TT Malware Log

マルウェア / サイバー攻撃 / 解析技術 / 攻撃組織 / 攻撃技術 に関する「個人」の調査・研究

標的型攻撃 の検索結果:

A hacking group is hijacking Microsoft Exchange web shells

…/03/12) https://therecord.media/a-hacking-group-is-hijacking-microsoft-exchange-web-shells/ 【関連まとめ記事】◆全体まとめ ◆インシデント (まとめ) ◆標的型攻撃のインシデント (まとめ) ◆Exchange Server への大規模サイバー攻撃 (まとめ) https://malware-log.hatenablog.com/entry/Exchange_Server_202103

Ransomware Operators Start Targeting Microsoft Exchange Vulnerabilities

…全体まとめ ◆インシデント (まとめ) ◆標的型攻撃のインシデント (まとめ) ◆Exchange Server への大規模サイバー攻撃 (まとめ) https://malware-log.hatenablog.com/entry/Exchange_Server_202103 ◆マルウェア / Malware (まとめ) ◆ランサムウェア (まとめ) ◆DearCry (まとめ) https://malware-log.hatenablog.com/entry/DearCry

Webシェル「Chopper」を利用した最近の標的型攻撃事例を解説

…r」を利用した最近の標的型攻撃事例を解説 (Trendmicro, 2021/03/11) https://blog.trendmicro.co.jp/archives/27354 【インディケータ情報】■ハッシュ情報(Sha256) -- ee63b49aca1495a170ea7273316385b606f3fd2df1e48e9f4de0f241d98bd055 5099264b16208d88c9bca960751f5e3de7a5420986fa0d7e2b2a6b…

ノルウェー議会にハッカー攻撃、データ盗まれる 昨年に続き

…れる 昨年に続き (ロイター, 2021/03/11 11:45) https://jp.reuters.com/article/norway-cyber-idJPL4N2L90KA 【関連まとめ記事】◆全体まとめ ◆インシデント (まとめ) ◆標的型攻撃のインシデント (まとめ) ◆Exchange Server への大規模サイバー攻撃 (まとめ) https://malware-log.hatenablog.com/entry/Exchange_Server_202103

Microsoft Exchange 2019 - SSRF to Arbitrary File Write (Proxylogon)

… (Proxylogon) (TESTANULL(Exploit DB), 2021/03/11) https://www.exploit-db.com/exploits/49637 【関連まとめ記事】◆全体まとめ ◆インシデント (まとめ) ◆標的型攻撃のインシデント (まとめ) ◆Exchange Server への大規模サイバー攻撃 (まとめ) https://malware-log.hatenablog.com/entry/Exchange_Server_202103

Linux Systems Under Attack By New RedXOR Malware

…atpost.com/linux-systems-redxor-malware/164689/ 【関連まとめ記事】◆全体まとめ ◆マルウェア / Malware (まとめ) ◆Linux マルウェア (まとめ) https://malware-log.hatenablog.com/entry/Linux_Malware ◆標的型攻撃マルウェア (まとめ) ◆RedXOR (まとめ) https://malware-log.hatenablog.com/entry/RedXOR

New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor

…re (まとめ) ◆標的型攻撃マルウェア (まとめ) ◆RedXOR (まとめ) https://malware-log.hatenablog.com/entry/RedXOR 【インディケータ情報】■ハッシュ情報(Sha256) - RedXOR - 0a76c55fa88d4c134012a5136c09fb938b4be88a382f88bf2804043253b0559f 0423258b94e8a9af58ad63ea493818618de2d8c60cf75ec7…

More hacking groups join Microsoft Exchange attack frenzy

…eepingcomputer.com/news/security/more-hacking-groups-join-microsoft-exchange-attack-frenzy/ 【関連まとめ記事】◆全体まとめ ◆インシデント (まとめ) ◆標的型攻撃のインシデント (まとめ) ◆Exchange Server への大規模サイバー攻撃 (まとめ) https://malware-log.hatenablog.com/entry/Exchange_Server_202103

Exchange servers under siege from at least 10 APT groups

…ント (まとめ) ◆標的型攻撃のインシデント (まとめ) ◆Exchange Server への大規模サイバー攻撃 (まとめ) https://malware-log.hatenablog.com/entry/Exchange_Server_202103 ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Mikroceen (まとめ) https://malware-log.hatenablog.com/entry/Mikroceen ◆AP…

SuperNova (まとめ)

…m/blog/supernova-web-shell-deployment-linked-to-spiral-threat-group ⇒ https://malware-log.hatenablog.com/entry/2021/03/08/000000_7 【関連まとめ記事】◆全体まとめ ◆マルウェア / Malware (まとめ) ◆標的型攻撃マルウェア (まとめ) https://malware-log.hatenablog.com/entry/APT_Malware

BitSight Observations Into the HAFNIUM Attacks: Part One

…1/03/09) [BitSightが見た「HAFNIUM」への攻撃。パート1] https://www.bitsight.com/blog/hafnium-observations 【関連まとめ記事】◆全体まとめ ◆インシデント (まとめ) ◆標的型攻撃のインシデント (まとめ) ◆Exchange Server への大規模サイバー攻撃 (まとめ) https://malware-log.hatenablog.com/entry/Exchange_Server_202103

「Exchange Server」攻撃が世界中で拡大、対応支援の要請殺到 中国の集団が関与か

…が、2日の時点で既に標的型攻撃に利用(ProxyLogon) 緊急パッチが適用されていないシステムを狙って複数の集団が攻撃を継続 緩和策は、もしも既にExchangeサーバが不正侵入されていた場合の問題解決にはならない ■攻撃方法 脆弱性を悪用してExchange Serverに接続 遠隔操作するために「WebShell」を導入 被害組織の電子メールアカウントに侵入し、データを盗み出す ■攻撃組織(Actor) Hafnium Hafnium以外にも、この問題を悪用する集団が…

Exchange Server の脆弱性悪用、マイクロソフトが新たな国家支援型サイバー攻撃を解説

…イバー攻撃 (Microsoft, 2021/03/05) https://news.microsoft.com/ja-jp/2021/03/05/210305-new-nation-state-cyberattacks/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

MicrosoftのExchange Server脆弱性が発覚してからの攻撃&対処のタイムラインはこんな感じ

…攻撃&対処のタイムラインはこんな感じ (Gigazine, 2021/03/09 12:35) https://gigazine.net/news/20210309-attacks-on-exchange-servers/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

マイクロソフト、「Exchange Server」の脆弱性に関連する侵入の痕跡を確認するスクリプト公開

…26/ 【GitHub】 ◆CSS-Exchange (Microsoft, 2021/03/09) https://github.com/microsoft/CSS-Exchange/tree/main/Security 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

SolarWindsハッキング、中国の脅威グループが「SUPERNOVA」マルウェア展開に関与か

…olarWindsハッキング、中国の脅威グループが「SUPERNOVA」マルウェア展開に関与か (ZDNet, 2021/03/09 13:32) https://japan.zdnet.com/article/35167528/ 【関連まとめ記事】◆全体まとめ ◆マルウェア / Malware (まとめ) ◆標的型攻撃マルウェア (まとめ) ◆SuperNova (まとめ) https://malware-log.hatenablog.com/entry/SuperNova

Microsoft、サポート対象外Exchange Serverへ例外的にアップデート提供開始

…対象外Exchange Serverへ例外的にアップデート提供開始 (マイナビニュース, 2021/03/09 15:12) https://news.mynavi.jp/article/20210309-1792223/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

Microsoft Exchangeのゼロデイ脆弱性の悪用への検知と対応

…ント (まとめ) ◆標的型攻撃のインシデント (まとめ) ◆Exchange Server への大規模サイバー攻撃 (まとめ) https://malware-log.hatenablog.com/entry/Exchange_Server_202103 【インディケータ情報】■ハッシュ情報(MD5) - Exchange Server の脆弱性 - 4b3039cf227c611c45d2242d1228a121 0fd9bffa49c76ee12e51e3b8ae0609…

ProxyLogonのまとめとExchange Serverの利用状況について

…ークス, 2021/03/08 11:48) https://blog.macnica.net/blog/2021/03/proxylogonexchange-server.html 【関連まとめ記事】◆全体まとめ ◆インシデント (まとめ) ◆標的型攻撃のインシデント (まとめ) ◆Exchange Server への大規模サイバー攻撃 (まとめ) https://malware-log.hatenablog.com/entry/Exchange_Server_202103

SUPERNOVA Web Shell Deployment Linked to SPIRAL Threat Group

…方に責任を負っていたことを示唆しています] https://www.secureworks.com/blog/supernova-web-shell-deployment-linked-to-spiral-threat-group 【関連まとめ記事】◆全体まとめ ◆マルウェア / Malware (まとめ) ◆標的型攻撃マルウェア (まとめ) ◆SuperNova (まとめ) https://malware-log.hatenablog.com/entry/SuperNova

中国によるサイバー攻撃で政府が緊急指令を発令、すでに3万以上の組織がハッキングされているとの指摘も

…も (Gigazine, 2021/03/08 11:31) https://gigazine.net/news/20210308-microsoft-exchange-server-hafnium-proxylogon/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

サイバー攻撃、国内被害なし 加藤官房長官

【ニュース】 ◆サイバー攻撃、国内被害なし 加藤官房長官 (時事通信, 2021/03/08 15:00) https://www.jiji.com/jc/article?k=2021030800666 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

ハッカー集団「ハフニウム」暗躍 中国政府が支援か

…朝, 2021/03/07 09:34) https://news.tv-asahi.co.jp/news_international/articles/000209114.html 【関連まとめ記事】◆全体まとめ ◆インシデント (まとめ) ◆標的型攻撃のインシデント (まとめ) ◆Exchange Server への大規模サイバー攻撃 (まとめ) https://malware-log.hatenablog.com/entry/Exchange_Server_202103

マイクロソフトのメール狙った攻撃で「被害多数」、米政府が懸念

…ール狙った攻撃で「被害多数」、米政府が懸念 (ロイター, 2021/03/06 07:15) https://jp.reuters.com/article/usa-cyber-microsoft-idJPKCN2AX2J1 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

米3万組織に攻撃、中国系ハッカーか Microsoft標的

…織に攻撃、中国系ハッカーか Microsoft標的 (日経新聞, 2021/03/06 19:40) https://www.nikkei.com/article/DGXZQOGN062GA0W1A300C2000000/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

新たな国家支援型サイバー攻撃について

…が新たな国家支援型サイバー攻撃を解説 (NetSecurity, 2021/03/09 08:05) https://scan.netsecurity.ne.jp/article/2021/03/09/45306.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

Microsoft rushes out fixes for four zero‑day flaws in Exchange Server

…しているという] https://www.welivesecurity.com/2021/03/04/microsoft-fixes-four-exchange-server-zero-day-vulnerabilities/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆攻撃組織: Calypso (まとめ) https://malware-log.hatenablog.com/entry/Calypso

Microsoft Exchange Serverに複数の脆弱性、4件の悪用を確認

…t Exchange Serverに複数の脆弱性、4件の悪用を確認 (マイナビニュース, 2021/03/04 08:57) https://news.mynavi.jp/article/20210304-1767789/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

更新:Microsoft Exchange Server の脆弱性対策について(CVE-2021-26855等)

… Server の脆弱性対策について(CVE-2021-26855等) (IPA, 2021/03/04) https://www.ipa.go.jp/security/ciadr/vul/20210303-ms.html 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium

中国の国家ハッカーがExchange Serverの脆弱性をゼロデイ攻撃、マイクロソフトが警告

…/jp.techcrunch.com/2021/03/04/2021-03-02-microsoft-says-china-backed-hackers-are-exploiting-exchange-zero-days/ 【関連まとめ記事】◆全体まとめ ◆攻撃組織 / Actor (まとめ) ◆標的型攻撃組織 / APT (まとめ) ◆Hafnium / ハフニウム (まとめ) https://malware-log.hatenablog.com/entry/Hafnium


Copyright (C) 谷川哲司 (Tetsuji Tanigawa) 1997 - 2023