ʱ¼ä£º2021-12-31
2021.12.23~12.30
¹¥»÷ÍÅ»ïÇ鱨
ÒÉËÆ“¶ÇÄԳ攽üÆÚÕë¶ÔÃϼÓÀ¹úµÄ¹¥»÷Ô˶¯ÆÊÎö
ÉîÈëÆÊÎöEquationGroupµÄDoubleFeatureºó¿ª·¢¿ò¼Ü
LazarusʹÓÃNukeSpedºóÞÙÐд¹ÂÚ¹¥»÷
BlackTechʹÓÃFlagpro¹¥»÷ÈÕ±¾ÊµÌå
¹¥»÷Ðж¯»òÊÂÎñÇ鱨
¹¥»÷ÕßʹÓÃÉç½»ÂÛ̳Èö²¥Echelon¶ñÒâÈí¼þ
ÇÔÈ¡ºÍÍÚ¾ò¼ÓÃÜÇ®±ÒµÄйÚÖ÷Ìâ´¹ÂÚÔ˶¯
·Âð°ÍÎ÷ÒøÐзַ¢¶ñÒâÈí¼þµÄÔ˶¯ÆÊÎö
·Âð»ÔÈðÉúÎïÖÆÒ©¹«Ë¾¾ÙÐÐÍøÂç´¹ÂÚ¹¥»÷Ô˶¯ÆÊÎö
¶ñÒâ´úÂëÇ鱨
BLISTER¶ñÒâÈí¼þÔ˶¯Åû¶
TigerRAT¡¢TigerDownloader¶ñÒâÈí¼þ¼Ò×å½üÆÚÈö²¥ÆÊÎö
ÐÂÐÍÀÕË÷Èí¼þRook·Å×ÝÈö²¥£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃBabuk´úÂë
Dridex¶ñÒâÈí¼þ¼Ò×å½üÆÚÈö²¥ÆÊÎö
Îó²îÇ鱨
ApacheLog4jÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2021-44832)ͨ¸æ
¹¥»÷ÍÅ»ïÇ鱨
01
ÒÉËÆ“¶ÇÄÔ³æ”APT×éÖ¯½üÆÚÕë¶ÔÃϼÓÀ¹úµÄ¹¥»÷Ô˶¯ÆÊÎö
Åû¶ʱ¼ä£º2021Äê12ÔÂ23ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/gsUN6lXMz17_jkR8xIrZNA
Ïà¹ØÐÅÏ¢£º
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÔÚÒ»Ñùƽ³£µÄÍþвá÷ÁÔ²¶»ñÒ»ÆðAPT×éÖ¯Donot½üÆÚÒÉËÆÕë¶ÔÃϼÓÀ¹ú¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£Ôڴ˹¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ÷ÒªÒÔ”ÃϼÓÀ¹úÖ°Òµ´óѧ2021Äêµç×Ó¹¤³ÌרҵÑÝʾÎĸå”ΪÖ÷Ì⣬£¬£¬£¬£¬£¬£¬½«PPTÓÕ¶üÎļþͨ¹ý´¹ÂÚÓʼþ·¢Ë͸øÊܺ¦Õß¡£¡£¡£¡£¡£¡£
µ±Êܺ¦Õß·¿ªÓÕ¶üÎļþ²¢Ö´Ðк꣬£¬£¬£¬£¬£¬£¬ºê»áÊÍ·Å%Public%\Music\delta.dllÎļþ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚϵͳÆô¶¯Ä¿Â¼ÏÂÊÍ·Åsdelta.batÎļþ¡£¡£¡£¡£¡£¡£sdelta.batÖ÷ÒªÊǽ¨ÉèÍýÏëʹÃüdeckteck£¬£¬£¬£¬£¬£¬£¬ÓÃÀ´¼ÓÔØµ¼³öº¯Êýqdsfakraksdfkdkfjk£¬£¬£¬£¬£¬£¬£¬ÒÔʵÏÖdelta.dll×ÔÆô¶¯¡£¡£¡£¡£¡£¡£×îºóÎĵµµ¯³ö½á¹¹µÄ¹ýʧµ¯¿òÓÃÀ´ÒÉ»óÓû§£¬£¬£¬£¬£¬£¬£¬ÑÚÊÎÊÍ·ÅÎļþµÄ¶ñÒâÐÐΪ£¬£¬£¬£¬£¬£¬£¬ÕâÖÖµ¯¿ò·½·¨ÔÚÒÔÍùDonot×éÖ¯¹¥»÷Ô˶¯ÖÐÒ²¾³£·ºÆð¡£¡£¡£¡£¡£¡£delta.dllÎļþ»áÉÏ´«ÅÌËã»úºÍÓû§»ù±¾ÐÅÏ¢µ½Ô¶³ÌЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬²¢ÏÂÔØºóÐø¹¥»÷Ä£¿£¿£¿£¿£¿éµ½ÍâµØÖ´ÐС£¡£¡£¡£¡£¡£
02
ÉîÈëÆÊÎöEquationGroupµÄDoubleFeatureºó¿ª·¢¿ò¼Ü
Åû¶ʱ¼ä£º2021Äê12ÔÂ27ÈÕ
Ç鱨ȪԴ£ºhttps://research.checkpoint.com/2021/a-deep-dive-into-doublefeature-equation-groups-post-exploitation-dashboard/
Ïà¹ØÐÅÏ¢£º
12ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬CheckPointÅû¶EquationGroupʹÓõÄÈ«¹¦Ð§¶ñÒâÈí¼þ¿ò¼ÜDanderSpritzµÄÊÖÒÕÆÊÎö¡£¡£¡£¡£¡£¡£DanderSpritzÓÚ2017Äê4ÔÂ14ÈÕ±»ShadowBrokers¹ûÕæ£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÓÃÓÚ³¤ÆÚÐÔ¡¢Õì̽¡¢ºáÏòÒÆ¶¯¡¢Èƹýɱ¶¾ÒýÇæµÈÔ˶¯µÄ¶àÖÖ¹¤¾ß¡£¡£¡£¡£¡£¡£
¸ÃÑо¿ÖصãÆÊÎöÆäÖеÄÒ»¸ö×é¼þDoubleFeature£¬£¬£¬£¬£¬£¬£¬ËüÓÃÀ´ÌìÉú¿É×°ÖÃÔÚÄ¿µÄ×°±¸ÖеŤ¾ßÀàÐ͵ÄÈÕÖ¾ºÍ±¨¸æ£¬£¬£¬£¬£¬£¬£¬²¢»áÍøÂç´ó×ÚÖÖÖÖÀàÐ͵ÄÊý¾Ý¡£¡£¡£¡£¡£¡£
03
LazarusʹÓÃNukeSpedºóÞÙÐд¹ÂÚ¹¥»÷
Åû¶ʱ¼ä£º2021Äê12ÔÂ28ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/834tMVCCH6UQe8zW0eEMSA
Ïà¹ØÐÅÏ¢£º
½üÆÚ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÀ´×ÔLazarusµÄ¶àÆð¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£Lazarus¾³£Ê¹ÓÃÆäÌØÓй¥»÷ÔØºÉNukeSped¾ÙÐй¥»÷Ô˶¯£¬£¬£¬£¬£¬£¬£¬´ËÎäÆ÷ºóÃŹ¦Ð§¸»ºñ£¬£¬£¬£¬£¬£¬£¬ÇÒÑù±¾µü´ú½Ï¿ì¡£¡£¡£¡£¡£¡£´Ë´Î²¶»ñµÄÑù±¾ÎªÎ´Åû¶¹ýµÄNukeSpedÏà¹ØÀàÐÍÑù±¾¡£¡£¡£¡£¡£¡£
LazarusʹÓÃÓëÕÐÆ¸ÊÂÇéÏà¹ØµÄÎĵµ×÷ΪÓÕ¶ü£¬£¬£¬£¬£¬£¬£¬À´ÒÉ»óÓû§µã»÷¡£¡£¡£¡£¡£¡£Óû§µã»÷ºó£¬£¬£¬£¬£¬£¬£¬Îĵµ¶ñÒâºê»á½âÃÜͼÐι¤¾ßÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢ÇëÇó±£´æµØµãÄ£°å¡£¡£¡£¡£¡£¡£½âÃܺóµÄÔØºÉÒÔÒþ²ØÎļþµÄÐÎʽÉúÑÄÔÚϵͳĿ¼%ProgramData%Ï£¬£¬£¬£¬£¬£¬£¬ËæºóÎĵµÅ²ÓÃrundll32.exeÖ´ÐÐÔØºÉ£¬£¬£¬£¬£¬£¬£¬ÓëЧÀÍÆ÷½¨ÉèͨѶÅþÁ¬¡£¡£¡£¡£¡£¡£
±¾´ÎÅû¶µÄÑù±¾Óë֮ǰÅû¶Ñù±¾ÊôÓÚͬÀàÐÍÑù±¾£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÑù±¾Ö®¼äÓÐËù²î±ð¡£¡£¡£¡£¡£¡£´Ë´ÎÅû¶Ñù±¾½á¹¹Ïà¶ÔÖØ´ó£¬£¬£¬£¬£¬£¬£¬ÔغɸüÐÂÒ²½ÏÁ¿¿ì£¬£¬£¬£¬£¬£¬£¬ÐèÒªÒýÆð×ã¹»µÄÖØÊÓ¡£¡£¡£¡£¡£¡£

04
BlackTechʹÓÃFlagpro¹¥»÷ÈÕ±¾ÊµÌå
Åû¶ʱ¼ä£º2021Äê12ÔÂ28ÈÕ
Ç鱨ȪԴ£ºhttps://insight-jp.nttsecurity.com/post/102hf3q/flagpro-the-new-malware-used-by-blacktech
Ïà¹ØÐÅÏ¢£º
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬NTTSecurityÑо¿Ö°Ô±Åû¶BlackTechʹÓÃFlagpro¶ñÒâÈí¼þ¹¥»÷ÈÕ±¾ÊµÌå¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷µÄ³õʼѬȾǰÑÔÊÇαװ³ÉÀ´×ÔÄ¿µÄÏàÖúͬ°éµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬£¬Ö®ºó¹¥»÷Õß»áʹÓÃFlagpro¾ÙÐÐÍøÂçÕì̽¡¢ÆÀ¹ÀÄ¿µÄÇéÐÎÒÔ¼°ÏÂÔØ²¢Ö´Ðеڶþ½×¶Î¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£
¾ÝNTTSecurity³Æ£¬£¬£¬£¬£¬£¬£¬´Ë´ÎÔ˶¯ÖÁÉÙʼÓÚ2020Äê10Ô£¬£¬£¬£¬£¬£¬£¬ÒÑÕë¶ÔÈÕ±¾¹«Ë¾Ò»Äê¶à£¬£¬£¬£¬£¬£¬£¬Éæ¼°¹ú·ÀÊÖÒÕ¡¢Ã½ÌåºÍͨѶÐÐÒµÔÚÄڵĶà¸öÁìÓò¡£¡£¡£¡£¡£¡£

¹¥»÷ÍÅ»ïÇ鱨
01
¹¥»÷ÕßʹÓÃÉç½»ÂÛ̳Èö²¥Echelon¶ñÒâÈí¼þ
Åû¶ʱ¼ä£º2021Äê12ÔÂ23ÈÕ
Ç鱨ȪԴ£ºhttps://www.safeguardcyber.com/blog/echelon-malware-crypto-wallet-stealer-malware
Ïà¹ØÐÅÏ¢£º
½üÆÚSafeguardCyberµÄÇå¾²Ñо¿Ö°Ô±¼à²âµ½ÔÚTelegramµÄÒ»¸öÊý×ÖÇ®±ÒÉúÒâÆµµÀÖÐÈö²¥Echelon¶ñÒâÈí¼þµÄÐÐΪ¡£¡£¡£¡£¡£¡£EchelonÑù±¾µÄÄ¿µÄÊÇÉϰ¶Æ¾Ö¤ºÍÊý×ÖÇ®±ÒÇ®°ü¡£¡£¡£¡£¡£¡£
¹¥»÷ÕßÐû²¼ÁËÒ»¸örarѹËõ°ü£¬£¬£¬£¬£¬£¬£¬Ñ¹Ëõ°üÄÚÀï°üÀ¨3¸öÎļþ£¬£¬£¬£¬£¬£¬£¬ÆäÖоÍÓÐEchelon¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¶Ô¿ÉÖ´ÐÐÎļþµÄÆÊÎöÅú×¢£¬£¬£¬£¬£¬£¬£¬ËüÓÐ2¸ö·´µ÷ÊÔ¹¦Ð§²¢Ê¹ÓÃConfuserEx¾ÙÐÐÁË´úÂë»ìÏý¡£¡£¡£¡£¡£¡£È¥»ìÏýºó£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷Echelon¾ßÓÐÊý×ÖÇ®±ÒÇ®°üºÍƾ֤ÇÔÈ¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Óò¼ì²âºÍÅÌËã»úÖ¸ÎÆÊ¶±ð¹¦Ð§¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þ»¹»áÊÔͼ½ØÆÁÊܺ¦ÕߵĵçÄÔ¡£¡£¡£¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬£¬£¬£¬WindowsDefenderÏÖÔÚ¿ÉÒÔ¼ì²â²¢É¨³ý¶ñÒâÑù±¾¡£¡£¡£¡£¡£¡£
02
ÇÔÈ¡ºÍÍÚ¾ò¼ÓÃÜÇ®±ÒµÄйÚÖ÷Ìâ´¹ÂÚÔ˶¯
Åû¶ʱ¼ä£º2021Äê12ÔÂ23ÈÕ
Ç鱨ȪԴ£ºhttps://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/covid-19-phishing-lure-to-steal-and-mine-cryptocurrency/
Ïà¹ØÐÅÏ¢£º
×î½ü£¬£¬£¬£¬£¬£¬£¬SpiderLabsÊӲ쵽һ¸öÈö²¥¶ñÒâÈí¼þµÄÀ¬»øÓʼþÔ˶¯£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃйÚÒßÇé×÷ΪÖ÷Ìâ¡£¡£¡£¡£¡£¡£ÕâЩµç×ÓÓʼþÀ´×Ô±»Ñ¬È¾µÄÓÊÏ䣬£¬£¬£¬£¬£¬£¬°üÀ¨Ò»¸öÖ¸ÏòWordÎĵµµÄÁ´½Ó¡£¡£¡£¡£¡£¡£Óʼþ·Âð³Éйڲ¡¶¾¼ì²â֪ͨ£¬£¬£¬£¬£¬£¬£¬ÓÕµ¼Óû§µã»÷Á´½Ó¡£¡£¡£¡£¡£¡£
ΪÁËÌӱܾ²Ì¬²¡¶¾¼ì²â£¬£¬£¬£¬£¬£¬£¬ÏÂÔØµÄWordÎĵµ²»°üÀ¨¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÔ¶³ÌÄ£°å×¢ÈëÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬ÔÚÊܺ¦Õß·¿ªÎĵµÊ±£¬£¬£¬£¬£¬£¬£¬´ÓÔ¶³ÌЧÀÍÆ÷¼ìË÷Ò»¸ö¶ñÒâµÄÆôÓúêµÄÄ£°å¡£¡£¡£¡£¡£¡£Ä£°åͨ¹ý×Ô½ç˵VBAº¯Êý½âÂë²¢¼ÓÔØÒ»Ð©Base64¶þ½øÖÆÎļþ¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬°üÀ¨ÐÅÏ¢ÇÔÈ¡Èí¼þClipBankerºÍÍÚ¿óÈí¼þÏÂÔØÆ÷¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹»á»ñÈ¡Êܺ¦ÕßµÄÓʼþÁªÏµÈËÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢¸´ÖÆÓÕ¶üÓʼþÈö²¥¡£¡£¡£¡£¡£¡£

03
¹¥»÷Õß·Âð°ÍÎ÷ÒøÐзַ¢¶ñÒâÈí¼þ
Åû¶ʱ¼ä£º2021Äê12ÔÂ23ÈÕ
Ç鱨ȪԴ£ºhttps://blog.cyble.com/2021/12/23/malicious-app-targets-major-brazilian-bank-itau-unibanco/
Ïà¹ØÐÅÏ¢£º
½üÆÚ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±²¶»ñµ½ÁËÕë¶Ô°ÍÎ÷Ò»¼ÒÃûΪItauUnibancoµÄÒøÐй«Ë¾µÄ¶ñÒâÈí¼þÑù±¾¡£¡£¡£¡£¡£¡£´Ë¶ñÒâÈí¼þÊÔͼÔÚÊܺ¦Õß²»ÖªÇéµÄÇéÐÎÏÂÒÔÒ»¸öÓµÓÐÀàËÆÍ¼±êºÍÃû³ÆµÄÐéαӦÓóÌÐò_lTAU_SINC/sincronizadorÀ´ÓÕÆÓû§ÒÔΪÆäÊÇÒ»¸öÓëItauUnibancoÓйصÄÕýµ±Ó¦ÓóÌÐò¡£¡£¡£¡£¡£¡£
¹¥»÷Õß½¨ÉèÁËÒ»¸öÐéαµÄGooglePlayÊÐËÁÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÉÏÃæÒÔ'sincronizador.apk'µÄÃûÒåÍйÜÁËÕë¶ÔItauUnibancoµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒ»Ö±µ÷½âÆä·Ö·¢·½·¨£¬£¬£¬£¬£¬£¬£¬ÒÔ×èÖ¹±»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÔ½À´Ô½ÖØ´óµÄÊÖÒÕÕÒµ½ÐµÄÒªÁìÀ´Õë¶ÔÓû§¡£¡£¡£¡£¡£¡£
ÕâÀà¶ñÒâÓ¦ÓóÌÐòÍùÍùαװ³ÉÕýµ±µÄÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬£¬ÒÔÓÕÆÓû§×°ÖÃËüÃÇ£¬£¬£¬£¬£¬£¬£¬²¢ÊÔͼÔÚÊܺ¦Õß²»ÖªÇéµÄÇéÐÎϾÙÐÐÚ²ÆÐÔ½ðÈÚÉúÒâ¡£¡£¡£¡£¡£¡£Óû§Ó¦¸ÃÔÚÑéÖ¤ÆäÕæÊµÐÔºóÔÙ×°ÖÃÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÖ»´Ó¹Ù·½µÄGooglePlayÊÐËÁºÍÆäËûÊÜÐÅÍеÄÃÅ»§ÍøÕ¾×°Ö㬣¬£¬£¬£¬£¬£¬ÒÔ×èÖ¹´ËÀ๥»÷¡£¡£¡£¡£¡£¡£
04
¹¥»÷Õß·Âð»ÔÈðÉúÎïÖÆÒ©¹«Ë¾¾ÙÐÐÍøÂç´¹ÂÚ¹¥»÷
Åû¶ʱ¼ä£º2021Äê12ÔÂ23ÈÕ
Ç鱨ȪԴ£ºhttps://www.inky.com/blog/fresh-phish-phishers-impersonate-pfizer-in-request-for-quotation-scam
Ïà¹ØÐÅÏ¢£º
8ÔÂÖÁ12ÔÂʱ´ú£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±¼ì²âµ½Ò»Æð¾ßÓкÜÇ¿Õë¶ÔÐÔµÄÍøÂç´¹ÂÚÔ˶¯¡£¡£¡£¡£¡£¡£¹¥»÷Õßð³äÉúÎïÊÖÒÕ¾ÞÍ·»ÔÈð£¨pfizer£©¹«Ë¾£¬£¬£¬£¬£¬£¬£¬·¢ËÍÁË410·âÍøÂç´¹ÂÚµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡ÉÌÒµºÍ²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»ÔÈðÊÇÒ»¼ÒÖøÃûµÄÖÆÒ©¹«Ë¾£¬£¬£¬£¬£¬£¬£¬×ܲ¿Î»ÓÚÃÀ¹úŦԼ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾³Æ×ÅʵÑéÐÔ¿¹Ð¹ÚÒ©ÎïPaxlovid¿ÉÒÔʹ¸ßΣйڻ¼ÕßµÄסԺÂʺÍéæÃüΣº¦ïÔÌ89%¡£¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬£¬×Ô2021Äê8ÔÂ15ÈÕ×îÏÈ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¾Íð³ä»ÔÈð¹«Ë¾Õö¿ªÁËÍøÂçµç×ÓÓʼþ´¹ÂÚÔ˶¯¡£¡£¡£¡£¡£¡£ÍøÂç´¹ÂÚÓʼþÀ´×ÔÓÚÒ»×éÒ×±»»ìÏýµÄÓòÃû£¬£¬£¬£¬£¬£¬£¬ÕâЩÓòÃûÊÇͨ¹ýNamecheap×¢²áµÄ¡£¡£¡£¡£¡£¡£ÕâЩÓòÃû±»Î±×°³ÉÊÇÓÉ»ÔÈð¹«Ë¾¿ØÖƵ쬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÒÔΪÕâÊÇ»ÔÈð¹«Ë¾µÄ¹Ù·½ÔÚÏßÍøÕ¾¡£¡£¡£¡£¡£¡£ÍøÂç´¹ÂÚµç×ÓÓʼþÖÐʹÓÃÁË“½ôÆÈѯ¼Û”¡¢“Ͷ±êÔ¼Ç딺͓¹¤Òµ×°±¸¹©Ó¦”µÈÖ÷Ìâ×÷ΪÓÕ¶ü¡£¡£¡£¡£¡£¡£ÓʼþÖеÄPDF¸½¼þÓÐÈýÒ³£¬£¬£¬£¬£¬£¬£¬¿´ÆðÀ´·Ç³£¿£¿£¿£¿£¿ÉÐÅ¡£¡£¡£¡£¡£¡£PDFÖв»°üÀ¨¶ñÒâÈí¼þͶ·ÅÁ´½Ó»òÍøÂç´¹ÂÚµÄURL£¬£¬£¬£¬£¬£¬£¬ÇÒÄÚÈÝÑϽ÷ûÓдí±ð×Ö¡£¡£¡£¡£¡£¡£PDFÄÚÈÝÖÐÌÖÂÛÁ˸¶¿î·½·¨ºÍÌõ¿î£¬£¬£¬£¬£¬£¬£¬ÒªÇóÊÕ¼þÈË·ÖÏíËûÃǵÄÒøÐÐÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£
´Ë´ÎÔ˶¯¼òÖ±ÇÐÄ¿µÄÉв»ÇåÎú£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áÔÚδÀ´Õë¶ÔÄ¿µÄ¹«Ë¾¿Í»§ÌᳫÉÌÒµµç×ÓÓʼþ¹¥»÷¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬µ±ÊÕµ½°üÀ¨Ò쳣Ͷ±êÇëÇóµÄµç×ÓÓʼþʱ£¬£¬£¬£¬£¬£¬£¬Ó¦Ê¹Óù«Ë¾µÄ¹Ù·½µç»°ºÅÂëÁªÏµ¹«Ë¾ÒÔÈ·ÈÏÓʼþ¡£¡£¡£¡£¡£¡£
¶ñÒâ´úÂëÇ鱨
01
BLISTER¶ñÒâÈí¼þÔ˶¯Åû¶
Åû¶ʱ¼ä£º2021Äê12ÔÂ23ÈÕ
Ç鱨ȪԴ£ºhttps://www.elastic.co/cn/blog/elastic-security-uncovers-blister-malware-campaign
Ïà¹ØÐÅÏ¢£º
ElasticSecurity½üÆÚ·¢Ã÷ÁËÒ»¸öʹÓÃÓÐÓÃÖ¤ÊéÀ´Ìӱܼì²âµÄ¶ñÒâÈí¼þÔ˶¯¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£Ô˶¯ÖзºÆðÁËÒ»ÖÖÐÂÐ͵ĶñÒâÈí¼þ¼ÓÔØÆ÷BLISTER£¬£¬£¬£¬£¬£¬£¬ÆäÓÃÓÚÔÚÄÚ´æÖÐÖ´Ðеڶþ½×¶Î¶ñÒâ¸ºÔØ²¢ÊµÏÖ³¤ÆÚ»¯¡£¡£¡£¡£¡£¡£
¸ÃÔ˶¯µÄÒ»¸öÒªº¦¾ÍÊÇʹÓÃÓÉSectigo½ÒÏþµÄÓÐÓôúÂëÊðÃûÖ¤Êé¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÇÔÈ¡Õýµ±µÄ´úÂëÊðÃûÖ¤Ê飬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔÖ±½Ó´ÓÖ¤Êé½ÒÏþ»ú¹¹»ò½èÖú¿Õ¿Ç¹«Ë¾¹ºÖÃÖ¤Êé¡£¡£¡£¡£¡£¡£¾ß±¸ÓÐÓÃÖ¤ÊéµÄ¿ÉÖ´ÐÐÎļþͨ³£¸üÉÙ±»×Ðϸ¼ì²é£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÒÔÈù¥»÷Õß¼á³ÖÔڽϳ¤Ò»¶Îʱ¼äÄÚ²»±»¼ì²â¡£¡£¡£¡£¡£¡£ÖÁÓÚжñÒâÈí¼þ¼ÓÔØÆ÷BLISTER£¬£¬£¬£¬£¬£¬£¬Ëü±»Æ´½Óµ½ÁËÕýµ±µÄ¿âÖУ¬£¬£¬£¬£¬£¬£¬¿É¾¼òÆÓµÄ¼ÓÔØ³ÌÐòдÈë´ÅÅ̲¢Ö´ÐС£¡£¡£¡£¡£¡£Ò»µ©Ö´ÐУ¬£¬£¬£¬£¬£¬£¬BLISTER½«ÊÍ·ÅCobaltStrikeºÍBitRatµÈ¸ºÔØ£¬£¬£¬£¬£¬£¬£¬²¢½¨É賤ÆÚ»¯¡£¡£¡£¡£¡£¡£
02
TigerRAT¡¢TigerDownloader¶ñÒâÈí¼þ¼Ò×å½üÆÚÈö²¥ÆÊÎö
Åû¶ʱ¼ä£º2021Äê12ÔÂ22ÈÕ
Ç鱨ȪԴ£ºhttps://threatray.com/blog/establishing-the-tigerrat-and-tigerdownloader-malware-families/
Ïà¹ØÐÅÏ¢£º
º«¹úCERT£¨KrCERT£©ÔÚÒ»Æð¹¥»÷Ô˶¯Öз¢Ã÷ÁËÒÔǰûÓеÄÐÂÊÖÒպͶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬²¢½«Õâ´Î¹¥»÷ÖеĶñÒâÈí¼þ¹¤¾ß³ÆÎªTigerDownloaderºÍTigerRAT¡£¡£¡£¡£¡£¡£¸ú½øºó·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¤¾ßÊôÓÚÏàͬµÄÏÂÔØÆ÷ºÍRAT¼Ò×å¡£¡£¡£¡£¡£¡£ÕâЩ¶þ½øÖÆÎļþ¹²Ïí²¿·Ö¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ÒÔʵÏÖÓÐÓõĽâ°ü¡£¡£¡£¡£¡£¡£ÆäÓàµÄ¹²Ïí¹¦Ð§ÊÇÓÃÀ´×èÖ¹±»·´²¡¶¾Èí¼þ¡¢YaraºÍÏà¹ØµÄ»ùÓÚģʽµÄ¼ì²âÊÖÒÕ¼ì²âµÄ¡£¡£¡£¡£¡£¡£
µ½ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬£¬´ò°üµÄÑù±¾¶¼ÊÇÓÉÒ»¸öÅäºÏµÄ´ò°üÆ÷´ò°üµÄ£¬£¬£¬£¬£¬£¬£¬´úÂë¾ßÓÐÒ»¶¨µÄ¹ØÁªÐÔ¡£¡£¡£¡£¡£¡£´úÂëÖ®¼äµÄ²î±ðÊÇÓÉÓÚÓÐÀ¬»ø´úÂëµÄ±£´æ¡£¡£¡£¡£¡£¡£¹ØÓÚTigerRAT£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÑо¿Ö°Ô±·¢Ã÷ÓÐÈý¸ö²î±ðµÄ°æ±¾¡£¡£¡£¡£¡£¡£¹ØÓÚTigerDownloader£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ·¢Ã÷ÁËÁ½¸ö°æ±¾£¬£¬£¬£¬£¬£¬£¬Ò»¸ö¾ßÓг¤ÆÚÐÔ£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öûÓС£¡£¡£¡£¡£¡£¶ø×î½üµÄÑо¿ÏÔʾ£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ»¹±£´æÆäËûÉÐδ¹ûÕæµÄ±äÖÖ¡£¡£¡£¡£¡£¡£

03
ÐÂÐÍÀÕË÷Èí¼þRook·Å×ÝÈö²¥£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃBabuk´úÂë
Åû¶ʱ¼ä£º2021Äê12ÔÂ23ÈÕ
Ç鱨ȪԴ£ºhttps://www.sentinelone.com/labs/new-rook-ransomware-feeds-off-the-code-of-babuk/
Ïà¹ØÐÅÏ¢£º
½üÆÚ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±²¶»ñµ½ÁËRookÀÕË÷Èí¼þµÄÑù±¾¡£¡£¡£¡£¡£¡£Rook½ÓÄÉÁËÒ»ÖÖË«¹ÜÆëϵÄÀÕË÷·½·¨£ºÊ×ÏÈÒªÇóÊܺ¦ÕßÖ§¸¶Êê½ðÀ´½âËø¼ÓÃÜÎļþ£¬£¬£¬£¬£¬£¬£¬È»ºóͨ¹ýÔËÓªÉ̵ÄÍøÕ¾¹ûÕæÍþвÀÕË÷£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÊܺ¦Õß²»×ñÊØÒªÇ󣬣¬£¬£¬£¬£¬£¬¾Í»á±»Ð¹Â¶Êý¾Ý¡£¡£¡£¡£¡£¡£RookÀÕË÷Èí¼þÖ÷ÒªÊÇͨ¹ýµÚÈý·½½»¸¶µÄ£¬£¬£¬£¬£¬£¬£¬ÀýÈçCobaltStrike£»£»£»£»£»£»£»¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬Ò²Óб¨¸æ³Æ£¬£¬£¬£¬£¬£¬£¬Í¨¹ý´¹ÂÚÓʼþ½»¸¶¡£¡£¡£¡£¡£¡£Èí¼þÑù±¾Í¨³£ÊÇÓÃUPX´ò°ü£¬£¬£¬£¬£¬£¬£¬µ«Ò²ÓÐÆäËûµÄ¼ÓÃÜÆ÷£¬£¬£¬£¬£¬£¬£¬ÈçVMProtect¡£¡£¡£¡£¡£¡£´ËÀÕË÷Èí¼þÊÔͼÖÕÖ¹ÈκοÉÄÜ×ÌÈżÓÃܵÄÀú³Ì¡£¡£¡£¡£¡£¡£Óë´ó´ó¶¼ÀÕË÷Èí¼þ¼Ò×åÒ»Ñù£¬£¬£¬£¬£¬£¬£¬RookÒ²»áÊÔͼɾ³ý¾íÓ°¸±±¾£¬£¬£¬£¬£¬£¬£¬ÒÔ±ÜÃâÊܺ¦Õß´Ó±¸·ÝÖлָ´¡£¡£¡£¡£¡£¡£´ËÀÕË÷Èí¼þ²»¾ßÓг¤ÆÚÐÔ£¬£¬£¬£¬£¬£¬£¬ÔÚÖ´ÐÐÍê±ÏÖ®ºó»á×ÔÐÐɾ³ý¡£¡£¡£¡£¡£¡£
RookºÍBabukÖ®¼äÓÐÐí¶àÏàËÆ´úÂ룬£¬£¬£¬£¬£¬£¬ÕâÊÇ2021ÄêBabukÔ´´úÂë×ß©µÄЧ¹û¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÍƲâRookÊÇÏÖÔÚʹÓÃBabukÔ´´úÂëµÄ×îÐÂÐÍÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£RookºÍBabuk¶¼»áʹÓÃWindowsÖØÆôÖÎÀíÆ÷APIÀ´×ÊÖúÀú³ÌÖÕÖ¹£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÓëMSOfficeºÍSteamÓйصÄÀú³Ì¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹×¢Öص½RookºÍBabukÔÚһЩÇéÐμì²éºÍºóÐøÐÐΪ·½ÃæµÄÖØµþ£¬£¬£¬£¬£¬£¬£¬°üÀ¨É¾³ý¾íÓ°¸±±¾¡£¡£¡£¡£¡£¡£

04
Dridex¶ñÒâÈí¼þ¼Ò×å½üÆÚÈö²¥ÆÊÎö
Åû¶ʱ¼ä£º2021Äê12ÔÂ23ÈÕ
Ç鱨ȪԴ£ºhttps://blog.malwarebytes.com/threat-intelligence/2021/12/dridex-affiliate-dresses-up-as-scrooge/
Ïà¹ØÐÅÏ¢£º
MalwarebytesLABS½üÆÚ·¢Ã÷ÁËÈö²¥DridexµÄ´¹ÂÚÓʼþÔ˶¯£¬£¬£¬£¬£¬£¬£¬DridexÊÇÒ»¸ö¶ñÒâÈí¼þÏÂÔØÆ÷£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ¼ÓÔØÌØÊâÓÐÓøºÔØ£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£´¹ÂÚÓʼþʹÓÃÁ˲ÃÈË֪ͨ¡¢Ð¹Ú×îбäÖÖOmicronµÈÖ÷Ì⣬£¬£¬£¬£¬£¬£¬¿ÉÄܶ¼À´×Ôͳһ·¸·¨ÍŻ¡£¡£¡£¡£¡£
´¹ÂÚÓʼþ°üÀ¨ÓÐÃÜÂë±£»£»£»£»£»£»£»¤µÄExcelÎĵµ£¬£¬£¬£¬£¬£¬£¬±»·¿ªºó»áµ¯³ö¶Ô»°¿òÀ´ÒªÇóÓû§ÆôÓúꡣ¡£¡£¡£¡£¡£ºêÔËÐкó»á½«Ò»¸örtfÎļþ·ÅÈë%programdata%Ŀ¼ÖУ¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýmshta.exeÖ´ÐС£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬»áÏÂÔØÕæÕýµÄ¶ñÒâ¸ºÔØ£¬£¬£¬£¬£¬£¬£¬¸Ã¸ºÔØÊôÓÚDridex¶ñÒâÈí¼þ¼Ò×å¡£¡£¡£¡£¡£¡£
Îó²îÏà¹Ø
01
ApacheLog4jÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2021-44832)ͨ¸æ
Åû¶ʱ¼ä£º2021Äê12ÔÂ29ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/8JObCLtNfHMU7Ib4JxPd2g
Ïà¹ØÐÅÏ¢£º
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT¼à²âµ½Apache¹Ù·½Ðû²¼ÁËApacheLog4jÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44832£©£¬£¬£¬£¬£¬£¬£¬ÔÚÄ³Ð©ÌØÊⳡ¾°Ï£¨Èçϵͳ½ÓÄɶ¯Ì¬¼ÓÔØÔ¶³ÌÉèÖÃÎļþµÄ³¡¾°µÈ£©£¬£¬£¬£¬£¬£¬£¬ÓÐȨÐÞËûÈÕÖ¾ÉèÖÃÎļþµÄ¹¥»÷Õß¿ÉÒÔ¹¹½¨¶ñÒâÉèÖ㬣¬£¬£¬£¬£¬£¬Í¨¹ýJDBCAppenderÒýÓÃJNDIURIÊý¾ÝÔ´´¥·¢JNDI×¢È룬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
ApacheLog4j1.x²»ÊÜ´ËÎó²îÓ°Ï죬£¬£¬£¬£¬£¬£¬Ö»ÓÐÒýÓÃlog4j-coreÒÀÀµÊÜ´ËÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£½öÒýÓÃlog4j-apiÒÀÀµ¶ø²»ÒýÓÃlog4j-coreµÄÓ¦ÓóÌÐò²»ÊÜ´ËÎó²îµÄÓ°Ïì¡£¡£¡£¡£¡£¡£ApacheLog4jÊÇΨһÊÜ´ËÎó²îÓ°ÏìµÄÈÕ־ЧÀÍ×ÓÏîÄ¿£¬£¬£¬£¬£¬£¬£¬Log4netºÍLog4cxxµÈÆäËûÏîÄ¿²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ