2018-07-13

°ä²¼¹¦·ò 2018-07-13

ÐÂÔöÊÂÎñ

ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Smurf.fileUpload(Confucius)_ÏνÓ

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½SmurfÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËSmurf¡£¡£¡£¡£¡£¡£
SmurfÊÇAPT×éÖ¯ConfuciusʹÓõÄÇÔÈ¡ÎļþµÄľÂí £¬£¬£¬£¬£¬£¬£¬ÔËÐÐºó £¬£¬£¬£¬£¬£¬£¬ÉÏ´«¸÷ÀàÎļþµ½C&C·þÎñÆ÷ £¬£¬£¬£¬£¬£¬£¬Èçdoc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx, .csvµÈ¡£¡£¡£¡£¡£¡£  

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

TCP_ľÂí_Win32.TrickBot_NetworkCollectorModule

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíTrickBot¡£¡£¡£¡£¡£¡£ TrickBotÊÇÒ»¸öÖ°ÄÜÇ¿´óµÄÇÔÃÜľÂí¡£¡£¡£¡£¡£¡£TrickbotÒøÐÐľÂíÖÐÔ̺¬Network Collector Module £¬£¬£¬£¬£¬£¬£¬¸ÃÄ£¿éÄܹ»ÍøÂçÓû§ÐÅÏ¢ÉÏ´«ÖÁ·þÎñÆ÷¡£¡£¡£¡£¡£¡£ ¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Win32.LoadMoney_Á¬½Ó

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½LoadmoneyÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËLoadmoney¡£¡£¡£¡£¡£¡£ LoadmoneyÊÇÒ»¸öľÂíÏÂÔØÕß £¬£¬£¬£¬£¬£¬£¬ÔËÐкó»áÏÂÔØÆäËü¶ñÒâÑù±¾¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_Malware_KardonLoader_Á¬½Ó·þÎñÆ÷

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Kardon LoaderÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËKardon Loader¡£¡£¡£¡£¡£¡£ Kardon LoaderÊÇÒ»¸öȫְÄܵÄÏÂÔØÆ÷ £¬£¬£¬£¬£¬£¬£¬Äܹ»ÏÂÔØºÍ×°ÖÃÆäËû¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ÀýÈç £¬£¬£¬£¬£¬£¬£¬ÒøÐÐľÂí/ƾ֤ÇÔÈ¡Èí¼þµÈ¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_DanaBot.Downloader_ÏνÓ

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½DanaBotÊÔͼÏÂÔØÖ÷ÌâMain dll×é¼þ¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDanaBot¡£¡£¡£¡£¡£¡£ DanaBotÊÇÒ»¸öÒøÐÐľÂí £¬£¬£¬£¬£¬£¬£¬Ô̺¬Ò»¸öÏÂÔØ×é¼þ¡£¡£¡£¡£¡£¡£ÏÂÔØ×é¼þÔËÐкó»áÏÂÔØÖ÷ÌâMain dll×é¼þ¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_DanaBot_Á¬½Ó

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½DanaBotµÄMain dllÊÔͼÏÂÔØÆäËü×é¼þ¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDanaBot¡£¡£¡£¡£¡£¡£ DanaBotÊÇÒ»¸öÒøÐÐľÂí £¬£¬£¬£¬£¬£¬£¬Ô̺¬Ò»¸öÏÂÔØ×é¼þ¡£¡£¡£¡£¡£¡£ÏÂÔØ×é¼þÔËÐкó»áÏÂÔØÖ÷ÌâMain dll×é¼þ¡£¡£¡£¡£¡£¡£Main dllÏÂÔØVNC¡¢Stealer¡¢SnifferµÈ×é¼þ £¬£¬£¬£¬£¬£¬£¬ÊµÏÖÇÔÃÜ¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_PoisonIvy_Keepalive_Á¬½Ó2

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½PoisonIvyµÄÐÄÌø°üÊý¾Ý¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPoison Ivy¡£¡£¡£¡£¡£¡£ Poison IvyÊÇÒ»¸ö±»¿í·ºÓ¦ÓõÄÔ¶³Ì½ÚÔ칤¾ß £¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_DVR_Ó²Å̼Ïñ»ú_µÇÂ¼ÈÆ¹ý·ì϶[CVE-2018-9995]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ÍøÂçÉ豸¹¥»÷ 

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃDVRÓ²Å̼Ïñ»úµÇÂ¼ÈÆ¹ý·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ £¬£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýÀûÓÃDVRÈÆ¹ýµÇ¼·ì϶µÇ¼µ½Ó²Å̼Ïñ»úºó¶Ü £¬£¬£¬£¬£¬£¬£¬·¸·¨Ê¹ÓÃÊÓÆµ¼à¿Ø×ÊÔ´¡£¡£¡£¡£¡£¡£ DVRÈ«³ÆDigital Video Recorder(Ó²Å̼Ïñ»ú) £¬£¬£¬£¬£¬£¬£¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеijÁÒª×é³É²¿ÃÅ¡£¡£¡£¡£¡£¡£¼ì²âµ½Óжà¿îDVRÉ豸´æÔÚµÇÂ¼ÈÆ¹ý·ì϶ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÅú¸ÄCookie:uid=adminÖ®ºó²¢½Ó¼ûÌØ¶¨DVRµÄ½ÚÔìÃæ°å £¬£¬£¬£¬£¬£¬£¬·µ»Ø´ËÉ豸µÄÃ÷ÎÄÖÎÀíԱƾ֤¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_anni°²ÄáXVR_ͬÖáÓ²Å̼Ïñ»ú_ÃÜÂëй¶·ì϶

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ÍøÂçÉ豸¹¥»÷ 

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃXVRͬÖáÓ²Å̼Ïñ»úÃÜÂëй¶·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ £¬£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýÀûÓÃXVRÃÜÂëй¶·ì϶ £¬£¬£¬£¬£¬£¬£¬½ø¶øµÇ¼µ½XVRºó¶Ü £¬£¬£¬£¬£¬£¬£¬·¸·¨Ê¹ÓÃÊÓÆµ¼à¿Ø×ÊÔ´¡£¡£¡£¡£¡£¡£ XVRͬÖáÓ²Å̼Ïñ»ú £¬£¬£¬£¬£¬£¬£¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеijÁÒª×é³É²¿ÃÅ¡£¡£¡£¡£¡£¡£¼ì²âµ½anni°²ÄáÓжà¿îXVRÉ豸´æÔÚÃÜÂëй¶ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý½Ó¼ûÖ¸¶¨µÄURL £¬£¬£¬£¬£¬£¬£¬XVRÉ豸¼´¿É·µ»ØµÇ¼ÃÜÂë¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_Ê©Ä͵Â_Åɶû¸ßϵÁÐÉãÏñ»ú_Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ÍøÂçÉ豸¹¥»÷ 

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃÊ©Ä͵ÂÅɶû¸ßϵÁÐÉãÏñ»úÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ £¬£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýÔ¶³ÌÖ´ÐÐËÁÒâºÅÁî £¬£¬£¬£¬£¬£¬£¬³¢ÊÔͨ¹ý¸ÃÉ豸½øÐÐÍÚ¿ó»òÕßDoS¹¥»÷µÈ·¸·¨ÐÐΪ¡£¡£¡£¡£¡£¡£ Ê©Ä͵¹«Ë¾ÆìϵÄÅɶû¸ßϵÁÐÉãÏñ»úͨ³£±»ÓÃÓÚ¸÷ÀàÉÌÒµºÍ¹¤Òµ¼à¿ØÁìÓò £¬£¬£¬£¬£¬£¬£¬ÓµÓнϺõĻ·¾³ÊÊÓ¦ÐÔ¡£¡£¡£¡£¡£¡£PelcoϵÁÐÉãÏñ»ú´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýPOSTÇëÇóÖеÄenable_leds²ÎÊý×¢ÈëËÁÒâ´úÂë»òºÅÁî £¬£¬£¬£¬£¬£¬£¬½ø¶øÆëÈ«½ÚÔìÉãÏñ»ú¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_NETGEAR_DGN1000_Ô¶³ÌºÅÁîÖ´Ðзì϶

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ÍøÂçÉ豸¹¥»÷ 

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃÃÀ¹úÍø¼þNETGEAR DGN1000ϵÁзÓÉÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ £¬£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýÔ¶³ÌÖ´ÐÐËÁÒâºÅÁî £¬£¬£¬£¬£¬£¬£¬³¢ÊÔͨ¹ý¸ÃÉ豸½øÐÐÍÚ¿ó»òÕßDoS¹¥»÷µÈ·¸·¨ÐÐΪ¡£¡£¡£¡£¡£¡£ ÃÀ¹úÍø¼þNETGEARÊÇÃÀ¹ú³ÛÃûµÄÆóÒµÉ豸ÌṩÉÌ £¬£¬£¬£¬£¬£¬£¬NETGEAR DGN1000ϵÁзÓÉÆ÷¿í·º±»²¿ÊðÔÚÈ«Çò¸÷´ó»¥ÁªÍø¹«Ë¾¼°¼ÒÍ¥¡£¡£¡£¡£¡£¡£DGN1000ϵÁзÓÉÆ÷´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýURLÖеÄcmd²ÎÊý×¢ÈëËÁÒâ´úÂë»òºÅÁî £¬£¬£¬£¬£¬£¬£¬½ø¶øÆëÈ«½ÚÔì·ÓÉÆ÷¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_NETGEAR_JWNR_ÃÜÂëй¶©¶´

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ÍøÂçÉ豸¹¥»÷ 

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃNETGEAR JWNRϵÁзÓÉÆ÷ÃÜÂëй¶·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ £¬£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýÀûÓÃJWNRϵÁзÓÉÆ÷ÃÜÂëй¶·ì϶ £¬£¬£¬£¬£¬£¬£¬½ø¶øµÇ¼µ½Â·ÓÉÆ÷ºó¶Ü £¬£¬£¬£¬£¬£¬£¬ÆëÈ«½ÚÔìÕû¸öÍøÂç¡£¡£¡£¡£¡£¡£ XVR ͬÖáÓ²Å̼Ïñ»ú £¬£¬£¬£¬£¬£¬£¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеijÁÒª×é³É²¿ÃÅ¡£¡£¡£¡£¡£¡£¼ì²âµ½anni°²ÄáÓжà¿îXVRÉ豸´æÔÚÃÜÂëй¶ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý½Ó¼ûÖ¸¶¨µÄURL £¬£¬£¬£¬£¬£¬£¬XVRÉ豸¼´¿É·µ»ØµÇ¼ÃÜÂë¡£¡£¡£¡£¡£¡£  

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú

Åú¸ÄÊÂÎñ

ÊÂÎñÃû³Æ£º

HTTP_Microsoft_Windows_HTTP_sysÔ¶³Ì´úÂëÖ´Ðзì϶[CVE-2015-1635]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

°²È«·ì϶ 

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýMicrosoft Windows HTTP.sysÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¡£¡£¡£ Http.sysÊÇ´¦ÀíHTTPÇëÇóµÄÄÚºËģʽÇý¶¯·¨Ê½¡£¡£¡£¡£¡£¡£ HTTP.sysÃýÎó½âÎö»ú¹ØµÄHTTPÇëÇóʱ £¬£¬£¬£¬£¬£¬£¬ÔÚʵÏÖÉÏ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶ºó £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÔÚSystemÕÊ»§¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ 

¸üй¦·ò£º

20180713

ĬÈÏ×÷Ϊ£º

Åׯú