľÂíºóÃÅ_Win32.Sisfader_ÅþÁ¬ |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËSisfader¡£SisfaderÊÇÒ»¸öºóÃÅ£¬¹¦Ð§ºÜÊÇÇ¿Ê¢¡£ÔËÐк󣬿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£ |
¸üÐÂʱ¼ä£º |
20180622 |
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
ÊÂÎñÃû³Æ£º |
TCP_GPON¼Òͥ·ÓÉÆ÷Çå¾²Îó²î[CVE-2018-10562] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýGPON¼Òͥ·ÓÉÆ÷Öб£´æµÄÇå¾²Îó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£Dasan GPONÊǺ«¹úDasan¹«Ë¾µÄÒ»¿î¼ÒÓ÷ÓÉÆ÷²úÆ·¡£Dasan GPON¼Òͥ·ÓÉÆ÷Öб£´æÇå¾²Îó²î¡£¹¥»÷Õß¿Éͨ¹ýÏò×°±¸µÄí§ÒâURLÌí¼Ó¡®?images¡¯Ê¹ÓøÃÎó²îÈƹýÉí·ÝÑéÖ¤¡£Dasan GPON¼Òͥ·ÓÉÆ÷Öб£´æÏÂÁî×¢ÈëÎó²î£¬¸ÃÎó²îÔ´ÓÚÓû§Ôٴλá¼û/diag.htmlÒ³Ãæʱ·ÓÉÆ÷½«ÒòÌØÍø°ü̽Ë÷Æ÷µÄЧ¹ûÉúÑÄÔÚ/tmpÖв¢½«Ëü´«Êä¸øÓû§¡£¹¥»÷Õß¿Éͨ¹ýÏòGponForm/diag_Form URI·¢ËÍ´øÓС®dest_host¡¯²ÎÊýµÄdiag_action=pingÇëÇóʹÓøÃÎó²îÖ´ÐÐÏÂÁî²¢¼ìË÷Êä³ö¡£muhstik.scanner »áÌᳫ¸ÃÎó²îɨÃ裬ʹÓøÃÎó²îÆÈʹGPONÒ׸Ð×°±¸Ïò±¨¸æ·þÎñÆ÷»ã±¨×´Ì¬¡£ |
¸üÐÂʱ¼ä£º |
20180622 |
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
ÊÂÎñÃû³Æ£º |
HTTP_ElasticSearch_ÏÂÁîÖ´ÐÐÎó²î[CVE-2014-3120] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½ÊÔͼͨ¹ýʹÓÃElasticSearchÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¾ÙÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearchÖ§³Ö´«È붯̬¾ç±¾£¨MVEL£©À´Ö´ÐÐһЩÖØ´óµÄ²Ù×÷£¬¶øMVEL¿ÉÖ´ÐÐJava´úÂ룬¹¥»÷ÕßʹÓøÃÎó²î¿ÉÒÔÔÚElasticSearch·þÎñÆ÷ÖÐÖ´ÐÐí§ÒâJava´úÂë»òÏÂÁî¡£ |
¸üÐÂʱ¼ä£º |
20180622 |
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
ÊÂÎñÃû³Æ£º |
HTTP_ElasticSearch_ÏÂÁîÖ´ÐÐÎó²î[CVE-2015-1427] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½ÊÔͼͨ¹ýʹÓÃElasticSearchÔ¶³ÌÃüÁîÖ´ÐÐÎó²î¾ÙÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearchÖ§³Ö´«È붯̬¾ç±¾£¨Groovy£©À´Ö´ÐÐһЩÖØ´óµÄ²Ù×÷£¬¶øGroovy¿ÉÖ´ÐÐJava´úÂë¡£ElasticSearchÔÚʹÓÃGroovyÓïÑÔÖ´ÐÐÏÂÁîʱ´æÔÚɳºÐ»úÖÆ£¬µ«¹¥»÷ÕßÈÔ¿ÉÒÔʹÓÃÎó²îÈƹýɳºÐÔÚElasticSearch·þÎñÆ÷ÖÐÖ´ÐÐí§ÒâJava´úÂë»òÏÂÁî¡£ |
¸üÐÂʱ¼ä£º |
20180622 |
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
ÊÂÎñÃû³Æ£º |
HTTP_elasticsearch-head_Ŀ¼´©Ô½Îó²î[CVE-2015-3337] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½ÊÔͼͨ¹ýʹÓÃElasticSearch head²å¼þĿ¼´©Ô½Îó²î¾ÙÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î¶ÁÈ¡µ½²Ù×÷ϵͳÉϵÄí§ÒâÎļþ¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearch head²å¼þ±£´æĿ¼´©Ô½Îó²î£¬¹¥»÷ÕßʹÓøÃÎó²î¿É¶ÁÈ¡²Ù×÷ϵͳÉϵÄí§ÒâÎļþ¡£ |
¸üÐÂʱ¼ä£º |
20180622 |
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
ÊÂÎñÃû³Æ£º |
HTTP_ElasticSearch_Ŀ¼´©Ô½Îó²î[CVE-2015-5531] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½ÊÔͼͨ¹ýʹÓÃElasticSearchĿ¼´©Ô½Îó²î¾ÙÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î¶ÁÈ¡µ½²Ù×÷ϵͳÉϵÄí§ÒâÎļþ¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearch±£´æĿ¼´©Ô½Îó²î£¬¹¥»÷ÕßʹÓøÃÎó²î¿É¶ÁÈ¡²Ù×÷ϵͳÉϵÄí§ÒâÎļþ¡£ |
¸üÐÂʱ¼ä£º |
20180622 |
ĬÈÏÐж¯£º |
ÑïÆú |