ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ21ÖÜ

Ðû²¼Ê±¼ä 2021-05-24

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê05ÔÂ17ÈÕÖÁ05ÔÂ23ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö £¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î£» £»£»£»£»Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³öÎó²î£» £»£»£»£»SolarWinds Orion Job Scheduler JobRouterService²»×¼È·ÊÚȨ´úÂëÖ´ÐÐÎó²î£» £»£»£»£»Cisco DNA Space CVE-2021-1559 OSÏÂÁîÖ´ÐÐÎó²î£» £»£»£»£»Ubiquiti Networks EdgeRouter²»×¼È·Ö¤ÊéУÑéí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰ®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti £¬ £¬£¬£¬±»ÀÕË÷½ü2000ÍòÃÀÔª£» £»£»£»£»DarkSideÀÕË÷Èí¼þЧÀÍÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª£» £»£»£»£»Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ» £»£»£»£»NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ£» £»£»£»£»UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬ £¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Microsoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î


Microsoft Windows JETÊý¾Ý¿âÒýÇæ±£´æÄÚ´æÆÆËðÎó²î £¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ £¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-594/


2.Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³öÎó²î


Pulse Connect Secureä¯ÀÀSMB¹²Ïí±£´æ»º³åÇøÒç³öÎó²î £¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ £¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800


3.SolarWinds Orion Job Scheduler JobRouterService²»×¼È·ÊÚȨ´úÂëÖ´ÐÐÎó²î


SolarWinds Orion Job Scheduler JobRouterService±£´æ²»×¼È·ÊÚȨÎó²î £¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ £¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-605/


4.Cisco DNA Space CVE-2021-1559 OSÏÂÁîÖ´ÐÐÎó²î


Cisco DNA Space±£´æÊäÈëÑéÖ¤Îó²î £¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ £¬£¬£¬¿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnasp-conn-cmdinj-HOj4YV5n


5.Ubiquiti Networks EdgeRouter²»×¼È·Ö¤ÊéУÑéí§Òâ´úÂëÖ´ÐÐÎó²î


Ubiquiti Networks EdgeRouter HTTPSÏÂÔØ¹Ì¼þ±£´æÖ¤ÊéУÑéÎó²î £¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ £¬£¬£¬¿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-601/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti £¬ £¬£¬£¬±»ÀÕË÷½ü2000ÍòÃÀÔª


1.jpg


°®¶ûÀ¼µÄÒ½ÁÆÐ§ÀÍ»ú¹¹HSEÌåÏÖ £¬ £¬£¬£¬ÆäÔâµ½ÁËContiÀÕË÷Èí¼þ¹¥»÷ £¬ £¬£¬£¬²¢±»ÒªÇóÖ§¸¶19999000ÃÀÔªµÄÊê½ð¡£¡£¡£¸Ã»ú¹¹ÔÚ·¢Ã÷¹¥»÷ºó £¬ £¬£¬£¬ÒÑÓÚÉÏÖÜÎ幨±ÕÁËËùÓÐITϵͳ¡£¡£¡£ContiÍÅ»ïÉù³ÆÒѾ­½øÈëHSEµÄÍøÂçÁ½ÖÜÁË £¬ £¬£¬£¬ÔÚ´Ëʱ´ú £¬ £¬£¬£¬ËûÃÇÇÔÈ¡ÁËHSE 700 GBµÄδ¼ÓÃÜÎļþ £¬ £¬£¬£¬°üÀ¨»¼ÕßÐÅÏ¢ºÍÔ±¹¤ÐÅÏ¢¡¢ÌõÔ¼¡¢²ÆÎñ±¨±íºÍÈËΪµ¥µÈ¡£¡£¡£°®¶ûÀ¼×ÜÀíTaoiseach Miche¨¢l MartinÓÚ5ÔÂ14ÈÕÔÚÐÂÎÅÐû²¼»áÉÏÌåÏÖ £¬ £¬£¬£¬ËûÃǽ«²»Ö§¸¶ÈκÎÊê½ð¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ireland-s-health-services-hit-with-20-million-ransomware-demand/


2¡¢DarkSideÀÕË÷Èí¼þЧÀÍÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª


2.jpg


DarkSideÊÇÒ»¸öÀÕË÷Èí¼þЧÀÍÆ÷ÍŻRaaS£© £¬ £¬£¬£¬Ò»ÖÜǰ¹¥»÷ÁËColonial Pipeline Co.²¢ÀÕË÷500ÍòÃÀÔª¡£¡£¡£¸ÃÍÅ»ïÓÚ2021Äê5ÔÂ13ÈÕÐû²¼ÉùÃ÷³Æ £¬ £¬£¬£¬ÓÉÓÚÖ´·¨Ðж¯ £¬ £¬£¬£¬ËûÃÇÏÖÔÚÒѾ­ÎÞ·¨Í¨¹ýSSH»á¼ûÆä¹«¹²Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢Ö§¸¶Ð§ÀÍÆ÷ºÍCDNЧÀÍÆ÷ £¬ £¬£¬£¬ÒÔ¼°Ö÷»ú½çÃæ¡£¡£¡£Òò´Ë½«ÎªËùÓÐÉÐδ¸¶¿îµÄ¹«Ë¾Ìṩ½âÃܹ¤¾ß £¬ £¬£¬£¬²¢ÔÊÐíÔÚ2021Äê5ÔÂ23ÈÕ֮ǰËÍ»¹ËùÓÐδ³¥Õ®Îñ¡£¡£¡£¸ÃÉùÃ÷»¹Ö¸³öÓÉÓÚÀ´×ÔÃÀ¹úµÄѹÁ¦ £¬ £¬£¬£¬Æä½«ÖÕÖ¹ÀÕË÷»î¶¯¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime


3¡¢Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ


3.jpg


¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷еİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐС£¡£¡£BizarroÊÇWindows¶ñÒâÈí¼þ £¬ £¬£¬£¬¾ßÓÐx64Ä£¿£¿£¿£¿ £¿é £¬ £¬£¬£¬¿ÉÒÔÓÕÆ­Êܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂë £¬ £¬£¬£¬»¹Ê¹ÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆ­Êܺ¦ÕßÏÂÔØÒÆ¶¯Ó¦ÓóÌÐò¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄµÄ½¹µã×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öÏÂÁîµÄºóÃÅ £¬ £¬£¬£¬Ö»Óе±Æä¼ì²âµ½ÒѾ­ÅþÁ¬µ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ £¬ £¬£¬£¬ºóÃŲŻáÆô¶¯¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html


4¡¢NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ


4.jpg


NetscoutÐû²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÖ¸³ö £¬ £¬£¬£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢¶¯ÁËԼĪ290Íò´ÎDDoS¹¥»÷ £¬ £¬£¬£¬±È2020ÄêͬÆÚÔöÌíÁË31£¥ £¬ £¬£¬£¬×î´óΪ480 Gbps £¬ £¬£¬£¬×î´óÍÌÍÂÁ¿Îª675 Mpps £¬ £¬£¬£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£¡£¡£ÆäÖÐ £¬ £¬£¬£¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷ £¬ £¬£¬£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷ £¬ £¬£¬£¬ÔÚÏßЧÀÍÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.netscout.com/blog/asert/beat-goes


5¡¢UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps


5.jpg


UptycsÍþвÑо¿ÍŶÓÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£¡£¡£ËüʹÓÃÎïÁªÍø£¨IoT£©½Úµã¶ÔÓÎÏ·ºÍÆäËûÄ¿µÄ¾ÙÐÐÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷ £¬ £¬£¬£¬ÓÚ2021Äê5ÔµĵÚÒ»Öܱ»·¢Ã÷¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö £¬ £¬£¬£¬¹¥»÷Õßͨ¹ýWgetÀ´Ê¹ÓÃshell¾ç±¾ºÍGafgyt£¨Keksec×îÇàíùµÄ¹¤¾ßÖ®Ò»£©Îª²î±ðµÄ»ùÓÚLinuxµÄϵͳװÖÃSimps payload¡£¡£¡£Æ¾Ö¤Ò»Ìõ°üÀ¨Gafgyt¶ñÒâÈí¼þÑù±¾µÄDiscordÐÂÎÅ £¬ £¬£¬£¬Ñо¿Ö°Ô±ÍƶϸöñÒâÈí¼þÓëKeksecÍÅ»ïÓйØ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.uptycs.com/blog/discovery-of-simps-botnet-leads-ties-to-keksec-group