ºÚ¿ÍÔÚÈÈÃźڿÍÂÛ̳ÉÏÉù³Æ¿ÇÅÆÊý¾ÝÔ⵽й¶
Ðû²¼Ê±¼ä 2024-05-315ÔÂ30ÈÕ£¬ÁîÈËÕ𾪵ÄÊÇ£¬Ò»ÃûÍþвÐÐΪÕßÉæÏÓй¶ÁËÊÀ½çÁìÏÈÄÜÔ´¹«Ë¾Ö®Ò»¿ÇÅƵÄÃô¸ÐÊý¾Ý¡£Æ¾¾Ý Data Web Informer µÄÍÆÎÄ£¬2024 Äê 5 ÔµÄÊý¾Ý±»Ðû²¼ÔÚÒ»¸öÁ÷ÐеĺڿÍÂÛ̳ÉÏ£¬Òý·¢ÁËÈËÃǶÔÍøÂçÄþ¾²ºÍÊý¾ÝÒþ˽µÄÑÏÖص£ÓÇ¡£¾Ý±¨µÀ£¬Ð¹Â¶µÄÐÅÏ¢°üÂÞ´óÁ¿¸öÈËÐÅÏ¢ºÍÃô¸ÐÊý¾Ý¡£Ð¹Â¶µÄÊý¾Ý°üÂÞ£º¹ºÎïÕß´úÂë¡¢Ãû×Ö¡¢ÐÕÊÏ¡¢×´Ì¬¡¢¹ºÎïÕßµç×ÓÓʼþ¡¢ÁªÏµÊÖ»ú¡¢ÓÊÕþ±àÂë¡¢»¨ÃÛ¡¢½¼Çø¡¢ÖÝ¡¢Õ¾µãµØÖ·¡¢½¼Çø 1¡¢¹ú¼Ò¡¢Õ¾µãÃû³Æ¡¢ÉϴεǼ¡¢¸¶¿îºÍлá±àºÅ¡£´Ë´ÎйÃÜʼþ¿ÉÄÜ»á¶Ô¿ÇÅƼ°Æä¿Í»§Ôì³ÉÑÏÖØÓ°Ï졣й¶Èç´ËÏêϸµÄ¸öÈËÐÅÏ¢¿ÉÄܻᵼÖÂÉí·Ý͵ÇÔ¡¢½ðÈÚÆÛÕ©ºÍÆäËû¶ñÒâ»î¶¯¡£½¨Òé¿Í»§ÃÜÇмà¿ØËûÃǵÄÕË»§²¢Á¢¼´³ÂËß¿ÉÒɻ¡£½ØÖÁÄ¿Ç°£¬¿ÇÅÆÉÐδ¾Í´Ë´ÎйÃÜʼþ·¢±í¹Ù·½ÉùÃ÷¡£²»Í⣬¸Ã¹«Ë¾Ô¤¼Æ½«Æô¶¯ÄÚ²¿ÊӲ죬²¢ÓëÍøÂçÄþ¾²×¨¼ÒºÏ×÷£¬ÆÀ¹ÀÎ¥¹æµÄˮƽ²¢¼õÇáÈκÎDZÔÚË𺦡£
https://gbhackers.com/claiming-shell-data-breach/
2. TicketmasterÔâºÚ¿Í¹¥»÷£¬Áè¼Ý5 ÒÚÓû§Êý¾ÝÐÅϢй¶
5ÔÂ30ÈÕ£¬¾Ý±¨µÀ£¬±¾ÖÜÕýÔÚÊÓ²ìµÄÒ»ÆðÍøÂçʼþÖУ¬Áè¼Ý 5 ÒÚ Ticketmaster Óû§µÄ¸öÈ˺ÍÐÅÓÿ¨Êý¾ÝÔ⵽й¶¡£¾Ý±¨µÀ£¬°Ä´óÀûÑÇÕþ¸®ÕýÔÚÓë Live Nation ºÍ Ticketmaster ºÏ×÷½â¾ö´Ëʼþ£¬µ«½ØÖÁÖÜÈýÉÏÎ磬Åû¶µÄϸ½ÚÓÐÏÞ¡£¾Ý¸ÃÐÂÎÅýÌ屨µÀ£¬°Ä´óÀûÑÇÄÚÕþ²¿¸æËß ABC£¬ËûÃÇÕýÔÚÓë Ticketmaster ºÏ×÷Á˽â´ËÊ¡£Ticketmaster »òÆäĸ¹«Ë¾ÉÐδ¾Í´ËÊ·¢±íÈκÎÉùÃ÷¡£ºÚ¿Í×éÖ¯ ShinyHunters Éù³ÆÒÑÆƽâ Ticketmaster ϵͳ²¢»ñÈ¡ÁËÔ¼ 1.3 TB µÄÊý¾Ý£¬ÆäÖаüÂÞÐÕÃû¡¢µØÖ·¡¢ÐÅÓÿ¨ºÅ¡¢µç»°ºÅÂëºÍ¸¶¿îÏêϸÐÅÏ¢¡£¾Ý˵ÕâЩÐÅÏ¢ÔÚ°µÍøÉϳöÊÛ£¬Òª¼Û 50 ÍòÃÀÔª¡£ÔçÆÚ³ÂËßÏÔʾ£¬Óû§Êý¾ÝÉæ¼°È«Çò 5.6 ÒÚ¿Í»§£¬µ«Éв»Çå³þÄÄЩÊг¡Êܵ½Ó°Ï죨»òÊÜÓ°ÏìµÄÏû·ÑÕßÖÐÓм¸¶àÀ´×ÔÄÄЩÊг¡£©¡£ÏÔÈ»£¬¿¼Âǵ½Éæ¼°µÄ¸ß¶ÈÃô¸ÐÊý¾Ý£¬ÈκÎÊÜÓ°ÏìµÄÏû·ÑÕߵķçÏÕ¶¼·Ç³£¸ß¡£
https://www.ticketnews.com/2024/05/ticketmaster-hack-data-of-half-a-billion-users-up-for-ransom/
3. XWorm v5.6 ¶ñÒâÈí¼þͨ¹ý Webhards ½øÐÐÁ÷´«
5ÔÂ30ÈÕ£¬°²ÊµÑéÊÒÄþ¾²Ç鱨ÖÐÐÄ£¨ASEC£©ÔÚ¼à¿Øº«¹ú¶ñÒâÈí¼þµÄÁ÷´«Ô´Ê±£¬×î½ü·¢ÏÖαװ³É³ÉÈËÓÎÏ·µÄXWorm v5.6¶ñÒâÈí¼þÕýÔÚͨ¹ýÍøÂçÓ²Å̽øÐÐÁ÷´«¡£ÍøÂçÓ²Å̺ÍÖÖ×ÓÊǺ«¹ú¶ñÒâÈí¼þÁ÷´«µÄ³£ÓÃƽ̨¡£¹¥»÷Õßͨ³£Ê¹ÓÃÈÝÒ×»ñµÃµÄ¶ñÒâÈí¼þ£¬ÀýÈç njRAT ºÍ UDP RAT£¬²¢½«Æäαװ³É°üÂÞÓÎÏ·»ò³ÉÈËÄÚÈÝÔÚÄÚµÄÕý³£·¨Ê½½øÐзַ¢¡£XWorm v5.6 Ò²¿ÉÒÔ´Ó GitHub µÈƽ̨ÇáËÉ»ñÈ¡¡£ÏÂÔز¢½âѹÓÎÏ·Îļþºó£¬»áµÃµ½ Start.exe¡£ËäÈ»¿´ÆðÀ´ÏñÊǺϷ¨µÄÓÎÏ·Æô¶¯Æ÷Îļþ£¬µ«Ö´ÐÐÓÎÏ·µÄ .exe ÎļþÊǵ¥¶ÀÉú³É²¢ÔËÐеģ¬¶øÇÒαװ³É SoundP2.muc µÄ¼ÓÔØ·¨Ê½¶ñÒâÈí¼þÒ²»á±»Ö´ÐС£Ö´ÐÐ Start.exe ²»»áÁ¢¼´ÔËÐжñÒâÈí¼þ»òÓÎÏ·£»ËüÃÇ»áÔÚÄú°´Ï¡°¿ªÊ¼ÓÎÏ·£¡¡±°´Å¥Ê±Ö´ÐС£ÕâÖÖ¼ÆıËƺõÊÇΪÁËÈƹýɳºÐģʽ¡£SoundP2.muc Ò²±»¸´ÖƲ¢Õ³Ìùµ½ Windows Îļþ¼ÐÖУ¬²¢Ìí¼Óµ½×¢²á±íÖÐÒÔ±ã×Ô¶¯Ö´ÐС£
https://asec.ahnlab.com/en/66099/
4. PyPI¶ñÒâÈí¼þPytoileurÇÔÈ¡¼ÓÃÜ»õ±Ò²¢Èƹý¼ì²â
5ÔÂ31ÈÕ£¬ÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁË Python Èí¼þ°üË÷Òý£¨PyPI£©ÉϵĶñÒâÈí¼þ°üpytoileur¡£¸ÃÈí¼þ°üαװ³ÉÓà Python ±àдµÄ API ¹ÜÀí¹¤¾ß£¬Òþ²ØÁËÏÂÔغͰ²×°Ä¾Âí Windows ¶þ½øÖÆÎļþµÄ´úÂë¡£ÕâЩ¶þ½øÖÆÎļþÄܹ»½øÐмàÊÓ¡¢ÊµÏÖ³Ö¾ÃÐÔ²¢ÇÔÈ¡¼ÓÃÜ»õ±Ò¡£¸ÃÈí¼þ°ü±» Sonatype µÄ×Ô¶¯¶ñÒâÈí¼þ¼ì²âϵͳ·¢ÏÖ£¬²¢ÔÚ±»±êÖ¾ºóѸËÙ±»É¾³ý¡£pytoileur Èí¼þ°üÔÚ±»ÒƳýÇ°Òѱ»ÏÂÔØ 264 ´Î£¬ËüʹÓÃÁËÆÛÆÐÔ¼¼ÊõÀ´ÖÆÖ¹±»¼ì²âµ½¡£ËüµÄÔªÊý¾Ý½«ÆäÃèÊöΪ¡°¿áìÅÈí¼þ°ü¡±£¬Ê¹ÓÃÒ»ÖÖ¼Æı£¬¼´¸øÈí¼þ°üÌùÉÏÎüÒýÈ˵ÄÄ£ºýÃèÊö±êÇ©£¬ÒÔÓÕʹ¿ª·¢ÈËÔ±ÏÂÔØËüÃÇ¡£Sonatype ½ñÌìÐû²¼µÄÒ»·Ý×Éѯ³ÂËßÖÐÃèÊöÁ˽øÒ»²½µÄ¼ì²é£¬·¢ÏÖÈí¼þ°ü°²×°ÎļþÖÐÒþ²Ø×Å´óÁ¿¿Õ¸ñËùÑڸǵĴúÂë¡£¸Ã´úÂëÖ´ÐÐÁËÒ»¸ö base64 ±àÂëµÄÓÐЧ¸ºÔØ£¬¸Ã¸ºÔØ´ÓÍⲿ·þÎñÆ÷¼ìË÷Á˶ñÒâ¿ÉÖ´ÐÐÎļþ¡£ÏÂÔصĶþ½øÖÆÎļþ¡°Runtime.exe¡±ÀûÓà PowerShell ºÍ VBScript ÃüÁî½øÐÐ×ÔÎÒ°²×°£¬È·±£ÔÚÊÜѬȾµÄϵͳÖг־ôæÔÚ¡£Ëü½ÓÄÉÖÖÖÖ·´¼ì²â´ëÊ©À´ÌÓ±ÜÄþ¾²Ñо¿ÈËÔ±µÄ·ÖÎö¡£
https://www.infosecurity-magazine.com/news/pypi-malware-pytoileur-steals/
5. °ÍÎ÷ÒøÐгÉΪ AllaKore RAT бäÖÖ AllaSenha µÄÄ¿±ê
5ÔÂ29ÈÕ£¬°ÍÎ÷ÒøÐлú×é³ÉΪлµÄÄ¿±ê£¬¸Ã»î¶¯·Ö·¢»ùÓÚ Windows µÄAllaKoreÔ¶³Ì·ÃÎÊľÂí (RAT)µÄ¶¨ÖƱäÖÖAllaSenha¡£·¨¹úÍøÂçÄþ¾²¹«Ë¾ HarfangLabÔÚÒ»·Ý¼¼Êõ·ÖÎöÖÐÌåÏÖ£¬¸Ã¶ñÒâÈí¼þ¡°×¨ÃÅÓÃÓÚÇÔÈ¡·ÃÎÊ°ÍÎ÷ÒøÐÐÕË»§ËùÐèµÄƾ֤£¬²¢ÀûÓà Azure ÔÆ×÷ΪÃüÁîºÍ¿ØÖÆ (C2) »ù´¡ÉèÊ©¡±¡£´Ë´Î¹¥»÷µÄÄ¿±ê°üÂÞ°ÍÎ÷ÒøÐС¢Bradesco¡¢Èø·òÀÒøÐС¢Caixa Econ?mica Federal¡¢Ita¨² Unibanco¡¢Sicoob ºÍ Sicredi µÈÒøÐС£ËäÈ»ÉÐδµÃµ½Ã÷ȷ֤ʵ£¬µ«×î³õµÄ·ÃÎÊÔØÌåÖ¸ÏòÁ˵öÓãÓʼþÖÐʹÓöñÒâÁ´½Ó¡£¹¥»÷µÄÆðµãÊÇÒ»¸ö¶ñÒâµÄ Windows ¿ì½Ý·½Ê½ (LNK) Îļþ£¬¸ÃÎļþαװ³É PDF Îĵµ£¨¡°NotaFiscal.pdf.lnk¡±£©£¬ÖÁÉÙ×Ô 2024 Äê 3 ÔÂÆðÍйÜÔÚ WebDAV ·þÎñÆ÷ÉÏ¡£»¹ÓÐÖ¤¾Ý±íÃ÷£¬¸Ã»î¶¯±³ºóµÄÍþвÐÐΪÕß֮ǰÔøÀÄÓà Autodesk A360 Drive ºÍ GitHub µÈºÏ·¨·þÎñÀ´ÍйÜÓÐЧ¸ºÔØ¡£
https://thehackernews.com/2024/05/brazilian-banks-targeted-by-new.html
6. ÀûÓÃDora RATÕë¶Ôº«¹úÆóÒµ£¨Andariel Group£©µÄAPT¹¥»÷
5ÔÂ30ÈÕ£¬AhnLab Äþ¾²Ç鱨ÖÐÐÄ (ASEC) ×î½ü·¢ÏÖÁËÕë¶Ôº«¹ú¹«Ë¾ºÍ»ú¹¹µÄ Andariel APT ¹¥»÷°¸Àý¡£Ä¿±ê×éÖ¯°üÂÞº«¹úµÄ½ÌÓý»ú¹¹ÒÔ¼°ÖÆÔìºÍ½¨ÖþÆóÒµ¡£¹¥»÷ʹÓÃÁ˺óÃÅÉϵļüÅ̼ǼÆ÷¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½ºÍÊðÀí¹¤¾ß¡£ÍþвÐÐΪÕß¿ÉÄÜʹÓÃÕâЩ¶ñÒâÈí¼þÀ´¿ØÖƺÍÇÔÈ¡ÊÜѬȾϵͳµÄÊý¾Ý¡£´Ë´Î¹¥»÷ʹÓÃÁË Andariel ¼¯ÍŹýÈ¥°¸ÀýÖз¢ÏֵĶñÒâÈí¼þ£¬ÆäÖÐ×îÒýÈËעĿµÄÊÇ Nestdoor£¬ÕâÊDZ¾ÎÄÖÐÌáµ½µÄºóÃÅ¡£ÆäËû°¸Àý°üÂÞÌí¼Ó Web Shell¡£Lazarus ¼¯ÍÅÏÈÇ°¹¥»÷Öз¢ÏÖµÄÊðÀí¹¤¾ßÒ²±»Ê¹Ó㬾¡¹ÜËüÃǵÄÎļþÓ뵱ǰ°¸Àý²¢²»Ïàͬ¡£ÔÚ¹¥»÷¹ý³ÌÖеÄÖÚ¶àÖ¤¾ÝÖУ¬Ò»¸öʵ¼Ê±»Ö¤ÊµµÄ°¸ÀýÉ漰ʹÓÃÔËÐÐ Apache Tomcat ·þÎñÆ÷µÄ Web ·þÎñÆ÷·Ö·¢¶ñÒâÈí¼þ¡£ÓÉÓÚÓÐÎÊÌâµÄϵͳÔËÐеÄÊÇ 2013 °æ Apache Tomcat£¬Òò´ËÈÝÒ×Êܵ½ÖÖÖÖ©¶´¹¥»÷¡£ÍþвÐÐΪÕßʹÓøà Web ·þÎñÆ÷°²×°ºóÃÅ¡¢ÊðÀí¹¤¾ßµÈ¡£
https://asec.ahnlab.com/en/66088/