2020-03-10
°ä²¼¹¦·ò 2020-03-11ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º
HTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
CMS¹¥»÷¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9548]¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ
¸üй¦·ò£º
20200310
ÊÂÎñÃû³Æ£º
HTTP_¿ÉÒÉ.NET·´ÐòÁл¯Êý¾Ý
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½Ô´IPÖ÷»úÔÚ¶Ô¿ÉÄÜ´æÔÚ.NET·´ÐòÁл¯·ì϶µÄÒ³Ãæ·¢ËÍ¿ÉÒÉ·´ÐòÁл¯Êý¾Ý
¹¥»÷Õß¿ÉÌá½»¾«ÐÄ»ú¹ØµÄ·´ÐòÁл¯Êý¾ÝÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÖ´ÐÐËÁÒâ´úÂë¡£
¸üй¦·ò£º
20200310
ÊÂÎñÃû³Æ£º
HTTP_ºóÃÅ_CharmingKitten.Backdoor_ÊÔͼÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½ CharmingKitten.Backdoor ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷,Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCharmingKitten.Backdoor¡£
CharmingKitten.BackdoorÊÇCharming Kitten×éÖ¯µÄÒ»¸öºóÃÅ£¬Ëü»áÇÔÈ¡Óû§µÄÍÆËã»úÐÅÏ¢£¬Èç²Ù×÷ϵͳÐÅÏ¢¡¢ipµØÖ·µÈ£¬²¢ÇÒ»¹»á´ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÎļþÖ´ÐС£
¸üй¦·ò£º
20200310
|
ÊÂÎñÃû³Æ£º |
UDP_½©Ê¬ÍøÂç_Mozi.P2PBotnet_ÏÎ½Ó |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½½©Ê¬ÍøÂçMoziÊÔͼºÍPeerͨѶ¡£ÓÉÓÚÊÇ»ùÓÚP2PºÍ̸£¬Ô´IPºÍÖ÷ÕÅIPµØµãµÄÖ÷»ú¿ÉÄܶ¼±»Ö²ÈëÁ˽©Ê¬ÍøÂçMozi¡£ MoziÊÇÒ»¸ö»ùÓÚP2PºÍ̸µÄ½©Ê¬ÍøÂç£¬ÖØÒªÖ§³ÖµÄÖ°ÄÜΪ£ºDDoS¹¥»÷¡¢ÍøÂçBotÐÅÏ¢¡¢Ö´ÐÐÖ¸¶¨URLµÄpayload¡¢´ÓÖ¸¶¨µÄURL¸üÐÂÑù±¾¡¢Ö´ÐÐϵͳ»ò×Ô½ç˵ºÅÁî¡£ |
|
¸üй¦·ò£º |
20200310 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º
HTTP_½©Ê¬ÍøÂç_MiraiXMiner_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½½©Ê¬ÍøÂçMiraiXMinerÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMiraiXMiner¡£
MiraiXMinerÊÇÒ»¸öÒÀÈ»»îÔ¾×ŵĽ©Ê¬ÍøÂ磬ÈÚºÏÁ˶àÖÖÒÑÖª²¡¶¾¼Ò×壬Ô̺¬Mirai¡¢MyKings¡¢Ô¶¿Ø¡¢ÍÚ¿óµÈ¡£ÀûÓÃÓÀºãÖ®À¶·ì϶¡¢¹ØÂ·µçÊÓÎïÁªÍøÉ豸·ì϶¡¢MSSQL·ì϶¡¢RDP±¬ÆÆºÍTelnet±¬ÆÆµÈ·½Ê½´«²¼×ÔÉí¡£
¸üй¦·ò£º
20200310
ÊÂÎñÃû³Æ£º
TCP_ľÂíºóÃÅ_Win32/Linux_ircBot_ÏνÓ
°²È«ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÃèÊö£º
¼ì²âµ½ircBotÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËircBot¡£
ircBotÊÇ»ùÓÚircºÍ̸µÄ½©Ê¬ÍøÂç£¬ÖØÒªÖ°ÄÜÊǶÔÖ¸¶¨Ö¸±êÖ÷»úÌáÒéDDoS¹¥»÷¡£»¹Äܹ»ÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£
¸üй¦·ò£º
20200310
ÊÂÎñÃû³Æ£º
TCP_Windows_ϵͳĬÈϹ²ÏíÏνÓ
°²È«ÀàÐÍ£º
°²È«Éó¼Æ
ÊÂÎñÃèÊö£º
¼ì²âµ½Ô´IP¶ÔÖ÷ÕÅÖ÷»ú½øÐÐĬÈÏÏνӵÄÐÐΪ.¡£
WindowsÆô¶¯Ê±³ÇÊÐĬÈÏ´ò¿ªadmin$ ipc$ ºÍÿ¸öÅÌ·ûµÄ¹²Ïí£¬¹¥»÷Õßͨ³£»áÀûÓù²Ïí·ì϶ÈëÇÖµçÄÔÖ÷»ú¡£
±¨¾¯¸ÃÊÂÎñ×¢Ã÷Óпͻ§¶ËÔÚÔ¶³ÌÏνӸ÷þÎñÆ÷£¬²¢ÇÒÓÐÅú¸Ä·þÎñ¶ËÎļþµÄÐÐΪ£¬ÈôÊÇ·þÎñ¶Ë»·¾³×ÔÉí¾ÍÓÐʹÓÃsmbÓйØÖ°ÄܵÄÒµÎñ£¬Äܹ»ºöÂÔ¸ÃÊÂÎñ¡£ÈôÊÇÏëÒª²»ÈÝC$¡¢D$¡¢E$Ò»ÀàµÄ¹²Ïí£¬Äܹ»µ¥»÷¡°ÆðÍ·¡úÔËÐÓ×±ºÅÁÔÚÔËÐд°¿Ú¼üÈë¡°Regedit¡±ºó»Ø³µ£¬´ò¿ª×¢²á±í±à×ëÆ÷¡£Ë³´Î·¢Õ¹[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters
]·ÖÖ§£¬½«ÓҲര¿ÚÖеÄDOWRDÖµ¡°AutoShareServer¡±ÉèÖÃΪ¡°0¡±¼´¿É¡£ ÈôÊÇÒª²»ÈÝADMIN$¹²Ïí£¬Äܹ»ÔÚͬÑùµÄ·ÖÖ§Ï£¬½«ÓҲര¿ÚÖеÄDOWRDÖµ¡°AutoShareWKs¡± ÉèÖÃΪ¡°0¡±¼´¿É¡£ ÈôÊÇÒª²»ÈÝIPC$¹²Ïí£¬Äܹ»ÔÚ×¢²á±í±à×ëÆ÷ÖÐ˳´Î·¢Õ¹[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]·ÖÖ§£¬½«ÓҲര¿ÚÖеÄDOWRDÖµ¡°restrictanonymous¡±ÉèÖÃֵΪ¡°1¡±¼´¿É¡£
¸üй¦·ò£º
20200310
ÊÂÎñÃû³Æ£º
HTTP_Java·´ÐòÁл¯_POST·½Ê½_ysoserial¶ñÒâÊý¾Ý
°²È«ÀàÐÍ£º
°²È«·ì϶
ÊÂÎñÃèÊö£º
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_Java·´ÐòÁл¯_POST·½Ê½_ysoserial¶ñÒâÊý¾Ý¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£
Èô½Ó¼ûµÄÒ³Ãæ´æÔÚ·ì϶£¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄ Java ÐòÁл¯¶ÔÏó£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£
¸üй¦·ò£º
20200310


¾©¹«Íø°²±¸11010802024551ºÅ