2020-02-25

°ä²¼¹¦·ò 2020-02-25

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

DNS_ºóÃÅ_Trojan.Mozart

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅ Mozart¡£

Mozart ÊÇÒ»¸öÖ°Äܼ«¶È׳´óµÄºóÃÅ £¬ÀûÓÃDNSºÍ̸ÓëC&C·þÎñÆ÷ͨѶ¡£Mozart¿ÉÄÜÍøÂçÍÆËã»úÐÅÏ¢·¢ËÍÖÁ·þÎñÆ÷ £¬²¢ÇÒ´Ó·þÎñÆ÷ÏÂÔØÎļþÖ´ÐС£

¸üй¦·ò£º

20200225

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_VMware_SD-WAN_by_VeloCloudÐÅϢй¶·ì϶[CVE-2019-5533]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýVMware SD-WAN by VeloCloudÐÅϢй¶·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£

VMware SD-WAN by VeloCloudÊÇÃÀ¹úÍþ¨VMware£©¹«Ë¾µÄÒ»Ì×Èí¼þ½ç˵µÄWAN£¨¹ãÓòÍø£©½â¾ö¹æ»®¡£¸Ã²úÆ·Ìṩ¶ÔÔÆÊý¾ÝÖÐÐĺÍÀûÓ÷¨Ê½µÄÓÅ»¯½Ó¼û¡£

VMware SD-WAN by VeloCloud   3.3.0֮ǰµÄ3.x°æ±¾ÖдæÔÚÐÅϢй¶·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÔËÐйý³ÌÖдæÔÚÅäÖõÈÃýÎó¡£Î´ÊÚȨµÄ¹¥»÷Õß¿ÉÀûÓ÷ì϶»ñÈ¡ÊÜÓ°Ïì×é¼þÃô¸ÐÐÅÏ¢¡£

¸üй¦·ò£º

20200225 


ÊÂÎñÃû³Æ£º

TCP_Jackson_Databind_¿ÉÒÉ·´ÐòÁл¯Àà_xbean[CVE-2020-8840]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃTCP_Jackson_databind_¿ÉÒÉ·´ÐòÁл¯À๥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£

¸üй¦·ò£º

20200225


ÊÂÎñÃû³Æ£º

HTTP_CryptoPatronumÀÕË÷²¡¶¾_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¸ÃÊÂÎñÅú×¢µ½ÀÕË÷Èí¼þCryptoPatronumÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÀÕË÷Èí¼þCryptoPatronum¡£

CryptoPatronumÊÇÒ»¿îÀÕË÷Èí¼þ £¬ÔËÐкó¼ÓÃܱ»Ö²Èë»úеÉϵÄÎļþ £¬²¢ÀÕË÷±ÈÌØ±ÒÀ´½âÃÜ¡£

¸üй¦·ò£º

20200225


ÊÂÎñÃû³Æ£º

HTTP_fusionauth_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-7799]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíFileStolen¡£

FileStolenµÄÖØÒªÖ°ÄÜΪÎļþÇÔÈ¡ £¬ÇÔȡָ¶¨Âß¼­´ÅÅÌÏÂÖ¸¶¨ÎļþÃûµÄÎļþ²¢ÇÒÉÏ´«µ½CC·þÎñÆ÷ £¬ÇÔÈ¡µÄÎļþÀàÐÍÔ̺¬£ºtxt¡¢ppt¡¢pptx¡¢pdf¡¢doc¡¢docx¡¢xls¡¢xlsx¡¢zip¡¢7z¡¢rtf¡£

¸ÃľÂíÔÚAPT×éÖ¯ÂûÁ黨BitterµÄ¹¥»÷ÖÐʹÓá£

¸üй¦·ò£º

20200225

 

Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Win32.FileStolen_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

CMS¹¥»÷¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃfusionauth_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-7799]¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£

¸üй¦·ò£º

20200225