Kaspersky·¢ÏÖUEFI¹Ì¼þrootkit CosmicStrand

Ðû²¼Ê±¼ä 2022-07-27
1¡¢Kaspersky·¢ÏÖUEFI¹Ì¼þrootkit CosmicStrand 

      

KasperskyÔÚ7ÔÂ25ÈÕÅû¶ÁËͳһ¿ÉÀ©Õ¹¹Ì¼þ½Ó¿Ú(UEFI)rootkit CosmicStrandµÄ¼¼Êõϸ½Ú ¡£Ñо¿ÈËÔ±ÌåÏÖ £¬¸ÃrootkitλÓÚ¼¼¼Î»ò»ªË¶Ö÷°åµÄ¹Ì¼þÓ³ÏñÖÐ £¬ÕâÊÇ2013ÄêÖÁ2015ÄêÖ®¼äµÄ¾ÉÓ²¼þ £¬ÏÖÔÚ´ó²¿ÃÅÒÑÍ£²ú ¡£ÕâЩӳÏñ¶¼ÓëʹÓÃH81оƬ×éµÄÉè¼ÆÓÐ¹Ø £¬Õâ±íÃ÷ÆäÖпÉÄÜ´æÔÚÒ»¸ö³£¼û©¶´ £¬¿É±»¹¥»÷ÕßÓÃÀ´½«rootkit×¢Èë¹Ì¼þµÄÓ³ÏñÖÐ ¡£Ä¿Ç° £¬Ñ¬È¾µÄ³õʼ·ÃÎÊý½éÈÔȻδ֪ ¡£


https://securelist.com/cosmicstrand-uefi-firmware-rootkit/106973/


2¡¢¹¥»÷ÕßÀûÓÃPrestaShopƽ̨ÖЩ¶´ÈëÇÖÔÚÏßÉ̵ê

      

¾Ý7ÔÂ25ÈÕ±¨µÀ £¬¹¥»÷ÕßÀûÓÿªÔ´µç×ÓÉÌÎñƽ̨PrestaShopÖеÄ©¶´£¨CVE-2022-36408£©¹¥»÷ÔÚÏßÉ̵ê ¡£PrestaShopÊÇÅ·ÖÞºÍÀ­¶¡ÃÀÖÞÁìÏȵĿªÔ´µç×ÓÉÌÎñ½â¾ö·½°¸ £¬±»È«Çò½ü300000¼ÒÔÚÏßÉ̼ÒʹÓà ¡£¸Ã©¶´Ó°ÏìÁËPrestaShop 1.6.0.10»ò¸ü¸ß°æ±¾ £¬ÒÔ¼°1.7.8.2»ò¸ü¸ß°æ±¾ÖÐÔËÐÐÁËÒ×±»SQL×¢Èë¹¥»÷µÄÄ£¿é£¨ÈçWishlist 2.0.0ÖÁ2.1.0Ä£¿é£© ¡£ÀûÓøÃ©¶´ £¬¹¥»÷Õß¿ÉÒÔÖ´ÐÐÈÎÒâ´úÂë²¢ÇÔÈ¡¿Í»§µÄÖ§¸¶ÐÅÏ¢ £¬¸Ã©¶´ÒÑÔÚ1.7.8.7°æ±¾ÖÐÐÞ¸´ ¡£


https://thehackernews.com/2022/07/hackers-exploit-prestashop-zero-day-to.html


3¡¢Ñо¿ÈËԱ͸¶QBotÀûÓÃWindows¼ÆËãÆ÷ѬȾĿ±êÉ豸

      

7ÔÂ24ÈÕ±¨µÀ £¬ProxyLife·¢ÏÖÖÁÉÙ´Ó7ÔÂ11ÈÕÆð £¬Qbot¾ÍÒ»Ö±ÔÚÀÄÓÃWindows 7 CalculatorÓ¦ÓýøÐÐDLL²à¼ÓÔØ¹¥»÷ ¡£»î¶¯Ê¹ÓõĶñÒâÓʼþÖÐÓÐÒ»¸öHTML¸½¼þ £¬»áÏÂÔØ°üÂÞISOÎļþµÄZIP ¡£ISOÖÐÓÐÒ»¸ö.LNK Îļþ¡¢¡°calc.exe¡±£¨Windows¼ÆËãÆ÷£©¸±±¾ºÍÁ½¸öDLLÎļþ £¬¼´WindowsCodecs.dllºÍÃûΪ7533.dllµÄpayload ¡£.LNK¿ì½Ý·½Ê½Ö¸ÏòWindowsÖеļÆËãÆ÷Ó¦Óà £¬¼ÓÔØºóWindows 7¼ÆËãÆ÷»á×Ô¶¯ËÑË÷²¢¼ÓÔØºÏ·¨WindowsCodecs DLLÎļþ ¡£µ«Ëü²»»á¼ì²éijЩӲ±àÂë·¾¶ÖеÄDLL £¬Èç¹û½«ÆäÓëCalc.exe·ÅÔÚͬһÎļþ¼ÐÖÐ £¬Ëü½«¼ÓÔØ¾ßÓÐÏàͬÃû³ÆµÄËùÓÐDLL ¡£


https://www.bleepingcomputer.com/news/security/qbot-phishing-uses-windows-calculator-sideloading-to-infect-devices/


4¡¢Ó¡¶È±£ÏÕ¹«Ë¾Policybazaar³ÆÆäϵͳ±»Î´ÊÚȨ·ÃÎÊ

      

ýÌå7ÔÂ19ÈÕ³Æ £¬Ó¡¶È±£ÏÕ¹«Ë¾PolicybazaarÔâµ½ÁËδ¾­ÊÚȨµÄ·ÃÎÊ ¡£¸Ã¹«Ë¾µÄĸ¹«Ë¾PB FintechÔÚÉÏÖÜÈÕÐû²¼Í¨¸æ £¬³ÆËüÔÚ7ÔÂ19ÈÕ·¢ÏÖÁËÀûÓÃÆäϵͳÖЩ¶´µÄ·Ç·¨µÄδ¾­ÊÚȨµÄ·ÃÎÊ ¡£¸Ã¹«Ë¾ÌåÏÖ £¬Ä¿Ç°ÒÑÐÞ¸´Â©¶´ £¬²¢ÒÑÆô¶¯¶ÔϵͳµÄÉó¼Æ £¬Éó²é·¢ÏÖûÓÐÈκÎÖØÒªµÄ¿Í»§Êý¾Ýй¶ ¡£Ð¹Â¶Í¨ÖªÉÐδÌá¼°ÄÄЩÊý¾ÝÒѱ»Ð¹Â¶»òÓм¸¶à¿Í»§Êܵ½Ó°Ïì ¡£´ËÍâ £¬PB FintechµÄ¹É¼Û´ÓÉÏÖÜÎåµÄ522¬±ÈϵøÖÁÖÜÒ»µÄ499.70¬±È ¡£


https://www.infosecurity-magazine.com/news/indian-insurance-policybazaar/


5¡¢ºÚ¿ÍÔÚ°µÍø¹ûÈ»Rust¿ª·¢µÄµÄijÇÔÈ¡·¨Ê½µÄÔ´´úÂë

      

ýÌå7ÔÂ25ÈÕ³Æ £¬ºÚ¿ÍÔÚ°µÍø¹ûÈ»ÁËÓÃRust¿ª·¢µÄµÄijÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÔ´´úÂë ¡£¸Ã¶ñÒâÈí¼þ¿ª·¢ÕßÉù³ÆÖ»ÓÃÁËÁù¸öСʱ¾Í¿ª·¢³öÀ´ÁË £¬Ëü·Ç³£Òþ±Î £¬VirusTotal·µ»ØµÄ¼ì²âÂÊԼΪ22% ¡£Cyble½«ÆäÃüÃûΪLuca Stealer £¬Ö´ÐÐʱËü»á´Ó30¸ö»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖÐÇÔÈ¡Êý¾Ý £¬Ö÷ÒªÕë¶ÔÃÜÂë¹ÜÀíÆ÷ä¯ÀÀÆ÷²å¼þ ¡£Cyble³ÂËßÒѾ­¼ì²âµ½ÖÁÉÙ25¸öÔÚÒ°ÀûÓõÄLuca StealerÑù±¾ £¬Éв»Çå³þÕâÖÖеĶñÒâÈí¼þÊÇ·ñ»á±»´ó¹æÄ£²¿Êð ¡£ËäÈ»¸Ã¶ñÒâÈí¼þÓÉ¿çÆ½Ì¨ÓïÑÔRust±àд £¬µ«Ä¿Ç°ÆäÖ»Õë¶ÔWindowsϵͳ ¡£

https://www.bleepingcomputer.com/news/security/source-code-for-rust-based-info-stealer-released-on-hacker-forums/


6¡¢Î¢ÈíÐû²¼ÀûÓöñÒâIISÀ©Õ¹µÄ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß

      

7ÔÂ26 £¬Î¢ÈíÐû²¼Á˹ØÓÚÀûÓÃInternetÐÅÏ¢·þÎñ(IIS)À©Õ¹µÄ¹¥»÷»î¶¯µÄ·ÖÎö ¡£³ÂËßÖ¸³ö £¬¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹ÓöñÒâIIS Web·þÎñÆ÷À©Õ¹×÷Ϊ·þÎñÆ÷µÄÒþ±ÎºóÃÅ £¬ÒòΪÓëWeb shellÏà±È £¬ËüµÄ¼ì²âÂʽϵÍ ¡£Í¨³£ £¬¹¥»÷ÕßÊ×ÏÈ»áÀûÓÃÍйÜÓ¦ÓÃÖеÄÒ»¸ö©¶´¿ªÊ¼³õʼ·ÃÎÊ £¬È»ºó°²×°Ò»¸ö½Å±¾Webshell×÷ΪµÚÒ»½×¶Îpayload ¡£Ö®ºó £¬¹¥»÷Õ߻ᰲװһ¸öIISºóÃÅ £¬ÒÔ¶Ô·þÎñÆ÷½øÐÐÒþ±ÎºÍ³Ö¾ÃµÄ·ÃÎÊ ¡£°²×°ºó £¬¶ñÒâIISÄ£¿é»á´ÓÄ¿±êϵͳµÄÄÚ´æÖÐÇÔȡƾ¾Ý £¬ÊÕ¼¯ÐÅÏ¢ £¬²¢°²×°¸ü¶àpayload ¡£Î¢ÈíÔ¤¼ÆÎ´À´»áÓиü¶à´ËÀ๥»÷ ¡£


https://www.microsoft.com/security/blog/2022/07/26/malicious-iis-extensions-quietly-open-persistent-backdoors-into-servers/