¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¾Íþвͨ¸æ¡¿¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021.12£©

2022-01-04

12Ô£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬Apache Log4j2 Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44228£©ºÍWindows Active Directory Óò·þÎñȨÏÞÌáÉýÎó²î£¨CVE-2021-42287,CVE-2021-42278£©Ó°Ïì¹æÄ£Ïà¶Ô½Ï´ó¡£Ç°ÕßÓÉÓÚApache Log4j2ijЩ¹¦Ð§±£´æµÝ¹éÆÊÎö¹¦Ð§£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÊâ½á¹¹µÄÊý¾ÝÇëÇó°ü£¬¿ÉÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂ룬CVSSÆÀ·Ö10.0¡£ºóÕßÓÉÓÚActive DirectoryûÓжÔÓòÖÐÅÌËãÆ÷Óë·þÎñÆ÷Õ˺ÅÃû¾ÙÐÐÑéÖ¤£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓøÃÎó²îÈÆ¹ýÇå¾²ÏÞÖÆ£¬¿É½«ÓòÖÐͨË×Óû§È¨ÏÞÌáÉýΪÓòÖÎÀíԱȨÏÞ²¢Ö´ÐÐí§Òâ´úÂ룬CVSSÆÀ·Ö8.8¡£

ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË67¸öÎó²î£¬°üÀ¨7¸öCritical¼¶±ðÎó²î£¬60¸öImportant ¼¶±ðÎó²î£¬ÆäÖаüÀ¨6¸ö0dayÎó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£

ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬Õë¶ÔÔÆÖ÷»úµÄ¹¥»÷ÊÂÎñÏà¶ÔƵÈÔ£¬ÆäÖаüÀ¨¹¥»÷ÕßʹÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷ÔÆÖ÷»ú£¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬Óй¥»÷ÕßÕýÔÚÆð¾¢Ê¹ÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22205£©¹¥»÷ÔÆÖ÷»ú£¬Í¬Ê±Ö²ÈëÐÂÐͺóÃÅľÂíGitlab-daemon£¬¸ÃºóÃÅľÂíµÄ¹¥»÷Ô˶¯Òѱ»ÌÚѶÇ徲ͨ¹ýCyber-HolmesÒýÇæÈ«³ÌÆÊÎöÕÆÎÕ¡£ÆÊÎö·¢Ã÷£¬¹¥»÷ÕßÒÑ¿ØÖÆÄ¿µÄϵͳƵÈÔ¸üкóÃųÌÐò£¬¹¥»÷ÕßÊ×ÏȽ«ºóÃÅαװΪ¿´ËÆËæ»úÃûµÄ.gzÎļþ£¬ÔÙʵÑéŲÓÃgunzip¾ÙÐнâѹºóÖ´ÐУ¬½è´ËαװÆä¶ñÒâÏÂÁîÖ´ÐвÙ×÷£»ÒÔ¼°¹¥»÷ÕßʹÓÃCERBERÀÕË÷Èí¼þͨ¹ýConfluence RCEµÈ¶à¸ö¸ßΣÎó²î¹¥»÷ÔÆÖ÷»ú£¬Ñо¿Ö°Ô±ÊӲ쵽´ó×ÚÓÐÓÃÔØºÉÊÔͼʹÓú£¿µÍþÊÓµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÀ´Ì½²â×°±¸×´Ì¬»ò´ÓÊܺ¦ÕßÄÇÀïÌáÈ¡Ãô¸ÐÊý¾Ý¡£ÌØÊâÊÇÒ»ÖÖÓÐÓÃÔØºÉÒýÆðÁËÑо¿Ö°Ô±µÄ×¢ÖØ¡£Ò»¸ö»ùÓÚ Mirai µÄ DDoS ½©Ê¬ÍøÂçÊÔͼɾ³ýÒ»¸öÌåÏÖ³öѬȾÐÐΪ²¢Ö´ÐÐ Moobot µÄÏÂÔØ³ÌÐò¡£¹¥»÷Õß¿ÉÒÔͨ¹ýº£¿µÍþÊÓÎó²î´«ËÍ´ËÓÐÓÃÔØºÉÌᳫÏÂÁî×¢Èë¹¥»÷ ¡£

ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/

Ò»¡¢ Îó²îÌ¬ÊÆ

2021Äê12Ô¾ÅÓÎÀÏ¸ç¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼426¸öÎó²î, ÆäÖиßΣÎó²î23¸ö£¬Î¢Èí¸ßΣÎó²î12¸ö¡£

 

* Êý¾ÝȪԴ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2022.01.04

×¢£º¾ÅÓÎÀÏ¸ç¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»

 

¶þ¡¢ ÍþвÊÂÎñ

1. Donot ×é֯ʹÓÃGoogleÔÆÅÌ·Ö·¢Ð¿î¶ñÒâ²å¼þÕë¶ÔWindowsÓëAndroid˫ƽ̨Ìᳫ¹¥»÷

¡¾±êÇ©¡¿Donot APT

¡¾Ê±¼ä¡¿2021-12-02

¡¾¼ò½é¡¿

¿ËÈÕ£¬Çå¾²Ñо¿Ôº·¢Ã÷Ò»ÆðDonot APT×éÖ¯½üÆÚ¹¥»÷Ô˶¯¡£Donot“¶ÇÄԳ攣¨APT-Q-38£©ÊÇÒÉËÆ¾ßÓÐÄÏÑÇÅä¾°µÄAPT×éÖ¯£¬ÆäÖ÷ÒªÒÔÖܱ߹ú¼ÒµÄÕþ¸®»ú¹¹ ΪĿµÄ¾ÙÐÐÍøÂç¹¥»÷Ô˶¯£¬Í¨³£ÒÔÇÔÈ¡Ãô¸ÐÐÅϢΪĿµÄ¡£¸Ã×éÖ¯¾ß±¸Õë¶ÔWindowsÓëAndroid˫ƽ̨µÄ¹¥»÷ÄÜÁ¦¡£Æ¾Ö¤Ñо¿Ö°Ô±¸ú×ÙÆÊÎö£¬Donot´Ë´ÎµÄ¹¥»÷Ô˶¯ÓÐÈçÏÂÌØµã£ºRTFÎĵµÖÐǶÈëPackage¹¤¾ß£¬·­¿ªºó×Ô¶¯ÊÍ·ÅÎļþµ½%temp%Ŀ¼¡¢C2²»ÔÙÓ²±àÂëµ½ÎļþÖУ¬¶øÊÇÓɵÚÈý·½ÍøÕ¾ÍйÜ£»´Ë´Î²¶»ñ¶à¸ö×é¼þ£¬Ïà±ÈÒÔǰ¹¦Ð§½ÏΪÍêÉÆ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN6A

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡11ÌõIOC£¬ÆäÖаüÀ¨11¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

2. ¹¥»÷ÕßʹÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷ÔÆÖ÷»ú

¡¾±êÇ©¡¿Gitlab-daemon

¡¾Ê±¼ä¡¿2021-12-02

¡¾¼ò½é¡¿

Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬Óй¥»÷ÕßÕýÔÚÆð¾¢Ê¹ÓÃGitLabÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-22205£©¹¥»÷ÔÆÖ÷»ú£¬Í¬Ê±Ö²ÈëÐÂÐͺóÃÅľÂíGitlab-daemon£¬¸ÃºóÃÅľÂíµÄ¹¥»÷Ô˶¯Òѱ»ÌÚѶÇ徲ͨ¹ýCyber-HolmesÒýÇæÈ«³ÌÆÊÎöÕÆÎÕ¡£ÆÊÎö·¢Ã÷£¬¹¥»÷ÕßÒÑ¿ØÖÆÄ¿µÄϵͳƵÈÔ¸üкóÃųÌÐò£¬¹¥»÷ÕßÊ×ÏȽ«ºóÃÅαװΪ¿´ËÆËæ»úÃûµÄ.gzÎļþ£¬ÔÙʵÑéŲÓÃgunzip¾ÙÐнâѹºóÖ´ÐУ¬½è´ËαװÆä¶ñÒâÏÂÁîÖ´ÐвÙ×÷¡£ºóÃÅÖ´Ðкó½«×ÔÉíÖ²Èë*/gitlab/git-dataĿ¼Ï£¬ÓÃGitlab-daemonÎļþÃûαװ£¬ÒÔÓÕÆ­ÔËάְԱ¡£È»ºóдÈëÍýÏëʹÃüÆô¶¯Ï´ËʱºóÃŲ¢²»Ö±½ÓÅþÁ¬C2£¬¶øÊÇÏÈÐÐÍ˳ö£¬ÆÚ´ýÍýÏëʹÃüÏÂÒ»´Î½«ÆäÀ­Æðʱ£¬ÔÙÖ´Ðиü½øÒ»²½µÄ¶ñÒ⹦Ч´úÂë¡£¶à´¦Ï¸½ÚÅú×¢¹¥»÷ÕßÏ£Íû½«×ÔÉíαװΪgitlabϵͳÎļþ£¬ÒÔʵÏÖ¶ÔÄ¿µÄϵͳµÄºã¾Ã¿ØÖÆ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN6z

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡7ÌõIOC£¬ÆäÖаüÀ¨1¸öIP£¬1¸öÓòÃûºÍ5¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

3. ¹¥»÷ÕßʹÓÃJavaScript ¶ñÒâÈí¼þѬȾwindows PC

¡¾±êÇ©¡¿RAT

¡¾Ê±¼ä¡¿2021-12-02

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±·¢Ã÷Ò»ÖÖеÄÒþ²ØJavaScript¼ÓÔØ³ÌÐòRATDispenserÒѱ»Ö¤Êµ¿ÉÓÃÓÚͨ¹ýÍøÂç´¹ÂÚ¹¥»÷ѬȾ¾ßÓÐÖÖÖÖÔ¶³Ì»á¼ûľÂí(RAT) µÄ×°±¸¡£Õâ¸öеļÓÔØÆ÷ÒѾ­ÓëÖÁÉٰ˸öÖ¼ÔÚÇÔÊØÐÅÏ¢²¢ÔÊÐí¹¥»÷Õß¿ØÖÆÄ¿µÄ×°±¸µÄ¶ñÒâÈí¼þ¼Ò×åѸËÙ½¨ÉèÁ˰²ÅÅÏàÖúͬ°é¹ØÏµ¡£Ñ¬È¾×îÏÈÓÚÍøÂç´¹ÂÚµç×ÓÓʼþ£¬ÆäÖаüÀ¨´øÓÐË«À©Õ¹Ãû“.TXT.js”µÄ¶ñÒâJavaScriptÎļþ¡£Windows ĬÈÏÒþ²ØÀ©Õ¹Ãû£¬Òò´ËÈôÊÇÊÕ¼þÈ˽«ÎļþÉúÑÄÔÚËûÃǵÄÅÌËã»úÉÏ£¬Ëü½«ÏÔʾΪÎÞº¦µÄÎı¾Îļþ¡£Õâ¸öÎı¾Îļþ¿ÉÒÔ±»ÑÏÖØ»ìÏýÒÔÈÆ¹ýÇå¾²Èí¼þµÄ¼ì²â£¬µ±ÄãË«»÷ÎļþÔËÐÐËüʱ£¬Ëü»á±»½âÂë¡£µ±¼ÓÔØÆ÷ÔËÐÐVBScriptÎļþ%TEMP%дÈëÎļþ¼ÐÖÐʱ£¬ÔËÐиÃÎļþ£¬¶ñÒâ´úÂë(RAT)ÏÂÔØÓÐÓøºÔØ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN6B

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡1ÌõIOC£¬ÆäÖаüÀ¨1ÌõURL£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

4. APT ¹¥»÷ÕßʹÓà ManageEngine ADSelfService Plus Èí¼þÖеÄÐÂÎó²îÌᳫ¹¥»÷

¡¾±êÇ©¡¿APT

¡¾Ê±¼ä¡¿2021-12-09

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±ÌåÏÖÔÚÈý¸öÔµÄʱ¼äÀһ¸ö¼á¶¨µÄ APT ¹¥»÷ÕßÌᳫÁ˶à´ÎÔ˶¯£¬µ¼ÖÂÖÁÉÙ 13 ¸ö×éÖ¯Êܵ½Ë𺦡£Ò»Ð©ÊÜÓ°ÏìµÄ×é֝ɿ¼°ÃÀ¹úµÄÒªº¦»ù´¡ÉèÊ©²¿·Ö£¬°üÀ¨¹ú·À¡¢½»Í¨¡¢Ò½ÁƱ£½¡ºÍÄÜÔ´¡£¸Ã¹¥»÷ÕߵĵÚÒ»¸öÔ˶¯Ê¹ÓÃÁË Zoho ManageEngine ADSelfService Plus Èí¼þÖеÄÁãÈÕÎó²î¡£10 ÔÂÏÂÑ®£¬¸Ã¹¥»÷ÕßÌᳫÁË×î½üµÄÔ˶¯£¬½«Öصã×ªÒÆµ½ Zoho ManageEngine ServiceDesk Plus Èí¼þÖÐÏÈǰδ¹ûÕæµÄÎó²î ( CVE-2021-44077 )¡£ÔÚʹÓôËÎó²îºó£¬¹¥»÷ÕßÉÏ´«ÁËÒ»¸öÐ嵀 dropper£¬ËüÔÚÊܺ¦ÍøÂçÉϰ²ÅÅÁË Godzilla webshel??l£¬Äܹ»Èƹý ADSelfService ºÍ ServiceDesk Plus ²úÆ·ÉϵÄÇå¾²¹ýÂËÆ÷¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN7L

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

5. ScarCruft ×é֯ʹÓÃChinotto¶ñÒâÈí¼þ¹¥»÷³¯ÏÊDZÌÓÕߺÍÈËȨÔ˶¯¼Ò

¡¾±êÇ©¡¿Chinotto

¡¾Ê±¼ä¡¿2021-12-09

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±·¢Ã÷ScarCruftÐÂÒ»²¨Õë¶ÔÐÔÇ¿µÄ¼àÊÓ¹¥»÷Õë¶Ô³¯ÏÊDZÌÓÕß¡¢±¨µÀ³¯ÏÊÏà¹ØÐÂÎŵļÇÕßÒÔ¼°Ó볯ÏÊÓйصÄÕþ¸®×éÖ¯¼°³¯Ïʰ뵺µÈ¡£¸Ã¹¥»÷ÕßʹÓÃÁËÈýÖÖ¾ßÓÐÏàËÆ¹¦Ð§µÄChinotto ¶ñÒâÈí¼þ£ºÔÚ PowerShell ÖÐʵÏֵİ汾¡¢Windows ¿ÉÖ´ÐÐÎļþºÍ Android Ó¦ÓóÌÐò¡£Ö»¹ÜÕë¶Ô²î±ðµÄƽ̨£¬µ«ËüÃǹ²Ïí»ùÓÚ HTTP ͨѶµÄÀàËÆÏÂÁîºÍ¿ØÖƼƻ®¡£Òò´Ë£¬¶ñÒâÈí¼þ²Ù×÷Õß¿ÉÒÔͨ¹ýÒ»×éÏÂÁîºÍ¿ØÖƽÅÔ­À´¿ØÖÆÕû¸ö¶ñÒâÈí¼þ¼Ò×å¡£ÔÚÖ÷»úÊÓ²ìÖÐÑо¿Ö°Ô±ÌåÏÖÁËÒ»¸ö¶ñÒâµÄ Windows ¿ÉÖ´ÐÐÎļþ£¬¸ÃÎļþ°üÀ¨¹¹½¨Â·¾¶¡£¶øChinotto ¶ñÒâÈí¼þµÄ Android Ó¦ÓóÌÐò°æ±¾£¨MD5 56f3d2bcf67cf9f7b7d16ce8a5f8140a£©¡£Õâ¸ö¶ñÒâ APK ƾ֤ AndroidManifest.xml ÎļþÇëÇó¹ý¶àµÄȨÏÞ£¬ÎªÁ˵ִï¼àÊÓÓû§µÄÄ¿µÄ£¬ÕâЩӦÓóÌÐòÒªÇóÓû§ÆôÓÃÖÖÖÖȨÏÞ¡£ÊÚÓèÕâЩȨÏÞÔÊÐíÓ¦ÓóÌÐòÍøÂçÃô¸ÐÐÅÏ¢£¬°üÀ¨ÁªÏµÈË¡¢ÐÂÎÅ¡¢Í¨»°¼Í¼¡¢×°±¸ÐÅÏ¢ºÍ¼Òô¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN7M

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡18ÌõIOC£¬ÆäÖаüÀ¨18¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

6. ¹¥»÷ÕßʹÓÃEwDoor½©Ê¬ÍøÂçÕë¶ÔAT¿Í»§ÌᳫDDoS ¹¥»÷

¡¾±êÇ©¡¿EwDoor

¡¾Ê±¼ä¡¿2021-12-09

¡¾¼ò½é¡¿

Çå¾²Ñо¿ÊµÑéÊÒµÄר¼Ò·¢Ã÷ÁËÒ»ÖÖÃûΪEwDoorµÄн©Ê¬ÍøÂ磬 ËüÕë¶ÔʹÓùûÕæÌ»Â¶ÓÚ Internet µÄ EdgeMarc ÆóÒµ»á»°½çÏß¿ØÖÆÆ÷ (ESBC) ±ßÑØ×°±¸µÄ AT ¿Í»§¡£×¨¼Ò×¢ÖØµ½ EwDoor¶ÔÆäC2ʹÓÃÁ˱¸·Ý»úÖÆ£¬²¢×¢²áÁËÒ»¸ö±¸·ÝÏÂÁîºÍ¿ØÖÆ(C2)Óò (iunno.se)À´ÆÊÎöÊÜѬȾװ±¸µÄÅþÁ¬¡£²¢ÇÒ½©Ê¬ÍøÂçʵÑéÁËһϵÁб£»¤²½·¥ÒÔ±ÜÃâÇ徲ר¼ÒµÄÆÊÎö£¬ÀýÈçʹÓÃTLSЭÒé±ÜÃâͨѶ±»×èµ²£¬¼ÓÃÜÃô¸Ð×ÊԴʹÆäÄÑÒÔÄæÏò¹¤³ÌÒÔ¼°½«C2ÒÆÖÁÔÆ¶Ë²¢ÓÉBT¸ú×ÙÆ÷·¢ËͱÜÃâ±»IOCϵͳֱ½ÓÌáÈ¡¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN7N

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡29ÌõIOC£¬ÆäÖаüÀ¨2¸öIP£¬11¸öÓòÃûºÍ16¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

7. ¹¥»÷ÕßʹÓûùÓÚMiraiµÄ½©Ê¬ÍøÂçMoobot¹¥»÷º£¿µÍþÊÓ

¡¾±êÇ©¡¿Moobot

¡¾Ê±¼ä¡¿2021-12-16

¡¾¼ò½é¡¿

Ñо¿Ö°Ô±ÊӲ쵽´ó×ÚÓÐÓÃÔØºÉÊÔͼʹÓú£¿µÍþÊÓµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÀ´Ì½²â×°±¸×´Ì¬»ò´ÓÊܺ¦ÕßÄÇÀïÌáÈ¡Ãô¸ÐÊý¾Ý¡£ÌØÊâÊÇÒ»ÖÖÓÐÓÃÔØºÉÒýÆðÁËÑо¿Ö°Ô±µÄ×¢ÖØ¡£Ò»¸ö»ùÓÚ Mirai µÄ DDoS ½©Ê¬ÍøÂçÊÔͼɾ³ýÒ»¸öÌåÏÖ³öѬȾÐÐΪ²¢Ö´ÐÐ Moobot µÄÏÂÔØ³ÌÐò¡£¹¥»÷Õß¿ÉÒÔͨ¹ýº£¿µÍþÊÓÎó²î´«ËÍ´ËÓÐÓÃÔØºÉÌᳫÏÂÁî×¢Èë¹¥»÷ ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN9q

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

8. ¹¥»÷ÕßʹÓÃCERBERÀÕË÷Èí¼þͨ¹ýConfluence RCEµÈ¶à¸ö¸ßΣÎó²î¹¥»÷ÔÆÖ÷»ú

¡¾±êÇ©¡¿CERBERÀÕË÷Èí¼þ

¡¾Ê±¼ä¡¿2021-12-16

¡¾¼ò½é¡¿

Ç徲ר¼Ò·¢Ã÷CERBERÀÕË÷Èí¼þÈö²¥ÕßʹÓÃAtlassian ConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26084£©ºÍGitLab exiftool Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2021-22205)¹¥»÷ÔÆÉÏÖ÷»ú¡£Ç°Õߣ¬ÊÇÒ»¸ö¹¤¾ßͼµ¼º½ÓïÑÔ (ONGL) ×¢ÈëÎó²î£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ Confluence Server »òData CenterʵÀýÉÏÖ´ÐÐí§Òâ´úÂ룬¹¥»÷ÕßʹÓÃÎó²î¿ÉÍêÈ«¿ØÖÆ·þÎñÆ÷¡£ºóÕßÓÉÓÚGitlabijЩ¶Ëµã·¾¶ÎÞÐèÊÚȨ£¬¹¥»÷Õß¿ÉÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏÂʹÓÃͼƬÉÏ´«¹¦Ð§Ö´ÐÐí§Òâ´úÂ룬¹¥»÷ÕßʹÓÃÎó²îͬÑù¿ÉÒÔÍêÈ«¿ØÖÆ·þÎñÆ÷¡£±»ÀÕË÷Èí¼þ¼ÓÃÜÆÆËðµÄÎļþÎÞÃÜÔ¿Ôݲ»¿É½âÃÜ£¬Ç徲ר¼Ò½¨ÒéËùÓÐÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´Îó²î£¬×èÖ¹Ôì³ÉÊý¾ÝÍêÈ«Ëðʧ£¬ÓªÒµ³¹µ×Í߽⡣

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN9o

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ3¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

9. ¹¥»÷ÕßÔÚ»ùÓÚDark MiraiµÄMANGAÔ˶¯ÖÐʹÓöñÒâÈí¼þ¹¥»÷TP-LinkÎÞÏß·ÓÉÆ÷

¡¾±êÇ©¡¿¶ñÒâÈí¼þ

¡¾Ê±¼ä¡¿2021-12-16

¡¾¼ò½é¡¿

Ç徲ʵÑéÊÒÍŶӷ¢Ã÷ÁËÒ»¸ö¶ñÒâÈí¼þÑù±¾£¬ÊÇ MANGA Ô˶¯£¨Ò²³ÆÎª Dark£©µÄ¸üбäÌ壬Ëüƾ֤ Mirai ÒÑÐû²¼µÄÔ´´úÂëÕýÔÚÒ°Íâ·Ö·¢Ñù±¾£¬Ä¿µÄÊÇ TP-link ÎÞÏß·ÓÉÆ÷¡£ËüʹÓÃ×î½üÁ½ÖÜǰÐû²¼µÄ¾­ÓÉÉí·ÝÑéÖ¤µÄ RCE Îó²îÅû¶ʱ¼äÓëÓ¦Óò¹¶¡À´ÆÆËðÎïÁªÍø×°±¸Ö®¼äµÄ²î±ð¡£Ñо¿Ö°Ô±ÌåÏÖÓë Mirai µÄÕý³£Ñ¬È¾³ÌÐòÒ»Ñù£¬Ö´ÐÐµÄ shell ¾ç±¾ÏÂÔØ²î±ð¼Ü¹¹Ç徲̨µÄÖ÷ÒªÓÐÓÃÔØºÉ¶þ½øÖÆÎļþ£¬²¢ÔÚÊܺ¦ÕßϵͳÖÐäĿִÐС£±ðµÄ£¬Ëü»¹Í¨¹ý×èÖ¹Óë³£¼ûÄ¿µÄ¶Ë¿ÚµÄÅþÁ¬À´±ÜÃâÆäËû½©Ê¬ÍøÂç½ÓÊÜ×°±¸¡£È»ºó£¬¶ñÒâÈí¼þÆÚ´ýÀ´×ÔÆäÏÂÁîºÍ¿ØÖÆ (C2) ·þÎñÆ÷µÄÏÂÁîÀ´Ö´Ðоܾø·þÎñ (DOS) ¹¥»÷µÄ²î±ð±äÌå¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlN9r

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡23ÌõIOC£¬ÆäÖаüÀ¨23¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

10. ¹¥»÷ÕßʹÓÃLog4j Îó²îÕë¶Ô Linux ϵͳÌᳫ¹¥»÷

¡¾±êÇ©¡¿Log4j Îó²î

¡¾Ê±¼ä¡¿2021-12-23

¡¾¼ò½é¡¿

Çå¾²Ñо¿Ôº²¶»ñÁË 2 ²¨Ê¹Óà Log4j Îó²îÐγɽ©Ê¬ÍøÂçµÄ¹¥»÷£¬²¢ÇÒ¿ìËÙÑùÌìÖ°ÎöÅú×¢ËüÃÇ»®·ÖÓÃÓÚÐÎ³É Muhstik ºÍ Mirai ½©Ê¬ÍøÂ磬¾ùÕë¶Ô Linux ×°±¸¡£²¢ÌåÏÖÐ嵀 Muhstik ±äÌåÌí¼ÓÁËÒ»¸öºóÃÅÄ£¿é ldm£¬ËüÄܹ»Ê¹ÓÃ×°ÖõĺóÃŹ«Ô¿Ìí¼Ó SSH ºóÃŹ«Ô¿¡£½«¹«Ô¿Ìí¼Óµ½~/.ssh/authorized_keys Îļþºó£¬¹¥»÷ÕßÎÞÐèÃÜÂëÑéÖ¤¼´¿ÉÖ±½ÓµÇ¼Զ³Ì·þÎñÆ÷¡£Ë¼Á¿µ½ log4j2 µÄÌØÊâÎó²î»úÖÆ£¬Muhstik ½ÓÄÉÁËÒ»ÖÖÉúÓ²µÄ·½·¨£¬ÔÚÖªµÀ»áÓÐÎó²î»úеµÄÇéÐÎÏÂÂþÎÞÄ¿µÄµØÈö²¥payload£¬²¢ÇÒΪÁËÖªµÀË­ÒѾ­±»Ñ¬È¾£¬Muhstik ½ÓÄÉ TOR ÍøÂç×÷ΪÆä±¨¸æ»úÖÆ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://ti.nsfocus.com/security-news/IlNam

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öÓòÃû£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼