Unit 42Åû¶Õë¶ÔÃÀ¹ú¹ú·À³Ð°üÉ̵ĺóÃÅSockDetourµÄϸ½Ú

Ðû²¼Ê±¼ä 2022-03-01

Unit 42Åû¶Õë¶ÔÃÀ¹ú¹ú·À³Ð°üÉ̵ĺóÃÅSockDetourµÄϸ½Ú


2ÔÂ24ÈÕ£¬Unit 42Ñо¿ÈËÔ±·¢ÎÄ³ÆÆäÔÚ¸ú×ÙAPT»î¶¯TiltedTempleʱ·¢ÏÖÁËкóÃÅSockDetour ¡£¸ÃºóÃÅÖÁÉÙ×Ô2019Äê7Ô¾ÍÒѾ­´æÔÚ£¬Ö÷Òª±»ÓÃ×÷±¸·ÝºóÃÅÒÔ·ÀÖ÷ºóÃű»É¾ ¡£ÒòÆäÔÚÄ¿±êWindows·þÎñÆ÷ÉÏÎÞÎļþÇÒÎÞÌ×½Ó×ÖµØÔËÐУ¬ËùÒÔºÜÄѱ»¼ì²âµ½ ¡£¾ÝϤ£¬´Ë´Î»î¶¯Ö÷ÒªÃé×¼ÃÀ¹úµÄ¹ú·À³Ð°üÉÌ£¬Ä¿Ç°ÖÁÉÙÓÐ4¼Ò´ËÀ๫˾Ôâµ½¹¥»÷ ¡£ËäÈ»ÉÐ佫ºóÃÅSockDetour¹éÒòÓÚÈκκڿÍ×éÖ¯£¬µ«TiltedTemple»î¶¯ÓëAPT27ÓйØ ¡£


https://unit42.paloaltonetworks.com/sockdetour/


Ӣΰ´ï³ÆÆäÕýÔÚÊӲ쵼Ö²¿ÃÅϵͳÖжÏ2ÌìµÄ¹¥»÷ʼþ


¾ÝýÌå2ÔÂ25ÈÕ±¨µÀ£¬GPUÖÆÔìÉÌӢΰ´ï£¨Nvidia£©ÕýÔÚÊӲ쵼Ö²¿ÃÅϵͳÖжÏ2ÌìµÄ¹¥»÷ʼþ ¡£´Ë´Î¹¥»÷Ó°ÏìÁ˹«Ë¾µÄ¿ª·¢ÈËÔ±¹¤¾ßºÍµç×ÓÓʼþϵͳ£¬µ«ÒµÎñºÍÉÌÒµ»î¶¯²¢Î´Êܵ½Ó°Ïì ¡£Éв»Çå³þÊÇ·ñÓÐÒµÎñ»ò¿Í»§µÄÐÅÏ¢±»µÁ£¬¸Ã¹«Ë¾Ä¿Ç°ÈÔÔÚÆÀ¹ÀʼþµÄÐÔÖʺͷ¶Î§ ¡£2ÔÂ26ÈÕ£¬Lapsus$ÍÅ»ïÉù³ÆËûÃÇÒÑÈëÇÖNvidiaµÄÍøÂç²¢ÇÔÈ¡ÁË1TBµÄÊý¾Ý£¬»¹¹ûÈ»ÁËNvidiaËùÓÐÔ±¹¤µÄÃÜÂë ¡£


https://www.bleepingcomputer.com/news/security/gpu-giant-nvidia-is-investigating-a-potential-cyberattack/


NHS¶Ø´ÙÓû§ÐÞ¸´Okta¿Í»§¶ËÖеÄRCE CVE-2022-24295


Ó¢¹úNHSÊý×Ö»ú¹¹ÔÚ2ÔÂ24ÈÕÐû²¼ÁËͨ¸æ£¬¶Ø´ÙÓû§¾¡¿ìÐÞ¸´Okta Advanced Server Access Éí·ÝÑéÖ¤¹ÜÀíÆ½Ì¨ÖеÄRCE©¶´ ¡£¸Ã©¶´×·×ÙΪCVE-2022-24295£¬¿ÉÓÃÀ´Í¨¹ýÌØÖÆURLÖ´ÐÐÃüÁî×¢È룬ÀÖ³ÉÀûÓÿɵ¼ÖÂÍêÈ«¿ØÖÆÏµÍ³¡¢Ö´Ðо²Ä¬µÄÊý¾Ýй¶¡¢ºáÏòÒÆ¶¯ÒÔ¼°¶Ô¹«Ë¾ÍøÂçµÄ³õʼ·ÃÎÊ ¡£NHS»¹ÌáÐѹÜÀíÔ±£¬OktaµÄ¼¸¸ö²úÎïÒ²Êܵ½Log4Shell©¶´µÄÓ°Ïì ¡£


https://www.bleepingcomputer.com/news/security/nhs-urges-orgs-to-apply-security-update-for-okta-client-rce-bug/


CISAÐû²¼¹ØÓÚÒÁÀÊMuddyWaterµÄ¼äµý»î¶¯µÄͨ¸æ


2ÔÂ24ÈÕ£¬CISA¡¢FBI¡¢CNMF¡¢NCSC-UKºÍNSAÐû²¼ÁËÒ»·ÝÁªºÏÍøÂçÄþ¾²×Éѯ ¡£¸Ã×ÉѯÅû¶ÁËÒÁÀÊAPT×éÖ¯MuddyWatterÔÚÕë¶ÔÈ«ÇòÒªº¦»ù´¡ÉèÊ©µÄ¹¥»÷ÖÐʹÓõÄжñÒâÈí¼þµÄÐÅÏ¢ ¡£¸Ã»î¶¯Õë¶ÔÑÇÖÞ¡¢·ÇÖÞ¡¢Å·Ö޺ͱ±ÃÀµÄµçÐÅ¡¢¹ú·À¡¢Ê¯ÓÍ¡¢ÌìÈ»ÆøÐÐÒµºÍµØ·½Õþ¸®×éÖ¯£¬Ê¹ÓÃÁËÖîÈçPowGoop¡¢Canopy/Starwhale¡¢Mori¡¢POWERSTATSµÈ¶àÖÖ¶ñÒâÈí¼þ ¡£Í¨¸æ»¹Öصã½éÉÜÁËPythonºóÃÅSmall SieveºÍÓÃÓÚ¼ÓÃÜC2ͨÐÅͨµÀµÄÒ»¸öPowerShellºóÃÅ ¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/02/24/iranian-government-sponsored-muddywater-actors-conducting


Check PointÐû²¼Ð¶ñÒâÈí¼þElectron BotµÄ·ÖÎö³ÂËß


2ÔÂ24ÈÕ£¬Check Point Research(CPR)Åû¶ÁËжñÒâÈí¼þElectron BotµÄ¼¼Êõϸ½Ú ¡£¸Ã»î¶¯»î¶¯Ê¼ÓÚ2018Äêµ×£¬Î±Ôì³É2Temple RunºÍSubway SurferµÈÈÈÃÅÓÎÏ·£¬Í¨¹ýMicrosoft Store½øÐÐÁ÷´«£¬ÏÖÔÚÒÑѬȾÁËÈðµä¡¢±£¼ÓÀûÑÇ¡¢¶íÂÞ˹¡¢°ÙĽ´óºÍÎ÷°àÑÀµÄ5000¶ą̀¼ÆËã»ú ¡£Electron BotÊÇÒ»ÖÖÄ£¿é»¯µÄ SEO Öж¾¶ñÒâÈí¼þ£¬Ö÷ÒªÓÃÓÚÉ罻ýÌåÍÆ¹ãºÍµã»÷ÆÛÕ©»î¶¯ ¡£


https://research.checkpoint.com/2022/new-malware-capable-of-controlling-social-media-accounts-infects-5000-machines-and-is-actively-being-distributed-via-gaming-applications-on-microsofts-official-store/


CiscoÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Æä¶à¸ö²úÎïÖеÄ©¶´


2ÔÂ23ÈÕ£¬CiscoÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Á˶à¿î²úÎïÖеÄ©¶´ ¡£ÆäÖнÏΪÑÏÖØµÄÊÇ˼¿ÆNX-OSÈí¼þNX-APIÃüÁî×¢Èë©¶´£¨CVE-2022-20650£©£¬Ô´ÓÚ¶ÔÓû§ÌṩµÄÊý¾Ýȱ·¦×ã¹»µÄÊäÈëÑéÖ¤£»ÒÔ¼°Cisco Fabric Services Over IP (CFSoIP)Öеľܾø·þÎñ©¶´£¨CVE-2022-20624£©ºÍNexus 9000ϵÁн»»»»úË«Ïòת·¢¼ì²â(BFD)Á÷Á¿¹¦Ð§Öеľܾø·þÎñ©¶´£¨CVE-2022-20623£© ¡£


https://thehackernews.com/2022/02/new-flaws-discovered-in-ciscos-network.html


Äþ¾²¹¤¾ß


Win Brute Logon


ÔÚûÓÐÈκÎȨÏÞµÄÇé¿öÏÂÆÆ½âÈκΠMicrosoft Windows Óû§ÃÜÂ루°üÂ޷ÿÍÕÊ»§£© ¡£


https://github.com/DarkCoderSc/win-brute-logon


PHP Malware Finder


¾¡ÆäËùÄܵؼì²âÄ£ºýµÄ´úÂ룬ÒÔ¼°ÔÚ¶ñÒâÈí¼þºÍwebshellÖо­³£Ê¹ÓõÄPHPº¯ÊýÎļþ ¡£


https://github.com/jvoisin/php-malware-finder


LDAP Password Hunter


Ëü°ü×°ÁË getTGT.py (Impacket) ºÍ ldapsearch µÄ¹¦Ð§£¬ÒÔ±ã²éÕÒ´æ´¢ÔÚ LDAP Êý¾Ý¿âÖеÄÃÜÂë ¡£


https://github.com/oldboy21/LDAP-Password-Hunter


Collabfiltrator


ÊÇÒ»ÖÖͨ¹ý Burp Collaborator ͨ¹ý DNS ÇÔȡԶ³Ì´úÂëÖ´ÐÐÊä³öµÄ¹¤¾ß


https://packetstormsecurity.com/files/166062/Collabfiltrator-2.1.zip


ostorlab


Ò»¸öÄþ¾²É¨ÃèÆ½Ì¨£¬Äܹ»ÒÔ¼òµ¥¡¢¿ÉÀ©Õ¹ºÍÂþÑÜʽµÄ·½Ê½ÔËÐÐÉæ¼°¶à¸ö¹¤¾ßµÄÅÓ´óÄþ¾²É¨ÃèÈÎÎñ ¡£


https://docs.ostorlab.co/



Äþ¾²·ÖÎö


΢Èí¾¯¸æÐ嵀 Windows 11 ÖØÖôíÎó


https://news.softpedia.com/news/microsoft-warns-of-new-windows-11-reset-bug-534943.shtml


Ãâ·ÑµÄ Android Ó¦ÓÿÉÈüì²â Apple AirTag ¸ú×Ù


https://www.bleepingcomputer.com/news/security/free-android-app-lets-users-detect-apple-airtag-tracking/


Android É쵀 Visual Voice Mail ¿ÉÄÜÈÝÒ×±»ÇÔÌý


https://www.bleepingcomputer.com/news/security/visual-voice-mail-on-android-may-be-vulnerable-to-eavesdropping/


΢Èí£º1 Ô Windows Server ¸üе¼Ö Netlogon ÎÊÌâ


https://www.bleepingcomputer.com/news/microsoft/microsoft-january-windows-server-updates-cause-netlogon-issues/


ÍøÂçºÚ¿ÍרעÓÚÔÚÃÀ¹úÏúÊ۸߼ÛֵĿ±ê


https://www.bleepingcomputer.com/news/security/network-hackers-focus-on-selling-high-value-targets-in-the-us/