ʱ¼ä£º2021-11-19
SideCopy×éÖ¯½üÆÚʹÓÃÖÐÓ¡Ê±ÊÆÐÂÎŵĹ¥»÷ÊÂÎñÆÊÎö
ÒÉËÆSideCopy×éÖ¯Õë¶ÔÓ¡¶ÈͶ·Å˫ƽ̨RAT
Kimsukyͨ¹ýBlogspotÕë¶Ôº«¹ú×ÅÃûÄ¿µÄÈö²¥¶ñÒâÈí¼þ
Lazarus×é֯ʹÓôøºóÃÅIDAÈí¼þ¹¥»÷Çå¾²Ñо¿Ö°Ô±
MosesStaff×éÖ¯Õë¶ÔÒÔÉ«Áй¥»÷Ô˶¯ÆÊÎö
SideCopyαÔìAndroidÓ¦ÓÃÊÐËÁµÄ¹¥»÷
FIN7±ê¼ÇÐÔʹÓù¤¾ßÖØÐ·ºÆð
Ïã¸ÛÍøÕ¾ÔâË®¿Ó¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔmacOS×°±¸
¹¥»÷ÕßʹÓÃParkingÓòÃûºÍGoogleµÄ×Ô½çËµÒ³ÃæÀ´Èö²¥¶ñÒâÈí¼þ
¶à½×¶ÎPowerShell¹¥»÷Õë¶Ô¹þÈø¿Ë˹̹
¹¥»÷ÕßʹÓÃÓòǰÖÃÊÖÒÕ¶ÔÃåµéÌᳫ¹¥»÷
ÐÂGolang¶ñÒâÈí¼þBotenaGo£¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ô·ÓÉÆ÷
жñÒâÈí¼þCovid22ÏÖÉí£¬£¬£¬£¬£¬£¬£¬£¬ÆÆËðÊܺ¦ÕßϵͳMBR
¹¥»÷ÕßÃé×¼°¢Àï°Í°ÍECS£¬£¬£¬£¬£¬£¬£¬£¬Èö²¥ÍÚ¿óÄ£¿£¿£¿£¿£¿£¿£¿£¿é
¶ñÒâÈí¼þEmotet»Ø¹é£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýTrickBotÖØÐÞ½©Ê¬ÍøÂç
GoogleÐû²¼11Ô¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ChromeÖеĶà¸öÎó²î
VMwarevCenterServerȨÏÞÌáÉýÎó²îͨ¸æ
01
SideCopy×éÖ¯½üÆÚʹÓÃÖÐÓ¡Ê±ÊÆÐÂÎŵĹ¥»÷ÊÂÎñÆÊÎö
Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/iZuB1IAtNm5DxrrUIJqyoA
Ïà¹ØÐÅÏ¢£º
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐIJ¶»ñµ½Ò»ÅúSideCopyÒÔÓ¡¶È¾üÊÂÏà¹Ø»°ÌâΪÓÕ¶üµÄ¹¥»÷Ñù±¾¡£¡£¡£¡£¡£¡£¡£¡£Ôڴ˹¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ÷ÒªÒÔÓ¡¶ÈµØÇø¿Ö²À·Ö×ÓÓëÊ¿±øÖ®¼äµÄ³åͻʹʱ¨¸æÎªÖ÷Ì⣬£¬£¬£¬£¬£¬£¬£¬½«ÏÂÔØÆ÷αװΪͨË×ͼƬÎļþÒýÓÕÄ¿µÄÓû§µã»÷ÔËÐС£¡£¡£¡£¡£¡£¡£¡£µ±Êܺ¦Õß½âѹ²¢Ö´ÐÐÓÕ¶üÎļþÖ®ºó£¬£¬£¬£¬£¬£¬£¬£¬³ÌÐò½«»á´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØÊý¾ÝÎļþµ½ÍâµØ¡£¡£¡£¡£¡£¡£¡£¡£´Ë³ÌÐòÊÇÒ»¸öÏÂÔØÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý°×Ãûµ¥µÄ¶ÌÁ´½Ó½«ÕæÊµURL¾ÙÐÐÒþ²Ø£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ´ËÀ´¹æ±ÜɱÈíµÄ¾²Ì¬²éɱ¡£¡£¡£¡£¡£¡£¡£¡£Í¨¹ý¶Ô¶ÌÁ´½ÓËùÖ¸ÏòµÄÊý¾Ý¾ÙÐÐÏÂÔØÒԺ󣬣¬£¬£¬£¬£¬£¬£¬Ê¹ÓýâÃÜËã·¨¾ÙÐнâÃÜ£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕ¼ÓÔØSideCopy×ÔÓÐÔ¶¿ØÈí¼þMargulasRAT¡£¡£¡£¡£¡£¡£¡£¡£
02
ÒÉËÆSideCopy×éÖ¯Õë¶ÔÓ¡¶ÈͶ·Å˫ƽ̨RAT
Åû¶ʱ¼ä£º2021Äê11ÔÂ15ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/BSfKTlMlOnNlsWKjV1NM8w
Ïà¹ØÐÅÏ¢£º
¿ËÈÕÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐĺìÓêµÎÍŶӲ¶»ñµ½Ò»ÀýÒÔÓ¡¶È×ÜÀíĪµÏ·ÃÃÀÏà¹Ø»°ÌâΪÓÕ¶üµÄLinuxƽ̨¹¥»÷Ñù±¾¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÑù±¾ÊÇÒÔĪµÏ·ÃÃÀ»°ÌâÃüÃûµÄtar.gzѹËõ°ü£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öLinux×ÀÃæÆô¶¯Îļþ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþÔÚÖ´ÐÐÖ®ºó»áÏÂÔØ²¢²¥·ÅÓÕ¶üÊÓÆµÒÔÒÉ»óÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±»áÏÂÔØÒ»¸öÓÃÓÚ¼ÓÔØRATµÄ¾ç±¾²¢Ö´ÐС£¡£¡£¡£¡£¡£¡£¡£
RATÊÇÒ»¿î»ùÓÚPythonµÄºá¿çWindowsºÍLinux˫ƽ̨µÄÔ¶¿Ø¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£ÁíÍâͨ¹ýC2ЧÀÍÆ÷µÄIP¾ÙÐйØÁª£¬£¬£¬£¬£¬£¬£¬£¬¸ÃIPÔøÆÊÎöµ½SideCopy×éÖ¯¿ØÖƵÄÓòÃûÉÏ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¸ÃÍÅ»ïÎäÆ÷¿âÖл¹°üÀ¨Õë¶ÔmacOSƽ̨µÄBellaRAT¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£¿É¼û¸Ã¹¥»÷ÍÅ»ïÊÔͼ½«¹¥»÷ÄÜÁ¦ÁýÕÖ°üÀ¨Linux¡¢WindowsºÍMacOSÔÚÄڵĶà¸öƽ̨¡£¡£¡£¡£¡£¡£¡£¡£
03
Kimsukyͨ¹ýBlogspotÕë¶Ôº«¹ú×ÅÃûÄ¿µÄÈö²¥¶ñÒâÈí¼þ
Åû¶ʱ¼ä£º2021Äê11ÔÂ10ÈÕ
Ç鱨ȪԴ£ºhttps://blog.talosintelligence.com/2021/11/kimsuky-abuses-blogs-delivers-malware.html
Ïà¹ØÐÅÏ¢£º
CiscoTalosÊӲ쵽£¬£¬£¬£¬£¬£¬£¬£¬×Ô2021Äê6ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬APT×éÖ¯KimsukyÔËÓªÁËÒ»³¡ÐµĶñÒâÈí¼þÔ˶¯¡£¡£¡£¡£¡£¡£¡£¡£ÕⳡÔ˶¯Ê¹ÓÃBlogspotÉϵĶñÒⲩ¿ÍÀ´Ïòº«¹úµÄ¸ß¼ÛֵĿµÄת´ïÈýÖÖÀàÐÍµÄÆðÔ´¶ñÒâÄÚÈÝ£ºbeacons¡¢ÎļþÍâй³ÌÐòºÍÖ²È밲Ş籾¡£¡£¡£¡£¡£¡£¡£¡£Ö²È밲Ş籾»á¼ÓÔØÌØÁíÍâÖ²Èë³ÌÐò(ÈçϵͳÐÅÏ¢ÇÔÈ¡Æ÷¡¢¼üÅ̼ͼ³ÌÐòºÍÖ¤ÊéÇÔÈ¡Æ÷)ѬȾĿµÄ¡£¡£¡£¡£¡£¡£¡£¡£
ÕâЩֲÈëµÄ¶ñÒâÈí¼þÊÇKimsukyµÄGoldDragon/BravePrince¶ñÒâÈí¼þ¼Ò×åµÄÑÜÉúÆ·£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ·Ö³ÉÈý¸ö×ÔÁ¦µÄÄ£¿£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÔ˶¯µÄÄ¿µÄÊÇÑо¿³¯ÏÊ¡¢Öйú¡¢¶íÂÞ˹¡¢ÃÀ¹úµÈÕþÖΡ¢Íâ½»¡¢¾üÊÂÎÊÌâµÄº«¹úÖǿ⡣¡£¡£¡£¡£¡£¡£¡£³ýÁËʹÓö¨ÖƵÄÎļþÍâй³ÌÐòÀ´ÇÔÈ¡Ñо¿Ð§¹ûÍ⣬£¬£¬£¬£¬£¬£¬£¬¸ÃÔ˶¯µÄÁíÒ»¸öÄ¿µÄÊÇʹÓÃľÂí¹¤¾ßÍøÂçÖ¤Ê飬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÖ²Èë³ÌÐò¼ÌÐø¶Ô¸ÐÐËȤµÄʵÌå¾ÙÐÐδ¾ÊÚȨµÄ»á¼û¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÓÐÕë¶ÔÐԵĹ¥»÷¿ÉÄܵ¼Ö·ǹûÕæµÄÑо¿Ð§¹ûй¶£¬£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄÌØ¹¤»á¼û£¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ¶ÔÄ¿µÄ×éÖ¯±£´æÆÆËðÐÔ¡£¡£¡£¡£¡£¡£¡£¡£

04
Lazarus×é֯ʹÓôøºóÃÅIDAÈí¼þ¹¥»÷Çå¾²Ñо¿Ö°Ô±
Åû¶ʱ¼ä£º2021Äê11ÔÂ10ÈÕ
Ç鱨ȪԴ£ºhttps://twitter.com/ESETresearch/status/1458438155149922312
Ïà¹ØÐÅÏ¢£º
½üÆÚÍâÑóÇå¾²³§ÉÌESETÆØ¹âÁ˳¯ÏÊAPT×éÖ¯LazarusµÄ×îй¥»÷Ô˶¯£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÔøÔÚ2021ÄêÒÔÎó²îÑо¿ÏàÖúΪ»Ï×Ó£¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÇå¾²Ñо¿Ö°Ô±¾ÙÐÐÍøÂç¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£¡£¡£¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬£¬LazarusÔÙ´ÎÊÔͼÕë¶ÔÇå¾²Ñо¿Ö°Ô±Õö¿ª¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¶øÕâ´ÎʹÓõÄÓÕ¶üÊÇÊ¢ÐеÄIDAProÄæÏò¹¤³ÌÓ¦ÓóÌÐòµÄľÂí»¯°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
¹¥»÷Õß½«IDAPro×°ÖðüÀïµÄidahelper.dllºÍwin_fw.dllÎļþÐÞ¸ÄΪ¶ñÒâDLL£¬£¬£¬£¬£¬£¬£¬£¬ÕâÁ½¸ö¶ñÒâ×é¼þ½«ÔÚ×°ÖóÌÐòÖÐÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£¶ñÒâwin_fw.dll»áÔÚWindowsʹÃüÍýÏë³ÌÐòÖн¨ÉèÒ»¸öÍýÏëʹÃü£¬£¬£¬£¬£¬£¬£¬£¬È»ºó´ÓIDAPlugins²å¼þÎļþ¼ÐÖÐÖ´ÐÐidahelper.dll¶ñÒâ×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©Æô¶¯£¬£¬£¬£¬£¬£¬£¬£¬idahelper.dll»áʵÑé´Ó¶ñÒâÁ´½ÓÏÂÔØÖ´ÐÐÏÂÒ»½×¶ÎµÄpayload¡£¡£¡£¡£¡£¡£¡£¡£¸Ãpayload±»ÒÔΪÊÇLazarus×é֮֯ǰʹÓõÄNukeSpedRATÔ¶¿ØÄ¾Âí£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×°ÖõÄRAT»á¼ûÑо¿Ö°Ô±µÄ×°±¸£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡Îļþ¡¢½ØÈ¡ÆÁÄ»½ØÍ¼¡¢¼Í¼»÷¼ü»òÖ´ÐнøÒ»²½µÄÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
05
MosesStaff×éÖ¯Õë¶ÔÒÔÉ«Áй¥»÷Ô˶¯ÆÊÎö
Åû¶ʱ¼ä£º2021Äê11ÔÂ15ÈÕ
Ç鱨ȪԴ£ºhttps://research.checkpoint.com/2021/mosesstaff-targeting-israeli-companies/
Ïà¹ØÐÅÏ¢£º
CheckPointÑо¿ÍŶÓÔÚ11ÔÂ15ÈÕÅû¶ÁËÒ»¸öеĺڿÍ×éÖ¯MosesStaff¡£¡£¡£¡£¡£¡£¡£¡£ËüÔÚÒÑÍùµÄ¼¸¸öÔÂÀïÔø¹¥»÷Á˶à¸öÒÔÉ«ÁеĹ«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÊDz¢Ã»ÓÐÌá³öÊê½ðÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Òò´ËÑо¿Ö°Ô±ÍƲâ¸ÃÍÅ»ïÓëPay2KeyºÍBlackShadowÓйأ¬£¬£¬£¬£¬£¬£¬£¬ËüÃǾßÓÐÏàͬµÄÄîÍ·ºÍÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ÷ҪʹÓÃÒѹûÕæµ«ÖÎÀíÔ±²¢Î´ÐÞ¸´µÄÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÈçMicrosoftExchangeÖеÄÎó²î£¬£¬£¬£¬£¬£¬£¬£¬È»ºóʹÓÃPsExec¡¢WMICºÍPowershellÔÚÍøÂçÖкáÏòÒÆ¶¯£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕ×°ÖÃ×Ô½ç˵¶ñÒâÈí¼þPyDCrypt¡£¡£¡£¡£¡£¡£¡£¡£

06
SideCopyαÔìAndroidÓ¦ÓÃÊÐËÁµÄ¹¥»÷
Åû¶ʱ¼ä£º2021Äê11ÔÂ16ÈÕ
Ç鱨ȪԴ£ºhttps://about.fb.com/news/2021/11/taking-action-against-hackers-in-pakistan-and-syria/
Ïà¹ØÐÅÏ¢£º
FacebookµÄÇå¾²ÍŶÓÔÚ11ÔÂ16ÈÕÅû¶ÁËSideCopyÐÂÒ»ÂֵĴ¹ÂÚÔ˶¯¡£¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÔ˶¯ÔÚ½ñÄê4ÔÂÖÁ8ÔÂÖ®¼ä£¬£¬£¬£¬£¬£¬£¬£¬½¨Éè²¢ÔËÓªÁËÒ»¸öαÔìµÄAndroidÓ¦ÓÃÊÐËÁ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ÷Ҫͨ³£»£»£»£»£»áð³äÄêÇáÅ®ÐÔÀ´¿¿½üÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÆä·¿ªÓÃÀ´ÓÃÀ´ÍøÂçÐÅÏ¢µÄ´¹ÂÚÍøÕ¾»òÕßαÔìµÄAndroidÓ¦ÓÃÊÐËÁ¡£¡£¡£¡£¡£¡£¡£¡£È»ºóͨ¹ýαװ³É̸ÌìÓ¦ÓõĶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬·Ö·¢PJobRATºÍMayhemµÈ¡£¡£¡£¡£¡£¡£¡£¡£
01
FIN7±ê¼ÇÐÔʹÓù¤¾ßÖØÐ·ºÆð
Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ
Ç鱨ȪԴ£ºhttps://www.splunk.com/en_us/blog/security/fin7-tools-resurface-in-the-field-splinter-or-copycat.html
Ïà¹ØÐÅÏ¢£º
FIN7ÊÇÒÔ½ðÈÚ¡¢Âùݡ¢²ÍÒû¡¢¶Ä²©µÈÐÐҵΪĿµÄ£¬£¬£¬£¬£¬£¬£¬£¬Óɸ߿Ƽ¼È˲Å×é³ÉµÄÓÐ×éÖ¯·¸·¨¼¯ÍÅ¡£¡£¡£¡£¡£¡£¡£¡£FIN7¾ÙÐÐÁËÊÖÒÕÖØ´óµÄ¶ñÒâÔ˶¯£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ê¹ÓÃ͵À´µÄÖ§¸¶¿¨¾ÙÐÐÄ¿µÄѬȾ¡¢ÉøÍ¸ºÍڲơ£¡£¡£¡£¡£¡£¡£¡£
×î½ü£¬£¬£¬£¬£¬£¬£¬£¬Ò»Ð©Çå¾²Ñо¿Ö°Ô±Åú×¢´ú±íFIN7µÄÌØ¶¨¹¤¾ßJSSLoaderÔٴηºÆð¡£¡£¡£¡£¡£¡£¡£¡£JSSLoaderµÄһЩ±äÌå±»±àÒë³É.net£¬£¬£¬£¬£¬£¬£¬£¬ÁíһЩÊÇc++¡£¡£¡£¡£¡£¡£¡£¡£Á½ÖÖJSSLoader¶¼»áÇÔȡĿµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£FIN7ºÜÉÆÓÚʹÓÃÓã²æÊ½ÍøÂç´¹ÂÚ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒͨ¹ýÏÂÔØ»òÖ´ÐлìÏýµÄjavascript×÷ΪµÚÒ»½×¶ÎÀ´¶ÔÄ¿µÄ¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
Ê×ÏÈ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ“user\public”Îļþ¼ÐÖн¨ÉèÒ»¸öÕýµ±µÄwmic.exeµÄ¸±±¾ºÍÒ»¸öxslÃûÌÃÎļþ¡£¡£¡£¡£¡£¡£¡£¡£È»ºó£¬£¬£¬£¬£¬£¬£¬£¬xslÎļþ½«Ö´ÐÐÀ©Õ¹ÃûΪ.txtµÄÏÖʵ¶ñÒâjs¡£¡£¡£¡£¡£¡£¡£¡£¸ÃjsÄܹ»Í¨¹ýÖ´Ðм¸¸öWMIÅÌÎÊÏÂÁîÀ´ÍøÂ类ѬȾÖ÷»úµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£×îºóÐÅÏ¢½«±»¼ÓÃܲ¢Ê¹ÓÃPOSTÇëÇó·¢Ë͵½C2ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Çå¾²Ö°Ô±»¹·¢Ã÷ÁËһЩʹÓÃDNSÉøÍ¸Êý¾ÝµÄ±äÌå¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ½«Ê×ÏȼÓÃÜËùÓÐÍøÂçµ½µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬½«Æä±àÂëΪbase64£¬£¬£¬£¬£¬£¬£¬£¬È»ºóʹÓÃnslookup½«±àÂëºóµÄÊý¾Ý·¢ÖÁC2ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
02
Ïã¸ÛÍøÕ¾ÔâË®¿Ó¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔmacOS×°±¸
Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ
Ç鱨ȪԴ£ºhttps://blog.google/threat-analysis-group/analyzing-watering-hole-campaign-using-macos-exploits/
Ïà¹ØÐÅÏ¢£º
2021Äê8ÔÂÏÂÑ®£¬£¬£¬£¬£¬£¬£¬£¬¹È¸èTAG·¢Ã÷Ïã¸ÛijýÌåºÍij»ú¹¹µÄÍøÕ¾Ô⵽ˮ¿Ó¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃË®¿Ó¹¥»÷ʹÓÃÁËÆ»¹û×°±¸µÄÏà¹ØÁãÈÕÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÊܺ¦Õß»úеÉÏ×°ÖÃÒ»¸öºóÃÅÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£
±»ºÚÍøÕ¾Ôâ¹¥»÷ÕßÖ²ÈëÁËÁ½¸ö¶ñÒâiframe£¬£¬£¬£¬£¬£¬£¬£¬»®·ÖÓÃÓÚ¹¥»÷iOSºÍmacOS×°±¸¡£¡£¡£¡£¡£¡£¡£¡£Õë¶ÔiOSµÄ¹¥»÷Á´°üÀ¨CVE-2019-8506µÈÎó²îʹÓᣡ£¡£¡£¡£¡£¡£¡£Õë¶ÔmacOSµÄ¹¥»÷Ôò²î±ð£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÒ»¸ö¼òÆÓµÄHTMLÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬¼ÓÔØÁ½¸ö¾ç±¾£¬£¬£¬£¬£¬£¬£¬£¬Ò»¸öÓÃÓÚ·´»ã±à£¬£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÓÃÓÚÎó²îʹÓÃÁ´¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îʹÓÃÁ´ÍŽáÁËCVE-2021-1789ºÍCVE-2021-30869¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÀÖ³ÉʹÓÃÎó²îºó£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»áÔÚÊܺ¦Õß»úеÉÏ×°ÖúóÃÅÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬Ëüͨ¹ýDDS¿ò¼ÜÖеÄÐû²¼-¶©ÔÄÄ£×ÓÀ´ÓëC2ͨѶ¡£¡£¡£¡£¡£¡£¡£¡£
03
ʹÓÃnamesiloParkingºÍGoogleµÄ×Ô½çËµÒ³ÃæÀ´Èö²¥¶ñÒâÈí¼þ
Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ
Ç鱨ȪԴ£ºhttps://blog.netlab.360.com/li-yong-namesilo-parkinghe-googlede-zi-ding-yi-ye-mian-lai-chuan-bo-e-yi-ruan-jian/
Ïà¹ØÐÅÏ¢£º
10Ô£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö¿ÉÒɵÄGoELFÑù±¾£¬£¬£¬£¬£¬£¬£¬£¬ÆÊÎöµÃÖªÊÇÒ»¸ödownloder£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÈö²¥Íڿ󡣡£¡£¡£¡£¡£¡£¡£ÆäʹÓÃnamesiloµÄParkingÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°GoogleµÄÓû§×Ô½çËµÒ³ÃæÀ´Èö²¥Ñù±¾¼°ÉèÖ㬣¬£¬£¬£¬£¬£¬£¬´Ó¶øÌӱܸú×Ù¡£¡£¡£¡£¡£¡£¡£¡£
´Ë°¸ÀýÖй¥»÷ÕßʹÓÃÁË“Óû§¿É¿Ø“µÄparkingÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ¼á³Öparking״̬µÄʱ¼ä£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ¶ñÒâÈí¼þÍÆ¹ã¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í²»ÐèÒªÓÐ×Ô¼ºµÄ»úеºÍIP£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÒªÓÃÓòÃû×¢²áÉÌÌṩµÄparkingµÄÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°googleµÄ×Ô½çËµÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬¾Í¿ÉÒÔÈö²¥×Ô¼ºµÄľÂí£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐgoogleµÄ×Ô½çËµÒ³ÃæÖаüÀ¨µÄÊÇbase64±àÂëµÄxmrigÍÚ¿óÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÍÅ»ïʹÓÃÕâЩ“¹«¹²ÉèÊ©”À´×éÖ¯×Ô¼ºµÄ¶ñÒâÈí¼þÈö²¥Á´Ìõ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ²¿·ÖµÄÌӱܸú×ÙºÍ×èµ²¡£¡£¡£¡£¡£¡£¡£¡£
04
¶à½×¶ÎPowerShell¹¥»÷Õë¶Ô¹þÈø¿Ë˹̹
Åû¶ʱ¼ä£º2021Äê11ÔÂ12ÈÕ
Ç鱨ȪԴ£ºhttps://blog.malwarebytes.com/threat-intelligence/2021/11/a-multi-stage-powershell-based-attack-targets-kazakhstan/
Ïà¹ØÐÅÏ¢£º
11ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Çå¾²Ö°Ô±·¢Ã÷ÁËÒ»´Î¶à½×¶ÎPowerShell¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷ʹÓÃÁËÒ»¸öð³ä¹þÈø¿Ë˹̹ÎÀÉú²¿µÄÎļþ×÷ÓÕ¶ü¡£¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷µÄÄ¿µÄ±»ÒÔΪÊǹþÈø¿Ë˹̹¡£¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ÕßÊ×ÏÈÈö²¥ÃûΪ“§µ§Ó§Ö§Õ§à§Þ§Ý§Ö§ß§Ú§Ö.rar(֪ͨ.rar)”µÄRARµµ°¸¡£¡£¡£¡£¡£¡£¡£¡£¸Ãµµ°¸Îļþ°üÀ¨Ò»¸öͬÃûµÄlnkÎļþ£¬£¬£¬£¬£¬£¬£¬£¬lnkÎļþð³äΪÀ´×Ô¹þÈø¿Ë˹̹¹²ºÍ¹úÎÀÉú²¿µÄPDFÎļþ¡£¡£¡£¡£¡£¡£¡£¡£·¿ªlnkÎļþºó£¬£¬£¬£¬£¬£¬£¬£¬½«ÏÔʾ¹þÈø¿Ë˹̹¹²ºÍ¹ú¹ú¼ÒÎÀÉú¾ÖÐû²¼µÄCovid19Õþ²ßµÄÐÞÕý°¸ÒÉ»óÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬£¬¶ø´Ëʱºǫ́½«Ö´Ðжà½×¶Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ʼÓÚÖ´ÐÐlnkÎļþ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþŲÓÃPowerShellÖ´ÐÐһЩ²Ù×÷£¬£¬£¬£¬£¬£¬£¬£¬ºÃ±Èͨ¹ýautorun×¢²á±íÏîʵÏÖȨÏÞÌáÉýºÍ³¤ÆÚÐÔ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ½«´ÓÒ»¸ö¶ñÒâµÄGitHub´úÂë¿âÏÂÔØºóÐø¶à¸öÓÐÓøºÔØ¡£¡£¡£¡£¡£¡£¡£¡£

05
¹¥»÷ÕßʹÓÃÓòǰÖÃÊÖÒÕ¶ÔÃåµéÌᳫ¹¥»÷
Åû¶ʱ¼ä£º2021Äê11ÔÂ08ÈÕ
Ç鱨ȪԴ£ºhttps://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html
Ïà¹ØÐÅÏ¢£º
½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬CiscoTalos·¢Ã÷ÁËÒ»ÆðʹÓÃCobaltStrikeÌᳫ¹¥»÷µÄ¶ñÒâÔ˶¯¡£¡£¡£¡£¡£¡£¡£¡£Ôڴ˰¸ÀýÖй¥»÷Õßͨ¹ýÔÚCloudFrontЧÀÍÉÏʹÓÃÓòǰÖÃÊÖÒÕ½«ÃåµéÕþ¸®ËùÓµÓеÄÓòÃûÖØ¶¨Ïòµ½Æä¿ØÖƵÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÖØÐÂ×¢²á×ÅÃûÓòÃû×÷ΪǰÖÃÓòÃûÀ´Ìӱܼì²â¡£¡£¡£¡£¡£¡£¡£¡£
¶ñÒâÈí¼þÔÚÊܺ¦Õß»úеÉÏÖ´Ðкó»á·´Éä¼ÓÔØCobaltStrikebeacon.dllÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±ÔÚÔËÐÐʱ¼ÓÔØ¶à¸ö¿â²¢Æ¾Ö¤Ç¶ÈëʽÉèÖÃÎļþÌìÉúbeacon¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚDNSÇëÇóÖÐʹÓÃÎÞº¦µÄÓòÃûÀ´¾ÙÐÐÅþÁ¬£¬£¬£¬£¬£¬£¬£¬£¬¶øÏÖʵҪÅþÁ¬µÄ±»·â±ÕÓòÃû½öÔÚ½¨ÉèHTTPSÅþÁ¬ºó·¢³ö£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚHostÍ·ÖÐЯ´øÁíÒ»¸öC2ÓòÃû¡£¡£¡£¡£¡£¡£¡£¡£

01
ÐÂGolang¶ñÒâÈí¼þBotenaGo£¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ô·ÓÉÆ÷ºÍÎïÁªÍø×°±¸
Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ
Ç鱨ȪԴ£ºhttps://cybersecurity.att.com/blogs/labs-research/att-alien-labs-finds-new-golang-malwarebotenago-targeting-millions-of-routers-and-iot-devices-with-more-than-30-exploits
Ïà¹ØÐÅÏ¢£º
AT&TAlienLabs·¢Ã÷ÁËÓÃGolang±àдµÄжñÒâÈí¼þBotenaGo¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓµÓÐ30¶à¸öÎó²îʹÓÃÄ£¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬£¬ÓÐÄÜÁ¦Õë¶ÔÊý°ÙÍò·ÓÉÆ÷ºÍÎïÁªÍø×°±¸·¢¶¯¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
BotenaGoÊ×Ïȳõʼ»¯È«¾ÖѬȾ¼ÆÊýÆ÷£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÊä³öµ½ÆÁÄ»ÉÏ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãºÚ¿ÍÏàʶÀÖ³ÉѬȾ×ÜÊý¡£¡£¡£¡£¡£¡£¡£¡£È»ºó¶ñÒâÈí¼þ²éÕÒ“dlrs”Îļþ¼Ð£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÆäÖмÓÔØshell¾ç±¾Îļþ¡£¡£¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þŲÓú¯Êý“scanerinitexploit”£¬£¬£¬£¬£¬£¬£¬£¬À´Æô¶¯¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þ¿ÉÒÔͨ¹ýÁ½ÖÖ²î±ðµÄ·½·¨ÎüÊÕÕë¶ÔÊܺ¦ÕßµÄÏÂÁ£¬£¬£¬£¬£¬£¬£¬Ëü½¨ÉèÁËÁ½¸öºóÃŶ˿Ú31412ºÍ19412¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ¶Ë¿Ú19412ÉÏ£¬£¬£¬£¬£¬£¬£¬£¬Ëü½«¼àÌýÎüÊÕÊܺ¦IP¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©ÎüÊÕµ½µ½¸Ã¶Ë¿ÚµÄÐÅÏ¢ÅþÁ¬£¬£¬£¬£¬£¬£¬£¬£¬Ëü½«±éÀúÎó²îʹÓú¯Êý²¢Ê¹Óøø¶¨µÄIPÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£µÚ¶þÖÖ·½·¨£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ½«Ò»¸ö¼àÌýÆ÷ÉèÖÃΪϵͳIOÓû§ÊäÈ룬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýËüÎüÊÕÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬£¬ÈôÊǶñÒâÈí¼þÔÚÐéÄâ»úÊÜÆµØÔËÐУ¬£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔͨ¹ýtelnet·¢ËÍÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
02
жñÒâÈí¼þCovid22ÏÖÉí£¬£¬£¬£¬£¬£¬£¬£¬ÆÆËðÊܺ¦ÕßϵͳMBR
Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ
Ç鱨ȪԴ£ºhttps://www.fortinet.com/blog/threat-research/to-joke-or-not-to-joke-covid-22-brings-disaster-to-mbr
Ïà¹ØÐÅÏ¢£º
FortiGuardʵÑéÊÒ×î½ü·¢Ã÷ÁËÒ»¸öÃûΪCovid22×°ÖóÌÐòµÄжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¾ßÓÐÆÆËðÐÔ£¬£¬£¬£¬£¬£¬£¬£¬Ëü»áµ¼ÖÂÊÜѬȾµÄ»úеÎÞ·¨Æô¶¯£¬£¬£¬£¬£¬£¬£¬£¬²¢²»ÏñÀÕË÷Èí¼þÒ»ÑùÒªÇóÊê½ðÒÔ»Ö¸´ÆÆË𣬣¬£¬£¬£¬£¬£¬£¬ËüµÄÄ¿µÄ¾ÍÊÇÆÆËðѬȾϵͳ¡£¡£¡£¡£¡£¡£¡£¡£
¸Ã¶ñÒâÈí¼þÎļþÃûΪCovid22¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÓÕµ¼Êܺ¦Õß·¿ªÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Covid22»áѯÎÊÊܺ¦ÕßÊÇ·ñÒª¼ÌÐø×°ÖÃCovid22¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©Êܺ¦Õß¼ÌÐø×°Ö㬣¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»á¼ÓÔØ¼¸¸ö¶ñÒâÎļþ²¢Ç¿ÖÆÖØÆô»úе¡£¡£¡£¡£¡£¡£¡£¡£±»ÊͷŵĶñÒâÎļþ»áÖ´ÐÐһϵÁжñÒâ²Ù×÷£¬£¬£¬£¬£¬£¬£¬£¬ÈçÒ»Ö±Ìø³öͼƬ»òÎÄ×Öµ¯´°¡¢Ê¹ÓÃÑïÉùÆ÷±¬·¢ÉùÒô¡¢Òƶ¯ÆÁÄ»ÉϵÄÏñËØ¿éµÈ¡£¡£¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»á¼ÓÔØ²¢Ö´ÐÐwiper¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬wiper»áÆÆËðÖ÷Ö¸µ¼¼Í¼(MBR)£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÌø³öÒ»¸öµ¯´°ºóÖØÆôϵͳ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚMBR¾ßÓÐÓ²ÅÌÇý¶¯Æ÷·ÖÇøµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬²¢³äµ±²Ù×÷ϵͳ(OS)µÄ¼ÓÔØÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Òò´Ë±»ÆÆËðMBRµÄ»úе½«ÎÞ·¨ÔÚÖØÐÂÆô¶¯Ê±¼ÓÔØ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£¡£
03
¹¥»÷ÕßÃé×¼°¢Àï°Í°ÍECS£¬£¬£¬£¬£¬£¬£¬£¬Èö²¥ÍÚ¿óÄ£¿£¿£¿£¿£¿£¿£¿£¿é
Åû¶ʱ¼ä£º2021Äê11ÔÂ15ÈÕ
Ç鱨ȪԴ£ºhttps://www.trendmicro.com/en_us/research/21/k/groups-target-alibaba-ecs-instances-for-cryptojacking.html
Ïà¹ØÐÅÏ¢£º
Çå¾²Ö°Ô±½üÆÚÔÚ¶à¸ö¶ñÒâÓÐÓøºÔØÖж¼·¢Ã÷ÁËÕë¶Ô°¢ÀïÔÆÐ§ÀÍÆ÷µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£°¢Àï°Í°ÍECSʵÀý×Ô´øÇå¾²ÊðÀí¡£¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ¶ñÒâÈí¼þÖÐʹÓÃÁËÌØ¶¨µÄ´úÂ룬£¬£¬£¬£¬£¬£¬£¬À´½¨Éè·À»ðǽ¹æÔò£¬£¬£¬£¬£¬£¬£¬£¬ÑïÆúÀ´×Ô°¢Àï°Í°ÍÄÚ²¿ÇøÓòºÍµØÇøµÄIP¹æÄ£µÄÊý¾Ý°ü¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ä¬Èϵİ¢Àï°Í°ÍECSʵÀýÌṩroot»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊǵǼÃÜÂ뱻й¶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔÖ±½Ó»ñÈ¡rootȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£µ±Ò»¸öÍÚ¿ó¶ñÒâÈí¼þÔÚ°¢Àï°Í°ÍECSÄÚ²¿ÔËÐÐʱ£¬£¬£¬£¬£¬£¬£¬£¬Ô¤×°µÄÇå¾²ÊðÆÊÎö·¢ËÍÒ»¸ö¶ñÒâ¾ç±¾ÔËÐеÄ֪ͨ¡£¡£¡£¡£¡£¡£¡£¡£Òò´Ë¶ñÒâÈí¼þ»áÔÚÇå¾²ÊðÀí³ÌÐò´¥·¢Ñ¬È¾¾¯±¨Ö®Ç°½«ÆäÐ¶ÔØ£¬£¬£¬£¬£¬£¬£¬£¬È»ºó×°ÖÃXMRig¡£¡£¡£¡£¡£¡£¡£¡£
04
¶ñÒâÈí¼þEmotet»Ø¹é£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýTrickBotÖØÐÞ½©Ê¬ÍøÂç
Åû¶ʱ¼ä£º2021Äê11ÔÂ16ÈÕ
Ç鱨ȪԴ£ºhttps://www.zscaler.com/blogs/security-research/return-emotet-malware
Ïà¹ØÐÅÏ¢£º
2021Äê1Ô£¬£¬£¬£¬£¬£¬£¬£¬Ö´·¨²¿·Ö×è¶ÏÁ˶ñÒâÈí¼þEmotet¼°Æä»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬£¬»¹¾Ð²¶ÁËһЩĻºóµÄÍþв·Ö×Ó¡£¡£¡£¡£¡£¡£¡£¡£Ò»Ð©Çå¾²Ñо¿Ö°Ô±ÒÔΪËüÒѾһȥ²»¸´·µÁË¡£¡£¡£¡£¡£¡£¡£¡£µ«ÔÚÖÐÖ¹ÁËÏÕЩһÄêÖ®ºó£¬£¬£¬£¬£¬£¬£¬£¬EmotetÓÖ¾íÍÁÖØÀ´¡£¡£¡£¡£¡£¡£¡£¡£ÔçǰÓб¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÓÚ2021Äê11ÔÂ14ÈÕÔٴηºÆð£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýTrickBot½©Ê¬ÍøÂç·Ö·¢¡£¡£¡£¡£¡£¡£¡£¡£»£»£»£»£ÉÐÓб¨¸æÏÔʾ¸Ã¶ñÒâÈí¼þͨ¹ýµç×ÓÓʼþÈö²¥£¬£¬£¬£¬£¬£¬£¬£¬À¬»øÓʼþÔ˶¯ÖÐʹÓӻظ´Á´”ÓʼþÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËdocm¡¢xlsmºÍzipÃûÌõĸ½¼þ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ð°汾µÄEmotetÔÚÐí¶à·½ÃæÓëÒÑÍùµÄ°æÄÚÇéËÆ£¬£¬£¬£¬£¬£¬£¬£¬ËƺõÒ²ÔÚʹÓÃHTTPS¶ø²»ÊÇͨË×µÄHTTPÀ´¾ÙÐÐÏÂÁîºÍ¿ØÖÆÍ¨Ñ¶¡£¡£¡£¡£¡£¡£¡£¡£
01
GoogleÐû²¼11Ô¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ChromeÖеĶà¸öÎó²î
Åû¶ʱ¼ä£º2021Äê11ÔÂ16ÈÕ
Ç鱨ȪԴ£ºhttps://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html
Ïà¹ØÐÅÏ¢£º
11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬GoogleÐû²¼Á˱¾ÔÂChromeµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´ÁË25¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬½ÏΪÑÏÖØµÄÊÇÔÚýÌåÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-38008£©¡¢V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-38007£©ºÍ¼ÓÔØÆ÷ÖÐÊͷźóʹÓÃÎó²î£¨CVE-2021-38005£©µÈ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬»¹ÐÞ¸´ÁËÖ¸ÎÆÊ¶±ðÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-38013£©ºÍSwiftshaderÖеÄÔ½½çдÈ루CVE-2021-38014£©µÈÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
VMwarevCenterServerȨÏÞÌáÉýÎó²îͨ¸æ
Åû¶ʱ¼ä£º2021Äê11ÔÂ12ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/zwiAQIrFuaDKxfvpJHNqyg
Ïà¹ØÐÅÏ¢£º
VMwarevCenterServerÌṩÁËÒ»¸ö¿ÉÉìËõ¡¢¿ÉÀ©Õ¹µÄƽ̨£¬£¬£¬£¬£¬£¬£¬£¬ÎªÐéÄ⻯ÖÎÀíµÓÚ¨ÁË»ù´¡¡£¡£¡£¡£¡£¡£¡£¡£VMwarevCenterServer£¨ÒÔǰ³ÆÎªVMwareVirtualCenter£©£¬£¬£¬£¬£¬£¬£¬£¬¿É¼¯ÖÐÖÎÀíVMwarevSphereÇéÐΣ¬£¬£¬£¬£¬£¬£¬£¬ÓëÆäËûÖÎÀíÆ½Ì¨Ïà±È£¬£¬£¬£¬£¬£¬£¬£¬¼«´óµØÌá¸ßÁËITÖÎÀíÔ±¶ÔÐéÄâÇéÐεĿØÖÆ¡£¡£¡£¡£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ