Ó¢¹ú³Æ¶íDZͧÕýÍþв³ÐÔØ³¬¹ý95%¹ú¼ÊÊý¾ÝµÄº£µ×µçÀÂ

°ä²¼¹¦·ò 2022-01-13

Ó¢¹ú³Æ¶íDZͧÕýÍþв³ÐÔØ³¬¹ý95%¹ú¼ÊÊý¾ÝµÄº£µ×µçÀÂ


Ó¢¹ú³Æ¶íDZͧÕýÍþв³ÐÔØ³¬¹ý95%¹ú¼ÊÊý¾ÝµÄº£µ×µçÀÂ.png


ýÌå1ÔÂ9ÈÕ±¨Â·£¬Ó¢¹ú¹ú·À²¿³¤Tony Radakin³Æ£¬¶íÂÞ˹DZͧÔÚÍþвº£µ×ÍøÂçµçÀÂÍøÂç¡£º£µ×µçÀ³ÐÔØ³¬¹ý95%µÄ¹ú¼ÊÊý¾Ý£¬½öÔÚ½ðÈÚÁìÓò£¬ËüÿÌì¾Í³ÐÔØ×ÅÔ¼10ÍòÒÚÃÀÔªµÄÂòÂô¡£Ó¢¹úµ±¾Ö³Æ£¬½ü20ÄêÖжíÂÞ˹µÄˮϻÏÔÖøÔö³¤£¬ËûÃÇÔøÔÚ2020Äê12Ô»÷ÖÐÒ»ËÒ¶íÂÞ˹DZͧ¡£×êÑÐÈËÔ±°µÊ¾£¬¼äµýÍŻﻹÄܹ»Í¨¹ýÔÚµçÀÂÔì×÷¹ý³ÌÖÐÖ²ÈëºóÃÅÀ´ÇÔÌý´«ÊäµÄÊý¾Ý¡£


https://securityaffairs.co/wordpress/126459/security/undersea-cables-protection.html


×êÑÐÍŶÓÅû¶ÐÂÀÕË÷Èí¼þNight Sky½üÆÚ¹¥»÷µÄϸ½Ú


¾ÝýÌå1ÔÂ6ÈÕ±¨Â·£¬Malware Hunter Team·¢ÏÖÁËÐÂÀÕË÷Èí¼þNight Sky¡£¸ÃÍÅ»ïµÄ»î¶¯ÆðÍ·ÓÚ12ÔÂ27ÈÕ£¬Í¬ÑùʹÓÃÁËË«³ÁÀÕË÷Õ½Êõ¡£´Ë±í£¬Night Sky²¢Î´Ê¹ÓÃTorÍøÕ¾ÓëÖ¸±ê½»É棬¶øÊÇʹÓÃÓʼþµØÖ·ºÍÔËÐÐRocket.ChatµÄÍøÕ¾¡£ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÏÔʾÒÑÓÐ2¸ö±»¹¥»÷Ö¸±ê£¬Ò»¸öÀ´×ÔÃϼÓÀ­¹ú£¬ÁíÒ»¸öÀ´×ÔÈÕ±¾£¬ËüÃÇÆäÖÐÖ®Ò»±»ÀÕË÷800000ÃÀÔª¡£


https://www.bleepingcomputer.com/news/security/night-sky-is-the-latest-ransomware-targeting-corporate-networks/


Malwarebytes·¢ÏÖPatchworkÕë¶Ô¿ÆÑÐÐÐÒµµÄ¹¥»÷»î¶¯


MalwarebytesÔÚ1ÔÂ7ÈÕ°ä²¼µÄ»ã±¨ÖаµÊ¾£¬Ó¡¶ÈAPT×éÖ¯PatchworkµÄ¿ª·¢ÏµÍ³±»×Ô¼ºµÄRATϰȾ£¬µ¼ÖÂÆÁÄ»½ØÍ¼ºÍ¼üÅ̼ͼµÈÐÅϢй¶¡£Í¨¹ýÕâЩÐÅÏ¢£¬×êÑÐÍŶÓÈ·¶¨Á˸ÃÍÅ»ïÔÚ½üÆÚµÄ¹¥»÷»î¶¯¡£2021Äê11ÔÂÏÂÑ®ÖÁ12ÔÂÉÏÑ®£¬¸ÃÍÅ»ï¼ÙÒâ°Í»ù˹̹µ±¾Ö£¬ÀûÓöñÒâRTFÎļþ·Ö·¢Ò»ÖÖÃûΪRagnatelaµÄBADNEWS RATбäÌå¡£Õâ´Î¹¥»÷µÄÖ¸±êÔ̺¬°Í»ù˹̹¹ú·À²¿¡¢ÒÁ˹À¼±¤¹ú·À´óѧºÍÀ­ºÏ¶û´óѧÉúÎï¿ÆÑ§Ñ§ÔºµÈ¡£


https://blog.malwarebytes.com/threat-intelligence/2022/01/patchwork-apt-caught-in-its-own-web/


Google DocsÆÀÂÛÖ°Äܱ»´¹µö»î¶¯ÓÃÀ´·¢ËͶñÒâÐÅÏ¢ 


1ÔÂ6ÈÕ£¬°²È«¹«Ë¾Avanan°ä²¼ÁËÕë¶ÔOutlookÓû§µÄ´¹µö»î¶¯µÄ·ÖÎö»ã±¨¡£Õâ´Î»î¶¯µÄ¹¥»÷Á´¼«¶Èµ¥Ò»£¬¹¥»÷Õ߯ð³õ´´½¨Ò»¸öGoogle Doc£¬²¢ÏòÆäÔö³¤Ò»ÌõÆÀÂÛ£¬¸ÃÆÀÂÛÔ̺¬¶ñÒâÁ´½Ó£¬²¢Ê¹Óá°@¡±À´Ìá¼°Ö¸±ê¡£¶øGoogleÔò»á×Ô¶¯ÏòÖ¸±ê·¢ËÍÒ»·âµç×ÓÓʼþ£¬Í¨ÖªÆäÓÐÌá¼°ËûÃǵÄÐÂÆÀÂÛ£¬²¢»áÏÔʾÔ̺¬¶ñÒâÁ´½ÓÔÚÄ򵀮ëÈ«ÆÀÂÛ¡£ÓÉÓÚÕâЩÓʼþÀ´×ÔGoogle£¬Òò¶ø°²È«½â¾ö¹æ»®²»»á½«ËüÃÇÏóÕ÷Ϊ¶ñÒâ¡£


https://securityaffairs.co/wordpress/126375/hacking/google-docs-comment-phishing.html


ŵ¶ÙÔÚÓû§µçÄÔÖÐÇ¿Ôì×°ÖÃÍÚ¿óÈí¼þNorton Crypto


ýÌå1ÔÂ7ÈÕ±¨Â·£¬É±¶¾Èí¼þNorton 360»áÔÚÓû§µçÄÔÖÐÇ¿Ôì×°ÖÃÍÚ¿óÈí¼þNorton Crypto¡£¾ÝϤ£¬¸ÃÈí¼þÔÚÈ¥Äê6Ô±»ÄÉÈëNortonɱ¶¾Èí¼þ£¬¿ÉÔ®ÊÖÓû§ÀûÓÃÏÔ¿¨×¬È¡¶î±íÊÕÈ루Óû§±£Áô85%ÊÕÈ룬ÆäÓà±»NortonLifeLock³é³É£©¡£²¿ÃÅÓû§°µÊ¾£¬¸Ã¿ó¹¤Èí¼þ»á×Ô¶¯×°Ö㬲¢ÇÒ³ý·ÇÐ¶ÔØÕû¸öɱ¶¾Èí¼þ£¬²»È»²»Äܵ¥¶Àɾ³ý¡£Norton»ØÓ¦³ÆNorton Crypto×÷ΪһÏî¿ÉѡְÄÜÌṩ£¬Î´¾­Óû§Ðí²»»áÆôÓá£


https://www.hackread.com/norton-antivirus-installs-cryptominer-way-out/


×êÑÐÈËÔ±ÔÚ16¸ö³£ÓõÄURL½âÎö¿âÖз¢ÏÖ8¸ö°²È«·ì϶


¾ÝýÌå1ÔÂ10ÈÕ±¨Â·³Æ£¬°²È«¹«Ë¾ClarotyºÍSynkµÄ½áºÏ×êÑÐÅû¶ÁË8¸öзì϶µÄϸ½Ú¡£×êÑз¢ÏÖ16¸öURL½âÎö¿âÖдæÔÚ²»Ò»ÖºͻìºÏÎÊÌ⣬ÕâЩÎÊÌâ¿É±»ÓÃÀ´ÈƹýÑéÖ¤²¢Îª¸÷À๥»÷¹¥»÷ÔØÌå´ò¿ª´óÃÅ¡£Õâ´ÎÅû¶µÄ·ì϶Ô̺¬Belledonne¡¯s SIP Stack(CVE-2021-33056)¡¢Video.js(CVE-2021-23414)¡¢Nagios XI(CVE-2021-37352)ºÍFlask-security-too(CVE-2021-32618)µÈ¡£Ä¿Ç°£¬·ì϶Òѱ»¸÷×ÔµÄÊØ»¤ÈËÔ±½¨¸´¡£


https://thehackernews.com/2022/01/researchers-find-bugs-in-over-dozen.html


°²È«¹¤¾ß


statiStrings


statiStrings ÊÇ YARA ¹æ¶¨µÄ×Ö·û´®Í³¼ÆÍÆËãÆ÷¡£


https://github.com/Sh3llyR/statiStrings


inject assembly


 ÔÚÏÖÓйý³ÌÖÐÖ´ÐÐ .NET£¬¿É´úÌæ Cobalt Strike µÄ´«Í³ fork ºÍ run Ö´ÐС£


https://github.com/kyleavery/inject-assembly


°²È«·ÖÎö


ÃÀ¹úNCSCºÍDoS°ä²¼Õë¶ÔóÒ׼ල¹¤¾ßµÄÖ¸ÄÏ


ÃÀ¹úNCSCºÍ¹úÎñÔº°ä²¼½áºÏÖ¸ÄÏ£¬ÌṩÁËÕмÜʹÓÃóÒ׼ල¹¤¾ß½øÐеĹ¥»÷µÄ×î¼Ñʵ¼Ê¡£


https://securityaffairs.co/wordpress/126497/digital-id/defending-against-surveillance-tools.html


CVE-2021-43326£ºÌáȨ·ì϶


Automox Agent 32´æÔÚ±¾µØÈ¨ÏÞÌáÉý·ì϶¡£


https://cxsecurity.com/issue/WLB-2022010046