¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2022Äê2Ô£©
2022-03-03
2Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬SambaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44142£©Ó°Ïì¹æÄ£Ïà¶Ô½Ï´ó¡£ÓÉÓÚSambaµÄvfs_fruitÄ£¿éĬÈÏÉèÖÃÏÂÔÊÐíͨ¹ýÀ©Õ¹ÎļþÊôÐÔ¾ÙÐÐÔ½½ç¶Ñ¶Áд¡£µ±smbdÆÊÎöEAÔªÊý¾Ýʱ£¬¶ÔÎļþÀ©Õ¹ÊôÐÔ¾ßÓÐд»á¼ûȨÏÞµÄÔ¶³Ì¹¥»÷Õߣ¨guestÕË»§»òδÊÚȨÓû§£©¿ÉʹÓÃsmbdµÄȨÏÞ(ͨ³£ÊÇroot)Ö´ÐÐí§Òâ´úÂ룬CVSSÆÀ·Ö9.9¡£
ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË48¸öÎó²î£¬Ö÷Òª£¨Im portant£©Îó²îÓÐ 48 ¸ö£¬ÆäÖÐÉæ¼°Windows¡¢Microsoft Office¡¢Microsoft Dynamics¡¢AzureµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐеȸßΣÎó²îÀàÐÍ¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬¹¥»÷ÕßʹÓòî±ð¶ñÒâÈí¼þ¶Ô¹ú¼Ò¼¶ÆóÒµÌᳫµÄ¹¥»÷Ïà¶ÔƵÈÔ£¬ÆäÖаüÀ¨A2541×é֯ʹÓÃAsyncRAT¶ñÒâÈí¼þ¶Ôº½¿ÕÒµÌᳫ´¹ÂÚ¹¥»÷£¬Ñо¿Ö°Ô±×·×Ù·¢Ã÷Ò»¸öÃûΪ TA2541 µÄ×éÖ¯´Ó 2017 Äê×îÏȵÄÍøÂç´¹ÂÚÔ˶¯¡£¸Ã×é֯ʹÓÃÕë¶Ôº½¿ÕÒµµÄÍøÂç´¹ÂÚ¹¥»÷µÄµç×ÓÓʼþÖÐÌáµ½ÁËȼÁÏ¡¢·É»úÁã¼þºÍÔËÊäµÈÖ÷Ìâ¡£ÕâÐ©ÍøÂç´¹ÂÚµç×ÓÓʼþ°üÀ¨Ö¸Ïò´æ´¢¶ñÒâ Visual Basic ÎļþµÄ google Çý¶¯Æ÷µÄÁ´½Ó£»ºÍ¹¥»÷ÕßʹÓÃWiper ¶ñÒâÈí¼þ¹¥»÷ÒÁÀʹ㲥¹«Ë¾ IRIB£¬Ñо¿Ö°Ô±ÌåÏÖÒÁÀʹú¼Ò¹ã²¥¹«Ë¾IRIBÔâµ½ÈëÇÖ£¬¶ñÒâ¿ÉÖ´ÐÐÎļþºÍ²Á³ýÆ÷Ó¦¶Ô¹¥»÷ÈÏÕæ¡£Wiper¶ñÒâÈí¼þ¾ßÓжàÖÖ¹¦Ð§£¬°üÀ¨Ð®Öƶà¸öµçÊǪ́²¥·ÅÕþÖÎ×èµ²ÅÉÏòµ¼ÈËÒªÇóıº¦ÒÁÀÊ×î¸ßÏòµ¼È˵ļÒô¡£ÆäËû¹¦Ð§°üÀ¨×Ô½ç˵ºóÃÅ¡¢ÆÁÄ»½ØÍ¼¹¦Ð§ºÍÓÃÓÚÏÂÔØÆäËû¶ñÒâ¿ÉÖ´ÐÐÎļþµÄ¼¸¸ö bash ¾ç±¾¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2022Äê02ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼203¸öÎó²î, ÆäÖиßΣÎó²î2¸ö£¬Î¢Èí¸ßΣÎó²î2¸ö¡£
* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2022.02.28
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. Lazarus APTʹÓà Windows ¸üпͻ§¶Ë GitHub
¡¾±êÇ©¡¿Lazarus
¡¾Ê±¼ä¡¿2022-02-09
¡¾¼ò½é¡¿
Lazarus Group ÊÇ×Ô 2009 ÄêÒÔÀ´Ò»Ö±»îÔ¾µÄ×îÖØ´óµÄ³¯ÏÊ APT Ö®Ò»¡£¸Ã×éÖ¯ÒÑÍù¶ÔÐí¶à¸ßµ÷µÄ¹¥»÷ÈÏÕæ£¬²¢»ñµÃÁËÈ«ÌìÏµĹØ×¢¡£Malwarebytes ÍþвÇ鱨ÍŶÓÕýÔÚÆð¾¢¼à¿ØÆäÔ˶¯£¬²¢Äܹ»ÔÚ 2022 Äê 1 Ô 18 ÈÕ·¢Ã÷еÄÔ˶¯¡£ÔÚÕâ´ÎÔ˶¯ÖУ¬Lazarus ¾ÙÐÐÁËÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷£¬ÕâЩ¹¥»÷ʹÓÃÁËʹÓÃÆäÒÑÖªÊÂÇéʱ»úÖ÷ÌâµÄ¶ñÒâÎĵµ×÷ΪÎäÆ÷¡£ÎÒÃÇ·¢Ã÷ÁËÁ½·Ýαװ³ÉÃÀ¹úÈ«ÇòÇå¾²ºÍº½¿Õº½Ìì¾ÞÍ·Âå¿ËÏ£µÂÂí¶¡¹«Ë¾µÄÓÕ¶üÎļþ£¬ÇÉÃîµØÊ¹Óà Windows Update À´Ö´ÐжñÒâ¸ºÔØ£¬ÒÔ¼°½« GitHub ×÷ΪÏÂÁîºÍ¿ØÖÆ·þÎñÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNgz
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡12ÌõIOC£¬ÆäÖаüÀ¨2¸öÓòÃûºÍ10¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. º£ÄÚijmacOS Ó¦ÓÃÏÂÔØÕ¾ÔâºÚ¿ÍͶ¶¾¹¥»÷
¡¾±êÇ©¡¿macOS
¡¾Ê±¼ä¡¿2022-02-22
¡¾¼ò½é¡¿
ÍþвÑо¿Ô±·¢Ã÷£¬º£ÄÚijµÚÈý·½ macOS Ó¦ÓÃÏÂÔØÕ¾£¨www.macwk.com£©ÉÏ·ºÆð±»APT ×é֯Ͷ¶¾µÄÊý¾Ý¿âÖÎÀíÓ¦Óà Navicat Premium¡£Navicat Premium ÊÇÒ»¿îÊ¢ÐеÄÊÕ·ÑÊý¾Ý¿âÖÎÀíÓ¦Ó㬹¥»÷ÕßʹÓò¿·ÖʹÓÃÕßѰÕÒÆÆ½â°æµÄÐèÇó£¬ÔÚÊ¢ÐеĵÚÈý·½ macOS Ó¦ÓÃÏÂÔØÕ¾Í¶·Å±»Í¶¶¾µÄ Navicat Premium ÆÆ½â°æ£¬½ø¶øÊµÏÖ¶ÔÏÂÔØÊ¹ÓÃÕßµÄÈëÇÖ¡£¼øÓÚ¸ÃÕ¾µãÉÏ´ËÓ¦ÓÃÏÂÔØÁ¿½Ï¸ß£¨ÀúÊ·×ܼƳ¬ 37 Íò´Î£©£¬ÇÒͶ¶¾ÊÂÎñÁè¼ÝÈýÖÜ£¬ÎÒÃÇÅжϸÃÊÂÎñÓ°Ïì¹æÄ£½Ï¹ã¡£Ïà¹ØÄ¾ÂíÓë 2021 Äê 9 Ô·ÝÅû¶µÄÇå¾²ÊÂÎñmacOS ƽ̨É϶à¿î³£ÓÃÔËά¹¤¾ßÔâ APT Ͷ¶¾¹¥»÷ÖÐʹÓõÄľÂíÏàͬ£¬Òò´Ë½«¹¥»÷Õß¹éÊôΪWinnti ×å×éÖ¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNi6
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ1¸öÓòÃû£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. Arid Viper APTʹÓÃDelphi¶ñÒâÈí¼þ¶Ô°ÍÀÕ˹̹ÌᳫÐÂÒ»²¨ÒÔÕþÖÎΪÖ÷ÌâµÄÍøÂç´¹ÂÚ¹¥»÷
¡¾±êÇ©¡¿Delphi¶ñÒâÈí¼þ
¡¾Ê±¼ä¡¿2022-02-23
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁË×Ô 2017 ÄêÒÔÀ´Ê¹Óà Delphi ¶ñÒâÈí¼þµÄÒ»Á¬Ô˶¯µÄÐÂÀ˳±¡£¶ø×î½üÒ»²¨¹¥»÷ʹÓÃ×î³õÐû²¼ÔÚÍÁ¶úÆä¹úӪͨѶÉçAnadoluºÍ°ÍÀÕ˹̹MA\'AN Éú³¤ÖÐÐĵÄÄÚÈÝÒÔÔ˶¯¼ÒºÍ°ÍÀÕ˹̹»ú¹¹ÎªÄ¿µÄ£¬ÊÓ²ìºó·¢Ã÷ÓÃÓÚÕë¶Ô°ÍÀÕ˹̹ʵÌåµÄÖ²ÈëÎïÓÉ»ùÓÚ Delphi µÄ Micropsia °æ±¾×é³É£¬¸ÃÖ²Èë³ÌÐòÓÉÒ»¸ö Delphi ±íµ¥×é³É£¬¸Ã±íµ¥¾ßÓÐËĸö°´Å¥ºÍËĸö¼ÆÊ±Æ÷£¬ÓÃÓÚÖ´ÐÐÏÂÊö²î±ðµÄ¶ñÒâÔ˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNim
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡22ÌõIOC£¬ÆäÖаüÀ¨7¸öÓòÃûºÍ15¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. ¹¥»÷ÕßʹÓöñÒâexcelÎļþÈö²¥BitRAT¶ñÒâÈí¼þ
¡¾±êÇ©¡¿BitRAT
¡¾Ê±¼ä¡¿2022-02-23
¡¾¼ò½é¡¿
Çå¾²Ñо¿Ô±×î½ü·¢Ã÷ÁËÒ»¸öÍâ¹ÛÆæÒìµÄExcel ºêÎļþ (XLSM)£¬ÆäÖÐËÆºõ°üÀ¨ NFT Ïà¹ØÐÅÏ¢¡£µ«Ïà·´£¬Ëü»áÔÚºǫ́ÏÂÔØ²¢×°Öà BitRAT ¶ñÒâÈí¼þ¡£Ê×ÏÈ£¬XLSM ±»ÃüÃûΪ“NFT_Items.xlsm”¡£Æä´Î£¬¸ÃÎļþÓÐÁ½±¾ÊÂÇé²¾£¬ÆäÖÐÒ»±¾ÊÇÏ£²®À´ÓïµÄ¡£¸ÃÊÂÇé²¾°üÀ¨ËƺõÊÇ´¦Öóͷ£ NFT µÄÕýµ± Discord £¬Ëü»¹°üÀ¨ NFT µÄÃû³Æ¡¢Ç±ÔÚͶ×ʻر¨µÄÕ¹Íû£¨³´×÷¡¢ÎÈ¹ÌºÍ 50/50£©ÒÔ¼°ÏúÊÛÊýÄ¿¡£Ñо¿Ö°Ô±ÌåÏÖ¹¥»÷ͨ¹ýʹÓà Discord ÍйܶñÒâÎļþÀ´ÀÄÓà Discord£¬²¢ÇÒ¹¥»÷ÕߺܿÉÄÜÏòÒÔÉ«ÁÐµÄ NFT ϲ»¶Õß·¢ËÍÁËÒ»ÌõÐÂÎÅ£¬ÒÔÓÕʹËûÃÇÏÂÔØ²¢·¿ª¶ñÒâ XLSM£¬´Ó¶øµÖ´ïÈö²¥BitRAT¶ñÒâÈí¼þµÄÄ¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNin
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. Transparent Tribe×é֯ʹÓÃCrimson RATÌᳫ´¹ÂÚ¹¥»÷
¡¾±êÇ©¡¿Crimson RAT
¡¾Ê±¼ä¡¿2022-02-23
¡¾¼ò½é¡¿
¿ËÈÕ£¬Çå¾²Ñо¿ÔºÔÚÒ»Ñùƽ³£µÄÍþвá÷ÁÔÖв¶»ñÁËTransparent Tribe×éÖ¯µÄ¶à¸öCrimson RAT¹¥»÷Ñù±¾¡£Ôڴ˹¥»÷Ô˶¯ÖУ¬¹¥»÷ÕßʹÓÃͼƬÎļþͼ±êÓÃ×÷¶ñÒâÈí¼þͼ±ê£¬ÓÕʹĿµÄ·¿ª\"ͼƬ\"Éó²é£¬ÊµÔòÔËÐжñÒâÈí¼þ¡£µ±Êܺ¦Õßµã»÷Ö´ÐÐÓÕ¶üÎļþÖ®ºó£¬½«»áÔÚÍâµØÊÍ·ÅÒ»¸öѹËõ°ü£¬²¢Ö´ÐÐѹËõ°üÄÚ°üÀ¨µÄTransparent Tribe×éÖ¯µÄ×ÔÓÐÔ¶¿ØÈí¼þCrimson RAT¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNio
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡8ÌõIOC£¬ÆäÖаüÀ¨2¸öIPºÍ6¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. ¹¥»÷ÕßʹÓÃWiper ¶ñÒâÈí¼þ¹¥»÷ÒÁÀʹ㲥¹«Ë¾ IRIB
¡¾±êÇ©¡¿Wiper
¡¾Ê±¼ä¡¿2022-02-24
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±ÌåÏÖÒÁÀʹú¼Ò¹ã²¥¹«Ë¾ IRIB Ôâµ½ÈëÇÖ£¬¶ñÒâ¿ÉÖ´ÐÐÎļþºÍ²Á³ýÆ÷Ó¦¶Ô¹¥»÷ÈÏÕæ¡£Wiper¶ñÒâÈí¼þ¾ßÓжàÖÖ¹¦Ð§£¬°üÀ¨Ð®Öƶà¸öµçÊǪ́²¥·ÅÕþÖÎ×èµ²ÅÉÏòµ¼ÈËÒªÇóıº¦ÒÁÀÊ×î¸ßÏòµ¼È˵ļÒô¡£ÆäËû¹¦Ð§°üÀ¨×Ô½ç˵ºóÃÅ¡¢ÆÁÄ»½ØÍ¼¹¦Ð§ºÍÓÃÓÚÏÂÔØÆäËû¶ñÒâ¿ÉÖ´ÐÐÎļþµÄ¼¸¸ö bash ¾ç±¾¡£ÔÚÊÓ²ìÑо¿ÖÐÑо¿Ö°Ô±·¢Ã÷ÁËÁ½¸öÏàͬµÄ .NET ʾÀýmsdskint.exe£¬ËüÃǵÄÖ÷ҪĿµÄÊDzÁ³ýÅÌËã»úµÄÎļþ¡¢Çý¶¯Æ÷ºÍ MBR¡£ÕâÒ²¿ÉÒÔ´Ó PDB ·¾¶ÖÐÍÆµ¼³öÀ´£ºC:\\work\\wiper\\Wiper\\obj\\Release\\Wiper.pdb¡£±ðµÄ£¬¸Ã¶ñÒâÈí¼þ»¹Äܹ»É¨³ý Windows ÊÂÎñÈÕÖ¾¡¢É¾³ý±¸·Ý¡¢ÖÕÖ¹Àú³Ì¡¢¸ü¸ÄÓû§ÃÜÂëµÈ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNiC
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡22ÌõIOC£¬ÆäÖаüÀ¨22¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
7. ¹¥»÷ÕßʹÓÃTrickbot¶ñÒâÈí¼þ¶Ô¶à¼Ò×ÅÃû¹«Ë¾µÄ¿Í»§Ìᳫ¹¥»÷
¡¾±êÇ©¡¿Trickbot
¡¾Ê±¼ä¡¿2022-02-24
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±ÌåÏÖTrickbot ÊÇÒ»ÖÖÖØ´óÇÒÓÃ;ÆÕ±éµÄ¶ñÒâÈí¼þ£¬¾ßÓÐ 20 ¶à¸ö¿É°´ÐèÏÂÔØºÍÖ´ÐеÄÄ£¿é¡£´ËÀàÄ£¿éÔÊÐíÖ´ÐÐÖÖÖÖ¶ñÒâÔ˶¯£¬²¢¶ÔÖ÷ҪλÓÚÃÀ¹úµÄ 60 ¼Ò×ÅÃû½ðÈÚ£¨°üÀ¨¼ÓÃÜÇ®±Ò£©ºÍÊÖÒÕ¹«Ë¾µÄ¿Í»§×é³ÉÖØ´óΣÏÕ¡£×Ô 2020 Äê 10 ÔÂÒÔÀ´£¬ÀàËÆÓÚ Zeus ¶ñÒâÈí¼þµÄ injectDll Ä£¿é±»ÆµÈÔʹÓ㬸ÃÄ£¿é½«¶ñÒâ´úÂë×¢Èë Web ä¯ÀÀÆ÷ÒÔÇÔÈ¡ÒøÐÐºÍÆ¾Ö¤Êý¾Ý¡£±ðµÄ£¬Trickbot ÓµÓжàÖÖ·´ÆÊÎöÊÖÒÕ£¬ÆäÖÐÐí¶àÔÚµÍˮƽÉ϶¼ºÜÊÇÖØ´ó¡£ÕâÖÖÔöÌíµÄ»ìÏýʹÆäÊܵ½Ï£ÍûÔڽϳ¤Ê±¼äÄÚÒþ²ØÆäÐÐΪµÄ¹¥»÷ÕߵĽӴý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNiE
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨2¸öÓòÃûºÍ1¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
8. A2541×é֯ʹÓÃAsyncRAT¶ñÒâÈí¼þ¶Ôº½¿ÕÒµÌᳫ´¹ÂÚ¹¥»÷
¡¾±êÇ©¡¿AsyncRAT
¡¾Ê±¼ä¡¿2022-02-24
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±×·×Ù·¢Ã÷Ò»¸öÃûΪ TA2541 µÄ×éÖ¯´Ó 2017 Äê×îÏȵÄÍøÂç´¹ÂÚÔ˶¯¡£¸Ã×é֯ʹÓÃÕë¶Ôº½¿ÕÒµµÄÍøÂç´¹ÂÚ¹¥»÷µÄµç×ÓÓʼþÖÐÌáµ½ÁËȼÁÏ¡¢·É»úÁã¼þºÍÔËÊäµÈÖ÷Ìâ¡£ÕâÐ©ÍøÂç´¹ÂÚµç×ÓÓʼþ°üÀ¨Ö¸Ïò´æ´¢¶ñÒâ Visual Basic ÎļþµÄ google Çý¶¯Æ÷µÄÁ´½Ó¡£Ò»µ©Ö´ÐУ¬ÕâЩÎļþ¾Í»áÔËÐÐ×¢Èë RegScvs.exe µÄ powershell ÏÂÁ´Ó¶øÔÊÐí¹¥»÷Õß½ûÓà Windows ·´¶ñÒâÈí¼þɨÃè½Ó¿Ú (AMSI)¡£ÔÚ·ÀÓùÊܵ½ÍþвµÄÇéÐÎÏ£¬powershell ÏÂÁî»áÅþÁ¬µ½¹¥»÷ÕßµÄ C2 »ù´¡ÉèÊ©ÒÔ×°ÖÃÔ¶³Ì»á¼ûľÂí (RAT)¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNiD
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡15ÌõIOC£¬ÆäÖаüÀ¨11¸öÓòÃûºÍ4¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
9. ShuckwormÕë¶ÔÎÚ¿ËÀ¼Ìá³«ÍøÂçÌØ¹¤¹¥»÷
¡¾±êÇ©¡¿Shuckworm
¡¾Ê±¼ä¡¿2022-02-11
¡¾¼ò½é¡¿
Óë¶íÂÞ˹ÓÐ¹ØµÄ Shuckworm ×éÖ¯£¨ÓÖÃû Gamaredon£¬Armageddon£©ÕýÔÚ¼ÌÐø¶ÔÎÚ¿ËÀ¼µÄÄ¿µÄ¾ÙÐÐÍøÂçÌØ¹¤¹¥»÷£¬½üÆÚ£¬Çå¾²Ñо¿Ô±·¢Ã÷ÁËÐí¶àÕë¶Ô¸Ã¹úÐí¶à×éÖ¯µÄδËì¹¥»÷µÄÖ¤¾Ý¡£ÖÚËùÖÜÖª£¬¸Ã×é֯ʹÓÃÍøÂç´¹ÂÚµç×ÓÓʼþÏòÄ¿µÄ·Ö·¢Ãâ·Ñ¿ÉÓõÄÔ¶³Ì»á¼û¹¤¾ß£¬°üÀ¨Ô¶³ÌʹÓÃÆ÷ϵͳ (RMS) ºÍ UltraVNC£¬»òÃûΪ Pterodo/Pteranodon µÄ¶¨ÖƶñÒâÈí¼þ¡£ÎÚ¿ËÀ¼Çå¾²¾Ö (SSU)×î½üÐû²¼µÄÒ»·Ý±¨¸æÖ¸³ö£¬Shuckworm µÄ¹¥»÷×î½ü±äµÃÔ½À´Ô½Öش󣬹¥»÷ÕßÏÖÔÚʹÓ÷ÇÍâµØ¹¤¾ßÀ´ÇÔȡƾ֤²¢ÔÚÊܺ¦ÕßÍøÂçÉϺáÏòÒÆ¶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNgA
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡Ìõ235ÌõIOC£¬ÆäÖаüÀ¨210¸öÑù±¾¡¢5¸öÓòÃûºÍ20¸öURL£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
10. ÒÁÀÊ APT MuddyWater ͨ¹ý¶ñÒâ PDF¡¢¿ÉÖ´ÐÐÎļþÕë¶ÔÍÁ¶úÆäÓû§
¡¾±êÇ©¡¿MuddyWater
¡¾Ê±¼ä¡¿2022-02-11
¡¾¼ò½é¡¿
MuddyWater½ÓÄɵĵ䷶ TTP ÊÇÔÚÆäѬȾÁ´Öдó×ÚʹÓþ籾£¬Ê¹Óà PowerShell ºÍ Visual Basic µÈÓïÑÔ£¬ÒÔ¼°ÆµÈÔʹÓÃÍâµØ¶þ½øÖÆÎļþ (LoLBins)£¬ÆµÈÔ¿ªÆôÖÖÖÖÔ˶¯¡£½üÆÚ£¬Çå¾²Ñо¿Ô±ÊӲ쵽 MuddyWater Õë¶ÔÍÁ¶úÆäÓû§¿ªÕ¹µÄÒ»ÏîÔ˶¯¡£¸ÃÔ˶¯°üÀ¨Ê¹ÓöñÒâ PDF ºÍ Microsoft Office Îĵµ (maldocs) ×÷Ϊ³õʼѬȾǰÑÔ¡£ÕâЩ¶ñÒâÎĵµ±»ÃüÃûΪαװ³ÉÍÁ¶úÆäÎÀÉúºÍÄÚÕþ²¿µÄÕýµ±Îļþ¡£¶ñÒâÈí¼þ»áÖ´ÐÐһϵÁа²ÅÅÔÚÊÜѬȾ¶ËµãÉϵľ籾£¬×÷ÎªÌØÊâ¸ºÔØµÄÏÂÔØÆ÷ºÍ¹¤¾ß¡£¸Ã¹¥»÷ÕßÔÚ´ËÔ˶¯ÖоÙÐеĹ¥»÷ÖÐʹÓÃÁ˱ê¼Ç»òÁîÅÆ¡£ÕâЩÁîÅÆÖ¼ÔÚÅú×¢¸Ã×éÖ¯µÄ¶ñÒ⹤¼þÒÑÀÖ³ÉѬȾĿµÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNgB
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡Ìõ56ÌõIOC£¬ÆäÖаüÀ¨14¸öURL¡¢11¸öIPºÍ31¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







