¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021Äê10Ô£©
2021-11-01
10Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬Windows Update Assistant ȨÏÞÌáÉý0dayÎó²îºÍGitLab ÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22205£©Ó°Ïì¹æÄ£Ïà¶Ô½Ï´ó¡£Ç°ÕßÓÉÓÚWindows Update Assistant Öб£´æÌض¨È±ÏÝ£¬¾ßÓеÍȨÏÞÉí·ÝµÄÍâµØ¹¥»÷Õß¿Éͨ¹ý½¨ÉèĿ¼ÅþÁ¬£¬Ê¹ÓÃWindows Update AssistantÀ´É¾³ýÎļþ£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÔÚÄ¿µÄϵͳÉÏÌáÉýΪÖÎÀíԱȨÏÞ²¢Ö´ÐÐí§Òâ´úÂ룻ºóÕß¹¥»÷ÕßʹÓÃÊܺ¦ÕßÔÚGitLabÖеÄExifToolûÓжԴ«ÈëµÄͼÏñÎļþµÄÀ©Õ¹Ãû¾ÙÐÐ׼ȷ´¦Öóͷ££¬¹¥»÷Õßͨ¹ýÉÏ´«ÌØÖƵĶñÒâͼƬ£¬¿ÉÒÔÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£CVSSÆÀ·ÖΪ9.9¡£
ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË81¸öÎó²î£¬°üÀ¨3¸öCritical¼¶±ðÎó²î£¬70¸öImportant ¼¶±ðÎó²î£¬ÆäÖаüÀ¨4¸ö0dayÎó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬Õë¶ÔÏà¹Ø¹ú¼ÒÏà¹Ø×éÖ¯µÄ¹¥»÷ÊÂÎñ½ÏÁ¿ÆµÈÔ¡£ÆäÖаüÀ¨BlackTech×é֯ʹÓÃGh0stTimes¶ñÒâÈí¼þ¶ÔÈÕ±¾×éÖ¯¾ÙÐй¥»÷£¬Ñо¿Ö°Ô±·¢Ã÷£¬Ò»¸ö¹¥»÷×éÖ¯BlackTechÒ»Ö±ÔÚ¶ÔÈÕ±¾×éÖ¯¾ÙÐй¥»÷£º¹¥»÷ÕßʹÓÃGh0stTimes ʹÓÃÆä×Ô½ç˵ÐÒéÓëC2·þÎñÆ÷ͨѶ£¬ÔÚ×îÏÈÓëC2·þÎñÆ÷ͨѶʱ£¬Gh0stTimes ·¢ËÍÉí·ÝÑéÖ¤IDºÍÊý¾ÝÒÔÌìÉúÓÃÓÚºóÐøÍ¨Ñ¶µÄ¼ÓÃÜÃÜÔ¿£¬C2·þÎñÆ÷¼ì²éÈÏÖ¤ID£¬Ö»½ÓÊÜÌØ¶¨IDµÄͨѶ£»ÒÔ¼°¹¥»÷ÕßʹÓù¥»÷¹¤¾ß¼¯¶Ô¶«ÄÏÑÇһϵÁÐ×éÖ¯Ìᳫ¹¥»÷£º¹¥»÷ÕßʹÓÃÒÔǰδ¼Í¼µÄ¹¤¾ß¼¯¾ÙÐеÄÌØ¹¤Ô˶¯Õë¶Ô¶«ÄÏÑǵÄһϵÁÐ×éÖ¯£¬È·¶¨µÄÄ¿µÄ°üÀ¨¹ú·À¡¢Ò½ÁƱ£½¡ÒÔ¼°ÐÅÏ¢ºÍͨѶÊÖÒÕ (ICT) ²¿·ÖµÄ×éÖ¯£¬¹¥»÷ÕßʹÓõŤ¾ß¼¯°üÀ¨¼ÓÔØÆ÷¡¢Ä£¿é»¯ºóÃÅ¡¢¼üÅ̼ͼÆ÷ºÍÖ¼ÔÚÀÄÓÃÔÆ´æ´¢·þÎñ Dropbox µÄÉøÂ©¹¤¾ß¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2021Äê10ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼521¸öÎó²î, ÆäÖиßΣÎó²î24¸ö£¬Î¢Èí¸ßΣÎó²î11¸ö¡£
* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2021.11.01
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. Mirai_ptea_Rimasuta±äÖÖʹÓÃÐÂÈñ½Ý·ÓÉÆ÷0dayÈö²¥
¡¾±êÇ©¡¿Mirai_ptea_Rimasuta±äÖÖ
¡¾Ê±¼ä¡¿2021-09-29
¡¾¼ò½é¡¿
Mirai_ptea_Rimasuta±äÖÖ£¬ÕâÊÇÒ»ÖÖͨ¹ý KGUARD DVR ÖÐδ¹ûÕæµÄÎó²îÈö²¥µÄ½©Ê¬ÍøÂç¡£ÔçÏÈÒÔΪÕâÊÇÒ»¸ö¶ÌÆÚ±£´æµÄ½©Ê¬ÍøÂ磬ºÜ¿ì¾Í»áÏûÊÅ£¬×î½üÊӲ쵽ËüÕýÔÚʹÓÃÈñ½Ý NBR700ϵÁзÓÉÆ÷ÖÐµÄ 0day Îó²î¾ÙÐÐÈö²¥¡£Mirai_ptea_Rimasuta ÄÚÖûúÖÆÀ´¼ì²éÔËÐÐÇéÐÎÊÇ·ñÊÇɳÏ䣬Ëü»¹¼ÓÃÜÍøÂçÁ÷Á¿ÒÔÓ¦¶ÔÍøÂç¼¶±ð¼ì²â¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMUT
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡12ÌõIOC£¬ÆäÖаüÀ¨6¸öÓòÃûºÍ6¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. ¹¥»÷ÕßDarkHaloʹÓÃTomiris¹¥»÷·þÎñÆ÷
¡¾±êÇ©¡¿Tomiris
¡¾Ê±¼ä¡¿2021-09-29
¡¾¼ò½é¡¿
Tomiris ÊÇÒ»¸öÓà Go ±àдµÄºóÃÅ£¬Æä×÷ÓÃÊÇÒ»Ö±ÅÌÎÊÆä C2 ·þÎñÆ÷ÒÔ»ñÈ¡¿ÉÖ´ÐÐÎļþ£¬ÒÔ±ãÔÚÊܺ¦ÏµÍ³ÉÏÏÂÔØºÍÖ´ÐС£ÔÚÖ´ÐÐÈκβÙ×÷֮ǰ£¬Ëü»áÐÝÃßÖÁÉÙ 9 ·ÖÖÓ£¬ÒÔÊÔͼ»÷°Ü»ùÓÚɳÏäµÄÆÊÎöϵͳ¡£Ëüͨ¹ý½¨ÉèºÍÔËÐаüÀ¨ÒÔÏÂÏÂÁîµÄÅú´¦Öóͷ£ÎļþÀ´½¨ÉèÍýÏëʹÃüµÄ³¤ÆÚÐÔ¡£C2 ·þÎñÆ÷µØµãûÓÐÖ±½ÓǶÈë Tomiris ÄÚ²¿£ºÏà·´£¬ËüÅþÁ¬µ½ÐźŷþÎñÆ÷£¬¸Ã·þÎñÆ÷ÌṩºóÃÅÓ¦ÅþÁ¬µ½µÄ URL ºÍ¶Ë¿Ú¡£È»ºó Tomiris Ïò¸Ã URL ·¢ËÍ GET ÇëÇó£¬Ö±µ½ C2 ·þÎñÆ÷ʹÓÃJSON ¹¤¾ßÏìÓ¦£¬Õâ¸ö¹¤¾ßÐÎòÁËÒ»¸ö¿ÉÖ´ÐÐÎļþ£¬Ëü±»°²ÅÅÔÚÊܺ¦»úеÉϲ¢Ê¹ÓÃÌṩµÄ²ÎÊýÔËÐС£´Ë¹¦Ð§ÒÔ¼° Tomiris ³ýÁËÏÂÔØ¸ü¶à¹¤¾ßÖ®ÍâûÓÐÆäËû¹¦Ð§µÄÊÂʵÅú×¢´Ë¹¤¾ß¼¯ÉÐÓÐÆäËû²¿·Ö£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÒ»¸ö Tomiris ±äÌ壨ÄÚ²¿ÃüÃûΪ“SBZ”£©£¬Ëü³äµ±ÎļþÇÔÈ¡Õߣ¬²¢½«ÈκÎÓëÓ²±àÂëÀ©Õ¹Ãû¼¯£¨.doc¡¢.docx¡¢.pdf¡¢.rar µÈ£©Æ¥ÅäµÄ×îÐÂÎļþÉÏ´«µ½C2¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/darkhalo-after-solarwinds-the-tomiris-connection/104311/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡13ÌõIOC£¬ÆäÖаüÀ¨9¸öÑù±¾¡¢1¸öÓòÃûºÍ3¸öIP£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. BlackTech×é֯ʹÓà Gh0stTimes¶ñÒâÈí¼þ¶ÔÈÕ±¾×éÖ¯¾ÙÐй¥»÷
¡¾±êÇ©¡¿Gh0stTimes¶ñÒâÈí¼þ
¡¾Ê±¼ä¡¿2021-10-04
¡¾¼ò½é¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷£¬Ò»¸ö¹¥»÷×éÖ¯BlackTechÒ»Ö±ÔÚ¶ÔÈÕ±¾×éÖ¯¾ÙÐй¥»÷¡£¹¥»÷ÕßʹÓÃGh0stTimes ʹÓÃÆä×Ô½ç˵ÐÒéÓë C2 ·þÎñÆ÷ͨѶ£¬ÔÚ×îÏÈÓë C2 ·þÎñÆ÷ͨѶʱ£¬Gh0stTimes ·¢ËÍÉí·ÝÑéÖ¤ ID ºÍÊý¾ÝÒÔÌìÉúÓÃÓÚºóÐøÍ¨Ñ¶µÄ¼ÓÃÜÃÜÔ¿¡£C2·þÎñÆ÷¼ì²éÈÏÖ¤ID£¬Ö»½ÓÊÜÌØ¶¨IDµÄͨѶ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMVn
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡15ÌõIOC£¬ÆäÖаüÀ¨4¸öIP£¬3¸öÓòÃûºÍ8¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. ¹¥»÷Õßð³äSafeMoon¹Ù·½Óû§ÇÔÈ¡Óû§ÐÅÏ¢
¡¾±êÇ©¡¿SafeMoon¹Ù·½Óû§
¡¾Ê±¼ä¡¿2021-10-06
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÏîÔ˶¯£¬¹¥»÷Õßð³ä SafeMoon¹Ù·½Óû§£¬²¢Ê¹ÓÃÐéÎ±ÍøÕ¾¸üн« Discord Óû§ÒýÓÕµ½·Ö·¢×ÅÃûÔ¶³Ì»á¼û¹¤¾ß (RAT) µÄÍøÕ¾¡£Õ©ÆÕßÏò Discord ÉϵÄÐí¶àÓû§·¢ËÍÒ»ÌõÐéαÁ´½Ó£¬µ±Óû§µã»÷ÐéαÁ´½ÓµÄurlºó£¬»á±»ÒýÓÕµ½Ò»¸öÍøÕ¾¾ÙÐеǼ£¬¸ÃÍøÕ¾Éè¼ÆÎª¿´ÆðÀ´ÏñÊÇ SafeMoon µÄ¾É°æ±¾¡£¹¥»÷ÕßËæÖ®»áÇÔÈ¡µ½Óû§µÄµÇ¼ƾ֤¡¢¼Í¼»÷¼ü¡¢Ð®ÖÆÍøÂçÉãÏñÍ·µÈÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMVm
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡1ÌõIOC£¬ÆäÖаüÀ¨1¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. ¹¥»÷ÕßʹÓÃRmgrľÂí¹¥»÷LinuxÖÕ¶Ë
¡¾±êÇ©¡¿RmgrľÂí
¡¾Ê±¼ä¡¿2021-10-13
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±²¶»ñµ½Ò»¸öºóÃÅľÂíÑù±¾£¬½«ÆäÃüÃûΪRmgrľÂí¡£¹¥»÷ÕßʹÓÃľÂí²¡¶¾ÅþÁ¬¶ñÒâÓòÃû£¬Òþ²Ø×Ô¼ºµÄÀú³Ì£¬²¢¶ÔÖÕ¶ËÖ²ÈëºóÃÅ£¬ÓÃÓÚºóÐø¾ÙÐÐÆäËûÈëÇÖÐÐΪ¡£Ä¾ÂíµÄĸÌåÎļþÖ»ÓÐ rmgr.ko ÕâÒ»¸öÎļþ£¬Í¨¹ý insmod ÏÂÁî×°ÔØµ½ÄÚºËÄ£¿éºó¿ªÆôÔË×÷£¬Öð²½ÊÍ·ÅľÂíµÄÆäËû×é¼þ²¿·Ö¡£Ä¾Âí×Ô¼º×÷Ϊһ¸öÄÚºËÄ£¿é£¬¾ßÓÐring0µÄȨÏÞ£¬¿ÉÒÔ´ÓÄں˲ãÃæÊµÏÖÒþ²ØÀú³Ì¡¢Îļþ¡¢¶Ë¿ÚµÈ²Ù×÷£¬Ïà½ÏÓÚring3¾ßÓиüÇ¿µÄÒþ²ØÄÜÁ¦¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMWB
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC£¬ÆäÖаüÀ¨4¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. ¹¥»÷ÕßʹÓöñÒâÈí¼þ¹¥»÷ Exchange ·þÎñÆ÷
¡¾±êÇ©¡¿GhostEmperor¼¯Èº
¡¾Ê±¼ä¡¿2021-10-15
¡¾¼ò½é¡¿
ÔÚÊÓ²ì×î½üÕë¶Ô Exchange ·þÎñÆ÷µÄ¹¥»÷ÉÏÉýʱ£¬Ñо¿Ö°Ô±·¢Ã÷ÔÚ¼¸¸ö²î±ðµÄÊÜÑ¬È¾ÍøÂçÖзºÆðÁËGhostEmperor¼¯Èº¡£¸Ã¼¯ÈºÒòÆäʹÓÃÁËÎÒÃdzÆÎª Demodex µÄÒÔǰδ֪µÄ Windows ÄÚºËģʽ rootkit ÒÔ¼°Ö¼ÔÚÌṩ¶ÔÊܹ¥»÷·þÎñÆ÷µÄÔ¶³Ì¿ØÖƵÄÖØ´ó¶à½×¶Î¶ñÒâÈí¼þ¿ò¼ÜÍÑÓ±¶ø³ö¡£Í¬Ê±·¢Ã÷Á˶à¸ö´¥·¢Ñ¬È¾Á´µÄ¹¥»÷ǰÑÔ£¬µ¼ÖÂÔÚÄÚ´æÖÐÖ´ÐжñÒâÈí¼þ¡£²¢×¢Öص½£¬´ó´ó¶¼ GhostEmperor ѬȾ¶¼°²ÅÅÔÚÃæÏò¹«ÖڵķþÎñÆ÷ÉÏ£¬ÓÉÓÚÐí¶à¶ñÒâ¹¹¼þÊÇÓÉ“httpd.exe”Apache ·þÎñÆ÷Àú³Ì¡¢“w3wp.exe”IIS Windows ·þÎñÆ÷Àú³Ì»ò“oc4j”×°Öõġ£ .jar\\\' Oracle ·þÎñÆ÷Àú³Ì¡£ÕâÒâζ׏¥»÷Õß¿ÉÄÜ»áÀÄÓÃÔÚÕâЩϵͳÉÏÔËÐÐµÄ Web Ó¦ÓóÌÐòÖеÄÎó²î£¬´Ó¶øÔÊÐíËûÃÇɾ³ýºÍÖ´ÐÐËûÃǵÄÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMVv
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡20ÌõIOC£¬ÆäÖаüÀ¨5¸öIP£¬7¸öÓòÃûºÍ8¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
7. ¹¥»÷ÕßʹÓÃlinuxÍÚ¿óľÂí¶ÔÖйúij×ÅÃû¹«Ë¾ÔÆ·þÎñÉ̾ÙÐй¥»÷
¡¾±êÇ©¡¿linuxÍÚ¿óľÂí¼Ò×å
¡¾Ê±¼ä¡¿2021-10-20
¡¾¼ò½é¡¿
±¾ÖÜ£¬×ÅÃûÇå¾²³§ÉÌÇ÷ÊÆ¿Æ¼¼Åû¶ÁËÒ»¸öÕë¶ÔÖйúij×ÅÃû¹«ÓÐÔÆ·þÎñÉ̾ÙÐй¥»÷µÄlinuxÍÚ¿óľÂí¼Ò×壬Ñо¿Ö°Ô±³Æ£¬¸ÃÍÚ¿óľÂí½öÕë¶ÔÔÆÇéÐΣ¬Ä¾Âí»áɾ³ýÆäËû¾ºÆ·ÍÚ¿óľÂí£¬²¢Í¬Ê±É¾³ýÆäËûÈëÇÖÕß½¨ÉèµÄÓû§¡£¹¥»÷Õß»áʹÓöà¸ö¸ßΣÎó²îºÍÈõ¿ÚÁî±¬ÆÆ¹¥»÷ÈëÇÖ£¬ÆäÖаüÀ¨£ºSSH Èõ¿ÚÁî±¬ÆÆ¡¢ Oracle WebLogic Server Îó²î (CVE-2020-14882)ºÍRedis δÊÚȨ»á¼ûÎó²î»òÈõ¿ÚÁî±¬ÆÆµÈ£¬¹¥»÷Àֳɺó»áÔÚʧÏÝÖ÷»úÌí¼ÓSSHÃÜÔ¿ÁôÖúóÃÅÀû±ãµÇ¼£¬Í¬Ê±»áÌí¼Ó¾ß±¸rootȨÏÞµÄÖÎÀíÔ±ÕÊ»§ÒÔÍêÈ«¿ØÖÆÊ§ÏÝϵͳ¡£Îª×èÖ¹±»¼ì²âµ½£¬¹¥»÷Õßͨ¹ý×°ÖÃTorÊðÀí·þÎñ£¬¼ÓÃÜÏà¹ØÍøÂçÁ÷Á¿ÒÔʵÏÖÄäÃû»¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMXK
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡1ÌõIOC£¬ÆäÖаüÀ¨1¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
8. ¹¥»÷ÕßʹÓÃyanluowangÀÕË÷Èí¼þÕë¶ÔÄ¿µÄÓû§¾ÙÐÐÂþÑÜʽ¾Ü¾ø·þÎñ¹¥»÷
¡¾±êÇ©¡¿Yanluowang ÀÕË÷Èí¼þ
¡¾Ê±¼ä¡¿2021-10-20
¡¾¼ò½é¡¿
Ñо¿ÕßÊ×ÏÈÔÚÊܺ¦×éÖ¯µÄÍøÂçÉÏ·¢Ã÷ÁË AdFind£¨Ò»ÖÖÕýµ±µÄÏÂÁîÐÐ Active Directory ÅÌÎʹ¤¾ß£©µÄ¿ÉÒÉʹÓ᣸ù¤¾ß¾³£±»ÀÕË÷Èí¼þ¹¥»÷ÕßÓÃ×÷Õì̽¹¤¾ß£¬²¢Îª¹¥»÷ÕßÌṩËûÃÇͨ¹ý Active Directory ¾ÙÐкáÏòÒÆ¶¯ËùÐèµÄ×ÊÔ´¡£×÷ΪǰÌ幤¾ßËüÊ×ÏȻὨÉèÒ»¸ö .txt Îļþ£¬Ê¹Óà Windows Management Instrumentation (WMI) £¬²¢»ñÈ¡ÔÚ .txt ÎļþÖÐÁгöµÄÔ¶³ÌÅÌËã»úÉÏÔËÐеÄÀú³ÌÁÐ±í£¬×îºó½«ËùÓÐÀú³ÌºÍÔ¶³Ì»úеÃû³Æ¼Í¼µ½ processes.txt¡£ÕâЩ׼±¸ÊÂÇéÍê³Éºó£¬¹¥»÷Õß½«ÔÚÄ¿µÄÅÌËã»úÉϰ²ÅÅ Yanluowang ÀÕË÷Èí¼þʵÑéÇÖȾ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMXJ
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
9. ¹¥»÷ÕßʹÓôó×ÚRAT¹¥»÷°¢¸»º¹ºÍÓ¡¶È
¡¾±êÇ©¡¿RAT
¡¾Ê±¼ä¡¿2021-10-29
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±×î½ü·¢Ã÷¹¥»÷ÕßʹÓÃÕþÖκÍÕþ¸®ÎªÖ÷ÌâµÄ¶ñÒâÓòÀ´Õë¶ÔÓ¡¶ÈºÍ°¢¸»º¹µÄʵÌå¡£ÕâЩ¹¥»÷ʹÓà dcRAT ºÍ QuasarRAT for Windows£¬Í¨¹ýʹÓÃCVE-2017-11882£¨Microsoft Office ÖеÄÄÚ´æËð»µÎó²î£©ºÍ AndroidRAT µÄ¶ñÒâÎĵµÀ´¹¥»÷ÒÆ¶¯×°±¸¡£¹¥»÷Õß»¹ÔÚ¹¥»÷µÄ³õʼÕì̽½×¶ÎʹÓÃ×Ô½ç˵Îļþö¾ÙÆ÷ºÍѬȾÆ÷¡£ËüµÄѬȾÁ´ÓɶñÒâ RTF ÎĵµºÍÏòÊܺ¦Õß·Ö·¢¶ñÒâÈí¼þµÄ PowerShell ¾ç±¾×é³É£¬Óë´ËͬʱÑо¿Ö°Ô±»¹ÊӲ쵽ʹÓûùÓÚ C# µÄÏÂÔØ³ÌÐò¶þ½øÖÆÎļþÀ´°²ÅŶñÒâÈí¼þ£¬Í¬Ê±ÏòÊܺ¦ÕßÏÔʾÓÕ¶üͼÏñÒÔʹÆä¿´ÆðÀ´Õýµ±£¬×îºóʵÏÖ¶ÔÊܺ¦Õ߶˵ãµÄÍêÈ«¿ØÖÆ——´ÓÆðÔ´Õì̽ÄÜÁ¦µ½í§ÒâÏÂÁîÖ´ÐкÍÊý¾Ýй¶¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMZf
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡496ÌõIOC£¬ÆäÖÐÆäÖаüÀ¨450¸öÑù±¾¡¢10¸öÓòÃû¡¢34¸öURLºÍ2¸öIP£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
10. ¹¥»÷ÕßʹÓù¥»÷¹¤¾ß¼¯¶Ô¶«ÄÏÑÇһϵÁÐ×éÖ¯Ìᳫ¹¥»÷
¡¾±êÇ©¡¿¼ÓÔØÆ÷,Ä£¿é»¯ºóÃÅ,¼üÅ̼ͼÆ÷
¡¾Ê±¼ä¡¿2021-10-29
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±·¢Ã÷¹¥»÷ÕßʹÓÃÒÔǰδ¼Í¼µÄ¹¤¾ß¼¯¾ÙÐеÄÌØ¹¤Ô˶¯Õë¶Ô¶«ÄÏÑǵÄһϵÁÐ×éÖ¯£¬È·¶¨µÄÄ¿µÄ°üÀ¨¹ú·À¡¢Ò½ÁƱ£½¡ÒÔ¼°ÐÅÏ¢ºÍͨѶÊÖÒÕ (ICT) ²¿·ÖµÄ×éÖ¯¡£¸ÃÔ˶¯ËƺõÒÑÓÚ 2020 Äê 9 ÔÂ×îÏÈ£¬²¢ÖÁÉÙÒ»Á¬µ½ 2021 Äê 5 Ô¡£¹¥»÷ÕßʹÓõŤ¾ß¼¯°üÀ¨¼ÓÔØÆ÷¡¢Ä£¿é»¯ºóÃÅ¡¢¼üÅ̼ͼÆ÷ºÍÖ¼ÔÚÀÄÓÃÔÆ´æ´¢·þÎñ Dropbox µÄÉøÂ©¹¤¾ß¡£×îÔç¼£ÏóÊÇÒ»¸ö¼ÓÔØÆ÷£¬Ëü´Ó .dat Îļþ½âÃܺͼÓÔØ¸ºÔØ¡£.dat ÎļþÖÁÉÙÓÐÁ½¸ö²î±ðµÄÎļþÃû£ºsdc-integrity.dat ºÍ scs-integrity.dat¡£¼ÓÔØ³ÌÐò»¹´Ó½âÃܵÄÓÐÓøºÔØÖÐŲÓà DumpAnalyze µ¼³ö¡£ÓÐÓÃÔØºÉÉÐδȷ¶¨£¬µ«ÏÕЩ¿ÉÒÔÒ»¶¨ÊÇÄ£¿é»¯ºóÃÅ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMZe
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡8ÌõIOC£¬ÆäÖаüÀ¨8¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







