Kaspersky·¢ÏÖUEFI¹Ì¼þrootkit CosmicStrand

°ä²¼¹¦·ò 2022-07-27
1¡¢Kaspersky·¢ÏÖUEFI¹Ì¼þrootkit CosmicStrand 

      

KasperskyÔÚ7ÔÂ25ÈÕÅû¶ÁËͳһ¿ÉÀ©´ó¹Ì¼þ½Ó¿Ú(UEFI)rootkit CosmicStrandµÄ¼¼Êõϸ½Ú¡£¡£¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬ £¬£¬£¬£¬£¬¸ÃrootkitλÓÚ¼¼¼Î»ò»ªË¶Ö÷°åµÄ¹Ì¼þÓ³ÏñÖУ¬ £¬£¬£¬£¬£¬ÕâÊÇ2013ÄêÖÁ2015ÄêÖ®¼äµÄ¾ÉÓ²¼þ£¬ £¬£¬£¬£¬£¬´Ë¿Ì´ó²¿ÃÅÒÑÍ£²ú¡£¡£¡£¡£ ¡£¡£¡£ÕâЩӳÏñ¶¼ÓëʹÓÃH81оƬ×éµÄÉè¼ÆÓйأ¬ £¬£¬£¬£¬£¬ÕâÅú×¢ÆäÖпÉÄÜ´æÔÚÒ»¸ö³£¼û·ì϶£¬ £¬£¬£¬£¬£¬¿É±»¹¥»÷ÕßÓÃÀ´½«rootkit×¢Èë¹Ì¼þµÄÓ³ÏñÖÓ×£¡£¡£¡£ ¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬£¬Ï°È¾µÄ³õʼ½Ó¼ûý½éÒÀȻδ֪¡£¡£¡£¡£ ¡£¡£¡£


https://securelist.com/cosmicstrand-uefi-firmware-rootkit/106973/


2¡¢¹¥»÷ÕßÀûÓÃPrestaShopƽ̨Öзì϶ÈëÇÖÔÚÏßÉ̵ê

      

¾Ý7ÔÂ25ÈÕ±¨Â·£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÿªÔ´µç×ÓÉÌÎñƽ̨PrestaShopÖеķì϶£¨CVE-2022-36408£©¹¥»÷ÔÚÏßÉ̵ꡣ¡£¡£¡£ ¡£¡£¡£PrestaShopÊÇÅ·ÖÞºÍÀ­¶¡ÃÀÖÞµ±ÏȵĿªÔ´µç×ÓÉÌÎñ½â¾ö¹æ»®£¬ £¬£¬£¬£¬£¬±»È«Çò½ü300000¼ÒÔÚÏßÉ̼ÒʹÓᣡ£¡£¡£ ¡£¡£¡£¸Ã·ì϶ӰÏìÁËPrestaShop 1.6.0.10»ò¸ü¸ß°æ±¾£¬ £¬£¬£¬£¬£¬ÒÔ¼°1.7.8.2»ò¸ü¸ß°æ±¾ÖÐÔËÐÐÁËÒ×±»SQL×¢Èë¹¥»÷µÄÄ£¿£¿£¿£¿£¿é£¨ÈçWishlist 2.0.0ÖÁ2.1.0Ä£¿£¿£¿£¿£¿é£©¡£¡£¡£¡£ ¡£¡£¡£ÀûÓø÷ì϶£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ö´ÐÐËÁÒâ´úÂë²¢ÇÔÈ¡¿Í»§µÄÖ§¸¶ÐÅÏ¢£¬ £¬£¬£¬£¬£¬¸Ã·ì϶ÒÑÔÚ1.7.8.7°æ±¾Öн¨¸´¡£¡£¡£¡£ ¡£¡£¡£


https://thehackernews.com/2022/07/hackers-exploit-prestashop-zero-day-to.html


3¡¢×êÑÐÈËԱй©QBotÀûÓÃWindowsÍÆËãÆ÷ϰȾָ±êÉ豸

      

7ÔÂ24ÈÕ±¨Â·£¬ £¬£¬£¬£¬£¬ProxyLife·¢ÏÖÖÁÉÙ´Ó7ÔÂ11ÈÕÆð£¬ £¬£¬£¬£¬£¬Qbot¾ÍÒ»ÏòÔÚÀÄÓÃWindows 7 CalculatorÀûÓýøÐÐDLL²à¼ÓÔØ¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£»£»£»£»£»£»î¶¯Ê¹ÓõĶñÒâÓʼþÖÐÓÐÒ»¸öHTML¸½¼þ£¬ £¬£¬£¬£¬£¬»áÏÂÔØÔ̺¬ISOÎļþµÄZIP¡£¡£¡£¡£ ¡£¡£¡£ISOÖÐÓÐÒ»¸ö.LNK Îļþ¡¢¡°calc.exe¡±£¨WindowsÍÆËãÆ÷£©¸±±¾ºÍÁ½¸öDLLÎļþ£¬ £¬£¬£¬£¬£¬¼´WindowsCodecs.dllºÍÃûΪ7533.dllµÄpayload¡£¡£¡£¡£ ¡£¡£¡£.LNK¿ì½Ý·½Ê½Ö¸ÏòWindowsÖеÄÍÆËãÆ÷ÀûÓ㬠£¬£¬£¬£¬£¬¼ÓÔØºóWindows 7ÍÆËãÆ÷»á×Ô¶¯ËÑË÷²¢¼ÓÔØºÏ·¨WindowsCodecs DLLÎļþ¡£¡£¡£¡£ ¡£¡£¡£µ«Ëü²»»á²é³­Ä³Ð©Ó²±àÂëõè¾¶ÖеÄDLL£¬ £¬£¬£¬£¬£¬ÈôÊǽ«ÆäÓëCalc.exe·ÅÔÚͳһÎļþ¼ÐÖУ¬ £¬£¬£¬£¬£¬Ëü½«¼ÓÔØÓµÓÐÒ»ÑùÃû³ÆµÄËùÓÐDLL¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/qbot-phishing-uses-windows-calculator-sideloading-to-infect-devices/


4¡¢Ó¡¶È±£ÏÕ¹«Ë¾Policybazaar³ÆÆäϵͳ±»Î´ÊÚȨ½Ó¼û

      

ýÌå7ÔÂ19Èճƣ¬ £¬£¬£¬£¬£¬Ó¡¶È±£ÏÕ¹«Ë¾PolicybazaarÔâµ½ÁËδ¾­ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾µÄĸ¹«Ë¾PB FintechÔÚÉÏÖÜÈÕ°ä²¼¹«¸æ£¬ £¬£¬£¬£¬£¬³ÆËüÔÚ7ÔÂ19ÈÕ·¢ÏÖÁËÀûÓÃÆäϵͳÖзì϶µÄ·¸·¨µÄδ¾­ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬ £¬£¬£¬£¬£¬Ä¿Ç°Òѽ¨¸´·ì϶£¬ £¬£¬£¬£¬£¬²¢ÒÑÆô¶¯¶ÔϵͳµÄÉ󼯣¬ £¬£¬£¬£¬£¬Éó²é·¢ÏÖûÓÐÈκγÁÒªµÄ¿Í»§Êý¾Ýй¶¡£¡£¡£¡£ ¡£¡£¡£Ð¹Â¶Í¨ÖªÉÐδÌá¼°ÄÄЩÊý¾ÝÒѱ»Ð¹Â¶»òÓм¸¶à¿Í»§Êܵ½Ó°Ïì¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬£¬PB FintechµÄ¹É¼Û´ÓÉÏÖÜÎåµÄ522¬±È×ÅÂäÖÁÖÜÒ»µÄ499.70¬±È¡£¡£¡£¡£ ¡£¡£¡£


https://www.infosecurity-magazine.com/news/indian-insurance-policybazaar/


5¡¢ºÚ¿ÍÔÚ°µÍø¹«¿ªRust¿ª·¢µÄµÄijÇÔÈ¡·¨Ê½µÄÔ´´úÂë

      

ýÌå7ÔÂ25Èճƣ¬ £¬£¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍø¹«¿ªÁËÓÃRust¿ª·¢µÄµÄijÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÔ´´úÂë¡£¡£¡£¡£ ¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿ª·¢ÕßÐû³ÆÖ»ÓÃÁËÁù¸öÓ±¾Ç®Í¿ª·¢³öÀ´ÁË£¬ £¬£¬£¬£¬£¬Ëü¼«¶ÈÒñ±Î£¬ £¬£¬£¬£¬£¬VirusTotal·µ»ØµÄ¼ì²âÂÊԼΪ22%¡£¡£¡£¡£ ¡£¡£¡£Cyble½«Æä¶¨ÃûΪLuca Stealer£¬ £¬£¬£¬£¬£¬Ö´ÐÐʱËü»á´Ó30¸ö»ùÓÚChromiumµÄä¯ÀÀÆ÷ÖÐÇÔÈ¡Êý¾Ý£¬ £¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÜÂëÖÎÀíÆ÷ä¯ÀÀÆ÷²å¼þ¡£¡£¡£¡£ ¡£¡£¡£Cyble»ã±¨ÒѾ­¼ì²âµ½ÖÁÉÙ25¸öÔÚÒ°ÀûÓõÄLuca StealerÑù±¾£¬ £¬£¬£¬£¬£¬Éв»Ã÷ÏÔÕâÖÖеĶñÒâÈí¼þÊÇ·ñ»á±»´ó¹æÄ£²¿Ê𡣡£¡£¡£ ¡£¡£¡£¹ÌÈ»¸Ã¶ñÒâÈí¼þÓÉ¿çÆ½Ì¨Ëµ»°Rust±àд£¬ £¬£¬£¬£¬£¬µ«Ä¿Ç°ÆäÖ»Õë¶ÔWindowsϵͳ¡£¡£¡£¡£ ¡£¡£¡£

https://www.bleepingcomputer.com/news/security/source-code-for-rust-based-info-stealer-released-on-hacker-forums/


6¡¢Î¢Èí°ä²¼ÀûÓöñÒâIISÀ©´óµÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨

      

7ÔÂ26£¬ £¬£¬£¬£¬£¬Î¢Èí°ä²¼Á˹ØÓÚÀûÓÃInternetÐÅÏ¢·þÎñ(IIS)À©´óµÄ¹¥»÷»î¶¯µÄ·ÖÎö¡£¡£¡£¡£ ¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹ÓöñÒâIIS Web·þÎñÆ÷À©´ó×÷Ϊ·þÎñÆ÷µÄÒñ±ÎºóÃÅ£¬ £¬£¬£¬£¬£¬ÓÉÓÚÓëWeb shellÏà±È£¬ £¬£¬£¬£¬£¬ËüµÄ¼ì²âÂʽϵ͡£¡£¡£¡£ ¡£¡£¡£Í¨³££¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏÈ»áÀûÓÃÍйÜÀûÓÃÖеÄÒ»¸ö©³¨ÆðÍ·³õʼ½Ó¼û£¬ £¬£¬£¬£¬£¬¶øºó×°ÖÃÒ»¸ö¾ç±¾Webshell×÷ΪµÚÒ»½×¶Îpayload¡£¡£¡£¡£ ¡£¡£¡£Ö®ºó£¬ £¬£¬£¬£¬£¬¹¥»÷Õß»á×°ÖÃÒ»¸öIISºóÃÅ£¬ £¬£¬£¬£¬£¬ÒÔ¶Ô·þÎñÆ÷½øÐÐÒñ±ÎºÍÓÆ¾ÃµÄ½Ó¼û¡£¡£¡£¡£ ¡£¡£¡£×°ÖÃºó£¬ £¬£¬£¬£¬£¬¶ñÒâIISÄ£¿£¿£¿£¿£¿é»á´ÓÖ¸±êϵͳµÄÄÚ´æÖÐÇÔȡʹ´¦£¬ £¬£¬£¬£¬£¬ÍøÂçÐÅÏ¢£¬ £¬£¬£¬£¬£¬²¢×°Öøü¶àpayload¡£¡£¡£¡£ ¡£¡£¡£Î¢ÈíÔ¤¼Æ½«À´»áÓиü¶à´ËÀ๥»÷¡£¡£¡£¡£ ¡£¡£¡£


https://www.microsoft.com/security/blog/2022/07/26/malicious-iis-extensions-quietly-open-persistent-backdoors-into-servers/