AG¹«Ë¾ÍþвÇ鱨Öܱ¨£¨20200406~20200412£©
2020-04-13
Ò»¡¢Íþвͨ¸æ
- ÐÂÐÍÀÕË÷Èí¼þWannaRen
¡¾Ðû²¼Ê±¼ä¡¿2020-04-08 22:00:00 GMT
¡¾¸ÅÊö¡¿¿ËÈÕ£¬ÍøÂçÉÏ·ºÆðÒ»ÖÖÐÂÐÍÀÕË÷²¡¶¾²¢ÔÚPCÉÏ×îÏÈÈö²¥¡£¸ÃÀÕË÷Èí¼þ»á¼ÓÃÜWindowsϵͳÖеÄÎļþ£¬²¢ÇÒÒÔ“.WannaRen”ºó׺ÃüÃû¡£¹¥»÷ÕßÁôϱÈÌØ±ÒÇ®°ü²¢Ë÷È¡ 0.05 ±ÈÌØ±Ò¡£AG¹«Ë¾¿Æ¼¼Ó¦¼±ÏìÓ¦ÍŶÓͨ¹ý¸ú×ÙÆÊÎö£¬·¢Ã÷“kms¼¤»î¹¤¾ß19.5.2.exe”ΪÀÕË÷Èí¼þÏÂÔØÆ÷£¬¸ÃÏÂÔØÆ÷αװ³Ékms¼¤»î¹¤¾ßÓÕµ¼Óû§ÏÂÔØ¡£AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄÒÑÖ§³Ö¶Ô¸ÃÊÂÎñµÄÔÚÏß¼ì²â£¬ÒÑʹÓÃÇ鱨¸³ÄܵIJúÆ·ÔÚÀëÏßÉý¼¶°üÖÐÒ²¿É»ñÈ¡ÏìÓ¦IOC£¨Ò»Á¬¸üУ©¡£
¡¾Á´½Ó¡¿http://blog.nsfocus.net/wannaren-0407/
- ÉîÐÅ·þSSL VPN±»¾³ÍâAPT×é֯ʹÓò¢Ï·¢¶ñÒâ´úÂë
¡¾Ðû²¼Ê±¼ä¡¿2020-04-06 23:00:00 GMT
¡¾¸ÅÊö¡¿4ÔÂ6ÈÕ£¬ÉîÐÅ·þ¹Ù·½Ðû²¼Í¨¸æ³Æ£¬Óо³ÍâAPT×é֯ͨ¹ý²»·¨ÊֶοØÖƲ¿·ÖÉîÐÅ·þSSL VPN×°±¸£¬²¢Ê¹Óÿͻ§¶ËÉý¼¶Îó²îÏ·¢¶ñÒâÎļþµ½¿Í»§¶Ë£¬AG¹«Ë¾¿Æ¼¼¶Ô¸ÃÊÂÎñÇ×½ü¹Ø×¢£¬²¢¾ÙÐÐÁËÕûÌåµÄÊáÀíºÍÆÊÎö£¬½¨ÒéÏà¹ØÓû§ÊµÊ±½ÓÄÉ·À»¤ºÍÓ¦¼±²½·¥¡£
¡¾Á´½Ó¡¿http://blog.nsfocus.net/sslvpn-0407/
¶þ¡¢ÈÈÃÅ×ÊѶ
- polaris½©Ê¬ÍøÂç¹¥»÷È«ÇòNetlink·ÓÉÆ÷
¡¾¸ÅÊö¡¿½üÆÚAG¹«Ë¾¿Æ¼¼¸ñÎïʵÑéÊÒ·¢Ã÷Õë¶ÔNetlink GPON·ÓÉÆ÷RCEÎó²îµÄʹÓÃÐÐΪ¡£ÔÚ2020Äê3ÔÂ18ÈÕNetlink GPON·ÓÉÆ÷µÄÔ¶³ÌÖ´ÐÐÎó²î±»Ðû²¼²»¾Ã£¬polaris½©Ê¬ÍøÂç±ãͨ¹ý¸ÃÎó²îÈö²¥ÆäÑù±¾£¬µ¼Ö¹¥»÷Ô´ÊýÄ¿¡¢¹¥»÷´ÎÊýÒÔ¼°²¶»ñµ½¹¥»÷µÄ½ÚµãÊýÄ¿¾ù³ÊÉÏÉýÇ÷ÊÆ¡£
¡¾²Î¿¼Á´½Ó¡¿https://mp.weixin.qq.com/s/9xEVrC5UzyuCF56Es1ppGA
- xHelperľÂíÕë¶ÔAndroidÊÖ»ú¾ÙÐдó¹æÄ£¹¥»÷
¡¾¸ÅÊö¡¿xHelperľÂíÔÚ2019Äê10Ô±»·¢Ã÷×îÏÈÕë¶ÔAndroidÊÖ»ú¾ÙÐдó¹æÄ£¹¥»÷£¬µ«×ÝÈ»ÏÖÔÚ£¬¸ÃľÂíÈÔÈ»ÏòÒÔǰһÑù»îÔ¾¡£xHelperÊǼ«¾ß¹¥»÷ÐԵľÂíÈí¼þ£¬Ëü½«×Ô¼ºÎ±×°³ÉÒ»¿îÊÖ»úÕûÀí¼ÓËÙÓ¦ÓóÌÐò£¬×°ÖÃÖ®ºóÔÚÖ÷ÆÁÄ»»ò³ÌÐò²Ëµ¥×Ô¶¯Òþ²Ø£¬×ÝÈ»ÕÒµ½²¢É¾³ýËüÉõÖÁ»Ö¸´³ö³§ÉèÖÃÒ²ÎÞÓã¬ËüÈԻᱣ±£´æÄÇÀ²¢ÇÒ¿ÉÒÔ×°ÖúóÃÅÏòÆäËû¶ñÒâÈí¼þ̻¶Óû§µÄÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿https://securelist.com/unkillable-xhelper-and-a-trojan-matryoshka/96487/
- APT41ʹÓÃZoho ManageEngineÖÐÎó²îÕë¶ÔÖ´·¨Ïà¹ØÊµÌå
¡¾¸ÅÊö¡¿½üÆÚAPT41×é֯ʹÓÃZoho ManageEngineµÄÁãÈÕÎó²îCVE-2020-10189¹¥»÷ÃÀ¹ú¡¢Å·ÖÞµØÇøµÄÖ´·¨Ïà¹Ø²¿·Ö¡£APT41ÊÇÒ»¸öÓëÖйúÓйصÄÍþв×éÖ¯£¬ÖÁÉÙ´Ó2012Äê»îÔ¾ÖÁ½ñ£¬Ö÷ÒªÓªÒµ°üÀ¨¹ú¼ÒÔÞÖúµÄÍøÂçÌØ¹¤Ô˶¯ÒÔ¼°³öÓÚ¾¼ÃÄîÍ·µÄÈëÇÖÔ˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿https://www.darktrace.com/en/blog/catching-apt-41-exploiting-a-zero-day-vulnerability/
- Kinsing¶ñÒâÈí¼þÕë¶ÔÈÝÆ÷ÇéÐεĹ¥»÷
¡¾¸ÅÊö¡¿½üÆÚÕë¶ÔÈÝÆ÷ÇéÐεĹ¥»÷ÊýÄ¿ÔÚÔöÌí¡£¹¥»÷ÕßʹÓò»Êܱ£»¤µÄ¿ª·ÅDocker API¶Ë¿ÚÀ´ÔËÐÐÒ»¸ö´øÓÐKinsing¶ñÒâÈí¼þµÄUbuntuÈÝÆ÷£¬¸Ã¶ñÒâÈí¼þÔËÐÐÒ»¸ö¼ÓÃÜÆ÷£¬È»ºóÊÔͼ½«¶ñÒâÈí¼þÈö²¥µ½ÆäËûÈÝÆ÷ºÍÖ÷»úÉÏ¡£
¡¾²Î¿¼Á´½Ó¡¿https://blog.aquasec.com/threat-alert-kinsing-malware-container-vulnerability
- WINDSHIFT×éÖ¯Õë¶ÔÖж«µÄÍøÂçÌØ¹¤Ô˶¯
¡¾¸ÅÊö¡¿WINDSHIFTÊÇÒ»¸ö´ÓʸßÕë¶ÔÐÔµÄÍøÂçÌØ¹¤Ô˶¯µÄ×éÖ¯£¬Õë¶ÔÕûÆäÖж«µØÇøµÄÕþ¸®²¿·ÖºÍÒªº¦»ù´¡ÉèÊ©ÊÂÇéµÄÌØ¶¨Ð¡ÎÒ˽¼Ò£¬¹¥»÷Ô˶¯ÖÐWindTailÊǸÃ×é֯ʹÓõĵÚÒ»½×¶ÎmacOSÖ²Èë³ÌÐò£¬Í¨¹ýÀÄÓÃmacOS¶Ô×Ô½ç˵URL¼Æ»®µÄÖ§³ÖÀ´Ô¶³ÌѬȾmacOSÄ¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿https://www.virusbulletin.com/virusbulletin/2020/04/vb2019-paper-cyber-espionage-middle-east-unravelling-osxwindtail/
- FIN6×éÖ¯ÔÚ¹¥»÷Ô˶¯Öзַ¢AnchorºÍPowerTrickºóÃÅ
¡¾¸ÅÊö¡¿½üÁ½ÄêÀ´£¬ÓÐ×éÖ¯µÄÍøÂç·¸·¨¼¯ÍÅÖ®¼äµÄÏàÖúÈÕÒæÔöÇ¿¡£FIN6ÊÇÒ»¸öÓÐ×éÖ¯µÄÍøÂç·¸·¨ÍŻ×Ô2015ÄêÒÔÀ´Ò»Ö±ºÜ»îÔ¾£¬Ö÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄʵÌåÁãÊÛÉ̺ÍÂùÝÐÐÒµµÄPOS»ú¡£½üÆÚÆäÓëTrickBotÏàÖúʹÓÃAnchorºÍPowerTrick¶ÔÆóÒµÍøÂç¾ÙÐÐÕë¶ÔÐԵĹ¥»÷¡£ÁíÍ⣬FIN6µÄÄ¿µÄ°üÀ¨µ«²»ÏÞÓÚµç×ÓÉÌÎñÇéÐκÍÀÕË÷Èí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿https://securityintelligence.com/posts/itg08-aka-fin6-partners-with-trickbot-gang-uses-anchor-framework/
- Hoaxcalls½©Ê¬ÍøÂçʹÓÃGrandstreamºÍDrayTek×°±¸Îó²îÈö²¥
¡¾¸ÅÊö¡¿HoaxcallsÊÇÒ»¸öеÄDDoS½©Ê¬ÍøÂ磬ʹÓÃGrandstreamºÍDrayTek×°±¸Îó²îÔÚÈ«Çò¹æÄ£ÄÚÆÕ±éÈö²¥£¬Ëüͨ¹ýIRCÓëC2·þÎñÆ÷ͨѶ£¬ÎüÊÕµ½C2ÏÂÁîºó£¬¿ÉÒÔʹÓÃCVE-2020-8515ºÍCVE-2020-5722Îó²îͨ¹ýɨÃèºÍѬȾÒ×Êܹ¥»÷µÄ×°±¸¾ÙÐÐÈö²¥¡£ÏÖÔÚÒÑÓÐÐí¶àGrandstream UCM6200ºÍDraytek Vigor×°±¸±»Ñ¬È¾»ò¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿https://unit42.paloaltonetworks.com/new-hoaxcalls-ddos-botnet/

AG¹«Ë¾ÔÆ







