×êÑÐÍŶӷ¢ÏÖÀûÓÃÀ¬»øÓʼþ·Ö·¢¶ñÒâÈí¼þMETAµÄ»î¶¯

°ä²¼¹¦·ò 2022-04-13

×êÑÐÍŶӷ¢ÏÖÀûÓÃÀ¬»øÓʼþ·Ö·¢¶ñÒâÈí¼þMETAµÄ»î¶¯


¾ÝýÌå4ÔÂ10ÈÕ±¨Â·£¬£¬£¬ £¬£¬ÐÂÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þMETAÔÚͨ¹ýÀ¬»øÓʼþ»î¶¯·Ö·¢¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÀûÓôøÓкêµÄExcelµç×Ó±í¸ñϰȾָ±ê£¬£¬£¬ £¬£¬ÒÔÐéαµÄתÕË֪ͨΪµö¶ü£¬£¬£¬ £¬£¬Ö¼ÔÚÇÔÈ¡´æ´¢ÔÚChrome¡¢Edge¡¢FirefoxÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°üÖеÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬META¿Éͨ¹ýPowerShell´Û¸ÄWindows DefenderÒÔ½«.exeÎļþÅųýÔÚɨÃèÁìÓòÖ®±í£¬£¬£¬ £¬£¬ÒÔÈÆ¹ý°²È«¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£META¡¢Mars StealerºÍBlackGuardÊÇÐÂÐÍÐÅÏ¢ÇÔÈ¡Èí¼þÖ®Ò»£¬£¬£¬ £¬£¬¹¥»÷Õßµ«Ô¸ÀûÓÃRaccoon StealerÍ˳öÊг¡µÄ»úÓö£¬£¬£¬ £¬£¬Ê¹Æä³ÉΪ¼ÌÈÎÕß¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-meta-information-stealer-distributed-in-malspam-campaign/


NB65ÍÅ»ï»ùÓÚConti¿ª·¢µÄÐÂÀÕË÷Èí¼þÒÔ¶íÂÞ˹Ϊָ±ê


ýÌå4ÔÂ10ÈÕ±¨Â·£¬£¬£¬ £¬£¬ºÚ¿ÍÍÅ»ïNB65ʹÓûùÓÚConti¿ª·¢µÄÐÂÀÕË÷Èí¼þ¹¥»÷¶íÂÞ˹¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ´ÓǰµÄÒ»¸öÔÂÀ£¬£¬ £¬£¬NB65¹¥»÷Á˶íÂÞ˹µÄ¶à¸ö×éÖ¯£¬£¬£¬ £¬£¬Ô̺¬ÎļþÖÎÀíÔËÓªÉÌTensor¡¢º½Ìì¾ÖRoscosmosºÍ¹ã²¥µçÊǪ́VGTRK¡£¡£¡£¡£¡£¡£¡£¡£×Ô3Ôµ×ÒÔÀ´¹¥»÷ÕßתÏòʹÓÃÒ»ÖÖÐÂÕ½Êõ£¬£¬£¬ £¬£¬ÆäÀûÓÃй¶µÄContiÀÕË÷Èí¼þµÄÔ´´úÂë´´½¨ÁË×Ô¼ºµÄÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÉÏÖÜÄ©ÔÚVirusTotal·¢ÏÖÁ˸ÃÑù±¾£¬£¬£¬ £¬£¬²¢È·¶¨ËüÓëContiÑù±¾66%µÄ´úÂëÒ»Ñù¡£¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/130051/hacktivism/nb65-modified-version-conti-ransomware.html


×êÑÐÈËÔ±·¢ÏÖÊ׸öÕë¶ÔAWS LambdaµÄ¶ñÒâÈí¼þDenonia


¾Ý4ÔÂ7ÈÕ±¨Â·£¬£¬£¬ £¬£¬Cado Security·¢ÏÖÁËÊ׸öÕë¶ÔAWS LambdaÔÆ»·¾³µÄ¶ñÒâÈí¼þDenonia¡£¡£¡£¡£¡£¡£¡£¡£AWS LambdaÊÇÒ»¸öÎÞ·þÎñÆ÷ÍÆËãÆ½Ì¨£¬£¬£¬ £¬£¬ÓÃÓÚÔËÐÐÀ´×ÔÊý°Ù¸öAWS SaaSÀûÓ÷¨Ê½µÄ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£DenoniaÊÇÒ»¸ö»ùÓÚGoµÄ·â×°·¨Ê½£¬£¬£¬ £¬£¬Òѱ»ÓÃÓÚ¹¥»÷»î¶¯ÖУ¬£¬£¬ £¬£¬Ö¼ÔÚ²¿ÊðÒ»¸ö×Ô½ç˵µÄXMRig¼ÓÃܿ󹤡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÓÚ1Ô·ÝÉÏ´«µ½VirusTotalµÄÑù±¾£¬£¬£¬ £¬£¬×¢Ã÷¹¥»÷ÖÁÉÙ³ÖÐøÁ˼¸¸öÔ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Ï°È¾Ã½½éÉв»Ã÷È·£¬£¬£¬ £¬£¬×êÑÐÈËÔ±´§¶È¹¥»÷Õß¿ÉÄÜʹÓÃÁËй¶µÄAWSÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-malware-targets-serverless-aws-lambda-with-cryptominers/


ÃÀ¹úSuperCareÔâδ¾­ÊÚȨ½Ó¼ûй¶³¬¹ý30ÍòÈ˵ÄÐÅÏ¢


ýÌå4ÔÂ11Èճƣ¬£¬£¬ £¬£¬ÃÀ¹ú¼ÓÀû¸£ÄáÑǵÄSuperCare Healthй¶318379È˵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÔÚ2021Äê7ÔÂ27ÈÕ±»·¢ÏÖ£¬£¬£¬ £¬£¬ÆäʱÆä¶à¸öϵͳÉϼì²âµ½Î´¾­ÊÚȨµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£ËæºóµÄµ÷²éÏÔʾ£¬£¬£¬ £¬£¬²¿ÃÅϵͳÔÚ7ÔÂ23ÈÕÖÁ7ÔÂ27ÈÕÒѱ»½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£½ñÄê2ÔÂ4ÈÕ£¬£¬£¬ £¬£¬¸Ã¹«Ë¾È·¶¨Ð¹Â¶ÐÅÏ¢Ô̺¬»¼ÕßÐÕÃû¡¢µØÖ·¡¢²¡ÀúºÅ¡¢Ò½ÔºÕ˺š¢½¡È«ºÍÀíÅâÓйØÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£SuperCareÓÚ3ÔÂ25ÈÕÏòÊÜÓ°ÏìµÄÓ×ÎÒ·¢³öÁ˸ÃÊÂÎñµÄ֪ͨ£¬£¬£¬ £¬£¬²¢°µÊ¾Ð¹Â¶µÄÊý¾ÝĿǰ²¢Î´±»ÀÄÓᣡ£¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/supercare-data-breach-300000/


Avast°ä²¼¹ØÓÚеÄParrot TDS·Ö·¢RATµÄ·ÖÎö»ã±¨


4ÔÂ7ÈÕ£¬£¬£¬ £¬£¬Avast°ä²¼¹ØÓÚÒ»ÖÖÃûΪParrotµÄÐÂÐͽ»Í¨Ö¸»Óϵͳ(TDS)µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£ËüĿǰÕý±»ÓÃÓÚ¹¥»÷»î¶¯FakeUpdate£¬£¬£¬ £¬£¬¸Ã»î¶¯Í¨¹ýÐéαµÄä¯ÀÀÆ÷¸üÐÂ֪ͨ·Ö·¢RAT¡£¡£¡£¡£¡£¡£¡£¡£Parrot TDSÒÑϰȾÍйÜÁË16500¶à¸öÍøÕ¾µÄ¶à¸öWeb·þÎñÆ÷£¬£¬£¬ £¬£¬Éæ¼°Ó×ÎÒ²©¿ÍÍøÕ¾¡¢´óÑ§ÍøÕ¾ºÍ´¦Ëùµ±¾ÖÍøÕ¾µÈ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ËƺõÓÚ2022Äê2ÔÂÆðÍ·£¬£¬£¬ £¬£¬µ«Parrot×îÔç¿É×·Òäµ½2021Äê10Ô¡£¡£¡£¡£¡£¡£¡£¡£Parrot TDS ÓëÆäËüTDSÖØÒªÇø±ðÖ®Ò»ÊÇËüµÄ¿í·ºÐÔ£¬£¬£¬ £¬£¬±»Ï°È¾ÍøÕ¾¼äËÆºõûÓÐÈκι²Í¬µã¡£¡£¡£¡£¡£¡£¡£¡£    


https://decoded.avast.io/janrubin/parrot-tds-takes-over-web-servers-and-threatens-millions/


Kaspersky°ä²¼¹ØÓÚBlackCatÍÅ»ïµÄ¼¼Êõ·ÖÎö»ã±¨


KasperskÓÚ4ÔÂ7ÈÕ°ä²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïBlackCatµÄ¼¼Êõ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£BlackCatÒ²³ÆALPHV£¬£¬£¬ £¬£¬ÓÚ2021Äê12Ô³õÆðÍ·»îÔ¾¡£¡£¡£¡£¡£¡£¡£¡£ÓëÆäËüÀÕË÷Èí¼þ×î´óÇø±ðÖ®Ò»ÊÇBlackCatÊÇÓÃRust±àдµÄ£¬£¬£¬ £¬£¬ËûÃǵĻù´¡ÉèÊ©ÍøÕ¾µÄ¿ª·¢·½Ê½Ò²ÓëÆäËüÍÅ»ï·ÖÆç£¬£¬£¬ £¬£¬WindowsºÍLinuxÑù±¾¾ùÓС£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬BlackCatʹÓÃÁË×Ô½ç˵¹¤¾ßFendrµÄ±äÌ壬£¬£¬ £¬£¬Ö¤Ã÷ÆäÓëBlackMatterÓйØÁª¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨»¹·ÖÎöÁËBlackCatÖ´Ðй¥»÷ʱµÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/a-bad-luck-blackcat/106254/





°²È«¹¤¾ß


vmlinux-to-elf


´Ë¹¤¾ßÔÊÐí´Ó vmlinux/vmlinuz/bzImage/zImage ÄÚºËÓ³Ïñ»ñÈ¡ÆëÈ«¿É·ÖÎöµÄ .ELF Îļþ¡£¡£¡£¡£¡£¡£¡£¡£


https://github.com/marin-m/vmlinux-to-elf


DumpSMBShare


´Ó Windows SMB ¹²ÏíÔ¶³Ìת´¢ÎļþºÍÎļþ¼Ð¡£¡£¡£¡£¡£¡£¡£¡£


https://github.com/p0dalirius/DumpSMBShare


Skanuvaty 


ΣÏյļ±¾ç dns/ÍøÂç/¶Ë¿ÚɨÃèÒÇ£¬£¬£¬ £¬£¬¶àºÏÒ»¡£¡£¡£¡£¡£¡£¡£¡£


https://github.com/Esc4iCEscEsc/skanuvaty





°²È«·ÖÎö


Microsoft µÄРAutopatch Ö°ÄÜ¿ÉÔ®ÊÔìóҵά³Öϵͳ¸üÐÂ


https://thehackernews.com/2022/04/microsofts-new-autopatch-feature-to.html


Windows 11 µÄÐÂÖ°ÄÜ


https://www.bleepingcomputer.com/news/microsoft/here-are-the-new-features-coming-to-windows-11/


¹È¸èͨ¹ýеĿª·¢Õ½Êõ¸ü¸ÄÉÆ²½ Android µÄ°²È«ÐÔ


https://www.bleepingcomputer.com/news/security/google-boosts-android-security-with-new-set-of-dev-policy-changes/


GitHub Action ¿ÉÔ¤·ÀÔÚ´úÂëÖÐÔö³¤ÒÑÖª·ì϶


https://securityaffairs.co/wordpress/130067/security/dependency-review-github-action.html


CVE-2022-22292 ¿ÉÓÃÓÚÈëÇÖÈýÐÇ Android É豸


https://securityaffairs.co/wordpress/129942/hacking/cve-2022-22292-hack-samsung-android-devices.html


Ð嵀 SolarMarker (Jupyter) »î¶¯


https://unit42.paloaltonetworks.com/solarmarker-malware/