FIN6¼°ÔËÓªTrickBotµÄÍÅ»ï½áºÏµÄ¹¥»÷»î¶¯£»£»£»£»£»£»HMR¹«Ë¾Ôâµ½ÀÕË÷Èí¼þMaze¹¥»÷
°ä²¼¹¦·ò 2020-04-091.Ò©Îï²âÊÔ¹«Ë¾HMRÔâµ½ÀÕË÷Èí¼þMaze¹¥»÷
Ò©Îï²âÊÔ¹«Ë¾HMRÔâµ½ÀÕË÷Èí¼þMaze¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ²¿ÃÅ×ÔÔ¸ÕßÐÅÏ¢±»µÁ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷²úÉúÔÚ3ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Maze¹¥»÷ÕßÇÔÈ¡ÁËHMRÍøÂçÉÏÍйܵÄÊý¾Ý²¢¶ÔÆäÍÆËã»ú½øÐмÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓڸù«Ë¾»Ø¾øÖ§¸¶Êê½ð£¬£¬£¬£¬£¬£¬£¬£¬MazeÍÅ»ïÓÚ3ÔÂ21ÈÕÔÚÆäÍøÕ¾Éϰ䲼Á˲¿Ãű»µÁµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝHMRµÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬£¬£¬Ê§ÇԵļͼÔ̺¬ÁËÒÔD¡¢G¡¢I»òJ¿ªÍ·µÄ×ÔÔ¸ÕßÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éí·ÝÖ¤Ã÷Îļþ¡¢½¡È«µ÷²é±í¡¢ÔÞ³ÉÊé¡¢²¿Ãżì²âÁ˾ֵȡ£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/drug-testing-firm-sends-data-breach-alerts-after-ransomware-attack/
2.Bitdefender×êÑÐÍŶӷ¢ÏÖÐÂIoT½©Ê¬ÍøÂçdark_nexus
Bitdefender×êÑÐÈËÔ±×î½ü·¢ÏÖÁËÒ»¸öеÄIoT½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬£¬£¬ËüÔ̺¬Á˳¬¹ý´óÎÞÊýIoT½©Ê¬ÍøÂçºÍ¶ñÒâÈí¼þµÄÐÂÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËԱƾ¾Ý½©Ê¬ÍøÂçʹÓõĵÄ×Ö·û´®½«Æä¶¨ÃûΪ¡°dark_nexus¡±¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹Üdark_nexus³ÁÓÃÁËһЩQbotºÍMirai´úÂ룬£¬£¬£¬£¬£¬£¬£¬µ«ÆäÖ÷ÌâÄ£¿£¿£¿£¿£¿é´ó¶àÊÇÔÉúµÄ¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¸Ã½©Ê¬ÍøÂç¿ÉÄÜÓëÒÔǰÒÑÖªµÄIoT½©Ê¬ÍøÂç¹²ÏíijЩְÄÜ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÊÇÆä²¿ÃÅÄ£¿£¿£¿£¿£¿éµÄ¿ª·¢·½Ê½Ê¹ÆäÖ°ÄÜÔ½·¢×³´ó£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÓÐÐ§ÔØºÉÕë¶Ô12ÖÖ·ÖÆçµÄCPU¼Ü¹¹½øÐбàÒ룬£¬£¬£¬£¬£¬£¬£¬²¢Æ¾¾ÝÊܺ¦ÕßµÄÅäÖö¯Ì¬´«µÝ¡£¡£¡£¡£¡£¡£¡£¡£dark_nexus»¹¹ÖÒìµØÊ¹ÓûùÓÚȨ³ÁºÍãÐÖµµÄÆÀ·ÖϵͳÀ´ÆÀ¹ÀÄÄЩ¹ý³Ì¿ÉÄÜ×é³É·çÏÕ£¬£¬£¬£¬£¬£¬£¬£¬²¢É±ËÀËùÓг¬¹ý¿ÉÒÉãÐÖµµÄÆäËü¹ý³Ì¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://labs.bitdefender.com/2020/04/new-dark_nexus-iot-botnet-puts-others-to-shame/
3.FIN6¼°ÔËÓªTrickBotµÄÍÅ»ï½áºÏµÄ¹¥»÷»î¶¯
IBM X-Force×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ×î½üµÄÍøÂç¹¥»÷Öз¢ÏÖÁËFIN6µÄºÛ¼££¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷»î¶¯×î³õÀûÓÃTrickBotľÂíϰȾÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬£¬¶øºó×îÖÕÏÂÔØÁËAnchorºóÃÅ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³ÆÕâÁ½¸ö·¸×ï×éÖ¯-TrickBotµÄÔËÓªÍÅ»ïÒÔ¼°FIN6-ÒѾ½øÐкÏ×÷£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÍøÂç·¸×OÌåÏÖÓкÏ×÷Ç÷ÏòÖеġ°ÐµÄΣÏÕתÕÛ¡±¡£¡£¡£¡£¡£¡£¡£¡£AnchorÖÁÉÙÄܹ»×·Òäµ½2018Ä꣬£¬£¬£¬£¬£¬£¬£¬ËƺõÊÇÓÉTrickBotµÄÔËÓªÍÅ»ï±àдµÄ¡°¡°¶àºÏÒ»¹¥»÷¿ò¼Ü¡±£¬£¬£¬£¬£¬£¬£¬£¬ËüÓɸ÷Àà×ÓÄ£¿£¿£¿£¿£¿é×é³É£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»Ô®ÊÖ¹¥»÷ÕßÔÚÍøÂçÉϺáÏò´«²¼£¨ÀýÈç×°ÖúóÃÅ£©¡£¡£¡£¡£¡£¡£¡£¡£Í¬Ê±TrickBotµÄÁíÒ»¸ö¹¤¾ßPowerTrickÖØÒªÓÃÓÚÔÚÊÜϰȾµÄ¸ß¼ÛÖµÖ¸±ê£¨ÀýÈç½ðÈÚ»ú¹¹£©ÄÚ²¿½øÐÐÒþÉí¡¢ÓÆ¾ÃÐԺͿúËÅ¡£¡£¡£¡£¡£¡£¡£¡£IBM X-ForceÖ¸³öFIN6²Î¼ÓÁËÀûÓÃAnchorºÍPowerTrickµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Æä´æÔÚµÄ×î´óÖ¸±êÊǹ¥»÷ÖÐʹÓõÄ×°ÔØ·¨Ê½£¨Terraloader£©ºÍºóÃÅ£¨More_eggs£©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/fin6-and-trickbot-combine-forces-in-anchor-attacks/154508/
4.¹¥»÷ÕßÀÄÓÃMalwarebytesÆ·ÅÆ·Ö·¢RaccoonľÂí
×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÀÄÓÃMalwarebytesÆ·ÅÆµÄ¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß´´½¨ÁËÒ»¸ö·ÂðµÄMalwarebytesÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾ÓÃÓÚ·Ö·¢RaccoonľÂí¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÓòÃûÊÇmalwarebytes-free[.]com£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ3ÔÂ29ÈÕͨ¹ýÓòÃû×¢²áÉÌREG.RU LLC×¢²á£¬£¬£¬£¬£¬£¬£¬£¬µ±Ç°ÍйÜÔÚ¶íÂÞ˹µÄIP 173.192.139[.]27ÉÏ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾ÉϵÄJavaScript´úÂë¶Î»á²é³·Ã¿ÍµÄä¯ÀÀÆ÷ÀàÐÍ£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÊÇInternet Explorer£¬£¬£¬£¬£¬£¬£¬£¬Ôò»á½«Óû§³Á¶¨ÏòÖÁFallout EKµÄ¶ñÒâURL£¬£¬£¬£¬£¬£¬£¬£¬²¢×îÖÕ×°ÖÃRaccoon¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/exploits-and-vulnerabilities/2020/04/copycat-criminals-abuse-malwarebytes-brand-in-malvertising-campaign/
5.¹È¸è°ä²¼Chrome°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´32¸ö·ì϶
¹È¸èÒÑÓÚ4ÔÂ7ÈÕÏòWindows¡¢macOSºÍLinux°ä²¼ÁËChrome 81£¬£¬£¬£¬£¬£¬£¬£¬³ýÁËbug½¨¸´¡¢ÐÂÖ°ÄÜÖ®±í£¬£¬£¬£¬£¬£¬£¬£¬¸Ã°æ±¾»¹½¨¸´ÁË32¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ3¸ö·ì϶µÄÑϳÁÐԵȼ¶Îª¸ß£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬À©´óÖеÄUAF·ì϶£¨CVE-2020-6454£©¡¢ÒôƵ×é¼þÖеÄUAF·ì϶£¨CVE-2020-6423£©ºÍWebSQLÖеÄÔ½½ç¶Á·ì϶£¨CVE-2020-6455£©¡£¡£¡£¡£¡£¡£¡£¡£ÆäÓà·ì϶µÄÑϳÁÐԵȼ¶ÎªÖлòµÍ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¹È¸èÔ´òËãÔÚChrome 81ÖÐÆëȫɾ³ý¶ÔTLS 1.0ºÍ1.1µÄÖ§³Ö£¬£¬£¬£¬£¬£¬£¬£¬µ«ÓÉÓÚ¹Ú×´²¡¶¾µÄÊ¢ÐУ¬£¬£¬£¬£¬£¬£¬£¬¹È¸èÒѾö¶¨½«ÕâÒ»Ðж¯ÍƳٵ½Chrome 84¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/google/chrome-81-released-with-32-security-fixes-and-web-nfc-api/
6.±´¼ÓÀ³½¨¸´Automation StudioÈí¼þÖеĶà¸ö·ì϶
×êÑÐÈËÔ±·¢ÏÖ±´¼ÓÀ³¹¤Òµ×Ô¶¯»¯¹«Ë¾µÄAutomation StudioÈí¼þ´æÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹©¸øÉÌÒÑÆðÍ·°ä²¼²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£±´¼ÓÀ³ÊÇÒ»¼ÒλÓڰµØÀûµÄ¹¤Òµ×Ô¶¯»¯¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬¾ÝÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©³Æ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄ²úÆ·ÔÚÈ«ÇòÁìÓòÄÚʹÓ㬣¬£¬£¬£¬£¬£¬£¬³ö¸ñÊÇÔÚÄÜÔ´¡¢»¯¹¤ºÍ¹Ø¼üÔì×÷ÁìÓò¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾µÄAutomation Studio°æ±¾4ÊÜÈý¸ö·ì϶µÄÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶ÓëAutomation StudioµÄ¸üзþÎñÓйأ¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÌØÈ¨Éý¼¶·ì϶¡¢²»ÆëÈ«µÄͨѶ¼ÓÃܺÍÑéÖ¤ÎÊÌâÒÔ¼°Óë2018Äê·¢ÏÖµÄZip SlipËÁÒâÎļþ¸²¸Ç·ì϶ÓйصÄõè¾¶±éÀú·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ִÐÐMITM¹¥»÷²¢¹ýÎÊÈí¼þ¸üйý³Ì¡£¡£¡£¡£¡£¡£¡£¡£±´¼ÓÀ³ÒѾΪ²¿ÃÅÊÜÓ°ÏìµÄ°æ±¾°ä²¼Á˲¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚΪÆäÓà°æ±¾½øÐн¨¸´¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/vulnerabilities-br-automation-software-facilitate-attacks-ics-networks


¾©¹«Íø°²±¸11010802024551ºÅ