ºÚ¿ÍÔÚÈȵãºÚ¿ÍÂÛÌÓð»¯ù³Æ¿ÇÅÆÊý¾ÝÔ⵽й¶
°ä²¼¹¦·ò 2024-05-315ÔÂ30ÈÕ£¬ÁîÈËÕ𾪵ÄÊÇ£¬Ò»ÃûÍþвÐÐΪÕßÉæÏÓй¶ÁËÊÀ½çµ±ÏÈÄÜÔ´¹«Ë¾Ö®Ò»¿ÇÅÆµÄÃô¸ÐÊý¾Ý¡£Æ¾¾Ý Data Web Informer µÄÍÆÎÄ£¬2024 Äê 5 ÔµÄÊý¾Ý±»°ä²¼ÔÚÒ»¸öÊ¢ÐеĺڿÍÂÛ̳ÉÏ£¬Òý·¢ÁËÈËÃǶÔÍøÂ簲ȫºÍÊý¾ÝÒþÖÔµÄÑϳÁÓÇÓô¡£¾Ý±¨Â·£¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬´óÁ¿Ó×ÎÒÐÅÏ¢ºÍÃô¸ÐÊý¾Ý¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬£º¹ºÎïÕß´úÂë¡¢Ãû×Ö¡¢ÐÕÊÏ¡¢×´Ì¬¡¢¹ºÎïÕßµç×ÓÓʼþ¡¢ÁªÏµÊÖ»ú¡¢ÓÊÕþ±àÂë¡¢»¨ÃÛ¡¢½¼Çø¡¢ÖÝ¡¢Õ¾µãµØÖ·¡¢½¼Çø 1¡¢¹ú¶È¡¢Õ¾µãÃû³Æ¡¢ÉϴεǼ¡¢¸¶¿îºÍлá±àºÅ¡£Õâ´ÎйÃÜÊÂÎñ¿ÉÄÜ»á¶Ô¿ÇÅÆ¼°Æä¿Í»§Ôì³ÉÑϳÁÓ°Ï졣й¶Èç´Ë¾ßÌåµÄÓ×ÎÒÐÅÏ¢¿ÉÄܻᵼÖÂÉí·Ý͵ÇÔ¡¢½ðÈÚÚ²ÆºÍÆäËû¶ñÒâ»î¶¯¡£½¨Òé¿Í»§Ç×êÇ¼à¿ØËûÃǵÄÕË»§²¢µ±¼´»ã±¨¿ÉÒɻ¡£½ØÖÁĿǰ£¬¿ÇÅÆÉÐδ¾ÍÕâ´ÎйÃÜÊÂÎñ°ä·¢¹Ù·½ÉêÃ÷¡£²»Í⣬¸Ã¹«Ë¾Ô¤¼Æ½«Æô¶¯ÄÚ²¿µ÷²é£¬²¢ÓëÍøÂ簲ȫר¼ÒºÏ×÷£¬ÆÀ¹ÀÎ¥¹æµÄˮƽ²¢¼õÇáÈκÎDZÔÚÇÖº¦¡£
https://gbhackers.com/claiming-shell-data-breach/
2. TicketmasterÔâºÚ¿Í¹¥»÷£¬³¬¹ý5 ÒÚÓû§Êý¾ÝÐÅϢй¶
5ÔÂ30ÈÕ£¬¾Ý±¨Â·£¬±¾ÖÜÔÚµ÷²éµÄÒ»Â·ÍøÂçÊÂÎñÖУ¬³¬¹ý 5 ÒÚ Ticketmaster Óû§µÄÓ×ÎÒºÍÐÅÓþ¿¨Êý¾ÝÔ⵽й¶¡£¾Ý±¨Â·£¬°Ä´óÀûÑǵ±¾ÖÔÚÓë Live Nation ºÍ Ticketmaster ºÏ×÷½â¾ö´ËÊÂÎñ£¬µ«½ØÖÁÖÜÈýÉÏÎ磬Åû¶µÄϸ½ÚÓÐÏÞ¡£¾Ý¸ÃÐÂÎÅýÌ屨·£¬°Ä´óÀûÑÇÄÚÕþ²¿Í¨Öª ABC£¬ËûÃÇÔÚÓë Ticketmaster ºÏ×÷Ïàʶ´ËÊ¡£Ticketmaster »òÆäĸ¹«Ë¾ÉÐδ¾Í´Ëʰ䷢ÈκÎÉêÃ÷¡£ºÚ¿Í×éÖ¯ ShinyHunters Ðû³ÆÒÑÆÆ½â Ticketmaster ϵͳ²¢»ñÈ¡ÁËÔ¼ 1.3 TB µÄÊý¾Ý£¬ÆäÖÐÔ̺¬ÐÕÃû¡¢µØÖ·¡¢ÐÅÓþ¿¨ºÅ¡¢µç»°ºÅÂëºÍ¸¶¿î¾ßÌåÐÅÏ¢¡£Ìý˵ÕâЩÐÅÏ¢ÔÚ°µÍøÉÏÏúÊÛ£¬Òª¼Û 50 ÍòÃÀÔª¡£ÔçÆÚ»ã±¨ÏÔʾ£¬Óû§Êý¾ÝÉæ¼°È«Çò 5.6 ÒÚ¿Í»§£¬µ«Éв»Ã÷ÏÔÄÄЩÊг¡Êܵ½Ó°Ï죨»òÊÜÓ°ÏìµÄÏû·ÑÕßÖÐÓм¸¶àÀ´×ÔÄÄЩÊг¡£©¡£ÏÔÈ»£¬Ë¼¿¼µ½Éæ¼°µÄ¸ß¶ÈÃô¸ÐÊý¾Ý£¬ÈκÎÊÜÓ°ÏìµÄÏû·ÑÕߵķçÏÕ¶¼¼«¶È¸ß¡£
https://www.ticketnews.com/2024/05/ticketmaster-hack-data-of-half-a-billion-users-up-for-ransom/
3. XWorm v5.6 ¶ñÒâÈí¼þͨ¹ý Webhards ½øÐд«²¼
5ÔÂ30ÈÕ£¬°²³¢ÊÔÊÒ°²È«µý±¨ÖÐÐÄ£¨ASEC£©ÔÚ¼à¿Øº«¹ú¶ñÒâÈí¼þµÄ´«²¼Ô´Ê±£¬×î½ü·¢ÏÖ¼Ù×°³É³ÉÈËÓÎÏ·µÄXWorm v5.6¶ñÒâÈí¼þÔÚͨ¹ýÍøÂçÓ²Å̽øÐд«²¼¡£ÍøÂçÓ²Å̺ÍÖÖ×ÓÊǺ«¹ú¶ñÒâÈí¼þ´«²¼µÄ³£ÓÃÆ½Ì¨¡£¹¥»÷Õßͨ³£Ê¹ÓÃÈÝÒ×»ñµÃµÄ¶ñÒâÈí¼þ£¬ÀýÈç njRAT ºÍ UDP RAT£¬²¢½«Æä¼Ù×°³ÉÔ̺¬ÓÎÏ·»ò³ÉÈËÄÚÈÝÔÚÄÚµÄÕý³£·¨Ê½½øÐзַ¢¡£XWorm v5.6 Ò²Äܹ»´Ó GitHub µÈƽ̨ÇáËÉ»ñÈ¡¡£ÏÂÔØ²¢½âѹÓÎÏ·Îļþºó£¬»áµÃµ½ Start.exe¡£¹ÌÈ»¿´ÆðÀ´ÏñÊǺϷ¨µÄÓÎÏ·Æô¶¯Æ÷Îļþ£¬µ«Ö´ÐÐÓÎÏ·µÄ .exe ÎļþÊǵ¥¶ÀÌìÉú²¢ÔËÐе쬲¢ÇÒ¼Ù×°³É SoundP2.muc µÄ¼ÓÔØ·¨Ê½¶ñÒâÈí¼þÒ²»á±»Ö´ÐС£Ö´ÐÐ Start.exe ²»»áµ±¼´ÔËÐжñÒâÈí¼þ»òÓÎÏ·£»ËüÃÇ»áÔÚÄú°´Ï¡°ÆðÍ·ÓÎÏ·£¡¡±°´Å¥Ê±Ö´ÐС£ÕâÖÖÕ½ÊõËÆºõÊÇΪÁËÈÆ¹ýɳºÐģʽ¡£SoundP2.muc Ò²±»¸´Ôì²¢Õ³Ìùµ½ Windows Îļþ¼ÐÖУ¬²¢Ôö³¤µ½×¢²á±íÖÐÒÔ±ã×Ô¶¯Ö´ÐС£
https://asec.ahnlab.com/en/66099/
4. PyPI¶ñÒâÈí¼þPytoileurÇÔÈ¡¼ÓÃÜÇ®±Ò²¢Èƹý¼ì²â
5ÔÂ31ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁË Python Èí¼þ°üË÷Òý£¨PyPI£©ÉϵĶñÒâÈí¼þ°üpytoileur¡£¸ÃÈí¼þ°ü¼Ù×°³ÉÓà Python ±àдµÄ API ÖÎÀí¹¤¾ß£¬°µ²ØÁËÏÂÔØºÍ×°ÖÃľÂí Windows ¶þ½øÔìÎļþµÄ´úÂë¡£ÕâЩ¶þ½øÔìÎļþ¿ÉÄܽøÐмල¡¢ÊµÏÖÓÆ¾ÃÐÔ²¢ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¸ÃÈí¼þ°ü±» Sonatype µÄ×Ô¶¯¶ñÒâÈí¼þ¼ì²âϵͳ·¢ÏÖ£¬²¢ÔÚ±»ÏóÕ÷ºóѸ¿ì±»É¾³ý¡£pytoileur Èí¼þ°üÔÚ±»ÒƳýǰÒѱ»ÏÂÔØ 264 ´Î£¬ËüʹÓÃÁ˺ýŪÐÔ¼¼ÊõÀ´Ô¤·À±»¼ì²âµ½¡£ËüµÄÔªÊý¾Ý½«ÆäÃèÊöΪ¡°¿áìÅÈí¼þ°ü¡±£¬Ê¹ÓÃÒ»ÖÖÕ½Êõ£¬¼´¸øÈí¼þ°üÌùÉÏÎüÒýÈ˵ÄÍÌÍÂÃèÊö±êÇ©£¬ÒÔÓÕʹ¿ª·¢ÈËÔ±ÏÂÔØËüÃÇ¡£Sonatype ½ñÌì°ä²¼µÄÒ»·ÝÕ÷ѯ»ã±¨ÖÐÃèÊöÁ˽øÒ»²½µÄ²é³£¬·¢ÏÖÈí¼þ°ü×°ÖÃÎļþÖаµ²Ø×Å´óÁ¿¿Õ¸ñËù¸²¸ÇµÄ´úÂë¡£¸Ã´úÂëÖ´ÐÐÁËÒ»¸ö base64 ±àÂëµÄÓÐЧ¸ºÔØ£¬¸Ã¸ºÔØ´Ó±í²¿·þÎñÆ÷¼ìË÷Á˶ñÒâ¿ÉÖ´ÐÐÎļþ¡£ÏÂÔØµÄ¶þ½øÔìÎļþ¡°Runtime.exe¡±ÀûÓà PowerShell ºÍ VBScript ºÅÁî½øÐÐ×ÔÎÒ×°Öã¬È·±£ÔÚÊÜϰȾµÄϵͳÖÐÓÆ¾Ã´æÔÚ¡£Ëüѡȡ¸÷Àà·´¼ì²â´ëÊ©À´Ìӱܰ²È«×êÑÐÈËÔ±µÄ·ÖÎö¡£
https://www.infosecurity-magazine.com/news/pypi-malware-pytoileur-steals/
5. °ÍÎ÷ÒøÐгÉΪ AllaKore RAT бäÖÖ AllaSenha µÄÖ¸±ê
5ÔÂ29ÈÕ£¬°ÍÎ÷ÒøÐлú×é³ÉΪлµÄÖ¸±ê£¬¸Ã»î¶¯·Ö·¢»ùÓÚ Windows µÄAllaKoreÔ¶³Ì½Ó¼ûľÂí (RAT)µÄ¶¨Ôì±äÖÖAllaSenha¡£·¨¹úÍøÂ簲ȫ¹«Ë¾ HarfangLabÔÚÒ»·Ý¼¼Êõ·ÖÎöÖаµÊ¾£¬¸Ã¶ñÒâÈí¼þ¡°×¨ÃÅÓÃÓÚÇÔÈ¡½Ó¼û°ÍÎ÷ÒøÐÐÕË»§ËùÐèµÄƾ֤£¬²¢ÀûÓà Azure ÔÆ×÷ΪºÅÁîºÍ½ÚÔì (C2) »ù´¡ÉèÊ©¡±¡£Õâ´Î¹¥»÷µÄÖ¸±êÔ̺¬°ÍÎ÷ÒøÐÓ×¢Bradesco¡¢Èø·òÀÒøÐÓ×¢Caixa Econ?mica Federal¡¢Ita¨² Unibanco¡¢Sicoob ºÍ Sicredi µÈÒøÐС£¹ÌÈ»ÉÐδµÃµ½Ã÷ȷ֤ʵ£¬µ«×î³õµÄ½Ó¼ûÔØÌåÖ¸ÏòÁË´¹µöÓʼþÖÐʹÓöñÒâÁ´½Ó¡£¹¥»÷µÄÆðµãÊÇÒ»¸ö¶ñÒâµÄ Windows ¿ì½Ý·½Ê½ (LNK) Îļþ£¬¸ÃÎļþ¼Ù×°³É PDF Îĵµ£¨¡°NotaFiscal.pdf.lnk¡±£©£¬ÖÁÉÙ×Ô 2024 Äê 3 ÔÂÆðÍйÜÔÚ WebDAV ·þÎñÆ÷ÉÏ¡£»¹ÓÐÖ¤¾ÝÅú×¢£¬¸Ã»î¶¯±³ºóµÄÍþвÐÐΪÕßÖ®Ç°ÔøÀÄÓà Autodesk A360 Drive ºÍ GitHub µÈºÏ·¨·þÎñÀ´ÍйÜÓÐЧ¸ºÔØ¡£
https://thehackernews.com/2024/05/brazilian-banks-targeted-by-new.html
6. ÀûÓÃDora RATÕë¶Ôº«¹úÆóÒµ£¨Andariel Group£©µÄAPT¹¥»÷
5ÔÂ30ÈÕ£¬AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ×î½ü·¢ÏÖÁËÕë¶Ôº«¹ú¹«Ë¾ºÍ»ú¹¹µÄ Andariel APT ¹¥»÷°¸Àý¡£Ö¸±ê×éÖ¯Ô̺¬º«¹úµÄ½ÌÓý»ú¹¹ÒÔ¼°Ôì×÷ºÍ¹¹ÖþÆóÒµ¡£¹¥»÷ʹÓÃÁ˺óÃÁ÷ÅÉļüÅ̼ͼÆ÷¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½ºÍ´úÀí¹¤¾ß¡£ÍþвÐÐΪÕß¿ÉÄÜʹÓÃÕâЩ¶ñÒâÈí¼þÀ´½ÚÔìºÍÇÔÈ¡ÊÜϰȾϵͳµÄÊý¾Ý¡£Õâ´Î¹¥»÷ʹÓÃÁË Andariel ¼¯ÍÅ´Óǰ°¸ÀýÖз¢ÏֵĶñÒâÈí¼þ£¬ÆäÖÐ×îÒýÈËÖõÖ÷ÕÅÊÇ Nestdoor£¬ÕâÊDZ¾ÎÄÖÐÌáµ½µÄºóÃÅ¡£ÆäËû°¸ÀýÔ̺¬Ôö³¤ Web Shell¡£Lazarus ¼¯ÍÅÏÈǰ¹¥»÷Öз¢ÏֵĴúÀí¹¤¾ßÒ²±»Ê¹Óã¬Ö»¹ÜËüÃǵÄÎļþÓ뵱ǰ°¸Àý²¢²»Ò»Ñù¡£ÔÚ¹¥»÷¹ý³ÌÖеĶà¶àÖ¤¾ÝÖУ¬Ò»¸öÏÖʵ±»Ö¤ÊµµÄ°¸ÀýÉæ¼°Ê¹ÓÃÔËÐÐ Apache Tomcat ·þÎñÆ÷µÄ Web ·þÎñÆ÷·Ö·¢¶ñÒâÈí¼þ¡£ÓÉÓÚÓÐÎÊÌâµÄϵͳÔËÐеÄÊÇ 2013 °æ Apache Tomcat£¬Òò¶øÈÝÒ×Êܵ½¸÷Àà·ì϶¹¥»÷¡£ÍþвÐÐΪÕßʹÓøà Web ·þÎñÆ÷×°ÖúóÃÅ¡¢´úÀí¹¤¾ßµÈ¡£
https://asec.ahnlab.com/en/66088/


¾©¹«Íø°²±¸11010802024551ºÅ