2020-11-24
Ðû²¼Ê±¼ä 2020-11-24ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_Linux.Ngioweb_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½NgiowebÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷£¬ÇëÇóµÚ¶þ½×¶ÎµÄC&C¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËNgioweb¡£NgiowebÊÇÒ»¸öLinuxϵͳϵÄProxy Botnet£¬Ö÷Òª¹¦Ð§ÊÇÔÚÊܺ¦Õß»úÆ÷ÉÏÌṩ·´ÏòÁ¬½Ó¡£¹²Ö§³Ö4¸öÃüÁWAIT¡¢CONNECT¡¢DISCONNECT¡¢CERT¡£Ä¿Ç°ÒѾÊӲ쵽ÓдóÁ¿²¿ÊðWordPressµÄWeb·þÎñÆ÷±»Ö²ÈëLinux.Ngioweb¡£ÔÚÊܺ¦Õß»úÆ÷ÉÏÌṩ·´ÏòÁ¬½Ó¡£ |
¸üÐÂʱ¼ä£º | 20201124 |
ʼþÃû³Æ£º | HTTP_Hadoop_YARN_ResourceManagerδÊÚȨ·ÃÎÊ©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃhadoop YARN ResourceManager´æÔÚµÄδÊÚȨ·ÃÎÊ©¶´½øÐй¥»÷µÄÐÐΪ |
¸üÐÂʱ¼ä£º | 20201124 |
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_XDDown(XDSpy)_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½×é¼þXDDownÊÔͼÁ¬½Ó·þÎñÆ÷£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËXDSpy×éÖ¯ÀûÓõĺóÃÅ,Ö÷Òª¹¥»÷¶«Å·ºÍÈû¶ûάÑǵÄÕþ¸®×éÖ¯²¢´ÓÖÐÇÔÈ¡Ãô¸ÐÎļþ¡£XDSpy APT ×éÖ¯´Ó2011Ä꿪ʼ»îÔ¾£¬µ«Ö±µ½½üÈղű»·¢ÏÖ£¬XDSpy APT×éÖ¯µÄ¹¥»÷Ä¿±êÖ÷ҪλÓÚ¶«Å·ºÍÈû¶ûάÑÇ£¬Êܺ¦ÕßÖ÷ÒªÊǾüÊ¡¢Íâ½»Ïà¹ØµÄÕþ¸®»ú¹¹ÒÔ¼°ÉÙÁ¿µÄ˽ӪÆóÒµ¡£ |
¸üÐÂʱ¼ä£º | 20201124 |
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_D_Regsvr32(KimsukyAPT)_ľÂíÁ¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | Kimsuky ×éÖ¯ÊÇ×ܲ¿Î»ÓÚ³¯Ï浀 APT ×éÖ¯£¬ÓÖ³Æ ¡°Black Banshee¡±¡¢¡°BabyShark¡± µÈ£¬ÖÁÉÙ´Ó 2013 Ä꿪ʼ»îÔ¾£¬¸Ã×éÖ¯ºã¾ÃÕë¶Ôº«¹úÕþ¸®¡¢ÐÂÎŵȻú¹¹½øÐй¥»÷»î¶¯£¬¾³£Ê¹ÓôøÓЩ¶´µÄ hwp Îļþ¡¢¶ñÒâºêÎļþÒÔ¼°ÊÍ·ÅÔØºÉµÄ PE ÎļþµÈ¶ñÒâÔغɡ£ |
¸üÐÂʱ¼ä£º | 20201124 |
ʼþÃû³Æ£º | HTTP_apache_solr_xxe©¶´£¨¹¥»÷Àֳɣ©[CVE-2018-1308][CNNVD-201804-415] |
Äþ¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃApache solrÕýÔÚÀûÓÃxxe©¶´½øÐÐÎļþ¶ÁÈ¡²Ù×÷£¬Apache SolrÊÇÒ»¸ö¿ªÔ´µÄËÑË÷·þÎñ£¬Ê¹ÓÃJavaÓïÑÔ¿ª·¢£¬Ö÷Òª»ùÓÚHTTPºÍApache LuceneʵÏֵġ£ |
¸üÐÂʱ¼ä£º | 20201124 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Discuz!XϵÁÐת»»¹¤¾ßÈÎÒâ´úÂëдÈ멶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Discuz!XϵÁÐת»»¹¤¾ßÈÎÒâ´úÂëдÈ멶´Êǹ¥»÷Õ߶Ô×¢ÊͲ¿ÃÅÀûÓû»Ðзûµ¼ÖÂ×¢Èë¶ñÒâPHP´úÂ룬¹¥»÷Àֳɺó¿ÉÒÔ»ñµÃÄ¿±êÖ÷»úµÄ Webshell £¬½øÒ»²½»ñµÃÍøÕ¾µÄ¿ØÖÆȨ¡£ |
¸üÐÂʱ¼ä£º | 20201124 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_WebLogic_ÈÎÒâÎļþÉÏ´«Â©¶´[CVE-2019-2618] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÈÎÒâÎļþÉÏ´«Â©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬CVE-2019-2618©¶´Ö÷ÒªÊÇÀûÓÃÁËWebLogic×é¼þÖеÄDeploymentService½Ó¿Ú£¬¸Ã½Ó¿ÚÖ§³ÖÏò·þÎñÆ÷ÉÏ´«ÈÎÒâÎļþ¡£¹¥»÷ÕßÍ»ÆÆÁËOAM£¨Oracle Access Management£©ÈÏÖ¤£¬ÉèÖÃwl_request_type²ÎÊýΪapp_upload£¬½á¹¹ÎļþÉÏ´«¸ñʽµÄPOSTÇëÇó°ü£¬ÉÏ´«"font-family:ËÎÌå">ľÂíÎļþ£¬½ø¶ø¿ÉÒÔ»ñµÃÕû¸ö·þÎñÆ÷µÄȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20201124 |
ʼþÃû³Æ£º | HTTP_Weblogic_ÈÎÒâÎļþ¶Áȡ©¶´[CVE-2019-2615] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWeblogicÈÎÒâÎļþ¶Áȡ©¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Weblogic_ÈÎÒâÎļþ¶Áȡ©¶´½Ó¿ÚÊÇÎļþÏÂÔØÏà¹Ø¹¦Ð§Ê¹ÓõĽӿڣ¬Ò²ÊÇweblogic serverÖÐÄÚ²¿Ê¹ÓõÄÕý³£¹¦Ð§£¬ËùÒԸ鶴ÐèÒªweblogicµÄÓû§ÃûÃÜÂ룬µÇ¼ºó¿ÉÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡¹ÜÀíԱȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20201124 |
ʼþÃû³Æ£º | TCP_JavaRMI·´ÐòÁл¯_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2017-3241] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃTCP_JavaRMI·´ÐòÁл¯Ô¶³ÌÃüÁîÖ´ÐЩ¶´½øÐй¥»÷µÄÐÐΪ£¬JavaRMI·´ÐòÁл¯Ô¶³ÌÃüÁîÖ´ÐЩ¶´½øÐй¥»÷µÄÐÐΪÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20201124 |
ʼþÃû³Æ£º | HTTP_fastjson_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2017-18349] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | FastjsonÊÇÒ»¸öJava¿â£¬¿ÉÒÔ½«Java¹¤¾ßת»»ÎªJSON¸ñʽ£¬fastjsonÔÚ1.2.24ÒÔ¼°Ö®Ç°°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣÄþ¾²Â©¶´¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸ö¾«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬µ±·¨Ê½Ö´ÐÐJSON·´ÐòÁл¯µÄ¹ý³ÌÖÐÖ´ÐжñÒâ´úÂ룬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20201124 |
ʼþÃû³Æ£º | DNS_ľÂí_NetReaper_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ê§ÏÝÖ÷»úÉϵÄľÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷£¨C&C£©¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËNetReaperľÂí¡£ |
¸üÐÂʱ¼ä£º | 20201124 |