¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021Äê4Ô£©
2021-05-17
2021Äê4Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬Weblogic¶à¸öÑÏÖØÎó²î£¨CVE-2021-2135/CVE-2021-2136/CVE-2021-2157/CVE-2021-2211£©ºÍExchange Server´úÂëÖ´ÐÐÎó²î£¨CVE-2021-28480/CVE-2021-28481/CVE-2021-28482/CVE-2021-28483£©Ó°Ïì¹æÄ£½Ï´ó¡£Ç°Õßʹδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õ߿ɷ¢ËͶñÒâÇëÇ󣬲¢ÔÚÄ¿µÄ·þÎñÆ÷Ö´ÐÐí§Òâ´úÂë/»á¼ûÒªº¦Êý¾Ý£»ºóÕß¹¥»÷Õß¿ÉʹÓÃÉÏÊöÎó²îÈÆ¹ýExchangeÉí·ÝÑéÖ¤£¬ÎÞÐèÓû§½»»¥¼´¿ÉʵÏÖÏÂÁîÖ´ÐС£ CVE-2021-28480ºÍCVE-2021-28481µÄCVSSÆÀ·ÖΪ9.8·Ö£¬ÊÇδÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²î£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÃÎó²î£¬¿ÉÔÚÄÚÍøµÄExchange·þÎñÆ÷¾ÙÐкáÏòÀ©É¢£¬¿ÉÄÜÔì³ÉÈ䳿¼¶Îó²îµÄΣº¦¡£
ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË114¸öÇå¾²Îó²î£¬ÆäÖаüÀ¨19¸öCritical¼¶±ðÎó²î£¬88¸öImportant ¼¶±ðÎó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬°üÀ¨Gamaredon×éÖ¯Õë¶ÔÎÚ¿ËÀ¼Õþ¸®¹ÙÔ±µÄ¹¥»÷Ô˶¯ºÍSofacy×éÖ¯Õë¶Ô¹þÈø¿Ë˹̹µÄ¹¥»÷£¬ÒÔ¼°FluBot¶ñÒâÈí¼þ¡¢SkidMap²¡¶¾¡¢¶ñÒâÎĵµÌìÉúÆ÷EtterSilentµÄ×îй¥»÷Ô˶¯¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2021Äê04ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼473¸öÎó²î, ÆäÖиßΣÎó²î79¸ö£¬Î¢Èí¸ßΣÎó²î47¸ö¡£
* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2021.04.30
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. ¶ñÒâÎĵµÌìÉúÆ÷EtterSilentÕýÔÚ±»¶à¸öÍøÂç·¸·¨×é֯ʹÓÃ
¡¾±êÇ©¡¿EtterSilent
¡¾Ê±¼ä¡¿2021-04-07
¡¾¼ò½é¡¿
¶ñÒâÎĵµÌìÉúÆ÷EtterSilentÕýÔÚ±»¶à¸öÍøÂç·¸·¨×é֯ʹÓã¬ÒÔ½¨ÉèÓÃÓÚ·Ö·¢ÖÖÖÖ¶ñÒâÈí¼þµÄ¶ñÒâÎĵµ£¬ÆäÖаüÀ¨TrickbotÒøÐÐľÂí£¬¸ÃÎĵµÌìÉúÆ÷ʹ¹¥»÷ÕßÄܹ»×Ô½ç˵ÓÃÓÚ·¢ËͶñÒâÎĵµµÄÈí¼þ°ü¡£EtterSilent½¨ÉèÁ½ÖÖ»ù±¾ÀàÐ͵ĶñÒâMicrosoft OfficeÎĵµ¡£Ò»¸öʹÓÃÁ˱»¸ú×ÙΪCVE-2017-8570µÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¬¶øÁíÒ»¸öÔòʹÓÃÁ˶ñÒâºê¡£ÔÚÕâÁ½ÖÖÇéÐÎÏ£¬Î±ÔìµÄOffice²úÆ·¶¼Î±×°³ÉDocuSignÎĵµ-Ò»ÖÖÓÃÓÚ¶ÔÎĵµ¾ÙÐеç×ÓÊðÃûµÄÉÌÒµ¹¤¾ß¡£
¡¾²Î¿¼Á´½Ó¡¿
https://intel471.com/blog/ettersilent-maldoc-builder-macro-trickbot-qbot/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡16ÌõIOC£¬ÆäÖаüÀ¨16¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. Gamaredon×éÖ¯Õë¶ÔÎÚ¿ËÀ¼Õþ¸®¹ÙÔ±µÄ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿Gamaredon
¡¾Ê±¼ä¡¿2021-04-15
¡¾¼ò½é¡¿
½üÆÚ·¢Ã÷Õë¶ÔÎÚ¿ËÀ¼ÔÚÕþ¸®¹ÙÔ±µÄ¹¥»÷ÊÂÎñ£¬²¢¹éÊôÓÚ¶íÂÞ˹×éÖ¯Gamaredon£¬Ôڴ˴ι¥»÷Ô˶¯ÖУ¬GamaredonͶµÝµÄÓÕ¶üÎĵµÖ÷ÒªÊÇÎÚ¿ËÀ¼ÓïΪÖ÷£¬ÒÔ¶íÂÞ˹ÓïΪ¸¨£¬Í¶µÝµÄÓÕ¶üÖ÷ÌâÖ÷ÒªÊÇÎ§ÈÆÎÚ¿ËÀ¼Óë±£¼ÓÀûÑǵÄÏÖ´ú¹ØÏµ¾ÙÐÐÕö¿ª¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.anomali.com/blog/primitive-bear-gamaredon-targets-ukraine-with-timely-themes
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡20ÌõIOC£¬ÆäÖаüÀ¨5¸öIPºÍ15¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. SkidMap²¡¶¾Ê¹ÓÃRedisδÊÚȨ»á¼ûÎó²î¹¥»÷ÔÆÖ÷»ú
¡¾±êÇ©¡¿SkidMap
¡¾Ê±¼ä¡¿2021-04-23
¡¾¼ò½é¡¿
½üÆÚÓй¥»÷ÕßʹÓÃRedisδÊÚȨ»á¼ûÎó²î¹¥»÷ÔÆ·þÎñÆ÷£¬Ñо¿Ö°Ô±ÅжÏΪSkidMap²¡¶¾±äÖֵĹ¥»÷Ô˶¯£¬Ô¼ÊýÇ§Ì¨ÔÆÖ÷»úÊܵ½Ó°Ï죬Êܺ¦Ö÷»úÒѱ»¹¥»÷Õß¿ØÖÆÂÙΪ¿ó»ú£¬ÏÂÔØÃÅÂÞ±Ò¡¢À³Ìرҡ¢±ÈÌØ±ÒÍÚ¿óľÂí£¬Í¨¹ýÍÚ¿óIJÀû£¬²¢¿ÉÄÜÔì³ÉÉñÃØÐÅϢй¶¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com/research/report/1304.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡20ÌõIOC£¬ÆäÖаüÀ¨4¸öÓòÃûºÍ16¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. Water PamolaÔ˶¯Ê¹ÓöñÒâ¶©µ¥¹¥»÷ÔÚÏßÊÐËÁ
¡¾±êÇ©¡¿Water Pamola
¡¾Ê±¼ä¡¿2021-04-28
¡¾¼ò½é¡¿
Water PamolaÔ˶¯×î³õͨ¹ý´øÓжñÒ⸽¼þµÄÀ¬»øÓʼþ¹¥»÷ÈÕ±¾¡¢°Ä´óÀûÑǺÍÅ·ÖÞ¹ú¼ÒµÄµç×ÓÉÌÎñÔÚÏßÊÐËÁ¡£2020ÄêÍ·ÒÔÀ´£¬¸ÃÔ˶¯µÄÊܺ¦ÕßÖ÷Òª·ºÆðÔÚÈÕ±¾¾³ÄÚ£¬²¢ÇÒ²»ÔÙͨ¹ýÀ¬»øÓʼþÌᳫ£¬¶øÊÇÖÎÀíÔ±ÔÚÆäÔÚÏßÊÐËÁµÄÖÎÀíÃæ°åÖÐÉó²é¿Í»§¶©µ¥Ê±£¬¾Í»áÖ´ÐжñÒâ¾ç±¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.trendmicro.com/en_us/research/21/d/water-pamola-attacked-online-shops-via-malicious-orders.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡41ÌõIOC£¬£¬ÆäÖаüÀ¨7¸öÓòÃûºÍ34¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. FluBot¶ñÒâÈí¼þͨ¹ýSMSÁ´½ÓÈö²¥Ñ¸ËÙÔÚÅ·ÖÞÈö²¥
¡¾±êÇ©¡¿FluBot
¡¾Ê±¼ä¡¿2021-04-27
¡¾¼ò½é¡¿
FlubotÌØ¹¤Èí½üÆÚ·Ç³£»îÔ¾£¬Í¨¹ýSMSÔÚÅ·ÖÞµØÇøÈö²¥£¬Ó¢¹úÒÑÓÐ7000¸öÊÜѬȾµÄ×°±¸¼ÓÈëÈö²¥£¬¶ñÒâ¶ÌÐŵÄÊýÄ¿¿ÉÒÔµÖ´ïÿСʱÊýÍòÌõ£¬Ò»Ð©Òƶ¯Óû§ÒѾÊÕµ½¶à´ï6Ìõ´øÓÐFluBotÁ´½ÓµÄ¶ÌÐÅ¡£FluBot¿ÉÒÔͬʱ³äµ±Ìع¤Èí¼þ¡¢¶ÌÐÅÀ¬»øÓʼþ·¢ËÍÕß¡¢ÐÅÓÿ¨ºÍÒøÐÐÆ¾Ö¤ÇÔÈ¡Õß¡£FluBot¶ñÒâÈí¼þ·¢ËÍÊܺ¦ÕßµÄÁªÏµÈËÁÐ±í£¬²¢¼ìË÷SMS´¹ÂÚÐÅÏ¢ºÍºÅÂëÒÔ¼ÌÐøÊ¹ÓÃÊܺ¦ÕßµÄ×°±¸Èö²¥¡£Æä×îÐÂÊܺ¦Õß°üÀ¨Ó¢¹ú¡¢µÂ¹ú¡¢ÐÙÑÀÀû¡¢Òâ´óÀû¡¢²¨À¼ºÍÎ÷°àÑÀµÄ°²×¿Óû§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.proofpoint.com/us/blog/threat-insight/flubot-android-malware-spreading-rapidly-through-europe-may-hit-us-soon
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡92ÌõIOC£¬¾ùΪÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. Sofacy×éÖ¯Õë¶Ô¹þÈø¿Ë˹̹¹¥»÷Ô˶¯
¡¾±êÇ©¡¿Sofacy
¡¾Ê±¼ä¡¿2021-04-19
¡¾¼ò½é¡¿
Sofacy£¨Ò²³ÆÎªAPT28£¬Pawn Storm£¬Fancy BearºÍSednit£©ÊÇÒ»¸ö×Ô2008ÄêÒÔÀ´×îÏÈ»îÔ¾ÍøÂçÌØ¹¤×éÖ¯£¬Ö÷ÒªÕë¶ÔÕþ¸®¡¢¾üʵȣ¬Ä¿µÄÖ÷Òª¼¯ÖÐÔÚǰËÕÁª¹²ºÍ¹úºÍÑÇÖÞ¡£ÔÚ2021Äê3Ô·¢Ã÷ʹÓÃDelphi±àдµÄDelphocy¶ñÒâÈí¼þÕë¶Ô¹þÈø¿Ë˹̹µÄ¹¥»÷Ô˶¯£¬¸Ã¶ñÒâÈí¼þÓëSofacy×éÖ¯Ïà¹Ø£¬¶ñÒâÑùÔÀ´×ÔÒ»¼ÒÃûΪKazchromeµÄ¹þÈø¿Ë˹̹¹«Ë¾£¬¸Ã¹«Ë¾ÊÇÒ»¼Ò²É¿óºÍ½ðÊô¹«Ë¾£¬²¢ÇÒÊÇÌìÏÂÉÏ×î´óµÄ¸õ¿óʯºÍÌúºÏ½ðÉú²úÉÌÖ®Ò»¡£
¡¾²Î¿¼Á´½Ó¡¿
https://labs.sentinelone.com/a-deep-dive-into-zebrocys-dropper-docs/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡10ÌõIOC£¬ÆäÖаüÀ¨2¸öURLsºÍ8¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







