ÒÔÉ«ÁÐ×î´óÁ¶Óͳ§BAZANµÄÍøÕ¾Ôâµ½DDoS¹¥»÷ÁÙʱÖжÏ

°ä²¼¹¦·ò 2023-07-31

1¡¢ÒÔÉ«ÁÐ×î´óÁ¶Óͳ§BAZANµÄÍøÕ¾Ôâµ½DDoS¹¥»÷ÁÙʱÖжÏ


¾ÝýÌå7ÔÂ30ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ÒÔÉ«ÁÐ×î´óµÄÁ¶Óͳ§ÔËÓªÉÌBAZAN GroupµÄÍøÕ¾Ôâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬ÔÚÈ«Çò´ó²¿ÃŵØÓò¶¼ÎÞ·¨½Ó¼û ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÄêÊÕÈ볬¹ý135ÒÚÃÀÔª£¬£¬£¬£¬£¬£¬Äê×ÜÁ¶ÓÍÄÜÁ¦Ô¼980Íò¶ÖÔ­ÓÍ ¡£¡£¡£¡£¡£±¾ÖÜÄ©£¬£¬£¬£¬£¬£¬BAZAN GroupÍøÕ¾bazan.co.ilºÍeng.bazan.co.ilҪô³öÏÖHTTP 502ÃýÎ󣬣¬£¬£¬£¬£¬ÒªÃ´±»¹«Ë¾·þÎñÆ÷»Ø¾ø ¡£¡£¡£¡£¡£²âÊÔ·¢ÏÖÒÔÉ«Áо³ÄÚÄܹ»½Ó¼û£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊÇBAZANÖ´ÐеĵØÀí¹Ø±Õ ¡£¡£¡£¡£¡£CyberAv3ngersÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬£¬£¬£¬£¬»¹¹«¿ªÁËBAZAN SCADA ϵͳµÄÆÁÄ»½ØÍ¼£¬£¬£¬£¬£¬£¬²¢Ð¹Â©ÀûÓÃÁËCheck Point·À»ðǽµÄ·ì϶ÈëÇָù«Ë¾ ¡£¡£¡£¡£¡£BAZAN°µÊ¾Ð¹Â¶µÄÐÅÏ¢¡°ÆëÂúÊÇÆ¾¿ÕµÄ¡±£¬£¬£¬£¬£¬£¬¶øCheck Point³Æµ÷²é·¢ÏÖûÓзì϶µ¼Ö´ËÀ๥»÷ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/israels-largest-oil-refinery-website-offline-after-ddos-attack/ 


2¡¢ºÚ¿ÍÂÛ̳BreachForumsÔ¼21ÍòÌõÓû§¼Í¼ÔÚ°µÍø±»ÏúÊÛ


¾Ý7ÔÂ29ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ÃûΪ¡°breached_db_person¡±µÄºÚ¿ÍÏúÊÛÁ˺ڿÍÂÛ̳BreachForumsµÄ±»µÁÊý¾Ý¿â ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬Have I Been PwnedÒÑÈ·Èϱ»µÁBreachForumsÊý¾ÝµÄºÏ·¨ÐÔ ¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬±»µÁÊý¾Ý¿âÔ̺¬212000±Ê¼Í¼£¬£¬£¬£¬£¬£¬Éæ¼°Óû§Ãû¡¢IPºÍÓʼþµØÖ·¡¢³ÉÔ±µÄ¸öÈËÐÂÎÅÒÔ¼°argon2¹þÏ£ÃÜÂëµÈÐÅÏ¢ ¡£¡£¡£¡£¡£ºÚ¿Í¹«¿ªµÄ2 GBÎļþÖÐÔ̺¬³ÉÔ±Êý¾Ý¿â¡¢¸öÈËÐÂÎźÍÖ§¸¶ÂòÂôµÄ¾ßÌåÐÅÏ¢ ¡£¡£¡£¡£¡£¹ÌÈ»±»µÁµÄBreachForumsÊý¾ÝÒѾ­Á÷ͨ£¬£¬£¬£¬£¬£¬µ«¼ÛÖµ²»·Æ£¬£¬£¬£¬£¬£¬2022Äê11ÔÂ29ÈÕµÄÊý¾Ý¿â¿ìÕյı¨¼Û´Ó10Íòµ½15ÍòÃÀÔª²»µÈ ¡£¡£¡£¡£¡£


https://www.hackread.com/breachforums-breached-pii-data-sold-online/


3¡¢BlueBravoÀûÓúóÃÅGraphicalProton¹¥»÷¶«Å·µÄ±í½»»ú¹¹


Recorded FutureÔÚ7ÔÂ27ÈÕÅû¶Á˶íÂÞ˹ÓйغڿÍÍÅ»ïBlueBravoÕë¶Ô¶«Å·µÄ±í½»»ú¹¹µÄ¹¥»÷»î¶¯ ¡£¡£¡£¡£¡£3ÔÂÖÁ5ÔÂÆÚ¼ä£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÁËÓã²æÊ½´¹µö»î¶¯£¬£¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢ÐºóÃÅGraphicalProton ¡£¡£¡£¡£¡£GraphicalProtonʹÓÃÁËMicrosoft OneDrive»òDropbox½øÐÐͨѶ ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÀÄÓúϷ¨»¥ÁªÍø·þÎñ(LIS) ×÷Ϊ³ÖÐøÐÔÕ½Êõ£¬£¬£¬£¬£¬£¬ÀûÓÃÁËTrello¡¢FirebaseºÍDropboxµÈÔÚÏß·þÎñÈÆ¹ý¼ì²â ¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ô¤²â£¬£¬£¬£¬£¬£¬½«À´BlueBravo½«³ÖÐøÕë¶Ôµ±¾ÖºÍ±í½»»ú¹¹ ¡£¡£¡£¡£¡£


https://go.recordedfuture.com/hubfs/reports/cta-2023-0727-1.pdf


4¡¢×êÑÐÈËÔ±·¢ÏÖÀûÓÃBarracuda·ì϶װÖúóÃÅSUBMARINEµÄ»î¶¯


7ÔÂ29ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÀûÓÃBarracuda ESGÉ豸Öзì϶£¨CVE-2023-2868£©×°ÖÃSUBMARINEµÄ»î¶¯ ¡£¡£¡£¡£¡£ÔçÔÚÈ¥Äê10Ô£¬£¬£¬£¬£¬£¬¸Ã·ì϶¾Í±»¹¥»÷ÕßÓÃÀ´»ñµÃESGÉ豸µÄ½Ó¼ûȨÏÞ ¡£¡£¡£¡£¡£SUBMARINEÊÇÒ»ÖÖÐÂÐÍÓÆ¾ÃÐÔºóÃÅ£¬£¬£¬£¬£¬£¬ÒÔrootȨÏÞÖ´ÐУ¬£¬£¬£¬£¬£¬´æÔÚÓÚESGÉ豸ÉϵÄSQLÊý¾Ý¿âÖÐ ¡£¡£¡£¡£¡£SUBMARINEÓɶà¸ö¹¤¼þ×é³É£¬£¬£¬£¬£¬£¬Ô̺¬SQL´¥·¢·¨Ê½¡¢shell¾ç±¾ºÍLinuxÊØ»¤·¨Ê½µÄ¼ÓÔØ¿â ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓúóÃŽøÐкáÏòÒÆ¶¯ ¡£¡£¡£¡£¡£


https://securityaffairs.com/148942/malware/submarine-backdoor-barracuda-esg-attacks.html


5¡¢Trend MicroÅûÂ¶Éæ¼°CherryBlosºÍFakeTradeµÄÁ½Æð»î¶¯


7ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬Trend MicroÅû¶ÁËÉæ¼°Á½¸öAndroid¶ñÒâÈí¼þCherryBlosºÍFakeTradeµÄ¹¥»÷»î¶¯ ¡£¡£¡£¡£¡£µÚÒ»¸ö»î¶¯ÀûÓÃÊ¢ÐеÄTelegram¡¢TwitterºÍYouTubeµÈƽ̨´«²¼£¬£¬£¬£¬£¬£¬ÓÕʹָ±êÏÂÔØºÍ×°ÖöñÒâÈí¼þCherryBlos ¡£¡£¡£¡£¡£CherryBlos×î³õ³öÏÖÓÚ4Ô·Ý£¬£¬£¬£¬£¬£¬¿Éͨ¹ý¹âѧ×Ö·û¼ø±ð(OCR)´ÓͼƬÖÐÍøÂçÆ¾Ö¤ ¡£¡£¡£¡£¡£Áíһ·»î¶¯Ê¹ÓÃÁ˶à¸öÐû³ÆÊǵç×ÓÉÌÎñƽ̨µÄڲƭÐÔÀûÓ㬣¬£¬£¬£¬£¬³Ðŵͨ¹ýÍÆ¼öºÍ³äֵΪÓû§Ôö³¤ÊÕÈ룬£¬£¬£¬£¬£¬Éæ¼°¶ñÒâÈí¼þFakeTrade ¡£¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/23/g/cherryblos-and-faketrade-android-malware-involved-in-scam-campai.html


6¡¢BankCard USAÔâµ½Black Basta¹¥»÷Òѽ»5ÍòÃÀÔªÊê½ð


ýÌå7ÔÂ29Èճƣ¬£¬£¬£¬£¬£¬BankCard USA(BUSA)Ôâµ½ÁËÀÕË÷ÍÅ»ïBlack BastaµÄ¹¥»÷£¬£¬£¬£¬£¬£¬²¢½»ÁË50000ÃÀÔªµÄÊê½ð ¡£¡£¡£¡£¡£BankCard USAΪ³¬¹ý100000¼ÒÃÀ¹ú¹«Ë¾Ìṩ¶Ëµ½¶Ëµç×ÓÖ§¸¶²úÆ·ºÍ·þÎñ ¡£¡£¡£¡£¡£ÔÚԼĪһ¸öԵŦ·òÀ£¬£¬£¬£¬£¬BUSAÔÚ½»ÉæÖÐÒªÇóBlack BastaÌṩһϵÁб£ÕÏ£¬£¬£¬£¬£¬£¬²¢Ìá³öÁ˵ÍÓÚÔ­¼Û10%µÄÊê½ð£¬£¬£¬£¬£¬£¬ÒªÇó¹¥»÷Õßɾ³ýËûÃÇÇÔÈ¡µÄ200 GBÎļþ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¡°²»»á°ä²¼ÈκÎÐÅÏ¢¡±µÄ±£ÕÏÏÔÈ»²»ÊÇÕæµÄ£¬£¬£¬£¬£¬£¬ÃÀ¹úÒøÐп¨¹«Ë¾µÄÃû³ÆÒÔ¼°²¿ÃŲÆÕþÎļþºÍ»¤ÕÕÒѾ­¹«¿ªÁËÒ»¸ö¶àÔ ¡£¡£¡£¡£¡£


https://www.databreaches.net/attacked-by-black-basta-bankcard-usa-paid-ransom/