AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2022Äê2Ô£©

2022-03-03

2Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬SambaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44142£©Ó°Ïì¹æÄ£Ïà¶Ô½Ï´ó¡£ÓÉÓÚSambaµÄvfs_fruitÄ£¿éĬÈÏÉèÖÃÏÂÔÊÐíͨ¹ýÀ©Õ¹ÎļþÊôÐÔ¾ÙÐÐÔ½½ç¶Ñ¶Áд¡£µ±smbdÆÊÎöEAÔªÊý¾Ýʱ£¬¶ÔÎļþÀ©Õ¹ÊôÐÔ¾ßÓÐд»á¼ûȨÏÞµÄÔ¶³Ì¹¥»÷Õߣ¨guestÕË»§»òδÊÚȨÓû§£©¿ÉʹÓÃsmbdµÄȨÏÞ(ͨ³£ÊÇroot)Ö´ÐÐí§Òâ´úÂ룬CVSSÆÀ·Ö9.9¡£

ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË48¸öÎó²î£¬Ö÷Òª£¨Im portant£©Îó²îÓÐ 48 ¸ö£¬ÆäÖÐÉæ¼°Windows¡¢Microsoft Office¡¢Microsoft Dynamics¡¢AzureµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐеȸßΣÎó²îÀàÐÍ¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£

ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬¹¥»÷ÕßʹÓòî±ð¶ñÒâÈí¼þ¶Ô¹ú¼Ò¼¶ÆóÒµÌᳫµÄ¹¥»÷Ïà¶ÔƵÈÔ£¬ÆäÖаüÀ¨A2541×é֯ʹÓÃAsyncRAT¶ñÒâÈí¼þ¶Ôº½¿ÕÒµÌᳫ´¹ÂÚ¹¥»÷£¬Ñо¿Ö°Ô±×·×Ù·¢Ã÷Ò»¸öÃûΪ TA2541 µÄ×éÖ¯´Ó 2017 Äê×îÏȵÄÍøÂç´¹ÂÚÔ˶¯¡£¸Ã×é֯ʹÓÃÕë¶Ôº½¿ÕÒµµÄÍøÂç´¹ÂÚ¹¥»÷µÄµç×ÓÓʼþÖÐÌáµ½ÁËȼÁÏ¡¢·É»úÁã¼þºÍÔËÊäµÈÖ÷Ìâ¡£ÕâÐ©ÍøÂç´¹ÂÚµç×ÓÓʼþ°üÀ¨Ö¸Ïò´æ´¢¶ñÒâ Visual Basic ÎļþµÄ google Çý¶¯Æ÷µÄÁ´½Ó£»ºÍ¹¥»÷ÕßʹÓÃWiper ¶ñÒâÈí¼þ¹¥»÷ÒÁÀʹ㲥¹«Ë¾ IRIB£¬Ñо¿Ö°Ô±ÌåÏÖÒÁÀʹú¼Ò¹ã²¥¹«Ë¾IRIBÔâµ½ÈëÇÖ£¬¶ñÒâ¿ÉÖ´ÐÐÎļþºÍ²Á³ýÆ÷Ó¦¶Ô¹¥»÷ÈÏÕæ¡£Wiper¶ñÒâÈí¼þ¾ßÓжàÖÖ¹¦Ð§£¬°üÀ¨Ð®Öƶà¸öµçÊǪ́²¥·ÅÕþÖÎ×èµ²ÅÉÏòµ¼ÈËÒªÇóıº¦ÒÁÀÊ×î¸ßÏòµ¼È˵ļÒô¡£ÆäËû¹¦Ð§°üÀ¨×Ô½ç˵ºóÃÅ¡¢ÆÁÄ»½ØÍ¼¹¦Ð§ºÍÓÃÓÚÏÂÔØÆäËû¶ñÒâ¿ÉÖ´ÐÐÎļþµÄ¼¸¸ö bash ¾ç±¾¡£

ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/

 

Ò»¡¢ Îó²îÌ¬ÊÆ

2022Äê02ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼203¸öÎó²î, ÆäÖиßΣÎó²î2¸ö£¬Î¢Èí¸ßΣÎó²î2¸ö¡£

 

* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2022.02.28

×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»

 

¶þ¡¢ ÍþвÊÂÎñ

1. Lazarus APTʹÓà Windows ¸üпͻ§¶Ë GitHub

¡¾±êÇ©¡¿Lazarus

¡¾Ê±¼ä¡¿2022-02-09

¡¾¼ò½é¡¿

Lazarus Group ÊÇ×Ô 2009 ÄêÒÔÀ´Ò»Ö±»îÔ¾µÄ×îÖØ´óµÄ³¯ÏÊ APT Ö®Ò»¡£¸Ã×éÖ¯ÒÑÍù¶ÔÐí¶à¸ßµ÷µÄ¹¥»÷ÈÏÕæ£¬²¢»ñµÃÁËÈ«ÌìÏµĹØ×¢¡£Malwarebytes ÍþвÇ鱨ÍŶÓÕýÔÚÆð¾¢¼à¿ØÆäÔ˶¯£¬²¢Äܹ»ÔÚ 2022 Äê 1 Ô 18 ÈÕ·¢Ã÷еÄÔ˶¯¡£ÔÚÕâ´ÎÔ˶¯ÖУ¬Lazarus ¾ÙÐÐÁËÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷£¬ÕâЩ¹¥»÷ʹÓÃÁËʹÓÃÆäÒÑÖªÊÂÇéʱ»úÖ÷ÌâµÄ¶ñÒâÎĵµ×÷ΪÎäÆ÷¡£ÎÒÃÇ·¢Ã÷ÁËÁ½·Ýαװ³ÉÃÀ¹úÈ«ÇòÇå¾²ºÍº½¿Õº½Ìì¾ÞÍ·Âå¿ËÏ£µÂÂí¶¡¹«Ë¾µÄÓÕ¶üÎļþ£¬ÇÉÃîµØÊ¹Óà Windows Update À´Ö´ÐжñÒâ¸ºÔØ£¬ÒÔ¼°½« GitHub ×÷ΪÏÂÁîºÍ¿ØÖÆ·þÎñÆ÷¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNgz

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡12ÌõIOC£¬ÆäÖаüÀ¨2¸öÓòÃûºÍ10¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

2. º£ÄÚijmacOS Ó¦ÓÃÏÂÔØÕ¾ÔâºÚ¿ÍͶ¶¾¹¥»÷

¡¾±êÇ©¡¿macOS

¡¾Ê±¼ä¡¿2022-02-22

¡¾¼ò½é¡¿

ÍþвÑо¿Ô±·¢Ã÷£¬º£ÄÚijµÚÈý·½ macOS Ó¦ÓÃÏÂÔØÕ¾£¨www.macwk.com£©ÉÏ·ºÆð±»APT ×é֯Ͷ¶¾µÄÊý¾Ý¿âÖÎÀíÓ¦Óà Navicat Premium¡£Navicat Premium ÊÇÒ»¿îÊ¢ÐеÄÊÕ·ÑÊý¾Ý¿âÖÎÀíÓ¦Ó㬹¥»÷ÕßʹÓò¿·ÖʹÓÃÕßѰÕÒÆÆ½â°æµÄÐèÇó£¬ÔÚÊ¢ÐеĵÚÈý·½ macOS Ó¦ÓÃÏÂÔØÕ¾Í¶·Å±»Í¶¶¾µÄ Navicat Premium ÆÆ½â°æ£¬½ø¶øÊµÏÖ¶ÔÏÂÔØÊ¹ÓÃÕßµÄÈëÇÖ¡£¼øÓÚ¸ÃÕ¾µãÉÏ´ËÓ¦ÓÃÏÂÔØÁ¿½Ï¸ß£¨ÀúÊ·×ܼƳ¬ 37 Íò´Î£©£¬ÇÒͶ¶¾ÊÂÎñÁè¼ÝÈýÖÜ£¬ÎÒÃÇÅжϸÃÊÂÎñÓ°Ïì¹æÄ£½Ï¹ã¡£Ïà¹ØÄ¾ÂíÓë 2021 Äê 9 Ô·ÝÅû¶µÄÇå¾²ÊÂÎñmacOS ƽ̨É϶à¿î³£ÓÃÔËά¹¤¾ßÔâ APT Ͷ¶¾¹¥»÷ÖÐʹÓõÄľÂíÏàͬ£¬Òò´Ë½«¹¥»÷Õß¹éÊôΪWinnti ×å×éÖ¯¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNi6

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ1¸öÓòÃû£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

3. Arid Viper APTʹÓÃDelphi¶ñÒâÈí¼þ¶Ô°ÍÀÕ˹̹ÌᳫÐÂÒ»²¨ÒÔÕþÖÎΪÖ÷ÌâµÄÍøÂç´¹ÂÚ¹¥»÷

¡¾±êÇ©¡¿Delphi¶ñÒâÈí¼þ

¡¾Ê±¼ä¡¿2022-02-23

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±·¢Ã÷ÁË×Ô 2017 ÄêÒÔÀ´Ê¹Óà Delphi ¶ñÒâÈí¼þµÄÒ»Á¬Ô˶¯µÄÐÂÀ˳±¡£¶ø×î½üÒ»²¨¹¥»÷ʹÓÃ×î³õÐû²¼ÔÚÍÁ¶úÆä¹úӪͨѶÉçAnadoluºÍ°ÍÀÕ˹̹MA\'AN Éú³¤ÖÐÐĵÄÄÚÈÝÒÔÔ˶¯¼ÒºÍ°ÍÀÕ˹̹»ú¹¹ÎªÄ¿µÄ£¬ÊÓ²ìºó·¢Ã÷ÓÃÓÚÕë¶Ô°ÍÀÕ˹̹ʵÌåµÄÖ²ÈëÎïÓÉ»ùÓÚ Delphi µÄ Micropsia °æ±¾×é³É£¬¸ÃÖ²Èë³ÌÐòÓÉÒ»¸ö Delphi ±íµ¥×é³É£¬¸Ã±íµ¥¾ßÓÐËĸö°´Å¥ºÍËĸö¼ÆÊ±Æ÷£¬ÓÃÓÚÖ´ÐÐÏÂÊö²î±ðµÄ¶ñÒâÔ˶¯¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNim

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡22ÌõIOC£¬ÆäÖаüÀ¨7¸öÓòÃûºÍ15¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

4. ¹¥»÷ÕßʹÓöñÒâexcelÎļþÈö²¥BitRAT¶ñÒâÈí¼þ

¡¾±êÇ©¡¿BitRAT

¡¾Ê±¼ä¡¿2022-02-23

¡¾¼ò½é¡¿

Çå¾²Ñо¿Ô±×î½ü·¢Ã÷ÁËÒ»¸öÍâ¹ÛÆæÒìµÄExcel ºêÎļþ (XLSM)£¬ÆäÖÐËÆºõ°üÀ¨ NFT Ïà¹ØÐÅÏ¢¡£µ«Ïà·´£¬Ëü»áÔÚºǫ́ÏÂÔØ²¢×°Öà BitRAT ¶ñÒâÈí¼þ¡£Ê×ÏÈ£¬XLSM ±»ÃüÃûΪ“NFT_Items.xlsm”¡£Æä´Î£¬¸ÃÎļþÓÐÁ½±¾ÊÂÇé²¾£¬ÆäÖÐÒ»±¾ÊÇÏ£²®À´ÓïµÄ¡£¸ÃÊÂÇé²¾°üÀ¨ËƺõÊÇ´¦Öóͷ£ NFT µÄÕýµ± Discord £¬Ëü»¹°üÀ¨ NFT µÄÃû³Æ¡¢Ç±ÔÚͶ×ʻر¨µÄÕ¹Íû£¨³´×÷¡¢ÎÈ¹ÌºÍ 50/50£©ÒÔ¼°ÏúÊÛÊýÄ¿¡£Ñо¿Ö°Ô±ÌåÏÖ¹¥»÷ͨ¹ýʹÓà Discord ÍйܶñÒâÎļþÀ´ÀÄÓà Discord£¬²¢ÇÒ¹¥»÷ÕߺܿÉÄÜÏòÒÔÉ«ÁÐµÄ NFT ϲ»¶Õß·¢ËÍÁËÒ»ÌõÐÂÎÅ£¬ÒÔÓÕʹËûÃÇÏÂÔØ²¢·­¿ª¶ñÒâ XLSM£¬´Ó¶øµÖ´ïÈö²¥BitRAT¶ñÒâÈí¼þµÄÄ¿µÄ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNin

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

5. Transparent Tribe×é֯ʹÓÃCrimson RATÌᳫ´¹ÂÚ¹¥»÷

¡¾±êÇ©¡¿Crimson RAT

¡¾Ê±¼ä¡¿2022-02-23

¡¾¼ò½é¡¿

¿ËÈÕ£¬Çå¾²Ñо¿ÔºÔÚÒ»Ñùƽ³£µÄÍþвá÷ÁÔÖв¶»ñÁËTransparent Tribe×éÖ¯µÄ¶à¸öCrimson RAT¹¥»÷Ñù±¾¡£Ôڴ˹¥»÷Ô˶¯ÖУ¬¹¥»÷ÕßʹÓÃͼƬÎļþͼ±êÓÃ×÷¶ñÒâÈí¼þͼ±ê£¬ÓÕʹĿµÄ·­¿ª\"ͼƬ\"Éó²é£¬ÊµÔòÔËÐжñÒâÈí¼þ¡£µ±Êܺ¦Õßµã»÷Ö´ÐÐÓÕ¶üÎļþÖ®ºó£¬½«»áÔÚÍâµØÊÍ·ÅÒ»¸öѹËõ°ü£¬²¢Ö´ÐÐѹËõ°üÄÚ°üÀ¨µÄTransparent Tribe×éÖ¯µÄ×ÔÓÐÔ¶¿ØÈí¼þCrimson RAT¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNio

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡8ÌõIOC£¬ÆäÖаüÀ¨2¸öIPºÍ6¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

6. ¹¥»÷ÕßʹÓÃWiper ¶ñÒâÈí¼þ¹¥»÷ÒÁÀʹ㲥¹«Ë¾ IRIB

¡¾±êÇ©¡¿Wiper

¡¾Ê±¼ä¡¿2022-02-24

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±ÌåÏÖÒÁÀʹú¼Ò¹ã²¥¹«Ë¾ IRIB Ôâµ½ÈëÇÖ£¬¶ñÒâ¿ÉÖ´ÐÐÎļþºÍ²Á³ýÆ÷Ó¦¶Ô¹¥»÷ÈÏÕæ¡£Wiper¶ñÒâÈí¼þ¾ßÓжàÖÖ¹¦Ð§£¬°üÀ¨Ð®Öƶà¸öµçÊǪ́²¥·ÅÕþÖÎ×èµ²ÅÉÏòµ¼ÈËÒªÇóıº¦ÒÁÀÊ×î¸ßÏòµ¼È˵ļÒô¡£ÆäËû¹¦Ð§°üÀ¨×Ô½ç˵ºóÃÅ¡¢ÆÁÄ»½ØÍ¼¹¦Ð§ºÍÓÃÓÚÏÂÔØÆäËû¶ñÒâ¿ÉÖ´ÐÐÎļþµÄ¼¸¸ö bash ¾ç±¾¡£ÔÚÊÓ²ìÑо¿ÖÐÑо¿Ö°Ô±·¢Ã÷ÁËÁ½¸öÏàͬµÄ .NET ʾÀýmsdskint.exe£¬ËüÃǵÄÖ÷ҪĿµÄÊDzÁ³ýÅÌËã»úµÄÎļþ¡¢Çý¶¯Æ÷ºÍ MBR¡£ÕâÒ²¿ÉÒÔ´Ó PDB ·¾¶ÖÐÍÆµ¼³öÀ´£ºC:\\work\\wiper\\Wiper\\obj\\Release\\Wiper.pdb¡£±ðµÄ£¬¸Ã¶ñÒâÈí¼þ»¹Äܹ»É¨³ý Windows ÊÂÎñÈÕÖ¾¡¢É¾³ý±¸·Ý¡¢ÖÕÖ¹Àú³Ì¡¢¸ü¸ÄÓû§ÃÜÂëµÈ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNiC

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡22ÌõIOC£¬ÆäÖаüÀ¨22¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

7. ¹¥»÷ÕßʹÓÃTrickbot¶ñÒâÈí¼þ¶Ô¶à¼Ò×ÅÃû¹«Ë¾µÄ¿Í»§Ìᳫ¹¥»÷

¡¾±êÇ©¡¿Trickbot

¡¾Ê±¼ä¡¿2022-02-24

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±ÌåÏÖTrickbot ÊÇÒ»ÖÖÖØ´óÇÒÓÃ;ÆÕ±éµÄ¶ñÒâÈí¼þ£¬¾ßÓÐ 20 ¶à¸ö¿É°´ÐèÏÂÔØºÍÖ´ÐеÄÄ£¿é¡£´ËÀàÄ£¿éÔÊÐíÖ´ÐÐÖÖÖÖ¶ñÒâÔ˶¯£¬²¢¶ÔÖ÷ҪλÓÚÃÀ¹úµÄ 60 ¼Ò×ÅÃû½ðÈÚ£¨°üÀ¨¼ÓÃÜÇ®±Ò£©ºÍÊÖÒÕ¹«Ë¾µÄ¿Í»§×é³ÉÖØ´óΣÏÕ¡£×Ô 2020 Äê 10 ÔÂÒÔÀ´£¬ÀàËÆÓÚ Zeus ¶ñÒâÈí¼þµÄ injectDll Ä£¿é±»ÆµÈÔʹÓ㬸ÃÄ£¿é½«¶ñÒâ´úÂë×¢Èë Web ä¯ÀÀÆ÷ÒÔÇÔÈ¡ÒøÐÐºÍÆ¾Ö¤Êý¾Ý¡£±ðµÄ£¬Trickbot ÓµÓжàÖÖ·´ÆÊÎöÊÖÒÕ£¬ÆäÖÐÐí¶àÔÚµÍˮƽÉ϶¼ºÜÊÇÖØ´ó¡£ÕâÖÖÔöÌíµÄ»ìÏýʹÆäÊܵ½Ï£ÍûÔڽϳ¤Ê±¼äÄÚÒþ²ØÆäÐÐΪµÄ¹¥»÷ÕߵĽӴý¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNiE

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨2¸öÓòÃûºÍ1¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

8. A2541×é֯ʹÓÃAsyncRAT¶ñÒâÈí¼þ¶Ôº½¿ÕÒµÌᳫ´¹ÂÚ¹¥»÷

¡¾±êÇ©¡¿AsyncRAT

¡¾Ê±¼ä¡¿2022-02-24

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±×·×Ù·¢Ã÷Ò»¸öÃûΪ TA2541 µÄ×éÖ¯´Ó 2017 Äê×îÏȵÄÍøÂç´¹ÂÚÔ˶¯¡£¸Ã×é֯ʹÓÃÕë¶Ôº½¿ÕÒµµÄÍøÂç´¹ÂÚ¹¥»÷µÄµç×ÓÓʼþÖÐÌáµ½ÁËȼÁÏ¡¢·É»úÁã¼þºÍÔËÊäµÈÖ÷Ìâ¡£ÕâÐ©ÍøÂç´¹ÂÚµç×ÓÓʼþ°üÀ¨Ö¸Ïò´æ´¢¶ñÒâ Visual Basic ÎļþµÄ google Çý¶¯Æ÷µÄÁ´½Ó¡£Ò»µ©Ö´ÐУ¬ÕâЩÎļþ¾Í»áÔËÐÐ×¢Èë RegScvs.exe µÄ powershell ÏÂÁ´Ó¶øÔÊÐí¹¥»÷Õß½ûÓà Windows ·´¶ñÒâÈí¼þɨÃè½Ó¿Ú (AMSI)¡£ÔÚ·ÀÓùÊܵ½ÍþвµÄÇéÐÎÏ£¬powershell ÏÂÁî»áÅþÁ¬µ½¹¥»÷ÕßµÄ C2 »ù´¡ÉèÊ©ÒÔ×°ÖÃÔ¶³Ì»á¼ûľÂí (RAT)¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNiD

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡15ÌõIOC£¬ÆäÖаüÀ¨11¸öÓòÃûºÍ4¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

9. ShuckwormÕë¶ÔÎÚ¿ËÀ¼Ìá³«ÍøÂçÌØ¹¤¹¥»÷

¡¾±êÇ©¡¿Shuckworm

¡¾Ê±¼ä¡¿2022-02-11

¡¾¼ò½é¡¿

Óë¶íÂÞ˹ÓÐ¹ØµÄ Shuckworm ×éÖ¯£¨ÓÖÃû Gamaredon£¬Armageddon£©ÕýÔÚ¼ÌÐø¶ÔÎÚ¿ËÀ¼µÄÄ¿µÄ¾ÙÐÐÍøÂçÌØ¹¤¹¥»÷£¬½üÆÚ£¬Çå¾²Ñо¿Ô±·¢Ã÷ÁËÐí¶àÕë¶Ô¸Ã¹úÐí¶à×éÖ¯µÄδËì¹¥»÷µÄÖ¤¾Ý¡£ÖÚËùÖÜÖª£¬¸Ã×é֯ʹÓÃÍøÂç´¹ÂÚµç×ÓÓʼþÏòÄ¿µÄ·Ö·¢Ãâ·Ñ¿ÉÓõÄÔ¶³Ì»á¼û¹¤¾ß£¬°üÀ¨Ô¶³ÌʹÓÃÆ÷ϵͳ (RMS) ºÍ UltraVNC£¬»òÃûΪ Pterodo/Pteranodon µÄ¶¨ÖƶñÒâÈí¼þ¡£ÎÚ¿ËÀ¼Çå¾²¾Ö (SSU)×î½üÐû²¼µÄÒ»·Ý±¨¸æÖ¸³ö£¬Shuckworm µÄ¹¥»÷×î½ü±äµÃÔ½À´Ô½Öش󣬹¥»÷ÕßÏÖÔÚʹÓ÷ÇÍâµØ¹¤¾ßÀ´ÇÔȡƾ֤²¢ÔÚÊܺ¦ÕßÍøÂçÉϺáÏòÒÆ¶¯¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNgA

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡Ìõ235ÌõIOC£¬ÆäÖаüÀ¨210¸öÑù±¾¡¢5¸öÓòÃûºÍ20¸öURL£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

10. ÒÁÀÊ APT MuddyWater ͨ¹ý¶ñÒâ PDF¡¢¿ÉÖ´ÐÐÎļþÕë¶ÔÍÁ¶úÆäÓû§

¡¾±êÇ©¡¿MuddyWater

¡¾Ê±¼ä¡¿2022-02-11

¡¾¼ò½é¡¿

MuddyWater½ÓÄɵĵ䷶ TTP ÊÇÔÚÆäѬȾÁ´Öдó×ÚʹÓþ籾£¬Ê¹Óà PowerShell ºÍ Visual Basic µÈÓïÑÔ£¬ÒÔ¼°ÆµÈÔʹÓÃÍâµØ¶þ½øÖÆÎļþ (LoLBins)£¬ÆµÈÔ¿ªÆôÖÖÖÖÔ˶¯¡£½üÆÚ£¬Çå¾²Ñо¿Ô±ÊӲ쵽 MuddyWater Õë¶ÔÍÁ¶úÆäÓû§¿ªÕ¹µÄÒ»ÏîÔ˶¯¡£¸ÃÔ˶¯°üÀ¨Ê¹ÓöñÒâ PDF ºÍ Microsoft Office Îĵµ (maldocs) ×÷Ϊ³õʼѬȾǰÑÔ¡£ÕâЩ¶ñÒâÎĵµ±»ÃüÃûΪαװ³ÉÍÁ¶úÆäÎÀÉúºÍÄÚÕþ²¿µÄÕýµ±Îļþ¡£¶ñÒâÈí¼þ»áÖ´ÐÐһϵÁа²ÅÅÔÚÊÜѬȾ¶ËµãÉϵľ籾£¬×÷ÎªÌØÊâ¸ºÔØµÄÏÂÔØÆ÷ºÍ¹¤¾ß¡£¸Ã¹¥»÷ÕßÔÚ´ËÔ˶¯ÖоÙÐеĹ¥»÷ÖÐʹÓÃÁ˱ê¼Ç»òÁîÅÆ¡£ÕâЩÁîÅÆÖ¼ÔÚÅú×¢¸Ã×éÖ¯µÄ¶ñÒ⹤¼þÒÑÀÖ³ÉѬȾĿµÄ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNgB

¡¾·À»¤²½·¥¡¿

AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡Ìõ56ÌõIOC£¬ÆäÖаüÀ¨14¸öURL¡¢11¸öIPºÍ31¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼