¶ñÒâÈí¼þDark HerringÒÑѬȾÉÏÒŲ́AndroidÉ豸

Ðû²¼Ê±¼ä 2022-02-10

¶ñÒâÈí¼þDark HerringÒÑѬȾÉÏÒŲ́AndroidÉ豸


¾ÝýÌå1ÔÂ26ÈÕ±¨µÀ£¬ZimperiumÔÚGoogle PlayÉϼì²âµ½470¿î¶ñÒâÓ¦Óá£ÕâЩӦÓÃÒÑÔÚÈ«ÇòÁè¼Ý1.05ÒŲ́AndroidÉ豸Éϰ²×°Á˶ñÒâÈí¼þDark Herring£¬Ëü¿ÉÒÔͨ¹ýÄ¿±êµÄ»°·ÑÕ˵¥ÇÔÈ¡×ʽ𡣸ûÿÔÂÏòÄ¿±êµÄ»°·ÑÕ˵¥ÖÐÔö¼Ó15ÃÀÔªµÄÓöÈ£¬ÓÚ2020Äê3ÔÂÊ״α»·¢ÏÖ£¬²¢Ò»Ö±Á¬Ðøµ½È¥Äê11Ô£¬¾ÝÔ¤¼ÆÇÔÈ¡µÄ½ð¶î×ÜÊýÒÑ´ïÊýÒÚ¡£Ä¿Ç°£¬GoogleÒÑÔÚPlayÉ̵êÖÐɾ³ýÁËÉÏÊöµÄ¶ñÒâÓ¦Óá£


https://threatpost.com/dark-herring-billing-malware-android/178032/


µÂ¹úBfV³ÆAPT27ÍÅ»ïÀûÓÃHyperBro¹¥»÷ÆäÉÌÒµ×éÖ¯ 


1ÔÂ26ÈÕ£¬µÂ¹úÁª°îÏÜ·¨±£»¤°ì¹«ÊÒ(BfV)Ðû²¼Í¨¸æ£¬³ÆAPT27ÍÅ»ïÕýÔÚ¹¥»÷ÆäÉÌÒµ×éÖ¯¡£APT27ÓÖÃûEmissary Panda£¬×Ô2010ÄêÒÔÀ´Ò»Ö±»îÔ¾¡£BfV³Æ£¬×Ô2021Äê3ÔÂÒÔÀ´£¬APT27Ò»Ö±ÔÚÀûÓÃMicrosoft ExchangeºÍZoho AdSelf Service Plus1Èí¼þÖеÄ©¶´¹¥»÷µÂ¹úµÄ¹«Ë¾¡£´ËÍ⣬»¹ÀûÓÃÁËHyperBro RAT£¬Ö¼ÔÚÇÔȡĿ±êµÄÊý¾Ý£¬²¢ÊÔͼÕë¶ÔÆä¿Í»§Ìᳫ¹©Ó¦Á´¹¥»÷¡£


https://securityaffairs.co/wordpress/127230/apt/german-intel-warns-apt27-attacks.html


¹¥»÷ÕßÀûÓÃ800¶à¸öÍøÕ¾·Ö·¢Õë¶Ô°ÍÎ÷µÄÒøÐÐľÂíChaes


ýÌå1ÔÂ26ÈÕ±¨µÀ£¬¹¥»÷ÕßʹÓÃ800¶à¸öÒѱ»ÈëÇÖµÄWordPressÍøÕ¾·Ö·¢Õë¶Ô°ÍÎ÷µÄÒøÐÐľÂíChaes¡£µ±Ä¿±ê·ÃÎʱ»Ñ¬È¾ÍøÕ¾Ê±£¬»á±»ÒªÇó°²×°Ò»¸ö¼ÙµÄJava RuntimeÓ¦Ó᣸ÃMSI°²×°·¨Ê½°üÂÞÈý¸ö¶ñÒâJavaScriptÎļþ£ºinstall.js¡¢sched.js¡¢sucesso.js£¬ËüÃÇΪÏÂÒ»½×¶ÎµÄ¼ÓÔØ·¨Ê½×¼±¸Python»·¾³¡£AvastÌåÏÖ£¬ÒѼì²âµ½ÁË5ÖÖ²îÒìµÄ¶ñÒâChromeÀ©Õ¹·¨Ê½¡£Ä¿Ç°£¬¸ÃÄþ¾²¹«Ë¾ÒÑ֪ͨ°ÍÎ÷CERT£¬µ«¹¥»÷»î¶¯ÈÔÔÚ½øÐÐÖС£


https://www.bleepingcomputer.com/news/security/chaes-banking-trojan-hijacks-chrome-with-malicious-extensions/


Bitdefender·¢ÏÖ´ó¹æÄ£·Ö·¢FluBotºÍTeaBotµÄ»î¶¯


1ÔÂ26ÈÕ±¨µÀ³Æ£¬ÐµÄFluBotºÍTeaBot¶ñÒâÈí¼þ·Ö·¢»î¶¯ÕýÔÚÕë¶Ô°Ä´óÀûÑÇ¡¢µÂ¹ú¡¢²¨À¼¡¢Î÷°àÑÀºÍÂÞÂíÄáÑǵÄAndroidÓû§¡£Bitdefender Labs×Ô2021Äê12ÔÂÒÔÀ´£¬½Ø»ñÁËÁè¼Ý10ÍòÌõ¶ñÒâ¶ÌÐÅ£¬Ö¼ÔÚÁ÷´«FluBot¡£¸Ã¹«Ë¾»¹³Æ£¬TeaBotÒѶà´Î·ºÆðÔÚGoogle PlayÉ̵êÖУ¬2021Äê12ÔÂ6ÈÕµ½2022Äê1ÔÂ17ÈÕ£¬ËûÃǼì²âµ½17¸ö²îÒì°æ±¾µÄTeaBotͨ¹ý¶à¸ö¶ñÒâÓ¦ÓÃѬȾÉ豸¡£


https://www.bleepingcomputer.com/news/security/new-flubot-and-teabot-campaigns-target-android-devices-worldwide/


DiscordÒòAPIºÍÊý¾Ý¿â·ºÆðÎÊÌâµ¼Ö´ó¹æÄ£·þÎñÖжÏ


1ÔÂ26ÈÕ£¬Discord·¢ÉúÁË´ó¹æÄ£ÖжϵÄÇé¿ö£¬µ¼ÖÂÓû§ÎÞ·¨µÇ¼·þÎñ»òʹÓÃÓïÒôÁÄÌì¡£ÖжϿªÊ¼ÓÚÃÀ¹ú¶«²¿³ß¶Èʱ¼äÏÂÎç2:49£¬×î³õÊÇÓÉAPIÖжÏÒýÆðµÄ£¬µ¼Ö¶à¸ö·þÎñÎÞ·¨Ï໥ͨÐÅ¡£È»¶ø£¬ÔÚ½â¾öAPIÎÊÌâºó£¬Discord·¢ÏÖÊý¾Ý¿â¼¯Èº·ºÆðÎÊÌ⣬Õâµ¼ÖÂÁ˸ü¶àÎÊÌâ¡£¸Ã¹«Ë¾ÔÚÐÞ¸´ÓÐÎÊÌâµÄÊý¾Ý¿â¼¯ÈºÊ±¿ªÊ¼ÏÞÖÆµÇ¼ËÙ¶È£¬ÒÔ·ÀÖ¹·þÎñÆ÷¹ýÔØ£¬Ö±µ½ÏÂÎç5:12×óÓÒ£¬ÏÞËÙ±»È¡Ïû¡£


https://www.bleepingcomputer.com/news/technology/major-discord-outage-caused-by-api-and-database-issues/


΢ÈíAzureÔÆÆ½Ì¨ÀֳɵÖÓù¸ß´ï3.47 TbpsµÄDDoS¹¥»÷


΢ÈíÔÚ1ÔÂ25ÈÕÐû²¼µÄ³ÂË߳ƣ¬ÆäAzureÒѵÖÓùÁ˸ߴï3.47 TbpsµÄDDoS¹¥»÷¡£11Ô£¬Î¢ÈíÑÇÖÞµÄÒ»¸ö¿Í»§Ôâµ½ÁË3.47 TbpsºÍÿÃë3.4ÒÚÊý¾Ý°ü(pps)µÄDDoS¹¥»÷£¬Õâ±»ÈÏΪÕâÊÇÀúÊ·ÉÏ×î´ó¹æÄ£µÄ¹¥»÷¡£´Ë´Î¹¥»÷À´×ÔԼĪ10000¸öÔ´£¬Éæ¼°Öйú¡¢º«¹ú¡¢¶íÂÞ˹¡¢Ì©¹ú¡¢Ó¡¶È¡¢Ô½ÄÏ¡¢ÒÁÀÊ¡¢Ó¡¶ÈÄáÎ÷Ñǵȶà¸ö¹ú¼Ò¡£¹¥»÷ÏòÁ¿ÊÇʹÓÃSSDP¡¢CLDAP¡¢DNSºÍNTPÔÚ80¶Ë¿ÚÉϵÄUDP·´É䣬×ÜÌå¹¥»÷Á¬ÐøÁËԼĪ15·ÖÖÓ¡£


https://azure.microsoft.com/en-us/blog/azure-ddos-protection-2021-q3-and-q4-ddos-attack-trends/


Äþ¾²¹¤¾ß


jfrog-npm-tools


JFrogÐû²¼Èý¿î¿ªÔ´¹¤¾ß£¬¿É´Ó npm ±£Ö¤ÀíÆ÷ÏÂÔØºÍ°²×°¶ñÒâ JavaScript °ü֮ǰ¶ÔÆä½øÐбêÖ¾¡£


https://github.com/jfrog/jfrog-npm-tools


EtherNet/IP & CIP Stack Detector


Äþ¾²¹«Ë¾ ClarotyÐû²¼ÐµĿªÔ´¹¤¾ßÓÐÖúÓÚʶ±ðÓÃÓÚ ICS Ñо¿ºÍ·ÖÎöµÄ EtherNet/IP ¶ÑÕ»¡£


https://www.securityweek.com/new-open-source-tool-helps-identify-ethernetip-stacks-ics-research-analysis


Wireshark Forensics Toolkit 


¿çƽ̨µÄ Wireshark ²å¼þ£¬¿É½«ÍøÂçÁ÷Á¿Êý¾ÝÓëÍþвÇ鱨¡¢×ʲú·ÖÀàºÍ©¶´Êý¾Ý¹ØÁªÆðÀ´£¬ÒÔ¼Ó¿ìÍøÂçȡ֤·ÖÎö¡£


https://github.com/rjbhide/wireshark-forensics-plugin


T-Reqs


ÊÇÒ»ÖÖ»ùÓÚÓï·¨µÄ HTTP Fuzzer¡£


https://github.com/bahruzjabiyev/T-Reqs-HTTP-Fuzzer


DotGit


¼ì²é .git ÊÇ·ñÔÚ·ÃÎʵÄÍøÕ¾ÖÐ̻¶µÄÀ©Õ¹¡£


https://github.com/davtur19/DotGit


Äþ¾²·ÖÎö


°×¹¬Ï£ÍûÃÀ¹úÕþ¸®Ê¹ÓÃÁãÐÅÈÎÄþ¾²Ä£ÐÍ


https://www.bleepingcomputer.com/news/security/white-house-wants-us-govt-to-use-a-zero-trust-security-model/



΢Èí¾¯¸æµöÓã OAuth Ó¦Ó÷¨Ê½


https://blog.malwarebytes.com/privacy-2/2022/01/microsoft-warns-of-phishy-oauth-apps/


¹È¸è·ÅÆú FLoC ²¢ÒýÈëÖ÷Ìâ API À´Ìæ»»¹ã¸æµÄ¸ú×Ù Cookie


https://thehackernews.com/2022/01/google-drops-floc-and-introduces-topics.html


ÀÕË÷Èí¼þ¹¥»÷ÕßʹÓõÄ©¶´¼¤Ôö 29%


https://www.infosecurity-magazine.com/news/29-surge-bugs-used-ransomware/


Let's Encrypt ÔÚÁ½ÌìÄÚÈ¡Ïû´óÁ¿ SSL Ö¤Êé


https://www.bleepingcomputer.com/news/security/lets-encrypt-is-revoking-lots-of-ssl-certificates-in-two-days/


MalwarebytesÐû²¼¹ØÓÚKONNI RATµÄ¼¼Êõ·ÖÎö³ÂËß


https://blog.malwarebytes.com/threat-intelligence/2022/01/konni-evolves-into-stealthier-rat/