¶íÂÞ˹ÔËÓªÉÌMiranda MediaÔâµ½´ó¹æÄ£DDoS¹¥»÷

°ä²¼¹¦·ò 2023-10-31

1¡¢¶íÂÞ˹ÔËÓªÉÌMiranda MediaÔâµ½´ó¹æÄ£DDoS¹¥»÷


¾ÝýÌå10ÔÂ29ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬Miranda Media ISPÔÚÉÏÖÜÎå°ä·¢ÕýÃæ¶Ô´ó¹æÄ£DDoS¹¥»÷¡£¡£¡£¡£¡£¡£IT Army of Ukraine×éÖ¯²¢²ß¶¯ÁËÕë¶Ô¶íÂÞ˹Èý´ó»¥ÁªÍøÌṩÉÌÖ´ÐÐDDoS¹¥»÷¡£¡£¡£¡£¡£¡£Miranda Media³Æ£¬£¬£¬ £¬£¬£¬×Ô10ÔÂ27ÈÕÉÏÎç9:05ÒÔÀ´£¬£¬£¬ £¬£¬£¬ÔËÓªÉÌMiranda-Media¼Í¼ÁËÀ´×ÔÎÚ¿ËÀ¼ÍÅ»ïµÄ´ó¹æÄ£DDoS¹¥»÷£¬£¬£¬ £¬£¬£¬Miranda-Media¡¢KrymtelecomºÍMirTelecomµÄ·þÎñÁÙʱ²»³ÉÓᣡ£¡£¡£¡£¡£¸ÃÊÂÎñ²»½öÓ°Ïìµ½¿ËÀïÃ×ÑÇ£¬£¬£¬ £¬£¬£¬»¹Ó°Ïìµ½ºÕ¶ûËÉ¡¢Ôú²¨ÂÞÈÈ¡¢¶ÙÄù´Ä¿ËºÍ¬¸Ê˹¿ËµØÓòµÄ²¿ÃŵØÓò¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/153192/hacktivism/it-army-of-ukraine-hit-russia-isp.html


2¡¢ÀÕË÷ÍÅ»ïRansomedVC°ä·¢Ç²É¢²¢ÏúÊÛÆä¹¤¾ß´úÂë


¾Ý10ÔÂ30ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬ÀÕË÷ÍÅ»ïRansomedVC°ä·¢Òò¡°Ó×ÎÒÔ­Òò¡±Ç²É¢£¬£¬£¬ £¬£¬£¬²¢½«ÏúÊÛÆäÕû¸öÍøÂç»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£RansomedVCÓÚ½ñÄê8Ô³õ´Î³öÏÖ£¬£¬£¬ £¬£¬£¬Õë¶Ô¹«Ë¾¡¢µ±¾Ö»ú¹¹ºÍ½ÌÓý»ú¹¹µÈ¡£¡£¡£¡£¡£¡£Õâ´ÎÏúÊÛµÄ×ʲúÊýÁ¿¾ªÈË£¬£¬£¬ £¬£¬£¬Ô̺¬¸÷ÀàÓòÃûºÍÂÛ̳¡¢ÀÕË÷Èí¼þÌìÉúÆ÷¡¢´ÓÊôÍÅ»ïµÄ½Ó¼ûȨÏÞ¡¢É罻ýÌåÕË»§¡¢TelegramƵ·¡¢¶à¼Ò¹«Ë¾µÄVPN½Ó¼ûȨÏ޺ͼÛÖµ³¬¹ý1000ÍòÃÀÔªµÄÊý¾Ý¿âµÈ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±´§Ä¦Ç²É¢µÄÔ­Òò£¬£¬£¬ £¬£¬£¬¿ÉÄÜÊÇÀ´×Ô·¨ÂÉ»ú¹¹µÄѹÁ¦£¬£¬£¬ £¬£¬£¬Ò²¿ÉÄÜÊÇÒ»¸öеĸü¸´ÔÓµÄÐж¯ÔÚÔÍÄðÖ®ÖС£¡£¡£¡£¡£¡£


https://www.hackread.com/ransomedvc-ransomware-quit-sell-infrastructure/


3¡¢Elastic·¢ÏÖͨ¹ýαÔìMSIXÀûÓ÷ַ¢GHOSTPULSEµÄ»î¶¯


10ÔÂ27ÈÕ£¬£¬£¬ £¬£¬£¬Elastic¼ì²âµ½Ò»ÖÖÐµĹ¥»÷»î¶¯£¬£¬£¬ £¬£¬£¬Ê¹ÓÃαÔìµÄMSIX WindowsÀûÓ÷¨Ê½°ü£¬£¬£¬ £¬£¬£¬À´·Ö·¢ÐÂÐͶñÒâÈí¼þ¼ÓÔØ·¨Ê½GHOSTPULSE¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ê×ÏÅ×ÕʹÓû§ÏÂÔØMSIXÈí¼þ°ü£¬£¬£¬ £¬£¬£¬µ±Óû§Æô¶¯MSIXÎļþ»áµ¯³öÒ»¸ö´°¿ÚÌáÐѵã»÷¡°×°Öá±°´Å¥¡£¡£¡£¡£¡£¡£µã»÷ºó£¬£¬£¬ £¬£¬£¬Ò»¸öPowerShell¾ç±¾»á°ÂÃØµØÔÚϵͳ¸ßµÍÔØ¡¢½âÃܺÍÖ´ÐÐGHOSTPULSE¡£¡£¡£¡£¡£¡£GHOSTPULSE×÷Ϊ¼ÓÔØ·¨Ê½£¬£¬£¬ £¬£¬£¬Ñ¡È¡Process Doppelg?nging¹¥»÷·½Ê½Æô¶¯×îÖÕpayload¡£¡£¡£¡£¡£¡£×îÖÕpayloadÒòÑù±¾¶øÒ죬£¬£¬ £¬£¬£¬Ô̺¬SectopRAT¡¢Rhadamanthys¡¢Vidar¡¢LummaºÍNetSupport RAT¡£¡£¡£¡£¡£¡£


https://www.elastic.co/security-labs/ghostpulse-haunts-victims-using-defense-evasion-bag-o-tricks


4¡¢¼ÓÖÝijÊÐÔâµ½NoEscapeµÄÀÕË÷¹¥»÷Ô¼200GBÊý¾Ý±»µÁ


ýÌå10ÔÂ27Èճƣ¬£¬£¬ £¬£¬£¬ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖÝά¿Ë¶àά¶ûй©ÆäÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¸ÃÊа䲼֪ͨ³Æ£¬£¬£¬ £¬£¬£¬ºÚ¿ÍÔÚ8ÔÂ12ÈÕÖÁ9ÔÂ26ÈÕÈëÇÖÁËËûÃǵÄϵͳ£¬£¬£¬ £¬£¬£¬¾ÓÃñÉç»á°²È«ºÅÂëºÍÒ½ÁÆÐÅÏ¢µÈй¶¡£¡£¡£¡£¡£¡£ÊÐÕþÔ±¹¤ÓÚ9ÔÂ25ÈÕÔÚFacebookÉϳÆ£¬£¬£¬ £¬£¬£¬ÔÚ´¦ÖÃÓ°Ïìµç»°ºÍÍøÕ¾ÏµÍ³µÄÖжÏÎÊÌ⣬£¬£¬ £¬£¬£¬Ö®ºó°µÊ¾ÒÑÓÚ10ÔÂ3ÈÕ¸´Ô­µç»°ºÍÍøÕ¾·þÎñ£¬£¬£¬ £¬£¬£¬µ«»ùÓÚÍøÂçµÄϵͳÈÔÎÞ·¨ÔËÐС£¡£¡£¡£¡£¡£ÉÏÖܶþ£¬£¬£¬ £¬£¬£¬NoEscape½«¸ÃÊÐÔö³¤µ½ÆäÁбíÖУ¬£¬£¬ £¬£¬£¬Ðû³ÆÒÑ´ÓÊÐÕþϵͳÖÐÇÔÈ¡ÁË200GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£


https://therecord.media/california-victorville-warns-of-data-breach-after-noescape-ransomware-claims


5¡¢Harmony Email°ä²¼¹ØÓÚQuishing¹¥»÷µÄ·ÖÎö»ã±¨


10ÔÂ26ÈÕ£¬£¬£¬ £¬£¬£¬Check PointµÄHarmony EmailÍŶӰ䲼Á˹ØÓÚQuishing£¨¼´¶þάÂë´¹µö£©¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£½ñÄê8Ôµ½9Ô£¬£¬£¬ £¬£¬£¬¶þάÂë¹¥»÷Ôö³¤ÁË587%¡£¡£¡£¡£¡£¡£¸Ã»ã±¨»¹¸ÅÊöÁËһ·¹¥»÷»î¶¯£¬£¬£¬ £¬£¬£¬À´»áÉ̺ڿÍÈôºÎÀûÓöþάÂëÇÔȡƾ֤¡£¡£¡£¡£¡£¡£¹¥»÷Õß´´½¨ÁËÒ»¸ö½«Óû§³Á¶¨Ïòµ½Í´´¦ÍøÂçÒ³ÃæµÄ¶þάÂ룬£¬£¬ £¬£¬£¬¶øºó·¢ËÍÒÔ¡°Microsoft MFA¼´½«¹ýÆÚ¡±Îªµö¶üµÄÓʼþ£¬£¬£¬ £¬£¬£¬ÒªÇóÊÕ¼þÈ˳ÁнøÐÐÉí·ÝÑéÖ¤£¬£¬£¬ £¬£¬£¬Óû§É¨Ãè¶þάÂëºó½«±»³Á¶¨Ïòµ½Ò»¸ö¿´ÆðÀ´Ïñ΢ÈíÍøÕ¾µÄÍ´´¦ÍøÂçÍøÕ¾¡£¡£¡£¡£¡£¡£ 


https://www.avanan.com/blog/the-rise-in-qr-code-attacks


6¡¢Cloudflare°ä²¼2023ÄêQ3 DDoS¹¥»÷Ì¬ÊÆµÄ»ã±¨


10ÔÂ26ÈÕ£¬£¬£¬ £¬£¬£¬Cloudflare°ä²¼ÁË2023ÄêµÚÈý¼¾¶ÈDDoS¹¥»÷Ì¬ÊÆµÄ»ã±¨¡£¡£¡£¡£¡£¡£µÚÈý¼¾¶È£¬£¬£¬ £¬£¬£¬Cloudflare½â¾öÁËÊýǧÆð´ó¹æÄ£HTTP DDoS¹¥»÷¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬ £¬£¬£¬89Æð³¬¹ýÿÃë1ÒÚÒªÇó (rps)£¬£¬£¬ £¬£¬£¬×î´ó·åֵΪ2.01ÒÚrps£¬£¬£¬ £¬£¬£¬ÕâÊÇ֮ǰ×î´ó¹æÄ£¹¥»÷(7100Íòrps)µÄÈý±¶£¬£¬£¬ £¬£¬£¬ÕâЩ¹¥»÷ÊÇͨ¹ýHTTP/2 Rapid ResetʵÏֵġ£¡£¡£¡£¡£¡£ÕâÒ»¼¾¶ÈµÄHTTP DDoS¹¥»÷Á÷Á¿½ÏÉÏÒ»¼¾¶È×ÜÌåÔö³¤65%£¬£¬£¬ £¬£¬£¬L3/4 DDoS¹¥»÷Ò²Ôö³¤ÁË14%¡£¡£¡£¡£¡£¡£Cloudflare»¹¹Û²ìµ½ÐµÄÇ÷Ïò£¬£¬£¬ £¬£¬£¬mDNS¹¥»÷Ôö³¤ÁË456%£¬£¬£¬ £¬£¬£¬CoAP DDoS¹¥»÷Ôö³¤ÁË387%£¬£¬£¬ £¬£¬£¬ESP DDoS¹¥»÷Ôö³¤ÁË303%£¬£¬£¬ £¬£¬£¬ÀÕË÷DDoS¹¥»÷³ÊÏÂÔØÇ÷Ïò¡£¡£¡£¡£¡£¡£


https://blog.cloudflare.com/ddos-threat-report-2023-q3/