ºÚ¿ÍÔÚÈȵãºÚ¿ÍÂÛÌÓð»¯ù³Æ¿ÇÅÆÊý¾ÝÔ⵽й¶

°ä²¼¹¦·ò 2024-05-31
1. ºÚ¿ÍÔÚÈȵãºÚ¿ÍÂÛÌÓð»¯ù³Æ¿ÇÅÆÊý¾ÝÔ⵽й¶


5ÔÂ30ÈÕ£¬£¬ £¬£¬ £¬ÁîÈËÕ𾪵ÄÊÇ£¬£¬ £¬£¬ £¬Ò»ÃûÍþвÐÐΪÕßÉæÏÓй¶ÁËÊÀ½çµ±ÏÈÄÜÔ´¹«Ë¾Ö®Ò»¿ÇÅÆµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Æ¾¾Ý Data Web Informer µÄÍÆÎÄ£¬£¬ £¬£¬ £¬2024 Äê 5 ÔµÄÊý¾Ý±»°ä²¼ÔÚÒ»¸öÊ¢ÐеĺڿÍÂÛ̳ÉÏ£¬£¬ £¬£¬ £¬Òý·¢ÁËÈËÃǶÔÍøÂ簲ȫºÍÊý¾ÝÒþÖÔµÄÑϳÁÓÇÓô¡£¡£¡£¡£¡£¾Ý±¨Â·£¬£¬ £¬£¬ £¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬´óÁ¿Ó×ÎÒÐÅÏ¢ºÍÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬£º¹ºÎïÕß´úÂë¡¢Ãû×Ö¡¢ÐÕÊÏ¡¢×´Ì¬¡¢¹ºÎïÕßµç×ÓÓʼþ¡¢ÁªÏµÊÖ»ú¡¢ÓÊÕþ±àÂë¡¢»¨ÃÛ¡¢½¼Çø¡¢ÖÝ¡¢Õ¾µãµØÖ·¡¢½¼Çø 1¡¢¹ú¶È¡¢Õ¾µãÃû³Æ¡¢ÉϴεǼ¡¢¸¶¿îºÍЭ»á±àºÅ¡£¡£¡£¡£¡£Õâ´ÎйÃÜÊÂÎñ¿ÉÄÜ»á¶Ô¿ÇÅÆ¼°Æä¿Í»§Ôì³ÉÑϳÁÓ°Ïì¡£¡£¡£¡£¡£Ð¹Â¶Èç´Ë¾ßÌåµÄÓ×ÎÒÐÅÏ¢¿ÉÄܻᵼÖÂÉí·Ý͵ÇÔ¡¢½ðÈÚڲƭºÍÆäËû¶ñÒâ»î¶¯¡£¡£¡£¡£¡£½¨Òé¿Í»§Ç×êÇ¼à¿ØËûÃǵÄÕË»§²¢Á¢¼´»ã±¨¿ÉÒɻ¡£¡£¡£¡£¡£½ØÖÁĿǰ£¬£¬ £¬£¬ £¬¿ÇÅÆÉÐδ¾ÍÕâ´ÎйÃÜÊÂÎñ°ä·¢¹Ù·½ÉêÃ÷¡£¡£¡£¡£¡£²»Í⣬£¬ £¬£¬ £¬¸Ã¹«Ë¾Ô¤¼Æ½«Æô¶¯ÄÚ²¿µ÷²é£¬£¬ £¬£¬ £¬²¢ÓëÍøÂ簲ȫר¼ÒºÏ×÷£¬£¬ £¬£¬ £¬ÆÀ¹ÀÎ¥¹æµÄˮƽ²¢¼õÇáÈκÎDZÔÚÇÖº¦¡£¡£¡£¡£¡£


https://gbhackers.com/claiming-shell-data-breach/


2. TicketmasterÔâºÚ¿Í¹¥»÷£¬£¬ £¬£¬ £¬³¬¹ý5 ÒÚÓû§Êý¾ÝÐÅϢй¶


5ÔÂ30ÈÕ£¬£¬ £¬£¬ £¬¾Ý±¨Â·£¬£¬ £¬£¬ £¬±¾ÖÜÔÚµ÷²éµÄÒ»Â·ÍøÂçÊÂÎñÖУ¬£¬ £¬£¬ £¬³¬¹ý 5 ÒÚ Ticketmaster Óû§µÄÓ×ÎÒºÍÐÅÓþ¿¨Êý¾ÝÔ⵽й¶¡£¡£¡£¡£¡£¾Ý±¨Â·£¬£¬ £¬£¬ £¬°Ä´óÀûÑǵ±¾ÖÔÚÓë Live Nation ºÍ Ticketmaster ºÏ×÷½â¾ö´ËÊÂÎñ£¬£¬ £¬£¬ £¬µ«½ØÖÁÖÜÈýÉÏÎ磬£¬ £¬£¬ £¬Åû¶µÄϸ½ÚÓÐÏÞ¡£¡£¡£¡£¡£¾Ý¸ÃÐÂÎÅýÌ屨·£¬£¬ £¬£¬ £¬°Ä´óÀûÑÇÄÚÕþ²¿Í¨Öª ABC£¬£¬ £¬£¬ £¬ËûÃÇÔÚÓë Ticketmaster ºÏ×÷Ïàʶ´ËÊ¡£¡£¡£¡£¡£Ticketmaster »òÆäĸ¹«Ë¾ÉÐδ¾Í´Ëʰ䷢ÈκÎÉêÃ÷¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯ ShinyHunters Ðû³ÆÒÑÆÆ½â Ticketmaster ϵͳ²¢»ñÈ¡ÁËÔ¼ 1.3 TB µÄÊý¾Ý£¬£¬ £¬£¬ £¬ÆäÖÐÔ̺¬ÐÕÃû¡¢µØÖ·¡¢ÐÅÓþ¿¨ºÅ¡¢µç»°ºÅÂëºÍ¸¶¿î¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£Ìý˵ÕâЩÐÅÏ¢ÔÚ°µÍøÉÏÏúÊÛ£¬£¬ £¬£¬ £¬Òª¼Û 50 ÍòÃÀÔª¡£¡£¡£¡£¡£ÔçÆÚ»ã±¨ÏÔʾ£¬£¬ £¬£¬ £¬Óû§Êý¾ÝÉæ¼°È«Çò 5.6 ÒÚ¿Í»§£¬£¬ £¬£¬ £¬µ«Éв»Ã÷ÏÔÄÄЩÊг¡Êܵ½Ó°Ï죨»òÊÜÓ°ÏìµÄÏû·ÑÕßÖÐÓм¸¶àÀ´×ÔÄÄЩÊг¡£¡£¡£¡£¡£©¡£¡£¡£¡£¡£ÏÔÈ»£¬£¬ £¬£¬ £¬Ë¼¿¼µ½Éæ¼°µÄ¸ß¶ÈÃô¸ÐÊý¾Ý£¬£¬ £¬£¬ £¬ÈκÎÊÜÓ°ÏìµÄÏû·ÑÕߵķçÏÕ¶¼¼«¶È¸ß¡£¡£¡£¡£¡£


https://www.ticketnews.com/2024/05/ticketmaster-hack-data-of-half-a-billion-users-up-for-ransom/


3. XWorm v5.6 ¶ñÒâÈí¼þͨ¹ý Webhards ½øÐд«²¼


5ÔÂ30ÈÕ£¬£¬ £¬£¬ £¬°²³¢ÊÔÊÒ°²È«µý±¨ÖÐÐÄ£¨ASEC£©ÔÚ¼à¿Øº«¹ú¶ñÒâÈí¼þµÄ´«²¼Ô´Ê±£¬£¬ £¬£¬ £¬×î½ü·¢ÏÖ¼Ù×°³É³ÉÈËÓÎÏ·µÄXWorm v5.6¶ñÒâÈí¼þÔÚͨ¹ýÍøÂçÓ²Å̽øÐд«²¼¡£¡£¡£¡£¡£ÍøÂçÓ²Å̺ÍÖÖ×ÓÊǺ«¹ú¶ñÒâÈí¼þ´«²¼µÄ³£ÓÃÆ½Ì¨¡£¡£¡£¡£¡£¹¥»÷Õßͨ³£Ê¹ÓÃÈÝÒ×»ñµÃµÄ¶ñÒâÈí¼þ£¬£¬ £¬£¬ £¬ÀýÈç njRAT ºÍ UDP RAT£¬£¬ £¬£¬ £¬²¢½«Æä¼Ù×°³ÉÔ̺¬ÓÎÏ·»ò³ÉÈËÄÚÈÝÔÚÄÚµÄÕý³£·¨Ê½½øÐзַ¢¡£¡£¡£¡£¡£XWorm v5.6 Ò²Äܹ»´Ó GitHub µÈƽ̨ÇáËÉ»ñÈ¡¡£¡£¡£¡£¡£ÏÂÔØ²¢½âѹÓÎÏ·Îļþºó£¬£¬ £¬£¬ £¬»áµÃµ½ Start.exe¡£¡£¡£¡£¡£¹ÌÈ»¿´ÆðÀ´ÏñÊǺϷ¨µÄÓÎÏ·Æô¶¯Æ÷Îļþ£¬£¬ £¬£¬ £¬µ«Ö´ÐÐÓÎÏ·µÄ .exe ÎļþÊǵ¥¶ÀÌìÉú²¢ÔËÐе쬣¬ £¬£¬ £¬²¢ÇÒ¼Ù×°³É SoundP2.muc µÄ¼ÓÔØ·¨Ê½¶ñÒâÈí¼þÒ²»á±»Ö´ÐС£¡£¡£¡£¡£Ö´ÐÐ Start.exe ²»»áÁ¢¼´ÔËÐжñÒâÈí¼þ»òÓÎÏ· £»£»£»£»£»£» £»ËüÃÇ»áÔÚÄú°´Ï¡°ÆðÍ·ÓÎÏ·£¡¡±°´Å¥Ê±Ö´ÐС£¡£¡£¡£¡£ÕâÖÖÕ½ÊõËÆºõÊÇΪÁËÈÆ¹ýɳºÐģʽ¡£¡£¡£¡£¡£SoundP2.muc Ò²±»¸´Ôì²¢Õ³Ìùµ½ Windows Îļþ¼ÐÖУ¬£¬ £¬£¬ £¬²¢Ôö³¤µ½×¢²á±íÖÐÒÔ±ã×Ô¶¯Ö´ÐС£¡£¡£¡£¡£


https://asec.ahnlab.com/en/66099/


4. PyPI¶ñÒâÈí¼þPytoileurÇÔÈ¡¼ÓÃÜÇ®±Ò²¢Èƹý¼ì²â


5ÔÂ31ÈÕ£¬£¬ £¬£¬ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁË Python Èí¼þ°üË÷Òý£¨PyPI£©ÉϵĶñÒâÈí¼þ°üpytoileur¡£¡£¡£¡£¡£¸ÃÈí¼þ°ü¼Ù×°³ÉÓà Python ±àдµÄ API ÖÎÀí¹¤¾ß£¬£¬ £¬£¬ £¬°µ²ØÁËÏÂÔØºÍ×°ÖÃľÂí Windows ¶þ½øÔìÎļþµÄ´úÂë¡£¡£¡£¡£¡£ÕâЩ¶þ½øÔìÎļþ¿ÉÄܽøÐмල¡¢ÊµÏÖÓÆ¾ÃÐÔ²¢ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¸ÃÈí¼þ°ü±» Sonatype µÄ×Ô¶¯¶ñÒâÈí¼þ¼ì²âϵͳ·¢ÏÖ£¬£¬ £¬£¬ £¬²¢ÔÚ±»ÏóÕ÷ºóѸËÙ±»É¾³ý¡£¡£¡£¡£¡£pytoileur Èí¼þ°üÔÚ±»ÒƳýǰÒѱ»ÏÂÔØ 264 ´Î£¬£¬ £¬£¬ £¬ËüʹÓÃÁ˺ýŪÐÔ¼¼ÊõÀ´Ô¤·À±»¼ì²âµ½¡£¡£¡£¡£¡£ËüµÄÔªÊý¾Ý½«ÆäÃèÊöΪ¡°¿áìÅÈí¼þ°ü¡±£¬£¬ £¬£¬ £¬Ê¹ÓÃÒ»ÖÖÕ½Êõ£¬£¬ £¬£¬ £¬¼´¸øÈí¼þ°üÌùÉÏÎüÒýÈ˵ÄÍÌÍÂÃèÊö±êÇ©£¬£¬ £¬£¬ £¬ÒÔÓÕʹ¿ª·¢ÈËÔ±ÏÂÔØËüÃÇ¡£¡£¡£¡£¡£Sonatype ½ñÌì°ä²¼µÄÒ»·ÝÕ÷ѯ»ã±¨ÖÐÃèÊöÁ˽øÒ»²½µÄ²é³­£¬£¬ £¬£¬ £¬·¢ÏÖÈí¼þ°ü×°ÖÃÎļþÖаµ²Ø×Å´óÁ¿¿Õ¸ñËù¸²¸ÇµÄ´úÂë¡£¡£¡£¡£¡£¸Ã´úÂëÖ´ÐÐÁËÒ»¸ö base64 ±àÂëµÄÓÐЧ¸ºÔØ£¬£¬ £¬£¬ £¬¸Ã¸ºÔØ´Ó±í²¿·þÎñÆ÷¼ìË÷Á˶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£ÏÂÔØµÄ¶þ½øÔìÎļþ¡°Runtime.exe¡±ÀûÓà PowerShell ºÍ VBScript ºÅÁî½øÐÐ×ÔÎÒ×°Ö㬣¬ £¬£¬ £¬È·±£ÔÚÊÜϰȾµÄϵͳÖÐÓÆ¾Ã´æÔÚ¡£¡£¡£¡£¡£Ëüѡȡ¸÷Àà·´¼ì²â´ëÊ©À´Ìӱܰ²È«×êÑÐÈËÔ±µÄ·ÖÎö¡£¡£¡£¡£¡£ 


https://www.infosecurity-magazine.com/news/pypi-malware-pytoileur-steals/


5. °ÍÎ÷ÒøÐгÉΪ AllaKore RAT бäÖÖ AllaSenha µÄÖ¸±ê


5ÔÂ29ÈÕ£¬£¬ £¬£¬ £¬°ÍÎ÷ÒøÐлú×é³ÉΪлµÄÖ¸±ê£¬£¬ £¬£¬ £¬¸Ã»î¶¯·Ö·¢»ùÓÚ Windows µÄAllaKoreÔ¶³Ì½Ó¼ûľÂí (RAT)µÄ¶¨Ôì±äÖÖAllaSenha¡£¡£¡£¡£¡£·¨¹úÍøÂ簲ȫ¹«Ë¾ HarfangLabÔÚÒ»·Ý¼¼Êõ·ÖÎöÖаµÊ¾£¬£¬ £¬£¬ £¬¸Ã¶ñÒâÈí¼þ¡°×¨ÃÅÓÃÓÚÇÔÈ¡½Ó¼û°ÍÎ÷ÒøÐÐÕË»§ËùÐèµÄƾ֤£¬£¬ £¬£¬ £¬²¢ÀûÓà Azure ÔÆ×÷ΪºÅÁîºÍ½ÚÔì (C2) »ù´¡ÉèÊ©¡±¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µÄÖ¸±êÔ̺¬°ÍÎ÷ÒøÐÓ×¢Bradesco¡¢Èø·òÀ­ÒøÐÓ×¢Caixa Econ?mica Federal¡¢Ita¨² Unibanco¡¢Sicoob ºÍ Sicredi µÈÒøÐС£¡£¡£¡£¡£¹ÌÈ»ÉÐδµÃµ½Ã÷ȷ֤ʵ£¬£¬ £¬£¬ £¬µ«×î³õµÄ½Ó¼ûÔØÌåÖ¸ÏòÁË´¹µöÓʼþÖÐʹÓöñÒâÁ´½Ó¡£¡£¡£¡£¡£¹¥»÷µÄÆðµãÊÇÒ»¸ö¶ñÒâµÄ Windows ¿ì½Ý·½Ê½ (LNK) Îļþ£¬£¬ £¬£¬ £¬¸ÃÎļþ¼Ù×°³É PDF Îĵµ£¨¡°NotaFiscal.pdf.lnk¡±£©£¬£¬ £¬£¬ £¬ÖÁÉÙ×Ô 2024 Äê 3 ÔÂÆðÍйÜÔÚ WebDAV ·þÎñÆ÷ÉÏ¡£¡£¡£¡£¡ £»£»£»£»£»£» £»¹ÓÐÖ¤¾ÝÅú×¢£¬£¬ £¬£¬ £¬¸Ã»î¶¯±³ºóµÄÍþвÐÐΪÕßÖ®Ç°ÔøÀÄÓà Autodesk A360 Drive ºÍ GitHub µÈºÏ·¨·þÎñÀ´ÍйÜÓÐЧ¸ºÔØ¡£¡£¡£¡£¡£


https://thehackernews.com/2024/05/brazilian-banks-targeted-by-new.html


6. ÀûÓÃDora RATÕë¶Ôº«¹úÆóÒµ£¨Andariel Group£©µÄAPT¹¥»÷


5ÔÂ30ÈÕ£¬£¬ £¬£¬ £¬AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ×î½ü·¢ÏÖÁËÕë¶Ôº«¹ú¹«Ë¾ºÍ»ú¹¹µÄ Andariel APT ¹¥»÷°¸Àý¡£¡£¡£¡£¡£Ö¸±ê×éÖ¯Ô̺¬º«¹úµÄ½ÌÓý»ú¹¹ÒÔ¼°Ôì×÷ºÍ¹¹ÖþÆóÒµ¡£¡£¡£¡£¡£¹¥»÷ʹÓÃÁ˺óÃÁ÷ÅÉļüÅ̼ͼÆ÷¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½ºÍ´úÀí¹¤¾ß¡£¡£¡£¡£¡£ÍþвÐÐΪÕß¿ÉÄÜʹÓÃÕâЩ¶ñÒâÈí¼þÀ´½ÚÔìºÍÇÔÈ¡ÊÜϰȾϵͳµÄÊý¾Ý¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ʹÓÃÁË Andariel ¼¯ÍÅ´Óǰ°¸ÀýÖз¢ÏֵĶñÒâÈí¼þ£¬£¬ £¬£¬ £¬ÆäÖÐ×îÒýÈËÖõÖ÷ÕÅÊÇ Nestdoor£¬£¬ £¬£¬ £¬ÕâÊDZ¾ÎÄÖÐÌáµ½µÄºóÃÅ¡£¡£¡£¡£¡£ÆäËû°¸ÀýÔ̺¬Ôö³¤ Web Shell¡£¡£¡£¡£¡£Lazarus ¼¯ÍÅÏÈǰ¹¥»÷Öз¢ÏֵĴúÀí¹¤¾ßÒ²±»Ê¹Ó㬣¬ £¬£¬ £¬Ö»¹ÜËüÃǵÄÎļþÓ뵱ǰ°¸Àý²¢²»Ò»Ñù¡£¡£¡£¡£¡£ÔÚ¹¥»÷¹ý³ÌÖеĶà¶àÖ¤¾ÝÖУ¬£¬ £¬£¬ £¬Ò»¸öÏÖʵ±»Ö¤ÊµµÄ°¸ÀýÉæ¼°Ê¹ÓÃÔËÐÐ Apache Tomcat ·þÎñÆ÷µÄ Web ·þÎñÆ÷·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ÓÉÓÚÓÐÎÊÌâµÄϵͳÔËÐеÄÊÇ 2013 °æ Apache Tomcat£¬£¬ £¬£¬ £¬Òò¶øÈÝÒ×Êܵ½¸÷Àà·ì϶¹¥»÷¡£¡£¡£¡£¡£ÍþвÐÐΪÕßʹÓøà Web ·þÎñÆ÷×°ÖúóÃÅ¡¢´úÀí¹¤¾ßµÈ¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/66088/