΢ÈíÔÚÊý°Ù¸ö×éÖ¯ÄÚÍøÖз¢ÏÖRaspberryRobin

°ä²¼¹¦·ò 2022-07-04

1¡¢Î¢Èíй©ÔÚÊý°Ù¸ö×éÖ¯µÄÄÚÍøÖз¢ÏÖRaspberry Robin 


¾Ý7ÔÂ2ÈÕ±¨Â·£¬Î¢Èí×î½üÔÚ¶à¸öÐÐÒµµÄÊý°Ù¼Ò×éÖ¯µÄÄÚÍøÖз¢ÏÖÁËÒ»ÖÖWindowsÈ䳿Raspberry Robin ¡£¸Ã¶ñÒâÈí¼þ¿Éͨ¹ý±»Ï°È¾µÄUSBÉ豸´«²¼£¬ÓÚ2021Äê9Ô³õ´Î±»·¢ÏÖ ¡£Raspberry Robinͨ¹ýÔ̺¬¶ñÒâ.LNKÎļþµÄUSBÇý¶¯Æ÷ÒÆ¶¯µ½ÐµÄWindowsϵͳ£¬Óû§Ò»µ©ÏνÓÁËUSBÉ豸²¢µ¥»÷Á´½Ó£¬¸ÃÈ䳿¾Í»áʹÓÃcmd.exeÌìÉúÒ»¸ömsiexec¹ý³ÌÀ´Æô¶¯´æ´¢ÔÚ±»Ï°È¾Çý¶¯Æ÷ÉϵĶñÒâÎļþ ¡£Ëü»¹Ê¹ÓÃÁ˼¸¸öºÏ·¨µÄWindows·¨Ê½Ö´ÐжñÒâpayload£ºfodhelper¡¢msiexecºÍodbcconf ¡£Î¢ÈíÒѽ«´Ë»î¶¯ÏóÕ÷Ϊ¸ß·çÏÕ£¬Ä¿Ç°ÉÐ佫Æä¹éÒòÓÚÈκι¥»÷ÍÅ»ï ¡£


https://www.bleepingcomputer.com/news/security/microsoft-finds-raspberry-robin-worm-in-hundreds-of-windows-networks/


2¡¢Sharp Boys³ÆÒÑÔÚÒÔÉ«ÁÐÓÎÀÀÍøÕ¾ÇÔÈ¡30ÍòÈËÐÅÏ¢


¾ÝýÌå7ÔÂ1ÈÕ±¨Â·£¬ºÚ¿ÍÍÅ»ïSharp BoysÐû³ÆÒÑÔÚÒÔÉ«ÁÐÓÎÀÀÍøÕ¾ÇÔÈ¡30ÍòÈËÐÅÏ¢ ¡£¾ÝϤ£¬Óг¬¹ý20¸ö¹Û¹âÉç¡¢¾ÆµêºÍ¶È¼Ù´åµÄÍøÕ¾±»ºÚ£¬Ô̺¬hotel4u.co.il¡¢hotels.co.il¡¢isrotel.com¡¢minihotel.co.il¡¢trivago.co.ilºÍdanhotels.comµÈ£¬Éæ¼°Óû§µÄÉí·ÝÖ¤ºÅÂë¡¢µØÖ·ºÍÐÅÓþ¿¨ÐÅÏ¢µÈ ¡£Ä¿Ç°£¬ÒÔÉ«ÁÐÒþÖÔ±£»¤¾ÖÒѾ­³ä¹«ÁËÍйܶà¸ö¹Û¹âÓйØÍøÕ¾µÄ·þÎñÆ÷£¬ÓÉÓÚËûÃǵÄÔËÓªÉÌδÄܽâ¾öµ¼ÖÂй¶³¬¹ý300000ÈËÐÅÏ¢µÄ°²È«ÎÊÌâ ¡£


https://www.databreaches.net/iranian-hackers-leak-info-of-over-300000-israelis-from-tourism-sites/


3¡¢³ö°æ¹«Ë¾MacmillanÔâµ½ÀÕË÷¹¥»÷ºó¹Ø¹ØÆä»ù´¡ÉèÊ©


ýÌå7ÔÂ2Èճƣ¬ÃÀ¹ú³ö°æ¹«Ë¾Âó¿ËÃ×Â×£¨Macmillan£©Ôâµ½ÍøÂç¹¥»÷ ¡£¹¥»÷²úÉúÔÚ6ÔÂ25ÈÕ£¬¸Ã¹«Ë¾³Æ¹¥»÷Õß¼ÓÃÜÁËMacmillanϵͳÉϵIJ¿ÃÅÎļþ£¬×êÑÐÈËÔ±´§Ä¦ÊÇÀÕË÷¹¥»÷£¬µ«Ä¿Ç°ÉÐδÓкÎÀÕË÷ÍÅ»ïÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬¸ÃÊÂÎñ»¹Ó°ÏìÁËÓ¢¹ú·Ö¹«Ë¾Pan Macmillan ¡£Ä¿Ç°£¬Macmillan¹Ø¹ØÁËÆäIT»ù´¡ÉèÊ©£¬ÒÔÔ¤·À¶ñÒâÈí¼þÔÚÆäÍøÂçÖд«²¼£¬²¢¶Ô´ËÊ·¢Õ¹µ÷²é£¬ÒÔ¾¡¿ì¸´Ô­È«ÃæµÄÍøÂçÖ°ÄÜ ¡£


https://securityaffairs.co/wordpress/132792/cyber-crime/macmillan-ransomware-attack.html


4¡¢Jenkins°ä²¼°²È«¹«¸æ£¬Åû¶Æä¶à¸ö²å¼þÖеÄ34¸ö·ì϶


ýÌå7ÔÂ1ÈÕ±¨Â·³Æ£¬Jenkins°²È«ÍŶӰ䲼Á˹ØÓÚ34¸ö°²È«·ì϶µÄ¹«¸æ£¬ËüÃÇÓ°ÏìÁËJenkins¿ªÔ´×Ô¶¯»¯·þÎñÆ÷µÄ29¸ö²å¼þ£¬ÆäÖÐ29¸ö·ì϶ÈÔÓдý½¨¸´ ¡£ÕâЩ·ì϶Ô̺¬XSS·ì϶¡¢´æ´¢ÐÍXSS·ì϶¡¢¿çÕ¾ÒªÇóαÔì(CSRF)·ì϶¡¢È¨Ï޲鳭ȱʧ£¬ÒÔ¼°ÒÔ´¿Îı¾´ó¾Ö´æ´¢ÃÜÂë¡¢APIÃÜÔ¿ºÍÁîÅÆµÈ ¡£Æ¾¾ÝJenkinsµÄͳ¼ÆÊý¾Ý£¬ÊÜÓ°ÏìµÄ²å¼þ×ܹ²±»×°Öó¬¹ý22000´Î ¡£ÐÒÔ˵ÄÊÇ£¬´óÎÞÊý¸ßÑϳÁÐԵķì϶±ØÒªÓëÓû§½»»¥ÄÜÁ¦±»ÀûÓà ¡£


https://www.bleepingcomputer.com/news/security/jenkins-discloses-dozens-of-zero-day-bugs-in-multiple-plugins/


5¡¢Kaspersky·¢ÏÖÕë¶ÔIIS·þÎñÆ÷µÄкóÃÅSessionManager


6ÔÂ30ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚкóÃÅSessionManagerµÄ·ÖÎö»ã±¨ ¡£×êÑÐÈËÔ±³Æ£¬¸ÃºóÃÅ×Ô2021Äê3ÔÂÒÔÀ´Ò»Ïò±»ÓÃÓÚÕë¶ÔMicrosoft IIS·þÎñÆ÷µÄ¹¥»÷ ¡£ËüÓÉC++±àд£¬ÀûÓÃExchange·þÎñÆ÷ÖеÄProxyLogon·ì϶¼Ù×°³ÉInternetÐÅÏ¢·þÎñ(IIS)µÄÄ£¿é£¬ÓµÓжÁÈ¡¡¢Ð´ÈëºÍɾ³ýËÁÒâÎļþµÄÖ°ÄÜ£¬¿É´Ó·þÎñÆ÷Ö´Ðжþ½øÔìÎļþ£¬²¢ÓëÍøÂçÖÐµÄÆäËü¶Ëµã³ÉÁ¢Í¨Ñ¶ ¡£´Ë±í£¬Æä³äÈÎÁËÒ»¸ö°ÂÃØÍ¨Â·£¬ÓÃÓÚ½øÐпúËÅ¡¢ÍøÂçÄÚ´æÃÜÂ룬²¢ÌṩÆäËü¹¤¾ß£¬ÈçMimikatzµÈ ¡£


https://securelist.com/the-sessionmanager-iis-backdoor/106868/


6¡¢ESET°ä²¼¼ÙÒâ¼ÓÄôó˰Îñ»ú¹¹µÄ´¹µö¹¥»÷»î¶¯µÄ»ã±¨


ESETÔÚ7ÔÂ1ÈÕ°ä²¼Á˼ÙÒâ¼ÓÄôó˰Îñ»ú¹¹µÄ´¹µö¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨ ¡£»î¶¯ÖÐʹÓõĴ¹µöÓʼþÐû³ÆÀ´×Ô¼ÓÄôó˰Îñ¾Ö(CRA)£¬²¢³Ðŵ¿ÉÍË˰½ü500¼ÓÔª ¡£µ±Ö¸±êµã»÷°´Å¥Interac e-Transfer Autodepositʱ£¬½«±»´ÓÍйÜÔÚistandyjeno[.]huµÄ¶ñÒâÁ´½Ó³Á¶¨Ïòµ½ÍйÜÔÚoraclehomes.comµÄ¶ñÒâ×ÓÎļþ¼Ðcra_ca_service ¡£Ö®ºó£¬´¹µöÍøÕ¾»áÓÕʹָ±êÊäÈëÓ×ÎÒÐÅÏ¢ºÍÐÅÓþ¿¨ÐÅÏ¢£¬¶øºóÔÙ½«Æä³Á¶¨Ïòµ½ºÏ·¨µÄCRAÍøÕ¾ ¡£


https://www.welivesecurity.com/2022/07/01/phishing-scam-posing-canadian-tax-agency-canada-day/