2020-04-07
Ðû²¼Ê±¼ä 2020-04-07ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMBÎó²îɨÃè[MS17-010]_ɨÃèÓÐÎó²î |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IP¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐMS17-010Îó²îɨÃèµÄÐÐΪ. Microsoft WindowsÊÇ΢ÈíÐû²¼µÄºÜÊÇÊ¢ÐеIJÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£ ÈôÊǹ¥»÷ÕßÏò Microsoft ЧÀÍÆ÷·¢Ë;ȫÐĽṹµÄ»ûÐÎÇëÇó°ü£¬£¬£¬£¬¿ÉÒÔ»ñȡĿµÄЧÀÍÆ÷µÄϵͳȨÏÞ£¬£¬£¬£¬²¢ÇÒÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ºóÃÅ_FakeSanforUD_ÅþÁ¬ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËRarog¡£¡£¡£¡£¡£¡£ ÉîÐÅ·þVPN¿Í»§¶Ë±£´æÎó²î£¬£¬£¬£¬ÔÚÉý¼¶Ê±»áÏÂÔØÖ´ÐÐÃûΪSangforUD.exeµÄ¸üгÌÐò¡£¡£¡£¡£¡£¡£µ«VPN¿Í»§¶Ë½ö¶ÔSangforUD.exe×öÁ˼òÆÓµÄ°æ±¾±ÈÕÕ£¬£¬£¬£¬Ã»ÓÐ×öÈκεÄÇå¾²¼ì²é¡£¡£¡£¡£¡£¡£APT×éÖ¯Darkhotel¹¥ÆÆÁËVPNЧÀÍÆ÷£¬£¬£¬£¬¸Ä¶¯Éý¼¶ÉèÖÃÎļþ²¢°ÑSangforUD.exeÌæ»»Îª¶ñÒâµÄºóÃÅFakeSanforUD¡£¡£¡£¡£¡£¡£ FakeSanforUDÊÇÒ»¸öºóÃÅ£¬£¬£¬£¬Í¨¹ýÏÂÔØÖ´ÐÐshellcode£¬£¬£¬£¬×îÖÕÏÂÔØ½¹µãµÄºóÃŶñÒâ×é¼þthinmon.dll¡£¡£¡£¡£¡£¡£½¹µãºóÃÅ×é¼þthinmon.dll»á½âÃÜÔÆ¶ËÏ·¢µÄÁíÍâÒ»¸ö¼ÓÃÜÎļþSangfor_tmp_1.dat£¬£¬£¬£¬ÒÔ¼ÓÔØ¡¢Ïß³ÌÆô¶¯¡¢×¢ÈëÀú³Ì3ÖÖ·½·¨ÖеÄÒ»ÖÖÆô¶¯datÎļþ £¬£¬£¬£¬×îÖÕÓÉdatÎļþʵÏÖÓëЧÀÍÆ÷½»»¥Ö´ÐжñÒâ²Ù×÷¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
TCP_Metasploit_ÄäÃû¹ÜµÀɨÃè |
|
Çå¾²ÀàÐÍ£º |
Ç徲ɨÃè |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓöÔÄ¿µÄÖ÷»úʹÓÃMetasploitͨ¹ýSMBÐÒé»ñÈ¡ÅÌËã»úÐÅÏ¢µÄÐÐΪ¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
TCP_SMB_NMAPɨÃè |
|
Çå¾²ÀàÐÍ£º |
Ç徲ɨÃè |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓöÔÄ¿µÄÖ÷»úʹÓÃNMAPͨ¹ýSMBÐÒé»ñÈ¡ÅÌËã»úÐÅÏ¢µÄÐÐΪ¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMBÎó²îɨÃè[MS17-010]_ɨÃèÎÞÎó²î |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IP¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐMS17-010Îó²îɨÃèµÄÐÐΪ. Microsoft WindowsÊÇ΢ÈíÐû²¼µÄºÜÊÇÊ¢ÐеIJÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£ ÈôÊǹ¥»÷ÕßÏò Microsoft ЧÀÍÆ÷·¢Ë;ȫÐĽṹµÄ»ûÐÎÇëÇó°ü£¬£¬£¬£¬¿ÉÒÔ»ñȡĿµÄЧÀÍÆ÷µÄϵͳȨÏÞ£¬£¬£¬£¬²¢ÇÒÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_DoublePulsarºóÃÅ_ɨÃè»òÖ²ÈëºóÃÅ_ÒÉËÆÖ´ÐлòÐ¶ÔØ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Í¨¹ýMS17-010µÄÎó²îÖ²ÈëDoublePulsarºóÃŵÄÐÐΪ¡£¡£¡£¡£¡£¡£ Microsoft WindowsÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾Ðû²¼µÄһϵÁвÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£SMBv1 serverÊÇÆäÖеÄÒ»¸öЧÀÍÆ÷ÐÒé×é¼þ¡£¡£¡£¡£¡£¡£DoublePulsarÊÇÒ»¸öºóÃųÌÐò£¬£¬£¬£¬ÓÃÓÚÔÚÒÑѬȾµÄϵͳÉÏ×¢ÈëºÍÔËÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£ Microsoft WindowsÖеÄSMBv1ЧÀÍÆ÷±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖÆµÄÊý¾Ý°üʹÓøÃÎó²îÖ²Èë»òɨÃèDoublePulsarºóÃÅ¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_DoublePulsarºóÃÅ_ɨÃè»òÖ²ÈëºóÃÅ_ÒÉËÆping |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Í¨¹ýMS17-010µÄÎó²îÖ²ÈëDoublePulsarºóÃŵÄÐÐΪ¡£¡£¡£¡£¡£¡£ Microsoft WindowsÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾Ðû²¼µÄһϵÁвÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£SMBv1 serverÊÇÆäÖеÄÒ»¸öЧÀÍÆ÷ÐÒé×é¼þ¡£¡£¡£¡£¡£¡£DoublePulsarÊÇÒ»¸öºóÃųÌÐò£¬£¬£¬£¬ÓÃÓÚÔÚÒÑѬȾµÄϵͳÉÏ×¢ÈëºÍÔËÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£ Microsoft WindowsÖеÄSMBv1ЧÀÍÆ÷±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖÆµÄÊý¾Ý°üʹÓøÃÎó²îÖ²ÈëDoublePulsarºóÃÅ¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
TCP_DrayTek_Ô¤Éí·ÝÑéÖ¤ÏÂÁî×¢ÈëÎó²î[CVE-2020-8515] |
|
Çå¾²ÀàÐÍ£º |
×¢Èë¹¥»÷ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½¹¥»÷ÕßʹÓÃDrayTekÔ¤Éí·ÝÑéÖ¤´¦µÄÁ½´¦ÏÂÁî×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£DrayTekÊÇÒ»¼ÒÔÚÖйúÉú²ú·À»ðǽ£¬£¬£¬£¬VPN×°±¸£¬£¬£¬£¬Â·ÓÉÆ÷£¬£¬£¬£¬WLAN×°±¸µÈµÄÖÆÔìÉÌ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ/cgi-bin/mainfunction.cgi³ÌÐòδ׼ȷ¹ýÂËkeyPath×ֶκÍrtick×Ö¶ÎÆäÖеÄÌØÊâ×Ö·û£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î²»¾ÓÉÉí·ÝÑéÖ¤ÒÔrootȨÏÞÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ZyXEL_Ô¤Éí·ÝÑéÖ¤ÏÂÁî×¢ÈëÎó²î[CVE-2020-9054] |
|
Çå¾²ÀàÐÍ£º |
×¢Èë¹¥»÷ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýZyXEL×°±¸ÖеÄÔ¤Éí·ÝÑéÖ¤µÄÏÂÁî×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
ÐÞ¸ÄÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMBÎó²îдÈëshellcode[MS17-010] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IP¶ÔÄ¿µÄÖ÷»úʹÓÃMS17-010Îó²îдÈëshellcodeµÄÐÐΪ. Microsoft WindowsÊÇ΢ÈíÐû²¼µÄºÜÊÇÊ¢ÐеIJÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£ ÈôÊǹ¥»÷ÕßÏò Microsoft ЧÀÍÆ÷·¢Ë;ȫÐĽṹµÄ»ûÐÎÇëÇó°ü£¬£¬£¬£¬¿ÉÒÔ»ñȡĿµÄЧÀÍÆ÷µÄϵͳȨÏÞ£¬£¬£¬£¬²¢ÇÒÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
TCP_Çå¾²Îó²î_Microsoft_SMBv3_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-0796] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»ú¿ÉÄÜÕýÔÚ¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐCVE-2020-0796Îó²îʹÓõÄÐÐΪ¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
UDP_½©Ê¬ÍøÂç_Mozi.P2PBotnet_ÅþÁ¬ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½½©Ê¬ÍøÂçMoziÊÔͼºÍPeerͨѶ¡£¡£¡£¡£¡£¡£ÓÉÓÚÊÇ»ùÓÚP2PÐÒ飬£¬£¬£¬Ô´IPºÍÄ¿µÄIPËùÔÚµÄÖ÷»ú¿ÉÄܶ¼±»Ö²ÈëÁ˽©Ê¬ÍøÂçMozi¡£¡£¡£¡£¡£¡£ MoziÊÇÒ»¸ö»ùÓÚP2PÐÒéµÄ½©Ê¬ÍøÂ磬£¬£¬£¬Ö÷ÒªÖ§³ÖµÄ¹¦Ð§Îª£ºDDoS¹¥»÷¡¢ÍøÂçBotÐÅÏ¢¡¢Ö´ÐÐÖ¸¶¨URLµÄpayload¡¢´ÓÖ¸¶¨µÄURL¸üÐÂÑù±¾¡¢Ö´ÐÐϵͳ»ò×Ô½ç˵ÏÂÁî¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |
|
ÊÂÎñÃû³Æ£º |
TCP_Tomcat/Coldfusion_AJP13_í§ÒâÎļþ¶ÁÈ¡[CVE-2020-1938/CVE-2020-3761/CVE-2020-3794] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃTomcat/Coldfusion_AJP13í§ÒâÎļþ¶ÁÈ¡Îó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200407 |


¾©¹«Íø°²±¸11010802024551ºÅ