¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2020Äê8Ô£©

2020-09-03

8Ô £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ £¬ÆäÖÐ £¬WebSphereÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4534£©£¨CVE-2020-4534£©Ó°Ïì½Ï´ó¡£¸ÃÎó²îÓÉÓÚδ׼ȷ´¦Öóͷ£UNC·¾¶¶øµ¼Ö £¬ ¾­ÓÉÍâµØÉí·ÝÈÏÖ¤ºó £¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÍê³É´úÂëÖ´ÐÐ £¬Îó²îÆÀ·ÖΪ7.8·Ö¡£

 

ÁíÍâ £¬±¾ÔÂ΢ÈíÐÞ¸´120¸öÇå¾²ÎÊÌâ £¬CriticalµÄÎó²î¹²ÓÐ16¸ö £¬ImportantµÄÎó²î103¸ö £¬ÇëÏà¹ØÓû§ÊµÊ±¸üв¹¶¡¾ÙÐзÀ»¤¡£

 

¹¥»÷×éÖ¯·½Ãæ £¬º£Á«»¨“OceaLotus"×é֯ʹÓÃMsMpEng¾ÙÐвàÔØ¹¥»÷ £¬TA551¹¥»÷×éÖ¯Õë¶ÔÒÔÓ¢ÓïΪĸÓïµÄÈË·Ö·¢IcedIDÒøÐÐľÂí £¬Transparent Tribe×é֯ʹÓöñÒâÈí¼þNET RATÒÔ¼°Muhstik½©Ê¬ÍøÂçÕë¶Ôº£ÄÚÔÆ·þÎñÆ÷ÐèÒªÒýÆð¹Ø×¢¡£

 

ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨 £¬ÒÔ¼°¹ØÁªµÄIOC £¬¾ù¿ÉÔÚ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄ»ñÈ¡ £¬ÍøÖ·£ºhttps://nti.nsfocus.com/

Ò»¡¢ Îó²îÌ¬ÊÆ

2020Äê08Ô¾ÅÓÎÀÏ¸ç¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼109Îó²î, ÆäÖиßΣÎó²î27¸ö £¬Î¢Èí¸ßΣÎó²î9¸ö¡£

¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

* Êý¾ÝȪԴ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ £¬±¾±íÊý¾Ý×èÖ¹µ½2020.08.28

×¢£º¾ÅÓÎÀÏ¸ç¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»

 

¶þ¡¢ ÍþвÊÂÎñ

1. NSOÌØ¹¤Èí¼þ¹¥»÷¶à¸ç

¡¾±êÇ©¡¿NSO

¡¾Ê±¼ä¡¿2020-08-02

¡¾¼ò½é¡¿

NSOÌØ¹¤Èí¼þ±»¹¥»÷ÕßʹÓù¥»÷¶à¸ç¹«ÃñÉç»á £¬ÆäÖаüÀ¨ÌìÖ÷½ÌÖ÷½Ì¡¢ÄÁʦºÍ×èµ²ÅÉÕþÖμÒ¡£NSOÌØ¹¤Èí¼þ²úƷͨ³£±»³ÆÎªPegasus £¬ÊÇÒ»ÖÖÊÖ»úºÚ¿Í¹¤¾ß £¬¿É»ñÈ¡¶ÔÄ¿µÄÒÆ¶¯×°±¸µÄÍêÈ«»á¼ûȨÏÞ £¬PegasusÔÊÐí¹¥»÷ÕßÌáÈ¡ÃÜÂë¡¢Îļþ¡¢ÕÕÆ¬¡¢ÍøÂçÀúÊ·¼Í¼¡¢ÁªÏµÈËÒÔ¼°Éí·ÝÊý¾ÝµÈÐÅÏ¢ £¬PegasusµÄÄ¿µÄ°üÀ¨ÑÇÖÞ £¬Å·ÖÞ £¬Öж«ºÍ±±ÃÀµÄÊýÊ®¸ö¹ú¼Ò¡£

¡¾²Î¿¼Á´½Ó¡¿

https://citizenlab.ca/2020/08/nothing-sacred-nso-sypware-in-togo/

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC £¬ÆäÖаüÀ¨4¸öÓòÃû£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

2. TAIDOORľÂíαװΪDLLÎļþѬȾĿµÄϵͳ

¡¾±êÇ©¡¿TAIDOOR

¡¾Ê±¼ä¡¿2020-08-02

¡¾¼ò½é¡¿

Taidoor×÷Ϊ·þÎñ¶¯Ì¬Á´½Ó¿âDLL×°ÖÃÔÚÄ¿µÄϵͳÉÏ £¬²¢ÇÒÓÉÁ½¸öÎļþ×é³É £¬µÚÒ»¸öÎļþÊǼÓÔØ³ÌÐò £¬×÷Ϊ·þÎñÆô¶¯ £¬¼ÓÔØ³ÌÐò½âÃܵڶþ¸öÎļþ £¬È»ºóÔÚÄÚ´æÖÐÖ´ÐиÃÎļþ £¬´ËÎļþÊÇÔ¶³Ì»á¼ûľÂí£¨RAT£©¡£

¡¾²Î¿¼Á´½Ó¡¿

https://us-cert.cisa.gov/ncas/analysis-reports/ar20-216a

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡22ÌõIOC £¬ÆäÖаüÀ¨1¸öIP £¬1¸öÓòÃûºÍ20¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

3. NetWalkerÀÕË÷Èí¼þÕë¶ÔÎ÷Å·¹ú¼ÒºÍÃÀ¹ú

¡¾±êÇ©¡¿NetWalker

¡¾Ê±¼ä¡¿2020-08-02

¡¾¼ò½é¡¿

NetWalkerÀÕË÷Èí¼þ×î³õ³ÆÎªMailto £¬×îÔçÔÚ2019Äê8Ô±»·¢Ã÷ £¬×Ô¾õÏÖÒÔÀ´Õë¶ÔÐí¶à²î±ðµÄÄ¿µÄ £¬Ö÷ҪλÓÚÎ÷Å·¹ú¼ÒºÍÃÀ¹ú¡£¹¥»÷Ô˶¯ÖÐNetWalkerÀÕË÷Èí¼þ½«Ëæ»úÀ©Õ¹Ãû¸½¼Óµ½ÊÜѬȾµÄÎļþÖÐ £¬²¢Ê¹ÓÃSalsa20¼ÓÃÜ £¬ËüʹÓÃÒ»ÖÖеķÀÓù¹æ±ÜÊÖÒÕ±»³ÆÎª·´ÉäDLL¼ÓÔØ £¬ÓÃÓÚ´ÓÄÚ´æÖÐ×¢ÈëDLL¡£

¡¾²Î¿¼Á´½Ó¡¿

https://www.mcafee.com//blogs/other-blogs/mcafee-labs/take-a-netwalk-on-the-wild-side/

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡117ÌõIOC £¬ÆäÖаüÀ¨117¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

4. ÍøÂç´¹ÂÚÓʼþÐ®ÖÆMicrosoft365ÕÊ»§

¡¾±êÇ©¡¿NetWalker

¡¾Ê±¼ä¡¿2020-08-02

¡¾¼ò½é¡¿

ÍøÂç×ï·¸Ô½À´Ô½¶àµØÃ°³äÊÜÐÅÍеÄSaaSƽ̨ºÍ¹©Ó¦ÉÌ¡£×î½ü £¬ÔÚÒ»Æð´¹ÂÚ¹¥»÷Ô˶¯ÖÐ £¬µç×ÓÓʼþÖÐÓÐÐí¶àÊÔͼÓÕʹÊÕ¼þÈ˵¥»÷¶ñÒâÁ´½Ó £¬¸ÃÁ´½ÓÖ¸Ïò°üÀ¨Æ¾Ö¤ÍøÂç¶ñÒâÈí¼þµÄÒ³Ãæ £¬¹¥»÷ÕßʹÓÃÊÜѬȾµÄMicrosoft 365ÕÊ»§ÔÚ¼¸¸öСʱÄÚ»á¼û¶à¸öÆäËûÕÊ»§¡£

¡¾²Î¿¼Á´½Ó¡¿

https://www.darktrace.com/en/blog/phishing-from-the-inside-microsoft-365-account-hijack/

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡1ÌõIOC £¬ÆäÖаüÀ¨1¸öÓòÃû£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£ 

 

5. LaoXinWonЯ´øÁ½¸öÀÕË÷²¡¶¾Ñù±¾

¡¾±êÇ©¡¿LaoXinWon

¡¾Ê±¼ä¡¿2020-08-04

¡¾¼ò½é¡¿

LaoXinWonµÄÀÕË÷²¡¶¾Í¨¹ýÈõ¿ÚÁî±¬ÆÆ·½·¨¾ÙÐÐÈö²¥ £¬ËüͬʱЯ´øÁ½¿îÀÕË÷²¡¶¾Ñù±¾ £¬Ò»¿îΪC#±àдµÄÀÕË÷Ä £¿é £¬¼ÓÃÜÌí¼Ó.aesÀ©Õ¹ºó׺£»ÁíÒ»¿îΪDelphi±àдµÄScarabÀÕË÷Ä £¿é £¬¼ÓÃÜÌí¼Ó.lamparÀ©Õ¹ºó׺¡£

¡¾²Î¿¼Á´½Ó¡¿

https://s.tencent.com//research/report/1072.html

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC £¬ÆäÖаüÀ¨2¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

6. PyPI ¹Ù·½¿ÍÕ»Ôârequest¶ñÒâ°üͶ¶¾

¡¾±êÇ©¡¿request¶ñÒâ°ü

¡¾Ê±¼ä¡¿2020-08-05

¡¾¼ò½é¡¿

¹¥»÷Õß½«request¶ñÒâ´¹ÂÚ°üÉÏ´«ÖÁPyPI¹Ù·½¿ÍÕ» £¬²¢Í¨¹ý¸Ã´¹ÂÚ°üʵÑéÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢¼°Êý×ÖÇ®±ÒÃÜÔ¿¡¢ÝªÖ²³¤ÆÚ»¯ºóÃÅ¡¢Ô¶³Ì¿ØÖƵÈһϵÁй¥»÷Ô˶¯¡£

¡¾²Î¿¼Á´½Ó¡¿

https://s.tencent.com//research/report/1073.html

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC £¬ÆäÖаüÀ¨1¸öIPºÍ2¸öÓòÃû£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

7. º£Á«»¨“OceaLotus"×é֯ʹÓÃMsMpEng¾ÙÐвàÔØ¹¥»÷

¡¾±êÇ©¡¿º£Á«»¨

¡¾Ê±¼ä¡¿2020-08-06

¡¾¼ò½é¡¿

¿ËÈÕ £¬¾ÅÓÎÀϸçÍþвÇ鱨£¨NTI£©·¢Ã÷ÁËÒ»Æð½èÓÃWindowsDefenderÖ÷Òª×é¼þMsMpEng.exe¾ÙÐвàÔØ¹¥»÷µÄÊÂÎñ¡£Í¨¹ý¶Ô±¾ÊÂÎñÒÔ¼°¶à¸ö¹ØÁªÊÂÎñµÄÆÊÎö £¬È·ÈϸÃϵÁй¥»÷ÊÂÎñµÄÌᳫÕßΪº£Á«»¨£¨OceanLotus £¬APT32£©×éÖ¯¡£³ýͨÀýÊÖ·¨Ö®Íâ £¬º£Á«»¨×éÖ¯ÔÚÕâÒ»ÔÙ¹¥»÷ÖÐʹÓÃÁËÒ»ÖÖеĻìÏýÊÖÒÕ £¬ÒÔ¼°Ò»¿îеÄÖÐÐÄÔØºÉ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://nti.nsfocus.com/

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡11ÌõIOC £¬ÆäÖаüÀ¨11¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

8. Muhstik½©Ê¬ÍøÂçÕë¶Ôº£ÄÚÔÆ·þÎñÆ÷

¡¾±êÇ©¡¿Muhstik

¡¾Ê±¼ä¡¿2020-08-06

¡¾¼ò½é¡¿

¹¥»÷Õßͨ¹ýSSH±¬ÆÆÉϰ¶·þÎñÆ÷Ö´ÐжñÒâÏÂÁîÏÂÔØMuhstik½©Ê¬ÍøÂçľÂí £¬×齨½©Ê¬ÍøÂç²¢¿ØÖÆÊ§ÏÝ·þÎñÆ÷Ö´ÐÐSSHºáÏòÒÆ¶¯¡¢ÏÂÔØÃÅÂÞ±ÒÍÚ¿óľÂíºÍ½ÓÊÜÔ¶³ÌÏÂÁîÌᳫDDoS¹¥»÷¡£

¡¾²Î¿¼Á´½Ó¡¿

https://s.tencent.com//research/report/1078.html

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡26ÌõIOC £¬ÆäÖаüÀ¨3¸öIP £¬2¸öÓòÃûºÍ21¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

9. TA551¹¥»÷×éÖ¯·Ö·¢IcedIDÒøÐÐľÂí

¡¾±êÇ©¡¿TA551

¡¾Ê±¼ä¡¿2020-08-06

¡¾¼ò½é¡¿

TA551×éÖ¯ÔÚ½üÆÚµÄ¹¥»÷Ô˶¯ÖÐÕë¶ÔÒÔÓ¢ÓïΪĸÓïµÄÈË £¬Ê¹ÓÃÀ¬»øÓʼþ·Ö·¢IcedIDÒøÐÐľÂí £¬ÕâЩÓʼþ¸½¼þÊÇ´øÓжñÒâºêµÄWordÎĵµ £¬Ò»µ©Óû§ÆôÓúê £¬HTTPͨѶµÄTCPÁ÷¿É¼ìË÷×°ÖöñÒâ³ÌÐòDLL¡£

¡¾²Î¿¼Á´½Ó¡¿

https://isc.sans.edu/diary/26438

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡56ÌõIOC £¬ÆäÖаüÀ¨2¸öIP £¬20¸öÓòÃûºÍ34¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

10. ¿çÎŤ¾ß°üÓÃÓÚÏóÐÎÎÄ×Ö¹¥»÷ÒÔ¾ÙÐÐÐÅÓÿ¨ÐÅÏ¢ÇÔÈ¡

¡¾±êÇ©¡¿Magecart

¡¾Ê±¼ä¡¿2020-08-05

¡¾¼ò½é¡¿

¹¥»÷ÕßʹÓÃÏóÐÎÎÄ×Ö¹¥»÷·½·¨À´ÇÔÊØÐÅÓÿ¨ÐÅÏ¢ £¬´Ë¹¥»÷ÊÖÒÕÔÚ¾ßÓÐIDNͬÐÎÒìÒå´Ê¹¥»÷µÄÍøÂç´¹ÂÚÕ©Æ­ÖÐÒѾ­±»Ê¹ÓÃÁËÒ»¶Îʱ¼ä¡£

¡¾²Î¿¼Á´½Ó¡¿

https://blog.malwarebytes.com/threat-analysis/2020/08/inter-skimming-kit-used-in-homoglyph-attacks/

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡5ÌõIOC £¬ÆäÖаüÀ¨1¸öIPºÍ4¸öÓòÃû£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

11. ¹¥»÷ÕßʹÓÃCOVID-19ΪÓÕ¶üÊÕÈ¡Ãô¸ÐÐÅÏ¢

¡¾±êÇ©¡¿COVID-19

¡¾Ê±¼ä¡¿2020-08-09

¡¾¼ò½é¡¿

½üÆÚʹÓÃÐÂÐ͹Ú×´²¡¶¾COVID-19Ö÷Ìâ×÷ΪÓÕ¶üµÄ´¹ÂÚ¹¥»÷Ô˶¯ÒÀÈ»»îÔ¾ £¬ÆäÖÐÓй¥»÷Õßͨ¹ýʹÓÃÖ÷ÌâΪ\"Covid-19»ù½ð¾ÈÔ®½±\" £¬»òÕßÀÄÓÃÍŽá¹úµÄ±ê¼ÇÀ´ÓÕµ¼Êܺ¦Õߣ»ÓеĹ¥»÷Ô˶¯ÒÔ±ÈÌØ±ÒÇÔȡΪĿµÄ £¬Í¨¹ý½«Êܺ¦ÕßÖ¸µ¼ÖÁ´¹ÂÚÒ³ÃæÒÔÇÔÈ¡±ÈÌØ±ÒÇ®°üÒÔ¼°ÕË»§Æ¾Ö¤£»ÉÐÓз¢Ã÷ÒÔ\"ÓÉÓÚÐÂÐ͹Ú×´²¡¶¾µ¼ÖÂÑÓ³Ù¸¶¿î\"ΪÖ÷Ìâ £¬ÓÕʹÊܺ¦Õß·­¿ª¸½¼þ £¬È»ºó¶ñÒâÎļþ½«½âѹËõ²¢´ÓGoogleÔÆÅÌÏÂÔØÓÐÓøºÔØNetWire¡£

¡¾²Î¿¼Á´½Ó¡¿

https://www.fortinet.com/blog/threat-research/latest-covid-19-variants-from-the-ridiculous-to-the-malicious

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC £¬ÆäÖаüÀ¨1¸öÓòÃûºÍ2¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

12. »ùÓھ籾µÄ¶ñÒâÈí¼þÕë¶ÔWindows²Ù×÷ϵͳÓû§

¡¾±êÇ©¡¿JScript RAT

¡¾Ê±¼ä¡¿2020-08-10

¡¾¼ò½é¡¿

½üÆÚÑо¿Ö°Ô±Í¨¹ýInternet Explorerä¯ÀÀÆ÷Îó²î¼ì²âµ½ÖØ´ó»ùÓھ籾µÄ¶ñÒâÈí¼þ £¬ÕâЩ¶ñÒâÈí¼þÕë¶ÔWindows²Ù×÷ϵͳÓû§ £¬¶ñÒâ¾ç±¾Ê¹ÓÃÁËCVE-2019-0752Îó²î £¬ÆäÖÐÒ»¸öJScriptÔ¶³Ì»á¼ûľÂí¿ÉÒÔÈ·±£ÔÚÄ¿µÄϵͳÉϵij¤ÆÚÐÔ £¬È»ºóÅþÁ¬µ½Ô¶³Ì·þÎñÆ÷ £¬¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄÅÌËãÉÏÖ´ÐÐí§ÒâÏÂÁî £¬ÒѾÙÐÐÍêÈ«¿ØÖÆ £¬µÚ¶þ¸öAutoITÏÂÔØÆ÷ʹÓÃÍøÂçÅþÁ¬ºÍ¾ç±¾¹¦Ð§À´ÏÂÔØºÍÖ´ÐжñÒâÈí¼þ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://unit42.paloaltonetworks.com/script-based-malware/

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC £¬ÆäÖаüÀ¨1¸öÏà¹ØÁªÎó²îºÍ3¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

13. PowerFallÔ˶¯Ê¹ÓÃInternet ExplorerÎó²îºÍWindowsÎó²îÕë¶Ôº«¹ú

¡¾±êÇ©¡¿PowerFall

¡¾Ê±¼ä¡¿2020-08-11

¡¾¼ò½é¡¿

Operation PowerFallÕ½ÕùÖй¥»÷ÕßʹÓÃÁ½¸ö0dayÎó²îÕë¶Ôº«¹ú¾ÙÐй¥»÷ £¬ÕâÁ½¸öÎó²î»®·Ö£ºInternet ExplorerµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2020-1380) £¬¸ÃÎó²îÔÚJavaScriptÒýÇæÖй¥»÷ÕßÄܹ»Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룻WindowsÌØÈ¨ÌáÉýÎó²î(CVE-2020-0986) £¬¸ÃÎó²îÔÚ²Ù×÷ϵͳ·þÎñÖб»¼ì²âµ½ £¬¹¥»÷Õß¿ÉÒÔÌáÉýÌØÈ¨²¢Ö´ÐÐδ¾­ÊÚȨµÄ²Ù×÷¡£´Ë´Î¹¥»÷Ô˶¯ÒÔWindows10µÄ×îа汾ΪĿµÄ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://securelist.com/ie-and-windows-zero-day-operation-powerfall/97976/

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡14ÌõIOC £¬ÆäÖаüÀ¨6¸öÏà¹ØÁªÎó²îºÍ8¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

14. BisonalºóÃÅÕë¶Ô¶«Å·µÄ½ðÈں;üÊÂ×éÖ¯

¡¾±êÇ©¡¿Bisonal

¡¾Ê±¼ä¡¿2020-08-12

¡¾¼ò½é¡¿

CactusPete £¬Ò²±»³ÆÎªKarma PandaºÍTonto Team £¬ÊÇÒ»¸öÖÁÉÙ´Ó2013Äê»îÔ¾ÖÁ½ñµÄÍþв×éÖ¯ £¬ºã¾ÃÄ¿µÄÕë¶ÔÑÇÖ޺Ͷ«Å·µÄ¾üÊ¡¢Íâ½»ºÍ»ù´¡ÉèÊ©¡£½üÆÚCactusPete×é֯ʹÓÃBisonalºóÃÅбäÖÖÃé×¼¶«Å·µÄ½ðÈں;üʲ¿·Ö £¬¸Ã×é֯ͨ¹ý´øÓжñÒ⸽¼þµÄÓã²æÊ½ÍøÂç´¹ÂÚÓʼþµÄ·½·¨À´×ª´ï¶ñÒâÈí¼þBisonal £¬¸Ã¶ñÒâÈí¼þÒÔ»ñÈ¡Êܺ¦ÕßµÄÃô¸ÐÊý¾ÝµÄ»á¼ûȨÏÞΪĿµÄ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://securelist.com/cactuspete-apt-groups-updated-bisonal-backdoor/97962/

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC £¬ÆäÖаüÀ¨1¸ö¹ØÁªÎó²îºÍ3¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

15. Continente and WortenÆ·ÅÆµÄÍøÂç´¹ÂÚÔ˶¯

¡¾±êÇ©¡¿Continente and Worten

¡¾Ê±¼ä¡¿2020-08-16

¡¾¼ò½é¡¿

´ú±íContinente and WortenÆ·ÅÆµÄ¹ã¸æÏµÁÐÕýÔÚͨ¹ýSMS£¨smishing£©¾ÙÐй²Ïí £¬´ËÔ˶¯ÏÖÔÚÕýÔÚÆÏÌÑÑÀÈö²¥ £¬¸ÃÔ˶¯²»µ«Õë¶ÔÆÏÌÑÑÀÆ·ÅÆºÍ×éÖ¯»¹½«ÆäËûÆ·ÅÆºÍ¹ú¼Ò×÷ΪĿµÄ £¬ÀýÈçÎ÷°àÑÀ £¬ÃÀ¹ú £¬¼ÓÄôó £¬Ó¢¹ú £¬ÐÙÑÀÀûµÈ¡£¹¥»÷Õßͨ¹ý½«Êܺ¦ÕßÖ¸µ¼µ½Ä¿µÄÉϰ¶Ò³ÃæµÄ·þÎñÆ÷À´ÍøÂçÊܺ¦ÕßµÄÏêϸÐÅÏ¢¡£ ÕâÖÖÐÅÏ¢¿ÉÄÜ»áÓÃÔÚÕâÖÖÐÔ×ÓµÄδÀ´Ô˶¯ÖÐ £¬ËüÊÇͨ¹ýÉç»á¹¤³ÌÕë¶ÔÊܺ¦ÕßµÄ £¬ÒÔʹÓÃеÄÍøÂç´¹ÂÚÀ˳±»ò¿ÉÄÜÉæ¼°¶ñÒâÈí¼þµÄÔ˶¯¡£

¡¾²Î¿¼Á´½Ó¡¿

https://seguranca-informatica.pt/campanhas-de-phishing-em-nome-da-marca-continente-e-worten-atualmente-a-serem-disseminadas-em-portugal/

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡8ÌõIOC £¬ÆäÖаüÀ¨1¸öIP £¬6¸öÑù±¾ºÍ1¸öÏà¹ØÁªµÄÓÊÏ䣻¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

 

16. Transparent Tribe×é֯ʹÓöñÒâÈí¼þNET RAT

¡¾±êÇ©¡¿Transparent Tribe

¡¾Ê±¼ä¡¿2020-08-19

¡¾¼ò½é¡¿

Transparent TribeÊÇÒ»¸ö¶à²úµÄ×éÖ¯ £¬¸Ã×éÖ¯ÔÚÒÑÍùÒ»ÄêÀïÕýÔÚÑݱä £¬ÔöÇ¿ÁËÔ˶¯ £¬×îÏÈÁË´ó¹æÄ£µÄѬȾÔ˶¯¡£ËûÃǵÄÖ÷Òª¶ñÒâÈí¼þÊÇ×Ô½ç˵µÄNET RAT £¬ÓÖ³ÆCrimson RAT £¬ÉÐÓÐÆäËû×Ô½ç˵NET¶ñÒâÈí¼þºÍ»ùÓÚPythonµÄRAT PeppyµÄʹÓ᣹¥»÷Õßͨ¹ýʹÓÃÓÉÖÖÖÖ×é¼þ×é³ÉµÄCrimsonÔÚÊÜѬȾµÄÅÌËã»úÉÏÖ´ÐжàÖÖÔ˶¯¡£

¡¾²Î¿¼Á´½Ó¡¿

https://securelist.com/transparent-tribe-part-1/98127/

¡¾·À»¤²½·¥¡¿

¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡21ÌõIOC £¬ÆäÖаüÀ¨4¸öIP £¬2¸öÓòÃûºÍ15¸öÑù±¾£»¾ÅÓÎÀϸçÇ徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý £¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼ £¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼