2020-09-01

Ðû²¼Ê±¼ä 2020-09-01

ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_APT¹¥»÷_Gamaredon×éÖ¯_Wget_Downloader_Á¬½ÓC2

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

GamaredonÊÇÒ»¸ö¶íÂÞ˹µÄAPT¹¥»÷×éÖ¯ £¬Ê״ηºÆðÓÚ2013Äê,Ö÷ÒªÊÇÕë¶ÔÎÚ¿ËÀ¼½øÐÐÍøÂç¼äµý»î¶¯¡£2017Äê £¬Palo AltoÅû¶¹ý¸Ã×éÖ¯Õë¶ÔÎÚ¿ËÀ¼¹¥»÷»î¶¯µÄϸ½Ú £¬²¢Ê״ν«¸Ã×éÖ¯ÃüÃûΪGamaredon group¡£¸Ã×éÖ¯Ö÷ÒªÀûÓÃÊÜѬȾÓòÃû¡¢¶¯Ì¬DNS¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼¹ú¼Ò´úÂë¶¥¼¶ÓòÃû£¨ccTLD£©ÒÔ¼°¶íÂÞ˹ÍйܷþÎñÌṩÉÌÀ´·Ö·¢Æä¶¨ÖƵĶñÒâÈí¼þ¡£Gamaredon×éÖ¯»áʹÓôóÁ¿ÏֳɵŤ¾ß £¬¾­¹ýÉú³¤ £¬Ò²¿ªÊ¼¶¨ÖÆ¿ª·¢Ïà¹ØµÄ¶ñÒâÈí¼þ¡£¸ÃʼþÊÇʹÓõÄWgetÏÂÔØ¹¤¾ßÏÂÔØÆäËûPayload²¢Ö´ÐС£

¸üÐÂʱ¼ä£º

20200901



ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_CobaltStrike_LogKeystrokes.js_´úÂëÏÂÔØÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike Éú³ÉµÄ ºóÃÅÎļþ LogKeystrokes.js ÕýÔÚ±»ÏÂÔØ, ¸ÃºóÃÅÎļþͨ³£Ç¶ÈëÔÚµöÓãÍøÒ³ £¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄÜ·ÃÎÊÁ˲»Äþ¾²»òÕßαװµÄÍøÒ³¡£LogKeystrokes.js Ö´Ðк󽫻á¼Ç¼ÔÚ´ËÍøÒ³Éϵİ´¼üÄÚÈÝ £¬Í¨³£ÓÃÓÚÇÔȡƾ֤ÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20200901


ʼþÃû³Æ£º

TCP_Java·´ÐòÁл¯_JRMPClient1_ÀûÓÃÁ´¹¥»÷

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃJRMPClient1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200901


ʼþÃû³Æ£º

TCP_Java·´ÐòÁл¯_Spring1_ÀûÓÃÁ´¹¥»÷

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃSpring1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200901


ʼþÃû³Æ£º

TCP_Java·´ÐòÁл¯_Spring2_ÀûÓÃÁ´¹¥»÷

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃSpring2µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200901


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

TCP_Oracle_WebLogic_·´ÐòÁл¯Â©¶´[CVE-2015-4852]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracle WebLogic·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´ £¬ÊÔͼͨ¹ý´«È뾫ÐĽṹµÄ¶ñÒâ´úÂë»òÃüÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£

¸üÐÂʱ¼ä£º

20200901


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Apache_Shiro_Éí·ÝÑéÖ¤ÈÆ¹ý©¶´[CVE-2020-11989][CNNVD-202006-1556]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

Apache ShiroÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü £¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí¡£Ä¿Ç°³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖнøÐÐÉí·ÝÑéÖ¤ £¬ÊÚȨµÈ¡£¶ÔÓÚApache Shiro 1.5.3֮ǰµÄ°æ±¾ £¬µ±½«Apache ShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ £¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£

¸üÐÂʱ¼ä£º

20200901