ÎÚ¿ËÀ¼ÖÁÉÙ11¼ÒµçÐŹ«Ë¾Ôâµ½¹¥»÷µ¼Ö·þÎñÁÙʱÖжÏ

°ä²¼¹¦·ò 2023-10-18

1¡¢ÎÚ¿ËÀ¼ÖÁÉÙ11¼ÒµçÐŹ«Ë¾Ôâµ½¹¥»÷µ¼Ö·þÎñÁÙʱÖжÏ


¾ÝýÌå10ÔÂ17ÈÕ±¨Â·£¬ £¬£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼´óÁ¿µçÐŹ«Ë¾Ôâµ½¹¥»÷¡£¡£ ¡£¡£¡£ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××é(CERT-UA)й©£¬ £¬£¬£¬£¬£¬£¬£¬5ÔÂ11ÈÕÖÁ9ÔÂ27ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÍŻ׷×ÙΪUAC-0165£©ÈëÇÖÁËÖÁÉÙ11¼ÒµçÕÛ·þÎñÌṩÉ̵ÄÐÅÏ¢ºÍͨѶϵͳ£¨ICS£©£¬ £¬£¬£¬£¬£¬£¬£¬µ¼Ö¿ͻ§·þÎñÖжÏ¡£¡£ ¡£¡£¡£¹¥»÷Ê×ÏÈÀûÓù¤¾ßmasscan¶ÔÖ¸±êÍøÂç½øÐпúËÅѰÕÒδ±£»£»£»£»£»£»¤µÄRDP»òSSH½Ó¿Ú£¬ £¬£¬£¬£¬£¬£¬£¬¶øºóʹÓÃffuf¡¢dirbuster¡¢gowitnessºÍnmapµÈ¹¤¾ßÀ´¼ìË÷Web·þÎñÖеķì϶¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±ÔÚ±»ÈëÇÖµÄISPϵͳÖл¹·¢ÏÖÁËÁ½¸öºóÃÅ£¬ £¬£¬£¬£¬£¬£¬£¬¼´PoemgateºÍPoseidon¡£¡£ ¡£¡£¡£


https://thehackernews.com/2023/10/cert-ua-reports-11-ukrainian-telecom.html


2¡¢ÃÀ¹ú¿°ÈøË¹Öݸ÷µØ·¨ÔºÔâµ½ÀÕË÷¹¥»÷ÔËÓªÊܵ½Ó°Ïì


ýÌå10ÔÂ16Èճƣ¬ £¬£¬£¬£¬£¬£¬£¬ÔÚÔâµ½ÀÕË÷¹¥»÷ºó£¬ £¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú¿°ÈøË¹Öݸ÷µØµÄ·¨ÔºÃæ¶Ôן÷ÀàÎÊÌâ¡£¡£ ¡£¡£¡£¿£¿£¿£¿£¿£¿°ÈøË¹ÖÝ×î¸ß·¨ÔºÔÚÉÏÖÜËİ䲼ÁËÒ»ÏîÐÐÕþºÅÁ £¬£¬£¬£¬£¬£¬£¬³Æ½ØÖÁ10ÔÂ15ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬·¨ÔºÊé¼Ç¹Ù°ì¹«ÊÒ½«ÎÞ·¨½øÐеç×ӹ鵵¡£¡£ ¡£¡£¡£±¾ÖÜÒ»£¬ £¬£¬£¬£¬£¬£¬£¬·¨ÔºÈÔʹÓÃÖ½Öʼͼ£¬ £¬£¬£¬£¬£¬£¬£¬ÇÒÓʼþϵͳ´¦ÓڹعØ×´×´Ì¬¡£¡£ ¡£¡£¡£¿£¿£¿£¿£¿£¿°ÈøË¹ÖÝÈûÆæÍþ¿ËÏØ·¨¹Ùй©£¬ £¬£¬£¬£¬£¬£¬£¬Õâ´ÎÖжÏÊÇÀÕË÷¹¥»÷µ¼ÖµÄ£¬ £¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐй©¹¥»÷ÍÅ»ïºÍÊê½ðµÄÓйØÐÅÏ¢¡£¡£ ¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬£¬£¬£¬¶Ô´ËÊÂÎñµÄµ÷²éÔÚ½øÐÐÖУ¬ £¬£¬£¬£¬£¬£¬£¬Éв»È·¶¨ÏµÍ³ºÎʱ»á¸´Ô­¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/kansas-courts-it-systems-offline-after-security-incident/


3¡¢µçÊÓ¸æ°×¹«Ë¾AmpersandÔâµ½Black BastaÀÕË÷¹¥»÷


¾Ý10ÔÂ17ÈÕ±¨Â·£¬ £¬£¬£¬£¬£¬£¬£¬ÃÀ¹úµçÊÓ¸æ°×ÏúÊۺͼ¼Êõ¹«Ë¾AmpersandÔâµ½ÀÕË÷¹¥»÷¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÓÉÃÀ¹úÈý´óÓÐÏßµçÊÓÔËÓªÉ̹²Í¬Õ¼ÓУ¬ £¬£¬£¬£¬£¬£¬£¬×Ô1981ÄêÒÔÀ´Ò»ÏòΪ¸æ°×ÉÌÌṩԼ8500Íò»§¼ÒÍ¥µÄÊÕÊÓÊý¾Ý¡£¡£ ¡£¡£¡£Ampersand³Æ×î½üÔâµ½ÀÕË÷¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔËÓªÁÙʱÖжÏ£¬ £¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÒѾ­¸´Ô­ÁË´ó²¿ÃÅÒµÎñµÄÔËÓª¡£¡£ ¡£¡£¡£Black BastaÔÚÉÏÖÜÄ©°µÊ¾¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬ £¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐй©ÇÔÈ¡Á˼¸¶àÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬£¬Ò²Ã»Óа䲼±»µÁÊý¾ÝÑù±¾¡£¡£ ¡£¡£¡£


https://therecord.media/ampersand-television-advertising-sales-company-ransomware


4¡¢Cloudflare·¢ÏÖ¼Ù×°³É¾¯±¨ÀûÓÃRedAlertµÄ¼äµýÈí¼þ


CloudflareÔÚ10ÔÂ14ÈÕ³ÆÆä·¢ÏÖ¶ñÒâ°æ±¾µÄRedAlert ¨C Rocket AlertsÀûÓ÷¨Ê½£¬ £¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÒÔÉ«ÁеÄAndroidÓû§¡£¡£ ¡£¡£¡£¸Ã¶ñÒâ°æ±¾Í¨¹ýÍøÕ¾redalerts[.]me´«²¼£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾´´½¨ÓÚ10ÔÂ12ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÏÂÔØiOSºÍAndroid°æ±¾ÀûÓᣡ£ ¡£¡£¡£ÆäÖÐiOSµÄÏÂÔØ»áÁ´½Óµ½ºÏ·¨µÄApp StoreÒ³Ãæ£¬ £¬£¬£¬£¬£¬£¬£¬AndroidÏÂÔØÖ±½ÓÌṩ¶ñÒâ°æ±¾µÄAPK¡£¡£ ¡£¡£¡£¸ÃAPKʹÓÃÁËÕæÕýµÄRedAlertµÄ´úÂ룬 £¬£¬£¬£¬£¬£¬£¬µ«»áÒªÇó¶î±íȨÏÞ¡£¡£ ¡£¡£¡£·¨Ê½Æô¶¯ºó£¬ £¬£¬£¬£¬£¬£¬£¬ºó¶Ü·þÎñ»áÀÄÓÃÕâЩȨÏÞÍøÂçÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÔÚCBCģʽÏÂÓÃAES¼ÓÃÜ£¬ £¬£¬£¬£¬£¬£¬£¬ÉÏ´«µ½Ò»¸öÓ²±àÂëIPµØÖ·¡£¡£ ¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾ÒѾ­¹Ø¹Ø¡£¡£ ¡£¡£¡£


https://blog.cloudflare.com/malicious-redalert-rocket-alerts-application-targets-israeli-phone-calls-sms-and-user-information/


5¡¢×êÑÐÈËÔ±Åû¶ͨ¹ýDiscord·Ö·¢Lumma StealerµÄ»î¶¯


10ÔÂ16ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬Trend MicroÏêÊöÁ˹¥»÷ÕßÈôºÎÀûÓÃDiscordµÄÄÚÈݽ»¸¶ÍøÂç(CDN)À´Íйܺʹ«²¼Lumma Stealer£¬ £¬£¬£¬£¬£¬£¬£¬²¢»áÉÌÁ˸ÃÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÐÂÔöÖ°ÄÜ¡£¡£ ¡£¡£¡£¹¥»÷Õßͨ³£Ê¹ÓÃËæ»úDiscordÕÊ»§ÏòÖ¸±ê·¢ËÍÐÂÎÅ£¬ £¬£¬£¬£¬£¬£¬£¬Í¨¹ýΪÏîĿ׷ÇóÔ®ÊÖ²¢Ìṩ10ÃÀÔª»òDiscord Nitro boostÀ´ÒýÓÕÖ¸±ê¡£¡£ ¡£¡£¡£Ö¸±êÔ޳ɺó»á±»ÒªÇóÏÂÔØÒ»¸öÎļþ£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Lumma Stealer¡£¡£ ¡£¡£¡£¾Ý³Æ£¬ £¬£¬£¬£¬£¬£¬£¬Lumma Stealer»¹»á¼ÓÔØÆäËü¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬£¬£¬²¢¿ÉÄÜÀûÓÃÈËΪÖÇÄܺÍÉî¶È½ø½¨À´¼ì²â»úеÈË¡£¡£ ¡£¡£¡£


https://www.trendmicro.com/en_us/research/23/j/beware-lumma-stealer-distributed-via-discord-cdn-.html


6¡¢Unit42°ä²¼¹ØÓÚXorDDoS¹¥»÷»î¶¯µÄÉî¿Ì·ÖÎö»ã±¨


10ÔÂ16ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬Unit42°ä²¼Á˹ØÓÚXorDDoS¹¥»÷»î¶¯µÄÉî¿Ì·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£Õâ´Î·ÖÎöµÄ»î¶¯ÓÚ7ÔÂ28ÈÕÆðÍ·£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÓÚ8ÔÂ12ÈÕ¼¤Ôö£¬ £¬£¬£¬£¬£¬£¬£¬³É¹¦ÈëÇÖÁËλÓÚ21¸ö¹ú¶È/µØÓòµÄϵͳ£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖдó²¿ÃŹ¥»÷Á÷Á¿¼¯ÖÐÔÚ·ÇÖÞ¡¢ÄÏÑǺͶ«ÄÏÑÇ¡£¡£ ¡£¡£¡£¸ÃľÂíϰȾLinuxÉ豸²¢½«Æä²ÎÓëΪ½©Ê¬ÍøÂçÒÔÖ´ÐÐDDoS¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÁËÒÔǰÀÄÓùýµÄC2ÓòЭµ÷½©Ê¬ÍøÂç¡£¡£ ¡£¡£¡£È»¶ø£¬ £¬£¬£¬£¬£¬£¬£¬ËûÃÇ×î½ü½«ÆäC2·þÎñÆ÷´Ó¹«¹²ÍйܷþÎñǨáãµ½ÁËеÄIPµØÖ·¡£¡£ ¡£¡£¡£


https://unit42.paloaltonetworks.com/new-linux-xorddos-trojan-campaign-delivers-malware/