2019-11-12

Ðû²¼Ê±¼ä 2019-11-12

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Fastweb_FASTGate_0067_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2018-11336]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_Fastweb_FASTGate_0067_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191112








ÊÂÎñÃû³Æ£º

HTTP_SoftNAS_Cloud_OS_ÏÂÁî×¢ÈëÎó²î[CVE-2018-14417]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_SoftNAS_Cloud_OS_ÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191112








ÊÂÎñÃû³Æ£º

TCP_SCADA_Advantech_WebAccess_Viewdll1_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-8845]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃAdvantech WebAccess Viewdll1 Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£

Advantech WebAccessµÈ¶¼ÊÇÑлª£¨Advantech£©¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£¡£Advantech WebAccessÊÇÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý¿ØÖÆ£¬ £¬£¬²¢ÌṩԶ³Ì¿ØÖƺÍÖÎÀí×Ô¶¯»¯×°±¸µÄ¹¦Ð§¡£¡£¡£¡£¡£¡£WebAccess DashboardÊÇÆäÖеÄÒ»¸öÒDZí°å×é¼þ£»£» £»£» £»WebAccess Scada NodeÊÇÆäÖеÄÒ»¸ö¼à¿Ø½Úµã×é¼þ¡£¡£¡£¡£¡£¡£WebAccess/NMSÊÇÒ»Ì×ÓÃÓÚÍøÂçÖÎÀíϵͳ£¨NMS£©µÄÍøÂçä¯ÀÀÆ÷»ù´¡Ì×¼þ¡£¡£¡£¡£¡£¡£ Advantech WebAccess²úÆ·Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191112
















ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_MSAServices.Bitter.Rat(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ BitterľÂí ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£¡£¡£¡£¡£¡£

BitterľÂí ÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ£¬ £¬£¬ÔËÐкó£¬ £¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191112









ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_SessionService.Bitter.Rat(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ BitterľÂí ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£¡£¡£¡£¡£¡£

BitterľÂí ÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ£¬ £¬£¬ÔËÐкó£¬ £¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191112









ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_HigaisaRat(ºÚ¸ñɯ)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ HigaisaRat ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷£¬ £¬£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÔ¶¿Ø HigaisaRat ¡£¡£¡£¡£¡£¡£HigaisaRat ÊÇÒ»¸ö»ùÓÚgh0st¿ªÔ´Ô¶¿Ø¿ò¼ÜÐ޸ĶøÀ´Ô¶³Ì¿ØÖÆÄ¾Âí£¬ £¬£¬ÔÊÐí¹¥»÷Õß¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191112










ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_NetBotAttacker_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷

NetBotAttackerÊÇÒ»¸öÔ¶³Ì¿ØÖÆÈí¼þ£¬ £¬£¬¿ÉÒÔ¶ÔÔ¶³ÌÖ÷»ú¾ÙÐÐí§Òâ²Ù×÷£¬ £¬£¬¼æÓжÔÖ¸¶¨Ä¿µÄIPÖ÷»ú·¢¶¯DDoS¹¥»÷µÄ¹¦Ð§¡£¡£¡£¡£¡£¡£

DoS£¨Denial Of Service£©¼´¾Ü¾øÐ§À͹¥»÷£¬ £¬£¬×î»ù±¾µÄDoS¹¥»÷¾ÍÊÇʹÓúÏÀíµÄЧÀÍÇëÇóÀ´Õ¼Óùý¶àµÄЧÀÍ×ÊÔ´£¬ £¬£¬´Ó¶øÊ¹Õýµ±Óû§ÎÞ·¨»ñµÃЧÀ͵ÄÏìÓ¦¡£¡£¡£¡£¡£¡£DDoS£¨Distributed Denial Of Service£©¼´ÂþÑÜʽ¾Ü¾øÐ§À͹¥»÷¡£¡£¡£¡£¡£¡£¼´Í¬Ê±Ê¹ÓÃÈô¸Ę́Ö÷»ú£¬ £¬£¬Í¬Ê±¶Ôһ̨Ö÷»ú¾ÙÐÐDoS¹¥»÷¡£¡£¡£¡£¡£¡£

DDoSÊÇDistributed Denial of ServiceµÄ¼ò³Æ£¬ £¬£¬¼´ÂþÑÜʽ¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£¹¥»÷Ö¸½èÖúÓÚ¿Í»§/ЧÀÍÆ÷ÊÖÒÕ£¬ £¬£¬½«¶à¸öÅÌËã»úÁªºÏÆðÀ´×÷Ϊ¹¥»÷ƽ̨£¬ £¬£¬¶ÔÒ»¸ö»ò¶à¸öÄ¿µÄ·¢¶¯DoS¹¥»÷£¬ £¬£¬´Ó¶ø³É±¶µØÌá¸ß¾Ü¾øÐ§À͹¥»÷µÄÍþÁ¦¡£¡£¡£¡£¡£¡£Í¨³££¬ £¬£¬¹¥»÷ÕßʹÓÃÒ»¸ö͵ÇÔÕʺŽ«DDoSÖ÷¿Ø³ÌÐò×°ÖÃÔÚһ̨ÅÌËã»úÉÏ£¬ £¬£¬ÔÚÒ»¸öÉ趨µÄʱ¼äÖ÷¿Ø³ÌÐò½«Óë´ó×ÚÊðÀí³ÌÐòͨѶ£¬ £¬£¬ÊðÀí³ÌÐòÒѾ­±»×°ÖÃÔÚInternetÉϵÄÐí¶àÅÌËã»úÉÏ¡£¡£¡£¡£¡£¡£ÊðÀí³ÌÐòÊÕµ½Ö¸Áîʱ¾Í·¢¶¯¹¥»÷¡£¡£¡£¡£¡£¡£Ê¹Óÿͻ§/ЧÀÍÆ÷ÊÖÒÕ£¬ £¬£¬Ö÷¿Ø³ÌÐòÄÜÔÚ¼¸ÃëÖÓÄÚ¼¤»î³É°ÙÉÏǧ¸öÊðÀí³ÌÐòµÄÔËÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191112




















ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Win32.Zebrocy.Downloader(APT28)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ZebrocyÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËZebrocy¡£¡£¡£¡£¡£¡£

ZebrocyÊÇAPT28×é֯ʹÓõŤ¾ß£¬ £¬£¬°üÀ¨3¸ö×é¼þ¡£¡£¡£¡£¡£¡£Á½¸ö»ùÓÚDelphi¡¢AutoITµÄÏÂÔØÕߣ¬ £¬£¬ÁíÒ»¸öÊÇDelphiºóÃÅ¡£¡£¡£¡£¡£¡£APT28×éÖ¯Ò²±»³ÆÎªSofacy¡¢Fancy Bear¡¢Sednit¡¢Tsar Team¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191112










ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Win32.ImmortalStealer_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÇÔÃÜľÂíImmortalStealer¡£¡£¡£¡£¡£¡£

ImmortalStealerÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄÇÔÃÜľÂí£¬ £¬£¬¿ÉÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷ÉúÑĵÄÕ˺ÅÃÜÂë¼°Cookie¡£¡£¡£¡£¡£¡£»£» £»£» £»¹¿ÉÒÔÇÔÈ¡ÖÖÖÖ¿Í»§¶ËµÄƾ֤£¬ £¬£¬ÈçÓÎÏ·Steam¡¢±ÈÌØ±ÒBitcoin-QtµÈ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191112











ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Mscleaner.Darkhotel_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½MscleanerÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMscleaner¡£¡£¡£¡£¡£¡£

MscleanerÊÇAPT×éÖ¯DarkhotelʹÓõĺóÃÅ£¬ £¬£¬Ö÷ÒªÓй¦Ð§¿ªÆôshell£¬ £¬£¬ÏÂÔØÎļþ£¬ £¬£¬ÉÏ´«Îļþ¡¢ÍøÂçÎļþÃû³ÆÐÅÏ¢¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191112