Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      ÿÖܻƽð³Ç¹ÙÍøËÙµÝ???|Gafgyt½©Ê¬ÍøÂçбäÖÖͨ¹ýÈõSSHÃÜÂë¹¥»÷GPU½øÐмÓÃÜ»õ±ÒÍÚ¿ó
      ·¢²¼Ê±¼ä£º2024-08-16 ÔĶÁ´ÎÊý£º 3035 ´Î
      ±¾ÖÜÈȵãʼþÍþвÇ鱨



      1

      Gafgyt½©Ê¬ÍøÂçбäÖÖͨ¹ýÈõSSHÃÜÂë¹¥»÷GPU½øÐмÓÃÜ»õ±ÒÍÚ¿ó

      Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖGafgyt½©Ê¬ÍøÂçбäÖÖ£¬¸Ã±äÖÖͨ¹ýÈõSSHÃÜÂë¹¥»÷»úÆ÷£¬×îÖÕÀûÓñ»¹¥ÏÝʵÀýµÄGPU¼ÆËãÄÜÁ¦½øÐмÓÃÜ»õ±ÒÍÚ¿ó¡£×îÐµĹ¥»÷Á´Éæ¼°±©Á¦ÆÆ½âSSH·þÎñÆ÷µÄÈõÃÜÂ룬ÒÔ²¿ÊðÏÂÒ»½×¶ÎµÄÓÐÐ§ÔØºÉ£¬´Ù½øÊ¹Óá°systemd-net¡±µÄ¼ÓÃÜ»õ±ÒÍÚ¿ó¹¥»÷£¬µ«ÔÚ´Ë֮ǰ»áÖÕÖ¹ÒÑÔÚ±»¹¥ÏÝÖ÷»úÉÏÔËÐеľºÕùÐÔ¶ñÒâÈí¼þ¡£Ëü»¹Ö´ÐÐÒ»¸öÈ䳿Ä£¿é£¬Ò»¸ö»ùÓÚGoµÄSSHɨÃèÆ÷ÃûΪld-musl-x86£¬¸ºÔðɨÃ軥ÁªÍøÖлƽð³Ç¹ÙÍøÐÔ²îµÄ·þÎñÆ÷²¢½«¶ñÒâÈí¼þ´«²¥µ½ÆäËûϵͳ£¬ÓÐЧµØÀ©´ó½©Ê¬ÍøÂçµÄ¹æÄ£¡£Õâ°üÀ¨SSH¡¢TelnetÒÔ¼°ÓëÓÎÏ··þÎñÆ÷ºÍAWS¡¢AzureºÍHadoopµÈÔÆ»·¾³Ïà¹ØµÄƾ¾Ý¡£__

      __

      ²Î¿¼Á´½Ó£º

      https://www.aquasec.com/blog/gafgyt-malware-variant-exploits-gpu-power-and-cloud-native-environments/



      2

      Black BastaÓйØÁªµÄ¹¥»÷ÕßÀûÓÃSystemBC¶ñÒâÈí¼þ½øÐÐÆ¾Ö¤µÁÇÔ

      Ñо¿ÈËÔ±·¢ÏÖ£¬Ò»¸öÓëBlack BastaÀÕË÷Èí¼þ×éÖ¯ÓйصÄÉç»á¹¤³Ì¹¥»÷»î¶¯£¬Ö¼ÔÚ½øÐÐÆ¾Ö¤µÁÇÔ²¢²¿ÊðÃûΪSystemBCµÄ¶ñÒâÈí¼þ¡£ÕâÒ»¹¥»÷Á´Éæ¼°¶à´ÎÈëÇÖ³¢ÊÔ£¬Ä¿±êÊÇÓû§µÄÃô¸ÐÊý¾Ý¡£¹¥»÷ÕßʹÓÃÒ»¸öÃûΪ¡°AntiSpam.exe¡±µÄ¿ÉÖ´ÐÐÎļþ£¬Éù³ÆÏÂÔØµç×ÓÓʼþÀ¬»ø¹ýÂËÆ÷£¬²¢ÒªÇóÓû§ÊäÈëWindowsƾ֤ÒÔÍê³É¸üС£½ÓÏÂÀ´Ö´Ðжà¸ö¶þ½øÖÆÎļþ¡¢DLLÎļþºÍPowerShell½Å±¾£¬°üÀ¨Ò»¸ö»ùÓÚGolangµÄHTTPÐű꣬ÓëÔ¶³Ì·þÎñÆ÷½¨Á¢ÁªÏµ£¬Ò»¸öSOCKS´úÀíºÍSystemBC¡£ÕâЩ¹¥»÷»î¶¯Ö»ÊÇ×î½ü¼¸ÖÜÄÚ·¢ÏֵĴóÁ¿µöÓãºÍÉç»á¹¤³Ì¹¥»÷ÖеÄ×îÐÂÒ»²¨£¬ÍþвÐÐΪÕß»¹Ô½À´Ô½¶àµØÀûÓüٶþάÂë½øÐжñÒâ»î¶¯¡£


      ²Î¿¼Á´½Ó£º

      https://www.rapid7.com/blog/post/2024/08/12/ongoing-social-engineering-campaign-refreshes-payloads/

      3

      RansomHubÀÕË÷Èí¼þ¹¥»÷ÕßÎäÆ÷¿âÐÂÔö¡°EDRKillShifter¡±ÆÆ»µ¹¤¾ß

      Ñо¿ÈËÔ±½üÈÕ·¢ÏÖ£¬Ò»Ãû·¸×ïÍÅ»ïÔÚ¶ÔÒ»×éÖ¯·¢ÆðÃûΪRansomHubµÄÀÕË÷Èí¼þ¹¥»÷ʱ£¬³¢ÊÔ²¿ÊðÁËÒ»¿îÐÂÐ͵ÄEDR£¨¶Ëµã¼ì²âºÍÏìÓ¦£©ÆÆ»µ¹¤¾ß¡°EDRKillShifter¡±¡£ËäÈ»Õâ´ÎÀÕË÷Èí¼þ¹¥»÷ûÓгɹ¦£¬µ«Êºó·ÖÎö½Ò¶ÁËÕâһרΪÖÕÖ¹¶Ëµã±£»¤Èí¼þ¶øÉè¼ÆµÄ¹¤¾ß¡£EDRKillShifter¹¤×÷Ô­ÀíÊÇͨ¹ýÒ»¸ö¡°¼ÓÔØÆ÷¡±¿ÉÖ´ÐÐÎļþ£¬ËüÊÇÒ»¸öºÏ·¨Çý¶¯³ÌÐòµÄ´«µÝ»úÖÆ£¬¸ÃÇý¶¯³ÌÐòÈÝÒ×±»ÀÄÓ᣹¥»÷Õß±ØÐëÖ´ÐдøÓÐÃÜÂë×Ö·û´®µÄÃüÁîÐÐÀ´ÔËÐÐEDRKillShifter¡£Ê¹ÓÃÕýÈ·µÄÃÜÂëÔËÐÐʱ£¬¸Ã¿ÉÖ´ÐÐÎļþ»á½âÃÜǶÈëµÄÃûΪBINµÄ×ÊÔ´£¬²¢ÔÚÄÚ´æÖÐÖ´ÐÐËü¡£BIN´úÂë½âѹ²¢Ö´ÐÐ×îÖÕµÄÓÐÐ§ÔØºÉ¡£Õâ×îÖÕµÄÓÐÐ§ÔØºÉ£¬ÓÃGo±à³ÌÓïÑÔ±àд£¬»á·ÅÖò¢ÀûÓöàÖÖ²»Í¬µÄÒ×Êܹ¥»÷¡¢ºÏ·¨µÄÇý¶¯³ÌÐòÒÔ»ñÈ¡×㹻ȨÏÞÒÔÈ¡ÏûEDR¹¤¾ßµÄ±£»¤¡£¸Ã¹¤¾ßµÄÑù±¾·ÖÎöÏÔʾ£¬ËùÓÐÑù±¾¹²ÏíÏàͬµÄ°æ±¾Êý¾Ý£¬Ô­Ê¼ÎļþÃûΪLoader.exe£¬²úÆ·ÃûΪARK-Game£¬¶þ½øÖÆÎļþµÄÓïÑÔÊôÐÔÊǶíÓï¡£ÕâЩÑù±¾¶¼ÐèÒª´«µÝ¸øÃüÁîÐеÄΨһ64×Ö·ûÃÜÂë¡£Èç¹ûÃÜÂë´íÎ󣨻òδÌṩ£©£¬Ëü½«²»»áÖ´ÐС£µ±Ö´ÐÐʱ£¬EDRKillShifter½«Ò»¸öÃûΪBINµÄ¼ÓÃÜ×ÊÔ´¼ÓÔØµ½ÄÚ´æÖУ¬»¹»á½«¸ÃÊý¾Ý¸´ÖƵ½Ò»¸öÐÂÎļþConfig.iniÖУ¬²¢½«¸ÃÎļþдÈëÖ´Ðжþ½øÖÆÎļþµÄͬһÎļþϵͳλÖá£

      _____

      ___

      ²Î¿¼Á´½Ó£º

      https://news.sophos.com/en-us/2024/08/14/edr-kill-shifter/

      4

      FBI¹Ø±ÕÁ˹¥»÷ÊýÊ®¼Ò¹«Ë¾ÀÕË÷Èí¼þÍÅ»ïµÄ·þÎñÆ÷

      FBI¿ËÀû·òÀ¼·Ö¾ÖÐû²¼³É¹¦ÆÆ»ñÁËÓÉÍøÃû¡°Brain¡±Áìµ¼µÄÀÕË÷Èí¼þ×éÖ¯¡°Radar/Dispossessor¡±£¬²¢²ð³ýÁËÈý̨ÃÀ¹ú·þÎñÆ÷¡¢Èý̨Ӣ¹ú·þÎñÆ÷¡¢Ê®°Ę̈µÂ¹ú·þÎñÆ÷¡¢°Ë¸öÃÀ¹úÓòÃûºÍÒ»¸öµÂ¹úÓòÃû¡£×Ô2023Äê8Ô³ÉÁ¢ÒÔÀ´£¬Radar/DispossessorѸËÙ·¢Õ¹³ÉΪһ¸ö¹ú¼ÊÐÔÓ°ÏìÁ¦µÄÀÕË÷Èí¼þ×éÖ¯£¬×¨ÃÅÕë¶ÔÖÐСÐÍÆóÒµ¼°×éÖ¯£¬Éæ¼°Éú²ú¡¢¿ª·¢¡¢½ÌÓý¡¢Ò½ÁÆ¡¢½ðÈÚ·þÎñºÍÔËÊäµÈ¶à¸öÐÐÒµ¡£µ÷²é·¢ÏÖ£¬¸Ã×éÖ¯ÔÚÃÀ¹ú¼°°¢¸ùÍ¢¡¢°Ä´óÀûÑÇ¡¢±ÈÀûʱ¡¢°ÍÎ÷¡¢ºé¶¼À­Ë¹¡¢Ó¡¶È¡¢¼ÓÄô󡢿ËÂÞµØÑÇ¡¢ÃØÂ³¡¢²¨À¼¡¢Ó¢¹ú¡¢°¢ÁªÇõºÍµÂ¹úµÈ¹ú¼Ò¹¥»÷ÁË43¼Ò¹«Ë¾¡£FBIÔÚµ÷²éÆÚ¼äʶ±ð³öÁ˶à¸öÓëBrain¼°ÆäÍŶÓÏà¹ØµÄÍøÕ¾¡£¾¡¹ÜĿǰÊÜÓ°ÏìµÄÆóÒµºÍ×éÖ¯×ÜÊýÉÐδȷ¶¨£¬FBI¹ÄÀøÈκÎÓйØÓÚBrain»òRadar RansomwareµÄÐÅÏ¢£¬»òÆäÒµÎñ»ò×éÖ¯Ôø³ÉΪÀÕË÷Èí¼þÄ¿±ê»òÊܺ¦ÕßµÄÈË£¬ÁªÏµ»¥ÁªÍø·¸×ïͶËßÖÐÐÄ»ò²¦´ò1-800-£ã£á£ì£ì-FBI£¬Éí·Ý¿ÉÒÔ±£³ÖÄäÃû¡£___

      ___


      ²Î¿¼Á´½Ó£º

      https://www.fbi.gov/contact-us/field-offices/cleveland/news/international-investigation-leads-to-shutdown-of-ransomware-group?7194ef805fa2d04b0f7e8c9521f97343

      5

      ÀÕË÷Èí¼þ×éÖ¯RhysidaÉù³ÆÇÔÈ¡Á½¼ÒÒ½ÁÆÏµÍ³Êý¾Ý

      ÀÕË÷Èí¼þ×éÖ¯RhysidaÐû³Æ¶ÔÁ½¼ÒеÄÒ½ÁÆÏµÍ³¡ª¡ªBayhealthºÍCommunity Care Alliance£¨CCA£©½øÐÐÁË´ó¹æÄ£Êý¾ÝµÁÇÔ¡£RhysidaÍþв½«»¼ÕßµÄÃô¸Ð½¡¿µºÍ¸öÈËÐÅÏ¢ÔÚ°µÍøÉϳöÊÛ»ò¹«¿ª¡£Î»ÓÚÌØÀ­»ªÖݵķÇÓªÀûÒ½ÁÆÏµÍ³BayhealthÓµÓжà¼ÒÒ½Ôº¡¢4000ÃûÔ±¹¤ºÍ650ÃûÒ½Éú¼°ÆäËûÁÙ´²Ò½»¤ÈËÔ±¡£RhysidaÉù³ÆÇÔÈ¡ÁËBayhealth»¼ÕߵĸöÈËÐÅÏ¢£¬²¢ÒªÇóÖ§¸¶25¸ö±ÈÌØ±Ò£¨Ô¼150ÍòÃÀÔª£©×÷ΪÊê½ð¡£Í¬Ê±£¬Î»ÓÚÂ޵µºµÄCommunity Care AllianceÌṩÐÄÀí½¡¿µ¡¢³Éñ«¡¢×¡·¿ºÍ´´ÉËÏà¹ØÎÊÌâµÄ·þÎñ¡£RhysidaÉù³ÆÇÔÈ¡ÁËÒ»¸ö°üº¬³¬¹ý2.5 TBÊý¾ÝµÄSQLÊý¾Ý¿â£¬ÄÚº¬µØÖ·¡¢Éç»á»Æ½ð³Ç¹ÙÍøºÅÂë¡¢µç»°ºÅÂëºÍÐÅÓÿ¨ºÅÂëµÈ¸öÈËÐÅÏ¢¡£CCAÉÐδ¶Ô´Ë×÷³ö¹«¿ª»ØÓ¦»òÔÚÆäÍøÕ¾ÉÏ·¢²¼Ïà¹ØÉùÃ÷¡£___

      ___

      ²Î¿¼Á´½Ó£º

      https://www.govinfosecurity.com/rhysida-claims-major-data-theft-from-2-more-health-systems-a-25997

      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿


      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿