2019-12-24
°ä²¼¹¦·ò 2019-12-24ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º
HTTP_ľÂí_BrowserStealer_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½ BrowserStealer ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBrowserStealer¡£
BrowserStealer ÊÇÒ»¸öÇÔÃÜÐÍľÂí£¬¿ÉÄÜ´ÓÓû§ä¯ÀÀÆ÷ÖÐÇÔÈ¡Óû§±£ÁôµÄµÇ¼ƾ֤£¬ÇÔÈ¡µÄä¯ÀÀÆ÷ÀàÐͺ¸ÇÁËÊÐÃæÉÏ´ó²¿ÃÅä¯ÀÀÆ÷¡£
¸üй¦·ò£º
20191224
ÊÂÎñÃû³Æ£º
HTTP_ľÂí_SectorJ04.EmailStealers_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½ SectorJ04.EmailStealers ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËSectorJ04.EmailStealers¡£
SectorJ04.EmailStealers ÊÇÒ»¸öµç×ÓÓʼþÇÔÈ¡·¨Ê½£¬Ëü¿ÉÄÜÍøÂçOutlookºÍThunderbirdÓʼþ¿Í»§¶Ë´æ´¢ÔÚ×¢²á±íÖеÄÏνӺÍ̸ÐÅÏ¢ºÍÕÊ»§ÐÅÏ¢£¬ÀýÈçSMTP£¬IMAPºÍPOP3£¬²¢½«ËüÃÇÒÔÌØ¶¨Ìåʽ·¢Ë͸ø¹¥»÷Õß·þÎñÆ÷¡£
¸üй¦·ò£º
20191224
ÊÂÎñÃû³Æ£º
TCP_ľÂíºóÃÅ_XpertRAT_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½ XpertRat ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÔ¶¿Ø XpertRat¡£XpertRat ÊÇÒ»¸ö¼«¶È¸´ÔӵĶàÖ°ÄÜÔ¶¿ØÄ¾Âí£¬ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì±»Ö²Èë»úе¡£
¸üй¦·ò£º
20191224
ÊÂÎñÃû³Æ£º
HTTP_Linksys_WRT110·ÓÉÆ÷_ºÅÁî×¢Èë·ì϶[CVE-2013-3568]
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃLinksys
WRT110·ÓÉÆ÷ºÅÁî×¢Èë·ì϶½øÐй¥»÷µÄÐÐΪ¡£
Linksys WRT110ÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷²úÆ·¡£
Linksys WRT110ÖдæÔÚºÅÁî×¢Èë·ì϶¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ִÐÐÖ´ÐÐÖÎÀíÔ±²Ù×÷£¬²¢ÒÔrootȨÏÞÖ´ÐÐËÁÒâshellºÅÁî¡£
¸üй¦·ò£º
20191224
ÊÂÎñÃû³Æ£º
TCP_LG_SuperSign_CMS_v2.5_°²È«·ì϶[CVE-2018-17173]
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃLG
SuperSign CMS v2.5°²È«·ì϶À´Ö´ÐкÅÁîµÄÐÐΪ¡£
LG SuperSign CMSÊǺ«¹úÀÖ½ð£¨LG£©¼¯ÍŵÄÒ»Ì×Õë¶ÔLG webOSµÄÄÚÈÝÖÎÀíϵͳ¡£¸Ãϵͳ֧³ÖÏÎ½Ó±í²¿Êý¾Ý¿â£¬²¢ÔÊÐí´ÓÒÆ¶¯É豸½Ó¼û·þÎñÆ÷¡£
LG SuperSign CMSÖдæÔÚ´æÔÚ°²È«·ì϶¡£Ô¶³Ì¹¥»÷¿Éͨ¹ýÏòqsr_server/device/getThumbnail·¢ËÍ¡®sourceUri¡¯²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
¸üй¦·ò£º
20191224
ÊÂÎñÃû³Æ£º
HTTP_WePresent_WIPG1000ÎļþÔ̺¬·ì϶
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½ÀûÓÃWePresent_WIPG1000ÎļþÔ̺¬·ì϶½øÐй¥»÷µÄÐÐΪ¡£
WePresent_WIPG1000ÊǰĴóÀûÑÇwePresentWiPG¹«Ë¾µÄÒ»¿îÓÃÓÚ¶àýÌ廥¶¯½²ÊÚ¡¢´óÐÍ»áÒéµÈµÄÎÞÏßͶӰÉ豸¡£
wePresent WiPG-1000É豸ÖдæÔÚÎļþÔ̺¬·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶¶ÁÈ¡·ÇÊÚȨ½Ó¼ûµÄÎļþ¡£
¸üй¦·ò£º
20191224
ÊÂÎñÃû³Æ£º
HTTP_WePresent_WIPG1000_ϵͳºÅÁî×¢Èë·ì϶
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½ÀûÓÃWePresent WIPG1000ϵͳºÅÁî×¢Èë·ì϶½øÐй¥»÷µÄÐÐΪ¡£
WePresent_WIPG1000ÊǰĴóÀûÑÇwePresentWiPG¹«Ë¾µÄÒ»¿îÓÃÓÚ¶àýÌ廥¶¯½²ÊÚ¡¢´óÐÍ»áÒéµÈµÄÎÞÏßͶӰÉ豸¡£
wePresent WiPG-1000É豸ÖдæÔÚϵͳºÅÁî×¢Èë·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâϵͳºÅÁî¡£
¸üй¦·ò£º
20191224
ÊÂÎñÃû³Æ£º
HTTP_ºóÃÅ_ScarCruft.Group123_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½Ä¾ÂíScarCruftÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËScarCruft¡£
ScarCruftÊdz¯ÏÊAPT×éÖ¯Group123ËùʹÓõÄÒ»¿îºóÃÅ£¬ÖØÒªÕë¶ÔÖк«µÄ±íóÐÐÒµ¡£
¸üй¦·ò£º
20191224
ÊÂÎñÃû³Æ£º
DNS_ľÂíºóÃÅ_AnchorDNS_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½ºóÃÅAnchorDNSÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAnchorDNS¡£
AnchorDNSÊÇTrickBotµÄ±äÖÖ£¬Í¨¹ýDNSºÍ̸ÓëÆäC&CͨѶ¡£ÖØÒªÕë¶Ô¸ß¶Ë½ðÈÚÖ¸±ê£¬ÒÉËÆÀ´×ÔLazarus×éÖ¯¡£
¸üй¦·ò£º
20191224
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB·ì϶ÀûÓÃ(win8.1/2012-x64)
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½Ô´IPÖ÷»ú¶ÔÖ÷ÕÅIP½øÐÐÓÀºãÖ®À¶·ì϶ÀûÓõÄÐÐΪ¡£
Microsoft WindowsÊÇ΢Èí°ä²¼µÄ¼«¶ÈÊ¢ÐеIJÙ×÷ϵͳ¡£
ÈôÊǹ¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;¾«ÐÄ»ú¹ØµÄ»ûÐÎÒªÇó°ü£¬Äܹ»»ñȡָ±ê·þÎñÆ÷µÄϵͳȨÏÞ£¬²¢ÇÒÆëÈ«½ÚÔìÖ¸±êϵͳ¡£
¸üй¦·ò£º
20191224
ÊÂÎñÃû³Æ£º
HTTP_Microsoft_ASP_NET¹þϣì¶ÜÔ¶³Ì»Ø¾ø·þÎñ·ì϶[MS11-100][CVE-2011-3414]
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýMicrosoft ASP.NET¹þϣì¶ÜÔ¶³Ì»Ø¾ø·þÎñ·ì϶[[MS11-100]¹¥»÷Ö÷ÕÅIPµØÖ·Ö÷»ú¡£
ASP.NETÊÇÒ»Ì×ÓÉMicrosoft·Ö·¢µÄÔ®ÊÖ¿ª·¢Õß¹¹½¨»ùÓÚWEBÀûÓõÄϵͳ¡£Microsoft ASP.NETÔÚ´¦ÖÃÆä±íµ¥ÒªÇóֵʱ»áÔì³É¹þϣì¶Ü£¬¹¥»÷Õßͨ¹ý·¢ËÍÒ»Ð©ÌØÔìµÄASP.NET±íµ¥ÒªÇóµ½ÊÜÓ°ÏìASP.NETÕ¾µã¡£ÀûÓô˷ì϶µ¼ÖÂʹÓÃASP.NETµÄÕ¾µãCPUÕ¼ÓÃÂʾçÔö£¬Ê§È¥ÏìÓ¦Õý³£Çé¿öµÄÄÜÁ¦¡£
¸üй¦·ò£º
20191224
ÊÂÎñÃû³Æ£º
HTTP_ºóÃÅ_APT×éÖ¯_MuddyWater_Ô¶³Ì·þÎñÆ÷ÏνÓ
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½Ä¾ÂíºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuddyWater×éÖ¯ÀûÓõĺóÃÅ¡£
MuddyWaterÊÇÒ»¸öÖØÒªÕë¶ÔÒÁÀ¿ËºÍÉ³ÌØ°¢À²®È·µ±¾Ö»ú¹¹µÄAPT×éÖ¯£¬¸ÃAPT×éÖ¯±³ºóµÄÍŶÓͬÑùÕë¶ÔÖж«Å·ÖÞºÍÃÀ¹úµÈÆäËû¹ú¶È¡£ÆäÖØÒªÀûÓÃPowershell½øÐÐËûÃǵĶñÒâÐÐΪ£¬ÔÚһϵÁÐÐж¯ÖÐÑÜÉú³öÁËËûÃǵÄרÓÐľÂíPOWERSTATS¡£¸Ã×éÖ¯µÄ¹¥»÷Ö¸±êÖØÒª¼¯ÖÐÔÚµ±¾Ö£¬Í¨Ñ¶ÓëʯÓÍÁìÓò£¬¸Ã×éÖ¯ÒÉËÆÀ´×ÔÓÚÒÁÀÊ¡£¸ÃÊÂÎñÅú×¢MuddyWater×éÖ¯ÀûÓúóÃÅÓëÔ¶³Ì·þÎñÆ÷ÏνӲ¢½Ó¹ÜºÅÁîÖ´ÐС£
¸üй¦·ò£º
20191224


¾©¹«Íø°²±¸11010802024551ºÅ