AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021Äê7Ô£©

2021-08-02

7Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬EximÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2020-28020£©ºÍLinuxÄÚºËȨÏÞÌáÉýÎó²îͨ¸æ£¨CVE-2021-33909£©Ó°Ïì¹æÄ£½Ï´ó¡£Ç°ÕßÔ´ÓÚreceive_msgº¯Êý£¬»ùÓÚEximÕûÊýÒç³öÎó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ý”\\n”ÈÆ¹ýExim¶ÔÓʼþÍ·¾ÞϸµÄÏÞÖÆ£¬´Ó¶øÔì³ÉÕûÊýÒç³ö£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÔì³É¾Ü¾ø·þÎñ»òÔ¶³Ì´úÂëÖ´ÐС£CVSSÆÀ·ÖΪ9.8£»ºóÕßΪLinuxÄں˵Äseq_file½Ó¿Ú±£´æsize_t-to-intÀàÐÍת»»Îó²î£¬ÓÉÓÚfs/seq_file.cûÓÐ׼ȷÏÞÖÆseq»º³åÇø·ÖÅÉ£¬´Ó¶øµ¼ÖÂÕûÊýÒç³ö¡¢Ô½½çдÈëÒÔ¼°È¨ÏÞÌáÉý¡£í§ÒâÓû§È¨Ï޵Ĺ¥»÷Õß¶¼¿ÉÒÔÔÚĬÈÏÉèÖÃÖÐʹÓôËÎó²î£¬´Ó¶ø»ñµÃÊÜÓ°ÏìÖ÷»úµÄrootȨÏÞ¡£¸ÃÎó²îÓ°ÏìÁË×Ô2014ÄêÒÔÀ´Ðû²¼µÄËùÓÐLinuxÄں˰汾£¬ÏÖÔÚPoCÒѹûÕæ£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤£¬CVSS ÆÀ·ÖΪ8.4¡£

ÁíÍ⣬±¾´Î΢ÈíÐÞ¸´ÁË13¸öCritical¼¶±ðÎó²î£¬103¸öImportant¼¶±ðÎó²î£¬Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£

ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬¶ÔÏà¹ØÆóÒµ£¬Õþ¸®×éÖ¯µÄ¹¥»÷ÊÂÎñ½ÏÁ¿ÆµÈÔ£¬ÆäÖаüÀ¨¹¥»÷ÕßʹÓÃNetwireRAT¶ñÒâÈí¼þ¶ÔÕþ¸®×éÖ¯Õö¿ªÕë¶ÔÐÔ¹¥»÷£¬ÆäÖй¥»÷Õß½«Ä¿µÄËø¶¨ÔÚ°Í»ù˹̹µÄÖÖÖÖ×éÖ¯£¬NetwiredRC±»ÓÃ×÷Õâ´Î¹¥»÷Ô˶¯µÄ×îÖÕÓÐÓÃÔØºÉ¡£TA402×é֯ʹÓÃжñÒâÈí¼þLastConn¹¥»÷Öж«¸÷¹úÕþ¸®£¬TA402ʹÓÃÕþÖκ;üÊÂÖ÷Ì⣬°üÀ¨¼ÓɳµØ´øÒ»Á¬µÄ³åÍ»£¬ÓÕʹÓû§·­¿ª¸½²¢µã»÷¶ñÒâÁ´½Ó¡£PuzzleMaker×éÖ¯¶ÔÈ«ÇòÆóÒµÕö¿ª¹¥»÷Ô˶¯£¬ÕâЩ¹¥»÷¶¼Ê¹ÓÃÁËһϵÁÐGoogleChromeºÍMicrosoftWindows0dayÎó²î¡£DarkCaracalʹÓöñÒâÈí¼þ¹¥»÷Î÷°àÑÀÓï¹ú¼ÒÆóÒµÍøÂçÔ˶¯£¬REvilʹÓù©Ó¦Á´Îó²î¹¥»÷Êý°Ù¼ÒÆóÒµ£¬Õë¶ÔÍйܷþÎñÌṩÉ̵Ŀͻ§ºÍKaseyaVSAÔ¶³Ì¼à¿ØºÍÖÎÀíÆ½Ì¨ÏÖ³¡°æµÄÆóÒµÓû§ÌᳫÁËÒ»¸ö¶ñÒâ¸üаü¡£

ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/

Ò»¡¢ Îó²îÌ¬ÊÆ

2021Äê07ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼603¸öÎó²î,ÆäÖиßΣÎó²î83¸ö£¬Î¢Èí¸ßΣÎó²î35¸ö¡£

 

*Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2021.08.02

×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»

 

¶þ¡¢ ÍþвÊÂÎñ

1. Mirai_ptea½©Ê¬ÍøÂçʹÓÃKGUARDDVRÎó²î¾ÙÐй¥»÷ÍøÕ¾

¡¾±êÇ©¡¿Mirai_ptea

¡¾Ê±¼ä¡¿2021-07-01

¡¾¼ò½é¡¿

2021Äê6ÔÂ22ÈÕ£¬ÎÒÃǼì²âµ½Ò»¸öMirai±äÌåÑù±¾£¬½«ÆäÃüÃûΪmirai_ptea½©Ê¬ÍøÂç,¸Ã½©Ê¬ÍøÂç±»ÓÃÓÚÒ»Á¬µÄDDoS¹¥»÷£¬²¢½«´ËÑù±¾Í¨¹ýKGUARDDVRµÄÐÂÎó²î¾ÙÐÐÈö²¥¡£Mirai_ptea½©Ê¬ÍøÂçʹÓÃKGUARDDVRÎó²î¾ÙÐй¥»÷ÍøÕ¾¡£

¡¾²Î¿¼Á´½Ó¡¿

https://blog.netlab.360.com/mirai_ptea-botnet-is-exploiting-undisclosed-kguard-dvr-vulnerability-en/

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡14ÌõIOC£¬ÆäÖаüÀ¨5¸öIP£¬7¸öÓòÃûºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

2. REvilʹÓù©Ó¦Á´Îó²î¹¥»÷Êý°Ù¼ÒÆóÒµ

¡¾±êÇ©¡¿REvil

¡¾Ê±¼ä¡¿2021-07-04

¡¾¼ò½é¡¿

7ÔÂ2ÈÕ£¬ËäÈ»Ðí¶àÆóÒµµÄÔ±¹¤ÒªÃ´ÒѾ­Ï°à£¬ÒªÃ´×¼±¸¶È¹ýÒ»¸ö³¤¼ÙÖÜÄ©£¬REvilÀÕË÷Èí¼þ×éÖ¯µÄÒ»¸öÁ¥Êô»ú¹¹ÌᳫÁËÒ»³¡ÆÕ±éµÄ¼ÓÃÜÀÕË÷Õ½ÂÔ¡£REvil¹¥»÷ÕßʹÓÃKaseyaVSAÔ¶³ÌÖÎÀí·þÎñµÄÎó²î£¬Õë¶ÔÍйܷþÎñÌṩÉ̵Ŀͻ§ºÍKaseyaVSAÔ¶³Ì¼à¿ØºÍÖÎÀíÆ½Ì¨ÏÖ³¡°æµÄÆóÒµÓû§ÌᳫÁËÒ»¸ö¶ñÒâ¸üаü¡£

¡¾²Î¿¼Á´½Ó¡¿

https://news.sophos.com/en-us/2021/07/04/independence-day-revil-uses-supply-chain-exploit-to-attack-hundreds-of-businesses/

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡5ÌõIOC£¬ÆäÖаüÀ¨3¸öÓòÃûºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

3. DarkCaracalʹÓöñÒâÈí¼þ¹¥»÷Î÷°àÑÀÓï¹ú¼ÒÆóÒµÍøÂçÔ˶¯

¡¾±êÇ©¡¿DarkCaracal

¡¾Ê±¼ä¡¿2021-07-07

¡¾¼ò½é¡¿

2021Ä꣬DarkCaracalÕë¶ÔÎ÷°àÑÀÓï¹ú¼ÒÆóÒµÍøÂçµÄÒ»Á¬¹¥»÷Ô˶¯£¬ÆäÖÐ90%µÄ¼ì²â±¬·¢ÔÚίÄÚÈðÀ­¡£½«´ËÔ˶¯ÖÐʹÓõĶñÒâÈí¼þÓë֮ǰ¼Í¼µÄÄÚÈݾÙÐнÏÁ¿Ê±£¬ÎÒÃÇ·¢Ã÷Á˴˶ñÒâÈí¼þµÄй¦Ð§£¬³ÆÎªBandook¡£ÎÒÃÇ»¹·¢Ã÷£¬ÕâÏîÕë¶ÔίÄÚÈðÀ­µÄÔ˶¯×Ô2015ÄêÒÔÀ´Ò»Ö±ºÜ»îÔ¾£¬µ«²»ÖªºÎÒÔÈÔȻûÓмͼ¡£¼øÓÚËùʹÓõĶñÒâÈí¼þºÍÄ¿¿ÚºÅÑÔÇéÐΣ¬ÎÒÃÇÑ¡Ôñ½«´ËÔ˶¯ÃüÃûΪBandidos¡£

¡¾²Î¿¼Á´½Ó¡¿

https://www.welivesecurity.com/2021/07/07/bandidos-at-large-spying-campaign-latin-america/

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

4. ¹¥»÷ÕßʹÓÃ¿çÆ½Ì¨È䳿²¡¶¾HolesWarm¹¥»÷windowsºÍlinuxϵͳ

¡¾±êÇ©¡¿HolesWarm

¡¾Ê±¼ä¡¿2021-07-12

¡¾¼ò½é¡¿

Çå¾²Ñо¿Ôº½üÆÚÒ»¿îÃûΪHolesWarmµÄ¿çƽ̨È䳿²¡¶¾£¬¸ÃÈ䳿²¡¶¾½üÆÚÀ©É¢Ê®·ÖѸËÙ£¬ËùʹÓõÄÎó²îÎäÆ÷Ôڶ̶ÌÒ»¸öÔµÄʱ¼äÀï¾ÍÁè¼Ý20ÖÖ£¬¿°³Æ“Îó²îʹÓÃÍõÕß”¡£×Ô6ÔÂÉÏÑ®ÒÔÀ´£¬HolesWarmÒÑÔì³É¶à´ÎÈëÇÖá¯Á룬Àۼƹ¥ÏÝÔÆÖ÷»ú¹ýǧ̨£¬¾­ÆÊÎö£¬HolesWarm²¡¶¾»áʹÓú£ÄÚʹÓÃÂʽϸߵÄÍøÂç×é¼þ¸ßΣÎó²î¹¥»÷Èö²¥£¬°üÀ¨º£ÄÚ³£ÓõÄÓÃÓÑ¡¢ÖÂÔ¶µÈ°ì¹«×é¼þ£¬ÒÔ¼°Tomcat¡¢Weblogic¡¢Shiro¡¢Structs2¡¢XXL-JOB¡¢Springboot¡¢JenkinsµÈ20Óà¸öÍøÂç×é¼þ¾ùÊÜÓ°Ï죬¹¥»÷Õß½ÓÊÜÔÆ¿Ø·þÎñÆ÷Ö¸ÁîÒ»Ö±¸üй¥»÷Ä£¿éºÍ¹¥»÷Ä¿µÄ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://s.tencent.com/research/report/78

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡9ÌõIOC£¬ÆäÖаüÀ¨1¸öÓòÃûºÍ8¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

5. ¹¥»÷ÕßʹÓÃNetwireRAT¶ñÒâÈí¼þ¶ÔÕþ¸®×éÖ¯Õö¿ªÕë¶ÔÐÔ¹¥»÷

¡¾±êÇ©¡¿NetwireRAT

¡¾Ê±¼ä¡¿2021-07-14

¡¾¼ò½é¡¿

Çå¾²Ñо¿Ô±ÊӲ쵽´Ó2021Äê7ÔÂ×îÏȵÄÒ»¸öÓÐȤµÄÓã²æÊ½ÍøÂç´¹ÂÚÔ˶¯£¬ÆäÖй¥»÷Õß½«Ä¿µÄËø¶¨ÔÚ°Í»ù˹̹µÄÖÖÖÖ×éÖ¯¡£NetwiredRC±»ÓÃ×÷Õâ´Î¹¥»÷Ô˶¯µÄ×îÖÕÓÐÓÃÔØºÉ¡£Óã²æÊ½ÍøÂç´¹ÂÚºÍʹÓÃÐÅÏ¢ÇÔÈ¡RATµÄÍŽáÅú×¢Õâ²»ÊǼòÆÓµÄÍøÂç·¸·¨£¬¶øÊÇÕë¶Ô°Í»ù˹̹¶à¸öÕþ¸®×éÖ¯ÒÔ¼°ÆäËû±ÊÖ±ÐÐÒµµÄ¸ü´óÍøÂç¹¥»÷Ô˶¯¡£

¡¾²Î¿¼Á´½Ó¡¿

https://www.zscaler.com/blogs/security-research/targeted-attack-government-organizations-delivers-netwire-rat

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡8ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ7¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

6. APT×éÖ¯FIN7ʹÓÃWINDOWS11»°ÌâÓÕ¶üµÄÓã²æ¹¥»÷Ô˶¯

¡¾±êÇ©¡¿FIN7

¡¾Ê±¼ä¡¿2021-07-16

¡¾¼ò½é¡¿

½üÆÚ£¬·üӰʵÑéÊÒ²¶»ñÁ˶à¸öʹÓÃwindows11Ïà¹Ø»°Ìâ×÷ΪÓÕ¶üµÄ´¹ÂÚÎĵµ¡£ÕâЩ´¹ÂÚÎĵµÏÔʾÁËһЩ²î±ðÓÚ³£¼û´¹ÂÚ¹¥»÷µÄ˼Ð÷ºÍ¼¼ÇÉ¡£Í¨¹ýÉîÈëÆÊÎö£¬·üӰʵÑéÊÒ·¢Ã÷ÕâЩ´¹ÂÚÎĵµÊÇFIN7×éÖ¯ÕýÔÚ¾ÙÐеĴó¹æÄ£Óã²æ¹¥»÷Ô˶¯µÄÒ»²¿·Ö£¬ÆäÊͷŵÄľÂíÏÖʵÉÏÊǸÃ×éÖ¯³£ÓõÄGriffonľÂíµÄ½ÏбäÖÖ¡£´¹ÂÚÎĵµÓëºóÐø¹¥»÷×é¼þµÄÊÖÒÕϸ½ÚÏÔʾ£¬FIN7×éÖ¯ÔÚ±¾´ÎÓã²æ¹¥»÷Ô˶¯ÖÐ×îÏȸüƵÈԵؼì²âÖ÷»úÇéÐΣ¬²¢ÔÚÑÚÊι¥»÷ºÛ¼£·½ÃæÆÆ·ÑÁ˸ü¶à¾«Éñ¡£ÕâЩ´¹ÂÚÎĵµÔÙ´Î֤ʵ£¬FIN7×éÖ¯²¢Î´Òò2018ÄêµÄ¼¯ÖÐ×¥²¶Ðж¯¶øÇýÖ𣬶øÊÇÔڸıäÁËı»®Ä£Ê½ºó£¬¸üÉóÉ÷µØ¾ÙÐÐÒÔ͵ȡ½ðÈÚ×ʲúΪÖ÷µÄÍøÂç·¸·¨Ô˶¯¡£Çå¾²³§ÉÌÓ¦Ç×½ü×¢ÖØÊ¹ÓÃFIN7×éÖ¯ÒÑÖª¹¥»÷¹¤¾ßµÄÖÖÖÖ¹¥»÷Ô˶¯¡£

¡¾²Î¿¼Á´½Ó¡¿

http://blog.nsfocus.net/apt-windows11/

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡12ÌõIOC£¬ÆäÖаüÀ¨2¸öIP£¬1¸öÓòÃûºÍ9¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

7. ¹¥»÷ÕßʹÓÃURLËõ¶ÌÆ÷·þÎñÏòAndroidÓû§·Ö·¢¶ñÒâÈí¼þFakeAdBlocker

¡¾±êÇ©¡¿FakeAdBlocker

¡¾Ê±¼ä¡¿2021-07-20

¡¾¼ò½é¡¿

ÍþвÑо¿Ô±½üÆÚ·¢Ã÷£¬Óû§ÊÕµ½Ò»Ð©URLµã»÷ºó»áµ¯³ö¹ã¸æ£¬ÕâЩ¹ã¸æÊ¹ÓõÄÊÇһЩÁ´½ÓËõ¶Ì·þÎñʹÓü¤½øµÄ¹ã¸æÊÖÒÕ£¬Í¨ÖªÓû§ËûÃǵÄ×°±¸Ñ¬È¾ÁËΣÏյĶñÒâÈí¼þ£¬Ö¸µ¼Óû§´ÓGooglePlayÊÐËÁÏÂÔØ¿ÉÒɵÄÓ¦ÓóÌÐò»ò¼ÓÈë¿ÉÒɵÄÊӲ죬Ìṩ³ÉÈËÄÚÈÝ£¬Ìṩ×îÏȸ߼¶SMS·þÎñ¶©ÔÄ£¬ÆôÓÃä¯ÀÀÆ÷֪ͨµÈ¡£»¹·¢Ã÷ÁËһЩÁ´½ÓËõ¶Ì·þÎñ½«“ÈÕÀú”ÎļþÍÆË͵½iOS×°±¸²¢·Ö·¢Android¶ñÒâÈí¼þ——ÎÒÃǽ«ÆäÃüÃûΪAndroid/FakeAdBlockerµÄ¶ñÒâÈí¼þ£¬ËüÏÂÔØ²¢Ö´ÐÐÌØÁíÍâÓÐÓÃÔØºÉ£¨ÀýÈçÒøÐÐľÂí¡¢¶ÌÐÅľÂí¡¢ºÍ¹¥»÷ÐÔ¹ã¸æÈí¼þ£©´ÓÆäC·þÎñÆ÷ÊÕµ½¡£

¡¾²Î¿¼Á´½Ó¡¿

7https://www.welivesecurity.com/2021/07/20/url-shortener-services-android-malware-banking-sms-trojans/

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡18ÌõIOC£¬ÆäÖаüÀ¨15¸öÓòÃûºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

8. ¹¥»÷ÕßʹÓöñÒâÈí¼þXLoaderÇÔÈ¡WindowsºÍmacOSµÄ·þÎñÐÅÏ¢

¡¾±êÇ©¡¿XLoader

¡¾Ê±¼ä¡¿2021-07-26

¡¾¼ò½é¡¿

¹¥»÷ÕßÕë¶ÔÏÖÔÚÖ÷Òª²Ù×÷ϵͳ¹©Ó¦É̶ԶñÒâÈí¼þ¾ÙÐÐÏà¹Øµ÷½â£¬¿ÉÒÔÔÚÒ»¸öƽ̨ÉϱàÒëÌìÉúÕë¶Ô¶à¸öƽ̨µÄ¿ÉÖ´ÐÐÎļþ¡£Ñо¿Ö°Ô±×îз¢Ã÷µÄ¶ñÒâÈí¼þÊÇXLoader£¬³Æ´Ë¶ñÒâÈí¼þXLoaderÊÇͨ¹ýFormBookÖпª·¢³öÀ´µÄ¡£¼´·þÎñÐÅÏ¢ÇÔÈ¡Æ÷ºÍ¼üÅ̼ͼÆ÷£¬¹¥»÷Õß¿ÉÒÔʹÓöñÒâÈí¼þXLoaderͬʱÔÚWindowsºÍmacOS°æ±¾ÉÏÇÔÈ¡·þÎñÐÅÏ¢¡£

¡¾²Î¿¼Á´½Ó¡¿

https://www.sentinelone.com/blog/detecting-xloader-a-macos-malware-as-a-service-info-stealer-and-keylogger/

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡13ÌõIOC£¬ÆäÖаüÀ¨10¸öIPºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

9. ¹¥»÷ÕßʹÓÃPlugX±äÌå¹¥»÷MicrosoftExchangeServer

¡¾±êÇ©¡¿PlugX

¡¾Ê±¼ä¡¿2021-07-27

¡¾¼ò½é¡¿

2021Äê3Ô£¬Ñо¿Ö°Ô±ÔÚ¼à²âMicrosoftExchangeServer¹¥»÷ʱ£¬·¢Ã÷ÁËÒ»ÖÖPlugXбäÌ壬¹¥»÷ÕßʹÓÃPlugXбäÌå¹¥»÷MicrosoftExchangeServer¡£¸ÃPlugX±äÌåÊÇ×÷Ϊһ¸ö±»¹¥»÷·þÎñÆ÷ʹÓúóÔ¶³Ì»á¼û¹¤¾ß(RAT)´«Ë͵½ÆäÖÐһ̨·þÎñÆ÷¡£PlugX±äÌ寿ÒìÖ®´¦ÔÚÓÚ¶Ô½¹µãÔ´´úÂëµÄ¸ü¸Ä¡£

¡¾²Î¿¼Á´½Ó¡¿

https://unit42.paloaltonetworks.com/thor-plugx-variant/

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡120ÌõIOC£¬ÆäÖаüÀ¨18¸öIP£¬23¸öÓòÃûºÍ79¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

10. Outlawͨ¹ýÈëÇÖSSH¹«Ô¿´ó¹æÄ£¹¥»÷ÔÆÖ÷»ú

¡¾±êÇ©¡¿Outlaw

¡¾Ê±¼ä¡¿2021-07-28

¡¾¼ò½é¡¿

Çå¾²Ñо¿Ô±ÆÊÎöÖ÷»úÇå¾²¼à²âÊý¾Ýʱ·¢Ã÷£¬Outlaw½©Ê¬ÍøÂçÍÅ»ïÔÚ½ñÌìÆÆÏþ×óÓÒͨ¹ýÈëÇÖSSH¹«Ô¿¶ÔÔÆÖ÷»úÌᳫ´ó¹æÄ£¹¥»÷£¬¹¥»÷ÕßÖ÷Ҫͨ¹ýÈëÇÖSSH¹«Ô¿»ñÈ¡µÇ¼ÃÜÂëºóдÈëSSH¹«Ô¿£¬È»ºóÖ´ÐжñÒâ³ÌÐò£¬Ò»µ©¹¥»÷ÔÆÖ÷»úÀֳɣ¬¹¥»÷Õß»áдÈëеÄSSH¹«Ô¿£¬ÉèÖÃÔ¶³ÌµÇ¼ÍêÈ«¿ØÖÆ·þÎñÆ÷¡£

¡¾²Î¿¼Á´½Ó¡¿

https://s.tencent.com/research/report/91

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öIP£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼