ÿÖÜÉý¼¶Í¨¸æ-2021-05-11

Ðû²¼Ê±¼ä 2021-05-12

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_tracertÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

¼ì²âµ½Ö÷»úÕýÔÚÏòÔ´ip·µ»ØÌåÖаüÀ¨ÏµÍ³ÏÂÁîtracertµÄÖ´ÐлØÏÔ £¬¿ÉÄÜÊǺڿ͹¥»÷µ¼ÖÂϵͳִÐÐÏÂÁîµÄ·µ»Ø £¬¿ÉÄÜÖ÷»úÒѾ­Ê§ÏÝ

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Rotajakiro.Oceanlotus(º£Á«»¨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅRotajakiro¡£RotajakiroÒÉËÆÊÇAPT×éÖ¯º£Á«»¨ËùµÄʹÓúóÃÅ £¬¹¦Ð§ºÜÊÇǿʢ £¬ÔËÐкó¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Opentsdb_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-35476][CNNVD-202012-1211]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOpentsdbÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£OpenTSDB(OpenTimeSeriesDataBase)ÊÇ»ùÓÚHBASE¹¹½¨µÄÂþÑÜʽ¡¢¿ÉÀ©Õ¹µÄʱ¼äÐòÁÐÊý¾Ý¿â¡£OpenTSDB¿ÉÒÔ»ñÈ¡µçÁ¦ÐÐÒµ¡¢»¯¹¤ÐÐÒµ¡¢ÎïÁªÍøÐÐÒµµÈÖÖÖÖÐÍʵʱ¼à²â¡¢¼ì²éÓëÆÊÎö×°±¸ËùÊÕÂÞ¡¢±¬·¢µÄʱ¼äÐòÁÐÊý¾Ý £¬²¢Ìṩ´æ´¢¡¢Ë÷ÒýÒÔ¼°Í¼Ðλ¯·þÎñ £¬Ê¹ÆäÒ×ÓÚ»á¼ûºÍ¿ÉÊÓ»¯¡£OpenTSDB2.4.0¼°Ö®Ç°°æ±¾Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î £¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâÇëÇóʵÏÖÔ¶³Ì´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_copy_ÏÂÁîÖ´ÐлØÏÔ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Ä¿½ñÖ÷»úÕýÔÚ·µ»ØcopyÏÂÁîÖ´ÐÐЧ¹û £¬copyÊÇÖ÷»ú¸´ÖÆÎļþµÄÏÂÁî £¬¹¥»÷Õß³£ÓÃÏÂÁî £¬ÈôÊÇ·µ»ØÌåÄÚÀï·ºÆðÏà¹ØÃûÌõÄÄÚÈÝ £¬Ôò¿ÉÄÜÖ÷»úÒѱ»¹¥ÏÝ

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

HTTP_ÌìÈÚÐÅÊý¾Ý·À×ß©ϵͳ_ԽȨÐÞ¸ÄÖÎÀíÔ±Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÌìÈÚÐÅÊý¾Ý·À×ß©ϵͳµÄԽȨÎó²î¾ÙÐÐÖÎÀíÔ±ÃÜÂëÐ޸ģ»ÌìÈÚÐÅÊý¾Ý·À×ß©ϵͳ(¼ò³Æ:TopDLP)ÊÇÒÔÉî¶ÈÄÚÈÝʶ±ðÊÖÒÕΪ½¹µã,ÔÚÊý¾Ý´æ´¢¡¢´«ÊäºÍʹÓÃÀú³ÌÖÐ,·¢Ã÷²¢Ê¶±ðÃô¸ÐÊý¾ÝÒþ»¼,È·±£Ãô¸ÐÊý¾ÝÕýµ±Ê¹ÓÃ,±ÜÃâÃô¸ÐÊý¾Ý×ß©µÄÊý¾ÝÇå¾²±£»¤ÏµÍ³¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

HTTP_APT¹¥»÷_Bitter(ÂûÁ黨)_Win32.Downloader_ÅþÁ¬C2

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

ÂûÁ黨£¨BITTER£©ÊÇÒÉËÆ¾ßÓÐÄÏÑÇÅä¾°µÄAPT×éÖ¯ £¬ÒòÆäÔçÆÚÌØÂíͨѶµÄÊý¾Ý°üÍ·²¿ÒÔ¡°BITTER¡±×÷Ϊ±êʶ¶øµÃÃû¡£¸Ã×éÖ¯Ö÷ÒªÕë¶ÔÖܱ߹ú¼ÒµØÇøµÄÕþ¸® £¬¾ü¹¤Òµ £¬µçÁ¦ £¬ºËµÈµ¥Î»¾ÙÐй¥»÷ £¬ÒÔÇÔÈ¡Ãô¸Ð×ÊÁÏΪĿµÄ £¬¾ßÓÐÇ¿ÁÒµÄÕþÖÎÅä¾°¡£¸ÃÊÂÎñÊÇÒ»¸ö.NETƽ̨µÄDownloader,»ñȡĿ½ñÅÌËã»úÓû§Ãû¡¢ÏµÍ³°æ±¾¡¢ÏµÍ³Î»Êý¡¢MACµØµãµÈÐÅÏ¢ £¬½«»ñÈ¡µÄÐÅϢƴ½ÓÉÏ´«µ½C2·þÎñÆ÷ £¬²¢´ÓC2·þÎñÆ÷ÏÂÔØÎļþÖ´ÐС£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_everythingËÑË÷Ò³Ãæ±»»á¼û

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

EverythingÊÇWindowsÉÏÒ»¿îËÑË÷ÒýÇæ £¬ÓÉÓÚÉèÖÃÖпªÆôÁËETP/FTPºÍHTTP·þÎñ £¬²¢Î´ÉèÖÃÕ˺ÅÃÜÂë £¬µ¼Ö¿ÉÒÔ»á¼û·þÎñÆ÷µÄÎļþ¡£ÈôÊǹ¥»÷ipÊÇÊÚȨip £¬ÔòÎÞÐè¹Ø×¢¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_nslookupÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ¶ÔÄ¿µÄIPÖ´ÐÐnslookupÏÂÁî £¬nslookupÓÃÓÚÅÌÎÊDNSµÄ¼Í¼ £¬ÅÌÎÊÓòÃûÆÊÎöÊÇ·ñÕý³£ £¬ÔÚÍøÂç¹ÊÕÏʱÓÃÀ´Õï¶ÏÍøÂçÎÊÌâ £¬Ò²¿É±»¹¥»÷ÕßÓÃÓÚ̽²â»úеÊÇ·ñ¿ÉÒÔÁªÍ¨ÍâÍø¡£

¸üÐÂʱ¼ä£º

20210511


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃûÆÊÎöÇëÇó

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ÍÚ¿óľÂíʵÑéÅþÁ¬¿ó³Ø £¬Êܺ¦Ö÷»ú±äÂý¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

TCP_±ùЫ_php_webshell_ÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«±ùЫphpwebwhellľÂí,¹¥»÷Õß¿ÉÔ¶³Ì¿ØÖƱ»ÉÏ´«webshellÖ÷»úÖ´ÐÐí§Òâ²Ù×÷¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

HTTP_Citrix_ADC_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-8193][CNNVD-202007-367]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÕýÔÚʹÓÃCitrix_ADCµÄȨÏÞÈÆ¹ýÎó²î £¬Í¨¹ý½¨Éèsession £¬½ø¶øÌáȨ¾ÙÐдúÂëÖ´Ðй¥»÷ £¬×îºóµ¼ÖÂÖ÷»úʧÏÝ £¬±»¹¥»÷Õß½ÓÊÜ¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·ºÎ¢OA8_ǰ̨SQLÖ´ÐÐ

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

·ºÎ¢OAÊǺ£ÄÚ¹«Ë¾Ðû²¼µÄÒ»¿îÒÆ¶¯°ì¹«Õý̨¡£¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓ÷ºÎ¢OA8ǰ̨µÄSQLÖ´ÐÐÎó²î £¬Í¨¹ý´ËÎó²î¿ÉÅÌÎʳöºǫ́ÃÜÂëµÈÊý¾Ý¿âÃô¸ÐÊý¾Ý¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win32.Salgorea(º£Á«»¨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅSalgorea¡£SalgoreaÊǺ£Á«»¨ËùʹÓõÄǿʢºóÃÅ £¬Ö÷Ҫͨ¹ýÓʼþÈö²¥¡£SalgoreaÔËÐкó £¬»áʵÑé»ñÈ¡Ãô¸ÐÐÅÏ¢ £¬Ò²¿ÉÖ´ÐÐC&C·µ»ØÖ¸Áî £¬È¥ÏÂÔØÆäËûºóÃÅ¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_IoT.Moobot_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½MoobotÊÔͼÅþÁ¬C&C·þÎñÆ÷¡£Ô´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçMoobot¡£MoobotÊÇÒ»¸öIoT½©Ê¬ÍøÂç £¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÌᳫDDoS¹¥»÷ £¬Í¨¹ýÖÖÖÖÎó²îÈö²¥×ÔÉí¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÒÚÓʵç×ÓÓʼþϵͳ_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃÒÚÓʵç×ÓÓʼþϵͳʹÓÃPOSTÒªÁìÔÚÄ¿µÄipÖ÷»úÖ´ÐÐÔ¶³Ì´úÂëÖ´ÐвÙ×÷ £¬ÒÚÓʵç×ÓÓʼþϵͳÊÇÓɱ±¾©ÒÚÖÐÓÊÐÅÏ¢ÊÖÒÕÓÐÏÞ¹«Ë¾£¨ÒÔϼò³ÆÒÚÓʹ«Ë¾£©¿ª·¢µÄÒ»¿îÃæÏòÖдóÐͼ¯ÍÅÆóÒµ¡¢Õþ¸®¡¢¸ßУÓû§µÄ¹ú²úÓʼþϵͳ¡£ÒÚÓʵç×ÓÓʼþϵͳ½ÓÄÉÁË×ÔÖ÷Ñз¢MTAÒýÇæ¡¢ÂþÑÜʽÎļþϵͳ´æ´¢·½·¨¡¢¶à¶ÔÁлúÖÆ¡¢ECS´æ´¢×Óϵͳ¡¢CacheϵͳµÈ¶àÏî½¹µãÊÖÒÕ £¬ÌṩÁ˸»ºñµÄÓʼþ¹¦Ð§¡£

¸üÐÂʱ¼ä£º

20210511