AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2020.11Ô£©
2020-12-01
11Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬WindowsÍøÂçÎļþϵͳԶ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17051£©ÒÔ¼°Cisco IMCÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3470£©Ó°Ïì½Ï´ó¡£Ç°ÕßÓÉÓÚWindows NFS v3·þÎñÆ÷Öб£´æ¿ÉÔ¶³ÌʹÓõĶÑÒç³öÎó²î¡£ÔÚnfssvr.sysÎļþµÄijº¯ÊýÖУ¬Ä³´¦×Ö·û´®ANSIת»»ÎªUNICODEºó£¬Å²ÓÃÁËmemcpy£¬´Ó¶øÔì³ÉÁË»º³åÇøÒç³ö£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÀ´»á¼ûϵͳ£¬²¢Í¨¹ýÈ«ÐÄÖÆ×÷µÄNFSÊý¾Ý°üÔ¶³ÌÖ´ÐжñÒâ´úÂ룻ºóÕßÓÉÓÚ˼¿Æ¼¯³ÉÖÎÀí¿ØÖÆÆ÷£¨IMC£©µÄAPI Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î,¶ÔÓû§ÊäÈëÄÚÈݵÄÑé֤ȱ·¦£¬Î´¾ÊÚȨµÄ¹¥»÷Õß¿Éͨ¹ýÏòÊÜÓ°ÏìµÄϵͳ·¢ËÍÌØÖÆµÄHTTP ÇëÇó£¬ÀÖ³ÉʹÓôËÎó²î¿ÉʹÓÃÖÎÀíԱȨÏÞÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË17¸öCritical¼¶±ðÎó²î£¬93¸öImportant ¼¶±ðÎó²î£¬2¸öLow¼¶Îó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬ÔÆ·þÎñÆ÷³ÉΪÁ˺ڿͽø¹¥µÄÖØµã£¬ÒÔ´ËÀ´µÖ´ïÍÚ¿ó»òÈëÇÖµÄÄ¿µÄ£»Æä´ÎÊÇʹÓÃÃÀ¹ú´óÑ¡×÷ΪÓÕ¶üʵÑéµÄ¹¥»÷¡£¹¥»÷Êֶη½Ã棬·ºÆðÁËʹÓÃÕýµ±µÄÇå¾²Èí¼þ¹©Ó¦Á´À´Èö²¥µÄз½·¨¡£¹¥»÷×éÖ¯·½Ã棬ÒÉËÆ¾ßÓж«±±ÑÇÅä¾°µÄKimsuky×é֯ʹÓÃÃÀ¹ú´óÑ¡¾ÙÐеĹ¥»÷ÒÔ¼°xHunt×éÖ¯µÄ»îÔ¾ÐèÒªÒýÆð¹Ø×¢¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2020Äê11ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼287¸öÎó²î, ÆäÖиßΣÎó²î68¸ö£¬Î¢Èí¸ßΣÎó²î38¸ö¡£
* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2020.11.27
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. UNC1945Õë¶ÔOracle Solaris²Ù×÷ϵͳ
¡¾±êÇ©¡¿UNC1945
¡¾Ê±¼ä¡¿2020-11-01
¡¾¼ò½é¡¿
UNC1945Õë¶ÔOracle Solaris²Ù×÷ϵͳ£¬Ê¹ÓÃÕë¶ÔWindowsºÍLinux²Ù×÷ϵͳµÄ¶àÖÖ¹¤¾ßºÍÊÊÓóÌÐò£¬¼ÓÔØºÍÔËÐÐ×Ô½ç˵ÐéÄâ»ú£¬²¢½ÓÄÉÁËÌӱܼì²âµÄÊÖÒÕ¡£UNC1945չʾÁ˶ԶàÖÖ²Ù×÷ϵͳµÄ¹¥»÷£¬¹¤¾ßºÍ¶ñÒâÈí¼þµÄ»á¼ûȨÏÞ£¬¶ÔÁýÕÖ»òʹÓÃÆäÔ˶¯µÄÑÏ¿áÐËȤ£¬²¢ÔÚ½»»¥²Ù×÷Àú³ÌÖÐչʾÁ˸߼¶ÊÖÒÕÄÜÁ¦¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.fireeye.com/blog/threat-research/2020/11/live-off-the-land-an-overview-of-unc1945.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡8ÌõIOC£¬ÆäÖаüÀ¨2¸öIPºÍ6¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. Kaiji DDoSľÂíͨ¹ýSSH±¬ÆÆÈëÇÖ·þÎñÆ÷
¡¾±êÇ©¡¿Kaiji DDos
¡¾Ê±¼ä¡¿2020-11-02
¡¾¼ò½é¡¿
¶Ô¸ÃÊÂÎñ¾ÙÐÐËÝÔ´×·²é·¢Ã÷ÓÐÒÉËÆº£ÄÚºÚ¿Í¿ª·¢µÄľÂíKaijiͨ¹ý22¶Ë¿ÚÈõ¿ÚÁî±¬ÆÆÈëÇÖ·þÎñÆ÷¡£¹¥»÷ÕßÈëÇÖÔÆÖ÷ʱ»úÏÂÔØ¶þ½øÖÆÄ¾Âí½«×ÔÉí×°Öõ½ÏµÍ³Æô¶¯Ïî¾ÙÐг¤ÆÚ»¯£¬²¢ÇÒ¿ÉÆ¾Ö¤C2·þÎñÆ÷·µ»ØµÄÖ¸Áî¾ÙÐÐDDoS¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1168.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨1¸öIP£¬1¸öÓòÃûºÍ1¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. Kimsuky×é֯ʹÓÃÃÀ¹ú´óѡΪÓÕ¶ü¾ÙÐÐAPT¹¥»÷
¡¾±êÇ©¡¿Kimsuky
¡¾Ê±¼ä¡¿2020-11-03
¡¾¼ò½é¡¿
Kimsuky×éÖ¯£¬ÓÖÃûMystery Baby£¬Baby Coin£¬Smoke Screen£¬Black Banshe¡£ÒÉËÆ¾ßÓж«±±ÑÇÅä¾°£¬Ö÷ÒªÕë¶Ôº«¹ú£¬¶íÂÞ˹¾ÙÐй¥»÷Ô˶¯£¬×îÔçÓÉ¿¨°Í˹»ùÅû¶¡£º«¹úÇå¾²¹«Ë¾ÒÔΪÆäÓëGroup123±£´æ²¿·ÖÖØµþ¡£¸Ã×éÖ¯×îз¢Ã÷ÒÔÃÀ¹ú´óѡΪÓÕ¶üµÄ¹¥»÷Ñù±¾£¬Ñù±¾ÎÊÌâÊÇÃÀ¹ú×Üͳ´óѡչÍû£¬ÓÕµ¼Êܺ¦Õßµã»÷Ö´ÐУ¬Í¬Ê±½ÓÄÉÔÚHWPÎĵµÖÐǶÈëVBS¾ç±¾·½·¨£¬¿ËÈÕ´ËÑù±¾Î´±»¶à¼ÒɱÈí¼ì²âÀֳɡ£
¡¾²Î¿¼Á´½Ó¡¿
https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247492852&idx=1&sn=432d94f3c21dadcdeadc4ff24f465fd0&chksm=ea661383dd119a952382bda56656a72150814ec3cb581293c6ff0ea3aef693c516a14dc88b6c&mpshare=1&srcid=1106UVleCNSq9LDko1h4plzY&sharer_sharetime=1604639069343&sharer_shareid=158f29a22d03cd699e85703e07b247a8&scene=1&subscene=10000&clicktime=1604639474&enterid=1604639474&ascene=1&devicetype=android-23&version=3.0.31.2998&nettype=3gnet&abtest_cookie=AAACAA%3D%3D&lang=zh_CN&exportkey=AY2BjYF9SXirwzfEttxPlUY%3D&pass_ticket=yNhGtF2ABs5GiW6FVX4cyJIhDe1MVml2NA1olsj74EbIBEbwyG7axwg3mId1qNDT&wx_header=1&platform=win
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡11ÌõIOC£¬ÆäÖаüÀ¨5¸öÓòÃûºÍ6¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. xHunt×é֯ʹÓÃÊÜѬȾExchange·þÎñÆ÷¾ÙÐй¥»÷Ô˶¯
¡¾±êÇ©¡¿xHunt
¡¾Ê±¼ä¡¿2020-11-08
¡¾¼ò½é¡¿
×Ô2018Äê7Ô£¬xHunt×éÖ¯Ò»Ö±ºÜ»îÔ¾£¬ËûµÄÄ¿µÄÊÇ¿ÆÍþÌØÕþ¸®ÒÔ¼°ÔËÊä×éÖ¯¡£×î½üÊӲ쵽ÈëÇÖÁË¿ÆÍþÌØÒ»¼Ò»ú¹¹µÄMicrosoft Exchange Server£¬»¹²»ÏàʶÈëÇÖµÄÏêϸҪÁì¡£»ùÓÚ»á¼û¿ØÖÆÈÕÖ¾ÅÌÎÊ£¬Äܹ»ÅжϹ¥»÷ÕßÒÑÔÚ2019Äê8ÔÂ22ÈÕµ±Ìì»ò֮ǰ»ñµÃÁ˶ÔExchange·þÎñÆ÷µÄ»á¼ûȨÏÞ¡£±¾´ÎÊÂÎñÉæ¼°Á½¸öºóÃÅÆäÖÐÒ»¸ö³ÆÎªTriFive£¬ÁíÒ»¸ö³ÆÎªSnugyÒ²ÊÇCASHY200µÄ±äÌåÒ»ÖÖWeb ShellÓÖ½ÐBumbleBee¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/xhunt-campaign-backdoors/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡10ÌõIOC£¬ÆäÖаüÀ¨5¸öÓòÃûºÍ5¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. ÐÂÍÚ¿óľÂíLoggerMiner£¬¹¥»÷ºó¿ÉѬȾDockerÈÝÆ÷
¡¾±êÇ©¡¿LoggerMiner
¡¾Ê±¼ä¡¿2020-11-15
¡¾¼ò½é¡¿
ÍÚ¿óľÂíLoggerMiner£¬¸ÃľÂíÔÚÔÆÉÏÖ÷»úÖй¥»÷Èö²¥£¬»áʹÓÃÄ¿½ñÖ÷»úÉϵÄsshÕ˺ÅÐÅÏ¢¶ÔÆäËûÖ÷»úÌᳫ¹¥»÷£¬ÒÔ¿ØÖƸü¶àϵͳ¡£²¢ÇÒ£¬LoggerMiner»¹»áʵÑé¶ÔÄ¿½ñÖ÷»úÉϵÄdockerÈÝÆ÷¾ÙÐÐѬȾ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1177.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡9ÌõIOC£¬ÆäÖаüÀ¨2¸öIP£¬1¸öÓòÃûºÍ6¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. Lazarus¶ñÒâÈí¼þͨ¹ýº«¹úµÄ¹©Ó¦Á´¹¥»÷¾ÙÐÐÈö²¥
¡¾±êÇ©¡¿supply-chain
¡¾Ê±¼ä¡¿2020-11-15
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±×î½ü·¢Ã÷£¬ESETÒ£²âÊý¾Ýͨ¹ýº«¹úµÄ¹©Ó¦Á´¹¥»÷À´°²ÅÅLazarus¶ñÒâÈí¼þ¡£ÎªÁË·Ö·¢Æä¶ñÒâÈí¼þ£¬¹¥»÷ÕßʹÓÃÁËÒ»ÖÖÌØÊâµÄ¹©Ó¦Á´»úÖÆ£¬ÀÄÓÃÁËÕýµ±µÄº«¹úÇå¾²Èí¼þÓëÇÔÈ¡µÄÁ½¼Ò¹«Ë¾Êý×ÖÖ¤Êé¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2020/11/16/lazarus-supply-chain-attack-south-korea/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡10ÌõIOC£¬ÆäÖаüÀ¨10¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







