AgentTesla»ùÓÚÎÞÎļþ .NET µÄ´úÂë×¢Èë½øÐд«²¼

°ä²¼¹¦·ò 2024-04-30
1. AgentTesla»ùÓÚÎÞÎļþ .NET µÄ´úÂë×¢Èë½øÐд«²¼


4ÔÂ29ÈÕ£¬£¬£¬£¬£¬×î½üµÄ¶ñÒâÈí¼þ»î¶¯Ê¹Óà Word ÎĵµÖÐµÄ VBA ºêÀ´ÏÂÔØ²¢Ö´ÐÐ 64 λ Rust ¶þ½øÔìÎļþ¡£¡£¡£¡£¡£¡£¸Ã¶þ½øÔìÎļþѡȡÎÞÎļþ×¢Èë¼¼Êõ½«¶ñÒâ AgentTesla ÓÐЧ¸ºÔؼÓÔØµ½ÆäÄÚ´æ¿Õ¼äÖÓ×£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÀûÓà CLR Íйܣ¨Ò»ÖÖ±¾»ú¹ý³ÌÖ´ÐÐ .NET ´úÂëµÄ»úÔ죩À´ÊµÏÖ´ËÖ÷ÕÅ£¬£¬£¬£¬£¬²¢ÇÒ¶¯Ì¬¼ÓÔØ .NET ÔËÐÐʱ¿â£¬£¬£¬£¬£¬´Ó¶øÔÊÐí¶ñÒâÈí¼þÔÚ²»½«ÎļþдÈë¹âÅ̵ÄÇé¿öϽøÐвÙ×÷¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ý½¨²¹¡°EtwEventWrite¡±API À´½ûÓà Windows ÊÂÎñ¸ú×Ù (ETW)£¬£¬£¬£¬£¬¶øºó´ÓÌØ¶¨ URL ÏÂÔØÔ̺¬ AgenetTesla ÓÐЧ¸ºÔØµÄ shellcode¡£¡£¡£¡£¡£¡£¶øºóʹÓá°EnumSystemLocalesA¡±API Ö´ÐÐ shellcode¡£¡£¡£¡£¡£¡£ 


https://gbhackers.com/clr-hosting-used-by-agenttesla/


2. Õë¶Ô USPS µÄÍøÂç´¹µö»î¶¯Óë USPS ×ÔÉíÒ»Ñù¶à


4ÔÂ26ÈÕ£¬£¬£¬£¬£¬Akamai ×êÑÐÈËÔ±·¢ÏÖÁË´óÁ¿¼«ÓпÉÄܵĶñÒâ»î¶¯ºÍÐû³ÆÓëÃÀ¹úÓÊÕþ·þÎñ (USPS) ÓйصÄÓòÃû¡£¡£¡£¡£¡£¡£Akamai ×êÑÐÈËÔ±½«Îå¸öÔµĺϷ¨ÓòÃû usps[.]com µÄ DNS Á÷Á¿Óë·¸·¨×éºÏÇÀ×¢ÓòÃûµÄ DNS Á÷Á¿½øÐÐÁ˱ÈÁ¦¡£¡£¡£¡£¡£¡£¶ñÒâÓòÓë usps[.]com µÄ×ܲéÎʼÆÊýÏÕЩһÑù£¬£¬£¬£¬£¬¼´±ã½öÍÆËãÔ̺¬Ã÷È· USPS Ëõд´ÊµÄÓòÒ²ÊÇÈç´Ë¡£¡£¡£¡£¡£¡£Ö»¹ÜÔÚ´Ë·ÖÎöÖУ¬£¬£¬£¬£¬USPS Ó®µÃÁËÕâ 5 ¸öÔÂÆÚ¼ä×ܲéÎÊÁ¿µÄ 51%£¬£¬£¬£¬£¬µ«ÎÒÃǹýÂËÊý¾ÝµÄ·½Ê½Åú×¢£¬£¬£¬£¬£¬¶ñÒâÁ÷Á¿ÏÔÖø³¬¹ýÁËÏÖʵÊÀ½çÖеĺϷ¨Á÷Á¿¡£¡£¡£¡£¡£¡£ÎÒÃÇ¿´µ½¶ñÒâÐÐΪÕßѡȡÁËÁ½ÖÖ·ÖÆçµÄ²½Ö裺ËûÃÇҪô½«Á÷Á¿·ÖÉ¢µ½ºÜ¶à·ÖÆçµÄÓòÃû£¬£¬£¬£¬£¬ÒªÃ´½öʹÓü¸¸öÓò£¬£¬£¬£¬£¬Ã¿¸öÓò¶¼ÓдóÁ¿Á÷Á¿¡£¡£¡£¡£¡£¡£Õâ¿ÉÄÜÊdzöÓÚ»ìºÏÖ÷ÕÅ£ºÔËÓªÉÌºÍÆäËûÍйÜÌṩÉÌÒâʶµ½ÕâЩڿƭµÄÆÕ±é´æÔÚ£¬£¬£¬£¬£¬²¢ÔÚ¾¯ÌèµØ³¢ÊÔ¼ø±ðºÍɾ³ýÕâÐ©Ò³Ãæ¡£¡£¡£¡£¡£¡£¿£¿ £¿ £¿ £Ë¼¿¼µ½½â³ýÕâЩȦÌ׵ĹØ×¢Ë®Æ½£¬£¬£¬£¬£¬ËûÃǵÄÁ˾ֺÍ8827Ì«Ñô¼¯ÍŹ۲ì¸üÁîÈËÓÇÓô¡£¡£¡£¡£¡£¡£


https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic


3. ¹È¸èä¯ÀÀÆ÷µÄкóÁ¿×Ó¼ÓÃܼ¼Êõ¿ÉÄÜ»á·ÛËé TLS ÏνÓ


4ÔÂ28ÈÕ£¬£¬£¬£¬£¬Ò»Ð© Google Chrome Óû§»ã±¨ÔÚ Chrome 124 ÉÏÖܰ䲼ºó£¬£¬£¬£¬£¬ÔÚĬÈÏÆôÓÃеĿ¹Á¿×Ó X25519Kyber768 ·â×°»úÔìµÄÇé¿öÏ£¬£¬£¬£¬£¬Ïνӵ½ÍøÕ¾¡¢·þÎñÆ÷ºÍ·À»ðǽʱ³öÏÖÎÊÌâ¡£¡£¡£¡£¡£¡£¹È¸èÒѲâÊÔÁ¿×Ó°²È« TLS ÃÜÔ¿·â×°»úÔ죬£¬£¬£¬£¬ÏÖÒÑÔÚ×îÐ嵀 Chrome °æ±¾ÖÐΪËùÓÐЧ»§ÆôÓᣡ£¡£¡£¡£¡£Ð°汾ÀûÓÃÓÃÓÚ TLS 1.3 ºÍ QUIC ÏÎ½ÓµÄ Kyber768 ¿¹Á¿×ÓÃÜԿЭÉÌËã·¨À´±£»£» £»£»£» £»¤ Chrome TLS Á÷Á¿ÃâÊÜÁ¿×ÓÃÜÂë·ÖÎö¡£¡£¡£¡£¡£¡£ÕâЩÃýÎó²»ÊÇÓÉ Google Chrome ÖеÄÃýÎóÒýÆðµÄ£¬£¬£¬£¬£¬¶øÊÇÓÉ Web ·þÎñÆ÷δÄÜÕýµÄÈ·ÏÖ´«Êä²ã°²È«ÐÔ (TLS) ÒÔ¼°ÎÞ·¨´¦ÖÃÓÃÓÚºóÁ¿×Ó¼ÓÃܵĽϴó ClientHello ÐÂÎÅÒýÆðµÄ¡£¡£¡£¡£¡£¡£ÈôÊDz»Ö§³Ö X25519Kyber768£¬£¬£¬£¬£¬Õâ»áµ¼ÖÂËûÃǻؾøÊ¹Óà Kyber768 ¿¹Á¿×ÓÃÜԿЭÉÌËã·¨µÄÏνÓ£¬£¬£¬£¬£¬¶ø²»ÊÇÇл»µ½¾­µä¼ÓÃÜ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/google-chromes-new-post-quantum-cryptography-may-break-tls-connections/


4. Kotak Mahindra ÒøÐб»²»ÈÝÀûÓ÷¨Ê½×¢²áпͻ§


4ÔÂ28ÈÕ£¬£¬£¬£¬£¬Ó¡¶È´¢ÐîÒøÐÐÒÑÖ´ÐÐ¶Ô Kotak Mahindra ÒøÐеĽûÁ£¬£¬£¬£¬²»ÈÝͨ¹ýÔÚÏß·þÎñºÍÀûÓ÷¨Ê½×¢²áпͻ§¡£¡£¡£¡£¡£¡£¸Ã´ëÊ©ÊÇÔÚITϵͳÖÎÀíÖз¢ÏÖ³Á´óȱµãºó²ÉÈ¡µÄ£¬£¬£¬£¬£¬ÕâЩȱµãÔ̺¬IT×ʲúÖÎÀí¡¢¸üк͵÷»»¡¢Óû§½Ó¼û¡¢¹©¸øÉÌÓйطçÏÕ¡¢Êý¾Ý°²È«¡¢Êý¾Ýй¶Ԥ·ÀÕ½ÊõºÍ¿àÄѸ´Ô­Õ½Êõ¡£¡£¡£¡£¡£¡£Kotak Mahindra Bank Ϊ³¬¹ý 4100 Íò¿Í»§Ìṩ·þÎñ£¬£¬£¬£¬£¬ÖÎÀí×ų¬¹ý 5000 ÒÚÃÀÔªµÄ×ʲú£¬£¬£¬£¬£¬¸ÃÒøÐÐÔÚ 2022/2023 ²ÆÄêÄê¶È»ã±¨ÖаµÊ¾£¬£¬£¬£¬£¬¸ÃÒøÐÐÒ»ÏòÖÂÁ¦ÓÚ¼ÓÇ¿°²È«´ëÊ©¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬ÑëÐÐÒÔΪÕâЩÖÂÁ¦²»¹»¡£¡£¡£¡£¡£¡£ÀúʱÁ½ÄêµÄ²é³­ÏÔʾ£¬£¬£¬£¬£¬¸ÃÐÐδÄܳä·Ö½â¾öIT·çÏÕºÍÐÅÏ¢°²È«ÖÎÀíÎÊÌâ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬¸ÃÒøÐл¹¾­ÀúÁËÓ°Ïì¿Í»§µÄ¼¼Êõ¹ÊÕÏ£¬£¬£¬£¬£¬Òý·¢ÁËÈËÃÇ¶ÔÆäά³ÖÔËÓªµ¯ÐÔÓëÆäÔö³¤ÂÊά³ÖÒ»ÖµÄÄÜÁ¦µÄÓÇÓô¡£¡£¡£¡£¡£¡£


https://meterpreter.org/rbi-cracks-down-on-kotak-mahindra-online-banking-halt/


5. ºÚ¿ÍÐû³ÆÒÑÉøÈë°×¶íÂÞ˹µÄÖØÒª°²È«ÊýÃÅ


4ÔÂ28ÈÕ£¬£¬£¬£¬£¬°×¶íÂÞ˹ºÚ¿Í×éÖ¯Ðû³ÆÒÑÉøÈëµ½¸Ã¹úÖØÒª¿Ë¸ñ²ª°²È«»ú¹¹µÄÍøÂ磬£¬£¬£¬£¬²¢½Ó¼ûÁ˸Ã×éÖ¯ 8600 ¶àÃûÔ±¹¤µÄÈËʵµ°¸£¬£¬£¬£¬£¬¸Ã×éÖ¯ÈÔÒÔÆäËÕÁªÃû³Æ¶¨Ãû¡£¡£¡£¡£¡£¡£ÎªÁËÖ§³Ôìä˵·¨£¬£¬£¬£¬£¬°×¶íÂÞË¹ÍøÂçÓλ÷¶ÓÔÚÐÂÎÅÀûÓ÷¨Ê½ Telegram µÄÒ³ÃæÉϰ䲼Á˸ÃÍøÕ¾ÖÎÀíÔ±¡¢Êý¾Ý¿âºÍ·þÎñÆ÷ÈÕÖ¾µÄÁÐ±í¡£¡£¡£¡£¡£¡£ÍøÂçÓλ÷¶ÓÔÚ´ÓǰËÄÄêÖж԰׶íÂÞ˹¹Ù·½Ã½Ìå½øÐÐÁËÊý´Î´ó¹æÄ£¹¥»÷£¬£¬£¬£¬£¬²¢ÔÚ 2022 Äê¶Ô°×¶íÂÞ˹Ìú·½øÐÐÁË 3 ´ÎºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬½Ù³ÖÁ˽»Í¨µÆºÍ½ÚÔìϵͳµÄ½ÚÔìȨ¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/hackers-claim-to-have-infiltrated-belarus-main-security-service/


6. ץȡDiscordµÄ6.2ÒÚÌõÐÅÏ¢µÄSpy.petÒѹعØ


4ÔÂ29ÈÕ£¬£¬£¬£¬£¬¸ÃÍøÕ¾×ÔÈ¥Äê 11 ÔÂÒÔÀ´Ò»ÏòÔÚÇÔÈ¡ Discord Óû§µÄ¹«¹²Êý¾Ý£¬£¬£¬£¬£¬²¢ÓÚÉÏÖܱ»·¢ÏÖ¸ÃÆ½Ì¨Ô̺¬À´×Ô 14000 ¶ą̀ Discord ·þÎñÆ÷µÄ½ü 6.2 ÒÚÓû§µÄÐÂÎÅºó±»ÆØ¹â¡£¡£¡£¡£¡£¡£µ± Spy.pet ±»·¢ÏÖʱ£¬£¬£¬£¬£¬Discord ÔÚÖÂÁ¦¶ÔÈκÎÎ¥·´Æä·þÎñÌõ¿î±êÈ˲ÉÈ¡Ðж¯£¬£¬£¬£¬£¬µ«ÎÞ·¨Ð¹Â©¸ü¶àÐÅÏ¢¡£¡£¡£¡£¡£¡£DiscordÒѾ­½ûÓÃÓëSpy.pet ÍøÕ¾ÓйصÄÕÊ»§¡£¡£¡£¡£¡£¡£Spy.pet Ðû³ÆÄܹ»½Ó¼ûµÄ Discord ·þÎñÆ÷ÊýÁ¿ÉÏÖÜÆðÍ·½µÂ䣬£¬£¬£¬£¬ÉÏÖÜËĽµÖÁÁã¡£¡£¡£¡£¡£¡£µ½ÖÜÎ壬£¬£¬£¬£¬Spy.pet ÍøÕ¾×ÔÉíÒѾ­ÖÕ³¡ÔËÓª¡ª¡ªÖ»¹ÜÉв»Ã÷ÏÔ¸ÃÍøÕ¾ÊÇ·ñÓÉÓÚ Discord µÄÐÐΪ¶øÀëÏß¡£¡£¡£¡£¡£¡£


https://www.theregister.com/2024/04/29/infosec_in_brief/