2019-11-26

°ä²¼¹¦·ò 2019-11-26

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_SCADA_Schneider_Electric_U.motion_Builder_ÊäÈëÑéÖ¤·ì϶[CVE-2018-7787]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃSchneider Electric U.motion BuilderÊäÈëÑéÖ¤·ì϶À´Ö´Ðй¥»÷µÄÐÐΪ¡£

Schneider Electric U.motion BuilderÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄÒ»Ì××Ô¶¯»¯»úÔì¹¹½¨½â¾ö¹æ»®¡£

Schneider Electric U.motion Builder 1.3.4֮ǰ°æ±¾ÖдæÔÚÊäÈëÑéÖ¤·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·µÄÑéÖ¤HTTP GETÒªÇóÖÓ×®context¡¯²ÎÊýµÄÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶й¼ûô¸ÐÐÅÏ¢¡£

¸üй¦·ò£º

20191126














ÊÂÎñÃû³Æ£º

HTTP_LCDS_LAquis_SCADA°²È«·ì϶[CVE-2018-18996]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃLCDS LAquis SCADA°²È«·ì϶À´Ö´ÐкÅÁîµÄÐÐΪ

LCDS LAquis SCADAÊǰÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾Ý²É¼¯Óë¼à¶½½ÚÔ죩ϵͳ¡£¸ÃÏµÍ³ÖØÒªÓÃÓÚ¶ÔÕ¼ÓÐͨѶ¼¼ÊõµÄÉ豸½øÐÐÊý¾Ý²É¼¯ºÍ¹ý³Ì½ÚÔì¡£

LCDS LAquis SCADA 4.1.0.3870°æ±¾ÖдæÔÚ°²È«·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓнøÐÐÕýÈ·µØÊÚȨ»ò¹ýÂ˱ã½Ó¹ÜÁËÓû§ÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚϵͳÉÏÖ´ÐдúÂë¡£

¸üй¦·ò£º

20191126












ÊÂÎñÃû³Æ£º

HTTP_LAquis_SCADA_HTTP²ÎÊýºÅÁî×¢Èë·ì϶[CVE-2018-18992]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃLAquis SCADA PAGINA TITULO HTTP²ÎÊýºÅÁî×¢Èë·ì϶À´Ö´ÐкÅÁîµÄÐÐΪ¡£

LCDS LAquis SCADAÊǰÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾Ý²É¼¯Óë¼à¶½½ÚÔ죩ϵͳ¡£¸ÃÏµÍ³ÖØÒªÓÃÓÚ¶ÔÕ¼ÓÐͨѶ¼¼ÊõµÄÉ豸½øÐÐÊý¾Ý²É¼¯ºÍ¹ý³Ì½ÚÔì¡£

LCDS LAquis SCADA 4.1.0.3870°æ±¾ÖдæÔÚ°²È«·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓнøÐÐÕýÈ·µØ¹ýÂ˱ã½Ó¹ÜÁËÓû§ÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚϵͳÉÏÖ´ÐдúÂë¡£

HTTPÒªÇóacompanhamentotela.lhtmlµÄPAGINA²ÎÊýºÍrelatorioindividual.lhtmlµÄÒªÇóÖеÄTITULO²ÎÊý¶¼²»ÊʺϺÅÁî×¢Èë×Ö·û¡£ ¹¥»÷ÕßÄܹ»·¢ËÍÌØÔìµÄHTTP GET»òPOSTÒªÇó£¬ÒÔÔÚÖ¸±êÍÆËã»úÉÏÖ´ÐкÅÁî¡£

¸üй¦·ò£º

20191119















ÊÂÎñÃû³Æ£º

TCP_Advantech_WebAccess_SCADA_BwPSLinkZip_Stack_Buffer_Overflow

[CVE-2018-7499]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃAdvantech WebAccess BwPSLinkZip »ùÓÚÕ»µÄ»º³åÇøÒç¶Âí½ÅÀ´Ö´ÐÐËÁÒâ´úÂëµÄÐÐΪ¡£

Advantech WebAccessÊÇÑлª£¨Advantech£©¹«Ë¾µÄ²úÆ·¡£Advantech WebAccessÊÇÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý½ÚÔ죬²¢ÌṩԶ³Ì½ÚÔìºÍÖÎÀí×Ô¶¯»¯É豸µÄÖ°ÄÜ¡£WebAccess DashboardÊÇÆäÖеÄÒ»¸öÒDZí°å×é¼þ£»WebAccess Scada NodeÊÇÆäÖеÄÒ»¸ö¼à¿Ø½Úµã×é¼þ¡£WebAccess/NMSÊÇÒ»Ì×ÓÃÓÚÍøÂçÖÎÀíϵͳ£¨NMS£©µÄÍøÂçä¯ÀÀÆ÷»ù´¡Ì×¼þ¡£

¸Ã·ì϶ÊÇÓÉÓÚÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´Ôìµ½BwPSLinkZip.exeµÄ²Ö¿â»º³åÇøÖÐʱ¶ÌȱÌìǵ²é³­ËùÖ¡£

ͨ¹ý¹¹½¨ÌØÊâµÄRPCÒªÇ󣬹¥»÷ÕßÄܹ»ÔÚWebAccess¹ý³ÌµÄ¸ßµÍÎÄÖе¼ÖÂËÁÒâ´úÂëÖ´ÐлòÒì³£ÖÕÖ¹¡£

¸üй¦·ò£º

20191126



















Åú¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_KG.Rat_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£

Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

KuGou.RatÊÇÒ»¸öºóÃÅ£¬ÏνÓÔ¶³Ì·þÎñÆ÷£¬½ÓÊÜÖ´ÐкڿÍÖ¸ÁÄܹ»ÆëÈ«½ÚÔ챻ϰȾ»úе¡£ÊÔͼ»ñÈ¡Ãô¸Ð£¬Èç¼Í¼°´¼üÐÅÏ¢£¬»ñÈ¡½¹µã´°¿ÚµÄ±êÌâ¡£

¸üй¦·ò£º

20191126










ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_PoisonIvy_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

Poison IvyÊÇÒ»¸ö¼«¶ÈÊ¢ÐеÄÔ¶³Ì½ÚÔ칤¾ß£¬ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì±»Ö²Èë»úе¡£

¸üй¦·ò£º

20191126








ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win32.WarZoneRat_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËWarZoneRat¡£

WarZoneRatÊÇÒ»¸öÖ°ÄÜ׳´óµÄÔ¶¿Ø£¬ÔËÐкó¿ÉÆëÈ«½ÚÔì±»Ö²Èë»úе¡£

¸üй¦·ò£º

20191126








ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_¹í»êÔ¶¿Ø¿ÉÒɱäÖÖ_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£

Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

¹í»êÔ¶¿Ø·¨Ê½ÊÇÀûÓÃÒ»¸öƾ¾ÝGh0stÔ¶¿ØµÄÔ´ÂëÅú¸Ä¶øÀ´µÄºóÃÅ¡£ÔËÐкóÄܹ»ÆëÈ«½ÚÔ챻ϰȾ»úе¡£

¸üй¦·ò£º

20191126










ÊÂÎñÃû³Æ£º

TUDP_ºóÃÅ_Win32.ZeroAcess_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£

Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

Win32.ZeroAcessÊÇÒ»¸öºóÃÅ£¬ÔËÐкó£¬×¢ÈëÆäËû¹ý³Ì¡£ÏÂÔØÆäËû²¡¶¾»òÕßÅäÏàÐÅÏ¢»òÕßÄ£¿éµÈ»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£

Éϱ¨¸ÃÊÂÎñÓÐÁ½ÖÖ¿ÉÄÜ£¬Ò»ÊÇÔ´Ö÷»ú±»Ï°È¾ÁË£¬ÏνÓCC·þÎñÆ÷£»¶þÊÇZeroAcess·þÎñÆ÷¶Ëͨ¹ýshadan´úÀí·½Ê½½øÐÐɨÃèÐÐΪ£¬ÖØÒª¿´Ô´IPÊÇ·ñÊDZ¾µ¥ÔªµÄIPµØÖ·¡£

¸üй¦·ò£º

20191126












ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Linux.BillGates_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅBillGates¡£

BillGatesÊÇLinuxƽ̨ϵÄÒ»¸ö½©Ê¬ÍøÂç£¬ÖØÒªÖ°ÄÜÊÇÕë¶ÔÖ¸¶¨Ö¸±ê½øÐÐDDoS¹¥»÷¡£

¸üй¦·ò£º

20191126









ÊÂÎñÃû³Æ£º

TCP_ľÂí_CoinMiner_ÏÎ½Ó¿ó³Ø³É¹¦

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinMinerľÂí¡£

CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£

¸üй¦·ò£º

20191126









ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_Win32.wingames(ÂûÁ黨)_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅwingames¡£

wingamesÊÇÒ»¸öÖ°Äܼ«¶È׳´óµÄºóÃÅ£¬ÔËÐкó£¬Äܹ»ÆëÈ«½ÚÔì±»Ö²Èë»úе¡£

¸üй¦·ò£º

20191126








ÊÂÎñÃû³Æ£º

TCP_ľÂí_CoinMiner_³¢ÊÔÏνӿó³Ø

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinminerľÂí¡£

CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£

¸üй¦·ò£º

20191126