2019-11-26

°ä²¼¹¦·ò 2019-11-26

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º£º

TCP_SCADA_Schneider_Electric_U.motion_Builder_ÊäÈëÑéÖ¤·ì϶[CVE-2018-7787]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃSchneider Electric U.motion BuilderÊäÈëÑéÖ¤·ì϶À´Ö´Ðй¥»÷µÄÐÐΪ¡£¡£¡£

Schneider Electric U.motion BuilderÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄÒ»Ì××Ô¶¯»¯»úÖÆ¹¹½¨½â¾ö¹æ»®¡£¡£¡£

Schneider Electric U.motion Builder 1.3.4֮ǰ°æ±¾ÖдæÔÚÊäÈëÑéÖ¤·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·µÄÑéÖ¤HTTP GETÒªÇóÖС®context¡¯²ÎÊýµÄÊäÈë¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶й¶Ãô¸ÐÐÅÏ¢¡£¡£¡£

¸üй¦·ò£º£º

20191126














ÊÂÎñÃû³Æ£º£º

HTTP_LCDS_LAquis_SCADA°²È«·ì϶[CVE-2018-18996]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃLCDS LAquis SCADA°²È«·ì϶À´Ö´ÐкÅÁîµÄÐÐΪ

LCDS LAquis SCADAÊǰÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾Ý²É¼¯Óë¼à¶½½ÚÖÆ£©ÏµÍ³¡£¡£¡£¸ÃÏµÍ³ÖØÒªÓÃÓÚ¶ÔÕ¼ÓÐͨѶ¼¼ÊõµÄÉ豸½øÐÐÊý¾Ý²É¼¯ºÍ¹ý³Ì½ÚÖÆ¡£¡£¡£

LCDS LAquis SCADA 4.1.0.3870°æ±¾ÖдæÔÚ°²È«·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓнøÐÐÕýÈ·µØÊÚȨ»ò¹ýÂ˱ã½Ó¹ÜÁËÓû§ÊäÈë¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚϵͳÉÏÖ´ÐдúÂë¡£¡£¡£

¸üй¦·ò£º£º

20191126












ÊÂÎñÃû³Æ£º£º

HTTP_LAquis_SCADA_HTTP²ÎÊýºÅÁî×¢Èë·ì϶[CVE-2018-18992]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃLAquis SCADA PAGINA TITULO HTTP²ÎÊýºÅÁî×¢Èë·ì϶À´Ö´ÐкÅÁîµÄÐÐΪ¡£¡£¡£

LCDS LAquis SCADAÊǰÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾Ý²É¼¯Óë¼à¶½½ÚÖÆ£©ÏµÍ³¡£¡£¡£¸ÃÏµÍ³ÖØÒªÓÃÓÚ¶ÔÕ¼ÓÐͨѶ¼¼ÊõµÄÉ豸½øÐÐÊý¾Ý²É¼¯ºÍ¹ý³Ì½ÚÖÆ¡£¡£¡£

LCDS LAquis SCADA 4.1.0.3870°æ±¾ÖдæÔÚ°²È«·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓнøÐÐÕýÈ·µØ¹ýÂ˱ã½Ó¹ÜÁËÓû§ÊäÈë¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚϵͳÉÏÖ´ÐдúÂë¡£¡£¡£

HTTPÒªÇóacompanhamentotela.lhtmlµÄPAGINA²ÎÊýºÍrelatorioindividual.lhtmlµÄÒªÇóÖеÄTITULO²ÎÊý¶¼²»ÊʺϺÅÁî×¢Èë×Ö·û¡£¡£¡£ ¹¥»÷ÕßÄܹ»·¢ËÍÌØÖÆµÄHTTP GET»òPOSTÒªÇó£¬ÒÔÔÚÖ¸±êÍÆËã»úÉÏÖ´ÐкÅÁî¡£¡£¡£

¸üй¦·ò£º£º

20191119















ÊÂÎñÃû³Æ£º£º

TCP_Advantech_WebAccess_SCADA_BwPSLinkZip_Stack_Buffer_Overflow

[CVE-2018-7499]

°²È«ÀàÐÍ£º£º

»º³åÒç³ö

ÊÂÎñÃèÊö£º£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃAdvantech WebAccess BwPSLinkZip »ùÓÚÕ»µÄ»º³åÇøÒç³ö·ì϶À´Ö´ÐÐËÁÒâ´úÂëµÄÐÐΪ¡£¡£¡£

Advantech WebAccessÊÇÑлª£¨Advantech£©¹«Ë¾µÄ²úÆ·¡£¡£¡£Advantech WebAccessÊÇÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¡£¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý½ÚÖÆ£¬²¢ÌṩԶ³Ì½ÚÖÆºÍÖÎÀí×Ô¶¯»¯É豸µÄÖ°ÄÜ¡£¡£¡£WebAccess DashboardÊÇÆäÖеÄÒ»¸öÒDZí°å×é¼þ £»WebAccess Scada NodeÊÇÆäÖеÄÒ»¸ö¼à¿Ø½Úµã×é¼þ¡£¡£¡£WebAccess/NMSÊÇÒ»Ì×ÓÃÓÚÍøÂçÖÎÀíϵͳ£¨NMS£©µÄÍøÂçä¯ÀÀÆ÷»ù´¡Ì×¼þ¡£¡£¡£

¸Ã·ì϶ÊÇÓÉÓÚÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´ÖƵ½BwPSLinkZip.exeµÄ²Ö¿â»º³åÇøÖÐʱ¶ÌȱÌìǵ²é³­ËùÖ¡£¡£¡£

ͨ¹ý¹¹½¨ÌØÊâµÄRPCÒªÇ󣬹¥»÷ÕßÄܹ»ÔÚWebAccess¹ý³ÌµÄ¸ßµÍÎÄÖе¼ÖÂËÁÒâ´úÂëÖ´ÐлòÒì³£ÖÕÖ¹¡£¡£¡£

¸üй¦·ò£º£º

20191126



















Åú¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º£º

TCP_ºóÃÅ_KG.Rat_ÏνÓ

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£

Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£

KuGou.RatÊÇÒ»¸öºóÃÅ£¬ÏνÓÔ¶³Ì·þÎñÆ÷£¬½ÓÊÜÖ´ÐкڿÍÖ¸ÁÄܹ»ÆëÈ«½ÚÖÆ±»Ï°È¾»úе¡£¡£¡£ÊÔͼ»ñÈ¡Ãô¸Ð£¬Èç¼Í¼°´¼üÐÅÏ¢£¬»ñÈ¡½¹µã´°¿ÚµÄ±êÌâ¡£¡£¡£

¸üй¦·ò£º£º

20191126










ÊÂÎñÃû³Æ£º£º

TCP_ºóÃÅ_PoisonIvy_ÏνÓ

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£

Poison IvyÊÇÒ»¸ö¼«¶ÈÊ¢ÐеÄÔ¶³Ì½ÚÖÆ¹¤¾ß£¬ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÖÆ±»Ö²Èë»úе¡£¡£¡£

¸üй¦·ò£º£º

20191126








ÊÂÎñÃû³Æ£º£º

TCP_ºóÃÅ_Win32.WarZoneRat_ÏνÓ

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½ºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËWarZoneRat¡£¡£¡£

WarZoneRatÊÇÒ»¸öÖ°ÄÜ׳´óµÄÔ¶¿Ø£¬ÔËÐкó¿ÉÆëÈ«½ÚÖÆ±»Ö²Èë»úе¡£¡£¡£

¸üй¦·ò£º£º

20191126








ÊÂÎñÃû³Æ£º£º

TCP_ºóÃÅ_¹í»êÔ¶¿Ø¿ÉÒɱäÖÖ_ÏνÓ

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£

Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£

¹í»êÔ¶¿Ø·¨Ê½ÊÇÀûÓÃÒ»¸öƾ¾ÝGh0stÔ¶¿ØµÄÔ´ÂëÅú¸Ä¶øÀ´µÄºóÃÅ¡£¡£¡£ÔËÐкóÄܹ»ÆëÈ«½ÚÖÆ±»Ï°È¾»úе¡£¡£¡£

¸üй¦·ò£º£º

20191126










ÊÂÎñÃû³Æ£º£º

TUDP_ºóÃÅ_Win32.ZeroAcess_ÏνÓ

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£

Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£

Win32.ZeroAcessÊÇÒ»¸öºóÃÅ£¬ÔËÐкó£¬×¢ÈëÆäËû¹ý³Ì¡£¡£¡£ÏÂÔØÆäËû²¡¶¾»òÕßÅäÏàÐÅÏ¢»òÕßÄ£¿£¿éµÈ»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£

Éϱ¨¸ÃÊÂÎñÓÐÁ½ÖÖ¿ÉÄÜ£¬Ò»ÊÇÔ´Ö÷»ú±»Ï°È¾ÁË£¬ÏνÓCC·þÎñÆ÷ £»¶þÊÇZeroAcess·þÎñÆ÷¶Ëͨ¹ýshadan´úÀí·½Ê½½øÐÐɨÃèÐÐΪ£¬ÖØÒª¿´Ô´IPÊÇ·ñÊDZ¾µ¥ÔªµÄIPµØÖ·¡£¡£¡£

¸üй¦·ò£º£º

20191126












ÊÂÎñÃû³Æ£º£º

TCP_ºóÃÅ_Linux.BillGates_ÏνÓ

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅBillGates¡£¡£¡£

BillGatesÊÇLinuxƽ̨ϵÄÒ»¸ö½©Ê¬ÍøÂç£¬ÖØÒªÖ°ÄÜÊÇÕë¶ÔÖ¸¶¨Ö¸±ê½øÐÐDDoS¹¥»÷¡£¡£¡£

¸üй¦·ò£º£º

20191126









ÊÂÎñÃû³Æ£º£º

TCP_ľÂí_CoinMiner_ÏÎ½Ó¿ó³Ø³É¹¦

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinMinerľÂí¡£¡£¡£

CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£

¸üй¦·ò£º£º

20191126









ÊÂÎñÃû³Æ£º£º

HTTP_ºóÃÅ_Win32.wingames(ÂûÁ黨)_ÏνÓ

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅwingames¡£¡£¡£

wingamesÊÇÒ»¸öÖ°Äܼ«¶È׳´óµÄºóÃÅ£¬ÔËÐкó£¬Äܹ»ÆëÈ«½ÚÖÆ±»Ö²Èë»úе¡£¡£¡£

¸üй¦·ò£º£º

20191126








ÊÂÎñÃû³Æ£º£º

TCP_ľÂí_CoinMiner_³¢ÊÔÏνӿó³Ø

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinminerľÂí¡£¡£¡£

CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£

¸üй¦·ò£º£º

20191126