Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.11.11~11.18)

ʱ¼ä£º2021-11-19 ×÷ÕߣºÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐÄ

·ÖÏíµ½£º

    2021.11.11~11.18

    ¹¥»÷ÍÅ»ïÇ鱨

    SideCopy×éÖ¯½üÆÚʹÓÃÖÐÓ¡Ê±ÊÆÐÂÎŵĹ¥»÷ÊÂÎñÆÊÎö

    ÒÉËÆSideCopy×éÖ¯Õë¶ÔÓ¡¶ÈͶ·Å˫ƽ̨RAT

    Kimsukyͨ¹ýBlogspotÕë¶Ôº«¹ú×ÅÃûÄ¿µÄÈö²¥¶ñÒâÈí¼þ

    Lazarus×é֯ʹÓôøºóÃÅIDAÈí¼þ¹¥»÷Çå¾²Ñо¿Ö°Ô±

    MosesStaff×éÖ¯Õë¶ÔÒÔÉ«Áй¥»÷Ô˶¯ÆÊÎö

    SideCopyαÔìAndroidÓ¦ÓÃÊÐËÁµÄ¹¥»÷

    ¹¥»÷Ðж¯»òÊÂÎñÇ鱨

    FIN7±ê¼ÇÐÔʹÓù¤¾ßÖØÐ·ºÆð

    Ïã¸ÛÍøÕ¾ÔâË®¿Ó¹¥»÷£¬£¬£¬ £¬ £¬£¬£¬£¬Õë¶ÔmacOS×°±¸

    ¹¥»÷ÕßʹÓÃParkingÓòÃûºÍGoogleµÄ×Ô½çËµÒ³ÃæÀ´Èö²¥¶ñÒâÈí¼þ

    ¶à½×¶ÎPowerShell¹¥»÷Õë¶Ô¹þÈø¿Ë˹̹

    ¹¥»÷ÕßʹÓÃÓòǰÖÃÊÖÒÕ¶ÔÃåµéÌᳫ¹¥»÷

    ¶ñÒâ´úÂëÇ鱨

    ÐÂGolang¶ñÒâÈí¼þBotenaGo£¬£¬£¬ £¬ £¬£¬£¬£¬Õë¶Ô·ÓÉÆ÷

    Ð¶ñÒâÈí¼þCovid22ÏÖÉí£¬£¬£¬ £¬ £¬£¬£¬£¬ÆÆËðÊܺ¦ÕßϵͳMBR

    ¹¥»÷ÕßÃé×¼°¢Àï°Í°ÍECS£¬£¬£¬ £¬ £¬£¬£¬£¬Èö²¥ÍÚ¿óÄ £¿£¿£¿£¿£¿£¿£¿£¿é

    ¶ñÒâÈí¼þEmotet»Ø¹é£¬£¬£¬ £¬ £¬£¬£¬£¬Í¨¹ýTrickBotÖØÐÞ½©Ê¬ÍøÂç

    Îó²îÇ鱨

    GoogleÐû²¼11Ô¸üУ¬£¬£¬ £¬ £¬£¬£¬£¬ÐÞ¸´ChromeÖеĶà¸öÎó²î

    VMwarevCenterServerȨÏÞÌáÉýÎó²îͨ¸æ


    ¹¥»÷ÍÅ»ïÇ鱨

    01

    SideCopy×éÖ¯½üÆÚʹÓÃÖÐÓ¡Ê±ÊÆÐÂÎŵĹ¥»÷ÊÂÎñÆÊÎö

    Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ

    Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/iZuB1IAtNm5DxrrUIJqyoA

    Ïà¹ØÐÅÏ¢£º

    ¿ËÈÕ£¬£¬£¬ £¬ £¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐIJ¶»ñµ½Ò»ÅúSideCopyÒÔÓ¡¶È¾üÊÂÏà¹Ø»°ÌâΪÓÕ¶üµÄ¹¥»÷Ñù±¾¡£¡£¡£¡£¡£¡£ ¡£¡£Ôڴ˹¥»÷Ô˶¯ÖУ¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷ÕßÖ÷ÒªÒÔÓ¡¶ÈµØÇø¿Ö²À·Ö×ÓÓëÊ¿±øÖ®¼äµÄ³åͻʹʱ¨¸æÎªÖ÷Ì⣬£¬£¬ £¬ £¬£¬£¬£¬½«ÏÂÔØÆ÷αװΪͨË×ͼƬÎļþÒýÓÕÄ¿µÄÓû§µã»÷ÔËÐС£¡£¡£¡£¡£¡£ ¡£¡£µ±Êܺ¦Õß½âѹ²¢Ö´ÐÐÓÕ¶üÎļþÖ®ºó£¬£¬£¬ £¬ £¬£¬£¬£¬³ÌÐò½«»á´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØÊý¾ÝÎļþµ½ÍâµØ¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë³ÌÐòÊÇÒ»¸öÏÂÔØÆ÷£¬£¬£¬ £¬ £¬£¬£¬£¬Í¨¹ý°×Ãûµ¥µÄ¶ÌÁ´½Ó½«ÕæÊµURL¾ÙÐÐÒþ²Ø£¬£¬£¬ £¬ £¬£¬£¬£¬ÒÔ´ËÀ´¹æ±ÜɱÈíµÄ¾²Ì¬²éɱ¡£¡£¡£¡£¡£¡£ ¡£¡£Í¨¹ý¶Ô¶ÌÁ´½ÓËùÖ¸ÏòµÄÊý¾Ý¾ÙÐÐÏÂÔØÒԺ󣬣¬£¬ £¬ £¬£¬£¬£¬Ê¹ÓýâÃÜËã·¨¾ÙÐнâÃÜ£¬£¬£¬ £¬ £¬£¬£¬£¬×îÖÕ¼ÓÔØSideCopy×ÔÓÐÔ¶¿ØÈí¼þMargulasRAT¡£¡£¡£¡£¡£¡£ ¡£¡£

    02

    ÒÉËÆSideCopy×éÖ¯Õë¶ÔÓ¡¶ÈͶ·Å˫ƽ̨RAT

    Åû¶ʱ¼ä£º2021Äê11ÔÂ15ÈÕ

    Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/BSfKTlMlOnNlsWKjV1NM8w

    Ïà¹ØÐÅÏ¢£º

    ¿ËÈÕÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐĺìÓêµÎÍŶӲ¶»ñµ½Ò»ÀýÒÔÓ¡¶È×ÜÀíĪµÏ·ÃÃÀÏà¹Ø»°ÌâΪÓÕ¶üµÄLinuxƽ̨¹¥»÷Ñù±¾¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÑù±¾ÊÇÒÔĪµÏ·ÃÃÀ»°ÌâÃüÃûµÄtar.gzѹËõ°ü£¬£¬£¬ £¬ £¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öLinux×ÀÃæÆô¶¯Îļþ£¬£¬£¬ £¬ £¬£¬£¬£¬¸ÃÎļþÔÚÖ´ÐÐÖ®ºó»áÏÂÔØ²¢²¥·ÅÓÕ¶üÊÓÆµÒÔÒÉ»óÊܺ¦Õߣ¬£¬£¬ £¬ £¬£¬£¬£¬Í¬Ê±»áÏÂÔØÒ»¸öÓÃÓÚ¼ÓÔØRATµÄ¾ç±¾²¢Ö´ÐС£¡£¡£¡£¡£¡£ ¡£¡£

    RATÊÇÒ»¿î»ùÓÚPythonµÄºá¿çWindowsºÍLinux˫ƽ̨µÄÔ¶¿Ø¹¤¾ß¡£¡£¡£¡£¡£¡£ ¡£¡£ÁíÍâͨ¹ýC2ЧÀÍÆ÷µÄIP¾ÙÐйØÁª£¬£¬£¬ £¬ £¬£¬£¬£¬¸ÃIPÔøÆÊÎöµ½SideCopy×éÖ¯¿ØÖƵÄÓòÃûÉÏ£¬£¬£¬ £¬ £¬£¬£¬£¬²¢ÇÒ¸ÃÍÅ»ïÎäÆ÷¿âÖл¹°üÀ¨Õë¶ÔmacOSƽ̨µÄBellaRAT¡£¡£¡£¡£¡£¡£ ¡£¡ £¿£¿£¿£¿£¿£¿£¿£¿É¼û¸Ã¹¥»÷ÍÅ»ïÊÔͼ½«¹¥»÷ÄÜÁ¦ÁýÕÖ°üÀ¨Linux¡¢WindowsºÍMacOSÔÚÄڵĶà¸öƽ̨¡£¡£¡£¡£¡£¡£ ¡£¡£

    03

    Kimsukyͨ¹ýBlogspotÕë¶Ôº«¹ú×ÅÃûÄ¿µÄÈö²¥¶ñÒâÈí¼þ

    Åû¶ʱ¼ä£º2021Äê11ÔÂ10ÈÕ

    Ç鱨ȪԴ£ºhttps://blog.talosintelligence.com/2021/11/kimsuky-abuses-blogs-delivers-malware.html

    Ïà¹ØÐÅÏ¢£º

    CiscoTalosÊӲ쵽£¬£¬£¬ £¬ £¬£¬£¬£¬×Ô2021Äê6ÔÂÒÔÀ´£¬£¬£¬ £¬ £¬£¬£¬£¬APT×éÖ¯KimsukyÔËÓªÁËÒ»³¡ÐµĶñÒâÈí¼þÔ˶¯¡£¡£¡£¡£¡£¡£ ¡£¡£ÕⳡÔ˶¯Ê¹ÓÃBlogspotÉϵĶñÒⲩ¿ÍÀ´Ïòº«¹úµÄ¸ß¼ÛֵĿµÄת´ïÈýÖÖÀàÐÍµÄÆðÔ´¶ñÒâÄÚÈÝ£ºbeacons¡¢ÎļþÍâй³ÌÐòºÍÖ²È밲Ş籾¡£¡£¡£¡£¡£¡£ ¡£¡£Ö²È밲Ş籾»á¼ÓÔØÌØÁíÍâÖ²Èë³ÌÐò(ÈçϵͳÐÅÏ¢ÇÔÈ¡Æ÷¡¢¼üÅ̼ͼ³ÌÐòºÍÖ¤ÊéÇÔÈ¡Æ÷)ѬȾĿµÄ¡£¡£¡£¡£¡£¡£ ¡£¡£

    ÕâЩֲÈëµÄ¶ñÒâÈí¼þÊÇKimsukyµÄGoldDragon/BravePrince¶ñÒâÈí¼þ¼Ò×åµÄÑÜÉúÆ·£¬£¬£¬ £¬ £¬£¬£¬£¬ÏÖÔÚ·Ö³ÉÈý¸ö×ÔÁ¦µÄÄ £¿£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë´ÎÔ˶¯µÄÄ¿µÄÊÇÑо¿³¯ÏÊ¡¢Öйú¡¢¶íÂÞ˹¡¢ÃÀ¹úµÈÕþÖΡ¢Íâ½»¡¢¾üÊÂÎÊÌâµÄº«¹úÖǿ⡣¡£¡£¡£¡£¡£ ¡£¡£³ýÁËʹÓö¨ÖƵÄÎļþÍâй³ÌÐòÀ´ÇÔÈ¡Ñо¿Ð§¹ûÍ⣬£¬£¬ £¬ £¬£¬£¬£¬¸ÃÔ˶¯µÄÁíÒ»¸öÄ¿µÄÊÇʹÓÃľÂí¹¤¾ßÍøÂçÖ¤Ê飬£¬£¬ £¬ £¬£¬£¬£¬²¢Ê¹ÓÃÖ²Èë³ÌÐò¼ÌÐø¶Ô¸ÐÐËȤµÄʵÌå¾ÙÐÐδ¾­ÊÚȨµÄ»á¼û¡£¡£¡£¡£¡£¡£ ¡£¡£ÕâÖÖÓÐÕë¶ÔÐԵĹ¥»÷¿ÉÄܵ¼Ö·ǹûÕæµÄÑо¿Ð§¹ûй¶£¬£¬£¬ £¬ £¬£¬£¬£¬Î´¾­ÊÚȨµÄÌØ¹¤»á¼û£¬£¬£¬ £¬ £¬£¬£¬£¬ÉõÖÁ¶ÔÄ¿µÄ×éÖ¯±£´æÆÆËðÐÔ¡£¡£¡£¡£¡£¡£ ¡£¡£

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.11.11~11.18)

    04

    Lazarus×é֯ʹÓôøºóÃÅIDAÈí¼þ¹¥»÷Çå¾²Ñо¿Ö°Ô±

    Åû¶ʱ¼ä£º2021Äê11ÔÂ10ÈÕ

    Ç鱨ȪԴ£ºhttps://twitter.com/ESETresearch/status/1458438155149922312

    Ïà¹ØÐÅÏ¢£º

    ½üÆÚÍâÑóÇå¾²³§ÉÌESETÆØ¹âÁ˳¯ÏÊAPT×éÖ¯LazarusµÄ×îй¥»÷Ô˶¯£¬£¬£¬ £¬ £¬£¬£¬£¬¸Ã×éÖ¯ÔøÔÚ2021ÄêÒÔÎó²îÑо¿ÏàÖúΪ»Ï×Ó£¬£¬£¬ £¬ £¬£¬£¬£¬Õë¶ÔÇå¾²Ñо¿Ö°Ô±¾ÙÐÐÍøÂç¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£ ¡£¡£¿ËÈÕ£¬£¬£¬ £¬ £¬£¬£¬£¬LazarusÔÙ´ÎÊÔͼÕë¶ÔÇå¾²Ñо¿Ö°Ô±Õö¿ª¹¥»÷£¬£¬£¬ £¬ £¬£¬£¬£¬¶øÕâ´ÎʹÓõÄÓÕ¶üÊÇÊ¢ÐеÄIDAProÄæÏò¹¤³ÌÓ¦ÓóÌÐòµÄľÂí»¯°æ±¾¡£¡£¡£¡£¡£¡£ ¡£¡£

    ¹¥»÷Õß½«IDAPro×°ÖðüÀïµÄidahelper.dllºÍwin_fw.dllÎļþÐÞ¸ÄΪ¶ñÒâDLL£¬£¬£¬ £¬ £¬£¬£¬£¬ÕâÁ½¸ö¶ñÒâ×é¼þ½«ÔÚ×°ÖóÌÐòÖÐÖ´ÐС£¡£¡£¡£¡£¡£ ¡£¡£¶ñÒâwin_fw.dll»áÔÚWindowsʹÃüÍýÏë³ÌÐòÖн¨ÉèÒ»¸öÍýÏëʹÃü£¬£¬£¬ £¬ £¬£¬£¬£¬È»ºó´ÓIDAPlugins²å¼þÎļþ¼ÐÖÐÖ´ÐÐidahelper.dll¶ñÒâ×é¼þ¡£¡£¡£¡£¡£¡£ ¡£¡£Ò»µ©Æô¶¯£¬£¬£¬ £¬ £¬£¬£¬£¬idahelper.dll»áʵÑé´Ó¶ñÒâÁ´½ÓÏÂÔØÖ´ÐÐÏÂÒ»½×¶ÎµÄpayload¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ãpayload±»ÒÔΪÊÇLazarus×é֮֯ǰʹÓõÄNukeSpedRATÔ¶¿ØÄ¾Âí£¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×°ÖõÄRAT»á¼ûÑо¿Ö°Ô±µÄ×°±¸£¬£¬£¬ £¬ £¬£¬£¬£¬´Ó¶øÇÔÈ¡Îļþ¡¢½ØÈ¡ÆÁÄ»½ØÍ¼¡¢¼Í¼»÷¼ü»òÖ´ÐнøÒ»²½µÄÏÂÁî¡£¡£¡£¡£¡£¡£ ¡£¡£

    05

    MosesStaff×éÖ¯Õë¶ÔÒÔÉ«Áй¥»÷Ô˶¯ÆÊÎö

    Åû¶ʱ¼ä£º2021Äê11ÔÂ15ÈÕ

    Ç鱨ȪԴ£ºhttps://research.checkpoint.com/2021/mosesstaff-targeting-israeli-companies/

    Ïà¹ØÐÅÏ¢£º

    CheckPointÑо¿ÍŶÓÔÚ11ÔÂ15ÈÕÅû¶ÁËÒ»¸öеĺڿÍ×éÖ¯MosesStaff¡£¡£¡£¡£¡£¡£ ¡£¡£ËüÔÚÒÑÍùµÄ¼¸¸öÔÂÀïÔø¹¥»÷Á˶à¸öÒÔÉ«ÁеĹ«Ë¾£¬£¬£¬ £¬ £¬£¬£¬£¬¿ÉÊDz¢Ã»ÓÐÌá³öÊê½ðÒªÇ󣬣¬£¬ £¬ £¬£¬£¬£¬Òò´ËÑо¿Ö°Ô±ÍƲâ¸ÃÍÅ»ïÓëPay2KeyºÍBlackShadowÓйأ¬£¬£¬ £¬ £¬£¬£¬£¬ËüÃǾßÓÐÏàͬµÄÄîÍ·ºÍÄ¿µÄ¡£¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÖ÷ҪʹÓÃÒѹûÕæµ«ÖÎÀíÔ±²¢Î´ÐÞ¸´µÄÎó²î£¬£¬£¬ £¬ £¬£¬£¬£¬ÈçMicrosoftExchangeÖеÄÎó²î£¬£¬£¬ £¬ £¬£¬£¬£¬È»ºóʹÓÃPsExec¡¢WMICºÍPowershellÔÚÍøÂçÖкáÏòÒÆ¶¯£¬£¬£¬ £¬ £¬£¬£¬£¬×îÖÕ×°ÖÃ×Ô½ç˵¶ñÒâÈí¼þPyDCrypt¡£¡£¡£¡£¡£¡£ ¡£¡£

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.11.11~11.18)

    06

    SideCopyαÔìAndroidÓ¦ÓÃÊÐËÁµÄ¹¥»÷

    Åû¶ʱ¼ä£º2021Äê11ÔÂ16ÈÕ

    Ç鱨ȪԴ£ºhttps://about.fb.com/news/2021/11/taking-action-against-hackers-in-pakistan-and-syria/

    Ïà¹ØÐÅÏ¢£º

    FacebookµÄÇå¾²ÍŶÓÔÚ11ÔÂ16ÈÕÅû¶ÁËSideCopyÐÂÒ»ÂֵĴ¹ÂÚÔ˶¯¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë´ÎÔ˶¯ÔÚ½ñÄê4ÔÂÖÁ8ÔÂÖ®¼ä£¬£¬£¬ £¬ £¬£¬£¬£¬½¨Éè²¢ÔËÓªÁËÒ»¸öαÔìµÄAndroidÓ¦ÓÃÊÐËÁ¡£¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÖ÷Ҫͨ³£»£»£» £» £»áð³äÄêÇáÅ®ÐÔÀ´¿¿½üÄ¿µÄ£¬£¬£¬ £¬ £¬£¬£¬£¬ÓÕʹÆä·­¿ªÓÃÀ´ÓÃÀ´ÍøÂçÐÅÏ¢µÄ´¹ÂÚÍøÕ¾»òÕßαÔìµÄAndroidÓ¦ÓÃÊÐËÁ¡£¡£¡£¡£¡£¡£ ¡£¡£È»ºóͨ¹ýαװ³É̸ÌìÓ¦ÓõĶñÒâÈí¼þ£¬£¬£¬ £¬ £¬£¬£¬£¬·Ö·¢PJobRATºÍMayhemµÈ¡£¡£¡£¡£¡£¡£ ¡£¡£

    ¹¥»÷ÍÅ»ïÇ鱨

    01

    FIN7±ê¼ÇÐÔʹÓù¤¾ßÖØÐ·ºÆð

    Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ

    Ç鱨ȪԴ£ºhttps://www.splunk.com/en_us/blog/security/fin7-tools-resurface-in-the-field-splinter-or-copycat.html

    Ïà¹ØÐÅÏ¢£º

    FIN7ÊÇÒÔ½ðÈÚ¡¢Âùݡ¢²ÍÒû¡¢¶Ä²©µÈÐÐҵΪĿµÄ£¬£¬£¬ £¬ £¬£¬£¬£¬Óɸ߿Ƽ¼È˲Å×é³ÉµÄÓÐ×éÖ¯·¸·¨¼¯ÍÅ¡£¡£¡£¡£¡£¡£ ¡£¡£FIN7¾ÙÐÐÁËÊÖÒÕÖØ´óµÄ¶ñÒâÔ˶¯£¬£¬£¬ £¬ £¬£¬£¬£¬°üÀ¨Ê¹ÓÃ͵À´µÄÖ§¸¶¿¨¾ÙÐÐÄ¿µÄѬȾ¡¢ÉøÍ¸ºÍڲƭ¡£¡£¡£¡£¡£¡£ ¡£¡£

    ×î½ü£¬£¬£¬ £¬ £¬£¬£¬£¬Ò»Ð©Çå¾²Ñо¿Ö°Ô±Åú×¢´ú±íFIN7µÄÌØ¶¨¹¤¾ßJSSLoaderÔٴηºÆð¡£¡£¡£¡£¡£¡£ ¡£¡£JSSLoaderµÄһЩ±äÌå±»±àÒë³É.net£¬£¬£¬ £¬ £¬£¬£¬£¬ÁíһЩÊÇc++¡£¡£¡£¡£¡£¡£ ¡£¡£Á½ÖÖJSSLoader¶¼»áÇÔȡĿµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£FIN7ºÜÉÆÓÚʹÓÃÓã²æÊ½ÍøÂç´¹ÂÚ£¬£¬£¬ £¬ £¬£¬£¬£¬²¢ÇÒͨ¹ýÏÂÔØ»òÖ´ÐлìÏýµÄjavascript×÷ΪµÚÒ»½×¶ÎÀ´¶ÔÄ¿µÄ¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£

    Ê×ÏÈ£¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷ÕßÔÚ“user\public”Îļþ¼ÐÖн¨ÉèÒ»¸öÕýµ±µÄwmic.exeµÄ¸±±¾ºÍÒ»¸öxslÃûÌÃÎļþ¡£¡£¡£¡£¡£¡£ ¡£¡£È»ºó£¬£¬£¬ £¬ £¬£¬£¬£¬xslÎļþ½«Ö´ÐÐÀ©Õ¹ÃûΪ.txtµÄÏÖʵ¶ñÒâjs¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃjsÄܹ»Í¨¹ýÖ´Ðм¸¸öWMIÅÌÎÊÏÂÁîÀ´ÍøÂ类ѬȾÖ÷»úµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£×îºóÐÅÏ¢½«±»¼ÓÃܲ¢Ê¹ÓÃPOSTÇëÇó·¢Ë͵½C2ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£ ¡£¡£

    ±ðµÄ£¬£¬£¬ £¬ £¬£¬£¬£¬Çå¾²Ö°Ô±»¹·¢Ã÷ÁËһЩʹÓÃDNSÉøÍ¸Êý¾ÝµÄ±äÌå¡£¡£¡£¡£¡£¡£ ¡£¡£ÕâÖÖÇéÐÎÏ£¬£¬£¬ £¬ £¬£¬£¬£¬¶ñÒâÈí¼þ½«Ê×ÏȼÓÃÜËùÓÐÍøÂçµ½µÄÊý¾Ý£¬£¬£¬ £¬ £¬£¬£¬£¬½«Æä±àÂëΪbase64£¬£¬£¬ £¬ £¬£¬£¬£¬È»ºóʹÓÃnslookup½«±àÂëºóµÄÊý¾Ý·¢ÖÁC2ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£ ¡£¡£

    02

    Ïã¸ÛÍøÕ¾ÔâË®¿Ó¹¥»÷£¬£¬£¬ £¬ £¬£¬£¬£¬Õë¶ÔmacOS×°±¸

    Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ

    Ç鱨ȪԴ£ºhttps://blog.google/threat-analysis-group/analyzing-watering-hole-campaign-using-macos-exploits/

    Ïà¹ØÐÅÏ¢£º

    2021Äê8ÔÂÏÂÑ®£¬£¬£¬ £¬ £¬£¬£¬£¬¹È¸èTAG·¢Ã÷Ïã¸ÛijýÌåºÍij»ú¹¹µÄÍøÕ¾Ô⵽ˮ¿Ó¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃË®¿Ó¹¥»÷ʹÓÃÁËÆ»¹û×°±¸µÄÏà¹ØÁãÈÕÎó²î£¬£¬£¬ £¬ £¬£¬£¬£¬¿ÉÔÚÊܺ¦Õß»úеÉÏ×°ÖÃÒ»¸öºóÃÅÈí¼þ¡£¡£¡£¡£¡£¡£ ¡£¡£

    ±»ºÚÍøÕ¾Ôâ¹¥»÷ÕßÖ²ÈëÁËÁ½¸ö¶ñÒâiframe£¬£¬£¬ £¬ £¬£¬£¬£¬»®·ÖÓÃÓÚ¹¥»÷iOSºÍmacOS×°±¸¡£¡£¡£¡£¡£¡£ ¡£¡£Õë¶ÔiOSµÄ¹¥»÷Á´°üÀ¨CVE-2019-8506µÈÎó²îʹÓᣡ£¡£¡£¡£¡£ ¡£¡£Õë¶ÔmacOSµÄ¹¥»÷Ôò²î±ð£¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÒ»¸ö¼òÆÓµÄHTMLÒ³Ãæ£¬£¬£¬ £¬ £¬£¬£¬£¬¼ÓÔØÁ½¸ö¾ç±¾£¬£¬£¬ £¬ £¬£¬£¬£¬Ò»¸öÓÃÓÚ·´»ã±à£¬£¬£¬ £¬ £¬£¬£¬£¬ÁíÒ»¸öÓÃÓÚÎó²îʹÓÃÁ´¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÎó²îʹÓÃÁ´ÍŽáÁËCVE-2021-1789ºÍCVE-2021-30869¡£¡£¡£¡£¡£¡£ ¡£¡£ÔÚÀÖ³ÉʹÓÃÎó²îºó£¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷Õß»áÔÚÊܺ¦Õß»úеÉÏ×°ÖúóÃÅÈí¼þ£¬£¬£¬ £¬ £¬£¬£¬£¬Ëüͨ¹ýDDS¿ò¼ÜÖеÄÐû²¼-¶©ÔÄÄ£×ÓÀ´ÓëC2ͨѶ¡£¡£¡£¡£¡£¡£ ¡£¡£

    03

    Ê¹ÓÃnamesiloParkingºÍGoogleµÄ×Ô½çËµÒ³ÃæÀ´Èö²¥¶ñÒâÈí¼þ

    Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ

    Ç鱨ȪԴ£ºhttps://blog.netlab.360.com/li-yong-namesilo-parkinghe-googlede-zi-ding-yi-ye-mian-lai-chuan-bo-e-yi-ruan-jian/

    Ïà¹ØÐÅÏ¢£º

    10Ô£¬£¬£¬ £¬ £¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö¿ÉÒɵÄGoELFÑù±¾£¬£¬£¬ £¬ £¬£¬£¬£¬ÆÊÎöµÃÖªÊÇÒ»¸ödownloder£¬£¬£¬ £¬ £¬£¬£¬£¬Ö÷ÒªÈö²¥Íڿ󡣡£¡£¡£¡£¡£ ¡£¡£ÆäʹÓÃnamesiloµÄParkingÒ³Ãæ£¬£¬£¬ £¬ £¬£¬£¬£¬ÒÔ¼°GoogleµÄÓû§×Ô½çËµÒ³ÃæÀ´Èö²¥Ñù±¾¼°ÉèÖ㬣¬£¬ £¬ £¬£¬£¬£¬´Ó¶øÌӱܸú×Ù¡£¡£¡£¡£¡£¡£ ¡£¡£

    ´Ë°¸ÀýÖй¥»÷ÕßʹÓÃÁË“Óû§¿É¿Ø“µÄparkingÒ³Ãæ£¬£¬£¬ £¬ £¬£¬£¬£¬ÔÚ¼á³Öparking״̬µÄʱ¼ä£¬£¬£¬ £¬ £¬£¬£¬£¬ÓÃÓÚ¶ñÒâÈí¼þÍÆ¹ã¡£¡£¡£¡£¡£¡£ ¡£¡£ºÚ¿Í²»ÐèÒªÓÐ×Ô¼ºµÄ»úеºÍIP£¬£¬£¬ £¬ £¬£¬£¬£¬Ö»ÒªÓÃÓòÃû×¢²áÉÌÌṩµÄparkingµÄÒ³Ãæ£¬£¬£¬ £¬ £¬£¬£¬£¬ÒÔ¼°googleµÄ×Ô½çËµÒ³Ãæ£¬£¬£¬ £¬ £¬£¬£¬£¬¾Í¿ÉÒÔÈö²¥×Ô¼ºµÄľÂí£¬£¬£¬ £¬ £¬£¬£¬£¬ÆäÖÐgoogleµÄ×Ô½çËµÒ³ÃæÖаüÀ¨µÄÊÇbase64±àÂëµÄxmrigÍÚ¿óÈí¼þ¡£¡£¡£¡£¡£¡£ ¡£¡£ºÚ¿ÍÍÅ»ïʹÓÃÕâЩ“¹«¹²ÉèÊ©”À´×éÖ¯×Ô¼ºµÄ¶ñÒâÈí¼þÈö²¥Á´Ìõ£¬£¬£¬ £¬ £¬£¬£¬£¬ÒÔ²¿·ÖµÄÌӱܸú×ÙºÍ×èµ²¡£¡£¡£¡£¡£¡£ ¡£¡£

    04

    ¶à½×¶ÎPowerShell¹¥»÷Õë¶Ô¹þÈø¿Ë˹̹

    Åû¶ʱ¼ä£º2021Äê11ÔÂ12ÈÕ

    Ç鱨ȪԴ£ºhttps://blog.malwarebytes.com/threat-intelligence/2021/11/a-multi-stage-powershell-based-attack-targets-kazakhstan/

    Ïà¹ØÐÅÏ¢£º

    11ÔÂ10ÈÕ£¬£¬£¬ £¬ £¬£¬£¬£¬Çå¾²Ö°Ô±·¢Ã÷ÁËÒ»´Î¶à½×¶ÎPowerShell¹¥»÷£¬£¬£¬ £¬ £¬£¬£¬£¬¸Ã¹¥»÷ʹÓÃÁËÒ»¸öð³ä¹þÈø¿Ë˹̹ÎÀÉú²¿µÄÎļþ×÷ÓÕ¶ü¡£¡£¡£¡£¡£¡£ ¡£¡£Òò´Ë£¬£¬£¬ £¬ £¬£¬£¬£¬¸Ã¹¥»÷µÄÄ¿µÄ±»ÒÔΪÊǹþÈø¿Ë˹̹¡£¡£¡£¡£¡£¡£ ¡£¡£

    ¹¥»÷ÕßÊ×ÏÈÈö²¥ÃûΪ“§µ§Ó§Ö§Õ§à§Þ§Ý§Ö§ß§Ú§Ö.rar(֪ͨ.rar)”µÄRARµµ°¸¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ãµµ°¸Îļþ°üÀ¨Ò»¸öͬÃûµÄlnkÎļþ£¬£¬£¬ £¬ £¬£¬£¬£¬lnkÎļþð³äΪÀ´×Ô¹þÈø¿Ë˹̹¹²ºÍ¹úÎÀÉú²¿µÄPDFÎļþ¡£¡£¡£¡£¡£¡£ ¡£¡£·­¿ªlnkÎļþºó£¬£¬£¬ £¬ £¬£¬£¬£¬½«ÏÔʾ¹þÈø¿Ë˹̹¹²ºÍ¹ú¹ú¼ÒÎÀÉú¾ÖÐû²¼µÄCovid19Õþ²ßµÄÐÞÕý°¸ÒÉ»óÊܺ¦Õߣ¬£¬£¬ £¬ £¬£¬£¬£¬¶ø´Ëʱºǫ́½«Ö´Ðжà½×¶Î¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ʼÓÚÖ´ÐÐlnkÎļþ£¬£¬£¬ £¬ £¬£¬£¬£¬¸ÃÎļþŲÓÃPowerShellÖ´ÐÐһЩ²Ù×÷£¬£¬£¬ £¬ £¬£¬£¬£¬ºÃ±Èͨ¹ýautorun×¢²á±íÏîʵÏÖȨÏÞÌáÉýºÍ³¤ÆÚÐÔ£¬£¬£¬ £¬ £¬£¬£¬£¬²¢ÇÒ½«´ÓÒ»¸ö¶ñÒâµÄGitHub´úÂë¿âÏÂÔØºóÐø¶à¸öÓÐÓøºÔØ¡£¡£¡£¡£¡£¡£ ¡£¡£

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.11.11~11.18)

    05

    ¹¥»÷ÕßʹÓÃÓòǰÖÃÊÖÒÕ¶ÔÃåµéÌᳫ¹¥»÷

    Åû¶ʱ¼ä£º2021Äê11ÔÂ08ÈÕ

    Ç鱨ȪԴ£ºhttps://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html

    Ïà¹ØÐÅÏ¢£º

    ½üÆÚ£¬£¬£¬ £¬ £¬£¬£¬£¬CiscoTalos·¢Ã÷ÁËÒ»ÆðʹÓÃCobaltStrikeÌᳫ¹¥»÷µÄ¶ñÒâÔ˶¯¡£¡£¡£¡£¡£¡£ ¡£¡£Ôڴ˰¸ÀýÖй¥»÷Õßͨ¹ýÔÚCloudFrontЧÀÍÉÏʹÓÃÓòǰÖÃÊÖÒÕ½«ÃåµéÕþ¸®ËùÓµÓеÄÓòÃûÖØ¶¨Ïòµ½Æä¿ØÖƵÄЧÀÍÆ÷£¬£¬£¬ £¬ £¬£¬£¬£¬²¢Í¨¹ýÖØÐÂ×¢²á×ÅÃûÓòÃû×÷ΪǰÖÃÓòÃûÀ´Ìӱܼì²â¡£¡£¡£¡£¡£¡£ ¡£¡£

    ¶ñÒâÈí¼þÔÚÊܺ¦Õß»úеÉÏÖ´Ðкó»á·´Éä¼ÓÔØCobaltStrikebeacon.dllÎļþ£¬£¬£¬ £¬ £¬£¬£¬£¬Í¬Ê±ÔÚÔËÐÐʱ¼ÓÔØ¶à¸ö¿â²¢Æ¾Ö¤Ç¶ÈëʽÉèÖÃÎļþÌìÉúbeacon¡£¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÔÚDNSÇëÇóÖÐʹÓÃÎÞº¦µÄÓòÃûÀ´¾ÙÐÐÅþÁ¬£¬£¬£¬ £¬ £¬£¬£¬£¬¶øÏÖʵҪÅþÁ¬µÄ±»·â±ÕÓòÃû½öÔÚ½¨ÉèHTTPSÅþÁ¬ºó·¢³ö£¬£¬£¬ £¬ £¬£¬£¬£¬²¢ÔÚHostÍ·ÖÐЯ´øÁíÒ»¸öC2ÓòÃû¡£¡£¡£¡£¡£¡£ ¡£¡£

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.11.11~11.18)

    ¶ñÒâ´úÂëÇ鱨

    01

    ÐÂGolang¶ñÒâÈí¼þBotenaGo£¬£¬£¬ £¬ £¬£¬£¬£¬Õë¶Ô·ÓÉÆ÷ºÍÎïÁªÍø×°±¸

    Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ

    Ç鱨ȪԴ£ºhttps://cybersecurity.att.com/blogs/labs-research/att-alien-labs-finds-new-golang-malwarebotenago-targeting-millions-of-routers-and-iot-devices-with-more-than-30-exploits

    Ïà¹ØÐÅÏ¢£º

    AT&TAlienLabs·¢Ã÷ÁËÓÃGolang±àдµÄжñÒâÈí¼þBotenaGo¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þÓµÓÐ30¶à¸öÎó²îʹÓÃÄ £¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬ £¬ £¬£¬£¬£¬ÓÐÄÜÁ¦Õë¶ÔÊý°ÙÍò·ÓÉÆ÷ºÍÎïÁªÍø×°±¸·¢¶¯¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£

    BotenaGoÊ×Ïȳõʼ»¯È«¾ÖѬȾ¼ÆÊýÆ÷£¬£¬£¬ £¬ £¬£¬£¬£¬²¢½«ÆäÊä³öµ½ÆÁÄ»ÉÏ£¬£¬£¬ £¬ £¬£¬£¬£¬ÒÔ±ãºÚ¿ÍÏàʶÀÖ³ÉѬȾ×ÜÊý¡£¡£¡£¡£¡£¡£ ¡£¡£È»ºó¶ñÒâÈí¼þ²éÕÒ“dlrs”Îļþ¼Ð£¬£¬£¬ £¬ £¬£¬£¬£¬ÔÚÆäÖмÓÔØshell¾ç±¾Îļþ¡£¡£¡£¡£¡£¡£ ¡£¡£×îºó£¬£¬£¬ £¬ £¬£¬£¬£¬¶ñÒâÈí¼þŲÓú¯Êý“scanerinitexploit”£¬£¬£¬ £¬ £¬£¬£¬£¬À´Æô¶¯¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£¶ñÒâÈí¼þ¿ÉÒÔͨ¹ýÁ½ÖÖ²î±ðµÄ·½·¨ÎüÊÕÕë¶ÔÊܺ¦ÕßµÄÏÂÁ£¬£¬ £¬ £¬£¬£¬£¬Ëü½¨ÉèÁËÁ½¸öºóÃŶ˿Ú31412ºÍ19412¡£¡£¡£¡£¡£¡£ ¡£¡£ÔÚ¶Ë¿Ú19412ÉÏ£¬£¬£¬ £¬ £¬£¬£¬£¬Ëü½«¼àÌýÎüÊÕÊܺ¦IP¡£¡£¡£¡£¡£¡£ ¡£¡£Ò»µ©ÎüÊÕµ½µ½¸Ã¶Ë¿ÚµÄÐÅÏ¢ÅþÁ¬£¬£¬£¬ £¬ £¬£¬£¬£¬Ëü½«±éÀúÎó²îʹÓú¯Êý²¢Ê¹Óøø¶¨µÄIPÖ´ÐС£¡£¡£¡£¡£¡£ ¡£¡£µÚ¶þÖÖ·½·¨£¬£¬£¬ £¬ £¬£¬£¬£¬¶ñÒâÈí¼þ½«Ò»¸ö¼àÌýÆ÷ÉèÖÃΪϵͳIOÓû§ÊäÈ룬£¬£¬ £¬ £¬£¬£¬£¬²¢Í¨¹ýËüÎüÊÕÄ¿µÄ¡£¡£¡£¡£¡£¡£ ¡£¡£ÀýÈ磬£¬£¬ £¬ £¬£¬£¬£¬ÈôÊǶñÒâÈí¼þÔÚÐéÄâ»úÊÜÆ­µØÔËÐУ¬£¬£¬ £¬ £¬£¬£¬£¬Ôò¿ÉÒÔͨ¹ýtelnet·¢ËÍÏÂÁî¡£¡£¡£¡£¡£¡£ ¡£¡£

    02

    Ð¶ñÒâÈí¼þCovid22ÏÖÉí£¬£¬£¬ £¬ £¬£¬£¬£¬ÆÆËðÊܺ¦ÕßϵͳMBR

    Åû¶ʱ¼ä£º2021Äê11ÔÂ11ÈÕ

    Ç鱨ȪԴ£ºhttps://www.fortinet.com/blog/threat-research/to-joke-or-not-to-joke-covid-22-brings-disaster-to-mbr

    Ïà¹ØÐÅÏ¢£º

    FortiGuardʵÑéÊÒ×î½ü·¢Ã÷ÁËÒ»¸öÃûΪCovid22×°ÖóÌÐòµÄжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þ¾ßÓÐÆÆËðÐÔ£¬£¬£¬ £¬ £¬£¬£¬£¬Ëü»áµ¼ÖÂÊÜѬȾµÄ»úеÎÞ·¨Æô¶¯£¬£¬£¬ £¬ £¬£¬£¬£¬²¢²»ÏñÀÕË÷Èí¼þÒ»ÑùÒªÇóÊê½ðÒÔ»Ö¸´ÆÆË𣬣¬£¬ £¬ £¬£¬£¬£¬ËüµÄÄ¿µÄ¾ÍÊÇÆÆËðѬȾϵͳ¡£¡£¡£¡£¡£¡£ ¡£¡£

    ¸Ã¶ñÒâÈí¼þÎļþÃûΪCovid22¡£¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÓÕµ¼Êܺ¦Õß·­¿ªÎļþ£¬£¬£¬ £¬ £¬£¬£¬£¬Covid22»áѯÎÊÊܺ¦ÕßÊÇ·ñÒª¼ÌÐø×°ÖÃCovid22¡£¡£¡£¡£¡£¡£ ¡£¡£Ò»µ©Êܺ¦Õß¼ÌÐø×°Ö㬣¬£¬ £¬ £¬£¬£¬£¬¶ñÒâÈí¼þ»á¼ÓÔØ¼¸¸ö¶ñÒâÎļþ²¢Ç¿ÖÆÖØÆô»úе¡£¡£¡£¡£¡£¡£ ¡£¡£±»ÊͷŵĶñÒâÎļþ»áÖ´ÐÐһϵÁжñÒâ²Ù×÷£¬£¬£¬ £¬ £¬£¬£¬£¬ÈçÒ»Ö±Ìø³öͼƬ»òÎÄ×Öµ¯´°¡¢Ê¹ÓÃÑïÉùÆ÷±¬·¢ÉùÒô¡¢Òƶ¯ÆÁÄ»ÉϵÄÏñËØ¿éµÈ¡£¡£¡£¡£¡£¡£ ¡£¡£×îºó£¬£¬£¬ £¬ £¬£¬£¬£¬¶ñÒâÈí¼þ»á¼ÓÔØ²¢Ö´ÐÐwiper¶ñÒâÈí¼þ£¬£¬£¬ £¬ £¬£¬£¬£¬wiper»áÆÆËðÖ÷Ö¸µ¼¼Í¼(MBR)£¬£¬£¬ £¬ £¬£¬£¬£¬²¢ÔÚÌø³öÒ»¸öµ¯´°ºóÖØÆôϵͳ¡£¡£¡£¡£¡£¡£ ¡£¡£ÓÉÓÚMBR¾ßÓÐÓ²ÅÌÇý¶¯Æ÷·ÖÇøµÄÐÅÏ¢£¬£¬£¬ £¬ £¬£¬£¬£¬²¢³äµ±²Ù×÷ϵͳ(OS)µÄ¼ÓÔØÆ÷£¬£¬£¬ £¬ £¬£¬£¬£¬Òò´Ë±»ÆÆËðMBRµÄ»úе½«ÎÞ·¨ÔÚÖØÐÂÆô¶¯Ê±¼ÓÔØ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£ ¡£¡£

    03

    ¹¥»÷ÕßÃé×¼°¢Àï°Í°ÍECS£¬£¬£¬ £¬ £¬£¬£¬£¬Èö²¥ÍÚ¿óÄ £¿£¿£¿£¿£¿£¿£¿£¿é

    Åû¶ʱ¼ä£º2021Äê11ÔÂ15ÈÕ

    Ç鱨ȪԴ£ºhttps://www.trendmicro.com/en_us/research/21/k/groups-target-alibaba-ecs-instances-for-cryptojacking.html

    Ïà¹ØÐÅÏ¢£º

    Çå¾²Ö°Ô±½üÆÚÔÚ¶à¸ö¶ñÒâÓÐÓøºÔØÖж¼·¢Ã÷ÁËÕë¶Ô°¢ÀïÔÆÐ§ÀÍÆ÷µÄ¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£°¢Àï°Í°ÍECSʵÀý×Ô´øÇå¾²ÊðÀí¡£¡£¡£¡£¡£¡£ ¡£¡£Òò´Ë£¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷ÕßÔÚ¶ñÒâÈí¼þÖÐʹÓÃÁËÌØ¶¨µÄ´úÂ룬£¬£¬ £¬ £¬£¬£¬£¬À´½¨Éè·À»ðǽ¹æÔò£¬£¬£¬ £¬ £¬£¬£¬£¬ÑïÆúÀ´×Ô°¢Àï°Í°ÍÄÚ²¿ÇøÓòºÍµØÇøµÄIP¹æÄ£µÄÊý¾Ý°ü¡£¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬ £¬ £¬£¬£¬£¬Ä¬Èϵİ¢Àï°Í°ÍECSʵÀýÌṩroot»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£ ¡£¡£ÈôÊǵǼÃÜÂ뱻й¶£¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔÖ±½Ó»ñÈ¡rootȨÏÞ¡£¡£¡£¡£¡£¡£ ¡£¡£µ±Ò»¸öÍÚ¿ó¶ñÒâÈí¼þÔÚ°¢Àï°Í°ÍECSÄÚ²¿ÔËÐÐʱ£¬£¬£¬ £¬ £¬£¬£¬£¬Ô¤×°µÄÇå¾²ÊðÆÊÎö·¢ËÍÒ»¸ö¶ñÒâ¾ç±¾ÔËÐеÄ֪ͨ¡£¡£¡£¡£¡£¡£ ¡£¡£Òò´Ë¶ñÒâÈí¼þ»áÔÚÇå¾²ÊðÀí³ÌÐò´¥·¢Ñ¬È¾¾¯±¨Ö®Ç°½«ÆäÐ¶ÔØ£¬£¬£¬ £¬ £¬£¬£¬£¬È»ºó×°ÖÃXMRig¡£¡£¡£¡£¡£¡£ ¡£¡£

    04

    ¶ñÒâÈí¼þEmotet»Ø¹é£¬£¬£¬ £¬ £¬£¬£¬£¬Í¨¹ýTrickBotÖØÐÞ½©Ê¬ÍøÂç

    Åû¶ʱ¼ä£º2021Äê11ÔÂ16ÈÕ

    Ç鱨ȪԴ£ºhttps://www.zscaler.com/blogs/security-research/return-emotet-malware

    Ïà¹ØÐÅÏ¢£º

    2021Äê1Ô£¬£¬£¬ £¬ £¬£¬£¬£¬Ö´·¨²¿·Ö×è¶ÏÁ˶ñÒâÈí¼þEmotet¼°Æä»ù´¡ÉèÊ©£¬£¬£¬ £¬ £¬£¬£¬£¬»¹¾Ð²¶ÁËһЩĻºóµÄÍþв·Ö×Ó¡£¡£¡£¡£¡£¡£ ¡£¡£Ò»Ð©Çå¾²Ñо¿Ö°Ô±ÒÔΪËüÒѾ­Ò»È¥²»¸´·µÁË¡£¡£¡£¡£¡£¡£ ¡£¡£µ«ÔÚÖÐÖ¹ÁËÏÕЩһÄêÖ®ºó£¬£¬£¬ £¬ £¬£¬£¬£¬EmotetÓÖ¾íÍÁÖØÀ´¡£¡£¡£¡£¡£¡£ ¡£¡£ÔçǰÓб¨¸æÏÔʾ£¬£¬£¬ £¬ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÓÚ2021Äê11ÔÂ14ÈÕÔٴηºÆð£¬£¬£¬ £¬ £¬£¬£¬£¬²¢Í¨¹ýTrickBot½©Ê¬ÍøÂç·Ö·¢¡£¡£¡£¡£¡£¡£ ¡£¡£»£»£» £» £ÉÐÓб¨¸æÏÔʾ¸Ã¶ñÒâÈí¼þͨ¹ýµç×ÓÓʼþÈö²¥£¬£¬£¬ £¬ £¬£¬£¬£¬À¬»øÓʼþÔ˶¯ÖÐʹÓӻظ´Á´”ÓʼþÕ½ÂÔ£¬£¬£¬ £¬ £¬£¬£¬£¬Ê¹ÓÃÁËdocm¡¢xlsmºÍzipÃûÌõĸ½¼þ¡£¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬ £¬ £¬£¬£¬£¬Ð°汾µÄEmotetÔÚÐí¶à·½ÃæÓëÒÑÍùµÄ°æÄÚÇéËÆ£¬£¬£¬ £¬ £¬£¬£¬£¬ËƺõÒ²ÔÚʹÓÃHTTPS¶ø²»ÊÇͨË×µÄHTTPÀ´¾ÙÐÐÏÂÁîºÍ¿ØÖÆÍ¨Ñ¶¡£¡£¡£¡£¡£¡£ ¡£¡£

    Îó²îÏà¹ØÇ鱨

    01

    GoogleÐû²¼11Ô¸üУ¬£¬£¬ £¬ £¬£¬£¬£¬ÐÞ¸´ChromeÖеĶà¸öÎó²î

    Åû¶ʱ¼ä£º2021Äê11ÔÂ16ÈÕ

    Ç鱨ȪԴ£ºhttps://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html

    Ïà¹ØÐÅÏ¢£º

    11ÔÂ16ÈÕ£¬£¬£¬ £¬ £¬£¬£¬£¬GoogleÐû²¼Á˱¾ÔÂChromeµÄÇå¾²¸üУ¬£¬£¬ £¬ £¬£¬£¬£¬×ܼÆÐÞ¸´ÁË25¸öÎó²î¡£¡£¡£¡£¡£¡£ ¡£¡£ÆäÖУ¬£¬£¬ £¬ £¬£¬£¬£¬½ÏΪÑÏÖØµÄÊÇÔÚýÌåÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-38008£©¡¢V8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-38007£©ºÍ¼ÓÔØÆ÷ÖÐÊͷźóʹÓÃÎó²î£¨CVE-2021-38005£©µÈ¡£¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬ £¬ £¬£¬£¬£¬»¹ÐÞ¸´ÁËÖ¸ÎÆÊ¶±ðÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-38013£©ºÍSwiftshaderÖеÄÔ½½çдÈ루CVE-2021-38014£©µÈÎó²î¡£¡£¡£¡£¡£¡£ ¡£¡£

    VMwarevCenterServerȨÏÞÌáÉýÎó²îͨ¸æ

    Åû¶ʱ¼ä£º2021Äê11ÔÂ12ÈÕ

    Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/zwiAQIrFuaDKxfvpJHNqyg

    Ïà¹ØÐÅÏ¢£º

    VMwarevCenterServerÌṩÁËÒ»¸ö¿ÉÉìËõ¡¢¿ÉÀ©Õ¹µÄƽ̨£¬£¬£¬ £¬ £¬£¬£¬£¬ÎªÐéÄ⻯ÖÎÀíµÓÚ¨ÁË»ù´¡¡£¡£¡£¡£¡£¡£ ¡£¡£VMwarevCenterServer£¨ÒÔǰ³ÆÎªVMwareVirtualCenter£©£¬£¬£¬ £¬ £¬£¬£¬£¬¿É¼¯ÖÐÖÎÀíVMwarevSphereÇéÐΣ¬£¬£¬ £¬ £¬£¬£¬£¬ÓëÆäËûÖÎÀíÆ½Ì¨Ïà±È£¬£¬£¬ £¬ £¬£¬£¬£¬¼«´óµØÌá¸ßÁËITÖÎÀíÔ±¶ÔÐéÄâÇéÐεĿØÖÆ¡£¡£¡£¡£¡£¡£ ¡£¡£

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015ÍøÂçÇ徲ЧÀÍÈÈÏß

95015ÍøÂçÇ徲ЧÀÍÈÈÏß

ɨһɨ¹Ø×¢

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! ÔÚÏ߿ͷþ Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015

Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ

ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿