2019-11-12
°ä²¼¹¦·ò 2019-11-12ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_Fastweb_FASTGate_0067_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2018-11336] |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_Fastweb_FASTGate_0067_Ô¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ ¡£ |
|
¸üй¦·ò£º |
20191112 |
|
ÊÂÎñÃû³Æ£º |
HTTP_SoftNAS_Cloud_OS_ºÅÁî×¢Èë·ì϶[CVE-2018-14417] |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_SoftNAS_Cloud_OS_ºÅÁî×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£ |
|
¸üй¦·ò£º |
20191112 |
|
ÊÂÎñÃû³Æ£º |
TCP_SCADA_Advantech_WebAccess_Viewdll1_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2018-8845] |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃAdvantech WebAccess Viewdll1 Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£ Advantech WebAccessµÈ¶¼ÊÇÑлª£¨Advantech£©¹«Ë¾µÄ²úÆ·¡£Advantech WebAccessÊÇÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý½ÚÔ죬²¢ÌṩԶ³Ì½ÚÔìºÍÖÎÀí×Ô¶¯»¯É豸µÄÖ°ÄÜ¡£WebAccess DashboardÊÇÆäÖеÄÒ»¸öÒDZí°å×é¼þ£»WebAccess Scada NodeÊÇÆäÖеÄÒ»¸ö¼à¿Ø½Úµã×é¼þ¡£WebAccess/NMSÊÇÒ»Ì×ÓÃÓÚÍøÂçÖÎÀíϵͳ£¨NMS£©µÄÍøÂçä¯ÀÀÆ÷»ù´¡Ì×¼þ¡£ Advantech WebAccess²úÆ·ÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£ |
|
¸üй¦·ò£º |
20191112 |
|
ÊÂÎñÃû³Æ£º |
TCP_ºóÃÅ_MSAServices.Bitter.Rat(ÂûÁ黨)_ÏÎ½Ó |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½ BitterľÂí ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£ BitterľÂí ÊÇÒ»¸öÖ°Äܼ«¶È׳´óµÄºóÃÅ£¬ÔËÐкó£¬Äܹ»ÆëÈ«½ÚÔì±»Ö²Èë»úе¡£ |
|
¸üй¦·ò£º |
20191112 |
|
ÊÂÎñÃû³Æ£º |
TCP_ºóÃÅ_SessionService.Bitter.Rat(ÂûÁ黨)_ÏÎ½Ó |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½ BitterľÂí ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£ BitterľÂí ÊÇÒ»¸öÖ°Äܼ«¶È׳´óµÄºóÃÅ£¬ÔËÐкó£¬Äܹ»ÆëÈ«½ÚÔì±»Ö²Èë»úе¡£ |
|
¸üй¦·ò£º |
20191112 |
|
ÊÂÎñÃû³Æ£º |
TCP_ľÂíºóÃÅ_HigaisaRat(ºÚ¸ñɯ)_ÏÎ½Ó |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½ HigaisaRat ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷£¬Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÔ¶¿Ø HigaisaRat ¡£HigaisaRat ÊÇÒ»¸ö»ùÓÚgh0st¿ªÔ´Ô¶¿Ø¿ò¼ÜÅú¸Ä¶øÀ´Ô¶³Ì½ÚÔìľÂí£¬ÔÊÐí¹¥»÷Õß½ÚÔì±»Ö²Èë»úе¡£ |
|
¸üй¦·ò£º |
20191112 |
Åú¸ÄÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
TCP_ºóÃÅ_NetBotAttacker_ÏÎ½Ó |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷ NetBotAttackerÊÇÒ»¸öÔ¶³Ì½ÚÔìÈí¼þ£¬Äܹ»¶ÔÔ¶³ÌÖ÷»ú½øÐÐËÁÒâ²Ù×÷£¬¼æÓжÔÖ¸¶¨Ö¸±êIPÖ÷»ú·¢ÆðDDoS¹¥»÷µÄÖ°ÄÜ¡£ DoS£¨Denial Of Service£©¼´»Ø¾ø·þÎñ¹¥»÷£¬×î¸ù»ùµÄDoS¹¥»÷¾ÍÊÇÀûÓúÏÀíµÄ·þÎñÒªÇóÀ´Õ¼Óùý¶àµÄ·þÎñ×ÊÔ´£¬´Ó¶øÊ¹ºÏ·¨Óû§ÎÞ·¨µÃµ½·þÎñµÄÏìÓ¦¡£DDoS£¨Distributed Denial Of Service£©¼´É¢²¼Ê½»Ø¾ø·þÎñ¹¥»÷¡£¼´Í¬Ê±Ê¹ÓÃÈô¸Ę́Ö÷»ú£¬Í¬Ê±¶Ôһ̨Ö÷»ú½øÐÐDoS¹¥»÷¡£ DDoSÊÇDistributed Denial of ServiceµÄ¼ò³Æ£¬¼´É¢²¼Ê½»Ø¾ø·þÎñ¡£¹¥»÷Ö¸½èÖúÓÚ¿Í»§/·þÎñÆ÷¼¼Êõ£¬½«¶à¸öÍÆËã»ú½áºÏÆðÀ´×÷Ϊ¹¥»÷ƽ̨£¬¶ÔÒ»¸ö»ò¶à¸öÖ¸±ê·¢ÆðDoS¹¥»÷£¬´Ó¶ø³É±¶µØÌá¸ß»Ø¾ø·þÎñ¹¥»÷µÄÍþÁ¦¡£Í¨³££¬¹¥»÷ÕßʹÓÃÒ»¸ö͵ÇÔÕʺŽ«DDoSÖ÷¿Ø·¨Ê½×°ÖÃÔÚÒ»Ì¨ÍÆËã»úÉÏ£¬ÔÚÒ»¸öÉ趨µÄ¹¦·òÖ÷¿Ø·¨Ê½½«Óë´óÁ¿´úÀí·¨Ê½Í¨Ñ¶£¬´úÀí·¨Ê½ÒѾ±»×°ÖÃÔÚInternetÉϵĺܶàÍÆËã»úÉÏ¡£´úÀí·¨Ê½ÊÕµ½Ö¸Áîʱ¾Í·¢Æð¹¥»÷¡£ÀûÓÿͻ§/·þÎñÆ÷¼¼Êõ£¬Ö÷¿Ø·¨Ê½ÄÜÔÚ¼¸ÃëÖÓÄÚ¼¤»î³É°ÙÉÏǧ¸ö´úÀí·¨Ê½µÄÔËÐС£ |
|
¸üй¦·ò£º |
20191112 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_Win32.Zebrocy.Downloader(APT28)_ÏÎ½Ó |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½ZebrocyÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËZebrocy¡£ ZebrocyÊÇAPT28×é֯ʹÓõŤ¾ß£¬Ô̺¬3¸ö×é¼þ¡£Á½¸ö»ùÓÚDelphi¡¢AutoITµÄÏÂÔØÕߣ¬ÁíÒ»¸öÊÇDelphiºóÃÅ¡£APT28×éÖ¯Ò²±»³ÆÎªSofacy¡¢Fancy Bear¡¢Sednit¡¢Tsar Team¡£ |
|
¸üй¦·ò£º |
20191112 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂí_Win32.ImmortalStealer_ÏÎ½Ó |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÇÔÃÜľÂíImmortalStealer¡£ ImmortalStealerÊÇÒ»¸öÖ°ÄÜ׳´óµÄÇÔÃÜľÂí£¬¿ÉÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷±£ÁôµÄÕ˺ÅÃÜÂë¼°Cookie¡£»¹Äܹ»ÇÔÈ¡¸÷Àà¿Í»§¶ËµÄƾ֤£¬ÈçÓÎÏ·Steam¡¢±ÈÌØ±ÒBitcoin-QtµÈ¡£ |
|
¸üй¦·ò£º |
20191112 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂí_Mscleaner.Darkhotel_ÏÎ½Ó |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½MscleanerÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMscleaner¡£ MscleanerÊÇAPT×éÖ¯DarkhotelʹÓõĺóÃÅ£¬ÖØÒªÓÐÖ°ÄÜ¿ªÆôshell£¬ÏÂÔØÎļþ£¬ÉÏ´«Îļþ¡¢ÍøÂçÎļþÃû³ÆÐÅÏ¢¡£ |
|
¸üй¦·ò£º |
20191112 |


¾©¹«Íø°²±¸11010802024551ºÅ