΢Èí°ä²¼²¼¸æ³ÆIE 0dayÒÑÔâÒ°±íÀûÓã¬Ä¿Ç°ÉÐÎÞ²¹¶¡£»Î÷ÃÅ×ÓÖÒ¸æ¿Í»§ÓйØÔÚ¹¤Òµ²úÆ·ÖÐʹÓÃActiveXµÄ·çÏÕ

°ä²¼¹¦·ò 2020-01-19


1.΢Èí°ä²¼²¼¸æ³ÆIE 0dayÒÑÔâÒ°±íÀûÓã¬Ä¿Ç°ÉÐÎÞ²¹¶¡


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


1ÔÂ17ÈÕ΢Èí°ä²¼°²È«²¼¸æ£¨ADV200001£©£¬ÖÒ¸æÓû§¹ØÓÚIE 0day£¨CVE-2020-0674£©ÒÑÔâÒ°±íÀûÓõÄÇé¿ö£¬²¢ÇҸ÷ì϶ÔÝÎÞ½¨¸´²¹¶¡£¬½öÓÐÓ¦±ä´ëÊ©»ººÍ½â´ëÊ©¡£Î¢Èí°µÊ¾ÔÚÍÆ³ö½â¾ö¹æ»®£¬¿ÉÄÜÔÚºóÐøÒÔ´ø±í¸üеķ½Ê½°ä²¼¡£¸Ã0dayδÔâ´ó¹æÄ£ÀûÓã¬Ö»ÊÇÕë¶ÔÉÙÁ¿Óû§¹¥»÷µÄÒ»²¿ÃÅ¡£Æ¾¾Ý²¼¸æ£¬Î¢Èí³Æ¸Ã0dayΪԶ³Ì´úÂëÖ´Ðзì϶£¨RCE£©£¬ÓëIE¾ç±¾ÒýÇæÔÚ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÓйØ¡£ÕâÊÇÒ»¸öÄÚ´æ°Ü»µ·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÒÔµ±Ç°Óû§µÄȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£ÔÚweb¹¥»÷³¡¾°ÖУ¬¹¥»÷Õß¿Éͨ¹ýÓÕʹÓû§½Ó¼û¶ñÒâÍøÕ¾À´ÀûÓø÷ì϶£¨ÀýÈçͨ¹ý´¹µöÓʼþ£©¡£Óû§¿Éͨ¹ýÏ޶ȶÔJScript.dllµÄ½Ó¼ûÀ´ÁÙʱ»º½â¸Ã·ì϶¡£

  Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/01/internet-explorer-zero-day-attack.html


2.Î÷ÃÅ×ÓÖÒ¸æ¿Í»§ÓйØÔÚ¹¤Òµ²úÆ·ÖÐʹÓÃActiveXµÄ·çÏÕ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Î÷ÃÅ×ÓµÄһЩ¹¤Òµ²úÆ·£¨Ô̺¬SIMATIC WinCC¡¢SIMATIC STEP 7¡¢SIMATIC PCS 7¡¢TIA PortalºÍS7-PLCSIM Advanced£©ÒÀÀµActiveX×é¼þ£¬¿Í»§±ØÒªÊ¹ÓÃInternet ExplorerÀ´Ö´ÐÐÕâЩ×é¼þ¡£µ«¸Ã³§ÉÌÖÒ¸æ¿Í»§³Æ£¬Ê¹ÓÃIE½Ó¼û²»ÊÜÐÅÀµµÄÍøÕ¾¿ÉÄÜ»á´øÀ´ÑϳÁµÄ°²È«·çÏÕ¡£Î÷ÃÅ×Ó½¨ÒéÔÚ½Ó¼ûÓ빫˾²úÆ·Î޹صÄÍøÒ³Ê±Ê¹Óò»Ö§³ÖActiveXµÄÍøÒ³ä¯ÀÀÆ÷¡£´Ë±í£¬Î÷ÃÅ×Ó½üÆÚ»¹½¨¸´ÁËSCALANCE X¹¤Òµ»¥»»»úÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2019-13933£¬CVSS v3.1ÆÀ·ÖΪ8.8·Ö£©¡¢ SINEMA ServerÖеIJ»ÕýÈ·µÄ»á»°ÑéÖ¤·ì϶£¨CVE-2019-10940£¬9.9·Ö£©ºÍTIA PortalÖеÄLPE·ì϶£¨CVE-2019-10934£¬7.8·Ö£©¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-warns-security-risks-associated-use-activex


3.×êÑÐÍŶӰ䲼ÀÕË÷Èí¼þParadiseµÄ½âÃܹ¤¾ß


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Bitdefender×êÑÐÍŶӰ䲼ÀÕË÷Èí¼þParadiseµÄ×îнâÃÜÆ÷¡£Paradise×î³õÓÚ2017Äê³öÏÖ£¬ËüÔÚ¼ÓÃÜʱ»áÈÆ¹ý¼üÅÌ˵»°Îª¶íÓï¡¢¹þÈø¿ËÓï¡¢°×¶íÂÞ˹Óï»òÎÚ¿ËÀ¼ÓïµÄϵͳ¡£Bitdefender°ä²¼µÄ×îнâÃÜÆ÷Ö§³ÖÒÔϺó׺ÃûµÄ±äÖÖ£º.FC¡¢.2ksys19¡¢.p3rf0rm4¡¢.Recognizer¡¢.VACv2¡¢.paradise¡¢.CORP¡¢.immortal¡¢.exploit¡¢.prt¡¢.STUB¡¢.sevºÍ.sambo¡£¸Ã¹¤¾ßÖ§³ÖGUI»òºÅÁî×ßÔËÐУ¬Óû§¿É´ÓBitdefender¹ÙÍøÏÂÔØ¸Ã¹¤¾ß¡£


 Ô­ÎÄÁ´½Ó£º

https://labs.bitdefender.com/2020/01/paradise-ransomware-decryption-tool/


4.ÍÁ¶úÆäºÚ¿Í¹¥»÷Ï£À°¶à¸öµ±²¿ÃÅÃźÍ֤ȯÂòÂôËùÍøÕ¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÉÏÖÜÎåÍÁ¶úÆäºÚ¿ÍÐû³ÆÒѾ­½Ù³ÖÁËÏ£À°Òé»á¡¢±í½»ºÍ¾­¼Ã²¿ÒÔ¼°¸Ã¹ú¶È֤ȯÂòÂôËùµÄ¹Ù·½ÍøÕ¾³¤´ï90¶à·ÖÖÓ¡£¸ÃºÚ¿ÍÍÅ»ïΪAnka Neferler Tim£¬ËûÃÇÔÚFacebookÒ³ÃæÉϱ绤³Æ¡°Ï£À°Ò»ÏòÔÚ°®ÇÙº£ºÍµØÖк£¶«²¿ÍþвÍÁ¶úÆä£¬´Ë¿ÌÓÖÔÚÍþвÀû±ÈÑÇºÍÆ½»áÒ顱¡£¸Ã»áÒéµÄÖ÷ÕÅÊÇÔÚ½áºÏ¹úµÄÖ÷³ÖÏÂÆô¶¯Àû±ÈÑÇµÄºÍÆ½¹ý³Ì£¬½«ÔÚ°ØÁÖ½øÐС£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/turkish-hackers-target-greek-government-websites-stock-exchange


5.ÐÂÔóÎ÷ÖÝÓÌÌ«½ÌÌÃÔâµ½ÀÕË÷Èí¼þSodinokibi¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÐÂÔóÎ÷ÖÝÎÖÂ×ÊеÄÓÌÌ«½ÌÌÃTemple Har ShalomÔâµ½ÀÕË÷Èí¼þSodinokibi¹¥»÷£¬ÆäÍøÂçÉϵĺܶàÍÆËã»úϵͳ±»¼ÓÃÜ¡£¸Ã½ÌÌÃÓÚ1ÔÂ9ÈÕ·¢ÏÖÁ˹¥»÷ÊÂÎñ£¬Æä·þÎñÆ÷ÉϵÄËùÓÐÎļþºÍµç×ÓÊý¾Ý¾ù±»¼ÓÃÜ£¬Ô̺¬ÕâЩÎļþºÍÊý¾ÝµÄ±¸·Ý¡£ÐÂÎÅÈËÊ¿³ÆSodinokibi¹¥»÷ÕßÒªÇó½ü50ÍòÃÀÔªµÄÊê½ð£¬µ«¸Ã½ÌÌðµÊ¾½«Óë»á¶àÁªÏµÒÔ»ñÈ¡³Á½¨¼ÓÃÜÎļþËùÐèµÄÐÅÏ¢£¬ÕâÅú×¢ËûÃÇÎÞÒâÖ§¸¶Êê½ð¡£ÓÉÓÚ¶àËùÖÜÖªSodinokibiÔÚ¼ÓÃÜÎļþ֮ǰ»áÏÈÇÔÈ¡Îļþ£¬Òò¶ø»á¶àµÄÐÕÃû¡¢µØÖ·ºÍµç×ÓÓʼþµØÖ·¿ÉÄܱ»µÁ£¬µ«¸Ã½ÌÌÃÒÔΪ¹¥»÷ÕßÎÞ·¨½Ó¼û²ÆÕþÐÅÏ¢¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-jersey-synagogue-suffers-sodinokibi-ransomware-attack/


6.¶ñÒâÈí¼þMetamorfoбäÖÖÖØÒªÕë¶Ô°ÍÎ÷½ðÈÚ»ú¹¹


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


FortiGuard Labs·¢ÏÖ¶ñÒâÈí¼þMetamorfoµÄбäÖÖ£¬¸Ã¶ñÒâÈí¼þÒÔÍøÂç°ÍÎ÷½ðÈÚ»ú¹¹¿Í»§µÄÊý¾Ý¶øÎÅÃû¡£¸Ã±äÖÖͨ¹ý´¹µöÓʼþ´«²¼£¬´¹µöÓʼþÓɰÍÎ÷¹Ù·½Ëµ»°ÆÏÌÑÑÀÓïд³É£¬ÄÚÈÝΪ¶½´ÙÊܺ¦ÕßÏÂÔØµç×Ó·¢Æ±£¨NF£©£¬µ«ÏÖʵÏÂÔØµÄÎļþΪXlsPlan_Visualize.msi¡£¸ÃMSIÎļþÖ»ÊÇÒ»¸ö¶ñÒâÈí¼þÏÂÔØÆ÷£¬×îÖÕ½«ÏÂÔØKJFLDKRE.msi²¢Ö´ÐУ¬¸ÃÎļþÊÇÕæÕýµÄMetamorfo¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þÄܹ»ÍøÂçÊܺ¦ÕßµÄÍÆËã»úÃû³Æ¡¢¿Í»§¶Ë°æ±¾¡¢²Ù×÷ϵͳÃû³Æ¡¢ÕË»§ÃÜÂëµÈÊý¾Ý²¢·¢ËÍÖÁC&C·þÎñÆ÷¡£


 Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/blog/threat-research/analysis-metamorfo-variant-targets-financial-organizations.html