΢Èí°ä²¼²¼¸æ³ÆIE 0dayÒÑÔâÒ°±íÀûÓ㬣¬£¬£¬£¬£¬£¬Ä¿Ç°ÉÐÎÞ²¹¶¡£¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»Î÷ÃÅ×ÓÖÒ¸æ¿Í»§ÓйØÔÚ¹¤Òµ²úÆ·ÖÐʹÓÃActiveXµÄ·çÏÕ
°ä²¼¹¦·ò 2020-01-19
1.΢Èí°ä²¼²¼¸æ³ÆIE 0dayÒÑÔâÒ°±íÀûÓ㬣¬£¬£¬£¬£¬£¬Ä¿Ç°ÉÐÎÞ²¹¶¡
1ÔÂ17ÈÕ΢Èí°ä²¼°²È«²¼¸æ£¨ADV200001£©£¬£¬£¬£¬£¬£¬£¬ÖÒ¸æÓû§¹ØÓÚIE 0day£¨CVE-2020-0674£©ÒÑÔâÒ°±íÀûÓõÄÇé¿ö£¬£¬£¬£¬£¬£¬£¬²¢ÇҸ÷ì϶ÔÝÎÞ½¨¸´²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬½öÓÐÓ¦±ä´ëÊ©»ººÍ½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£Î¢Èí°µÊ¾ÔÚÍÆ³ö½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÔÚºóÐøÒÔ´ø±í¸üеķ½Ê½°ä²¼¡£¡£¡£¡£¡£¡£¡£¡£¸Ã0dayδÔâ´ó¹æÄ£ÀûÓ㬣¬£¬£¬£¬£¬£¬Ö»ÊÇÕë¶ÔÉÙÁ¿Óû§¹¥»÷µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý²¼¸æ£¬£¬£¬£¬£¬£¬£¬Î¢Èí³Æ¸Ã0dayΪԶ³Ì´úÂëÖ´Ðзì϶£¨RCE£©£¬£¬£¬£¬£¬£¬£¬ÓëIE¾ç±¾ÒýÇæÔÚ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½Óйء£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÄÚ´æ°Ü»µ·ì϶£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÒÔµ±Ç°Óû§µÄȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ÔÚweb¹¥»÷³¡¾°ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÓÕʹÓû§½Ó¼û¶ñÒâÍøÕ¾À´ÀûÓø÷ì϶£¨ÀýÈçͨ¹ý´¹µöÓʼþ£©¡£¡£¡£¡£¡£¡£¡£¡£Óû§¿Éͨ¹ýÏ޶ȶÔJScript.dllµÄ½Ó¼ûÀ´ÁÙʱ»º½â¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/01/internet-explorer-zero-day-attack.html
2.Î÷ÃÅ×ÓÖÒ¸æ¿Í»§ÓйØÔÚ¹¤Òµ²úÆ·ÖÐʹÓÃActiveXµÄ·çÏÕ
Î÷ÃÅ×ÓµÄһЩ¹¤Òµ²úÆ·£¨Ô̺¬SIMATIC WinCC¡¢SIMATIC STEP 7¡¢SIMATIC PCS 7¡¢TIA PortalºÍS7-PLCSIM Advanced£©ÒÀÀµActiveX×é¼þ£¬£¬£¬£¬£¬£¬£¬¿Í»§±ØÒªÊ¹ÓÃInternet ExplorerÀ´Ö´ÐÐÕâЩ×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£µ«¸Ã³§ÉÌÖÒ¸æ¿Í»§³Æ£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃIE½Ó¼û²»ÊÜÐÅÀµµÄÍøÕ¾¿ÉÄÜ»á´øÀ´ÑϳÁµÄ°²È«·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£Î÷ÃÅ×Ó½¨ÒéÔÚ½Ó¼ûÓ빫˾²úÆ·Î޹صÄÍøÒ³Ê±Ê¹Óò»Ö§³ÖActiveXµÄÍøÒ³ä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Î÷ÃÅ×Ó½üÆÚ»¹½¨¸´ÁËSCALANCE X¹¤Òµ»¥»»»úÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2019-13933£¬£¬£¬£¬£¬£¬£¬CVSS v3.1ÆÀ·ÖΪ8.8·Ö£©¡¢ SINEMA ServerÖеIJ»ÕýÈ·µÄ»á»°ÑéÖ¤·ì϶£¨CVE-2019-10940£¬£¬£¬£¬£¬£¬£¬9.9·Ö£©ºÍTIA PortalÖеÄLPE·ì϶£¨CVE-2019-10934£¬£¬£¬£¬£¬£¬£¬7.8·Ö£©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/siemens-warns-security-risks-associated-use-activex
3.×êÑÐÍŶӰ䲼ÀÕË÷Èí¼þParadiseµÄ½âÃܹ¤¾ß
Bitdefender×êÑÐÍŶӰ䲼ÀÕË÷Èí¼þParadiseµÄ×îнâÃÜÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Paradise×î³õÓÚ2017Äê³öÏÖ£¬£¬£¬£¬£¬£¬£¬ËüÔÚ¼ÓÃÜʱ»áÈÆ¹ý¼üÅÌ˵»°Îª¶íÓï¡¢¹þÈø¿ËÓï¡¢°×¶íÂÞ˹Óï»òÎÚ¿ËÀ¼ÓïµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¡£Bitdefender°ä²¼µÄ×îнâÃÜÆ÷Ö§³ÖÒÔϺó׺ÃûµÄ±äÖÖ£º.FC¡¢.2ksys19¡¢.p3rf0rm4¡¢.Recognizer¡¢.VACv2¡¢.paradise¡¢.CORP¡¢.immortal¡¢.exploit¡¢.prt¡¢.STUB¡¢.sevºÍ.sambo¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ßÖ§³ÖGUI»òºÅÁî×ßÔËÐУ¬£¬£¬£¬£¬£¬£¬Óû§¿É´ÓBitdefender¹ÙÍøÏÂÔØ¸Ã¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://labs.bitdefender.com/2020/01/paradise-ransomware-decryption-tool/
4.ÍÁ¶úÆäºÚ¿Í¹¥»÷Ï£À°¶à¸öµ±²¿ÃÅÃźÍ֤ȯÂòÂôËùÍøÕ¾
ÉÏÖÜÎåÍÁ¶úÆäºÚ¿ÍÐû³ÆÒѾ½Ù³ÖÁËÏ£À°Òé»á¡¢±í½»ºÍ¾¼Ã²¿ÒÔ¼°¸Ã¹ú¶È֤ȯÂòÂôËùµÄ¹Ù·½ÍøÕ¾³¤´ï90¶à·ÖÖÓ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃºÚ¿ÍÍÅ»ïΪAnka Neferler Tim£¬£¬£¬£¬£¬£¬£¬ËûÃÇÔÚFacebookÒ³ÃæÉϱ绤³Æ¡°Ï£À°Ò»ÏòÔÚ°®ÇÙº£ºÍµØÖк£¶«²¿ÍþвÍÁ¶úÆä£¬£¬£¬£¬£¬£¬£¬´Ë¿ÌÓÖÔÚÍþвÀû±ÈÑÇºÍÆ½»áÒ顱¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»áÒéµÄÖ÷ÕÅÊÇÔÚ½áºÏ¹úµÄÖ÷³ÖÏÂÆô¶¯Àû±ÈÑÇµÄºÍÆ½¹ý³Ì£¬£¬£¬£¬£¬£¬£¬½«ÔÚ°ØÁÖ½øÐС£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/turkish-hackers-target-greek-government-websites-stock-exchange
5.ÐÂÔóÎ÷ÖÝÓÌÌ«½ÌÌÃÔâµ½ÀÕË÷Èí¼þSodinokibi¹¥»÷
ÐÂÔóÎ÷ÖÝÎÖÂ×ÊеÄÓÌÌ«½ÌÌÃTemple Har ShalomÔâµ½ÀÕË÷Èí¼þSodinokibi¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÆäÍøÂçÉϵĺܶàÍÆËã»úϵͳ±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã½ÌÌÃÓÚ1ÔÂ9ÈÕ·¢ÏÖÁ˹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬Æä·þÎñÆ÷ÉϵÄËùÓÐÎļþºÍµç×ÓÊý¾Ý¾ù±»¼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÕâЩÎļþºÍÊý¾ÝµÄ±¸·Ý¡£¡£¡£¡£¡£¡£¡£¡£ÐÂÎÅÈËÊ¿³ÆSodinokibi¹¥»÷ÕßÒªÇó½ü50ÍòÃÀÔªµÄÊê½ð£¬£¬£¬£¬£¬£¬£¬µ«¸Ã½ÌÌðµÊ¾½«Óë»á¶àÁªÏµÒÔ»ñÈ¡³Á½¨¼ÓÃÜÎļþËùÐèµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢ËûÃÇÎÞÒâÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¶àËùÖÜÖªSodinokibiÔÚ¼ÓÃÜÎļþ֮ǰ»áÏÈÇÔÈ¡Îļþ£¬£¬£¬£¬£¬£¬£¬Òò¶ø»á¶àµÄÐÕÃû¡¢µØÖ·ºÍµç×ÓÓʼþµØÖ·¿ÉÄܱ»µÁ£¬£¬£¬£¬£¬£¬£¬µ«¸Ã½ÌÌÃÒÔΪ¹¥»÷ÕßÎÞ·¨½Ó¼û²ÆÕþÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-jersey-synagogue-suffers-sodinokibi-ransomware-attack/
6.¶ñÒâÈí¼þMetamorfoбäÖÖÖØÒªÕë¶Ô°ÍÎ÷½ðÈÚ»ú¹¹
FortiGuard Labs·¢ÏÖ¶ñÒâÈí¼þMetamorfoµÄбäÖÖ£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÒÔÍøÂç°ÍÎ÷½ðÈÚ»ú¹¹¿Í»§µÄÊý¾Ý¶øÎÅÃû¡£¡£¡£¡£¡£¡£¡£¡£¸Ã±äÖÖͨ¹ý´¹µöÓʼþ´«²¼£¬£¬£¬£¬£¬£¬£¬´¹µöÓʼþÓɰÍÎ÷¹Ù·½Ëµ»°ÆÏÌÑÑÀÓïд³É£¬£¬£¬£¬£¬£¬£¬ÄÚÈÝΪ¶½´ÙÊܺ¦ÕßÏÂÔØµç×Ó·¢Æ±£¨NF£©£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÏÂÔØµÄÎļþΪXlsPlan_Visualize.msi¡£¡£¡£¡£¡£¡£¡£¡£¸ÃMSIÎļþÖ»ÊÇÒ»¸ö¶ñÒâÈí¼þÏÂÔØÆ÷£¬£¬£¬£¬£¬£¬£¬×îÖÕ½«ÏÂÔØKJFLDKRE.msi²¢Ö´ÐУ¬£¬£¬£¬£¬£¬£¬¸ÃÎļþÊÇÕæÕýµÄMetamorfo¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÄܹ»ÍøÂçÊܺ¦ÕßµÄÍÆËã»úÃû³Æ¡¢¿Í»§¶Ë°æ±¾¡¢²Ù×÷ϵͳÃû³Æ¡¢ÕË»§ÃÜÂëµÈÊý¾Ý²¢·¢ËÍÖÁC&C·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.fortinet.com/blog/threat-research/analysis-metamorfo-variant-targets-financial-organizations.html


¾©¹«Íø°²±¸11010802024551ºÅ