MikroTik¹«¿ªDDoS½©Ê¬ÍøÂ磺Unit 42°ä²¼ÒÔÓÎÀÀÖ÷ÌâµÄ´¹µö»î¶¯
°ä²¼¹¦·ò 2021-09-18Anonymous³ÆÒÑÇÔÈ¡ÍйÜÔËÓªÉÌEpik½üÊ®ÄêµÄÊý¾Ý

AnonymousÔÚ9ÔÂ15ÈÕÐû³ÆÒÑÇÔÈ¡ÍйÜÔËÓªÉÌEpik½üÊ®ÄêµÄÊý¾Ý£¬²¢ÔÚDDoSecretsÉϹ«¿ª¡£EpikµÄ¿Í»§Ô̺¬Parler¡¢Gab¡¢The DonaldºÍprolifewhistleblower.comµÈ¡£Õâ´Î¹¥»÷ÊÇEPIKFAILÐж¯µÄÒ»²¿ÃÅ£¬×ܼÆÇÔÈ¡ÁËÔ¼180GBµÄÊý¾Ý£¬Ô̺¬ÕË»§Æ¾Ö¤¡¢WHOISº¹Çà¡¢DNS¸ü¸Ä¡¢Git´æ´¢¿âºÍÖ÷ÌâϵͳµÄ/home/ºÍ/root/Ŀ¼µÈ¡£´Ë±í£¬¸ÃÍÅ»ïÔøÔÚÉÏÖÜÈëÇÖÁËGOP£¨µÂ¿ËÈøË¹¹²ºÍµ³£©µÄ¹Ù·½ÍøÕ¾¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/anonymous-steals-far-right-web-host-epik-data/
ÃÀ¹úDesert WellsÒ½ÔºEHRϵͳÔâµ½¹¥»÷ÇÒÊý¾ÝÃÔʧ

ÃÀ¹úÑÇÀûÉ£ÄÇÖݵÄÒ½ÔºDesert Wells Family Medicine³ÆÆäµç×Ó½¡È«¼Í¼(EHR)ϵͳÔâµ½¹¥»÷¡£¹¥»÷²úÉúÔÚ5ÔÂ21ÈÕ£¬¼´±ã¸ÃÒ½ÔºÔÚ¹¥»÷²úÉúǰ±¸·ÝÁËEHRÖеÄËùº±¼û¾Ý£¬µ«¹¥»÷Õß¶ÔÁ½¸öϵͳÖеÄÊý¾Ý¾ù½øÐÐÁ˼ÓÃÜ£¬Ê¹µÃϵͳÖеÄËùÓÐEHRÐÅÏ¢¶¼ÒÑÓÀÔ¼ûÔʧ¡£Desert Wells°µÊ¾ÒѾ¡ÆäËùÄܸ´ÔÊý¾Ýµ«Ã»ÓÐÈκÎ×÷Óã¬ËûÃÇÔÚ¹¹½¨È«ÐµÄEHRϵͳ¡£´Ë±í£¬ÆäÒÑ֪ͨ35000¸ö»¼ÕßËûÃǵĽ¡È«ÐÅÏ¢¿ÉÄÜÒѾй¶¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/arizona-medical-practice-loses-ehr/
MikroTik¹«¿ªDDoS½©Ê¬ÍøÂçM¨¥ris»î¶¯µÄ¾ßÌåÐÅÏ¢

ÀÍÑάÑÇÍøÂçÉ豸Ôì×÷ÉÌMikroTikÔÚ9ÔÂ15ÈÕ¹«¿ªÁËM¨¥ris¹¥»÷»î¶¯µÄÐÅÏ¢¡£MicroTik½²»°È˳ƣ¬Õâ´Î¹¥»÷ʹÓõÄ·ÓÉÆ÷Óë2018Äê±»ÈëÇֵķÓÉÆ÷Ò»Ñù£¬ÆäʱMikroTik RouterOSÖдæÔÚÒ»¸ö·ì϶£¬µ«¸Ã·ì϶ºÜ¿ì¾Í±»½¨¸´ÁË¡£²»Íâ½ö½¨¸´·ì϶²¢²»Äܱ£»¤Â·ÓÉÆ÷£¬ÓÉÓÚ¹¥»÷ÕßÔÚ2018Äê¾Í»ñµÃÁËÓû§µÄÍ´´¦¡£MicroTik½¨ÒéÓû§¶¨ÆÚÉý¼¶É豸£¬ÒÔ¼°Ê¹ÓÃÇ¿ÃÜÂë²¢¶¨ÆÚ¸ü»»µÈ´ëÊ©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mikrotik-shares-info-on-securing-routers-hit-by-massive-m-ris-botnet/
°²È«¹«Ë¾Bitdefender°ä²¼ÀÕË÷Èí¼þREvilÖ÷½âÃÜÆ÷

°²È«¹«Ë¾Bitdefender°ä²¼ÁËÕë¶ÔÀÕË÷Èí¼þREvilÖ÷½âÃÜÆ÷¡£Bitdefender³Æ¸Ã½âÃÜÆ÷ÊÇÓÉÆäºÍij·¨Âɲ¿ÃźÏ×÷¿ª·¢µÄ£¬ºÏÓÃÓÚ7ÔÂ13ÈÕ֮ǰÔâµ½REvil¹¥»÷µÄËùÓÐÊܺ¦Õß¡£BleepingComputer×êÑÐÈËÔ±ÀûÓýñÄêÔçЩʱ³½µÄREvilÑù±¾¶ÔÆä½øÐÐÑéÖ¤£¬È·¶¨Ã»ÓÐÎÊÌâ¡£7Ô·Ýʱ£¬KaseyaÒ²Ôø»ñµÃÁËREvil½âÃÜÆ÷£¬µ«¸Ã¹¤¾ßÖ»ºÏÓÃÓÚÕë¶ÔKaseyaµÄ¹¥»÷»î¶¯µÄÊܺ¦Õß¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/free-revil-ransomware-master-decrypter-released-for-past-victims/
΢ÈíÅû¶½üÆÚÀûÓÃMSHTML·ì϶µÄ´¹µö¹¥»÷»î¶¯

΢ÈíÔÚ9ÔÂ15Èճƣ¬ÆäÍþвµý±¨ÖÐÐÄÔÚ8Ô·ݷ¢ÏÖÁËÉÙÁ¿Í¨¹ýÌØÔìMicrosoftOfficeÎĵ·ûÓÃMSHTMLÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-40444£©µÄ»î¶¯¡£Õâ´Î»î¶¯ÀûÓÃÁ˽»¸¶»úÔ죬ͨ¹ýÍйÜÔÚÎļþ¹²ÏíÕ¾µãÉϵĺÏͬºÍ˾·¨ºÍ̸£¬ÓÕʹָ±êÏÂÔØCabinet¹éµµÎļþ£¬ÆäÔ̺¬Ò»¸öÀ©´óÃûΪINFµÄDLL£¬¸ÃDLL½«¼ìË÷²¢ÏÂÔØÔ¶³ÌÍйܵÄshellcode¡£Î¢Èí½«Õâ´Î»î¶¯¹éÒòÓÚºÚ¿Í×éÖ¯DEV-0413ºÍDEV-0365¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/09/windows-mshtml-0-day-exploited-to.html
Unit 42°ä²¼ÒÔÓÎÀÀΪÖ÷ÌâµÄ´¹µö»î¶¯µÄ·ÖÎö»ã±¨

Unit 42ÓÚ9ÔÂ15ÈÕ°ä²¼ÁËÒÔÓÎÀÀΪÖ÷ÌâµÄ´¹µö»î¶¯µÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±·ÖÎöÁË2019Äê10ÔÂÖÁ2021Äê8Ô´´½¨µÄÒÔÓÎÀÀΪÖ÷ÌâµÄ´¹µöURL£¬·¢ÏÖÊýÁ¿³ÊÖð²½ÉÏÉýµÄÇ÷Ïò£¬²¢ÔÚ2021Äê6Ô³öÏÖÏÔÖøÔö³¤¡£»ã±¨ÌṩÁËDridexÔÚ2021ÄêʹÓõĴøÓÓ×°º½¿Õ¹«Ë¾¡±ºÍ¡°¼ÙÆÚ¡±¹Ø¼ü´ÊµÄ´¹µö»î¶¯µÄ¼¼Êõϸ½Ú¡£´Ë±í£¬·ÖÎö·¢ÏÖ¹¥»÷Õßͨ³£ÀûÓÃGoogle FirebaseÓòÀ´ºýŪָ±ê²¢Èƹý°²È«¹ýÂËÆ÷¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/travel-themed-phishing/


¾©¹«Íø°²±¸11010802024551ºÅ