¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021Äê1Ô£©
2021-02-01
1Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬Windows NTFS Ô¶³Ì´úÂëÖ´ÐÐÎó²î CVE-2020-17096ÒÔ¼°Linux sudoȨÏÞÌáÉýÎó²î£¨CVE-2021-3156£©Ó°Ïì½Ï´ó¡£Ç°ÕßÓÉÓÚWindows NTFS ±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÍâµØ¹¥»÷Õß¿Éͨ¹ýÔËÐÐÌØÖÆµÄÓ¦ÓóÌÐò£¬´Ó¶øÌáÉýÓû§µÄȨÏÞ£¬¾ßÓÐ SMBv2 »á¼ûȨÏÞµÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆµÄÇëÇó£¬Ê¹ÓôËÎó²îÔÚÄ¿µÄϵͳÉÏÖ´ÐдúÂ룻ºóÕßÓÉÓÚµ±sudoͨ¹ý-s»ò-iÏÂÁîÐÐÑ¡ÏîÔÚshellģʽÏÂÔËÐÐÏÂÁîʱ£¬Ëü½«ÔÚÏÂÁî²ÎÊýÖÐʹÓ÷´Ð±¸ÜתÒåÌØÊâ×Ö·û¡£µ«Ê¹ÓÃ-s»ò -i±ê¼ÇÔËÐÐsudoeditʱ£¬ÏÖʵÉϲ¢Î´¾ÙÐÐתÒ壬´Ó¶ø¿ÉÄܵ¼Ö»º³åÇøÒç³ö¡£Ö»Òª±£´æsudoersÎļþ£¨Í¨³£ÊÇ /etc/sudoers£©£¬¹¥»÷Õ߾ͿÉÒÔʹÓÃÍâµØÍ¨Ë×Óû§Ê¹ÓÃsudo»ñµÃϵͳrootȨÏÞ¡£
ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË9¸öCritical¼¶±ðÎó²î£¬73¸öImportant ¼¶±ðÎó²î£¬1¸öModerate¼¶Îó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬ÔÆ·þÎñÆ÷ÒÀÈ»ÊǺڿÍ×éÖ¯½ø¹¥µÄÖØµã£¬ÊܽüÆÚ±ÈÌØ±Ò±©ÕÇ·¢¶¯Êý×ÖÐéÄâ±ÒÕûÌåÊÐÖµìÉýÓ°Ï죬ÍÚ¿óľÂíÊ®·Ö»îÔ¾¡£¹¥»÷Êֶη½Ã棬·ºÆðÁËʹÓÃIRC¾ÙÐÐͨѶ¿ØÖÆ·þÎñÆ÷×é¼þ½©Ê¬ÍøÂ磬ÒÔ¼°Í¨¹ýState Cashbackµç×ÓÖ§¸¶¹¤¾ß¾ÙÐжñÒâÈí¼þÈö²¥µÄ¹¥»÷·½·¨¡£Í¬Ê±£¬incaseformatÈ䳿²¡¶¾µÄÔٴλîÔ¾ÐèÒªÒýÆð¹Ø×¢¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2021Äê01ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼375¸öÎó²î, ÆäÖиßΣÎó²î46¸ö£¬Î¢Èí¸ßΣÎó²î10¸ö¡£

* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2021.01.28
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. TOPMinerÍÚ¿óľÂíͨ¹ýSSHÈõ¿ÚÁî±¬ÆÆ¹¥»÷Ô¼1.5Íǫ̀·þÎñÆ÷
¡¾±êÇ©¡¿TOPMiner
¡¾Ê±¼ä¡¿2021-01-04
¡¾¼ò½é¡¿
ÍÚ¿óľÂíTopMiner½üÆÚ¹¥»÷Ê®·Ö»îÔ¾£¬¸ÃľÂíͨ¹ýSSHÈõ¿ÚÁî±¬ÆÆ¾ÙÐй¥»÷ÈëÇÖ£¬»áɨ³ý¾ºÆ·ÍÚ¿óľÂí£¬Í¬Ê±»áʹÓñ¬ÆÆ¹¤¾ßÔÚÄÚÍøºáÏòÈö²¥¡£Æ¾Ö¤ÆäÍÚ¿óÇ®°üÊÕÒæ¹ÀË㣬ԼÓÐ1.5Íǫ̀·þÎñÆ÷±»¸ÃÍÅ»ï¿ØÖÆÍÚ¿ó¡£ÓÉÓÚÆäʹÓõÄÍÚ¿óľÂíÃûΪtop£¬Ñо¿Ö°Ô±½«ÆäÃüÃûΪTopMinerÍÚ¿óľÂí¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1213.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡10ÌõIOC£¬ÆäÖаüÀ¨1¸öIP£¬1¸öÓòÃûºÍ8¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. ºÚ¿Íͨ¹ýState Cashback·Ö·¢µç×ÓÓʼþÈö²¥¶ñÒâÈí¼þµÄ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿State Cashback
¡¾Ê±¼ä¡¿2021-01-05
¡¾¼ò½é¡¿
ͨ¹ýʹÓÃ×î½üµÄÏÖ½ðÍË¿îÍýÏëÀ´¾ÙÐеç×ÓÀ¬»øÓʼþÔ˶¯£¬ÒÔÈö²¥¶ñÒâÈí¼þ£¬¸ÃÍýÏëÓÃÓÚʹÓõç×ÓÖ§¸¶¹¤¾ß£¨¸üÃûΪState Cashback£©¾ÙÐеĹºÖá£
¡¾²Î¿¼Á´½Ó¡¿
https://cert-agid.gov.it/news/malware/falsa-comunicazione-cashback-di-stato-veicola-malware/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡5ÌõIOC£¬ÆäÖаüÀ¨2¸öÓòÃûºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. golangÓïÑÔ±àдµÄ¾ç±¾Ä¾ÂíʹÓöà¸ö²î±ðlinux·þÎñÆ÷×é¼þµÄ¸ßΣÎó²îÈëÇÖÔÆ·þÎñÆ÷
¡¾±êÇ©¡¿golang
¡¾Ê±¼ä¡¿2021-01-11
¡¾¼ò½é¡¿
ÊܽüÆÚ±ÈÌØ±Ò±©ÕÇ·¢¶¯Êý×ÖÐéÄâ±ÒÕûÌåÊÐÖµìÉýÓ°Ï죬ÍÚ¿óľÂíÊ®·Ö»îÔ¾¡£Ê¹ÓÃRedisδÊÚȨ»á¼ûÎó²îÖ±½ÓдÈëÍýÏëʹÃü£¬ÏÂÔØÓÃgolangÓïÑÔ±àдµÄÍÚ¿óľÂíÏÂÔØÆ÷superman£¬Æ¾Ö¤ÍÚ¿óËãÁ¦ÍƲâ¸ÃÍÅ»ïÒÑ¿ØÖÆÔ¼1Íǫ̀ʧÏÝϵͳ¾ÙÐÐÃÅÂÞ±ÒÍÚ¿ó¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1219.html,https://paper.seebug.org/1440/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. еÄAndroidÌØ¹¤Èí¼þÕë¶Ô°Í»ù˹̹µÄÓû§ÇÔÈ¡Ãô¸ÐÊý¾ÝµÄ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿Android
¡¾Ê±¼ä¡¿2021-01-12
¡¾¼ò½é¡¿
ÏÖÔÚÓÐÑо¿Ö°Ô±ÒÑ·¢Ã÷һСȺľÂí°æ±¾µÄAndroidÓ¦ÓóÌÐò£¬Ö÷ÒªÏúÊÛ¸øÆÜÉíÔÚ°Í»ù˹̹µÄÈË¡£ÓÐÈËÐÞ¸ÄÁËÕâЩԱ¾Õýµ±µÄÓ¦ÓóÌÐò£¨¿É´ÓGoogle PlayÊÐËÁÏÂÔØÕýµ±°æ±¾£©£¬Èô˳ÌÐòÌí¼ÓÉñÃØ¼àÊÓºÍÌØ¹¤Ô˶¯µÄ¶ñÒ⹦Ч¡£
¡¾²Î¿¼Á´½Ó¡¿
https://news.sophos.com/en-us/2021/01/12/new-android-spyware-targets-users-in-pakistan/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡27ÌõIOC£¬ÆäÖаüÀ¨4¸öIP£¬4¸öÓòÃûºÍ19¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. Ìð˯¶àÄêµÄincaseformatÈ䳿²¡¶¾±»½ÐÐÑ
¡¾±êÇ©¡¿incaseformat
¡¾Ê±¼ä¡¿2021-01-13
¡¾¼ò½é¡¿
2021Äê1ÔÂ13ÈÕ£¬AG¹«Ë¾¿Æ¼¼Ó¦¼±ÏìÓ¦ÍŶӽӵ½Ìì϶à¸ö¿Í»§·´ÏìѬȾËùνµÄincaseformat²¡¶¾£¬Éæ¼°Õþ¸®¡¢Ò½ÁÆ¡¢½ÌÓý¡¢ÔËÓªÉ̵ȶà¸öÐÐÒµ£¬ÇÒѬȾÖ÷»ú¶àΪ²ÆÎñÖÎÀíÏà¹ØÓ¦ÓÃϵͳ¡£Ñ¬È¾Ö÷»úÌåÏÖΪËùÓзÇϵͳ·ÖÇøÎļþ¾ù±»É¾³ý£¬ÓÉÓÚ±»É¾³ýÎļþ·ÖÇø¸ùĿ¼Ï¾ù±£´æÃûΪincaseformat.logµÄ¿ÕÎļþ£¬Òò´ËÍøÂçÉϽ«´Ë²¡¶¾ÃüÃûΪincaseformat¡£´ÓËÑË÷ÒýÇæÐ§¹ûÀ´¿´£¬¸Ã²¡¶¾×îÔç·ºÆðʱ¼äΪ2009Ä꣬Ö÷Á÷ɱ¶¾Èí¼þ³§É̾ù½«´Ë²¡¶¾ÃüÃûΪWorm.Win32.Autorun£¬´ÓÃû³Æ¿ÉÒÔÅжϸò¡¶¾ÎªWindowsƽ̨ͨ¹ýÒÆ¶¯½éÖÊÈö²¥µÄÈ䳿²¡¶¾¡£²¡¶¾ÎļþÔËÐкó£¬Ê×Ïȸ´ÖÆ×ÔÉíµ½WindowsĿ¼Ï£¬Îļþͼ±êαװΪÎļþ¼Ð¡£²¡¶¾Îļþ½«ÔÚÖ÷»úÖØÆôºóÔËÐУ¬²¢×îÏȱéÀúËùÓзÇϵͳ·ÖÇøÏÂĿ¼²¢ÉèÖÃΪÒþ²Ø£¬Í¬Ê±½¨ÉèͬÃûµÄ²¡¶¾Îļþ¡£±ðµÄ»¹»áͨ¹ýÐÞ¸Ä×¢²á±í£¬ÊµÏÖ²»ÏÔʾÒþ²ØÎļþ¼°Òþ²ØÒÑÖªÎļþÀàÐÍÀ©Õ¹Ãû¡£×îºó¶Ô·Çϵͳ·ÖÇøÏÂËùÓÐÎļþÖ´ÐÐɾ³ý²Ù×÷£¬²¢½¨Éèincaseformat.logÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://m.threatbook.cn/detail/3157
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡558ÌõIOC£¬ÆäÖаüÀ¨558¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. TeamTNT бäÖÖʹÓÃIRC¾ÙÐÐͨѶ¿ØÖÆ·þÎñÆ÷×齨½©Ê¬ÍøÂçµÄ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿TeamTNT
¡¾Ê±¼ä¡¿2021-01-14
¡¾¼ò½é¡¿
TeamTNT ±äÖÖʹÓÃIRC¾ÙÐÐͨѶ¿ØÖÆÈ⼦·þÎñÆ÷×齨½©Ê¬ÍøÂ磬´Ë´ÎʹÓõÄIRC ½ÓÄɵÄÊÇgithub¿ªÔ´µÄoragono£¬ÔÝδ¼ì²âµ½ºóÃÅÓÐÖ´Ðоܾø·þÎñ£¨DoS£©¹¦Ð§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1226.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡11ÌõIOC£¬ÆäÖаüÀ¨3¸öIP£¬3¸öÓòÃûºÍ5¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
7. RunMinerÍÚ¿óľÂíÍÅ»ïʹÓÃÐÂÔöÎó²î¹¥»÷ÔÆÖ÷»ú¾ÙÐÐÍÚ¿ó
¡¾±êÇ©¡¿RunMiner
¡¾Ê±¼ä¡¿2021-01-19
¡¾¼ò½é¡¿
RunMinerÍÚ¿óľÂíÍÅ»ïʹÓÃÐÂÔöÎó²îÎäÆ÷¹¥»÷ÔÆÖ÷»úÍÚ¿ó£º Ê¹ÓÃweblogic·´ÐòÁл¯Îó²î£¨CVE-2017-10271£©¶ÔÔÆÖ÷»úÌᳫ¹¥»÷£¬¹¥»÷ÀֳɺóÖ´ÐжñÒâ¾ç±¾¶ÔLinux¡¢Windows˫ƽֲ̨ÈëÍÚ¿óľÂí£¬¾ÙÐÐÃÅÂÞ±ÒÍÚ¿ó²Ù×÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1229.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡7ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ6¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
8. Lazarus ×éÖ¯Õë¶ÔÎó²îÇå¾²Ñо¿Ô±¾ÙÐд¹ÂÚ¹¥»÷
¡¾±êÇ©¡¿Lazarus
¡¾Ê±¼ä¡¿2021-01-26
¡¾¼ò½é¡¿
´Ë´ÎÊÂÎñÓÉGoogleÇå¾²ÍŶÓÅû¶¡£¹¥»÷Õßͨ¹ýÔÚTwitter½¨Éè¶à¸öÇå¾²Ñо¿ÕßÕ˺ţ¬Ðû²¼´ó×ÚµÄÎó²îÆÊÎöÎÄÕÂÎüÒýÎó²îÇå¾²Ñо¿ÕߵĹØ×¢£¬Í¬Ê±½¨ÉèÁËÒ»¸öÑо¿²©¿Í£¬Ðû²¼0dayÏà¹ØµÄÎó²îÑо¿¼°ÆÊÎö¡£Í¨¹ýÕâÒ»ÒªÁ죬ɸѡ²¢ÕÒµ½Ç±ÔÚµÄÄ¿µÄ£¬²¢ÓëÖ®»¥¶¯¡£¹¥»÷ÕßʹÓÃÁËÑо¿ÕßÐèҪʵʱ¹Ø×¢ÐÐÒµÖÐÎó²îÅû¶״̬µÄÐÄÀí£¬ÀÖ³ÉÎüÒýÁËһЩÑо¿ÕߵĹØ×¢£¬²¢Í¨¹ý˽Ðŵȷ½·¨£¬ÇëÇóÓëÑо¿Õß¼´Ç±ÔڵĹ¥»÷Ä¿µÄÒ»ÆðÆÊÎöËùνµÄ0day£¬ÔÚÑо¿ÕßÔÊÐíÏàÖúºó£¬·¢ËÍËùνµÄ“POC”¹¤³ÌÎļþ£¬¸ÃαÔìµÄPOC¹¤³ÌÎļþÊÇÒ»¸öVS Studio¹¤³ÌÎļþ£¬ÆäÖÐǶÈëÁ˶ñÒâ´úÂë¡£µ±Ñо¿Ö°Ô±·¿ª¸Ã¹¤³ÌÎļþºó£¬¶ñÒâ´úÂë»áÁ¬Ã¦ÔËÐÐÆðÀ´¡£Æ¾Ö¤GoogleÑо¿ÍŶÓÅû¶µÄÐÅÏ¢£¬ÓÐЩÑо¿Ö°Ô±»á¼û¹¥»÷ÕßÔËÓªµÄÑо¿²©¿ÍʱҲѬȾÁ˲¡¶¾£¬µ«Ñо¿Ö°Ô±µÄChromeä¯ÀÀÆ÷Ϊ×îа汾£¬ÓÉ´ËÍÆ²â¿ÉÄܱ£´æä¯ÀÀÆ÷0day¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡12ÌõIOC£¬ÆäÖаüÀ¨7¸öÓòÃûºÍ5¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







