ÃÀ¹úÌìÈ»Æø¹Ü·ÔËÓªÉÌÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £» £»£»£»£»£»£»SharePointÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2019-0604)

°ä²¼¹¦·ò 2020-02-19

1.ÃÀ¹úÌìÈ»Æø¹Ü·ÔËÓªÉÌÔâµ½ÀÕË÷Èí¼þ¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝÃÀ¹úºÓɽ°²È«ÊýÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨DHS CISA£©°ä²¼µÄ´«µÝ£¬£¬£¬£¬ £¬ £¬£¬Ò»¼Òδ¾ßÃûµÄÃÀ¹úÌìÈ»ÆøÑ¹Ëõ¹¤³§ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ £¬ £¬£¬µ¼ÖÂÔËÓªÖжÏÁËÁ½ÌìµÄ¹¦·ò¡£¡£¡£¡£¡£¡£¡£¡£CISA°µÊ¾¹¥»÷ÕßÊ×ÏÈÀûÓô¹µöÁ´½Ó»ñµÃÁ˶ԸÃ×éÖ¯ITÍøÂçµÄ½Ó¼û£¬£¬£¬£¬ £¬ £¬£¬¶øºóתÏòÆäOTÍøÂç²¢²¿ÊðÁËÉÌÓÃÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þͬʱÔÚITºÍOTÍøÂçÉ϶Թ«Ë¾µÄÊý¾Ý½øÐмÓÃÜ£¬£¬£¬£¬ £¬ £¬£¬ÒÔ×î´óˮƽµØ·ÛËéÆóÒµ£¬£¬£¬£¬ £¬ £¬£¬¶øºó²ÅÒªÇóÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þ²¢Î´Ó°ÏìÈκÎPLC£¬£¬£¬£¬ £¬ £¬£¬µ«ÈËÀà²Ù×÷Ô±ÎÞ·¨»ã×ܺͶÁÈ¡Óйع¤Òµ¹ý³ÌÖеÄÊý¾Ý£¬£¬£¬£¬ £¬ £¬£¬ÀýÈçHMI¡¢Êý¾Ýº¹Çà¼Í¼ºÍÂÖѯ·þÎñÆ÷£¬£¬£¬£¬ £¬ £¬£¬´Ó¶øµ¼ÖÂÔ±¹¤ÎÞ·¨°ÑÎչܷÉèÊ©µÄÔËÐÐÇé¿ö¡£¡£¡£¡£¡£¡£¡£¡£¹Ü·ÔËÓªÉÌÖ´ÐÐÁË¡°ÓдòËãµÄ¡¢ÊܿصĹعء±´ëÊ©£¬£¬£¬£¬ £¬ £¬£¬ÒÔÔ¤·À²¢Ô¤·ÀÈκÎÊÂÎñµÄ²úÉú¡£¡£¡£¡£¡£¡£¡£¡£CISA°µÊ¾ÔËÓªÖжϳÖÐøÁËÔ¼Á½Ì죬£¬£¬£¬ £¬ £¬£¬¶øºó¸´Ô­ÁËÕý³£ÔË×÷¡£¡£¡£¡£¡£¡£¡£¡£CISAûÓÐй©ÀÕË÷Èí¼þµÄÃû³Æ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/dhs-says-ransomware-hit-us-gas-pipeline-operator/


2.SharePointÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2019-0604)


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÔ±Dhiraj Mishra·¢ÏÖSharePoint´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0604£©£¬£¬£¬£¬ £¬ £¬£¬¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâSharePointÊý¾Ý°üÀ´ÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£Ó¡¶È˰Îñ¾Ö¹ÙÍø£¨incometaxindia.gov.in£©¼°ÂéÊ¡Àí¹¤µÄ˹¡ÖÎÀíÑ§ÔºÍøÕ¾¶¼Êܵ½¸Ã·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±±ðÀëÔÚ2ÔÂ12ÈÕºÍ13ÈÕ֪ͨÁËCERT-InºÍMIT°²È«ÍŶӣ¬£¬£¬£¬ £¬ £¬£¬ÕâÁ½¸öÍøÕ¾¶¼ÒѾ²Ä¬½¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/98043/hacking/sharepoint-rce.html


3.·¸×ïÍÅ»ïAPT-C-23ÓÕÆ­ÒÔÉ«Áйú·ÀÊ¿±ø×°ÖöñÒâÈí¼þ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÒÔÉ«Áйú·À¾ü£¨IDF£©°µÊ¾¹þÂí˹¼¤½ø×éÖ¯ÀûÓÃÃÀÅ®µÄÕÕÆ¬ÓÕÆ­ÒÔÉ«Áйú·ÀÊ¿±ø×°ÖöñÒâÈí¼þ£¬£¬£¬£¬ £¬ £¬£¬¸Ã¹¥»÷Õß±»¼ø±ðΪAPT-C-23¡£¡£¡£¡£¡£¡£¡£¡£IDF½²»°ÈËHedy Silberman³Æ¹¥»÷Õß´´½¨ÁËÁù¸öÅ®ÐÔ½ÇÉ«£¬£¬£¬£¬ £¬ £¬£¬Í¨¹ý¶àÖÖÐÂÎÅ´«µÝƽ̨£¨Facebook¡¢WhatsApp¡¢Telegram¡¢Instagram£©ÓëÊ¿±øÌ¸Ì죬£¬£¬£¬ £¬ £¬£¬¶øºóÓÕʹËûÃÇ´ÓÒ»¸öÁ´½ÓÖÐÏÂÔØ¾Ý³ÆÀàËÆÓÚSnapchatµÄAPP¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩAPPÖ»ÊÇÊÖ»úÔ¶¿ØÄ¾Âí£¨MRAT£©µÄ¼Ù×°£¬£¬£¬£¬ £¬ £¬£¬¶ñÒâÈí¼þ½«Í¨¹ýMQTTºÍ̸ÓëC2·þÎñÆ÷½øÐÐͨѶ£¬£¬£¬£¬ £¬ £¬£¬²¢Äܹ»ÍøÂçÉ豸µÄÐÅÏ¢£¬£¬£¬£¬ £¬ £¬£¬Ô̺¬µç»°ºÅÂë¡¢GPSÐÅÏ¢¡¢´æ´¢Êý¾ÝºÍSMSÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£¡£IDFÖ¸³ö¸Ã¶ñÒâÈí¼þ»¹Äܹ»ÅÄÕÕ¡¢ÇÔÈ¡ÁªÏµÈËÁбíÒÔ¼°ÏÂÔØºÍÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-group-catfishes-israeli-soldiers-into-installing-mobile-rat/


4.°®ºÉ»ªÖÝÒ½ÁƱ£½¡¹«Ë¾MCHCй¶Լ7500Ãû»¼ÕßÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°®ºÉ»ªÖÝÒ½ÁƱ£½¡¹«Ë¾£¨MCHC£©ÔÚÖÜÒ»°ä²¼µÄÐÂÎÅÖгƣ¬£¬£¬£¬ £¬ £¬£¬¸Ã×éÖ¯ÓÚ2019Äê12ÔÂ19ÈÕ·¢ÏÔìäµç×ÓÓʼþϵͳÔâµ½¹¥»÷£¬£¬£¬£¬ £¬ £¬£¬Ô¼ÓÐ7500Ãû»¼ÕßµÄÒ½ÁÆÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚ2019Äê10ÔÂ28ÈÕÖÁ2020Äê1ÔÂ20ÈÕÖ®¼ä½Ó¼ûÁ˶à¸öÔ±¹¤µÄµç×ÓÓʼþÕË»§£¬£¬£¬£¬ £¬ £¬£¬¿ÉÄÜÇÔÈ¡µÄ»¼ÕßÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢±£ÏÕÐÅÏ¢ºÍÁÙ´²ÐÅÏ¢£¨ÀýÈç¾ÍÕïÔ­Òò£©¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯°µÊ¾²¿ÃÅ»¼ÕßµÄÉç»á°²È«ºÅÂë¿ÉÄÜÒ²ÔâÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯°µÊ¾ËùÓÐMCHCÔ±¹¤¶¼±ØÐë³ÁÉèÆäµç×ÓÓʼþÕÊ»§ÃÜÂë²¢½ÓÊÜеÄÍøÂ簲ȫÅàѵ¡£¡£¡£¡£¡£¡£¡£¡£ÐÂΟ廹³ÆÊÜÓ°ÏìµÄ»¼ÕßÄܹ»Í¨¹ýMCHC»ñµÃÒ»ÄêµÄÐÅÓþ¼à¿Ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.desmoinesregister.com/story/news/2020/02/17/monroe-iowa-county-hospital-patients-data-breach-victims/4790481002/


5.AZORultľÂíбäÖÖ¼Ù×°³ÉProtonVPN×°Ö÷¨Ê½´«²¼


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÈËÔ±¹Û²ìµ½AZORultľÂíµÄбäÖÖ¼Ù×°³ÉProtonVPN×°Ö÷¨Ê½½øÐзַ¢¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯×Ô2019Äê11ÔÂÆðÍ·£¬£¬£¬£¬ £¬ £¬£¬¹¥»÷Õßͨ¹ýÏò¶íÂÞ˹ע²áÉÌ×¢²áÓòÃû¡°protonvpn[.]store¡±À´ÌáÒé´Ë¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓöñÒâ¸æ°××÷ΪÆä³õʼϰȾý½é£¬£¬£¬£¬ £¬ £¬£¬AZORult½«ÍøÂçÊܺ¦ÕßµÄϵͳ»·¾³Êý¾Ý£¬£¬£¬£¬ £¬ £¬£¬²¢½«Æä·¢Ë͵½Î»ÓÚaccounts[.]protonvpn[.]storeµÄC2·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃľÂí»¹Äܹ»´Ó±¾µØÇ®°üÇÔÈ¡¼ÓÃÜÇ®±Ò£¨Electrum¡¢Bitcoin¡¢EtheriumµÈ£©£¬£¬£¬£¬ £¬ £¬£¬´ÓFileZillaÇÔÈ¡FTPµÇ¼ÃûºÍÃÜÂëÒÔ¼°ÇÔÈ¡µç×ÓÓʼþÍ´´¦ºÍä¯ÀÀÆ÷cookieµÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/featured/azorult-trojan-disguised-itself-as-fake-protonvpn-installer/


6.×êÑÐÍŶӰ䲼Gamaredon APT¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Yoroy-Cybaze ZLabµÄ°²È«×¨¼Ò¶ÔGamaredon APTʹÓõĶñÒâÈí¼þ½øÐÐÁ˾ßÌåµÄ·ÖÎö¡£¡£¡£¡£¡£¡£¡£¡£Gamaredon×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬ £¬ £¬£¬ÆäÖØÒªÓë¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÄµØÔµÕþÖÎÓйØ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯×ʹÓõĶñÒâÈí¼þÖ²È뷨ʽΪPteranodon»òPterodo£¬£¬£¬£¬ £¬ £¬£¬ËüÓɶ༶ºóÃÅ×é³É£¬£¬£¬£¬ £¬ £¬£¬Ö¼ÔÚÍøÂçÃô¸ÐÐÅÏ¢»òά³ÖÊÜϰȾ»úеµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£PterodoÖØÒªÍ¨¹ýÕë¶Ô¾üÊÂÈËÔ±µÄ´¹µö»î¶¯·Ö·¢£¬£¬£¬£¬ £¬ £¬£¬×î½üµÄÒ»²¨¹¥»÷º£³±Äܹ»×·ÒäÖÁ2019Äê11Ô¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/97992/apt/gamaredon-espionage-campaign.html