¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.07.26-2021.08.01£©
2021-08-02
Ò»¡¢ Íþвͨ¸æ
EximÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2020-28020£©
¡¾Ðû²¼Ê±¼ä¡¿2021-07-2718:00:00GMT
¡¾¸ÅÊö¡¿
5Ô·ÝQualys¹ûÕæÅû¶ÁËEximÓʼþ·þÎñÆ÷ÖеÄ21¸öÇå¾²Îó²î£¬ÕâЩÎó²îÓ°ÏìEximÔÚ2004ÄêÖ®ºó¿ª·¢µÄËùÓа汾£¬ÇÒ´ó´ó¶¼¿ÉÒÔÔÚĬÈÏÉèÖÃÖб»Ê¹Óã¬AG¹«Ë¾¿Æ¼¼¿ËÈÕ¼à²âµ½Óв¿·ÖÎó²îϸ½ÚÓëPoC±»¹ûÕæ£¬ÆäÖÐ×îÑÏÖØµÄΪEximÕûÊýÒç³öÎó²î£¨CVE-2020-28020£©£¬¸ÃÎó²îÔ´ÓÚreceive_msgº¯Êý£¬¹¥»÷Õß¿ÉÒÔͨ¹ý”\\n”ÈÆ¹ýExim¶ÔÓʼþÍ·¾ÞϸµÄÏÞÖÆ£¬´Ó¶øÔì³ÉÕûÊýÒç³ö£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÔì³É¾Ü¾ø·þÎñ»òÔ¶³Ì´úÂëÖ´ÐС£ÏÖÔÚÎó²îÏêÇéÓë¿´·¨ÑéÖ¤³ÌÐòÒѹûÕæ£¬ÇëÏà¹ØÓû§ÊµÊ±½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£EximÊÇÒ»¿îÓʼþ´«ÊäÊðÀíÈí¼þ£¨MTA£©£¬¿ÉʵÏÖÓʼþµÄ·ÓÉ¡¢×ª·¢ºÍͶµÝ¡£Ö÷Òª±»¹¹½¨ÔÚÀàUnix²Ù×÷ϵͳÉÏ·¢ËͺÍÎüÊÕµç×ÓÓʼþ£¬°üÀ¨Solaris¡¢AIX¡¢LinuxµÈ£»Exim¿ÉÒÔ´¦Öóͷ£´ó×Ú»¥ÁªÍøÁ÷Á¿£¬ÓÉÓÚÆä¾ßÓÐÉèÖÃÎÞаµÄÌØµã£¬Í¨³£»áÓëÆäËûÓ¦ÓÃÈí¼þ´îÅäʹÓá£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ¹¥»÷ÕßʹÓÃWiper¹¥»÷¶«¾©°ÂÔË»á
¡¾¸ÅÊö¡¿
¾ÝTheRecord±¨µÀ£¬ÔÚ2021Äê¶«¾©°ÂÔ˻ῪĻʽ֮ǰ£¬ÈÕ±¾Çå¾²¹«Ë¾Ñо¿Ö°Ô±¼ì²âµ½Ò»ÖÖÒÔ°ÂÔË»áΪÖ÷ÌâµÄ¶ñÒâÈí¼þWiper£¬¹¥»÷ÕßʹÓÃWiper¶ñÒâÈí¼þ¹¥»÷¶«¾©°ÂÔ˻ᣬʹÓÃURLÓ¦ÓóÌÐò»á¼ûXVideosÊÓÆµÃÅ»§ÉϵÄÄÚÈÝ£¬×¨¼ÒÒÔΪ£¬ÊµÑé´Ë¹¦Ð§ÊÇΪÁËÓÕʹר¼ÒÐÅÍÐÄÚÈÝѬȾÊÇÔÚ»á¼ûÍøÕ¾Ê±±¬·¢µÄ¡£Í¬Ê±É¾³ýÊÜѬȾϵͳÉϵÄÎļþ¡£¸Ã¶ñÒâÈí¼þ½öÕë¶ÔÓû§Îļþ¼ÐϵÄÊý¾Ý£¬¶ñÒâÈí¼þµÄÄ¿µÄÊÇʹÓÃIchitaroÈÕÓïÎÄ×Ö´¦Öóͷ£Æ÷½¨ÉèµÄÎļþ£¬ÕâÖÖÇéÐÎÅú×¢ËüÊÇΪÈÕ±¾Óû§¿ª·¢µÄ¡£¶ñÒâÈí¼þ»¹ÊµÏÖÁ˹æ±ÜºÍ·´ÆÊÎö¹¦Ð§£¬ÒÔ±ÜÃâ¶ñÒâ´úÂë±»ÆÊÎö¡£¸Ã¶ñÒâÈí¼þ»¹Äܹ»´ÓÊÜѬȾµÄÅÌËã»úÖÐɾ³ý×ÔÉí¼°Æä±£´æµÄÖ¤¾Ý¡£”
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYS2
2. ÀÕË÷Èí¼þÍÅ»ïʹÓÃKaseyaVSAµÄ0dayÎó²î¹¥»÷ÖÎÀí·þÎñÉÌ
¡¾¸ÅÊö¡¿
7ÔÂ2ºÅ£¬ÀÕË÷Èí¼þÍÅ»ïRevilʹÓÃKaseyaVSAÔ¶³ÌÖÎÀíÓ¦ÓõÄ0dayÎó²î¶Ô¶à¸öÖÎÀí·þÎñÌṩÉÌºÍÆóÒµ·¢¶¯ÁË´ó¹æÄ£µÄ¹¥»÷£¬¶ÔÔ¼60¸öÖÎÀí·þÎñÌṩÉ̺ÍÔ¼1500¼ÒÆóÒµ¾ÙÐÐÁ˼ÓÃÜ£¬¹¥»÷ÕßÔÚÍê³É¹¥»÷ºó£¬»ñȡͨÓýâÃÜÆ÷¡£Ö®ºó£¬ÀÕË÷Èí¼þÍŻ↑³ö¼ÛÇ®£ºÍ¨ÓýâÃÜÆ÷ÐèÒª7000ÍòÃÀÔª£¬½âÃÜËùÓÐÊÜѬȾµÄÍйܷþÎñÌṩÉÌÐèÒª500Íò£¬½â¾öÒ»¸öÊܺ¦ÕßÍøÂçÉÏÀ©Õ¹µÄ¼ÓÃÜÐèÒª4ÍòÃÀÔª¡£Ëæºó£¬REvilÀÕË÷Èí¼þÍÅ»ïÈ´ÉñÃØÏûÊÅ£¬Ò²¹Ø±ÕÁËËûÃǵÄÖ§¸¶ÍøÕ¾ºÍ»ù´¡ÉèÊ©¡£Æäʱ´ó²¿·ÖÊܺ¦Õß»¹Ã»ÓÐÖ§¸¶Êê½ð£¬ÀÕË÷Èí¼þÍÅ»ïµÄÏûÊÅҲʹµÃÄÇЩÐèÒª¹ºÖýâÃÜÆ÷µÄ¹«Ë¾ÎÞ·¨¾ÙÐйºÖá£7ÔÂ22ÈÕ£¬Kaseya±¬·¢ÉùÃ÷£¬ËûÃÇ´ÓÒ»¸ö“ÊÜÐÅÍеĵÚÈý·½”ÊÕµ½Á˶ÔÓ¦ÉÏ´ÎÀÕË÷¹¥»÷µÄͨÓýâÃÜÆ÷£¬ÏÖÔÚÒ²ÒѾ·Ö·¢¸øÁËÊܵ½Ó°ÏìµÄÖ÷¹Ë¡£Ö»¹ÜKaseya²¢Î´Í¸Â¶ÃÜԿȪԴ£¬µ«ËüÃÇÏòBleepingComputerÌåÏÖ£¬±»·Ö·¢¼òÖ±Êǹ¥»÷µÄͨÓýâÃÜÃÜÔ¿£¬ÄÜÈÃËùÓÐÍйܷþÎñÌṩÉ̼°Æä¿Í»§Ã⺬»ìÃÜÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYTn
3. ¹¥»÷ÕßʹÓÃPlugX±äÌåÀ´¹¥»÷MS-ExchangeServer
¡¾¸ÅÊö¡¿
2021Äê3Ô£¬Ñо¿Ö°Ô±ÔÚ¼à²âMicrosoftExchangeServer¹¥»÷ʱ£¬·¢Ã÷ÁËÒ»ÖÖPlugXбäÌ壬¹¥»÷ÕßʹÓÃPlugXбäÌå¹¥»÷MicrosoftExchangeServer¡£¸ÃPlugX±äÌåÊÇ×÷Ϊһ¸ö±»¹¥»÷·þÎñÆ÷ʹÓúóÔ¶³Ì»á¼û¹¤¾ß(RAT)´«Ë͵½ÆäÖÐһ̨·þÎñÆ÷¡£PlugX±äÌ寿ÒìÖ®´¦ÔÚÓÚ¶Ô½¹µãÔ´´úÂëµÄ¸ü¸Ä¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYT9
4. PrayingMantisʹÓÃWebÓ¦ÓóÌÐòÖеÄÎó²îÇÔÈ¡·þÎñÆ÷Êý¾Ý
¡¾¸ÅÊö¡¿
Ò»¸öз¢Ã÷ÃûΪPrayingMantisµÄÍþв×éÖ¯Õýͨ¹ýʹÓÃÃæÏò»¥ÁªÍøµÄWebÓ¦ÓóÌÐòÖеÄÎó²îÇÔȡƾ֤ºÍÆäËûÊý¾Ý¡£ÔÚijЩÇéÐÎÏ£¬¸Ã×é֯ʹÓÃCheckboxSurveyÖеÄÁãÈÕÎó²î¹¥»÷ÓÃÓÚWebÍйܵÄWindowsInternetÐÅÏ¢·þÎñÆ÷¡£×îб¨¸æÏÔʾ£¬ÔÚʹÓÃÎó²îºó£¬¸Ã×éÖ¯°²ÅÅÁËÒ»¸ö¶ñÒâÈí¼þÀ´ÍøÂçϵͳÐÅÏ¢£¬²¢°²ÅÅÌØÁíÍâJavaScript¶ñÒâÈí¼þ²¢Ö´ÐÐHTTPºÍSQLÁ÷Á¿×ª·¢¡£ÌØÁíÍâÓÐÓÃÔØºÉËæºó»áÍøÂçÆ¾Ö¤²¢Î£º¦¸ü¶àÒ×Êܹ¥»÷µÄ·þÎñÆ÷¡£“
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYSP
5. ¹¥»÷ÕßʹÓÃͼƬ¹¥»÷°Í²¼¿ËÀÕË÷Èí¼þÍÅ»ïµÄÂÛ̳
¡¾¸ÅÊö¡¿
ƾ֤±¨¸æ³Æ£¬BabukÀÕË÷Èí¼þÔËÓªÉÌÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷£¬¹¥»÷ÕßʹÓÃËûÃǵÄÂÛ̳¿ñ»¶Í¼Æ¬¶ÔBabukÀÕË÷Èí¼þÔËÓªÉÌÕö¿ª´ó¹æÄ£¹¥»÷£¬6ÔÂ⣬BabukLockerÀÕË÷Èí¼þÔÚÍøÉÏй¶ÐÅÏ¢£¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÀ´½¨Éè×Ô¼ºµÄÀÕË÷Èí¼þ°æ±¾¡£
Ö®ºó£¬ÀÕË÷Èí¼þÍÅ»ïÍ»È뻪ʢ¶ÙÌØÇø´ó¶¼»á¾¯Ô±¾Ö£¬ÔÚ»ªÊ¢¶ÙÌØÇø¾¯Ô±¾ÖÔ⵽Ϯ»÷ºó£¬¹¥»÷Õß¶ÔÆäÎļþ¾ÙÐмÓÃܲ¢Ïò»ªÊ¢¶ÙÌØÇø¾¯Ô±¾ÖË÷Òª400ÍòÃÀÔªµÄÊê½ð¡£5ÔÂ⣬BabukÀÕË÷Èí¼þÔËÓªÉ̽«ËûÃǵÄÀÕË÷Èí¼þ×ß©վµã¸üÃûΪPayload.bin£¬²¢×îÏÈÏòÆäËûÍÅ»ïÌṩʹÓôÓÊܺ¦ÕßÄÇÀïÇÔÈ¡µÄÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYSM
6. ¹¥»÷ÕßʹÓÃÀÕË÷Èí¼þ¹¥»÷ÄÏ·ÇÎïÁ÷¹«Ë¾
¡¾¸ÅÊö¡¿
ÄÏ·Ç´óÐÍÌú·¡¢¿Ú°¶ºÍ¹ÜµÀ¹«Ë¾TransnetSOCLtdÐû²¼Ôâµ½ÆÆËðÐÔÍøÂç¹¥»÷¡£7ÔÂ22ÈÕ£¬ÄÏ·ÇÎïÁ÷¹«Ë¾TransnetSOCÊܵ½¹¥»÷Õ߯ÆËðÐÔÍøÂç¹¥»÷£¬Òò´Ë¸Ã¹«Ë¾×èÖ¹ÁËËùÓпڰ¶ÂëÍ·µÄÔËÓª¡£Transnet͸¶£º“¿Ú°¶ÂëÍ·ÔÚÕû¸öϵͳÖÐÔËÐУ¬µ«¼¯×°ÏäÂëÍ·³ýÍ⣬ÓÉÓÚ¿¨³µÔËÊä·½ÃæµÄNavisϵͳÊܵ½ÁËÓ°Ïì¡£”
Õë¶ÔÕâ´Î¹¥»÷£¬¸Ã¹«Ë¾¸æË߯äÔ±¹¤ÔÚÁíÐÐ֪֮ͨǰ£¬ËùÓÐÔ±¹¤¹Ø±ÕÌõ¼Ç±¾µçÄÔºĮ́ʽ»ú£¬²¢ÇÒ²»µÃ»á¼ûËûÃǵĵç×ÓÓʼþ£¬ÒÔ±ÜÃâÍþвÉìÕÅ¡£¸Ã¹«Ë¾µÄÒ»·ÝÉùÃ÷ÖÐдµÀ¡£“ÕýÔÚÆð¾¢ïÔÌÍ£»úʱ¼ä£¬ÒÔÈ·±£ÊÜÓ°ÏìµÄϵͳ¾¡¿ìÖØÐÂÆô¶¯²¢ÔËÐУ¬”ÓÉÓÚÕâ´Î¹¥»÷£¬TransnetSOCLtdÍøÕ¾¹Ø±Õ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYSV
7. ¹¥»÷ÕßʹÓ÷¢ËͶñÒâµç×ÓÓʼþ¹¥»÷Zimbra·þÎñÆ÷
¡¾¸ÅÊö¡¿
¹¥»÷Õßͨ¹ý·¢ËͶñÒâµç×ÓÓʼþÀ´¹¥»÷Zimbra·þÎñÆ÷£¬Ñо¿Ö°Ô±ÌåÏÖ£¬ZimbraÍøÂçÓʼþ·þÎñÆ÷ÓÐÁ½¸öÎó²î£¬¹¥»÷Õß»áʹÓÃÕâЩÎó²îÉó²éËùÓÐʹÓÃÕâ¿îÐ×÷¹¤¾ßµÄÆóÒµÖÐËùÓÐÔ±¹¤µÄÊÕ¼þÏäºÍ·¢¼þÏä¡£ÓÉÓÚZimbra´¦Öóͷ£´ó×ÚÐÂÎŵĸ߶ÈÃô¸ÐÐÔ£¬Òò´ËÓÐÁè¼Ý200,000¼ÒÆóÒµ¡¢Ò»Ç§¼ÒÕþ¸®ºÍ½ðÈÚ»ú¹¹ÒÔ¼°ÊýÒÚÓû§Ê¹ÓÃÔÚZimbraÍøÕ¾Öеĵç×ÓÓʼþºÍÐ×÷¹¤¾ß£¬ÌìÌì¶¼ÔÚ½»Á÷µç×ÓÓʼþ¡£±¨¸æ³Æ£¬“µ±¹¥»÷Õß»á¼ûÔ±¹¤µÄµç×ÓÓʼþÕÊ»§Ê±£¬Í¨³£»á±¬·¢ÑÏÖØµÄÇå¾²Òþ»¼¡£”“³ýÁ˽»Á÷µÄÉñÃØÐÅÏ¢ºÍÎļþÍ⣬µç×ÓÓʼþÕÊ»§Í¨³£ÓëÆäËûÔÊÐíÖØÖÃÃÜÂëµÄÃô¸ÐÕÊ»§Ïà¹ØÁª¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYSJ
8. ¹¥»÷ÕßʹÓüÓÃܶñÒâÈí¼þLemonDuck¹¥»÷Windows¡¢Linux×°±¸
¡¾¸ÅÊö¡¿
ƾ֤Microsoft365DefenderÍþвÇ鱨ÍŶӵÄÒ»·Ýб¨¸æ£¬¹¥»÷ÕßʹÓÃLemonDuck¼ÓÃÜÍÚ¾ò¶ñÒâÈí¼þ¹¥»÷WindowsºÍLinux×°±¸¡£¸Ã¶ñÒâÈí¼þÔÊÐí¹¥»÷ÕßÇÔȡƾ֤²¢ÔÚÊÜѬȾµÄϵͳÉϾÙÐÐһϵÁжñÒâÔ˶¯¡£¸Ã¶ñÒâÈí¼þͨ¹ýÎó²îʹÓá¢ÍøÂç´¹ÂÚµç×ÓÓʼþ¡¢USB×°±¸ºÍ±©Á¦¹¥»÷ÔÚ²î±ð¹ú¼Ò¾ÙÐÐÈö²¥¡£
LemonDuck¶ñÒâÈí¼þ¶ÔÆóÒµµÄÍþв»¹ÔÚÓÚËüÊÇÒ»ÖÖ¿çÆ½Ì¨Íþв¡£ËüÊÇÕë¶ÔLinuxϵͳºÍWindows×°±¸µÄ½©Ê¬¶ñÒâÈí¼þ¼Ò×åÖ®Ò»£¬”¶ñÒâÈí¼þ¿ÉÒÔʹÓÃеÄÎó²î£¬¾ÝÑо¿Ö°Ô±³Æ£¬LemonDuck¶ñÒâÈí¼þ±³ºóµÄÍþвÐÐΪÕßÏÕЩ¿ÉÒÔÁ¬Ã¦Ê¹ÓÃÐÂÎó²î²¢ÓÐÓõؿªÕ¹Õ©ÆÔ˶¯¡£ÀýÈ磬ËûÃÇÔÚ2020ÄêÔÚ»ùÓÚµç×ÓÓʼþµÄ¹¥»÷ÖÐʹÓÃÁËCOVID-19Ö÷ÌâÓÕ¶ü¡£½ñÄ꣬ËûÃÇÈÈÖÔÓÚʹÓÃMSExchangeServerÎó²î»á¼ûδÐÞ²¹µÄϵͳ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYSL
9. ºÚ¿Í×éÖ¯°²ÅŶñÒâÈí¼þ¹¥»÷AndroidºÍWindowsÓû§
¡¾¸ÅÊö¡¿
Hack-for-hire×éÖ¯StrongPity°²ÅÅÁËAndroid¶ñÒâÈí¼þ£¬ÒÔÃé×¼ÐðÀûÑǵç×ÓÕþÎñÍøÕ¾µÄ»á¼ûÕß¡£ÔÚÕâ´Î×îеÄÔ˶¯ÖУ¬ºÚ¿Í×é֯ʹÓÃwateringholeÊÖÒÕÈëÇÖÐðÀûÑǵĵç×ÓÕþÎñÍøÕ¾£¬È»ºóÓÃľÂí°æ±¾Ìæ»»¹Ù·½Ó¦ÓóÌÐò¡£¹¥»÷ÕßËæºóʹÓøÃÓ¦ÓóÌÐò´ÓÊܺ¦ÕßµÄ×°±¸ÖÐÇÔÈ¡Îļþ¡£
³ýÁ˸öñÒâÈí¼þµÄAndroid°æ±¾Í⣬¹¥»÷Õß»¹°²ÅÅÁËÒ»¿îÕë¶ÔWindowsÓû§µÄÓ¦ÓóÌÐò¡£ÕýÔÚΪÕâÁ½¸öÓ¦ÓóÌÐò°æ±¾¿ª·¢Ð¹¦Ð§¡£Ê×Ïȹ¥»÷Õß´ÓMalwareHunterTeamTwitterÉϹ²ÏíµÄÒ»¸öÏß³ÌÖÐÏàʶµ½¸ÃÑù±¾¡£Æ¾Ö¤Ïß³ÌÏàʶµ½¹²ÏíÑù±¾ÊÇÐðÀûÑǵç×ÓÕþÎñAndroidÓ¦ÓóÌÐòµÄľÂí»¯°æ±¾£¬¸ÃÓ¦ÓóÌÐò»áÇÔÈ¡ÁªÏµÈËÁÐ±í²¢ÍøÂç¾ßÓÐÌØ¶¨ÌØÕ÷µÄÎļþ£¬À´×ÔÊܺ¦Õß×°±¸µÄÎļþÀ©Õ¹Ãû¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYRY
10. MicrosoftHyper-VÖеÄÒ»¸öÒªº¦Îó²îÐÅÏ¢
¡¾¸ÅÊö¡¿
SafeBreachµÄÑо¿Ö°Ô±±¨¸æËµ£¬ÓйØMicrosoftHyper-VÖÐÒ»¸öÒªº¦È±ÏݵÄÏêϸÐÅÏ¢£¬¸ú×ÙΪCVE-2021-28476£¬¸ÃȱÏÝ¿ÉÒÔ´¥·¢DoS²¢ÔÚÆäÉÏÖ´ÐÐí§Òâ´úÂë¡£¸ÃÎó²î±£´æÓÚMicrosoftHyper-VµÄÍøÂç½»Á÷»úÇý¶¯³ÌÐòÖУ¬ËüÓ°ÏìWindows10ºÍWindowsServer2012µ½2019¡£CVE-2021-28476Îó²îµÄÑÏÖØÐÔÆÀ·ÖΪ9.9£¬Î¢ÈíÒÑÓÚ5Ô½â¾öÁ˸ÃÎó²î¡£¹¥»÷Õß¿ÉÒÔͨ¹ý´ÓÐéÄâ»úÏòHyper-VÖ÷»ú·¢ËÍÌØÖÆÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/4qYTp

AG¹«Ë¾ÔÆ







