¶íÂÞ˹ÔËÓªÉÌMiranda MediaÔâµ½´ó¹æÄ£DDoS¹¥»÷

°ä²¼¹¦·ò 2023-10-31

1¡¢¶íÂÞ˹ÔËÓªÉÌMiranda MediaÔâµ½´ó¹æÄ£DDoS¹¥»÷


¾ÝýÌå10ÔÂ29ÈÕ±¨Â·£¬Miranda Media ISPÔÚÉÏÖÜÎå°ä·¢ÕýÃæ¶Ô´ó¹æÄ£DDoS¹¥»÷¡£IT Army of Ukraine×éÖ¯²¢²ß¶¯ÁËÕë¶Ô¶íÂÞ˹Èý´ó»¥ÁªÍøÌṩÉÌÖ´ÐÐDDoS¹¥»÷¡£Miranda Media³Æ£¬×Ô10ÔÂ27ÈÕÉÏÎç9:05ÒÔÀ´£¬ÔËÓªÉÌMiranda-Media¼Í¼ÁËÀ´×ÔÎÚ¿ËÀ¼ÍÅ»ïµÄ´ó¹æÄ£DDoS¹¥»÷£¬Miranda-Media¡¢KrymtelecomºÍMirTelecomµÄ·þÎñÁÙʱ²»³ÉÓ᣸ÃÊÂÎñ²»½öÓ°Ïìµ½¿ËÀïÃ×ÑÇ£¬»¹Ó°Ïìµ½ºÕ¶ûËÉ¡¢Ôú²¨ÂÞÈÈ¡¢¶ÙÄù´Ä¿ËºÍ¬¸Ê˹¿ËµØÓòµÄ²¿ÃŵØÓò¡£


https://securityaffairs.com/153192/hacktivism/it-army-of-ukraine-hit-russia-isp.html


2¡¢ÀÕË÷ÍÅ»ïRansomedVC°ä·¢Ç²É¢²¢ÏúÊÛÆä¹¤¾ß´úÂë


¾Ý10ÔÂ30ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïRansomedVC°ä·¢Òò¡°Ó×ÎÒÔ­Òò¡±Ç²É¢£¬²¢½«ÏúÊÛÆäÕû¸öÍøÂç»ù´¡ÉèÊ©¡£RansomedVCÓÚ½ñÄê8Ô³õ´Î³öÏÖ£¬Õë¶Ô¹«Ë¾¡¢µ±¾Ö»ú¹¹ºÍ½ÌÓý»ú¹¹µÈ¡£Õâ´ÎÏúÊÛµÄ×ʲúÊýÁ¿¾ªÈË£¬Ô̺¬¸÷ÀàÓòÃûºÍÂÛ̳¡¢ÀÕË÷Èí¼þÌìÉúÆ÷¡¢´ÓÊôÍÅ»ïµÄ½Ó¼ûȨÏÞ¡¢É罻ýÌåÕË»§¡¢TelegramƵ·¡¢¶à¼Ò¹«Ë¾µÄVPN½Ó¼ûȨÏ޺ͼÛÖµ³¬¹ý1000ÍòÃÀÔªµÄÊý¾Ý¿âµÈ¡£×êÑÐÈËÔ±´§Ä¦Ç²É¢µÄÔ­Òò£¬¿ÉÄÜÊÇÀ´×Ô·¨ÂÉ»ú¹¹µÄѹÁ¦£¬Ò²¿ÉÄÜÊÇÒ»¸öеĸü¸´ÔÓµÄÐж¯ÔÚÔÍÄðÖ®ÖС£


https://www.hackread.com/ransomedvc-ransomware-quit-sell-infrastructure/


3¡¢Elastic·¢ÏÖͨ¹ýαÔìMSIXÀûÓ÷ַ¢GHOSTPULSEµÄ»î¶¯


10ÔÂ27ÈÕ£¬Elastic¼ì²âµ½Ò»ÖÖÐµĹ¥»÷»î¶¯£¬Ê¹ÓÃαÔìµÄMSIX WindowsÀûÓ÷¨Ê½°ü£¬À´·Ö·¢ÐÂÐͶñÒâÈí¼þ¼ÓÔØ·¨Ê½GHOSTPULSE¡£¸Ã»î¶¯Ê×ÏÅ×ÕʹÓû§ÏÂÔØMSIXÈí¼þ°ü£¬µ±Óû§Æô¶¯MSIXÎļþ»áµ¯³öÒ»¸ö´°¿ÚÌáÐѵã»÷¡°×°Öá±°´Å¥¡£µã»÷ºó£¬Ò»¸öPowerShell¾ç±¾»á°ÂÃØµØÔÚϵͳ¸ßµÍÔØ¡¢½âÃܺÍÖ´ÐÐGHOSTPULSE¡£GHOSTPULSE×÷Ϊ¼ÓÔØ·¨Ê½£¬Ñ¡È¡Process Doppelg?nging¹¥»÷·½Ê½Æô¶¯×îÖÕpayload¡£×îÖÕpayloadÒòÑù±¾¶øÒ죬Ô̺¬SectopRAT¡¢Rhadamanthys¡¢Vidar¡¢LummaºÍNetSupport RAT¡£


https://www.elastic.co/security-labs/ghostpulse-haunts-victims-using-defense-evasion-bag-o-tricks


4¡¢¼ÓÖÝijÊÐÔâµ½NoEscapeµÄÀÕË÷¹¥»÷Ô¼200GBÊý¾Ý±»µÁ


ýÌå10ÔÂ27Èճƣ¬ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖÝά¿Ë¶àά¶ûй©ÆäÔâµ½ÁËÀÕË÷¹¥»÷¡£¸ÃÊа䲼֪ͨ³Æ£¬ºÚ¿ÍÔÚ8ÔÂ12ÈÕÖÁ9ÔÂ26ÈÕÈëÇÖÁËËûÃǵÄϵͳ£¬¾ÓÃñÉç»á°²È«ºÅÂëºÍÒ½ÁÆÐÅÏ¢µÈй¶¡£ÊÐÕþÔ±¹¤ÓÚ9ÔÂ25ÈÕÔÚFacebookÉϳÆ£¬ÔÚ´¦ÖÃÓ°Ïìµç»°ºÍÍøÕ¾ÏµÍ³µÄÖжÏÎÊÌ⣬֮ºó°µÊ¾ÒÑÓÚ10ÔÂ3ÈÕ¸´Ô­µç»°ºÍÍøÕ¾·þÎñ£¬µ«»ùÓÚÍøÂçµÄϵͳÈÔÎÞ·¨ÔËÐС£ÉÏÖܶþ£¬NoEscape½«¸ÃÊÐÔö³¤µ½ÆäÁбíÖУ¬Ðû³ÆÒÑ´ÓÊÐÕþϵͳÖÐÇÔÈ¡ÁË200GBµÄÊý¾Ý¡£


https://therecord.media/california-victorville-warns-of-data-breach-after-noescape-ransomware-claims


5¡¢Harmony Email°ä²¼¹ØÓÚQuishing¹¥»÷µÄ·ÖÎö»ã±¨


10ÔÂ26ÈÕ£¬Check PointµÄHarmony EmailÍŶӰ䲼Á˹ØÓÚQuishing£¨¼´¶þάÂë´¹µö£©¹¥»÷µÄ·ÖÎö»ã±¨¡£½ñÄê8Ôµ½9Ô£¬¶þάÂë¹¥»÷Ôö³¤ÁË587%¡£¸Ã»ã±¨»¹¸ÅÊöÁËһ·¹¥»÷»î¶¯£¬À´»áÉ̺ڿÍÈôºÎÀûÓöþάÂëÇÔȡƾ֤¡£¹¥»÷Õß´´½¨ÁËÒ»¸ö½«Óû§³Á¶¨Ïòµ½Í´´¦ÍøÂçÒ³ÃæµÄ¶þάÂ룬¶øºó·¢ËÍÒÔ¡°Microsoft MFA¼´½«¹ýÆÚ¡±Îªµö¶üµÄÓʼþ£¬ÒªÇóÊÕ¼þÈ˳ÁнøÐÐÉí·ÝÑéÖ¤£¬Óû§É¨Ãè¶þάÂëºó½«±»³Á¶¨Ïòµ½Ò»¸ö¿´ÆðÀ´Ïñ΢ÈíÍøÕ¾µÄÍ´´¦ÍøÂçÍøÕ¾¡£ 


https://www.avanan.com/blog/the-rise-in-qr-code-attacks


6¡¢Cloudflare°ä²¼2023ÄêQ3 DDoS¹¥»÷Ì¬ÊÆµÄ»ã±¨


10ÔÂ26ÈÕ£¬Cloudflare°ä²¼ÁË2023ÄêµÚÈý¼¾¶ÈDDoS¹¥»÷Ì¬ÊÆµÄ»ã±¨¡£µÚÈý¼¾¶È£¬Cloudflare½â¾öÁËÊýǧÆð´ó¹æÄ£HTTP DDoS¹¥»÷¡£ÆäÖУ¬89Æð³¬¹ýÿÃë1ÒÚÒªÇó (rps)£¬×î´ó·åֵΪ2.01ÒÚrps£¬ÕâÊÇ֮ǰ×î´ó¹æÄ£¹¥»÷(7100Íòrps)µÄÈý±¶£¬ÕâЩ¹¥»÷ÊÇͨ¹ýHTTP/2 Rapid ResetʵÏֵġ£ÕâÒ»¼¾¶ÈµÄHTTP DDoS¹¥»÷Á÷Á¿½ÏÉÏÒ»¼¾¶È×ÜÌåÔö³¤65%£¬L3/4 DDoS¹¥»÷Ò²Ôö³¤ÁË14%¡£Cloudflare»¹¹Û²ìµ½ÐµÄÇ÷Ïò£¬mDNS¹¥»÷Ôö³¤ÁË456%£¬CoAP DDoS¹¥»÷Ôö³¤ÁË387%£¬ESP DDoS¹¥»÷Ôö³¤ÁË303%£¬ÀÕË÷DDoS¹¥»÷³ÊÏÂÔØÇ÷Ïò¡£


https://blog.cloudflare.com/ddos-threat-report-2023-q3/