AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.11.15-2021.11.21£©

2021-11-23

Ò»¡¢ ÈÈÃÅ×ÊѶ

1. ¹¥»÷ÕßʹÓÃHTML×ß˽ÊÖÒÕÌᳫ´¹ÂÚ¹¥»÷

¡¾¸ÅÊö¡¿

Ñо¿Ö°Ô±ÖÒÑÔ˵ £¬¹¥»÷ÕßÔ½À´Ô½¶àµØÔÚÍøÂç´¹ÂÚÔ˶¯ÖÐʹÓà HTML ×ß˽ÊÖÒÕ¡£ËüÊÇÒ»ÖÖʹÓÃÕýµ± HTML5 ºÍ JavaScript ¹¦Ð§µÄ¶ñÒâÈí¼þ´«Ë͵ĸ߶ȹæ±ÜÊÖÒÕ £¬¶ñÒâ¸ºÔØÍ¨¹ý HTML ¸½¼þ»òÍøÒ³ÖеıàÂë×Ö·û´®´«ËÍ¡£¶ñÒâ HTML ´úÂëÊÇÔÚÄ¿µÄÉè±¹ØÁ¬Ää¯ÀÀÆ÷ÖÐÌìÉúµÄ £¬¸Ã×°±¸ÒѾ­´¦ÓÚÊܺ¦ÕßÍøÂçµÄÇå¾²¹æÄ£ÄÚ¡£µ±Ä¿µÄÓû§ÔÚÆä Web ä¯ÀÀÆ÷Öз­¿ª HTML ʱ £¬ä¯ÀÀÆ÷»á¶Ô¶ñÒâ¾ç±¾¾ÙÐнâÂë £¬½ø¶øÔÚÖ÷»ú×°±¸ÉÏ×é×°ÓÐÓÃÔØºÉ¡£Òò´Ë £¬¹¥»÷Õß²»ÊÇÈöñÒâ¿ÉÖ´ÐÐÎļþÖ±½Óͨ¹ýÍøÂç £¬¶øÊÇÔÚ·À»ðǽºóÃæÍâµØ¹¹½¨¶ñÒâÈí¼þ´Ó¶øµÖ´ï¹¥»÷Ä¿µÄ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN1I

 

2. BotenaGo½©Ê¬ÍøÂçʹÓöà¸öÎó²î¹¥»÷Êý°ÙÍò·ÓÉÆ÷ºÍÎïÁªÍø×°±¸

¡¾¸ÅÊö¡¿

Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÐ嵀 BotenaGo ½©Ê¬ÍøÂç £¬¸ÃÍøÂçʹÓà 33 ¸öÎó²î¹¥»÷Êý°ÙÍò·ÓÉÆ÷ºÍÎïÁªÍø×°±¸¡£BotenaGo ÊÇÓà Golang (Go) ±àдµÄ £¬ÔÚר¼ÒÐû²¼±¨¸æÊ± £¬ËüµÄ·À²¡¶¾ (AV) ¼ì²âÂÊºÜµÍ (6/62)¡£ÎªÁËÌṩÎó²îʹÓà £¬¶ñÒâÈí¼þÊ×ÏÈʹÓüòÆÓµÄ“GET”ÇëÇóÅÌÎÊÄ¿µÄ¡£È»ºó £¬ËüʹÓÃÓ³Éäµ½¹¥»÷º¯ÊýµÄÿ¸öϵͳÊðÃûËÑË÷´Ó“GET”ÇëÇ󷵻صÄÊý¾Ý¡£“×Ö·û´®“Server: Boa/0.93.15”Ó³Éäµ½º¯Êý“main_infectFunctionGponFiber” £¬¸Ãº¯ÊýÊÔͼʹÓÃÒ×Êܹ¥»÷µÄÄ¿µÄ £¬ÔÊÐí¹¥»÷Õßͨ¹ýÌØ¶¨µÄ Web ÇëÇóÖ´ÐвÙ×÷ϵͳÏÂÁî (CVE-2020-8958)¡£¸Ã½©Ê¬ÍøÂçÕë¶ÔÊý°ÙÍò¾ßÓÐʹÓÃÉÏÊöȱÏݵĹ¦Ð§µÄ×°±¸ £¬ÀýÈçÏòShodan ÅÌÎÊ×Ö·û´® Boa £¬ÕâÊÇÒ»¸öÒÑÍ£²úµÄÓÃÓÚǶÈëʽӦÓóÌÐòµÄ¿ªÔ´ Web ·þÎñÆ÷ £¬Ëü·µ»Ø½ü 200 Íǫ̀װ±¸¡£×°Öúó £¬bot ¶ñÒâÈí¼þ½«ÕìÌý¶Ë¿Ú 31412 ºÍ 19412 £¬ºóÕßÓÃÓÚÎüÊÕÊܺ¦Õß IP¡£Ò»µ©ÎüÊÕµ½Óë¸Ã¶Ë¿ÚÐÅÏ¢µÄÅþÁ¬ £¬Ëü¾Í»á±éÀúÓ³ÉäµÄÎó²îʹÓú¯Êý²¢Ê¹Óøø¶¨µÄ IP Ö´ÐÐËüÃÇ¡£BotenaGo ½«ÔÚÊÜѬȾµÄ×°±¸ÉÏÖ´ÐÐÔ¶³Ì shell ÏÂÁî £¬Æ¾Ö¤ÊÜѬȾµÄϵͳ £¬bot ʹÓÃÓë²î±ðÓÐÓÃÔØºÉÏà¹ØÁªµÄ²î±ðÁ´½Ó¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN1L

 

3. Moses Staff кڿÍ×éÖ¯¹¥»÷ÒÔÉ«ÁÐ×éÖ¯

¡¾¸ÅÊö¡¿

Ò»¸öÃûΪMoses Staff µÄкڿÍ×éÖ¯¹¥»÷ÁËÒÔÉ«ÁÐ×éÖ¯ £¬ÆÆËðÁËËûÃǵÄÍøÂç £¬¼ÓÃÜÁËËûÃǵÄÊý¾Ý £¬µ«Ëæºó¾Ü¾øÐ­ÉÌÖ§¸¶Êê½ð £¬Çå¾²Ñо¿Ö°Ô±½«ÆäÐÎòΪ³öÓÚÕþÖÎÄîÍ·µÄÆÆËðÐÔ¹¥»÷¡£¸Ã×é֯ͨ¹ýʹÓÃδÐÞ²¹µÄ¾ÉÎó²îÀ´ÆÆËðÊܺ¦ÕßµÄÍøÂç £¬ÒÑÍùµÄÈëÇÖÓëδ´ò²¹¶¡µÄ Microsoft Exchange ·þÎñÆ÷ÓйØ¡£Ò»µ©ËûÃÇÆÆËðÁËϵͳ £¬¸Ã×éÖ¯¾Í»áʹÓà PsExec¡¢WMIC ºÍ Powershell µÈ¹¤¾ßÉîÈëÊܺ¦ÕßµÄÍøÂçÄÚ²¿¡£¸Ã×é֯ȻºóÔÚ¼ÓÃÜÆäÊý¾Ý֮ǰ´ÓÊܺ¦ÕßµÄÍøÂçÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢ £¬Moses Staff ͨ³ £»á°²ÅÅ¿ªÔ´ DiskCryptor ¿âÀ´Ö´Ðоí¼ÓÃܲ¢Ê¹ÓÃÖ¸µ¼¼ÓÔØ³ÌÐòËø¶¨Êܺ¦ÕßµÄÅÌËã»ú £¬Ö¸µ¼¼ÓÔØ³ÌÐò²»ÔÊÐíÅÌËã»úÔÚûÓÐ׼ȷÃÜÂëµÄÇéÐÎÏÂÆô¶¯¡£×ÝÈ»ÌṩÁË׼ȷµÄÂë £¬Ò»µ©ÏµÍ³Æô¶¯ £¬Êý¾ÝÈÔÈ»»á±»¼ÓÔØ £¬Check Point ÌåÏÖÔÚijЩÇéÐÎÏ¿ÉÒÔ»Ö¸´Æô¶¯ÃÜÂëºÍ¼ÓÃÜÃÜÔ¿¡£ºÚ¿Í»¹Ä±ÆëÕû¸ö Telegram ƵµÀºÍ Twitter ÕÊ»§ £¬ÔÚÄÇÀïËûÃÇÐû²¼ËûÃÇÌí¼Óµ½Ð¹ÃÜÍøÕ¾µÄÐÂÊܺ¦Õß¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN24

 

4. ³¯ÏʺڿÍʹÓÃľÂí»¯IDA Pro¹¥»÷ÍøÂçÇå¾²Ñо¿Ö°Ô±

¡¾¸ÅÊö¡¿

¾Ý±¨µÀ £¬Á¥ÊôÓÚ³¯ÏʵĹú¼Ò×ÊÖú×éÖ¯ Lazarus ÕýÊÔͼʹÓÃÊ¢ÐÐµÄ IDA Pro ÄæÏò¹¤³ÌÈí¼þµÄľÂí»¯µÁ°æ°æ±¾ £¬ÔÙ´ÎÕë¶Ô¾ßÓкóÃźÍÔ¶³Ì»á¼ûľÂíµÄÇå¾²Ñо¿Ö°Ô±¡£Ñо¿Ö°Ô±ÌåÏÖIDA Pro ÊÇÒ»ÖÖ½»»¥Ê½·´»ã±à³ÌÐò £¬Ö¼ÔÚ½«»úеÓïÑÔ£¨Ò²³ÆÎª¿ÉÖ´ÐÐÎļþ£©·­Òë³É»ã±àÓïÑÔ £¬Ê¹Çå¾²Ñо¿Ö°Ô±Äܹ»ÆÊÎö³ÌÐòµÄÄÚ²¿ÊÂÇ飨¶ñÒâ»òÆäËû£© £¬²¢×÷Ϊµ÷ÊÔÆ÷À´¼ì²â¹ýʧ¡£Ë¹Âå·¥¿ËÍøÂçÇå¾²¹«Ë¾³Æ¹¥»÷Õß½« [Hex-Rays] ¿ª·¢µÄԭʼ IDA Pro 7.5 Èí¼þÓëÁ½¸ö¶ñÒâ×é¼þÀ¦°óÔÚÒ»Æð £¬ÆäÖÐÒ»¸öÊÇÃûΪ“win_fw.dll”µÄÄÚ²¿Ä£¿é £¬¸ÃÄ£¿éÔÚÓ¦ÓóÌÐò×°ÖÃʱ´úÖ´ÐС£Õâ¸ö±»¸Ä¶¯µÄ°æ±¾Ëæºó±»±àÅÅÒÔ´ÓϵͳÉ쵀 IDA ²å¼þÎļþ¼Ð¼ÓÔØÃûΪ“idahelper.dll”µÄµÚ¶þ¸ö×é¼þ £¬ÀÖ³ÉÖ´Ðкó £¬“idahelper.dll”¶þ½øÖÆÎļþÅþÁ¬µ½Î»ÓÚ“www[.]devguardmap[.]org”µÄÔ¶³Ì·þÎñÆ÷ÒÔ¼ìË÷ºóÐøÓÐÓøºÔØ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN23

 

5. ¹¥»÷ÕßʹÓüÓÃܶñÒâÈí¼þ¹¥»÷°¢ÀïÔÆ

¡¾¸ÅÊö¡¿

Ñо¿Ö°Ô±·¢Ã÷¹¥»÷ÕßµÄÄ¿µÄÊǰ¢Àï°Í°Íµ¯ÐÔÅÌËã·þÎñ (ECS) ʵÀý £¬½ûÓÃijЩÇå¾²¹¦Ð§ÒÔ½øÒ»²½ÊµÏÖËûÃǵļÓÃÜÄ¿µÄ¡£²¢Ö¸³ö £¬°¢Àï°Í°ÍÌṩÁËÒ»Ð©ÆæÒìµÄÑ¡Ôñ £¬Ê¹Æä³ÉΪ¹¥»÷Õß¼«¾ßÎüÒýÁ¦µÄÄ¿µÄ¡£¹¥»÷ÕßʹÓüÓÃܶñÒâÈí¼þÖеÄһС¶ÎÌØ¶¨´úÂëÀ´½¨ÉèеķÀ»ðǽ¹æÔò £¬Ö¸Ê¾Çå¾²¹ýÂËÆ÷ÑïÆúÀ´×ÔÊôÓÚ°¢Àï°Í°ÍÄÚ²¿ÇøÓòºÍÇøÓòµÄ IP ¹æÄ£µÄ´«ÈëÊý¾Ý°ü £¬Í¨³£ £¬µ±¼ÓÃÜÐ®ÖÆ¶ñÒâÈí¼þ×°ÖÃÔÚ°¢Àï°Í°Í ECS ´æ´¢Í°ÖÐʱ £¬Çå¾²ÊðÆÊÎöÏòÓû§·¢ËͶñÒâ¾ç±¾ÕýÔÚÔËÐеÄ֪ͨ¡£¿ÉÊÇÇå¾²ÊðÀíÔÚ´¥·¢ÈëÇÖ¾¯±¨Ö®Ç°Òѱ»Ð¶ÔØ¡£Ò»µ©Ëüͨ¹ýÁËÇå¾²¹¦Ð§ £¬¶ñÒâÈí¼þ¾Í»á¼ÌÐø×°ÖÃÏÖ³ÉµÄ XMRig ¼ÓÃÜÇ®±Ò¿ó¹¤ £¬ËüΪÃÅÂÞ±ÒÍÚ¿ó¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN2h

 

6. ¹¥»÷ÕßʹÓÃSharkBot¹¥»÷Å·ÖÞÒøÐÐ

¡¾¸ÅÊö¡¿

Cleafy µÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪ SharkBot µÄÐÂÐÍ Android ÒøÐÐľÂí £¬ËüÕë¶ÔÅ·ÖÞµÄÒøÐС£¸Ã¶ñÒâÈí¼þÖÁÉÙ×Ô 2021 Äê 10 ÔÂÏÂÑ®ÒÔÀ´Ò»Ö±´¦ÓÚ»îԾ״̬ £¬ÆäÄ¿µÄÊÇÒâ´óÀû¡¢Ó¢¹úºÍÃÀ¹úÒøÐеÄÒÆ¶¯Óû§¡£¸ÃľÂíÔÊÐíÐ®ÖÆÓû§µÄÒÆ¶¯×°±¸²¢´ÓÍøÉÏÒøÐкͼÓÃÜÇ®±ÒÕË»§ÖÐÇÔÈ¡×ʽð¡£Ò»µ©ÒøÐÐľÂí×°ÖÃÔÚÊܺ¦ÕßµÄ×°±¸ÉÏ £¬¹¥»÷Õ߾ͿÉÒÔͨ¹ýÀÄÓø¨Öú·þÎñ£¨¼´µÇ¼ƾ֤¡¢Ð¡ÎÒ˽¼ÒÐÅÏ¢¡¢Ä¿½ñÓà¶îµÈ£©ÇÔÈ¡Ãô¸ÐµÄÒøÐÐÐÅÏ¢ £¬SharkBot ʵÑéÁýÕÖ¹¥»÷À´ÇÔÈ¡µÇ¼ƾ֤ºÍÐÅÓÿ¨ÐÅÏ¢¡£²¢ÇÒËüʵÑéÁ˶àÖÖ·´ÆÊÎöÊÖÒÕ £¬°üÀ¨×Ö·û´®»ìÏýÀý³Ì¡¢Ä£ÄâÆ÷¼ì²âºÍÓòÌìÉúËã·¨ (DGA)¡£SharkBot »áÀÄÓà Accessibility Service ÔÚÊÜѬȾװ±¸ÄÚ¾ÙÐÐ ATS ¹¥»÷¡£ATS£¨×Ô¶¯×ªÕËϵͳ£©¹¥»÷ÔÊÐí Treat ¼ÓÈëÕß×Ô¶¯ÌîдÕýµ±ÊÖ»úÒøÐÐÖеÄ×Ö¶Î £¬ÒԱ㽫×ʽð´ÓÊÜѬȾװ±¸×ªÒƵ½¹¥»÷Õß¿ØÖÆÏµÄÕË»§¡£ÕâÖÖÊÖÒÕÔÊÐí×Ô¶¯»¯ÕâЩ²Ù×÷ £¬×î´óÏ޶ȵØïÔÌ­Óû§¸ÉÔ¤¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN2i

 

 

7. ¹¥»÷ÕßʹÓÃÓòǰ¶ËÊÖÒÕÒÔCobalt Strike ¹¥»÷Ãåµé

¡¾¸ÅÊö¡¿

Cisco Talos ÓÚ2021 Äê9Ô·¢Ã÷ÁËÒ»Ïî¶ñÒâÔ˶¯ £¬¸ÃÔ˶¯Ê¹Óþ­ÓÉ»ìÏýµÄ Meterpreter stager °²ÅÅ Cobalt Strike Ðűê¡£¸Ã¹¥»÷ÕßʹÓÃÃåµéÕþ¸®ÓµÓкÍÔËÓªµÄÓòÃåµéÊý×ÖÐÂÎÅÍøÂç×÷ΪÆäÐűêµÄÓòǰ¶Ë¡£¶ñÒâÈí¼þͨ³£ÊÇÒ»¸öÔÚÊܺ¦»úеÉÏÔËÐеļÓÔØ³ÌÐò £¬Í¨¹ý·´Éä×¢Èë½âÂë²¢Ö´ÐÐ Cobalt Strike Ðűê DLL¡£ËüÔÚÔËÐÐʱ¼ÓÔØ¶à¸ö¿â £¬²¢Æ¾Ö¤Ç¶ÈëµÄÉèÖÃÎļþÌìÉúÐűêÁ÷Á¿¡£ÉèÖÃÎļþ°üÀ¨ÓëÏÂÁîºÍ¿ØÖÆ (C2) ·þÎñÆ÷Ïà¹ØµÄÐÅÏ¢ £¬¸Ã·þÎñÆ÷ָʾÊܺ¦ÕߵĻúе·¢Ëͳõʼ DNS ÇëÇó £¬ÊµÑéÅþÁ¬µ½ÃåµéÕþ¸®ËùÓÐÓòÃû www[.]mdn[.]gov[ µÄÖ÷»ú [.] ¡£]ºÁÃס£¸ÃÕ¾µãÍйÜÔÚ Cloudflare ÄÚÈݽ»¸¶ÍøÂçÖ®ºó £¬ÏÖʵµÄ C2 Á÷Á¿Æ¾Ö¤ÐűêÉèÖÃÊý¾ÝÖÐÖ¸¶¨µÄHTTPÖ÷»ú±êÍ·ÐÅÏ¢ÖØ¶¨Ïòµ½¹¥»÷Õß¿ØÖƵķþÎñÆ÷ test[.]softlemon[.]net¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN2k

 

8. °Í»ù˹̹ºÚ¿Íı»®¼ÙÓ¦ÓÃÊÐËÁÒÔ¹¥»÷°¢¸»º¹Ç°¹ÙÔ±

¡¾¸ÅÊö¡¿

Ñо¿Ö°Ô±·¢Ã÷һȺ°Í»ù˹̹ºÚ¿Í½¨Éè²¢ÔËÓªÁËÒ»¸öÐéαµÄ Android Ó¦ÓóÌÐòÊÐËÁ £¬Ä¿µÄÊÇÔÚ°¢¸»º¹Ç°Õþ¸®ÂÙΪÐÂËþÀû°àÕþȨ֮ǰºÍʱ´ú £¬¹¥»÷ºÍѬȾÓë¸ÃÕþ¸®ÓйصÄСÎÒ˽¼Ò¡£ºÚ¿ÍÔ˶¯±¬·¢ÔÚ½ñÄê 4 ÔÂÖÁ 8 ÔÂÖ®¼ä £¬ÓÉÒ»¸öÃûΪSideCopyµÄ×é֯ʵÑé ¡£Facebook Çå¾²Ñо¿Ö°Ô±ÌåÏÖ £¬SideCopy ÔËÓªÉÌÔÚÆäÆ½Ì¨ÉϽ¨ÉèÁËÐéαСÎÒ˽¼Ò×ÊÁÏ £¬Í¨³£Ã°³äÄêÇáÅ®ÐÔ £¬²¢¿¿½üÄ¿µÄ £¬Ä¿µÄÊÇÈÃËûÃǵã»÷¶ñÒâÁ´½Ó¡£ÕâЩÁ´½Ó½«Êܺ¦ÕßÖØ¶¨Ïòµ½ÍøÂçµÇ¼ƾ֤µÄÍøÂç´¹ÂÚÕ¾µã £¬»òÕßÔÚijЩÇéÐÎÏ £¬Öض¨Ïòµ½ÍйÜÊܶñÒâÈí¼þѬȾµÄ Android Ó¦ÓóÌÐòµÄÐéαӦÓóÌÐòÊÐËÁ¡£SideCopy ͨ³£Ê¹ÓÃαװ³É̸ÌìÐÂÎÅÓ¦ÓóÌÐòµÄ¶ñÒâÓ¦ÓóÌÐò¡£ËûÃÇҪôģÄâ Viber ºÍ Signal µÈ×ÅÃûÆ·ÅÆ £¬ÒªÃ´Íêȫð³äеÄ̸ÌìÓ¦ÓóÌÐò¡£ÕâЩ Android Ó¦ÓóÌÐò°üÀ¨Ô¶³Ì»á¼ûľÂí¡£Ò»Ð©Ó¦ÓóÌÐò°üÀ¨Ò»¸öÃûΪPJobRATµÄ¶¾Öê £¬¶øÆäËûÓ¦ÓóÌÐò°üÀ¨Ò»¸ö ÒÔǰ䱨¸æµÄ Android ¶ñÒâÈí¼þ¶¾Öê Facebook £¬ÃûΪ Mayhem¡£ÕâÁ½ÖÖ¶ñÒâÈí¼þʹ SideCopy ²Ù×÷Ô±¿ÉÒÔÍêÈ«¿ØÖÆÊÜѬȾµÄ×°±¸¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN2w

 

9. ¹¥»÷ÕßʹÓÃÌØ¹¤Èí¼þ¶ÔÓ¢¹úºÍÖж«µÄʵÌåÌᳫˮ¿Ó¹¥»÷

¡¾¸ÅÊö¡¿

Ñо¿Ö°Ô±·¢Ã÷ÒÔÉ«ÁÐÌØ¹¤Èí¼þ¹©Ó¦ÉÌCandiru £¬Ëü±»Ìí¼Óµ½Õâ¸öÔµľ­¼Ã¿éÁбí £¬Ìý˵ÒѾ­·¢¶¯Á˶ÔÓ¢¹úºÍÖж«¸ßµ÷ʵÌå“Ë®¿Ó”¹¥»÷ £¬ËüÊÇÒ»ÖÖÕë¶ÔÐÔºÜÇ¿µÄÈëÇÖÐÎʽ £¬ÓÉÓÚËüÃÇÇãÏòÓÚͨʺóÃÅÑ¬È¾ÌØ¶¨µÄ×îÖÕÓû§×é £¬¸Ã×éµÄ³ÉÔ±ÒÑÖª¾­³£»á¼û¸Ã×éµÄÍøÕ¾ £¬Ä¿µÄÊÇ·­¿ªÍ¨ÍùÆä»úеµÄÍø¹ØÒÔ¾ÙÐкóÐøÊ¹ÓÃÔ˶¯¡£²¢ÌåÏÖ×î³õµÄ¹¥»÷Á´Éæ¼°´ÓÔ¶³Ì¹¥»÷Õß¿ØÖƵÄÓò½« JavaScript ´úÂë×¢ÈëÍøÕ¾ £¬¸ÃÓòÖ¼ÔÚÍøÂçºÍй¶ÓйØÊܺ¦Õß»úеµÄ IP µØÀíλÖúÍϵͳÐÅÏ¢ £¬½öµ±Ïà¹Ø²Ù×÷ϵͳÊÇ Windows »ò macOS ʱ²ÅÑ¡Ôñ¼ÌÐø¾ÙÐÐ £¬Åú×¢¸ÃÔ˶¯ÊÇÕë¶ÔÅÌËã»ú¶ø·ÇÒÆ¶¯×°±¸È«ÐIJ߻®µÄ¡£×îºóÒ»²½µ¼ÖÂÁËÒ»¸ö¿ÉÄܵÄä¯ÀÀÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î £¬Ê¹¹¥»÷ÕßÄܹ»Ð®ÖƶԻúеµÄ¿ØÖÆ¡£È»¶ø2021 Äê 1 ÔÂÊӲ쵽µÄµÚ¶þ²¨µÄÌØµãÊÇÔ½·¢Òþ²Ø £¬ÓÉÓÚ¶ÔÍøÕ¾Ê¹ÓõÄÕýµ± WordPress ¾ç±¾£¨“ wp-embed.min.js ”£©¾ÙÐÐÁË JavaScript ÐÞ¸Ä £¬¶ø²»Êǽ«¶ñÒâ´úÂëÖ±½ÓÌí¼Óµ½Ö÷ HTML Ò³Ãæ £¬Ê¹ÓøÃÒªÁì´Ó¹¥»÷Õß¿ØÖÆÏµķþÎñÆ÷¼ÓÔØ¾ç±¾¡£¸üÖ÷ÒªµÄÊÇ £¬Ö¸ÎÆÊ¶±ð¾ç±¾»¹ÓâÔ½ÁËÍøÂçϵͳԪÊý¾ÝÒÔ²¶»ñĬÈÏÓïÑÔ¡¢ä¯ÀÀÆ÷Ö§³ÖµÄ×ÖÌåÁÐ±í¡¢Ê±ÇøºÍä¯ÀÀÆ÷²å¼þÁбí¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN2z

 

10.  ¹¥»÷ÕßʹÓÃEmotet ¶ñÒâÈí¼þ¶ÔÈ«ÇòÓÊÏäÌᳫ¹¥»÷

¡¾¸ÅÊö¡¿

Ñо¿Ö°Ô±·¢Ã÷Emotet¶ñÒâÈí¼þÔÚÖÐֹʮ¸öÔºó £¬ÓÚ15ÈÕ×îÏÈÔËÐС£¸ÃÈí¼þͨ¹ý¶à´ÎÀ¬»øÓʼþ¹¥»÷ £¬ÏòÈ«ÇòÓÊÏä·¢ËͶñÒâÎĵµ¡£EmotetÊÇÒ»ÖÖ¶ñÒâÈí¼þѬȾ £¬Í¨¹ý´øÓжñÒ⸽¼þµÄÀ¬»øÓʼþ¹¥»÷Èö²¥¡£ÈôÊÇÓû§·­¿ª¸½¼þ £¬¶ñÒâºê»òJavaScriptÎļþ £¬½«ÏÂÔØEmotet DLL²¢Ê¹ÓÃPowerShell½«Æä¼ÓÔØµ½ÄÚ´æÖС£Ò»µ©¼ÓÔØ £¬¶ñÒâÈí¼þ½«ËÑË÷ºÍÇÔÈ¡µç×ÓÓʼþ £¬ÓÃÓÚÖ®ºóµÄÀ¬»øÓʼþ¹¥»÷ £¬²¢Ö²ÈëÌØÁíÍâÓÐÓÃÔØºÉ £¬ÈçTrickBot»òQbot £¬ÕâÐ©ÔØºÉͨ³ £»áʹװ±¸ÔâÀÕË÷Èí¼þѬȾ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN2y

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼ £¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼