ÃÀ¹úÌìÈ»Æø¹Ü·ÔËÓªÉÌÔâµ½ÀÕË÷Èí¼þ¹¥»÷£»SharePointÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2019-0604)

°ä²¼¹¦·ò 2020-02-19

1.ÃÀ¹úÌìÈ»Æø¹Ü·ÔËÓªÉÌÔâµ½ÀÕË÷Èí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÃÀ¹úºÓɽ°²È«ÊýÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨DHS CISA£©°ä²¼µÄ´«µÝ£¬Ò»¼Òδ¾ßÃûµÄÃÀ¹úÌìÈ»ÆøÑ¹Ëõ¹¤³§ÔâÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÔËÓªÖжÏÁËÁ½ÌìµÄ¹¦·ò¡£CISA°µÊ¾¹¥»÷ÕßÊ×ÏÈÀûÓô¹µöÁ´½Ó»ñµÃÁ˶ԸÃ×éÖ¯ITÍøÂçµÄ½Ó¼û£¬¶øºóתÏòÆäOTÍøÂç²¢²¿ÊðÁËÉÌÓÃÀÕË÷Èí¼þ¡£¸ÃÈí¼þͬʱÔÚITºÍOTÍøÂçÉ϶Թ«Ë¾µÄÊý¾Ý½øÐмÓÃÜ£¬ÒÔ×î´óˮƽµØ·ÛËéÆóÒµ£¬¶øºó²ÅÒªÇóÖ§¸¶Êê½ð¡£¸ÃÀÕË÷Èí¼þ²¢Î´Ó°ÏìÈκÎPLC£¬µ«ÈËÀà²Ù×÷Ô±ÎÞ·¨»ã×ܺͶÁÈ¡Óйع¤Òµ¹ý³ÌÖеÄÊý¾Ý£¬ÀýÈçHMI¡¢Êý¾Ýº¹Çà¼Í¼ºÍÂÖѯ·þÎñÆ÷£¬´Ó¶øµ¼ÖÂÔ±¹¤ÎÞ·¨°ÑÎչܷÉèÊ©µÄÔËÐÐÇé¿ö¡£¹Ü·ÔËÓªÉÌÖ´ÐÐÁË¡°ÓдòËãµÄ¡¢ÊܿصĹعء±´ëÊ©£¬ÒÔÔ¤·À²¢Ô¤·ÀÈκÎÊÂÎñµÄ²úÉú¡£CISA°µÊ¾ÔËÓªÖжϳÖÐøÁËÔ¼Á½Ì죬¶øºó¸´Ô­ÁËÕý³£ÔË×÷¡£CISAûÓÐй©ÀÕË÷Èí¼þµÄÃû³Æ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/dhs-says-ransomware-hit-us-gas-pipeline-operator/


2.SharePointÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2019-0604)


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÔ±Dhiraj Mishra·¢ÏÖSharePoint´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0604£©£¬¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâSharePointÊý¾Ý°üÀ´ÀûÓø÷ì϶¡£Ó¡¶È˰Îñ¾Ö¹ÙÍø£¨incometaxindia.gov.in£©¼°ÂéÊ¡Àí¹¤µÄ˹¡ÖÎÀíÑ§ÔºÍøÕ¾¶¼Êܵ½¸Ã·ì϶µÄÓ°Ïì¡£×êÑÐÈËÔ±±ðÀëÔÚ2ÔÂ12ÈÕºÍ13ÈÕ֪ͨÁËCERT-InºÍMIT°²È«ÍŶÓ£¬ÕâÁ½¸öÍøÕ¾¶¼ÒѾ²Ä¬½¨¸´Á˸÷ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/98043/hacking/sharepoint-rce.html


3.·¸×ïÍÅ»ïAPT-C-23ÓÕÆ­ÒÔÉ«Áйú·ÀÊ¿±ø×°ÖöñÒâÈí¼þ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÒÔÉ«Áйú·À¾ü£¨IDF£©°µÊ¾¹þÂí˹¼¤½ø×éÖ¯ÀûÓÃÃÀÅ®µÄÕÕÆ¬ÓÕÆ­ÒÔÉ«Áйú·ÀÊ¿±ø×°ÖöñÒâÈí¼þ£¬¸Ã¹¥»÷Õß±»¼ø±ðΪAPT-C-23¡£IDF½²»°ÈËHedy Silberman³Æ¹¥»÷Õß´´½¨ÁËÁù¸öÅ®ÐÔ½ÇÉ«£¬Í¨¹ý¶àÖÖÐÂÎÅ´«µÝƽ̨£¨Facebook¡¢WhatsApp¡¢Telegram¡¢Instagram£©ÓëÊ¿±øÌ¸Ì죬¶øºóÓÕʹËûÃÇ´ÓÒ»¸öÁ´½ÓÖÐÏÂÔØ¾Ý³ÆÀàËÆÓÚSnapchatµÄAPP¡£ÕâЩAPPÖ»ÊÇÊÖ»úÔ¶¿ØÄ¾Âí£¨MRAT£©µÄ¼Ù×°£¬¶ñÒâÈí¼þ½«Í¨¹ýMQTTºÍ̸ÓëC2·þÎñÆ÷½øÐÐͨѶ£¬²¢Äܹ»ÍøÂçÉ豸µÄÐÅÏ¢£¬Ô̺¬µç»°ºÅÂë¡¢GPSÐÅÏ¢¡¢´æ´¢Êý¾ÝºÍSMSÐÂÎÅ¡£IDFÖ¸³ö¸Ã¶ñÒâÈí¼þ»¹Äܹ»ÅÄÕÕ¡¢ÇÔÈ¡ÁªÏµÈËÁбíÒÔ¼°ÏÂÔØºÍÖ´ÐÐÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-group-catfishes-israeli-soldiers-into-installing-mobile-rat/


4.°®ºÉ»ªÖÝÒ½ÁƱ£½¡¹«Ë¾MCHCй¶Լ7500Ãû»¼ÕßÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°®ºÉ»ªÖÝÒ½ÁƱ£½¡¹«Ë¾£¨MCHC£©ÔÚÖÜÒ»°ä²¼µÄÐÂÎÅÖгÆ£¬¸Ã×éÖ¯ÓÚ2019Äê12ÔÂ19ÈÕ·¢ÏÔìäµç×ÓÓʼþϵͳÔâµ½¹¥»÷£¬Ô¼ÓÐ7500Ãû»¼ÕßµÄÒ½ÁÆÐÅÏ¢¿ÉÄÜй¶¡£¹¥»÷ÕßÔÚ2019Äê10ÔÂ28ÈÕÖÁ2020Äê1ÔÂ20ÈÕÖ®¼ä½Ó¼ûÁ˶à¸öÔ±¹¤µÄµç×ÓÓʼþÕË»§£¬¿ÉÄÜÇÔÈ¡µÄ»¼ÕßÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢±£ÏÕÐÅÏ¢ºÍÁÙ´²ÐÅÏ¢£¨ÀýÈç¾ÍÕïÔ­Òò£©¡£¸Ã×éÖ¯°µÊ¾²¿ÃÅ»¼ÕßµÄÉç»á°²È«ºÅÂë¿ÉÄÜÒ²ÔâÇÔÈ¡¡£¸Ã×éÖ¯°µÊ¾ËùÓÐMCHCÔ±¹¤¶¼±ØÐë³ÁÉèÆäµç×ÓÓʼþÕÊ»§ÃÜÂë²¢½ÓÊÜеÄÍøÂ簲ȫÅàѵ¡£ÐÂΟ廹³ÆÊÜÓ°ÏìµÄ»¼ÕßÄܹ»Í¨¹ýMCHC»ñµÃÒ»ÄêµÄÐÅÓþ¼à¿Ø·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.desmoinesregister.com/story/news/2020/02/17/monroe-iowa-county-hospital-patients-data-breach-victims/4790481002/


5.AZORultľÂíбäÖÖ¼Ù×°³ÉProtonVPN×°Ö÷¨Ê½´«²¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±¹Û²ìµ½AZORultľÂíµÄбäÖÖ¼Ù×°³ÉProtonVPN×°Ö÷¨Ê½½øÐзַ¢¡£¸Ã¹¥»÷»î¶¯×Ô2019Äê11ÔÂÆðÍ·£¬¹¥»÷Õßͨ¹ýÏò¶íÂÞ˹ע²áÉÌ×¢²áÓòÃû¡°protonvpn[.]store¡±À´ÌáÒé´Ë¹¥»÷»î¶¯¡£¹¥»÷ÕßʹÓöñÒâ¸æ°××÷ΪÆä³õʼϰȾý½é£¬AZORult½«ÍøÂçÊܺ¦ÕßµÄϵͳ»·¾³Êý¾Ý£¬²¢½«Æä·¢Ë͵½Î»ÓÚaccounts[.]protonvpn[.]storeµÄC2·þÎñÆ÷¡£¸ÃľÂí»¹Äܹ»´Ó±¾µØÇ®°üÇÔÈ¡¼ÓÃÜÇ®±Ò£¨Electrum¡¢Bitcoin¡¢EtheriumµÈ£©£¬´ÓFileZillaÇÔÈ¡FTPµÇ¼ÃûºÍÃÜÂëÒÔ¼°ÇÔÈ¡µç×ÓÓʼþÍ´´¦ºÍä¯ÀÀÆ÷cookieµÈÃô¸ÐÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/featured/azorult-trojan-disguised-itself-as-fake-protonvpn-installer/


6.×êÑÐÍŶӰ䲼Gamaredon APT¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Yoroy-Cybaze ZLabµÄ°²È«×¨¼Ò¶ÔGamaredon APTʹÓõĶñÒâÈí¼þ½øÐÐÁ˾ßÌåµÄ·ÖÎö¡£Gamaredon×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬ÆäÖØÒªÓë¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÄµØÔµÕþÖÎÓйØ¡£¸Ã×éÖ¯×ʹÓõĶñÒâÈí¼þÖ²È뷨ʽΪPteranodon»òPterodo£¬ËüÓɶ༶ºóÃÅ×é³É£¬Ö¼ÔÚÍøÂçÃô¸ÐÐÅÏ¢»òά³ÖÊÜϰȾ»úеµÄ½Ó¼ûȨÏÞ¡£PterodoÖØÒªÍ¨¹ýÕë¶Ô¾üÊÂÈËÔ±µÄ´¹µö»î¶¯·Ö·¢£¬×î½üµÄÒ»²¨¹¥»÷º£³±Äܹ»×·ÒäÖÁ2019Äê11Ô¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/97992/apt/gamaredon-espionage-campaign.html