AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.06.29-2020.07.05£©
2020-07-07
Ò»¡¢ Íþвͨ¸æ
Treck TCP/IPÐÒé¿â“ Ripple20”Îó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-06-30 18:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬ÒÔÉ«ÁÐÍøÂçÇå¾²¹«Ë¾JSOFµÄÑо¿Ö°Ô±ÔÚTreck¹«Ë¾¿ª·¢µÄµ×²ãTCP/IPÈí¼þ¿âÖз¢Ã÷ÁË19¸ö0dayÎó²î£¬°üÀ¨ CVE-2020-11896¡¢CVE-2020-11897¡¢CVE-2020-11898¡¢CVE-2020-11899¡¢CVE-2020-11900¡¢CVE-2020-11901¡¢CVE-2020-11902¡¢CVE-2020-11903¡¢CVE-2020-11904¡¢ CVE-2020-11905¡¢CVE-2020-11906¡¢CVE-2020-11907¡¢CVE-2020-11908¡¢CVE-2020-11909¡¢CVE2020-11910¡¢CVE-2020-11911¡¢CVE-2020-11912¡¢CVE-2020-11913¡¢CVE-2020-11914¡£ÕâЩÎó²î±»JSOFÃüÃûΪ“Ripple20”¡£ TreckTCP/IPÊÇרÃÅΪǶÈëʽϵͳÉè¼ÆµÄ¸ßÐÔÄÜTCP/IPÐÒéÌ×¼þ£¬ÕâһϵÁÐÎó²î¶¼ÎªÄÚ´æ Ëð»µÎÊÌ⣬ԴÓÚʹÓòî±ðÐÒ飨°üÀ¨ IPv4£¬ICMPv4£¬IPv6£¬IPv6OverIPv4£¬TCP£¬UDP£¬ARP£¬D HCP£¬DNS»òÒÔÌ«ÍøÁ´Â·²ã£©ÔÚÍøÂçÉÏ·¢Ë͵ÄÊý¾Ý°üµÄ´¦Öóͷ£¹ýʧ¡£“Ripple20”Ó°ÏìÆÕ±éÁìÓòµÄÎïÁªÍø×°±¸£¬Éæ¼°HP¡¢SchneiderElectric¡¢Cisco¡¢RockwellAutomation¡¢Caterpillar¡¢BaxterµÈÖڶ๩ӦÉÌ£¬¿ÉÄܵ¼ÖÂloT×°±¸Êܵ½¾Ü¾ø·þÎñºÍÔ¶³ÌÏÂÁîÖ´Ðеȹ¥»÷¡£
¡¾Á´½Ó¡¿
http://blog.nsfocus.net/ripple-20-0630/
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. Microsoft Windows±à½âÂëÆ÷¿âÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä7ÔÂ1ÈÕ£¬Î¢ÈíÐû²¼ÔÝʱͨ¸æ³ÆÐÞ¸´ÁË2¸öWindows±à½âÂëÆ÷¿â£¨Microsoft Windows Codecs Library£©Öб£´æµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-1425,CVE-2020-1457£©¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÒ»¸öÌØÖÆµÄͼÏñÎļþÀ´´¥·¢¸ÃÎó²î£¬´Ó¶øÖ´ÐдúÂë¡£ÏÖÔÚ΢ÈíÒѾÐû²¼²¹¶¡¾ÙÐÐÁËÐÞ¸´¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/ms-codecs-library-0701/
2. F5 BIG-IP TMUI Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬F5¹Ù·½Ðû²¼Í¨¸æÐÞ¸´ÁËÒ»¸öÁ÷Á¿ÖÎÀíÓû§½çÃæ£¨TMUI£©±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-5902£©¡£´ËÎó²îÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß»ò¾ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýBIG-IPÖÎÀí¶Ë¿ÚºÍ/»ò×ÔÉíIP¶ÔTMUI¾ÙÐÐÍøÂç»á¼û£¬ÒÔÖ´ÐÐí§ÒâϵͳÏÂÁ½¨Éè»òɾ³ýÎļþ£¬½ûÓ÷þÎñºÍ/»òÖ´ÐÐí§Òâ²Ù×÷Java´úÂë¡£´ËÎó²î¿ÉÄܵ¼ÖÂÍêÕûµÄϵͳΣº¦¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/f5-big-ip-tmui-0705/
3. WastedLockerÀÕË÷Èí¼þÕë¶ÔÃÀ¹ú¹«Ë¾
¡¾¸ÅÊö¡¿
¹¥»÷Õßͨ¹ýSocGholish¶ñÒâ¿ò¼ÜÔÚαװ³ÉÈí¼þ¸üеÄÍøÕ¾ÉϾÙÐÐÈö²¥£¬»ñµÃÊܺ¦ÕßÍøÂçµÄ»á¼ûȨÏÞºó£¬Ê¹ÓÃCobalt Strike¹¤¾ßºÍÆäËûÔ¶³ÌÅþÁ¬¹¤¾ßÀ´ÇÔȡƾ֤£¬Éý¼¶ÌØÈ¨²¢ÔÚÍøÂçÉÏÈö²¥°²ÅÅWastedLockerÀÕË÷Èí¼þ¡£WastedLockerÀÕË÷Èí¼þ¶ÔÃÀ¹ú¹«Ë¾£¬Í¨¹ý¶Ô´ó´ó¶¼ÅÌËã»úºÍ·þÎñÆ÷¾ÙÐмÓÃÜÀ´Ï÷ÈõIT»ù´¡¼Ü¹¹£¬ÒÔÒªÇó»ñµÃÊý°ÙÍòÃÀÔªµÄÊê½ð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/wastedlocker-ransomware-us
4. PROMETHIUM×é֯ʹÓÃStrongPity3¶ñÒâÈí¼þ¾ÙÐй¥»÷
¡¾¸ÅÊö¡¿
PROMETHIUM×é֯ͨ¹ýFirefoxä¯ÀÀÆ÷¡¢VPNpro¿Í»§¶Ë¡¢DriverPackÇý¶¯³ÌÐòºÍ5kPlayerýÌå²¥·ÅÆ÷ËĸöÐµÄľÂí»¯×°ÖÃÎļþÈö²¥¶ñÒâÈí¼þStrongPity3£¬´Ë´Î¹¥»÷Ô˶¯Õë¶Ô¸çÂ×±ÈÑÇ¡¢Ó¡¶È¡¢¼ÓÄôóºÍÔ½ÄÏ¡£PROMETHIUMÊÇÒ»¸öÖÁÉÙ´Ó2012Äê×îÏÈ»îÔ¾µÄÍþв×éÖ¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.talosintelligence.com/2020/06/promethium-extends-with-strongpity3.html
5. ThanosÀÕË÷Èí¼þͨ¹ý´¹ÂÚÓʼþÈö²¥
¡¾¸ÅÊö¡¿
ThanosÀÕË÷Èí¼þÖ÷Ҫͨ¹ýÒÔ²ÆÎñÐÅÏ¢×÷ΪÓÕ¶üµÄÍøÂç´¹ÂÚµç×ÓÓʼþ¾ÙÐÐÈö²¥£¬¸ÃÈí¼þÔÚ°ëÄêÄÚ¾ÙÐпìËÙµü´ú£¬ÔöÌíÁËÐí¶àй¦Ð§£¬²¢ÇÒʹÓÃRIPlaceÊÖÒÕÌÓ±ÜÇå¾²¼ì²â¡£
¡¾²Î¿¼Á´½Ó¡¿
https://labs.sentinelone.com/thanos-ransomware-riplace-bootlocker-and-more-added-to-feature-set/
6. Firefox²î±ð°æ±¾Öз¢Ã÷mPathÎó²î
¡¾¸ÅÊö¡¿
½üÆÚÑо¿Ö°Ô±·¢Ã÷Mozilla Firefox°æ±¾76.0.2 x64ºÍFirefox Nightly°æ±¾78.0a1 x64µÄURL mPathÎó²î£¬¹¥»÷ÕßʹÓôËÎó²îÐèÒª½¨ÉèÒ»¸öÌØÖÆµÄÍøÒ³£¬²¢ÈÃDZÔÚµÄÊܺ¦Õßͨ¹ýä¯ÀÀÆ÷¾ÙÐлá¼û¡£URL¹¤¾ßµ¼ÖÂÔ½½ç¶ÁÈ¡£¬²¢Ê¹¹¥»÷ÕßÄܹ»Ê¹ÓÃ×ß©µÄÄÚ´æÀ´ÈƹýASLRºÍÆäËûÎó²î£¬²¢×îÖÕ»ñµÃí§Òâ´úÂëÖ´ÐС£
¡¾²Î¿¼Á´½Ó¡¿
https://www.binarydefense.com/threat_watch/mpath-vulnerability-discovered-in-different-firefox-versions/
7. Outlaw½©Ê¬ÍøÂç¹¥»÷º£ÄÚ´ó×ÚÆóÒµ
¡¾¸ÅÊö¡¿
Outlaw½©Ê¬ÍøÂçÖ÷ÒªÌØÕ÷Ϊͨ¹ýSSH±¬ÆÆ¹¥»÷Ä¿µÄϵͳ£¬Í¬Ê±Èö²¥»ùÓÚPerlµÄShellbotºÍÃÅÂÞ±ÒÍÚ¿óľÂí¡£¿ËÈÕOutlaw½©Ê¬ÍøÂçʹÓÃÎïÁªÍø£¨IoT£©×°±¸ºÍLinux·þÎñÆ÷Éϵij£¼ûÏÂÁî×¢ÈëÎó²î¾ÙÐÐѬȾ£¬Ñ¬È¾ÀֳɺóÔÚLinux·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂ룬º£ÄÚ´ó×ÚÆóÒµÓû§ÊÕµ½Ó°Ïì¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1021.html
8. Agent Teslaͨ¹ýÍøÂç´¹ÂÚÓʼþÈö²¥
¡¾¸ÅÊö¡¿
Agent TeslaÊÇÒ»ÖÖ¿ÉÒÔÇÔÈ¡ä¯ÀÀÆ÷¡¢FTPºÍÓʼþƾ֤µÈÊý¾ÝµÄÌØ¹¤Èí¼þ£¬ÒÔRTFÎļþ×÷Ϊ¸½¼þµÄÍøÂç´¹ÂÚµç×ÓÓʼþÈö²¥£¬Óû§Ö´Ðи½¼þºó»áͨ¹ýÎå¸öÒ»Á¬ÆôÓúêµÄÇëÇóÓÕµ¼Óû§Ö´ÐÐÌìÉúµÄPowershell´úÂëÏÂÔØ¸Ã¶ñÒâÈí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.deepinstinct.com/2020/07/02/agent-tesla-a-lesson-in-how-complexity-gets-you-under-the-radar/
9. Ursnif¶ñÒâÈí¼þð³ä˰Îñ¾ÖÓʼþÈö²¥
¡¾¸ÅÊö¡¿
¹¥»÷Õßͨ¹ýÄ£Äâ˰Îñ¾ÖµÄµç×ÓÓʼþ·¢Ë͸øÓû§£¬²¢ÓÕµ¼Óû§Éó²éÓʼþÖи½¼ÓXLSÎĵµÒÔ×°ÖÃUrsnif¶ñÒâÈí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://cert-agid.gov.it/news/finta-comunicazione-dellagenzia-delle-entrate-veicola-il-malware-ursnif/
10. MyKings½©Ê¬ÍøÂçÒýÓÃCorona²¡¶¾
¡¾¸ÅÊö¡¿
MyKingsÊÇÒ»¿îÆÆ½âSQL Server»òʹÓÃEternalBlueÎó²îѬȾÅÌËã»úµÄ½©Ê¬ÍøÂ磬½üÆÚ¶ÔÆäʹÓõÄEternalBlueÄ£¿é¾ÙÐÐÁËÉÙÁ¿¸ü¸Ä£¬Éý¼¶Á˸üлúÖÆ£¬²¢ÇÒʹÓÃÁ˶ÔCorona²¡¶¾µÄÒýÓá£
¡¾²Î¿¼Á´½Ó¡¿
https://news.sophos.com/en-us/2020/07/02/mykings-jumps-on-the-corona-train/
11. ÐÂÀÕË÷Èí¼þEvilQuestÕë¶ÔmacOSÓû§
¡¾¸ÅÊö¡¿
ÐÂÀÕË÷Èí¼þEvilQuestÖ¼ÔÚ¶ÔmacOSϵͳ¾ÙÐмÓÃÜ£¬ÓëÆäËûÀÕË÷Èí¼þ²î±ðµÄÊÇ£¬EvilQuest»¹×°ÖÃÁ˼üÅ̼ͼ³ÌÐò¡¢·´ÏòÍâ¿Ç²¢´ÓÊÜѬȾµÄÖ÷»úÉÏÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°ü¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/105419/malware/macos-evilquest-ransomware.html

AG¹«Ë¾ÔÆ







