ºÚ¿ÍÔÚÈȵãºÚ¿ÍÂÛÌÓð»¯ù³Æ¿ÇÅÆÊý¾ÝÔ⵽й¶

°ä²¼¹¦·ò 2024-05-31
1. ºÚ¿ÍÔÚÈȵãºÚ¿ÍÂÛÌÓð»¯ù³Æ¿ÇÅÆÊý¾ÝÔ⵽й¶


5ÔÂ30ÈÕ £¬ÁîÈËÕ𾪵ÄÊÇ £¬Ò»ÃûÍþвÐÐΪÕßÉæÏÓй¶ÁËÊÀ½çµ±ÏÈÄÜÔ´¹«Ë¾Ö®Ò»¿ÇÅÆµÄÃô¸ÐÊý¾Ý¡£Æ¾¾Ý Data Web Informer µÄÍÆÎÄ £¬2024 Äê 5 ÔµÄÊý¾Ý±»°ä²¼ÔÚÒ»¸öÊ¢ÐеĺڿÍÂÛ̳ÉÏ £¬Òý·¢ÁËÈËÃǶÔÍøÂ簲ȫºÍÊý¾ÝÒþÖÔµÄÑϳÁÓÇÓô¡£¾Ý±¨Â· £¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬´óÁ¿Ó×ÎÒÐÅÏ¢ºÍÃô¸ÐÊý¾Ý¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬£º¹ºÎïÕß´úÂë¡¢Ãû×Ö¡¢ÐÕÊÏ¡¢×´Ì¬¡¢¹ºÎïÕßµç×ÓÓʼþ¡¢ÁªÏµÊÖ»ú¡¢ÓÊÕþ±àÂë¡¢»¨ÃÛ¡¢½¼Çø¡¢ÖÝ¡¢Õ¾µãµØÖ·¡¢½¼Çø 1¡¢¹ú¶È¡¢Õ¾µãÃû³Æ¡¢ÉϴεǼ¡¢¸¶¿îºÍЭ»á±àºÅ¡£Õâ´ÎйÃÜÊÂÎñ¿ÉÄÜ»á¶Ô¿ÇÅÆ¼°Æä¿Í»§Ôì³ÉÑϳÁÓ°Ï졣й¶Èç´Ë¾ßÌåµÄÓ×ÎÒÐÅÏ¢¿ÉÄܻᵼÖÂÉí·Ý͵ÇÔ¡¢½ðÈÚڲƭºÍÆäËû¶ñÒâ»î¶¯¡£½¨Òé¿Í»§Ç×êÇ¼à¿ØËûÃǵÄÕË»§²¢Á¢¼´»ã±¨¿ÉÒɻ¡£½ØÖÁĿǰ £¬¿ÇÅÆÉÐδ¾ÍÕâ´ÎйÃÜÊÂÎñ°ä·¢¹Ù·½ÉêÃ÷¡£²»Íâ £¬¸Ã¹«Ë¾Ô¤¼Æ½«Æô¶¯ÄÚ²¿µ÷²é £¬²¢ÓëÍøÂ簲ȫר¼ÒºÏ×÷ £¬ÆÀ¹ÀÎ¥¹æµÄˮƽ²¢¼õÇáÈκÎDZÔÚÇÖº¦¡£


https://gbhackers.com/claiming-shell-data-breach/


2. TicketmasterÔâºÚ¿Í¹¥»÷ £¬³¬¹ý5 ÒÚÓû§Êý¾ÝÐÅϢй¶


5ÔÂ30ÈÕ £¬¾Ý±¨Â· £¬±¾ÖÜÔÚµ÷²éµÄÒ»Â·ÍøÂçÊÂÎñÖÐ £¬³¬¹ý 5 ÒÚ Ticketmaster Óû§µÄÓ×ÎÒºÍÐÅÓþ¿¨Êý¾ÝÔ⵽й¶¡£¾Ý±¨Â· £¬°Ä´óÀûÑǵ±¾ÖÔÚÓë Live Nation ºÍ Ticketmaster ºÏ×÷½â¾ö´ËÊÂÎñ £¬µ«½ØÖÁÖÜÈýÉÏÎç £¬Åû¶µÄϸ½ÚÓÐÏÞ¡£¾Ý¸ÃÐÂÎÅýÌ屨· £¬°Ä´óÀûÑÇÄÚÕþ²¿Í¨Öª ABC £¬ËûÃÇÔÚÓë Ticketmaster ºÏ×÷Ïàʶ´ËÊ¡£Ticketmaster »òÆäĸ¹«Ë¾ÉÐδ¾Í´Ëʰ䷢ÈκÎÉêÃ÷¡£ºÚ¿Í×éÖ¯ ShinyHunters Ðû³ÆÒÑÆÆ½â Ticketmaster ϵͳ²¢»ñÈ¡ÁËÔ¼ 1.3 TB µÄÊý¾Ý £¬ÆäÖÐÔ̺¬ÐÕÃû¡¢µØÖ·¡¢ÐÅÓþ¿¨ºÅ¡¢µç»°ºÅÂëºÍ¸¶¿î¾ßÌåÐÅÏ¢¡£Ìý˵ÕâЩÐÅÏ¢ÔÚ°µÍøÉÏÏúÊÛ £¬Òª¼Û 50 ÍòÃÀÔª¡£ÔçÆÚ»ã±¨ÏÔʾ £¬Óû§Êý¾ÝÉæ¼°È«Çò 5.6 ÒÚ¿Í»§ £¬µ«Éв»Ã÷ÏÔÄÄЩÊг¡Êܵ½Ó°Ï죨»òÊÜÓ°ÏìµÄÏû·ÑÕßÖÐÓм¸¶àÀ´×ÔÄÄЩÊг¡£©¡£ÏÔÈ» £¬Ë¼¿¼µ½Éæ¼°µÄ¸ß¶ÈÃô¸ÐÊý¾Ý £¬ÈκÎÊÜÓ°ÏìµÄÏû·ÑÕߵķçÏÕ¶¼¼«¶È¸ß¡£


https://www.ticketnews.com/2024/05/ticketmaster-hack-data-of-half-a-billion-users-up-for-ransom/


3. XWorm v5.6 ¶ñÒâÈí¼þͨ¹ý Webhards ½øÐд«²¼


5ÔÂ30ÈÕ £¬°²³¢ÊÔÊÒ°²È«µý±¨ÖÐÐÄ£¨ASEC£©ÔÚ¼à¿Øº«¹ú¶ñÒâÈí¼þµÄ´«²¼Ô´Ê± £¬×î½ü·¢ÏÖ¼Ù×°³É³ÉÈËÓÎÏ·µÄXWorm v5.6¶ñÒâÈí¼þÔÚͨ¹ýÍøÂçÓ²Å̽øÐд«²¼¡£ÍøÂçÓ²Å̺ÍÖÖ×ÓÊǺ«¹ú¶ñÒâÈí¼þ´«²¼µÄ³£ÓÃÆ½Ì¨¡£¹¥»÷Õßͨ³£Ê¹ÓÃÈÝÒ×»ñµÃµÄ¶ñÒâÈí¼þ £¬ÀýÈç njRAT ºÍ UDP RAT £¬²¢½«Æä¼Ù×°³ÉÔ̺¬ÓÎÏ·»ò³ÉÈËÄÚÈÝÔÚÄÚµÄÕý³£·¨Ê½½øÐзַ¢¡£XWorm v5.6 Ò²Äܹ»´Ó GitHub µÈƽ̨ÇáËÉ»ñÈ¡¡£ÏÂÔØ²¢½âѹÓÎÏ·Îļþºó £¬»áµÃµ½ Start.exe¡£¹ÌÈ»¿´ÆðÀ´ÏñÊǺϷ¨µÄÓÎÏ·Æô¶¯Æ÷Îļþ £¬µ«Ö´ÐÐÓÎÏ·µÄ .exe ÎļþÊǵ¥¶ÀÌìÉú²¢ÔËÐеÄ £¬²¢ÇÒ¼Ù×°³É SoundP2.muc µÄ¼ÓÔØ·¨Ê½¶ñÒâÈí¼þÒ²»á±»Ö´ÐС£Ö´ÐÐ Start.exe ²»»áÁ¢¼´ÔËÐжñÒâÈí¼þ»òÓÎÏ·  £»ËüÃÇ»áÔÚÄú°´Ï¡°ÆðÍ·ÓÎÏ·£¡¡±°´Å¥Ê±Ö´ÐС£ÕâÖÖÕ½ÊõËÆºõÊÇΪÁËÈÆ¹ýɳºÐģʽ¡£SoundP2.muc Ò²±»¸´Ôì²¢Õ³Ìùµ½ Windows Îļþ¼ÐÖÐ £¬²¢Ôö³¤µ½×¢²á±íÖÐÒÔ±ã×Ô¶¯Ö´ÐС£


https://asec.ahnlab.com/en/66099/


4. PyPI¶ñÒâÈí¼þPytoileurÇÔÈ¡¼ÓÃÜÇ®±Ò²¢Èƹý¼ì²â


5ÔÂ31ÈÕ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁË Python Èí¼þ°üË÷Òý£¨PyPI£©ÉϵĶñÒâÈí¼þ°üpytoileur¡£¸ÃÈí¼þ°ü¼Ù×°³ÉÓà Python ±àдµÄ API ÖÎÀí¹¤¾ß £¬°µ²ØÁËÏÂÔØºÍ×°ÖÃľÂí Windows ¶þ½øÔìÎļþµÄ´úÂë¡£ÕâЩ¶þ½øÔìÎļþ¿ÉÄܽøÐмල¡¢ÊµÏÖÓÆ¾ÃÐÔ²¢ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¸ÃÈí¼þ°ü±» Sonatype µÄ×Ô¶¯¶ñÒâÈí¼þ¼ì²âϵͳ·¢ÏÖ £¬²¢ÔÚ±»ÏóÕ÷ºóѸËÙ±»É¾³ý¡£pytoileur Èí¼þ°üÔÚ±»ÒƳýǰÒѱ»ÏÂÔØ 264 ´Î £¬ËüʹÓÃÁ˺ýŪÐÔ¼¼ÊõÀ´Ô¤·À±»¼ì²âµ½¡£ËüµÄÔªÊý¾Ý½«ÆäÃèÊöΪ¡°¿áìÅÈí¼þ°ü¡± £¬Ê¹ÓÃÒ»ÖÖÕ½Êõ £¬¼´¸øÈí¼þ°üÌùÉÏÎüÒýÈ˵ÄÍÌÍÂÃèÊö±êÇ© £¬ÒÔÓÕʹ¿ª·¢ÈËÔ±ÏÂÔØËüÃÇ¡£Sonatype ½ñÌì°ä²¼µÄÒ»·ÝÕ÷ѯ»ã±¨ÖÐÃèÊöÁ˽øÒ»²½µÄ²é³­ £¬·¢ÏÖÈí¼þ°ü×°ÖÃÎļþÖаµ²Ø×Å´óÁ¿¿Õ¸ñËù¸²¸ÇµÄ´úÂë¡£¸Ã´úÂëÖ´ÐÐÁËÒ»¸ö base64 ±àÂëµÄÓÐЧ¸ºÔØ £¬¸Ã¸ºÔØ´Ó±í²¿·þÎñÆ÷¼ìË÷Á˶ñÒâ¿ÉÖ´ÐÐÎļþ¡£ÏÂÔØµÄ¶þ½øÔìÎļþ¡°Runtime.exe¡±ÀûÓà PowerShell ºÍ VBScript ºÅÁî½øÐÐ×ÔÎÒ×°Öà £¬È·±£ÔÚÊÜϰȾµÄϵͳÖÐÓÆ¾Ã´æÔÚ¡£Ëüѡȡ¸÷Àà·´¼ì²â´ëÊ©À´Ìӱܰ²È«×êÑÐÈËÔ±µÄ·ÖÎö¡£ 


https://www.infosecurity-magazine.com/news/pypi-malware-pytoileur-steals/


5. °ÍÎ÷ÒøÐгÉΪ AllaKore RAT бäÖÖ AllaSenha µÄÖ¸±ê


5ÔÂ29ÈÕ £¬°ÍÎ÷ÒøÐлú×é³ÉΪлµÄÖ¸±ê £¬¸Ã»î¶¯·Ö·¢»ùÓÚ Windows µÄAllaKoreÔ¶³Ì½Ó¼ûľÂí (RAT)µÄ¶¨Ôì±äÖÖAllaSenha¡£·¨¹úÍøÂ簲ȫ¹«Ë¾ HarfangLabÔÚÒ»·Ý¼¼Êõ·ÖÎöÖаµÊ¾ £¬¸Ã¶ñÒâÈí¼þ¡°×¨ÃÅÓÃÓÚÇÔÈ¡½Ó¼û°ÍÎ÷ÒøÐÐÕË»§ËùÐèµÄƾ֤ £¬²¢ÀûÓà Azure ÔÆ×÷ΪºÅÁîºÍ½ÚÔì (C2) »ù´¡ÉèÊ©¡±¡£Õâ´Î¹¥»÷µÄÖ¸±êÔ̺¬°ÍÎ÷ÒøÐÓ×¢Bradesco¡¢Èø·òÀ­ÒøÐÓ×¢Caixa Econ?mica Federal¡¢Ita¨² Unibanco¡¢Sicoob ºÍ Sicredi µÈÒøÐС£¹ÌÈ»ÉÐδµÃµ½Ã÷ȷ֤ʵ £¬µ«×î³õµÄ½Ó¼ûÔØÌåÖ¸ÏòÁË´¹µöÓʼþÖÐʹÓöñÒâÁ´½Ó¡£¹¥»÷µÄÆðµãÊÇÒ»¸ö¶ñÒâµÄ Windows ¿ì½Ý·½Ê½ (LNK) Îļþ £¬¸ÃÎļþ¼Ù×°³É PDF Îĵµ£¨¡°NotaFiscal.pdf.lnk¡±£© £¬ÖÁÉÙ×Ô 2024 Äê 3 ÔÂÆðÍйÜÔÚ WebDAV ·þÎñÆ÷ÉÏ¡  £»¹ÓÐÖ¤¾ÝÅú×¢ £¬¸Ã»î¶¯±³ºóµÄÍþвÐÐΪÕßÖ®Ç°ÔøÀÄÓà Autodesk A360 Drive ºÍ GitHub µÈºÏ·¨·þÎñÀ´ÍйÜÓÐЧ¸ºÔØ¡£


https://thehackernews.com/2024/05/brazilian-banks-targeted-by-new.html


6. ÀûÓÃDora RATÕë¶Ôº«¹úÆóÒµ£¨Andariel Group£©µÄAPT¹¥»÷


5ÔÂ30ÈÕ £¬AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ×î½ü·¢ÏÖÁËÕë¶Ôº«¹ú¹«Ë¾ºÍ»ú¹¹µÄ Andariel APT ¹¥»÷°¸Àý¡£Ö¸±ê×éÖ¯Ô̺¬º«¹úµÄ½ÌÓý»ú¹¹ÒÔ¼°Ôì×÷ºÍ¹¹ÖþÆóÒµ¡£¹¥»÷ʹÓÃÁ˺óÃÁ÷ÅÉļüÅ̼ͼÆ÷¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½ºÍ´úÀí¹¤¾ß¡£ÍþвÐÐΪÕß¿ÉÄÜʹÓÃÕâЩ¶ñÒâÈí¼þÀ´½ÚÔìºÍÇÔÈ¡ÊÜϰȾϵͳµÄÊý¾Ý¡£Õâ´Î¹¥»÷ʹÓÃÁË Andariel ¼¯ÍÅ´Óǰ°¸ÀýÖз¢ÏֵĶñÒâÈí¼þ £¬ÆäÖÐ×îÒýÈËÖõÖ÷ÕÅÊÇ Nestdoor £¬ÕâÊDZ¾ÎÄÖÐÌáµ½µÄºóÃÅ¡£ÆäËû°¸ÀýÔ̺¬Ôö³¤ Web Shell¡£Lazarus ¼¯ÍÅÏÈǰ¹¥»÷Öз¢ÏֵĴúÀí¹¤¾ßÒ²±»Ê¹Óà £¬Ö»¹ÜËüÃǵÄÎļþÓ뵱ǰ°¸Àý²¢²»Ò»Ñù¡£ÔÚ¹¥»÷¹ý³ÌÖеĶà¶àÖ¤¾ÝÖÐ £¬Ò»¸öÏÖʵ±»Ö¤ÊµµÄ°¸ÀýÉæ¼°Ê¹ÓÃÔËÐÐ Apache Tomcat ·þÎñÆ÷µÄ Web ·þÎñÆ÷·Ö·¢¶ñÒâÈí¼þ¡£ÓÉÓÚÓÐÎÊÌâµÄϵͳÔËÐеÄÊÇ 2013 °æ Apache Tomcat £¬Òò¶øÈÝÒ×Êܵ½¸÷Àà·ì϶¹¥»÷¡£ÍþвÐÐΪÕßʹÓøà Web ·þÎñÆ÷×°ÖúóÃÅ¡¢´úÀí¹¤¾ßµÈ¡£


https://asec.ahnlab.com/en/66088/