SolarWinds½¨¸´Serv-UÖÐÊäÈëÑéÖ¤·ì϶CVE-2021-35247

°ä²¼¹¦·ò 2022-01-26

SolarWinds½¨¸´Serv-UÖÐÊäÈëÑéÖ¤·ì϶CVE-2021-35247


¾ÝýÌå1ÔÂ19ÈÕ±¨Â·£¬£¬£¬£¬£¬SolarWinds½¨¸´ÁËServ-UÖÐÒѱ»ÔÚÒ°ÀûÓõÄÊäÈëÑéÖ¤·ì϶¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2021-35247£¬£¬£¬£¬£¬ÓÉ΢Èí×êÑÐÈËÔ±Jonathan Bar OrÔÚ¼à¿ØÀûÓÃLog4j¿âÖеķì϶½øÐеĹ¥»÷ʱ·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿É±»ÓÃÀ´ÔÚ¸ø¶¨Ò»Ð©ÊäÈëµÄÇé¿öϹ¹½¨Ò»¸ö²éÎÊ£¬£¬£¬£¬£¬²¢ÔÚδ¾­´¦ÖõÄÇé¿öÏÂͨ¹ýÍøÂç·¢Ë͸òéÎÊ¡£¡£¡£¡£¡£¡£¡£SolarWinds²¼¸æ³Æ£¬£¬£¬£¬£¬LDAPÈÏÖ¤µÄServ-U webµÇ¼½çÃæÔÊÐí½ÓÊÜûÓгä·Ö¹ýÂ˵Ä×Ö·û£¬£¬£¬£¬£¬¸ÃÎÊÌâÔÚServ-U 15.3Öнâ¾ö¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/126933/security/solarwinds-serv-u-flaw.html



ASEC·¢ÏÖͨ¹ýº«¹úWebHardƽ̨´«²¼µÄDDoS IRC Bot


AhnLab°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ(ASEC)ÔÚ1ÔÂ19ÈÕ°ä²¼µÄ»ã±¨ÖаµÊ¾£¬£¬£¬£¬£¬DDoS IRC BotÕýͨ¹ýº«¹úWebHardƽ̨´«²¼¡£¡£¡£¡£¡£¡£¡£»£» £»£»£»£»£»£»î¶¯½«´øÓжñÒâÈí¼þµÄÓÎÏ·ÒÔZIPÎļþµÄ´ó¾ÖÉÏ´«µ½ÍøÂçÓ²ÅÌ£¬£¬£¬£¬£¬¸ÃÎļþÖÐÔ̺¬Ò»¸ö¿ÉÖ´ÐÐÎļþ£¨¡°Game_Open.exe¡±£©£¬£¬£¬£¬£¬Ëü³ýÁËÄܹ»Æô¶¯ÓÎÏ·±í£¬£¬£¬£¬£¬»¹»áÔËÐжñÒâÈí¼þpayload¡£¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þÊÇ»ùÓÚGoLangµÄDDoS IRC Bot£¬£¬£¬£¬£¬±»ÓÃÓÚÌáÒéÕë¶Ôº«¹úµÄDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/01/ddos-irc-bot-malware-spreading-through.html



ÓªÏú¹«Ë¾RR Donnelly³ÆÆäÔâµ½ContiµÄÀÕË÷¹¥»÷


ýÌå1ÔÂ19ÈÕ±¨Â·£¬£¬£¬£¬£¬ÓªÏú¹«Ë¾RR Donnelly(RRD)ÈÏ¿ÉÆäÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£12ÔÂ27ÈÕ£¬£¬£¬£¬£¬RRDÏòSECÌá½»8-K±í¸ñ³ÆËûÃǵÄϵͳÔâµ½ÈëÇÖ£¬£¬£¬£¬£¬ÆäÒѹعØÏµÍ³Ô¤·À¹¥»÷ÊæÕ¹¡£¡£¡£¡£¡£¡£¡£1ÔÂ15ÈÕ£¬£¬£¬£¬£¬ContiÍÅ»ïÐû³Æ¶Ô´ËÕÆ¹Ü£¬£¬£¬£¬£¬²¢ÒÑ´ÓRRDÇÔÈ¡ÁË2.5GBÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬ContiÔÚÓëRRD½øÐн»Éæºó£¬£¬£¬£¬£¬Òѽ«ÕâЩÊý¾Ýɾ³ý¡£¡£¡£¡£¡£¡£¡£1ÔÂ18ÈÕ£¬£¬£¬£¬£¬RRDÓÖ°ä²¼ÁËÒ»·Ý8-KÎļþ£¬£¬£¬£¬£¬ÈÏ¿ÉÆäÊý¾ÝÒÑÔÚ¹¥»÷ÆÚ¼ä±»µÁ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/marketing-giant-rrd-confirms-data-theft-in-conti-ransomware-attack/



ÁÔÓ¥Ðж¯II³É¹¦¿ÛÁôÄáÈÕÀûÑÇBECÍÅ»ïµÄ11¸ö³ÉÔ±


¾ÝýÌå1ÔÂ19ÈÕ±¨Â·£¬£¬£¬£¬£¬¹ú¼ÊÐ̾¯×é֯Эµ÷µÄÁÔÓ¥Ðж¯IIÒѳɹ¦¿ÛÁôÄáÈÕÀûÑÇBECÍÅ»ïµÄ11¸ö³ÉÔ±¡£¡£¡£¡£¡£¡£¡£Õâ´Î·¨Âɻ·¢Õ¹ÓÚ2021Äê12ÔÂ12ÈÕÖÁ22ÈÕ£¬£¬£¬£¬£¬ÊÇ2020ÄêÁÔÓ¥Ðж¯IÖ®ºó¶ÔÌØ¶¨×éÖ¯µÄµÚ¶þ´Î½ø¹¥¡£¡£¡£¡£¡£¡£¡£¹ú¼ÊÐ̾¯×éÖ¯µÄ²¼¸æ³Æ£¬£¬£¬£¬£¬±»²¶µÄÏÓÒÉÈË¿ÉÄÜÒѹ¥»÷50000¶à¸öÖ¸±ê£¬£¬£¬£¬£¬ÆäÖÐÒ»È˵ıʼDZ¾ÉÏÓг¬¹ý800000¸öDZÔÚÖ¸±êÓòµÄÍ´´¦¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÒÔΪ£¬£¬£¬£¬£¬²¿Ãű»²¶ÕßÊôÓÚBECÍÅ»ïSilverTerrier£¨±ðÃûTMT£©¡£¡£¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/operation-falcon-ii-silverterrier-nigerian-bec/



×êÑÐÍŶÓÔÚÒ°·¢ÏÖÕë¶Ô¼ÓÃÜÇ®±ÒµÄжñÒâÈí¼þBHUNT


BitdefenderÓÚ1ÔÂ19ÈÕ°ä²¼»ã±¨£¬£¬£¬£¬£¬Åû¶Ð¶ñÒâÈí¼þBHUNTµÄϸ½Ú¡£¡£¡£¡£¡£¡£¡£BHUNTÊÇÒ»¸öÓÃ.NET ±àдµÄÄ£¿£¿£¿£¿£¿£¿£¿é»¯ÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬¿ÉÄÜÇÔÈ¡¼ÓÃÜÇ®°ü£¨Exodus¡¢Electrum¡¢Atomic¡¢JaxxºÍEthereumµÈ£©ÖеÄÄÚÈÝ¡¢´æ´¢ÔÚä¯ÀÀÆ÷ÖеÄÃÜÂëÒÔ¼°´Ó¼ôÌù°åÖв¶»ñµÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯Éæ¼°°Ä´óÀûÑÇ¡¢°£¼°¡¢µÂ¹ú¡¢Ó¡¶È¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÈÕ±¾¡¢ÂíÀ´Î÷ÑÇ¡¢Å²Íþ¡¢ÐÂ¼ÓÆÂ¡¢ÄÏ·Ç¡¢Î÷°àÑÀºÍÃÀ¹ú£¬£¬£¬£¬£¬¿ÉÄÜÊÇͨ¹ýÆÆ½âÈí¼þ×°Ö÷¨Ê½½øÐзַ¢¡£¡£¡£¡£¡£¡£¡£


https://www.bitdefender.com/blog/labs/poking-holes-in-crypto-wallets-a-short-analysis-of-bhunt-stealer/



Crypto.com½ü500¸öÕË»§±»ºÚ£¬£¬£¬£¬£¬Ôì³É3400ÍòÃÀÔªËðʧ


ýÌå1ÔÂ20Èճƣ¬£¬£¬£¬£¬ÐÂ¼ÓÆÂCrypto.com°ä²¼µÄÉêÃ÷°µÊ¾Æä483¸öÕË»§±»ºÚ£¬£¬£¬£¬£¬Ôì³É3400ÍòÃÀÔªËðʧ¡£¡£¡£¡£¡£¡£¡£×î³õ£¬£¬£¬£¬£¬²¿ÃÅÓû§»ã±¨ÆäÕÊ»§´æÔÚ¿ÉÒÉÂòÂô£¬£¬£¬£¬£¬Ö»¹ÜÊܵ½2FA±£»£» £»£»£»£»£»£»¤µ«ÈÔº±¼ûǧÃÀÔªETH±»µÁ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ1ÔÂ17ÈÕ³õ´Î¼ì²âµ½¹¥»÷£¬£¬£¬£¬£¬ÆäʱÉÙÊýÓû§µÄÕÊ»§ÉÏ´æÔÚδ¾­ÊÚȨµÄÌá¿î¡£¡£¡£¡£¡£¡£¡£Ö®ºó¹«Ë¾ÔÝÍ£ÁËËùÓÐÌá¿îÂòÂô£¬£¬£¬£¬£¬ÔÚ¾­¹ý°²È«¼Ó¹Ìºó£¬£¬£¬£¬£¬Ìá¿î·þÎñÓÚ1ÔÂ18ÈÕÏÂÎç5:46×óÓÒ¸´Ô­¡£¡£¡£¡£¡£¡£¡£Crypto.com°µÊ¾ÒÑ×èÖ¹´ó²¿ÃÅδ¾­ÊÚȨµÄÌá¿î£¬£¬£¬£¬£¬²¢½«ÎªÊÜÓ°Ïì¿Í»§È«¶î±¨Ïú¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cryptocom-confirms-483-accounts-hacked-34-million-withdrawn/



°²È«¹¤¾ß


Raven


ÊǼò»¯¡¢¿É¶¨ÔìÇÒÏìӦѸËٵĸ߼¶ÍøÂçÍþвͼ¡£¡£¡£¡£¡£¡£¡£


https://github.com/qeeqbox/raven


Espoofer


ÊÇÒ»ÖÖ¿ªÔ´²âÊÔ¹¤¾ß£¬£¬£¬£¬£¬¿ÉÈÆ¹ýµç×ÓÓʼþϵͳÖÐµÄ SPF¡¢DKIM ºÍ DMARC Éí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£


https://github.com/chenjj/espoofer


pip-audit


ÊÇÒ»ÖÖÓÃÓÚɨÃè Python »·¾³ÒÔ²éÕÒÓµÓÐÒÑÖª·ì϶µÄ°üµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£


https://github.com/trailofbits/pip-audit


°²È«·ÖÎö


Õë¶ÔÎÚ¿ËÀ¼¹Ù·½ÍøÕ¾µÄ¶ñÒâÈí¼þWhisperGate·ÖÎö


1ÔÂ13ÈÕÎÚ¿ËÀ¼´óÁ¿µÄ¹Ù·½ÍøÕ¾±»¹¥»÷£¬£¬£¬£¬£¬ÎÄÕ·ÖÎöÁ˸ÃÊÂÎñÖжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£


https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3


2021 ÄêµÄÍþÐ²Ì¬ÊÆ·ÖÎö


´Ó²»ÐÝ·¢Õ¹µÄÀÕË÷Èí¼þÉú̬ϵͳµ½Õë¶Ô¹Ø¼ü»ù´¡ÉèÊ©µÄ¹¥»÷£¬£¬£¬£¬£¬ÈüÃÅÌú¿Ë»ØÊ×ÁË 2021 ÄêµÄÍøÂç°²È«Ì¬ÊÆ¡£¡£¡£¡£¡£¡£¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/threat-landscape-2021



Ó¢¹úNCSC°ä²¼×éÖ¯Õмܵ绰ºÍ¶ÌÐÅڲƭ»î¶¯µÄÖ¸ÄÏ


Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ (NCSC) °ä²¼Á˵ÄÖ¸ÄÏÖ¼ÔÚ±£»£» £»£»£»£»£»£»¤¿Í»§ÃâÊÜڲƭ»î¶¯µÄ¹¥»÷£¬£¬£¬£¬£¬Í¬Ê±È·±£ËûÃÇµÄ SMS ºÍµç»°ÐÂÎÅ¿¿µÃס¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/126916/security/ncsc-guidance-communications-with-customers.html