¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨£»ÐµĶñÒâÈí¼þMrbMinerÒÑϰȾÊýǧ¸öMSSQLÊý¾Ý¿â

°ä²¼¹¦·ò 2020-09-17

1.¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨


1.jpg


¿¨°Í˹»ù¶ÔÒßÇéÆÚ¼äµÄ¹¤ÒµÍøÂ簲ȫÇé¿ö½øÐÐÁË×êÑÐ £¬²¢°ä²¼ÁË2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨¡£»ã±¨ÏÔʾ £¬³¬¹ýÒ»°ë(53%)µÄÊÜ·ÃÕßÈÏ¿É £¬COVID-19µ¼Ö¸ü¶àÔ±¹¤ÔڼҰ칫 £¬ÕâÒѳÉΪ¶ÔÐÅÏ¢°²È«·þÎñµÄÒ»ÖÖѹÁ¦²âÊÔ¡£ÓÉÓÚ±í²¿ÏνÓÊýÁ¿¶à¶à £¬´Ë¿Ì¾ø´óÎÞÊý¹«Ë¾¶¼ÔÚ¶ÔOTÍøÂçµÄ°²È«¼¶±ð½øÐж¨ÆÚÆÀ¹À¡£ºÜ¶à×éÖ¯²»µÃ²»³ÁÐÂ˼¿¼ËûÃÇÄÚÍøµÄ±£»¤²½Öè £¬Ö»ÓÐ7%µÄÊÜ·ÃÕß°µÊ¾ £¬ËûÃǵÄÍøÂ簲ȫսÊõÔÚCOVID-19ÆÚ¼äÏ൱ÓÐЧ¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/industrial-cybersecurity-2020/37031/


2.еĶñÒâÈí¼þMrbMinerÒÑϰȾÊýǧ¸öMSSQLÊý¾Ý¿â


2.jpg


×êÑÐÈËÔ±·¢ÏÖ £¬´ÓǰµÄ¼¸¸öÔÂÖÐ £¬ºÚ¿Í×éÖ¯ÒÑÀûÓÃеĶñÒâÈí¼þMrbMinerÈëÇÖÊýǧ¸öMicrosoft SQL Server£¨MSSQL£©²¢×°ÖÃÁ˼ÓÃܿ󹤡£¸Ã¶ñÒâÈí¼þͨ¹ýɨÃèÍøÂçÉϵÄMSSQL·þÎñÆ÷½øÐд«²¼ £¬¶øºóͨ¹ý·´¸´³¢ÊÔ¸÷ÀàÈõÃÜÂëµÄÖÎÀíÔ¹ØÊ»§À´½øÐб©Á¦¹¥»÷¡£Ò»µ©¹¥»÷Õ߳ɹ¦ÈëÇÖϵͳ £¬ËûÃDZã»áÏÂÔØassm.exeÎļþ £¬ÒÔ³ÉÁ¢ºóÃÅÕÊ»§¹©½«À´½Ó¼û¡£×îºó £¬Ëü½«ÏνÓC2·þÎñÆ÷ £¬²¢ÏÂÔØÒ»¸öÀûÓÃÒÔÍÚ¾òMonero£¨XMR£©¼ÓÃÜÇ®±Ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-mrbminer-malware-has-infected-thousands-of-mssql-databases/


3.Check PointÖÒ¸æÕë¶Ô½ÌÓýºÍѧÊõÁìÓòµÄDDoS¹¥»÷¼¤Ôö


3.png


ÍøÂ簲ȫ¹«Ë¾Check Point·¢ÏÖ £¬Õë¶Ô½ÌÓýºÍѧÊõÁìÓòµÄDDoS¹¥»÷¼¤Ôö¡£ÆäÖ¸³ö £¬´óÎÞÊý¹¥»÷¶¼ÊÇÕë¶ÔÃÀ¹úµÄ»ú¹¹ £¬ÔÚ7ÔºÍ8Ô £¬Õë¶ÔѧÊõ²¿ÃŵĹ¥»÷¾ùÔÈÿÖÜÔö³¤30£¥ £¬´ÓÎåÔºÍÁùÔµÄ468´ÎÔ¾ÉýÖÁ608´Î¡£´Ë±í £¬¹¥»÷ÕßÔÚÕë¶ÔÃÀ¹ú¡¢Å·ÖÞºÍÑÇÖ޵ĽÌÓýºÍ×êÑв¿ÃÅʱѡȡÁË·ÖÆçµÄ²½ÖèºÍÕ½Êõ £¬×îÖÕÖ¸±êËÆºõÒ²ÒòµØÓò¶øÒì¡£Õë¶ÔÅ·Ö޵Ĺ¥»÷ΪÐÅϢй¶ £¬´ÓÎå¡¢ÁùÔµÄ638´ÎÔ¾ÉýÖÁÆß¡¢°ËÔµÄ793´Î £¬Ôö³¤ÁË24£¥¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/surge-in-ddos-attacks-targeting-education-and-academic-sector/


4.×êÑÐÈËÔ±·¢ÏÖWin10ÖеÄFingerºÅÁî¿É±»ÓÃÀ´ÇÔÈ¡Îļþ


4.png


×êÑÐÔ±John Page·¢ÏÖ £¬Microsoft Windows TCPIP FingerºÅÁÄܹ»³äÈÎÎļþÏÂÔØÆ÷ºÍmakeshiftºÅÁîÓë½ÚÔ죨C3£©·þÎñÆ÷ £¬ÒÔÓÃÓÚ·¢ËͺÅÁîºÍÇÔÈ¡Êý¾Ý¡£ÓйØ×êÑÐÈËÔ±³Æ £¬C2ºÅÁîÄܹ»¼Ù×°³Éfinger queriesÀ´ÇÔÈ¡Êý¾Ý £¬¶ø²»±»Windows Defender¼ì²âµ½ÕâÖÖÒì³£ÐÐΪ¡£ÕâÖÖ²½Ö轫ÔÊÐíͨ¹ý·À»ðǽ¹æ¶¨ £¬²¢Ê¹Óò»ÊÜÏ޶ȵÄHTTP¶Ë¿ÚÓë·þÎñÆ÷ͨѶ¡£Í¨¹ýÕâÖÖ²½Öè £¬Portproxy²éÎʱ»´«µÝµ½±¾µØIP £¬¶øºóת·¢µ½Ö¸¶¨µÄC2Ö÷»ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-10-finger-command-can-be-abused-to-download-or-steal-files/


5.Adobe°ä²¼´ø±í¸üР£¬½¨¸´Media EncoderÖÐ3¸ö·ì϶


5.png


Adobe°ä²¼´ø±í¸üР£¬½¨¸´Adobe Media EncoderÖеÄ3¸öÑϳÁµÄ·ì϶¡£ÕâÈý¸ö·ì϶¾ùΪԽ½ç¶ÁÈ¡µ¼ÖµÄÐÅϢй¶·ì϶ £¬±»×·×ÙΪCVE-2020-9739¡¢CVE-2020-9744ºÍCVE-2020-9745 £¬¿ÉÄܻᵼÖÂÓû§µÄÃô¸ÐÐÅϢй©¡£Adobe½¨ÒéÓû§¾¡¿ì×°ÖÃAdobe Media Encoder 14.4À´½¨¸´ÕâÈý¸ö·ì϶ £¬ÒÔ×èÖ¹ÊÔIJÀûÓÃ佨²¹µÄ·ì϶µÄ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-out-of-band-security-update-for-adobe-media-encoder/


6.ÐÂÔóÎ÷´óѧҽԺϰȾSunCrypt £¬240 GBÊý¾Ý»òÒÑй©


6.jpg


ÐÂÔóÎ÷´óѧҽԺ£¨UHNJ£©Ôâµ½SunCryptÀÕË÷Èí¼þ¹¥»÷ £¬240 GBÊý¾Ý»òÒÑй©¡£ÀÕË÷Èí¼þ×éÖ¯SunCryptÐû³Æ £¬ÆäÔÚ9Ô·ÝÀÕË÷Èí¼þ¹¥»÷ÖдÓUHNJÇÔÈ¡ÁË240 GBÊý¾Ý £¬²¢ÇÒĿǰÒѾ­Ð¹Â©ÁË1.7 GBµÄ´æµµ £¬ÆäÖÐÔ̺¬³¬¹ý48000¸öÎĵµ¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬À¨»¼ÕßÐÅÏ¢°ä²¼ÊÚȨ±í¡¢¼ÝÊ»ÅÆÕÕ¸±±¾¡¢Éç»á°²È«ºÅÂ루SSN£©¡¢µ®ÉúÈÕÆÚ£¨DOB£©ÒÔ¼°Óйض­Ê»áµÄ¼Í¼¡£ÖªÁµÈËÊ¿Åú×¢ £¬UHNJµÄÒ»ÃûÔ±¹¤ÔÚ8Ôµ×ϰȾÁËTrickBotľÂí £¬Õâ¿ÉÄܵ¼ÖÂÍøÂçÊÜË𠣬×îÖÕ»á×°ÖÃÀÕË÷Èí¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/university-hospital-new-jersey-hit-by-suncrypt-ransomware-data-leaked/