2020-09-01

Ðû²¼Ê±¼ä 2020-09-01

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_APT¹¥»÷_Gamaredon×éÖ¯_Wget_Downloader_ÅþÁ¬C2

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

GamaredonÊÇÒ»¸ö¶íÂÞ˹µÄAPT¹¥»÷×éÖ¯£¬Ê״ηºÆðÓÚ2013Äê,Ö÷ÒªÊÇÕë¶ÔÎÚ¿ËÀ¼¾ÙÐÐÍøÂçÌع¤Ô˶¯¡£2017Ä꣬Palo AltoÅû¶¹ý¸Ã×éÖ¯Õë¶ÔÎÚ¿ËÀ¼¹¥»÷Ô˶¯µÄϸ½Ú£¬²¢Ê״ν«¸Ã×éÖ¯ÃüÃûΪGamaredon group¡£¸Ã×éÖ¯Ö÷ҪʹÓÃÊÜѬȾÓòÃû¡¢¶¯Ì¬DNS¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼¹ú¼Ò´úÂ붥¼¶ÓòÃû£¨ccTLD£©ÒÔ¼°¶íÂÞ˹ÍйܷþÎñÌṩÉÌÀ´·Ö·¢Æ䶨ÖƵĶñÒâÈí¼þ¡£Gamaredon×éÖ¯»áʹÓôó×ÚÏֳɵŤ¾ß£¬¾­ÓÉÉú³¤£¬Ò²×îÏȶ¨ÖÆ¿ª·¢Ïà¹ØµÄ¶ñÒâÈí¼þ¡£¸ÃÊÂÎñÊÇʹÓõÄWgetÏÂÔع¤¾ßÏÂÔØÆäËûPayload²¢Ö´ÐС£

¸üÐÂʱ¼ä£º

20200901



ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_CobaltStrike_LogKeystrokes.js_´úÂëÏÂÔØÖ´ÐÐ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄ ºóÃÅÎļþ LogKeystrokes.js ÕýÔÚ±»ÏÂÔØ, ¸ÃºóÃÅÎļþͨ³£Ç¶ÈëÔÚ´¹ÂÚÍøÒ³£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄÜ»á¼ûÁ˲»Çå¾²»òÕßαװµÄÍøÒ³¡£LogKeystrokes.js Ö´Ðк󽫻á¼Í¼ÔÚ´ËÍøÒ³Éϵİ´¼üÄÚÈÝ£¬Í¨³£ÓÃÓÚÇÔȡƾ֤ÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20200901


ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_JRMPClient1_ʹÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃJRMPClient1µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200901


ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_Spring1_ʹÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSpring1µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200901


ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_Spring2_ʹÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSpring2µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200901


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_Oracle_WebLogic_·´ÐòÁл¯Îó²î[CVE-2015-4852]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracle WebLogic·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£

¸üÐÂʱ¼ä£º

20200901


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache_Shiro_Éí·ÝÑéÖ¤ÈƹýÎó²î[CVE-2020-11989][CNNVD-202006-1556]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Apache ShiroÊÇÒ»¸öÇ¿Ê¢ÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£ÏÖÔÚ³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖоÙÐÐÉí·ÝÑéÖ¤£¬ÊÚȨµÈ¡£¹ØÓÚApache Shiro 1.5.3֮ǰµÄ°æ±¾£¬µ±½«Apache ShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤Èƹý¡£

¸üÐÂʱ¼ä£º

20200901