2021-04-06

°ä²¼¹¦·ò 2021-04-07

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Mirai.Putin_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçMirai±äÖÖPutinÊÔͼÏνÓC&C·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai±äÖÖPutin¡£Mirai½©Ê¬ÍøÂçÈä³æÖØÒªÍ¨¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍøÉ豸£¨IoT£©£¬Ô̺¬£ºÂ·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·¡¢DVRÉ豸µÈµÈ£¬IoTÉè±¸ÖØÒªÊÇMIPS¡¢ARMµÈ¼Ü¹¹£¬Òò´æÔÚĬÈÏÃÜÂë¡¢ÈõÃÜÂë¡¢ÑϳÁ·ì϶δʵʱ½¨¸´µÈ³É·Ö£¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£ÓÉÓÚÔ´´úÂëÒѾ­¹«¿ª£¬Mirai³öÏÖÁ˺öà±äÖÖ£¬±¾ÊÂÎñÕë¶ÔÆä±äÖÖPutin¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_SAP_NetWeaver_δÊÚȨËÁÒâÓû§´´½¨·ì϶[CVE-2020-6287][CNNVD-202007-800]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

SAP NetWeaver AS for Java Web×é¼þÖжÌȱÉí·ÝÑéÖ¤£¬Òò¶øÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄSAPϵͳÉϽøÐиßÌØÈ¨»î¶¯¡£ÈôÊDZ»³É¹¦ÀûÓã¬Ôòδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý´´½¨ÓµÓÐ×î´óÌØÈ¨µÄÐÂSAPÓû§£¬ÈƹýËùÓнӼûºÍÊÚȨ½ÚÔ죬´Ó¶øÆëÈ«½ÚÔìSAPϵͳ¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ìøÂ·PMS_ÎļþÉÏ´«·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ìøÂ·PMS£¨ZenTao Project Management System£©ÊÇÒ»¿îÖÐÓ×ÐÍÆóÒµÏîÄ¿ÖÎÀí¹¤¾ß£¬¼¯²úÆ·ÖÎÀí¡¢ÏîÄ¿ÖÎÀí¡¢²âÊÔÖÎÀíÓÚÒ»Éí£¬Í¬Ê±Ô̺¬ÊÂÎñÖÎÀí¡¢×éÖ¯ÖÎÀíµÈÖî¶àÖ°ÄÜ¡£ÔÚìøÂ·PMSÓ×ÓÚ12.4.2µÄ°æ±¾ÖдæÔÚÎļþÉÏ´«·ì϶¡£µÇ½ºó¶ÜµÄ¶ñÒâ¹¥»÷ÕßÄܹ»Í¨¹ýfopen/fread/fwrite²½Öè¶ÁÈ¡»òÉÏ´«ËÁÒâÎļþ£¬³É¹¦ÀûÓ÷ì϶Äܹ»¶Áȡָ±êϵͳÃô¸ÐÎļþÒÔ¼°»ñµÃϵͳÖÎÀíȨÏÞ¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

HTTP_JetBrainsĿ¼й¶

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÀûÓÃJetBrainsµÄ.idea½øÐÐĿ¼ÐÅÏ¢ÇÔÈ¡¡£JetBrainsÊÇÒ»¼Ò½Ý¿ËµÄÈí¼þ¿ª·¢¹«Ë¾£¬ÆìϺ­¸Ç¸÷À࿪·¢²úÆ·

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

HTTP_socat_·´µ¯shellºÅÁî×¢Èë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÏòÖ÷ÕÅÖ÷»ú½øÐÐsocat·´µ¯shellºÅÁî×¢Èë¹¥»÷¡£·´µ¯ÏνÓ£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨·þÎñ¶Ë£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯Ïνӹ¥»÷ÕߵķþÎñ¶Ë·¨Ê½¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞ²»¼°¡¢¶Ë¿Ú±»Õ¼ÓõÈÇé¾°¡£¹¥»÷Õß¹¥»÷³É¹¦ºóÄܹ»Ô¶³ÌÖ´ÐÐϵͳºÅÁî¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

ICMP_ľÂí_¿ÉÒÉICMPËí·_ÏνÓ

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

·¢ÏÖ¿ÉÒɵĵÄicmpÁ÷Á¿¡£Ô´IP¿ÉÄܱ»Ö²ÈëÁËicmpËí·¹¤¾ß£¬Èçicmpsh¡¢icmptunnelµÈ¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_webshell_Yu1uPHPSh3ll_ÉÏ´«ºóÃÅ·¨Ê½

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPµØÖ·Ö÷»úÔÚÏòÖ÷ÕÅIPµØÖ·Ö÷»ú´«ËÍ¿ÉÒɵÄYu1uPHPSh3llwebshellÎļþ¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£µ¥Ò»Ëµ£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬Ê±Ê±½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ¸éÖÃÔÚÍøÕ¾·þÎñÆ÷µÄwebĿ¼ÖУ¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚһ·¡£¶øºó¹¥»÷Õß¾ÍÄܹ»ÓÃwebµÄ·½Ê½£¬Í¨¹ý¸ÃľÂíºóÃŽÚÔìÍøÕ¾·þÎñÆ÷£¬Ô̺¬ÉÏ´«ÏÂÔØÎļþ¡¢²é¿´Êý¾Ý¿â¡¢Ö´ÐÐËÁÒⷨʽºÅÁîµÈ¡£webshellÄܹ»´©Ô½·À»ðǽ£¬ÓÉÓÚÓë±»½ÚÔìµÄ·þÎñÆ÷»òÔ¶³ÌÖ÷»ú»¥»»µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Ú´«µÝµÄ£¬Òò¶ø²»»á±»·À»ðǽÀ¹½Ø¡£²¢ÇÒʹÓÃwebshellͨ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬ÖÎÀíÔ±½ÏÄÑ¿´³öÈëÇÖºÛ¼£¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

HTTP_Fastadmin_chunkid·Ô쬴úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃfastadminµÄ·Ôì¬ÉÏ´«Ö°ÄÜ´æÔڵķì϶Ӳ±àÂëºó׺À´¶¨ÃûºÍ±£ÁôÎļþ£¬²¢Ö´ÐÐËÁÒâ´úÂë¡£fastadminÊÇ»ùÓÚThinkPHP5µÄÄÚÈÝÖÎÀíϵͳ(º¬Ó×·¨Ê½),¿É×Ô½ç˵ÄÚÈÝÄ£ÐÍ¡¢×Ô½ç˵µ¥Ò³¡¢×Ô½ç˵±íµ¥¡¢×Ô½ç˵»áÔ±°ä²¼¡¢¸¶·ÑÔĶÁ¡¢Ó×·¨Ê½µÈÖ°ÄÜ,ÕûºÏFastAdmin»áÔ±ÖÐÐÄ¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_webshell_safedog_dÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÏòÖ÷ÕÅIPÖ÷»úÌáÒésafedog_dÏνÓ¡£safedog_dΪ´óÂí£¬½Ó¼û¸Ã´óÂíÄܹ»»ñµÃwebshellµÄÍøÒ³£¬ÔÚ¸ÃÒ³ÃæÉÏʵÏÖ¿É·´µ¯¶Ë¿Ú£¬sqlÖ´ÐеȲÙ×÷¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_JIRA_δÊÚȨSSRF·ì϶[CVE-2017-9506][CNNVD-201706-286]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

JIRAÊÇAtlassian¹«Ë¾³öÆ·µÄÏîÄ¿ÓëÊÂÎñ¸ú×Ù¹¤¾ß£¬±»¿í·ºÀûÓÃÓÚȱµã¸ú×Ù¡¢¿Í»§·þÎñ¡¢ÐèÒªÍøÂç¡¢Á÷³ÌÉóÅú¡¢¹¤×÷¸ú×Ù¡¢ÏîÄ¿¸ú×ٺͻð¿ìÖÎÀíµÈ¹¤×÷ÁìÓò¡£JiraµÄplugins/servlet/oauth/users/icon-uri×ÊÔ´´æÔÚSSRF·ì϶£¬ÖØÒªÎªJIRAµÄͨ³£Óû§¾ù¿É³É¹¦ÀûÓô˷ì϶ÒÔJira·þÎñ¶ËµÄÉí·Ý½Ó¼ûÄÚÍø×ÊÔ´¡£

¸üй¦·ò£º

20210406


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_±ùЫ_php_webshell_ÉÏ´«

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÖ÷ÕÅÖ÷»úÉÏ´«±ùЫphpwebwhellľÂí¹¥»÷Õß¿ÉÔ¶³Ì½ÚÔì±»ÉÏ´«webshellÖ÷»úÖ´ÐÐËÁÒâ²Ù×÷¡£

¸üй¦·ò£º

20210406


1


ÊÂÎñÃû³Æ£º

TCP_ZooKeeper_δÊÚȨ½Ó¼û·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃZooKeeper´æÔÚµÄδÊÚȨ½Ó¼û·ì϶½øÐй¥»÷µÄÐÐΪ¡£ZooKeeperÊÇÒ»¸öÉ¢²¼Ê½µÄ£¬Ê¢¿ªÔ´ÂëµÄÉ¢²¼Ê½ÀûÓ÷¨Ê½Ð­µ÷·þÎñ£¬ÊÇGoogleµÄChubbyÒ»¸ö¿ªÔ´µÄʵÏÖ£¬ÊÇHadoopºÍHbaseµÄ³ÁÒª×é¼þ¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

DNS_ľÂíºóÃÅ_CobaltStrike.Stager_´úÂëÏÂÔØÖ´ÐÐ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ßCobaltStrikeÌìÉúµÄºóÃÅStagerÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾ÂíCobaltStrike.Beacon,Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÆëÈ«½ÚÔìÊܺ¦»úе£¬²¢½øÐкáÏòÒÆ¶¯¡£CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½Ð­Í¬ºóÉøÈë¹¥»÷¿ò¼Ü¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socket´úÀí¡¢ÌáȨ¡¢´¹µö¡¢Ô¶¿ØÄ¾ÂíµÈÖ°ÄÜ¡£¸Ã¹¤¾ßÏÕЩ¸²¸ÇÁËAPT¹¥»÷Á´ÖÐËù±ØÒªÓõ½µÄ¸÷¸ö¼¼Êõ»·½Ú£¬ÉîÊܺڿÍÃǵÄϲ»¶¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_ASPX_reGeorg-v1.0_ºóÃÅÉÏ´«

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÖ÷ÕÅÖ÷»úÉÏ´«reGeorg-v1.0ľÂíºóÃÅÎļþ¡£reGeorg-v1.0ľÂíÊǺڿͳ£ÓõÄÒ»ÖÖÄÚÍøÉøÈëÁ÷Á¿×ª·¢Ä¾Âí£¬¹¥»÷Õßͨ¹ýÉÏ´«¸ÃľÂíÎļþµ½Web·þÎñÆ÷£¬¶øºóÔÚ±¾µØÍ¨¹ýÌØ¶¨¹¥»÷¾ç±¾ÏνӷþÎñ¶ËµÄľÂíÎļþ½øÐÐÄÚÍøÁ÷Á¿×ª·¢¡£¹¥»÷Õß̰ͼͨ¹ýÕâÖÖ·½Ê½ÈƹýÄÚÍø·À»¤É豸ÒÔWeb·þÎñÆ÷ÎªÌø°å¹¥»÷ÆäËûÄÚÍøÖ÷»ú£¬ÊÔͼ»ñÈ¡ÄÚÍøÆäËû·þÎñÆ÷µÄ½ÚÔìȨ¡£ÉÏ´«Ä¾ÂíºóÃÅ£¬½ø¶øÔ¶³ÌÏνÓľÂíºóÃŹ¥»÷ÄÚÍøÆäËûÖ÷»ú¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

HTTP_Oracle_Weblogic_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-14882][CVE-2020-14750]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃOracleWebLogicÔ¶³Ì´úÂëÖ´Ðзì϶£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâHTTPÒªÇóÀûÓø÷ì϶£¬³É¹¦ÀûÓô˷ì϶¿ÉÄÜÊÕÊÜOracleWebLogicServer¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_MSIL.LimeRat_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËLimeRat¡£LimeRatÊÇÒ»¸ö»ùÓÚCSharpµÄÔ¶¿Ø£¬ÔËÐкó¿ÉÆëÈ«½ÚÔì±»Ö²Èë»úе¡£¿ÉÆëÈ«½ÚÔì±»Ö²Èë»úе¡£

¸üй¦·ò£º

20210406


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_CobaltStrike.Powershell_´úÂëÏÂÔØÖ´ÐÐ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ßCobaltStrikeÌìÉúµÄºóÃÅpowershellºÅÁîÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÄ¾ÂíCobaltStrike.Beacon,Ô´IPµØµãµÄÖ÷»ú¿ÉÄÜÖ´ÐÐÁ˺óÃÅPowershellºÅÁî¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÆëÈ«½ÚÔìÊܺ¦»úе£¬²¢½øÐкáÏòÒÆ¶¯¡£CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½Ð­Í¬ºóÉøÈë¹¥»÷¿ò¼Ü¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socket´úÀí¡¢ÌáȨ¡¢´¹µö¡¢Ô¶¿ØÄ¾ÂíµÈÖ°ÄÜ¡£¸Ã¹¤¾ßÏÕЩ¸²¸ÇÁËAPT¹¥»÷Á´ÖÐËù±ØÒªÓõ½µÄ¸÷¸ö¼¼Êõ»·½Ú£¬ÉîÊܺڿÍÃǵÄϲ»¶¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬ÆëÈ«½Ó¼û½ÚÔì

¸üй¦·ò£º

20210406