2020-04-07
Ðû²¼Ê±¼ä 2020-04-07ÐÂÔöʼþ
ʼþÃû³Æ£º |
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB©¶´É¨Ãè[MS17-010]_ɨÃèÓЩ¶´ |
Äþ¾²ÀàÐÍ£º |
Äþ¾²Â©¶´ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IP¶ÔÄ¿µÄÖ÷»ú½øÐÐMS17-010©¶´É¨ÃèµÄÐÐΪ. Microsoft WindowsÊÇ΢ÈíÐû²¼µÄ·Ç³£Á÷ÐеIJÙ×÷ϵͳ¡£ Èç¹û¹¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;¾«ÐĽṹµÄ»ûÐÎÇëÇó°ü£¬¿ÉÒÔ»ñȡĿ±ê·þÎñÆ÷µÄϵͳȨÏÞ£¬¶øÇÒÍêÈ«¿ØÖÆÄ¿±êϵͳ¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
HTTP_ºóÃÅ_FakeSanforUD_Á¬½Ó |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËRarog¡£ ÉîÐÅ·þVPN¿Í»§¶Ë´æÔÚ©¶´£¬ÔÚÉý¼¶Ê±»áÏÂÔØÖ´ÐÐÃûΪSangforUD.exeµÄ¸üз¨Ê½¡£µ«VPN¿Í»§¶Ë½ö¶ÔSangforUD.exe×öÁ˼òµ¥µÄ°æ±¾¶Ô±È£¬Ã»ÓÐ×öÈκεÄÄþ¾²¼ì²é¡£APT×éÖ¯Darkhotel¹¥ÆÆÁËVPN·þÎñÆ÷£¬¸Ä¶¯Éý¼¶ÅäÖÃÎļþ²¢°ÑSangforUD.exeÌæ»»Îª¶ñÒâµÄºóÃÅFakeSanforUD¡£ FakeSanforUDÊÇÒ»¸öºóÃÅ£¬Í¨¹ýÏÂÔØÖ´ÐÐshellcode£¬×îÖÕÏÂÔØºËÐĵĺóÃŶñÒâ×é¼þthinmon.dll¡£ºËÐĺóÃÅ×é¼þthinmon.dll»á½âÃÜÔÆ¶ËÏ·¢µÄÁíÍâÒ»¸ö¼ÓÃÜÎļþSangfor_tmp_1.dat£¬ÒÔ¼ÓÔØ¡¢Ïß³ÌÆô¶¯¡¢×¢Èë½ø³Ì3ÖÖ·½Ê½ÖеÄÒ»ÖÖÆô¶¯datÎļþ £¬×îÖÕÓÉdatÎļþʵÏÖÓë·þÎñÆ÷½»»¥Ö´ÐжñÒâ²Ù×÷¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
TCP_Metasploit_ÄäÃû¹ÜµÀɨÃè |
Äþ¾²ÀàÐÍ£º |
Äþ¾²É¨Ãè |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓöÔÄ¿µÄÖ÷»úʹÓÃMetasploitͨ¹ýSMBÐÒé»ñÈ¡¼ÆËã»úÐÅÏ¢µÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
TCP_SMB_NMAPɨÃè |
Äþ¾²ÀàÐÍ£º |
Äþ¾²É¨Ãè |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓöÔÄ¿µÄÖ÷»úʹÓÃNMAPͨ¹ýSMBÐÒé»ñÈ¡¼ÆËã»úÐÅÏ¢µÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB©¶´É¨Ãè[MS17-010]_ɨÃèÎÞ©¶´ |
Äþ¾²ÀàÐÍ£º |
Äþ¾²Â©¶´ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IP¶ÔÄ¿µÄÖ÷»ú½øÐÐMS17-010©¶´É¨ÃèµÄÐÐΪ. Microsoft WindowsÊÇ΢ÈíÐû²¼µÄ·Ç³£Á÷ÐеIJÙ×÷ϵͳ¡£ Èç¹û¹¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;¾«ÐĽṹµÄ»ûÐÎÇëÇó°ü£¬¿ÉÒÔ»ñȡĿ±ê·þÎñÆ÷µÄϵͳȨÏÞ£¬¶øÇÒÍêÈ«¿ØÖÆÄ¿±êϵͳ¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_DoublePulsarºóÃÅ_ɨÃè»òÖ²ÈëºóÃÅ_ÒÉËÆÖ´ÐлòÐ¶ÔØ |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½Í¨¹ýMS17-010µÄ©¶´Ö²ÈëDoublePulsarºóÃŵÄÐÐΪ¡£ Microsoft WindowsÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾Ðû²¼µÄһϵÁвÙ×÷ϵͳ¡£SMBv1 serverÊÇÆäÖеÄÒ»¸ö·þÎñÆ÷ÐÒé×é¼þ¡£DoublePulsarÊÇÒ»¸öºóÃÅ·¨Ê½£¬ÓÃÓÚÔÚÒÑѬȾµÄϵͳÉÏ×¢ÈëºÍÔËÐжñÒâ´úÂë¡£ Microsoft WindowsÖеÄSMBv1·þÎñÆ÷´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖÆµÄÊý¾Ý°üÀûÓøÃ©¶´Ö²Èë»òɨÃèDoublePulsarºóÃÅ¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_DoublePulsarºóÃÅ_ɨÃè»òÖ²ÈëºóÃÅ_ÒÉËÆping |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½Í¨¹ýMS17-010µÄ©¶´Ö²ÈëDoublePulsarºóÃŵÄÐÐΪ¡£ Microsoft WindowsÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾Ðû²¼µÄһϵÁвÙ×÷ϵͳ¡£SMBv1 serverÊÇÆäÖеÄÒ»¸ö·þÎñÆ÷ÐÒé×é¼þ¡£DoublePulsarÊÇÒ»¸öºóÃÅ·¨Ê½£¬ÓÃÓÚÔÚÒÑѬȾµÄϵͳÉÏ×¢ÈëºÍÔËÐжñÒâ´úÂë¡£ Microsoft WindowsÖеÄSMBv1·þÎñÆ÷´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖÆµÄÊý¾Ý°üÀûÓøÃ©¶´Ö²ÈëDoublePulsarºóÃÅ¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
TCP_DrayTek_Ô¤Éí·ÝÑéÖ¤ÃüÁî×¢Èë©¶´[CVE-2020-8515] |
Äþ¾²ÀàÐÍ£º |
×¢Èë¹¥»÷ |
ʼþÃèÊö£º |
¼ì²âµ½¹¥»÷ÕßÀûÓÃDrayTekÔ¤Éí·ÝÑéÖ¤´¦µÄÁ½´¦ÃüÁî×¢Èë©¶´½øÐй¥»÷µÄÐÐΪ¡£DrayTekÊÇÒ»¼ÒÔÚÖйúÉú²ú·À»ðǽ£¬VPNÉ豸£¬Â·ÓÉÆ÷£¬WLANÉ豸µÈµÄÖÆÔìÉÌ¡£¸Ã©¶´Ô´ÓÚ/cgi-bin/mainfunction.cgi·¨Ê½Î´ÕýÈ·¹ýÂËkeyPath×ֶκÍrtick×Ö¶ÎÆäÖеÄÌØÊâ×Ö·û£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´²»¾¹ýÉí·ÝÑéÖ¤ÒÔrootȨÏÞÖ´ÐдúÂë¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
HTTP_ZyXEL_Ô¤Éí·ÝÑéÖ¤ÃüÁî×¢Èë©¶´[CVE-2020-9054] |
Äþ¾²ÀàÐÍ£º |
×¢Èë¹¥»÷ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýZyXELÉ豸ÖеÄÔ¤Éí·ÝÑéÖ¤µÄÃüÁî×¢Èë©¶´½øÐй¥»÷µÄÐÐΪ¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º |
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB©¶´Ð´Èëshellcode[MS17-010] |
Äþ¾²ÀàÐÍ£º |
Äþ¾²Â©¶´ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IP¶ÔÄ¿µÄÖ÷»úÀûÓÃMS17-010©¶´Ð´ÈëshellcodeµÄÐÐΪ. Microsoft WindowsÊÇ΢ÈíÐû²¼µÄ·Ç³£Á÷ÐеIJÙ×÷ϵͳ¡£ Èç¹û¹¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;¾«ÐĽṹµÄ»ûÐÎÇëÇó°ü£¬¿ÉÒÔ»ñȡĿ±ê·þÎñÆ÷µÄϵͳȨÏÞ£¬¶øÇÒÍêÈ«¿ØÖÆÄ¿±êϵͳ¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
TCP_Äþ¾²Â©¶´_Microsoft_SMBv3_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-0796] |
Äþ¾²ÀàÐÍ£º |
Äþ¾²Â©¶´ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»ú¿ÉÄÜÕýÔÚ¶ÔÄ¿µÄÖ÷»ú½øÐÐCVE-2020-0796©¶´ÀûÓõÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
UDP_½©Ê¬ÍøÂç_Mozi.P2PBotnet_Á¬½Ó |
Äþ¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ʼþÃèÊö£º |
¼ì²âµ½½©Ê¬ÍøÂçMoziÊÔͼºÍPeerͨÐÅ¡£ÒòΪÊÇ»ùÓÚP2PÐÒ飬ԴIPºÍÄ¿µÄIPËùÔÚµÄÖ÷»ú¿ÉÄܶ¼±»Ö²ÈëÁ˽©Ê¬ÍøÂçMozi¡£ MoziÊÇÒ»¸ö»ùÓÚP2PÐÒéµÄ½©Ê¬ÍøÂ磬Ö÷ÒªÖ§³ÖµÄ¹¦Ð§Îª£ºDDoS¹¥»÷¡¢ÊÕ¼¯BotÐÅÏ¢¡¢Ö´ÐÐÖ¸¶¨URLµÄpayload¡¢´ÓÖ¸¶¨µÄURL¸üÐÂÑù±¾¡¢Ö´ÐÐϵͳ»ò×Ô½ç˵ÃüÁî¡£ |
¸üÐÂʱ¼ä£º |
20200407 |
ʼþÃû³Æ£º |
TCP_Tomcat/Coldfusion_AJP13_ÈÎÒâÎļþ¶ÁÈ¡[CVE-2020-1938/CVE-2020-3761/CVE-2020-3794] |
Äþ¾²ÀàÐÍ£º |
Äþ¾²Â©¶´ |
ʼþÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃTomcat/Coldfusion_AJP13ÈÎÒâÎļþ¶Áȡ©¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º |
20200407 |