AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021Äê6Ô£©

2021-07-02

6Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬Windows NTFS ȨÏÞÌáÉýÎó²î£¨CVE-2021-31956£©ºÍWindows Print SpoolerȨÏÞÌáÉýÎó²î£¨CVE-2021-1675£©Ó°Ïì¹æÄ£½Ï´ó¡£Ç°ÕßΪntfs.sys ÖлùÓڶѵĻº³åÇøÒç³öÎó²î£¬¾­ÓÉÉí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÔËÐÐÌØÖÆµÄ³ÌÐò¾ÙÐÐϵͳÌáȨ¡£¹¥»÷Õßͨ³£Í¨¹ýÓÕµ¼Óû§·­¿ªÌØÖƵÄÎļþÀ´Ê¹ÓôËÎó²î£¬CVSS ÆÀ·ÖΪ 9.3£»ºóÕß±»Î¢ÈíÔÚͨ¸æÖбê¼ÇΪImportant¼¶±ðµÄÍâµØÈ¨ÏÞÌáÉýÎó²î£¬µ«ÏÖʵÉÏÔÚÓòÇéÐÎÖкÏÊʵÄÌõ¼þÏ£¬ÎÞÐèÈκÎÓû§½»»¥£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õ߾ͿÉÒÔʹÓøÃÎó²îÒÔSYSTEMȨÏÞÔÚÓò¿ØÖÆÆ÷ÉÏÖ´ÐÐí§Òâ´úÂ룬´Ó¶ø»ñµÃÕû¸öÓòµÄ¿ØÖÆÈ¨£¬ÎÒÃÇÒÔΪ¸ÃÎó²îÏÖʵÍþвƷ¼¶½Ï¸ß£¬½¨ÒéÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤£¬ÓÈÆäÊÇÓò¿ØÖÆÆ÷µÈ·þÎñÆ÷£¬CVSS ÆÀ·ÖΪ 7.8¡£

ÁíÍ⣬±¾´Î΢ÈíÐÞ¸´ÁË5¸öCritical¼¶±ðÎó²î£¬45¸öImportant ¼¶±ðÎó²î£¬Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£

ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬¶ÔÔÆÖ÷»úµÄ¹¥»÷ÊÂÇé½ÏÁ¿ÆµÈÔ£¬ÆäÖаüÀ¨CleanfdaÍÚ¿óľÂí¶ÔÔÆÖ÷»úÌᳫµÄ¹¥»÷£º¹¥»÷ÕßʹÓÃDocker Remote ApiδÊÚȨÏÂÁîÖ´ÐÐÎó²î¹¥»÷ÔÆÖ÷»ú£¬¹¥»÷Àֳɺó»áͶµÝCleanfdaÍÚ¿óľÂí£»Satan DDoS½©Ê¬ÍøÂçľÂí¶ÔÔÆÖ÷»úµÄ¹¥»÷£º¹¥»÷Õßͨ¹ýShiro1.2.4·´ÐòÁл¯Îó²î¶ÔÔÆÖ÷»úÌᳫ¹¥»÷Ô˶¯£¬ÒâͼֲÈëÃûΪSatan DDoSµÄ½©Ê¬ÍøÂçľÂí³ÌÐò£»TeamTNTÍÚ¿óľÂí±äÖÖ¶ÔÔÆÖ÷»úÌᳫµÄ¹¥»÷£ºÓÉij¸ölinuxÍÚ¿óľÂíÒýÆð£¬×îÖÕÅжÏΪTeamTNTÍÚ¿óľÂí×îбäÖֵĹ¥»÷¡£

ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/

 £¬

Ò»¡¢ Îó²îÌ¬ÊÆ

2021Äê06ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼541¸öÎó²î, ÆäÖиßΣÎó²î24¸ö£¬Î¢Èí¸ßΣÎó²î16¸ö¡£

 

* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2021.06.30

×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»

 

¶þ¡¢ ÍþвÊÂÎñ

1. ¹¥»÷ÕßʹÓÃÊ¢ÐÐÓ¦ÓóÌÐòÄ£×ÓÔÚ Android ÉÏÈö²¥ Teabot ºÍ Flubot ¶ñÒâÈí¼þ

¡¾±êÇ©¡¿TeaBot,Flubot

¡¾Ê±¼ä¡¿2021-06-01

¡¾¼ò½é¡¿

ÔÚ Android ×°±¸ÉÏÈö²¥¶ñÒâÈí¼þ²¢½ûÖ¹Ò×£¬ÓÉÓÚ¹Ù·½ÊÐËÁͨ³££¨²¢·Ç×ÜÊÇ£©¿ÉÒÔ×èÖ¹ÕâЩÀàÐ͵ÄÓ¦ÓóÌÐòµÖ´ïÓû§ÊÖÖС£¿ÉÊÇ£¬Android ×î´óµÄÓÅÊÆÖ®Ò»£¬¼´Äܹ»´Ó·Ç¹Ù·½ÈªÔ´ÅÔ¼ÓÔØÓ¦ÓóÌÐò£¬ÕâÒ²ÊÇÒ»¸öÈõµã¡£·¸·¨·Ö×ÓʹÓöàÖÖ¼¼ÇÉ˵·þÓû§ÔÚ¹Ù·½ÊÐËÁÖ®Íâ×°ÖÃÓ¦ÓóÌÐò£¬Í¨¹ýÅÔ¼ÓÔØÈö²¥´ó²¿·Ö¶ñÒâÈí¼þ¡£ÈôÊÇÒÆ¶¯×°±¸Ã»ÓÐ×°ÖÃÇå¾²½â¾ö¼Æ»®£¬¶ñÒâÓ¦ÓóÌÐò¾Í»á×ÔÓÉÖÜÓΡ£TeaBot ºÍ Flubot ÊÇ×îеÄÒøÐÐľÂí¼Ò×壬¶àλÇå¾²Ñо¿Ö°Ô±ÔÚ2021 ÄêÍ·¼¸¸öÔ·¢Ã÷ÁËËüÃÇ¡£Bitdefender Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÅúеĶñÒâ Android Ó¦ÓóÌÐò£¬ËüÃÇÄ£ÄâÊ¢ÐÐÆ·ÅƵÄÕæÊµÓ¦ÓóÌÐò£¬µ«´øÓжñÒâÈí¼þ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://labs.bitdefender.com/2021/06/threat-actors-use-mockups-of-popular-apps-to-spread-teabot-and-flubot-malware-on-android/

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡6ÌõIOC£¬ÆäÖаüÀ¨3¸öÓòÃûºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

2. CleanfdaÍÚ¿óľÂí¶ÔÔÆÖ÷»úÌᳫ¹¥»÷£¬¹¥»÷Õß¿ÉÍêÈ«¿ØÖÆÊ§ÏÝÖ÷»ú

¡¾±êÇ©¡¿Cleanfda

¡¾Ê±¼ä¡¿2021-06-03

¡¾¼ò½é¡¿

¹¥»÷ÕßʹÓÃDocker Remote ApiδÊÚȨÏÂÁîÖ´ÐÐÎó²î¹¥»÷ÔÆÖ÷»ú£¬¹¥»÷Àֳɺó»áͶµÝÍÚ¿óľÂí£¬¸ÃÍÅ»ïµÄ¹¥»÷Ô˶¯ÒÑÓ°ÏìÉÏÇ§Ì¨ÔÆÖ÷»ú¡£±¾´Î¹¥»÷Ô˶¯»áʹÓöà¸öÎó²î¾ÙÐÐÈ䳿»¯À©É¢£¬Ê§ÏÝ·þÎñÆ÷Òò¹¥»÷ÕßÌí¼ÓµÇ¼ºóÃÅÒѱ»ÍêÈ«¿ØÖÆ£¬ÎÒÃÇÆ¾Ö¤Ä¾ÂíÏÂÔØ×ÊÔ´µÄ·¾¶Ãû½«ÆäÃüÃûΪCleanfdaÍÚ¿óľÂí¡£

¡¾²Î¿¼Á´½Ó¡¿

https://s.tencent.com//research/report/1318.html

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡8ÌõIOC£¬ÆäÖаüÀ¨3¸öIPºÍ5¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

3. ÍøÂç´¹ÂÚ¶ñÒâÈí¼þÐ®ÖÆ±ÈÌØ±ÒµØµã²¢ÌṩеÄÊðÀí Tesla Variant

¡¾±êÇ©¡¿Tesla Variant

¡¾Ê±¼ä¡¿2021-06-04

¡¾¼ò½é¡¿

Çå¾²Ö°Ô±×î½ü²¶»ñÁËÒ»¸öеÄÍøÂç´¹ÂÚÔ˶¯£¬ÆäÖи½¼Óµ½À¬»øÓʼþµÄ Microsoft Excel ÎĵµÏÂÔØ²¢Ö´ÐÐÁ˼¸¶Î VBscript ´úÂë¡£¸Ã¶ñÒâÈí¼þÓÃÓÚÐ®ÖÆ±ÈÌØ±ÒµØµãÐÅÏ¢£¬²¢½« Agent Tesla µÄбäÌå´«Ë͵½Êܺ¦ÕßµÄ×°±¸ÉÏ¡£ Agent Tesla ÓÚ 2014 Äêµ×Ê״α»·¢Ã÷£¬ÊÇÒ»ÖÖÒÑÖªµÄÌØ¹¤Èí¼þ£¬×¨×¢ÓÚ´ÓÊܺ¦ÕßµÄ×°±¸ÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬ÀýÈçÉúÑĵÄÓ¦ÓóÌÐòƾ֤¡¢¼üÅÌÊäÈ루¼üÅ̼ͼÆ÷£©µÈ¡£ÎÒÃÇÒѾ­Ðû²¼ÁËÐí¶àÕë¶Ô Agent Tesla Ô˶¯µÄÏêϸÆÊÎö²©¿ÍÔÚÒÑÍùµÄ¼¸ÄêÀï±» FortiGuard Labs ²¶»ñ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://www.fortinet.com/blog/threat-research/phishing-malware-hijacks-bitcoin-addresses-delivers-new-agent-tesla-variant

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

4. Satan DDoS½©Ê¬ÍøÂçľÂí¶ÔÔÆÖ÷»úµÄ¹¥»÷

¡¾±êÇ©¡¿Satan

¡¾Ê±¼ä¡¿2021-06-08

¡¾¼ò½é¡¿

Óй¥»÷Õßͨ¹ýShiro1.2.4·´ÐòÁл¯Îó²î¶ÔÔÆÖ÷»úÌᳫ¹¥»÷Ô˶¯£¬ÒâͼֲÈëÃûΪSatan DDoSµÄ½©Ê¬ÍøÂçľÂí³ÌÐò¡£¸Ã½©Ê¬ÍøÂçľÂí´ËǰÖ÷Òª¹¥»÷Windowsϵͳ£¬×÷ÕßÔÚ¶ñÒâ´úÂëÖÐ×ԳƓ¿É¹¥»÷¶àƽ̨£¬Ä¾ÂíÖ§³Ö¶à¼Ü¹¹£¬¿ÉʹÓöà¸öÎó²î¹¥»÷Èö²¥”¡£

¡¾²Î¿¼Á´½Ó¡¿

https://unit42.paloaltonetworks.com/lucifer-new-cryptojacking-and-ddos-hybrid-malware/,https://digital.nhs.uk/cyber-alerts/2020/cc-3526

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

5. APT41Õë¶ÔÓ¡¶Èº½¿Õ¹«Ë¾Ìᳫ¹¥»÷

¡¾±êÇ©¡¿APT41

¡¾Ê±¼ä¡¿2021-06-10

¡¾¼ò½é¡¿

еÄÑо¿ÏÔʾ£¬ÉϸöÔÂÓ°ÏìÓ¡¶Èº½¿ÕµÄ´ó¹æÄ£Êý¾Ýй¶ÊÂÎñÆØ¹âºó£¬Ó¡¶ÈµÄÔØÆìº½¿Õ¹«Ë¾ËƺõÒ²ÔâÊÜÁ˵¥¶ÀµÄÍøÂç¹¥»÷£¬´Ë´Î¹¥»÷Ò»Á¬ÁËÖÁÉÙÁ½¸öÔÂÁã 26 Ìì¡£

¡¾²Î¿¼Á´½Ó¡¿

https://blog.group-ib.com/colunmtk_apt41

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡25ÌõIOC£¬ÆäÖаüÀ¨5¸öIP£¬1¸öÓòÃûºÍ19¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

6. ×Ϻü²¡¶¾¶ñÒâ¹¥»÷SQL·þÎñÆ÷£¬²¢³ÊÈä³æÊ½À©É¢

¡¾±êÇ©¡¿×Ϻü²¡¶¾

¡¾Ê±¼ä¡¿2021-06-11

¡¾¼ò½é¡¿

×Ϻü²¡¶¾×îбäÖÖÕý²þâ±¹¥»÷ÆóÒµSQL Server·þÎñÆ÷µÄ1433¶Ë¿Ú£¬Ê¹ÓÃÈõ¿ÚÁî±¬ÆÆ¹¥»÷À©É¢¡£Í¨¹ýÍþвÇ鱨Êý¾Ý»ØËÝÆÊÎö£¬·¢Ã÷¸Ã±äÖÖ×Ô5ÔÂÖÐÑ®ÒÔÀ´Ñ¬È¾Á¿Òѳʴó·ùÉÏÉýÌ¬ÊÆ¡£×Ϻü²¡¶¾¼Ò×å×îÏÈ·ºÆðÔÚ2018Ä꣬×î³õͨ¹ýľÂíÏÂÔØÆ÷¡¢Ë¢Á¿Èí¼þ¡¢ÓÎÏ·Íâ¹ÒµÈ¹¤¾ß·Ö·¢£¬Ò²ÔøÊ¹ÓÃWeblogicºÍThinkPHPµÈ·þÎñÆ÷×é¼þÎó²î¹¥»÷À©É¢¡£×Ϻü²¡¶¾ÍÅ»ïÖ÷Ҫͨ¹ýÁ÷Ã¥Èí¼þ·Ö·¢¡¢Ë¢Á¿¡¢Ëøä¯ÀÀÆ÷Ö÷Ò³µÈ·½·¨Ä²Àû£¬Æä×îбäÖÖÕë¶ÔÆóÒµSQL·þÎñÆ÷µÄÈä³æÊ½¹¥»÷£¬»á¶ÔÆóÒµÐÅÏ¢Çå¾²´øÀ´ÑÏÖØÓ°Ïì¡£

¡¾²Î¿¼Á´½Ó¡¿

https://s.tencent.com//research/report/1322.html

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC£¬ÆäÖаüÀ¨4¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

7. TeamTNTÍÚ¿óľÂí±äÖÖÔÙÏ®£¬Ó°ÏìÉÏÇ§ÔÆÖ÷»ú

¡¾±êÇ©¡¿TeamTNT

¡¾Ê±¼ä¡¿2021-06-17

¡¾¼ò½é¡¿

ÊÂÎñÓÉij¸ölinuxÍÚ¿óľÂíÒýÆð£¬×îÖÕÅжÏΪTeamTNTÍÚ¿óľÂí×îбäÖֵĹ¥»÷£¬¾­Çå¾²ÍþвÇ鱨Êý¾ÝÅÌÎÊ£¬·¢Ã÷±¾´Î¹¥»÷ÊÂÎñÓ°ÏìÊýÇ§Ì¨ÔÆÖ÷»ú¡£

¡¾²Î¿¼Á´½Ó¡¿

https://s.tencent.com//research/report/1323.html

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡9ÌõIOC£¬ÆäÖаüÀ¨1¸öIP£¬4¸öÓòÃûºÍ4¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

8. ¹¥»÷ÕßʹÓÃCOVID-19ÒßÃç½ÓÖÖ¹ÒºÅÍýÏëÌᳫ´¹ÂÚ¹¥»÷

¡¾±êÇ©¡¿Agent Tesla

¡¾Ê±¼ä¡¿2021-06-18

¡¾¼ò½é¡¿

×î½üÕë¶Ô Windows ÅÌËã»úµÄÍøÂç´¹ÂÚÔ˶¯ÊÔͼÓÃ×îа汾µÄ Agent Tesla Ô¶³Ì»á¼ûľÂí (RAT) ֮һѬȾÓû§¡£·´À¬»øÓʼþʵÑéÊÒ·¢Ã÷¹¥»÷ÕßÊÔͼÒÔ COVID-19 ÒßÃç½ÓÖÖÍýÏ븽¼þΪ»Ï×ÓÌᳫ¶ñÒâÔ˶¯£¬¶ñÒâÀ¬»øÓʼþÔ˶¯ÔÚÈ«Çò¹æÄ£ÄÚÊèÉ¢£¬µ« 50% µÄ¶ñÒâµç×ÓÓʼþ±»¶¨Ïòµ½º«¹ú¡£

¡¾²Î¿¼Á´½Ó¡¿

https://hotforsecurity.bitdefender.com/blog/threat-actors-spread-agent-tesla-disguised-as-covid-19-vaccination-registration-25998.html

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

9. Î¢ÈíÇ©ÊðÁ˶ñÒâNetfilterÇý¶¯³ÌÐò

¡¾±êÇ©¡¿Netfilter

¡¾Ê±¼ä¡¿2021-06-25

¡¾¼ò½é¡¿

ÉÏÖÜ£¬ÎÒÃǵľ¯±¨ÏµÍ³Í¨ÖªÎÒÃÇ¿ÉÄÜ·ºÆðÎ󱨣¬ÓÉÓÚÎÒÃǼì²âµ½Ò»¸öÃûΪ“Netfilter”µÄÇý¶¯³ÌÐò£¬¸ÃÇý¶¯³ÌÐòÓÐ Microsoft ÊðÃû¡£´Ó Windows Vista ×îÏÈ£¬ÈκÎÔÚÄÚºËģʽÏÂÔËÐеĴúÂë¶¼ÐèÒªÔÚ¹ûÕæÐû²¼Ö®Ç°¾ÙÐвâÊÔºÍÊðÃû£¬ÒÔÈ·±£²Ù×÷ϵͳµÄÎȹÌÐÔ¡£Ä¬ÈÏÇéÐÎÏÂÎÞ·¨×°ÖÃûÓÐ Microsoft Ö¤ÊéµÄÇý¶¯³ÌÐò¡£ÔÚÕâÖÖÇéÐÎÏ£¬¼ì²âЧ¹ûÎªÕæÑôÐÔ£¬Òò´ËÎÒÃǽ«ÎÒÃǵķ¢Ã÷ת·¢¸øÁË Microsoft£¬Microsoft Á¬Ã¦½«¶ñÒâÈí¼þÊðÃûÌí¼Óµ½ Windows Defender ÖУ¬ÏÖÔÚÕýÔÚ¾ÙÐÐÄÚ²¿ÊӲ졣ÏÖÔÚΪֹ£¬Çý¶¯³ÌÐòÔõÑùͨ¹ýÊðÃûÀú³ÌÈÔȻδ֪¡£

¡¾²Î¿¼Á´½Ó¡¿

https://www.gdatasoftware.com/blog/microsoft-signed-a-malicious-netfilter-rootkit

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼