2018-10-12

°ä²¼¹¦·ò 2018-10-12

ÐÂÔöÊÂÎñ

ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_OSX_OCEANLOTUS.D(º£Á«»¨)_ÏνÓ

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅOceanLotus¡£¡£¡£¡£¡£OceanLotusÊÇÒ»¸öÖ°ÄÜ׳´óµÄºóÃÅ£¬ £¬ £¬£¬£¬ÖØÒªÍ¨¹ýÓʼþ´«²¼¡£¡£¡£¡£¡£OceanLotusÔËÐкó£¬ £¬ £¬£¬£¬»á³¢ÊÔ»ñÈ¡Ãô¸ÐÐÅÏ¢£¬ £¬ £¬£¬£¬Ò²¿ÉÖ´ÐÐC&C·µ»ØÖ¸Á £¬ £¬£¬£¬È¥ÏÂÔØÆäËûºóÃÅ¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_Win32.Nokki_ÏνÓ

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ºóÃÅNokkiÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËNokki¡£¡£¡£¡£¡£NokkiÊÇÒ»¸öÖ°ÄÜ׳´óµÄºóÃÅ£¬ £¬ £¬£¬£¬³õ´Î³öÏÖÊÇÔÚ2018ÄêÒ»Ô£¬ £¬ £¬£¬£¬ÖØÒªÕë¶ÔÅ·ÖÞ¡¢¶«ÄÏÑǵȵØÓò¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

HTTP_Apache_Portals_Pluto_3.0.0Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2018-1306]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃApache PortletV3AnnotatedDemo.MultipartPortlet²å¼þÎļþÉÏ´«·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£ PortletV3AnnotatedDemo.MultipartPortlet²å¼þ´æÔÚÎļþÉÏ´«·ì϶£¬ £¬ £¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÉÏ´«ËÁÒâÎļþ¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

HTTP_NVRMini2_ÈÆ¹ýÉí·ÝÑéÖ¤Åú¸ÄÓû§ÃÜÂë[CVE-2018-1150]

ÊÂÎñ¼¶±ð£º

µÍ¼¶ÊÂÎñ

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÊÔIJÀûÓÃNVRMini2_ÈÆ¹ýÉí·ÝÑéÖ¤Åú¸ÄÓû§ÃÜÂë¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£ÈôÊÇ´æÔÚÃûΪ/ tmp / mosesµÄÎļþ£¬ £¬ £¬£¬£¬ÔòÆôÓúóÃÅ¡£¡£¡£¡£¡£ËüÔÊÐíÔÚϵͳÉÏÁгöËùÓÐЧ»§ÕÊ»§£¬ £¬ £¬£¬£¬²¢ÔÊÐíijÈ˸ü¸ÄÈκÎÕÊ»§µÄÃÜÂë¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

HTTP_NVRMini2_cgi_system_»º³åÇøÒç¶Âí½Å[CVE-2018-1149]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ 

°²È«ÀàÐÍ£º

»º³åÒç³ö 

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÊÔIJÀûÓÃNVRMini2_cgi_system»º³åÇøÒç¶Âí½Å¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£ NVRMini2ʹÓÿªÔ´Web·þÎñÆ÷£¬ £¬ £¬£¬£¬Í¨¹ý¹«¹²Íø¹Ø½Ó¿Ú£¨CGI£©ºÍ̸֧³ÖһЩ¿ÉÖ´Ðжþ½øÔìÎļþ¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£Äܹ»ÔÚNVRMini2ÉÏÖ´ÐеÄCGI¶þ½øÔìÎļþÖ®Ò»ÊÇ¡°cgi_system¡±£¬ £¬ £¬£¬£¬Äܹ»Í¨¹ýhttp£º// xxxx / cgi-bin / cgi_system½Ó¼ûËü¡£¡£¡£¡£¡£´Ë¶þ½øÔìÎļþ´¦ÖñØÒªÓû§½øÐÐÉí·ÝÑéÖ¤µÄ¸÷ÀàºÅÁîºÍ²Ù×÷¡£¡£¡£¡£¡£ÔÚÉí·ÝÑéÖ¤ÆÚ¼ä£¬ £¬ £¬£¬£¬²»²é³­cookie²ÎÊýµÄ»á»°ID´óÓ×£¬ £¬ £¬£¬£¬ÕâÔÊÐísprintfº¯ÊýÖеIJֿ⻺³åÇøÒç³ö¡£¡£¡£¡£¡£´Ë·ì϶ÔÊÐíʹÓá°root¡±»òÖÎÀíԱȨÏÞÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

HTTP_Joomla_Component_Music_Collection_3.0.3_SQL×¢Èë·ì϶[CVE-2018-17375]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

CGI¹¥»÷ 

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÊÔIJÀûÓÃJoomla_Component_Music_Collection_3.0.3_SQL_Injection·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

HTTP_Joomla_Component_Reverse_Auction_Factory_4.3.8_SQL_Injection[CVE-2018-17376]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ 

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÊÔIJÀûÓÃJoomla_Component_Reverse_Auction_Factory_4.3.8_SQL_Injection·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

HTTP_Joomla_Component_Questions_1.4.3_SQL_Injection[CVE-2018-17377]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApache Struts2Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£ Apache StrutsÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áÕÆ¹ÜÊØ»¤µÄÒ»¿îÓÃÓÚ´´½¨ÆóÒµ¼¶JavaWebÀûÓõĿªÔ´¿ò¼Ü¡£¡£¡£¡£¡£ Apache Struts 2.0.0ÖÁ2.3.15.1°æ±¾ÖдæÔÚ°²È«·ì϶£¬ £¬ £¬£¬£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ä¬ÈÏÆôÓÃDynamic Method Invocation»úÔì¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓô˷ì϶ÔÚÊÜÓ°ÏìÀûÓøߵÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

HTTP_Joomla_Component_Penny_Auction_Factory_2.0.4_SQL_Injection[CVE-2018-17378]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÊÔIJÀûÓÃJoomla_Component_Questions_1.4.3_SQL_Injection·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

TCP_Malware_VPNFilter_±äÖÖÏνÓCC

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ 

ÊÂÎñÃèÊö£º

¼ì²âµ½VPNFilterÊÔͼͨ¹ýSYNËí·¼¼Êõ»ñÈ¡C&CµÄIPµØÖ·¡£¡£¡£¡£¡£ ¸Ã¶ñÒâÈí¼þͨ¹ýÀûÓ÷ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽµÈÎïÁªÍøÉ豸·ì϶½øÐÐ¿í·ºµÄϰȾºÍ´«²¼

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


Åú¸ÄÊÂÎñ

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_ZXShell_·´ÏòÏνÓ

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¸ÃÊÂÎñÔ´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËZXShellľÂí£¬ £¬ £¬£¬£¬Ä¾ÂíµÄ½ÚÔìÕßÄܹ»Í¨¹ý¸ÃľÂí¶Ô±»Ö²ÈëľÂíµÄÖ÷»úÖ´ÐÐÆëÈ«µÄ½ÚÔì¡£¡£¡£¡£¡£ ZXShellÊÇÒ»¿îÔ¶³Ì½ÚÔ취ʽ£¬ £¬ £¬£¬£¬ÖØÒªÖ°ÄÜÈçÏ£º Ô¶³Ì×¥ÆÁ£¬ £¬ £¬£¬£¬ÊÓÆµ²¶»ñ£¬ £¬ £¬£¬£¬ÎļþÖÎÀí¡¢×¢²á±íÖÎÀí¡¢¹ý³ÌÖÎÀí¡¢¼üÅ̼ͼ¡¢Ô¶³ÌÖ´ÐÐÎļþ£¬ £¬ £¬£¬£¬Ô¶³ÌÏÂÔØÎļþµÈÖ°ÄÜ¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Linux.DDoS.Gafgyt_ÏνÓ

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ 

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDDoS.Gafgyt¡£¡£¡£¡£¡£ DDoS.GafgytÊÇÒ»¸öLinux½©Ê¬ÍøÂ磬 £¬ £¬£¬£¬ÖØÒªÖ°ÄÜÊǶÔÖ¸¶¨Ö¸±ê»úеÌáÒéDDoS¹¥»÷

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Win32.TaskHost.Stealer_ÏνÓ

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíTaskHost¡£¡£¡£¡£¡£ TaskHostÊÇÒ»¸öÇÔÃÜľÂí£¬ £¬ £¬£¬£¬»áÉÏ´«Ìض¨ºó׺ÃûµÄÎļþµ½ÆäC&C£¬ £¬ £¬£¬£¬Èç.doc¡¢.xls¡¢.pdf¡¢.ppt¡¢.eml¡¢.msg¡¢.rtfµÈ¡£¡£¡£¡£¡£

¸üй¦·ò£º

20181012

ĬÈÏ×÷Ϊ£º

Åׯú