¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.11.15-2021.11.21£©
2021-11-23
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. ¹¥»÷ÕßʹÓÃHTML×ß˽ÊÖÒÕÌᳫ´¹ÂÚ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÖÒÑÔ˵£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÔÚÍøÂç´¹ÂÚÔ˶¯ÖÐʹÓà HTML ×ß˽ÊÖÒÕ¡£ËüÊÇÒ»ÖÖʹÓÃÕýµ± HTML5 ºÍ JavaScript ¹¦Ð§µÄ¶ñÒâÈí¼þ´«Ë͵ĸ߶ȹæ±ÜÊÖÒÕ£¬¶ñÒâ¸ºÔØÍ¨¹ý HTML ¸½¼þ»òÍøÒ³ÖеıàÂë×Ö·û´®´«ËÍ¡£¶ñÒâ HTML ´úÂëÊÇÔÚÄ¿µÄÉè±¹ØÁ¬Ää¯ÀÀÆ÷ÖÐÌìÉúµÄ£¬¸Ã×°±¸ÒѾ´¦ÓÚÊܺ¦ÕßÍøÂçµÄÇå¾²¹æÄ£ÄÚ¡£µ±Ä¿µÄÓû§ÔÚÆä Web ä¯ÀÀÆ÷Öз¿ª HTML ʱ£¬ä¯ÀÀÆ÷»á¶Ô¶ñÒâ¾ç±¾¾ÙÐнâÂ룬½ø¶øÔÚÖ÷»ú×°±¸ÉÏ×é×°ÓÐÓÃÔØºÉ¡£Òò´Ë£¬¹¥»÷Õß²»ÊÇÈöñÒâ¿ÉÖ´ÐÐÎļþÖ±½Óͨ¹ýÍøÂ磬¶øÊÇÔÚ·À»ðǽºóÃæÍâµØ¹¹½¨¶ñÒâÈí¼þ´Ó¶øµÖ´ï¹¥»÷Ä¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN1I
2. BotenaGo½©Ê¬ÍøÂçʹÓöà¸öÎó²î¹¥»÷Êý°ÙÍò·ÓÉÆ÷ºÍÎïÁªÍø×°±¸
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÐ嵀 BotenaGo ½©Ê¬ÍøÂ磬¸ÃÍøÂçʹÓà 33 ¸öÎó²î¹¥»÷Êý°ÙÍò·ÓÉÆ÷ºÍÎïÁªÍø×°±¸¡£BotenaGo ÊÇÓà Golang (Go) ±àдµÄ£¬ÔÚר¼ÒÐû²¼±¨¸æÊ±£¬ËüµÄ·À²¡¶¾ (AV) ¼ì²âÂÊºÜµÍ (6/62)¡£ÎªÁËÌṩÎó²îʹÓ㬶ñÒâÈí¼þÊ×ÏÈʹÓüòÆÓµÄ“GET”ÇëÇóÅÌÎÊÄ¿µÄ¡£È»ºó£¬ËüʹÓÃÓ³Éäµ½¹¥»÷º¯ÊýµÄÿ¸öϵͳÊðÃûËÑË÷´Ó“GET”ÇëÇ󷵻صÄÊý¾Ý¡£“×Ö·û´®“Server: Boa/0.93.15”Ó³Éäµ½º¯Êý“main_infectFunctionGponFiber”£¬¸Ãº¯ÊýÊÔͼʹÓÃÒ×Êܹ¥»÷µÄÄ¿µÄ£¬ÔÊÐí¹¥»÷Õßͨ¹ýÌØ¶¨µÄ Web ÇëÇóÖ´ÐвÙ×÷ϵͳÏÂÁî (CVE-2020-8958)¡£¸Ã½©Ê¬ÍøÂçÕë¶ÔÊý°ÙÍò¾ßÓÐʹÓÃÉÏÊöȱÏݵĹ¦Ð§µÄ×°±¸£¬ÀýÈçÏòShodan ÅÌÎÊ×Ö·û´® Boa£¬ÕâÊÇÒ»¸öÒÑÍ£²úµÄÓÃÓÚǶÈëʽӦÓóÌÐòµÄ¿ªÔ´ Web ·þÎñÆ÷£¬Ëü·µ»Ø½ü 200 Íǫ̀װ±¸¡£×°Öúó£¬bot ¶ñÒâÈí¼þ½«ÕìÌý¶Ë¿Ú 31412 ºÍ 19412£¬ºóÕßÓÃÓÚÎüÊÕÊܺ¦Õß IP¡£Ò»µ©ÎüÊÕµ½Óë¸Ã¶Ë¿ÚÐÅÏ¢µÄÅþÁ¬£¬Ëü¾Í»á±éÀúÓ³ÉäµÄÎó²îʹÓú¯Êý²¢Ê¹Óøø¶¨µÄ IP Ö´ÐÐËüÃÇ¡£BotenaGo ½«ÔÚÊÜѬȾµÄ×°±¸ÉÏÖ´ÐÐÔ¶³Ì shell ÏÂÁƾ֤ÊÜѬȾµÄϵͳ£¬bot ʹÓÃÓë²î±ðÓÐÓÃÔØºÉÏà¹ØÁªµÄ²î±ðÁ´½Ó¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN1L
3. Moses Staff кڿÍ×éÖ¯¹¥»÷ÒÔÉ«ÁÐ×éÖ¯
¡¾¸ÅÊö¡¿
Ò»¸öÃûΪMoses Staff µÄкڿÍ×éÖ¯¹¥»÷ÁËÒÔÉ«ÁÐ×éÖ¯£¬ÆÆËðÁËËûÃǵÄÍøÂ磬¼ÓÃÜÁËËûÃǵÄÊý¾Ý£¬µ«Ëæºó¾Ü¾øÐÉÌÖ§¸¶Êê½ð£¬Çå¾²Ñо¿Ö°Ô±½«ÆäÐÎòΪ³öÓÚÕþÖÎÄîÍ·µÄÆÆËðÐÔ¹¥»÷¡£¸Ã×é֯ͨ¹ýʹÓÃδÐÞ²¹µÄ¾ÉÎó²îÀ´ÆÆËðÊܺ¦ÕßµÄÍøÂ磬ÒÑÍùµÄÈëÇÖÓëδ´ò²¹¶¡µÄ Microsoft Exchange ·þÎñÆ÷Óйء£Ò»µ©ËûÃÇÆÆËðÁËϵͳ£¬¸Ã×éÖ¯¾Í»áʹÓà PsExec¡¢WMIC ºÍ Powershell µÈ¹¤¾ßÉîÈëÊܺ¦ÕßµÄÍøÂçÄÚ²¿¡£¸Ã×é֯ȻºóÔÚ¼ÓÃÜÆäÊý¾Ý֮ǰ´ÓÊܺ¦ÕßµÄÍøÂçÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬Moses Staff ͨ³£»á°²ÅÅ¿ªÔ´ DiskCryptor ¿âÀ´Ö´Ðоí¼ÓÃܲ¢Ê¹ÓÃÖ¸µ¼¼ÓÔØ³ÌÐòËø¶¨Êܺ¦ÕßµÄÅÌËã»ú£¬Ö¸µ¼¼ÓÔØ³ÌÐò²»ÔÊÐíÅÌËã»úÔÚûÓÐ׼ȷÃÜÂëµÄÇéÐÎÏÂÆô¶¯¡£×ÝÈ»ÌṩÁË׼ȷµÄÂ룬һµ©ÏµÍ³Æô¶¯£¬Êý¾ÝÈÔÈ»»á±»¼ÓÔØ£¬Check Point ÌåÏÖÔÚijЩÇéÐÎÏ¿ÉÒÔ»Ö¸´Æô¶¯ÃÜÂëºÍ¼ÓÃÜÃÜÔ¿¡£ºÚ¿Í»¹Ä±ÆëÕû¸ö Telegram ƵµÀºÍ Twitter ÕÊ»§£¬ÔÚÄÇÀïËûÃÇÐû²¼ËûÃÇÌí¼Óµ½Ð¹ÃÜÍøÕ¾µÄÐÂÊܺ¦Õß¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN24
4. ³¯ÏʺڿÍʹÓÃľÂí»¯IDA Pro¹¥»÷ÍøÂçÇå¾²Ñо¿Ö°Ô±
¡¾¸ÅÊö¡¿
¾Ý±¨µÀ£¬Á¥ÊôÓÚ³¯ÏʵĹú¼Ò×ÊÖú×éÖ¯ Lazarus ÕýÊÔͼʹÓÃÊ¢ÐÐµÄ IDA Pro ÄæÏò¹¤³ÌÈí¼þµÄľÂí»¯µÁ°æ°æ±¾£¬ÔÙ´ÎÕë¶Ô¾ßÓкóÃźÍÔ¶³Ì»á¼ûľÂíµÄÇå¾²Ñо¿Ö°Ô±¡£Ñо¿Ö°Ô±ÌåÏÖIDA Pro ÊÇÒ»ÖÖ½»»¥Ê½·´»ã±à³ÌÐò£¬Ö¼ÔÚ½«»úеÓïÑÔ£¨Ò²³ÆÎª¿ÉÖ´ÐÐÎļþ£©·Òë³É»ã±àÓïÑÔ£¬Ê¹Çå¾²Ñо¿Ö°Ô±Äܹ»ÆÊÎö³ÌÐòµÄÄÚ²¿ÊÂÇ飨¶ñÒâ»òÆäËû£©£¬²¢×÷Ϊµ÷ÊÔÆ÷À´¼ì²â¹ýʧ¡£Ë¹Âå·¥¿ËÍøÂçÇå¾²¹«Ë¾³Æ¹¥»÷Õß½« [Hex-Rays] ¿ª·¢µÄÔʼ IDA Pro 7.5 Èí¼þÓëÁ½¸ö¶ñÒâ×é¼þÀ¦°óÔÚÒ»Æð£¬ÆäÖÐÒ»¸öÊÇÃûΪ“win_fw.dll”µÄÄÚ²¿Ä£¿é£¬¸ÃÄ£¿éÔÚÓ¦ÓóÌÐò×°ÖÃʱ´úÖ´ÐС£Õâ¸ö±»¸Ä¶¯µÄ°æ±¾Ëæºó±»±àÅÅÒÔ´ÓϵͳÉ쵀 IDA ²å¼þÎļþ¼Ð¼ÓÔØÃûΪ“idahelper.dll”µÄµÚ¶þ¸ö×é¼þ£¬ÀÖ³ÉÖ´Ðк󣬓idahelper.dll”¶þ½øÖÆÎļþÅþÁ¬µ½Î»ÓÚ“www[.]devguardmap[.]org”µÄÔ¶³Ì·þÎñÆ÷ÒÔ¼ìË÷ºóÐøÓÐÓøºÔØ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN23
5. ¹¥»÷ÕßʹÓüÓÃܶñÒâÈí¼þ¹¥»÷°¢ÀïÔÆ
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷¹¥»÷ÕßµÄÄ¿µÄÊǰ¢Àï°Í°Íµ¯ÐÔÅÌËã·þÎñ (ECS) ʵÀý£¬½ûÓÃijЩÇå¾²¹¦Ð§ÒÔ½øÒ»²½ÊµÏÖËûÃǵļÓÃÜÄ¿µÄ¡£²¢Ö¸³ö£¬°¢Àï°Í°ÍÌṩÁËÒ»Ð©ÆæÒìµÄÑ¡Ôñ£¬Ê¹Æä³ÉΪ¹¥»÷Õß¼«¾ßÎüÒýÁ¦µÄÄ¿µÄ¡£¹¥»÷ÕßʹÓüÓÃܶñÒâÈí¼þÖеÄһС¶ÎÌØ¶¨´úÂëÀ´½¨ÉèеķÀ»ðǽ¹æÔò£¬Ö¸Ê¾Çå¾²¹ýÂËÆ÷ÑïÆúÀ´×ÔÊôÓÚ°¢Àï°Í°ÍÄÚ²¿ÇøÓòºÍÇøÓòµÄ IP ¹æÄ£µÄ´«ÈëÊý¾Ý°ü£¬Í¨³££¬µ±¼ÓÃÜÐ®ÖÆ¶ñÒâÈí¼þ×°ÖÃÔÚ°¢Àï°Í°Í ECS ´æ´¢Í°ÖÐʱ£¬Çå¾²ÊðÆÊÎöÏòÓû§·¢ËͶñÒâ¾ç±¾ÕýÔÚÔËÐеÄ֪ͨ¡£¿ÉÊÇÇå¾²ÊðÀíÔÚ´¥·¢ÈëÇÖ¾¯±¨Ö®Ç°Òѱ»Ð¶ÔØ¡£Ò»µ©Ëüͨ¹ýÁËÇå¾²¹¦Ð§£¬¶ñÒâÈí¼þ¾Í»á¼ÌÐø×°ÖÃÏÖ³ÉµÄ XMRig ¼ÓÃÜÇ®±Ò¿ó¹¤£¬ËüΪÃÅÂÞ±ÒÍÚ¿ó¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN2h
6. ¹¥»÷ÕßʹÓÃSharkBot¹¥»÷Å·ÖÞÒøÐÐ
¡¾¸ÅÊö¡¿
Cleafy µÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪ SharkBot µÄÐÂÐÍ Android ÒøÐÐľÂí£¬ËüÕë¶ÔÅ·ÖÞµÄÒøÐС£¸Ã¶ñÒâÈí¼þÖÁÉÙ×Ô 2021 Äê 10 ÔÂÏÂÑ®ÒÔÀ´Ò»Ö±´¦ÓÚ»îԾ״̬£¬ÆäÄ¿µÄÊÇÒâ´óÀû¡¢Ó¢¹úºÍÃÀ¹úÒøÐеÄÒÆ¶¯Óû§¡£¸ÃľÂíÔÊÐíÐ®ÖÆÓû§µÄÒÆ¶¯×°±¸²¢´ÓÍøÉÏÒøÐкͼÓÃÜÇ®±ÒÕË»§ÖÐÇÔÈ¡×ʽð¡£Ò»µ©ÒøÐÐľÂí×°ÖÃÔÚÊܺ¦ÕßµÄ×°±¸ÉÏ£¬¹¥»÷Õ߾ͿÉÒÔͨ¹ýÀÄÓø¨Öú·þÎñ£¨¼´µÇ¼ƾ֤¡¢Ð¡ÎÒ˽¼ÒÐÅÏ¢¡¢Ä¿½ñÓà¶îµÈ£©ÇÔÈ¡Ãô¸ÐµÄÒøÐÐÐÅÏ¢£¬SharkBot ʵÑéÁýÕÖ¹¥»÷À´ÇÔÈ¡µÇ¼ƾ֤ºÍÐÅÓÿ¨ÐÅÏ¢¡£²¢ÇÒËüʵÑéÁ˶àÖÖ·´ÆÊÎöÊÖÒÕ£¬°üÀ¨×Ö·û´®»ìÏýÀý³Ì¡¢Ä£ÄâÆ÷¼ì²âºÍÓòÌìÉúËã·¨ (DGA)¡£SharkBot »áÀÄÓà Accessibility Service ÔÚÊÜѬȾװ±¸ÄÚ¾ÙÐÐ ATS ¹¥»÷¡£ATS£¨×Ô¶¯×ªÕËϵͳ£©¹¥»÷ÔÊÐí Treat ¼ÓÈëÕß×Ô¶¯ÌîдÕýµ±ÊÖ»úÒøÐÐÖеÄ×ֶΣ¬ÒԱ㽫×ʽð´ÓÊÜѬȾװ±¸×ªÒƵ½¹¥»÷Õß¿ØÖÆÏµÄÕË»§¡£ÕâÖÖÊÖÒÕÔÊÐí×Ô¶¯»¯ÕâЩ²Ù×÷£¬×î´óÏ޶ȵØïÔÌÓû§¸ÉÔ¤¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN2i
7. ¹¥»÷ÕßʹÓÃÓòǰ¶ËÊÖÒÕÒÔCobalt Strike ¹¥»÷Ãåµé
¡¾¸ÅÊö¡¿
Cisco Talos ÓÚ2021 Äê9Ô·¢Ã÷ÁËÒ»Ïî¶ñÒâÔ˶¯£¬¸ÃÔ˶¯Ê¹ÓþÓÉ»ìÏýµÄ Meterpreter stager °²ÅÅ Cobalt Strike Ðűꡣ¸Ã¹¥»÷ÕßʹÓÃÃåµéÕþ¸®ÓµÓкÍÔËÓªµÄÓòÃåµéÊý×ÖÐÂÎÅÍøÂç×÷ΪÆäÐűêµÄÓòǰ¶Ë¡£¶ñÒâÈí¼þͨ³£ÊÇÒ»¸öÔÚÊܺ¦»úеÉÏÔËÐеļÓÔØ³ÌÐò£¬Í¨¹ý·´Éä×¢Èë½âÂë²¢Ö´ÐÐ Cobalt Strike Ðűê DLL¡£ËüÔÚÔËÐÐʱ¼ÓÔØ¶à¸ö¿â£¬²¢Æ¾Ö¤Ç¶ÈëµÄÉèÖÃÎļþÌìÉúÐűêÁ÷Á¿¡£ÉèÖÃÎļþ°üÀ¨ÓëÏÂÁîºÍ¿ØÖÆ (C2) ·þÎñÆ÷Ïà¹ØµÄÐÅÏ¢£¬¸Ã·þÎñÆ÷ָʾÊܺ¦ÕߵĻúе·¢Ëͳõʼ DNS ÇëÇó£¬ÊµÑéÅþÁ¬µ½ÃåµéÕþ¸®ËùÓÐÓòÃû www[.]mdn[.]gov[ µÄÖ÷»ú [.] ¡£]ºÁÃס£¸ÃÕ¾µãÍйÜÔÚ Cloudflare ÄÚÈݽ»¸¶ÍøÂçÖ®ºó£¬ÏÖʵµÄ C2 Á÷Á¿Æ¾Ö¤ÐűêÉèÖÃÊý¾ÝÖÐÖ¸¶¨µÄHTTPÖ÷»ú±êÍ·ÐÅÏ¢ÖØ¶¨Ïòµ½¹¥»÷Õß¿ØÖƵķþÎñÆ÷ test[.]softlemon[.]net¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN2k
8. °Í»ù˹̹ºÚ¿Íı»®¼ÙÓ¦ÓÃÊÐËÁÒÔ¹¥»÷°¢¸»º¹Ç°¹ÙÔ±
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷һȺ°Í»ù˹̹ºÚ¿Í½¨Éè²¢ÔËÓªÁËÒ»¸öÐéαµÄ Android Ó¦ÓóÌÐòÊÐËÁ£¬Ä¿µÄÊÇÔÚ°¢¸»º¹Ç°Õþ¸®ÂÙΪÐÂËþÀû°àÕþȨ֮ǰºÍʱ´ú£¬¹¥»÷ºÍѬȾÓë¸ÃÕþ¸®ÓйصÄСÎÒ˽¼Ò¡£ºÚ¿ÍÔ˶¯±¬·¢ÔÚ½ñÄê 4 ÔÂÖÁ 8 ÔÂÖ®¼ä£¬ÓÉÒ»¸öÃûΪSideCopyµÄ×é֯ʵÑé ¡£Facebook Çå¾²Ñо¿Ö°Ô±ÌåÏÖ£¬SideCopy ÔËÓªÉÌÔÚÆäÆ½Ì¨ÉϽ¨ÉèÁËÐéαСÎÒ˽¼Ò×ÊÁÏ£¬Í¨³£Ã°³äÄêÇáÅ®ÐÔ£¬²¢¿¿½üÄ¿µÄ£¬Ä¿µÄÊÇÈÃËûÃǵã»÷¶ñÒâÁ´½Ó¡£ÕâЩÁ´½Ó½«Êܺ¦ÕßÖØ¶¨Ïòµ½ÍøÂçµÇ¼ƾ֤µÄÍøÂç´¹ÂÚÕ¾µã£¬»òÕßÔÚijЩÇéÐÎÏ£¬Öض¨Ïòµ½ÍйÜÊܶñÒâÈí¼þѬȾµÄ Android Ó¦ÓóÌÐòµÄÐéαӦÓóÌÐòÊÐËÁ¡£SideCopy ͨ³£Ê¹ÓÃαװ³É̸ÌìÐÂÎÅÓ¦ÓóÌÐòµÄ¶ñÒâÓ¦ÓóÌÐò¡£ËûÃÇҪôģÄâ Viber ºÍ Signal µÈ×ÅÃûÆ·ÅÆ£¬ÒªÃ´Íêȫð³äеÄ̸ÌìÓ¦ÓóÌÐò¡£ÕâЩ Android Ó¦ÓóÌÐò°üÀ¨Ô¶³Ì»á¼ûľÂí¡£Ò»Ð©Ó¦ÓóÌÐò°üÀ¨Ò»¸öÃûΪPJobRATµÄ¶¾Ö꣬¶øÆäËûÓ¦ÓóÌÐò°üÀ¨Ò»¸ö ÒÔǰ䱨¸æµÄ Android ¶ñÒâÈí¼þ¶¾Öê Facebook£¬ÃûΪ Mayhem¡£ÕâÁ½ÖÖ¶ñÒâÈí¼þʹ SideCopy ²Ù×÷Ô±¿ÉÒÔÍêÈ«¿ØÖÆÊÜѬȾµÄ×°±¸¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN2w
9. ¹¥»÷ÕßʹÓÃÌØ¹¤Èí¼þ¶ÔÓ¢¹úºÍÖж«µÄʵÌåÌᳫˮ¿Ó¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÒÔÉ«ÁÐÌØ¹¤Èí¼þ¹©Ó¦ÉÌCandiru£¬Ëü±»Ìí¼Óµ½Õâ¸öÔµľ¼Ã¿éÁÐ±í£¬Ìý˵ÒѾ·¢¶¯Á˶ÔÓ¢¹úºÍÖж«¸ßµ÷ʵÌå“Ë®¿Ó”¹¥»÷£¬ËüÊÇÒ»ÖÖÕë¶ÔÐÔºÜÇ¿µÄÈëÇÖÐÎʽ£¬ÓÉÓÚËüÃÇÇãÏòÓÚͨʺóÃÅÑ¬È¾ÌØ¶¨µÄ×îÖÕÓû§×飬¸Ã×éµÄ³ÉÔ±ÒÑÖª¾³£»á¼û¸Ã×éµÄÍøÕ¾£¬Ä¿µÄÊÇ·¿ªÍ¨ÍùÆä»úеµÄÍø¹ØÒÔ¾ÙÐкóÐøÊ¹ÓÃÔ˶¯¡£²¢ÌåÏÖ×î³õµÄ¹¥»÷Á´Éæ¼°´ÓÔ¶³Ì¹¥»÷Õß¿ØÖƵÄÓò½« JavaScript ´úÂë×¢ÈëÍøÕ¾£¬¸ÃÓòÖ¼ÔÚÍøÂçºÍй¶ÓйØÊܺ¦Õß»úеµÄ IP µØÀíλÖúÍϵͳÐÅÏ¢£¬½öµ±Ïà¹Ø²Ù×÷ϵͳÊÇ Windows »ò macOS ʱ²ÅÑ¡Ôñ¼ÌÐø¾ÙÐУ¬Åú×¢¸ÃÔ˶¯ÊÇÕë¶ÔÅÌËã»ú¶ø·ÇÒÆ¶¯×°±¸È«ÐIJ߻®µÄ¡£×îºóÒ»²½µ¼ÖÂÁËÒ»¸ö¿ÉÄܵÄä¯ÀÀÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¬Ê¹¹¥»÷ÕßÄܹ»Ð®ÖƶԻúеµÄ¿ØÖÆ¡£È»¶ø2021 Äê 1 ÔÂÊӲ쵽µÄµÚ¶þ²¨µÄÌØµãÊÇÔ½·¢Òþ²Ø£¬ÓÉÓÚ¶ÔÍøÕ¾Ê¹ÓõÄÕýµ± WordPress ¾ç±¾£¨“ wp-embed.min.js ”£©¾ÙÐÐÁË JavaScript Ð޸쬶ø²»Êǽ«¶ñÒâ´úÂëÖ±½ÓÌí¼Óµ½Ö÷ HTML Ò³Ãæ£¬Ê¹ÓøÃÒªÁì´Ó¹¥»÷Õß¿ØÖÆÏµķþÎñÆ÷¼ÓÔØ¾ç±¾¡£¸üÖ÷ÒªµÄÊÇ£¬Ö¸ÎÆÊ¶±ð¾ç±¾»¹ÓâÔ½ÁËÍøÂçϵͳԪÊý¾ÝÒÔ²¶»ñĬÈÏÓïÑÔ¡¢ä¯ÀÀÆ÷Ö§³ÖµÄ×ÖÌåÁÐ±í¡¢Ê±ÇøºÍä¯ÀÀÆ÷²å¼þÁÐ±í¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN2z
10. ¹¥»÷ÕßʹÓÃEmotet ¶ñÒâÈí¼þ¶ÔÈ«ÇòÓÊÏäÌᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷Emotet¶ñÒâÈí¼þÔÚÖÐֹʮ¸öÔºó£¬ÓÚ15ÈÕ×îÏÈÔËÐС£¸ÃÈí¼þͨ¹ý¶à´ÎÀ¬»øÓʼþ¹¥»÷£¬ÏòÈ«ÇòÓÊÏä·¢ËͶñÒâÎĵµ¡£EmotetÊÇÒ»ÖÖ¶ñÒâÈí¼þѬȾ£¬Í¨¹ý´øÓжñÒ⸽¼þµÄÀ¬»øÓʼþ¹¥»÷Èö²¥¡£ÈôÊÇÓû§·¿ª¸½¼þ£¬¶ñÒâºê»òJavaScriptÎļþ£¬½«ÏÂÔØEmotet DLL²¢Ê¹ÓÃPowerShell½«Æä¼ÓÔØµ½ÄÚ´æÖС£Ò»µ©¼ÓÔØ£¬¶ñÒâÈí¼þ½«ËÑË÷ºÍÇÔÈ¡µç×ÓÓʼþ£¬ÓÃÓÚÖ®ºóµÄÀ¬»øÓʼþ¹¥»÷£¬²¢Ö²ÈëÌØÁíÍâÓÐÓÃÔØºÉ£¬ÈçTrickBot»òQbot£¬ÕâÐ©ÔØºÉͨ³£»áʹװ±¸ÔâÀÕË÷Èí¼þѬȾ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN2y

AG¹«Ë¾ÔÆ







