¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021.12£©
2022-01-04
12Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬Apache Log4j2 Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44228£©ºÍWindows Active Directory Óò·þÎñȨÏÞÌáÉýÎó²î£¨CVE-2021-42287,CVE-2021-42278£©Ó°Ïì¹æÄ£Ïà¶Ô½Ï´ó¡£Ç°ÕßÓÉÓÚApache Log4j2ijЩ¹¦Ð§±£´æµÝ¹éÆÊÎö¹¦Ð§£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÊâ½á¹¹µÄÊý¾ÝÇëÇó°ü£¬¿ÉÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂ룬CVSSÆÀ·Ö10.0¡£ºóÕßÓÉÓÚActive DirectoryûÓжÔÓòÖÐÅÌËãÆ÷Óë·þÎñÆ÷Õ˺ÅÃû¾ÙÐÐÑéÖ¤£¬¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓøÃÎó²îÈÆ¹ýÇå¾²ÏÞÖÆ£¬¿É½«ÓòÖÐͨË×Óû§È¨ÏÞÌáÉýΪÓòÖÎÀíԱȨÏÞ²¢Ö´ÐÐí§Òâ´úÂ룬CVSSÆÀ·Ö8.8¡£
ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË67¸öÎó²î£¬°üÀ¨7¸öCritical¼¶±ðÎó²î£¬60¸öImportant ¼¶±ðÎó²î£¬ÆäÖаüÀ¨6¸ö0dayÎó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬Õë¶ÔÔÆÖ÷»úµÄ¹¥»÷ÊÂÎñÏà¶ÔƵÈÔ£¬ÆäÖаüÀ¨¹¥»÷ÕßʹÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷ÔÆÖ÷»ú£¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬Óй¥»÷ÕßÕýÔÚÆð¾¢Ê¹ÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22205£©¹¥»÷ÔÆÖ÷»ú£¬Í¬Ê±Ö²ÈëÐÂÐͺóÃÅľÂíGitlab-daemon£¬¸ÃºóÃÅľÂíµÄ¹¥»÷Ô˶¯Òѱ»ÌÚѶÇ徲ͨ¹ýCyber-HolmesÒýÇæÈ«³ÌÆÊÎöÕÆÎÕ¡£ÆÊÎö·¢Ã÷£¬¹¥»÷ÕßÒÑ¿ØÖÆÄ¿µÄϵͳƵÈÔ¸üкóÃųÌÐò£¬¹¥»÷ÕßÊ×ÏȽ«ºóÃÅαװΪ¿´ËÆËæ»úÃûµÄ.gzÎļþ£¬ÔÙʵÑéŲÓÃgunzip¾ÙÐнâѹºóÖ´ÐУ¬½è´ËαװÆä¶ñÒâÏÂÁîÖ´ÐвÙ×÷£»ÒÔ¼°¹¥»÷ÕßʹÓÃCERBERÀÕË÷Èí¼þͨ¹ýConfluence RCEµÈ¶à¸ö¸ßΣÎó²î¹¥»÷ÔÆÖ÷»ú£¬Ñо¿Ö°Ô±ÊӲ쵽´ó×ÚÓÐÓÃÔØºÉÊÔͼʹÓú£¿µÍþÊÓµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÀ´Ì½²â×°±¸×´Ì¬»ò´ÓÊܺ¦ÕßÄÇÀïÌáÈ¡Ãô¸ÐÊý¾Ý¡£ÌØÊâÊÇÒ»ÖÖÓÐÓÃÔØºÉÒýÆðÁËÑо¿Ö°Ô±µÄ×¢ÖØ¡£Ò»¸ö»ùÓÚ Mirai µÄ DDoS ½©Ê¬ÍøÂçÊÔͼɾ³ýÒ»¸öÌåÏÖ³öѬȾÐÐΪ²¢Ö´ÐÐ Moobot µÄÏÂÔØ³ÌÐò¡£¹¥»÷Õß¿ÉÒÔͨ¹ýº£¿µÍþÊÓÎó²î´«ËÍ´ËÓÐÓÃÔØºÉÌᳫÏÂÁî×¢Èë¹¥»÷ ¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2021Äê12ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼426¸öÎó²î, ÆäÖиßΣÎó²î23¸ö£¬Î¢Èí¸ßΣÎó²î12¸ö¡£
* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2022.01.04
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. Donot ×é֯ʹÓÃGoogleÔÆÅÌ·Ö·¢Ð¿î¶ñÒâ²å¼þÕë¶ÔWindowsÓëAndroid˫ƽ̨Ìᳫ¹¥»÷
¡¾±êÇ©¡¿Donot APT
¡¾Ê±¼ä¡¿2021-12-02
¡¾¼ò½é¡¿
¿ËÈÕ£¬Çå¾²Ñо¿Ôº·¢Ã÷Ò»ÆðDonot APT×éÖ¯½üÆÚ¹¥»÷Ô˶¯¡£Donot“¶ÇÄԳ攣¨APT-Q-38£©ÊÇÒÉËÆ¾ßÓÐÄÏÑÇÅä¾°µÄAPT×éÖ¯£¬ÆäÖ÷ÒªÒÔÖܱ߹ú¼ÒµÄÕþ¸®»ú¹¹ ΪĿµÄ¾ÙÐÐÍøÂç¹¥»÷Ô˶¯£¬Í¨³£ÒÔÇÔÈ¡Ãô¸ÐÐÅϢΪĿµÄ¡£¸Ã×éÖ¯¾ß±¸Õë¶ÔWindowsÓëAndroid˫ƽ̨µÄ¹¥»÷ÄÜÁ¦¡£Æ¾Ö¤Ñо¿Ö°Ô±¸ú×ÙÆÊÎö£¬Donot´Ë´ÎµÄ¹¥»÷Ô˶¯ÓÐÈçÏÂÌØµã£ºRTFÎĵµÖÐǶÈëPackage¹¤¾ß£¬·¿ªºó×Ô¶¯ÊÍ·ÅÎļþµ½%temp%Ŀ¼¡¢C2²»ÔÙÓ²±àÂëµ½ÎļþÖУ¬¶øÊÇÓɵÚÈý·½ÍøÕ¾Íйܣ»´Ë´Î²¶»ñ¶à¸ö×é¼þ£¬Ïà±ÈÒÔǰ¹¦Ð§½ÏΪÍêÉÆ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN6A
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡11ÌõIOC£¬ÆäÖаüÀ¨11¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. ¹¥»÷ÕßʹÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷ÔÆÖ÷»ú
¡¾±êÇ©¡¿Gitlab-daemon
¡¾Ê±¼ä¡¿2021-12-02
¡¾¼ò½é¡¿
Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬Óй¥»÷ÕßÕýÔÚÆð¾¢Ê¹ÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22205£©¹¥»÷ÔÆÖ÷»ú£¬Í¬Ê±Ö²ÈëÐÂÐͺóÃÅľÂíGitlab-daemon£¬¸ÃºóÃÅľÂíµÄ¹¥»÷Ô˶¯Òѱ»ÌÚѶÇ徲ͨ¹ýCyber-HolmesÒýÇæÈ«³ÌÆÊÎöÕÆÎÕ¡£ÆÊÎö·¢Ã÷£¬¹¥»÷ÕßÒÑ¿ØÖÆÄ¿µÄϵͳƵÈÔ¸üкóÃųÌÐò£¬¹¥»÷ÕßÊ×ÏȽ«ºóÃÅαװΪ¿´ËÆËæ»úÃûµÄ.gzÎļþ£¬ÔÙʵÑéŲÓÃgunzip¾ÙÐнâѹºóÖ´ÐУ¬½è´ËαװÆä¶ñÒâÏÂÁîÖ´ÐвÙ×÷¡£ºóÃÅÖ´Ðкó½«×ÔÉíÖ²Èë*/gitlab/git-dataĿ¼Ï£¬ÓÃGitlab-daemonÎļþÃûαװ£¬ÒÔÓÕÆÔËάְԱ¡£È»ºóдÈëÍýÏëʹÃüÆô¶¯Ï´ËʱºóÃŲ¢²»Ö±½ÓÅþÁ¬C2£¬¶øÊÇÏÈÐÐÍ˳ö£¬ÆÚ´ýÍýÏëʹÃüÏÂÒ»´Î½«ÆäÀÆðʱ£¬ÔÙÖ´Ðиü½øÒ»²½µÄ¶ñÒ⹦Ч´úÂë¡£¶à´¦Ï¸½ÚÅú×¢¹¥»÷ÕßÏ£Íû½«×ÔÉíαװΪgitlabϵͳÎļþ£¬ÒÔʵÏÖ¶ÔÄ¿µÄϵͳµÄºã¾Ã¿ØÖÆ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN6z
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡7ÌõIOC£¬ÆäÖаüÀ¨1¸öIP£¬1¸öÓòÃûºÍ5¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. ¹¥»÷ÕßʹÓÃJavaScript ¶ñÒâÈí¼þѬȾwindows PC
¡¾±êÇ©¡¿RAT
¡¾Ê±¼ä¡¿2021-12-02
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±·¢Ã÷Ò»ÖÖеÄÒþ²ØJavaScript¼ÓÔØ³ÌÐòRATDispenserÒѱ»Ö¤Êµ¿ÉÓÃÓÚͨ¹ýÍøÂç´¹ÂÚ¹¥»÷ѬȾ¾ßÓÐÖÖÖÖÔ¶³Ì»á¼ûľÂí(RAT) µÄ×°±¸¡£Õâ¸öеļÓÔØÆ÷ÒѾÓëÖÁÉٰ˸öÖ¼ÔÚÇÔÊØÐÅÏ¢²¢ÔÊÐí¹¥»÷Õß¿ØÖÆÄ¿µÄ×°±¸µÄ¶ñÒâÈí¼þ¼Ò×åѸËÙ½¨ÉèÁ˰²ÅÅÏàÖúͬ°é¹ØÏµ¡£Ñ¬È¾×îÏÈÓÚÍøÂç´¹ÂÚµç×ÓÓʼþ£¬ÆäÖаüÀ¨´øÓÐË«À©Õ¹Ãû“.TXT.js”µÄ¶ñÒâJavaScriptÎļþ¡£Windows ĬÈÏÒþ²ØÀ©Õ¹Ãû£¬Òò´ËÈôÊÇÊÕ¼þÈ˽«ÎļþÉúÑÄÔÚËûÃǵÄÅÌËã»úÉÏ£¬Ëü½«ÏÔʾΪÎÞº¦µÄÎı¾Îļþ¡£Õâ¸öÎı¾Îļþ¿ÉÒÔ±»ÑÏÖØ»ìÏýÒÔÈÆ¹ýÇå¾²Èí¼þµÄ¼ì²â£¬µ±ÄãË«»÷ÎļþÔËÐÐËüʱ£¬Ëü»á±»½âÂë¡£µ±¼ÓÔØÆ÷ÔËÐÐVBScriptÎļþ%TEMP%дÈëÎļþ¼ÐÖÐʱ£¬ÔËÐиÃÎļþ£¬¶ñÒâ´úÂë(RAT)ÏÂÔØÓÐÓøºÔØ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN6B
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡1ÌõIOC£¬ÆäÖаüÀ¨1ÌõURL£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. APT ¹¥»÷ÕßʹÓà ManageEngine ADSelfService Plus Èí¼þÖеÄÐÂÎó²îÌᳫ¹¥»÷
¡¾±êÇ©¡¿APT
¡¾Ê±¼ä¡¿2021-12-09
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±ÌåÏÖÔÚÈý¸öÔµÄʱ¼äÀһ¸ö¼á¶¨µÄ APT ¹¥»÷ÕßÌᳫÁ˶à´ÎÔ˶¯£¬µ¼ÖÂÖÁÉÙ 13 ¸ö×éÖ¯Êܵ½Ë𺦡£Ò»Ð©ÊÜÓ°ÏìµÄ×é֝ɿ¼°ÃÀ¹úµÄÒªº¦»ù´¡ÉèÊ©²¿·Ö£¬°üÀ¨¹ú·À¡¢½»Í¨¡¢Ò½ÁƱ£½¡ºÍÄÜÔ´¡£¸Ã¹¥»÷ÕߵĵÚÒ»¸öÔ˶¯Ê¹ÓÃÁË Zoho ManageEngine ADSelfService Plus Èí¼þÖеÄÁãÈÕÎó²î¡£10 ÔÂÏÂÑ®£¬¸Ã¹¥»÷ÕßÌᳫÁË×î½üµÄÔ˶¯£¬½«Öصã×ªÒÆµ½ Zoho ManageEngine ServiceDesk Plus Èí¼þÖÐÏÈǰδ¹ûÕæµÄÎó²î ( CVE-2021-44077 )¡£ÔÚʹÓôËÎó²îºó£¬¹¥»÷ÕßÉÏ´«ÁËÒ»¸öÐ嵀 dropper£¬ËüÔÚÊܺ¦ÍøÂçÉϰ²ÅÅÁË Godzilla webshel??l£¬Äܹ»Èƹý ADSelfService ºÍ ServiceDesk Plus ²úÆ·ÉϵÄÇå¾²¹ýÂËÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7L
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. ScarCruft ×é֯ʹÓÃChinotto¶ñÒâÈí¼þ¹¥»÷³¯ÏÊDZÌÓÕߺÍÈËȨÔ˶¯¼Ò
¡¾±êÇ©¡¿Chinotto
¡¾Ê±¼ä¡¿2021-12-09
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±·¢Ã÷ScarCruftÐÂÒ»²¨Õë¶ÔÐÔÇ¿µÄ¼àÊÓ¹¥»÷Õë¶Ô³¯ÏÊDZÌÓÕß¡¢±¨µÀ³¯ÏÊÏà¹ØÐÂÎŵļÇÕßÒÔ¼°Ó볯ÏÊÓйصÄÕþ¸®×éÖ¯¼°³¯Ïʰ뵺µÈ¡£¸Ã¹¥»÷ÕßʹÓÃÁËÈýÖÖ¾ßÓÐÏàËÆ¹¦Ð§µÄChinotto ¶ñÒâÈí¼þ£ºÔÚ PowerShell ÖÐʵÏֵİ汾¡¢Windows ¿ÉÖ´ÐÐÎļþºÍ Android Ó¦ÓóÌÐò¡£Ö»¹ÜÕë¶Ô²î±ðµÄƽ̨£¬µ«ËüÃǹ²Ïí»ùÓÚ HTTP ͨѶµÄÀàËÆÏÂÁîºÍ¿ØÖƼƻ®¡£Òò´Ë£¬¶ñÒâÈí¼þ²Ù×÷Õß¿ÉÒÔͨ¹ýÒ»×éÏÂÁîºÍ¿ØÖƽÅÔÀ´¿ØÖÆÕû¸ö¶ñÒâÈí¼þ¼Ò×å¡£ÔÚÖ÷»úÊÓ²ìÖÐÑо¿Ö°Ô±ÌåÏÖÁËÒ»¸ö¶ñÒâµÄ Windows ¿ÉÖ´ÐÐÎļþ£¬¸ÃÎļþ°üÀ¨¹¹½¨Â·¾¶¡£¶øChinotto ¶ñÒâÈí¼þµÄ Android Ó¦ÓóÌÐò°æ±¾£¨MD5 56f3d2bcf67cf9f7b7d16ce8a5f8140a£©¡£Õâ¸ö¶ñÒâ APK ƾ֤ AndroidManifest.xml ÎļþÇëÇó¹ý¶àµÄȨÏÞ£¬ÎªÁ˵ִï¼àÊÓÓû§µÄÄ¿µÄ£¬ÕâЩӦÓóÌÐòÒªÇóÓû§ÆôÓÃÖÖÖÖȨÏÞ¡£ÊÚÓèÕâЩȨÏÞÔÊÐíÓ¦ÓóÌÐòÍøÂçÃô¸ÐÐÅÏ¢£¬°üÀ¨ÁªÏµÈË¡¢ÐÂÎÅ¡¢Í¨»°¼Í¼¡¢×°±¸ÐÅÏ¢ºÍ¼Òô¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7M
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡18ÌõIOC£¬ÆäÖаüÀ¨18¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. ¹¥»÷ÕßʹÓÃEwDoor½©Ê¬ÍøÂçÕë¶ÔAT¿Í»§ÌᳫDDoS ¹¥»÷
¡¾±êÇ©¡¿EwDoor
¡¾Ê±¼ä¡¿2021-12-09
¡¾¼ò½é¡¿
Çå¾²Ñо¿ÊµÑéÊÒµÄר¼Ò·¢Ã÷ÁËÒ»ÖÖÃûΪEwDoorµÄн©Ê¬ÍøÂ磬 ËüÕë¶ÔʹÓùûÕæÌ»Â¶ÓÚ Internet µÄ EdgeMarc ÆóÒµ»á»°½çÏß¿ØÖÆÆ÷ (ESBC) ±ßÑØ×°±¸µÄ AT ¿Í»§¡£×¨¼Ò×¢ÖØµ½ EwDoor¶ÔÆäC2ʹÓÃÁ˱¸·Ý»úÖÆ£¬²¢×¢²áÁËÒ»¸ö±¸·ÝÏÂÁîºÍ¿ØÖÆ(C2)Óò (iunno.se)À´ÆÊÎöÊÜѬȾװ±¸µÄÅþÁ¬¡£²¢ÇÒ½©Ê¬ÍøÂçʵÑéÁËһϵÁб£»¤²½·¥ÒÔ±ÜÃâÇ徲ר¼ÒµÄÆÊÎö£¬ÀýÈçʹÓÃTLSÐÒé±ÜÃâͨѶ±»×èµ²£¬¼ÓÃÜÃô¸Ð×ÊԴʹÆäÄÑÒÔÄæÏò¹¤³ÌÒÔ¼°½«C2ÒÆÖÁÔÆ¶Ë²¢ÓÉBT¸ú×ÙÆ÷·¢ËͱÜÃâ±»IOCϵͳֱ½ÓÌáÈ¡¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN7N
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡29ÌõIOC£¬ÆäÖаüÀ¨2¸öIP£¬11¸öÓòÃûºÍ16¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
7. ¹¥»÷ÕßʹÓûùÓÚMiraiµÄ½©Ê¬ÍøÂçMoobot¹¥»÷º£¿µÍþÊÓ
¡¾±êÇ©¡¿Moobot
¡¾Ê±¼ä¡¿2021-12-16
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±ÊӲ쵽´ó×ÚÓÐÓÃÔØºÉÊÔͼʹÓú£¿µÍþÊÓµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÀ´Ì½²â×°±¸×´Ì¬»ò´ÓÊܺ¦ÕßÄÇÀïÌáÈ¡Ãô¸ÐÊý¾Ý¡£ÌØÊâÊÇÒ»ÖÖÓÐÓÃÔØºÉÒýÆðÁËÑо¿Ö°Ô±µÄ×¢ÖØ¡£Ò»¸ö»ùÓÚ Mirai µÄ DDoS ½©Ê¬ÍøÂçÊÔͼɾ³ýÒ»¸öÌåÏÖ³öѬȾÐÐΪ²¢Ö´ÐÐ Moobot µÄÏÂÔØ³ÌÐò¡£¹¥»÷Õß¿ÉÒÔͨ¹ýº£¿µÍþÊÓÎó²î´«ËÍ´ËÓÐÓÃÔØºÉÌᳫÏÂÁî×¢Èë¹¥»÷ ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9q
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
8. ¹¥»÷ÕßʹÓÃCERBERÀÕË÷Èí¼þͨ¹ýConfluence RCEµÈ¶à¸ö¸ßΣÎó²î¹¥»÷ÔÆÖ÷»ú
¡¾±êÇ©¡¿CERBERÀÕË÷Èí¼þ
¡¾Ê±¼ä¡¿2021-12-16
¡¾¼ò½é¡¿
Ç徲ר¼Ò·¢Ã÷CERBERÀÕË÷Èí¼þÈö²¥ÕßʹÓÃAtlassian ConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26084£©ºÍGitLab exiftool Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2021-22205)¹¥»÷ÔÆÉÏÖ÷»ú¡£Ç°Õߣ¬ÊÇÒ»¸ö¹¤¾ßͼµ¼º½ÓïÑÔ (ONGL) ×¢ÈëÎó²î£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ Confluence Server »òData CenterʵÀýÉÏÖ´ÐÐí§Òâ´úÂ룬¹¥»÷ÕßʹÓÃÎó²î¿ÉÍêÈ«¿ØÖÆ·þÎñÆ÷¡£ºóÕßÓÉÓÚGitlabijЩ¶Ëµã·¾¶ÎÞÐèÊÚȨ£¬¹¥»÷Õß¿ÉÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏÂʹÓÃͼƬÉÏ´«¹¦Ð§Ö´ÐÐí§Òâ´úÂ룬¹¥»÷ÕßʹÓÃÎó²îͬÑù¿ÉÒÔÍêÈ«¿ØÖÆ·þÎñÆ÷¡£±»ÀÕË÷Èí¼þ¼ÓÃÜÆÆËðµÄÎļþÎÞÃÜÔ¿Ôݲ»¿É½âÃÜ£¬Ç徲ר¼Ò½¨ÒéËùÓÐÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´Îó²î£¬×èÖ¹Ôì³ÉÊý¾ÝÍêÈ«Ëðʧ£¬ÓªÒµ³¹µ×Í߽⡣
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9o
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
9. ¹¥»÷ÕßÔÚ»ùÓÚDark MiraiµÄMANGAÔ˶¯ÖÐʹÓöñÒâÈí¼þ¹¥»÷TP-LinkÎÞÏß·ÓÉÆ÷
¡¾±êÇ©¡¿¶ñÒâÈí¼þ
¡¾Ê±¼ä¡¿2021-12-16
¡¾¼ò½é¡¿
Ç徲ʵÑéÊÒÍŶӷ¢Ã÷ÁËÒ»¸ö¶ñÒâÈí¼þÑù±¾£¬ÊÇ MANGA Ô˶¯£¨Ò²³ÆÎª Dark£©µÄ¸üбäÌ壬Ëüƾ֤ Mirai ÒÑÐû²¼µÄÔ´´úÂëÕýÔÚÒ°Íâ·Ö·¢Ñù±¾£¬Ä¿µÄÊÇ TP-link ÎÞÏß·ÓÉÆ÷¡£ËüʹÓÃ×î½üÁ½ÖÜǰÐû²¼µÄ¾ÓÉÉí·ÝÑéÖ¤µÄ RCE Îó²îÅû¶ʱ¼äÓëÓ¦Óò¹¶¡À´ÆÆËðÎïÁªÍø×°±¸Ö®¼äµÄ²î±ð¡£Ñо¿Ö°Ô±ÌåÏÖÓë Mirai µÄÕý³£Ñ¬È¾³ÌÐòÒ»Ñù£¬Ö´ÐÐµÄ shell ¾ç±¾ÏÂÔØ²î±ð¼Ü¹¹Ç徲̨µÄÖ÷ÒªÓÐÓÃÔØºÉ¶þ½øÖÆÎļþ£¬²¢ÔÚÊܺ¦ÕßϵͳÖÐäĿִÐС£±ðµÄ£¬Ëü»¹Í¨¹ý×èÖ¹Óë³£¼ûÄ¿µÄ¶Ë¿ÚµÄÅþÁ¬À´±ÜÃâÆäËû½©Ê¬ÍøÂç½ÓÊÜ×°±¸¡£È»ºó£¬¶ñÒâÈí¼þÆÚ´ýÀ´×ÔÆäÏÂÁîºÍ¿ØÖÆ (C2) ·þÎñÆ÷µÄÏÂÁîÀ´Ö´Ðоܾø·þÎñ (DOS) ¹¥»÷µÄ²î±ð±äÌå¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlN9r
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡23ÌõIOC£¬ÆäÖаüÀ¨23¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
10. ¹¥»÷ÕßʹÓÃLog4j Îó²îÕë¶Ô Linux ϵͳÌᳫ¹¥»÷
¡¾±êÇ©¡¿Log4j Îó²î
¡¾Ê±¼ä¡¿2021-12-23
¡¾¼ò½é¡¿
Çå¾²Ñо¿Ôº²¶»ñÁË 2 ²¨Ê¹Óà Log4j Îó²îÐγɽ©Ê¬ÍøÂçµÄ¹¥»÷£¬²¢ÇÒ¿ìËÙÑùÌìÖ°ÎöÅú×¢ËüÃÇ»®·ÖÓÃÓÚÐÎ³É Muhstik ºÍ Mirai ½©Ê¬ÍøÂ磬¾ùÕë¶Ô Linux ×°±¸¡£²¢ÌåÏÖÐ嵀 Muhstik ±äÌåÌí¼ÓÁËÒ»¸öºóÃÅÄ£¿é ldm£¬ËüÄܹ»Ê¹ÓÃ×°ÖõĺóÃŹ«Ô¿Ìí¼Ó SSH ºóÃŹ«Ô¿¡£½«¹«Ô¿Ìí¼Óµ½~/.ssh/authorized_keys Îļþºó£¬¹¥»÷ÕßÎÞÐèÃÜÂëÑéÖ¤¼´¿ÉÖ±½ÓµÇ¼Զ³Ì·þÎñÆ÷¡£Ë¼Á¿µ½ log4j2 µÄÌØÊâÎó²î»úÖÆ£¬Muhstik ½ÓÄÉÁËÒ»ÖÖÉúÓ²µÄ·½·¨£¬ÔÚÖªµÀ»áÓÐÎó²î»úеµÄÇéÐÎÏÂÂþÎÞÄ¿µÄµØÈö²¥payload£¬²¢ÇÒΪÁËÖªµÀËÒѾ±»Ñ¬È¾£¬Muhstik ½ÓÄÉ TOR ÍøÂç×÷ΪÆä±¨¸æ»úÖÆ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNam
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öÓòÃû£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







