AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.08.03-2020.08.09£©
2020-08-11
Ò»¡¢ Íþвͨ¸æ
WebSphereÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4534£©
¡¾Ðû²¼Ê±¼ä¡¿2020-08-10 12:00:00 GMT
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä2020Äê7ÔÂ31ÈÕ£¬IBM¹Ù·½Ðû²¼Í¨¸æÐÞ¸´ÁËWebSphere Application Server£¨WAS£©ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4534£©¡£¸ÃÎó²îÓÉÓÚδ׼ȷ´¦Öóͷ£UNC·¾¶¶øµ¼Ö£¬¾ÓÉÍâµØÉí·ÝÈÏÖ¤ºó£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÍê³É´úÂëÖ´ÐУ¬Îó²îÆÀ·ÖΪ7.8·Ö¡£¸ÃÎó²î£¨CVE-2020-4534£©ÓÉAG¹«Ë¾¿Æ¼¼·üӰʵÑéÊÒ·¢Ã÷²¢Ìá½»ÖÁIBM¡£¾×¨¼ÒÅжϣ¬¸ÃÎó²î¿ÉÒÔÓë´ËǰAG¹«Ë¾¿Æ¼¼Ìá½»ÖÁIBMµÄCVE-2020-4450×éºÏʹÓã¬ÎÞÐèÉí·ÝÈÏÖ¤¼´¿ÉÔÚÄ¿µÄ·þÎñ¶ËÖ´ÐÐí§Òâ´úÂ룬»ñȡϵͳȨÏÞ£¬½ø¶ø½ÓÊÜ·þÎñÆ÷¡£
¡¾Á´½Ó¡¿
http://blog.nsfocus.net/websphere-cve-2020-4534-0810/
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. º£Á«»¨×é֯ʹÓÃMsMpEng¾ÙÐвàÔØ¹¥»÷
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾ÍþвÇ鱨£¨NTI£©·¢Ã÷ÁËÒ»Æð½èÓÃWindowsDefenderÖ÷Òª×é¼þMsMpEng.exe¾ÙÐвàÔØ¹¥»÷µÄÊÂÎñ¡£Í¨¹ý¶Ô±¾ÊÂÎñÒÔ¼°¶à¸ö¹ØÁªÊÂÎñµÄÆÊÎö£¬È·ÈϸÃϵÁй¥»÷ÊÂÎñµÄÌᳫÕßΪº£Á«»¨£¨OceanLotus£¬APT32£©×éÖ¯¡£³ýͨÀýÊÖ·¨Ö®Í⣬º£Á«»¨×éÖ¯ÔÚÕâÒ»ÔÙ¹¥»÷ÖÐʹÓÃÁËÒ»ÖÖеĻìÏýÊÖÒÕ£¬ÒÔ¼°Ò»¿îеÄÖÐÐÄÔØºÉ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://nti.nsfocus.com/
2. NetWalkerÀÕË÷Èí¼þÕë¶ÔÎ÷Å·¹ú¼ÒºÍÃÀ¹ú
¡¾¸ÅÊö¡¿
NetWalkerÀÕË÷Èí¼þ×î³õ³ÆÎªMailto£¬×îÔçÔÚ2019Äê8Ô±»·¢Ã÷£¬×Ô¾õÏÖÒÔÀ´Õë¶ÔÐí¶à²î±ðµÄÄ¿µÄ£¬Ö÷ҪλÓÚÎ÷Å·¹ú¼ÒºÍÃÀ¹ú¡£¹¥»÷Ô˶¯ÖÐNetWalkerÀÕË÷Èí¼þ½«Ëæ»úÀ©Õ¹Ãû¸½¼Óµ½ÊÜѬȾµÄÎļþÖУ¬²¢Ê¹ÓÃSalsa20¼ÓÃÜ£¬ËüʹÓÃÒ»ÖÖеķÀÓù¹æ±ÜÊÖÒÕ±»³ÆÎª·´ÉäDLL¼ÓÔØ£¬ÓÃÓÚ´ÓÄÚ´æÖÐ×¢ÈëDLL¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.mcafee.com//blogs/other-blogs/mcafee-labs/take-a-netwalk-on-the-wild-side/
3. TA551¹¥»÷×éÖ¯·Ö·¢IcedIDÒøÐÐľÂí
¡¾¸ÅÊö¡¿
TA551×éÖ¯ÔÚ½üÆÚµÄ¹¥»÷Ô˶¯ÖÐÕë¶ÔÒÔÓ¢ÓïΪĸÓïµÄÄ¿µÄ£¬Ê¹ÓÃÀ¬»øÓʼþ·Ö·¢IcedIDÒøÐÐľÂí£¬ÕâЩÓʼþ¸½¼þÊÇ´øÓжñÒâºêµÄWordÎĵµ£¬Ò»µ©Óû§ÆôÓú꣬HTTPͨѶµÄTCPÁ÷¿É¼ìË÷×°ÖöñÒâ³ÌÐòDLL£¬ÓÉ×°ÖóÌÐòDLL½¨ÉèIcedIDµÄEXEÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://isc.sans.edu/diary/26438
4. ¿çÎŤ¾ß°üÓÃÓÚÏóÐÎÎÄ×Ö¹¥»÷ÒÔ¾ÙÐÐÐÅÓÿ¨ÐÅÏ¢ÇÔÈ¡
¡¾¸ÅÊö¡¿
¹¥»÷Õß½üÆÚʹÓÃÏóÐÎÎÄ×Ö¹¥»÷·½·¨À´ÇÔÊØÐÅÓÿ¨ÐÅÏ¢£¬´Ë¹¥»÷ÊÖÒÕÔÚ¾ßÓÐIDNͬÐÎÒìÒå´Ê¹¥»÷µÄÍøÂç´¹ÂÚÕ©ÆÖÐÒѾ±»Ê¹ÓÃÁËÒ»¶Îʱ¼ä£¬Ê¹Óÿ´ÆðÀ´ÏàͬµÄ×Ö·ûÀ´ÓÕÆÓû§£¬ÓÐʱ×Ö·ûÀ´×Ô²î±ðµÄÓïÑÔ¼¯¡£Éó²é¶ñÒâ»ù´¡»ú¹¹£¨51.83.209[.]11£©£¬¹¥»÷Õß×î½üʹÓÃÏàͬµÄÏóÐÎÎÄ×ÖÊÖÒÕ×¢²áÁ˶à¸öÓò£¬´Ë´Î¹¥»÷Ô˶¯ÒÉËÆÓÐMagecart ×éÖ¯Óйء£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.malwarebytes.com/threat-analysis/2020/08/inter-skimming-kit-used-in-homoglyph-attacks/
5. TAIDOORľÂíαװΪDLLÎļþѬȾĿµÄϵͳ
¡¾¸ÅÊö¡¿
TaidoorľÂí×÷Ϊ·þÎñ¶¯Ì¬Á´½Ó¿âDLL×°ÖÃÔÚÄ¿µÄϵͳÉÏ£¬²¢ÇÒÓÉÁ½¸öÎļþ×é³É£¬µÚÒ»¸öÎļþÊǼÓÔØ³ÌÐò£¬×÷Ϊ·þÎñÆô¶¯£¬¼ÓÔØ³ÌÐò½âÃܵڶþ¸öÎļþ£¬È»ºóÔÚÄÚ´æÖÐÖ´ÐиÃÎļþ£¬´ËÎļþÊÇÔ¶³Ì»á¼ûľÂí£¨RAT£©¡£¾Ý³ÆTaidoorľÂíÖÁÉÙ´Ó2008Äê»îÔ¾ÖÁ½ñ£¬Ö÷ҪĿµÄÕë¶ÔIT·þÎñÌṩÉÌ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://us-cert.cisa.gov/ncas/analysis-reports/ar20-216a
6. Black Hat 2020:ʹÓý©Ê¬ÍøÂçʹÓÃÄÜÔ´Êг¡»ñÈ¡¸ß¶îÀûÈó
¡¾¸ÅÊö¡¿
Black Hat 2020¾Û»áÖÐÑо¿Ö°Ô±Ìáµ½Ò»ÀàÐÂÐ͵Ľ©Ê¬ÍøÂç¿ÉÄܻᱻ±à×éÆðÀ´£¬Í¨¹ýºÄµçµÄÅþÁ¬×°±¸£¨Èç¿Õµ÷¡¢Ï´Íë»ú¡¢¼ÓÈÈÆ÷¡¢ºæ¸É»úºÍÊý×ÖºãÎÂÆ÷µÈ£©Ê¹ÓÃÄÜÔ´Êг¡£¬¾ÙÐÐÂþÑÜʽ¾Ü¾ø·þÎñ¹¥»÷ºÍµØÀ×¼ÓÃÜÇ®±Ò£¬¿ÉÄܻᵼÖÂÄÜÔ´¹ÉÖ¸ÊýÉÏÉý»òϽµ£¬´Ó¶øÎªÓжñÒâÍýÏëµÄÔËÓªÉÌÌṩ׬ǮµÄʱ»ú¡£
¡¾²Î¿¼Á´½Ó¡¿
7. NSOÌØ¹¤Èí¼þ¹¥»÷¶à¸ç
¡¾¸ÅÊö¡¿
NSOÌØ¹¤Èí¼þ±»¹¥»÷ÕßʹÓù¥»÷¶à¸ç¹«ÃñÉç»á£¬ÆäÖаüÀ¨ÌìÖ÷½ÌÖ÷½Ì¡¢ÄÁʦºÍ×èµ²ÅÉÕþÖμҡ£NSOÌØ¹¤Èí¼þ²úƷͨ³£±»³ÆÎªPegasus£¬ÊÇÒ»ÖÖÊÖ»úºÚ¿Í¹¤¾ß£¬¿É»ñÈ¡¶ÔÄ¿µÄÒÆ¶¯×°±¸µÄÍêÈ«»á¼ûȨÏÞ£¬PegasusÔÊÐí¹¥»÷ÕßÌáÈ¡ÃÜÂë¡¢Îļþ¡¢ÕÕÆ¬¡¢ÍøÂçÀúÊ·¼Í¼¡¢ÁªÏµÈËÒÔ¼°Éí·ÝÊý¾ÝµÈÐÅÏ¢£¬PegasusµÄÄ¿µÄ°üÀ¨ÑÇÖÞ£¬Å·ÖÞ£¬Öж«ºÍ±±ÃÀµÄÊýÊ®¸ö¹ú¼Ò¡£
¡¾²Î¿¼Á´½Ó¡¿
https://citizenlab.ca/2020/08/nothing-sacred-nso-sypware-in-togo/
8. CanonÔâÀÕË÷Èí¼þMaze¹¥»÷
¡¾¸ÅÊö¡¿
½üÆÚCanon¼¯ÍÅÔâÊܵ½ÀÕË÷Èí¼þµÄMaze¹¥»÷£¬µ¼ÖÂÆäÔÚÃÀ¹úÍøÕ¾¡¢µç×ÓÓʼþ¡¢Ð×÷ƽ̨ºÍÖÖÖÖÄÚ²¿ÏµÍ³Ì±»¾¡£MazeÀÕË÷²¡¶¾£¨ÓÖÃûChaCha£©ÓÚ2019Äê5ÔÂÊ״α»·¢Ã÷£¬Ã¿´ÎÉù³ÆÒÔÇÔÈ¡Êý¾ÝΪĿµÄ£¬µ«Êܺ¦Õßδ֧¸¶Êê½ð£¬Í¨³£»á±»Ð¹Â¶»ò³öÊÛÃô¸ÐÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/canon-ransomware-attack-employee-note/158157/
9. ÍøÂç´¹ÂÚÓʼþÐ®ÖÆMicrosoft 365ÕÊ»§
¡¾¸ÅÊö¡¿
ÍøÂç×ï·¸Ô½À´Ô½¶àµØÃ°³äÊÜÐÅÍеÄSaaSƽ̨ºÍ¹©Ó¦ÉÌ¡£×î½ü£¬ÔÚÒ»Æð´¹ÂÚ¹¥»÷Ô˶¯ÖУ¬µç×ÓÓʼþÖÐÓÐÐí¶àÊÔͼÓÕʹÊÕ¼þÈ˵¥»÷¶ñÒâÁ´½Ó£¬¸ÃÁ´½ÓÖ¸Ïò°üÀ¨Æ¾Ö¤ÍøÂç¶ñÒâÈí¼þµÄÒ³Ãæ£¬¹¥»÷ÕßʹÓÃÊÜѬȾµÄMicrosoft 365ÕÊ»§ÔÚ¼¸¸öСʱÄÚ»á¼û¶à¸öÆäËûÕÊ»§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.darktrace.com/en/blog/phishing-from-the-inside-microsoft-365-account-hijack/
10. PyPI¹Ù·½¿ÍÕ»Ôârequest¶ñÒâ°üͶ¶¾
¡¾¸ÅÊö¡¿
¹¥»÷Õß½«request¶ñÒâ´¹ÂÚ°üÉÏ´«ÖÁPyPI¹Ù·½¿ÍÕ»£¬²¢Í¨¹ý¸Ã´¹ÂÚ°üʵÑéÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢¼°Êý×ÖÇ®±ÒÃÜÔ¿¡¢ÝªÖ²³¤ÆÚ»¯ºóÃÅ¡¢Ô¶³Ì¿ØÖƵÈһϵÁй¥»÷Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1073.html

AG¹«Ë¾ÔÆ







