Aqua SecurityÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄÊÖÒÕϸ½Ú
Ðû²¼Ê±¼ä 2021-12-31Unit42³Æ´ó¶àAPTÍÅ»ïʹÓõÄÓò×¢²áÓÚÊýÄê֮ǰ
Unit42ÔÚ12ÔÂ29ÈÕÐû²¼µÄ×îÐÂÑо¿ÏÔʾ£¬£¬£¬´ó¶àAPTÍÅ»ïʹÓõÄÓò×¢²áÓÚÊýÄê֮ǰ¡£¡£¡£¡£¡£Í¨³££¬£¬£¬ÐÂ×¢²áµÄÓò(NRD) ¸üÓпÉÄÜÊǶñÒâµÄ£¬£¬£¬Òò´ËÇå¾²½â¾ö¼Æ»®½«Öصã¼ì²â²¢±ê¼ÇËüÃÇ¡£¡£¡£¡£¡£µ«Unit42Ö¸³ö£¬£¬£¬ÍùÄê×¢²áµÄÓòÊǶñÒâµÄ¿ÉÄÜÐÔ±ÈNRD¸ßÈý±¶¡£¡£¡£¡£¡£ÓÐʱ£¬£¬£¬´ËÀàÓòÃûÔÚÐÝÃßÁ½ÄêÖ®ºóDNSÁ÷Á¿¼¤Ôö165±¶£¬£¬£¬ÕâÅú×¢¹¥»÷ÕßÒÑÌᳫ¹¥»÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ9Ô·ݵÄͳ¼ÆÐ§¹ûÏÔʾ£¬£¬£¬Ô¼3.8%µÄÓòÃûÊǶñÒâµÄ£¬£¬£¬19%ÊÇ¿ÉÒɵ쬣¬£¬2%µÄÇéÐβ»Çå¾²¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/strategically-aged-domain-detection/
Aqua SecurityÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄÊÖÒÕϸ½Ú
12ÔÂ29ÈÕ£¬£¬£¬DevSecOpsºÍAqua SecurityÁªºÏÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¸Ã»î¶¯Ê״ηºÆðÓÚ2019Ä꣬£¬£¬×îÏÈ»áÔÚÔËÐÐÔ°æ¾µÏñalpine:latestʱִÐжñÒâÏÂÁ£¬£¬²¢ÏÂÔØÃûΪautom.shµÄshell¾ç±¾¡£¡£¡£¡£¡£Ö®ºó»áʹÓøþ籾½¨ÉèÒ»¸öÐÂÓû§akay²¢½«ÆäȨÏÞÉý¼¶Îªroot£¬£¬£¬Ê¹ÓøÃÓû§ÔÚÄ¿µÄ×°±¸ÉÏÔËÐÐí§ÒâÏÂÁ£¬£¬²¢ÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£±¨¸æ»¹Áгö¸Ã»î¶¯µÄMITRE ATT&CKºÍIOC¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.aquasec.com/attack-techniques-autom-cryptomining-campaign
AmnpardazÔÚÒ°·¢Ã÷Õë¶ÔHP iLOµÄÐÂiLOBleed
¾ÝýÌå12ÔÂ28Èճƣ¬£¬£¬ÒÁÀÊÇå¾²¹«Ë¾AmnpardazÔÚÒ°·¢Ã÷Õë¶Ô»ÝÆÕIntegrated Lights-Out(iLO)µÄжñÒâÈí¼þiLOBleed¡£¡£¡£¡£¡£ÕâÊÇÊ׸öÕë¶ÔiLO¹Ì¼þµÄrootkit£¬£¬£¬Ëü¿ÉÒÔ³¤Ê±¼äµØÒþ²ØÔÚiLOÖв¢ÇÒ²»»áÔڹ̼þÉý¼¶Öб»É¾³ý¡£¡£¡£¡£¡£iLOBleed×Ô2020ÄêÒÔÀ´Ò»Ö±±»ÓÃÓÚ¹¥»÷£¬£¬£¬¿É¸Ä¶¯¹Ì¼þÄ£¿£¿£¿£¿é²¢É¾³ý±»Ñ¬È¾ÏµÍ³ÖеÄÊý¾Ý¡£¡£¡£¡£¡£ÏÖÔڸöñÒâÈí¼þ±³ºó¹¥»÷ÕßµÄÉí·ÝÈÔδȷ¶¨£¬£¬£¬µ«AmnpardazÍÆ²âËüÓëij¸öÓɹú¼ÒÖ§³ÖµÄAPT×éÖ¯Óйء£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threats.amnpardaz.com/en/2021/12/28/implant-arm-ilobleed-a/
Ô½ÄϹ«Ë¾ONUSÔâÀÕË÷¹¥»÷£¬£¬£¬¾Ü¾øÖ§¸¶500ÍòÃÀÔªÊê½ð
¾ÝýÌå12ÔÂ29ÈÕ±¨µÀ£¬£¬£¬Ô½ÄϵĽðÈڿƼ¼¹«Ë¾ONUSÔâµ½ÀÕË÷¹¥»÷¡£¡£¡£¡£¡£12ÔÂ11ÈÕÖÁ13ÈÕʱ´ú£¬£¬£¬¹¥»÷ÕßÀÖ³ÉʹÓÃONUS CyclosЧÀÍÆ÷ÉϵÄLog4ShellÎó²î£¬£¬£¬²¢Ö²ÈëºóÃÅ¡£¡£¡£¡£¡£CyclosÔÚ13ÈÕÐû²¼Í¨¸æ³ÆÐÞ¸´Æäϵͳ£¬£¬£¬µ«´ËʱΪʱÒÑÍí¡£¡£¡£¡£¡£¹¥»÷ÕßÒÑÇÔÈ¡¸Ã¹«Ë¾½ü200ÍòÌõ¿Í»§¼Í¼£¬£¬£¬°üÀ¨E-KYCÊý¾Ý¡¢Ð¡ÎÒ˽¼ÒÐÅÏ¢ºÍÃÜÂë¡£¡£¡£¡£¡£12ÔÂ25ÈÕ£¬£¬£¬ONUS¾Ü¾øÖ§¸¶500ÍòÃÀÔªµÄÊê½ðÖ®ºó£¬£¬£¬¹¥»÷Õß×îÏȳöÊÛÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fintech-firm-hit-by-log4j-hack-refuses-to-pay-5-million-ransom/
AvosLockerÔÚÈëÇÖÃÀ¹ú¾¯Ô±¾ÖºóÏòÆäÌṩ½âÃÜÆ÷
ýÌå12ÔÂ29Èճƣ¬£¬£¬AvosLockerÒÑÃâ·ÑÏòÃÀ¹ú¾¯Ô±¾ÖÌṩ½âÃÜÆ÷¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÉϸöÔÂÒÑÈëÇÖÃÀ¹úµÄ¾¯Ô±¾Ö£¬£¬£¬¹¥»÷ʱ´úÇÔÈ¡¸Ã»ú¹¹µÄÊý¾Ý²¢¼ÓÃÜÆä×°±¸¡£¡£¡£¡£¡£AvosLockerÔÚµÃÖª¶Ô·½ÊÇÕþ¸®»ú¹¹ºóÁ¬Ã¦ÖÂǸ£¬£¬£¬²¢Ãâ·ÑÌṩ½âÃÜÆ÷¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄ³ÉÔ±ÌåÏÖ£¬£¬£¬ËûÃÇûÓÐÏêϸµÄÕë¶ÔÄ¿µÄµÄÕþ²ß£¬£¬£¬µ«Í¨³£»£»£»£»á×èÖ¹¶ÔÕþ¸®»ú¹¹ºÍÒ½Ôº¾ÙÐй¥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-gang-coughs-up-decryptor-after-realizing-they-hit-the-police/
Òò»ÝÆÕ³¬ËãµÄ±¸·Ýϵͳ¹ýʧ£¬£¬£¬¾©¶¼´óѧɥʧ77TBÊý¾Ý
¾ÝýÌåÓÚ12ÔÂ30ÈÕ±¨µÀ£¬£¬£¬ÓÉÓÚ»ÝÆÕ¹«Ë¾³¬µÈÅÌËã»úµÄ±¸·Ýϵͳ·ºÆð¹ýʧ£¬£¬£¬µ¼ÖÂÈÕ±¾¾©¶¼´óѧԼ77TBµÄ¿ÆÑÐÊý¾Ý±»Îóɾ¡£¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2021Äê12ÔÂ14ÈÕÖÁ16ÈÕ£¬£¬£¬14¸ö¿ÆÑÐС×éµÄ3400Íò·ÝÎļþ´ÓϵͳºÍ±¸·ÝÎļþÖб»É¾³ý¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬±¸·Ý³ÌÐò±¾Ó¦Ê¹ÓÃfindÏÂÁîɾ³ýÁè¼Ý10ÌìµÄÎôÈÕÖ¾£¬£¬£¬µ«Æä¹ýʧµØÖ´ÐÐÁ˰üÀ¨Î´½ç˵±äÁ¿µÄfindÏÂÁ£¬£¬É¾³ýÁË/LARGE0Ŀ¼ÏµÄÕý³£Îļþ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬¸Ã´óѧÒÑ·ÅÆú¸Ã±¸·Ýϵͳ£¬£¬£¬²¢ÍýÏëÔÚ2022Äê1ÔÂÖØÐÂÒýÈë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/university-loses-77tb-of-research-data-due-to-backup-error/