2020-04-07

Ðû²¼Ê±¼ä 2020-04-07

ÐÂÔöÊÂÎñ



ÊÂÎñÃû³Æ£º

TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMBÎó²îɨÃè[MS17-010]_ɨÃèÓÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐMS17-010Îó²îɨÃèµÄÐÐΪ.

Microsoft WindowsÊÇ΢ÈíÐû²¼µÄºÜÊÇÊ¢ÐеIJÙ×÷ϵͳ¡£

ÈôÊǹ¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;­È«ÐĽṹµÄ»ûÐÎÇëÇó°ü£¬¿ÉÒÔ»ñÈ¡Ä¿µÄ·þÎñÆ÷µÄϵͳȨÏÞ£¬²¢ÇÒÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£

¸üÐÂʱ¼ä£º

20200407










ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_FakeSanforUD_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËRarog¡£

ÉîÐÅ·þVPN¿Í»§¶Ë±£´æÎó²î£¬ÔÚÉý¼¶Ê±»áÏÂÔØÖ´ÐÐÃûΪSangforUD.exeµÄ¸üгÌÐò¡£µ«VPN¿Í»§¶Ë½ö¶ÔSangforUD.exe×öÁ˼òÆӵİ汾±ÈÕÕ£¬Ã»ÓÐ×öÈκεÄÇå¾²¼ì²é¡£APT×éÖ¯Darkhotel¹¥ÆÆÁËVPN·þÎñÆ÷£¬¸Ä¶¯Éý¼¶ÉèÖÃÎļþ²¢°ÑSangforUD.exeÌ滻Ϊ¶ñÒâµÄºóÃÅFakeSanforUD¡£

FakeSanforUDÊÇÒ»¸öºóÃÅ£¬Í¨¹ýÏÂÔØÖ´ÐÐshellcode£¬×îÖÕÏÂÔؽ¹µãµÄºóÃŶñÒâ×é¼þthinmon.dll¡£½¹µãºóÃÅ×é¼þthinmon.dll»á½âÃÜÔƶËÏ·¢µÄÁíÍâÒ»¸ö¼ÓÃÜÎļþSangfor_tmp_1.dat£¬ÒÔ¼ÓÔØ¡¢Ïß³ÌÆô¶¯¡¢×¢ÈëÀú³Ì3ÖÖ·½·¨ÖеÄÒ»ÖÖÆô¶¯datÎļþ £¬×îÖÕÓÉdatÎļþʵÏÖÓë·þÎñÆ÷½»»¥Ö´ÐжñÒâ²Ù×÷¡£

¸üÐÂʱ¼ä£º

20200407















ÊÂÎñÃû³Æ£º

TCP_Metasploit_ÄäÃû¹ÜµÀɨÃè

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓöÔÄ¿µÄÖ÷»úʹÓÃMetasploitͨ¹ýSMBЭÒé»ñÈ¡ÅÌËã»úÐÅÏ¢µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200407








ÊÂÎñÃû³Æ£º

TCP_SMB_NMAPɨÃè

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓöÔÄ¿µÄÖ÷»úʹÓÃNMAPͨ¹ýSMBЭÒé»ñÈ¡ÅÌËã»úÐÅÏ¢µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200407









ÊÂÎñÃû³Æ£º

TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMBÎó²îɨÃè[MS17-010]_ɨÃèÎÞÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐMS17-010Îó²îɨÃèµÄÐÐΪ.

Microsoft WindowsÊÇ΢ÈíÐû²¼µÄºÜÊÇÊ¢ÐеIJÙ×÷ϵͳ¡£

ÈôÊǹ¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;­È«ÐĽṹµÄ»ûÐÎÇëÇó°ü£¬¿ÉÒÔ»ñÈ¡Ä¿µÄ·þÎñÆ÷µÄϵͳȨÏÞ£¬²¢ÇÒÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£

¸üÐÂʱ¼ä£º

20200407










ÊÂÎñÃû³Æ£º

TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_DoublePulsarºóÃÅ_ɨÃè»òÖ²ÈëºóÃÅ_ÒÉËÆÖ´ÐлòжÔØ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Í¨¹ýMS17-010µÄÎó²îÖ²ÈëDoublePulsarºóÃŵÄÐÐΪ¡£

Microsoft WindowsÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾Ðû²¼µÄһϵÁвÙ×÷ϵͳ¡£SMBv1 serverÊÇÆäÖеÄÒ»¸ö·þÎñÆ÷ЭÒé×é¼þ¡£DoublePulsarÊÇÒ»¸öºóÃųÌÐò£¬ÓÃÓÚÔÚÒÑѬȾµÄϵͳÉÏ×¢ÈëºÍÔËÐжñÒâ´úÂë¡£

Microsoft WindowsÖеÄSMBv1·þÎñÆ÷±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖƵÄÊý¾Ý°üʹÓøÃÎó²îÖ²Èë»òɨÃèDoublePulsarºóÃÅ¡£

¸üÐÂʱ¼ä£º

20200407













ÊÂÎñÃû³Æ£º

TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_DoublePulsarºóÃÅ_ɨÃè»òÖ²ÈëºóÃÅ_ÒÉËÆping

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Í¨¹ýMS17-010µÄÎó²îÖ²ÈëDoublePulsarºóÃŵÄÐÐΪ¡£

Microsoft WindowsÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾Ðû²¼µÄһϵÁвÙ×÷ϵͳ¡£SMBv1 serverÊÇÆäÖеÄÒ»¸ö·þÎñÆ÷ЭÒé×é¼þ¡£DoublePulsarÊÇÒ»¸öºóÃųÌÐò£¬ÓÃÓÚÔÚÒÑѬȾµÄϵͳÉÏ×¢ÈëºÍÔËÐжñÒâ´úÂë¡£

Microsoft WindowsÖеÄSMBv1·þÎñÆ÷±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖƵÄÊý¾Ý°üʹÓøÃÎó²îÖ²ÈëDoublePulsarºóÃÅ¡£

¸üÐÂʱ¼ä£º

20200407













ÊÂÎñÃû³Æ£º

TCP_DrayTek_Ô¤Éí·ÝÑéÖ¤ÏÂÁî×¢ÈëÎó²î[CVE-2020-8515]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½¹¥»÷ÕßʹÓÃDrayTekÔ¤Éí·ÝÑéÖ¤´¦µÄÁ½´¦ÏÂÁî×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£DrayTekÊÇÒ»¼ÒÔÚÖйúÉú²ú·À»ðǽ£¬VPN×°±¸£¬Â·ÓÉÆ÷£¬WLAN×°±¸µÈµÄÖÆÔìÉÌ¡£¸ÃÎó²îÔ´ÓÚ/cgi-bin/mainfunction.cgi³ÌÐòδ׼ȷ¹ýÂËkeyPath×ֶκÍrtick×Ö¶ÎÆäÖеÄÌØÊâ×Ö·û£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î²»¾­ÓÉÉí·ÝÑéÖ¤ÒÔrootȨÏÞÖ´ÐдúÂë¡£

¸üÐÂʱ¼ä£º

20200407










ÊÂÎñÃû³Æ£º

HTTP_ZyXEL_Ô¤Éí·ÝÑéÖ¤ÏÂÁî×¢ÈëÎó²î[CVE-2020-9054]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýZyXEL×°±¸ÖеÄÔ¤Éí·ÝÑéÖ¤µÄÏÂÁî×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20200407








ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMBÎó²îдÈëshellcode[MS17-010]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP¶ÔÄ¿µÄÖ÷»úʹÓÃMS17-010Îó²îдÈëshellcodeµÄÐÐΪ.

Microsoft WindowsÊÇ΢ÈíÐû²¼µÄºÜÊÇÊ¢ÐеIJÙ×÷ϵͳ¡£

ÈôÊǹ¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;­È«ÐĽṹµÄ»ûÐÎÇëÇó°ü£¬¿ÉÒÔ»ñÈ¡Ä¿µÄ·þÎñÆ÷µÄϵͳȨÏÞ£¬²¢ÇÒÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£

¸üÐÂʱ¼ä£º

20200407










ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Microsoft_SMBv3_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-0796]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»ú¿ÉÄÜÕýÔÚ¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐCVE-2020-0796Îó²îʹÓõÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200407








ÊÂÎñÃû³Æ£º

UDP_½©Ê¬ÍøÂç_Mozi.P2PBotnet_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½½©Ê¬ÍøÂçMoziÊÔͼºÍPeerͨѶ¡£ÓÉÓÚÊÇ»ùÓÚP2PЭÒ飬ԴIPºÍÄ¿µÄIPËùÔÚµÄÖ÷»ú¿ÉÄܶ¼±»Ö²ÈëÁ˽©Ê¬ÍøÂçMozi¡£

MoziÊÇÒ»¸ö»ùÓÚP2PЭÒéµÄ½©Ê¬ÍøÂ磬Ö÷ÒªÖ§³ÖµÄ¹¦Ð§Îª£ºDDoS¹¥»÷¡¢ÍøÂçBotÐÅÏ¢¡¢Ö´ÐÐÖ¸¶¨URLµÄpayload¡¢´ÓÖ¸¶¨µÄURL¸üÐÂÑù±¾¡¢Ö´ÐÐϵͳ»ò×Ô½ç˵ÏÂÁî¡£

¸üÐÂʱ¼ä£º

20200407










ÊÂÎñÃû³Æ£º

TCP_Tomcat/Coldfusion_AJP13_í§ÒâÎļþ¶ÁÈ¡[CVE-2020-1938/CVE-2020-3761/CVE-2020-3794]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃTomcat/Coldfusion_AJP13í§ÒâÎļþ¶ÁÈ¡Îó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200407