CleafyÔÚGoogle Play·¢ÏÖ¼Ù×°³É¶þάÂëÀûÓõÄTeaBot

°ä²¼¹¦·ò 2022-03-04

CleafyÔÚGoogle Play·¢ÏÖ¼Ù×°³É¶þάÂëÀûÓõÄTeaBot


3ÔÂ1ÈÕ £¬Cleafy°ä²¼»ã±¨³ÆÆäÔÚGoogle PlayÉ̵êÖз¢ÏÖÁËÒøÐÐľÂíTeaBot¡£¸ÃľÂí¼Ù×°³É¶þάÂëÀûÓá°QR Code & Barcode ¨C Scanner¡± £¬Òѱ»ÏÂÔØ³¬¹ý10000´Î¡£Óë֮ǰ·ÖÆçµÄÊÇ £¬¸Ã±äÌåÕë¶ÔµÄÖ¸±êÀûÓÃÖÖÀàÔö³¤ £¬ÏÖÒÑϯ¾íÁ˼ÒÍ¥ÒøÐÐÀûÓᢱ£ÏÕÀûÓúͼÓÃÜÇ®°üµÅצÓá£ÔÚ²»µ½Ò»ÄêµÄ¹¦·òÀï £¬TeaBotÕë¶ÔÖ¸±êµÄÊýÁ¿Ôö³¤ÁË500%ÒÔÉÏ £¬´Ó60¸öÔö³¤µ½400¶à¸ö¡£Ä¿Ç° £¬TeaBotÖØÒªÃÀ¹úÓû§ £¬½üÆÚ»¹ÐÂÔöÁ˶íÓ˹Âå·¥¿ËÓïºÍÖÐÎİ汾 £¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þÔÚ¶Ô׼ȫÇò¡£


https://www.bleepingcomputer.com/news/security/teabot-malware-slips-back-into-google-play-store-to-target-us-users/


CloudSEK³ÆÕë¶ÔÓ¡¶ÈµÄ´¹µö¹¥»÷ÒÑÔì³ÉÉϰÙÍòÃÀÔªËðʧ


ÐÂ¼ÓÆÂ°²È«¹«Ë¾CloudSEKÔÚ3ÔÂ1ÈÕÅû¶ÁËÕë¶ÔÓ¡¶ÈµÄ´¹µö¹¥»÷µÄϸ½ÚÐÅÏ¢¡£Õâ´Î¹¥»÷»î¶¯Éæ¼°200¶à¸ö´¹µöÍøÕ¾ £¬ÒԵ綯Æû³µÎªµö¶ü £¬ÒÑÔì³É¸ß´ï1000000ÃÀÔªµÄËðʧ¡£Ó¡¶Èµ±¾Ö×î½üÍÆ³öÁËÐÂÕþ²ß £¬ÒÔÍÆ½ø¸Ã¹úµç¶¯Æû³µ£¨EV£©ÐÐÒµµÄÔö³¤¡£¹¥»÷Õßͨ¹ýÀûÓÃGoogle Ads¡¢Ê¹ÓÃÓйعؼü×ÖÒÔ¼°·ÂÕÕRevoltºÍAtherµÈÆ·ÅÆÀ´ÓÕʹָ±ê½øÈë´¹µöÍøÕ¾ £¬¶øºóÒªÇóËûÃÇÊäÈëÓ×ÎÒºÍÒøÐп¨ÐÅÏ¢ £¬×îÖÕÇÔȡָ±êµÄÕË»§×ʽð¡£


https://cloudsek.com/whitepapers_reports/unearthing-the-million-dollar-scams-targeting-the-indian-electric-vehicle-industry-scams/


Malwarebytes·¢ÏÖÖ¼ÔÚÇÔȡ΢ÈíÓû§Í´´¦µÄ´¹µö»î¶¯


3ÔÂ1ÈÕ £¬Malwarebytes°ä²¼Ò»·Ý»ã±¨ £¬ÏêÊöÁËÕë¶ÔMicrosoftÕÊ»§µÄ´¹µö»î¶¯¡£¸Ã»î¶¯ÒÔ¡°MicrosoftÕÊ»§Òì³£µÇ¼»î¶¯¡±ÎªÖ÷Ìâ £¬Ðû³Æ¼ì²âµ½À´×Ô¶íÂÞ˹/Ī˹¿ÆµÄÓû§¸Õ¸Õ´ÓÐÂÉ豸µÇ¼ÕÊ»§¡£µ±ÊÕ¼þÈ˵ã»÷´¹µöÓʼþÖеġ°»ã±¨Óû§¡±ºó £¬±ã»áÏò¹¥»÷Õß·¢ËÍÒ»·âÔ̺¬Ô¤Ìî³äÐÂÎŵÄÓʼþ £¬Ö®ºó¿ÉÄܻᱻҪÇóÊäÈëµÇ¼ƾ֤ºÍÒøÐÐÐÅÏ¢µÈ¡£


https://blog.malwarebytes.com/scams/2022/03/unusual-sign-in-activity-mail-goes-phishing-for-microsoft-account-holders/


JFrog°ä²¼¹ØÓÚ¿ªÔ´¿âPJSIPÖÐ5¸öÄÚ´æ°Ü»µ·ì϶µÄ»ã±¨


JFrogÔÚ3ÔÂ1ÈÕ°ä²¼Á˹ØÓÚPJSIPÖÐ5¸öÄÚ´æ°Ü»µ·ì϶µÄ»ã±¨¡£PJSIPÊÇÒ»¸ö¿ªÔ´¶àýÌåͨѶ¿â £¬ÌṩÁËIPµç»°ÀûÓÃʹÓõÄAPI¡£·ì϶Ô̺¬¿Éµ¼ÖµĴúÂëÖ´ÐеIJֿâÒç¶Âí½Å£¨CVE-2021-43299¡¢CVE-2021-43300ºÍCVE-2021-43301£© £¬ÒÔ¼°¿Éµ¼Ö»ؾø·þÎñµÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2021-43302£©»ººÍ³åÇøÒç¶Âí½Å£¨CVE-2021-43303£©¡£ÕâЩ·ì϶ÒÑͨ¹ý2ÔÂ24ÈÕ°ä²¼µÄ²¹¶¡½¨¸´¡£


https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/


Google°ä²¼°²È«¸üР£¬½¨¸´ChromeÖеÄ28¸ö·ì϶


GoogleÓÚ3ÔÂ1ÈÕÍÆ³öChrome 99 £¬½¨¸´ÁË28¸ö°²È«·ì϶¡£ÆäÖнÏΪÑϳÁµÄ·ì϶ÊÇANGLEÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2022-0789£©¡¢Cast UIÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2022-0790£©¡¢¶àÖ°ÄÜ¿òÖпªÊͺóʹÓ÷ì϶£¨CVE-2022-0791£©¡¢Blink²¼¾ÖÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2022-0795£©ºÍANGLEÖÐÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2022-0792£©µÈ¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/03/02/google-releases-security-updates-chrome


ESET°ä²¼IsaacWiperºÍHermeticWizardµÄ·ÖÎö»ã±¨


ESETÔÚ3ÔÂ1ÈÕ°ä²¼ÁËIsaacWiperºÍHermeticWizardµÄ·ÖÎö»ã±¨¡£IsaacWipeÊÇÒ»¸öеÄWiper £¬´æÔÚÓÚûÓÐAuthenticodeÊðÃûµÄWindows DLL»òEXEÖÐ £¬×îÔçµÄPE±àÒ빦·ò´ÁÊÇ2021Äê10ÔÂ19¡£ÓÚ2ÔÂ24ÈÕÔÚÎÚ¿ËÀ¼µ±¾Ö»ú¹¹µÄÍøÂçÖб»·¢ÏÖ £¬ÉÐδȷ¶¨ÊÇ·ñÓëHermeticWiperÓйØÁª¡£HermeticWizardÊÇ×Ô½ç˵È䳿 £¬ÓÃÓÚͨ¹ýWMIºÍSMBÔÚ±¾µØÍøÂçÖд«²¼HermeticWiper¡£


https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/



°²È«¹¤¾ß


Searpy


ËÑË÷¹¤¾ß £¬¿ÉÓÃÓڲɼ¯ºÍËÝÔ´ £¬Ö§³Öpy2ºÍpy3¡£


https://github.com/j3ers3/Searpy


CAPEv2


ÊÇÒ»¸ö¶ñÒâÈí¼þɳÏä £¬´ÓËÁÒâ¶ñÒâÈí¼þ¼Ò×åÖÐÌáÈ¡ÅäÖûò½âѹpayload¡£


https://github.com/kevoreilly/CAPEv2


S1EM


S1EM ÊÇÒ»¸ö´øÓÐ SIRP ºÍ Threat Intel µÄ SIEM £¬Ò»¸öÆëÈ«µÄÊý¾Ý°ü²¶»ñ £¬¶àºÏÒ»¡£


https://github.com/V1D1AN/S1EM


WMEye


ΪʹÓà WMI ºÍÔ¶³Ì MSBuild Ö´ÐÐÖ´ÐкáÏòÒÆ¶¯¶ø¿ª·¢µÄ³¢ÊÔÐÔ¹¤¾ß¡£


https://github.com/pwn1sher/WMEye



°²È«·ÖÎö


Æ»¹û°ä²¼ iOS 15.4 Beta 5


https://news.softpedia.com/news/apple-releases-ios-15-4-beta-5-534963.shtml


΢ÈíΪÖÐÓׯóÒµÍÆ³öеĶ˵㰲ȫ½â¾ö¹æ»®


https://www.bleepingcomputer.com/news/microsoft/microsoft-rolling-out-new-endpoint-security-solution-for-smbs/


ASEC·¢ÏÖ¼Ù×°³ÉMSIµÄMagniber·Ö·¢»î¶¯


https://asec.ahnlab.com/en/32226/


΢Èí£ºLSASS±ÀÀ£µ¼ÖÂWindowsÓò½ÚÔìÆ÷³ÁÆô


https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-domain-controller-restarts-caused-by-lsass-crashes/


Reality Winner µÄ Twitter ÕË»§±»ºÚ¿Í¹¥»÷ÒÔÕë¶Ô¼ÇÕß


https://www.bleepingcomputer.com/news/security/reality-winners-twitter-account-was-hacked-to-target-journalists/


VoIPmonitor ¼à¿ØÈí¼þÖз¢ÏÖµÄÑϳÁ°²È«·ì϶


https://thehackernews.com/2022/03/critical-security-bugs-uncovered-in.html