ShroudedSnooperÀûÓÃHTTPSnoop¹¥»÷Öж«µçÐŹ«Ë¾

°ä²¼¹¦·ò 2023-09-21

1¡¢ShroudedSnooperÀûÓÃHTTPSnoop¹¥»÷Öж«µçÐŹ«Ë¾


¾Ý9ÔÂ19ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬£¬Cisco Talos·¢ÏÖShroudedSnooperÀûÓÃкóÃÅHTTPSnoop¹¥»÷Öж«µçÐÅÌṩÉÌ¡£¡£¡£¡£¡£ ¡£HTTPSnoopÓëWindows HTTPÄÚºËÇý¶¯·¨Ê½ºÍÉ豸½»»¥£¬£¬£¬ £¬£¬£¬£¬£¬ÕìÌýÌØ¶¨HTTP(S) URLµÄ´«ÈëÒªÇ󡣡£¡£¡£¡£ ¡£×êÑÐÈËÔ±»¹·¢ÏÖÁËPipeSnoop£¬£¬£¬ £¬£¬£¬£¬£¬ËüÄܹ»½ÓÊÜÀ´×Ô¶¨Ãû¹Ü·µÄËÁÒâshellcode²¢ÔÚ±»Ï°È¾µÄÉ豸ÉÏÖ´ÐÐËü¡£¡£¡£¡£¡£ ¡£ÕâÁ½¸öÖ²È뷨ʽ¶¼¼Ù×°³ÉPalo Alto NetworksµÄCortex XDR²úÆ·µÄ°²È«×é¼þÀ´Èƹý¼ì²â¡£¡£¡£¡£¡£ ¡£


https://blog.talosintelligence.com/introducing-shrouded-snooper/


2¡¢¼ÓÄôóµÄ×ÔÖ÷Öµ»úÖÕ¶ËÔâµ½DDoS¹¥»÷Èë¾³³öÏÖÎÊÌâ


¾ÝýÌå9ÔÂ20ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬£¬¼ÓÄôóµÄ×ÔÖ÷Öµ»úÖÕ¶ËÔâµ½DDoS¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂÈë¾³³öÏÖÎÊÌâ¡£¡£¡£¡£¡£ ¡£¸ÃÊÂÎñ²úÉúÔÚÉÏÖÜÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬¼ÓÄôóÈ«¹ú¸÷µØµÄ±ßÚï²é³­Õ¾Öµ»úͤµÄÍÆËã»ú³öÏÖ¹ÊÕÏ£¬£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂÈë¾³´î¿Í°ìÀíÊÖÐøµÄËٶȼõÂýÁËÒ»¸ö¶àÓ×ʱ¡£¡£¡£¡£¡£ ¡£¼ÓÄôó±ßÚï·þÎñ¾Ö£¨CBSA£©±¾Öܶþ°µÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬Ó°Ïì»ú³¡×ÔÖ÷·þÎñÖն˺͵ç×ӵǻú¿ÚµÄÏνÓÎÊÌâÊÇDDoS¹¥»÷µ¼Öµġ£¡£¡£¡£¡£ ¡£NoName057ÔÚTelegramÉϰ䷢¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬ÕâÖÖ¹¥»÷¶Ô¹ú¶È»ù´¡ÉèÊ©²úÉúÕæÕýÓ°ÏìµÄÇé¿ö¼´±ã²»ÊǵÚÒ»´Î£¬£¬£¬ £¬£¬£¬£¬£¬Ò²ÊǺ±¼ûµÄ¡£¡£¡£¡£¡£ ¡£


https://www.databreaches.net/outage-at-canadian-airports-was-from-a-ddos-attack/


3¡¢Unit42·¢ÏÖ¼ÙCVE-2023-40477 PoC·Ö·¢VenomRAT


Unit42ÔÚ9ÔÂ19ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öαÔìµÄWinRAR·ì϶µÄPoC£¬£¬£¬ £¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢VenomRAT¡£¡£¡£¡£¡£ ¡£8ÔÂ17ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬Zero Day Initiative¹«¿ªÁËWinRARÖеÄRCE·ì϶£¨CVE-2023-40477£©£¬£¬£¬ £¬£¬£¬£¬£¬ºÚ¿ÍhalersplonkÓÚËÄÌìºóÏòÆäGitHub´æ´¢¿âÌá½»ÁËÒ»¸öαÔìµÄPoC¡£¡£¡£¡£¡£ ¡£¸ÃPoCÏÖʵÉÏÊǶÔGeoServerÖеÄSQL×¢Èë·ì϶£¨CVE-2023-25157£©µÄPoCµÄÅú¸Ä¡£¡£¡£¡£¡£ ¡£Ö´ÐÐʱ£¬£¬£¬ £¬£¬£¬£¬£¬PoC²»»áÔËÐзì϶ÀûÓ÷¨Ê½£¬£¬£¬ £¬£¬£¬£¬£¬¶øÊÇÆô¶¯ÁËÒ»¸öϰȾÁ´À´×°ÖÃVenomRAT payload¡£¡£¡£¡£¡£ ¡£Unit42ÒÔΪ¹¥»÷Õß²¢²»ÊÇרÃÅÕë¶Ô×êÑÐÈËÔ±µÄ£¬£¬£¬ £¬£¬£¬£¬£¬Ïà·´£¬£¬£¬ £¬£¬£¬£¬£¬¿ÉÄÜÊǵ«Ô¸¹¥»÷ÆäËûÊÔIJÀûÓÃзì϶µÄ·¸·¨·Ö×Ó¡£¡£¡£¡£¡£ ¡£


https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/


4¡¢ºÚÝ®Åû¶Õë¶Ô±±ÃÀºÍÑÇÌ«µØÓòµÄ»î¶¯Silent Skimmer


9ÔÂ18ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬ºÚÝ®Åû¶ÁËÒ»¸öÃûΪSilent SkimmerµÄл£¬£¬£¬ £¬£¬£¬£¬£¬ÖØÒªÕë¶Ô±±ÃÀºÍÑÇÌ«µØÓòµÄÔÚÏßÖ§¸¶ÆóÒµ¡£¡£¡£¡£¡£ ¡£¸Ã»î¶¯ÒѳÖÐøÒ»Äê¶à£¬£¬£¬ £¬£¬£¬£¬£¬Õë¶ÔÍйܻò´´½¨Ö§¸¶»ù´¡ÉèÊ©µÄ·ÖÆçÒµÒµ¡£¡£¡£¡£¡£ ¡£¹¥»÷ÕßÀûÓÃWebÀûÓûñµÃ³õʼ½Ó¼ûȨÏÞ£¬£¬£¬ £¬£¬£¬£¬£¬¶øºó²¿Êð¸÷À๤¾ßºÍ¼¼Êõ£¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬¿ªÔ´¹¤¾ßºÍLOLBAS£¬£¬£¬ £¬£¬£¬£¬£¬ËùÓй¤¾ßºÍpayload¶¼ÍйÜÔÚVPSÉϵÄHTTPÎļþ·þÎñÆ÷(HFS)ÖÓ×£¡£¡£¡£¡£ ¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃASP.NET AJAXµÄ.NET·´ÐòÁл¯·ì϶(CVE-2019-18935)ÔÚ·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£ ¡£¸Ã»î¶¯Ö÷ÕÅÊÇÔÚÖ¸±êʵÌåµÄ¸¶¿î½áÕËÒ³ÃæÉϲ¿Êðweb skimmer£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔÇÔÈ¡Óû§Õ˵¥ºÍÐÅÓþ¿¨ÐÅÏ¢µÈ²ÆÕþÊý¾Ý¡£¡£¡£¡£¡£ ¡£


https://blogs.blackberry.com/en/2023/09/silent-skimmer-online-payment-scraping-campaign-shifts-targets-from-apac-to-nala


5¡¢¹ú¼ÊÐÌÊ·¨Ôº£¨ICC£©Ð¹Â©ÆäϵͳÔâµ½ºÚ¿ÍÈëÇÖ    


ýÌå9ÔÂ19ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬£¬¹ú¼ÊÐÌÊ·¨Ôº£¨ICC£©Ð¹Â©ÆäϵͳÔâµ½Á˺ڿÍÈëÇÖ¡£¡£¡£¡£¡£ ¡£·¨ÔºÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬ÉÏÖÜÄ©£¬£¬£¬ £¬£¬£¬£¬£¬ICCµÄ·þÎñ²¿Ãżì²âµ½Ó°ÏìÆäÐÅϢϵͳµÄÒì³£»£»£»£»£»£»£»£»î¶¯£¬£¬£¬ £¬£¬£¬£¬£¬ÒÑÁ¢¼´²ÉÈ¡´ëʩӦ¶ÔÕâÒ»ÍøÂ簲ȫÊÂÎñ²¢¼õÇáÆäÓ°Ïì¡£¡£¡£¡£¡£ ¡£Ä¿Ç°£¬£¬£¬ £¬£¬£¬£¬£¬»¹Ã»ÓйØÓÚÍøÂç¹¥»÷µÄÐÔÖʺͶÔICCϵͳµÄÓ°ÏìˮƽµÄÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬£¬Ò²Ã»ÓйØÓÚ¹¥»÷ÕßÊÇ·ñ½Ó¼û»òÇÔÈ¡ÁËÊý¾Ý»òÎļþµÄÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¸Ã»ú¹¹°µÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬»áÓÅÏÈ˼¿¼È·±£·¨ÔºµÄÖ÷Ì⹤×÷³ÖÐø½øÐУ¬£¬£¬ £¬£¬£¬£¬£¬²¢½«ÔÚĿǰ½øÐеÄÏÖÓй¤×÷µÄ»ù´¡ÉϼÓÇ¿ÆäÍøÂ簲ȫ¿ò¼Ü£¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬¼Ó¿ìÔÆ¼¼ÊõµÄʹÓᣡ£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/hackers-breached-international-criminal-courts-systems-last-week/


6¡¢Check Point°ä²¼¹ØÓÚRemcosºÍGuLoaderµÄ·ÖÎö»ã±¨


9ÔÂ19ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬Check Point°ä²¼Á˹ØÓÚRemcosºÍGuLoaderµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£ÕâÁ½¸ö·¨Ê½±»¶¨Î»ÎªºÏ·¨¹¤¾ß£¬£¬£¬ £¬£¬£¬£¬£¬¹ÌÈ»Âô¼ÒÒ²Ðû³ÆÕâЩ¹¤¾ßÖ»ÄܺϷ¨Ê¹Ó㬣¬£¬ £¬£¬£¬£¬£¬µ«ÊÂʵÊÇËûÃǵÄÖØÒª¿Í»§ÕýÊÇÍøÂç·¸×ï·Ö×Ó¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±·¢ÏÖÁ½ÕßÖ®¼ä´æÔÚÇ×êǵÄÁªÏµ£¬£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚRemcosºÜÈÝÒ×±»É±¶¾Èí¼þ¼ì²âµ½£¬£¬£¬ £¬£¬£¬£¬£¬Òò¶øºÜÄÑÓÃÓÚ¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÊÇGuLoader¿ÉÓÃÓÚÔ®ÊÔìäÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£ ¡£»£»£»£»£»£»£»£»¯ÃûΪEMIN§ïMµÄÈËÖÎÀíןϷ¨ÍøÕ¾BreakingSecurityºÍVgoStore£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔÐÂÃû³ÆTheProtect¹«¿ªÏúÊÛRemcosºÍGuLoader¡£¡£¡£¡£¡£ ¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬£¬EMIN§ïM»¹Ôø²Î¼ÓFormbookºÍAmadey LoaderµÈ¶ñÒâÈí¼þµÄ´«²¼¡£¡£¡£¡£¡£ ¡£


https://research.checkpoint.com/2023/unveiling-the-shadows-the-dark-alliance-between-guloader-and-remcos/