¡¾Ç徲ͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.2.15-2.21£©
2021-02-23
Ò»¡¢ Íþвͨ¸æ
΢Èí2ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ£¨CVE-2021-1727¡¢CVE-2021-1732¡¢CVE-2021-24074£©
¡¾Ðû²¼Ê±¼ä¡¿2021-02-15 14:00:00 GMT
¡¾¸ÅÊö¡¿
΢ÈíÐû²¼2ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË56¸öÇå¾²ÎÊÌâ£¬Éæ¼°Microsoft Windows¡¢Microsoft Office¡¢Microsoft Exchange Server¡¢Visual Studio¡¢Microsoft .NET FrameworkµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²îÓÐ 11 ¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ 43 ¸ö¡£ÇëÏà¹ØÓû§ÊµÊ±¸üв¹¶¡¾ÙÐзÀ»¤£¬ÏêϸÎó²îÁбíÇë²Î¿¼¸½Â¼¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. еÄMassloggerÌØÂåÒÁľÂí±äÖֿɹýÂËÓû§Æ¾Ö¤
¡¾¸ÅÊö¡¿
ÎÛÃûÕÑÖøµÄMassLogger Windowsƾ֤ÇÔÈ¡³ÌÐòÓÖ»ØÀ´ÁË£¬ËüÒÑÉý¼¶Îª¿ÉÒÔ´ÓOutlook£¬ChromeºÍ¼´Ê±Í¨Ñ¶³ÌÐòÓ¦ÓóÌÐòÇÔȡƾ֤¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/114783/malware/masslogger-trojan.html
2. ʹÓÃÃûÌùýʧURLǰ׺µÄ´¹ÂÚ¹¥»÷¼¤Ôö6000%
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Ëµ£¬¹¥»÷ÕßÕýÔÚ·´´¹ÂÚÓʼþURLÖмӷ´Ð±¸ÜÒÔÌӱܱ£»¤¡£
À´×ÔGreatHornµÄÑо¿Ö°Ô±±¨¸æËµ£¬ËûÃÇÒѾÊӲ쵽ʹÓÓÃûÌùýʧµÄURLǰ׺”µÄ¹¥»÷ÌøÔ¾Á˽ü6,000£¥£¬´Ó¶øÌӱܱ£»¤²¢·¢ËÍ¿´ÉÏÈ¥Õýµ±µÄÍøÂç´¹ÂÚµç×ÓÓʼþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/malformed-url-prefix-phishing-attacks-spike-6000/164132/
3. ºÚ¿ÍʹÓÃIT¼à¿Ø¹¤¾ßÖÐÐÄÀ´¼à¿Ø¶à¸ö·¨¹ú¹«Ë¾
¡¾¸ÅÊö¡¿
Óë¶íÂÞ˹ÓйØÁªµÄ¡¢Óɹú¼ÒÖ§³ÖµÄ¹¥»÷×éÖ¯SandwormºÍÒ»Ï´ïÈýÄêµÄÉñÃØÐж¯Óйأ¬¸ÃÐж¯Ê¹ÓÃÃûΪCentreonµÄIT¼à¿Ø¹¤¾ß¹¥»÷Ä¿µÄ¡£
·¨¹úÐÅÏ¢Çå¾²»ú¹¹ANSSIÔÚÒ»·Ý×Éѯ±¨¸æÖÐÌåÏÖ£¬Æ¾Ö¤Ñо¿£¬´Ë´ÎµÄ¹¥»÷Ô˶¯ÒѾ¹¥»÷ÁË“¼¸¸ö·¨¹ú¹«Ë¾”£¬¸ÃÔ˶¯Ê¼ÓÚ2017Äêµ×£¬Ò»Á¬µ½2020Ä꣬¹¥»÷ÌØÊâÓ°ÏìÁËWebÍйÜÌṩÉÌ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.4hou.com/posts/MNEQ
4. ºÚ¿ÍÀÄÓùȸèÓ¦ÓóÌÐò¾ç±¾ÇÔÊØÐÅÓÿ¨Êý¾Ý
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±±¨¸æËµ£¬ÍþвÐж¯ÕßÕýÔÚÀÄÓÃGoogleµÄApps ScriptÉÌÒµÓ¦Óÿª·¢Æ½Ì¨À´ÇÔÈ¡µç×ÓÉÌÎñÍøÕ¾¿Í»§ÌṩµÄÐÅÓÿ¨Êý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/114750/cyber-crime/googles-apps-script-magecart.html
5. ÆðÑÇÈ·ÈÏÔâDoppelPaymerÀÕË÷Èí¼þ¹¥»÷µÄÊê½ð¸ß´ïÁ½ÍòÍò
¡¾¸ÅÊö¡¿
ÆðÑÇÆû³µÃÀ¹ú¹«Ë¾ÔâÊÜÁËDoppelPaymerÍÅ»ïµÄÀÕË÷Èí¼þ¹¥»÷£¬ÒªÇóÌṩ2000ÍòÃÀÔªÓÃÓÚ½âÃÜÆ÷£¬²¢ÇÒ²»µÃ×ß©±»µÁµÄÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.bleepingcomputer.com/news/security/kia-motors-america-suffers-ransomware-attack-20-million-ransom/
6. ·¨¹úºÍÎÚ¿ËÀ¼¾¯·½¾Ð²¶Éæ¼°EgregorÀÕË÷Èí¼þµÄ·¸·¨ÍÅ»ï
¡¾¸ÅÊö¡¿
ÎÚ¿ËÀ¼ºÍ·¨¹úµÄÖ´·¨²¿·ÖÍŽῪչÐж¯£¬¾Ð²¶ÁËһЩÓëEgregor RaaSÓÐÁªÏµµÄÈË£¬¶ø²»ÊÇÖ÷ÒªµÄÀÕË÷Èí¼þ°ïÅÉ¡£
¾Ý·¨¹úýÌ峯£¬Õþ¸®Ã»ÓÐ͸¶ÏÓÒÉÈ˵ÄÐÕÃû¡£ÏÓÒÉÈËÕýÔÚÓëEgregorÀÕË÷Èí¼þÔËÓªÉÌÁªÏµ£¬²¢ÏòËûÃÇÌṩºóÇںͲÆÎñÖ§³Ö¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/114590/cyber-crime/egregor-ransomware-arrests.html
7. EmotetÖ»¹ÜÒѱ»¹¥ÏÝ£¬µ«ÈÔÈ»ÊÇ×î´óµÄ¶ñÒâÈí¼þÍþв
¡¾¸ÅÊö¡¿
ÎÒÃÇ×îеÄ2021Äê1ÔÂÈ«ÇòÍþвָÊýÏÔʾ£¬Ö»¹Ü¹ú¼Ê¾¯Ô±Ðж¯ÔÚ27ÈÕ¿ØÖÆÁ˸ý©Ê¬ÍøÂ磬µ«EmotetľÂíÈÔÒ»Á¬µÚ¶þ¸öÔÂÔÚ¶¥¼¶¶ñÒâÈí¼þÁбíÖÐÅÅÃûµÚÒ»£¬Ó°ÏìÁËÈ«Çò6£¥µÄ×éÖ¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.checkpoint.com//blog.checkpoint.com/2021/02/11/january-2021s-most-wanted-malware-emotet-continues-reign-as-top-malware-threat-despite-takedown/
8. ÃÀ¹úÆðËß³¯ÏʺڿÍ͵ÇÔ2ÒÚÃÀÔª
¡¾¸ÅÊö¡¿
ÃÀ¹ú˾·¨²¿½ñÌìÕë¶ÔÈýÃû±»Ö¸¿ØÓ볯ÏÊÕþȨÏàÖúʵÑéÍøÂç·¸·¨¹¥»÷µÄÈË£¬ÌᳫÁËÆðËß¡£ÆäÍøÂç·¸·¨¹æÄ£°üÀ¨2014Äê¶ÔSony PicturesµÄºÚ¿Í¹¥»÷£¬2017ÄêÈ«ÇòWannaCryÀÕË÷Èí¼þÉìÕÅ£¬²¢ÍµÇÔÁËԼĪ2ÒÚÃÀÔª£¬²¢ÊÔͼ´ÓÈ«ÇòµÄÒøÐÐºÍÆäËûÊܺ¦Õß͵ÇÔ12ÒÚ¶àÃÀÔª¡£
¡¾²Î¿¼Á´½Ó¡¿
https://krebsonsecurity.com/2021/02/u-s-indicts-north-korean-hackers-in-theft-of-200-million/
9. Chimera-Ò»¸öPowerShell»ìÏý¾ç±¾
¡¾¸ÅÊö¡¿
ChimeraÊÇÒ»¸öPowerShell ¾ç±¾£¬Ö¼ÔÚÈÆ¹ýAMSIºÍ·À²¡¶¾½â¾ö¼Æ»®¡£Ëü»á´¥·¢AVµÄ¶ñÒâPS1£¬²¢Ê¹ÓÃ×Ö·û´®Ìæ»»ºÍ±äÁ¿´®ÁªÀ´Ìӱܳ£¼ûµÄ¼ì²âÊðÃû¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.kitploit.com/2021/02/chimera-shiny-and-very-hack-ish.html
10. ScamClub malvertisingÍÅ»ïÀÄÓÃWebKitä¯ÀÀÆ÷ÁãÈÕÎó²î
¡¾¸ÅÊö¡¿
¶ñÒâ¹ã¸æÍÅ»ïScamClubÀÄÓÃÁË»ùÓÚWebKitµÄä¯ÀÀÆ÷ÖÐδÐÞ²¹µÄÁãÈÕÎó²î£¬ÒÔÈÆ¹ýÇå¾²²½·¥²¢½«Óû§´ÓÕýµ±Õ¾µãÖØ¶¨Ïòµ½ÍйÜÔÚÏßÀñÎ│ڲƵÄÍøÕ¾¡£
¶ñÒâ¹ã¸æÔ˶¯×îÔçÓÚ2020Äê6Ô·¢Ã÷£¬Ö»¹Ü¸ÃÎó²îÒÑÔÚ±¾Ô³õÐû²¼µÄÇå¾²¸üÐÂÖлñµÃ½â¾ö£¬µ«ÈÔÔÚ¼ÌÐø¾ÙÐС£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/114689/cyber-crime/scamclub-malvertising-webkit-zero-day.htm

AG¹«Ë¾ÔÆ







