¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.3.8-3.14£©
2021-03-15
Ò»¡¢ Íþвͨ¸æ
΢Èí2021Äê3ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-03-10 16:00:00 GMT
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä3ÔÂ10ÈÕ£¬Î¢ÈíÐû²¼3ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË89¸öÇå¾²ÎÊÌâ£¬Éæ¼°Microsoft Windows¡¢MicrosoftOffice¡¢MicrosoftExchange Server¡¢InternetExplorer¡¢VisualStudio µÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£ ±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²îÓÐ14¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ75¸ö¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
F5 BIG-IP/BIG-IQ¶à¸ö¸ßΣÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-03-11 16:00:00 GMT
¡¾¸ÅÊö¡¿
2021Äê3ÔÂ11ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½F5¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËÓ°ÏìF5µÄBIG-IPºÍBIG-IQµÄ¶à¸ö¸ßΣÎó²î£¨CVE-2021-22986£¬CVE-2021-22987£¬CVE-2021-22988£¬CVE-2021-22989£¬CVE-2021-22990£¬CVE-2021-22991£¬CVE-2021-22992£©£¬½¨ÒéÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£ BIG-IPÊÇÃÀ¹ú F5¹«Ë¾µÄÒ»¿î¼¯³ÉÁËÍøÂçÁ÷Á¿ÖÎÀí¡¢Ó¦ÓóÌÐòÇå¾²ÖÎÀí¡¢¸ºÔØÆ½ºâµÈ¹¦Ð§ µÄÓ¦Óý»¸¶Æ½Ì¨¡£BIG-IQÊÇÒ»¿îÓÃÓÚÖÎÀíºÍе÷F5Çå¾²ÓëÓ¦Óý»¸¶½â¾ö¼Æ»®µÄÖÇÄÜ¿ò¼Ü¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. GafgytбäÌåÕë¶ÔD-LinkºÍÎïÁªÍø×°±¸µÄ¹¥»÷Ô˶¯
¡¾¸ÅÊö¡¿
Gafgyt½©Ê¬ÍøÂçµÄбäÖÖÊÇÒÀÀµTorͨѶµÄ¶ñÒâÈí¼þ£¬Ö÷ÒªÕë¶ÔÒ×Êܹ¥»÷µÄD-LinkºÍÎïÁªÍø×°±¸¡£GafgytÊÇÒ»¸öÓÚ2014Äê·¢Ã÷µÄ½©Ê¬ÍøÂ磬ËüÒò·¢¶¯´ó¹æÄ£ÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷¶øÉùÃûÉ¢ÂÒ£¬Ð±äÖÖGafgyt_torΪ¹æ±Ü¼ì²â£¬Ê¹ÓÃTorÀ´Òþ²ØÆäÏÂÁîºÍ¿ØÖÆ£¨C2£©Í¨Ñ¶£¬²¢¶ÔÑù±¾ÖеÄÃô¸Ð×Ö·û´®¾ÙÐмÓÃÜ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/d-link-iot-tor-gafgyt-variant/164529/
2. Õë¶Ôº½¿Õ¹«Ë¾µÄ¹©Ó¦Á´¹¥»÷Ô˶¯
¡¾¸ÅÊö¡¿
×ܲ¿Î»ÓÚÈðÊ¿µÄIT¹«Ë¾SITA£¬ÎªÈ«Çò90%µÄº½¿Õ¹«Ë¾ÌṩIT·þÎñ£¬½üÆÚ¸Ã¹«Ë¾Êܵ½¹©Ó¦Á´¹¥»÷µ¼Ö´ó×ÚÂÿÍÐÅÏ¢Ôâй¶£¬ÒÑÓÐÂíÀ´Î÷ÑǺ½¿Õ¡¢ÐÂ¼ÓÆÂº½¿Õ¡¢·ÒÀ¼º½¿ÕºÍÐÂÎ÷À¼º½¿ÕÊܵ½´Ë´Î¹¥»÷Ô˶¯µÄÓ°Ïì¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/supply-chain-attack-jolts-airlines-a-16123
3. ºÚ¿ÍÈëÇÖÅ·ÃËÒøÐÐî¿Ïµ»ú¹¹EBAµÄExchange·þÎñÆ÷
¡¾¸ÅÊö¡¿
Å·ÃËÒøÐÐî¿Ïµ»ú¹¹EBAµÄMicrosoft Exchangeµç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬´Ë´Î¹¥»÷Ô˶¯ÒÉËÆÓëHAFNIUM¹¥»÷×éÖ¯Óйء£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/115396/data-breach/eba-microsoft-exchange-hacked.html
4. EmotetľÂíÍþвÔ˶¯¹©Ó¦Á´ÆÊÎö
¡¾¸ÅÊö¡¿
ÒøÐÐľÂíEmotet×Ô2020Äê12ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Emotetͨ³£ËæÍøÂç´¹ÂÚµç×ÓÓʼþÒ»Æð·¢ËÍ£¬¸½´øWordÎĵµ£¬Emotet¹¥»÷Á´Öеİ취£ºa.WordÎĵµÒÑ·Ö·¢²¢ÔÚÆôÓúêµÄÇéÐÎÏ·¿ª;b.ÔËÐÐVBScriptºêÒÔÌìÉú¶ñÒâµÄPowerShell¾ç±¾;c.¶ñÒâµÄPowerShell¾ç±¾½«³õʼDLL¶þ½øÖÆÎļþÏÂÔØÎª¼ÓÔØ³ÌÐò;d.³õʼ¼ÓÔØ³ÌÐò½«É¾³ýºóÐøµÄDLL¶þ½øÖÆÎļþ£¬¸Ã¶þ½øÖÆÎļþ½«¾ÙÐÐ×ÔÎÒ¸üÐÂ;e.×îÖÕµÄDLL»áÇÔÈ¡Êܺ¦ÕßµÄÃô¸ÐÊý¾Ý£¬»òÕßͨ¹ýÓëC2·þÎñÆ÷¾ÙÐÐͨѶÀ´¾ÙÐнøÒ»²½µÄ¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/attack-chain-overview-emotet-in-december-2020-and-january-2021/
5. ¼ÓÃÜÍÚ¿óÔ˶¯Õë¶ÔQNAP NAS×°±¸
¡¾¸ÅÊö¡¿
½üÆÚ¶ñÒâ¼ÓÃÜÇ®±ÒÔ˶¯Öй¥»÷ÕßʹÓÃUnityMiner¶ñÒâÈí¼þÕë¶ÔQNAP SystemsÍøÂçÅþÁ¬´æ´¢£¨NAS£©×°±¸£¬¸Ã×°±¸Òªº¦¹Ì¼þ¿ÉÄܱ£´æÎ´ÐÞ²¹Îó²î£¨CVE-2020-2506£¬CVE-2020-2507£©£¬Æ¾Ö¤QNAP×°±¸Ó³É䣬ÃÀ¹úºÍÖйúµÄ110ÍòQNAP NASÓû§Êܵ½ÑÏÖØÓ°Ï죬ռȫÇòѬȾ×ÜÊýµÄ80%¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/miner-campaign-targets-unpatched-qnap-nas/164580/
6. ZLoader¶ñÒâÈí¼þÒþ²ØÔÚ¼ÓÃܵÄExcelÎļþÖÐ
¡¾¸ÅÊö¡¿
ZLoaderÊÇÒ»ÖÖ¶àÓÃ;ľÂí£¬Í¨³£³äµ±Í¶µÝ³ÌÐò£¬ÔÚ¶à½×¶ÎÀÕË÷Èí¼þ¹¥»÷£¨ÀýÈçRyukºÍEgregor£©ÖÐת´ï»ùÓÚZeusµÄ¶ñÒâÈí¼þ¡£½üÆÚ·¢Ã÷Ò»ÆðÍøÂç´¹ÂÚ¹¥»÷Ô˶¯ÖУ¬¹¥»÷ÕßʹÓùú˰¾Ö˰Êպͷ¢Æ±Îļþ×÷ΪÓÕ¶ü£¬½«¶ñÒâÈí¼þZLoaderÒþ²ØÔÚ¼ÓÃܵÄExcelÎļþÖоÙÐÐÈö²¥£¬Ö¼ÔÚÇÔÈ¡Ãô¸ÐÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/zloader-malware-hidden-in-encrypted-excel-file-a-16146
7. VerkadaÉãÏñÍ·±»ºÚ¿Í¹¥»÷
¡¾¸ÅÊö¡¿
ºÚ¿Í½üÆÚʹÓÃVerkadaÉãÏñÍ·ÖеÄÎó²î¿ÉÔ¶³Ì»á¼û¿Í»§ÉãÏñÍ·£¬Êܺ¦Õß°üÀ¨Æû³µÖÆÔìÉÌTesla¡¢ÍøÂç»ù´¡ÉèÊ©¹«Ë¾Cloudflare¡¢Éí·ÝºÍ»á¼ûÖÎÀí³§ÉÌOktaÒÔ¼°¶à¼ÒÒ½ÔººÍÀÎÓü¡£Verkada×ܲ¿Î»ÓÚ¼ÓÀû¸£ÄáÑÇÖÝÊ¥ÂíÌØ°Â£¬ÎªÖÚ¶à×éÖ¯ÖÎÀíºÍά»¤150,000¸ö¿ÉÔ¶³Ì»á¼ûµÄ¼àÊÓÉãÏñ»ú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/startup-probes-hack-internet-connected-security-cameras-a-16155
8. OVHÔÆÊý¾ÝÖÐÐı»´ó»ðÏú»Ù
¡¾¸ÅÊö¡¿
OVHÊÇÅ·ÖÞ×î´óµÄÍйܷþÎñÌṩÉÌ£¬Ò²ÊÇÌìϵÚÈý´óÍйܷþÎñÌṩÉÌ£¬¸ÃÔÆ¹«Ë¾ÅÌËãÌṩÐéÄâרÓ÷þÎñÆ÷£¬×¨Ó÷þÎñÆ÷ºÍÆäËûÍøÂç·þÎñ¡£¿ËÈÕÒ»¸öOVHÊý¾ÝÖÐÐı¬·¢»ðÔÖ£¬´Ý»ÙÁËÒ»¸öÊý¾ÝÖÐÐÄ£¬²¢Ê¹ÁíÍâÁ½¸öÊý¾ÝÖÐÐĵôÏߣ»ÒÑÈ·ÈÏÊÜÓ°ÏìµÄEU·þÎñÆ÷ËùÓÐɥʧ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.malwarebytes.com/malwarebytes-news/2021/03/ovh-cloud-datacenter-destroyed-by-fire/
9. ÊýÊ®Íǫ̀Microsoft·þÎñÆ÷Ò»Á¬±»ºÚ¿ÍÈëÇÖ
¡¾¸ÅÊö¡¿
Õë¶ÔMicrosoft Exchange·þÎñÆ÷µÄ¹¥»÷±ÈÏëÏóµÄÒªÔã¸âÐí¶à£¬¾ÝÊý¾ÝÏÔʾ£¬È«ÇòÒÑÓÐÊýÊ®Íǫ̀Microsoft·þÎñÆ÷ÔâºÚ¿Í¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.forbes.com/sites/daveywinder/2021/03/06/warning-hundreds-of-thousands-of-microsoft-servers-hacked-in-ongoing-attack/?sh=63b15eb828e6
10. Õë¶ÔAzureÔÆÆ½Ì¨Óû§µÄй¥»÷Ô˶¯
¡¾¸ÅÊö¡¿
΢ÈíÖÒÑÔÆäAzureÔÆÆ½Ì¨µÄÓû§£¬ºÚ¿ÍÕýÔÚʹÓü¸ÖÖ“living off the land”¹¥»÷ÊÖÒÕÀ´ÌÓ±ÜÇå¾²²½·¥£¬ÌáÉýÌØÈ¨ºÍ°²ÅżÓÃܿ󹤡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/hackers-waging-living-off-land-attacks-on-azure-a-16158
11. REvilÀÕË÷Èí¼þʹÓÃDDoS¹¥»÷ºÍÓïÒôºô½ÐÏòÊܺ¦Õßʩѹ
¡¾¸ÅÊö¡¿
REvilÀÕË÷Èí¼þÔËÓªÉÌÕýÔÚʹÓÃDDoS¹¥»÷£¬²¢Ïò¼ÇÕߺÍÊܺ¦È˵ÄÉÌҵͬ°é·¢³öÓïÒôºô½Ð£¬ÒÔÆÈʹÊܺ¦ÈËÖ§¸¶Êê½ð
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/115345/cyber-crime/revil-ransomware-ddos-voice-calls.html

AG¹«Ë¾ÔÆ







