2020-02-18

°ä²¼¹¦·ò 2020-02-18

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º
TCP_ľÂíºóÃÅ_MoleRAT/Pierogi_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½ Pierogi ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÔ¶¿Ø Pierogi ¡£Pierogi ÊÇÒ»¸ö¼«¶È¸´ÔӵĶàÖ°ÄÜÔ¶¿ØÄ¾Âí£¬ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì±»Ö²Èë»úе¡£
¸üй¦·ò£º
20200218


ÊÂÎñÃû³Æ£º
HTTP_ľÂíºóÃÅ_APT34_TONEDEAF2.0_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½ TONEDEAF2.0 ľÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËTONEDEAF2.0 ľÂí ¡£ TONEDEAF2.0ÊÇ TONEDEAF ľÂíµÄ¸ß¶ÈÅú¸Ä°æ±¾¡£TONEDEAFÊÇÒ»¸öľÂí£¬Äܹ»Í¨¹ýHTTPÓëËüµÄCommand and Control·þÎñÆ÷½øÐÐͨѶ£¬ÒÔ±ã½Ó¹ÜºÍÖ´ÐкÅÁî¡£ TONEDEAF 2.0ÊÇTONEDEAFµÄ¸ß¼¶°æ±¾£¬ÓµÓÐÓëԭʼ°æ±¾Ò»ÑùµÄÖ÷ÕÅ£¬µ«ÓµÓо­¹ý¸Ä½øµÄC2ͨѶºÍ̸ºÍ¾­¹ýÄÚÈÝÐÔÅú¸ÄµÄ´úÂë¿â¡£ÓëԭʼµÄTONEDEAFÏà±È£¬TONEDEAF 2.0½öÔ̺¬ËÁÒâShellÖ´ÐÐÖ°ÄÜ£¬²¢ÇÒ²»Ö§³ÖÈκÎÔ¤Ô¼ÒåºÅÁî¡£ËüÒ²¸üÒñ±Î£¬²¢ÇÒÔ̺¬ÖîÈ綯̬µ¼È룬×Ö·û´®½âÂëºÍÊܺ¦ÕߺýŪ²½ÖèÖ®ÀàµÄм¼ÇÉ¡£
¸üй¦·ò£º
20200218


ÊÂÎñÃû³Æ£º
UDP_ºóÃÅ_Roboto.Botnet_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½½©Ê¬ÍøÂçRobotoÊÔͼºÍPeerͨѶ¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçRoboto¡£ RobotoÊÇÒ»¸ö»ùÓÚP2PºÍ̸µÄ½©Ê¬ÍøÂç£¬ÖØÒªÖ§³Ö7ÖÖÖ°ÄÜ£º·´µ¯Shell£¬×ÔÐ¶ÔØ£¬»ñÈ¡¹ý³ÌÍøÂçÐÅÏ¢£¬»ñÈ¡BotÐÅÏ¢£¬Ö´ÐÐϵͳºÅÁÔËÐÐÖ¸¶¨URLÖеļÓÃÜÎļþ£¬DDoS¹¥»÷µÈ¡£
¸üй¦·ò£º
20200218


 

ÊÂÎñÃû³Æ£º
HTTP_SQLServer_ReportingServices_·´ÐòÁл¯_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2020-0618]
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½Ô´IPÖ÷»úÔÚ¶Ô¿ÉÄÜ´æÔÚ·ì϶(CVE-2020-0618)µÄÒ³ÃæÖ´Ðй¥»÷ SQL Server Reporting Services Ìṩһ×é±¾µØ¹¤¾ßºÍ·þÎñ£¬ÓÃÓÚ´´½¨¡¢²¿ÊðºÍÖÎÀí±¨±í¡£SQL Server Reporting Services ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬½öÐè»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÄܹ»ÏòÊÜÓ°Ïì°æ±¾µÄ Reporting Services Ê·ýÌá½»¾«ÐÄ»ú¹ØµÄÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÔÚ Report Server ·þÎñÕÊ»§¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£
¸üй¦·ò£º
20200218