Unit 42Åû¶Õë¶ÔÃÀ¹ú¹ú·À³Ð°üÉ̵ĺóÃÅSockDetourµÄϸ½Ú

°ä²¼¹¦·ò 2022-03-01

Unit 42Åû¶Õë¶ÔÃÀ¹ú¹ú·À³Ð°üÉ̵ĺóÃÅSockDetourµÄϸ½Ú


2ÔÂ24ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Unit 42×êÑÐÈËÔ±·¢ÎÄ³ÆÆäÔÚ¸ú×ÙAPT»î¶¯TiltedTempleʱ·¢ÏÖÁËкóÃÅSockDetour¡£ ¡£¡£¡£¡£¡£¸ÃºóÃÅÖÁÉÙ×Ô2019Äê7Ô¾ÍÒѾ­´æÔÚ£¬£¬£¬£¬£¬ £¬£¬£¬ÖØÒª±»ÓÃ×÷±¸·ÝºóÃÅÒÔ·ÀÖ÷ºóÃű»É¾¡£ ¡£¡£¡£¡£¡£ÒòÆäÔÚÖ¸±êWindows·þÎñÆ÷ÉÏÎÞÎļþÇÒÎÞÌ×½Ó×ÖµØÔËÐУ¬£¬£¬£¬£¬ £¬£¬£¬ËùÒÔºÜÄѱ»¼ì²âµ½¡£ ¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬ £¬£¬£¬Õâ´Î»î¶¯ÖØÒª¶Ô×¼ÃÀ¹úµÄ¹ú·À³Ð°üÉÌ£¬£¬£¬£¬£¬ £¬£¬£¬Ä¿Ç°ÖÁÉÙÓÐ4¼Ò´ËÀ๫˾Ôâµ½¹¥»÷¡£ ¡£¡£¡£¡£¡£¹ÌÈ»ÉÐ佫ºóÃÅSockDetour¹éÒòÓÚÈκκڿÍ×éÖ¯£¬£¬£¬£¬£¬ £¬£¬£¬µ«TiltedTemple»î¶¯ÓëAPT27ÓйØ¡£ ¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/sockdetour/


Ӣΰ´ï³ÆÆäÔÚµ÷²éµ¼Ö²¿ÃÅϵͳÖжÏ2ÌìµÄ¹¥»÷ÊÂÎñ


¾ÝýÌå2ÔÂ25ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬£¬£¬GPUÔì×÷ÉÌӢΰ´ï£¨Nvidia£©ÔÚµ÷²éµ¼Ö²¿ÃÅϵͳÖжÏ2ÌìµÄ¹¥»÷ÊÂÎñ¡£ ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷Ó°ÏìÁ˹«Ë¾µÄ¿ª·¢ÈËÔ±¹¤¾ßºÍµç×ÓÓʼþϵͳ£¬£¬£¬£¬£¬ £¬£¬£¬µ«ÒµÎñºÍóÒ׻²¢Î´Êܵ½Ó°Ïì¡£ ¡£¡£¡£¡£¡£Éв»Ã÷ÏÔÊÇ·ñÓÐÒµÎñ»ò¿Í»§µÄÐÅÏ¢±»µÁ£¬£¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾Ä¿Ç°ÈÔÔÚÆÀ¹ÀÊÂÎñµÄÐÔÖʺÍÁìÓò¡£ ¡£¡£¡£¡£¡£2ÔÂ26ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Lapsus$ÍÅ»ïÐû³ÆËûÃÇÒÑÈëÇÖNvidiaµÄÍøÂç²¢ÇÔÈ¡ÁË1TBµÄÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬»¹¹«¿ªÁËNvidiaËùÓÐÔ±¹¤µÄÃÜÂë¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/gpu-giant-nvidia-is-investigating-a-potential-cyberattack/


NHS¶½´ÙÓû§½¨¸´Okta¿Í»§¶ËÖеÄRCE CVE-2022-24295


Ó¢¹úNHSÊý×Ö»ú¹¹ÔÚ2ÔÂ24ÈÕ°ä²¼Á˹«¸æ£¬£¬£¬£¬£¬ £¬£¬£¬¶½´ÙÓû§¾¡¿ì½¨¸´Okta Advanced Server Access Éí·ÝÑéÖ¤ÖÎÀíÆ½Ì¨ÖеÄRCE·ì϶¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2022-24295£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÓÃÀ´Í¨¹ýÌØÔìURLÖ´ÐкÅÁî×¢È룬£¬£¬£¬£¬ £¬£¬£¬³É¹¦ÀûÓÿɵ¼ÖÂÆëÈ«½ÚÔìϵͳ¡¢Ö´Ðо²Ä¬µÄÊý¾Ýй¶¡¢ºáÏòÒÆ¶¯ÒÔ¼°¶Ô¹«Ë¾ÍøÂçµÄ³õʼ½Ó¼û¡£ ¡£¡£¡£¡£¡£NHS»¹ÌáÐÑÖÎÀíÔ±£¬£¬£¬£¬£¬ £¬£¬£¬OktaµÄ¼¸¸ö²úÆ·Ò²Êܵ½Log4Shell·ì϶µÄÓ°Ïì¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/nhs-urges-orgs-to-apply-security-update-for-okta-client-rce-bug/


CISA°ä²¼¹ØÓÚÒÁÀÊMuddyWaterµÄ¼äµý»î¶¯µÄ¹«¸æ


2ÔÂ24ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬CISA¡¢FBI¡¢CNMF¡¢NCSC-UKºÍNSA°ä²¼ÁËÒ»·Ý½áºÏÍøÂ簲ȫÕ÷ѯ¡£ ¡£¡£¡£¡£¡£¸ÃÕ÷ѯÅû¶ÁËÒÁÀÊAPT×éÖ¯MuddyWatterÔÚÕë¶ÔÈ«Çò¹Ø¼ü»ù´¡ÉèÊ©µÄ¹¥»÷ÖÐʹÓõÄжñÒâÈí¼þµÄÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¸Ã»î¶¯Õë¶ÔÑÇÖÞ¡¢·ÇÖÞ¡¢Å·Ö޺ͱ±ÃÀµÄµçÐÅ¡¢¹ú·À¡¢Ê¯ÓÍ¡¢ÌìÈ»ÆøÐÐÒµºÍ´¦Ëùµ±¾Ö×éÖ¯£¬£¬£¬£¬£¬ £¬£¬£¬Ê¹ÓÃÁËÖîÈçPowGoop¡¢Canopy/Starwhale¡¢Mori¡¢POWERSTATSµÈ¶àÖÖ¶ñÒâÈí¼þ¡£ ¡£¡£¡£¡£¡£¹«¸æ»¹³Áµã½éÉÜÁËPythonºóÃÅSmall SieveºÍÓÃÓÚ¼ÓÃÜC2ͨѶͨ·µÄÒ»¸öPowerShellºóÃÅ¡£ ¡£¡£¡£¡£¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/02/24/iranian-government-sponsored-muddywater-actors-conducting


Check Point°ä²¼Ð¶ñÒâÈí¼þElectron BotµÄ·ÖÎö»ã±¨


2ÔÂ24ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Check Point Research(CPR)Åû¶ÁËжñÒâÈí¼þElectron BotµÄ¼¼Êõϸ½Ú¡£ ¡£¡£¡£¡£¡£¸Ã»î¶¯»î¶¯Ê¼ÓÚ2018Äêµ×£¬£¬£¬£¬£¬ £¬£¬£¬Î±Ôì³É2Temple RunºÍSubway SurferµÈÈȵãÓÎÏ·£¬£¬£¬£¬£¬ £¬£¬£¬Í¨¹ýMicrosoft Store½øÐд«²¼£¬£¬£¬£¬£¬ £¬£¬£¬´Ë¿ÌÒÑϰȾÁËÈðµä¡¢±£¼ÓÀûÑÇ¡¢¶íÂÞ˹¡¢°ÙĽ´óºÍÎ÷°àÑÀµÄ5000¶àÌ¨ÍÆËã»ú¡£ ¡£¡£¡£¡£¡£Electron BotÊÇÒ»ÖÖÄ £¿£¿£¿£¿£¿ £¿£¿é»¯µÄ SEO Öж¾¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬£¬£¬ÖØÒªÓÃÓÚÉ罻ýÌåÍÆ¹ãºÍµã»÷ڲƭ»î¶¯¡£ ¡£¡£¡£¡£¡£


https://research.checkpoint.com/2022/new-malware-capable-of-controlling-social-media-accounts-infects-5000-machines-and-is-actively-being-distributed-via-gaming-applications-on-microsofts-official-store/


Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬ £¬£¬£¬½¨¸´Æä¶à¸ö²úÆ·Öеķì϶


2ÔÂ23ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬ £¬£¬£¬½¨¸´Á˶à¿î²úÆ·Öеķì϶¡£ ¡£¡£¡£¡£¡£ÆäÖнÏΪÑϳÁµÄÊÇ˼¿ÆNX-OSÈí¼þNX-APIºÅÁî×¢Èë·ì϶£¨CVE-2022-20650£©£¬£¬£¬£¬£¬ £¬£¬£¬Ô´ÓÚ¶ÔÓû§ÌṩµÄÊý¾Ý²»×ã×ã¹»µÄÊäÈëÑéÖ¤£»£»£»£»£»£»£»£»ÒÔ¼°Cisco Fabric Services Over IP (CFSoIP)ÖеĻؾø·þÎñ·ì϶£¨CVE-2022-20624£©ºÍNexus 9000ϵÁл¥»»»úË«Ïòת·¢¼ì²â(BFD)Á÷Á¿Ö°ÄÜÖеĻؾø·þÎñ·ì϶£¨CVE-2022-20623£©¡£ ¡£¡£¡£¡£¡£


https://thehackernews.com/2022/02/new-flaws-discovered-in-ciscos-network.html


°²È«¹¤¾ß


Win Brute Logon


ÔÚûÓÐÈκÎȨÏÞµÄÇé¿öÏÂÆÆ½âÈκΠMicrosoft Windows Óû§ÃÜÂ루Ô̺¬·Ã¿ÍÕÊ»§£©¡£ ¡£¡£¡£¡£¡£


https://github.com/DarkCoderSc/win-brute-logon


PHP Malware Finder


¾¡ÆäËùÄܵؼì²âÍÌ͵ĴúÂ룬£¬£¬£¬£¬ £¬£¬£¬ÒÔ¼°ÔÚ¶ñÒâÈí¼þºÍwebshellÖÐʱʱʹÓõÄPHPº¯ÊýÎļþ¡£ ¡£¡£¡£¡£¡£


https://github.com/jvoisin/php-malware-finder


LDAP Password Hunter


Ëü°ü×°ÁË getTGT.py (Impacket) ºÍ ldapsearch µÄÖ°ÄÜ£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔ±ã²éÕÒ´æ´¢ÔÚ LDAP Êý¾Ý¿âÖеÄÃÜÂë¡£ ¡£¡£¡£¡£¡£


https://github.com/oldboy21/LDAP-Password-Hunter


Collabfiltrator


ÊÇÒ»ÖÖͨ¹ý Burp Collaborator ͨ¹ý DNS ÇÔȡԶ³Ì´úÂëÖ´ÐÐÊä³öµÄ¹¤¾ß


https://packetstormsecurity.com/files/166062/Collabfiltrator-2.1.zip


ostorlab


Ò»¸ö°²È«É¨ÃèÆ½Ì¨£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÄÜÒÔµ¥Ò»¡¢¿ÉÀ©´óºÍÉ¢²¼Ê½µÄ·½Ê½ÔËÐÐÉæ¼°¶à¸ö¹¤¾ßµÄ¸´ÔÓ°²È«É¨Ã蹤×÷¡£ ¡£¡£¡£¡£¡£


https://docs.ostorlab.co/



°²È«·ÖÎö


΢ÈíÖÒ¸æÐ嵀 Windows 11 ³ÁÖÃÃýÎó


https://news.softpedia.com/news/microsoft-warns-of-new-windows-11-reset-bug-534943.shtml


Ãâ·ÑµÄ Android ÀûÓÿÉÈüì²â Apple AirTag ¸ú×Ù


https://www.bleepingcomputer.com/news/security/free-android-app-lets-users-detect-apple-airtag-tracking/


Android É쵀 Visual Voice Mail ¿ÉÄÜÈÝÒ×±»ÇÔÌý


https://www.bleepingcomputer.com/news/security/visual-voice-mail-on-android-may-be-vulnerable-to-eavesdropping/


΢Èí£º1 Ô Windows Server ¸üе¼Ö Netlogon ÎÊÌâ


https://www.bleepingcomputer.com/news/microsoft/microsoft-january-windows-server-updates-cause-netlogon-issues/


ÍøÂçºÚ¿ÍרһÓÚÔÚÃÀ¹úÏúÊ۸߼ÛÖµÖ¸±ê


https://www.bleepingcomputer.com/news/security/network-hackers-focus-on-selling-high-value-targets-in-the-us/