2018-06-22

Ðû²¼Ê±¼ä 2018-06-22

ÐÂÔöʼþ

ʼþÃû³Æ£º

HTTP_ºóÃÅ_Win32.Kazuar_Á¬½Ó

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËKazuar¡£KazuarÊÇAPT×éÖ¯Turla¿ª·¢Ê¹ÓõÄÒ»¸öºóÃÅ£¬¹¦Ð§·Ç³£Ç¿´ó£¬ÔËÐкóÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£

¸üÐÂʱ¼ä£º

20180622

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

TCP_ºóÃÅ_Win32.Duuzer(HiddenCobra)_Á¬½Ó

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½ºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDuuzer¡£DuuzerÊÇAPT×éÖ¯Hidden CobraËùʹÓõĺóÃÅ£¬¹¦Ð§·Ç³£Ç¿´ó¡£ÔËÐк󣬿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£

¸üÐÂʱ¼ä£º

20180622

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

TCP_Malware_VPNFilter_GetCC

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½VPNFilterÊÔͼͨ¹ýSYNËíµÀ¼¼Êõ»ñÈ¡C&CµÄIPµØÖ·¡£¸Ã¶ñÒâÈí¼þͨ¹ýÀûÓ÷ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽµÈÎïÁªÍøÉ豸©¶´½øÐй㷺µÄѬȾºÍÁ÷´«¡£

¸üÐÂʱ¼ä£º

20180622

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

TCP_Malware_Akdoor.R228914_Á¬½Ó·þÎñÆ÷

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Akdoor.R228914ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£¶ñÒâÈí¼þAkdoor.R228914ÊÇÒ»¸ö¼òµ¥µÄºóÃÅ£¬Í¨¹ýÃüÁîÌáʾ·ûÖ´ÐÐÃüÁî¡£ ËüÓÐÒ»¸öÆæÌØµÄÃüÁîºÍ¿ØÖÆÐ­Òé¡£

¸üÐÂʱ¼ä£º

20180622

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32.Sisfader_Á¬½Ó

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½ºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËSisfader¡£SisfaderÊÇÒ»¸öºóÃÅ£¬¹¦Ð§·Ç³£Ç¿´ó¡£ÔËÐк󣬿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£

¸üÐÂʱ¼ä£º

20180622

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

TCP_GPON¼Òͥ·ÓÉÆ÷Äþ¾²Â©¶´[CVE-2018-10562]

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýGPON¼Òͥ·ÓÉÆ÷ÖдæÔÚµÄÄþ¾²Â©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£Dasan GPONÊǺ«¹úDasan¹«Ë¾µÄÒ»¿î¼ÒÓ÷ÓÉÆ÷²úÎï¡£Dasan GPON¼Òͥ·ÓÉÆ÷ÖдæÔÚÄþ¾²Â©¶´¡£¹¥»÷Õß¿Éͨ¹ýÏòÉ豸µÄÈÎÒâURLÌí¼Ó¡®?images¡¯ÀûÓøÃ©¶´ÈƹýÉí·ÝÑéÖ¤¡£Dasan GPON¼Òͥ·ÓÉÆ÷ÖдæÔÚÃüÁî×¢Èë©¶´£¬¸Ã©¶´Ô´ÓÚÓû§ÔٴηÃÎÊ/diag.htmlÒ³ÃæÊ±Â·ÓÉÆ÷½«ÒòÌØÍø°ü̽Ë÷Æ÷µÄ½á¹ûÉú´æÔÚ/tmpÖв¢½«Ëü´«Ê䏸Óû§¡£¹¥»÷Õß¿Éͨ¹ýÏòGponForm/diag_Form URI·¢ËÍ´øÓС®dest_host¡¯²ÎÊýµÄdiag_action=pingÇëÇóÀûÓøÃ©¶´Ö´ÐÐÃüÁî²¢¼ìË÷Êä³ö¡£muhstik.scanner »áÌᳫ¸Ã©¶´É¨Ã裬ÀûÓøÃ©¶´ÆÈʹGPONÒ׸ÐÉ豸Ïò³ÂËß·þÎñÆ÷»ã±¨×´Ì¬¡£

¸üÐÂʱ¼ä£º

20180622

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_ElasticSearch_ÃüÁîÖ´ÐЩ¶´[CVE-2014-3120]

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃElasticSearchÔ¶³ÌÃüÁîÖ´ÐЩ¶´½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´Ö´ÐÐÈÎÒâÃüÁî¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearchÖ§³Ö´«È붯̬½Å±¾£¨MVEL£©À´Ö´ÐÐһЩÅÓ´óµÄ²Ù×÷£¬¶øMVEL¿ÉÖ´ÐÐJava´úÂ룬¹¥»÷ÕßÀûÓøÃ©¶´¿ÉÒÔÔÚElasticSearch·þÎñÆ÷ÖÐÖ´ÐÐÈÎÒâJava´úÂë»òÃüÁî¡£

¸üÐÂʱ¼ä£º

20180622

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_ElasticSearch_ÃüÁîÖ´ÐЩ¶´[CVE-2015-1427]

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃElasticSearchÔ¶³ÌÃüÁîÖ´ÐЩ¶´½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´Ö´ÐÐÈÎÒâÃüÁî¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearchÖ§³Ö´«È붯̬½Å±¾£¨Groovy£©À´Ö´ÐÐһЩÅÓ´óµÄ²Ù×÷£¬¶øGroovy¿ÉÖ´ÐÐJava´úÂë¡£ElasticSearchÔÚʹÓÃGroovyÓïÑÔÖ´ÐÐÃüÁîʱ´æÔÚɳºÐ»úÖÆ£¬µ«¹¥»÷ÕßÈÔ¿ÉÒÔÀûÓé¶´ÈƹýɳºÐÔÚElasticSearch·þÎñÆ÷ÖÐÖ´ÐÐÈÎÒâJava´úÂë»òÃüÁî¡£

¸üÐÂʱ¼ä£º

20180622

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_elasticsearch-head_Ŀ¼´©Ô½Â©¶´[CVE-2015-3337]

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃElasticSearch head²å¼þĿ¼´©Ô½Â©¶´½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´¶ÁÈ¡µ½²Ù×÷ϵͳÉϵÄÈÎÒâÎļþ¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearch head²å¼þ´æÔÚĿ¼´©Ô½Â©¶´£¬¹¥»÷ÕßÀûÓøÃ©¶´¿É¶ÁÈ¡²Ù×÷ϵͳÉϵÄÈÎÒâÎļþ¡£

¸üÐÂʱ¼ä£º

20180622

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_ElasticSearch_Ŀ¼´©Ô½Â©¶´[CVE-2015-5531]

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃElasticSearchĿ¼´©Ô½Â©¶´½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´¶ÁÈ¡µ½²Ù×÷ϵͳÉϵÄÈÎÒâÎļþ¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearch´æÔÚĿ¼´©Ô½Â©¶´£¬¹¥»÷ÕßÀûÓøÃ©¶´¿É¶ÁÈ¡²Ù×÷ϵͳÉϵÄÈÎÒâÎļþ¡£

¸üÐÂʱ¼ä£º

20180622

ĬÈÏÐж¯£º

Åׯú