΢Èí·¢ÏÖ³¯Ïʹ¥»÷ÕßÀûÓÃH0lyGh0st¹¥»÷ÖÐСÐÍÆóÒµ

Ðû²¼Ê±¼ä 2022-07-18
1¡¢Î¢Èí·¢ÏÖ³¯Ïʹ¥»÷ÕßÀûÓÃH0lyGh0st¹¥»÷ÖÐСÐÍÆóÒµ

      

7ÔÂ14ÈÕ£¬Î¢ÈíÐû²¼³ÂËß·ÖÎöÁ˳¯ÏÊDEV-0530£¨×Ô³ÆÎªH0lyGh0st£©µÄ¹¥»÷¼ÆÄ±ÒÔ¼°ÆäÀÕË÷Èí¼þµÄ¼¼Êõϸ½Ú ¡£×Ô2021Äê6ÔÂÒÔÀ´£¬¸ÃÍÅ»ïÒ»Ö±ÔÚ¿ª·¢ºÍʹÓÃÀÕË÷Èí¼þ½øÐй¥»÷£¬²¢ÔçÔÚ2021Äê9Ô¾ÍÀÖ³ÉÈëÇÖÁ˶à¸ö¹ú¼ÒµÄСÐÍÆóÒµ ¡£Ñо¿ÈËÔ±½«¸ÃÍÅ»ïµÄÀÕË÷Èí¼þ¹éÀàΪÁ½¸öϵÁУºSiennaPurpleºÍSiennaBlue£¬²¢ÔÚÕâЩϵÁÐÏÂÈ·¶¨ÁËËĸö±äÌ壺BTLC_C.exe¡¢HolyRS.exe¡¢HolyLock.exeºÍBLTC.exe ¡£


https://www.microsoft.com/security/blog/2022/07/14/north-korean-threat-actor-targets-small-and-midsize-businesses-with-h0lygh0st-ransomware/


2¡¢ÃÀ¹úÖÐÇé¾Öǰ¹¤³ÌʦÒòVault 7й¶Ê¼þ¶ø±»ÖÎ×ï

      

¾Ý7ÔÂ14ÈÕ±¨µÀ£¬Å¦Ô¼µÄÒ»¸öÁª°îÅãÉóÍÅÐû²¼£¬ÖÐÑëÇ鱨¾ÖÈí¼þ¹¤³ÌʦÏòά»ù½âÃÜÍøÕ¾(WikiLeaks)й¶´óÁ¿»úÃÜÎļþµÄ×ïÃû½¨Á¢ ¡£ÏÖÄê33ËêµÄJoshua SchulteÃæÁٵľÅÏîÖ¸¿Ø×ïÃû¾ù½¨Á¢£¬°üÂÞ·Ç·¨ÊÕ¼¯¹ú·ÀÐÅÏ¢µÈ ¡£Î¬»ù½âÃܽ«ÕâЩ»úÃÜÎļþÃüÃûΪ¡°Vault 7¡±£¬²¢ÔÚ2017ÄêÐû²¼£¬ÕâЩÎļþÏêϸ½Ò¶ÁËCIAÈçºÎÈëÇÖµçÄÔ¡¢ÖÇÄÜÊÖ»ú¡¢Ó¦Óú͵çÊÓ»úµÈ ¡£Î¬»ù½âÃܳÆ£¬Vault 7ÊÇÓÐÊ·ÒÔÀ´¹ØÓÚCIAµÄ×î´óÒ»´Î»úÃÜÎļþÐû²¼ ¡£¸ß¼¶Ç鱨¹ÙÔ±ÆÕ±éÈÏΪ£¬ÕâÊǶÔÃÀ¹ú¼äµý»ú½á¹¹³É¹¥»÷µÄ×î¾ßÆÆ»µÐÔµÄйÃÜʼþÖ®Ò» ¡£


https://thehackernews.com/2022/07/former-cia-engineer-convicted-of.html


3¡¢Cloudflare³ÆÆä½üǧÃû¿Í»§Ôâµ½À´×ÔMantisµÄDDoS¹¥»÷ 

      

ýÌå7ÔÂ14ÈÕ±¨µÀ£¬CloudflareÌåÏÖÆäÔÚ6Ô·ݻº½âÁËÀ´×ÔMantisµÄ´ó¹æÄ£DDoS¹¥»÷ ¡£MantisÖ÷ÒªÕë¶ÔITºÍµçÐÅÐÐÒµ(36%)¡¢ÐÂÎÅýÌåºÍ³öÊéÎïÐÐÒµ(15%)¡¢½ðÈÚÐÐÒµ(10%) ºÍÓÎÏ·ÐÐÒµ(12%)µÄʵÌå ¡£¸Ã¹«Ë¾Ö¸³ö£¬ÔÚ¹ýÈ¥30ÌìÀÆä½üǧÃû¿Í»§Ôâµ½ÁË3000¶à´ÎDDoS¹¥»÷ ¡£ÓëÓÉIoTÉ豸×é³ÉµÄ´«Í³½©Ê¬ÍøÂç²îÒ죬MantisʹÓõÄÊDZ»½Ù³ÖµÄÐéÄâ»úºÍ·þÎñÆ÷£¬Ëü½öÓÃ5000¶à¸ö»úÆ÷È˾ÍÄÜÿÃëÉú³É2600Íò¸öHTTPSÇëÇó ¡£¸Ã»î¶¯Ö÷ÒªÕë¶ÔÃÀ¹ú(20%)ºÍ¶íÂÞ˹(15%)£¬Æä´ÎÊÇÍÁ¶úÆä¡¢·¨¹úºÍ²¨À¼µÈ ¡£


https://www.bleepingcomputer.com/news/security/mantis-botnet-behind-the-record-breaking-ddos-attack-in-june/


4¡¢Netwrix AuditorÖдæÔÚ¿ÉÓÃÀ´Ö´ÐÐÈÎÒâ´úÂëµÄ©¶´

      

¾Ý7ÔÂ16ÈÕ±¨µÀ£¬Bishop FoxµÄÔÚNetwrix AuditorÈí¼þÖз¢ÏÖÁËÒ»¸ö©¶´£¬¿ÉÓÃÀ´ÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐÈÎÒâ´úÂë ¡£Netwrix AuditorÊÇÒ»¿îÔÊÐí×éÖ¯¼à¿ØÆäIT»ù´¡ÉèÊ©µÄÉó¼ÆÈí¼þ£¬±»È«ÇòÓÐÁè¼Ý11000¸ö×é֯ʹÓà ¡£ÕâÊÇÒ»¸ö²»Äþ¾²µÄ¹¤¾ß·´ÐòÁл¯Â©¶´£¬»ù´¡Ô­ÒòÊÇ´æÔÚÒ»¸ö²»Äþ¾²µÄ.NETÔ¶³Ì´¦Ö÷þÎñ£¬¿ÉÔÚNetwrix·þÎñÆ÷ÉϵÄTCP¶Ë¿Ú9004ÉÏ·ÃÎÊ£¬Äܱ»ÓÃÀ´ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâÃüÁî ¡£´ËÍ⣬ÓÉÓÚ¸ÃÃüÁîÊÇÒÔNT AUTHORITY/SYSTEMȨÏÞÖ´ÐеÄ£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÍêÈ«¿ØÖÆNetwrix·þÎñÆ÷ ¡£Ä¿Ç°£¬Â©¶´Òѱ»ÐÞ¸´ ¡£


https://securityaffairs.co/wordpress/133310/hacking/netwrix-auditor-flaw.html 


5¡¢Unit 42͸¶Õë¶ÔElastix VoIPϵͳµÄ¹¥»÷»î¶¯µÄϸ½Ú

      

7ÔÂ15ÈÕ£¬Unit 42³ÆÆä·¢ÏÖÁËÒ»³¡Õë¶ÔElastix VoIPµç»°·þÎñÆ÷µÄ´ó¹æÄ £»î¶¯ ¡£ElastixÊÇͳһͨÐŵķþÎñÆ÷Èí¼þ£¬ÓÃÓÚFreePBXµÄDigiumµç»°Ä£¿é ¡£¹¥»÷»î¶¯¿ªÊ¼×Ô2021Äê12Ô£¬ÖÁ2022Äê3ÔÂÑо¿ÈËÔ±ÒÑ·¢ÏÖÁËÁè¼Ý50Íò¸ö¶ñÒâÈí¼þÑù±¾ ¡£³ÂËßÖ¸³ö£¬¹¥»÷Õß»áͨ¹ýÔÚÄ¿±êµÄDigiumÈí¼þÖÐÏÂÔØºÍÖ´ÐÐÌØ±ðµÄpayload£¬Ö²ÈëÒ»¸öweb shellÀ´ÇÔÈ¡Êý¾Ý ¡£¾Íʱ¼äÏß¶øÑÔ£¬Web shellËÆºõÓëRest Phone Apps(restapps)Ä£¿éÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-45461£©Ïà¹Ø ¡£


https://unit42.paloaltonetworks.com/digium-phones-web-shell/


6¡¢Wordfence³Æ´ó¹æÄ£¹¥»÷»î¶¯ÒÑɨÃè160Íò¸öWPÍøÕ¾

      

¾ÝýÌå7ÔÂ15Èճƣ¬WordfenceÑо¿ÈËÔ±¼ì²âµ½ÁËÒ»³¡´ó¹æÄ£¹¥»÷»î¶¯£¬ÒѾ­É¨ÃèÁ˽ü160Íò¸öWordPressÍøÕ¾ ¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔKaswara Modern WPBakeryÒ³ÃæÉú³ÉÆ÷£¬¸Ã²å¼þÒѱ»Æä¿ª·¢Õß·ÅÆú ¡£¾ÝWordfenceÒ£²âÊý¾Ý£¬¹¥»÷´Ó7ÔÂ4ÈÕ¿ªÊ¼£¬Ä¿Ç°ÈÔÔÚ½øÐÐÖУ¬Æ½¾ùÿÌìÓÐ443868´Î¹¥»÷ʵÑé ¡£¹¥»÷Õß»áÏò¡°wp-admin/admin-ajax/php¡±·¢ËÍPOSTÇëÇ󣬲¢ÀûÓòå¼þµÄ¡°uploadFontIcon¡±AJAXº¯ÊýÉÏ´«°üÂÞPHPÎļþµÄ¶ñÒâZIP payload ¡£ÕâЩ¹¥»÷À´×Ô10215¸ö²îÒìµÄIPµØÖ·£¬Ñо¿ÈËÔ±½¨ÒéÓû§Á¢¿Ìɾ³ý¸Ã²å¼þ£¬²¢×èÖ¹¹¥»÷ÕßʹÓõÄIPµØÖ· ¡£


https://www.bleepingcomputer.com/news/security/attackers-scan-16-million-wordpress-sites-for-vulnerable-plugin/