ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ21ÖÜ

Ðû²¼Ê±¼ä 2021-05-24

> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö


2021Äê05ÔÂ17ÈÕÖÁ05ÔÂ23ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î£»Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³öÎó²î£»SolarWinds Orion Job Scheduler JobRouterService²»×¼È·ÊÚȨ´úÂëÖ´ÐÐÎó²î£»Cisco DNA Space CVE-2021-1559 OSÏÂÁîÖ´ÐÐÎó²î£»Ubiquiti Networks EdgeRouter²»×¼È·Ö¤ÊéУÑéí§Òâ´úÂëÖ´ÐÐÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti£¬±»ÀÕË÷½ü2000ÍòÃÀÔª£»DarkSideÀÕË÷Èí¼þ·þÎñÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª£»Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ£»UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Microsoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î


Microsoft Windows JETÊý¾Ý¿âÒýÇæ±£´æÄÚ´æÆÆËðÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-594/


2.Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³öÎó²î


Pulse Connect Secureä¯ÀÀSMB¹²Ïí±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800


3.SolarWinds Orion Job Scheduler JobRouterService²»×¼È·ÊÚȨ´úÂëÖ´ÐÐÎó²î


SolarWinds Orion Job Scheduler JobRouterService±£´æ²»×¼È·ÊÚȨÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-605/


4.Cisco DNA Space CVE-2021-1559 OSÏÂÁîÖ´ÐÐÎó²î


Cisco DNA Space±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnasp-conn-cmdinj-HOj4YV5n


5.Ubiquiti Networks EdgeRouter²»×¼È·Ö¤ÊéУÑéí§Òâ´úÂëÖ´ÐÐÎó²î


Ubiquiti Networks EdgeRouter HTTPSÏÂÔع̼þ±£´æÖ¤ÊéУÑéÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-601/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti£¬±»ÀÕË÷½ü2000ÍòÃÀÔª


1.jpg


°®¶ûÀ¼µÄÒ½ÁÆ·þÎñ»ú¹¹HSEÌåÏÖ£¬ÆäÔâµ½ÁËContiÀÕË÷Èí¼þ¹¥»÷£¬²¢±»ÒªÇóÖ§¸¶19999000ÃÀÔªµÄÊê½ð¡£¸Ã»ú¹¹ÔÚ·¢Ã÷¹¥»÷ºó£¬ÒÑÓÚÉÏÖÜÎå¹Ø±ÕÁËËùÓÐITϵͳ¡£ContiÍÅ»ïÉù³ÆÒѾ­½øÈëHSEµÄÍøÂçÁ½ÖÜÁË£¬ÔÚ´Ëʱ´ú£¬ËûÃÇÇÔÈ¡ÁËHSE 700 GBµÄδ¼ÓÃÜÎļþ£¬°üÀ¨»¼ÕßÐÅÏ¢ºÍÔ±¹¤ÐÅÏ¢¡¢ÌõÔ¼¡¢²ÆÎñ±¨±íºÍÈËΪµ¥µÈ¡£°®¶ûÀ¼×ÜÀíTaoiseach Miche¨¢l MartinÓÚ5ÔÂ14ÈÕÔÚÐÂÎÅÐû²¼»áÉÏÌåÏÖ£¬ËûÃǽ«²»Ö§¸¶ÈκÎÊê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ireland-s-health-services-hit-with-20-million-ransomware-demand/


2¡¢DarkSideÀÕË÷Èí¼þ·þÎñÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª


2.jpg


DarkSideÊÇÒ»¸öÀÕË÷Èí¼þ·þÎñÆ÷ÍŻRaaS£©£¬Ò»ÖÜÇ°¹¥»÷ÁËColonial Pipeline Co.²¢ÀÕË÷500ÍòÃÀÔª¡£¸ÃÍÅ»ïÓÚ2021Äê5ÔÂ13ÈÕÐû²¼ÉùÃ÷³Æ£¬ÓÉÓÚÖ´·¨Ðж¯£¬ËûÃÇÏÖÔÚÒѾ­ÎÞ·¨Í¨¹ýSSH»á¼ûÆ乫¹²Êý¾Ýй¶ÍøÕ¾¡¢Ö§¸¶·þÎñÆ÷ºÍCDN·þÎñÆ÷£¬ÒÔ¼°Ö÷»ú½çÃæ¡£Òò´Ë½«ÎªËùÓÐÉÐδ¸¶¿îµÄ¹«Ë¾Ìṩ½âÃܹ¤¾ß£¬²¢ÔÊÐíÔÚ2021Äê5ÔÂ23ÈÕ֮ǰËÍ»¹ËùÓÐδ³¥Õ®Îñ¡£¸ÃÉùÃ÷»¹Ö¸³öÓÉÓÚÀ´×ÔÃÀ¹úµÄѹÁ¦£¬Æ佫ÖÕÖ¹ÀÕË÷Ô˶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime


3¡¢Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ


3.jpg


¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷еİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐС£BizarroÊÇWindows¶ñÒâÈí¼þ£¬¾ßÓÐx64Ä£¿é£¬¿ÉÒÔÓÕÆ­Êܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬»¹Ê¹ÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆ­Êܺ¦ÕßÏÂÔØÒƶ¯Ó¦ÓóÌÐò¡£¸Ã¶ñÒâÈí¼þµÄµÄ½¹µã×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öÏÂÁîµÄºóÃÅ£¬Ö»Óе±Æä¼ì²âµ½ÒѾ­ÅþÁ¬µ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬ºóÃŲŻáÆô¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html


4¡¢NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ


4.jpg


NetscoutÐû²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢¶¯ÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬±È2020ÄêͬÆÚÔöÌíÁË31£¥£¬×î´óΪ480 Gbps£¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£ÆäÖУ¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬ÔÚÏß·þÎñÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.netscout.com/blog/asert/beat-goes


5¡¢UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps


5.jpg


UptycsÍþвÑо¿ÍŶÓÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£ËüʹÓÃÎïÁªÍø£¨IoT£©½Úµã¶ÔÓÎÏ·ºÍÆäËûÄ¿µÄ¾ÙÐÐÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷£¬ÓÚ2021Äê5ÔµĵÚÒ»Öܱ»·¢Ã÷¡£Ñо¿Ö°Ô±Ö¸³ö£¬¹¥»÷Õßͨ¹ýWgetÀ´Ê¹ÓÃshell¾ç±¾ºÍGafgyt£¨Keksec×îÇàíùµÄ¹¤¾ßÖ®Ò»£©Îª²î±ðµÄ»ùÓÚLinuxµÄϵͳװÖÃSimps payload¡£Æ¾Ö¤Ò»Ìõ°üÀ¨Gafgyt¶ñÒâÈí¼þÑù±¾µÄDiscordÐÂÎÅ£¬Ñо¿Ö°Ô±ÍƶϸöñÒâÈí¼þÓëKeksecÍÅ»ïÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.uptycs.com/blog/discovery-of-simps-botnet-leads-ties-to-keksec-group