NCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ£»£»£»ÐµÄAndroidľÂíBanker.BRʹÓÃÁýÕÖ¹¥»÷Ãé×¼ÒøÐÐÖ÷¹Ë

Ðû²¼Ê±¼ä 2020-04-22

1.CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ ¡£¡£¡£¡£¸Ã±¨¸æ×¤×ãÓÚCNCERTÍøÂçÇå¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù±¨¸æ£¬£¬£¬£¬ £¬£¬£¬Éæ¼°2019Äêµä·¶ÍøÂçÇå¾²ÊÂÎñ¡¢ÍøÂçÇå¾²ÐÂÇ÷ÊÆ¼°Ò»Ñùƽ³£ÍøÂçÇå¾²ÊÂÎñÓ¦¼±´¦Öóͷ£Êµ¼ùµÈÄÚÈÝ ¡£¡£¡£¡£±¨¸æÖ÷Òª°üÀ¨Ëĸö²¿·Ö£¬£¬£¬£¬ £¬£¬£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲״̬£¬£¬£¬£¬ £¬£¬£¬¶þÊÇÕ¹Íû2020ÄêÍøÂçÇå¾²ÈÈÃÅ£¬£¬£¬£¬ £¬£¬£¬ÈýÊÇÁ¬ÏµÍøÂçÇå¾²Ì¬ÊÆÆÊÎöÌá³ö¶Ô²ß½¨Ò飬£¬£¬£¬ £¬£¬£¬ËÄÊÇÊáÀíÍøÂçÇå¾²¼à²âÊý¾Ý ¡£¡£¡£¡£¸Ã±¨¸æ¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂçÇå¾²ÐÎÊÆ£¬£¬£¬£¬ £¬£¬£¬Ìá¸ßÍøÂçÇå¾²Òâʶ£¬£¬£¬£¬ £¬£¬£¬×öºÃÍøÂçÇå¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm


2.Winnti groupÕë¶ÔµÂ¹ú»¯¹¤¹«Ë¾¹¥»÷Ñù±¾µÄÆÊÎö±¨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


1Ô·ÝQuoIntelligence£¨QuoINT£©¼ì²âµ½Ò»¸öеÄWinntiÑù±¾²¢¶ÔÆä¾ÙÐÐÁËÆðÔ´µÄÆÊÎö ¡£¡£¡£¡£ÆÊÎö·¢Ã÷£¬£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÄÜÊÇÔÚ2015Äê±»¿ª·¢³öÀ´µÄ ¡£¡£¡£¡£¸ÃÑù±¾±»ÓÃÓÚ¹¥»÷Ò»¼ÒµÂ¹ú»¯¹¤¹«Ë¾£¬£¬£¬£¬ £¬£¬£¬ÏÖÔÚÉв»ÇåÎú¸Ã¹«Ë¾µÄÏêϸÃû³Æ ¡£¡£¡£¡£¸ÃÑù±¾½ÓÄÉÁËеÄC2ÊÖÒÕ£¬£¬£¬£¬ £¬£¬£¬ÒÀÀµÓÚͨ¹ýiodineÔ´´úÂëʵÏÖµÄDNSËíµÀ¾ÙÐÐͨѶ ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÒ»¸öÒÔǰδ֪µÄ±»µÁÊý×ÖÖ¤Ê飬£¬£¬£¬ £¬£¬£¬¸ÃÖ¤ÊéÖ÷ÒªÓÃÀ´¶ÔWinntiÏà¹ØµÄÇý¶¯³ÌÐò¾ÙÐÐÊý×ÖÊðÃû£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒÓÃÓÚ¹¥»÷º«¹úÓÎÏ·¹«Ë¾Gravity ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://quointelligence.eu/2020/04/winnti-group-insights-from-the-past/


3.½©Ê¬ÍøÂçMootbotʹÓÃ0day¹¥»÷9¿î¹âÏË·ÓÉÆ÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷×Ô2ÔÂÏÂÑ®Æð£¬£¬£¬£¬ £¬£¬£¬½©Ê¬ÍøÂçMootbot±ã×îÏÈʹÓÃ0day¹¥»÷9¿î¼ÒÓü°ÉÌÓùâÏË·ÓÉÆ÷£¨°üÀ¨Netlink GPON·ÓÉÆ÷£© ¡£¡£¡£¡£MoobotÊÇ»ùÓÚMiraiµÄн©Ê¬ÍøÂ磬£¬£¬£¬ £¬£¬£¬ÆäÄ¿µÄÊÇÎïÁªÍø£¨IoT£©×°±¸ ¡£¡£¡£¡£ÓÉÓÚ´ó´ó¶¼¹©Ó¦É̺ܿÉÄÜÊǽÓÄÉÁËͳһԭʼ¹©Ó¦É̵ÄOEM²úÆ·£¬£¬£¬£¬ £¬£¬£¬Òò´ËÕâЩ·ÓÉÆ÷ÊÜͳһ0dayÓ°Ïì ¡£¡£¡£¡£¸ÃÎó²îΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬ £¬£¬£¬ÆäPoCÒѾ­Ðû²¼£¬£¬£¬£¬ £¬£¬£¬µ¥¶ÀʹÓøÃÎó²î²»»áÔì³ÉΣº¦£¬£¬£¬£¬ £¬£¬£¬Ö»ÓÐÓëÁíÒ»¸öÎó²îÒ»ÆðʹÓòŻªÊµÏÖ¹¥»÷ ¡£¡£¡£¡£Ñо¿Ö°Ô±Ã»ÓÐÅû¶µÚ¶þ¸öÎó²îµÄÏêϸÐÅÏ¢ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/mootbot-fiber-routers-zero-days/154962/


4.ProofpointÖÒÑÔʹÓÃÊÓÆµ¾Û»á¹«Ë¾µÄ´¹ÂÚ¹¥»÷³ÊÔöÌíÇ÷ÊÆ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ProofpointÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬ £¬£¬£¬ÒÔÊÓÆµ¾Û»á¹«Ë¾ÎªÖ÷ÌâµÄÍøÂç´¹ÂÚ¹¥»÷ÊýÄ¿³ÊÔöÌíÇ÷ÊÆ£¬£¬£¬£¬ £¬£¬£¬ÕâЩ¹¥»÷Ö¼ÔÚÇÔÈ¡Óû§µÇ¼ƾ֤ºÍÈö²¥¶ñÒâÈí¼þ ¡£¡£¡£¡£ProofpointÖÒÑԳƣ¬£¬£¬£¬ £¬£¬£¬ºÚ¿Í²»»áÖ±½Ó¹¥»÷ÕâЩÊÓÆµ¾Û»áÈí¼þ£¬£¬£¬£¬ £¬£¬£¬¿ÉÊÇ»áÒÔÊÓÆµ¾Û»á¹«Ë¾µÄÃû³ÆÎªÓÕ¶üÇÔÈ¡Óû§ÕÊ»§Æ¾Ö¤ºÍÈö²¥¶ñÒâÈí¼þ ¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷µÄ´¹ÂÚ³¡¾°°üÀ¨£ºÎ±ÔìCisco WebExµÄÖÒÑÔÓʼþÀ´ÇÔÈ¡ÃÀ¹úÓû§µÄÕË»§ÐÅÏ¢£»£»£»Ã°³äZoom AccountÇÔÈ¡ÃÀ¹úÄÜÔ´¡¢ÖÆÔìºÍÉÌÒµµÈÐÐÒµµÄÓû§Æ¾Ö¤£»£»£»ÒÔ"zoom call"ΪÖ÷ÌâÈö²¥ServLoaderºÍNetSupport RATµÈ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.proofpoint.com/us/threat-insight/post/remote-video-conferencing-themes-credential-theft-and-malware-threats


5.FoxitÐÞ¸´PDF Reader¼°PhantomPDFÖеĶà¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


FoxitÐÞ¸´ÁËWindows°æ±¾µÄFoxit ReaderºÍFoxit PhantomPDFÖеÄ20¸öCVEÎó²î ¡£¡£¡£¡£Ê×ÏÈ£¬£¬£¬£¬ £¬£¬£¬FoxitÔÚPDF Reader 9.7.2°æ±¾ÖÐÐÞ¸´Á˶à¸öRCEÎó²î£¬£¬£¬£¬ £¬£¬£¬°üÀ¨XFAÄ£°å´¦Öóͷ£Àú³ÌÖеÄRCEÎó²î£¨CVE-2020-10899¡¢ CVE-2020-10907£©£¬£¬£¬£¬ £¬£¬£¬AcroFormsÖеÄRCEÎó²î£¨CVE-2020-10900£©ÒÔ¼°resetFormÖеÄRCEÎó²î£¨CVE-2020-10906£© ¡£¡£¡£¡£¹ØÓÚPhantomPDF£¬£¬£¬£¬ £¬£¬£¬´Ë´Î¸üÐÂÐÞ¸´ÁËAPIͨѶÖеÄÁ½¸öÒ×±»Ê¹ÓõÄí§ÒâÎļþдÈëÎó²î£¨CVE-2020-10890ºÍCVE-2020-10892£©£¬£¬£¬£¬ £¬£¬£¬ÒÔ¼°Á½¸öÓйØSetFieldValueÏÂÁî´¦Öóͷ£µÄ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-10912ºÍCVE-2020-10912£© ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËU3DBrowser²å¼þÖеÄ11¸öÎó²î ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/foxit-pdf-reader-phantompdf-remote-code-execution/154942/


6.еÄAndroidľÂíBanker.BRʹÓÃÆÁÄ»ÁýÕÖ¹¥»÷Ãé×¼ÒøÐпͻ§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


IBM X-ForceÑо¿Ö°Ô±·¢Ã÷еÄAndroidľÂíBanker.BR£¬£¬£¬£¬ £¬£¬£¬ÆäʹÓÃÆÁÄ»ÁýÕÖ¹¥»÷Õë¶ÔʹÓÃÎ÷°àÑÀÓï»òÆÏÌÑÑÀÓ°üÀ¨Î÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢°ÍÎ÷ºÍÀ­¶¡ÃÀÖÞÆäËûµØÇø£©µÄÒøÐпͻ§£¬£¬£¬£¬ £¬£¬£¬ÍýÏëÇÔÈ¡Óû§Æ¾Ö¤²¢ÍµÈ¡ÆäÕË»§ ¡£¡£¡£¡£Ñо¿·¢Ã÷£¬£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þµÄÔçÆÚ°æ±¾½ö¾ßÓлù±¾µÄSMSÇÔÈ¡¹¦Ð§£¬£¬£¬£¬ £¬£¬£¬¿ÉÊÇBanker.BR¸üΪϸÄ壬£¬£¬£¬ £¬£¬£¬¾ßÓÐÁýÕÖ¹¥»÷µÄ¹¦Ð§²¢ÇÒÓÐȫеĴúÂ룬£¬£¬£¬ £¬£¬£¬²»ÒÀÀµÓÚÏÈǰ×ß©µÄ´úÂë»òÏÖÓеÄÒÆ¶¯¶ñÒâÈí¼þ ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýÓÕʹÓû§ÏÂÔØÃ°³äµÄÒøÐÐÇå¾²Ó¦ÓóÌÐò¾ÙÐÐÈö²¥£¬£¬£¬£¬ £¬£¬£¬µÈÓû§ÀÖ³É×°Öúó±ã»áÇÔÈ¡Óû§×°±¸ÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬°üÀ¨µç»°ºÅÂë¡¢¹ú¼ÊÒÆ¶¯×°±¸Ê¶±ðÂ루IMEI£©¡¢¹ú¼ÊÒÆ¶¯Óû§Ê¶±ðÂ루IMSI£©ºÍSIMÐòÁкÅ£¬£¬£¬£¬ £¬£¬£¬²¢½«ÐÅÏ¢·¢Ë͸øC2ЧÀÍÆ÷ ¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þÒÀÈ»ÔÚ¿ª·¢ÖÐ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/android-banking-br-trojan-credential-stealing/154990/