2018-07-13

Ðû²¼Ê±¼ä 2018-07-13

ÐÂÔöʼþ

ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_Smurf.fileUpload(Confucius)_Á¬½Ó

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½SmurfÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËSmurf¡£
SmurfÊÇAPT×éÖ¯ConfuciusʹÓõÄÇÔÈ¡ÎļþµÄľÂí £¬ÔËÐкó £¬ÉÏ´«ÖÖÖÖÎļþµ½C&C·þÎñÆ÷ £¬Èçdoc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx, .csvµÈ¡£  

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

TCP_ľÂí_Win32.TrickBot_NetworkCollectorModule

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíTrickBot¡£ TrickBotÊÇÒ»¸ö¹¦Ð§Ç¿´óµÄÇÔÃÜľÂí¡£TrickbotÒøÐÐľÂíÖаüÂÞNetwork Collector Module £¬¸ÃÄ£¿é¿ÉÒÔËѼ¯Óû§ÐÅÏ¢ÉÏ´«ÖÁ·þÎñÆ÷¡£ ¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_Win32.LoadMoney_Á¬½Ó

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½LoadmoneyÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËLoadmoney¡£ LoadmoneyÊÇÒ»¸öľÂíÏÂÔØÕß £¬ÔËÐкó»áÏÂÔØÆäËü¶ñÒâÑù±¾¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_Malware_KardonLoader_Á¬½Ó·þÎñÆ÷

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Kardon LoaderÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËKardon Loader¡£ Kardon LoaderÊÇÒ»¸öÈ«¹¦Ð§µÄÏÂÔØÆ÷ £¬¿ÉÒÔÏÂÔØºÍ°²×°ÆäËû¶ñÒâÈí¼þ¡£ÀýÈç £¬ÒøÐÐľÂí/ƾ֤ÇÔÈ¡Èí¼þµÈ¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_DanaBot.Downloader_Á¬½Ó

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½DanaBotÊÔͼÏÂÔØºËÐÄMain dll×é¼þ¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDanaBot¡£ DanaBotÊÇÒ»¸öÒøÐÐľÂí £¬°üÂÞÒ»¸öÏÂÔØ×é¼þ¡£ÏÂÔØ×é¼þÔËÐкó»áÏÂÔØºËÐÄMain dll×é¼þ¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

TCP_ľÂíºóÃÅ_DanaBot_Á¬½Ó

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½DanaBotµÄMain dllÊÔͼÏÂÔØÆäËü×é¼þ¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDanaBot¡£ DanaBotÊÇÒ»¸öÒøÐÐľÂí £¬°üÂÞÒ»¸öÏÂÔØ×é¼þ¡£ÏÂÔØ×é¼þÔËÐкó»áÏÂÔØºËÐÄMain dll×é¼þ¡£Main dllÏÂÔØVNC¡¢Stealer¡¢SnifferµÈ×é¼þ £¬Íê³ÉÇÔÃÜ¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

TCP_ºóÃÅ_PoisonIvy_Keepalive_Á¬½Ó2

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½PoisonIvyµÄÐÄÌø°üÊý¾Ý¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPoison Ivy¡£ Poison IvyÊÇÒ»¸ö±»¹ã·ºÓ¦ÓõÄÔ¶³Ì¿ØÖƹ¤¾ß £¬ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_DVR_Ó²Å̼Ïñ»ú_µÇÂ¼ÈÆ¹ý©¶´[CVE-2018-9995]

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ÍøÂçÉ豸¹¥»÷ 

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃDVRÓ²Å̼Ïñ»úµÇÂ¼ÈÆ¹ý©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ £¬ÊÔͼͨ¹ýÀûÓÃDVRÈÆ¹ýµÇ¼©¶´µÇ¼µ½Ó²Å̼Ïñ»úºǫ́ £¬·Ç·¨Ê¹ÓÃÊÓÆµ¼à¿Ø×ÊÔ´¡£ DVRÈ«³ÆDigital Video Recorder(Ó²Å̼Ïñ»ú) £¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеÄÖØÒª×é³É²¿ÃÅ¡£¼ì²âµ½Óжà¿îDVRÉ豸´æÔÚµÇÂ¼ÈÆ¹ý©¶´ £¬¹¥»÷Õßͨ¹ýÐÞ¸ÄCookie:uid=adminÖ®ºó²¢·ÃÎÊÌØ¶¨DVRµÄ¿ØÖÆÃæ°å £¬·µ»Ø´ËÉ豸µÄÃ÷ÎĹÜÀíԱƾ֤¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_anni°²ÄáXVR_ͬÖáÓ²Å̼Ïñ»ú_ÃÜÂëй¶©¶´

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ÍøÂçÉ豸¹¥»÷ 

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃXVRͬÖáÓ²Å̼Ïñ»úÃÜÂëй¶©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ £¬ÊÔͼͨ¹ýÀûÓÃXVRÃÜÂëй¶©¶´ £¬½ø¶øµÇ¼µ½XVRºǫ́ £¬·Ç·¨Ê¹ÓÃÊÓÆµ¼à¿Ø×ÊÔ´¡£ XVRͬÖáÓ²Å̼Ïñ»ú £¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеÄÖØÒª×é³É²¿ÃÅ¡£¼ì²âµ½anni°²ÄáÓжà¿îXVRÉ豸´æÔÚÃÜÂëй¶ £¬¹¥»÷Õßͨ¹ý·ÃÎÊÖ¸¶¨µÄURL £¬XVRÉ豸¼´¿É·µ»ØµÇ¼ÃÜÂë¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_Ê©Ä͵Â_Åɶû¸ßϵÁÐÉãÏñ»ú_Ô¶³Ì´úÂëÖ´ÐЩ¶´

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ÍøÂçÉ豸¹¥»÷ 

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÊ©Ä͵ÂÅɶû¸ßϵÁÐÉãÏñ»úÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ £¬ÊÔͼͨ¹ýÔ¶³ÌÖ´ÐÐÈÎÒâÃüÁî £¬ÊµÑéͨ¹ý¸ÃÉ豸½øÐÐÍÚ¿ó»òÕßDoS¹¥»÷µÈ·Ç·¨ÐÐΪ¡£ Ê©Ä͵¹«Ë¾ÆìϵÄÅɶû¸ßϵÁÐÉãÏñ»úͨ³£±»ÓÃÓÚÖÖÖÖÉÌÒµºÍ¹¤Òµ¼à¿ØÁìÓò £¬¾ßÓнϺõĻ·¾³ÊÊÓ¦ÐÔ¡£PelcoϵÁÐÉãÏñ»ú´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´ £¬¹¥»÷Õß¿ÉÒÔͨ¹ýPOSTÇëÇóÖеÄenable_leds²ÎÊý×¢ÈëÈÎÒâ´úÂë»òÃüÁî £¬½ø¶øÍêÈ«¿ØÖÆÉãÏñ»ú¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_NETGEAR_DGN1000_Ô¶³ÌÃüÁîÖ´ÐЩ¶´

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ÍøÂçÉ豸¹¥»÷ 

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÃÀ¹úÍø¼þNETGEAR DGN1000ϵÁзÓÉÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ £¬ÊÔͼͨ¹ýÔ¶³ÌÖ´ÐÐÈÎÒâÃüÁî £¬ÊµÑéͨ¹ý¸ÃÉ豸½øÐÐÍÚ¿ó»òÕßDoS¹¥»÷µÈ·Ç·¨ÐÐΪ¡£ ÃÀ¹úÍø¼þNETGEARÊÇÃÀ¹úÖªÃûµÄÆóÒµÉ豸ÌṩÉÌ £¬NETGEAR DGN1000ϵÁзÓÉÆ÷¹ã·º±»²¿ÊðÔÚÈ«Çò¸÷´ó»¥ÁªÍø¹«Ë¾¼°¼ÒÍ¥¡£DGN1000ϵÁзÓÉÆ÷´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´ £¬¹¥»÷Õß¿ÉÒÔͨ¹ýURLÖеÄcmd²ÎÊý×¢ÈëÈÎÒâ´úÂë»òÃüÁî £¬½ø¶øÍêÈ«¿ØÖÆÂ·ÓÉÆ÷¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ʼþÃû³Æ£º

HTTP_NETGEAR_JWNR_ÃÜÂëй¶©¶´

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

ÍøÂçÉ豸¹¥»÷ 

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃNETGEAR JWNRϵÁзÓÉÆ÷ÃÜÂëй¶©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ £¬ÊÔͼͨ¹ýÀûÓÃJWNRϵÁзÓÉÆ÷ÃÜÂëй¶©¶´ £¬½ø¶øµÇ¼µ½Â·ÓÉÆ÷ºǫ́ £¬ÍêÈ«¿ØÖÆÕû¸öÍøÂç¡£ XVR ͬÖáÓ²Å̼Ïñ»ú £¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеÄÖØÒª×é³É²¿ÃÅ¡£¼ì²âµ½anni°²ÄáÓжà¿îXVRÉ豸´æÔÚÃÜÂëй¶ £¬¹¥»÷Õßͨ¹ý·ÃÎÊÖ¸¶¨µÄURL £¬XVRÉ豸¼´¿É·µ»ØµÇ¼ÃÜÂë¡£  

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú

ÐÞ¸Äʼþ

ʼþÃû³Æ£º

HTTP_Microsoft_Windows_HTTP_sysÔ¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2015-1635]

ʼþ¼¶±ð£º

Öм¶Ê¼þ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´ 

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýMicrosoft Windows HTTP.sysÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ Http.sysÊÇ´¦ÀíHTTPÇëÇóµÄÄÚºËģʽÇý¶¯·¨Ê½¡£ HTTP.sys´íÎó½âÎö½á¹¹µÄHTTPÇëÇóʱ £¬ÔÚʵÏÖÉÏ´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´ £¬ÀÖ³ÉÀûÓôË©¶´ºó £¬¹¥»÷Õß¿ÉÔÚSystemÕÊ»§ÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂë¡£ 

¸üÐÂʱ¼ä£º

20180713

ĬÈÏÐж¯£º

Åׯú