2021-04-06
Ðû²¼Ê±¼ä 2021-04-07ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_½©Ê¬ÍøÂç_Mirai.Putin_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½½©Ê¬ÍøÂçMirai±äÖÖPutinÊÔͼÅþÁ¬C&CЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai±äÖÖPutin¡£¡£¡£¡£¡£¡£Mirai½©Ê¬ÍøÂçÈ䳿Ö÷Ҫͨ¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍø×°±¸£¨IoT£©£¬£¬£¬°üÀ¨£ºÂ·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·¡¢DVR×°±¸µÈµÈ£¬£¬£¬IoT×°±¸Ö÷ÒªÊÇMIPS¡¢ARMµÈ¼Ü¹¹£¬£¬£¬Òò±£´æÄ¬ÈÏÃÜÂë¡¢ÈõÃÜÂë¡¢ÑÏÖØÎó²îδʵʱÐÞ¸´µÈÒòËØ£¬£¬£¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£¡£¡£¡£¡£¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£ÓÉÓÚÔ´´úÂëÒѾ¹ûÕæ£¬£¬£¬Mirai·ºÆðÁËÐí¶à±äÖÖ£¬£¬£¬±¾ÊÂÎñÕë¶ÔÆä±äÖÖPutin¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_SAP_NetWeaver_δÊÚȨí§ÒâÓû§½¨ÉèÎó²î[CVE-2020-6287][CNNVD-202007-800] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | SAP NetWeaver AS for Java Web×é¼þÖÐȱÉÙÉí·ÝÑéÖ¤£¬£¬£¬Òò´ËÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄSAPϵͳÉϾÙÐиßÌØÈ¨»î¶¯¡£¡£¡£¡£¡£¡£ÈôÊDZ»ÀÖ³ÉʹÓ㬣¬£¬Ôòδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý½¨Éè¾ßÓÐ×î´óÌØÈ¨µÄÐÂSAPÓû§£¬£¬£¬ÈƹýËùÓлá¼ûºÍÊÚȨ¿ØÖÆ£¬£¬£¬´Ó¶øÍêÈ«¿ØÖÆSAPϵͳ¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_ìøµÀPMS_ÎļþÉÏ´«Îó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ìøµÀPMS£¨ZenTao Project Management System£©ÊÇÒ»¿îÖÐСÐÍÆóÒµÏîÄ¿ÖÎÀí¹¤¾ß£¬£¬£¬¼¯²úÆ·ÖÎÀí¡¢ÏîÄ¿ÖÎÀí¡¢²âÊÔÖÎÀíÓÚÒ»Éí£¬£¬£¬Í¬Ê±°üÀ¨ÊÂÎñÖÎÀí¡¢×éÖ¯ÖÎÀíµÈÖî¶à¹¦Ð§¡£¡£¡£¡£¡£¡£ÔÚìøµÀPMSСÓÚ12.4.2µÄ°æ±¾Öб£´æÎļþÉÏ´«Îó²î¡£¡£¡£¡£¡£¡£Éϰ¶ºǫ́µÄ¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ýfopen/fread/fwriteÒªÁì¶ÁÈ¡»òÉÏ´«í§ÒâÎļþ£¬£¬£¬ÀÖ³ÉʹÓÃÎó²î¿ÉÒÔ¶ÁȡĿµÄϵͳÃô¸ÐÎļþÒÔ¼°»ñµÃϵͳÖÎÀíȨÏÞ¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | HTTP_JetBrainsĿ¼й¶ |
Çå¾²ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPʹÓÃJetBrainsµÄ.idea¾ÙÐÐĿ¼ÐÅÏ¢ÇÔÈ¡¡£¡£¡£¡£¡£¡£JetBrainsÊÇÒ»¼Ò½Ý¿ËµÄÈí¼þ¿ª·¢¹«Ë¾£¬£¬£¬ÆìϺ¸ÇÖÖÖÖ¿ª·¢²úÆ· |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | HTTP_socat_·´µ¯shellÏÂÁî×¢Èë |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄÖ÷»ú¾ÙÐÐsocat·´µ¯shellÏÂÁî×¢Èë¹¥»÷¡£¡£¡£¡£¡£¡£·´µ¯ÅþÁ¬£¬£¬£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨Ð§ÀͶˣ¬£¬£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯ÅþÁ¬¹¥»÷ÕßµÄЧÀͶ˳ÌÐò¡£¡£¡£¡£¡£¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞȱ·¦¡¢¶Ë¿Ú±»Õ¼ÓõÈÇéÐΡ£¡£¡£¡£¡£¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÒÔÔ¶³ÌÖ´ÐÐϵͳÏÂÁî¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | ICMP_ľÂí_¿ÉÒÉICMPËíµÀ_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò£º | ·¢Ã÷¿ÉÒɵĵÄicmpÁ÷Á¿¡£¡£¡£¡£¡£¡£Ô´IP¿ÉÄܱ»Ö²ÈëÁËicmpËíµÀ¹¤¾ß£¬£¬£¬Èçicmpsh¡¢icmptunnelµÈ¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_webshell_Yu1uPHPSh3ll_ÉÏ´«ºóÃųÌÐò |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄYu1uPHPSh3llwebshellÎļþ¡£¡£¡£¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¡£¡£¡£¼òÆÓ˵£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | HTTP_Fastadmin_chunkid·ÖƬ´úÂëÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastadminµÄ·ÖƬÉÏ´«¹¦Ð§±£´æµÄÎó²îÓ²±àÂëºó׺À´ÃüÃûºÍÉúÑÄÎļþ£¬£¬£¬²¢Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£fastadminÊÇ»ùÓÚThinkPHP5µÄÄÚÈÝÖÎÀíϵͳ(º¬Ð¡³ÌÐò),¿É×Ô½ç˵ÄÚÈÝÄ£×Ó¡¢×Ô½ç˵µ¥Ò³¡¢×Ô½ç˵±íµ¥¡¢×Ô½ç˵»áÔ±Ðû²¼¡¢¸¶·ÑÔĶÁ¡¢Ð¡³ÌÐòµÈ¹¦Ð§,ÕûºÏFastAdmin»áÔ±ÖÐÐÄ¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_webshell_safedog_dÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÌᳫsafedog_dÅþÁ¬¡£¡£¡£¡£¡£¡£safedog_dΪ´óÂí£¬£¬£¬»á¼û¸Ã´óÂí¿ÉÒÔ»ñµÃwebshellµÄÍøÒ³£¬£¬£¬ÔÚ¸ÃÒ³ÃæÉÏÍê³É¿É·´µ¯¶Ë¿Ú£¬£¬£¬sqlÖ´ÐеȲÙ×÷¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_JIRA_δÊÚȨSSRFÎó²î[CVE-2017-9506][CNNVD-201706-286] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | JIRAÊÇAtlassian¹«Ë¾³öÆ·µÄÏîÄ¿ÓëÊÂÎñ¸ú×Ù¹¤¾ß£¬£¬£¬±»ÆÕ±éÓ¦ÓÃÓÚȱÏݸú×Ù¡¢¿Í»§Ð§ÀÍ¡¢ÐèÇóÍøÂç¡¢Á÷³ÌÉóÅú¡¢Ê¹Ãü¸ú×Ù¡¢ÏîÄ¿¸ú×ÙºÍѸËÙÖÎÀíµÈÊÂÇéÁìÓò¡£¡£¡£¡£¡£¡£JiraµÄplugins/servlet/oauth/users/icon-uri×ÊÔ´±£´æSSRFÎó²î£¬£¬£¬Ö÷ҪΪJIRAµÄͨË×Óû§¾ù¿ÉÀÖ³ÉʹÓôËÎó²îÒÔJiraЧÀͶ˵ÄÉí·Ý»á¼ûÄÚÍø×ÊÔ´¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_±ùЫ_php_webshell_ÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«±ùЫphpwebwhellľÂí¹¥»÷Õß¿ÉÔ¶³Ì¿ØÖƱ»ÉÏ´«webshellÖ÷»úÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |

ÊÂÎñÃû³Æ£º | TCP_ZooKeeper_δÊÚȨ»á¼ûÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃZooKeeper±£´æµÄδÊÚȨ»á¼ûÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£ZooKeeperÊÇÒ»¸öÂþÑÜʽµÄ£¬£¬£¬¿ª·ÅÔ´ÂëµÄÂþÑÜʽӦÓóÌÐòе÷ЧÀÍ£¬£¬£¬ÊÇGoogleµÄChubbyÒ»¸ö¿ªÔ´µÄʵÏÖ£¬£¬£¬ÊÇHadoopºÍHbaseµÄÖ÷Òª×é¼þ¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | DNS_ľÂíºóÃÅ_CobaltStrike.Stager_´úÂëÏÂÔØÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Óɺڿ͹¤¾ßCobaltStrikeÌìÉúµÄºóÃÅStagerÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷ÏÂÔØÄ¾ÂíCobaltStrike.Beacon,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCobaltStrike.Stager¡£¡£¡£¡£¡£¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉʹÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úе£¬£¬£¬²¢¾ÙÐкáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½ÐͬºóÉøÍ¸¹¥»÷¿ò¼Ü¡£¡£¡£¡£¡£¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socketÊðÀí¡¢ÌáȨ¡¢´¹ÂÚ¡¢Ô¶¿ØÄ¾ÂíµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ßÏÕЩÁýÕÖÁËAPT¹¥»÷Á´ÖÐËùÐèÒªÓõ½µÄ¸÷¸öÊÖÒÕ»·½Ú£¬£¬£¬ÉîÊܺڿÍÃǵÄϲ»¶¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | TCP_ľÂíºóÃÅ_ASPX_reGeorg-v1.0_ºóÃÅÉÏ´« |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«reGeorg-v1.0ľÂíºóÃÅÎļþ¡£¡£¡£¡£¡£¡£reGeorg-v1.0ľÂíÊǺڿͳ£ÓõÄÒ»ÖÖÄÚÍøÉøÍ¸Á÷Á¿×ª·¢Ä¾Âí£¬£¬£¬¹¥»÷Õßͨ¹ýÉÏ´«¸ÃľÂíÎļþµ½WebЧÀÍÆ÷£¬£¬£¬È»ºóÔÚÍâµØÍ¨¹ýÌØ¶¨¹¥»÷¾ç±¾ÅþÁ¬Ð§ÀͶ˵ÄľÂíÎļþ¾ÙÐÐÄÚÍøÁ÷Á¿×ª·¢¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÍýÏëͨ¹ýÕâÖÖ·½·¨ÈƹýÄÚÍø·À»¤×°±¸ÒÔWebЧÀÍÆ÷ÎªÌø°å¹¥»÷ÆäËûÄÚÍøÖ÷»ú£¬£¬£¬ÊÔͼ»ñÈ¡ÄÚÍøÆäËûЧÀÍÆ÷µÄ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£ÉÏ´«Ä¾ÂíºóÃÅ£¬£¬£¬½ø¶øÔ¶³ÌÅþÁ¬Ä¾ÂíºóÃŹ¥»÷ÄÚÍøÆäËûÖ÷»ú¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | HTTP_Oracle_Weblogic_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-14882][CVE-2020-14750] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracleWebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâHTTPÇëÇóʹÓøÃÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܽÓÊÜOracleWebLogicServer¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | TCP_ºóÃÅ_MSIL.LimeRat_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËLimeRat¡£¡£¡£¡£¡£¡£LimeRatÊÇÒ»¸ö»ùÓÚCSharpµÄÔ¶¿Ø£¬£¬£¬ÔËÐкó¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£¿£¿£¿£¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210406 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_CobaltStrike.Powershell_´úÂëÏÂÔØÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Óɺڿ͹¤¾ßCobaltStrikeÌìÉúµÄºóÃÅpowershellÏÂÁîÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷ÏÂÔØÄ¾ÂíCobaltStrike.Beacon,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄÜÖ´ÐÐÁ˺óÃÅPowershellÏÂÁî¡£¡£¡£¡£¡£¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉʹÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úе£¬£¬£¬²¢¾ÙÐкáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£CobatStrikeÊÇÒ»¿î»ùÓÚjava±àдµÄȫƽ̨¶à·½ÐͬºóÉøÍ¸¹¥»÷¿ò¼Ü¡£¡£¡£¡£¡£¡£CobaltStrike¼¯³ÉÁ˶˿Úת·¢¡¢¶Ë¿ÚɨÃè¡¢socketÊðÀí¡¢ÌáȨ¡¢´¹ÂÚ¡¢Ô¶¿ØÄ¾ÂíµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ßÏÕЩÁýÕÖÁËAPT¹¥»÷Á´ÖÐËùÐèÒªÓõ½µÄ¸÷¸öÊÖÒÕ»·½Ú£¬£¬£¬ÉîÊܺڿÍÃǵÄϲ»¶¡£¡£¡£¡£¡£¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬ÍêÈ«»á¼û¿ØÖÆ |
¸üÐÂʱ¼ä£º | 20210406 |


¾©¹«Íø°²±¸11010802024551ºÅ