AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2020Äê10Ô£©
2020-10-29
10Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬Windows TCP/IPÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2020-16898£©ÒÔ¼°VMware ESXi Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3992£©Ó°Ïì½Ï´ó¡£Îó²îCVSSÆÀ·Ö¾ùΪ9.8£¬Ç°ÕßÓÉÓÚWindows TCP/IPÐÒéÕ»ÔÚ´¦Öóͷ£IMCPv6 Router AdvertisementÊý¾Ý°üʱ±£´æÎó²î£¬¹¥»÷Õß¿ÉÏòÊÜÓ°ÏìÖ÷»ú·¢ËÍÌØÖÆµÄICMPv6 Router AdvertisementÊý¾Ý°ü¾ÙÐÐʹÓã¬ÊµÏÖÔÚÄ¿µÄ·þÎñÆ÷»ò¿Í»§¶ËÉÏÖ´ÐÐí§Òâ´úÂë £»ºóÕßÓÉÓÚÔÚÖÎÀíÍøÂ磨management network£©ÖпÉÒÔͨ¹ý427¶Ë¿Ú´¥·¢Ò»¸öOpenSLP·þÎñµÄuser-after-freeÎó²î£¬Ê¹¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË11¸öCritical¼¶±ðÎó²î£¬75 ¸ö Important ¼¶±ðÎó²î£¬1¸öModerate ¼¶±ðÎó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬Ó¿ÏÖ³öÁ˸ü¶àµÄ¹¥»÷¹¤¾ß°ü£¬Í¬Ê±¹¥»÷¸ü¾ßÓÐÕë¶ÔÐÔ¡£¹¥»÷Êֶη½Ã棬ʹÓõç×ÓÓʼþºÍÎó²î¾ÙÐÐÈö²¥ÒÀ¾É½ÏΪ³£¼û¡£¹¥»÷×éÖ¯·½Ã棬ÓëÒÁÀÊÓÐÁªÏµµÄSeedwÌØ¹¤×éÖ¯Õë¶ÔÖж«Õþ¸®×éÖ¯µÄ¹¥»÷ÐèÒªÒýÆð¹Ø×¢¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2020Äê10ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼37¸öÎó²î, ÆäÖиßΣÎó²î12¸ö£¬Î¢Èí¸ßΣÎó²î5¸ö¡£

* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2020.10.28
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. HEH½©Ê¬ÍøÂçÕë¶Ôtelnet·þÎñ
¡¾±êÇ©¡¿HEH
¡¾Ê±¼ä¡¿2020-10-05
¡¾¼ò½é¡¿
HEH½©Ê¬ÍøÂçÑù±¾×î³õÊÇÓÉÃûΪwpqnbw.txtµÄ¶ñÒâShell¾ç±¾ÏÂÔØ²¢Ö´Ðеġ£¸Ã¶ñÒâShell¾ç±¾½«ÏÂÔØ²¢Ö´ÐÐÕë¶ÔËùÓвî±ðCPU¼Ü¹¹µÄÿ¸ö¶ñÒâ³ÌÐò£¬ÎÞÐè¾ÙÐÐÇéÐμì²é»òÀàËÆ²Ù×÷£¬Ö»ÐèÒÀ´ÎÔËÐÐËùÓгÌÐò¼´¿É¡£¶ñÒâ¾ç±¾ºÍ¶þ½øÖƳÌÐòλÓÚpomf.catÍøÕ¾ÉÏ£¨Çë×¢ÖØ£¬prmf.catÊÇÕýµ±ÍøÕ¾£¬ÇëÎð×èÖ¹Ëü£©¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.netlab.360.com/heh-an-iot-p2p-botnet/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡9ÌõIOC£¬ÆäÖаüÀ¨9¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. MontysThreeʹÓÃÒþдÊõºÍ¼ÓÃܼƻ®¾ÙÐÐÉèÖýâÃÜ
¡¾±êÇ©¡¿MontysThree
¡¾Ê±¼ä¡¿2020-10-07
¡¾¼ò½é¡¿
¶ñÒâÈí¼þ°üÀ¨Ò»×éÓÃÓÚ³¤ÆÚÐÔµÄC ++Ä£¿é£¬Ê¹ÓÃÒþдÊõ´Óλͼ»ñÈ¡Êý¾Ý£¬½âÃÜÉèÖÃʹÃü£¨ÖÆ×÷ÆÁÄ»½ØÍ¼£¬¶ÔÄ¿µÄ¾ÙÐÐÖ¸ÎÆÊ¶±ð£¬»ñÈ¡ÎļþµÈ£©¼°ÆäÖ´ÐÐÒÔ¼°ÓëÖ÷ÒªÕýµ±¹«ÖÚµÄÍøÂçͨѶ¡£ÔÆ·þÎñ£¬ÀýÈçGoogle£¬MicrosoftºÍDropbox¡£MontysThreeÉèÖÃΪËÑË÷´æ´¢ÔÚÄ¿½ñÎĵµÄ¿Â¼ºÍ¿ÉÒÆ¶¯Ã½ÌåÖеÄÌØ¶¨Microsoft OfficeºÍAdobe AcrobatÎĵµ¡£¸Ã¶ñÒâÈí¼þʹÓÃ×Ô½ç˵ÒþдÊõºÍ¶àÖÖ¼ÓÃܼƻ®£º³ýÁË»ùÓÚXORµÄ×Ô½ç˵¼ÓÃÜÍ⣬ÕâЩģ¿é»¹ÒÀÀµ3DESºÍRSAËã·¨¾ÙÐÐÉèÖýâÃܺÍͨѶ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/montysthree-industrial-espionage/98972/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡14ÌõIOC£¬ÆäÖаüÀ¨5¸öÓòÃûºÍ9¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. ͨ¹ýµç×ÓÓʼþÈö²¥SlothfulMedia¶ñÒâÈí¼þ
¡¾±êÇ©¡¿SlothfulMedia
¡¾Ê±¼ä¡¿2020-10-13
¡¾¼ò½é¡¿
½üÆÚ£¬Ðû²¼ÁËÓйØÃûΪSlothfulMediaµÄ¶ñÒâÈí¼þ¼Ò×åµÄÐÅÏ¢£¬ÕâЩÐÅÏ¢¹é¹¦ÓÚÖØ´óµÄÍþв¼ÓÈëÕߣ¬È·¶¨Á˸ÃÍþв¼ÓÈëÕßʹÓõÄÈýÖÖ²î±ðµÄ¶ñÒâÈí¼þ¼Ò×壬ÆäÖÐÖ®Ò»ÊÇSlothfulMedia¡£ËüÊÇͨ¹ý°üÀ¨¶ñÒâWordÎĵµµÄÓã²æÊ½ÍøÂç´¹ÂÚµç×ÓÓʼþ·Ö·¢µÄ£¬µ«ÎÞ·¨»ñÈ¡ÆäÖеÄÑù±¾¡£Ñ¬È¾Àú³ÌÒÀÀµÓÚPowerShell¾ç±¾£¬¸Ã¾ç±¾´ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÒþ²ØÔÚÓ³ÏñÎļþÖеÄbase64±àÂëµÄÓÐÓøºÔØ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/iamtheking-and-the-slothfulmedia-malware-family/99000/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡11ÌõIOC£¬ÆäÖаüÀ¨11¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. ÐÂÎó²î×÷Ϊ¹¥»÷ǰÑÔÀ´×ª´ïMirai±äÌå
¡¾±êÇ©¡¿Mirai
¡¾Ê±¼ä¡¿2020-10-14
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±ÊӲ쵽Á½ÖÖÎïÁªÍøÎó²îÒÔ¼°¹¥»÷ʱ´úÌṩµÄËÄÖÖMirai±äÌå¡£×î½ü·¢Ã÷ÁË×ܹ²ËĸöMirai±äÌ壬ʹÓÃÁ½¸öÐÂÎó²î×÷Ϊ¹¥»÷ǰÑÔÀ´×ª´ïMirai¡£ÀÖ³ÉʹÓú󣬽«Å²ÓÃwgetÊÊÓóÌÐò´Ó¶ñÒâÈí¼þ»ù´¡½á¹¹ÖÐÏÂÔØShell¾ç±¾£¬È»ºóshell¾ç±¾»áÏÂÔØÎª²î±ð¼Ü¹¹±àÒëµÄ¶à¸öMirai¶þ½øÖÆÎļþ£¬²¢ÖðÒ»Ö´ÐÐÕâЩÏÂÔØµÄ¶þ½øÖÆÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/iot-vulnerabilities-mirai-payloads/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡13ÌõIOC£¬ÆäÖаüÀ¨13¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. Purple Fox¹¥»÷¹¤¾ß°üÕë¶ÔInternet Explorer
¡¾±êÇ©¡¿Purple Fox
¡¾Ê±¼ä¡¿2020-10-18
¡¾¼ò½é¡¿
ÏÖÔÚ£¬Purple Fox½«CVE-2020-0674ºÍCVE-2019-1458Ìí¼Óµ½ÆäÎäÆ÷¿âÖУ¬Óпª·¢Ö°Ô±ÒÑÔٴξÙÐеü´ú£¬Ìí¼ÓÁ˸ü¶àCVEÒÔʵÏÖÌØÈ¨Éý¼¶£¬²¢½ÓÄÉÒþдºÍÐéÄ⻯ÊÖÒÕÀ´×èÖ¹¼ì²âºÍ¹ÊÕÏÆÊÎö¡£Í¨¹ý¹ã¸æ»ò½öͨ¹ýµ¥»÷¹ýʧµÄURL½«Êܺ¦Õß¶¨Ïòµ½¶ñÒâÕ¾µã¡£¹¥»÷Õß½«ËûÃǵĶñÒâÈí¼þÍйÜÔÚspeedjudgmentacceleration [.com]ÉÏ£¬²¢Õë¶ÔInternet ExplorerÓû§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://labs.sentinelone.com/purple-fox-ek-new-cves-steganography-and-virtualization-added-to-attack-flow/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡19ÌõIOC£¬ÆäÖаüÀ¨4¸öÓòÃûºÍ15¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. SeedwÌØ¹¤×éÖ¯Õë¶ÔÖж«Õþ¸®×éÖ¯
¡¾±êÇ©¡¿Seedw
¡¾Ê±¼ä¡¿2020-10-20
¡¾¼ò½é¡¿
ÓëÒÁÀÊÓÐÁªÏµµÄÌØ¹¤×éÖ¯Seedworm£¨ÓÖÃûMuddyWater£©ÔÚ×î½ü¼¸¸öÔÂÒ»Ö±·Ç³£»îÔ¾£¬¹¥»÷ÁËÆÕ±éµÄÄ¿µÄ£¬°üÀ¨Öж«µÄÐí¶àÕþ¸®×éÖ¯¡£Ðí¶àÊܵ½Seedworm¹¥»÷µÄ×éÖ¯Ò²Êܵ½ÁË×î½ü·¢Ã÷µÄÃûΪPowGoop£¨Downloader.Covic£©µÄ¹¤¾ßµÄ¹¥»÷£¬Åú×¢¸Ã¹¤¾ßÒѳÉΪSeedwormÄÉÈëÆäÎäÆ÷¿âµÄ¹¤¾ß¡£ÔÚÒÁÀ¿Ë£¬ÍÁ¶úÆä£¬¿ÆÍþÌØ£¬°¢À²®ÍŽáÇõ³¤¹úºÍ¸ñ³¼ªÑÇ·¢Ã÷ÁËÕë¶ÔÄ¿µÄµÄÏ®»÷¡£³ýÁËһЩÕþ¸®ÊµÌ壬µçÐźÍÅÌËã»ú·þÎñ²¿·ÖµÄ×éÖ¯Ò²³ÉΪĿµÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/seedworm-apt-iran-middle-east
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡30ÌõIOC£¬ÆäÖаüÀ¨9¸öIPºÍ21¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







