¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190304

Ðû²¼Ê±¼ä 2019-03-04
1¡¢APT×éÖ¯Bronze Unionй¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬£¬Ö÷Òª·Ö·¢ZxShellµÈľÂí

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


´÷¶ûCTUÑо¿Ö°Ô±·¢Ã÷APT×éÖ¯Bronze Union£¨ÓÖ³ÆAPT27£©ÔÚ2018ÄêµÄй¥»÷»î¶¯Öа²ÅÅÁËеĶñÒâÈí¼þ£¬£¬ £¬£¬£¬£¬£¬°üÀ¨ZxShell¡¢Gh0st RATºÍSysUpdate¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÍøÂç´¹ÂÚ¡¢Îó²îɨÃèÒÔ¼°Ë®¿Ó¹¥»÷µÈÊÖÒÕ£¬£¬ £¬£¬£¬£¬£¬Ãé×¼ÍÁ¶úÆä¼°ÃɹŵÄÖ÷Òª×éÖ¯¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÕâЩ¶ñÒâÈí¼þµÄˢбäÖÖ£¬£¬ £¬£¬£¬£¬£¬Ê¹µÃÆä¶ñÒâ»î¶¯Ô½·¢ÄÑÒÔ±»¼ì²âµ½¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/apt-group-bronze-union-comes-up-with-upated-rat-malware-dd4ccb28

2¡¢Ð·¸·¨ÍÅ»ïPacha Group£¬£¬ £¬£¬£¬£¬£¬Ö÷Òª¹¥»÷LinuxЧÀÍÆ÷¾ÙÐÐÍÚ¿ó

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


IntezerÇå¾²Ñо¿Ö°Ô±·¢Ã÷Ò»¸öÐµķ¸·¨ÍÅ»ïPacha Group£¬£¬ £¬£¬£¬£¬£¬¸ÃÍÅ»ïÖ÷Òª¹¥»÷LinuxЧÀÍÆ÷¾ÙÐÐÍڿ󡣡£¡£¡£¡£¹¥»÷ÕßÖ÷Ҫͨ¹ý±©Á¦¹¥»÷ÈëÇÖÀàËÆWordPress»òPhpMyAdminµÈЧÀÍ£¬£¬ £¬£¬£¬£¬£¬²¢×îÖÕ°²ÅŶñÒâÈí¼þLinux.GreedyAntd¡£¡£¡£¡£¡£Antd´úÂëÖØ´ó£¬£¬ £¬£¬£¬£¬£¬»ùÓÚÄ £¿£¿£¿£¿£¿£¿é»¯Éè¼Æ²¢¿ÉÔÚ¶àC&CЧÀÍÆ÷ÏÂÊÂÇé¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³ÆAntdÓë¸ÃÍÅ»ïµÄÁíÒ»¸ö¶ñÒâÈí¼þLinux.HelloBotµÄ´úÂë¾ßÓÐÖØµþÖ®´¦¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/linux-servers-targeted-by-new-chinese-crypto-mining-group/

3¡¢Ð´¹ÂÚ¹¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬£¬Ö÷ҪʹÓÃXLMºê·Ö·¢FlawedAmmyyľÂí

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

2019Äê2ÔÂSI-LAB²¶»ñÁ˶à¸ö´øÓжñÒâExcel 4.0ºê£¨Ò²³ÆXLMºê£©µÄExcel´¹ÂÚÑù±¾£¬£¬ £¬£¬£¬£¬£¬ÕâЩÑù±¾ÓÃÓÚÏÂÔØºÍÖ´ÐÐFlawedAmmyy RAT¡£¡£¡£¡£¡£¸Ã´¹ÂÚ¹¥»÷±³ºóµÄ¹¥»÷ÕßÊÇ·¸·¨ÍÅ»ïTA505£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßµÄC&CЧÀÍÆ÷£¨195.123.209.169£©Î»ÓÚÀ­ÍÑάÑÇ£¬£¬ £¬£¬£¬£¬£¬Ä¿½ñ´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£Æä·Ö·¢µÄFlawedAmmyy RAT¿ÉÇÔȡĿµÄµÄÎļþ¡¢Æ¾Ö¤¡¢ÆÁÄ»½ØÍ¼ÒÔ¼°»á¼ûÉãÏñÍ·ºÍÂó¿Ë·çµÈ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/81857/malware/flawedammyy-undetected-xlm-macros.html

4¡¢Ñо¿Åú×¢Operation Sharpshooter¾ßÓиü¸ßµÄÖØÆ¯ºóºÍ¸ü¹ãµÄ¹æÄ£

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

McAfeeÑо¿Ö°Ô±ÔÚÒ»·Ýб¨¸æÖÐÖ¸³ö£¬£¬ £¬£¬£¬£¬£¬Operation SharpshooterµÄ¹¥»÷»î¶¯ÔÚÖØ´óÐÔ¡¢¹æÄ£ºÍ¹ã¶ÈÉϱÈ֮ǰÒÔΪµÄÒªÔ½·¢ÆÕ±é¡£¡£¡£¡£¡£SharpshooterÓÚ2018Äê12ÔÂÊ״α»Åû¶£¬£¬ £¬£¬£¬£¬£¬ÆäÖ÷ÒªÕë¶ÔÈ«ÇòµÄ¹ú·ÀºÍÒªº¦»ù´¡ÉèÊ©£¬£¬ £¬£¬£¬£¬£¬°üÀ¨ºËÄÜ¡¢¹ú·À¡¢ÄÜÔ´ºÍ½ðÈÚÆóÒµ¡£¡£¡£¡£¡£ÐÂÑо¿Åú×¢£¬£¬ £¬£¬£¬£¬£¬Sharpshooter×îÔçÓÚ2017Äê9ÔÂ×îÏȻ£¬£¬ £¬£¬£¬£¬£¬Õë¶Ô¸ü¶àµÄ¹ú¼ÒºÍÐÐÒµ£¬£¬ £¬£¬£¬£¬£¬¸Ã»î¶¯ÏÖÔÚ»¹ÔÚ¾ÙÐÐÖ®ÖС£¡£¡£¡£¡£Êܵ½¹¥»÷×î¶àµÄÄ¿µÄÊǵ¹ú¡¢ÍÁ¶úÆä¡¢Ó¢¹úºÍÃÀ¹ú¡£¡£¡£¡£¡£¸Ã±¨¸æ»¹Ö¸³öSharpshooterÓëAPT×éÖ¯LazarusµÄ¹¥»÷¾ßÓжà¸öÏàËÆÌØÕ÷¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/sharpshooter-complexity-scope/142359/

5¡¢ÀÕË÷Èí¼þGarrantyDecryptбäÖÖ£¬£¬ £¬£¬£¬£¬£¬Î±×°³ÉÇå¾²ÍŶӾÙÐÐÓÕÆ­

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

2Ô·ÝÑо¿Ö°Ô±Michael Gillespie·¢Ã÷ÀÕË÷Èí¼þGarrantyDecryptµÄÒ»¸öбäÖÖ£¬£¬ £¬£¬£¬£¬£¬¸Ã±äÖÖ½ÓÄÉÁËÒ»ÖÖеÄÕ½ÂÔ¾ÙÐÐÓÕÆ­£ºÔÚÃûΪSECURITY-ISSUE-INFO.txtµÄÀÕË÷Ʊ¾ÝÖУ¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÉù³ÆÄ¿µÄÓû§Ôâµ½¡°ÍⲿְԱ¡±µÄ¹¥»÷£¬£¬ £¬£¬£¬£¬£¬¶øProtonÇå¾²ÍŶӵÄSECURE-SERVERЧÀͶÔÓû§µÄÊý¾Ý¾ÙÐÐÁ˱£»£»£»£»¤ÐԵļÓÃÜ¡£¡£¡£¡£¡£¹¥»÷ÕßÉõÖÁ½«PROTONµÄ°æÈ¨ÉùÃ÷°²ÅÅÔÚÎļþµ×²¿£¬£¬ £¬£¬£¬£¬£¬ÒÔÔöÌíÆäÕýµ±ÐÔ¡£¡£¡£¡£¡£¹¥»÷Õß³ÆProtonµÄSECURE-SERVERЧÀÍÐèÒªÊÕÈ¡780ÃÀÔªµÄÓöȲŻª½âÃÜÎļþ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-pretends-to-be-proton-security-team-securing-data-from-hackers/

6¡¢Ñо¿Ö°Ô±Åû¶Windows IoT Core×°±¸ÖеÄÎó²î£¬£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂȨÏÞ±»Ð®ÖÆ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


SafeBreachÇå¾²Ñо¿Ö°Ô±Dor AzouriÅû¶ÁËÒ»¸öÓ°ÏìWindows IoT CoreϵͳµÄÐÂÎó²î£¬£¬ £¬£¬£¬£¬£¬¸ÃÎó²î±£´æÓÚͨѶЭÒéSirep/WPConÖУ¬£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂ×°±¸µÄ»á¼ûȨÏÞ±»Ð®ÖÆ£¬£¬ £¬£¬£¬£¬£¬²¢Ê¹µÃ¹¥»÷Õß¿ÉÒÔÍêÈ«¿ØÖƸÃ×°±¸¡£¡£¡£¡£¡£AzouriÌåÏÖ¸ÃÎó²î½öÓ°ÏìCore°æ±¾µÄϵͳ£¬£¬ £¬£¬£¬£¬£¬¶ø²»Ó°ÏìEnterprise°æ¡£¡£¡£¡£¡£Azouri»¹¹¹½¨ÁËÒ»¸öÓÃÓÚ²âÊÔ¸ÃÎó²îµÄ¹¤¾ßSirepRAT£¬£¬ £¬£¬£¬£¬£¬¸Ã¹¤¾ß½«ÔÚGitHubÉϾÙÐпªÔ´¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-exploit-lets-attackers-take-control-of-windows-iot-core-devices/

ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí