¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.08.30-2021.09.05£©
2021-09-07
Ò»¡¢ Íþвͨ¸æ
ÀÕË÷Èí¼þʹÓÃExchange1dayÎó²îÈö²¥È«ÆÊÎö£¨CVE-2021-34473¡¢CVE-2021-34523¡¢CVE-2021-31207£©
¡¾Ðû²¼Ê±¼ä¡¿2021-08-3113:00:00GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²â·¢Ã÷¶àÆðʹÓÃMicrosoftExchange¶à¸öÎó²î£¨ProxyShell£©¾ÙÐй¥»÷µÄÇå¾²ÊÂÎñ£¬²¢ÓÐнúµÄLockFileÀÕË÷²¡¶¾×é֯ʹÓÃProxyShellÓëPetitPotamÎó²î¶ÔÆóÒµÓòÇéÐξÙÐй¥»÷£¬×îÖÕµ¼Ö¶à¼Òµ¥Î»ÓòÄÚÖ÷»ú±»ÅúÁ¿Ö´ÐÐÀÕË÷¼ÓÃÜ¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. Marketo×éÖ¯ÇÔÈ¡ÁËPUMA¹«Ë¾1GBµÄÊý¾Ý
¡¾¸ÅÊö¡¿
8ÔÂ29ÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷£¬Marketo×éÖ¯ÇÔÈ¡ÁËPUMA¹«Ë¾1GBµÄÊý¾Ý£¬¸Ã×éÖ¯×÷Ϊһ¸ö“±»µÁÊý¾ÝÊг¡”µÄÔËÓªÉÌ£¬²î±ðÓڵ䷶µÄÀÕË÷Èí¼þ¼¯ÍÅ£¬ËûÃÇÊÇͨ¹ý×èÖ¹Êܺ¦ÕßµÄÍøÂ磬¼ÓÃÜÖÖÖÖÊý¾Ý´æ´¢ÉϵĿÉÓÃÎļþÀ´·Ö·¢¶ñÒâ´úÂë£¬ÆÆËðITÔËÓª·þÎñ¡£ÇÔÈ¡PUMA¹«Ë¾µÄÃô¸ÐÊý¾ÝÔÚ°µÍøÆ½Ì¨ÉϾÙÐйûÕæÅÄÂô¡£ÆäÖаüÀ¨Á´½Óµ½¹«Ë¾²úÆ·ÖÎÀíÃÅ»§ÄÚ²¿ÖÎÀíÓ¦ÓóÌÐòµÄÔ´´úÂ룬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÊý¾ÝÀ´²ß»®¶Ô¹«Ë¾¸üÖØ´óµÄ¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMOp
2. ¹¥»÷ÕßÏòÓû§·Ö·¢ÐéαµÄµç×ÓÓʼþ¾ÙÐÐÍøÂç´¹ÂÚÔ˶¯
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±¼ì²âµ½¶àÆðÒÔйÚÒßÃçCOVID-19ΪÖ÷ÌâµÄÍøÂç´¹ÂÚÔ˶¯¡£¹¥»÷ÕßʹÓÃÐéαµÄÍøÂç´¹ÂÚµç×ÓÓʼþΪÓÕ¶üÏòÓû§·¢ËͶñÒâ½á¹¹µÄÑù±¾Á´½ÓÓÕÆÓû§µã»÷£¬´Ë´ÎÓÕ¶üÎļþÃû×ÖΪ“Certification-Vaccination-Status-Form.pdf”£¬Êܺ¦Õßͨ¹ýµã»÷ÓÕ¶üÎļþÆô¶¯PowerShell³ÌÐò²¢Ö´ÐжñÒâ¾ç±¾ºó£¬³ÌÐò»á´ÓÖ¸¶¨µÄÍøÂçµØµãÇëÇó²¢»ñÈ¡ºóÐøµÄPowerShell¶ñÒâ¾ç±¾£¬»á½«Ä¿µÄÔ±¹¤´øµ½Ò»¸öð³äMicrosoftOutlookWebÓ¦ÓóÌÐòµÇÂ¼Ò³ÃæµÄ¶ñÒâÓò£¬×îÖÕËûÃǽ«±»´øµ½Ò»¸öð³äÊÜÐÅÍÐÆ·ÅƵı»Ð®ÖÆÍøÒ³¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMOj
3. ²¨Ê¿¶Ù¹«¹²Í¼Êé¹ÝÔâµ½ºÚ¿Í¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Åú×¢£¬²¨Ê¿¶Ù¹«¹²Í¼Êé¹ÝÅÌËã»úÍøÂçÔâµ½ºÚ¿ÍÑÏÖØ¹¥»÷£¬µ¼Ö¸ÃͼÊé¹ÝÕû¸öϵͳÖÐÖ¹£¬ÊÜÓ°ÏìµÄϵͳÒÑÏÂÏߣ¬ÔÝÍ£Á˹«¹²ÅÌËã»úºÍ¹«¹²´òÓ¡·þÎñ£¬ÒÔ¼°Ò»Ð©ÔÚÏß×ÊÔ´¡£ÏÖÔÚ£¬¸ÃͼÊé¹ÝÈÔÈ»¿ª·Å£¬µ«´ó²¿·Öµç×Ó¹¦Ð§´¦ÓÚÀëÏß״̬£¬ÏÖÔÚËùÓеÄÊÂÇéÕ¾µã¶¼ÔÚÊÖ¶¯´¦Öóͷ£ÉúÒâ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMOi
4. ¹¥»÷ÕßʹÓÃKonniRAT¶ñÒâÈí¼þ¹¥»÷¶íÂÞ˹
¡¾¸ÅÊö¡¿
MalwarebytesLabsµÄÑо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÕýÔÚ¾ÙÐеĶñÒâÈí¼þÔ˶¯£¬´Ë´Î¹¥»÷Ô˶¯µÄÄ¿µÄÊǶíÂÞ˹¡£¹¥»÷ÕßʹÓÃÁ½·Ý¶íÓï±àдµÄÎäÆ÷»¯Îļþ×÷ΪÓÕ¶ü£¬ÆäÖÐÒ»·ÝʹÓöíÂÞ˹Ó볯Ïʰ뵺֮¼äµÄÉÌÒµºÍ¾¼ÃÎÊÌ⣬µÚ¶þ·ÝÎļþÒÔ¶íÂÞ˹-ÃɹÅÕþ¸®¼äίԱ»áµÄ¾Û»áΪÓÕ¶ü¡£µ±¹¥»÷Õ߯ôÓúêºó£¬ËüÖ´ÐеÄѬȾÁ´½«×îÏȰ²ÅÅÒ»¸ö¾ÓÉÑÏÖØ»ìÏýµÄÐÂKonniRAT±äÌ壬¹¥»÷ÕßÊÔͼÔÚÎĵµÄÚÈݵÄĩβÒþ²ØÆäÖ÷ÒªÔ˶¯×îÏȵĶñÒâJS£¬²¢Ã»Óн«ÆäÖ±½Ó·ÅÈëºêÖУ¬ÒÔ×èÖ¹±»AV²úÆ·¼ì²âµ½²¢Òþ²ØÆäËûÃǵÄÖ÷ÒªÒâͼ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMO1
5. ÉÁµç´ûºÚ¿ÍÇÔÈ¡Á˽ðÈÚÆ½Ì¨CREAM Finance 2900ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¹¤Òµ
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷£¬ÉÁµç´ûºÚ¿Í´Ó½ðÈÚÆ½Ì¨CREAMFinanceDefiÇÔÈ¡ÁËÁè¼Ý2900ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò×ʲú¡£CREAMFinanceDefiÊÇÒ»ÖÖÈ¥ÖÐÐÄ»¯½è´ûÐÒ飬¹©Ð¡ÎÒ˽¼Ò¡¢»ú¹¹ºÍÐÒé»á¼û½ðÈÚ·þÎñ¡£ËüÏò±»¶¯³ÖÓÐETH»òwBTCµÄÓû§ÔÊÐíÊÕÒæ¡£ÔÚ¹¥»÷Ô˶¯ÖУ¬¹¥»÷ÕßÔÚÆä“ÉÁµç´û”¹¦Ð§ÖоÙÐÐÁË“ÖØÈë¹¥»÷”£¬ÇÔÈ¡ÁË418,311,571¸öAMP´ú±ÒºÍ1,308.09¸öETH´ú±Ò¡£ºÚ¿ÍÔÚ×ªÒÆ×ʲúÀú³ÌÖÐͨ¹ýÖØÐ½èÓÃAmp´ú±Ò¾ÙÐÐÁË500ETHµÄÉÁ´û£¬È»ºóÔÚ17±Êµ¥¶ÀµÄÉúÒâÖиüеÚÒ»¸ö½èÈë×ʲú¡£ÌṩÁËÒ»¸öʾÀýÊÂÎñ£¬ºÚ¿Íʹ500ETHµÄflashloanºÍ´æÈëµÄ×ʽð×÷ΪµäÖÊ¡£CREAMFinanceÐû²¼£¬ÒѾÔÝÍ£Amp´ú±ÒµÄ¹©Ó¦ºÍ½èÓúÏÔ¼À´×èÖ¹ºÚ¿ÍʹÓá£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMOx
6. LockBitÀÕË÷Èí¼þ×éÖ¯¹¥»÷Âü¹Èº½¿Õ¹«Ë¾
¡¾¸ÅÊö¡¿
8ÔÂ30ÈÕ£¬LockBitÀÕË÷Èí¼þ×éÖ¯Àֳɹ¥»÷ÁËÂü¹Èº½¿Õ¹«Ë¾µÄÄÚ²¿ÏµÍ³£¬ÇÔÈ¡Á˸ù«Ë¾103GBÓëÆä¿Í»§ÓйصÄСÎÒ˽¼ÒÊý¾Ý£¬±»µÁÊý¾Ý°üÀ¨ÐÕÃû¡¢¹ú¼®¡¢ÐԱ𡢵绰ºÅÂë¡¢µç×ÓÓʼþ¡¢µØµã¡¢ÁªÏµÐÅÏ¢¡¢»¤ÕÕÐÅÏ¢¡¢ÀúÊ·ÂÃÐÐÐÅÏ¢¡¢²¿·ÖÐÅÓÿ¨ÐÅÏ¢ºÍº½¿Õ¹«Ë¾Âÿ͵ÄÌØÊâÉÅʳÐÅÏ¢¡£¹¥»÷ÕßÔÚÆäйÃÜÍøÕ¾ÉÏÐû²¼ÁËÒ»ÌõÐÂÎÅ£¬ÈôÊÇÂü¹Èº½¿Õ¹«Ë¾²»Ö§¸¶Êê½ð£¬¾Í»áй¶±»µÁÊý¾Ý£¬ÐÂÎÅ»¹ÏÔʾËûÃÇÓиü¶àµÄÊý¾ÝҪй¶¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMOC
7. Õ©ÆÕßͨ¹ýð³äOpenSea¹«Ë¾Ô±¹¤ÇÔÈ¡Êý×Ö×ʲú
¡¾¸ÅÊö¡¿
OpenSeaÊÇÒ»¸ö»ùÓÚÇø¿éÁ´µÄÊý×Ö×ʲúÊг¡£¬Õ©ÆÕßð³äOpenSea¹«Ë¾Ô±¹¤ÒÔÇÔÈ¡Êý×Ö×ʲú£¬OpenSeaÓû§ºÍÒÕÊõ¼ÒJeffNicholas³ÉΪ¸ÃȦÌ×µÄÊܺ¦Õߣ¬¹¥»÷Õß´ÓLedgerÇ®°üÖÐÇÔÈ¡ÁËËû³ÖÓеÄÊý×Ö×ʲúÒÔ¼°¼ÛÖµÔ¼14,600ÃÀÔªµÄ4.5ÒÔÌ«±Ò¡£¹¥»÷µÄ·½·¨ÊÇ£¬Õ©ÆÕßʹÓÃDiscord̸ÌìÆ½Ì¨Ìṩ¿Í»§Ö§³Ö£¬ÈËÃDZ»¼û¸æÈ¥OpenSeaDiscord²¢Ðû²¼ËûÃǵÄÖ§³ÖƱ£¬¹¥»÷ÕßÕýÔÚ¼àÊÓÕâЩÇþµÀ£¬È»ºóÁªÏµÃ°³äOpenSeaÖ§³ÖµÄÈË£¬²¢ÌṩÓйØËûÃÇÖ§³ÖË÷ÅâµÄÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMOA
8. ¹¥»÷ÕßʹÓÿª·ÅÖØ¶¨ÏòÁ´½ÓÒýÓÕÓû§»á¼û¶ñÒâÍøÕ¾»ñÈ¡Office365ƾ֤
¡¾¸ÅÊö¡¿
ƾ֤×î½üÐû²¼µÄÒ»·ÝÑо¿±¨¸æ³Æ£¬±£´æ“ÆÕ±é”µÄÍøÂç´¹ÂÚÔ˶¯£¬Ú²ÆÕßʹÓÿª·ÅÖØ¶¨ÏòÁ´½ÓÒýÓÕÓû§»á¼û¶ñÒâÍøÕ¾£¬ÒÔ»ñÈ¡Office365ƾ֤¡£³ýÁËʹÓÃÉç»á¹¤³ÌÊÖÒÕÄ£ÄâÉú²úÁ¦¹¤¾ßºÍ·þÎñÀ´ÒýÓÕÓû§µã»÷Ö®Í⣬ڲÆÕß»¹»á°²ÅÅÒ»¸ö¶ñÒâµÄCAPTCHAÑéÖ¤Ò³Ãæ£¬×ÊÖúÒýÓÕÓû§µã»÷¶ñÒâÁ´½Ó²¢×ÊÖúÚ²ÆÕ߱ܿªÄ³Ð©Çå¾²¹¤¾ß£¬Óû§»áµ¥»÷ÖØ¶¨ÏòÁ´½Ó£¬Õâ»á·¿ªÒ»¸öËûÃDZØÐèÌîдµÄÐéαCAPTCHAÕ¾µã£¬Ò»µ©Êܺ¦ÕßÍê³ÉαÔìµÄCAPTCHAÒ³Ãæ£¬Óû§¾Í»á±»·¢Ë͵½Ò»¸ö¶ñÒâÓò£¬¸ÃÓòÖ¼ÔÚ¿´ÆðÀ´ÏñÒ»¸öÕýµ±µÄOffice365»òÆäËûµÇÂ¼ÍøÕ¾¡£»áÒªÇóÓû§ÊäÈëÁ½´Îƾ֤£¬ÒÔÈ·±£Ú²ÆÕßÍøÂç׼ȷµÄÓû§ÃûºÍÃÜÂë×éºÏ¡£Ò»µ©Óû§µÚ¶þ´ÎÊäÈëÃÜÂ룬¸ÃÒ³Ãæ¾Í»á¶¨Ïòµ½Ò»¸öÕýµ±µÄSophosÍøÕ¾£¬¸ÃÍøÕ¾Éù³Æ¸Ãµç×ÓÓʼþÒѱ»ÊÍ·Å£¬´Ó¶øÎª¹¥»÷ÔöÌíÁËÁíÒ»²ãÕýµ±ÐÔ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMOF
9. Ó¢¹úµçÐŹ«Ë¾ÔâÊÜDDOS¹¥»÷
¡¾¸ÅÊö¡¿
Ó¢¹úÁ½¼Ò»ùÓÚ»¥ÁªÍøµÄµçÐŹ«Ë¾VoipUnlimitedºÍVoipfoneÔÚÆäÍøÕ¾Éϱ¨¸æËµ£¬ËüÃÇÒѾÔâµ½ÁËÂþÑÜʽ¾Ü¾ø·þÎñDDOSÒ»Á¬µÄ¹¥»÷£¬µ¼Ö¹«Ë¾ÏµÍ³½¹µãÍøÂçÒѾÖÐÖ¹ÁË·þÎñ£¬ÒÔ¼°ÖÐÖ¹Á˺ô½Ð¡¢×¢²áºÍ¿Í»§ÃÅ»§»á¼ûµÈ·þÎñ£¬Ôì³ÉµÄ·þÎṉ̃»¾Ã¿Ð¡Ê±ËðʧµÍÓÚ1000Ó¢°÷£¬¹¥»÷ǰÑԓһֱת±ä”£¬ÆäÍøÂçÍŶÓÕýÔÚÆ¾Ö¤ÐèÒªÓ¦Óûº½â²½·¥¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMPu
10. FIN7ÍÅ»ïʹÓÃWordÎĵµÀ´Í¶·Å¶ñÒâ¸ºÔØ¹¥»÷ÃÀ¹úÏúÊÛµã·þÎñÌṩÉÌ
¡¾¸ÅÊö¡¿
Anomali Threat Research ר¼Ò¼à²âÁË×î½üÓÉFIN7ÍÅ»ï¾ÙÐеÄÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷Ô˶¯£¬´Ë´Î¹¥»÷µÄÄ¿µÄÊÇÃÀ¹úÏúÊÛµã (PoS) ·þÎñÌṩÉÌ£¬ ¸ÃÍÅ»ïͨ¹ý½ÓÄÉWordÎĵµÀ´Í¶·Å¶ñÒâ¸ºÔØ¹¥»÷Á´ÇÖÈëPoS·þÎñÉÌÍøÂ磬¹¥»÷Á´Ê¼ÓÚÒ»¸ö Microsoft Word Îĵµ (.doc)£¬ÆäÖаüÀ¨Ò»¸öÉù³ÆÊ¹Óà Windows 11 Alpha ÖÆ×÷µÄÓÕ¶üͼÏñ¡£¸ÃͼÏñÒªÇóÊÕ¼þÈËÆôÓÃ±à¼ºÍÆôÓÃÄÚÈÝÒÔ»á¼ûÆäÄÚÈÝ£¬ÆôÓúêºó£¬½«Ö´Ðи߶ȻìÏýµÄ VBA ºêÒÔ¼ìË÷ JavaScript ¸ºÔØ¡£¶ñÒâ¾ç±¾»¹»á¼ì²éÐéÄâ»úÒÔ±ÜÃâÔÚÐéÄ⻯ÇéÐÎÖоÙÐÐÆÊÎö£¬ÎªÁË×èÖ¹·¢Ã÷£¬¸Ã×éÖ¯»¹ÔÚ VBA ºêÖвåÈëÀ¬»øÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMPj

AG¹«Ë¾ÔÆ







