2018-07-13
Ðû²¼Ê±¼ä 2018-07-13ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_Smurf.fileUpload(Confucius)_ÅþÁ¬ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½SmurfÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËSmurf¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
|
|
ÊÂÎñÃû³Æ£º |
TCP_ľÂí_Win32.TrickBot_NetworkCollectorModule |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíTrickBot¡£¡£¡£¡£¡£ TrickBotÊÇÒ»¸ö¹¦Ð§Ç¿´óµÄÇÔÃÜľÂí¡£¡£¡£¡£¡£TrickbotÒøÐÐľÂíÖаüÀ¨Network Collector Module£¬£¬£¬£¬£¬£¬¸ÃÄ£¿é¿ÉÒÔËѼ¯Óû§ÐÅÏ¢ÉÏ´«ÖÁ·þÎñÆ÷¡£¡£¡£¡£¡£ ¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
|
|
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_Win32.LoadMoney_Á¬½Ó |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½LoadmoneyÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËLoadmoney¡£¡£¡£¡£¡£ LoadmoneyÊÇÒ»¸öľÂíÏÂÔØÕߣ¬£¬£¬£¬£¬£¬ÔËÐкó»áÏÂÔØÆäËü¶ñÒâÑù±¾¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
HTTP_Malware_KardonLoader_Á¬½Ó·þÎñÆ÷ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Kardon LoaderÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËKardon Loader¡£¡£¡£¡£¡£ Kardon LoaderÊÇÒ»¸öÈ«¹¦Ð§µÄÏÂÔØÆ÷£¬£¬£¬£¬£¬£¬¿ÉÒÔÏÂÔØºÍ×°ÖÃÆäËû¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬ÒøÐÐľÂí/ƾ֤ÇÔÈ¡Èí¼þµÈ¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_DanaBot.Downloader_ÅþÁ¬ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½DanaBotÊÔͼÏÂÔØ½¹µãMain dll×é¼þ¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDanaBot¡£¡£¡£¡£¡£ DanaBotÊÇÒ»¸öÒøÐÐľÂí£¬£¬£¬£¬£¬£¬°üÀ¨Ò»¸öÏÂÔØ×é¼þ¡£¡£¡£¡£¡£ÏÂÔØ×é¼þÔËÐкó»áÏÂÔØ½¹µãMain dll×é¼þ¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
TCP_ľÂíºóÃÅ_DanaBot_Á¬½Ó |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½DanaBotµÄMain dllÊÔͼÏÂÔØÆäËü×é¼þ¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDanaBot¡£¡£¡£¡£¡£ DanaBotÊÇÒ»¸öÒøÐÐľÂí£¬£¬£¬£¬£¬£¬°üÀ¨Ò»¸öÏÂÔØ×é¼þ¡£¡£¡£¡£¡£ÏÂÔØ×é¼þÔËÐкó»áÏÂÔØ½¹µãMain dll×é¼þ¡£¡£¡£¡£¡£Main dllÏÂÔØVNC¡¢Stealer¡¢SnifferµÈ×é¼þ£¬£¬£¬£¬£¬£¬Íê³ÉÇÔÃÜ¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
TCP_ºóÃÅ_PoisonIvy_Keepalive_Á¬½Ó2 |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½PoisonIvyµÄÐÄÌø°üÊý¾Ý¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPoison Ivy¡£¡£¡£¡£¡£ Poison IvyÊÇÒ»¸ö±»ÆÕ±éÓ¦ÓõÄÔ¶³Ì¿ØÖƹ¤¾ß£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
HTTP_DVR_Ó²Å̼Ïñ»ú_µÇÂ¼ÈÆ¹ýÎó²î[CVE-2018-9995] |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ÍøÂç×°±¸¹¥»÷ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃDVRÓ²Å̼Ïñ»úµÇÂ¼ÈÆ¹ýÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýʹÓÃDVRÈÆ¹ýµÇ¼Îó²îµÇ¼µ½Ó²Å̼Ïñ»úºǫ́£¬£¬£¬£¬£¬£¬²»·¨Ê¹ÓÃÊÓÆµ¼à¿Ø×ÊÔ´¡£¡£¡£¡£¡£ DVRÈ«³ÆDigital Video Recorder(Ó²Å̼Ïñ»ú)£¬£¬£¬£¬£¬£¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеÄÖ÷Òª×é³É²¿·Ö¡£¡£¡£¡£¡£¼ì²âµ½Óжà¿îDVR×°±¸±£´æµÇÂ¼ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÐÞ¸ÄCookie:uid=adminÖ®ºó²¢»á¼ûÌØ¶¨DVRµÄ¿ØÖÆÃæ°å£¬£¬£¬£¬£¬£¬·µ»Ø´Ë×°±¸µÄÃ÷ÎÄÖÎÀíԱƾ֤¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
HTTP_anni°²ÄáXVR_ͬÖáÓ²Å̼Ïñ»ú_ÃÜÂëй¶Îó²î |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ÍøÂç×°±¸¹¥»÷ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃXVRͬÖáÓ²Å̼ÏñÉñÃØÂëй¶Îó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýʹÓÃXVRÃÜÂëй¶Îó²î£¬£¬£¬£¬£¬£¬½ø¶øµÇ¼µ½XVRºǫ́£¬£¬£¬£¬£¬£¬²»·¨Ê¹ÓÃÊÓÆµ¼à¿Ø×ÊÔ´¡£¡£¡£¡£¡£ XVRͬÖáÓ²Å̼Ïñ»ú£¬£¬£¬£¬£¬£¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеÄÖ÷Òª×é³É²¿·Ö¡£¡£¡£¡£¡£¼ì²âµ½anni°²ÄáÓжà¿îXVR×°±¸±£´æÃÜÂëй¶£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý»á¼ûÖ¸¶¨µÄURL£¬£¬£¬£¬£¬£¬XVR×°±¸¼´¿É·µ»ØµÇ¼ÃÜÂë¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
HTTP_Ê©Ä͵Â_Åɶû¸ßϵÁÐÉãÏñ»ú_Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ÍøÂç×°±¸¹¥»÷ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÊ©Ä͵ÂÅɶû¸ßϵÁÐÉãÏñ»úÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬£¬ÊµÑéͨ¹ý¸Ã×°±¸½øÐÐÍÚ¿ó»òÕßDoS¹¥»÷µÈ²»·¨ÐÐΪ¡£¡£¡£¡£¡£ Ê©Ä͵¹«Ë¾ÆìϵÄÅɶû¸ßϵÁÐÉãÏñ»úͨ³£±»ÓÃÓÚÖÖÖÖÉÌÒµºÍ¹¤Òµ¼à¿ØÁìÓò£¬£¬£¬£¬£¬£¬¾ßÓнϺõĻ·¾³ÊÊÓ¦ÐÔ¡£¡£¡£¡£¡£PelcoϵÁÐÉãÏñ»ú±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýPOSTÇëÇóÖеÄenable_leds²ÎÊý×¢Èëí§Òâ´úÂë»òÏÂÁ£¬£¬£¬£¬£¬½ø¶øÍêÈ«¿ØÖÆÉãÏñ»ú¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
HTTP_NETGEAR_DGN1000_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ÍøÂç×°±¸¹¥»÷ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÃÀ¹úÍø¼þNETGEAR DGN1000ϵÁзÓÉÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬£¬ÊµÑéͨ¹ý¸Ã×°±¸½øÐÐÍÚ¿ó»òÕßDoS¹¥»÷µÈ²»·¨ÐÐΪ¡£¡£¡£¡£¡£ ÃÀ¹úÍø¼þNETGEARÊÇÃÀ¹ú×ÅÃûµÄÆóÒµ×°±¸ÌṩÉÌ£¬£¬£¬£¬£¬£¬NETGEAR DGN1000ϵÁзÓÉÆ÷ÆÕ±é±»°²ÅÅÔÚÈ«Çò¸÷´ó»¥ÁªÍø¹«Ë¾¼°¼ÒÍ¥¡£¡£¡£¡£¡£DGN1000ϵÁзÓÉÆ÷±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýURLÖеÄcmd²ÎÊý×¢Èëí§Òâ´úÂë»òÏÂÁ£¬£¬£¬£¬£¬½ø¶øÍêÈ«¿ØÖÆÂ·ÓÉÆ÷¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
|
ÊÂÎñÃû³Æ£º |
HTTP_NETGEAR_JWNR_ÃÜÂëй¶©¶´ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
Çå¾²ÀàÐÍ£º |
ÍøÂç×°±¸¹¥»÷ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃNETGEAR JWNRϵÁзÓÉÆ÷ÃÜÂëй¶Îó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ýʹÓÃJWNRϵÁзÓÉÆ÷ÃÜÂëй¶Îó²î£¬£¬£¬£¬£¬£¬½ø¶øµÇ¼µ½Â·ÓÉÆ÷ºǫ́£¬£¬£¬£¬£¬£¬ÍêÈ«¿ØÖÆÕû¸öÍøÂç¡£¡£¡£¡£¡£ XVR ͬÖáÓ²Å̼Ïñ»ú£¬£¬£¬£¬£¬£¬Í¨³£ÊÇÊÓÆµ¼à¿ØÏµÍ³ÖеÄÖ÷Òª×é³É²¿·Ö¡£¡£¡£¡£¡£¼ì²âµ½anni°²ÄáÓжà¿îXVR×°±¸±£´æÃÜÂëй¶£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý»á¼ûÖ¸¶¨µÄURL£¬£¬£¬£¬£¬£¬XVR×°±¸¼´¿É·µ»ØµÇ¼ÃÜÂë¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20180713 |
|
ĬÈÏÐж¯£º |
ÑïÆú |
ÐÞ¸ÄÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_Microsoft_Windows_HTTP_sysÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2015-1635] |
||
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
||
|
Çå¾²ÀàÐÍ£º |
|
||
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýMicrosoft Windows HTTP.sysÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£ Http.sysÊÇ´¦ÀíHTTPÇëÇóµÄÄÚºËģʽÇý¶¯³ÌÐò¡£¡£¡£¡£¡£ HTTP.sys¹ýʧÆÊÎö½á¹¹µÄHTTPÇëÇóʱ£¬£¬£¬£¬£¬£¬ÔÚʵÏÖÉϱ£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îºó£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÔÚSystemÕÊ»§ÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ |
||
|
¸üÐÂʱ¼ä£º |
20180713 |
||
|
ĬÈÏÐж¯£º |
ÑïÆú |


¾©¹«Íø°²±¸11010802024551ºÅ