2020-11-24
°ä²¼¹¦·ò 2020-11-24ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_Linux.Ngioweb_ÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½NgiowebÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷£¬ÒªÇóµÚ¶þ½×¶ÎµÄC&C¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËNgioweb¡£NgiowebÊÇÒ»¸öLinuxϵͳϵÄProxy Botnet£¬ÖØÒªÖ°ÄÜÊÇÔÚÊܺ¦Õß»úеÉÏÌṩ·´ÏòÏνӡ£¹²Ö§³Ö4¸öºÅÁWAIT¡¢CONNECT¡¢DISCONNECT¡¢CERT¡£Ä¿Ç°ÒѾ¹Û²ìµ½ÓдóÁ¿²¿ÊðWordPressµÄWeb·þÎñÆ÷±»Ö²ÈëLinux.Ngioweb¡£ÔÚÊܺ¦Õß»úеÉÏÌṩ·´ÏòÏνӡ£ |
¸üй¦·ò£º | 20201124 |
ÊÂÎñÃû³Æ£º | HTTP_Hadoop_YARN_ResourceManagerδÊÚȨ½Ó¼û·ì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃhadoop YARN ResourceManager´æÔÚµÄδÊÚȨ½Ó¼û·ì϶½øÐй¥»÷µÄÐÐΪ |
¸üй¦·ò£º | 20201124 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_XDDown(XDSpy)_ÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½×é¼þXDDownÊÔͼÏνӷþÎñÆ÷£¬Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËXDSpy×éÖ¯ÀûÓõĺóÃÅ,ÖØÒª¹¥»÷¶«Å·ºÍÈû¶ûάÑÇÈ·µ±¾Ö×éÖ¯²¢´ÓÖÐÇÔÈ¡Ãô¸ÐÎļþ¡£XDSpy APT ×éÖ¯´Ó2011ÄêÆðÍ·»îÔ¾£¬µ«Ö±µ½½üÈղű»·¢ÏÖ£¬XDSpy APT×éÖ¯µÄ¹¥»÷Ö¸±êÖØÒªÎ»ÓÚ¶«Å·ºÍÈû¶ûάÑÇ£¬Êܺ¦ÕßÖØÒªÊǾüÊ¡¢±í½»ÓйØÈ·µ±¾Ö»ú¹¹ÒÔ¼°ÉÙÁ¿µÄ˽ӪÆóÒµ¡£ |
¸üй¦·ò£º | 20201124 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_D_Regsvr32(KimsukyAPT)_ľÂíÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | Kimsuky ×éÖ¯ÊÇ×ܲ¿Î»ÓÚ³¯Ï浀 APT ×éÖ¯£¬ÓÖ³Æ ¡°Black Banshee¡±¡¢¡°BabyShark¡± µÈ£¬ÖÁÉÙ´Ó 2013 ÄêÆðÍ·»îÔ¾£¬¸Ã×éÖ¯³Ö¾ÃÕë¶Ôº«¹úµ±¾Ö¡¢ÐÂÎŵȻú¹¹½øÐй¥»÷»î¶¯£¬Ê±Ê±Ê¹ÓôøÓзì϶µÄ hwp Îļþ¡¢¶ñÒâºêÎļþÒÔ¼°¿ªÊÍÔØºÉµÄ PE ÎļþµÈ¶ñÒâÔØºÉ¡£ |
¸üй¦·ò£º | 20201124 |
ÊÂÎñÃû³Æ£º | HTTP_apache_solr_xxe·ì϶£¨¹¥»÷³É¹¦£©[CVE-2018-1308][CNNVD-201804-415] |
°²È«ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃApache solrÔÚÀûÓÃxxe·ì϶½øÐÐÎļþ¶ÁÈ¡²Ù×÷£¬Apache SolrÊÇÒ»¸ö¿ªÔ´µÄËÑË÷·þÎñ£¬Ê¹ÓÃJava˵»°¿ª·¢£¬ÖØÒª»ùÓÚHTTPºÍApache LuceneʵÏֵġ£ |
¸üй¦·ò£º | 20201124 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Discuz!XϵÁÐת»»¹¤¾ßËÁÒâ´úÂëдÈë·ì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | Discuz!XϵÁÐת»»¹¤¾ßËÁÒâ´úÂëдÈë·ì϶Êǹ¥»÷Õß¶Ô×¢½â²¿ÃÅÀûÓû»Ðзûµ¼ÖÂ×¢Èë¶ñÒâPHP´úÂ룬¹¥»÷³É¹¦ºóÄܹ»»ñµÃÖ¸±êÖ÷»úµÄ Webshell £¬½øÒ»²½»ñµÃÍøÕ¾µÄ½ÚÔìȨ¡£ |
¸üй¦·ò£º | 20201124 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_WebLogic_ËÁÒâÎļþÉÏ´«·ì϶[CVE-2019-2618] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃËÁÒâÎļþÉÏ´«·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ£¬CVE-2019-2618·ìÏ¶ÖØÒªÊÇÀûÓÃÁËWebLogic×é¼þÖеÄDeploymentService½Ó¿Ú£¬¸Ã½Ó¿ÚÖ§³ÖÏò·þÎñÆ÷ÉÏ´«ËÁÒâÎļþ¡£¹¥»÷ÕßÍ»ÆÆÁËOAM£¨Oracle Access Management£©ÈÏÖ¤£¬ÉèÖÃwl_request_type²ÎÊýΪapp_upload£¬»ú¹ØÎļþÉÏ´«ÌåʽµÄPOSTÒªÇó°ü£¬ÉÏ´«"font-family:ËÎÌå">ľÂíÎļþ£¬½ø¶øÄܹ»»ñµÃÕû¸ö·þÎñÆ÷µÄȨÏÞ¡£ |
¸üй¦·ò£º | 20201124 |
ÊÂÎñÃû³Æ£º | HTTP_Weblogic_ËÁÒâÎļþ¶ÁÈ¡·ì϶[CVE-2019-2615] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃWeblogicËÁÒâÎļþ¶ÁÈ¡·ì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Weblogic_ËÁÒâÎļþ¶ÁÈ¡·ì϶½Ó¿ÚÊÇÎļþÏÂÔØÓйØÖ°ÄÜʹÓõĽӿڣ¬Ò²ÊÇweblogic serverÖÐÄÚ²¿Ê¹ÓõÄÕý³£Ö°ÄÜ£¬ËùÒԸ÷ì϶±ØÒªweblogicµÄÓû§ÃûÃÜÂ룬µÇ¼ºó¿ÉÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£ |
¸üй¦·ò£º | 20201124 |
ÊÂÎñÃû³Æ£º | TCP_JavaRMI·´ÐòÁл¯_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2017-3241] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃTCP_JavaRMI·´ÐòÁл¯Ô¶³ÌºÅÁîÖ´Ðзì϶½øÐй¥»÷µÄÐÐΪ£¬JavaRMI·´ÐòÁл¯Ô¶³ÌºÅÁîÖ´Ðзì϶½øÐй¥»÷µÄÐÐΪÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâºÅÁî¡£ |
¸üй¦·ò£º | 20201124 |
ÊÂÎñÃû³Æ£º | HTTP_fastjson_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2017-18349] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | FastjsonÊÇÒ»¸öJava¿â£¬Äܹ»½«Java¶ÔÏóת»»ÎªJSONÌåʽ£¬fastjsonÔÚ1.2.24ÒÔ¼°Ö®Ç°°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ°²È«·ì϶¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸ö¾«ÐÄ»ú¹ØµÄJSONÐòÁл¯¶ñÒâ´úÂ룬µ±·¨Ê½Ö´ÐÐJSON·´ÐòÁл¯µÄ¹ý³ÌÖÐÖ´ÐжñÒâ´úÂ룬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ |
¸üй¦·ò£º | 20201124 |
ÊÂÎñÃû³Æ£º | DNS_ľÂí_NetReaper_ÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ê§ÏÝÖ÷»úÉϵÄľÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷£¨C&C£©¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËNetReaperľÂí¡£ |
¸üй¦·ò£º | 20201124 |


¾©¹«Íø°²±¸11010802024551ºÅ