ÐÂÀÕË÷Èí¼þMalasLockerÒªÇóÖ¸±êÏò´È±¯»ú¹¹¾è¿î

°ä²¼¹¦·ò 2023-05-19

1¡¢ÐÂÀÕË÷Èí¼þMalasLockerÒªÇóÖ¸±êÏò´È±¯»ú¹¹¾è¿î


¾ÝýÌå5ÔÂ17ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ÐÂÀÕË÷Èí¼þMalasLockerͨ¹ýÈëÇÖZimbra·þÎñÆ÷À´ÇÔÈ¡Óʼþ²¢¼ÓÃÜÎļþ¡£¡£¡£¡£¡£ ¡£µ«¹¥»÷Õß²¢Ã»ÓÐÒªÇóÖ¸±ê½»Êê½ð£¬£¬£¬£¬£¬£¬£¬¶øÊÇÒªÇóËûÃÇÏòÖ¸¶¨µÄ·ÇͶ»ú´È±¯»ú¹¹¾è¿î¡£¡£¡£¡£¡£ ¡£¸Ã»î¶¯Ê¼ÓÚ3Ôµף¬£¬£¬£¬£¬£¬£¬ÔÚ¼ÓÃܵç×ÓÓʼþʱ£¬£¬£¬£¬£¬£¬£¬Ëü²»»áÔÚÎļþÃû¸½¼Ó¶î±íµÄÀ©´óÃû¡£¡£¡£¡£¡£ ¡£µ«ËûÃÇÔÚÿ¸ö¼ÓÃÜÎļþµÄĩβ¶¼¸½¼ÓÁËÒ»¸ö"´ËÎļþÒѼÓÃÜ£¬£¬£¬£¬£¬£¬£¬Çë²é¿´README.txtÏàʶ½âÃÜ×¢Ã÷"µÄÐÅÏ¢¡£¡£¡£¡£¡£ ¡£Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷ÕßÊÇÈôºÎÈëÇÖZimbra·þÎñÆ÷¡£¡£¡£¡£¡£ ¡£MalasLockerµÄÍøÕ¾Ä¿Òѹ«¿ªÈý¼Ò¹«Ë¾µÄÊý¾ÝºÍÆäËû169¸ö±»¹¥»÷ÕßµÄZimbraÅäÖᣡ£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/malaslocker-ransomware-targets-zimbra-servers-demands-charity-donation/


2¡¢Apple½¨¸´iPhone¡¢MacºÍiPadÖÐÈý¸öÒѱ»ÀûÓõķì϶


5ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬£¬Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËiPhone¡¢MacºÍiPadÖÐÈý¸öÒѱ»ÀûÓõķì϶¡£¡£¡£¡£¡£ ¡£ÕâЩ·ì϶¾ùÔÚ¶àÆ½Ì¨WebKitä¯ÀÀÆ÷ÒýÇæÖб»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬±ðÀëÊÇ¿ÉÓÃÀ´Í»ÆÆWebÄÚÈÝɳÏäµÄɳÏäÌÓÒÝ·ì϶£¨CVE-2023-32409£©¡¢½Ó¼ûÃô¸ÐÐÅÏ¢µÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2023-28204£©ºÍÖ´ÐÐËÁÒâ´úÂëµÄ¿ªÊͺóʹÓ÷ì϶£¨CVE-2023-32373£©¡£¡£¡£¡£¡£ ¡£Appleͨ¹ý¸Ä½øÌìǵ²é³­¡¢ÊäÈëÑéÖ¤ºÍÄÚ´æÖÎÀí½â¾öÁËÕâЩÎÊÌ⣬£¬£¬£¬£¬£¬£¬Ã»Óй«¿ªÓйØÕâЩ¹¥»÷µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£ ¡£×ÔËêÊ×ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬AppleÒѽ¨¸´ÁË6¸öÁãÈÕ·ì϶¡£¡£¡£¡£¡£ ¡£ 


https://securityaffairs.com/146411/security/apple-3-new-zero-day-bugs.html


3¡¢BatLoaderÔÚ½üÆÚ¹¥»÷ÖмÙÒâChatGPTºÍMidjourney


eSentireÔÚ5ÔÂ16ÈÕ³ÆÆä·¢ÏÖÁËBatLoader¼ÙÒâChatGPTºÍMidjourneyµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬ÕâÁ½ÖÖAI·þÎñ¶¼¼«¶ÈÊÜ»¶Ó­£¬£¬£¬£¬£¬£¬£¬µ«ÊÇûÓйٷ½µÄ¶ÀÁ¢ÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬Óû§Ö»ÄÜͨ¹ýÍøÂç½çÃæºÍDiscordÓëChatGPTºÍMidjourney½»»¥¡£¡£¡£¡£¡£ ¡£¹¥»÷ÕßÀûÓÃÁËÕâÖÖ¿Õȱ£¬£¬£¬£¬£¬£¬£¬½«ËÑË÷AIÀûÓ÷¨Ê½µÄÓû§Òýµ½Ã°ÅÆÍøÒ³¡£¡£¡£¡£¡£ ¡£ÔÚ¼ÙÒâChatGPTµÄ»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬BatLoaderͨ¹ýMSIX Windows App InstallerÎļþºÍRedline StealerÀ´Ï°È¾É豸¡£¡£¡£¡£¡£ ¡£ÔÚ¼ÙÒâMidjourneyµÄ»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬»áÏÂÔØÓÉAshana Global Ltd.ÊðÃûµÄWindowsÀûÓ÷¨Ê½°ü¡£¡£¡£¡£¡£ ¡£


https://www.esentire.com/blog/batloader-impersonates-midjourney-chatgpt-in-drive-by-cyberattacks


4¡¢¼¼ÊõÌṩÉÌScanSourceÔâµ½ÀÕË÷¹¥»÷ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û


¾Ý5ÔÂ17ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬¼¼ÊõÌṩÉÌScanSourceй©ÆäÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¿ÃÅϵͳ¡¢ÒµÎñÔËÓªºÍ¿Í»§ÃÅ»§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£ ¡£5ÔÂ15ÈÕÆðÍ·£¬£¬£¬£¬£¬£¬£¬ScanSourceµÄ¿Í»§³ÆÎÞ·¨½Ó¼û¹«Ë¾µÄÍøÕ¾¡£¡£¡£¡£¡£ ¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ö¤ÊµËûÔÚ5ÔÂ14ÈÕÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£ ¡£Õâ´Î¹¥»÷µÄÓ°ÏìÊǾ޴óµÄ£¬£¬£¬£¬£¬£¬£¬ÓÉÓڸù«Ë¾Ëµ£¬£¬£¬£¬£¬£¬£¬ÔÚ½«À´Ò»¶Î¹¦·òÄÚ£¬£¬£¬£¬£¬£¬£¬Ïò¿Í»§ÌṩµÄ·þÎñ½«»á³öÏÖÑÓ³¤£¬£¬£¬£¬£¬£¬£¬Ô¤¼Æ½«Ó°Ïì±±ÃÀºÍ°ÍÎ÷µÄÒµÎñ¡£¡£¡£¡£¡£ ¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Æä¹É¼ÛÔÚ5ÔÂ17ÈÕ×ÅÂäÁË1.42%£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊǹ¥»÷Ôì³ÉµÄÓ°Ïì¡£¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/scansource-says-ransomware-attack-behind-multi-day-outages/


5¡¢KasperskyÅû¶¶ñÒâ¿ó¹¤Minas¹¥»÷»î¶¯µÄ¼¼Êõϸ½Ú   

 

KasperskyÓÚ5ÔÂ17ÈÕÅû¶Á˶ñÒâ¿ó¹¤Minas¹¥»÷»î¶¯µÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±´ÓÖ´ÐÐPowerShellÆðÍ·³Á½¨ÁËËüµÄϰȾÁ´£ºPowerShell¾ç±¾Í¨¹ý¹¤×÷´òË㷨ʽÔËÐУ¬£¬£¬£¬£¬£¬£¬²¢´ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØlgntoerr.gifÎļþ£¬£¬£¬£¬£¬£¬£¬½âÃܺóÌìÉú.NET DLL£¬£¬£¬£¬£¬£¬£¬²¢´ÓÆä×ÊÔ´ÖÐÌáÈ¡ºÍ½âÃÜÈý¸öÎļþ£¬£¬£¬£¬£¬£¬£¬×îºó»áÔÚÄÚ´æÖÐÌáÈ¡²¢Æô¶¯¿ó¹¤DLL¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬MinasÊÇÒ»¸öʹÓó߶ÈʵÏֵĿ󹤣¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ°µ²ØÆä´æÔÚ¡£¡£¡£¡£¡£ ¡£Ä¿Ç°ÎÞ·¨Æëȫȷ¶¨×î³õµÄPowerShellºÅÁîÊÇÈôºÎÖ´Ðе쬣¬£¬£¬£¬£¬£¬µ«¸÷ÖÖ¼£ÏóÅú×¢ÊÇͨ¹ýGPOÖ´ÐеÄ¡£¡£¡£¡£¡£ ¡£


https://securelist.com/minas-miner-on-the-way-to-complexity/109692/


6¡¢Trend Micro°ä²¼¹ØÓÚ8220 GangÐÂÕ½ÊõµÄ·ÖÎö»ã±¨


5ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬Trend Micro°ä²¼Á˹ØÓÚ8220 GangÐÂÕ½ÊõµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£¸ÃÍÅ»ï×î½ü¼¸¸öÔÂÒ»ÏòºÜ»îÔ¾£¬£¬£¬£¬£¬£¬£¬ËüÀûÓÃÁËOracle WebLogic ServerÖеķì϶£¨CVE-2017-3506£©À´·Ö·¢PowerShell£¬£¬£¬£¬£¬£¬£¬¶øºóÔÚÄÚ´æÖд´½¨ÁíÒ»¸ö»ìºÏµÄPowerShell¾ç±¾¡£¡£¡£¡£¡£ ¡£Õâ¸öеľ籾»á½ûÓÃWindows AMSI¼ì²â²¢Æô¶¯Ò»¸öWindows¶þ½øÔìÎļþ£¬£¬£¬£¬£¬£¬£¬ËüËæºó»áÏνӵ½Ô¶³Ì·þÎñÆ÷ÒÔ¼ìË÷payload¡£¡£¡£¡£¡£ ¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¹¥»÷»¹ÀûÓÃÁËÒ»ÖֺϷ¨Linux¹¤¾ßlwp-download£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÔÚÖ¸±êÖ÷»úÉϱ£ÁôËÁÒâÎļþ¡£¡£¡£¡£¡£ ¡£ 


https://www.trendmicro.com/en_us/research/23/e/8220-gang-evolution-new-strategies-adapted.html