¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021Äê5Ô£©
2021-06-03
5Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬HTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31166£©ºÍVMware vCenter ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2021-21985)Ó°Ïì¹æÄ£½Ï´ó¡£Ç°Õß±£´æÓÚHTTP ÐÒéÕ» (http.sys) µÄ´¦Öóͷ£³ÌÐòÖУ¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòÄ¿µÄÖ÷»ú·¢ËÍÌØÖÆÊý¾Ý°üÀ´¾ÙÐÐʹÓ㬴ӶøÔÚÄ¿µÄϵͳÉÏÒÔÄÚºËÉí·ÝÖ´ÐÐí§Òâ´úÂ룬CVSSÆÀ·ÖΪ9.8£¬Î¢ÈíÌåÏÖ´ËÎó²î¿ÉÓÃÓÚÈä³æÊ½Èö²¥£»ºóÕßÊÇÓÉÓÚvCenter ServerÖеIJå¼þVirtual SAN Health CheckȱÉÙÊäÈëÑéÖ¤£¬Í¨¹ý443¶Ë¿Ú»á¼ûvSphere Client(HTML5)µÄ¹¥»÷Õߣ¬¿ÉÒÔ½á¹¹ÌØÊâµÄÊý¾Ý°üÔÚÄ¿µÄÖ÷»úÉÏÖ´ÐÐí§Òâ´úÂ룬ÎÞÂÛÊÇ·ñʹÓÃvSAN£¬vCenter Server¶¼»áĬÈÏÆôÓøÃÊÜÓ°ÏìµÄ²å¼þ£¬CVSSÆÀ·ÖΪ9.8¡£
ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´55¸öÇå¾²Îó²î£¬ÆäÖÐ4¸öCritical¼¶±ðÎó²î¡¢50¸öImportant ¼¶±ðÎó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬ÀÕË÷Èí¼þ³ÉΪ¹Ø×¢µÄÖØµã£¬ÃÀ¹úÓÍÆø¹ÜµÀÔËÓªÉÌColonial PipelineÔâDarkSideÀÕË÷Èí¼þ¹¥»÷£¬ÃÀ¹úÐû²¼½øÈë½ôÆÈ״̬£»¹¥»÷Êֶη½Ã棬·ºÆð¶ñÒâÈí¼þ¼Ò×壨ÀýÈç´ÅÅ̲Á³ýÆ÷µÈ£©Î±×°³ÉÀÕË÷Èí¼þ¶ÔÄ¿µÄÊܺ¦Õß¾ÙÐй¥»÷Ô˶¯£»Í¬Ê±ÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯REvil/SodinokibiÐèÒªÒýÆð¹Ø×¢¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2021Äê05ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼454¸öÎó²î, ÆäÖиßΣÎó²î48¸ö£¬Î¢Èí¸ßΣÎó²î25¸ö¡£
* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2021.05.31
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. DarkSideÀÕË÷Èí¼þ¹¥»÷ÊÂÎñÆÊÎö
¡¾±êÇ©¡¿DarkSide
¡¾Ê±¼ä¡¿2021-05-11
¡¾¼ò½é¡¿
5ÔÂ7ÈÕ£¬ÃÀ¹úÓÍÆø¹ÜµÀÔËÓªÉÌColonial PipelineÐû²¼ÁËÒ»·ÝÉùÃ÷£¬³ÆÆäÓÉÓÚÊÕµ½ÍøÂç¹¥»÷£¬²»µÃ²»¹Ø±ÕÒ»²¿·ÖITϵͳ£¬½ø¶øµ¼Ö¹«Ë¾ÆìϵÄËùÓйܵÀ×èÖ¹ÔËÐС£¾Ý³Æ£¬¸ÃÆðÍøÂç¹¥»÷ÊÂÎñµÄÔ´Í·À´×ÔÒ»¸ö×Ô³ÆÎªDarkSideµÄÀÕË÷Èí¼þÔËÓªÍŻ¸ÃÍÅ»ïʹÓÃ×ÔÖ÷¿ª·¢µÄͬÃûÀÕË÷Èí¼þÈëÇÖÁËColonial PipelineµÄϵͳ¡£´ÓÊܺ¦ÕßµÄÓ¦¶Ô²½·¥¿ÉÒÔÍÆ¶Ï£¬±¾´Î¶ÔColonial PipelineµÄ¹¥»÷ÒѳÉΪ½ñÄê¶È×îÑÏÖØµÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬²¢ÇÒÖ±½ÓչʾÁËÀÕË÷Èí¼þǿʢµÄÆÆËðÄÜÁ¦¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/darkside-colonial/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡86ÌõIOC£¬ÆäÖаüÀ¨5¸öÓòÃûºÍ81¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. ICEDIDÕë¶Ô½ðÈÚ»ú¹¹µÄ×îÐÂÔ˶¯
¡¾±êÇ©¡¿ICEDID
¡¾Ê±¼ä¡¿2021-05-12
¡¾¼ò½é¡¿
ǰ¶Îʱ¼ä£¬AG¹«Ë¾¿Æ¼¼·üӰʵÑéÊÒ²¶»ñµ½Ò»ÅúÏàËÆ¶ÈÊ®·Ö¿¿½üµÄÑù±¾¡£ÎÒÃǶÔÕâÅúÑù±¾¾ÙÐÐÁËÒ»Á¬¸ú×Ù£¬²¢¾ÙÐÐÁËÖÜÈ«µÄÆÊÎö£¬·¢Ã÷ÆäΪICEDID×îÐÂÔ˶¯£¬±¾´ÎÔ˶¯Öй¥»÷Õßй¹ÁËÒ»ÖÖ¶ñÒâÈí¼þ¼ÓÔØÆ÷Gziploader¡£¸ÃÀàÑù±¾ÔÚ2021Äê3ÔÂÖÐÑ®×îÏÈ´ó×Ú»îÔ¾£¬Ñù±¾ÊýÄ¿Öڶ࣬Ö÷Ҫͨ¹ýÀ¬»øÓʼþ»ò´¹ÂÚÓʼþµÄ·½·¨¾ÙÐÐÈö²¥¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/icedid-gziploader/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡263ÌõIOC£¬ÆäÖаüÀ¨7¸öÓòÃûºÍ256¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. Freakout½©Ê¬ÍøÂç¿ØÖÆÖÇÄÜ×°±¸¹¥»÷ÔÆÖ÷»ú
¡¾±êÇ©¡¿Freakout
¡¾Ê±¼ä¡¿2021-05-13
¡¾¼ò½é¡¿
½üÆÚ·¢Ã÷Freakout½©Ê¬ÍøÂçµÄ¹¥»÷Ä¿µÄ³ýÁËIoTÖÇÄÜ×°±¸£¬»¹»á¹¥»÷WindowsºÍlinuxÖ÷»ú£¬ÔÚÎó²î¹¥»÷µ½ÊÖÖ®ºó£¬»áÏòʧÏÝÖ÷»úÖ²ÈëIRCºóÃÅľÂíºÍÃÅÂÞ±ÒÍÚ¿óľÂí£¬×îÖÕͨ¹ýÃÅÂÞ±ÒÍÚ¿óIJÀû¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com/research/report/1311.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC£¬ÆäÖаüÀ¨1¸öÓòÃûºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. BizarroÒøÐÐľÂí½«¹¥»÷¹æÄ£À©´óµ½Å·ÖÞ
¡¾±êÇ©¡¿Bizarro
¡¾Ê±¼ä¡¿2021-05-17
¡¾¼ò½é¡¿
Bizarro ÊÇÒ»¸öÔ´×Ô°ÍÎ÷µÄÒøÐÐľÂí¼Ò×壬ÏÖÔÚÔÚÌìÏÂÆäËûµØÇøÒ²Óз¢Ã÷£¬°üÀ¨Î÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢·¨¹úºÍÒâ´óÀûµÄÓû§³ÉΪ¹¥»÷Ä¿µÄ¡£ÏÖÔÚBizarro ÒѾʵÑéÀúÀ´×Ô²î±ðÅ·ÖÞºÍÄÏÃÀ¹ú¼ÒµÄ 70 ¼ÒÒøÐеĿͻ§ÄÇÀïÇÔȡƾ֤¡£Bizarro ¾ßÓÐ x64 Ä£¿é£¬Äܹ»ÓÕʹÓû§ÔÚÐéαµ¯³ö´°¿ÚÖÐÊäÈëÁ½ÒòËØÉí·ÝÑéÖ¤´úÂë¡£Ëü»¹¿ÉÄÜʹÓÃÉç»á¹¤³ÌÀ´Ëµ·þÊܺ¦ÕßÏÂÔØÖÇÄÜÊÖ»úÓ¦ÓóÌÐò¡£Bizzaro ±³ºóµÄÍŶÓʹÓÃÍйÜÔÚ Azure ºÍÑÇÂíÑ· (AWS) ÉϵķþÎñÆ÷ÒÔ¼°ÊÜѬȾµÄ WordPress ·þÎñÆ÷À´´æ´¢¶ñÒâÈí¼þ²¢ÍøÂçÒ£²âÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/bizarro-banking-trojan-expands-its-attacks-to-europe/102258/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡10ÌõIOC£¬ÆäÖаüÀ¨10¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. TeamTNT°²ÅÅDockerÓ³ÏñÈö²¥Tsunami±äÌå
¡¾±êÇ©¡¿TeamTNT,Tsunami
¡¾Ê±¼ä¡¿2021-05-25
¡¾¼ò½é¡¿
TeamTNT ʹÓÃÕýµ±Óû§µÄ Docker Hub ÕÊ»§ÔÚ Docker Hub Éϰ²ÅŶñÒâÓ³Ïñ£¬¶ñÒâÓ³ÏñÖаüÀ¨µÄ¶ñÒâ³ÌÐò°üÀ¨Tsunami±äÌ壬ÒÔÏÂÔØXMRig¶þ½øÖÆÎļþ£¬¾ÙÐжñÒâÍÚ¿óÔ˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.lacework.com/taking-teamtnt-docker-images-offline/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡9ÌõIOC£¬ÆäÖаüÀ¨9¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. Agrius ×é֯ʹÓôÅÅ̲Á³ýÆ÷¹¥»÷ÒÔÉ«ÁÐ
¡¾±êÇ©¡¿Apostle,Agrius
¡¾Ê±¼ä¡¿2021-05-25
¡¾¼ò½é¡¿
Apostle ÊÇÒ»ÖÖÆæÒìÇÒǰËùδ¼ûµÄ´ÅÅ̲Á³ý¶ñÒâÈí¼þ£¬Î±×°³ÉÀÕË÷Èí¼þ£¬¶ÔÒÔÉ«ÁеIJî±ðÄ¿µÄ·¢¶¯ÆÆËðÐÔ¹¥»÷£¬Ö÷ÒªÕë¶ÔÍøÂç»ù´¡ÉèÊ©¡£´Ë´Î¹¥»÷Ô˶¯ÓÉAgrius ºÚ¿Í×éÖ¯Ìᳫ£¬¸Ã×éÖ¯ÊÇÓëÒÁÀÊÕþ¸®Óйصģ¬Í¨³£Ê¹Óö¨ÖƵŤ¾ß¼¯ºÍÏֳɵÄÇå¾²Èí¼þÀ´°²ÅŶ¨ÖƵIJÁ³ýÆ÷¼æÀÕË÷Èí¼þ»òÆÆËðÐԵIJÁ³ýÆ÷±äÌ壬Ö÷ÒªÖØµãÊÇÊý¾ÝÆÆËðºÍÍøÂçÌØ¹¤Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://labs.sentinelone.com/from-wiper-to-ransomware-the-evolution-of-agrius/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡26ÌõIOC£¬ÆäÖаüÀ¨5¸öÓòÃûºÍ21¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
7. REvil·çÔÆÔÙÆð£¬APTʽÀÕË÷±¬·¢
¡¾±êÇ©¡¿REvil
¡¾Ê±¼ä¡¿2021-05-25
¡¾¼ò½é¡¿
2021Äê5Ô£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½REvil/SodinokibiÀÕË÷¼Ò×åµÄ¶àÆðÔ˶¯£¬REvilΪRansomware Evil£¨ÓÖ³ÆSodinokibi£©µÄËõд£¬ÊÇÒ»¸ö˽ÈËÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯¡£ÓÚ2019Äê4ÔÂÊ״α»·¢Ã÷£¬ÔÚÒ»ÄêÄÚ¾ÍÒѱ»ÓÃÓÚһЩ×ÅÃûÍøÂç¹¥»÷£¬2019Äê8ÔµÄPerCSoft¹¥»÷£¬2020Äê1ÔµÄTravelexÀÕË÷Èí¼þ¹¥»÷£¬¼°2020Äê1ÔµÄGedia Automotive¹¥»÷µÈÊÂÎñ¡£½üÆÚ£¬¸Ã×éÖ¯ÈëÇÖÁËÆ»¹û¹«Ë¾µÄ¹©Ó¦ÉÌ£¬²¢ÇÔÈ¡ÁËÆ»¹û¹«Ë¾¼´½«ÍƳöµÄ²úÆ·ÉñÃØÔÀíͼ¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/revil-apt/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
8. ¹¥»÷ÕßαÔìÓ°Ï·Á÷ýÌå·þÎñÈö²¥BazaLoaderµÄ¶ñÒâÔ˶¯
¡¾±êÇ©¡¿BazaLoader
¡¾Ê±¼ä¡¿2021-05-26
¡¾¼ò½é¡¿
¹¥»÷ÕßαÔìÓ°Ï·Á÷ýÌåÍøÕ¾BravoMoviesµÄ¹¦Ð§°üÀ¨Î±ÔìµÄÓ°Ï·º£±¨ºÍ´øÓÐFAQ³£¼ûÎÊÌâ½â´ð¡¢ÒÔ¼°¿ÉÓÃÀ´“×÷·Ï”ÕâÏî·þÎñµÄExcelµç×Ó±í¸ñ£¬µ«ËüÏÂÔØµÄÖ»ÊǶñÒâÈí¼þBazaLoader¡£BazaLoader ÊÇÒ»ÖÖ¼ÓÔØ³ÌÐò£¬ÓÃÓÚ°²ÅÅÀÕË÷Èí¼þ»òÆäËûÀàÐ͵ĶñÒâÈí¼þ£¬²¢´ÓÊܺ¦ÏµÍ³ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£BravoMovies Ô˶¯Ê¹ÓÃÈ«ÐÄÉè¼ÆµÄѬȾÁ´£¬Óë BazaLoader Á¥Êô»ú¹¹¼á³ÖÒ»Ö£¬ÕâЩÁ¥Êô»ú¹¹ÓÕʹÊܺ¦ÕßÌø¹ý¶à¸öȦÌ×ÒÔ´¥·¢¶ñÒâÈí¼þ¸ºÔØ£¬ÍþвÐÐΪÕß´ÓÒ»·âµç×ÓÓʼþ×îÏÈ£¬¸æËßÊÕ¼þÈ˳ý·Ç×÷·ÏËûÃǶԷþÎñµÄ¶©ÔÄ£¬²»È»ËûÃǵÄÐÅÓÿ¨½«±»ÊÕÈ¡Óöȣ¬ÕâÊÇËûÃÇ´ÓδǩÊð¹ýµÄ¶©ÔÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.proofpoint.com/us/blog/threat-insight/bazaflix-bazaloader-fakes-movie-streaming-service
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡13ÌõIOC£¬ÆäÖаüÀ¨9¸öIP£¬3¸öÓòÃûºÍ1¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
9. ¶à¸ö¶ñÒâÈí¼þ¼Ò×åʹÓÃProxylogonÎó²î¾ÙÐй¥»÷Ô˶¯
¡¾±êÇ©¡¿BlackKingdom,Prometei,LemonDuck
¡¾Ê±¼ä¡¿2021-05-06
¡¾¼ò½é¡¿
´Ó3ÔÂ×îÏÈÈý¸ö¶ñÒâÈí¼þ¼Ò×壨BlackKingdomÀÕË÷Èí¼þ£¬Prometei½©Ê¬ÍøÂ磬LemonDuckÓ²±ÒÍÚ¿ó³ÌÐò£©×îÏÈʹÓÃProxyLogonÎó²î£¨Microsoft Exchange ServerÎó²îCVE-2021-26855£©Ìᳫ¹¥»÷¡£Í¨¹ý´ËÎó²î£¬¹¥»÷Õß¿ÉÒÔÖ´ÐÐChopper Web Shell£¬´Ó¶ø°²ÅŸ÷×ÔѬȾÖеÄ×îÖÕÓÐÓÃÔØºÉ¡£Chopper web shell ÓÚ 2012 ÄêÊ״α»·¢Ã÷£¬±»ÍþвÐÐΪÕ߯ձéʹÓã¬ÓÃÓÚÔ¶³Ì»á¼ûÄ¿µÄϵͳ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.trendmicro.com/en_us/research/21/e/proxylogon-a-coinminer--a-ransomware--and-a-botnet-join-the-part.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡19ÌõIOC£¬ÆäÖаüÀ¨19¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







