¿¨°Í˹»ùÐû²¼2020Äê¹¤ÒµÍøÂçÇå¾²ÊÓ²ìÑо¿±¨¸æ£»£»£» £»£»£»£»ÐµĶñÒâÈí¼þMrbMinerÒÑѬȾÊýǧ¸öMSSQLÊý¾Ý¿â

Ðû²¼Ê±¼ä 2020-09-17

1.¿¨°Í˹»ùÐû²¼2020Äê¹¤ÒµÍøÂçÇå¾²ÊÓ²ìÑо¿±¨¸æ


1.jpg


¿¨°Í˹»ù¶ÔÒßÇéʱ´úµÄ¹¤ÒµÍøÂçÇ徲״̬¾ÙÐÐÁËÑо¿£¬£¬ £¬²¢Ðû²¼ÁË2020Äê¹¤ÒµÍøÂçÇå¾²ÊÓ²ìÑо¿±¨¸æ¡£¡£¡£±¨¸æÏÔʾ£¬£¬ £¬Áè¼ÝÒ»°ë(53%)µÄÊÜ·ÃÕßÈϿɣ¬£¬ £¬COVID-19µ¼Ö¸ü¶àÔ±¹¤ÔڼҰ칫£¬£¬ £¬ÕâÒѳÉΪ¶ÔÐÅÏ¢Ç徲ЧÀ͵ÄÒ»ÖÖѹÁ¦²âÊÔ¡£¡£¡£ÓÉÓÚÍⲿÅþÁ¬ÊýÄ¿Öڶ࣬£¬ £¬ÏÖÔÚ¾ø´ó´ó¶¼¹«Ë¾¶¼ÔÚ¶ÔOTÍøÂçµÄÇå¾²¼¶±ð¾ÙÐа´ÆÚÆÀ¹À¡£¡£¡£Ðí¶à×éÖ¯²»µÃ²»ÖØÐÂ˼Á¿ËûÃÇÄÚÍøµÄ±£»£»£» £»£»£»£»¤ÒªÁ죬£¬ £¬Ö»ÓÐ7%µÄÊÜ·ÃÕßÌåÏÖ£¬£¬ £¬ËûÃǵÄÍøÂçÇå¾²Õ½ÂÔÔÚCOVID-19ʱ´úÏ൱ÓÐÓᣡ£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/industrial-cybersecurity-2020/37031/


2.еĶñÒâÈí¼þMrbMinerÒÑѬȾÊýǧ¸öMSSQLÊý¾Ý¿â


2.jpg


Ñо¿Ö°Ô±·¢Ã÷£¬£¬ £¬ÒÑÍùµÄ¼¸¸öÔÂÖУ¬£¬ £¬ºÚ¿Í×éÖ¯ÒÑʹÓÃеĶñÒâÈí¼þMrbMinerÈëÇÖÊýǧ¸öMicrosoft SQL Server£¨MSSQL£©²¢×°ÖÃÁ˼ÓÃܿ󹤡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýɨÃèÍøÂçÉϵÄMSSQLЧÀÍÆ÷¾ÙÐÐÈö²¥£¬£¬ £¬È»ºóͨ¹ýÖØ¸´ÊµÑéÖÖÖÖÈõÃÜÂëµÄÖÎÀíÔ±ÕÊ»§À´¾ÙÐб©Á¦¹¥»÷¡£¡£¡£Ò»µ©¹¥»÷ÕßÀÖ³ÉÈëÇÖϵͳ£¬£¬ £¬ËûÃDZã»áÏÂÔØassm.exeÎļþ£¬£¬ £¬ÒÔ½¨ÉèºóÃÅÕÊ»§¹©Î´À´»á¼û¡£¡£¡£×îºó£¬£¬ £¬Ëü½«ÅþÁ¬C2ЧÀÍÆ÷£¬£¬ £¬²¢ÏÂÔØÒ»¸öÓ¦ÓÃÒÔÍÚ¾òMonero£¨XMR£©¼ÓÃÜÇ®±Ò¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-mrbminer-malware-has-infected-thousands-of-mssql-databases/


3.Check PointÖÒÑÔÕë¶Ô½ÌÓýºÍѧÊõÁìÓòµÄDDoS¹¥»÷¼¤Ôö


3.png


ÍøÂçÇå¾²¹«Ë¾Check Point·¢Ã÷£¬£¬ £¬Õë¶Ô½ÌÓýºÍѧÊõÁìÓòµÄDDoS¹¥»÷¼¤Ôö¡£¡£¡£ÆäÖ¸³ö£¬£¬ £¬´ó´ó¶¼¹¥»÷¶¼ÊÇÕë¶ÔÃÀ¹úµÄ»ú¹¹£¬£¬ £¬ÔÚ7ÔºÍ8Ô£¬£¬ £¬Õë¶ÔѧÊõ²¿·ÖµÄ¹¥»÷ƽ¾ùÿÖÜÔöÌí30£¥£¬£¬ £¬´ÓÎåÔºÍÁùÔµÄ468´ÎÔ¾ÉýÖÁ608´Î¡£¡£¡£±ðµÄ£¬£¬ £¬¹¥»÷ÕßÔÚÕë¶ÔÃÀ¹ú¡¢Å·ÖÞºÍÑÇÖ޵ĽÌÓýºÍÑо¿²¿·Öʱ½ÓÄÉÁ˲î±ðµÄÒªÁìºÍÕ½Êõ£¬£¬ £¬×îÖÕÄ¿µÄËÆºõÒ²ÒòµØÇø¶øÒì¡£¡£¡£Õë¶ÔÅ·Ö޵Ĺ¥»÷ΪÐÅϢй¶£¬£¬ £¬´ÓÎå¡¢ÁùÔµÄ638´ÎÔ¾ÉýÖÁÆß¡¢°ËÔµÄ793´Î£¬£¬ £¬ÔöÌíÁË24£¥¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/surge-in-ddos-attacks-targeting-education-and-academic-sector/


4.Ñо¿Ö°Ô±·¢Ã÷Win10ÖеÄFingerÏÂÁî¿É±»ÓÃÀ´ÇÔÈ¡Îļþ


4.png


Ñо¿Ô±John Page·¢Ã÷£¬£¬ £¬Microsoft Windows TCPIP FingerÏÂÁ¿ÉÒԳ䵱ÎļþÏÂÔØÆ÷ºÍmakeshiftÏÂÁîÓë¿ØÖÆ£¨C3£©Ð§ÀÍÆ÷£¬£¬ £¬ÒÔÓÃÓÚ·¢ËÍÏÂÁîºÍÇÔÈ¡Êý¾Ý¡£¡£¡£Ïà¹ØÑо¿Ö°Ô±³Æ£¬£¬ £¬C2ÏÂÁî¿ÉÒÔαװ³Éfinger queriesÀ´ÇÔÈ¡Êý¾Ý£¬£¬ £¬¶ø²»±»Windows Defender¼ì²âµ½ÕâÖÖÒì³£ÐÐΪ¡£¡£¡£ÕâÖÖÒªÁ콫ÔÊÐíͨ¹ý·À»ðǽ¹æÔò£¬£¬ £¬²¢Ê¹Óò»ÊÜÏÞÖÆµÄHTTP¶Ë¿ÚÓëЧÀÍÆ÷ͨѶ¡£¡£¡£Í¨¹ýÕâÖÖÒªÁ죬£¬ £¬PortproxyÅÌÎʱ»×ª´ïµ½ÍâµØIP£¬£¬ £¬È»ºóת·¢µ½Ö¸¶¨µÄC2Ö÷»ú¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-10-finger-command-can-be-abused-to-download-or-steal-files/


5.AdobeÐû²¼´øÍâ¸üУ¬£¬ £¬ÐÞ¸´Media EncoderÖÐ3¸öÎó²î


5.png


AdobeÐû²¼´øÍâ¸üУ¬£¬ £¬ÐÞ¸´Adobe Media EncoderÖеÄ3¸öÑÏÖØµÄÎó²î¡£¡£¡£ÕâÈý¸öÎó²î¾ùΪԽ½ç¶ÁÈ¡µ¼ÖµÄÐÅϢй¶Îó²î£¬£¬ £¬±»×·×ÙΪCVE-2020-9739¡¢CVE-2020-9744ºÍCVE-2020-9745£¬£¬ £¬¿ÉÄܻᵼÖÂÓû§µÄÃô¸ÐÐÅÏ¢×ß©¡£¡£¡£Adobe½¨ÒéÓû§¾¡¿ì×°ÖÃAdobe Media Encoder 14.4À´ÐÞ¸´ÕâÈý¸öÎó²î£¬£¬ £¬ÒÔ×èÖ¹ÊÔͼʹÓÃδÐÞ²¹µÄÎó²îµÄ¹¥»÷¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-out-of-band-security-update-for-adobe-media-encoder/


6.ÐÂÔóÎ÷´óѧҽԺѬȾSunCrypt£¬£¬ £¬240 GBÊý¾Ý»òÒÑ×ß©


6.jpg


ÐÂÔóÎ÷´óѧҽԺ£¨UHNJ£©Ôâµ½SunCryptÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬240 GBÊý¾Ý»òÒÑ×ß©¡£¡£¡£ÀÕË÷Èí¼þ×éÖ¯SunCryptÉù³Æ£¬£¬ £¬ÆäÔÚ9Ô·ÝÀÕË÷Èí¼þ¹¥»÷ÖдÓUHNJÇÔÈ¡ÁË240 GBÊý¾Ý£¬£¬ £¬²¢ÇÒÏÖÔÚÒѾ­×ß©ÁË1.7 GBµÄ´æµµ£¬£¬ £¬ÆäÖаüÀ¨Áè¼Ý48000¸öÎĵµ¡£¡£¡£´Ë´Îй¶µÄÊý¾Ý°üÀ¨À¨»¼ÕßÐÅÏ¢Ðû²¼ÊÚȨ±í¡¢¼ÝʻִÕÕ¸±±¾¡¢Éç»áÇå¾²ºÅÂ루SSN£©¡¢³öÉúÈÕÆÚ£¨DOB£©ÒÔ¼°Óйض­Ê»áµÄ¼Í¼¡£¡£¡£ÖªÇéÈËÊ¿Åú×¢£¬£¬ £¬UHNJµÄÒ»ÃûÔ±¹¤ÔÚ8ÔÂβѬȾÁËTrickBotľÂí£¬£¬ £¬Õâ¿ÉÄܵ¼ÖÂÍøÂçÊÜË𣬣¬ £¬×îÖÕ»á×°ÖÃÀÕË÷Èí¼þ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/university-hospital-new-jersey-hit-by-suncrypt-ransomware-data-leaked/