Guacamaya¹ûÈ»ÖÇÀûµÈ¶à¸ö¹ú¼ÒµÄ¾üÊ»ú¹¹Ô¼10 GBÊý¾Ý

Ðû²¼Ê±¼ä 2022-09-21

1¡¢Guacamaya¹ûÈ»ÖÇÀûµÈ¶à¸ö¹ú¼ÒµÄ¾üÊ»ú¹¹Ô¼10 GBÊý¾Ý

      

¾Ý9ÔÂ19ÈÕ±¨µÀ£¬×Ô³ÆGuacamayaµÄºÚ¿ÍÍÅ»ïÐû²¼ÁËÀ´×ÔÖÇÀûºÍÄ«Î÷¸çµÈ¶à¸ö¹ú¼ÒµÄ¾üʺ;¯²ì»ú¹¹Ô¼10 GBµÄµç×ÓÓʼþµÈÖÊÁÏ¡£¸ÃÍÅ»ïÖ÷ÒªÕë¶ÔÖÐÃÀÖÞµØÓòµÄ×éÖ¯£¬ÕâÊÇÆä×Ô2022Äê3ÔÂÒÔÀ´µÚËĴιûÈ»Êý¾Ý£¬ÕâЩÊý¾Ý¶¼±»Ðû²¼µ½ÁËEnlace Hacktivista¡£¾ÝϤ£¬´Ë´ÎʼþÖ÷񻃾¼°ÁËÖÇÀûÎä×°¶ÓÎéÕÕÁϳ¤ÁªÏ¯»áÒ顢īÎ÷¸ç¹ú·À²¿¡¢Èø¶ûÍß¶à¹ú¼ÒÃñ¾¯ºÍÈø¶ûÍß¶àÎä×°¶ÓÎé¡¢¸çÂ×±ÈÑÇÎä×°¶ÓÎé×Ü˾Á¡¢ÃØÂ³Îä×°¶ÓÎéÁªºÏ˾ÁºÍÃØÂ³¾ü¶Ó¡£


https://www.cyberscoop.com/central-american-hacking-group-releases-emails/


2¡¢Imperva³ÆÒÑ×èÖ¹·¢ËÍÁè¼Ý253ÒÚ´ÎÇëÇóµÄDDoS¹¥»÷

      

9ÔÂ19ÈÕ£¬Äþ¾²¹«Ë¾ImpervaÐû²¼ÒÑÀֳɵÖÓùÏòÆä¿Í»§·¢ËÍÁËÁè¼Ý253ÒÚ´ÎÇëÇóµÄDDoS¹¥»÷¡£¹¥»÷µÄÄ¿±êÊÇÒ»¼ÒµçÐÅ·þÎñÌṩÉÌ£¬ÓÚ2022Äê6ÔÂ27ÈÕ¿ªÊ¼£¬·åֵΪÿÃë390Íò´ÎÇëÇó(RPS)£¬Æ½¾ùΪ180Íò´ÎRPS¡£·åÖµÁè¼Ý100ÍòRPSµÄ¹¥»÷ͨ³£Ö»Á¬Ðø¼¸Ãëµ½¼¸·ÖÖÓ£¬µ«´Ë´Î¹¥»÷Á¬ÐøÁËËĸö¶àСʱ¡£´Ë´Î¹¥»÷ÊÇÓɱ鲼180¸ö¹ú¼ÒºÍµØÓòµÄ½©Ê¬ÍøÂçÌᳫµÄ£¬ÆäÖдó¶àÊýIPµØÖ·Î»ÓÚÃÀ¹ú¡¢°ÍÎ÷ºÍÓ¡¶ÈÄáÎ÷ÑÇ¡£½©Ê¬ÍøÂçʹÓÃÁË170000¸ö±»Ñ¬È¾É豸£¬°üÂÞµ÷ÖÆ½âµ÷Æ÷ºÍÖÇÄÜÉãÏñÍ·µÈ¡£


https://www.imperva.com/blog/record-25-3-billion-request-multiplexing-attack-mitigated-by-imperva/


3¡¢VMwareºÍ΢ÈíÌáÐÑChromeloader½üÆÚµÄ¶ñÒâ¹¥»÷»î¶¯

      

¾ÝýÌå9ÔÂ20ÈÕ±¨µÀ£¬VMwareºÍMicrosoft·¢ÏÖChromeloader½üÆÚµÄ¹¥»÷»î¶¯»áÁ÷´«¶à¸ö¶ñÒâÈí¼þ¼Ò×塣΢ÈíÔÚÉÏÖÜÎåÅû¶ÁËÒ»Æðµã»÷ÆÛÕ©»î¶¯£¬ÀûÓÃChromeloader·Ö·¢ÖÖÖÖ¶ñÒâÈí¼þ£¬¹éÒòÓÚDEV-0796ÍŻVMwareÐû²¼Ò»·Ý³ÂËߣ¬ÏêÊöÁË×Ô8ÔÂÒÔÀ´·¢ÏֵĶà¸öChromeloader±äÌåµÄ¼¼Êõϸ½Ú¡£¸Ã¶ñÒâÈí¼þÖ÷ÒªÒÔISOÎļþµÄÐÎʽ·Ö·¢¶ñÒâä¯ÀÀÆ÷À©Õ¹¡¢node-WebKit¶ñÒâÈí¼þºÍÀÕË÷Èí¼þµÈ¡£


https://securityaffairs.co/wordpress/135949/malware/chromeloader-malware-campaigns.html


4¡¢SandwormÍÅ»ïαװ³ÉµçÐÅÌṩÉ̹¥»÷ÎÚ¿ËÀ¼µÄ×éÖ¯

     

Recorded FutureÔÚ9ÔÂ19ÈÕÅû¶Á˺ڿÍÍÅ»ïSandwormαװ³ÉµçÐÅÌṩÉ̹¥»÷ÎÚ¿ËÀ¼×éÖ¯µÄ»î¶¯¡£Sandworm±»ÃÀ¹úÕþ¸®¹éΪ¶íÂÞ˹GRUÍâ¹ú¾üÊÂÇ鱨²¿ÃŵÄÒ»²¿ÃÅ£¬ÔÚ½ñÄêÌᳫÁ˶à´Î¹¥»÷£¬°üÂÞ¶ÔÎÚ¿ËÀ¼ÄÜÔ´»ù´¡ÉèÊ©µÄ¹¥»÷¡£´Ó½ñÄê8Ô¿ªÊ¼£¬Ñо¿ÈËÔ±·¢ÏÖʹÓÃαװ³ÉÎÚ¿ËÀ¼µçÐÅ·þÎñÌṩÉ̵Ķ¯Ì¬DNSÓòµÄSandworm C2»ù´¡ÉèÊ©ÓÐËùÔö¼Ó£¬×î½üµÄ»î¶¯Ö¼ÔÚ½«Colibri LoaderºÍWarzone RATµÈÉÌÆ·¶ñÒâÈí¼þ°²×°µ½Ä¿±êµÄϵͳÉÏ¡£


https://www.recordedfuture.com/russia-nexus-uac-0113-emulating-telecommunication-providers-in-ukraine


5¡¢½ðÈڿƼ¼¹«Ë¾Revolut 5Íò¶à¿Í»§µÄ¸öÈËÐÅϢй¶

      

ýÌå9ÔÂ19ÈÕ³ÆRevolutÔâµ½¹¥»÷£¬Î´¾­ÊÚȨµÄµÚÈý·½·ÃÎÊÁË5Íò¶à¸ö¿Í»§µÄÐÅÏ¢¡£Revolut½¨Á¢ÓÚ2015Ä꣬ÊÇÒ»¼Ò½ðÈڿƼ¼¹«Ë¾£¬Ä¿Ç°ÎªÈ«Çò¿Í»§Ìá¹©ÒøÐС¢×ʽð¹ÜÀíºÍͶ×Ê·þÎñ¡£¹¥»÷·¢ÉúÔÚÒ»ÖÜǰ£¬Æ¾¾Ý³õ·¨Ê½²é½á¹û£¬¹¥»÷Õßͨ¹ýÉç»á¹¤³Ì¼¼Êõ·ÃÎÊÁËRevolutµÄÊý¾Ý¿â£¬Ó°ÏìÁ˸ù«Ë¾0.16%µÄ¿Í»§¡£´Ë´Îʼþй¶Á˿ͻ§µÄÐÕÃû¡¢µØÖ·¡¢Óʼþ¡¢µç»°ºÅÂë¡¢²¿ÃÅÖ§¸¶¿¨Êý¾ÝºÍÕË»§Êý¾ÝµÈ¡£


https://www.bleepingcomputer.com/news/security/revolut-hack-exposes-data-of-50-000-users-fuels-new-phishing-wave/


6¡¢KasperskyÐû²¼¹ØÓÚÑÇÌ«µØÓòÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß

      

9ÔÂ19ÈÕ£¬KasperskyÐû²¼¹ØÓÚÑÇÌ«µØÓòÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£¸Ã³ÂËßÖØµã·ÖÎöÁËÓ°ÏìÑÇÌ«µØÓò15¸ö¹ú¼ÒºÍµØÓòµÄ4700¶à¸ö×éÖ¯µÄÍⲿÍþвºÍÍøÂç·¸×ï»î¶¯µÄÊý¾Ý¡£³ÂËßÖ¸³ö£¬Áè¼ÝÊ®·ÖÖ®Ò»µÄ©¶´ÊÇProxyLogon£¬ÔÚÈÕ±¾43%δ´ò²¹¶¡µÄ·þÎñÖж¼·¢ÏÖÁËÕâ¸ö©¶´ £»16003¸öÔ¶³Ì·ÃÎʺ͹ÜÀí·þÎñ¿É¹©¹¥»÷ÕßʹÓã¬Õþ¸®»ú¹¹ÊÜÓ°Ïì×î´ó £»ÔÚ°µÍø£¬ºÚ¿Í¸üϲ»¶¹ºÖúͳöÊÛÀ´×Ô°Ä´óÀûÑÇ¡¢Öйú¡¢Ó¡¶ÈºÍÈÕ±¾µÄ×éÖ¯µÄ·ÃÎÊȨÏÞ¡£


https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/09/16113048/Kaspersky-DFI_V7_opt.pdf