Aqua SecurityÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄ¼¼Êõϸ½Ú

°ä²¼¹¦·ò 2021-12-31

Unit42³Æ´ó¶àAPTÍÅ»ïʹÓõÄÓò×¢²áÓÚÊýÄê֮ǰ


Unit42³Æ´ó¶àAPTÍÅ»ïʹÓõÄÓò×¢²áÓÚÊýÄê֮ǰ.png


Unit42ÔÚ12ÔÂ29ÈÕ°ä²¼µÄ×îÐÂ×êÑÐÏÔʾ£¬£¬ £¬£¬£¬£¬ £¬´ó¶àAPTÍÅ»ïʹÓõÄÓò×¢²áÓÚÊýÄê֮ǰ¡£¡£¡£¡£¡£¡£Í¨³££¬£¬ £¬£¬£¬£¬ £¬ÐÂ×¢²áµÄÓò(NRD) ¸üÓпÉÄÜÊǶñÒâµÄ£¬£¬ £¬£¬£¬£¬ £¬Òò¶ø°²È«½â¾ö¹æ»®½«³Áµã¼ì²â²¢ÏóÕ÷ËüÃÇ¡£¡£¡£¡£¡£¡£µ«Unit42Ö¸³ö£¬£¬ £¬£¬£¬£¬ £¬ÍùÄê×¢²áµÄÓòÊǶñÒâµÄ¿ÉÄÜÐÔ±ÈNRD¸ßÈý±¶¡£¡£¡£¡£¡£¡£ÓÐʱ£¬£¬ £¬£¬£¬£¬ £¬´ËÀàÓòÃûÔÚÐÝÃßÁ½ÄêÖ®ºóDNSÁ÷Á¿¼¤Ôö165±¶£¬£¬ £¬£¬£¬£¬ £¬ÕâÅú×¢¹¥»÷ÕßÒÑÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ9Ô·ݵÄͳ¼ÆÁ˾ÖÏÔʾ£¬£¬ £¬£¬£¬£¬ £¬Ô¼3.8%µÄÓòÃûÊǶñÒâµÄ£¬£¬ £¬£¬£¬£¬ £¬19%ÊÇ¿ÉÒɵ쬣¬ £¬£¬£¬£¬ £¬2%µÄ»·¾³²»°²È«¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/strategically-aged-domain-detection/


Aqua SecurityÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄ¼¼Êõϸ½Ú


Aqua SecurityÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄ¼¼Êõϸ½Ú.png


12ÔÂ29ÈÕ£¬£¬ £¬£¬£¬£¬ £¬DevSecOpsºÍAqua Security½áºÏÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¡£¸Ã»î¶¯³õ´Î³öÏÖÓÚ2019Ä꣬£¬ £¬£¬£¬£¬ £¬ÆðÍ·»áÔÚÔËÐÐÔ­°æ¾µÏñalpine:latestʱִÐжñÒâºÅÁ£¬ £¬£¬£¬£¬ £¬²¢ÏÂÔØÃûΪautom.shµÄshell¾ç±¾¡£¡£¡£¡£¡£¡£Ö®ºó»áÀûÓøþ籾´´½¨Ò»¸öÐÂÓû§akay²¢½«ÆäȨÏÞÉý¼¶Îªroot£¬£¬ £¬£¬£¬£¬ £¬Ê¹ÓøÃÓû§ÔÚÖ¸±êÉ豸ÉÏÔËÐÐËÁÒâºÅÁ£¬ £¬£¬£¬£¬ £¬²¢ÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£»ã±¨»¹Áгö¸Ã»î¶¯µÄMITRE ATT&CKºÍIOC¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.aquasec.com/attack-techniques-autom-cryptomining-campaign


AmnpardazÔÚÒ°·¢ÏÖÕë¶ÔHP iLOµÄÐÂiLOBleed


AmnpardazÔÚÒ°·¢ÏÖÕë¶ÔHP iLOµÄÐÂiLOBleed.png


¾ÝýÌå12ÔÂ28Èճƣ¬£¬ £¬£¬£¬£¬ £¬ÒÁÀʰ²È«¹«Ë¾AmnpardazÔÚÒ°·¢ÏÖÕë¶Ô»ÝÆÕIntegrated Lights-Out(iLO)µÄжñÒâÈí¼þiLOBleed¡£¡£¡£¡£¡£¡£ÕâÊÇÊ׸öÕë¶ÔiLO¹Ì¼þµÄrootkit£¬£¬ £¬£¬£¬£¬ £¬ËüÄܹ»³¤¹¦·òµØ°µ²ØÔÚiLOÖв¢ÇÒ²»»áÔڹ̼þÉý¼¶Öб»É¾³ý¡£¡£¡£¡£¡£¡£iLOBleed×Ô2020ÄêÒÔÀ´Ò»Ïò±»ÓÃÓÚ¹¥»÷£¬£¬ £¬£¬£¬£¬ £¬¿É´Û¸Ä¹Ì¼þÄ£¿£¿ £¿£¿£¿£¿ £¿ £¿é²¢É¾³ý±»Ï°È¾ÏµÍ³ÖеÄÊý¾Ý¡£¡£¡£¡£¡£¡£Ä¿Ç°¸Ã¶ñÒâÈí¼þ±³ºó¹¥»÷ÕßµÄÉí·ÝÈÔδȷ¶¨£¬£¬ £¬£¬£¬£¬ £¬µ«Amnpardaz´§Ä¦ËüÓëij¸öÓɹú¶ÈÖ§³ÖµÄAPT×éÖ¯Óйء£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threats.amnpardaz.com/en/2021/12/28/implant-arm-ilobleed-a/


Ô½ÄϹ«Ë¾ONUSÔâÀÕË÷¹¥»÷£¬£¬ £¬£¬£¬£¬ £¬»Ø¾øÖ§¸¶500ÍòÃÀÔªÊê½ð


Ô½ÄϹ«Ë¾ONUSÔâÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬»Ø¾øÖ§¸¶500ÍòÃÀÔªÊê½ð.png


¾ÝýÌå12ÔÂ29ÈÕ±¨Â·£¬£¬ £¬£¬£¬£¬ £¬Ô½ÄϵĽðÈڿƼ¼¹«Ë¾ONUSÔâµ½ÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£12ÔÂ11ÈÕÖÁ13ÈÕÆÚ¼ä£¬£¬ £¬£¬£¬£¬ £¬¹¥»÷Õ߳ɹ¦ÀûÓÃONUS Cyclos·þÎñÆ÷ÉϵÄLog4Shell·ì϶£¬£¬ £¬£¬£¬£¬ £¬²¢Ö²ÈëºóÃÅ¡£¡£¡£¡£¡£¡£CyclosÔÚ13ÈÕ°ä²¼²¼¸æ³Æ½¨¸´Æäϵͳ£¬£¬ £¬£¬£¬£¬ £¬µ«´ËʱΪʱÒÑÍí¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒÑÇÔÈ¡¸Ã¹«Ë¾½ü200ÍòÌõ¿Í»§¼Í¼£¬£¬ £¬£¬£¬£¬ £¬Ô̺¬E-KYCÊý¾Ý¡¢Ó×ÎÒÐÅÏ¢ºÍÃÜÂë¡£¡£¡£¡£¡£¡£12ÔÂ25ÈÕ£¬£¬ £¬£¬£¬£¬ £¬ONUS»Ø¾øÖ§¸¶500ÍòÃÀÔªµÄÊê½ðÖ®ºó£¬£¬ £¬£¬£¬£¬ £¬¹¥»÷Õ߯ðÍ·ÏúÊÛÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fintech-firm-hit-by-log4j-hack-refuses-to-pay-5-million-ransom/


AvosLockerÔÚÈëÇÖÃÀ¹ú¾¯Ô±¾ÖºóÏòÆäÌṩ½âÃÜÆ÷


AvosLockerÔÚÈëÇÖÃÀ¹ú¾¯Ô±¾ÖºóÏòÆäÌṩ½âÃÜÆ÷.png


ýÌå12ÔÂ29Èճƣ¬£¬ £¬£¬£¬£¬ £¬AvosLockerÒÑÃâ·ÑÏòÃÀ¹ú¾¯Ô±¾ÖÌṩ½âÃÜÆ÷¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÉϸöÔÂÒÑÈëÇÖÃÀ¹úµÄ¾¯Ô±¾Ö£¬£¬ £¬£¬£¬£¬ £¬¹¥»÷ÆÚ¼äÇÔÈ¡¸Ã»ú¹¹µÄÊý¾Ý²¢¼ÓÃÜÆäÉ豸¡£¡£¡£¡£¡£¡£AvosLockerÔÚµÃÖª¶Ô·½Êǵ±¾Ö»ú¹¹ºóÁ¢¿Ì·Ǹ£¬£¬ £¬£¬£¬£¬ £¬²¢Ãâ·ÑÌṩ½âÃÜÆ÷¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄ³ÉÔ±°µÊ¾£¬£¬ £¬£¬£¬£¬ £¬ËûÃÇûÓоßÌåµÄÕë¶ÔÖ¸±êµÄÕþ²ß£¬£¬ £¬£¬£¬£¬ £¬µ«Í¨³£»£»£»£»£»áÔ¤·À¶Ôµ±¾Ö»ú¹¹ºÍÒ½Ôº½øÐй¥»÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-gang-coughs-up-decryptor-after-realizing-they-hit-the-police/


Òò»ÝÆÕ³¬ËãµÄ±¸·ÝϵͳÃýÎ󣬣¬ £¬£¬£¬£¬ £¬¾©¶¼´óѧÃÔʧ77TBÊý¾Ý


Òò»ÝÆÕ³¬ËãµÄ±¸·ÝϵͳÃýÎ󣬣¬£¬£¬£¬£¬£¬¾©¶¼´óѧÃÔʧ77TBÊý¾Ý.png


¾ÝýÌåÓÚ12ÔÂ30ÈÕ±¨Â·£¬£¬ £¬£¬£¬£¬ £¬ÓÉÓÚ»ÝÆÕ¹«Ë¾³¬µÈÍÆËã»úµÄ±¸·Ýϵͳ³öÏÖÃýÎ󣬣¬ £¬£¬£¬£¬ £¬µ¼ÖÂÈÕ±¾¾©¶¼´óѧԼ77TBµÄ¿ÆÑÐÊý¾Ý±»Îóɾ¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ²úÉúÔÚ2021Äê12ÔÂ14ÈÕÖÁ16ÈÕ£¬£¬ £¬£¬£¬£¬ £¬14¸ö¿ÆÑÐÓ××éµÄ3400Íò·ÝÎļþ´ÓϵͳºÍ±¸·ÝÎļþÖб»É¾³ý¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬ £¬£¬£¬£¬ £¬±¸·Ý·¨Ê½±¾Ó¦Ê¹ÓÃfindºÅÁîɾ³ý³¬¹ý10ÌìµÄ¾ÉÈÕÖ¾£¬£¬ £¬£¬£¬£¬ £¬µ«ÆäÃýÎóµØÖ´ÐÐÁËÔ̺¬Î´½ç˵±äÁ¿µÄfindºÅÁ£¬ £¬£¬£¬£¬ £¬É¾³ýÁË/LARGE0Ŀ¼ÏµÄÕý³£Îļþ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬ £¬£¬£¬£¬ £¬¸Ã´óѧÒѰγý¸Ã±¸·Ýϵͳ£¬£¬ £¬£¬£¬£¬ £¬²¢´òËãÔÚ2022Äê1Ô³ÁÐÂÒýÈë¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/university-loses-77tb-of-research-data-due-to-backup-error/