¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2022.01.17-2022.01.23£©
2022-01-24
Ò»¡¢ Íþвͨ¸æ
Oracleȫϵ²úÆ·1ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æ£¨CVE-2022-21306¡¢CVE-2022-21292¡¢CVE-2022-21371£©
¡¾Ðû²¼Ê±¼ä¡¿2022-01-20 11:00:00 GMT
¡¾¸ÅÊö¡¿
2022Äê1ÔÂ19ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²â·¢Ã÷Oracle¹Ù·½Ðû²¼ÁË1ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æCPU£¨Critical Patch Update£©£¬´Ë´Î¹²ÐÞ¸´ÁË497¸ö²î±ðˮƽµÄÎó²î£¬´Ë´ÎÇå¾²¸üÐÂÉæ¼°Oracle WebLogic Server¡¢Oracle MySQL¡¢Oracle Java SE¡¢Oracle FusionMiddleware¡¢Oracle Retail ApplicationsµÈ¶à¸ö³£ÓòúÆ·¡£OracleÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÓ¦ÓÃÒªº¦²¹¶¡¸üÐÂÐÞ¸´³ÌÐò£¬¶ÔÎó²î¾ÙÐÐÐÞ¸´¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
HTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2022-21907£©
¡¾Ðû²¼Ê±¼ä¡¿2022-01-18 10:00:00 GMT
¡¾¸ÅÊö¡¿
1ÔÂ12ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼Ô¶ÈÇå¾²¸üУ¬ÆäÖÐÐÞ¸´ÁËÒ»¸öHTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-21907£©¡£ÓÉÓÚHTTPÐÒéÕ»£¨HTTP.sys£©ÖеÄHTTP Trailer Support¹¦Ð§±£´æ½çÏß¹ýʧ¿Éµ¼Ö»º³åÇøÒç³ö¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòWeb·þÎñÆ÷·¢ËÍÌØÖÆµÄHTTPÊý¾Ý°ü£¬´Ó¶øÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¸ÃÎó²î±»Î¢ÈíÌáÐÑΪ“¿ÉÈ䳿»¯”£¬ÎÞÐèÓû§½»»¥±ã¿Éͨ¹ýÍøÂç¾ÙÐÐ×ÔÎÒÈö²¥£¬CVSSÆÀ·ÖΪ9.8¡£ÏÖÔÚÒÑÓпɵ¼ÖÂÄ¿µÄÖ÷»úBSoDµÄPoC¹ûÕæ£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. FIN7×é֯ͨ¹ýÓʼĶñÒâUÅÌÀ´Í¶·ÅÀÕË÷Èí¼þ
¡¾¸ÅÊö¡¿
ÃÀ¹úÁª°îÊÓ²ì¾ÖÖÜÎåÖÒÑÔ˵£¬ÀÕË÷Èí¼þÍÅ»ïÕýÔÚÓʼĶñÒâµÄUÅÌ£¬Ã°³äÃÀ¹úÎÀÉúÓ빫ÖÚ·þÎñ²¿£¨HHS£©ºÍÑÇÂíÑ·¼¯ÍÅ£¬Õë¶ÔÔËÊä¡¢°ü¹ÜºÍ¹ú·ÀÐÐÒµ¾ÙÐÐÀÕË÷Èí¼þѬȾ¹¥»÷¡£²¢ÌåÏÖ£¬¹¥»÷Õß¶ÔÕâЩ°ü¹ü¾ÙÐÐÁËαװ£¬°ÑËüÃÇαװ³ÉÁËÓë´óÊ¢Ðв¡ÓйصÄÎïÆ·£¬»òÕßαװ³ÉÀ´×ÔÑÇÂíÑ·µÄÉÌÆ·¡£°ü¹üÖ÷ÒªÓÐÁ½ÖÖ£¬ÄÇЩģÄâHHSµÄ°ü¹üͨ³£¸½ÓÐÌá¼°COVID-19Ö¸ÄϵÄÐżþ£¬²¢¸½ÉÏÒ»¸öUSB£»¶øÄÇЩαװ³ÉÑÇÂíÑ·µÄ°ü¹üÔò»á×°ÔÚÒ»¸öÓÐ×°ÊÎÐÔµÄÀñÎïºÐÖУ¬ÆäÖаüÀ¨Ò»·â¾ßÓÐÚ²ÆÐÔµÄллÐÅ¡¢Î±ÔìµÄÀñÎ│ºÍÒ»¸öUSB¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNdq
2. ¹¥»÷Õß´ÓLympo NTFƽ̨ÇÔÈ¡ÁË1870ÍòÃÀÔª
¡¾¸ÅÊö¡¿
Lympo ÕýÔÚ¹¹½¨Ò»¸öÌåÓý NFT Éú̬ϵͳ£¬°üÀ¨ÓµÓÐÌìÏÂÖøÃûÔË·¢¶¯ºÍ¾ãÀÖ²¿ÖªÊ¶²úȨµÄ NFT¡£¸ÃÉú̬ϵͳ»¹½«°üÀ¨ÓÉÖÖÖÖÒÕÊõ¼ÒºÍÌåÓýÓ°ÏìÕß½¨ÉèµÄ×Ô½ç˵ÌåÓý½ÇÉ«¡£2022 Äê1ÔÂ10ÈÕÏÂÖç2:32×óÓÒ£¨UTC +2£©£¬ºÚ¿ÍÏë·¨»á¼ûÁËLympoµÄÔËÓªÈÈÇ®°ü£¬²¢´ÓÖÐÇÔÈ¡ÁËԼĪ1.652 ÒÚ¸öLMT¡£¶øÕë¶ÔÇå¾²Îó²î£¬LympoÔöÇ¿Á˱£»¤²½·¥ÒÔ±ÜÃâÆäËû LMT ±»µÁ£¬¸Ã¹«Ë¾»¹ÔÝʱ½« LMT ´Ó¸÷¸öÁ÷¶¯×ʽð³ØÖÐÒÆ³ý£¬ÒÔ×îºéÁ÷ƽµØïÔ̹¥»÷µÄÓ°Ïì¡£±»µÁ´ú±Ò±»·¢Ë͵½¹¥»÷ÕßʹÓõĵ¥¸öµØµã£¬ÓÃÓÚÔÚSushiSwap»òUniswapÉϽ«Æä»»³É Ether£¬È»ºó½«ËüÃÇ·¢Ë͵½ÆäËûµØµã¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNdB
3. ³¯ÏʺڿʹÓÈ«Çò¼ÓÃÜÇ®±ÒÊ×´´¹«Ë¾ÇÔÈ¡ÁËÊý°ÙÍòÃÀÔª
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ Lazarus ×Ó×éÖ¯ BlueNoroff Ïà¹ØµÄÔËÓªÉÌÓëһϵÁÐÕë¶ÔÈ«ÇòÖÐСÐ͹«Ë¾µÄÍøÂç¹¥»÷Óйأ¬Ö¼Ôںľ¡ËûÃǵļÓÃÜÇ®±Ò×ʽð£¬ÕâÊdz¯Ïʹú¼ÒÔÞÖúµÄ¶à²úµÄÓÖÒ»´Î³öÓÚ¾¼ÃÄîÍ·µÄÐж¯ÑÝÔ±¡£¹¥»÷ÕßÒ»Ö±ÔÚÇÉÃîµØÀÄÓÃÔÚÄ¿µÄ¹«Ë¾ÊÂÇéµÄÔ±¹¤µÄÐÅÍУ¬ÏòËûÃÇ·¢ËÍ´øÓмàÊÓ¹¦Ð§µÄÈ«¹¦Ð§ Windows ºóÃÅ£¬Î±×°³ÉÌõÔ¼»òÆäËûÓªÒµÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNdr
4. ¹¥»÷ÕßʹÓÃÊý¾Ý²Á³ý¶ñÒâÈí¼þÕë¶ÔÎÚ¿ËÀ¼¶à¸öÕþ¸®ÏµÍ³Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±³Æ£¬ÐÂÒ»²¨Êý¾Ý²Á³ý¶ñÒâÈí¼þ£¨´úºÅDEV-0586£©ÕýÔÚÏ®»÷ÎÚ¿ËÀ¼¶à¸öÕþ¸®²¿·Ö¡¢ÐÅÏ¢ÊÖÒÕ»ú¹¹µÈ£¬ÏÖÔÚÒÑÓÐÊýÊ®¸öϵͳѬȾ£»¾ÍÔÚǰһÌ죬ÎÚ¿ËÀ¼Õþ¸®»¹ÔâÓöÁË´ó¹æÄ£ÍøÂç¹¥»÷£¬´ó×ÚÕþ¸®ÍøÕ¾ÄÚÈݱ»¸Ä¶¯Îª“Êý¾ÝÇÔÈ¡ºÍй¶ÑÔÂÛ”£¬¹Ù·½Ëæºó±Ùҥ䱬·¢Êý¾Ýй¶£»¶ñÒâÈí¼þÊ×ÏÈ»á²Á³ýÄ¿µÄWindowsϵͳÖеÄÖ÷Ö¸µ¼¼Í¼£¬Ê¹ÆäÎÞ·¨ÔËÐС£ÆäÖ÷Òª¿ÉÖ´ÐÐÎļþ“ͨ³£”ÃüÃûΪstage1.exe£¬Í¨¹ýImpacketÏ·¢Ö´ÐС£¹¥»÷Àú³ÌµÄµÚ¶þ½×¶Î£¬¸Ã²Á³ýÆ÷µÄstage2.exe»áºá³åֱײ°ãµØÉ¨µ´ÏµÍ³ÖÐµÄÆäÓಿ·Ö£¬ÁýÕÖ´ÓWordÎĵµµ½ÍøÒ³£¨.HTMLÓë.PHPÎļþ£©¡¢Í¼ÏñÓëÊý¾Ý¿âµÈËùÓÐÄÚÈÝ¡£Ëü»áËÑË÷¶àÖÖÎļþÀ©Õ¹Ãû£¬²¢“ʹÓÃÀο¿ÊýÄ¿µÄ0xCC×Ö½Ú£¨×ܼÆ1 MB£©”ÁýÕÖÎļþµÄÄÚÈÝ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNdZ
5. ¹¥»÷ÕßʹÓÃ×ÅÃûÈí¼þ°²ÅźóÃųÌÐòÌᳫ´¹ÂÚ¹¥»÷
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Çå¾²Ñо¿ÍŶӲ¶»ñµ½ÁËÒ»¸öľÂí³ÌÐò£¬¹¥»÷Õßͨ¹ýÍøÂç´¹ÂÚµÄÊÖ¶ÎÓÕµ¼Êܺ¦Õßµã»÷ÔËÐÐÓʼþÖи½´øµÄľÂí³ÌÐò£¬ÍŽáÕý³£µÄAdobe CEF Helper³ÌÐò¾ÙÐй¥»÷£»ÔÚ¾ÖÓòÍøÄÚͨ¹ý¹²ÏíĿ¼¾ÙÐÐÈö²¥£¬²¢ÔÚÓû§Ö÷»úÉÏÁôϺóÃųÌÐò¾ÙÐÐÇÔÃÜ»òÕ߯äËû¶ñÒâÐÐΪ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNdS
6. TransCreditÒòÊý¾Ý¿âÉèÖùýʧÖÂʹ´ó×ÚÃÀ¹úÈ˺ͼÓÄôóÈ˵IJÆÎñÊý¾ÝÔâй¶
¡¾¸ÅÊö¡¿
¾ÝÍâÑóÇ徲ýÌ屨µÀ£¬Ò»¼ÒλÓÚ·ðÂÞÀï´ïÖݽܿËѷά¶ûµÄ½»Í¨ÔËÊäÐÐÒµÉÌÒµÐÅÓñ¨¸æ»ú¹¹TransCreditÒòÉèÖùýʧÖÂʹ50ÍòÈ˲ÆÎñÊý¾Ýй¶¡£Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÉèÖùýʧµÄÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âΪÔËÊäÐÐÒµÉÌÒµÐÅÓñ¨¸æ»ú¹¹ TransCredit ÓµÓС£¾Ý Website Planet µÄ Jeremiah Fowler ³Æ£¬¸ÃÊý¾Ý¿â°üÀ¨¿Í»§Ãô¸Ð²ÆÎñºÍСÎÒ˽¼ÒÊý¾ÝµÄ±¦¿â£¬ÆäÖаüÀ¨¼ÓÄôóºÍÃÀ¹úµÄ»õÔ˺ÍÔËÊ乫˾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNdE
7. ¹¥»÷Õß½« IRC Bot ¶ñÒâÈí¼þͶÈ뺫¹úWebHardƽ̨¾ÙÐÐÈö²¥
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷¶ñÒâÈí¼þÕýÔÚÒÔ³ÉÈËÓÎÏ·µÄÃûÒåÈö²¥¡£²¢ÌåÏָù¥»÷ͨ¹ý½«´øÓжñÒâÈí¼þµÄÓÎÏ·ÉÏ´«µ½webhardsÀ´¾ÙÐУ¬¸ÃÍøÂçÓ²ÅÌÊÇÖ¸ÍøÂçÓ²ÅÌÇý¶¯Æ÷»òÔ¶³ÌÎļþÍйܷþÎñ£¬ÒÔѹËõZIP´æµµµÄÐÎʽ£¬·¿ªÊ±°üÀ¨Ò»¸ö¿ÉÖ´ÐÐÎļþ£¨“Game_Open.exe”£©£¬ËüÊdzýÁËÆô¶¯ÏÖʵÓÎÏ·Í⣬»¹È«ÐIJ߻®ÁËÔËÐжñÒâÈí¼þÓÐÓøºÔØ¡£Õâ¸öÓÐÓÃÔØºÉÊÇÒ»¸ö»ùÓÚ GoLang µÄÏÂÔØÆ÷£¬ËüÓëÔ¶³ÌÏÂÁîºÍ¿ØÖÆ (C) ·þÎñÆ÷½¨ÉèÅþÁ¬ÒÔ¼ìË÷ÆäËû¶ñÒâÈí¼þ£¬°üÀ¨¿ÉÒÔÖ´ÐÐ DDoS ¹¥»÷µÄ IRC »úеÈË¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNec
8. Ó¡¶ÈʱװÁãÊÛÉÌÊý¾ÝÔÚ°µÍøÊг¡ÉÏй¶
¡¾¸ÅÊö¡¿
¾Ý±¨µÀ£¬ÀÕË÷Èí¼þ¼¯ÍÅ ShinyHunters ÇÔÈ¡ÁËÊôÓÚÓ¡¶ÈʱÉкÍÁãÊÛ¹«Ë¾ Aditya Birla Fashion and Retail¡¢ABFRL µÄ¿Í»§ºÍÔ±¹¤µÄ 700 GB Êý¾Ý¡£²¢ÌåÏÖ¿Í»§ÑÛǰµÄÊÜËðÊý¾Ý°üÀ¨ 540 Íò¸öΨһµÄµç×ÓÓʼþµØµã¡¢ÐÕÃû¡¢µç»°ºÅÂë¡¢½ÖµÀµØµã¡¢¶©µ¥ÀúÊ·¼Í¼ºÍÃÜÂ룬ÕâЩÊý¾Ý´æ´¢Îª Machine Digest-5 »ò MD5 ¹þÏ£Öµ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNe9
9. ¹¥»÷Õßð³äÃÀ¹úDOLÀ´»ñÈ¡ÆóÒµµç×ÓÓʼþƾ֤ÒÔÌᳫ´¹ÂÚ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÖÒÑÔ˵£¬ÍøÂç´¹ÂÚÕßÕýÊÔͼͨ¹ýð³äÃÀ¹úÀ͹¤²¿ (DOL)À´»ñÈ¡Office 365»òÆäËûÆóÒµµç×ÓÓʼþÕÊ»§µÄƾ֤¡£Ñо¿Ö°Ô±·¢Ã÷DOL ÍâòÉÏÊÇÔÚÔ¼Ç빫˾Ìá½»“¼°¸ñ³Ð°üÉ̶ÔÕýÔÚ¾ÙÐеÄÕþ¸®ÏîÄ¿µÄÌá°¸”£¬Í¨¹ýµã»÷ PDF ÖеēBID”°´Å¥£¬Ç±ÔÚµÄÊܺ¦Õ߻ᱻ´øµ½Ò»¸öÓëÕæÊµ DOL ÍøÕ¾ÍêÈ«ÏàͬµÄÐéα DOL ²É¹ºÃÅ»§ÍøÕ¾¡£×îºó£¬µ±µã»÷“µã»÷ÕâÀï³ö¼Û”°´Å¥Ê±£¬ËûÃDZ»ÒªÇóʹÓÃÆóÒµµç×ÓÓʼþÕÊ»§µÇ¼¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNed
10. ¹¥»÷ÕßʹÓÃеÄBHUNT ÇÔÈ¡³ÌÐòÕë¶Ô¼ÓÃÜÇ®±ÒÇ®°üÌᳫ¹¥»÷
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪBHUNTµÄйæ±ÜÐÔ¼ÓÃÜÇ®±ÒÇÔÈ¡³ÌÐò£¬ËüÄܹ»ÇÔȡǮ°ü£¨Exodus¡¢Electrum¡¢Atomic¡¢Jaxx¡¢ÒÔÌ«·»¡¢±ÈÌØ±Ò¡¢À³ÌرÒÇ®°ü£©µÄÄÚÈÝ¡¢´æ´¢ÔÚä¯ÀÀÆ÷ÖеÄÃÜÂëÒÔ¼°¼ôÌù°åÖеÄÊý¾Ý¡£BHUNT ÊÇÒ»¸öÓà .NET ±àдµÄÄ£¿é»¯ÇÔÈ¡³ÌÐò£¬Æä¶þ½øÖÆÎļþʹÓà Themida ºÍ VMProtect µÈÉÌÒµ´ò°ü³ÌÐò¸ß¶È¼ÓÃÜ¡£×¨¼ÒÅжϵÄÑù±¾ÊÇÓ÷¢¸øÈí¼þ¹«Ë¾µÄÊý×ÖÖ¤Êé¾ÙÐÐÊý×ÖÊðÃûµÄ£¬µ« Ñо¿Ö°Ô± Ö¸³öÊý×ÖÖ¤ÊéÓë¶þ½øÖÆÎļþ²»Æ¥Åä¡£ÆÊÎöµÄÑù±¾Ê¹Óôӹ«¹² Pastebin Ò³ÃæÏÂÔØµÄ¼ÓÃÜÉèÖþ籾¡£¾Ýר¼Ò³Æ£¬¸Ã¶ñÒâÈí¼þͨ¹ýÆÆ½âÈí¼þ×°ÖóÌÐòºÍÊÜѬȾµÄÓû§ÔÚ¶à¸ö¹ú¼ÒÈö²¥£¬°üÀ¨°Ä´óÀûÑÇ¡¢°£¼°¡¢µÂ¹ú¡¢Ó¡¶È¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÈÕ±¾¡¢ÂíÀ´Î÷ÑÇ¡¢Å²Íþ¡¢ÐÂ¼ÓÆÂ¡¢ÄÏ·Ç¡¢Î÷°àÑÀºÍÃÀ¹ú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNem

AG¹«Ë¾ÔÆ







