2019-11-12

°ä²¼¹¦·ò 2019-11-12

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Fastweb_FASTGate_0067_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2018-11336]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_Fastweb_FASTGate_0067_Ô¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ ¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20191112








ÊÂÎñÃû³Æ£º

HTTP_SoftNAS_Cloud_OS_ºÅÁî×¢Èë·ì϶[CVE-2018-14417]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_SoftNAS_Cloud_OS_ºÅÁî×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20191112








ÊÂÎñÃû³Æ£º

TCP_SCADA_Advantech_WebAccess_Viewdll1_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2018-8845]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃAdvantech WebAccess Viewdll1 Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£

Advantech WebAccessµÈ¶¼ÊÇÑлª£¨Advantech£©¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£¡£Advantech WebAccessÊÇÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý½ÚÔ죬 £¬£¬£¬£¬£¬£¬²¢ÌṩԶ³Ì½ÚÔìºÍÖÎÀí×Ô¶¯»¯É豸µÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£WebAccess DashboardÊÇÆäÖеÄÒ»¸öÒDZí°å×é¼þ£»£»£» £»£»£»£»£»WebAccess Scada NodeÊÇÆäÖеÄÒ»¸ö¼à¿Ø½Úµã×é¼þ¡£¡£¡£¡£¡£¡£WebAccess/NMSÊÇÒ»Ì×ÓÃÓÚÍøÂçÖÎÀíϵͳ£¨NMS£©µÄÍøÂçä¯ÀÀÆ÷»ù´¡Ì×¼þ¡£¡£¡£¡£¡£¡£ Advantech WebAccess²úÆ·ÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20191112
















ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_MSAServices.Bitter.Rat(ÂûÁ黨)_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ BitterľÂí ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£¡£¡£¡£¡£¡£

BitterľÂí ÊÇÒ»¸öÖ°Äܼ«¶È׳´óµÄºóÃÅ£¬ £¬£¬£¬£¬£¬£¬ÔËÐкó£¬ £¬£¬£¬£¬£¬£¬Äܹ»ÆëÈ«½ÚÔì±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20191112









ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_SessionService.Bitter.Rat(ÂûÁ黨)_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ BitterľÂí ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£¡£¡£¡£¡£¡£

BitterľÂí ÊÇÒ»¸öÖ°Äܼ«¶È׳´óµÄºóÃÅ£¬ £¬£¬£¬£¬£¬£¬ÔËÐкó£¬ £¬£¬£¬£¬£¬£¬Äܹ»ÆëÈ«½ÚÔì±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20191112









ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_HigaisaRat(ºÚ¸ñɯ)_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ HigaisaRat ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷£¬ £¬£¬£¬£¬£¬£¬Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÔ¶¿Ø HigaisaRat ¡£¡£¡£¡£¡£¡£HigaisaRat ÊÇÒ»¸ö»ùÓÚgh0st¿ªÔ´Ô¶¿Ø¿ò¼ÜÅú¸Ä¶øÀ´Ô¶³Ì½ÚÔìľÂí£¬ £¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õß½ÚÔì±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20191112










Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_NetBotAttacker_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷

NetBotAttackerÊÇÒ»¸öÔ¶³Ì½ÚÔìÈí¼þ£¬ £¬£¬£¬£¬£¬£¬Äܹ»¶ÔÔ¶³ÌÖ÷»ú½øÐÐËÁÒâ²Ù×÷£¬ £¬£¬£¬£¬£¬£¬¼æÓжÔÖ¸¶¨Ö¸±êIPÖ÷»ú·¢ÆðDDoS¹¥»÷µÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£

DoS£¨Denial Of Service£©¼´»Ø¾ø·þÎñ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬×î¸ù»ùµÄDoS¹¥»÷¾ÍÊÇÀûÓúÏÀíµÄ·þÎñÒªÇóÀ´Õ¼Óùý¶àµÄ·þÎñ×ÊÔ´£¬ £¬£¬£¬£¬£¬£¬´Ó¶øÊ¹ºÏ·¨Óû§ÎÞ·¨µÃµ½·þÎñµÄÏìÓ¦¡£¡£¡£¡£¡£¡£DDoS£¨Distributed Denial Of Service£©¼´É¢²¼Ê½»Ø¾ø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£¼´Í¬Ê±Ê¹ÓÃÈô¸Ę́Ö÷»ú£¬ £¬£¬£¬£¬£¬£¬Í¬Ê±¶Ôһ̨Ö÷»ú½øÐÐDoS¹¥»÷¡£¡£¡£¡£¡£¡£

DDoSÊÇDistributed Denial of ServiceµÄ¼ò³Æ£¬ £¬£¬£¬£¬£¬£¬¼´É¢²¼Ê½»Ø¾ø·þÎñ¡£¡£¡£¡£¡£¡£¹¥»÷Ö¸½èÖúÓÚ¿Í»§/·þÎñÆ÷¼¼Êõ£¬ £¬£¬£¬£¬£¬£¬½«¶à¸öÍÆËã»ú½áºÏÆðÀ´×÷Ϊ¹¥»÷ƽ̨£¬ £¬£¬£¬£¬£¬£¬¶ÔÒ»¸ö»ò¶à¸öÖ¸±ê·¢ÆðDoS¹¥»÷£¬ £¬£¬£¬£¬£¬£¬´Ó¶ø³É±¶µØÌá¸ß»Ø¾ø·þÎñ¹¥»÷µÄÍþÁ¦¡£¡£¡£¡£¡£¡£Í¨³££¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÒ»¸ö͵ÇÔÕʺŽ«DDoSÖ÷¿Ø·¨Ê½×°ÖÃÔÚÒ»Ì¨ÍÆËã»úÉÏ£¬ £¬£¬£¬£¬£¬£¬ÔÚÒ»¸öÉ趨µÄ¹¦·òÖ÷¿Ø·¨Ê½½«Óë´óÁ¿´úÀí·¨Ê½Í¨Ñ¶£¬ £¬£¬£¬£¬£¬£¬´úÀí·¨Ê½ÒѾ­±»×°ÖÃÔÚInternetÉϵĺܶàÍÆËã»úÉÏ¡£¡£¡£¡£¡£¡£´úÀí·¨Ê½ÊÕµ½Ö¸Áîʱ¾Í·¢Æð¹¥»÷¡£¡£¡£¡£¡£¡£ÀûÓÿͻ§/·þÎñÆ÷¼¼Êõ£¬ £¬£¬£¬£¬£¬£¬Ö÷¿Ø·¨Ê½ÄÜÔÚ¼¸ÃëÖÓÄÚ¼¤»î³É°ÙÉÏǧ¸ö´úÀí·¨Ê½µÄÔËÐÓ×£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20191112




















ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Win32.Zebrocy.Downloader(APT28)_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ZebrocyÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËZebrocy¡£¡£¡£¡£¡£¡£

ZebrocyÊÇAPT28×é֯ʹÓõŤ¾ß£¬ £¬£¬£¬£¬£¬£¬Ô̺¬3¸ö×é¼þ¡£¡£¡£¡£¡£¡£Á½¸ö»ùÓÚDelphi¡¢AutoITµÄÏÂÔØÕߣ¬ £¬£¬£¬£¬£¬£¬ÁíÒ»¸öÊÇDelphiºóÃÅ¡£¡£¡£¡£¡£¡£APT28×éÖ¯Ò²±»³ÆÎªSofacy¡¢Fancy Bear¡¢Sednit¡¢Tsar Team¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20191112










ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Win32.ImmortalStealer_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÇÔÃÜľÂíImmortalStealer¡£¡£¡£¡£¡£¡£

ImmortalStealerÊÇÒ»¸öÖ°ÄÜ׳´óµÄÇÔÃÜľÂí£¬ £¬£¬£¬£¬£¬£¬¿ÉÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷±£ÁôµÄÕ˺ÅÃÜÂë¼°Cookie¡£¡£¡£¡£¡£¡£»£»£» £»£»£»£»£»¹Äܹ»ÇÔÈ¡¸÷Àà¿Í»§¶ËµÄƾ֤£¬ £¬£¬£¬£¬£¬£¬ÈçÓÎÏ·Steam¡¢±ÈÌØ±ÒBitcoin-QtµÈ¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20191112











ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Mscleaner.Darkhotel_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½MscleanerÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMscleaner¡£¡£¡£¡£¡£¡£

MscleanerÊÇAPT×éÖ¯DarkhotelʹÓõĺóÃÅ£¬ £¬£¬£¬£¬£¬£¬ÖØÒªÓÐÖ°ÄÜ¿ªÆôshell£¬ £¬£¬£¬£¬£¬£¬ÏÂÔØÎļþ£¬ £¬£¬£¬£¬£¬£¬ÉÏ´«Îļþ¡¢ÍøÂçÎļþÃû³ÆÐÅÏ¢¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20191112