AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021.12£©

2022-01-04

12Ô £¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ £¬ÆäÖÐ £¬Apache Log4j2 Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44228£©ºÍWindows Active Directory Óò·þÎñȨÏÞÌáÉýÎó²î£¨CVE-2021-42287,CVE-2021-42278£©Ó°Ïì¹æÄ£Ïà¶Ô½Ï´ó¡£Ç°ÕßÓÉÓÚApache Log4j2ijЩ¹¦Ð§±£´æµÝ¹éÆÊÎö¹¦Ð§ £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÊâ½á¹¹µÄÊý¾ÝÇëÇó°ü £¬¿ÉÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë £¬CVSSÆÀ·Ö10.0¡£ºóÕßÓÉÓÚActive DirectoryûÓжÔÓòÖÐÅÌËãÆ÷Óë·þÎñÆ÷Õ˺ÅÃû¾ÙÐÐÑéÖ¤ £¬¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓøÃÎó²îÈÆ¹ýÇå¾²ÏÞÖÆ £¬¿É½«ÓòÖÐͨË×Óû§È¨ÏÞÌáÉýΪÓòÖÎÀíԱȨÏÞ²¢Ö´ÐÐí§Òâ´úÂë £¬CVSSÆÀ·Ö8.8¡£

ÁíÍâ £¬±¾´Î΢Èí¹²ÐÞ¸´ÁË67¸öÎó²î £¬°üÀ¨7¸öCritical¼¶±ðÎó²î £¬60¸öImportant ¼¶±ðÎó²î £¬ÆäÖаüÀ¨6¸ö0dayÎó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£

ÔÚ±¾ÔµÄÍþвÊÂÎñÖÐ £¬Õë¶ÔÔÆÖ÷»úµÄ¹¥»÷ÊÂÎñÏà¶ÔƵÈÔ £¬ÆäÖаüÀ¨¹¥»÷ÕßʹÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷ÔÆÖ÷»ú £¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷ £¬Óй¥»÷ÕßÕýÔÚÆð¾¢Ê¹ÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22205£©¹¥»÷ÔÆÖ÷»ú £¬Í¬Ê±Ö²ÈëÐÂÐͺóÃÅľÂíGitlab-daemon £¬¸ÃºóÃÅľÂíµÄ¹¥»÷Ô˶¯Òѱ»ÌÚѶÇ徲ͨ¹ýCyber-HolmesÒýÇæÈ«³ÌÆÊÎöÕÆÎÕ¡£ÆÊÎö·¢Ã÷ £¬¹¥»÷ÕßÒÑ¿ØÖÆÄ¿µÄϵͳƵÈÔ¸üкóÃųÌÐò £¬¹¥»÷ÕßÊ×ÏȽ«ºóÃÅαװΪ¿´ËÆËæ»úÃûµÄ.gzÎļþ £¬ÔÙʵÑéŲÓÃgunzip¾ÙÐнâѹºóÖ´ÐÐ £¬½è´ËαװÆä¶ñÒâÏÂÁîÖ´ÐвÙ×÷£»ÒÔ¼°¹¥»÷ÕßʹÓÃCERBERÀÕË÷Èí¼þͨ¹ýConfluence RCEµÈ¶à¸ö¸ßΣÎó²î¹¥»÷ÔÆÖ÷»ú £¬Ñо¿Ö°Ô±ÊӲ쵽´ó×ÚÓÐÓÃÔØºÉÊÔͼʹÓú£¿µÍþÊÓµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÀ´Ì½²â×°±¸×´Ì¬»ò´ÓÊܺ¦ÕßÄÇÀïÌáÈ¡Ãô¸ÐÊý¾Ý¡£ÌØÊâÊÇÒ»ÖÖÓÐÓÃÔØºÉÒýÆðÁËÑо¿Ö°Ô±µÄ×¢ÖØ¡£Ò»¸ö»ùÓÚ Mirai µÄ DDoS ½©Ê¬ÍøÂçÊÔͼɾ³ýÒ»¸öÌåÏÖ³öѬȾÐÐΪ²¢Ö´ÐÐ Moobot µÄÏÂÔØ³ÌÐò¡£¹¥»÷Õß¿ÉÒÔͨ¹ýº£¿µÍþÊÓÎó²î´«ËÍ´ËÓÐÓÃÔØºÉÌᳫÏÂÁî×¢Èë¹¥»÷ ¡£

ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨 £¬ÒÔ¼°¹ØÁªµÄIOC £¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡ £¬ÍøÖ·£ºhttps://nti.nsfocus.com/

Ò»¡¢ Îó²îÌ¬ÊÆ

2021Äê12ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼426¸öÎó²î, ÆäÖиßΣÎó²î23¸ö £¬Î¢Èí¸ßΣÎó²î12¸ö¡£

 

* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ £¬±¾±íÊý¾Ý×èÖ¹µ½2022.01.04

×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»

 

¶þ¡¢ ÍþвÊÂÎñ

1. Donot ×é֯ʹÓÃGoogleÔÆÅÌ·Ö·¢Ð¿î¶ñÒâ²å¼þÕë¶ÔWindowsÓëAndroid˫ƽ̨Ìᳫ¹¥»÷

¡¾±êÇ©¡¿Donot APT

¡¾Ê±¼ä¡¿2021-12-02

¡¾¼ò½é¡¿

¿ËÈÕ £¬Çå¾²Ñо¿Ôº·¢Ã÷Ò»ÆðDonot APT×éÖ¯½üÆÚ¹¥»÷Ô˶¯¡£Donot“¶ÇÄԳ攣¨APT-Q-38£©ÊÇÒÉËÆ¾ßÓÐÄÏÑÇÅä¾°µÄAPT×éÖ¯ £¬ÆäÖ÷ÒªÒÔÖܱ߹ú¼ÒµÄÕþ¸®»ú¹¹ ΪĿµÄ¾ÙÐÐÍøÂç¹¥»÷Ô˶¯ £¬Í¨³£ÒÔÇÔÈ¡Ãô¸ÐÐÅϢΪĿµÄ¡£¸Ã×éÖ¯¾ß±¸Õë¶ÔWindowsÓëAndroid˫ƽ̨µÄ¹¥»÷ÄÜÁ¦¡£Æ¾Ö¤Ñо¿Ö°Ô±¸ú×ÙÆÊÎö £¬Donot´Ë´ÎµÄ¹¥»÷Ô˶¯ÓÐÈçÏÂÌØµã£ºRTFÎĵµÖÐǶÈëPackage¹¤¾ß £¬·­¿ªºó×Ô¶¯ÊÍ·ÅÎļþµ½%temp%Ŀ¼¡¢C2²»ÔÙÓ²±àÂëµ½ÎļþÖÐ £¬¶øÊÇÓɵÚÈý·½ÍøÕ¾ÍйÜ£»´Ë´Î²¶»ñ¶à¸ö×é¼þ £¬Ïà±ÈÒÔǰ¹¦Ð§½ÏΪÍêÉÆ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN6A

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡11ÌõIOC £¬ÆäÖаüÀ¨11¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

2. ¹¥»÷ÕßʹÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷ÔÆÖ÷»ú

¡¾±êÇ©¡¿Gitlab-daemon

¡¾Ê±¼ä¡¿2021-12-02

¡¾¼ò½é¡¿

Çå¾²Ñо¿Ö°Ô±·¢Ã÷ £¬Óй¥»÷ÕßÕýÔÚÆð¾¢Ê¹ÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22205£©¹¥»÷ÔÆÖ÷»ú £¬Í¬Ê±Ö²ÈëÐÂÐͺóÃÅľÂíGitlab-daemon £¬¸ÃºóÃÅľÂíµÄ¹¥»÷Ô˶¯Òѱ»ÌÚѶÇ徲ͨ¹ýCyber-HolmesÒýÇæÈ«³ÌÆÊÎöÕÆÎÕ¡£ÆÊÎö·¢Ã÷ £¬¹¥»÷ÕßÒÑ¿ØÖÆÄ¿µÄϵͳƵÈÔ¸üкóÃųÌÐò £¬¹¥»÷ÕßÊ×ÏȽ«ºóÃÅαװΪ¿´ËÆËæ»úÃûµÄ.gzÎļþ £¬ÔÙʵÑéŲÓÃgunzip¾ÙÐнâѹºóÖ´ÐÐ £¬½è´ËαװÆä¶ñÒâÏÂÁîÖ´ÐвÙ×÷¡£ºóÃÅÖ´Ðкó½«×ÔÉíÖ²Èë*/gitlab/git-dataĿ¼Ï £¬ÓÃGitlab-daemonÎļþÃûαװ £¬ÒÔÓÕÆ­ÔËάְԱ¡£È»ºóдÈëÍýÏëʹÃüÆô¶¯Ïî £¬´ËʱºóÃŲ¢²»Ö±½ÓÅþÁ¬C2 £¬¶øÊÇÏÈÐÐÍ˳ö £¬ÆÚ´ýÍýÏëʹÃüÏÂÒ»´Î½«ÆäÀ­Æðʱ £¬ÔÙÖ´Ðиü½øÒ»²½µÄ¶ñÒ⹦Ч´úÂë¡£¶à´¦Ï¸½ÚÅú×¢¹¥»÷ÕßÏ£Íû½«×ÔÉíαװΪgitlabϵͳÎļþ £¬ÒÔʵÏÖ¶ÔÄ¿µÄϵͳµÄºã¾Ã¿ØÖÆ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN6z

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡7ÌõIOC £¬ÆäÖаüÀ¨1¸öIP £¬1¸öÓòÃûºÍ5¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

3. ¹¥»÷ÕßʹÓÃJavaScript ¶ñÒâÈí¼þѬȾwindows PC

¡¾±êÇ©¡¿RAT

¡¾Ê±¼ä¡¿2021-12-02

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±·¢Ã÷Ò»ÖÖеÄÒþ²ØJavaScript¼ÓÔØ³ÌÐòRATDispenserÒѱ»Ö¤Êµ¿ÉÓÃÓÚͨ¹ýÍøÂç´¹ÂÚ¹¥»÷ѬȾ¾ßÓÐÖÖÖÖÔ¶³Ì»á¼ûľÂí(RAT) µÄ×°±¸¡£Õâ¸öеļÓÔØÆ÷ÒѾ­ÓëÖÁÉٰ˸öÖ¼ÔÚÇÔÊØÐÅÏ¢²¢ÔÊÐí¹¥»÷Õß¿ØÖÆÄ¿µÄ×°±¸µÄ¶ñÒâÈí¼þ¼Ò×åѸËÙ½¨ÉèÁ˰²ÅÅÏàÖúͬ°é¹ØÏµ¡£Ñ¬È¾×îÏÈÓÚÍøÂç´¹ÂÚµç×ÓÓʼþ £¬ÆäÖаüÀ¨´øÓÐË«À©Õ¹Ãû“.TXT.js”µÄ¶ñÒâJavaScriptÎļþ¡£Windows ĬÈÏÒþ²ØÀ©Õ¹Ãû £¬Òò´ËÈôÊÇÊÕ¼þÈ˽«ÎļþÉúÑÄÔÚËûÃǵÄÅÌËã»úÉÏ £¬Ëü½«ÏÔʾΪÎÞº¦µÄÎı¾Îļþ¡£Õâ¸öÎı¾Îļþ¿ÉÒÔ±»ÑÏÖØ»ìÏýÒÔÈÆ¹ýÇå¾²Èí¼þµÄ¼ì²â £¬µ±ÄãË«»÷ÎļþÔËÐÐËüʱ £¬Ëü»á±»½âÂë¡£µ±¼ÓÔØÆ÷ÔËÐÐVBScriptÎļþ%TEMP%дÈëÎļþ¼ÐÖÐʱ £¬ÔËÐиÃÎļþ £¬¶ñÒâ´úÂë(RAT)ÏÂÔØÓÐÓøºÔØ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN6B

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡1ÌõIOC £¬ÆäÖаüÀ¨1ÌõURL£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

4. APT ¹¥»÷ÕßʹÓà ManageEngine ADSelfService Plus Èí¼þÖеÄÐÂÎó²îÌᳫ¹¥»÷

¡¾±êÇ©¡¿APT

¡¾Ê±¼ä¡¿2021-12-09

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±ÌåÏÖÔÚÈý¸öÔµÄʱ¼äÀï £¬Ò»¸ö¼á¶¨µÄ APT ¹¥»÷ÕßÌᳫÁ˶à´ÎÔ˶¯ £¬µ¼ÖÂÖÁÉÙ 13 ¸ö×éÖ¯Êܵ½Ë𺦡£Ò»Ð©ÊÜÓ°ÏìµÄ×é֝ɿ¼°ÃÀ¹úµÄÒªº¦»ù´¡ÉèÊ©²¿·Ö £¬°üÀ¨¹ú·À¡¢½»Í¨¡¢Ò½ÁƱ£½¡ºÍÄÜÔ´¡£¸Ã¹¥»÷ÕߵĵÚÒ»¸öÔ˶¯Ê¹ÓÃÁË Zoho ManageEngine ADSelfService Plus Èí¼þÖеÄÁãÈÕÎó²î¡£10 ÔÂÏÂÑ® £¬¸Ã¹¥»÷ÕßÌᳫÁË×î½üµÄÔ˶¯ £¬½«Öصã×ªÒÆµ½ Zoho ManageEngine ServiceDesk Plus Èí¼þÖÐÏÈǰδ¹ûÕæµÄÎó²î ( CVE-2021-44077 )¡£ÔÚʹÓôËÎó²îºó £¬¹¥»÷ÕßÉÏ´«ÁËÒ»¸öÐ嵀 dropper £¬ËüÔÚÊܺ¦ÍøÂçÉϰ²ÅÅÁË Godzilla webshel??l £¬Äܹ»Èƹý ADSelfService ºÍ ServiceDesk Plus ²úÆ·ÉϵÄÇå¾²¹ýÂËÆ÷¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN7L

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC £¬ÆäÖаüÀ¨2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

5. ScarCruft ×é֯ʹÓÃChinotto¶ñÒâÈí¼þ¹¥»÷³¯ÏÊDZÌÓÕߺÍÈËȨÔ˶¯¼Ò

¡¾±êÇ©¡¿Chinotto

¡¾Ê±¼ä¡¿2021-12-09

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±·¢Ã÷ScarCruftÐÂÒ»²¨Õë¶ÔÐÔÇ¿µÄ¼àÊÓ¹¥»÷Õë¶Ô³¯ÏÊDZÌÓÕß¡¢±¨µÀ³¯ÏÊÏà¹ØÐÂÎŵļÇÕßÒÔ¼°Ó볯ÏÊÓйصÄÕþ¸®×éÖ¯¼°³¯Ïʰ뵺µÈ¡£¸Ã¹¥»÷ÕßʹÓÃÁËÈýÖÖ¾ßÓÐÏàËÆ¹¦Ð§µÄChinotto ¶ñÒâÈí¼þ£ºÔÚ PowerShell ÖÐʵÏֵİ汾¡¢Windows ¿ÉÖ´ÐÐÎļþºÍ Android Ó¦ÓóÌÐò¡£Ö»¹ÜÕë¶Ô²î±ðµÄƽ̨ £¬µ«ËüÃǹ²Ïí»ùÓÚ HTTP ͨѶµÄÀàËÆÏÂÁîºÍ¿ØÖƼƻ®¡£Òò´Ë £¬¶ñÒâÈí¼þ²Ù×÷Õß¿ÉÒÔͨ¹ýÒ»×éÏÂÁîºÍ¿ØÖƽÅÔ­À´¿ØÖÆÕû¸ö¶ñÒâÈí¼þ¼Ò×å¡£ÔÚÖ÷»úÊÓ²ìÖÐÑо¿Ö°Ô±ÌåÏÖÁËÒ»¸ö¶ñÒâµÄ Windows ¿ÉÖ´ÐÐÎļþ £¬¸ÃÎļþ°üÀ¨¹¹½¨Â·¾¶¡£¶øChinotto ¶ñÒâÈí¼þµÄ Android Ó¦ÓóÌÐò°æ±¾£¨MD5 56f3d2bcf67cf9f7b7d16ce8a5f8140a£©¡£Õâ¸ö¶ñÒâ APK ƾ֤ AndroidManifest.xml ÎļþÇëÇó¹ý¶àµÄȨÏÞ £¬ÎªÁ˵ִï¼àÊÓÓû§µÄÄ¿µÄ £¬ÕâЩӦÓóÌÐòÒªÇóÓû§ÆôÓÃÖÖÖÖȨÏÞ¡£ÊÚÓèÕâЩȨÏÞÔÊÐíÓ¦ÓóÌÐòÍøÂçÃô¸ÐÐÅÏ¢ £¬°üÀ¨ÁªÏµÈË¡¢ÐÂÎÅ¡¢Í¨»°¼Í¼¡¢×°±¸ÐÅÏ¢ºÍ¼Òô¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN7M

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡18ÌõIOC £¬ÆäÖаüÀ¨18¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

6. ¹¥»÷ÕßʹÓÃEwDoor½©Ê¬ÍøÂçÕë¶ÔAT¿Í»§ÌᳫDDoS ¹¥»÷

¡¾±êÇ©¡¿EwDoor

¡¾Ê±¼ä¡¿2021-12-09

¡¾¼ò½é¡¿

Çå¾²Ñо¿ÊµÑéÊÒµÄר¼Ò·¢Ã÷ÁËÒ»ÖÖÃûΪEwDoorµÄн©Ê¬ÍøÂç £¬ ËüÕë¶ÔʹÓùûÕæÌ»Â¶ÓÚ Internet µÄ EdgeMarc ÆóÒµ»á»°½çÏß¿ØÖÆÆ÷ (ESBC) ±ßÑØ×°±¸µÄ AT ¿Í»§¡£×¨¼Ò×¢ÖØµ½ EwDoor¶ÔÆäC2ʹÓÃÁ˱¸·Ý»úÖÆ £¬²¢×¢²áÁËÒ»¸ö±¸·ÝÏÂÁîºÍ¿ØÖÆ(C2)Óò (iunno.se)À´ÆÊÎöÊÜѬȾװ±¸µÄÅþÁ¬¡£²¢ÇÒ½©Ê¬ÍøÂçʵÑéÁËһϵÁб£»¤²½·¥ÒÔ±ÜÃâÇ徲ר¼ÒµÄÆÊÎö £¬ÀýÈçʹÓÃTLSЭÒé±ÜÃâͨѶ±»×èµ² £¬¼ÓÃÜÃô¸Ð×ÊԴʹÆäÄÑÒÔÄæÏò¹¤³ÌÒÔ¼°½«C2ÒÆÖÁÔÆ¶Ë²¢ÓÉBT¸ú×ÙÆ÷·¢ËͱÜÃâ±»IOCϵͳֱ½ÓÌáÈ¡¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN7N

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡29ÌõIOC £¬ÆäÖаüÀ¨2¸öIP £¬11¸öÓòÃûºÍ16¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

7. ¹¥»÷ÕßʹÓûùÓÚMiraiµÄ½©Ê¬ÍøÂçMoobot¹¥»÷º£¿µÍþÊÓ

¡¾±êÇ©¡¿Moobot

¡¾Ê±¼ä¡¿2021-12-16

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±ÊӲ쵽´ó×ÚÓÐÓÃÔØºÉÊÔͼʹÓú£¿µÍþÊÓµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÀ´Ì½²â×°±¸×´Ì¬»ò´ÓÊܺ¦ÕßÄÇÀïÌáÈ¡Ãô¸ÐÊý¾Ý¡£ÌØÊâÊÇÒ»ÖÖÓÐÓÃÔØºÉÒýÆðÁËÑо¿Ö°Ô±µÄ×¢ÖØ¡£Ò»¸ö»ùÓÚ Mirai µÄ DDoS ½©Ê¬ÍøÂçÊÔͼɾ³ýÒ»¸öÌåÏÖ³öѬȾÐÐΪ²¢Ö´ÐÐ Moobot µÄÏÂÔØ³ÌÐò¡£¹¥»÷Õß¿ÉÒÔͨ¹ýº£¿µÍþÊÓÎó²î´«ËÍ´ËÓÐÓÃÔØºÉÌᳫÏÂÁî×¢Èë¹¥»÷ ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN9q

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC £¬ÆäÖаüÀ¨2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

8. ¹¥»÷ÕßʹÓÃCERBERÀÕË÷Èí¼þͨ¹ýConfluence RCEµÈ¶à¸ö¸ßΣÎó²î¹¥»÷ÔÆÖ÷»ú

¡¾±êÇ©¡¿CERBERÀÕË÷Èí¼þ

¡¾Ê±¼ä¡¿2021-12-16

¡¾¼ò½é¡¿

Ç徲ר¼Ò·¢Ã÷CERBERÀÕË÷Èí¼þÈö²¥ÕßʹÓÃAtlassian ConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26084£©ºÍGitLab exiftool Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2021-22205)¹¥»÷ÔÆÉÏÖ÷»ú¡£Ç°Õß £¬ÊÇÒ»¸ö¹¤¾ßͼµ¼º½ÓïÑÔ (ONGL) ×¢ÈëÎó²î £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ Confluence Server »òData CenterʵÀýÉÏÖ´ÐÐí§Òâ´úÂë £¬¹¥»÷ÕßʹÓÃÎó²î¿ÉÍêÈ«¿ØÖÆ·þÎñÆ÷¡£ºóÕßÓÉÓÚGitlabijЩ¶Ëµã·¾¶ÎÞÐèÊÚȨ £¬¹¥»÷Õß¿ÉÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏÂʹÓÃͼƬÉÏ´«¹¦Ð§Ö´ÐÐí§Òâ´úÂë £¬¹¥»÷ÕßʹÓÃÎó²îͬÑù¿ÉÒÔÍêÈ«¿ØÖÆ·þÎñÆ÷¡£±»ÀÕË÷Èí¼þ¼ÓÃÜÆÆËðµÄÎļþÎÞÃÜÔ¿Ôݲ»¿É½âÃÜ £¬Ç徲ר¼Ò½¨ÒéËùÓÐÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´Îó²î £¬×èÖ¹Ôì³ÉÊý¾ÝÍêÈ«Ëðʧ £¬ÓªÒµ³¹µ×Í߽⡣

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN9o

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC £¬ÆäÖаüÀ¨1¸öIPºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

9. ¹¥»÷ÕßÔÚ»ùÓÚDark MiraiµÄMANGAÔ˶¯ÖÐʹÓöñÒâÈí¼þ¹¥»÷TP-LinkÎÞÏß·ÓÉÆ÷

¡¾±êÇ©¡¿¶ñÒâÈí¼þ

¡¾Ê±¼ä¡¿2021-12-16

¡¾¼ò½é¡¿

Ç徲ʵÑéÊÒÍŶӷ¢Ã÷ÁËÒ»¸ö¶ñÒâÈí¼þÑù±¾ £¬ÊÇ MANGA Ô˶¯£¨Ò²³ÆÎª Dark£©µÄ¸üбäÌå £¬Ëüƾ֤ Mirai ÒÑÐû²¼µÄÔ´´úÂëÕýÔÚÒ°Íâ·Ö·¢Ñù±¾ £¬Ä¿µÄÊÇ TP-link ÎÞÏß·ÓÉÆ÷¡£ËüʹÓÃ×î½üÁ½ÖÜǰÐû²¼µÄ¾­ÓÉÉí·ÝÑéÖ¤µÄ RCE Îó²îÅû¶ʱ¼äÓëÓ¦Óò¹¶¡À´ÆÆËðÎïÁªÍø×°±¸Ö®¼äµÄ²î±ð¡£Ñо¿Ö°Ô±ÌåÏÖÓë Mirai µÄÕý³£Ñ¬È¾³ÌÐòÒ»Ñù £¬Ö´ÐÐµÄ shell ¾ç±¾ÏÂÔØ²î±ð¼Ü¹¹Ç徲̨µÄÖ÷ÒªÓÐÓÃÔØºÉ¶þ½øÖÆÎļþ £¬²¢ÔÚÊܺ¦ÕßϵͳÖÐäĿִÐС£±ðµÄ £¬Ëü»¹Í¨¹ý×èÖ¹Óë³£¼ûÄ¿µÄ¶Ë¿ÚµÄÅþÁ¬À´±ÜÃâÆäËû½©Ê¬ÍøÂç½ÓÊÜ×°±¸¡£È»ºó £¬¶ñÒâÈí¼þÆÚ´ýÀ´×ÔÆäÏÂÁîºÍ¿ØÖÆ (C2) ·þÎñÆ÷µÄÏÂÁîÀ´Ö´Ðоܾø·þÎñ (DOS) ¹¥»÷µÄ²î±ð±äÌå¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN9r

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡23ÌõIOC £¬ÆäÖаüÀ¨23¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

10. ¹¥»÷ÕßʹÓÃLog4j Îó²îÕë¶Ô Linux ϵͳÌᳫ¹¥»÷

¡¾±êÇ©¡¿Log4j Îó²î

¡¾Ê±¼ä¡¿2021-12-23

¡¾¼ò½é¡¿

Çå¾²Ñо¿Ôº²¶»ñÁË 2 ²¨Ê¹Óà Log4j Îó²îÐγɽ©Ê¬ÍøÂçµÄ¹¥»÷ £¬²¢ÇÒ¿ìËÙÑùÌìÖ°ÎöÅú×¢ËüÃÇ»®·ÖÓÃÓÚÐÎ³É Muhstik ºÍ Mirai ½©Ê¬ÍøÂç £¬¾ùÕë¶Ô Linux ×°±¸¡£²¢ÌåÏÖÐ嵀 Muhstik ±äÌåÌí¼ÓÁËÒ»¸öºóÃÅÄ£¿é ldm £¬ËüÄܹ»Ê¹ÓÃ×°ÖõĺóÃŹ«Ô¿Ìí¼Ó SSH ºóÃŹ«Ô¿¡£½«¹«Ô¿Ìí¼Óµ½~/.ssh/authorized_keys Îļþºó £¬¹¥»÷ÕßÎÞÐèÃÜÂëÑéÖ¤¼´¿ÉÖ±½ÓµÇ¼Զ³Ì·þÎñÆ÷¡£Ë¼Á¿µ½ log4j2 µÄÌØÊâÎó²î»úÖÆ £¬Muhstik ½ÓÄÉÁËÒ»ÖÖÉúÓ²µÄ·½·¨ £¬ÔÚÖªµÀ»áÓÐÎó²î»úеµÄÇéÐÎÏÂÂþÎÞÄ¿µÄµØÈö²¥payload £¬²¢ÇÒΪÁËÖªµÀË­ÒѾ­±»Ñ¬È¾ £¬Muhstik ½ÓÄÉ TOR ÍøÂç×÷ΪÆä±¨¸æ»úÖÆ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNam

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC £¬ÆäÖаüÀ¨2¸öÓòÃû£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼ £¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼