¶ñÒâGoogle¸æ°×ÍÆËÍ´øÓаµ²ØºóÃŵļÙIPɨÃèÈí¼þ
°ä²¼¹¦·ò 2024-04-191. ¶ñÒâGoogle¸æ°×ÍÆËÍ´øÓаµ²ØºóÃŵļÙIPɨÃèÈí¼þ
4ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ð嵀 Google ¶ñÒâ¸æ°×»î¶¯ÔÚÀûÓÃÒ»×é·ÂÕպϷ¨ IP ɨÃèÈí¼þµÄÓòÀ´Ìṩһ¸öÒÔǰδ֪µÄÃûΪMadMxShell µÄºóÃÅ¡£¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕßʹÓÃÎóÖ²¼¼Êõ×¢²áÁ˶à¸öÀàËÆµÄÓòÃû£¬£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓà Google Ads ½«ÕâЩÓòÃûÍÆÖÁÕë¶ÔÌØ¶¨ËÑË÷¹Ø¼ü×ÖµÄËÑË÷ÒýÇæÁ˾ֵĶ¥²¿£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÒýÓÕÊܺ¦Õß½Ó¼ûÕâÐ©ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬£¬£¬2023 Äê 11 ÔÂÖÁ 2024 Äê 3 ÔÂÆÚ¼ä×¢²áµÄÓòÃû¶à´ï 45 ¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÕâÐ©ÍøÕ¾¼Ù×°³É¶Ë¿ÚɨÃèºÍ IT ÖÎÀíÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬Èç Advanced IP Scanner¡¢Angry IP Scanner¡¢IP ɨÃèÒÇ PRTG ºÍ ManageEngine¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»Õâ²¢²»ÊÇÍþвÐÐΪÕßµÚÒ»´ÎÀûÓöñÒâ¸æ°×¼¼Êõͨ¹ýÀàËÆµÄÍøÕ¾Ìṩ¶ñÒâÈí¼þ·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÕâÒ»·¢Õ¹±ê־ȡ½»¸¶¹¤¾ß³õ´Î±»ÓÃÀ´´«²¼¸´Ô Windows ºóÃÅ¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/04/malicious-google-ads-pushing-fake-ip.html
2. ¹¥»÷ÕßÀûÓÃOpenMetadataÔÚKubernetesÉϽøÐÐÍÚ¿ó
4ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Microsoft Threat Intelligence ·¢ÏÖÁËÕë¶ÔÔËÐÐÊ¢ÐпªÔ´ÔªÊý¾Ýƽ̨ OpenMetadata µÄ Kubernetes ¼¯ÈºµÄй¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚÀûÓÃһϵÁÐ×î½üÅû¶µÄ¹Ø¼ü·ì϶À´½Ó¼û¹¤×÷¸ºÔز¢×°ÖüÓÃÜÇ®±ÒÍÚ¾ò¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÀûÓÃÁË 1.3.1 ֮ǰµÄ OpenMetadata °æ±¾ÖдæÔڵĶà¸ö°²È«·ì϶£¨CVE-2024-28255¡¢CVE-2024-28847¡¢CVE-2024-28253¡¢CVE-2024-28848¡¢CVE-2024-28254£©¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶½«¸³Óè¹¥»÷ÕßÔ¶³ÌÖ´ÐдúÂëµÄÄÜÁ¦£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹ËûÃÇ¿ÉÄÜÆëÈ«½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ͨ³£´ÓÍøÂç·¸×ï·Ö×ÓɨÃèÔËÐÐÒ×Êܹ¥»÷µÄ OpenMetadata Ê·ýµÄ¶³öÓÚ»¥ÁªÍøµÄ Kubernetes ¹¤×÷¸ºÔØÆðÍ·¡£¡£¡£¡£¡£¡£¡£Ò»µ©¼ø±ð³öÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻáÀûÓÃÕâЩ·ì϶À´½ÚÔìÍÐ¹Ü OpenMetadata µÄÈÝÆ÷¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/attackers-exploit-critical-openmetadata-flaws-for-cryptomining-on-kubernetes/
3. SoumniBot ¶ñÒâÈí¼þÀûÓà Android ·ì϶À´Èƹý¼ì²â
4ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ò»ÖÖÃûΪ¡°SoumniBot¡±µÄРAndroid ÒøÐжñÒâÈí¼þͨ¹ýÀûÓà Android Çåµ¥ÌáÈ¡ºÍ½âÎö¹ý³ÌÖеÄÈõµã£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÒ»ÖÖ²»Ì«³£¼ûµÄ»ìºÏ²½Öè¡£¡£¡£¡£¡£¡£¡£¸Ã²½Öèʹ SoumniBot ¿ÉÄܶã±Ü Android ÊÖ»úÖеij߶Ȱ²È«´ëÊ©²¢Ö´ÐÐÐÅÏ¢ÇÔÈ¡²Ù×÷¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÉ¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖ²¢·ÖÎö£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÌṩÁË ¸Ã¶ñÒâÈí¼þÀûÓà Android Àý³Ì½âÎöºÍÌáÈ¡ APK Çåµ¥µÄ²½ÖèµÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¡£¡£Çåµ¥Îļþ£¨¡°AndroidManifest.xml¡±£©Î»ÓÚÿ¸öÀûÓ÷¨Ê½µÄ¸ùĿ¼ÖУ¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÓйØ×é¼þ£¨·þÎñ¡¢¹ã²¥½Ó¹ÜÆ÷¡¢ÄÚÈÝÌṩ·¨Ê½£©¡¢È¨ÏÞºÍÀûÓ÷¨Ê½Êý¾ÝµÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»¶ñÒâ APK Äܹ»Ê¹Óà Zimperium µÄ¸÷ÀàѹËõ¼¼ÇÉÀ´ÓÞŪ°²È«¹¤¾ß²¢ÌӱܷÖÎö£¬£¬£¬£¬£¬£¬£¬£¬µ«¿¨°Í˹»ù·ÖÎöʦ·¢ÏÖ SoumniBot ʹÓÃÈýÖÖ·ÖÆçµÄ²½ÖèÀ´Èƹý½âÎöÆ÷²é³£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÉæ¼°°Ñ³ÖÇåµ¥ÎļþµÄѹËõºÍ´óÓס£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/soumnibot-malware-exploits-android-bugs-to-evade-detection/
4. FIN7 Õë¶ÔÃÀ¹úÆû³µÔì×÷ÉÌµÄ IT Ô±¹¤ÌáÒéÍøÂç´¹µö¹¥»÷
4ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬³öÓÚ¾¼Ã¶¯»úµÄÍþв×éÖ¯ FIN7 Õë¶ÔÒ»¼ÒÃÀ¹ú´óÐÍÆû³µÔì×÷ÉÌ£¬£¬£¬£¬£¬£¬£¬£¬Ïò IT ²¿ÃŵÄÔ±¹¤·¢ËÍÓã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÀûÓà Anunak ºóÃÅϰȾϵͳ¡£¡£¡£¡£¡£¡£¡£¾ÝºÚÝ®×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷²úÉúÔÚÈ¥Äêµ×£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÒÀÀµÓڷDZ¾µØ¶þ½øÔìÎļþ¡¢¾ç±¾ºÍ¿â (LoLBas)¡£¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕß½«³Áµã·ÅÔÚÓµÓи߼¶È¨ÏÞµÄÖ¸±êÉÏ£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¼ÙÒâºÏ·¨¸ß¼¶ IP ɨÃèÆ÷¹¤¾ßµÄ¶ñÒâ URL Á´½ÓÀ´ÒýÓÕËûÃÇ¡£¡£¡£¡£¡£¡£¡£ºÚÝ®¸ß¶ÈÈ·ÐÅÕâ´Î¹¥»÷ÊÇÓÉ FIN7 ÌáÒéµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓڸù¥»÷ʹÓÃÁ˹ÖÒìµÄ PowerShell ¾ç±¾£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾Ê¹ÓÃÁ˵ÐÊÖµÄÊðÃû¡°PowerTrash¡±»ìºÏµÄ shellcode ŲÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾³õ´Î³Ê´Ë¿Ì 2022 ÄêµÄÒ»´Î»î¶¯ÖС£¡£¡£¡£¡£¡£¡£ÔÚ´Ë֮ǰ£¬£¬£¬£¬£¬£¬£¬£¬FIN7 ±»·¢ÏÖÒÔ¶³öµÄVeeam ±¸·ÝºÍMicrosoft Exchange·þÎñÆ÷Ϊָ±ê£¬£¬£¬£¬£¬£¬£¬£¬²¢½«Black BastaºÍClop ÀÕË÷Èí¼þ¸ºÔز¿Êðµ½ÆóÒµÍøÂçÉÏ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fin7-targets-american-automakers-it-staff-in-phishing-attacks/
5. Óë¶íÂÞ˹ÓйصÄSandworm ¹¥»÷¾üе¿âÖеÄкóÃÅKapeka
4ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬³ýÁË΢ÈíÓÚ 2024 Äê 2 Ô 14 ÈÕ°ä²¼µÄ¹ØÓÚ·¢ÏÖÒ»¸öÃûΪ KnuckleTouch µÄкóÃŵļò¶ÌÃèÊöÖ®±í£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°¹«¼Ò¶Ô Kapeka ºóÃŵÄÏàʶÏÕЩΪÁã¡£¡£¡£¡£¡£¡£¡£Î¢Èí½« KnuckleTouch ºóÃŹé×ïÓÚ SeaShell Blizzard£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÆä¶Ô Sandworm µÄÃû³Æ¡£¡£¡£¡£¡£¡£¡£Microsoft ÉÐδ¶Ô´Ë¶ñÒâÈí¼þ½øÐзÖÎö£¬£¬£¬£¬£¬£¬£¬£¬µ« WithSecure È·ÐÅ KnuckleTouch ¾ÍÊÇ Kapeka¡£¡£¡£¡£¡£¡£¡£Î¢ÈíºÍ WithSecure ÒÔΪ¸Ã¶ñÒâÈí¼þ×Ô 2022 ÄêÒÔÀ´Ò»ÏòÔÚʹÓ㬣¬£¬£¬£¬£¬£¬£¬µ«³ýÁË WithSecure ·ÖÎöÖ®±í£¬£¬£¬£¬£¬£¬£¬£¬ÈËÃÇ¶Ô Kapeka ÖªÖ®ÉõÉÙ¡£¡£¡£¡£¡£¡£¡£WithSecure Æù½ñΪֹֻ·¢ÏÖÁËÁ½¸öÒ°±íÑù±¾¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£Ë¼¿¼µ½µ±Ç°µÄµØÔµÕþÖΣ¬£¬£¬£¬£¬£¬£¬£¬Êܺ¦ÕßѧҲÅú×¢Æä·¢Ô´ÓÚ¶íÂÞ˹£º°®É³ÄáÑǺÍÎÚ¿ËÀ¼¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÓÐÏÞµÄÒ£²â¿ÉÄÜÊÇÓÉÓڸöñÒâÈí¼þÉÐδ¿í·ºÊ¹Ó㬣¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÄÜÊÇÓÉÓÚ Kapeka Ⱥ²ßȺÁ¦Î¬³ÖÒþÃØ¡£¡£¡£¡£¡£¡£¡£
https://www.securityweek.com/kapeka-a-new-backdoor-in-sandworms-arsenal-of-aggression/
6. VisaÕë¶Ô½ðÈÚ»ú¹¹µÄJSOutProxÈÕÒæÔö³¤µÄÍþв·¢³ö¹«¸æ
4ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Visa ×î½ü°ä²¼Á˹ØÓÚ³ö¸ñΣÏÕµÄJSOutProx ¶ñÒâÈí¼þ»î¶¯ÏÔ×ÅÔö³¤µÄÑϳÁ°²È«¾¯±¨¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÔ¶³Ì½Ó¼ûľÂí ( RAT ) ÒÔÆä¶Ô½ðÈÚ»ú¹¹¼°Æä¿Í»§µÄ¸´ÔÓ¹¥»÷ÄÜÁ¦¶øÎÅÃû£¬£¬£¬£¬£¬£¬£¬£¬³ö¸ñÊÇÕë¶ÔÄÏÑǺͶ«ÄÏÑÇ¡¢Öж«ºÍ·ÇÖÞµØÓò¡£¡£¡£¡£¡£¡£¡£JSOutProx ÓÚ 2019 Äê 12 Ô³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»Öָ߶ȻìºÏµÄ JavaScript ºóÃÅ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÍøÂç·¸×ï·Ö×Ó¿ÉÄÜÖ´ÐдóÁ¿¶ñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬ÔËÐÐ shell ºÅÁî¡¢ÏÂÔØ¶î±íµÄÓк¦¸ºÔØ¡¢Ö´ÐÐÎļþ¡¢²¶»ñÆÁÄ»½ØÍ¼ÒÔ¼°ÆëÈ«½ÚÔìÊÜϰȾÉ豸µÄ¼üÅ̺ÍÊó±ê¡£¡£¡£¡£¡£¡£¡£Ëæ×ʦ·òµÄÍÆÒÆ£¬£¬£¬£¬£¬£¬£¬£¬JSOutProx ²»ÐÝ·¢Õ¹£¬£¬£¬£¬£¬£¬£¬£¬¼ÓÇ¿ÁËÆä¶ã±Ü¼¼ÊõÒÔÔ¤·À¼ì²â²¢¼ÓÇ¿ÁËÆä·ÛËéÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£JSOutProx µÄ³õʼÓÐЧ¸ºÔØÖ§³Ö¸ù»ùµ«¹Ø¼üµÄÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹¹¥»÷Õß¿ÉÄܶÔÊÜϰȾµÄϵͳ½øÐÐÏ൱´óµÄ½ÚÔì¡£¡£¡£¡£¡£¡£¡£
https://securityboulevard.com/2024/04/jsoutprox-malware-variant-targeting-financial-orgs-warns-visa/#google_vignette


¾©¹«Íø°²±¸11010802024551ºÅ