ÃÀ¹úµÄRateForceÍøÕ¾Ô¼93 GBµÄ³¬¹ý25Íò±Ê¼Í¼й¶
°ä²¼¹¦·ò 2023-06-261¡¢ÃÀ¹úµÄRateForceÍøÕ¾Ô¼93 GBµÄ³¬¹ý25Íò±Ê¼Í¼й¶
¾ÝýÌå6ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ÃÀ¹úÆû³µ±£ÏձȼÛÍøÕ¾RateForceй¶ÁË´óÁ¿Óû§PIIÐÅÏ¢¡£¡£¡£¡£¡£¡£×ܹ²Ð¹Â¶ÁË96175¸öÎļþ¼Ð£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬255756±Ê¼Í¼£¬£¬£¬£¬£¬£¬×Ü´óÓ×Ϊ93.93GB¡£¡£¡£¡£¡£¡£Õâ´Îй¶ÊÂÎñ³ÖÐøÁËÖÁÉÙÁ½ÖÜ£¬£¬£¬£¬£¬£¬Ô´ÓÚÒ»¸ö²»°²È«µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬Éæ¼°¸÷ÀàÎļþµÄɨÃè¼þºÍͼƬ£¬£¬£¬£¬£¬£¬Ô̺¬³µÁ¾µÇ¼Ç¡¢¼ÝÊ»ÅÆÕÕ¡¢±£ÏÕ¿¨ºÍ³µÁ¾ËùÓÐȨµÈ¡£¡£¡£¡£¡£¡£½øÒ»´ëÊ©²é·¢ÏÖ£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖб£µ¥µÄÖØÒª±£ÏÕ¹«Ë¾ÊÇUSA Underwriters¡£¡£¡£¡£¡£¡£USA Underwriters³ÎÇå·£¬£¬£¬£¬£¬£¬ËûÃÇÀñƸÁ˶ÀÁ¢µÄIT¹«Ë¾À´ÖÎÀíÆä»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬²¢ÇÒ²»³Ðµ£ÖÎÀí¶³öµÄÊý¾Ý¿âµÄÈκÎÔðÈΡ£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÒѱ»±£»£»£»£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£
https://www.hackread.com/rateforce-auto-insurance-data-leak/
2¡¢Ä¾Âí»¯³¬µÈÂíÀï°ÂÐÖµÜÓÎÏ·×°Ö÷¨Ê½´«²¼¶àÖÖ¶ñÒâÈí¼þ
CybleÔÚ6ÔÂ23ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öºÏÓÃÓÚWindowsµÄľÂí»¯³¬µÈÂíÀï°ÂÐÖµÜÓÎÏ·×°Ö÷¨Ê½£¬£¬£¬£¬£¬£¬±»ÓÃÓÚ´«²¼¶àÖÖ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£Ô̺¬XMRÍÚ¿ó·¨Ê½¡¢SupremeBotÍÚ¿ó¿Í»§¶ËºÍ¿ªÔ´UmbralÇÔÈ¡·¨Ê½¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ®ËùÒÔÕë¶ÔÓÎÏ·Íæ¼Ò£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚËûÃÇʱʱʹÓÃ׳´óµÄÓ²¼þ½øÐÐÓÎÏ·£¬£¬£¬£¬£¬£¬Õ⼫¶ÈÊʺÏÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¹¥»÷Õß´Û¸ÄÁËNSIS×°Ö÷¨Ê½Îļþ£¬£¬£¬£¬£¬£¬ÌìÉúµÄ¿ÉÖ´ÐÐÎļþÔ̺¬ºÏ·¨µÄÀûÓÃÒÔ¼°¶ñÒâ¿ÉÖ´ÐÐÎļþjava.exeºÍatom.exe¡£¡£¡£¡£¡£¡£×°Öóɹ¦ºó»áÆô¶¯ÓÎÏ·£¬£¬£¬£¬£¬£¬²¢ÔÚºó¶Ü½øÐÐÍڿ󡣡£¡£¡£¡£¡£
https://blog.cyble.com/2023/06/23/trojanized-super-mario-game-installer-spreads-supremebot-malware/
3¡¢Fortinet½¨¸´FortiNAC RCE·ì϶CVE-2023-33299
¾Ý6ÔÂ23ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬Fortinet°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´ÁËÆäÁãÐÅÀµ½Ó¼û½â¾ö¹æ»®FortiNACÖеķ´ÐòÁл¯·ì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2023-33299£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.6¡£¡£¡£¡£¡£¡£FortinetµÄ°²È«Õ÷ѯÖÐÖ¸³ö£¬£¬£¬£¬£¬£¬FortiNACÖеIJ»³ÉÐÅÊý¾Ý·´ÐòÁл¯·ì϶¿ÉÄܵ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓÃÌØÔìµÄTCP/1050·þÎñÒªÇóÖ´ÐÐδ¾ÊÚȨµÄ´úÂë»òºÅÁî¡£¡£¡£¡£¡£¡£¹©¸øÉÌûÓÐÌṩ»º½â½¨Ò飬£¬£¬£¬£¬£¬Òò¶ø½¨ÒéÓû§Á¢¼´ÀûÓÿÉÓõݲȫ¸üС£¡£¡£¡£¡£¡£
https://securityaffairs.com/147770/security/fortinet-fortinac-critical-flaw.html
4¡¢×êÑÐÈËÔ±·¢ÏÖеÄPindOS·Ö·¢IcedIDºÍBumblebee
Deep InstinctÔÚ6ÔÂ22ÈÕÅû¶ÁËÒ»ÖÖеÄJavaScript dropper PindOS£¬£¬£¬£¬£¬£¬»á·Ö·¢¶ñÒâÈí¼þBumblebeeºÍIcedID¡£¡£¡£¡£¡£¡£BumblebeeÊÇÒ»ÖÖ¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½£¬£¬£¬£¬£¬£¬IcedIDÊÇÒ»ÖÖÄ£¿£¿£¿£¿£¿£¿£¿é»¯ÒøÐжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¶ÔPindOSµÄÔ´´úÂë·ÖÎöÏÔʾ£¬£¬£¬£¬£¬£¬ËüÔ̺¬¶íÓïµÄ×¢½â¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬Ò»µ©È¥³ý»ìºÏ£¬£¬£¬£¬£¬£¬¸Ãdropper¾Í¼«¶Èµ¥Ò»¡£¡£¡£¡£¡£¡£ËüÓÉÒ»¸öº¯Êýexec×é³É£¬£¬£¬£¬£¬£¬Ô̺¬Ëĸö²ÎÊý£¬£¬£¬£¬£¬£¬UserAgent¡¢URL1¡¢URL2ºÍRunDLL£¬£¬£¬£¬£¬£¬ÆäÖÐURL2×÷ΪURL1ÎÞ·¨»ñÈ¡DLLʱµÄºó±¸¡£¡£¡£¡£¡£¡£
https://www.deepinstinct.com/blog/pindos-new-javascript-dropper-delivering-bumblebee-and-icedid
5¡¢Unit 42¹«¿ªÀûÓöà¸öIoT·ì϶µÄÐÂÒ»ÂÖMirai»î¶¯
6ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬Unit 42¹«¿ªÁËÀûÓöà¸öIoT·ì϶µÄÐÂÒ»ÂÖMirai»î¶¯¡£¡£¡£¡£¡£¡£¸Ã»î¶¯×Ô3ÔÂ14ÈÕÆðÍ·»îÔ¾£¬£¬£¬£¬£¬£¬²¢ÔÚ4ÔºÍ6Ô³öÏÖ¼¤Ôö¡£¡£¡£¡£¡£¡£ÕâÒ»±äÌåÕë¶Ô22¸ö·ì϶£¬£¬£¬£¬£¬£¬Ö¼ÔÚ½ÚÔìD-Link¡¢Arris¡¢Zyxel¡¢TP-Link¡¢Tenda¡¢NetgearºÍMediaTekµÈÉ豸£¬£¬£¬£¬£¬£¬²¢ÀûÓÃËüÃÇÖ´ÐÐDDoS¹¥»÷¡£¡£¡£¡£¡£¡£Unit 42»¹Ö¸³ö£¬£¬£¬£¬£¬£¬¸ÃMirai±äÌå²»¾ß±¸±©Á¦ÆÆ½âtelnet/SSHµÇ¼ʹ´¦µÄÖ°ÄÜ£¬£¬£¬£¬£¬£¬Òò¶øÆä·Ö·¢ÆëÈ«ÒÀÀµÓÚÔËÓªÈËÔ±ÊÖ¶¯ÀûÓ÷ì϶¡£¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/mirai-variant-targets-iot-exploits/
6¡¢SecuronixÅû¶Õë¶ÔÓ¡¶ÈºÍÃÀ¹úµÄ´¹µö»î¶¯MULTI#STORM
6ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬SecuronixÅû¶ÁË´úºÅΪMULTI#STORMµÄÐÂÒ»ÂÖ´¹µö»î¶¯£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÓ¡¶ÈºÍÃÀ¹ú¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÀûÓÃÁËJavaScriptÎļþÔÚ±»Ï°È¾µÄϵͳÉÏ´«²¼Ô¶³Ì½Ó¼ûľÂí¡£¡£¡£¡£¡£¡£¹¥»÷Á´Ê¼ÓÚÒ»¸öZIPÎļþREQUEST.zipÖб»ÑϳÁ»ìºÏµÄJavaScriptÎļþREQUEST.js¡£¡£¡£¡£¡£¡£×îÖÕ»á×°Ööà¸ö¹ÖÒìµÄRAT£¬£¬£¬£¬£¬£¬ÈçWarzone RATºÍQuasar RAT¡£¡£¡£¡£¡£¡£ÔÚϰȾÁ´µÄ·ÖÆç½×¶Î£¬£¬£¬£¬£¬£¬Á½Õß¶¼±»ÓÃÓÚC2¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ÕƹÜ×î³õÈëÇÖÖ÷»úµÄ¼ÓÔØ·¨Ê½µÄÖ°ÄÜÓëDBatLoader¼«¶ÈÀàËÆ£¬£¬£¬£¬£¬£¬µ«ËüÓÃPython¿ª·¢£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃPyInstaller´ò°ü£¬£¬£¬£¬£¬£¬ÀûÓÃÁËһЩ¸´Ôӵļ¼ÊõÀ´³ÉÁ¢ÓƾÃÐÔ£¬£¬£¬£¬£¬£¬²¢ÔÚ·Ö·¢payloadÖ®Ç°ÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£
https://www.securonix.com/securonix-threat-labs-security-advisory-multistorm-leverages-python-based-loader-as-onedrive-utilities-to-drop-rat-payloads/


¾©¹«Íø°²±¸11010802024551ºÅ