2018-06-22

°ä²¼¹¦·ò 2018-06-22

ÐÂÔöÊÂÎñ

ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_Win32.Kazuar_ÏνÓ

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËKazuar¡£KazuarÊÇAPT×éÖ¯Turla¿ª·¢Ê¹ÓõÄÒ»¸öºóÃÅ£¬Ö°Äܼ«¶È׳´ó£¬ÔËÐкóÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì±»Ö²Èë»úе¡£

¸üй¦·ò£º

20180622

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win32.Duuzer(HiddenCobra)_ÏνÓ

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDuuzer¡£DuuzerÊÇAPT×éÖ¯Hidden CobraËùʹÓõĺóÃÅ£¬Ö°Äܼ«¶È׳´ó¡£ÔËÐкó£¬¿ÉÆëÈ«½ÚÔì±»Ö²Èë»úе¡£

¸üй¦·ò£º

20180622

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

TCP_Malware_VPNFilter_GetCC

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½VPNFilterÊÔͼͨ¹ýSYNËí·¼¼Êõ»ñÈ¡C&CµÄIPµØÖ·¡£¸Ã¶ñÒâÈí¼þͨ¹ýÀûÓ÷ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽµÈÎïÁªÍøÉ豸·ì϶½øÐÐ¿í·ºµÄϰȾºÍ´«²¼¡£

¸üй¦·ò£º

20180622

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

TCP_Malware_Akdoor.R228914_ÏνӷþÎñÆ÷

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Akdoor.R228914ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¶ñÒâÈí¼þAkdoor.R228914ÊÇÒ»¸öµ¥Ò»µÄºóÃÅ£¬Í¨¹ýºÅÁîÌáÐÑ·ûÖ´ÐкÅÁî¡£ ËüÓÐÒ»¸ö¹ÖÒìµÄºÅÁîºÍ½ÚÔìºÍ̸¡£

¸üй¦·ò£º

20180622

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32.Sisfader_ÏνÓ

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËSisfader¡£SisfaderÊÇÒ»¸öºóÃÅ£¬Ö°Äܼ«¶È׳´ó¡£ÔËÐкó£¬¿ÉÆëÈ«½ÚÔì±»Ö²Èë»úе¡£

¸üй¦·ò£º

20180622

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

TCP_GPON¼Òͥ·ÓÉÆ÷°²È«·ì϶[CVE-2018-10562]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýGPON¼Òͥ·ÓÉÆ÷ÖдæÔڵݲȫ·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£Dasan GPONÊǺ«¹úDasan¹«Ë¾µÄÒ»¿î¼ÒÓ÷ÓÉÆ÷²úÆ·¡£Dasan GPON¼Òͥ·ÓÉÆ÷ÖдæÔÚ°²È«·ì϶¡£¹¥»÷Õß¿Éͨ¹ýÏòÉ豸µÄËÁÒâURLÔö³¤¡®?images¡¯ÀûÓø÷ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤¡£Dasan GPON¼Òͥ·ÓÉÆ÷ÖдæÔÚºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚÓû§ÔٴνӼû/diag.htmlÒ³ÃæÊ±Â·ÓÉÆ÷½«ÒòÌØÍø°üË÷ÇóÆ÷µÄÁ˾ֱ£ÁôÔÚ/tmpÖв¢½«Ëü´«Ê䏸Óû§¡£¹¥»÷Õß¿Éͨ¹ýÏòGponForm/diag_Form URI·¢ËÍ´øÓС®dest_host¡¯²ÎÊýµÄdiag_action=pingÒªÇóÀûÓø÷ì϶ִÐкÅÁî²¢¼ìË÷Êä³ö¡£muhstik.scanner »áÌáÒé¸Ã·ì϶ɨÃ裬ÀûÓø÷ì϶ÆÈʹGPONÒ׸ÐÉ豸Ïò»ã±¨·þÎñÆ÷»ã±¨×´Ì¬¡£

¸üй¦·ò£º

20180622

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_ElasticSearch_ºÅÁîÖ´Ðзì϶[CVE-2014-3120]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃElasticSearchÔ¶³ÌºÅÁîÖ´Ðзì϶½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearchÖ§³Ö´«È붯̬¾ç±¾£¨MVEL£©À´Ö´ÐÐһЩ¸´ÔӵIJÙ×÷£¬¶øMVEL¿ÉÖ´ÐÐJava´úÂ룬¹¥»÷ÕßÀûÓø÷ì϶Äܹ»ÔÚElasticSearch·þÎñÆ÷ÖÐÖ´ÐÐËÁÒâJava´úÂë»òºÅÁî¡£

¸üй¦·ò£º

20180622

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_ElasticSearch_ºÅÁîÖ´Ðзì϶[CVE-2015-1427]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃElasticSearchÔ¶³ÌÃüÁîÖ´Ðзì϶½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearchÖ§³Ö´«È붯̬¾ç±¾£¨Groovy£©À´Ö´ÐÐһЩ¸´ÔӵIJÙ×÷£¬¶øGroovy¿ÉÖ´ÐÐJava´úÂë¡£ElasticSearchÔÚʹÓÃGroovy˵»°Ö´ÐкÅÁîʱ´æÔÚɳºÐ»úÔ죬µ«¹¥»÷ÕßÈÔÄܹ»ÀûÓ÷ìÏ¶ÈÆ¹ýɳºÐÔÚElasticSearch·þÎñÆ÷ÖÐÖ´ÐÐËÁÒâJava´úÂë»òºÅÁî¡£

¸üй¦·ò£º

20180622

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_elasticsearch-head_Ŀ¼´©Ô½·ì϶[CVE-2015-3337]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃElasticSearch head²å¼þĿ¼´©Ô½·ì϶½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔÀûÓø÷ì϶¶ÁÈ¡µ½²Ù×÷ϵͳÉϵÄËÁÒâÎļþ¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearch head²å¼þ´æÔÚĿ¼´©Ô½·ì϶£¬¹¥»÷ÕßÀûÓø÷ì϶¿É¶ÁÈ¡²Ù×÷ϵͳÉϵÄËÁÒâÎļþ¡£

¸üй¦·ò£º

20180622

ĬÈÏ×÷Ϊ£º

Åׯú

ÊÂÎñÃû³Æ£º

HTTP_ElasticSearch_Ŀ¼´©Ô½·ì϶[CVE-2015-5531]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃElasticSearchĿ¼´©Ô½·ì϶½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔÀûÓø÷ì϶¶ÁÈ¡µ½²Ù×÷ϵͳÉϵÄËÁÒâÎļþ¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearch´æÔÚĿ¼´©Ô½·ì϶£¬¹¥»÷ÕßÀûÓø÷ì϶¿É¶ÁÈ¡²Ù×÷ϵͳÉϵÄËÁÒâÎļþ¡£

¸üй¦·ò£º

20180622

ĬÈÏ×÷Ϊ£º

Åׯú