¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.12.13-2021.12.19£©
2021-12-20
Ò»¡¢ Íþвͨ¸æ
΢Èí12ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ£¨CVE-2021-43890¡¢CVE-2021-43883¡¢CVE-2021-43215£©
¡¾Ðû²¼Ê±¼ä¡¿2021-12-16 14:00:00 GMT
¡¾¸ÅÊö¡¿
12ÔÂ15ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼12ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË67¸öÇå¾²ÎÊÌâ£¬Éæ¼°Windows¡¢Microsoft Office¡¢Microsoft Visual Studio¡¢Microsoft PowerShellµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐеȸßΣÎó²îÀàÐÍ¡£±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²îÓÐ7¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ60¸ö£¬ÆäÖаüÀ¨6¸ö0dayÎó²î£ºWindows AppX InstallerÓÕÆÎó²î(CVE-2021-43890)NTFS Set Short NameȨÏÞÌáÉýÎó²î£¨CVE-2021-43240£©Windows Print SpoolerȨÏÞÌáÉýÎó²î£¨CVE-2021-41333£©Windows Mobile Device ManagementȨÏÞÌáÉýÎó²î£¨CVE-2021-43880£©Windows InstallerȨÏÞÌáÉýÎó²î£¨CVE-2021-43883£©Windows Encrypting File System (EFS) ȨÏÞÌáÉýÎó²î£¨CVE-2021-43893£©ÇëÏà¹ØÓû§¾¡¿ì¸üв¹¶¡¾ÙÐзÀ»¤£¬ÍêÕûÎó²îÁбíÇë²Î¿¼¸½Â¼¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Windows Active DirectoryÓò·þÎñȨÏÞÌáÉýÎó²îͨ¸æ£¨CVE-2021-42287¡¢CVE-2021-42278£©
¡¾Ðû²¼Ê±¼ä¡¿2021-12-14 15:00:00 GMT
¡¾¸ÅÊö¡¿
12ÔÂ13ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²â·¢Ã÷ÓÐÑо¿Ö°Ô±¹ûÕæÁËActive Directory Domain ServicesȨÏÞÌáÉýÎó²î£¨CVE-2021-42287¡¢CVE-2021-42278£©µÄ PoC¡£Î¢Èí¹Ù·½ÒÑÔÚ11ÔµÄÇå¾²¸üÐÂÐû²¼ÁËÒÔÉÏÎó²îµÄÐÞ¸´²¹¶¡£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
VMware ¶à¸ö²úÆ·±£´æ Log4j2Ô¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2021-44228£©
¡¾Ðû²¼Ê±¼ä¡¿2021-12-14 13:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½VMware Ðû²¼Ç徲ͨ¸æ£¬VMwareµÄÖÚ¶à²úÆ·ÊÜApache Log4j2Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44228£©µÄÓ°Ïì¡£ÓÉÓÚApache Log4j2ijЩ¹¦Ð§±£´æµÝ¹éÆÊÎö¹¦Ð§£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÊâ½á¹¹µÄÊý¾ÝÇëÇó°ü£¬¿ÉÔÚÊÜÓ°ÏìµÄ VMware ²úÆ·ÖÐÖ´ÐÐí§Òâ´úÂë¡£Îó²îPoCÒѹûÕæ£¬ÇÒ·¢Ã÷ÔÚҰʹÓ㬽¨ÒéÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐÐÅŲéÓë·À»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Apache Log4j2 Ô¶³Ì´úÂëÖ´ÐÐÎó²î´¦Öóͷ£ÊֲᣨCVE-2021-44228£©
¡¾Ðû²¼Ê±¼ä¡¿2021-12-16 14:00:00 GMT
¡¾¸ÅÊö¡¿
12ÔÂ9ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½ÍøÉÏÅû¶Apache Log4jÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44228£©£¬ÓÉÓÚApache Log4j2ijЩ¹¦Ð§±£´æµÝ¹éÆÊÎö¹¦Ð§£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÊâ½á¹¹µÄÊý¾ÝÇëÇó°ü£¬¿ÉÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£Îó²îPoCÒÑÔÚÍøÉϹûÕæ£¬Ä¬ÈÏÉèÖü´¿É¾ÙÐÐʹÓ㬸ÃÎó²îÓ°Ïì¹æÄ£¼«¹ã£¬½¨ÒéÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐÐÅŲéÓë·À»¤¡£12ÔÂ10ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT·¢Ã÷Apache Log4j 2.15.0-rc1 °æ±¾½öÐÞ¸´LDAPºÍÔöÌíÁËhost°×Ãûµ¥£¬·ÇĬÈÏÉèÖÃÏ¿ÉÒÔ±»ÈƹýʹÓ㻹ٷ½¶Ô´ËÐû²¼ÁËApache Log4j 2.15.0-rc2°æ±¾£¨Óë¹ÙÍøµÄ2.15.0Îȹ̰æÏàͬ£©¾ÙÐÐÐÞ¸´£¬ÔöÌíÁ˶ÔurIÒì³£µÄ´¦Öóͷ£¡£12ÔÂ12ÈÕ£¬¹Ù·½ÓÖÐû²¼ÁËApache Log4j 2.15.1-rc1°æ±¾£¬Ö±½Ó½ûÓÃÁËJNDI¹¦Ð§£¬ÈôÊÇÏà¹ØÓªÒµÐèÒªÓõ½lookup¹¦Ð§£¬½¨ÒéÉý¼¶µ½´Ë°æ±¾²¢ÊÖ¶¯½«log4j2.formatMsgNoLookupsĬÈÏÉèÖÃΪfalse¡£Apache Log4j2ÊÇÒ»¿î¿ªÔ´µÄJavaÈÕÖ¾¿ò¼Ü£¬±»ÆÕ±éµØÓ¦ÓÃÔÚÖÐÐļþ¡¢¿ª·¢¿ò¼ÜÓëWebÓ¦ÓÃÖУ¬ÓÃÀ´¼Í¼ÈÕÖ¾ÐÅÏ¢¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. “Karakurt”ÍøÂç·¸·¨ÍÅ»ïרעÓÚÊý¾Ý͵ÇÔºÍÀÕË÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÏêϸÏÈÈÝÁËÒ»¸öÃûΪ Karakurt µÄÖØ´óµÄ³öÓÚ¾¼ÃÄîÍ·µÄ¹¥»÷ÕßµÄÔ˶¯¡£¸ÃÕûÌåµÄÔ˶¯ÓÚ 2021 Äê 6 ÔÂÊ״α»·¢Ã÷£¬µ«¸ÃÕûÌåÔÚ 2021 ÄêµÚÈý¼¾¶ÈÔ½·¢»îÔ¾¡£¶ÔÓë¸Ã¹¥»÷ÕßÏà¹ØµÄ¹¥»÷Á´µÄÆÊÎöÅú×¢£¬ËüÖ÷ҪʹÓà VPN ƾ֤À´»ñµÃ¶ÔÄ¿µÄÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£ÔÚ×î³õµÄ¹¥»÷ÖУ¬¸Ã×é֯ͨ¹ýʹÓÃÊ¢Ðеĺ󿪷¢¹¤¾ß Cobalt Strike »ñµÃÁ˳¤ÆÚÐÔ¡£ÔÚ×î½üµÄ¹¥»÷ÖУ¬¸Ã×éÖ¯¿ªÆôÁË VPN IP ³Ø»ò AnyDesk Èí¼þÒÔ½¨É賤ÆÚÐÔ²¢×èÖ¹¼ì²â¡£Ò»µ©»ñµÃ¶ÔÄ¿µÄÍøÂçµÄ»á¼ûȨÏÞ£¬¸Ã×éÖ¯¾Í»áʹÓÃÖÖÖÖ¹¤¾ßÀ´ÌáÉýȨÏÞ£¬°üÀ¨ Mimikatz »ò PowerShell À´ÇÔÈ¡°üÀ¨ Active Directory Êý¾ÝµÄntds.dit£¬¿ÉÊÇ£¬´ó´ó¶¼¹¥»÷ÖеÄÍþв×é»áʹÓÃÏÈǰ»ñµÃµÄƾ֤ÌáÉýȨÏÞ¡£¹ØÓÚÊý¾Ýй¶£¬¸Ã×é֯ʹÓà 7zip ºÍ WinZip ¾ÙÐÐѹËõ£¬ÒÔ¼°Ê¹Óà Rclone »ò FileZilla (SFTP) ½«Êý¾ÝÉÏ´«µ½ Mega.io ÔÆ´æ´¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7O
2. ¹¥»÷Õß´ó¹æÄ£¹¥»÷Õë¶Ô160Íò¸öWordPressÍøÕ¾
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷£¬Õë¶ÔÁè¼Ý160 Íò¸öWordPress Õ¾µãµÄ´ó¹æÄ£¹¥»÷À˳±ÒѾȷ¶¨£¬ËûÃDZ¨¸æÁË36 СʱÄÚÁè¼Ý 1370Íò´Î¹¥»÷£¬ÖصãÊÇʹÓÃËĸö²î±ðµÄWordPress²å¼þºÍ¼¸¸öEpsilon¿ò¼ÜÖ÷Ìâ¡£ Ñо¿Ö°Ô±ÌåÏÖ£¬¹¥»÷ÕßµÄÄ¿µÄÊÇËĸöµ¥¶ÀµÄ²å¼þ£¬ÆäÖаüÀ¨Î´¾Éí·ÝÑéÖ¤µÄí§ÒâÑ¡Ïî¸üÐÂÎó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7S
3. ¹¥»÷Õß¶ÔʹÓöþάÂëµÄµÂ¹úÒøÐпͻ§Ìá³«ÍøÂç´¹ÂÚ¹¥»÷
¡¾¸ÅÊö¡¿
×î½ü·¢Ã÷µÄÒ»ÏîÔ˶¯ÖÐʹÓõÄÐÅϢʹÓöþάÂëÀ´ÓÕÆÁ½¼ÒGeman ½ðÈÚ»ú¹¹SparkasseºÍVolksbanken RaiffeisenbankenµÄÓû§£¬²¢ÇÔÈ¡Êý×ÖÒøÐÐÐÅÏ¢¡£²¢ÌåÏÖÍøÂç´¹ÂÚÓʼþ¾ÓÉÈ«ÐÄÖÆ×÷£¬ÄÚÈݽṹºÏÀí£¬²¢´øÓÐÒøÐбê¼Ç¡£ÍþвÐÐΪÕßʹÓòî±ðµÄÉç»á¹¤³Ì¼¼ÇÉÀ´ÓÕÆÎüÊÕÕߣ¬ÀýÈçÒªÇóËûÃÇÔÞ³ÉÒøÐÐʵÑéµÄÊý¾ÝÕþ²ß¸ü¸Ä»òÒªÇóËûÃÇÉó²éеÄÇå¾²³ÌÐò¡£È»¶ø£¬ÔÚ×î½üµÄ¹¥»÷ÖУ¬Æ×ÓʹÓöþάÂë¶ø²»ÊÇÒªÇóÊÕ¼þÈËɨÃèËüÃǵİ´£¬¡£Ê¹ÓöþάÂëʹµç×ÓÓʼþ¹ýÂËÆ÷ÄÑÒÔ½«Óʼþ±ê¼ÇΪ¶ñÒâÓʼþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7P
4. “Seedworm”¹¥»÷Õß¹¥»÷ÑÇÖÞºÍÖж«µÄµçÐŹ«Ë¾
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÌåÏÖ£¬×îÐÂÔ˶¯ÖеÄÒ»´Îµä·¶¹¥»÷ʼÓÚ¹¥»÷Õ߯ÆËðÄ¿µÄÍøÂ磬ȻºóÊÔͼÇÔȡƾ֤ÒÔºáÏòÒÆ¶¯£¬ÒÔ±ã¿ÉÒÔ½« webshell°²Åŵ½Exchange·þÎñÆ÷ÉÏ¡£Ñо¿Ö°Ô±ÌåÏÖ£¬×îÐÂÔ˶¯ÖеÄÒ»´Îµä·¶¹¥»÷ʼÓÚ¹¥»÷Õ߯ÆËðÄ¿µÄÍøÂ磬ȻºóÊÔͼÇÔȡƾ֤ÒÔºáÏòÒÆ¶¯£¬ÒÔ±ã¿ÉÒÔ½« webshell°²Åŵ½Exchange ·þÎñÆ÷ÉÏ¡£Ñо¿Ö°Ô±ÆÊÎöÁË8ÔÂ×îÏȵÄÕë¶ÔÖж«Ò»¼ÒµçÐŹ«Ë¾µÄÌØ¶¨¹¥»÷¡£Ñо¿Ö°Ô±Ëµ£¬ÔÚÕâÖÖÇéÐÎÏ£¬µÚÒ»¸öÍ×еÄÖ¤¾ÝÊǽ¨ÉèÁËÒ»Ïî·þÎñÀ´Æô¶¯Ò»¸öδ֪µÄ Windows ¾ç±¾Îļþ (WSF)¡£¹¥»÷ÕßËæºóʹÓþ籾·¢³öÖÖÖÖÓò¡¢Óû§·¢Ã÷ºÍÔ¶³Ì·þÎñ·¢Ã÷ÏÂÁ²¢×îÖÕʹÓà PowerShell ÏÂÔØºÍÖ´ÐÐÎļþºÍ¾ç±¾¡£Ñо¿Ö°Ô±»¹ÌåÏÖ£¬¹¥»÷Õß»¹°²ÅÅÁËÒ»ÖÖÔ¶³Ì»á¼û¹¤¾ß£¬Ëƺõ¿ÉÒÔÅÌÎÊÆäËû×éÖ¯µÄ Exchange ·þÎñÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN8k
5. ¹¥»÷ÕßʹÓÃTinyNuke ÒøÐжñÒâÈí¼þÕë¶Ô·¨¹ú×éÖ¯Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÏîרÃÅÕë¶ÔÔÚ·¨¹ú¿ªÕ¹ÓªÒµµÄ·¨¹úʵÌåºÍ×éÖ¯µÄÔ˶¯£¬ÆäÖаüÀ¨ÒøÐжñÒâÈí¼þTinyNuke¡£¹¥»÷ÕßʹÓÃÒÔ·¢Æ±ÎªÖ÷ÌâµÄÓÕ¶üÕë¶ÔÖÆÔì¡¢¹¤Òµ¡¢ÊÖÒÕ¡¢½ðÈÚºÍÆäËû±ÊÖ±ÁìÓòµÄʵÌå¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN8f
6. ¹¥»÷ÕßʹÓÃLog4jÎó²î×齨botnetÕë¶ÔLinux×°±¸Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Ê¹ÓÃAnglerfishºÍApacketÃÛ¹ÞÏȺ󲶻ñµ½2²¨Ê¹ÓÃLog4jÎó²î×齨botnetµÄ¹¥»÷£¬¿ìËÙµÄÑùÌìÖ°ÎöÅú×¢ËüÃÇ»®·ÖÓÃÓÚ×齨MuhstikºÍMirai botnet£¬Õë¶ÔµÄ¶¼ÊÇLinux×°±¸¡£²¢ÌåÏÖÐÂMuhstik±äÖÖÔöÌíÁËÒ»¸öºóÃÅÄ£¿éldm£¬Ëü¾ßÓÐÔöÌíSSHºóÃŹ«Ô¿µÄÄÜÁ¦¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7Q
7. ¹¥»÷ÕßʹÓÃAclipºóÃŹ¥»÷º½¿Õ¹«Ë¾
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÊӲ쵽¶ÔÒ»¼ÒÑÇÖÞº½¿Õ¹«Ë¾µÄ¹¥»÷£¬ËûÃÇÆÀ¹À¸Ã¹¥»÷ºÜ¿ÉÄܱ»¹ú¼Ò×ÊÖúµÄµÐÊÖʹÓÃʹÓÃSlackµÄкóÃÅÈëÇÖ¡£¹¥»÷ÕßʹÓÃSlackÉϵÄÃâ·ÑÊÂÇé¿Õ¼ä£¬ÕâÊÇÒ»ÖÖÕýµ±µÄÐÂÎÅת´ïºÍÐ×÷Ó¦ÓóÌÐò£¬¿ÉÄÜ»á»ìÏý²Ù×÷ͨѶ£¬´Ó¶øÊ¹¶ñÒâÁ÷Á¿»ò¾ßÓÐDZÔÚ¶ñÒâÒâͼµÄÁ÷Á¿±»ºöÊÓ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN8y
8. ¹¥»÷ÕßʹÓÃAnubisÌØÂåÒÁľÂí¹¥»÷ÒøÐпͻ§
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÌåÏÖÐÂÔ˶¯Î±×°³ÉOrange TelecomÕÊ»§ÖÎÀíÓ¦ÓóÌÐò£¬ÒÔÌṩAnubisÒøÐжñÒâÈí¼þµÄ×îа汾¡£´óÍ¨ÒøÐС¢¸»¹úÒøÐС¢ÃÀ¹úÒøÐк͵ÚÒ»×ÊÔ´µÄ¿Í»§ÒÔ¼°½ü400¼ÒÆäËû½ðÈÚ»ú¹¹Õý³ÉΪαװ³É·¨¹úµçÐŹ«Ë¾Orange SA¹Ù·½ÕË»§ÖÎÀíÆ½Ì¨µÄ¶ñÒâÓ¦ÓóÌÐòµÄÄ¿µÄ¡£Ò»µ©ÏÂÔØ£¬¶ñÒâÈí¼þ£¨Ò»ÖÖÒøÐÐľÂíAnubisµÄ±äÖÖ£©¾Í»áÇÔÈ¡Óû§µÄСÎÒ˽¼ÒÊý¾ÝÒÔ½«Æä͵ȡ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN8x
9. ¹¥»÷ÕßʹÓÃAgent TeslaбäÖÖ¶Ôº«¹úÌá³«ÍøÂç´¹ÂÚ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±½üÆÚ·¢Ã÷ÁËÕë¶Ôº«¹úÌᳫ¹¥»÷µÄÍøÂç´¹ÂÚ¹¥»÷£¬ÓʼþʹÓú«ÎÄÌÜд²¢ÒªÇóÊÕ¼þÈË·¿ª¸½¼þÖÐµÄ PowerPoint ÎļþÒÔÉó²é²É¹º¶©µ¥£¬¸Ã¶ñÒâPowerPoint Îļþ»áÈö²¥ Agent Tesla µÄбäÖÖ¡£Agent Tesla ÊÇÒ»¸ö .Net ±àдµÄ¶ñÒâÈí¼þ£¬Ö÷ÒªÓÃÓÚ´ÓʧÏÝÖ÷»úÉÏÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬Èç¼ôÌù°åÊý¾Ý¡¢¼üÅ̰´¼ü¼Í¼¡¢Èí¼þƾ֤£¨ä¯ÀÀÆ÷¡¢Óʼþ¡¢VPN¡¢FTP¡¢¼´Ê±Í¨Ñ¶Èí¼þµÈ£©¡¢ÆÁÄ»½ØÍ¼µÈ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN8V
10. ºÚ¿ÍʹÓöñÒâIIS·þÎñÆ÷Ä£¿éÇÔÈ¡Microsoft Exchangeƾ֤
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷¹¥»÷ÕßÕýÔÚMicrosoft Exchange Outlook Web Access ·þÎñÆ÷Éϰ²ÅÅÒ»¸öÒÔǰδ±»·¢Ã÷µÄ¶þ½øÖÆÎļþ£¬Ò»¸öÃûΪ“ Owowa ”µÄ Internet ÐÅÏ¢·þÎñ ( IIS ) ÍøÂç·þÎñÆ÷Ä£¿é£¬Ä¿µÄÊÇÇÔȡƾ֤²¢ÆôÓÃÔ¶³ÌÏÂÁîÖ´ÐС£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN8H

AG¹«Ë¾ÔÆ







