΢Èí·¢ÏÖ³¯Ïʹ¥»÷ÕßÀûÓÃH0lyGh0st¹¥»÷ÖÐÓ×ÐÍÆóÒµ

°ä²¼¹¦·ò 2022-07-18
1¡¢Î¢Èí·¢ÏÖ³¯Ïʹ¥»÷ÕßÀûÓÃH0lyGh0st¹¥»÷ÖÐÓ×ÐÍÆóÒµ

      

7ÔÂ14ÈÕ£¬£¬£¬ £¬£¬Î¢Èí°ä²¼»ã±¨·ÖÎöÁ˳¯ÏÊDEV-0530£¨×Ô³ÆÎªH0lyGh0st£©µÄ¹¥»÷Õ½ÊõÒÔ¼°ÆäÀÕË÷Èí¼þµÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£×Ô2021Äê6ÔÂÒÔÀ´£¬£¬£¬ £¬£¬¸ÃÍÅ»ïÒ»ÏòÔÚ¿ª·¢ºÍʹÓÃÀÕË÷Èí¼þ½øÐй¥»÷£¬£¬£¬ £¬£¬²¢ÔçÔÚ2021Äê9Ô¾ͳɹ¦ÈëÇÖÁ˶à¸ö¹ú¶ÈµÄÓ×ÐÍÆóÒµ¡£¡£¡£¡£¡£×êÑÐÈËÔ±½«¸ÃÍÅ»ïµÄÀÕË÷Èí¼þ¹éÀàΪÁ½¸öϵÁУºSiennaPurpleºÍSiennaBlue£¬£¬£¬ £¬£¬²¢ÔÚÕâЩϵÁÐÏÂÈ·¶¨ÁËËĸö±äÌ壺BTLC_C.exe¡¢HolyRS.exe¡¢HolyLock.exeºÍBLTC.exe¡£¡£¡£¡£¡£


https://www.microsoft.com/security/blog/2022/07/14/north-korean-threat-actor-targets-small-and-midsize-businesses-with-h0lygh0st-ransomware/


2¡¢ÃÀ¹úÖÐÇé¾Öǰ¹¤³ÌʦÒòVault 7й¶ÊÂÎñ¶ø±»¶¨×ï

      

¾Ý7ÔÂ14ÈÕ±¨Â·£¬£¬£¬ £¬£¬Å¦Ô¼µÄÒ»¸öÁª¹úÅãÉóÍŰ䷢£¬£¬£¬ £¬£¬ÖÐÑëµý±¨¾ÖÈí¼þ¹¤³ÌʦÏòά»ù½âÃÜÍøÕ¾(WikiLeaks)й¶´óÁ¿»úÃÜÎļþµÄ×ïÃû³ÉÁ¢¡£¡£¡£¡£¡£ÏÖÄê33ËêµÄJoshua SchulteÃæ¶ÔµÄ¾ÅÏîÖ¸¿Ø×ïÃû¾ù³ÉÁ¢£¬£¬£¬ £¬£¬Ô̺¬·¸·¨ÍøÂç¹ú·ÀÐÅÏ¢µÈ¡£¡£¡£¡£¡£Î¬»ù½âÃܽ«ÕâЩ»úÃÜÎļþ¶¨ÃûΪ¡°Vault 7¡±£¬£¬£¬ £¬£¬²¢ÔÚ2017Äê°ä²¼£¬£¬£¬ £¬£¬ÕâЩÎļþ¾ßÌ叿·¢ÁËCIAÈôºÎÈëÇÖµçÄÔ¡¢ÖÇÄÜÊÖ»ú¡¢ÀûÓú͵çÊÓ»úµÈ¡£¡£¡£¡£¡£Î¬»ù½âÃܳÆ£¬£¬£¬ £¬£¬Vault 7ÊÇÓÐÊ·ÒÔÀ´¹ØÓÚCIAµÄ×î´óÒ»´Î»úÃÜÎļþ°ä²¼¡£¡£¡£¡£¡£¸ß¼¶µý±¨¹ÙÔ±ÆÕ±éÒÔΪ£¬£¬£¬ £¬£¬ÕâÊǶÔÃÀ¹ú¼äµý»ú»ú¹Ø³É½ø¹¥µÄ×î¾ß·ÛËéÐÔµÄйÃÜÊÂÎñÖ®Ò»¡£¡£¡£¡£¡£


https://thehackernews.com/2022/07/former-cia-engineer-convicted-of.html


3¡¢Cloudflare³ÆÆä½üǧÃû¿Í»§Ôâµ½À´×ÔMantisµÄDDoS¹¥»÷ 

      

ýÌå7ÔÂ14ÈÕ±¨Â·£¬£¬£¬ £¬£¬Cloudflare°µÊ¾ÆäÔÚ6Ô·ݻº½âÁËÀ´×ÔMantisµÄ´ó¹æÄ£DDoS¹¥»÷¡£¡£¡£¡£¡£MantisÖØÒªÕë¶ÔITºÍµçÐÅÐÐÒµ(36%)¡¢ÐÂÎÅýÌåºÍ³ö°æÎïÐÐÒµ(15%)¡¢½ðÈÚÐÐÒµ(10%) ºÍÓÎÏ·ÐÐÒµ(12%)µÄʵÌå¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬£¬ £¬£¬ÔÚ´Óǰ30ÌìÀ£¬£¬ £¬£¬Æä½üǧÃû¿Í»§Ôâµ½ÁË3000ÂÅ´ÎDDoS¹¥»÷¡£¡£¡£¡£¡£ÓëÓÉIoTÉ豸×é³ÉµÄ´«Í³½©Ê¬ÍøÂç·ÖÆç£¬£¬£¬ £¬£¬MantisʹÓõÄÊDZ»½Ù³ÖµÄÐé¹¹»úºÍ·þÎñÆ÷£¬£¬£¬ £¬£¬Ëü½öÓÃ5000¶à¸ö»úеÈ˾ÍÄÜÿÃëÌìÉú2600Íò¸öHTTPSÒªÇ󡣡£¡£¡£¡£¸Ã»î¶¯ÖØÒªÕë¶ÔÃÀ¹ú(20%)ºÍ¶íÂÞ˹(15%)£¬£¬£¬ £¬£¬Æä´ÎÊÇÍÁ¶úÆä¡¢·¨¹úºÍ²¨À¼µÈ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/mantis-botnet-behind-the-record-breaking-ddos-attack-in-june/


4¡¢Netwrix AuditorÖдæÔÚ¿ÉÓÃÀ´Ö´ÐÐËÁÒâ´úÂëµÄ·ì϶

      

¾Ý7ÔÂ16ÈÕ±¨Â·£¬£¬£¬ £¬£¬Bishop FoxµÄÔÚNetwrix AuditorÈí¼þÖз¢ÏÖÁËÒ»¸ö·ì϶£¬£¬£¬ £¬£¬¿ÉÓÃÀ´ÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£Netwrix AuditorÊÇÒ»¿îÔÊÐí×éÖ¯¼à¿ØÆäIT»ù´¡ÉèÊ©µÄÉó¼ÆÈí¼þ£¬£¬£¬ £¬£¬±»È«ÇòÓг¬¹ý11000¸ö×é֯ʹÓᣡ£¡£¡£¡£ÕâÊÇÒ»¸ö²»°²È«µÄ¶ÔÏó·´ÐòÁл¯·ì϶£¬£¬£¬ £¬£¬µ××ÓÔ­ÒòÊÇ´æÔÚÒ»¸ö²»°²È«µÄ.NETÔ¶³Ì´¦Ö÷þÎñ£¬£¬£¬ £¬£¬¿ÉÔÚNetwrix·þÎñÆ÷ÉϵÄTCP¶Ë¿Ú9004ÉϽӼû£¬£¬£¬ £¬£¬Äܱ»ÓÃÀ´ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬ÓÉÓڸúÅÁîÊÇÒÔNT AUTHORITY/SYSTEMȨÏÞÖ´ÐеÄ£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÆëÈ«½ÚÔìNetwrix·þÎñÆ÷¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬£¬·ì϶Òѱ»½¨¸´¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/133310/hacking/netwrix-auditor-flaw.html 


5¡¢Unit 42й©Õë¶ÔElastix VoIPϵͳµÄ¹¥»÷»î¶¯µÄϸ½Ú

      

7ÔÂ15ÈÕ£¬£¬£¬ £¬£¬Unit 42³ÆÆä·¢ÏÖÁËÒ»³¡Õë¶ÔElastix VoIPµç»°·þÎñÆ÷µÄ´ó¹æÄ£»£»£»£»£»î¶¯¡£¡£¡£¡£¡£ElastixÊÇͳһͨѶµÄ·þÎñÆ÷Èí¼þ£¬£¬£¬ £¬£¬ÓÃÓÚFreePBXµÄDigiumµç»°Ä£¿£¿£¿£¿£¿£¿£¿ £¿é¡£¡£¡£¡£¡£¹¥»÷»î¶¯ÆðÍ·×Ô2021Äê12Ô£¬£¬£¬ £¬£¬ÖÁ2022Äê3ÔÂ×êÑÐÈËÔ±ÒÑ·¢ÏÖÁ˳¬¹ý50Íò¸ö¶ñÒâÈí¼þÑù±¾¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬ £¬£¬¹¥»÷Õß»áͨ¹ýÔÚÖ¸±êµÄDigiumÈí¼þÖÐÏÂÔØºÍÖ´Ðжî±íµÄpayload£¬£¬£¬ £¬£¬Ö²ÈëÒ»¸öweb shellÀ´ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¾Í¹¦·òÏß¶øÑÔ£¬£¬£¬ £¬£¬Web shellËÆºõÓëRest Phone Apps(restapps)Ä£¿£¿£¿£¿£¿£¿£¿ £¿éÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-45461£©ÓйØ¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/digium-phones-web-shell/


6¡¢Wordfence³Æ´ó¹æÄ£¹¥»÷»î¶¯ÒÑɨÃè160Íò¸öWPÍøÕ¾

      

¾ÝýÌå7ÔÂ15Èճƣ¬£¬£¬ £¬£¬Wordfence×êÑÐÈËÔ±¼ì²âµ½ÁËÒ»³¡´ó¹æÄ£¹¥»÷»î¶¯£¬£¬£¬ £¬£¬ÒѾ­É¨ÃèÁ˽ü160Íò¸öWordPressÍøÕ¾¡£¡£¡£¡£¡£¹¥»÷ÕßÖØÒªÕë¶ÔKaswara Modern WPBakeryÒ³ÃæÌìÉúÆ÷£¬£¬£¬ £¬£¬¸Ã²å¼þÒѱ»Æä¿ª·¢ÕßÉÕ»Ù¡£¡£¡£¡£¡£¾ÝWordfenceÒ£²âÊý¾Ý£¬£¬£¬ £¬£¬¹¥»÷´Ó7ÔÂ4ÈÕÆðÍ·£¬£¬£¬ £¬£¬Ä¿Ç°ÈÔÔÚ½øÐÐÖУ¬£¬£¬ £¬£¬¾ùÔÈÿÌìÓÐ443868´Î¹¥»÷³¢ÊÔ¡£¡£¡£¡£¡£¹¥»÷Õß»áÏò¡°wp-admin/admin-ajax/php¡±·¢ËÍPOSTÒªÇ󣬣¬£¬ £¬£¬²¢ÀûÓòå¼þµÄ¡°uploadFontIcon¡±AJAXº¯ÊýÉÏ´«Ô̺¬PHPÎļþµÄ¶ñÒâZIP payload¡£¡£¡£¡£¡£ÕâЩ¹¥»÷À´×Ô10215¸ö·ÖÆçµÄIPµØÖ·£¬£¬£¬ £¬£¬×êÑÐÈËÔ±½¨ÒéÓû§Á¢¿Ìɾ³ý¸Ã²å¼þ£¬£¬£¬ £¬£¬²¢×èÖ¹¹¥»÷ÕßʹÓõÄIPµØÖ·¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/attackers-scan-16-million-wordpress-sites-for-vulnerable-plugin/