ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ1ÖÜ
°ä²¼¹¦·ò 2021-01-04> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê12ÔÂ28ÈÕÖÁ2021Äê01ÔÂ03ÈÕ¹²ÊÕ¼°²È«·ì϶52¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇKLog Server actions/authenticate.phpºÅÁî×¢Èë·ì϶£»Solarwinds Orion Platform Request.PathInfo°²È«Èƹý·ì϶£»Panasonic Security SystemÓ²±àÂë·ì϶£»Netgear NMS300 CVE-2020-35789ºÅÁî×¢Èë·ì϶£»NETGEAR D7800 CVE-2020-35791ºÅÁî×¢Èë·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇApple iCloudÖжÏ36Ó×ʱ£¬Éв»Ã÷ÏÔ¹ÊÕÏÔÒò£»GoDaddyÏòÔ±¹¤·¢ËÍ´¹µöÓʼþ£¬²âÊÔÔ±¹¤µÄ·´Ó³£»Ð¶ñÒâÈí¼þ¿ÉÀûÓÃImgurÀ´½âÂëCobalt Strike¾ç±¾£»ÈÕ±¾¾ü¹¤ÆóÒµ´¨Æé³Á¹¤Ôâµ½¹¥»÷£¬»ò½«µ¼ÖÂÊý¾Ýй¶£»WasabiÔÆ´æ´¢·þÎñÒòDNS½âÎöÎÊÌâµ¼ÖÂÖжÏ13¸öÓ×ʱ¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.KLog Server actions/authenticate.phpºÅÁî×¢Èë·ì϶
KLog Server actions/authenticate.php´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâOSºÅÁî²¢Ö´ÐС£
https://github.com/mustgundogdu/Research/blob/main/KLOG_SERVER/Exploit_Code
2.Solarwinds Orion Platform Request.PathInfo°²È«Èƹý·ì϶
Solarwinds Orion Platform Request.PathInfo´æÔÚÑéÖ¤ÈÆ¹ý·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐδÊÚȨµÄAPIºÅÁî¡£
https://www.kb.cert.org/vuls/id/843464
3.Panasonic Security SystemÓ²±àÂë·ì϶
Panasonic Security System´æÔÚlkjhgfdsaÓ²±àÂë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼ûÉ豸¡£
https://security.panasonic.com/products_technology/products/wv-s2231l/
4.Netgear NMS300 CVE-2020-35789ºÅÁî×¢Èë·ì϶
Netgear NMS300´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼ûÉ豸¡£
https://kb.netgear.com/000062686/Security-Advisory-for-Post-Authentication-Command-Injection-on-NMS300-PSV-2020-0559
5.NETGEAR D7800 CVE-2020-35791ºÅÁî×¢Èë·ì϶
NETGEAR D7800´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼ûÉ豸¡£
https://kb.netgear.com/000062714/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2019-0079
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Apple iCloudÖжÏ36Ó×ʱ£¬Éв»Ã÷ÏÔ¹ÊÕÏÔÒò

Apple iCloud·þÎñ³öÏÖ¹ÊÕÏ£¬Ê¹Óû§ÎÞ·¨µÇ¼¸Ã·þÎñ½Ó¼ûÎļþ»òÉèÖÃÐÂÉ豸¡£Õâ´ÎÖжϴÓÃÀ¹ú¶«²¿¹¦·ò12ÔÂ25ÈÕÉÏÎç4:45ÆðÍ·£¬Ö±µ½12ÔÂ26ÈÕÏÂÎç4:35²Å±»½¨¸´£¬Àúʱ36Ó×ʱ¡£ÖÐ¶ÏÆÚ¼ä£¬AppleµÄϵͳ״̬ҳÉϽöÏÔʾ¡°Óû§¿ÉÄÜÓöµ½´Ë·þÎñµÄÎÊÌ⡱µÄÌáÐÑ£¬Ã»Óиü¶àÓÐ¹ØÆäÖжϵÄÐÅÏ¢¡£Ä¿Ç°£¬Apple¹«Ë¾Ã»ÓÐÌṩÈκÎÒÔÕÏÔÒò¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/apple/apple-icloud-outage-prevents-device-activations-access-to-data/
2¡¢GoDaddyÏòÔ±¹¤·¢ËÍ´¹µöÓʼþ£¬²âÊÔÔ±¹¤µÄ·´Ó³

GoDaddyÏòÔ±¹¤·¢ËÍ´¹µöÓʼþ£¬ÒÔ²âÊÔÔ±¹¤¶ÔÍøÂç´¹µö»î¶¯µÄ·´Ó³¡£¸Ã²âÊÔÓÚ12Ô½øÐУ¬ÓʼþÐû³Æ½«Ìṩ650ÃÀÔªµÄÊ¥µ®½Ú½±½ð£¬ÒÔÔ®ÊÖÔ±¹¤Ó¦¶ÔÒòCOVID-19·¢×÷¶øµ¼Öµľ¼ÃÎÊÌ⣬²¢ÒªÇóËûÃÇÌîдÓ×ÎÒÐÅÏ¢±í¸ñ¡£Õâ´Î²âÊԻԼĪ500ÃûÔ±¹¤ÖÐÕУ¬ËûÃǽ«±»ÒªÇó³ÁвÎÓëÉç»á¹¤³Ì°²È«ÒâʶµÄÅàѵ¡£ÓÉÓÚ²âÊÔÖÐʹÓõĵö¶üºÍ·ÂÕÕ¹¦·òµÄÑ¡Ôñ£¬¸Ã²½ÖèÊܵ½Á˲¿ÃÅÍøÂ簲ȫ¼¯ÌåµÄÆ·ÆÀ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112664/security/godaddy-phishing-test-employees.html
3¡¢Ð¶ñÒâÈí¼þ¿ÉÀûÓÃImgurÀ´½âÂëCobalt Strike¾ç±¾

жñÒâÈí¼þ¿ÉÀûÓÃͼÏñÍйܷþÎñImgurÏÂÔØºÏ·¨µÄͼÏñ£¬À´½âÂëCobalt Strike¾ç±¾¡£ÐµĶñÒâÈí¼þʹÓôøÓкêµÄWordÎļþ´ÓGitHubÏÂÔØPowerShell¾ç±¾£¬¸Ã¾ç±¾½«´ÓImgurÏÂÔØÏÖʵPNGÎļþ¡£Ö®ºó£¬ÀûÓÃÏñInvoke-PSImageÕâÑùµÄ¹¤¾ßÀ´Ê¹ÓÃPNGÎļþÖеÄÏñËØÖµ±àÂëPowerShell¾ç±¾£¬²¢ÌìÉúÒ»ÐкÅÁîÀ´Ö´ÐÐpayload£¬×îÖÕ»ñµÃCobalt Strike¾ç±¾¡£×êÑÐÈËÔ±´§Ä¦´Ë¶ñÒâÈí¼þ¿ÉÄÜÓëÖØÒªÕë¶ÔÖж«ÊµÌåµÄAPT×éÖ¯MuddyWaterÓйء£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/github-hosted-malware-calculates-cobalt-strike-payload-from-imgur-pic/
4¡¢ÈÕ±¾¾ü¹¤ÆóÒµ´¨Æé³Á¹¤Ôâµ½¹¥»÷£¬»ò½«µ¼ÖÂÊý¾Ýй¶

ÈÕ±¾¾ü¹¤ÆóÒµ´¨Æé³Á¹¤Ôâµ½¹¥»÷£¬»ò½«µ¼ÖÂÊý¾Ýй¶¡£´¨Æé³Á¹¤£¨Kawasaki£©³Æ£¬2020Äê6ÔÂ11ÈÕÓÐδ¾ÊÚȨµÄµÚÈý·½´ÓÌ©¹ú´¦Ê´¦½Ó¼ûÁËÈÕ±¾µÄ·þÎñÆ÷£¬ÔÚ·¢ÏÖ¸ÃÎÊÌâºóÁ½¸öÕ¾µãÖ®¼äµÄËùÓÐͨѶ¶¼±»ÖÕ³¡¡£Ëæºó£¬¸Ã¹«Ë¾ÓÖ·¢ÏÖÁËÆäËûº£±íÕ¾µã£¨Ó¡¶ÈÄáÎ÷ÑÇ¡¢·ÆÂɱöºÍÃÀ¹ú£©Î´¾ÊÚȨ½Ó¼ûÈÕ±¾·þÎñÆ÷µÄÇé¿ö£¬²¢¶Â½ØÍ¨Ñ¶¡£´¨Æé³ÆÕâ´Î¹¥»÷ʹÓÃÁËÏȽø¼¼Êõ¶øÃ»ÓÐÁôÏÂÈκκۼ£ºÍÖ¤¾Ý£¬µ«¹«Ë¾Êý¾Ý»òÐíÒѾй¶¡£ËùÓб»ÖÕÖ¹µÄͨѶÓÚ11ÔÂ30ÈÕ¸´ÔÕý³£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112765/data-breach/kawasaki-heavy-industries-cyber-attack.html
5¡¢WasabiÔÆ´æ´¢·þÎñÒòDNS½âÎöÎÊÌâµ¼ÖÂÖжÏ13¸öÓ×ʱ

WasabiÔÆ´æ´¢·þÎñÒòDNS½âÎöÎÊÌâµ¼ÖÂÖжÏ13¸öÓ×ʱ¡£12ÔÂ28ÈÕÏÂÎç2:30 ESTÓû§·¢ÏÖÎÞ·¨½Ó¼ûwasabisys.comÉϵĴ洢Ͱ£¬WasabiÔÚÖжϻ㱨ÖгÆÊÇÓÉÓÚDNS½âÎöÎÊÌâµ¼Ö¡£¾ÝϤ£¬¸Ãƽ̨Óû§ÉÏ´«Á˶ñÒâÈí¼þ£¬ÆäÓòÃû³Æ×¢²áÉÌ·¢ÏÖºóÏëҪͨ¹ýµç×ÓÓʼþ֪ͨWasabi£¬È´°Ñ»ã±¨×ª·¢µ½ÁËÃýÎóµÄµØÖ·£¬Ê¹µÃWasabiδµÃµ½Í¨Öª¡£¶ø¸Ã×¢²áÉÌÒòδµÃµ½»Ø¸´¶øÔÝÍ£Á˸ÃÓò£¬WasabiÔÚµÃÖª¸ÃÊÂÎñºóɾ³ýÁËÍйܶñÒâÈí¼þ²¢ÒªÇó³Áм¤¸ÃËÀÓò£¬Æ½Ì¨ÔÚ12ÔÂ29ÈÕÏÂÎç12:57 ESTÖÕÓڵõ½¸´Ô¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/wasabi-cloud-storage-service-knocked-offline-for-hosting-malware/


¾©¹«Íø°²±¸11010802024551ºÅ