FIN6¼°ÔËÓªTrickBotµÄÍÅ»ï½áºÏµÄ¹¥»÷»î¶¯£»HMR¹«Ë¾Ôâµ½ÀÕË÷Èí¼þMaze¹¥»÷

°ä²¼¹¦·ò 2020-04-09

1.Ò©Îï²âÊÔ¹«Ë¾HMRÔâµ½ÀÕË÷Èí¼þMaze¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ò©Îï²âÊÔ¹«Ë¾HMRÔâµ½ÀÕË÷Èí¼þMaze¹¥»÷£¬²¢ÇÒ²¿ÃÅ×ÔÔ¸ÕßÐÅÏ¢±»µÁ ¡£¸Ã¹¥»÷²úÉúÔÚ3ÔÂ14ÈÕ£¬Maze¹¥»÷ÕßÇÔÈ¡ÁËHMRÍøÂçÉÏÍйܵÄÊý¾Ý²¢¶ÔÆäÍÆËã»ú½øÐмÓÃÜ ¡£ÓÉÓڸù«Ë¾»Ø¾øÖ§¸¶Êê½ð£¬MazeÍÅ»ïÓÚ3ÔÂ21ÈÕÔÚÆäÍøÕ¾Éϰ䲼Á˲¿Ãű»µÁµÄÊý¾Ý ¡£Æ¾¾ÝHMRµÄÊý¾Ýй¶֪ͨ£¬Ê§ÇԵļͼÔ̺¬ÁËÒÔD¡¢G¡¢I»òJ¿ªÍ·µÄ×ÔÔ¸ÕßÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éí·ÝÖ¤Ã÷Îļþ¡¢½¡È«µ÷²é±í¡¢ÔÞ³ÉÊé¡¢²¿Ãżì²âÁ˾ֵÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/drug-testing-firm-sends-data-breach-alerts-after-ransomware-attack/


2.Bitdefender×êÑÐÍŶӷ¢ÏÖÐÂIoT½©Ê¬ÍøÂçdark_nexus


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Bitdefender×êÑÐÈËÔ±×î½ü·¢ÏÖÁËÒ»¸öеÄIoT½©Ê¬ÍøÂ磬ËüÔ̺¬Á˳¬¹ý´óÎÞÊýIoT½©Ê¬ÍøÂçºÍ¶ñÒâÈí¼þµÄÐÂÖ°ÄÜ ¡£×êÑÐÈËԱƾ¾Ý½©Ê¬ÍøÂçʹÓõĵÄ×Ö·û´®½«Æä¶¨ÃûΪ¡°dark_nexus¡± ¡£Ö»¹Üdark_nexus³ÁÓÃÁËһЩQbotºÍMirai´úÂ룬µ«ÆäÖ÷ÌâÄ£¿é´ó¶àÊÇÔ­ÉúµÄ ¡£Ö»¹Ü¸Ã½©Ê¬ÍøÂç¿ÉÄÜÓëÒÔǰÒÑÖªµÄIoT½©Ê¬ÍøÂç¹²ÏíijЩְÄÜ£¬µ«ÊÇÆä²¿ÃÅÄ£¿éµÄ¿ª·¢·½Ê½Ê¹ÆäÖ°ÄÜÔ½·¢×³´ó£¬ÀýÈçÓÐÐ§ÔØºÉÕë¶Ô12ÖÖ·ÖÆçµÄCPU¼Ü¹¹½øÐбàÒ룬²¢Æ¾¾ÝÊܺ¦ÕßµÄÅäÖö¯Ì¬´«µÝ ¡£dark_nexus»¹¹ÖÒìµØÊ¹ÓûùÓÚȨ³ÁºÍãÐÖµµÄÆÀ·ÖϵͳÀ´ÆÀ¹ÀÄÄЩ¹ý³Ì¿ÉÄÜ×é³É·çÏÕ£¬²¢É±ËÀËùÓг¬¹ý¿ÉÒÉãÐÖµµÄÆäËü¹ý³Ì ¡£


Ô­ÎÄÁ´½Ó£º

https://labs.bitdefender.com/2020/04/new-dark_nexus-iot-botnet-puts-others-to-shame/


3.FIN6¼°ÔËÓªTrickBotµÄÍÅ»ï½áºÏµÄ¹¥»÷»î¶¯


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


IBM X-Force×êÑÐÈËÔ±°µÊ¾£¬ÔÚ×î½üµÄÍøÂç¹¥»÷Öз¢ÏÖÁËFIN6µÄºÛ¼££¬ÕâЩ¹¥»÷»î¶¯×î³õÀûÓÃTrickBotľÂíϰȾÊܺ¦Õߣ¬¶øºó×îÖÕÏÂÔØÁËAnchorºóÃÅ ¡£×êÑÐÈËÔ±³ÆÕâÁ½¸ö·¸×ï×éÖ¯-TrickBotµÄÔËÓªÍÅ»ïÒÔ¼°FIN6-ÒѾ­½øÐкÏ×÷£¬ÕâÊÇÍøÂç·¸×OÌåÏÖÓкÏ×÷Ç÷ÏòÖеġ°ÐµÄΣÏÕתÕÛ¡± ¡£AnchorÖÁÉÙÄܹ»×·Òäµ½2018Ä꣬ËƺõÊÇÓÉTrickBotµÄÔËÓªÍÅ»ï±àдµÄ¡°¡°¶àºÏÒ»¹¥»÷¿ò¼Ü¡±£¬ËüÓɸ÷Àà×ÓÄ£¿é×é³É£¬Äܹ»Ô®ÊÖ¹¥»÷ÕßÔÚÍøÂçÉϺáÏò´«²¼£¨ÀýÈç×°ÖúóÃÅ£© ¡£Í¬Ê±TrickBotµÄÁíÒ»¸ö¹¤¾ßPowerTrickÖØÒªÓÃÓÚÔÚÊÜϰȾµÄ¸ß¼ÛÖµÖ¸±ê£¨ÀýÈç½ðÈÚ»ú¹¹£©ÄÚ²¿½øÐÐÒþÉí¡¢ÓÆ¾ÃÐԺͿúËÅ ¡£IBM X-ForceÖ¸³öFIN6²Î¼ÓÁËÀûÓÃAnchorºÍPowerTrickµÄ¹¥»÷£¬Æä´æÔÚµÄ×î´óÖ¸±êÊǹ¥»÷ÖÐʹÓõÄ×°ÔØ·¨Ê½£¨Terraloader£©ºÍºóÃÅ£¨More_eggs£© ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/fin6-and-trickbot-combine-forces-in-anchor-attacks/154508/


4.¹¥»÷ÕßÀÄÓÃMalwarebytesÆ·ÅÆ·Ö·¢RaccoonľÂí


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÀÄÓÃMalwarebytesÆ·ÅÆµÄ¶ñÒâ»î¶¯£¬¹¥»÷Õß´´½¨ÁËÒ»¸ö·ÂðµÄMalwarebytesÍøÕ¾£¬¸ÃÍøÕ¾ÓÃÓÚ·Ö·¢RaccoonľÂí ¡£¸Ã¶ñÒâÓòÃûÊÇmalwarebytes-free[.]com£¬ÔÚ3ÔÂ29ÈÕͨ¹ýÓòÃû×¢²áÉÌREG.RU LLC×¢²á£¬µ±Ç°ÍйÜÔÚ¶íÂÞ˹µÄIP 173.192.139[.]27ÉÏ ¡£¸ÃÍøÕ¾ÉϵÄJavaScript´úÂë¶Î»á²é³­·Ã¿ÍµÄä¯ÀÀÆ÷ÀàÐÍ£¬ÈôÊÇÊÇInternet Explorer£¬Ôò»á½«Óû§³Á¶¨ÏòÖÁFallout EKµÄ¶ñÒâURL£¬²¢×îÖÕ×°ÖÃRaccoon ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/exploits-and-vulnerabilities/2020/04/copycat-criminals-abuse-malwarebytes-brand-in-malvertising-campaign/


5.¹È¸è°ä²¼Chrome°²È«¸üУ¬½¨¸´32¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸èÒÑÓÚ4ÔÂ7ÈÕÏòWindows¡¢macOSºÍLinux°ä²¼ÁËChrome 81£¬³ýÁËbug½¨¸´¡¢ÐÂÖ°ÄÜÖ®±í£¬¸Ã°æ±¾»¹½¨¸´ÁË32¸ö°²È«·ì϶ ¡£ÆäÖÐ3¸ö·ì϶µÄÑϳÁÐԵȼ¶Îª¸ß£¬Ô̺¬À©´óÖеÄUAF·ì϶£¨CVE-2020-6454£©¡¢ÒôƵ×é¼þÖеÄUAF·ì϶£¨CVE-2020-6423£©ºÍWebSQLÖеÄÔ½½ç¶Á·ì϶£¨CVE-2020-6455£© ¡£ÆäÓà·ì϶µÄÑϳÁÐԵȼ¶ÎªÖлòµÍ ¡£´Ë±í£¬¹È¸èÔ­´òËãÔÚChrome 81ÖÐÆëȫɾ³ý¶ÔTLS 1.0ºÍ1.1µÄÖ§³Ö£¬µ«ÓÉÓÚ¹Ú×´²¡¶¾µÄÊ¢ÐУ¬¹È¸èÒѾö¶¨½«ÕâÒ»Ðж¯ÍƳٵ½Chrome 84 ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/chrome-81-released-with-32-security-fixes-and-web-nfc-api/


6.±´¼ÓÀ³½¨¸´Automation StudioÈí¼þÖеĶà¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖ±´¼ÓÀ³¹¤Òµ×Ô¶¯»¯¹«Ë¾µÄAutomation StudioÈí¼þ´æÔÚ¶à¸ö·ì϶£¬¹©¸øÉÌÒÑÆðÍ·°ä²¼²¹¶¡ ¡£±´¼ÓÀ³ÊÇÒ»¼ÒλÓڰµØÀûµÄ¹¤Òµ×Ô¶¯»¯¹«Ë¾£¬¾ÝÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©³Æ£¬¸Ã¹«Ë¾µÄ²úÆ·ÔÚÈ«ÇòÁìÓòÄÚʹÓ㬳ö¸ñÊÇÔÚÄÜÔ´¡¢»¯¹¤ºÍ¹Ø¼üÔì×÷ÁìÓò ¡£¸Ã¹«Ë¾µÄAutomation Studio°æ±¾4ÊÜÈý¸ö·ì϶µÄÓ°Ï죬ÕâЩ·ì϶ÓëAutomation StudioµÄ¸üзþÎñÓйØ£¬Ô̺¬ÌØÈ¨Éý¼¶·ì϶¡¢²»ÆëÈ«µÄͨѶ¼ÓÃܺÍÑéÖ¤ÎÊÌâÒÔ¼°Óë2018Äê·¢ÏÖµÄZip SlipËÁÒâÎļþ¸²¸Ç·ì϶ÓйصÄõè¾¶±éÀú·ì϶ ¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ִÐÐMITM¹¥»÷²¢¹ýÎÊÈí¼þ¸üйý³Ì ¡£±´¼ÓÀ³ÒѾ­Îª²¿ÃÅÊÜÓ°ÏìµÄ°æ±¾°ä²¼Á˲¹¶¡£¬²¢ÔÚΪÆäÓà°æ±¾½øÐн¨¸´ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/vulnerabilities-br-automation-software-facilitate-attacks-ics-networks