TP-Link SR20·ÓÉÆ÷0day£»ÀÕË÷Èí¼þDharmaºÍUNNAM3D£»Gustuff¶Ô×¼ÒøÐкͼÓÃÜÇ®±ÒAPP

°ä²¼¹¦·ò 2019-03-29
1¡¢TP-Link SR20·ÓÉÆ÷0day £¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐÐ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸è¿ª·¢ÈËÔ±GarretÅû¶ÁËTP-Link SR20ÖÇÄܼҾÓ·ÓÉÆ÷ÖеÄ0day £¬¸Ã·ì϶ÔÊÐíÍ³Ò»ÍøÂçÖеÄDZÔÚ¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë ¡£GarretÏòTP-Link»ã±¨Á˸÷ì϶ £¬µ«ÔÚ90ÌìÄÚ²¢Î´µÃµ½TP-LinkµÄ»Ø¸´ £¬Òò¶øËû°ä²¼ÁËÕâÒ»·ì϶ ¡£¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÒÔrootÉí·ÝÖ´ÐÐËÁÒâºÅÁî £¬Garret»¹°ä²¼ÁËÓйØPoC ¡£½ØÖÁĿǰTP-LinkÉÐδ½øÐлØÓ¦ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zero-day-tp-link-sr20-router-vulnerability-disclosed-by-google-dev/

2¡¢¼ÓÄôóÓòÃû×¢²á»ú¹¹CIRAÔâÀÕË÷Èí¼þDharma¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÄôó»¥ÁªÍø×¢²áÖÎÀí¾Ö£¨CIRA£©µÄÔ±¹¤Í£³µ³¡ÔâÀÕË÷Èí¼þDharma¹¥»÷ £¬µ¼ÖÂÈκÎÈ˶¼Äܹ»½øÈëÍ£³µ¶øÎÞÐèÑéÖ¤½Ó¼û¿¨ ¡£¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚÐÇÆÚ¶þ £¬µ«ÎÊÌâÉÐδµÃµ½½â¾ö ¡£CIRAÊÇÒ»¸ö·ÇͶ»ú×éÖ¯ £¬ÕƹÜÖÎÀí¼ÓÄô󶥼¶ÓòÃû.CA £¬ÆäÍ£³µ³¡ÏµÍ³ÓɸöÈ˹«Ë¾Precise ParkLinkÕÆ¹ÜÔËÓª ¡£±»Ï°È¾ÏµÍ³ÉÏÏÔʾµÄÊê½ðµ¥¾ÝÖ¸ÏòÀÕË÷Èí¼þDharma £¬¸Ã±äÌ彫.ETHÀ©´óÃû¸½¼ÓÔÚ¼ÓÃܵÄÎļþºó ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-hits-garage-of-canadian-domain-registration-authority/

3¡¢ÐÂÒøÐÐľÂíGustuff £¬¶Ô×¼100¶à¼ÒÒøÐкÍ32¸ö¼ÓÃÜÇ®±ÒAPP

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Group-IB×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÒøÐÐľÂíGustuff £¬¸ÃľÂí¶Ô׼ȫÇò100¶à¼ÒÒøÐм°32¸ö¼ÓÃÜÇ®±ÒAPPµÄÓû§ £¬ÆäÖÐÔ̺¬ÃÀ¹úÒøÐÓ×¢ËÕ¸ñÀ¼ÒøÐÓעĦ¸ù´óÍ¨ÒøÐÓ×¢¸»¹úÒøÐеȶ¥¼¶¹ú¼ÊÒøÐкÍBitPay¡¢Cryptopay¡¢CoinbaseµÈ³ÛÃû±ÈÌØ±ÒÇ®°ü ¡£GustuffÀûÓÃAndroid¸¨ÖúÖ°ÄÜÀ´ÏÔʾÐéαÆÁÄ» £¬²¢¿Éͨ¹ý¶ÁÈ¡ÁªÏµÈËÁбíÀ´·¢ËͶñÒâ×°ÖðüµÄÁ´½Ó ¡£GustuffµÄÖ°ÄÜÔ̺¬C&CͨѶ¡¢¶ÁÈ¡/·¢ËÍSMS¶ÌÐÅ¡¢ÇÔÈ¡Îļþ£¨Ô̺¬ÎĵµÉ¨Ãè¡¢ÆÁÄ»½ØÍ¼¡¢ÕÕÆ¬£©µÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/gustuff-android-malware-targets-100-banking-and-32-cryptocurrency-apps/

4¡¢ÐÂÀÕË÷Èí¼þUNNAM3D £¬ÒªÇóÖ§¸¶50ÃÀÔªµÄÑÇÂíÑ·ÀñÎ│


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÐÂÀÕË÷Èí¼þUNNAM3DÔÚͨ¹ý´¹µöÓʼþ½øÐзַ¢ £¬ÕâЩ´¹µöÓʼþ¼Ù×°³ÉÀ´×ÔAdobeµÄÓʼþ £¬²¢Ô̺¬ÐéαFlash Player¸üеÄÁ´½Ó ¡£UNNAM3D°ó¸¿ÁËÒ»¸öWinRar.exe £¬ÓÃÓÚ½«Óû§µÄÎļþ·ÅÈëÔ̺¬ÃÜÂëµÄѹËõ°üÖÐ £¬²¢ÀÕË÷50ÃÀÔªµÄÑÇÂíÑ·ÀñÎ│ ¡£¸ÃÀÕË÷Èí¼þµÄ¿ª·¢ÈËÔ±³ÆËûÃǹ²·¢ËÍÁËÔ¼3Íò·â´¹µöÓʼþ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/unnam3d-ransomware-locks-files-in-protected-archives-demands-gift-cards/

5¡¢Ë¼¿Æ°ä²¼27¸ö²¹¶¡ £¬½¨¸´IOS XE¼°Ó×ÐÍÆóҵ·ÓÉÆ÷ÖеĶà¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖÜÈý˼¿Æ°ä²¼27¸ö²¹¶¡¸üР£¬½¨¸´ÁËIOS XE²Ù×÷ϵͳ¼°Ó×ÐÍÆóҵ·ÓÉÆ÷£¨RV320ºÍRV325£©ÖеĶà¸ö·ì϶ ¡£Ó°ÏìÕâÁ½¸ö·ÓÉÆ÷µÄ·ì϶±ðÀëÊǺÅÁî×¢Èë·ì϶£¨CVE-2019-1652£©ºÍÐÅϢй¶·ì϶£¨CVE-2019-1653£© £¬Ë¼¿ÆÔøÓÚ1Ô·ݰ䲼ÁËÕâÁ½¸ö·ì϶µÄ½¨¸´²¹¶¡ £¬µ«´Ë¿Ì˼¿Æ³ÆÆäʱµÄ²¹¶¡²¢Î´ÆëÈ«½¨¸´¸Ã·ì϶ ¡£Ë¼¿Æ»¹½¨¸´ÁËIOS XEÖеĺÅÁî×¢Èë·ì϶£¨CVE-2019-1745¡¢CVE-2019-1756ºÍCVE-2019-1755£©µÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cisco-releases-flood-of-patches-for-ios-xe-and-small-business-routers/143228/

6¡¢APT33й¥»÷»î¶¯ £¬Õë¶ÔÃÀ¹úºÍÉ³ÌØ¶à¼Ò¹«Ë¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý±¾ÖÜÈýÈüÃÅÌú¿Ë°ä²¼µÄ»ã±¨ £¬ÒÁÀÊ·¸×ïÍÅ»ïElfin£¨Ò²³ÆAPT33£©³ÖÐøÕë¶ÔÃÀ¹úºÍÉ³ÌØ°¢À­²®µÄÆóÒµ ¡£APT33ÔçÔÚ2015µ×¾ÍÆðÍ·»îÔ¾ £¬²¢Õë¶Ô¿í·ºµÄÆóÒµ £¬Ô̺¬µ±¾Ö¡¢¿ÆÑÓ×¢»¯Ñ§¡¢¹¤³Ì¡¢Ôì×÷¡¢Õ÷ѯ¡¢½ðÈں͵çÐŵÈ ¡£APT33ÔÚ»ý¼«ÀûÓÃ×î½ü·¢ÏÖµÄWinRAR·ì϶£¨CVE-2018-20250£© £¬²¢·Ö·¢NotestukºóÃÅ¡¢StonedrillľÂíºÍÒ»¸öAutoIt±àдµÄºóÃÅ ¡£´Ë±í £¬APT33»¹Óë2018Äê12ÔÂÕë¶ÔÄÜÔ´²¿ÃŵÄShamoon¹¥»÷ÊÂÎñÓйØ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/apt33-cyber-espionage-hacking.html

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù