¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.09.06-2021.09.12£©
2021-09-13
Ò»¡¢ Íþвͨ¸æ
MicrosoftMSHTMLÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40444£©
¡¾Ðû²¼Ê±¼ä¡¿2021-09-0913:00:00GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼Ç徲ͨ¸æÅû¶ÁËMicrosoftMSHTMLÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¹¥»÷Õß¿Éͨ¹ýÖÆ×÷¶ñÒâµÄActiveX¿Ø¼þ¹©ÍйÜä¯ÀÀÆ÷·ºÆðÒýÇæµÄMicrosoftOfficeÎĵµÊ¹Óã¬ÀÖ³ÉÓÕµ¼Óû§·¿ª¶ñÒâÎĵµºó£¬¿ÉÔÚÄ¿µÄϵͳÉÏÒÔ¸ÃÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂ롣΢ÈíÔÚͨ¸æÖÐÖ¸³öÒѼì²âµ½¸ÃÎó²î±»ÔÚҰʹÓã¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. AVOSLockerRansomwareÔËÓªÉ̹¥»÷̫ƽÑó¶¼»áÒøÐÐ
¡¾¸ÅÊö¡¿
PacificCityBankÊÇÒ»¼ÒÃÀ¹ú̫ƽÑó¶¼»áÒøÐУ¬×¨×¢ÓÚλÓÚ¼ÓÀû¸£ÄáÑÇÖݵĺ«ÒáÃÀ¹úÈËÉçÇø£¬²¢ÌṩÉÌÒµÒøÐзþÎñ£¬¸ÃÒøÐÐÔâµ½AVOSLockerRansomwareÔËÓªÉ̵Ĺ¥»÷£¬²¢ÇÒ´Ó½ðÈÚ»ú¹¹ÇÔÈ¡ÁËÃô¸ÐÎļþ¡£2021Äê9ÔÂ4ÈÕ£¬ÀÕË÷Èí¼þÍŻォ¸ÃÒøÐÐÐÅÏ¢Ìí¼Óµ½ÆäйÃÜÕ¾µã£¬²¢Ðû²¼ÁËһЩÆÁÄ»½ØÍ¼×÷Ϊ¹¥»÷µÄÖ¤¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMPI
2. RagnarLockerÀÕË÷Èí¼þÍÅ»ïÇÔȡ̨ÍåÍþ¸Õ¹«Ë¾1.5TBµÄÊý¾Ý
¡¾¸ÅÊö¡¿
RagnarLockerÀÕË÷Èí¼þÍÅ»ïÀÖ³ÉÇÔȡ̨ÍåÍþ¸Õ¹«Ë¾1.5TBµÄÊý¾Ý£¬±»µÁÊý¾Ý°üÀ¨Ãô¸ÐÐÅÏ¢£¬Èç±£ÃÜÐÒé¡¢²ÆÎñÎļþ¡¢ÌõÔ¼ºÍÆäËûÎļþ¡£¸Ã¹«Ë¾¾Ü¾øÖ§¸¶ºÚ¿ÍÒªÇóµÄÊê½ð¡£ÈôÊÇÊܺ¦ÕßÊÔͼÁªÏµÖ´·¨»ú¹¹£¬RagnarLockerÀÕË÷Èí¼þÍÅ»ïÍþвҪй¶±»µÁÊý¾Ý¡£¸Ã×éÖ¯ÔÚÆä°µÍø×ß©վµãÉÏÐû²¼ÁËÒ»ÌõÐÂÎÅ£¬Ðû²¼ÁËÆäÐÂÕ½ÂÔ£¬ÈôÊÇÊܺ¦ÕßÊÔͼÁªÏµÖ´·¨»ú¹¹£¬RagnarLockerÀÕË÷Èí¼þÔËÓªÉÌÍþвҪй¶±»µÁÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMPS
3. BladeHawk×éÖ¯Õë¶Ô¿â¶ûµÂ×åȺAndroidÓû§ÓÐÕë¶ÔÐÔÌᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬BladeHawk×éÖ¯Õë¶Ô¿â¶ûµÂ×åȺAndroidÓû§ÓÐÕë¶ÔÐÔÌᳫ¹¥»÷¡£¸Ã×é֯ʹÓÃÁ½¸öÉÌÒµAndroidRAT¹¤¾ß£¬»®·ÖÊÇ888RATºÍSpyNote¡£Ê¹ÓÃAndroid888RATÄܹ»Ö´ÐÐ´ÓÆäC&C·þÎñÆ÷ÊÕµ½µÄ42¸öÏÂÁ´Ó×°±¸ÖÐÇÔÈ¡ºÍɾ³ýÎļþ¡¢½ØÈ¡ÆÁÄ»½ØÍ¼¡¢»ñȡװ±¸Î»Öᢴ¹ÂÚFacebookƾ֤¡¢»ñÈ¡ÒÑ×°ÖõÄÓ¦ÓóÌÐòÁÐ±í¡¢ÇÔÈ¡Óû§ÕÕÆ¬¡¢ÕÕÏà¡¢¼Í¼ÖÜΧµÄÒôƵºÍµç»°¡¢²¦´òµç»°¡¢ÇÔÈ¡¶ÌÐÅÐÅÏ¢¡¢ÇÔȡװ±¸µÄÁªÏµÈËÁÐ±í¡¢·¢ËͶÌÐŵȡ£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMPW
4. ¹¥»÷ÕßʹÓÃContiÀÕË÷Èí¼þ¹¥»÷HSE°®¶ûÀ¼¹ú¼ÒÎÀÉú·þÎñÌṩÉÌ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬Õë¶Ô°®¶ûÀ¼¹ú¼ÒÎÀÉú·þÎñÌṩÉÌHealthServiceExecutiveµÄÀÕË÷Èí¼þ¹¥»÷Ô˶¯£¬¹¥»÷ÖÐʹÓÃÁËContiÀÕË÷Èí¼þ£¬´Ë´Î¹¥»÷¶ÔHSEµÄϵͳÔì³ÉÁËÆÕ±éÆÆË𣬹¥»÷ÕßÉù³Æ´ÓHSEÇÔÈ¡ÁË700GB»¼ÕßµÄСÎÒ˽¼ÒÊý¾Ý£¬°üÀ¨Ð¡ÎÒ˽¼ÒÎļþ¡¢µç»°ºÅÂë¡¢ÁªÏµÈË¡¢ÈËΪµ¥ºÍÒøÐжÔÕʵ¥£¬È»ºóÒªÇóÖ§¸¶2000ÍòÃÀÔª£¬µ«°®¶ûÀ¼×ÜÀíÂõ¿Ë¶û·Âí¶¡¾Ü¾øÖ§¸¶ÈκÎÊê½ð£¬²¢¸æËßÌìÏÂýÌ壬Õþ¸®Ã»ÓÐÓëÏ®»÷ÕßÏàͬ¡£È»¶ø£¬Ò»Öܺ󣬱»Ö¸¿ØµÄ¹¥»÷ÕßÏòHSEÌṩÁËÒ»¸ö½âÃÜÃÜÔ¿£¬Ìõ¼þÊÇËüÖ§¸¶1900ÍòÃÀÔªµÄÊê½ð»ò¹ûÕæÆä»¼ÕßÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMPN
5. REvilÀÕË÷Èí¼þÔËÓªÉ̹¥»÷Kaseya»ùÓÚÔÆµÄMSPƽ̨
¡¾¸ÅÊö¡¿
REvilÀÕË÷Èí¼þÍÅ»ïÏ®»÷ÁËKaseya»ùÓÚÔÆµÄMSPƽ̨£¬Ó°ÏìÁËMSP¼°Æä¿Í»§¡£¸ÃÍÅ»ïÆÆËðÁËKaseyaVSAµÄ»ù´¡ÉèÊ©£¬È»ºóÍÆ³öÁËVSAÄÚ²¿°²ÅÅ·þÎñÆ÷µÄ¶ñÒâ¸üУ¬ÒÔÔÚÆóÒµÍøÂçÉϰ²ÅÅÀÕË÷Èí¼þ¡£¸Ã×éÖ¯ÒªÇóÌṩ¼ÛÖµ7000ÍòÃÀÔªµÄ±ÈÌØ±ÒÀ´½âÃÜËùÓÐÊÜKaseya¹©Ó¦Á´ÀÕË÷Èí¼þ¹¥»÷Ó°ÏìµÄϵͳ¡£Õâ´ÎÏ®»÷ÒýÆðÁËýÌåºÍ¾¯Ô±Õþ¸®µÄ×¢ÖØ£¬ÔöÌíÁ˶ԸÃ×éÖ¯µÄѹÁ¦¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMQf
6. ¹¥»÷ÕßʹÓÃTrojan.Win32.BreakWi¶ñÒâÈí¼þ¹¥»÷ÒÁÀÊÍøÂçÇå¾²¹«Ë¾
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷£¬¹¥»÷ÕßʹÓÃTrojan.Win32.BreakWi¶ñÒâÈí¼þ¹¥»÷ÒÁÀÊÍøÂçÇå¾²¹«Ë¾£¬ÒÁÀÊÌú·õè¾¶Óë¶¼»áÉú³¤ÏµÍ³²¿³ÉÎªÍøÂç¹¥»÷µÄÄ¿µÄ¡£ºÚ¿ÍÔÚÌìϸ÷µØ³µÕ¾µÄÐÅÏ¢°åÉÏÏÔʾ»ð³µÑÓÎó»ò×÷·ÏµÄÐÅÏ¢£¬²¢±Þ²ßÂÿͲ¦´òµç»°ÒÔ»ñÈ¡¸ü¶àÐÅÏ¢£¬Ö®ºó£¬ÒÁÀÊõè¾¶ºÍ¶¼»á»¯²¿µÄÍøÕ¾·ºÆð“ÍøÂçÖÐÖ¹”ºó×èÖ¹·þÎñ£¬¹¥»÷ÕßÔÚÍøÂçÇå¾²¹«Ë¾ÍøÂçÖпª·¢²¢°²ÅÅÁËÖÁÉÙ3ÖÖ²î±ð°æ±¾µÄ¹¤¾ß£¨Meteor¡¢Stardust¡¢Comet£©¡£¹¥»÷Ö÷ÒªÓÐÓÃÔØºÉÊÇmsapp.exe£¬ÆäÄ¿µÄÊÇËø¶¨Êܺ¦Õß»úе²¢²Á³ýÆäÄÚÈÝʹÆä×èÖ¹·þÎñ¡£Ö´ÐÐʱ¶ñÒâÈí¼þ»áÒþ²Ø´Ë¿ÉÖ´ÐÐÎļþµÄ¿ØÖÆÌ¨´°¿Ú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMQj
7. APT×é֯ʹÓÃGoldenSAML¹¥»÷»ñÈ¡¶ÔActiveDirectoryµÄ»á¼ûȨÏÞ
¡¾¸ÅÊö¡¿
APT×é֯ʹÓÃGoldenSAML¹¥»÷À´ÈƹýÉí·ÝÑéÖ¤¿ØÖƲ¢»á¼ûOffice365ÇéÐΡ£´ó´ó¶¼Êܺ¦Õß½ÓÄÉ»ìÏýÉí·ÝÑé֤ģ×Ó£¬ÆÆËðADFS·þÎñÆ÷ÁîÅÆÊðÃûÖ¤Êé»áµ¼Ö»á¼ûAzure/Office365ÇéÐΡ£Ä¬ÈÏÇéÐÎÏ£¬Ö¤ÊéµÄÓÐÓÃÆÚΪһÄ꣬ÕâÔÊÐíAPT×éÖ¯ÒÔADÖеÄÈκÎÓû§Éí·Ý¼á³Ö³¤ÆÚÐÔ²¢ÖØÐ½øÈëAzure/Office365ÇéÐΣ¬¶ø²»¹ÜÈκÎÃÜÂëÖØÖûò¶àÖØÉí·ÝÑéÖ¤¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMQ8
8. ¶íÂÞ˹»¥ÁªÍø·þÎñÌṩÉÌYandexÊܵ½´ó¹æÄ£¾Ü¾ø·þÎñ£¨DDOS£©¹¥»÷
¡¾¸ÅÊö¡¿
ÃÀ¹ú¹«Ë¾Cloudflare֤ʵÁË´ó¹æÄ£DDoS¹¥»÷µÄÊÂÎñ£¬´Ë´Î¹¥»÷µÄÄ¿µÄÊǶíÂÞ˹»¥ÁªÍø·þÎñÌṩÉÌYandex£¬Yandex¹«Ë¾·þÎñÆ÷ÔâÓö¶íÂÞË¹ÍøÊ·ÉÏ×îÇ¿µÄÒ»´ÎDDoS¹¥»÷£¬¸Ã¹«Ë¾ÌåÏÖ£¬´Ë´Î¹¥»÷Ò»Á¬Ê±¼ä³¤´ï6Сʱ£¬µ¼Ö»¥ÁªÍøÒÑÏÝÈë̱»¾¡£Ó°ÏìÁË´ó×ÚµÄÉ罻ýÌåÓû§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMQz
9. ÐÂÎ÷À¼¶à¸öÒøÐкÍÓʾÖÔâµ½DDOS¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Åú×¢£¬ÐÂÎ÷À¼¶à¸öÒøÐкÍÓʾÖÔâµ½Ò»Á¬µÄÂþÑÜʽ¾Ü¾ø·þÎñDDOS¹¥»÷£¬´Ë´Î¹¥»÷µ¼Ö¸ùúµÄÒøÐкÍÓʾֵÄÍøÕ¾ÒѾ¹Ø±Õ£¬²¿·ÖÓªÒµÒѾÖÐÖ¹£¬°üÀ¨Ó¦ÓóÌÐò¡¢ÍøÉÏÒøÐС¢µç»°ÒøÐкÍÍøÕ¾ÒѾÖÐÖ¹¡£ÆäËûÊܺ¦Õß°üÀ¨°ÄÐÂÒøÐÐÐÂÎ÷À¼ÓÐÏÞ¹«Ë¾£¬ÖÜÈý£¬ANZ Bank New Zealand Ltd.ÔÚ Facebook ÉÏ·¢Ìû³Æ£¬ËüÂÄÀúÁËÒ»´ÎÖÐÖ¹£¬Ó°ÏìÁË¶ÔÆä²¿·ÖÔÚÏß·þÎñµÄ»á¼û¡£¹ÙÔ±ÃÇÌåÏÖËûÃÇÕýÔÚÓëÍøÂç¹¥»÷×÷¶·Õù¡£Ò»Ð©ÊÜÓ°ÏìµÄ×éÖ¯Äܹ»Ê¹ËûÃǵķþÎñÖØÐÂÉÏÏߣ¬µ«ËûÃÇÈÔÈ»Óöµ½¼äЪÐÔÖÐÖ¹¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMQB
10. SANGKANCILºÚ¿ÍÇÔÈ¡ÁËCITY4UÍøÕ¾700ÍòÒÔÉ«ÁÐÈ˵ÄСÎÒ˽¼ÒÐÅÏ¢
¡¾¸ÅÊö¡¿
9ÔÂ7ÈÕ£¬ÒÔÉ«Áеط½Õþ¸®µÄCITY4UÍøÕ¾±»Ò»ÃûÃûΪSANGKANCILµÄºÚ¿ÍÈëÇÖ£¬¸ÃºÚ¿ÍÉù³ÆÒѾÇÔÈ¡Á˸ÃÍøÕ¾700ÍòÒÔÉ«ÁÐÈ˵ÄÏêϸÐÅÏ¢¡£ÔÚËûµÄTelegramÕÊ»§ÖУ¬Ëû·ÖÏíÁËÒ»Ð©Ëæ»úÕÕÆ¬£¬ÆäÖаüÀ¨¼¸Î»ÒÔÉ«Áй«ÃñµÄСÎÒ˽¼ÒÏêϸÐÅÏ¢£¬ÀýÈçÉí·ÝÖ¤¼°ÆäÕÕÆ¬¡¢µØµã¡¢È«Ãû¡¢µç»°ºÅÂë¡¢¹¤ÒµË°Ö§¸¶ÇéÐεȡ£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMQp

AG¹«Ë¾ÔÆ







