Aqua SecurityÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄÊÖÒÕϸ½Ú

Ðû²¼Ê±¼ä 2021-12-31

Unit42³Æ´ó¶àAPTÍÅ»ïʹÓõÄÓò×¢²áÓÚÊýÄê֮ǰ


Unit42³Æ´ó¶àAPTÍÅ»ïʹÓõÄÓò×¢²áÓÚÊýÄê֮ǰ.png


Unit42ÔÚ12ÔÂ29ÈÕÐû²¼µÄ×îÐÂÑо¿ÏÔʾ£¬£¬£¬£¬ £¬´ó¶àAPTÍÅ»ïʹÓõÄÓò×¢²áÓÚÊýÄê֮ǰ ¡£¡£¡£Í¨³££¬£¬£¬£¬ £¬ÐÂ×¢²áµÄÓò(NRD) ¸üÓпÉÄÜÊǶñÒâµÄ£¬£¬£¬£¬ £¬Òò´ËÇå¾²½â¾ö¼Æ»®½«Öصã¼ì²â²¢±ê¼ÇËüÃÇ ¡£¡£¡£µ«Unit42Ö¸³ö£¬£¬£¬£¬ £¬ÍùÄê×¢²áµÄÓòÊǶñÒâµÄ¿ÉÄÜÐÔ±ÈNRD¸ßÈý±¶ ¡£¡£¡£ÓÐʱ£¬£¬£¬£¬ £¬´ËÀàÓòÃûÔÚÐÝÃßÁ½ÄêÖ®ºóDNSÁ÷Á¿¼¤Ôö165±¶£¬£¬£¬£¬ £¬ÕâÅú×¢¹¥»÷ÕßÒÑÌᳫ¹¥»÷ ¡£¡£¡£Ñо¿Ö°Ô±ÔÚ9Ô·ݵÄͳ¼ÆÐ§¹ûÏÔʾ£¬£¬£¬£¬ £¬Ô¼3.8%µÄÓòÃûÊǶñÒâµÄ£¬£¬£¬£¬ £¬19%ÊÇ¿ÉÒɵÄ£¬£¬£¬£¬ £¬2%µÄÇéÐβ»Çå¾² ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/strategically-aged-domain-detection/


Aqua SecurityÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄÊÖÒÕϸ½Ú


Aqua SecurityÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄÊÖÒÕϸ½Ú.png


12ÔÂ29ÈÕ£¬£¬£¬£¬ £¬DevSecOpsºÍAqua SecurityÁªºÏÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄÊÖÒÕϸ½Ú ¡£¡£¡£¸Ã»î¶¯Ê״ηºÆðÓÚ2019Ä꣬£¬£¬£¬ £¬×îÏÈ»áÔÚÔËÐÐÔ­°æ¾µÏñalpine:latestʱִÐжñÒâÏÂÁ£¬£¬£¬ £¬²¢ÏÂÔØÃûΪautom.shµÄshell¾ç±¾ ¡£¡£¡£Ö®ºó»áʹÓøþ籾½¨ÉèÒ»¸öÐÂÓû§akay²¢½«ÆäȨÏÞÉý¼¶Îªroot£¬£¬£¬£¬ £¬Ê¹ÓøÃÓû§ÔÚÄ¿µÄ×°±¸ÉÏÔËÐÐí§ÒâÏÂÁ£¬£¬£¬ £¬²¢ÍÚ¾ò¼ÓÃÜÇ®±Ò ¡£¡£¡£±¨¸æ»¹Áгö¸Ã»î¶¯µÄMITRE ATT&CKºÍIOC ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.aquasec.com/attack-techniques-autom-cryptomining-campaign


AmnpardazÔÚÒ°·¢Ã÷Õë¶ÔHP iLOµÄÐÂiLOBleed


AmnpardazÔÚÒ°·¢Ã÷Õë¶ÔHP iLOµÄÐÂiLOBleed.png


¾ÝýÌå12ÔÂ28Èճƣ¬£¬£¬£¬ £¬ÒÁÀÊÇå¾²¹«Ë¾AmnpardazÔÚÒ°·¢Ã÷Õë¶Ô»ÝÆÕIntegrated Lights-Out(iLO)µÄжñÒâÈí¼þiLOBleed ¡£¡£¡£ÕâÊÇÊ׸öÕë¶ÔiLO¹Ì¼þµÄrootkit£¬£¬£¬£¬ £¬Ëü¿ÉÒÔ³¤Ê±¼äµØÒþ²ØÔÚiLOÖв¢ÇÒ²»»áÔڹ̼þÉý¼¶Öб»É¾³ý ¡£¡£¡£iLOBleed×Ô2020ÄêÒÔÀ´Ò»Ö±±»ÓÃÓÚ¹¥»÷£¬£¬£¬£¬ £¬¿É¸Ä¶¯¹Ì¼þÄ£¿£¿£¿£¿£¿é²¢É¾³ý±»Ñ¬È¾ÏµÍ³ÖеÄÊý¾Ý ¡£¡£¡£ÏÖÔڸöñÒâÈí¼þ±³ºó¹¥»÷ÕßµÄÉí·ÝÈÔδȷ¶¨£¬£¬£¬£¬ £¬µ«AmnpardazÍÆ²âËüÓëij¸öÓɹú¼ÒÖ§³ÖµÄAPT×éÖ¯ÓÐ¹Ø ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threats.amnpardaz.com/en/2021/12/28/implant-arm-ilobleed-a/


Ô½ÄϹ«Ë¾ONUSÔâÀÕË÷¹¥»÷£¬£¬£¬£¬ £¬¾Ü¾øÖ§¸¶500ÍòÃÀÔªÊê½ð


Ô½ÄϹ«Ë¾ONUSÔâÀÕË÷¹¥»÷£¬£¬£¬£¬£¬¾Ü¾øÖ§¸¶500ÍòÃÀÔªÊê½ð.png


¾ÝýÌå12ÔÂ29ÈÕ±¨µÀ£¬£¬£¬£¬ £¬Ô½ÄϵĽðÈڿƼ¼¹«Ë¾ONUSÔâµ½ÀÕË÷¹¥»÷ ¡£¡£¡£12ÔÂ11ÈÕÖÁ13ÈÕʱ´ú£¬£¬£¬£¬ £¬¹¥»÷ÕßÀÖ³ÉʹÓÃONUS CyclosЧÀÍÆ÷ÉϵÄLog4ShellÎó²î£¬£¬£¬£¬ £¬²¢Ö²ÈëºóÃÅ ¡£¡£¡£CyclosÔÚ13ÈÕÐû²¼Í¨¸æ³ÆÐÞ¸´Æäϵͳ£¬£¬£¬£¬ £¬µ«´ËʱΪʱÒÑÍí ¡£¡£¡£¹¥»÷ÕßÒÑÇÔÈ¡¸Ã¹«Ë¾½ü200ÍòÌõ¿Í»§¼Í¼£¬£¬£¬£¬ £¬°üÀ¨E-KYCÊý¾Ý¡¢Ð¡ÎÒ˽¼ÒÐÅÏ¢ºÍÃÜÂë ¡£¡£¡£12ÔÂ25ÈÕ£¬£¬£¬£¬ £¬ONUS¾Ü¾øÖ§¸¶500ÍòÃÀÔªµÄÊê½ðÖ®ºó£¬£¬£¬£¬ £¬¹¥»÷Õß×îÏȳöÊÛÇÔÈ¡µÄÊý¾Ý ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fintech-firm-hit-by-log4j-hack-refuses-to-pay-5-million-ransom/


AvosLockerÔÚÈëÇÖÃÀ¹ú¾¯Ô±¾ÖºóÏòÆäÌṩ½âÃÜÆ÷


AvosLockerÔÚÈëÇÖÃÀ¹ú¾¯Ô±¾ÖºóÏòÆäÌṩ½âÃÜÆ÷.png


ýÌå12ÔÂ29Èճƣ¬£¬£¬£¬ £¬AvosLockerÒÑÃâ·ÑÏòÃÀ¹ú¾¯Ô±¾ÖÌṩ½âÃÜÆ÷ ¡£¡£¡£¸ÃÍÅ»ïÔÚÉϸöÔÂÒÑÈëÇÖÃÀ¹úµÄ¾¯Ô±¾Ö£¬£¬£¬£¬ £¬¹¥»÷ʱ´úÇÔÈ¡¸Ã»ú¹¹µÄÊý¾Ý²¢¼ÓÃÜÆä×°±¸ ¡£¡£¡£AvosLockerÔÚµÃÖª¶Ô·½ÊÇÕþ¸®»ú¹¹ºóÁ¬Ã¦ÖÂǸ£¬£¬£¬£¬ £¬²¢Ãâ·ÑÌṩ½âÃÜÆ÷ ¡£¡£¡£¸ÃÍÅ»ïµÄ³ÉÔ±ÌåÏÖ£¬£¬£¬£¬ £¬ËûÃÇûÓÐÏêϸµÄÕë¶ÔÄ¿µÄµÄÕþ²ß£¬£¬£¬£¬ £¬µ«Í¨³£»£»£»£»£»á×èÖ¹¶ÔÕþ¸®»ú¹¹ºÍÒ½Ôº¾ÙÐй¥»÷ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-gang-coughs-up-decryptor-after-realizing-they-hit-the-police/


Òò»ÝÆÕ³¬ËãµÄ±¸·Ýϵͳ¹ýʧ£¬£¬£¬£¬ £¬¾©¶¼´óѧɥʧ77TBÊý¾Ý


Òò»ÝÆÕ³¬ËãµÄ±¸·Ýϵͳ¹ýʧ£¬£¬£¬£¬£¬¾©¶¼´óѧɥʧ77TBÊý¾Ý.png


¾ÝýÌåÓÚ12ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬ £¬ÓÉÓÚ»ÝÆÕ¹«Ë¾³¬µÈÅÌËã»úµÄ±¸·Ýϵͳ·ºÆð¹ýʧ£¬£¬£¬£¬ £¬µ¼ÖÂÈÕ±¾¾©¶¼´óѧԼ77TBµÄ¿ÆÑÐÊý¾Ý±»Îóɾ ¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2021Äê12ÔÂ14ÈÕÖÁ16ÈÕ£¬£¬£¬£¬ £¬14¸ö¿ÆÑÐС×éµÄ3400Íò·ÝÎļþ´ÓϵͳºÍ±¸·ÝÎļþÖб»É¾³ý ¡£¡£¡£¾ÝϤ£¬£¬£¬£¬ £¬±¸·Ý³ÌÐò±¾Ó¦Ê¹ÓÃfindÏÂÁîɾ³ýÁè¼Ý10ÌìµÄÎôÈÕÖ¾£¬£¬£¬£¬ £¬µ«Æä¹ýʧµØÖ´ÐÐÁ˰üÀ¨Î´½ç˵±äÁ¿µÄfindÏÂÁ£¬£¬£¬ £¬É¾³ýÁË/LARGE0Ŀ¼ÏµÄÕý³£Îļþ ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ £¬¸Ã´óѧÒÑ·ÅÆú¸Ã±¸·Ýϵͳ£¬£¬£¬£¬ £¬²¢ÍýÏëÔÚ2022Äê1ÔÂÖØÐÂÒýÈë ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/university-loses-77tb-of-research-data-due-to-backup-error/