ÃÀ¹úµÄRateForceÍøÕ¾Ô¼93 GBµÄÁè¼Ý25ÍòÌõ¼Ç¼й¶

Ðû²¼Ê±¼ä 2023-06-26

1¡¢ÃÀ¹úµÄRateForceÍøÕ¾Ô¼93 GBµÄÁè¼Ý25ÍòÌõ¼Ç¼й¶


¾ÝýÌå6ÔÂ22ÈÕ±¨µÀ £¬ÃÀ¹úÆû³µ±£ÏձȼÛÍøÕ¾RateForceй¶ÁË´óÁ¿Óû§PIIÐÅÏ¢ ¡£×ܹ²Ð¹Â¶ÁË96175¸öÎļþ¼Ð £¬ÆäÖаüÂÞ255756Ìõ¼Ç¼ £¬×ܾÞϸΪ93.93GB ¡£´Ë´Îй¶Ê¼þÁ¬ÐøÁËÖÁÉÙÁ½ÖÜ £¬Ô´ÓÚÒ»¸ö²»Äþ¾²µÄÊý¾Ý¿â £¬Éæ¼°ÖÖÖÖÎļþµÄɨÃè¼þºÍͼƬ £¬°üÂÞ³µÁ¾¹ÒºÅ¡¢¼ÝʻִÕÕ¡¢±£ÏÕ¿¨ºÍ³µÁ¾ËùÓÐȨµÈ ¡£½øÒ»·¨Ê½²é·¢ÏÖ £¬Êý¾Ý¿âÖб£µ¥µÄÖ÷Òª±£ÏÕ¹«Ë¾ÊÇUSA Underwriters ¡£USA Underwriters³ÎÇåµÀ £¬ËûÃÇÆ¸ÇëÁ˶ÀÁ¢µÄIT¹«Ë¾À´¹ÜÀíÆä»ù´¡ÉèÊ© £¬¶øÇÒ²»¸ºµ£¹ÜÀí̻¶µÄÊý¾Ý¿âµÄÈκÎÔðÈÎ ¡£Ä¿Ç° £¬Êý¾Ý¿âÒѱ»±£»¤ÆðÀ´ ¡£


https://www.hackread.com/rateforce-auto-insurance-data-leak/


2¡¢Ä¾Âí»¯³¬¼¶ÂíÀï°ÂÐÖµÜÓÎÏ·°²×°·¨Ê½Á÷´«¶àÖÖ¶ñÒâÈí¼þ


CybleÔÚ6ÔÂ23ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÊÊÓÃÓÚWindowsµÄľÂí»¯³¬¼¶ÂíÀï°ÂÐÖµÜÓÎÏ·°²×°·¨Ê½ £¬±»ÓÃÓÚÁ÷´«¶àÖÖ¶ñÒâÈí¼þ ¡£°üÂÞXMRÍÚ¿ó·¨Ê½¡¢SupremeBotÍÚ¿ó¿Í»§¶ËºÍ¿ªÔ´UmbralÇÔÈ¡·¨Ê½ ¡£Ñо¿ÈËÔ±Ö¸³ö £¬¹¥»÷ÕßÖ®ËùÒÔÕë¶ÔÓÎÏ·Íæ¼Ò £¬ÊÇÒòΪËûÃǾ­³£Ê¹ÓÃÇ¿´óµÄÓ²¼þ½øÐÐÓÎÏ· £¬Õâ·Ç³£ÊʺÏÍÚ¾ò¼ÓÃÜ»õ±Ò ¡£¹¥»÷Õ߸͝ÁËNSIS°²×°·¨Ê½Îļþ £¬Éú³ÉµÄ¿ÉÖ´ÐÐÎļþ°üÂ޺Ϸ¨µÄÓ¦ÓÃÒÔ¼°¶ñÒâ¿ÉÖ´ÐÐÎļþjava.exeºÍatom.exe ¡£°²×°Àֳɺó»áÆô¶¯ÓÎÏ· £¬²¢ÔÚºǫ́½øÐÐÍÚ¿ó ¡£


https://blog.cyble.com/2023/06/23/trojanized-super-mario-game-installer-spreads-supremebot-malware/


3¡¢FortinetÐÞ¸´FortiNAC RCE©¶´CVE-2023-33299


¾Ý6ÔÂ23ÈÕ±¨µÀ £¬FortinetÐû²¼Äþ¾²¸üР£¬ÐÞ¸´ÁËÆäÁãÐÅÈηÃÎʽâ¾ö·½°¸FortiNACÖеķ´ÐòÁл¯Â©¶´ ¡£¸Ã©¶´×·×ÙΪCVE-2023-33299 £¬CVSSÆÀ·ÖΪ9.6 ¡£FortinetµÄÄþ¾²×ÉѯÖÐÖ¸³ö £¬FortiNACÖеIJ»ÐÐÐÅÊý¾Ý·´ÐòÁл¯Â©¶´¿ÉÄܵ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓÃÌØÖÆµÄTCP/1050·þÎñÇëÇóÖ´ÐÐδ¾­ÊÚȨµÄ´úÂë»òÃüÁî ¡£¹©Ó¦ÉÌûÓÐÌṩ»º½â½¨Òé £¬Òò´Ë½¨ÒéÓû§Á¢¼´Ó¦ÓÿÉÓõÄÄþ¾²¸üР¡£


https://securityaffairs.com/147770/security/fortinet-fortinac-critical-flaw.html


4¡¢Ñо¿ÈËÔ±·¢ÏÖеÄPindOS·Ö·¢IcedIDºÍBumblebee


Deep InstinctÔÚ6ÔÂ22ÈÕÅû¶ÁËÒ»ÖÖеÄJavaScript dropper PindOS £¬»á·Ö·¢¶ñÒâÈí¼þBumblebeeºÍIcedID ¡£BumblebeeÊÇÒ»ÖÖ¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½ £¬IcedIDÊÇÒ»ÖÖÄ£¿é»¯ÒøÐжñÒâÈí¼þ ¡£¶ÔPindOSµÄÔ´´úÂë·ÖÎöÏÔʾ £¬Ëü°üÂÞ¶íÓïµÄ×¢ÊÍ ¡£Ñо¿ÈËÔ±ÌåÏÖ £¬Ò»µ©È¥³ý»ìÏý £¬¸Ãdropper¾Í·Ç³£¼òµ¥ ¡£ËüÓÉÒ»¸öº¯Êýexec×é³É £¬°üÂÞËĸö²ÎÊý £¬UserAgent¡¢URL1¡¢URL2ºÍRunDLL £¬ÆäÖÐURL2×÷ΪURL1ÎÞ·¨»ñÈ¡DLLʱµÄºó±¸ ¡£


https://www.deepinstinct.com/blog/pindos-new-javascript-dropper-delivering-bumblebee-and-icedid


5¡¢Unit 42¹ûÈ»ÀûÓöà¸öIoT©¶´µÄÐÂÒ»ÂÖMirai»î¶¯


6ÔÂ22ÈÕ £¬Unit 42¹ûÈ»ÁËÀûÓöà¸öIoT©¶´µÄÐÂÒ»ÂÖMirai»î¶¯ ¡£¸Ã»î¶¯×Ô3ÔÂ14ÈÕ¿ªÊ¼»îÔ¾ £¬²¢ÔÚ4ÔºÍ6Ô·ºÆð¼¤Ôö ¡£ÕâÒ»±äÌåÕë¶Ô22¸ö©¶´ £¬Ö¼ÔÚ¿ØÖÆD-Link¡¢Arris¡¢Zyxel¡¢TP-Link¡¢Tenda¡¢NetgearºÍMediaTekµÈÉ豸 £¬²¢ÀûÓÃËüÃÇÖ´ÐÐDDoS¹¥»÷ ¡£Unit 42»¹Ö¸³ö £¬¸ÃMirai±äÌå²»¾ß±¸±©Á¦ÆÆ½âtelnet/SSHµÇ¼ƾ¾ÝµÄ¹¦Ð§ £¬Òò´ËÆä·Ö·¢ÍêÈ«ÒÀÀµÓÚÔËÓªÈËÔ±ÊÖ¶¯ÀûÓé¶´ ¡£


https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/


6¡¢SecuronixÅû¶Õë¶ÔÓ¡¶ÈºÍÃÀ¹úµÄµöÓã»î¶¯MULTI#STORM


6ÔÂ21ÈÕ £¬SecuronixÅû¶ÁË´úºÅΪMULTI#STORMµÄÐÂÒ»ÂÖµöÓã»î¶¯ £¬Ö÷ÒªÕë¶ÔÓ¡¶ÈºÍÃÀ¹ú ¡£¸Ã»î¶¯ÀûÓÃÁËJavaScriptÎļþÔÚ±»Ñ¬È¾µÄϵͳÉÏÁ÷´«Ô¶³Ì·ÃÎÊľÂí ¡£¹¥»÷Á´Ê¼ÓÚÒ»¸öZIPÎļþREQUEST.zipÖб»ÑÏÖØ»ìÏýµÄJavaScriptÎļþREQUEST.js ¡£×îÖջᰲװ¶à¸öÆæÌØµÄRAT £¬ÈçWarzone RATºÍQuasar RAT ¡£ÔÚѬȾÁ´µÄ²îÒì½×¶Î £¬Á½Õß¶¼±»ÓÃÓÚC2 ¡£´ËÍâ £¬ÂôÁ¦×î³õÈëÇÖÖ÷»úµÄ¼ÓÔØ·¨Ê½µÄ¹¦Ð§ÓëDBatLoader·Ç³£ÏàËÆ £¬µ«ËüÓÃPython¿ª·¢ £¬²¢Ê¹ÓÃPyInstaller´ò°ü £¬ÀûÓÃÁËһЩÅÓ´óµÄ¼¼ÊõÀ´½¨Á¢³Ö¾ÃÐÔ £¬²¢ÔÚ·Ö·¢payloadÖ®Ç°ÈÆ¹ý¼ì²â ¡£


https://www.securonix.com/securonix-threat-labs-security-advisory-multistorm-leverages-python-based-loader-as-onedrive-utilities-to-drop-rat-payloads/