¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2022.1£©
2022-01-27
1Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬Apache DubboÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-43297£©ºÍHTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-21907£©Ó°ÏìÏà¶Ô½Ï´ó¡£Ç°ÕßÓÉÓÚÔÚDubboµÄhessian-liteÖб£´æ·´ÐòÁл¯Îó²î£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÄ¿µÄϵͳÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£´ó´ó¶¼ Dubbo Óû§Ä¬ÈÏʹÓà Hessian2×÷ΪÐòÁл¯/·´ÐòÁл¯ÐÒ飬ÔÚHessian ²¶»ñµ½Ò쳣ʱ£¬Hessian½«»á×¢ÏúһЩÓû§ÐÅÏ¢£¬Õâ¿ÉÄܻᵼÖÂÔ¶³ÌÏÂÁîÖ´ÐУ¬CVSSÆÀ·Ö9.8¡£ºóÕßÓÉÓÚHTTPÐÒéÕ»£¨HTTP.sys£©ÖеÄHTTP Trailer Support¹¦Ð§±£´æ½çÏß¹ýʧ¿Éµ¼Ö»º³åÇøÒç³ö¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòWeb·þÎñÆ÷·¢ËÍÌØÖÆµÄHTTPÊý¾Ý°ü£¬´Ó¶øÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬CVSSÆÀ·Ö9.8¡£
ÁíÍ⣬±¾´Î΢ÈíÐÞ¸´ÁË 497 ¸öÎó²î£¬°üÀ¨ 28 ¸ö Critical ¼¶±ðÎó²î£¬207 ¸ö Important ¼¶±ðÎó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬Ê¹ÓöñÒâľÂí³ÌÐòÌᳫµÄ´¹ÂÚ¹¥»÷ÊÂÎñÏà±ÈÕÕÆµÈÔ£¬ÆäÖаüÀ¨APT×éÖ¯EVILNUMʹÓÃÒþдÊõ¡¢Ð¡»ðÁúÓëAGENTVXľÂí³ÌÐòÌá³«ÍøÂç´¹ÂÚ¹¥»÷£¬Çå¾²Ñо¿ÊµÑéÊÒ²¶»ñµ½¶à¸öÒÔ»¤ÕÕɨÃèÎļþ×÷ΪÓÕ¶üµÄÍøÂç´¹ÂÚÔ˶¯£¬¾Ì«¹ýÎö£¬Ñо¿Ö°Ô±È·ÈϸÃÔ˶¯À´×ÔAPT×éÖ¯Evilnum£¬ÊÇÆäºã¾ÃÒÔÀ´Õë¶Ô½ðÈÚÄ¿µÄ·¸·¨Ô˶¯µÄÑÓÐø¡£Evilnum¹¥»÷ÕßÔÚ±¾´Î´¹ÂÚÔ˶¯Öй¹½¨ÁËÐÂÐ͹¥»÷Á÷³Ì£¬²¢Í¨¹ýNSIS°ü×°¡¢ÊðÃû¡¢ÒþдÊõµÈ²Ù×÷ʵÏÖÃâɱ£¬×îÖÕͶµÝÒ»ÖÖÐÂÐÍľÂí³ÌÐòAgentVX£¬Õ¹ÏÖÁ˽ϸߵÄÊÖÒÕˮƽ£»ÒÔ¼°¹¥»÷ÕßʹÓÃPyMICROPSIA˫βЫµÄÐÂÐÍÐÅÏ¢ÇÔȡľÂíÌᳫ¹¥»÷£¬Çå¾²Ñо¿Ô±²¶»ñÁËÒÔPython¹¹½¨µÄ¹¥»÷Ñù±¾£¬¸ÃÑù±¾×îÔçÓÉÍâÑó³§ÉÌ·¢Ã÷²¢ÃüÃûΪPyMICROPSIA£¬Ëü¾ßÓи»ºñµÄÐÅÏ¢ÇÔÈ¡ºÍ¿ØÖƹ¦Ð§¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2022Äê01ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼308¸öÎó²î, ÆäÖиßΣÎó²î60¸ö£¬Î¢Èí¸ßΣÎó²î28¸ö¡£
* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2022.01.27
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. APT×éÖ¯EVILNUMʹÓÃÒþдÊõ¡¢Ð¡»ðÁúÓëAGENTVXľÂí³ÌÐòÌá³«ÍøÂç´¹ÂÚ¹¥»÷
¡¾±êÇ©¡¿EVILNUM
¡¾Ê±¼ä¡¿2022-01-06
¡¾¼ò½é¡¿
½üÆÚ£¬Çå¾²Ñо¿ÊµÑéÊÒ²¶»ñµ½¶à¸öÒÔ»¤ÕÕɨÃèÎļþ×÷ΪÓÕ¶üµÄÍøÂç´¹ÂÚÔ˶¯¡£¾Ì«¹ýÎö£¬Ñо¿Ö°Ô±È·ÈϸÃÔ˶¯À´×ÔAPT×éÖ¯Evilnum£¬ÊÇÆäºã¾ÃÒÔÀ´Õë¶Ô½ðÈÚÄ¿µÄ·¸·¨Ô˶¯µÄÑÓÐø¡£Evilnum¹¥»÷ÕßÔÚ±¾´Î´¹ÂÚÔ˶¯Öй¹½¨ÁËÐÂÐ͹¥»÷Á÷³Ì£¬²¢Í¨¹ýNSIS°ü×°¡¢ÊðÃû¡¢ÒþдÊõµÈ²Ù×÷ʵÏÖÃâɱ£¬×îÖÕͶµÝÒ»ÖÖÐÂÐÍľÂí³ÌÐòAgentVX£¬Õ¹ÏÖÁ˽ϸߵÄÊÖÒÕˮƽ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNe8
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñ¹²ÌáÈ¡6ÌõIOC£¬ÆäÖаüÀ¨6¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. Donot APT×éÖ¯½üÆÚ¶ÔÃϼÓÀ¹úÌᳫ´¹ÂÚ¹¥»÷
¡¾±êÇ©¡¿Donot APT
¡¾Ê±¼ä¡¿2022-01-06
¡¾¼ò½é¡¿
¿ËÈÕ£¬Çå¾²Ñо¿Ô±ÔÚÒ»Ñùƽ³£µÄÍþвá÷ÁÔ²¶»ñÒ»Æð Donot APT ×éÖ¯½üÆÚÒÉËÆÕë¶ÔÃϼÓÀ¹ú¹¥»÷Ô˶¯£¬Ôڴ˹¥»÷Ô˶¯ÖУ¬¹¥»÷ÕßÖ÷ÒªÒÔ”ÃϼÓÀ¹úÖ°Òµ´óѧ2021Äêµç×Ó¹¤³ÌרҵÑÝʾÎĸå”ΪÖ÷Ì⣬½«PPTÓÕ¶üÎļþͨ¹ý´¹ÂÚÓʼþ·¢Ë͸øÊܺ¦Õß¡£µ±Êܺ¦Õß·¿ªÓÕ¶üÎļþ²¢Ö´Ðкêºó£¬»áÉÏ´«ÅÌËã»úºÍÓû§»ù±¾ÐÅÏ¢µ½Ô¶³Ì·þÎñÆ÷£¬²¢ÏÂÔØºóÐø¹¥»÷Ä£¿éµ½ÍâµØÖ´ÐС£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNe8
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñ¹²ÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨1¸öÓòÃûºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. ¶à¸ö¼Ò×åʹÓÃLog4j2Îó²îÈö²¥¶ñÒâÑù±¾
¡¾±êÇ©¡¿Log4j2Îó²î
¡¾Ê±¼ä¡¿2022-01-06
¡¾¼ò½é¡¿
2021Äê12ÔÂ11ºÅ£¬Ñо¿Ö°Ô±²¶»ñµ½Muhstik½©Ê¬ÍøÂçÑù±¾Í¨¹ýLog4j2 RCEÎó²îÈö²¥¡£2Ììºó£¬Â½ÐøÓÖ²¶»ñµ½ÆäËü¼Ò×åµÄÑù±¾£¬ÏÖÔÚ£¬Õâ¸ö¼Ò×åÁбíÒѾÁè¼Ý10¸ö¡£Ñо¿Ö°Ô±Í¨¹ý¶ÔɨÃè¶Ë¿ÚÆÊÎö·¢Ã÷£¬É¨ÃèÄ¿µÄ¶Ë¿ÚÖ÷ÒªÊÇ8081¶Ë¿Ú£¬ÇÒÒѾ²¶»ñÁè¼Ý1050¸ö¹¥»÷Ô´IP£¬Ö÷ÒªÀ´×ÔÓÚALPHASTRIKE-RESEARCH£¬ASMKºÍDIGITALOCEAN-ASN¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNe7
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñ¹²ÌáÈ¡819ÌõIOC£¬ÆäÖаüÀ¨819¸öIP£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. ¹¥»÷ÕßʹÓÃÔÆÊÓÆµÆ½Ì¨·Ö·¢skimmerÌᳫ¹©Ó¦Á´¹¥»÷
¡¾±êÇ©¡¿skimmer
¡¾Ê±¼ä¡¿2022-01-14
¡¾¼ò½é¡¿
×î½ü£¬Ñо¿Ö°Ô±·¢Ã÷¹©Ó¦Á´¹¥»÷ʹÓÃÔÆÊÓÆµÆ½Ì¨·Ö·¢ skimmer£¨ÓÖÃûformjacking£©Ô˶¯¡£ÔÚskimmer¹¥»÷ÖУ¬¹¥»÷Õß×¢Èë¶ñÒâJavaScript ´úÂëÀ´ÈëÇÖÍøÕ¾²¢½ÓÊÜÍøÕ¾HTML±íµ¥Ò³ÃæµÄ¹¦Ð§ÒÔÍøÂçÃô¸ÐµÄÓû§ÐÅÏ¢¡£ÔÚÑо¿µÄ¹¥»÷°¸ÀýÖУ¬¹¥»÷Õß½«Æ²È¡JavaScript´úÂë×¢Èëµ½ÊÓÆµÖУ¬Òò´Ëÿµ±ÆäËûÈ˵¼ÈëÊÓÆµÊ±£¬ËûÃǵÄÍøÕ¾Ò²»áǶÈëÆ²È¡´úÂë¡£½èÖúPalo Alto NetworksµÄ×Ô¶¯¼à¿ØºÍ¼ì²â·þÎñ£¬Ñо¿Õß¼ì²âµ½ÁË100 ¶à¸ö·¿µØ²úÍøÕ¾£¬ÕâÐ©ÍøÕ¾¶¼Êܵ½ÁËÏàͬµÄƲÔüÆ÷¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNe3
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñ¹²ÌáÈ¡0ÌõIOC£¬ÆäÖаüÀ¨£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. BlackTech×é֯ʹÓÃеĶñÒâÈí¼þFlagpro¶ÔÈÕ±¾¹«Ë¾Ìᳫ¹¥»÷
¡¾±êÇ©¡¿Flagpro
¡¾Ê±¼ä¡¿2022-01-14
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±ÔÚÊÓ²ìһЩÕë¶ÔÈÕ±¾¹«Ë¾µÄ¹¥»÷°¸ÀýÖз¢Ã÷£¬BlackTech ʹÓÃÁËÒ»ÖÖеĶñÒâÈí¼þFlagproÌᳫ¹¥»÷¡£¹¥»÷Õß½«ÊÜÃÜÂë±£»¤µÄ´æµµÎļþ£¨ZIP »ò RAR£©¸½¼Óµ½µç×ÓÓʼþÖУ¬²¢½«ÆäÃÜÂëдÈëÓʼþÖС£´æµµÎļþ°üÀ¨Ò»¸ö xlsmÃûÌÃÎļþ£¬ÄÚÀï°üÀ¨Ò»¸ö¶ñÒâºê¡£ÈôÊÇÓû§¼¤»îºê£¬¶ñÒâÈí¼þ½«±»ÑïÆú¡£ËûÃÇ»¹½«xlsmÎļþµÄÄÚÈݵ÷½âΪĿµÄ¡£ºêÖ´Ðк󣬻áÔÚÆô¶¯Ä¿Â¼Ï½¨ÉèÒ»EXEÎļþ¡£Õâ¸öEXEÎļþÊÇ“Flagpro”¡£ÔÚ´ó´ó¶¼ÇéÐÎÏ£¬Õâ¸ö½¨ÉèµÄEXE Îļþ±»ÃüÃûΪ“dwm.exe”¡£Ï´ÎϵͳÆô¶¯Ê±£¬»áÖ´ÐÐÒÔ“dwm.exe”µÄÐÎʽ°²ÅÅÔÚÆô¶¯Ä¿Â¼ÖеÄFlagpro¡£µ±FlagproÓë C·þÎñÆ÷ͨѶ£¬Ëü´Ó·þÎñÆ÷ÎüÊÕÒªÖ´ÐеÄÏÂÁ»òÕß Flagpro ÏÂÔØµÚ¶þ½×¶ÎµÄ¶ñÒâÈí¼þÈ»ºóÖ´ÐÐËü¡£¹¥»÷Õß¼ì²éµÚÒ»½×¶ÎµÄÄ¿µÄÇéÐÎÊÇ·ñÊʺÏÔËÐеڶþ½×¶Î¶ñÒâÈí¼þ¡£ÈôÊÇËûÃǾöÒé¹¥»÷Ä¿µÄ£¬Ôò»áÏÂÔØ²¢Ö´ÐÐÁíÒ»¸ö¶ñÒâÈí¼þÑù±¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNe5
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñ¹²ÌáÈ¡14ÌõIOC£¬ÆäÖаüÀ¨5¸öIP£¬2¸öÓòÃûºÍ7¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. ¹¥»÷ÕßʹÓÃCOVID Omicron ±äÌå×÷ΪÓÕ¶üÓÃÓÚ·Ö·¢ RedLine Stealer
¡¾±êÇ©¡¿Omicron
¡¾Ê±¼ä¡¿2022-01-20
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±×î½ü·¢Ã÷ÁËÒ»¸öÃûΪ“Omicron Stats.exe”µÄÏ£ÆæÎļþ£¬¾Ö¤ÊµËüÊÇ Redline Stealer ¶ñÒâÈí¼þµÄ±äÖÖ¡£ÓÉÓÚ¹¥»÷Õß½«´Ë¶ñÒâÈí¼þǶÈëÔÚÓÉÊܺ¦Õß·¿ªµÄÎĵµÖУ¬Òò´ËÑо¿Ö°Ô±µÃ³ö½áÂÛ£¬µç×ÓÓʼþÒ²ÊǴ˱äÌåµÄѬȾǰÑÔ¡£µ±Óû§Ö´ÐÐ Omicron Stats.exe ºó£¬Ëü»áʹÓÃÃÜÂëģʽ ECB ºÍÌî³äģʽ PKCS7 ½âѹËõʹÓÃÈýÖØ DES¼ÓÃܵÄ×ÊÔ´¡£È»ºó½«½âѹËõµÄ×ÊÔ´×¢Èëvbc.exe¡£Ëü½«×ÔÉí¸´ÖÆµ½ C:\\\\Users\\\\Username\\\\AppData\\\\Roaming\\\\chromedrlvers.exe ²¢½¨ÉèÍýÏëʹÃüÒÔ¾ÙÐг¤ÆÚÐÔ£¬È»ºó£¬¶ñÒâÈí¼þ»áʵÑé´Ó Windows Management Instrumentation (WMI) ÖÐÇÔȡϵͳÐÅÏ¢£ºÏÔ¿¨Ãû³Æ¡¢BIOS ÖÆÔìÉÌ¡¢Ê¶±ðÂë¡¢ÐòÁкš¢Ðû²¼ÈÕÆÚºÍ°æ±¾¡¢´ÅÅÌÇý¶¯Æ÷ÖÆÔìÉÌ¡¢Ðͺš¢×Ü´ÅÍ·ÊýºÍÊðÃû¼°´¦Öóͷ£Æ÷ (CPU) ÐÅÏ¢£¬ÀýÈçΨһ ID¡¢´¦Öóͷ£Æ÷ ID¡¢ÖÆÔìÉÌ¡¢Ãû³Æ¡¢×î´óʱÖÓËÙÂʺÍÖ÷°åÐÅÏ¢µÈ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNeN
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡¹²20ÌõIOC£¬ÆäÖаüÀ¨10¸öIPºÍ10¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
7. Donot TeamʹÓÃyty ¶ñÒâÈí¼þ¿ò¼ÜÌᳫ´¹ÂÚ¹¥»÷
¡¾±êÇ©¡¿Donot Team
¡¾Ê±¼ä¡¿2022-01-24
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±·¢Ã÷Donot Team Ò»Ö±ÒÔÿÁ½µ½ËĸöÔÂÒ»²¨´øÓжñÒ⸽¼þµÄÓã²æÊ½´¹ÂÚµç×ÓÓʼþΪĿµÄ£¬Ò»Ö±Õë¶ÔÏàͬµÄʵÌ壬¶øÄܹ»¼ìË÷ºÍÆÊÎöµÄµç×ÓÓʼþ²¢Ã»ÓÐÏÔʾ³öÓÕÆµÄ¼£Ïó¡£Í¨¹ýÓã²æÊ½ÍøÂç´¹ÂÚµç×ÓÓʼþ£¬¹¥»÷ÕßʹÓöñÒâ Microsoft Office ÎĵµÀ´°²ÅÅËûÃǵĶñÒâÈí¼þ¡£Ñо¿Ô±ÒѾÊӲ쵽 Donot Team ÖÁÉÙʹÓÃÁËÈýÖÖÊÖÒÕ¡£µÚÒ»ÖÖÊÇ Word¡¢Excel ºÍ PowerPoint ÎĵµÖеĺ꣬µÚ¶þÖÖÊÖÒÕÊÇ´øÓÐ.docÀ©Õ¹ÃûµÄRTF Îļþ£¬Ê¹Óù«Ê½±à¼Æ÷ÖеÄÄÚ´æËð»µÎó²îCVE-2017-11882£¬µÚÈýÖÖÊÖÒÕÊÇÔ¶³ÌRTF Ä£°å×¢È룬ËüÔÊÐí¹¥»÷ÕßÔÚ·¿ª RTF ÎĵµÊ±´ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÓÐÓøºÔØ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNeQ
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñ¹²ÌáÈ¡18ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ17¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
8. SideCopy×é֯ʹÓÃPython ´ò°üµÄ˫ƽ̨¹¥»÷ÎäÆ÷Õë¶ÔLinuxƽ̨Ìᳫ¹¥»÷
¡¾±êÇ©¡¿SideCopy
¡¾Ê±¼ä¡¿2022-01-24
¡¾¼ò½é¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±ÔÚÒ»Ñùƽ³£Íþвá÷ÁÔÖÐÔٴβ¶»ñµ½Ò»ÀýÕë¶ÔLinuxƽ̨µÄ¹¥»÷Ñù±¾¡£ÓëÉϴβî±ðµÄÊÇ£¬´Ë´Î²¶»ñÑù±¾ÓÉGoÓïÑÔ±àд¶ø²»ÊÇPython£¬¸ÃÑù±¾¹¦Ð§½ÏΪ¼òµ¥£¬½öʵÏÖÁ˶ÔÄ¿µÄÊܺ¦ÕßÖ÷»úĿ¼µÄɨÃèºÍÇÔÈ¡¡£Ñо¿Ö°Ô±ÌåÏÖ£¬´Ó¹¥»÷Á÷³ÌÀ´¿´£¬SideCopy×é֯ʹÓÃ207.180.243.186Ï·¢ºóÐø¹¥»÷×é¼þ¡£¶ø±¾´Î²¶»ñµÄÑù±¾¹¦Ð§¼òÆÓ£¬ºÜÏñijÌõ¹¥»÷Á´ÖÐʹÓõÄijһ×é¼þ¡£ËäÈ»¡¶Ó¡¶È¹ú·ÀÕÕÁϳ¤×¹»ú£ºSideCopy APT×éÖ¯³Ã»ðÂÓ¶á¡·Ò»ÎÄÖÐÅû¶µÄÊÇÕë¶ÔWindowsƽ̨µÄ¹¥»÷£¬µ«Ñо¿Ô±ÍƲâ¸Ã×éÖ¯¿ÉÄÜÔÚͳһʱÆÚ×îÏȲ߻®Õë¶ÔLinuxƽ̨µÄ¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNeP
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñ¹²ÌáÈ¡6ÌõIOC£¬ÆäÖаüÀ¨2¸öIPºÍ4¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
9. ¹¥»÷ÕßʹÓÃCOVID-19 ²âÊÔÖ¸ÁîÌá³«ÍøÂç´¹ÂÚ¹¥»÷
¡¾±êÇ©¡¿COVID-19
¡¾Ê±¼ä¡¿2021-12-30
¡¾¼ò½é¡¿
×î½ü£¬Çå¾²Ñо¿ÔºÊӲ쵽¶ñÒâÈí¼þÀ¬»øÓʼþÔ˶¯ÕýÆð¾¢Ê¹ÓÃÄ¿½ñµÄCOVID-19ÇéÐΡ£ÕâЩµç×ÓÓʼþÊÇʹÓÃÓʼþ³ÌÐò¾ç±¾´ÓÊÜѬȾµÄÓÊÏä·¢Ë͵ġ£ÐÂÎÅÀï°üÀ¨Ò»¸öÖ¸ÏòWordÎĵµµÄÁ´½Ó¡£¸Ãµç×ÓÓʼþÀûCOVID-19²âÊÔÖ¸Áî×÷ΪÄó´Ê£¬ÒýÓÕºÁÎÞ½äÐĵÄÓû§µ¥»÷Á´½Ó²¢ÏÂÔØÎĵµ¡£Ñо¿Ö°Ô±ÌåÏÖ×î³õÏÂÔØµÄ Word ÎĵµÃ»ÓжñÒâ´úÂë¡£¿ÉÊÇÒ»µ©Êܺ¦Õß·¿ªWord Îĵµ£¬Ëü¾Í»áʵÑé´ÓÔ¶³Ì·þÎñÆ÷¼ìË÷ÆôÓÃÁ˺êµÄ¶ñÒâÄ£°å¡£¸ÃÊÖÒÕ³ÆÎªÔ¶³ÌÄ£°å×¢È룬ͨ³£ÓÃÓÚÌӱܾ²Ì¬¼ì²â£¬¶øÔÚ¼ÓÔØÔ¶³ÌÄ£°åºó£¬Ëü½«ÌáÐÑÓû§ÆôÓúêÄÚÈÝ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNbu
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñ¹²ÌáÈ¡Ìõ8ÌõIOC£¬ÆäÖаüÀ¨5¸öÑù±¾ºÍ3¸öURL£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
10. ¹¥»÷ÕßʹÓÃPyMICROPSIA˫βЫµÄÐÂÐÍÐÅÏ¢ÇÔȡľÂíÌᳫ¹¥»÷
¡¾±êÇ©¡¿PyMICROPSIA
¡¾Ê±¼ä¡¿2021-12-30
¡¾¼ò½é¡¿
×î½ü£¬Çå¾²Ñо¿Ô±²¶»ñÁËÒÔPython¹¹½¨µÄ¹¥»÷Ñù±¾£¬¸ÃÑù±¾×îÔçÓÉÍâÑó³§ÉÌ·¢Ã÷²¢ÃüÃûΪPyMICROPSIA£¬Ëü¾ßÓи»ºñµÄÐÅÏ¢ÇÔÈ¡ºÍ¿ØÖƹ¦Ð§¡£Ë«Î²Ð«ÊÇÒ»¸öºã¾ÃÕë¶ÔÖж«µØÇøµÄ¸ß¼¶Ò»Á¬Íþв×éÖ¯£¬Æä×îÔçÓÚ2017Äê±»Åû¶¡£¸Ã×éÖ¯ÖÁÉÙ2016Äê5ÔÂÆð£¬Ò»Á¬Õë¶Ô°ÍÀÕ˹̹½ÌÓý»ú¹¹¡¢¾üÊ»ú¹¹µÈÖ÷ÒªÁìÓò¾ÙÐÐÍøÂçÌØ¹¤Ô˶¯£¬ÒÔÇÔÈ¡Ãô¸ÐÐÅϢΪÖ÷µÄÍøÂç¹¥»÷×éÖ¯£¬¿ªÕ¹ÁËÓÐ×éÖ¯£¬ÓÐÍýÏ룬ÓÐÕë¶ÔÐԵĹ¥»÷¡£Ë«Î²Ð«×éÖ¯¾ßÓÐWindowsºÍAndroid˫ƽ̨¹¥»÷ÎäÆ÷£¬ÇÒ½öWindowsƽ̨¶ñÒâ´úÂë¾Í¸»ºñ¶à±ä£¬¾ßÓжàÖÖÓïÑÔ±àÒëµÄºóÃÅ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNbs
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñ¹²ÌáÈ¡Ìõ7ÌõIOC£¬ÆäÖаüÀ¨3¸öURL£¬Ò»¸öIPºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







