΢ÈíÐû²¼Í¨¸æ³ÆIE 0dayÒÑÔâÒ°ÍâʹÓ㬣¬£¬ÏÖÔÚÉÐÎÞ²¹¶¡£¡£¡£¡£¡£» £»£»£»£»£»Î÷ÃÅ×ÓÖÒÑÔ¿Í»§ÓйØÔÚ¹¤Òµ²úÆ·ÖÐʹÓÃActiveXµÄΣº¦

Ðû²¼Ê±¼ä 2020-01-19


1.΢ÈíÐû²¼Í¨¸æ³ÆIE 0dayÒÑÔâÒ°ÍâʹÓ㬣¬£¬ÏÖÔÚÉÐÎÞ²¹¶¡


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


1ÔÂ17ÈÕ΢ÈíÐû²¼Ç徲ͨ¸æ£¨ADV200001£©£¬£¬£¬ÖÒÑÔÓû§¹ØÓÚIE 0day£¨CVE-2020-0674£©ÒÑÔâÒ°ÍâʹÓõÄÇéÐΣ¬£¬£¬²¢ÇÒ¸ÃÎó²îÔÝÎÞÐÞ¸´²¹¶¡£¬£¬£¬½öÓÐÓ¦±ä²½·¥»ººÍ½â²½·¥¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖÕýÔÚÍÆ³ö½â¾ö¼Æ»®£¬£¬£¬¿ÉÄÜÔÚºóÐøÒÔ´øÍâ¸üÐµķ½·¨Ðû²¼¡£¡£¡£¡£¡£¸Ã0dayδÔâ´ó¹æÄ£Ê¹Ó㬣¬£¬Ö»ÊÇÕë¶ÔÉÙÁ¿Óû§¹¥»÷µÄÒ»²¿·Ö¡£¡£¡£¡£¡£Æ¾Ö¤Í¨¸æ£¬£¬£¬Î¢Èí³Æ¸Ã0dayΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¨RCE£©£¬£¬£¬ÓëIE¾ç±¾ÒýÇæÔÚ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Óйء£¡£¡£¡£¡£ÕâÊÇÒ»¸öÄÚ´æËð»µÎó²î£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÒÔÄ¿½ñÓû§µÄȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ÔÚweb¹¥»÷³¡¾°ÖУ¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÓÕʹÓû§»á¼û¶ñÒâÍøÕ¾À´Ê¹ÓøÃÎó²î£¨ÀýÈçͨ¹ý´¹ÂÚÓʼþ£©¡£¡£¡£¡£¡£Óû§¿Éͨ¹ýÏÞÖÆ¶ÔJScript.dllµÄ»á¼ûÀ´ÔÝʱ»º½â¸ÃÎó²î¡£¡£¡£¡£¡£

  Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/01/internet-explorer-zero-day-attack.html


2.Î÷ÃÅ×ÓÖÒÑÔ¿Í»§ÓйØÔÚ¹¤Òµ²úÆ·ÖÐʹÓÃActiveXµÄΣº¦


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Î÷ÃÅ×ÓµÄһЩ¹¤Òµ²úÆ·£¨°üÀ¨SIMATIC WinCC¡¢SIMATIC STEP 7¡¢SIMATIC PCS 7¡¢TIA PortalºÍS7-PLCSIM Advanced£©ÒÀÀµActiveX×é¼þ£¬£¬£¬¿Í»§ÐèҪʹÓÃInternet ExplorerÀ´Ö´ÐÐÕâЩ×é¼þ¡£¡£¡£¡£¡£µ«¸Ã³§ÉÌÖÒÑÔ¿Í»§³Æ£¬£¬£¬Ê¹ÓÃIE»á¼û²»ÊÜÐÅÈεÄÍøÕ¾¿ÉÄÜ»á´øÀ´ÑÏÖØµÄÇ徲Σº¦¡£¡£¡£¡£¡£Î÷ÃÅ×Ó½¨ÒéÔÚ»á¼ûÓ빫˾²úÆ·Î޹صÄÍøÒ³Ê±Ê¹Óò»Ö§³ÖActiveXµÄÍøÒ³ä¯ÀÀÆ÷¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬Î÷ÃÅ×Ó½üÆÚ»¹ÐÞ¸´ÁËSCALANCE X¹¤Òµ½»Á÷»úÖеÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2019-13933£¬£¬£¬CVSS v3.1ÆÀ·ÖΪ8.8·Ö£©¡¢ SINEMA ServerÖеIJ»×¼È·µÄ»á»°ÑéÖ¤Îó²î£¨CVE-2019-10940£¬£¬£¬9.9·Ö£©ºÍTIA PortalÖеÄLPEÎó²î£¨CVE-2019-10934£¬£¬£¬7.8·Ö£©¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-warns-security-risks-associated-use-activex


3.Ñо¿ÍŶÓÐû²¼ÀÕË÷Èí¼þParadiseµÄ½âÃܹ¤¾ß


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


BitdefenderÑо¿ÍŶÓÐû²¼ÀÕË÷Èí¼þParadiseµÄ×îнâÃÜÆ÷¡£¡£¡£¡£¡£Paradise×î³õÓÚ2017Äê·ºÆð£¬£¬£¬ËüÔÚ¼ÓÃÜʱ»áÈÆ¹ý¼üÅÌÓïÑÔΪ¶íÓï¡¢¹þÈø¿ËÓï¡¢°×¶íÂÞ˹Óï»òÎÚ¿ËÀ¼ÓïµÄϵͳ¡£¡£¡£¡£¡£BitdefenderÐû²¼µÄ×îнâÃÜÆ÷Ö§³ÖÒÔϺó׺ÃûµÄ±äÖÖ£º.FC¡¢.2ksys19¡¢.p3rf0rm4¡¢.Recognizer¡¢.VACv2¡¢.paradise¡¢.CORP¡¢.immortal¡¢.exploit¡¢.prt¡¢.STUB¡¢.sevºÍ.sambo¡£¡£¡£¡£¡£¸Ã¹¤¾ßÖ§³ÖGUI»òÏÂÁîÐÐÔËÐУ¬£¬£¬Óû§¿É´ÓBitdefender¹ÙÍøÏÂÔØ¸Ã¹¤¾ß¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://labs.bitdefender.com/2020/01/paradise-ransomware-decryption-tool/


4.ÍÁ¶úÆäºÚ¿Í¹¥»÷Ï£À°¶à¸öÕþ¸®²¿·ÖºÍ֤ȯÉúÒâËùÍøÕ¾


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÉÏÖÜÎåÍÁ¶úÆäºÚ¿ÍÉù³ÆÒѾ­Ð®ÖÆÁËÏ£À°Òé»á¡¢Íâ½»ºÍ¾­¼Ã²¿ÒÔ¼°¸Ã¹ú¼Ò֤ȯÉúÒâËùµÄ¹Ù·½ÍøÕ¾³¤´ï90¶à·ÖÖÓ¡£¡£¡£¡£¡£¸ÃºÚ¿ÍÍÅ»ïΪAnka Neferler Tim£¬£¬£¬ËûÃÇÔÚFacebookÒ³ÃæÉϱ绤³Æ¡°Ï£À°Ò»Ö±ÔÚ°®ÇÙº£ºÍµØÖк£¶«²¿ÍþвÍÁ¶úÆä£¬£¬£¬ÏÖÔÚÓÖÔÚÍþвÀû±ÈÑÇÇå¾²¾Û»á¡±¡£¡£¡£¡£¡£¸Ã¾Û»áµÄÄ¿µÄÊÇÔÚÁªºÏ¹úµÄÖ÷³ÖÏÂÆô¶¯Àû±ÈÑǵÄÇå¾²Àú³Ì£¬£¬£¬½«ÔÚ°ØÁÖ¾ÙÐС£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/turkish-hackers-target-greek-government-websites-stock-exchange


5.ÐÂÔóÎ÷ÖÝÓÌÌ«½ÌÌÃÔâµ½ÀÕË÷Èí¼þSodinokibi¹¥»÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÐÂÔóÎ÷ÖÝÎÖÂ×ÊеÄÓÌÌ«½ÌÌÃTemple Har ShalomÔâµ½ÀÕË÷Èí¼þSodinokibi¹¥»÷£¬£¬£¬ÆäÍøÂçÉϵÄÐí¶àÅÌËã»úϵͳ±»¼ÓÃÜ¡£¡£¡£¡£¡£¸Ã½ÌÌÃÓÚ1ÔÂ9ÈÕ·¢Ã÷Á˹¥»÷ÊÂÎñ£¬£¬£¬ÆäЧÀÍÆ÷ÉϵÄËùÓÐÎļþºÍµç×ÓÊý¾Ý¾ù±»¼ÓÃÜ£¬£¬£¬°üÀ¨ÕâЩÎļþºÍÊý¾ÝµÄ±¸·Ý¡£¡£¡£¡£¡£ÐÂÎÅÈËÊ¿³ÆSodinokibi¹¥»÷ÕßÒªÇó½ü50ÍòÃÀÔªµÄÊê½ð£¬£¬£¬µ«¸Ã½ÌÌÃÌåÏÖ½«Óë»áÖÚÁªÏµÒÔ»ñÈ¡ÖØÐÞ¼ÓÃÜÎļþËùÐèµÄÐÅÏ¢£¬£¬£¬ÕâÅú×¢ËûÃÇÎÞÒâÖ§¸¶Êê½ð¡£¡£¡£¡£¡£ÓÉÓÚÖÚËùÖÜÖªSodinokibiÔÚ¼ÓÃÜÎļþ֮ǰ»áÏÈÇÔÈ¡Îļþ£¬£¬£¬Òò´Ë»áÖÚµÄÐÕÃû¡¢µØµãºÍµç×ÓÓʼþµØµã¿ÉÄܱ»µÁ£¬£¬£¬µ«¸Ã½ÌÌÃÒÔΪ¹¥»÷ÕßÎÞ·¨»á¼û²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-jersey-synagogue-suffers-sodinokibi-ransomware-attack/


6.¶ñÒâÈí¼þMetamorfoбäÖÖÖ÷ÒªÕë¶Ô°ÍÎ÷½ðÈÚ»ú¹¹


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


FortiGuard Labs·¢Ã÷¶ñÒâÈí¼þMetamorfoµÄбäÖÖ£¬£¬£¬¸Ã¶ñÒâÈí¼þÒÔÍøÂç°ÍÎ÷½ðÈÚ»ú¹¹¿Í»§µÄÊý¾Ý¶øÖøÃû¡£¡£¡£¡£¡£¸Ã±äÖÖͨ¹ý´¹ÂÚÓʼþÈö²¥£¬£¬£¬´¹ÂÚÓʼþÓɰÍÎ÷¹Ù·½ÓïÑÔÆÏÌÑÑÀÓïд³É£¬£¬£¬ÄÚÈÝΪ´ß´ÙÊܺ¦ÕßÏÂÔØµç×Ó·¢Æ±£¨NF£©£¬£¬£¬µ«ÏÖʵÏÂÔØµÄÎļþΪXlsPlan_Visualize.msi¡£¡£¡£¡£¡£¸ÃMSIÎļþÖ»ÊÇÒ»¸ö¶ñÒâÈí¼þÏÂÔØÆ÷£¬£¬£¬×îÖÕ½«ÏÂÔØKJFLDKRE.msi²¢Ö´ÐУ¬£¬£¬¸ÃÎļþÊÇÕæÕýµÄMetamorfo¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿ÉÒÔÍøÂçÊܺ¦ÕßµÄÅÌËã»úÃû³Æ¡¢¿Í»§¶Ë°æ±¾¡¢²Ù×÷ϵͳÃû³Æ¡¢ÕË»§ÃÜÂëµÈÊý¾Ý²¢·¢ËÍÖÁC&CЧÀÍÆ÷¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/blog/threat-research/analysis-metamorfo-variant-targets-financial-organizations.html