2021-04-06
Ðû²¼Ê±¼ä 2021-04-07ÐÂÔöʼþ
ʼþÃû³Æ£º | TCP_½©Ê¬ÍøÂç_Mirai.Putin_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½½©Ê¬ÍøÂçMirai±äÖÖPutinÊÔͼÁ¬½ÓC&C·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai±äÖÖPutin¡£Mirai½©Ê¬ÍøÂçÈä³æÖ÷Ҫͨ¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍøÉ豸£¨IoT£©£¬°üÂÞ£ºÂ·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·¡¢DVRÉ豸µÈµÈ£¬IoTÉ豸Ö÷ÒªÊÇMIPS¡¢ARMµÈ¼Ü¹¹£¬Òò´æÔÚĬÈÏÃÜÂë¡¢ÈõÃÜÂë¡¢ÑÏÖØ©¶´Î´¼°Ê±ÐÞ¸´µÈÒòËØ£¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡¹ÜÀíԱȨÏÞ¡£ÓÉÓÚÔ´´úÂëÒѾ¹ûÈ»£¬Mirai·ºÆðÁ˺ܶà±äÖÖ£¬±¾Ê¼þÕë¶ÔÆä±äÖÖPutin¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_SAP_NetWeaver_δÊÚȨÈÎÒâÓû§´´½¨Â©¶´[CVE-2020-6287][CNNVD-202007-800] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | SAP NetWeaver AS for Java Web×é¼þÖÐȱÉÙÉí·ÝÑéÖ¤£¬Òò´ËÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄSAPϵͳÉϽøÐиßÌØȨ»î¶¯¡£Èç¹û±»ÀÖ³ÉÀûÓã¬Ôòδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý´´½¨¾ßÓÐ×î´óÌØȨµÄÐÂSAPÓû§£¬ÈƹýËùÓзÃÎʺÍÊÚȨ¿ØÖÆ£¬´Ó¶øÍêÈ«¿ØÖÆSAPϵͳ¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ìøµÀPMS_ÎļþÉÏ´«Â©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ìøµÀPMS£¨ZenTao Project Management System£©ÊÇÒ»¿îÖÐСÐÍÆóÒµÏîÄ¿¹ÜÀí¹¤¾ß£¬¼¯²úÎï¹ÜÀí¡¢ÏîÄ¿¹ÜÀí¡¢²âÊÔ¹ÜÀíÓÚÒ»Éí£¬Í¬Ê±°üÂÞÊÂÎñ¹ÜÀí¡¢×éÖ¯¹ÜÀíµÈÖî¶à¹¦Ð§¡£ÔÚìøµÀPMSСÓÚ12.4.2µÄ°æ±¾ÖдæÔÚÎļþÉÏ´«Â©¶´¡£µÇ½ºǫ́µÄ¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ýfopen/fread/fwriteÒªÁì¶ÁÈ¡»òÉÏ´«ÈÎÒâÎļþ£¬ÀÖ³ÉÀûÓ鶴¿ÉÒÔ¶ÁÈ¡Ä¿±êϵͳÃô¸ÐÎļþÒÔ¼°»ñµÃϵͳ¹ÜÀíȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | HTTP_JetBrainsĿ¼й¶ |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃJetBrainsµÄ.idea½øÐÐĿ¼ÐÅÏ¢ÇÔÈ¡¡£JetBrainsÊÇÒ»¼Ò½Ý¿ËµÄÈí¼þ¿ª·¢¹«Ë¾£¬ÆìϺ¸ÇÖÖÖÖ¿ª·¢²úÎï |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | HTTP_socat_·´µ¯shellÃüÁî×¢Èë |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄÖ÷»ú½øÐÐsocat·´µ¯shellÃüÁî×¢Èë¹¥»÷¡£·´µ¯Á¬½Ó£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨·þÎñ¶Ë£¬Êܺ¦ÕßÖ÷»úÖ÷¶¯Á¬½Ó¹¥»÷ÕߵķþÎñ¶Ë·¨Ê½¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞ²»×ã¡¢¶Ë¿Ú±»Õ¼ÓõÈÇéÐΡ£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÒÔÔ¶³ÌÖ´ÐÐϵͳÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | ICMP_ľÂí_¿ÉÒÉICMPËíµÀ_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | ·¢ÏÖ¿ÉÒɵĵÄicmpÁ÷Á¿¡£Ô´IP¿ÉÄܱ»Ö²ÈëÁËicmpËíµÀ¹¤¾ß£¬Èçicmpsh¡¢icmptunnelµÈ¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_webshell_Yu1uPHPSh3ll_ÉÏ´«ºóÃÅ·¨Ê½ |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPµØÖ·Ö÷»úÕýÔÚÏòÄ¿µÄIPµØÖ·Ö÷»ú´«ËÍ¿ÉÒɵÄYu1uPHPSh3llwebshellÎļþ¡£webshellÊÇwebÈëÇֵĽű¾¹¥»÷¹¤¾ß¡£¼òµ¥Ëµ£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ·ÅÖÃÔÚÍøÕ¾·þÎñÆ÷µÄwebĿ¼ÖУ¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½Ê½£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾·þÎñÆ÷£¬°üÂÞÉÏ´«ÏÂÔØÎļþ¡¢¼ì²ìÊý¾Ý¿â¡¢Ö´ÐÐÈÎÒⷨʽÃüÁîµÈ¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬ÓÉÓÚÓë±»¿ØÖƵķþÎñÆ÷»òÔ¶³ÌÖ÷»ú½»»»µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úͨ±¨µÄ£¬Òò´Ë²»»á±»·À»ðǽÀ¹½Ø¡£¶øÇÒʹÓÃwebshellÒ»°ã²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼǼ£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Ç¼£¬¹ÜÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | HTTP_Fastadmin_chunkid·ÖƬ´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃfastadminµÄ·ÖƬÉÏ´«¹¦Ð§´æÔڵĩ¶´Ó²±àÂëºó׺À´ÃüÃûºÍÉú´æÎļþ£¬²¢Ö´ÐÐÈÎÒâ´úÂë¡£fastadminÊÇ»ùÓÚThinkPHP5µÄÄÚÈݹÜÀíϵͳ(º¬Ð¡·¨Ê½),¿É×Ô½ç˵ÄÚÈÝÄ£ÐÍ¡¢×Ô½ç˵µ¥Ò³¡¢×Ô½ç˵±íµ¥¡¢×Ô½ç˵»áÔ±Ðû²¼¡¢¸¶·ÑÔĶÁ¡¢Ð¡·¨Ê½µÈ¹¦Ð§,ÕûºÏFastAdmin»áÔ±ÖÐÐÄ¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_webshell_safedog_dÁ¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÌᳫsafedog_dÁ¬½Ó¡£safedog_dΪ´óÂí£¬·ÃÎʸôóÂí¿ÉÒÔ»ñµÃwebshellµÄÍøÒ³£¬ÔÚ¸ÃÒ³ÃæÉÏÍê³É¿É·´µ¯¶Ë¿Ú£¬sqlÖ´ÐеȲÙ×÷¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_JIRA_δÊÚȨSSRF©¶´[CVE-2017-9506][CNNVD-201706-286] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | JIRAÊÇAtlassian¹«Ë¾³öÆ·µÄÏîÄ¿ÓëÊÂÎñ¸ú×Ù¹¤¾ß£¬±»¹ã·ºÓ¦ÓÃÓÚȱÏݸú×Ù¡¢¿Í»§·þÎñ¡¢ÐèÇóÊÕ¼¯¡¢Á÷³ÌÉóÅú¡¢ÈÎÎñ¸ú×Ù¡¢ÏîÄ¿¸ú×ÙºÍÃô½Ý¹ÜÀíµÈÊÂÇéÁìÓò¡£JiraµÄplugins/servlet/oauth/users/icon-uri×ÊÔ´´æÔÚSSRF©¶´£¬Ö÷ҪΪJIRAµÄÆÕͨÓû§¾ù¿ÉÀÖ³ÉÀûÓôË©¶´ÒÔJira·þÎñ¶ËµÄÉí·Ý·ÃÎÊÄÚÍø×ÊÔ´¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | TCP_±ùЫ_php_webshell_ÉÏ´« |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«±ùЫphpwebwhellľÂí¹¥»÷Õß¿ÉÔ¶³Ì¿ØÖƱ»ÉÏ´«webshellÖ÷»úÖ´ÐÐÈÎÒâ²Ù×÷¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | TCP_ZooKeeper_δÊÚȨ·ÃÎÊ©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃZooKeeper´æÔÚµÄδÊÚȨ·ÃÎÊ©¶´½øÐй¥»÷µÄÐÐΪ¡£ZooKeeperÊÇÒ»¸öÂþÑÜʽµÄ£¬¿ª·ÅÔ´ÂëµÄÂþÑÜʽӦÓ÷¨Ê½Ðµ÷·þÎñ£¬ÊÇGoogleµÄChubbyÒ»¸ö¿ªÔ´µÄʵÏÖ£¬ÊÇHadoopºÍHbaseµÄÖØÒª×é¼þ¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | DNS_ľÂíºóÃÅ_CobaltStrike.Stager_´úÂëÏÂÔØÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Óɺڿ͹¤¾ßCobaltStrikeÉú³ÉµÄºóÃÅStagerÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØľÂíCobaltStrike.Beacon,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úÆ÷£¬²¢½øÐкáÏòÒƶ¯¡£CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½ÐͬºóÉø͸¹¥»÷¿ò¼Ü¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socketÊðÀí¡¢ÌáȨ¡¢µöÓã¡¢Ô¶¿ØľÂíµÈ¹¦Ð§¡£¸Ã¹¤¾ß¼¸ºõÁýÕÖÁËAPT¹¥»÷Á´ÖÐËùÐèÒªÓõ½µÄ¸÷¸ö¼¼Êõ»·½Ú£¬ÉîÊܺڿÍÃǵÄϲ°®¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | TCP_ľÂíºóÃÅ_ASPX_reGeorg-v1.0_ºóÃÅÉÏ´« |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«reGeorg-v1.0ľÂíºóÃÅÎļþ¡£reGeorg-v1.0ľÂíÊǺڿͳ£ÓõÄÒ»ÖÖÄÚÍøÉø͸Á÷Á¿×ª·¢Ä¾Âí£¬¹¥»÷Õßͨ¹ýÉÏ´«¸ÃľÂíÎļþµ½Web·þÎñÆ÷£¬È»ºóÔÚµ±µØͨ¹ýÌض¨¹¥»÷½Å±¾Á¬½Ó·þÎñ¶ËµÄľÂíÎļþ½øÐÐÄÚÍøÁ÷Á¿×ª·¢¡£¹¥»÷ÕßÆóͼͨ¹ýÕâÖÖ·½Ê½ÈƹýÄÚÍø·À»¤É豸ÒÔWeb·þÎñÆ÷ΪÌø°å¹¥»÷ÆäËûÄÚÍøÖ÷»ú£¬ÊÔͼ»ñÈ¡ÄÚÍøÆäËû·þÎñÆ÷µÄ¿ØÖÆȨ¡£ÉÏ´«Ä¾ÂíºóÃÅ£¬½ø¶øÔ¶³ÌÁ¬½ÓľÂíºóÃŹ¥»÷ÄÚÍøÆäËûÖ÷»ú¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | HTTP_Oracle_Weblogic_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-14882][CVE-2020-14750] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracleWebLogicÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâHTTPÇëÇóÀûÓø鶴£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÄܽӹÜOracleWebLogicServer¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | TCP_ºóÃÅ_MSIL.LimeRat_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½ºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËLimeRat¡£LimeRatÊÇÒ»¸ö»ùÓÚCSharpµÄÔ¶¿Ø£¬ÔËÐкó¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_CobaltStrike.Powershell_´úÂëÏÂÔØÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Óɺڿ͹¤¾ßCobaltStrikeÉú³ÉµÄºóÃÅpowershellÃüÁîÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØľÂíCobaltStrike.Beacon,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄÜÖ´ÐÐÁ˺óÃÅPowershellÃüÁî¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úÆ÷£¬²¢½øÐкáÏòÒƶ¯¡£CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½ÐͬºóÉø͸¹¥»÷¿ò¼Ü¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socketÊðÀí¡¢ÌáȨ¡¢µöÓã¡¢Ô¶¿ØľÂíµÈ¹¦Ð§¡£¸Ã¹¤¾ß¼¸ºõÁýÕÖÁËAPT¹¥»÷Á´ÖÐËùÐèÒªÓõ½µÄ¸÷¸ö¼¼Êõ»·½Ú£¬ÉîÊܺڿÍÃǵÄϲ°®¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬ÍêÈ«·ÃÎÊ¿ØÖÆ |
¸üÐÂʱ¼ä£º | 20210406 |