Òò¹©¸øÉÌÔâµ½¹¥»÷ ÈÕ±¾·áÌïÆû³µµÄ14¼Ò¹¤³§Í£²ú

°ä²¼¹¦·ò 2022-03-02

Òò¹©¸øÉÌÔâµ½¹¥»÷£¬ÈÕ±¾·áÌïÆû³µµÄ14¼Ò¹¤³§Í£²ú


ÈÕ±¾·áÌïÆû³µÔÚ2ÔÂ28ÈÕ°ä·¢£¬½«ÓÚ±¾Öܶþ3ÔÂ1ÈÕÆðÍ·£¬ÔÝÍ£ÈÕ±¾14¼Ò¹¤³§µÄ28Ìõ³ö²úÏßµÄÔËÓª¡£Õâ´ÎÖжÏÊÇÓÉÓÚÆä³ÁÒªÁã¼þ¹©¸øÉÌÓ×µº¹¤Òµ£¨Kojima Industries£©µÄϵͳ¹ÊÕÏÔì³ÉµÄ£¬¾Ý±¨Â·¸Ã¹«Ë¾Ôâµ½ÁËÍøÂç¹¥»÷¡£¾Ý¹À¼Æ£¬Õâ´ÎÊÂÎñ½«µ¼Ö·áÌïÔÚÈÕ±¾µÄÔ²úÁ¿½µÂä5%£¬Ô¼ºÏ13000Á¾Æû³µ¡£·áÌïµÄ×Ó¹«Ë¾´ó·¢Æû³µºÍÈÕÒ°Æû³µÒ²½«Í£²ú£¬Éв»Ã÷È·ËüÃÇÊܵ½µÄ¾ßÌåÓ°Ï졣Ŀǰ£¬¸Ã¹«Ë¾ÈÔ²»È·¶¨Õâ´ÎÖжϻá³ÖÐø¶à¾Ã¡£


https://threatpost.com/toyota-to-close-japan-plants-after-suspected-cyberattack/178686/


°×¶íÂÞ˹Ìú·Ôâµ½AnonymouÈëÇÖµ¼ÖÂËùÓзþÎñÖжÏ


¾ÝýÌå2ÔÂ27ÈÕ±¨Â·£¬ºÚ¿ÍÍÅ»ïAnonymouÐû³ÆÒÑÈëÇÖ°×¶íÂÞ˹Ìú·µÄÄÚ²¿ÍøÂ磬²¢¹Ø¹ØËùÓзþÎñ¡£Ä¿Ç°£¬ÍøÕ¾pass.rw.by¡¢portal.rw.by¡¢rw.byÈÔÎÞ·¨½Ó¼û£¬ÇҸùúÌú·ϵͳ±»ÆÈתΪÊÖ¶¯½ÚÔìģʽ£¬Õâ¶ÔÁгµµÄÔËÓª²úÉúÁ˼«´óµÄÓ°Ïì¡£¼¸ÈÕǰ£¬Anonymous»¹ÈëÇÖÁ˰׶íÂÞ˹µÄ±øÆ÷Ôì×÷ÉÌTetraedr£¬²¢ÇÔÈ¡ÁËÔ¼200GBµÄµç×ÓÓʼþ¡£


https://securityaffairs.co/wordpress/128486/hacktivism/anonymous-breached-belarusian-railways.html


×êÑÐÍŶӷ¢ÏÖÕë¶Ô»¨ÆìÒøÐеĴó¹æÄ£´¹µöµÄ¹¥»÷»î¶¯


¾Ý2ÔÂ24Èյı¨Â·£¬Bitdefender·¢ÏÖÁ˽üÆÚÕë¶Ô»¨ÆìÒøÐеĴó¹æÄ£´¹µöµÄ¹¥»÷»î¶¯¡£¸Ã»î¶¯Ê¹ÓôøÓл¨ÆìÒøÐлձêµÄÓʼþ£¬ÒÔÕË»§¶³½áΪµö¶ü£¬ÓÕʹָ±êµÇ¼¼Ù×°³É»¨ÆìÒøÐйÙÍøµÄ´¹µöÍøÕ¾²¢ÊäÈëÓû§IDºÍÃÜÂ룬ּÔÚÇÔȡָ±êÒøÐÐÕË»§ÖеÄÓà¶î¡£¾ÝBitdefenderͳ¼ÆÊý¾Ý£¬´ó²¿ÃÅ´¹µöÓʼþÕë¶ÔÃÀ¹úÓû§£¨81%£©£¬Æä´ÎΪӢ¹ú£¨7%£©£»´ó²¿ÃÅÓʼþÀ´×ÔÃÀ¹úµÄIPµØÖ·£¨40%£©£¬Æä´ÎÊÇÄ«Î÷¸ç£¨13%£©¡£


https://www.bleepingcomputer.com/news/security/citibank-phishing-baits-customers-with-fake-suspension-alerts/


×êÑÐÈËÔ±¹«¿ªÊýÍòÌõÀÕË÷ÍÅ»ïContiÄÚ²¿µÄ̸Ìì¼Í¼


2ÔÂ27ÈÕ±¨Â·³Æ£¬ÀÕË÷ÍÅ»ïContiÄÚ²¿µÄÊýÍòÌõ̸Ìì¼Í¼¹«¿ª¡£¾ÝϤ£¬Êý¾ÝÊÇÓÉÎÚ¿ËÀ¼µÄÒ»Ãû×êÑÐÈËԱй¶µÄ£¬ËûÄܹ»½Ó¼ûContiµÄXMPP̸Ìì·þÎñÆ÷µÄejabberdÊý¾Ý¿âºó¶Ë£¬×ܹ²ÓÐ393¸öJSONÎļþ£¬Ô̺¬2021Äê1ÔÂ21ÈÕÖÁ½ñµÄ60694ÌõÐÂÎÅ¡£ÕâЩ¼ÍÂ¼Éæ¼°¸ÃÍÅ»ï¸÷Àà»î¶¯µÄÐÅÏ¢£¬Ô̺¬ÒÔǰδ¹«¿ªµÄ±»¹¥»÷Ö¸±ê¡¢¸öÈËÊý¾Ýй¶URL¡¢±ÈÌØ±ÒµØÖ·ÒÔ¼°ÓÐ¹ØÆäÔËÓªµÄ»áÉ̵È¡£


https://www.bleepingcomputer.com/news/security/conti-ransomwares-internal-chats-leaked-after-siding-with-russia/


Cyble°ä²¼Ð¶ñÒâÈí¼þJester StealerµÄ¼¼Êõ·ÖÎö»ã±¨


2ÔÂ24ÈÕ£¬Cyble Research°ä²¼Á˹ØÓÚжñÒâÈí¼þJester StealerµÄ¼¼Êõ·ÖÎö»ã±¨¡£¸Ã¶ñÒâÈí¼þÓÚ2021Äê7Ô³õ´Î³öÏÖ£¬ÒѸüÐÂÁËÆß´Î¡£ËüÊÇÒ»ÖÖ»ùÓÚ.NetµÄ¶ñÒâÈí¼þ£¬Í¨³£¼Ù×°³Étxt¡¢jarºÍbatµÈ¸½¼þ£¬Í¨¹ýÍøÂç´¹µöµç×ÓÓʼþ½øÈëÖ¸±êϵͳ¡£Æä½áºÏÁËÇÔÈ¡·¨Ê½¡¢clipper¡¢¼ÓÃܿ󹤺ͽ©Ê¬ÍøÂçµÄÖ°ÄÜ£¬Ê¹ÓÃAES-CBC-256¼ÓÃÜͨѶ£¬Ö§³ÖTorÍøÂ磬½«ÈÕÖ¾³Á¶¨Ïòµ½Telegram bots£¬²¢ÔÚй¶֮ǰ»á½«±»µÁÊý¾Ý´æ·ÅÔÚÄÚ´æÖС£


https://blog.cyble.com/2022/02/24/jester-stealer-an-emerging-info-stealer/


Intel 471°ä²¼PPI¶ñÒâÈí¼þPrivateLoaderµÄ·ÖÎö»ã±¨


¾Ý2ÔÂ27ÈÕ±¨Â·£¬Intel 471Åû¶Á˰´×°Öø¶·Ñ(PPI)¶ñÒâÈí¼þPrivateLoaderµÄϸ½Ú¡£¸Ã¶ñÒâÈí¼þÓÉC++±àд£¬Äܹ»Óëºó¶Ë»ù´¡ÉèʩͨѶÀ´¼ìË÷¶ñÒâpayloadµÄURL£¬²¢×°ÖÃÔÚÖ¸±êÖ÷»úÉÏ£¬Ëü»¹»á´«»Ø¸÷Ààͳ¼ÆÐÅÏ¢£¬ÀýÈç³É¹¦ÏÂÔØºÍÆô¶¯ÁËÄÄЩpayload¡£Í¨³£ÒÀ¸½¾­¹ýSEOÓÅ»¯µÄÆÆ½âÈí¼þÍøÕ¾½øÐзַ¢£¬¿É×°Öò¢Ö´ÐжàÖÖ¶ñÒâpayload£¬ÀýÈçVidar¡¢Raccoon¡¢Redline¡¢Smokeloader¡¢Danabot ¡¢GCleanerºÍDiscoloaderµÈ¡£


https://www.hackread.com/malware-families-pay-per-install-service-expand-targets/




°²È«¹¤¾ß


DRAKVUF Sandbox


×Ô¶¯»¯µÄºÚºÐ¶ñÒâÈí¼þ·ÖÎöϵͳ£¬ÆäÒý´øÓÐDRAKVUFÒýÇæ£¬²»±ØÒª¿Í»§²Ù×÷ϵͳÉϵĴúÀí¡£


https://github.com/CERT-Polska/drakvuf-sandbox


StayKit


Cobalt Strike ÓÆ¾ÃÐÔµÄÀ©´ó£¬ËüÀûÓà SharpStay .NET ·¨Ê½¼¯µÄ execute_assembly º¯Êý¡£


https://github.com/0xthirteen/StayKit


Fennec


Óà Rust ±àдµÄ¹¤¼þÍøÂ繤¾ß£¬ÓÃÓÚÔÚ»ùÓÚ *nix µÄϵͳÉϵÄÊÂÎñÏìÓ¦ÆÚ¼äʹÓá£


https://github.com/AbdulRhmanAlfaifi/Fennec


request smuggler


Http ÒªÇó×ß˽·ì϶ɨÃèÆ÷£¬ÕÒµ½¿ÉÄÜÈÝÒ×Êܵ½ÒªÇó×ß˽·ì϶¹¥»÷µÄ·þÎñÆ÷¡£


https://github.com/Sh1Yo/request_smuggler


Shellcode Template


ºÏÓÃÓÚ Windows x64/x86µÄÒ×ÓÚÅú¸ÄµÄshellcodeÄ£°å¡£


https://github.com/Cracked5pider/ShellcodeTemplate




°²È«·ÖÎö


CVE-2022-23131£ºZabbix ǰ¶ËÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶


https://securityonline.info/cve-2022-23131-zabbix-frontend-authentication-bypass-vulnerability/


ºÚ¿ÍÂÛ̳ Raidforums.com ±»µ±¾Ö²é·â


https://www.hackread.com/hacking-forum-raidforums-com-seized-by-authorities/


ÓòÉý¼¶£ºPetitPotam NTLM Öм̵½ ADCS ¶Ëµã


https://www.hackingarticles.in/domain-escalation-petitpotam-ntlm-relay-to-adcs-endpoints/


΢Èí°ä·¢ÔÚ Windows 11 ÖнøÐÐÐ嵀 Windows ¸üиĽø


https://news.softpedia.com/news/microsoft-announces-new-windows-update-improvements-in-windows-11-534940.shtml