ÔËÓªÉÌUkrtelecom³ÆÆäÖ÷Ìâ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷

°ä²¼¹¦·ò 2022-03-31

ÔËÓªÉÌUkrtelecom³ÆÆäÖ÷Ìâ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷


¾ÝýÌå3ÔÂ29ÈÕ±¨Â· £¬ÎÚ¿ËÀ¼ÖØÒªµÄÔËÓªÉÌUkrtelecomÔâµ½ÁË´ó¹æÄ£µÄÍøÂç¹¥»÷ £¬Ôì³ÉÁËÑϳÁµÄÍøÂçÖжÏ¡£Æ¾¾Ý»¥ÁªÍø¼à¿Ø·þÎñNetBlockµÄÊý¾Ý £¬ÊµÊ±ÍøÂçÊý¾ÝÏÔʾÏνÓÐÔ½µÂäµ½Õý³£Ë®Æ½µÄ13%¡£ÎÚ¿ËÀ¼SSSCIP°µÊ¾ £¬ºÚ¿Í¹¥»÷ÁËUkrtelecomµÄIT»ù´¡ÉèÊ© £¬ËûÃÇÒѳɹ¦ÕмÜÕâ´Î¹¥»÷¡£´Ë±í £¬ÎªÁ˱£»¤Æä»ù´¡ÉèÊ©²¢³ÖÐøÎªÎÚ¿ËÀ¼Îä×°¶ÓÁÐºÍÆäËû¾üÊÂ×éÖ¯ºÍ¿Í»§Ìṩ·þÎñ £¬UkrtelecomÁÙʱÏÞ¶ÈÁË´óÎÞÊý¸öÈËºÍÆóÒµ¿Í»§µÄ·þÎñ¡£


https://securityaffairs.co/wordpress/129585/cyber-warfare-2/ukraine-cyberattack-ukrtelecom.html


΢Èí½¨¸´Windows 11 SMBºÍDirectXÖеÄBSODÎÊÌâ


ýÌå3ÔÂ28ÈÕ±¨Â· £¬Microsoft°ä²¼Á˺ÏÓÃÓÚWindows 11µÄ¿ÉÑ¡KB5011563ÀÛ»ý¸üС£Õâ´Î¸üÐÂÖØÒª½¨¸´ÁË2¸öÀ¶ÆÁËÀ»ú(BSOD)ÎÊÌâ £¬Ô̺¬DirectXÄÚºË×é¼þÖеÄÖÕ³¡ÃýÎó£¨0xD1 £¬DRIVER_IRQL_NOT_LESS_OR_EQUAL£©ºÍSMB·þÎñÆ÷£¨srv2.sys£©ÖеÄÖÕ³¡ÃýÎó0x1E¡£Õâ´Î¸üл¹Ôö³¤Á˺öàеÄÖ°ÄÜ £¬ÀýÈçͬʱÏÔʾ×î¶àÈý¸ö¸ßÓÅÏȼ¶Toast֪ͨ¡£Óû§Äܹ»ÔÚÉèÖÃÖÐÊÖ¶¯²é³­¸üР£¬»ò´ÓMicrosoft¸üÐÂĿ¼ÊÖ¶¯ÏÂÔØ²¢×°Öô˸üС£ 


https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5011563-update-fixes-smb-directx-blue-screens/


ÎÚ¿ËÀ¼µÄ¶à¸öÍøÕ¾Ôâµ½À´×ÔÊý°Ù¸öÍøÕ¾µÄDDoS¹¥»÷


¾Ý3ÔÂ28ÈÕ±¨Â· £¬MalwareHunterTeam·¢ÏÖÁËÒ»¸ö¶ñÒâ¾ç±¾¡£¹¥»÷ÕßÒÑÀûÓÃWordPressÖеķì϶ÈëÇÖÁËÉϰٸöÍøÕ¾ £¬¶øºó²åÈë¸Ã¶ñÒâ¾ç±¾¶ÔÎÚ¿ËÀ¼µÄÍøÕ¾Ö´ÐÐDDoS¹¥»÷ £¬Éæ¼°ÎÚ¿ËÀ¼µ±¾Ö»ú¹¹¡¢ÖÇÄÒÍÅ¡¢¹ú·À¾üÕÐļºÍ½ðÈÚµÈÓйØÍøÕ¾¡£Õâ¸öJavaScript¾ç±¾½«Ç¿Ôì±»ÈëÇÖµÄä¯ÀÀÆ÷¶ÔÁгöµÄ¶àÓÐÍøÕ¾Ö´ÐÐHTTP GETÒªÇó £¬Ò»´Î²»³¬¹ý1000¸ö²¢·¢ÏνÓ¡£´Ë±í £¬¶ÔÖ¸±êÍøÕ¾µÄÿ¸öÒªÇó¶¼½«Ê¹ÓÃÒ»¸öËæ»ú²éÎÊ×Ö·û´® £¬ÕâÑùÒªÇó¾Í²»»áͨ¹ý»º´æ·þÎñ£¨ÈçCloudflare£©Ìṩ·þÎñ £¬¶øÊÇÖ±½ÓÓɱ»¹¥»÷µÄ·þÎñÆ÷½Ó¹Ü¡£


https://www.bleepingcomputer.com/news/security/hacked-wordpress-sites-force-visitors-to-ddos-ukrainian-targets/


Minerva°ä²¼¹ØÓÚÀÕË÷Èí¼þSunCryptµÄ·ÖÎö»ã±¨ 


3ÔÂ28ÈÕ £¬Minerva Labs°ä²¼¹ØÓÚÀÕË÷Èí¼þSunCryptµÄ·ÖÎö»ã±¨¡£SunCryptÊÇRaaSÍÅ»ï £¬ÓÚ2019Äê10Ô³õ´Î³öÏÖ £¬ÊÇ×îÔçʹÓÃÈý³ÁÀÕË÷Õ½ÊõµÄ×éÖ¯Ö®Ò»¡£»ã±¨Ö¸³ö £¬´Ë2022 SunCrypt±äÖÖÔö³¤Á˺öàеÄÖ°ÄÜ £¬Ô̺¬ÖÕÖ¹¹ý³Ì¡¢ÖÕ³¡·þÎñ²¢¶Ï¸ùÀÕË÷Èí¼þÖ´Ðеĺۼ£¡£¸ÃÀÕË÷Èí¼þ»¹Ê¹ÓÃÒ»¸öwinlogon.exe½Ó¼ûÁîÅÆ £¬²¢Í¨¹ýʹÓÃSetThreadToken APIŲÓý«ÆäÉèÖÃΪÆäÖ÷Ï̡߳£


https://blog.minerva-labs.com/suncrypt-ransomware-gains-new-abilities-in-2022


Rapid7°ä²¼¹ØÓÚ2021Ä갲ȫ·ìÏ¶Ì¬ÊÆµÄ·ÖÎö»ã±¨


3ÔÂ28ÈÕ £¬Rapid7°ä²¼ÁËÆä×îеķìÏ¶Ì¬ÊÆ·ÖÎö»ã±¨ £¬×êÑÐÁË2021Äê×îÏÔÖøµÄ°²È«·ì϶ºÍÍøÂç¹¥»÷¡£2021ÄêµÄÍþвÖÐ £¬³¬¹ý50%µÄʼÓÚÁãÈÕ·ì϶¡£¸Ã»ã±¨×êÑÐÁË50¸ö·ì϶ £¬ÆäÖÐÓÐ43¸öÒѱ»ÀûÓà £¬½üÒ»°ëÊÇÔÚ½¨¸´Ö®Ç°±»ÓÃÓÚÁãÈÕ¹¥»÷¡£ÓÃ×÷ÁãÈÕ¹¥»÷µÄ·ì϶ÊýÁ¿±È2020ÄêÔö³¤ÁË100% £¬ÇÒÀûÓõľùÔȹ¦·ò´Ó2020ÄêµÄ42È«¹ú½µµ½2021ÄêµÄ12Ì죻66%µÄ·ì϶±»¹éÀàΪ¿í·ºÍþв £¬ÆäÖÐ60%ÒÔÉϱ»ÓÃÓÚÀÕË÷¹¥»÷¡£


https://www.rapid7.com/info/2021-vulnerability-intelligence-report/


CISAÓëÄÜÔ´²¿½áºÏ°ä²¼Õë¶ÔUPSÉ豸µÄ¹¥»÷µÄÕ÷ѯ


3ÔÂ29ÈÕ £¬ÃÀ¹úCISAÓëÄÜÔ´²¿½áºÏ°ä²¼ÁËÕë¶Ô²»¼ä¶ÏµçÔ´(UPS)É豸µÄ¹¥»÷µÄ°²È«Õ÷ѯ¡£¹«¸æÖ¸³ö £¬ÕâЩ»ú¹¹·¢ÏÖ¹¥»÷Õßͨ³£Í¨¹ýδ¸ü¸ÄµÄĬÈÏÓû§ÃûºÍÃÜÂëÀ´½Ó¼û¸÷ÀàÁªÍøµÄUPSÉ豸,×éÖ¯Äܹ»Í¨¹ý´Ó»¥ÁªÍøÉÑþ³ØýÖÎÀí½Ó¿ÚÀ´»º½â¶ÔÆäUPSÉ豸µÄ¹¥»÷¡£CISAºÍDOE»¹ÌṩÁËÆäËüµÄ»º½â´ëÊ© £¬ÆäÖÐÔ̺¬²éÕÒ×éÖ¯ÍøÂçÉϵÄËùÓÐUPSºÍÆäËüÓ¦¼±µçԴϵͳ £¬²¢È·±£ËüÃÇÎÞ·¨Í¨¹ýInternet½Ó¼û¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/03/29/mitigating-attacks-against-uninterruptable-power-supply-devices




°²È«¹¤¾ß


Gitcolombo


OSINT ¹¤¾ß £¬ÓÃÓÚ´Ó git ´æ´¢¿âÖÐÌáÈ¡ÓйØÈËÔ±µÄÐÅÏ¢¡£


https://github.com/soxoj/gitcolombo


ScheduleRunner


AC# ¹¤¾ß £¬¿É¸ü½Ã½ÝµØ×Ô½ç˵´òË㹤×÷ £¬ÒÔʵÏÖºì¶Ó²Ù×÷ÖеÄÓÆ¾ÃÐԺͺáÏòÒÆ¶¯¡£


https://github.com/netero1010/ScheduleRunner


phantun


Ò»¸öÇáÁ¿¼¶ºÍ¼±¾çµÄ UDP µ½ TCP »ìºÏÆ÷¡£


https://github.com/dndx/phantun/




°²È«·ÖÎö


AnonymousºÚ¿ÍÈëÇÖ 2 ¼Ò¶íÂÞ˹¹¤Òµ¹«Ë¾ £¬Ð¹Â¶ 112GB Êý¾Ý


https://www.hackread.com/anonymous-hack-russian-industrial-firms-data-leak/


Ð嵀 Windows °²È«Ö°ÄÜ¿É×èÖ¹Ò×Êܹ¥»÷µÄÇý¶¯·¨Ê½


https://www.bleepingcomputer.com/news/microsoft/new-windows-security-feature-blocks-vulnerable-drivers/


¶íÂÞ˹ÒòÉ豸Ƿȱ¶øÃæ¶Ô»¥ÁªÍøÖжÏ


https://www.bleepingcomputer.com/news/technology/russia-facing-internet-outages-due-to-equipment-shortage/


΢ÈíΪ AMD Çý¶¯µÄ Surface Laptop 4 °ä²¼¹Ì¼þ¸üÐÂ


https://news.softpedia.com/news/microsoft-releases-firmware-update-for-amd-powered-surface-laptop-4-535118.shtml


Trend MicroÅû¶Purple Fox½üÆÚ¹¥»÷»î¶¯µÄϸ½ÚÐÅÏ¢


https://www.trendmicro.com/en_us/research/22/c/purple-fox-uses-new-arrival-vector-and-improves-malware-arsenal.html