Cash³ÆÆä820ÍòµÄÓû§ÐÅÏ¢ÒÑй¶ ÄÚ²¿Ô±¹¤Î¥¹æÏÂÔØ

°ä²¼¹¦·ò 2022-04-08

Cash³ÆÆä820ÍòµÄÓû§ÐÅÏ¢ÒÑй¶ £¬£¬£¬£¬£¬£¬ £¬ÄÚ²¿Ô±¹¤Î¥¹æÏÂÔØ


¾ÝýÌå4ÔÂ5ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬ £¬Cash App 820ÍòµÄÓû§ÐÅÏ¢ÒÑй¶¡£ ¡£¡£¡£¡£¡£¡£Cash AppµÄĸ¹«Ë¾Block,Inc.ÔÚÌá½»µÄ8-K±í¸ñÖаµÊ¾ £¬£¬£¬£¬£¬£¬ £¬ÊÂÎñ²úÉúÔÚ2021Äê12ÔÂ10ÈÕ £¬£¬£¬£¬£¬£¬ £¬ÆäÒ»¸öǰԱ¹¤ÔÚÈ¥Ö°ºóÏÂÔØÁËCash AppµÄÄÚ²¿»ã±¨¡£ ¡£¡£¡£¡£¡£¡£Õâ´Îй¶ÁËÓû§µÄÓ×ÎÒÐÅÏ¢ £¬£¬£¬£¬£¬£¬ £¬ÒÔ¼°ÆäÔÚCash AppÉϵÄͶ×ʻÓйصÄÐÅÏ¢ £¬£¬£¬£¬£¬£¬ £¬Èç³Ö¹ÉÁ¿ºÍÂòÂô»î¶¯µÈ¡£ ¡£¡£¡£¡£¡£¡£Block°µÊ¾ £¬£¬£¬£¬£¬£¬ £¬Ä¿Ç°ËûÃÇÔÚ֪ͨÊÜй¶ÊÂÎñÓ°ÏìµÄ820Íò¿Í»§ÓйشËʵĸü¶àÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cash-app-notifies-82-million-us-customers-about-data-breach/


ÎÚ¿ËÀ¼CERT-UA·¢ÏÖArmageddonÐÂÒ»ÂÖ´¹µö¹¥»÷»î¶¯


ýÌå4ÔÂ5ÈÕ³Æ £¬£¬£¬£¬£¬£¬ £¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××é(CERT-UA)·¢ÏÖÁËArmageddon(Gamaredon)еĴ¹µö»î¶¯¡£ ¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÒѾ­È·¶¨ÁËÁ½¸ö¶ÀÁ¢µÄ°¸¼þ £¬£¬£¬£¬£¬£¬ £¬Ò»¸öÕë¶ÔÎÚ¿ËÀ¼µÄ×éÖ¯ £¬£¬£¬£¬£¬£¬ £¬ÁíÒ»¸öÕë¶ÔÅ·ÃËÈ·µ±¾Ö»ú¹¹¡£ ¡£¡£¡£¡£¡£¡£Õë¶ÔÎÚ¿ËÀ¼µÄ»î¶¯ÒÔ¶íÂÞ˹ս·¸ÐÅϢΪµö¶ü £¬£¬£¬£¬£¬£¬ £¬Ê¹Óø½ÓÐHTMLÎļþµÄ´¹µöÓʼþ·Ö·¢¶ñÒâÈí¼þ£»£»£»£»£»£»£»£»Õë¶ÔÅ·Ã˵ĻÒÔ¾üʺÍÈË·Ö÷Òå¾ÈÖúΪÌâ £¬£¬£¬£¬£¬£¬ £¬Í¨¹ýÒ»¸öRAR¸½¼þ·Ö·¢¶ñÒâÈí¼þ¡£ ¡£¡£¡£¡£¡£¡£ArmageddonÓë¶íÂÞ˹FSBÓÐ¹Ø £¬£¬£¬£¬£¬£¬ £¬×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ukraine-spots-russian-linked-armageddon-phishing-attacks/


ContiÍÅ»ïй¶´ÓParker HannifinÇÔÈ¡µÄÊýGBÎļþ


ýÌå4ÔÂ5ÈÕ±¨Â·³Æ £¬£¬£¬£¬£¬£¬ £¬ÃÀ¹ú¹¤Òµ¹«Ë¾Parker Hannifin´óÁ¿Êý¾Ýй¶¡£ ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÖØÒªÎªº½¿Õº½Ìì¡¢ÒÆ¶¯ºÍ¹¤ÒµÁìÓòµÄ×éÖ¯Ìṩ¾«Ãܹ¤³Ì½â¾ö¹æ»®¡£ ¡£¡£¡£¡£¡£¡£ËüÔÚ3ÔÂ14ÈÕ¼ì²âµ½ÏµÍ³Ôâµ½ÈëÇÖ £¬£¬£¬£¬£¬£¬ £¬Ö®ºóÁ¢¿Ì¹Ø¹Ø²¿ÃÅϵͳ²¢·¢Õ¹µ÷²é¡£ ¡£¡£¡£¡£¡£¡£Ä¿Ç°µ÷²éÈÔÔÚ½øÐÐÖÐ £¬£¬£¬£¬£¬£¬ £¬µ«ÒÑÈ·¶¨Ô̺¬Ô±¹¤Ó×ÎÒÐÅÏ¢ÔÚÄڵIJ¿ÃÅÊý¾ÝÒѾ­Ð¹Â¶¡£ ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ £¬£¬£¬£¬£¬£¬ £¬ContiÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹«¿ªÁË´ÓParkerÇÔÈ¡µÄ³¬¹ý5GBÊý¾Ý £¬£¬£¬£¬£¬£¬ £¬²¢³ÆÕâ½öΪ±»µÁÊý¾ÝµÄ3%¡£ ¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/ransomware-gang-leaks-files-stolen-industrial-giant-parker-hannifin


Ó¢¹úThe WorksÔâµ½¹¥»÷ºó²¿ÃÅÁãÊÛÉ̵êÁÙʱ¹ØÃÅ


¾Ý4ÔÂ5ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬ £¬Ó¢¹úThe Works³ÆÆäϵͳÔâµ½·¸·¨½Ó¼û £¬£¬£¬£¬£¬£¬ £¬µ¼Ö²¿ÃÅÁãÊÛÉ̵êÁÙʱ¹ØÃÅ¡£ ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÓ¢¹úºÍ°®¶ûÀ¼Õ¼ÓÐ530¼ÒÃÅµê £¬£¬£¬£¬£¬£¬ £¬ÏúÊÛÊé¼®¡¢Íæ¾ß¡¢Îľߡ¢ÒÕÊõÆ·ºÍ¹¤ÒÕ×ÊÁÏµÈ £¬£¬£¬£¬£¬£¬ £¬ÄêÊÕÈëԼΪ3ÒÚÃÀÔª¡£ ¡£¡£¡£¡£¡£¡£The Works²¢Î´Åû¶¹ØÓÚÕâ´Î¹¦·òµÄ¸ü¶àϸ½Ú £¬£¬£¬£¬£¬£¬ £¬µ«ÆäÅäËÍ·þÎñÊܵ½Ó°Ïì £¬£¬£¬£¬£¬£¬ £¬ÓÐЩÃŵêÖ»ÄܽÓÊÜÏֽ𡣠¡£¡£¡£¡£¡£¡£²¿ÃÅýÌ屨· £¬£¬£¬£¬£¬£¬ £¬¸ÃÊÂÎñÔ´ÓÚÒ»ÃûÔ±¹¤Ôâµ½¶ñÒâÓʼþµÄ¹¥»÷ £¬£¬£¬£¬£¬£¬ £¬µ¼Ö¹«Ë¾µÄϵͳϰȾÀÕË÷Èí¼þ¡£ ¡£¡£¡£¡£¡£¡£  


https://www.bitdefender.com/blog/hotforsecurity/the-works-hit-by-hackers-uk-retailer-shuts-some-stores-after-problems-with-payment-tills/


Symantec°ä²¼CicadaÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


4ÔÂ5ÈÕ £¬£¬£¬£¬£¬£¬ £¬Symantec°ä²¼ÁËCicada£¨±ðÃûAPT10£©½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£ ¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ2021ÄêÄêÖÐ £¬£¬£¬£¬£¬£¬ £¬ÖØÒªÕë¶Ô¶à¸ö¹ú¶È£¨Éæ¼°Å·ÖÞ¡¢ÑÇÖ޺ͱ±ÃÀ£©È·µ±¾Ö¡¢Ë¾·¨¡¢×ڽ̺ͷǵ±¾Ö×éÖ¯(NGO)¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈͨ¹ý佨¸´µÄMicrosoft Exchange·þÎñÆ÷»ñµÃ³õʼ½Ó¼ûȨÏÞ £¬£¬£¬£¬£¬£¬ £¬²¢Ê¹ÓúóÃÅSodamasterµÈ¶ñÒâÈí¼þÖ´Ðй¥»÷¡£ ¡£¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß»¹Í¨¹ýDLL²àÔØ¼¼Êõ £¬£¬£¬£¬£¬£¬ £¬ÀûÓúϷ¨µÄVLCýÌå²¥·ÅÆ÷À´×°ÖÃ×Ô½ç˵¼ÓÔØ·¨Ê½¡£ ¡£¡£¡£¡£¡£¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-china-ngo-government-attacks


Malwarebytes°ä²¼Colibri LoaderлµÄ×êÑл㱨


MalwarebytesÔÚ4ÔÂ5ÈÕ°ä²¼ÁËColibri LoaderлµÄ×êÑл㱨¡£ ¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÏà¶Ô½ÏеĶñÒâÈí¼þ £¬£¬£¬£¬£¬£¬ £¬ÓÚ2021Äê8Ô³õ´Î³Ê´Ë¿ÌºÚ¿ÍÂÛ̳ÉÏ £¬£¬£¬£¬£¬£¬ £¬ÓÃÓÚ·Ö·¢ºÍÖÎÀípayload¡£ ¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÀûÓÃÁ˶ñÒâWordÎĵµ £¬£¬£¬£¬£¬£¬ £¬×îÖÕÖ¼ÔÚ·Ö·¢Vidar Stealer¡£ ¡£¡£¡£¡£¡£¡£ÎĵµÏÅ×ëλÓÚ(securetunnel[.]co)µÄÔ¶³Ì·þÎñÆ÷ÏÎ½Ó £¬£¬£¬£¬£¬£¬ £¬ÒÔ¼ÓÔØÃûΪtrkal0.dotµÄÔ¶³ÌÄ£°å £¬£¬£¬£¬£¬£¬ £¬¸ÃÄ£°åÓë¶ñÒâºêÁªÏ·´Ê¹PowerShellÒÔsetup.exeµÄ´ó¾ÖÏÂÔØColibri Loader¡£ ¡£¡£¡£¡£¡£¡£


https://blog.malwarebytes.com/threat-intelligence/2022/04/colibri-loader-combines-task-scheduler-and-powershell-in-clever-persistence-technique/    




°²È«¹¤¾ß


Process Overwriting


PE×¢Èë¼¼Êõ £¬£¬£¬£¬£¬£¬ £¬ÓëProcess Hollowing ºÍ Module OverloadingÇ×êÇÓйء£ ¡£¡£¡£¡£¡£¡£


https://github.com/hasherezade/process_overwriting


jfscan v1.1.8 


»ùÓÚ Masscan ºÍ NMap µÄ³¬¼±¾çºÍ¿É¶¨ÔìµÄ¶Ë¿ÚɨÃèÆ÷¡£ ¡£¡£¡£¡£¡£¡£


https://github.com/nullt3r/jfscan


Auto-Elevate


´Ë¹¤¾ßÑÝʾÁË UAC ÈÆ¹ýµÄ׳´óÖ°ÄÜºÍ Windows µÄÄÚÖÃÖ°ÄÜ¡£ ¡£¡£¡£¡£¡£¡£


https://github.com/FULLSHADE/Auto-Elevate


Subdomains.Sh


subdomains.sh°ü×°ÓÃÓÚ×ÓÓòö¾ÙµÄ¹¤¾ß £¬£¬£¬£¬£¬£¬ £¬ÒÔÔÚ¸ø¶¨ÓòÉÏ×Ô¶¯»¯¹¤×÷Á÷¡£ ¡£¡£¡£¡£¡£¡£


https://github.com/enenumxela/subdomains.sh




°²È«·ÖÎö


Ó¢ÌØ¶û¹Ø¹ØÔÚ¶íÂÞ˹µÄËùÓÐÒµÎñÔËÓª


https://www.bleepingcomputer.com/news/technology/intel-shuts-down-all-business-operations-in-russia/


Mandiant ¹É¶«¸æ×´×èÖ¹¹È¸è 5.4 ÒÚÃÀÔªµÄÂòÂô


https://www.theregister.com/2022/04/04/mandiant_google_lawsuit/


΢Èí½«±¾µØ Exchange¡¢SharePoint Ôö³¤µ½·ì϶Éͽð´òËã


https://www.bleepingcomputer.com/news/security/microsoft-adds-on-premises-exchange-sharepoint-to-bug-bounty-program/


΢Èí°ä·¢Ð嵀 Windows 11 °²È«¡¢¼ÓÃÜÖ°ÄÜ


https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-new-windows-11-security-encryption-features/


Rockwell PLC ÖеÄÑϳÁ·ì϶¿ÉÄÜÓÃÀ´Ö²Èë¶ñÒâ´úÂë


https://thehackernews.com/2022/04/critical-bugs-in-rockwell-plc-could.html


Spring4Shell (CVE-2022-22965)£º¾ßÌåÐÅÏ¢»ººÍ½â´ëÊ©


https://securelist.com/spring4shell-cve-2022-22965/106239/