ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ15ÖÜ

°ä²¼¹¦·ò 2020-04-14

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ06ÈÕÖÁ12ÈÕ¹²ÊÕ¼°²È«·ì϶55¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇBroadcom Advanced Secure Gateway/ProxySGδÊÚȨ½Ó¼û·ì϶; Linux kernel drivers/input/input.cÔ½½çд·ì϶£»OpsRamp GatewayĬÈϱàÂë·ì϶£»Synergy Systems & Solutions HUSKY RTU 6049-E70 telnetÑéÖ¤ÈÆ¹ý·ì϶£»SolarWinds Dameware ECDH key»¥»»»º³åÇøÒç¶Âí½Å¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇFireEye°ä²¼×î½üÊýÄê0dayÀûÓÃÇé¿öµÄ·ÖÎö»ã±¨£»FIN6¼°ÔËÓªTrickBotµÄÍÅ»ï½áºÏµÄ¹¥»÷»î¶¯£»Äá²´¶ûISP VianetÔâºÚ¿ÍÈëÇÖ £¬170Íò¿Í»§Êý¾Ýй¶£»¶íÂÞ˹µçÐŹ«Ë¾Rostelecom½Ù³Ö¶à¸öÆóÒµµÄ»¥ÁªÍøÁ÷Á¿£»Î¢Èí°ä²¼Emotet¹¥»÷Fabrikam¹«Ë¾µÄ°¸Àý×êÑл㱨¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖС£


>³ÁÒª°²È«·ì϶Áбí



1. Broadcom Advanced Secure Gateway/ProxySGδÊÚȨ½Ó¼û·ì϶


Broadcom Advanced Secure Gateway/ProxySG½ÚÔį̀´æÔڻỰ½Ù³ÖÎÊÌâ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉδÊÚȨ½Ó¼ûÖÎÀí½Ó¿Ú¡£

https://support.broadcom.com/security-advisory/security-advisory-detail.html?notificationId=SYMSA1752


2. Linux kernel drivers/input/input.cÔ½½çд·ì϶


Linux kernel drivers/input/input.c´æÔÚÔ½½çд·ì϶ £¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Í¨¹ýÌØÖúµÄkeycode±í´¥·¢ £¬ÌáÉýȨÏÞ¡£

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cb222aed03d798fc074be55e59d9a112338ee784


3. OpsRamp GatewayĬÈϱàÂë·ì϶


OpsRamp Gateway´æÔÚÃÜÂëΪpassword 9vt@f3VtµÄÖÎÀíÔ¹ØË»§ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉδÊÚȨ½Ó¼ûϵͳ¡£

https://www.criticalstart.com/hard-coded-administrator-password-discovered-in-opsramp/


4. Synergy Systems & Solutions HUSKY RTU 6049-E70 telnetÑéÖ¤ÈÆ¹ý·ì϶


Synergy Systems £¦ Solutions HUSKY RTU 6049-E70 telnet·þÎñ²»±ØÒªÑéÖ¤·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉδÊÚȨ½Ó¼û¡£

https://www.us-cert.gov/ics/advisories/icsa-20-042-01


5. SolarWinds Dameware ECDH key»¥»»»º³åÇøÒç¶Âí½Å


SolarWinds Dameware ECDH key»¥»»´¦ÖÃ'SigPubkeyLen'´æÔÚ»º³åÇøÒç¶Âí½Å £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»ò¿ÉÖ´ÐÐËÁÒâ´úÂë¡£

https://www.tenable.com/security/research/tra-2020-19



> ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢FireEye°ä²¼×î½üÊýÄê0dayÀûÓÃÇé¿öµÄ·ÖÎö»ã±¨


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



FireEye MandiantÍþвµý±¨ÍŶӼͼµÄ2019Äê0dayÀûÓÃÁ¿±ÈǰÈýÄêÖеÄÈκÎÒ»Äê¶¼Òª¶à¡£Ö»¹Ü²¢²»Äܽ«Ã¿Ò»¸ö0dayÀûÓö¼¹éÒòµ½Ìض¨µÄ¹¥»÷Õß £¬µ«×êÑÐÈËÔ±°ÑÎȵ½Ô½À´Ô½¶àµÄ¹¥»÷Õß»ñµÃÁË0dayÀûÓõÄÄÜÁ¦¡£FireEyeÒÔΪ £¬ÕâÖÖ¼¤ÔöÖÁÉÙ²¿ÃÅÊÇÓÉÓÚ²»ÐÝ·¢Õ¹µÄ¹ÍÓ¶ºÚ¿ÍÐÐÒµ·¢Õ¹ÆðÀ´µÄ £¬ÕâЩÐÐÒµ¿ª·¢0dayÀûÓù¤¾ß²¢½«ÆäÏúÊÛ¸øÊÀ½ç¸÷µØµÄµý±¨»ú¹¹¡£¹¥»÷ÕßÓë0dayÀûÓÃÖ®¼äµÄ×î´ó×è°­²»ÊǼ¼Êõ £¬¶øÊÇÏֽ𡣾ßÌåÀ´Ëµ £¬FireEyeÖ¸³öNSO Group¡¢Gamma GroupºÍHacking TeamÊÇÕâÀà³Ð°üÉÌ £¬ÕâЩ³Ð°üÉÌʹһÅúеĹú¶È/µØÓò¿ÉÄܲɰì0dayÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2020/04/zero-day-exploitation-demonstrates-access-to-money-not-skill.html


2¡¢FIN6¼°ÔËÓªTrickBotµÄÍÅ»ï½áºÏµÄ¹¥»÷»î¶¯


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


IBM X-Force×êÑÐÈËÔ±°µÊ¾ £¬ÔÚ×î½üµÄÍøÂç¹¥»÷Öз¢ÏÖÁËFIN6µÄºÛ¼£ £¬ÕâЩ¹¥»÷»î¶¯×î³õÀûÓÃTrickBotľÂíϰȾÊܺ¦Õß £¬¶øºó×îÖÕÏÂÔØÁËAnchorºóÃÅ¡£×êÑÐÈËÔ±³ÆÕâÁ½¸ö·¸×ï×éÖ¯-TrickBotµÄÔËÓªÍÅ»ïÒÔ¼°FIN6-ÒѾ­½øÐкÏ×÷ £¬ÕâÊÇÍøÂç·¸×OÌåÏÖÓкÏ×÷Ç÷ÏòÖеġ°ÐµÄΣÏÕתÕÛ¡±¡£AnchorÖÁÉÙÄܹ»×·Òäµ½2018Äê £¬ËƺõÊÇÓÉTrickBotµÄÔËÓªÍÅ»ï±àдµÄ¡°¡°¶àºÏÒ»¹¥»÷¿ò¼Ü¡± £¬ËüÓɸ÷Àà×ÓÄ£¿é×é³É £¬Äܹ»Ô®ÊÖ¹¥»÷ÕßÔÚÍøÂçÉϺáÏò´«²¼£¨ÀýÈç×°ÖúóÃÅ£©¡£Í¬Ê±TrickBotµÄÁíÒ»¸ö¹¤¾ßPowerTrickÖØÒªÓÃÓÚÔÚÊÜϰȾµÄ¸ß¼ÛÖµÖ¸±ê£¨ÀýÈç½ðÈÚ»ú¹¹£©ÄÚ²¿½øÐÐÒþÉí¡¢ÓÆ¾ÃÐԺͿúËÅ¡£IBM X-ForceÖ¸³öFIN6²Î¼ÓÁËÀûÓÃAnchorºÍPowerTrickµÄ¹¥»÷ £¬Æä´æÔÚµÄ×î´óÖ¸±êÊǹ¥»÷ÖÐʹÓõÄ×°ÔØ·¨Ê½£¨Terraloader£©ºÍºóÃÅ£¨More_eggs£©¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/fin6-and-trickbot-combine-forces-in-anchor-attacks/154508/


3¡¢Äá²´¶ûISP VianetÔâºÚ¿ÍÈëÇÖ £¬170Íò¿Í»§Êý¾Ýй¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Äá²´¶û»¥ÁªÍø·þÎñÌṩÉÌVianet CommunicationsÈ·ÈÏÆäÐÅϢϵͳÔâºÚ¿ÍÈëÇÖ £¬¿Í»§µÄÓ×ÎÒÐÅÏ¢±»ÇÔ¡£ºÚ¿ÍÔÚTwitterÕÊ»§ÉÏÐû³ÆÇÔÈ¡ÁË170ÍòVianet¿Í»§µÄÊý¾Ý £¬Ô̺¬ËûÃǵÄÐÕÃû¡¢ÊÖ»úºÅÂë¡¢µØÖ·ºÍµç×ÓÓʼþµØÖ·¡£ºÚ¿ÍµÄÍÆÎÄÖл¹Ô̺¬ÍйÜÔÚÑó´ÐÍøÂçÉϵÄй¶Êý¾ÝÁ´½Ó¡£VianetÔÚÆä¹Ù·½ÉêÃ÷ÖÐÈ·ÈÏÁËÕâÒ»ÊÂÎñ £¬²¢°µÊ¾ÒѾ­È·¶¨ÁËй¶µÄ±¾Ô­ºÍ²ÉÈ¡Êʵ±µÄ´ëÊ©À´¼ÓÇ¿°²È«ÐÔ¡£


Ô­ÎÄÁ´½Ó£º

https://www.nepalitelecom.com/2020/04/vianet-customer-data-leaks-hack.html


4¡¢¶íÂÞ˹µçÐŹ«Ë¾Rostelecom½Ù³Ö¶à¸öÆóÒµµÄ»¥ÁªÍøÁ÷Á¿


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


4ÔÂ1ÈÕ¶íÂÞ˹µçÐŹ«Ë¾Rostelecom½Ù³ÖÁ˹ȸèµÈ¹«Ë¾µÄ»¥ÁªÍøÁ÷Á¿ £¬¸ÃÊÂÎñÓ°ÏìÁËÊÀ½çÉÏ×î´óµÄ200¶à¸öCDNÍøÂç¼°ÔÆÍйܷþÎñÉÌ £¬³ÖÐøÁËԼĪ1¸öÓ×ʱ¡£ÊÜÓ°ÏìµÄÆóÒµÔ̺¬¹È¸è¡¢ÑÇÂíÑ·¡¢Facebook¡¢Akamai¡¢Cloudflare¡¢GoDaddy¡¢Digital Ocean¡¢Joyent¡¢LeaseWeb¡¢HetznerºÍLinodeµÈ³ÛÃû¹«Ë¾¡£ÕâÊÇÒ»´ÎµäÐ͵ÄBGP½Ù³ÖÊÂÎñ £¬¸ÃÊÂÎñµÄÔ­Òò¿ÉÄÜÊÇRostelecomµÄÄÚ²¿Á÷Á¿½¨¸ÄϵͳÃýÎ󵨽«²»ÕýÈ·µÄBGP·Óɶ³öÔÚ¹«ÍøÉÏ £¬²¢ÇÒ±»ÉÏÓι©¸øÉ̹㲥Ôì³ÉµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/russian-telco-hijacks-internet-traffic-for-google-aws-cloudflare-and-others/


5¡¢Î¢Èí°ä²¼Emotet¹¥»÷Fabrikam¹«Ë¾µÄ°¸Àý×êÑл㱨


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


΢ÈíÔÚ¼ì²âºÍÏìÓ¦Ó××飨DART£©°¸Àý»ã±¨002ÖзÖÏíÁËFabrikam¹«Ë¾Ôâ·êEmotet¹¥»÷µÄ¾ßÌåÐÅÏ¢¡£¸Ã¹¥»÷ʼÓÚÍøÂç´¹µöÓʼþ £¬µ±ÄÚ²¿Ô±¹¤½Ó¼ûÁË´¹µöÐÅÏ¢ºó £¬EmotetϰȾÁËÆäϵͳ²¢ºáÏòϰȾÁËÍ³Ò»ÍøÂçÖÐµÄÆäËüϵͳ¡£¸Ã²¡¶¾Ô¤·ÀÁËͨ¹ýºÅÁîºÍ½ÚÔì·þÎñÆ÷£¨C2£©½øÐж¨ÆÚ¸üжø±»·À²¡¶¾½â¾ö¹æ»®¼ì²âµ½µÄÇé¿ö £¬²¢ÇÒͨ¹ýʹWindowsÉ豸ÉϵÄCPUʹÓÃÂÊ´ïµ½¹ÄºÍÀ´ÖÕ³¡Ö÷Ìâ·þÎñ £¬µ¼Ö¸Ã×éÖ¯µÄ¸ù»ù·þÎñºÍÍøÂçÖжÏÁ˽«½üÒ»ÖܵŦ·ò¡£CPUʹÓÃÂÊÒ»Ïò¹ÄºÍʹµÃÍÆËã»ú¹ýÈÈ £¬µ¼ÖÂÄÚ²¿ÏµÍ³¿¨ËÀ¡¢³ÁÆôºÍÍøÂçÏνӽµÂä¡£¸Ã¶ñÒâÈí¼þͨ¹ýÇÔÈ¡ÖÎÀíÔ¹ØÊ»§Í´´¦½øÐкáÏòÒÆ¶¯ £¬ÔÚ×î³õϰȾºóµÄ8ÌìÖ®ÄÚ £¬FabrikamµÄÕû¸öÍøÂç¾Í±»¹Ø¹ØÁË¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/wp-content/uploads/2020/04/Case-study_Full-Operational-Shutdown.pdf