2019-11-26

Ðû²¼Ê±¼ä 2019-11-26

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_SCADA_Schneider_Electric_U.motion_Builder_ÊäÈëÑéÖ¤Îó²î[CVE-2018-7787]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃSchneider Electric U.motion BuilderÊäÈëÑéÖ¤Îó²îÀ´Ö´Ðй¥»÷µÄÐÐΪ¡£

Schneider Electric U.motion BuilderÊÇ·¨¹úÊ©Ä͵µçÆø£¨Schneider Electric£©¹«Ë¾µÄÒ»Ì××Ô¶¯»¯»úÖƹ¹½¨½â¾ö¼Æ»®¡£

Schneider Electric U.motion Builder 1.3.4֮ǰ°æ±¾Öб£´æÊäÈëÑéÖ¤Îó²î£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷµÄÑéÖ¤HTTP GETÇëÇóÖС®context¡¯²ÎÊýµÄÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îй¶Ãô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20191126














ÊÂÎñÃû³Æ£º

HTTP_LCDS_LAquis_SCADAÇå¾²Îó²î[CVE-2018-18996]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃLCDS LAquis SCADAÇå¾²Îó²îÀ´Ö´ÐÐÏÂÁîµÄÐÐΪ

LCDS LAquis SCADAÊÇ°ÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾ÝÊÕÂÞÓë¼àÊÓ¿ØÖÆ£©ÏµÍ³¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÓµÓÐͨѶÊÖÒÕµÄ×°±¸¾ÙÐÐÊý¾ÝÊÕÂÞºÍÀú³Ì¿ØÖÆ¡£

LCDS LAquis SCADA 4.1.0.3870°æ±¾Öб£´æÇå¾²Îó²î£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓоÙÐÐ׼ȷµØÊÚȨ»ò¹ýÂ˱ãÎüÊÕÁËÓû§ÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚϵͳÉÏÖ´ÐдúÂë¡£

¸üÐÂʱ¼ä£º

20191126












ÊÂÎñÃû³Æ£º

HTTP_LAquis_SCADA_HTTP²ÎÊýÏÂÁî×¢ÈëÎó²î[CVE-2018-18992]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃLAquis SCADA PAGINA TITULO HTTP²ÎÊýÏÂÁî×¢ÈëÎó²îÀ´Ö´ÐÐÏÂÁîµÄÐÐΪ¡£

LCDS LAquis SCADAÊÇ°ÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾ÝÊÕÂÞÓë¼àÊÓ¿ØÖÆ£©ÏµÍ³¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÓµÓÐͨѶÊÖÒÕµÄ×°±¸¾ÙÐÐÊý¾ÝÊÕÂÞºÍÀú³Ì¿ØÖÆ¡£

LCDS LAquis SCADA 4.1.0.3870°æ±¾Öб£´æÇå¾²Îó²î£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓоÙÐÐ׼ȷµØ¹ýÂ˱ãÎüÊÕÁËÓû§ÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚϵͳÉÏÖ´ÐдúÂë¡£

HTTPÒªÇóacompanhamentotela.lhtmlµÄPAGINA²ÎÊýºÍrelatorioindividual.lhtmlµÄÇëÇóÖеÄTITULO²ÎÊý¶¼²»ÊʺÏÏÂÁî×¢Èë×Ö·û¡£ ¹¥»÷Õß¿ÉÒÔ·¢ËÍÌØÖƵÄHTTP GET»òPOSTÇëÇó£¬ÒÔÔÚÄ¿µÄÅÌËã»úÉÏÖ´ÐÐÏÂÁî¡£

¸üÐÂʱ¼ä£º

20191119















ÊÂÎñÃû³Æ£º

TCP_Advantech_WebAccess_SCADA_BwPSLinkZip_Stack_Buffer_Overflow

[CVE-2018-7499]

Çå¾²ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃAdvantech WebAccess BwPSLinkZip »ùÓÚÕ»µÄ»º³åÇøÒç³öÎó²îÀ´Ö´ÐÐí§Òâ´úÂëµÄÐÐΪ¡£

Advantech WebAccessÊÇÑлª£¨Advantech£©¹«Ë¾µÄ²úÆ·¡£Advantech WebAccessÊÇÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý¿ØÖÆ£¬²¢ÌṩԶ³Ì¿ØÖƺÍÖÎÀí×Ô¶¯»¯×°±¸µÄ¹¦Ð§¡£WebAccess DashboardÊÇÆäÖеÄÒ»¸öÒDZí°å×é¼þ£»WebAccess Scada NodeÊÇÆäÖеÄÒ»¸ö¼à¿Ø½Úµã×é¼þ¡£WebAccess/NMSÊÇÒ»Ì×ÓÃÓÚÍøÂçÖÎÀíϵͳ£¨NMS£©µÄÍøÂçä¯ÀÀÆ÷»ù´¡Ì×¼þ¡£

¸ÃÎó²îÊÇÓÉÓÚÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´ÖƵ½BwPSLinkZip.exeµÄ¿ÍÕ»»º³åÇøÖÐʱȱÉÙ½çÏß¼ì²éËùÖ¡£

ͨ¹ý¹¹½¨ÌØÊâµÄRPCÇëÇ󣬹¥»÷Õß¿ÉÒÔÔÚWebAccessÀú³ÌµÄÉÏÏÂÎÄÖе¼ÖÂí§Òâ´úÂëÖ´ÐлòÒì³£ÖÕÖ¹¡£

¸üÐÂʱ¼ä£º

20191126



















ÐÞ¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_KG.Rat_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£

Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

KuGou.RatÊÇÒ»¸öºóÃÅ£¬ÅþÁ¬Ô¶³Ì·þÎñÆ÷£¬½ÓÊÜÖ´ÐкڿÍÖ¸Á¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£ÊÔͼ»ñÈ¡Ãô¸Ð£¬Èç¼Í¼°´¼üÐÅÏ¢£¬»ñÈ¡½¹µã´°¿ÚµÄÎÊÌâ¡£

¸üÐÂʱ¼ä£º

20191126










ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_PoisonIvy_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

Poison IvyÊÇÒ»¸öºÜÊÇÊ¢ÐеÄÔ¶³Ì¿ØÖƹ¤¾ß£¬ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20191126








ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win32.WarZoneRat_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËWarZoneRat¡£

WarZoneRatÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄÔ¶¿Ø£¬ÔËÐкó¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20191126








ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_ÓÄÁéÔ¶¿Ø¿ÉÒɱäÖÖ_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£

Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

ÓÄÁéÔ¶¿Ø³ÌÐòÊÇʹÓÃÒ»¸öƾ֤Gh0stÔ¶¿ØµÄÔ´ÂëÐ޸ĶøÀ´µÄºóÃÅ¡£ÔËÐкó¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£

¸üÐÂʱ¼ä£º

20191126










ÊÂÎñÃû³Æ£º

TUDP_ºóÃÅ_Win32.ZeroAcess_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£

Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

Win32.ZeroAcessÊÇÒ»¸öºóÃÅ£¬ÔËÐкó£¬×¢ÈëÆäËûÀú³Ì¡£ÏÂÔØÆäËû²¡¶¾»òÕßÉèÖÃÐÅÏ¢»òÕßÄ£¿éµÈ»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£

Éϱ¨¸ÃÊÂÎñÓÐÁ½ÖÖ¿ÉÄÜ£¬Ò»ÊÇÔ´Ö÷»ú±»Ñ¬È¾ÁË£¬ÅþÁ¬CC·þÎñÆ÷£»¶þÊÇZeroAcess·þÎñÆ÷¶Ëͨ¹ýshadanÊðÀí·½·¨¾ÙÐÐɨÃèÐÐΪ£¬Ö÷Òª¿´Ô´IPÊÇ·ñÊDZ¾µ¥Î»µÄIPµØµã¡£

¸üÐÂʱ¼ä£º

20191126












ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Linux.BillGates_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅBillGates¡£

BillGatesÊÇLinuxƽ̨ϵÄÒ»¸ö½©Ê¬ÍøÂ磬Ö÷Òª¹¦Ð§ÊÇÕë¶ÔÖ¸¶¨Ä¿µÄ¾ÙÐÐDDoS¹¥»÷¡£

¸üÐÂʱ¼ä£º

20191126









ÊÂÎñÃû³Æ£º

TCP_ľÂí_CoinMiner_ÅþÁ¬¿ó³ØÀÖ³É

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinMinerľÂí¡£

CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£

¸üÐÂʱ¼ä£º

20191126









ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_Win32.wingames(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅwingames¡£

wingamesÊÇÒ»¸ö¹¦Ð§ºÜÊÇÇ¿Ê¢µÄºóÃÅ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20191126








ÊÂÎñÃû³Æ£º

TCP_ľÂí_CoinMiner_ʵÑéÅþÁ¬¿ó³Ø

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinminerľÂí¡£

CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£

¸üÐÂʱ¼ä£º

20191126