2019-11-26

Ðû²¼Ê±¼ä 2019-11-26

ÐÂÔöʼþ


ʼþÃû³Æ£º

TCP_SCADA_Schneider_Electric_U.motion_Builder_ÊäÈëÑé֤©¶´[CVE-2018-7787]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃSchneider Electric U.motion BuilderÊäÈëÑé֤©¶´À´Ö´Ðй¥»÷µÄÐÐΪ¡£

Schneider Electric U.motion BuilderÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄÒ»Ì××Ô¶¯»¯»úÖÆ¹¹½¨½â¾ö·½°¸¡£

Schneider Electric U.motion Builder 1.3.4֮ǰ°æ±¾ÖдæÔÚÊäÈëÑé֤©¶´£¬¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓÐÕýÈ·µÄÑéÖ¤HTTP GETÇëÇóÖС®context¡¯²ÎÊýµÄÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓøÃ©¶´Ð¹Â¶Ãô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20191126














ʼþÃû³Æ£º

HTTP_LCDS_LAquis_SCADAÄþ¾²Â©¶´[CVE-2018-18996]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃLCDS LAquis SCADAÄþ¾²Â©¶´À´Ö´ÐÐÃüÁîµÄÐÐΪ

LCDS LAquis SCADAÊǰÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾ÝÊÕÂÞÓë¼àÊÓ¿ØÖÆ£©ÏµÍ³¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÓµÓÐͨÐż¼ÊõµÄÉ豸½øÐÐÊý¾ÝÊÕÂ޺͹ý³Ì¿ØÖÆ¡£

LCDS LAquis SCADA 4.1.0.3870°æ±¾ÖдæÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓнøÐÐÕýÈ·µØÊÚȨ»ò¹ýÂ˱ã½ÓÊÕÁËÓû§ÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÔÚϵͳÉÏÖ´ÐдúÂë¡£

¸üÐÂʱ¼ä£º

20191126












ʼþÃû³Æ£º

HTTP_LAquis_SCADA_HTTP²ÎÊýÃüÁî×¢Èë©¶´[CVE-2018-18992]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃLAquis SCADA PAGINA TITULO HTTP²ÎÊýÃüÁî×¢Èë©¶´À´Ö´ÐÐÃüÁîµÄÐÐΪ¡£

LCDS LAquis SCADAÊǰÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾ÝÊÕÂÞÓë¼àÊÓ¿ØÖÆ£©ÏµÍ³¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÓµÓÐͨÐż¼ÊõµÄÉ豸½øÐÐÊý¾ÝÊÕÂ޺͹ý³Ì¿ØÖÆ¡£

LCDS LAquis SCADA 4.1.0.3870°æ±¾ÖдæÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓнøÐÐÕýÈ·µØ¹ýÂ˱ã½ÓÊÕÁËÓû§ÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÔÚϵͳÉÏÖ´ÐдúÂë¡£

HTTPÒªÇóacompanhamentotela.lhtmlµÄPAGINA²ÎÊýºÍrelatorioindividual.lhtmlµÄÇëÇóÖеÄTITULO²ÎÊý¶¼²»ÊʺÏÃüÁî×¢Èë×Ö·û¡£ ¹¥»÷Õß¿ÉÒÔ·¢ËÍÌØÖÆµÄHTTP GET»òPOSTÇëÇó£¬ÒÔÔÚÄ¿±ê¼ÆËã»úÉÏÖ´ÐÐÃüÁî¡£

¸üÐÂʱ¼ä£º

20191119















ʼþÃû³Æ£º

TCP_Advantech_WebAccess_SCADA_BwPSLinkZip_Stack_Buffer_Overflow

[CVE-2018-7499]

Äþ¾²ÀàÐÍ£º

»º³åÒç³ö

ʼþÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃAdvantech WebAccess BwPSLinkZip »ùÓÚÕ»µÄ»º³åÇøÒç³ö©¶´À´Ö´ÐÐÈÎÒâ´úÂëµÄÐÐΪ¡£

Advantech WebAccessÊÇÑлª£¨Advantech£©¹«Ë¾µÄ²úÎï¡£Advantech WebAccessÊÇÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý¿ØÖÆ£¬²¢ÌṩԶ³Ì¿ØÖƺ͹ÜÀí×Ô¶¯»¯É豸µÄ¹¦Ð§¡£WebAccess DashboardÊÇÆäÖеÄÒ»¸öÒDZí°å×é¼þ£»WebAccess Scada NodeÊÇÆäÖеÄÒ»¸ö¼à¿Ø½Úµã×é¼þ¡£WebAccess/NMSÊÇÒ»Ì×ÓÃÓÚÍøÂç¹ÜÀíϵͳ£¨NMS£©µÄÍøÂçä¯ÀÀÆ÷»ù´¡Ì×¼þ¡£

¸Ã©¶´ÊÇÓÉÓÚÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´ÖƵ½BwPSLinkZip.exeµÄ¶ÑÕ»»º³åÇøÖÐʱȱÉÙ½çÏÞ¼ì²éËùÖ¡£

ͨ¹ý¹¹½¨ÌØÊâµÄRPCÇëÇ󣬹¥»÷Õß¿ÉÒÔÔÚWebAccess½ø³ÌµÄÉÏÏÂÎÄÖе¼ÖÂÈÎÒâ´úÂëÖ´ÐлòÒì³£ÖÕÖ¹¡£

¸üÐÂʱ¼ä£º

20191126



















ÐÞ¸Äʼþ



ʼþÃû³Æ£º

TCP_ºóÃÅ_KG.Rat_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£

Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

KuGou.RatÊÇÒ»¸öºóÃÅ£¬Á¬½ÓÔ¶³Ì·þÎñÆ÷£¬½ÓÊÜÖ´ÐкڿÍÖ¸Á¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úÆ÷¡£ÊÔͼ»ñÈ¡Ãô¸Ð£¬Èç¼Ç¼°´¼üÐÅÏ¢£¬»ñÈ¡½¹µã´°¿ÚµÄ±êÌâ¡£

¸üÐÂʱ¼ä£º

20191126










ʼþÃû³Æ£º

TCP_ºóÃÅ_PoisonIvy_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

Poison IvyÊÇÒ»¸ö·Ç³£Á÷ÐеÄÔ¶³Ì¿ØÖƹ¤¾ß£¬ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£

¸üÐÂʱ¼ä£º

20191126








ʼþÃû³Æ£º

TCP_ºóÃÅ_Win32.WarZoneRat_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½ºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËWarZoneRat¡£

WarZoneRatÊÇÒ»¸ö¹¦Ð§Ç¿´óµÄÔ¶¿Ø£¬ÔËÐкó¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£

¸üÐÂʱ¼ä£º

20191126








ʼþÃû³Æ£º

TCP_ºóÃÅ_ÓÄÁéÔ¶¿Ø¿ÉÒɱäÖÖ_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£

Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

ÓÄÁéÔ¶¿Ø·¨Ê½ÊÇÀûÓÃÒ»¸öƾ¾ÝGh0stÔ¶¿ØµÄÔ´ÂëÐ޸ĶøÀ´µÄºóÃÅ¡£ÔËÐкó¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úÆ÷¡£

¸üÐÂʱ¼ä£º

20191126










ʼþÃû³Æ£º

TUDP_ºóÃÅ_Win32.ZeroAcess_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£

Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

Win32.ZeroAcessÊÇÒ»¸öºóÃÅ£¬ÔËÐкó£¬×¢ÈëÆäËû½ø³Ì¡£ÏÂÔØÆäËû²¡¶¾»òÕßÅäÖÃÐÅÏ¢»òÕßÄ£¿éµÈ»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£

Éϱ¨¸ÃʼþÓÐÁ½ÖÖ¿ÉÄÜ£¬Ò»ÊÇÔ´Ö÷»ú±»Ñ¬È¾ÁË£¬Á¬½ÓCC·þÎñÆ÷£»¶þÊÇZeroAcess·þÎñÆ÷¶Ëͨ¹ýshadanÊðÀí·½Ê½½øÐÐɨÃèÐÐΪ£¬Ö÷Òª¿´Ô´IPÊÇ·ñÊDZ¾µ¥ÔªµÄIPµØÖ·¡£

¸üÐÂʱ¼ä£º

20191126












ʼþÃû³Æ£º

TCP_ºóÃÅ_Linux.BillGates_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅBillGates¡£

BillGatesÊÇLinuxƽ̨ϵÄÒ»¸ö½©Ê¬ÍøÂ磬Ö÷Òª¹¦Ð§ÊÇÕë¶ÔÖ¸¶¨Ä¿±ê½øÐÐDDoS¹¥»÷¡£

¸üÐÂʱ¼ä£º

20191126









ʼþÃû³Æ£º

TCP_ľÂí_CoinMiner_Á¬½Ó¿ó³ØÀÖ³É

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinMinerľÂí¡£

CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£

¸üÐÂʱ¼ä£º

20191126









ʼþÃû³Æ£º

HTTP_ºóÃÅ_Win32.wingames(ÂûÁ黨)_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅwingames¡£

wingamesÊÇÒ»¸ö¹¦Ð§·Ç³£Ç¿´óµÄºóÃÅ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£

¸üÐÂʱ¼ä£º

20191126








ʼþÃû³Æ£º

TCP_ľÂí_CoinMiner_ʵÑéÁ¬½Ó¿ó³Ø

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinminerľÂí¡£

CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£

¸üÐÂʱ¼ä£º

20191126