΢Èí°ä²¼²¼¸æ³ÆIE 0dayÒÑÔâÒ°±íÀûÓ㬣¬ £¬£¬£¬£¬£¬Ä¿Ç°ÉÐÎÞ²¹¶¡£¡£¡£¡£¡£¡£¡£¡£» £»£»£»£»£»Î÷ÃÅ×ÓÖÒ¸æ¿Í»§ÓйØÔÚ¹¤Òµ²úÆ·ÖÐʹÓÃActiveXµÄ·çÏÕ

°ä²¼¹¦·ò 2020-01-19


1.΢Èí°ä²¼²¼¸æ³ÆIE 0dayÒÑÔâÒ°±íÀûÓ㬣¬ £¬£¬£¬£¬£¬Ä¿Ç°ÉÐÎÞ²¹¶¡


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


1ÔÂ17ÈÕ΢Èí°ä²¼°²È«²¼¸æ£¨ADV200001£©£¬£¬ £¬£¬£¬£¬£¬ÖÒ¸æÓû§¹ØÓÚIE 0day£¨CVE-2020-0674£©ÒÑÔâÒ°±íÀûÓõÄÇé¿ö£¬£¬ £¬£¬£¬£¬£¬²¢ÇҸ÷ì϶ÔÝÎÞ½¨¸´²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬ £¬£¬£¬£¬£¬½öÓÐÓ¦±ä´ëÊ©»ººÍ½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£Î¢Èí°µÊ¾ÔÚÍÆ³ö½â¾ö¹æ»®£¬£¬ £¬£¬£¬£¬£¬¿ÉÄÜÔÚºóÐøÒÔ´ø±í¸üеķ½Ê½°ä²¼¡£¡£¡£¡£¡£¡£¡£¡£¸Ã0dayδÔâ´ó¹æÄ£ÀûÓ㬣¬ £¬£¬£¬£¬£¬Ö»ÊÇÕë¶ÔÉÙÁ¿Óû§¹¥»÷µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý²¼¸æ£¬£¬ £¬£¬£¬£¬£¬Î¢Èí³Æ¸Ã0dayΪԶ³Ì´úÂëÖ´Ðзì϶£¨RCE£©£¬£¬ £¬£¬£¬£¬£¬ÓëIE¾ç±¾ÒýÇæÔÚ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÓйØ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÄÚ´æ°Ü»µ·ì϶£¬£¬ £¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÒÔµ±Ç°Óû§µÄȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ÔÚweb¹¥»÷³¡¾°ÖУ¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÓÕʹÓû§½Ó¼û¶ñÒâÍøÕ¾À´ÀûÓø÷ì϶£¨ÀýÈçͨ¹ý´¹µöÓʼþ£©¡£¡£¡£¡£¡£¡£¡£¡£Óû§¿Éͨ¹ýÏ޶ȶÔJScript.dllµÄ½Ó¼ûÀ´ÁÙʱ»º½â¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£¡£

  Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/01/internet-explorer-zero-day-attack.html


2.Î÷ÃÅ×ÓÖÒ¸æ¿Í»§ÓйØÔÚ¹¤Òµ²úÆ·ÖÐʹÓÃActiveXµÄ·çÏÕ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Î÷ÃÅ×ÓµÄһЩ¹¤Òµ²úÆ·£¨Ô̺¬SIMATIC WinCC¡¢SIMATIC STEP 7¡¢SIMATIC PCS 7¡¢TIA PortalºÍS7-PLCSIM Advanced£©ÒÀÀµActiveX×é¼þ£¬£¬ £¬£¬£¬£¬£¬¿Í»§±ØÒªÊ¹ÓÃInternet ExplorerÀ´Ö´ÐÐÕâЩ×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£µ«¸Ã³§ÉÌÖÒ¸æ¿Í»§³Æ£¬£¬ £¬£¬£¬£¬£¬Ê¹ÓÃIE½Ó¼û²»ÊÜÐÅÀµµÄÍøÕ¾¿ÉÄÜ»á´øÀ´ÑϳÁµÄ°²È«·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£Î÷ÃÅ×Ó½¨ÒéÔÚ½Ó¼ûÓ빫˾²úÆ·Î޹صÄÍøÒ³Ê±Ê¹Óò»Ö§³ÖActiveXµÄÍøÒ³ä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬Î÷ÃÅ×Ó½üÆÚ»¹½¨¸´ÁËSCALANCE X¹¤Òµ»¥»»»úÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2019-13933£¬£¬ £¬£¬£¬£¬£¬CVSS v3.1ÆÀ·ÖΪ8.8·Ö£©¡¢ SINEMA ServerÖеIJ»ÕýÈ·µÄ»á»°ÑéÖ¤·ì϶£¨CVE-2019-10940£¬£¬ £¬£¬£¬£¬£¬9.9·Ö£©ºÍTIA PortalÖеÄLPE·ì϶£¨CVE-2019-10934£¬£¬ £¬£¬£¬£¬£¬7.8·Ö£©¡£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-warns-security-risks-associated-use-activex


3.×êÑÐÍŶӰ䲼ÀÕË÷Èí¼þParadiseµÄ½âÃܹ¤¾ß


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Bitdefender×êÑÐÍŶӰ䲼ÀÕË÷Èí¼þParadiseµÄ×îнâÃÜÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Paradise×î³õÓÚ2017Äê³öÏÖ£¬£¬ £¬£¬£¬£¬£¬ËüÔÚ¼ÓÃÜʱ»áÈÆ¹ý¼üÅÌ˵»°Îª¶íÓï¡¢¹þÈø¿ËÓï¡¢°×¶íÂÞ˹Óï»òÎÚ¿ËÀ¼ÓïµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¡£Bitdefender°ä²¼µÄ×îнâÃÜÆ÷Ö§³ÖÒÔϺó׺ÃûµÄ±äÖÖ£º.FC¡¢.2ksys19¡¢.p3rf0rm4¡¢.Recognizer¡¢.VACv2¡¢.paradise¡¢.CORP¡¢.immortal¡¢.exploit¡¢.prt¡¢.STUB¡¢.sevºÍ.sambo¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ßÖ§³ÖGUI»òºÅÁî×ßÔËÐУ¬£¬ £¬£¬£¬£¬£¬Óû§¿É´ÓBitdefender¹ÙÍøÏÂÔØ¸Ã¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://labs.bitdefender.com/2020/01/paradise-ransomware-decryption-tool/


4.ÍÁ¶úÆäºÚ¿Í¹¥»÷Ï£À°¶à¸öµ±²¿ÃÅÃźÍ֤ȯÂòÂôËùÍøÕ¾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÉÏÖÜÎåÍÁ¶úÆäºÚ¿ÍÐû³ÆÒѾ­½Ù³ÖÁËÏ£À°Òé»á¡¢±í½»ºÍ¾­¼Ã²¿ÒÔ¼°¸Ã¹ú¶È֤ȯÂòÂôËùµÄ¹Ù·½ÍøÕ¾³¤´ï90¶à·ÖÖÓ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃºÚ¿ÍÍÅ»ïΪAnka Neferler Tim£¬£¬ £¬£¬£¬£¬£¬ËûÃÇÔÚFacebookÒ³ÃæÉϱ绤³Æ¡°Ï£À°Ò»ÏòÔÚ°®ÇÙº£ºÍµØÖк£¶«²¿ÍþвÍÁ¶úÆä£¬£¬ £¬£¬£¬£¬£¬´Ë¿ÌÓÖÔÚÍþвÀû±ÈÑÇºÍÆ½»áÒ顱¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»áÒéµÄÖ÷ÕÅÊÇÔÚ½áºÏ¹úµÄÖ÷³ÖÏÂÆô¶¯Àû±ÈÑÇµÄºÍÆ½¹ý³Ì£¬£¬ £¬£¬£¬£¬£¬½«ÔÚ°ØÁÖ½øÐС£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/turkish-hackers-target-greek-government-websites-stock-exchange


5.ÐÂÔóÎ÷ÖÝÓÌÌ«½ÌÌÃÔâµ½ÀÕË÷Èí¼þSodinokibi¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÐÂÔóÎ÷ÖÝÎÖÂ×ÊеÄÓÌÌ«½ÌÌÃTemple Har ShalomÔâµ½ÀÕË÷Èí¼þSodinokibi¹¥»÷£¬£¬ £¬£¬£¬£¬£¬ÆäÍøÂçÉϵĺܶàÍÆËã»úϵͳ±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã½ÌÌÃÓÚ1ÔÂ9ÈÕ·¢ÏÖÁ˹¥»÷ÊÂÎñ£¬£¬ £¬£¬£¬£¬£¬Æä·þÎñÆ÷ÉϵÄËùÓÐÎļþºÍµç×ÓÊý¾Ý¾ù±»¼ÓÃÜ£¬£¬ £¬£¬£¬£¬£¬Ô̺¬ÕâЩÎļþºÍÊý¾ÝµÄ±¸·Ý¡£¡£¡£¡£¡£¡£¡£¡£ÐÂÎÅÈËÊ¿³ÆSodinokibi¹¥»÷ÕßÒªÇó½ü50ÍòÃÀÔªµÄÊê½ð£¬£¬ £¬£¬£¬£¬£¬µ«¸Ã½ÌÌðµÊ¾½«Óë»á¶àÁªÏµÒÔ»ñÈ¡³Á½¨¼ÓÃÜÎļþËùÐèµÄÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬ÕâÅú×¢ËûÃÇÎÞÒâÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¶àËùÖÜÖªSodinokibiÔÚ¼ÓÃÜÎļþ֮ǰ»áÏÈÇÔÈ¡Îļþ£¬£¬ £¬£¬£¬£¬£¬Òò¶ø»á¶àµÄÐÕÃû¡¢µØÖ·ºÍµç×ÓÓʼþµØÖ·¿ÉÄܱ»µÁ£¬£¬ £¬£¬£¬£¬£¬µ«¸Ã½ÌÌÃÒÔΪ¹¥»÷ÕßÎÞ·¨½Ó¼û²ÆÕþÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-jersey-synagogue-suffers-sodinokibi-ransomware-attack/


6.¶ñÒâÈí¼þMetamorfoбäÖÖÖØÒªÕë¶Ô°ÍÎ÷½ðÈÚ»ú¹¹


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


FortiGuard Labs·¢ÏÖ¶ñÒâÈí¼þMetamorfoµÄбäÖÖ£¬£¬ £¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÒÔÍøÂç°ÍÎ÷½ðÈÚ»ú¹¹¿Í»§µÄÊý¾Ý¶øÎÅÃû¡£¡£¡£¡£¡£¡£¡£¡£¸Ã±äÖÖͨ¹ý´¹µöÓʼþ´«²¼£¬£¬ £¬£¬£¬£¬£¬´¹µöÓʼþÓɰÍÎ÷¹Ù·½Ëµ»°ÆÏÌÑÑÀÓïд³É£¬£¬ £¬£¬£¬£¬£¬ÄÚÈÝΪ¶½´ÙÊܺ¦ÕßÏÂÔØµç×Ó·¢Æ±£¨NF£©£¬£¬ £¬£¬£¬£¬£¬µ«ÏÖʵÏÂÔØµÄÎļþΪXlsPlan_Visualize.msi¡£¡£¡£¡£¡£¡£¡£¡£¸ÃMSIÎļþÖ»ÊÇÒ»¸ö¶ñÒâÈí¼þÏÂÔØÆ÷£¬£¬ £¬£¬£¬£¬£¬×îÖÕ½«ÏÂÔØKJFLDKRE.msi²¢Ö´ÐУ¬£¬ £¬£¬£¬£¬£¬¸ÃÎļþÊÇÕæÕýµÄMetamorfo¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÄܹ»ÍøÂçÊܺ¦ÕßµÄÍÆËã»úÃû³Æ¡¢¿Í»§¶Ë°æ±¾¡¢²Ù×÷ϵͳÃû³Æ¡¢ÕË»§ÃÜÂëµÈÊý¾Ý²¢·¢ËÍÖÁC&C·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/blog/threat-research/analysis-metamorfo-variant-targets-financial-organizations.html