ÃÀ¹úµÄRateForceÍøÕ¾Ô¼93 GBµÄÁè¼Ý25ÍòÌõ¼Í¼й¶

Ðû²¼Ê±¼ä 2023-06-26

1¡¢ÃÀ¹úµÄRateForceÍøÕ¾Ô¼93 GBµÄÁè¼Ý25ÍòÌõ¼Í¼й¶


¾ÝýÌå6ÔÂ22ÈÕ±¨µÀ £¬ÃÀ¹úÆû³µ°ü¹Ü±È¼ÛÍøÕ¾RateForceй¶ÁË´ó×ÚÓû§PIIÐÅÏ¢¡£×ܹ²Ð¹Â¶ÁË96175¸öÎļþ¼Ð £¬ÆäÖаüÀ¨255756Ìõ¼Í¼ £¬×ܾÞϸΪ93.93GB¡£´Ë´Îй¶ÊÂÎñÒ»Á¬ÁËÖÁÉÙÁ½ÖÜ £¬Ô´ÓÚÒ»¸ö²»Çå¾²µÄÊý¾Ý¿â £¬Éæ¼°ÖÖÖÖÎļþµÄɨÃè¼þºÍͼƬ £¬°üÀ¨³µÁ¾¹ÒºÅ¡¢¼ÝʻִÕÕ¡¢°ü¹Ü¿¨ºÍ³µÁ¾ËùÓÐȨµÈ¡£½øÒ»³ÌÐò²é·¢Ã÷ £¬Êý¾Ý¿âÖб£µ¥µÄÖ÷Òª°ü¹Ü¹«Ë¾ÊÇUSA Underwriters¡£USA Underwriters³ÎÇåµÀ £¬ËûÃÇÔ¼ÇëÁË×ÔÁ¦µÄIT¹«Ë¾À´ÖÎÀíÆä»ù´¡ÉèÊ© £¬²¢ÇÒ²»¼ç¸ºÖÎÀí̻¶µÄÊý¾Ý¿âµÄÈκÎÔðÈΡ£ÏÖÔÚ £¬Êý¾Ý¿âÒѱ»± £»¤ÆðÀ´¡£


https://www.hackread.com/rateforce-auto-insurance-data-leak/


2¡¢Ä¾Âí»¯³¬µÈÂíÀï°ÂÐÖµÜÓÎÏ·×°ÖóÌÐòÈö²¥¶àÖÖ¶ñÒâÈí¼þ


CybleÔÚ6ÔÂ23ÈÕ³ÆÆä·¢Ã÷ÁËÒ»¸öÊÊÓÃÓÚWindowsµÄľÂí»¯³¬µÈÂíÀï°ÂÐÖµÜÓÎÏ·×°ÖóÌÐò £¬±»ÓÃÓÚÈö²¥¶àÖÖ¶ñÒâÈí¼þ¡£°üÀ¨XMRÍÚ¿ó³ÌÐò¡¢SupremeBotÍÚ¿ó¿Í»§¶ËºÍ¿ªÔ´UmbralÇÔÈ¡³ÌÐò¡£Ñо¿Ö°Ô±Ö¸³ö £¬¹¥»÷ÕßÖ®ÒÔÊÇÕë¶ÔÓÎÏ·Íæ¼Ò £¬ÊÇÓÉÓÚËûÃǾ­³£Ê¹ÓÃÇ¿Ê¢µÄÓ²¼þ¾ÙÐÐÓÎÏ· £¬ÕâºÜÊÇÊʺÏÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¹¥»÷Õ߸Ķ¯ÁËNSIS×°ÖóÌÐòÎļþ £¬ÌìÉúµÄ¿ÉÖ´ÐÐÎļþ°üÀ¨Õýµ±µÄÓ¦ÓÃÒÔ¼°¶ñÒâ¿ÉÖ´ÐÐÎļþjava.exeºÍatom.exe¡£×°ÖÃÀֳɺó»áÆô¶¯ÓÎÏ· £¬²¢ÔÚºǫ́¾ÙÐÐÍÚ¿ó¡£


https://blog.cyble.com/2023/06/23/trojanized-super-mario-game-installer-spreads-supremebot-malware/


3¡¢FortinetÐÞ¸´FortiNAC RCEÎó²îCVE-2023-33299


¾Ý6ÔÂ23ÈÕ±¨µÀ £¬FortinetÐû²¼Çå¾²¸üР£¬ÐÞ¸´ÁËÆäÁãÐÅÍлῴ·¨¾ö¼Æ»®FortiNACÖеķ´ÐòÁл¯Îó²î¡£¸ÃÎó²î×·×ÙΪCVE-2023-33299 £¬CVSSÆÀ·ÖΪ9.6¡£FortinetµÄÇå¾²×ÉѯÖÐÖ¸³ö £¬FortiNACÖеIJ»¿ÉÐÅÊý¾Ý·´ÐòÁл¯Îó²î¿ÉÄܵ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÃÌØÖƵÄTCP/1050·þÎñÇëÇóÖ´ÐÐδ¾­ÊÚȨµÄ´úÂë»òÏÂÁî¡£¹©Ó¦ÉÌûÓÐÌṩ»º½â½¨Òé £¬Òò´Ë½¨ÒéÓû§Á¬Ã¦Ó¦ÓÿÉÓõÄÇå¾²¸üС£


https://securityaffairs.com/147770/security/fortinet-fortinac-critical-flaw.html


4¡¢Ñо¿Ö°Ô±·¢Ã÷еÄPindOS·Ö·¢IcedIDºÍBumblebee


Deep InstinctÔÚ6ÔÂ22ÈÕÅû¶ÁËÒ»ÖÖеÄJavaScript dropper PindOS £¬»á·Ö·¢¶ñÒâÈí¼þBumblebeeºÍIcedID¡£BumblebeeÊÇÒ»ÖÖ¶ñÒâÈí¼þ¼ÓÔسÌÐò £¬IcedIDÊÇÒ»ÖÖÄ£¿é»¯ÒøÐжñÒâÈí¼þ¡£¶ÔPindOSµÄÔ´´úÂëÆÊÎöÏÔʾ £¬Ëü°üÀ¨¶íÓïµÄ×¢ÊÍ¡£Ñо¿Ö°Ô±ÌåÏÖ £¬Ò»µ©È¥³ý»ìÏý £¬¸Ãdropper¾ÍºÜÊǼòÆÓ¡£ËüÓÉÒ»¸öº¯Êýexec×é³É £¬°üÀ¨Ëĸö²ÎÊý £¬UserAgent¡¢URL1¡¢URL2ºÍRunDLL £¬ÆäÖÐURL2×÷ΪURL1ÎÞ·¨»ñÈ¡DLLʱµÄºó±¸¡£


https://www.deepinstinct.com/blog/pindos-new-javascript-dropper-delivering-bumblebee-and-icedid


5¡¢Unit 42¹ûÕæʹÓöà¸öIoTÎó²îµÄÐÂÒ»ÂÖMiraiÔ˶¯


6ÔÂ22ÈÕ £¬Unit 42¹ûÕæÁËʹÓöà¸öIoTÎó²îµÄÐÂÒ»ÂÖMiraiÔ˶¯¡£¸ÃÔ˶¯×Ô3ÔÂ14ÈÕ×îÏÈ»îÔ¾ £¬²¢ÔÚ4ÔºÍ6Ô·ºÆð¼¤Ôö¡£ÕâÒ»±äÌåÕë¶Ô22¸öÎó²î £¬Ö¼ÔÚ¿ØÖÆD-Link¡¢Arris¡¢Zyxel¡¢TP-Link¡¢Tenda¡¢NetgearºÍMediaTekµÈ×°±¸ £¬²¢Ê¹ÓÃËüÃÇÖ´ÐÐDDoS¹¥»÷¡£Unit 42»¹Ö¸³ö £¬¸ÃMirai±äÌå²»¾ß±¸±©Á¦Æƽâtelnet/SSHµÇ¼ƾ֤µÄ¹¦Ð§ £¬Òò´ËÆä·Ö·¢ÍêÈ«ÒÀÀµÓÚÔËÓªÖ°Ô±ÊÖ¶¯Ê¹ÓÃÎó²î¡£


https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/


6¡¢SecuronixÅû¶Õë¶ÔÓ¡¶ÈºÍÃÀ¹úµÄ´¹ÂÚÔ˶¯MULTI#STORM


6ÔÂ21ÈÕ £¬SecuronixÅû¶ÁË´úºÅΪMULTI#STORMµÄÐÂÒ»ÂÖ´¹ÂÚÔ˶¯ £¬Ö÷ÒªÕë¶ÔÓ¡¶ÈºÍÃÀ¹ú¡£¸ÃÔ˶¯Ê¹ÓÃÁËJavaScriptÎļþÔÚ±»Ñ¬È¾µÄϵͳÉÏÈö²¥Ô¶³Ì»á¼ûľÂí¡£¹¥»÷Á´Ê¼ÓÚÒ»¸öZIPÎļþREQUEST.zipÖб»ÑÏÖØ»ìÏýµÄJavaScriptÎļþREQUEST.js¡£×îÖÕ»á×°Ööà¸öÆæÒìµÄRAT £¬ÈçWarzone RATºÍQuasar RAT¡£ÔÚѬȾÁ´µÄ²î±ð½×¶Î £¬Á½Õ߶¼±»ÓÃÓÚC2¡£±ðµÄ £¬ÈÏÕæ×î³õÈëÇÖÖ÷»úµÄ¼ÓÔسÌÐòµÄ¹¦Ð§ÓëDBatLoaderºÜÊÇÏàËÆ £¬µ«ËüÓÃPython¿ª·¢ £¬²¢Ê¹ÓÃPyInstaller´ò°ü £¬Ê¹ÓÃÁËһЩÖØ´óµÄÊÖÒÕÀ´½¨É賤ÆÚÐÔ £¬²¢ÔÚ·Ö·¢payload֮ǰÈƹý¼ì²â¡£


https://www.securonix.com/securonix-threat-labs-security-advisory-multistorm-leverages-python-based-loader-as-onedrive-utilities-to-drop-rat-payloads/