¡¾Ç徲ͨ¸æ¡¿FireEye ÔâÍøÂç¹¥»÷£¬ºì¶Ó¹¤¾ß±»µÁ
2020-12-09
ÊÂÎñ¸ÅÊö
ÍâµØÊ±¼ä12ÔÂ8ÈÕ£¬¾ÝFireEye²©¿ÍÐû²¼£¬Ä³¸ß¼¶×é֯͵ȡÁËFireEyeºì¶Ó¹¤¾ß¡£ÓÉÓÚÔݲ»¿ÉÈ·¶¨¹¥»÷Õß½«×Ô¼ºÊ¹Óñ»µÁ¹¤¾ßÕվɹûÕæÅû¶£¬ÒÔÊÇFireEyeÂÊÏÈÔÚ²©¿ÍÖÐÐû²¼¶Ô²ß£¬ÒÔʹ¸÷×éÖ¯¹»Ìáǰ½ÓÄÉÓ¦¶Ô²½·¥¡£
±»µÁ¹¤¾ß¼ò½é
±»µÁºì¶Ó¹¤¾ßµÄÖÖÀà°üÀ¨ÓÃÓÚ×Ô¶¯Õì̽µÄ¼òÆÓ¾ç±¾µ½ÓëCobaltStrike¡¢MetasploitµÈÊÖÒÕÀàËÆµÄÕûÌå¿ò¼Ü¡£ÆäÖÐÐí¶à¹¤¾ßÒÑÏòÉçÇø»òÔÚÆä¿ªÔ´ÐéÄâ»úCommandoVMÖÐÐû²¼¡£ÕâЩ¹¤¾ßÖÐһЩÊǾÓÉÐÞ¸ÄÒÔÌӱܻù±¾Çå¾²¼ì²â»úÖÆµÄ¹ûÕæ¹¤¾ß£¬ÁíһЩ¹¤¾ßºÍ¿ò¼ÜÔòÊÇÓɺì¶ÓÄÚ²¿¿ª·¢¡£
´Ë´Î±»µÁµÄºì¶Ó¹¤¾ßÖв¢²»°üÀ¨ 0day Îó²îµÄʹÓã¬Ò²²»°üÀ¨Î´¹ûÕæÊÖÒÕ¡£
ÏÖÔÚ»¹ÔÝδ¼ì²âµ½¹¤¾ß±»É¢²¥ºÍʹÓá£
ʶ±ð¼ì²âÒªÁì
ΪÁË×ÊÖú×éÖ¯Äܹ»Ê¶±ðµ½ÕâЩ¹¤¾ß£¬FireEye ÒÑÐû²¼OpenIOC£¬Yara£¬SnortºÍClamAV¼ì²â¹æÔò¡£Ïêϸ¹æÔòÏê¼û£ºhttps://github.com/fireeye/red_team_tool_countermeasures
±¸×¢£º¹æÔòÁÐ±í»¹»áÒ»Á¬¸üС£
ÐèÌØÊâ¹Ø×¢µÄCVE
±ðµÄ£¬ÐÞ¸´ÒÔÏÂÎó²îÄÜÓÐÓÃÏÞÖÆºì¶Ó¹¤¾ßʩչ×÷Óãº
|
CVE-2014-1812 |
Windows ÍâµØÌáȨ |
|
CVE-2016-0167 |
Microsoft Windows Àϰ汾ÍâµØÌáȨ |
|
CVE-2017-11774 |
Microsoft OutlookÖÐͨ¹ýÓÕµ¼Óû§ÊÖ¶¯Ö´ÐÐÎĵµ£¨´¹ÂÚ£©ÊµÏÖRCE |
|
CVE-2018-13379 |
Fortinet Fortigate SSL VPNÔ¤ÊÚȨí§ÒâÎļþ¶ÁÈ¡ |
|
CVE-2018-15961 |
Adobe ColdFusion RCE£¨¿ÉÓÃÓÚÉÏ´«JSP Web shell£© |
|
CVE-2018-8581 |
Microsoft Exchange Server ÌØÈ¨ÌáÉý |
|
CVE-2019-0604 |
Microsoft Sharepoint RCE |
|
CVE-2019-0708 |
Windows Ô¶³Ì×ÀÃæ·þÎñ£¨RDS£©RCE |
|
CVE-2019-11510 |
Pulse Secure SSL VPNs Ô¤ÊÚȨí§ÒâÎļþ¶ÁÈ¡ |
|
CVE-2019-11580 |
Atlassian Crowd RCE |
|
CVE-2019-19781 |
CitrixÓ¦Óý»¸¶¿ØÖÆÆ÷ºÍCitrixÍø¹ØµÄRCE |
|
CVE-2019-3398 |
ConfluenceÐè¾ÈÏÖ¤µÄ RCE |
|
CVE-2019-8394 |
ZoHo ManageEngine ServiceDesk Plus Ô¤ÊÚȨí§ÒâÎļþÉÏ´« |
|
CVE-2020-0688 |
Microsoft Exchange RCE |
|
CVE-2020-10189 |
ZoHo ManageEngine Desktop Central RCE |
|
CVE-2020-1472 |
Microsoft Active Directory ÌØÈ¨ÌáÉý |
²Î¿¼Á´½Ó
https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html
https://www.fireeye.com/blog/products-and-services/2020/12/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







