AgentTesla»ùÓÚÎÞÎļþ .NET µÄ´úÂë×¢Èë½øÐÐÁ÷´«
Ðû²¼Ê±¼ä 2024-04-304ÔÂ29ÈÕ£¬×î½üµÄ¶ñÒâÈí¼þ»î¶¯Ê¹Óà Word ÎĵµÖÐµÄ VBA ºêÀ´ÏÂÔز¢Ö´ÐÐ 64 λ Rust ¶þ½øÖÆÎļþ¡£¸Ã¶þ½øÖÆÎļþ½ÓÄÉÎÞÎļþ×¢Èë¼¼Êõ½«¶ñÒâ AgentTesla ÓÐЧ¸ºÔؼÓÔص½ÆäÄÚ´æ¿Õ¼äÖС£¸Ã¶ñÒâÈí¼þÀûÓà CLR Íйܣ¨Ò»ÖÖ±¾»ú½ø³ÌÖ´ÐÐ .NET ´úÂëµÄ»úÖÆ£©À´ÊµÏÖ´ËÄ¿µÄ£¬¶øÇÒ¶¯Ì¬¼ÓÔØ .NET ÔËÐÐʱ¿â£¬´Ó¶øÔÊÐí¶ñÒâÈí¼þÔÚ²»½«ÎļþдÈë¹âÅ̵ÄÇé¿öϽøÐвÙ×÷¡£¸Ã¶ñÒâÈí¼þͨ¹ýÐÞ²¹¡°EtwEventWrite¡±API À´½ûÓà Windows ʼþ¸ú×Ù (ETW)£¬È»ºó´ÓÌض¨ URL ÏÂÔØ°üÂÞ AgenetTesla ÓÐЧ¸ºÔØµÄ shellcode¡£È»ºóʹÓá°EnumSystemLocalesA¡±API Ö´ÐÐ shellcode¡£
https://gbhackers.com/clr-hosting-used-by-agenttesla/
2. Õë¶Ô USPS µÄÍøÂçµöÓã»î¶¯Óë USPS ×Ô¼ºÒ»Ñù¶à
4ÔÂ26ÈÕ£¬Akamai Ñо¿ÈËÔ±·¢ÏÖÁË´óÁ¿¼«ÓпÉÄܵĶñÒâ»î¶¯ºÍÉù³ÆÓëÃÀ¹úÓÊÕþ·þÎñ (USPS) Ïà¹ØµÄÓòÃû¡£Akamai Ñо¿ÈËÔ±½«Îå¸öÔµĺϷ¨ÓòÃû usps[.]com µÄ DNS Á÷Á¿Óë·Ç·¨×éºÏÇÀ×¢ÓòÃûµÄ DNS Á÷Á¿½øÐÐÁ˱ÈÁ¦¡£¶ñÒâÓòÓë usps[.]com µÄ×ܲéѯ¼ÆÊý¼¸ºõÏàͬ£¬¼´Ê¹½ö¼ÆËã°üÂÞÃ÷È· USPS Ëõд´ÊµÄÓòÒ²ÊÇÈç´Ë¡£¾¡¹ÜÔÚ´Ë·ÖÎöÖУ¬USPS Ó®µÃÁËÕâ 5 ¸öÔÂÆÚ¼ä×ܲéѯÁ¿µÄ 51%£¬µ«ÎÒÃǹýÂËÊý¾ÝµÄ·½Ê½±íÃ÷£¬¶ñÒâÁ÷Á¿Ã÷ÏÔÁè¼ÝÁËÏÖʵÊÀ½çÖеĺϷ¨Á÷Á¿¡£ÎÒÃÇ¿´µ½¶ñÒâÐÐΪÕß½ÓÄÉÁËÁ½ÖÖ²îÒìµÄÒªÁ죺ËûÃÇҪô½«Á÷Á¿ÊèÉ¢µ½Ðí¶à²îÒìµÄÓòÃû£¬ÒªÃ´½öʹÓü¸¸öÓò£¬Ã¿¸öÓò¶¼ÓдóÁ¿Á÷Á¿¡£Õâ¿ÉÄÜÊdzöÓÚ»ìÏýÄ¿µÄ£ºÔËÓªÉ̺ÍÆäËûÍйÜÌṩÉÌÒâʶµ½ÕâЩթƵÄÆÕ±é´æÔÚ£¬²¢ÕýÔÚ¾¯ÌèµØʵÑéʶ±ðºÍɾ³ýÕâЩҳÃæ¡£¿¼Âǵ½Ïû³ýÕâЩƾֵĹØעˮƽ£¬ËûÃǵĽá¹ûºÍÎÒÃǵÄÊÓ²ì¸üÁîÈ˵£ÓÇ¡£
https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic
3. ¹È¸èä¯ÀÀÆ÷µÄкóÁ¿×Ó¼ÓÃܼ¼Êõ¿ÉÄÜ»áÆÆ»µ TLS Á¬½Ó
4ÔÂ28ÈÕ£¬Ò»Ð© Google Chrome Óû§³ÂËßÔÚ Chrome 124 ÉÏÖÜÐû²¼ºó£¬ÔÚĬÈÏÆôÓÃеĿ¹Á¿×Ó X25519Kyber768 ·â×°»úÖƵÄÇé¿öÏ£¬Á¬½Óµ½ÍøÕ¾¡¢·þÎñÆ÷ºÍ·À»ðǽʱ·ºÆðÎÊÌâ¡£¹È¸èÒѲâÊÔÁ¿×ÓÄþ¾² TLS ÃÜÔ¿·â×°»úÖÆ£¬ÏÖÒÑÔÚ×îÐ嵀 Chrome °æ±¾ÖÐΪËùÓÐÓû§ÆôÓá£Ð°汾ÀûÓÃÓÃÓÚ TLS 1.3 ºÍ QUIC Á¬½ÓµÄ Kyber768 ¿¹Á¿×ÓÃÜÔ¿ÐÉÌËã·¨À´±£»¤ Chrome TLS Á÷Á¿ÃâÊÜÁ¿×ÓÃÜÂë·ÖÎö¡£ÕâЩ´íÎó²»ÊÇÓÉ Google Chrome ÖеĴíÎóÒýÆðµÄ£¬¶øÊÇÓÉ Web ·þÎñÆ÷δÄÜÕýȷʵÏÖ´«Êä²ãÄþ¾²ÐÔ (TLS) ÒÔ¼°ÎÞ·¨´¦ÖÃÓÃÓÚºóÁ¿×Ó¼ÓÃܵĽϴó ClientHello ÏûÏ¢ÒýÆðµÄ¡£Èç¹û²»Ö§³Ö X25519Kyber768£¬Õâ»áµ¼ÖÂËûÃǾܾøʹÓà Kyber768 ¿¹Á¿×ÓÃÜÔ¿ÐÉÌËã·¨µÄÁ¬½Ó£¬¶ø²»ÊÇÇл»µ½¾µä¼ÓÃÜ¡£
https://www.bleepingcomputer.com/news/security/google-chromes-new-post-quantum-cryptography-may-break-tls-connections/
4. Kotak Mahindra ÒøÐб»½ûÖ¹Ó¦Ó÷¨Ê½×¢²áпͻ§
4ÔÂ28ÈÕ£¬Ó¡¶È´¢ÐîÒøÐÐÒÑʵʩ¶Ô Kotak Mahindra ÒøÐеĽûÁ½ûֹͨ¹ýÔÚÏß·þÎñºÍÓ¦Ó÷¨Ê½×¢²áпͻ§¡£¸Ã´ëÊ©ÊÇÔÚITϵͳ¹ÜÀíÖз¢ÏÖÖØ´óȱÏݺó½ÓÄɵģ¬ÕâЩȱÏÝ°üÂÞIT×ʲú¹ÜÀí¡¢¸üкͱ任¡¢Óû§·ÃÎÊ¡¢¹©Ó¦ÉÌÏà¹Ø·çÏÕ¡¢Êý¾ÝÄþ¾²¡¢Êý¾Ýй¶Ԥ·À¼ÆıºÍÔÖÄѻָ´¼Æı¡£Kotak Mahindra Bank ΪÁè¼Ý 4100 Íò¿Í»§Ìṩ·þÎñ£¬¹ÜÀí×ÅÁè¼Ý 5000 ÒÚÃÀÔªµÄ×ʲú£¬¸ÃÒøÐÐÔÚ 2022/2023 ²ÆÄêÄê¶È³ÂËßÖÐÌåÏÖ£¬¸ÃÒøÐÐÒ»Ö±ÖÂÁ¦ÓÚ¼ÓÇ¿Äþ¾²´ëÊ©¡£È»¶ø£¬ÑëÐÐÈÏΪÕâЩŬÁ¦²»¹»¡£ÀúʱÁ½ÄêµÄ¼ì²éÏÔʾ£¬¸ÃÐÐδÄܳäʵ½â¾öIT·çÏÕºÍÐÅÏ¢Äþ¾²¹ÜÀíÎÊÌâ¡£´ËÍ⣬¸ÃÒøÐл¹¾ÀúÁËÓ°Ïì¿Í»§µÄ¼¼Êõ¹ÊÕÏ£¬Òý·¢ÁËÈËÃǶÔÆä±£³ÖÔËÓªµ¯ÐÔÓëÆäÔö³¤Âʱ£³ÖÒ»ÖµÄÄÜÁ¦µÄµ£ÓÇ¡£
https://meterpreter.org/rbi-cracks-down-on-kotak-mahindra-online-banking-halt/
5. ºÚ¿ÍÉù³ÆÒÑÉø͸°×¶íÂÞ˹µÄÖ÷ÒªÄþ¾²²¿ÃÅ
4ÔÂ28ÈÕ£¬°×¶íÂÞ˹ºÚ¿Í×éÖ¯Éù³ÆÒÑÉø͸µ½¸Ã¹úÖ÷Òª¿Ë¸ñ²ªÄþ¾²»ú¹¹µÄÍøÂ磬²¢·ÃÎÊÁ˸Ã×éÖ¯ 8600 ¶àÃûÔ±¹¤µÄÈËʵµ°¸£¬¸Ã×éÖ¯ÈÔÒÔÆäËÕÁªÃû³ÆÃüÃû¡£ÎªÁËÖ§³ÖÆä˵·¨£¬°×¶íÂÞ˹ÍøÂçÓλ÷¶ÓÔÚÏûÏ¢Ó¦Ó÷¨Ê½ Telegram µÄÒ³ÃæÉÏÐû²¼Á˸ÃÍøÕ¾¹ÜÀíÔ±¡¢Êý¾Ý¿âºÍ·þÎñÆ÷ÈÕÖ¾µÄÁÐ±í¡£ÍøÂçÓλ÷¶ÓÔÚ¹ýÈ¥ËÄÄêÖж԰׶íÂÞ˹¹Ù·½Ã½Ìå½øÐÐÁËÊý´Î´ó¹æÄ£¹¥»÷£¬²¢ÔÚ 2022 Äê¶Ô°×¶íÂÞ˹Ìú·½øÐÐÁË 3 ´ÎºÚ¿Í¹¥»÷£¬½Ù³ÖÁ˽»Í¨µÆºÍ¿ØÖÆϵͳµÄ¿ØÖÆȨ¡£
https://www.securityweek.com/hackers-claim-to-have-infiltrated-belarus-main-security-service/
6. ץȡDiscordµÄ6.2ÒÚÌõÐÅÏ¢µÄSpy.petÒѹرÕ
4ÔÂ29ÈÕ£¬¸ÃÍøÕ¾×ÔÈ¥Äê 11 ÔÂÒÔÀ´Ò»Ö±ÔÚÇÔÈ¡ Discord Óû§µÄ¹«¹²Êý¾Ý£¬²¢ÓÚÉÏÖܱ»·¢ÏÖ¸Ãƽ̨°üÂÞÀ´×Ô 14000 ¶ą̀ Discord ·þÎñÆ÷µÄ½ü 6.2 ÒÚÓû§µÄÏûÏ¢ºó±»Æع⡣µ± Spy.pet ±»·¢ÏÖʱ£¬Discord ÕýÔÚŬÁ¦¶ÔÈκÎÎ¥·´Æä·þÎñÌõ¿îµÄÈ˽ÓÄÉÐж¯£¬µ«ÎÞ·¨Í¸Â¶¸ü¶àÐÅÏ¢¡£DiscordÒѾ½ûÓÃÓëSpy.pet ÍøÕ¾ÓйصÄÕÊ»§¡£Spy.pet Éù³Æ¿ÉÒÔ·ÃÎ浀 Discord ·þÎñÆ÷ÊýÁ¿ÉÏÖÜ¿ªÊ¼Ï½µ£¬ÉÏÖÜËĽµÖÁÁã¡£µ½ÖÜÎ壬Spy.pet ÍøÕ¾×Ô¼ºÒѾֹͣÔËÓª¡ª¡ª¾¡¹ÜÉв»Çå³þ¸ÃÍøÕ¾ÊÇ·ñÒòΪ Discord µÄÐÐΪ¶øÀëÏß¡£
https://www.theregister.com/2024/04/29/infosec_in_brief/