΢ÈíÔÚÊý°Ù¸ö×éÖ¯ÄÚÍøÖз¢ÏÖRaspberryRobin

°ä²¼¹¦·ò 2022-07-04

1¡¢Î¢Èíй©ÔÚÊý°Ù¸ö×éÖ¯µÄÄÚÍøÖз¢ÏÖRaspberry Robin 


¾Ý7ÔÂ2ÈÕ±¨Â·£¬£¬£¬£¬£¬Î¢Èí×î½üÔÚ¶à¸öÐÐÒµµÄÊý°Ù¼Ò×éÖ¯µÄÄÚÍøÖз¢ÏÖÁËÒ»ÖÖWindowsÈ䳿Raspberry Robin¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿Éͨ¹ý±»Ï°È¾µÄUSBÉ豸´«²¼£¬£¬£¬£¬£¬ÓÚ2021Äê9Ô³õ´Î±»·¢ÏÖ¡£¡£¡£¡£¡£¡£Raspberry Robinͨ¹ýÔ̺¬¶ñÒâ.LNKÎļþµÄUSBÇý¶¯Æ÷ÒÆ¶¯µ½ÐµÄWindowsϵͳ£¬£¬£¬£¬£¬Óû§Ò»µ©ÏνÓÁËUSBÉ豸²¢µ¥»÷Á´½Ó£¬£¬£¬£¬£¬¸ÃÈ䳿¾Í»áʹÓÃcmd.exeÌìÉúÒ»¸ömsiexec¹ý³ÌÀ´Æô¶¯´æ´¢ÔÚ±»Ï°È¾Çý¶¯Æ÷ÉϵĶñÒâÎļþ¡£¡£¡£¡£¡£¡£Ëü»¹Ê¹ÓÃÁ˼¸¸öºÏ·¨µÄWindows·¨Ê½Ö´ÐжñÒâpayload£ºfodhelper¡¢msiexecºÍodbcconf¡£¡£¡£¡£¡£¡£Î¢ÈíÒѽ«´Ë»î¶¯ÏóÕ÷Ϊ¸ß·çÏÕ£¬£¬£¬£¬£¬Ä¿Ç°ÉÐ佫Æä¹éÒòÓÚÈκι¥»÷ÍŻ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-finds-raspberry-robin-worm-in-hundreds-of-windows-networks/


2¡¢Sharp Boys³ÆÒÑÔÚÒÔÉ«ÁÐÓÎÀÀÍøÕ¾ÇÔÈ¡30ÍòÈËÐÅÏ¢


¾ÝýÌå7ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïSharp BoysÐû³ÆÒÑÔÚÒÔÉ«ÁÐÓÎÀÀÍøÕ¾ÇÔÈ¡30ÍòÈËÐÅÏ¢¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬Óг¬¹ý20¸ö¹Û¹âÉç¡¢¾ÆµêºÍ¶È¼Ù´åµÄÍøÕ¾±»ºÚ£¬£¬£¬£¬£¬Ô̺¬hotel4u.co.il¡¢hotels.co.il¡¢isrotel.com¡¢minihotel.co.il¡¢trivago.co.ilºÍdanhotels.comµÈ£¬£¬£¬£¬£¬Éæ¼°Óû§µÄÉí·ÝÖ¤ºÅÂë¡¢µØÖ·ºÍÐÅÓþ¿¨ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ÒÔÉ«ÁÐÒþÖÔ±£»£»£»£»£» £»¤¾ÖÒѾ­³ä¹«ÁËÍйܶà¸ö¹Û¹âÓйØÍøÕ¾µÄ·þÎñÆ÷£¬£¬£¬£¬£¬ÓÉÓÚËûÃǵÄÔËÓªÉÌδÄܽâ¾öµ¼ÖÂй¶³¬¹ý300000ÈËÐÅÏ¢µÄ°²È«ÎÊÌâ¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/iranian-hackers-leak-info-of-over-300000-israelis-from-tourism-sites/


3¡¢³ö°æ¹«Ë¾MacmillanÔâµ½ÀÕË÷¹¥»÷ºó¹Ø¹ØÆä»ù´¡ÉèÊ©


ýÌå7ÔÂ2Èճƣ¬£¬£¬£¬£¬ÃÀ¹ú³ö°æ¹«Ë¾Âó¿ËÃ×Â×£¨Macmillan£©Ôâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ6ÔÂ25ÈÕ£¬£¬£¬£¬£¬¸Ã¹«Ë¾³Æ¹¥»÷Õß¼ÓÃÜÁËMacmillanϵͳÉϵIJ¿ÃÅÎļþ£¬£¬£¬£¬£¬×êÑÐÈËÔ±´§Ä¦ÊÇÀÕË÷¹¥»÷£¬£¬£¬£¬£¬µ«Ä¿Ç°ÉÐδÓкÎÀÕË÷ÍÅ»ïÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬£¬£¬£¬£¬¸ÃÊÂÎñ»¹Ó°ÏìÁËÓ¢¹ú·Ö¹«Ë¾Pan Macmillan¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬Macmillan¹Ø¹ØÁËÆäIT»ù´¡ÉèÊ©£¬£¬£¬£¬£¬ÒÔÔ¤·À¶ñÒâÈí¼þÔÚÆäÍøÂçÖд«²¼£¬£¬£¬£¬£¬²¢¶Ô´ËÊ·¢Õ¹µ÷²é£¬£¬£¬£¬£¬ÒÔ¾¡¿ì¸´Ô­È«ÃæµÄÍøÂçÖ°ÄÜ¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/132792/cyber-crime/macmillan-ransomware-attack.html


4¡¢Jenkins°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬Åû¶Æä¶à¸ö²å¼þÖеÄ34¸ö·ì϶


ýÌå7ÔÂ1ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬Jenkins°²È«ÍŶӰ䲼Á˹ØÓÚ34¸ö°²È«·ì϶µÄ¹«¸æ£¬£¬£¬£¬£¬ËüÃÇÓ°ÏìÁËJenkins¿ªÔ´×Ô¶¯»¯·þÎñÆ÷µÄ29¸ö²å¼þ£¬£¬£¬£¬£¬ÆäÖÐ29¸ö·ì϶ÈÔÓдý½¨¸´¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶Ô̺¬XSS·ì϶¡¢´æ´¢ÐÍXSS·ì϶¡¢¿çÕ¾ÒªÇóαÔì(CSRF)·ì϶¡¢È¨Ï޲鳭ȱʧ£¬£¬£¬£¬£¬ÒÔ¼°ÒÔ´¿Îı¾´ó¾Ö´æ´¢ÃÜÂë¡¢APIÃÜÔ¿ºÍÁîÅÆµÈ¡£¡£¡£¡£¡£¡£Æ¾¾ÝJenkinsµÄͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²å¼þ×ܹ²±»×°Öó¬¹ý22000´Î¡£¡£¡£¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬£¬´óÎÞÊý¸ßÑϳÁÐԵķì϶±ØÒªÓëÓû§½»»¥ÄÜÁ¦±»ÀûÓᣡ£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/jenkins-discloses-dozens-of-zero-day-bugs-in-multiple-plugins/


5¡¢Kaspersky·¢ÏÖÕë¶ÔIIS·þÎñÆ÷µÄкóÃÅSessionManager


6ÔÂ30ÈÕ£¬£¬£¬£¬£¬Kaspersky°ä²¼Á˹ØÓÚкóÃÅSessionManagerµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬¸ÃºóÃÅ×Ô2021Äê3ÔÂÒÔÀ´Ò»Ïò±»ÓÃÓÚÕë¶ÔMicrosoft IIS·þÎñÆ÷µÄ¹¥»÷¡£¡£¡£¡£¡£¡£ËüÓÉC++±àд£¬£¬£¬£¬£¬ÀûÓÃExchange·þÎñÆ÷ÖеÄProxyLogon·ì϶¼Ù×°³ÉInternetÐÅÏ¢·þÎñ(IIS)µÄÄ£¿£¿£¿£¿£¿£¿ £¿£¿é£¬£¬£¬£¬£¬ÓµÓжÁÈ¡¡¢Ð´ÈëºÍɾ³ýËÁÒâÎļþµÄÖ°ÄÜ£¬£¬£¬£¬£¬¿É´Ó·þÎñÆ÷Ö´Ðжþ½øÔìÎļþ£¬£¬£¬£¬£¬²¢ÓëÍøÂçÖÐµÄÆäËü¶Ëµã³ÉÁ¢Í¨Ñ¶¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Æä³äÈÎÁËÒ»¸ö°ÂÃØÍ¨Â·£¬£¬£¬£¬£¬ÓÃÓÚ½øÐпúËÅ¡¢ÍøÂçÄÚ´æÃÜÂ룬£¬£¬£¬£¬²¢ÌṩÆäËü¹¤¾ß£¬£¬£¬£¬£¬ÈçMimikatzµÈ¡£¡£¡£¡£¡£¡£


https://securelist.com/the-sessionmanager-iis-backdoor/106868/


6¡¢ESET°ä²¼¼ÙÒâ¼ÓÄôó˰Îñ»ú¹¹µÄ´¹µö¹¥»÷»î¶¯µÄ»ã±¨


ESETÔÚ7ÔÂ1ÈÕ°ä²¼Á˼ÙÒâ¼ÓÄôó˰Îñ»ú¹¹µÄ´¹µö¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»£»£»£»£» £»î¶¯ÖÐʹÓõĴ¹µöÓʼþÐû³ÆÀ´×Ô¼ÓÄôó˰Îñ¾Ö(CRA)£¬£¬£¬£¬£¬²¢³Ðŵ¿ÉÍË˰½ü500¼ÓÔª¡£¡£¡£¡£¡£¡£µ±Ö¸±êµã»÷°´Å¥Interac e-Transfer Autodepositʱ£¬£¬£¬£¬£¬½«±»´ÓÍйÜÔÚistandyjeno[.]huµÄ¶ñÒâÁ´½Ó³Á¶¨Ïòµ½ÍйÜÔÚoraclehomes.comµÄ¶ñÒâ×ÓÎļþ¼Ðcra_ca_service¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬´¹µöÍøÕ¾»áÓÕʹָ±êÊäÈëÓ×ÎÒÐÅÏ¢ºÍÐÅÓþ¿¨ÐÅÏ¢£¬£¬£¬£¬£¬¶øºóÔÙ½«Æä³Á¶¨Ïòµ½ºÏ·¨µÄCRAÍøÕ¾¡£¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2022/07/01/phishing-scam-posing-canadian-tax-agency-canada-day/