FIN6¼°ÔËÓªTrickBotµÄÍÅ»ï½áºÏµÄ¹¥»÷»î¶¯£»HMR¹«Ë¾Ôâµ½ÀÕË÷Èí¼þMaze¹¥»÷
°ä²¼¹¦·ò 2020-04-091.Ò©Îï²âÊÔ¹«Ë¾HMRÔâµ½ÀÕË÷Èí¼þMaze¹¥»÷
Ò©Îï²âÊÔ¹«Ë¾HMRÔâµ½ÀÕË÷Èí¼þMaze¹¥»÷£¬²¢ÇÒ²¿ÃÅ×ÔÔ¸ÕßÐÅÏ¢±»µÁ¡£¸Ã¹¥»÷²úÉúÔÚ3ÔÂ14ÈÕ£¬Maze¹¥»÷ÕßÇÔÈ¡ÁËHMRÍøÂçÉÏÍйܵÄÊý¾Ý²¢¶ÔÆäÍÆËã»ú½øÐмÓÃÜ¡£ÓÉÓڸù«Ë¾»Ø¾øÖ§¸¶Êê½ð£¬MazeÍÅ»ïÓÚ3ÔÂ21ÈÕÔÚÆäÍøÕ¾Éϰ䲼Á˲¿Ãű»µÁµÄÊý¾Ý¡£Æ¾¾ÝHMRµÄÊý¾Ýй¶֪ͨ£¬Ê§ÇԵļͼÔ̺¬ÁËÒÔD¡¢G¡¢I»òJ¿ªÍ·µÄ×ÔÔ¸ÕßÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éí·ÝÖ¤Ã÷Îļþ¡¢½¡È«µ÷²é±í¡¢ÔÞ³ÉÊé¡¢²¿Ãżì²âÁ˾ֵȡ£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/drug-testing-firm-sends-data-breach-alerts-after-ransomware-attack/
2.Bitdefender×êÑÐÍŶӷ¢ÏÖÐÂIoT½©Ê¬ÍøÂçdark_nexus
Bitdefender×êÑÐÈËÔ±×î½ü·¢ÏÖÁËÒ»¸öеÄIoT½©Ê¬ÍøÂ磬ËüÔ̺¬Á˳¬¹ý´óÎÞÊýIoT½©Ê¬ÍøÂçºÍ¶ñÒâÈí¼þµÄÐÂÖ°ÄÜ¡£×êÑÐÈËԱƾ¾Ý½©Ê¬ÍøÂçʹÓõĵÄ×Ö·û´®½«Æä¶¨ÃûΪ¡°dark_nexus¡±¡£Ö»¹Üdark_nexus³ÁÓÃÁËһЩQbotºÍMirai´úÂ룬µ«ÆäÖ÷ÌâÄ£¿é´ó¶àÊÇÔÉúµÄ¡£Ö»¹Ü¸Ã½©Ê¬ÍøÂç¿ÉÄÜÓëÒÔǰÒÑÖªµÄIoT½©Ê¬ÍøÂç¹²ÏíijЩְÄÜ£¬µ«ÊÇÆä²¿ÃÅÄ£¿éµÄ¿ª·¢·½Ê½Ê¹ÆäÖ°ÄÜÔ½·¢×³´ó£¬ÀýÈçÓÐÐ§ÔØºÉÕë¶Ô12ÖÖ·ÖÆçµÄCPU¼Ü¹¹½øÐбàÒ룬²¢Æ¾¾ÝÊܺ¦ÕßµÄÅäÖö¯Ì¬´«µÝ¡£dark_nexus»¹¹ÖÒìµØÊ¹ÓûùÓÚȨ³ÁºÍãÐÖµµÄÆÀ·ÖϵͳÀ´ÆÀ¹ÀÄÄЩ¹ý³Ì¿ÉÄÜ×é³É·çÏÕ£¬²¢É±ËÀËùÓг¬¹ý¿ÉÒÉãÐÖµµÄÆäËü¹ý³Ì¡£
ÔÎÄÁ´½Ó£º
https://labs.bitdefender.com/2020/04/new-dark_nexus-iot-botnet-puts-others-to-shame/
3.FIN6¼°ÔËÓªTrickBotµÄÍÅ»ï½áºÏµÄ¹¥»÷»î¶¯
IBM X-Force×êÑÐÈËÔ±°µÊ¾£¬ÔÚ×î½üµÄÍøÂç¹¥»÷Öз¢ÏÖÁËFIN6µÄºÛ¼££¬ÕâЩ¹¥»÷»î¶¯×î³õÀûÓÃTrickBotľÂíϰȾÊܺ¦Õߣ¬¶øºó×îÖÕÏÂÔØÁËAnchorºóÃÅ¡£×êÑÐÈËÔ±³ÆÕâÁ½¸ö·¸×ï×éÖ¯-TrickBotµÄÔËÓªÍÅ»ïÒÔ¼°FIN6-ÒѾ½øÐкÏ×÷£¬ÕâÊÇÍøÂç·¸×OÌåÏÖÓкÏ×÷Ç÷ÏòÖеġ°ÐµÄΣÏÕתÕÛ¡±¡£AnchorÖÁÉÙÄܹ»×·Òäµ½2018Äê£¬ËÆºõÊÇÓÉTrickBotµÄÔËÓªÍÅ»ï±àдµÄ¡°¡°¶àºÏÒ»¹¥»÷¿ò¼Ü¡±£¬ËüÓɸ÷Àà×ÓÄ£¿é×é³É£¬Äܹ»Ô®ÊÖ¹¥»÷ÕßÔÚÍøÂçÉϺáÏò´«²¼£¨ÀýÈç×°ÖúóÃÅ£©¡£Í¬Ê±TrickBotµÄÁíÒ»¸ö¹¤¾ßPowerTrickÖØÒªÓÃÓÚÔÚÊÜϰȾµÄ¸ß¼ÛÖµÖ¸±ê£¨ÀýÈç½ðÈÚ»ú¹¹£©ÄÚ²¿½øÐÐÒþÉí¡¢ÓÆ¾ÃÐԺͿúËÅ¡£IBM X-ForceÖ¸³öFIN6²Î¼ÓÁËÀûÓÃAnchorºÍPowerTrickµÄ¹¥»÷£¬Æä´æÔÚµÄ×î´óÖ¸±êÊǹ¥»÷ÖÐʹÓõÄ×°ÔØ·¨Ê½£¨Terraloader£©ºÍºóÃÅ£¨More_eggs£©¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/fin6-and-trickbot-combine-forces-in-anchor-attacks/154508/
4.¹¥»÷ÕßÀÄÓÃMalwarebytesÆ·ÅÆ·Ö·¢RaccoonľÂí
×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÀÄÓÃMalwarebytesÆ·ÅÆµÄ¶ñÒâ»î¶¯£¬¹¥»÷Õß´´½¨ÁËÒ»¸ö·ÂðµÄMalwarebytesÍøÕ¾£¬¸ÃÍøÕ¾ÓÃÓÚ·Ö·¢RaccoonľÂí¡£¸Ã¶ñÒâÓòÃûÊÇmalwarebytes-free[.]com£¬ÔÚ3ÔÂ29ÈÕͨ¹ýÓòÃû×¢²áÉÌREG.RU LLC×¢²á£¬µ±Ç°ÍйÜÔÚ¶íÂÞ˹µÄIP 173.192.139[.]27ÉÏ¡£¸ÃÍøÕ¾ÉϵÄJavaScript´úÂë¶Î»á²é³·Ã¿ÍµÄä¯ÀÀÆ÷ÀàÐÍ£¬ÈôÊÇÊÇInternet Explorer£¬Ôò»á½«Óû§³Á¶¨ÏòÖÁFallout EKµÄ¶ñÒâURL£¬²¢×îÖÕ×°ÖÃRaccoon¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/exploits-and-vulnerabilities/2020/04/copycat-criminals-abuse-malwarebytes-brand-in-malvertising-campaign/
5.¹È¸è°ä²¼Chrome°²È«¸üУ¬½¨¸´32¸ö·ì϶
¹È¸èÒÑÓÚ4ÔÂ7ÈÕÏòWindows¡¢macOSºÍLinux°ä²¼ÁËChrome 81£¬³ýÁËbug½¨¸´¡¢ÐÂÖ°ÄÜÖ®±í£¬¸Ã°æ±¾»¹½¨¸´ÁË32¸ö°²È«·ì϶¡£ÆäÖÐ3¸ö·ì϶µÄÑϳÁÐԵȼ¶Îª¸ß£¬Ô̺¬À©´óÖеÄUAF·ì϶£¨CVE-2020-6454£©¡¢ÒôƵ×é¼þÖеÄUAF·ì϶£¨CVE-2020-6423£©ºÍWebSQLÖеÄÔ½½ç¶Á·ì϶£¨CVE-2020-6455£©¡£ÆäÓà·ì϶µÄÑϳÁÐԵȼ¶ÎªÖлòµÍ¡£´Ë±í£¬¹È¸èÔ´òËãÔÚChrome 81ÖÐÆëȫɾ³ý¶ÔTLS 1.0ºÍ1.1µÄÖ§³Ö£¬µ«ÓÉÓÚ¹Ú×´²¡¶¾µÄÊ¢ÐУ¬¹È¸èÒѾö¶¨½«ÕâÒ»Ðж¯ÍƳٵ½Chrome 84¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/google/chrome-81-released-with-32-security-fixes-and-web-nfc-api/
6.±´¼ÓÀ³½¨¸´Automation StudioÈí¼þÖеĶà¸ö·ì϶
×êÑÐÈËÔ±·¢ÏÖ±´¼ÓÀ³¹¤Òµ×Ô¶¯»¯¹«Ë¾µÄAutomation StudioÈí¼þ´æÔÚ¶à¸ö·ì϶£¬¹©¸øÉÌÒÑÆðÍ·°ä²¼²¹¶¡¡£±´¼ÓÀ³ÊÇÒ»¼ÒλÓڰµØÀûµÄ¹¤Òµ×Ô¶¯»¯¹«Ë¾£¬¾ÝÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©³Æ£¬¸Ã¹«Ë¾µÄ²úÆ·ÔÚÈ«ÇòÁìÓòÄÚʹÓ㬳ö¸ñÊÇÔÚÄÜÔ´¡¢»¯¹¤ºÍ¹Ø¼üÔì×÷ÁìÓò¡£¸Ã¹«Ë¾µÄAutomation Studio°æ±¾4ÊÜÈý¸ö·ì϶µÄÓ°Ï죬ÕâЩ·ì϶ÓëAutomation StudioµÄ¸üзþÎñÓйأ¬Ô̺¬ÌØÈ¨Éý¼¶·ì϶¡¢²»ÆëÈ«µÄͨѶ¼ÓÃܺÍÑéÖ¤ÎÊÌâÒÔ¼°Óë2018Äê·¢ÏÖµÄZip SlipËÁÒâÎļþ¸²¸Ç·ì϶ÓйصÄõè¾¶±éÀú·ì϶¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ִÐÐMITM¹¥»÷²¢¹ýÎÊÈí¼þ¸üйý³Ì¡£±´¼ÓÀ³ÒѾΪ²¿ÃÅÊÜÓ°ÏìµÄ°æ±¾°ä²¼Á˲¹¶¡£¬²¢ÔÚΪÆäÓà°æ±¾½øÐн¨¸´¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/vulnerabilities-br-automation-software-facilitate-attacks-ics-networks


¾©¹«Íø°²±¸11010802024551ºÅ